<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mike Jones: self-issued &#187; Phishing Resistance</title>
	<atom:link href="http://self-issued.info/?feed=rss2&#038;cat=19" rel="self" type="application/rss+xml" />
	<link>http://self-issued.info</link>
	<description>Musings on Digital Identity</description>
	<lastBuildDate>Wed, 01 Sep 2010 00:29:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
	<url>http://self-issued.info/feed_header_image.png</url> 
	<title>Mike Jones: self-issued</title> 
	<link>http://self-issued.info</link> 
	<width>120</width> 
	<height>80</height> 
	</image>		<item>
		<title>An Experimental Identity Selector for OpenID</title>
		<link>http://self-issued.info/?p=235</link>
		<comments>http://self-issued.info/?p=235#comments</comments>
		<pubDate>Mon, 16 Nov 2009 11:10:11 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[JanRain]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=235</guid>
		<description><![CDATA[The OpenID community has been talking about the value that an optional active client could bring to OpenID for well over a year.  To concretely explore this possibility, as many of you know by now, a team at Microsoft built a prototype multi-protocol identity selector supporting OpenID, starting with CardSpace 2, which I and [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/openid-logo.png" alt="OpenID logo" /></span>The OpenID community has been talking about the value that an optional active client could bring to OpenID for well over a year.  To concretely explore this possibility, as many of you know by now, a team at Microsoft built a prototype multi-protocol identity selector supporting OpenID, starting with CardSpace 2, which I and others demonstrated at the <a href="http://openid.eventbrite.com/">OpenID Summit</a> and the <a href="http://www.internetidentityworkshop.com/">Internet Identity Workshop</a>.  We did this to stimulate discussion and engage the community about the value of adding active client support to OpenID.  And I’ll say up front that enormous thanks go to <a href="http://joseph.myplaxo.com/">Joseph Smarr at Plaxo</a>, the team at <a href="http://www.janrain.com/">JanRain</a>, and <a href="http://blog.nerdbank.net/">Andrew Arnott</a> for building demonstration relying parties that worked with the prototype, which made the demonstrations possible.</p>
<p>While you may have read about it <a href="http://www.identityblog.com/?p=1070">on Kim’s blog</a> and many of you were there in person, I wanted to capture screen shots from the demos to make them available, so those who weren’t there can join the discussion as well.  Plus, I’ve posted <a href="http://self-issued.info/presentations/An_Experimental_Active_Client_for_OpenID.pdf">the presentation that accompanied the demos</a>, rather than reproducing that content here.  Now, on to the demo, which closely follows the one actually given at the Summit…</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">Using a selector for the first time</font></strong></p>
<p>I start by demonstrating the user experience for a first-time selector user at a a selector-enabled OpenID relying party.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Plaxo_signin.png" alt="Plaxo signin" /></span><br />
The first screen shot shows a standard Plaxo login screen, but augmented behind the covers to enable it to pass its OpenID authentication request parameters to an active client, if present.  I will click on the “Sign in with OpenID” button on the Plaxo signin page, invoking the selector.</p>
<p>In the prototype, selector-enabled relying parties use a variant of the Information Card object tag to communicate their request parameters to the selector.  The object tag parameters used on Plaxo’s RP page are:<br />
<code>&lt;object type="application/x-informationCard" id=infoCardObjectTag&gt;<br />
&lt;param name=protocol value="http://specs.openid.net/auth/2.0"/&gt;<br />
&lt;param name=tokenType value="http://specs.openid.net/auth/2.0"/&gt;<br />
&lt;param name=issuer value="Google.com/accounts/o8/id Yahoo.com myOpenID.com"/&gt;<br />
&lt;param name=issuerExclusive value=false/&gt;<br />
&lt;param name=OpenIDAuthParameters value=<br />
"openid.ns:http://specs.openid.net/auth/2.0<br />
openid.return_to:http://www.plaxo.com/openid?actionType=complete<br />
openid.realm:http://*.plaxo.com/<br />
openid.ns.sreg:http://openid.net/extensions/sreg/1.1<br />
openid.sreg.required:email<br />
openid.sreg.optional:fullname,nickname,dob,gender,postcode,country,language,timezone<br />
openid.sreg.policy_url:http://www.plaxo.com/about/privacy_policy<br />
"/&gt;<br />
&lt;/object&gt;<br />
</code></p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Plaxo_empty_selector.png" alt="Plaxo empty selector" /></span><br />
Here I’ve clicked on the “Sign in with OpenID” button, invoking the selector.  (The “Google” and “Yahoo” buttons would have invoked the selector too.)  This shows the first-time selector user experience, where it isn’t yet remembering any OpenIDs for me.  The three OPs suggested by Plaxo – Google, Yahoo, and MyOpenID, are shown, as well as the option to type in a different OpenID.  I click on the Yahoo suggestion.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Plaxo_Yahoo_first_time.png" alt="Plaxo Yahoo first time" /></span><br />
Clicking on Plaxo’s Yahoo suggestion resulted in a Yahoo OpenID card being made available for use.  Note that, by default, the selector will remember this card for me.  (Those of you who know OpenID well are probably thinking “Where did the selector get the Yahoo logo and friendly name string”?  For this prototype, they are baked into the selector.  Longer term, the right way is for the selector to retrieve these from the OP’s discovery document.  The OpenID UX working group is considering defining discovery syntax for doing just that.)</p>
<p>Once I’ve clicked “OK” to select the identity to use, the selector (not the RP) redirects the browser to the OP – in this case, to the Yahoo login page.  The selector’s work is done at this point.  The remainder of the protocol flow is standard OpenID 2.0.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Yahoo_Plaxo_signin.png" alt="Yahoo Plaxo signin" /></span><br />
This is the standard Yahoo OpenID signin page, which the selector redirected the browser to after I choose to use the suggested Yahoo OpenID.  I sign into Yahoo.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Yahoo_Plaxo_permission.png" alt="Yahoo Plaxo permission" /></span><br />
The signin page is followed by the standard Yahoo permissions page.  I click “Agree”.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Plaxo_signed_in.png" alt="Plaxo signed in" /></span><br />
After logging with Yahoo, I’m redirected back to Plaxo.  Because I’d previously associated my Yahoo OpenID with my Plaxo account, I’m now logged into Plaxo.  My status “Michael is demonstrating an OpenID selector at the OpenID Summit”, which I updated live during the demo at the OpenID Summit, is shown.</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">Selector defaults to the OpenID last used at the site</font></strong></p>
<p>At this point in the demo, I’ve signed out of Plaxo and returned to the selector-enabled sign-in page.  After clicking “Sign in with OpenID” again, the selector reappears.</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Plaxo_Yahoo_second_time.png" alt="Plaxo Yahoo second time" /></span><br />
This time, the selector has remembered the OpenID I last used at the site and tells me when I last used it there.  (This is one of the ways that a selector can help protect people from phishing.)  By default, the OpenID last used at a relying party is automatically selected – in this case, Yahoo.  I click “OK” to select it, with the rest of the flow again being the standard OpenID 2.0 flow.</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">Experience at a new RP plus a trusted OP experience</font></strong></p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Interscope_homepage.png" alt="Interscope homepage" /></span><br />
<a href="http://www.janrain.com/">JanRain</a> selector-enabled several production sites, including interscope.com, uservoice.com, and pibb.com, which use JanRain’s hosted <a href="http://www.janrain.com/products/rpx">RPX service</a>.  This could be done with no impact on users without a selector by using JavaScript to detect whether a selector is present or not, and customizing the page accordingly.  The page above is the production Interscope Records page.  I click the OpenID button on the right under the “Join The Community” banner.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Interscope_signon.png" alt="Interscope signon" /></span><br />
The OpenID button invokes the RPX “NASCAR” experience.  (Arguably, this page could be omitted from the experience if a selector is detected.)  I click the OpenID button on the “NASCAR” page.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Interscope_Yahoo_never_used_here.png" alt="Interscope Yahoo never used here" /></span><br />
The selector is invoked by Interscope (really, by RPX) to let me choose an OpenID.  My Yahoo OpenID is shown and the “Never used here” tells me that I haven’t used it at this site before.  I could choose it by clicking OK or hitting Enter.  Instead, I click the “Other OpenIDs” button to explore other options.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Interscope_other_OpenIDs.png" alt="Interscope other OpenIDs" /></span><br />
The “Other OpenIDs” tile shows me the OpenID providers suggested by Interscope – in this case, Flickr, Yahoo, and Google.  I click on the Google suggestion.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Interscope_Google_first_time.png" alt="Interscope Google first time" /></span><br />
The selector has created a Google OpenID card for me to use.  It is marked “Verified” because it (like Yahoo) was on a whitelist in the selector and considered “safe” to use.  Of course, in production use, such a whitelist would have to be maintained by a neutral third party or parties and dynamically updated.  In the prototype, we hard-coded a few common providers so we could show a user experience that relies on a whitelist of OPs, to start the discussion about that possibility.  I hit Enter to use the new Google card at Interscope.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Google_UniversalMusic_signin.png" alt="Google UniversalMusic signin" /></span><br />
Once I chose to use my Google card, the selector redirected me to Google’s signin page, with the actual RP for Interscope being signup.universalmusic.com.  I sign into Google.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Google_UniversalMusic_permission.png" alt="Google UniversalMusic permission" /></span><br />
Following signin, Google asks me permission to release information to signup.universalmusic.com.  I allow it.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Interscope_registration.png" alt="Interscope registration" /></span><br />
I’m redirected back to Interscope, which asked me to complete a sign-up process by supplying more information via a web form.</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">Selector remembering which OpenID&#8217;s you&#8217;ve used where</font></strong></p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/Interscope_Google_second_time.png" alt="Interscope Google second time" /></span><br />
When visiting Interscope again after having signed out, signing in with OpenID shows me that I last used my Google OpenID here.  For that reason, it’s selected as the default.  I can also see that I haven&#8217;t used my Yahoo OpenID here.</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">Trusted versus untrusted OpenIDs</font></strong></p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_signin.png" alt="test-id signin" /></span><br />
<a href="http://blog.nerdbank.net/">Andrew Arnott</a> created the first selector-enabled relying party site for us, which is shown above.  I click “Log in using your OpenID Selector”.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_Google_never_used_here.png" alt="test-id Google never used here" /></span><br />
Now I have both Yahoo and Google cards, but neither have been used at test-id.org.  I notice that I can get more details about my cards, and click “More details” on the Google card.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_Google_more_details.png" alt="test-id Google more details" /></span><br />
“More details” tells me where and when I used the card (signup.universalmusic.com), the discovered OpenID endpoint, and that this OpenID was on the selector’s whitelist.  I could now use either of these OpenIDs, but I select “Other OpenIDs” instead.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_other_OpenIDs.png" alt="test-id other OpenIDs" /></span><br />
The “Other OpenIDs” panel shows me OPs suggested by the site, as well as a dialog box to enter another OpenID.  I decide to enter my blog URL self-issued.info, which is also an OpenID.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_self-issued_being_entered.png" alt="test-id self-issued being entered" /></span><br />
Here I’m entering my blog URL self-issued.info into the selector.  I then click Verify or OK to have the selector perform discovery on the OpenID to add it as one of my choices.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_self-issued_not_verified.png" alt="test-id self-issued not verified" /></span><br />
Discovery has succeeded, but the OP my blog is delegated to, signon.com, is not on the selector’s whitelist.  Because it’s not, a warning shield is shown, rather than the OP logo.  I’ll also have to make an explicit decision to trust this OpenID provider before the selector will let me use it.  The same would have happened if I chose an OP suggested by the RP if the OP was not on the whitelist.  This is another aspect of the selector’s phishing protection.  I check the “Continue, I trust this provider” box.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_self-issued_trusted.png" alt="test-id self-issued trusted" /></span><br />
After checking the “Continue, I trust this provider” box, the warning shield is replaced by either the OP logo, if it can be discovered, or a generic OpenID logo, as in this case.  I click OK to use this OpenID.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/signon_test-id_signin.png" alt="signon test-id signin" /></span><br />
The selector follows my delegation link from self-issued.info and redirects me to signon.com.  (Ping, are you going to fix the signon.com UX issue above someday?)  I sign into signon.com.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_signed_in.png" alt="test-id signed in" /></span><br />
Having signed into my OpenID at signon.com, I’m redirected back to the test site, which received an authentication response from the OP.  I click “Reset test” to sign out, in preparation for another test.</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">More details</font></strong></p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_self-issued_second_time.png" alt="test-id self-issued second time" /></span><br />
Upon a second visit to test-id.org, the selector has remembered that I last used the OpenID self-issued.info, which is actually delegated to mbj.signon.com.  I click “More details” to learn more about this OpenID.</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_self-issued_more_details.png" alt="test-id self-issued more details" /></span><br />
“More details” tells me where and when I last used the OpenID and that the OpenID has been verified.  But unlike my Google OpenID, which was verified via the whitelist, I told the selector to trust this OpenID myself.</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">Delegation to a trusted OP</font></strong></p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_davidrecordon_being_entered.png" alt="test-id davidrecordon being entered" /></span><br />
At the OpenID Summit, people wanted to see the untrusted user experience again, so I entered an OpenID that I was sure wasn’t on our built-in whitelist – davidrecordon.com.  However, verifying the OpenID actually brought me and those in attendance a surprise…</p>
<p>&nbsp;</p>
<p><span class="plain"><img src="http://self-issued.info/images/OpenID_Selector/test-id_davidrecordon_verified.png" alt="test-id davidrecordon verified" /></span><br />
Because davidrecordon.com is delegated to myopenid.com, which is on the whitelist, it turns out that the prototype considered davidrecordon.com to be trusted as well.  Upon reflection, this is probably the right behavior, but I’d never seen it until giving the demo live.  (Great job, Oren!)  I tried factoryjoe.com next and got the same result.  Finally Will Norris helped me out by saying that willnorris.com isn’t delegated, so we got to see the untrusted user experience again.</p>
<p>&nbsp;</p>
<hr />
<strong><font size="4">Conclusion</font></strong></p>
<p>I’d like to thank Chuck Reeves and Oren Melzer for quickly building a killer prototype and to thank Ariel Gordon and Arun Nanda for helping design it, as well as others, both from Microsoft and other companies, who provided feedback that helped us fine-tune it as we built it.  See <a href="http://self-issued.info/presentations/An_Experimental_Active_Client_for_OpenID.pdf">the presentation</a> for a much more comprehensive list of thank-yous.</p>
<p>I’ll close by saying that in the OpenID v.Next planning meeting at IIW, there was an unopposed consensus that optional active client support should be included as a feature of v.Next.  Hopefully our demo, as well as those by others, including Markus Sabadello of <a href="http://www.eclipse.org/higgins/">Higgins</a>, helped the community decide that this is a good idea by enabling people to concretely experience the benefits that an active client can bring to OpenID.  If so, I’d call the experiment a success!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=235</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>PAPE Specification Approved and Ready for Use</title>
		<link>http://self-issued.info/?p=98</link>
		<comments>http://self-issued.info/?p=98#comments</comments>
		<pubDate>Wed, 31 Dec 2008 05:33:12 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Safety]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=98</guid>
		<description><![CDATA[As I just announced on openid.net, OpenID Provider Authentication Policy Extension 1.0 (PAPE) has just been just been approved as an OpenID specification.  Deployment of PAPE will go a long way towards mitigating the phishing vulnerabilities of password-based OpenIDs by enabling OpenID Relying Parties to request that OpenID Providers employ phishing-resistant authentication methods when [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/openid-logo.png" alt="OpenID logo" /></span>As <a href="http://openid.net/2008/12/31/pape-approved-as-an-openid-specification/">I just announced on openid.net</a>, <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0.html">OpenID Provider Authentication Policy Extension 1.0</a> (PAPE) has just been just been approved as an OpenID specification.  Deployment of PAPE will go a long way towards mitigating the <a href="http://self-issued.info/?p=73">phishing vulnerabilities of password-based OpenIDs</a> by enabling OpenID Relying Parties to request that OpenID Providers employ phishing-resistant authentication methods when authenticating users and for OpenID Providers to inform Relying Parties whether this (and other) authentication policies were satisfied.</p>
<p>It’s tempting to say that the approval of the specification is the fulfillment of the promise of the <a href="http://blogs.verisign.com/infrablog/2007/02/verisign_microsoft_partners_to_1.php">OpenID/CardSpace collaboration for phishing-resistant authentication</a> i<a href="http://www.microsoft.com/Presspass/exec/billg/speeches/2007/02-06RSA.mspx">ntroduced by Bill Gates and Craig Mundie</a> the RSA Security Conference last year, but it’s really just an enabling step.  The true value of PAPE will come when it is widely deployed by security-conscious OpenID Relying Parties, and the use of phishing-resistant authentication methods, such as Information Cards and others, is widespread and commonplace.  Let the deployments begin!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=98</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PAPE Specification Entering Public Review Period</title>
		<link>http://self-issued.info/?p=88</link>
		<comments>http://self-issued.info/?p=88#comments</comments>
		<pubDate>Thu, 23 Oct 2008 03:52:57 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=88</guid>
		<description><![CDATA[The OpenID Provider Authentication Policy Extension (PAPE) specification enables an OpenID Relying Party to request that the OpenID Provider satisfy a set of policies specified by the RP when the OP logs the user in.  And it likewise enables the OP to reply to the RP saying which of the policies it satisfied.
One of [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/openid-logo.png" alt="OpenID logo" /></span>The <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-07.html">OpenID Provider Authentication Policy Extension (PAPE) specification</a> enables an OpenID Relying Party to request that the OpenID Provider satisfy a set of policies specified by the RP when the OP logs the user in.  And it likewise enables the OP to reply to the RP saying which of the policies it satisfied.</p>
<p>One of these policies lets the RP request that the OP perform phishing-resistant authentication, the need for which has been discussed <a href="http://self-issued.info/?p=73">here</a> and <a href="http://www.identityblog.com/?p=923">elsewhere</a>.  Another capability I’m a fan of is the ability for the RP to “freshness date” the login, requiring that the OP actively authenticate the user if the current authentication was performed longer ago than an RP-specified number of seconds.</p>
<p>The PAPE Working Group just <a href="http://openid.net/2008/10/23/pape-specification-review-period-commencing/">recommended that the OpenID Foundation members approve</a> <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-07.html">the current draft (Draft 7)</a> as an OpenID specification.  Today starts a 60 day review period required as part of the <a href="http://openid.net/foundation/intellectual-property/">OpenID specification process</a>, which occurs prior to an approval vote by the members.  PAPE is the first new specification to be produced under this process, and I’m pleased as an OpenID board member to report we now have an existence proof that the process works (or more precisely, we will once this specification is approved).</p>
<p>There are already four implementations of this spec in existence and even better, there are public testing endpoints for these implementations where you can kick the tires.  You can try the DotNetOpenId and JanRain implementations at these sites:</p>
<ul>
<li><a href="http://nerdbank.org/pape.demo/">http://nerdbank.org/pape.demo/</a></li>
<li><a href="http://openidenabled.com/php-openid/trunk/examples/consumer/">http://openidenabled.com/php-openid/trunk/examples/consumer/</a> and <a href="http://openidenabled.com/php-openid/trunk/examples/server/server.php">http://openidenabled.com/php-openid/trunk/examples/server/server.php</a></li>
<li><a href="http://openidenabled.com/python-openid/trunk/examples/consumer/">http://openidenabled.com/python-openid/trunk/examples/consumer/</a> and <a href="http://openidenabled.com/python-openid/trunk/examples/server/">http://openidenabled.com/python-openid/trunk/examples/server/</a></li>
<li><a href="http://openidenabled.com/ruby-openid/trunk/examples/consumer/">http://openidenabled.com/ruby-openid/trunk/examples/consumer/</a> and <a href="http://openidenabled.com/ruby-openid/trunk/examples/">http://openidenabled.com/ruby-openid/trunk/examples/</a></li>
</ul>
<p>You should also be able to test the relying parties with <a href="https://www.signon.com/">signon.com</a> and <a href="https://www.myopenid.com/">myopenid.com</a>, which currently implement earlier drafts, since the authentication policy syntax didn’t change.</p>
<p>This spec was a collaborative effort among a number of people.  <a href="http://daveman692.livejournal.com/">David Recordon</a> wrote the initial drafts last year, with input from the people thanked in <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-02.html">Draft 2</a>.  Since then, <a href="http://www.sakimura.org/en/modules/wordpress/">Nat Sakimura</a> was responsible for the generalization of the authentication levels to enable levels other than just those defined by NIST be used.  <a href="http://www.links.org/">Ben Laurie</a> was an ardent and practical security advocate (as always).  <a href="http://www.allentom.com/">Allen Tom</a> was a proponent of the strong “level 0” description.  <a href="http://blog.nerdbank.net/">Andrew Arnott</a> of the <a href="http://code.google.com/p/dotnetopenid/">DotNetOpenId project</a> shared his experiences building an independent implementation with the working group, helping improve the specification.  And <a href="http://thread-safe.livejournal.com/">John Bradley</a> was a never-ending source of common sense, although he would deny it to your face if asked.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=88</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Digital Identity Podcast for MySuccessGateway</title>
		<link>http://self-issued.info/?p=79</link>
		<comments>http://self-issued.info/?p=79#comments</comments>
		<pubDate>Fri, 04 Jul 2008 07:32:17 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Claims]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=79</guid>
		<description><![CDATA[Kim Cameron and I recorded a podcast on digital identity for MySuccessGateway this week at the invitation of Jim Peake of SpeechRep Consulting.  Jim was a gracious, informed, and enthusiastic host during our conversation, which covered a wide range of digital identity topics including identity theft, shared secrets, privacy, Information Cards and the Information [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/microphone.png" alt="Microphone" /><a href="http://www.identityblog.com/">Kim Cameron</a> and I recorded a <a href="http://www.mysuccessgateway.com/guru/podcasts.php?id=95">podcast on digital identity</a> for <a href="http://www.mysuccessgateway.com/">MySuccessGateway</a> this week at the invitation of Jim Peake of <a href="http://speechrep.com/">SpeechRep Consulting</a>.  Jim was a gracious, informed, and enthusiastic host during our conversation, which covered a wide range of digital identity topics including identity theft, shared secrets, privacy, Information Cards and the <a href="http://informationcard.net/">Information Card Foundation</a>, the value of verified claims, business models for identity providers, password fatigue, defeating phishing attacks, <a href="http://openid.net/">OpenID</a>, why interoperability is essential and the <a href="http://osis.idcommons.net/">interoperability testing</a> the industry is doing together to make it a reality, some of the identity products that are shipping and forthcoming, and the <a href="http://www.identityblog.com/?p=354">Laws of Identity</a>.   He even asked us how we felt about Bill Gates’ retirement, as a kicker.</p>
<p>If that sounds interesting to you, <a href="http://www.mysuccessgateway.com/guru/podcasts.php?id=95">give it a listen</a>…</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=79</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Personal Perspective on the Information Card Foundation Launch</title>
		<link>http://self-issued.info/?p=76</link>
		<comments>http://self-issued.info/?p=76#comments</comments>
		<pubDate>Tue, 24 Jun 2008 10:28:38 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Bandit Project]]></category>
		<category><![CDATA[Higgins Project]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Pamela Project]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=76</guid>
		<description><![CDATA[
In May 2005, when I wrote the whitepaper “Microsoft’s Vision for an Identity Metasystem”, these sentences were aspirational:

Microsoft&#8217;s implementation will be fully interoperable via WS-* protocols with other identity selector implementations, with other relying party implementations, and with other identity provider implementations.
Non-Microsoft applications will have the same ability to use &#34;InfoCard&#34; to manage their identities [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><a href="http://informationcard.net/"><img src="http://self-issued.info/images/icf_banner.jpg" alt="Information Card Foundation banner" /></a></span></p>
<p>In May 2005, when I wrote the whitepaper “<a href="http://msdn.microsoft.com/en-us/library/ms996422.aspx">Microsoft’s Vision for an Identity Metasystem</a>”, these sentences were aspirational:</p>
<blockquote><p>
Microsoft&#8217;s implementation will be fully interoperable via WS-* protocols with other identity selector implementations, with other relying party implementations, and with other identity provider implementations.</p>
<p>Non-Microsoft applications will have the same ability to use &quot;InfoCard&quot; to manage their identities as Microsoft applications will.  Non-Windows operating systems will be able to be full participants of the identity metasystem we are building in cooperation with the industry.  Others can build an entire end-to-end implementation of the metasystem without any Microsoft software, payments to Microsoft, or usage of any Microsoft online identity service.
</p></blockquote>
<p>Now they are present-day reality.</p>
<p>This didn’t happen overnight and it wasn’t easy.  Indeed, despite it being hard, the identity industry saw it as vitally important, and made it happen through concerted, cooperative effort.  Key steps along the way included the <a href="http://www.identityblog.com/?p=354">Laws of Identity</a>, the Berkman Center Identity Workshops in 2005 and <a href="http://www.identitymash-up.org/">2006</a>, the <a href="http://iiw.idcommons.net/">Internet Identity Workshops</a>, the establishment of <a href="http://osis.idcommons.net/">OSIS</a>, the formation of the <a href="http://www.eclipse.org/higgins/">Higgins</a>, <a href="http://www.bandit-project.org/">Bandit</a>, <a href="https://opensso.dev.java.net/">OpenSSO</a>, <a href="http://xmldap.org/">xmldap</a>, and <a href="http://pamelaproject.com/">Pamela</a> projects, publication of the <a href="http://self-issued.info/?p=8">Identity Selector Interoperability Profile</a>, the <a href="http://www.microsoft.com/interop/osp/">Open Specification Promise</a>, the OSIS user-centric identity interops (<a href="http://self-issued.info/?p=12">I1 rehearsal</a>, <a href="http://self-issued.info/?p=25">I1</a>, <a href="http://self-issued.info/?p=39">I2</a>, <a href="http://self-issued.info/?p=68">I3</a>, and the current <a href="http://osis.idcommons.net/wiki/I4_User-Centric_Identity_Interop_through_Digital_ID_World_2008">I4</a>), the <a href="http://www.identityblog.com/?p=668">OpenID anti-phishing collaboration</a>, the <a href="http://self-issued.info/?p=17">Information Card icon</a>, and of course numerous software releases by individuals and companies for all major development platforms, including releases by <a href="http://blog.beuchelt.org/2008/03/31/Lifting+The+Curtain.aspx">Sun</a>, <a href="http://www.ca.com/files/whitepapers/ca_microsoft_usercentric_identity_wp.pdf">CA</a>, and <a href="http://www.internetnews.com/infra/article.php/3748166/IBM+Expands+Federated+Identity+Effort.htm">IBM</a>.</p>
<p>Of course, despite all the groundwork that’s been laid and the cooperation that’s been established, the fun is really just beginning.  What most excites me about the group of companies that have come together around Information Cards is that many of them are potential <b><i>deployers</i></b> of Information Cards, rather than just being producers of the underlying software.</p>
<p>The Internet is still missing a much-needed ubiquitous identity layer. The good news is that the broad industry collaboration that has emerged around Information Cards and the visual Information Card metaphor is a key enabler for building it, together in partnership with other key technologies and organizations.</p>
<p>The members of the Information Card Foundation (and many others also working with us) share this vision from the conclusion of <a href="http://msdn.microsoft.com/en-us/library/ms996422.aspx">the whitepaper</a>:</p>
<blockquote><p>
We believe that many of the dangers, complications, annoyances, and uncertainties of today&#8217;s online experiences can be a thing of the past.  Widespread deployment of the identity metasystem has the potential to solve many of these problems, benefiting everyone and accelerating the long-term growth of connectivity by making the online world safer, more trustworthy, and easier to use.
</p></blockquote>
<p>In that spirit, please join me in welcoming all of these companies and individuals to the <a href="http://informationcard.net/">Information Card Foundation</a>: founding corporate board members <a href="http://www.equifax.com/">Equifax</a>, <a href="http://www.google.com/">Google</a>, <a href="http://www.microsoft.com/">Microsoft</a>, <a href="http://www.novell.com/">Novell</a>, <a href="http://www.oracle.com/">Oracle</a>, and <a href="https://www.paypal.com/">PayPal</a>; founding individual board members <a href="http://www.identityblog.com/">Kim Cameron</a>, <a href="http://eternaloptimist.wordpress.com/">Pamela Dingle</a>, <a href="http://blog.pingidentity.com/blog/ctotalk/">Patrick Harding</a>, <a href="http://ahodgkinson.wordpress.com/">Andrew Hodgkinson</a>, <a href="http://www.links.org/">Ben Laurie</a>, <a href="http://ignisvulpis.blogspot.com/">Axel Nennker</a>, <a href="http://www.equalsdrummond.name/">Drummond Reed</a>, <a href="http://www.socialphysics.org/mary_ruddy.html.htm">Mary Ruddy</a>, and <a href="http://incontextblog.com/">Paul Trevithick</a>; launch members <a href="http://www.arcot.com/">Arcot Systems</a>, <a href="http://www.aristotle.com/">Aristotle</a>, <a href="http://www.ate-software.net/">A.T.E. Software</a>, <a href="https://www.backgroundchecks.com/">BackgroundChecks.com</a>, <a href="http://www.corisecio.com/">CORISECIO</a>, <a href="http://fugensolutions.com/">FuGen Solutions</a>, <a href="http://www.fun.de/">Fun Communications</a>, <a href="http://www.gemalto.com/">Gemalto</a>, <a href="http://www.idology.com/">IDology</a>, <a href="http://www.ipcommerce.com/">IPcommerce</a>, <a href="http://www.ootao.com/">ooTao</a>, <a href="http://www.parity.com">Parity Communications</a>, <a href="http://www.pingidentity.com/">Ping Identity</a>, <a href="http://www.privo.com/">Privo</a>, <a href="http://www.wave.com/">Wave Systems</a>, and <a href="http://wso2.com/">WSO2</a>; associate members <a href="http://www.fraunhofer.de/EN/">Fraunhofer Institute</a> and <a href="http://www.projectliberty.org/">Liberty Alliance</a>; individual members <a href="http://www.dbartholomew.net/">Daniel Bartholomew</a> and <a href="http://tootallsid.blogspot.com/">Sid Sidner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=76</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Identity Choice at HealthVault</title>
		<link>http://self-issued.info/?p=75</link>
		<comments>http://self-issued.info/?p=75#comments</comments>
		<pubDate>Mon, 23 Jun 2008 22:32:29 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[LiveID]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=75</guid>
		<description><![CDATA[Sean Nolan, chief architect of Microsoft’s HealthVault service, posted an article about giving their users choice for the identities they use to access their information.  He announced that in addition to accepting LiveIDs, HealthVault is about to start accepting OpenIDs from two OpenID Providers and is also building native Information Card support.  As [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/openid-logo.png" alt="OpenID logo" /></span><a href="http://blogs.msdn.com/familyhealthguy/">Sean Nolan</a>, chief architect of Microsoft’s <a href="http://healthvault.com/">HealthVault</a> service, <a href="http://blogs.msdn.com/familyhealthguy/archive/2008/06/22/openid-comes-to-healthvault.aspx">posted an article</a> about giving their users choice for the identities they use to access their information.  He announced that in addition to accepting LiveIDs, HealthVault is about to start accepting OpenIDs from two OpenID Providers and is also building native Information Card support.  As <a href="http://blogs.msdn.com/familyhealthguy/archive/2008/06/22/openid-comes-to-healthvault.aspx">Sean wrote</a>:</p>
<blockquote><p>
As we&#8217;ve always said, HealthVault is about consumer control &#8212; empowering individuals with tools that let them choose how to share and safeguard their personal health information. OpenID support is a natural fit for this approach, because it allows users to choose the &#8220;locksmith&#8221; that they are most comfortable with.</p>
<p>You can certainly expect to see more such options in the future. For example, we are in the process of building in native support for <a href="http://msdn.microsoft.com/en-us/netframework/aa663320.aspx">Information Cards</a>, which provide some unique advantages, in particular around foiling phishing attempts.
</p></blockquote>
<p>Talking about OpenID, Sean also wrote:</p>
<blockquote><p>
As we learn more, and as OpenID continues to mature, we fully expect to broaden the set of providers that work with HealthVault. We believe that a critical part of that expansion is the formalization and adoption of <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-02.html">PAPE</a>, which gives relying parties a richer set of tools to determine if they are comfortable with the policies of an identity provider.
</p></blockquote>
<p>Please join me in congratulating the HealthVault team on being the first Microsoft service to employ OpenID and for their commitment to providing their users convenient, secure access to their healthcare data.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=75</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Even Phishers Have Their Problems</title>
		<link>http://self-issued.info/?p=74</link>
		<comments>http://self-issued.info/?p=74#comments</comments>
		<pubDate>Mon, 26 May 2008 20:37:03 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=74</guid>
		<description><![CDATA[While gone phishing, I discovered that the use of JavaScript puts one barrier up that phishers have to overcome to impersonate a legitimate site.  In a characteristically hilarious post, Paul Madsen points out that, besides having to overcome active defenses like Sxipper (“Down girl!”), phishers may also inadvertently present pages localized for their locale, [...]]]></description>
			<content:encoded><![CDATA[<p>While <a href="http://self-issued.info/?p=73">gone phishing</a>, I discovered that the use of JavaScript puts one barrier up that phishers have to overcome to impersonate a legitimate site.  In a characteristically hilarious post, <a href="http://connectid.blogspot.com/2008/05/security-through-localization.html">Paul Madsen points out that</a>, besides having to overcome active defenses like <a href="http://www.sxipper.com/">Sxipper</a> (“Down girl!”), phishers may also inadvertently present pages localized for <em><strong>their</strong></em> locale, rather than the victim’s.</p>
<p>Intrepid identity adventurer though Paul may be, this stopped him dead in his tracks:</p>
<p><span class="plain"><img src="http://self-issued.info/images/Deutsche_Blogger_login.png" alt="Deutsche Blogger login" /></span></p>
<p>Of course, maybe Paul’s German was better than he thought, as the page was urging him to “Gehen Sie auf Nummer sicher!  Schützen Sie sich von Phishing und Identitätsdiebstahl.” – “Go safe!  Protect yourself from phishing and identity theft.” :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=74</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gone Phishing</title>
		<link>http://self-issued.info/?p=73</link>
		<comments>http://self-issued.info/?p=73#comments</comments>
		<pubDate>Mon, 26 May 2008 09:58:50 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=73</guid>
		<description><![CDATA[Fun Communications’ site idtheft.fun.de lets you mount your very own man-in-the-middle based phishing attack against the OpenID provider of your choosing.  Rather than redirecting you to the OpenID provider you specify, it instead redirects you to a page impersonating the OpenID provider, created using content scraped from the real site behind the scenes.
This is [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.fun.de/">Fun Communications</a>’ site <a href="http://idtheft.fun.de/">idtheft.fun.de</a> lets you mount your very own man-in-the-middle based phishing attack against the OpenID provider of your choosing.  Rather than redirecting you to the OpenID provider you specify, it instead redirects you to a page impersonating the OpenID provider, created using content scraped from the real site behind the scenes.</p>
<p>This is the same kind of attack shown in <a href="http://www.identityblog.com/?p=923">Kim’s phishing video</a>.  <a href="http://idtheft.fun.de/">idtheft.fun.de</a> lets you have the fun of doing it yourself!</p>
<p>I tried it myself with several OpenID providers I use.  Predictably, I was typically able to “steal” the passwords for OpenIDs when logging into them with passwords and hijack the resulting logged-in sessions.  “Protecting” an account with a one-time-password (OTP) device did nothing to stop this; my “attack” still succeeded in hijacking the session established using a password in combination with an OTP value.</p>
<p>Two things did defeat these attacks.  Because Information Cards generate site-specific sign-in information and the attacker’s site is different than the authentic site, even when I was “tricked” into submitting an Information Card to the imposter site, it didn’t give the imposter the ability to log into the real site.  No shared secret was present to steal and no session was established to hijack.</p>
<p>The other thing that defeated this specific attack was the use of JavaScript in the sign-in process by the OpenID provider.  While a slightly more sophisticated attack could almost certainly get past this obstacle, idtheft.fun.de apparently doesn’t correctly mimic JavaScript site features like “Sign In” buttons invoking an onclick method.</p>
<p>This ability to both phish passwords and hijack the resulting logged-in sessions is exactly why I and others are working on finishing the OpenID <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-02.html">Provider Authentication Policy Extension (PAPE)</a> extension.  As <a href="http://self-issued.info/?p=15">I wrote</a> when the first draft was published, PAPE enables “OpenID relying parties to request that a phishing-resistant authentication method be used by the OpenID provider and for providers to inform relying parties whether a phishing-resistant authentication method, such as Windows CardSpace, was used.”  It’s time for PAPE to become an OpenID standard.</p>
<hr />
<p>What follows are screen shots from a successful phishing attack and a thwarted one – both against the same OP.  The difference is whether passwords or Information Cards were used to log in.</p>
<p><span class="plain"><img src="http://self-issued.info/images/idtheft.start.png" alt="Figure 1: idtheft start" /></span></p>
<p><strong>Figure 1:</strong>  About to mount my attack against my OpenID at myopenid.com.  I’ve typed the URL of my OpenID into the relying party.</p>
<p><span class="plain"><img src="http://self-issued.info/images/idtheft.signin.png" alt="Figure 2: idtheft signin" /></span></p>
<p><strong>Figure 2:</strong>  Next, I’m logging in with a password.  An observant user could notice several things wrong:   the address bar shows the imposter’s URL, the imposter’s URL is present in the “You must sign in to authenticate to …” message, and the “Your Personal Icon” space is blank.  Unfortunately, there is <a href="http://usablesecurity.org/emperor/">strong evidence that users are not observant</a>.</p>
<p><span class="plain"><img src="http://self-issued.info/images/idtheft.allow.png" alt="Figure 3: idtheft allow" /></span></p>
<p><strong>Figure 3:</strong>  Phishing already accomplished.  Same cues are present that something’s amiss.  Of course, a more sophisticated attack could replace the imposter’s URL in the page with the “real one” in both of these screens, eliminating the most obvious cue.  I scroll down and click “Allow Once”.</p>
<p><span class="plain"><img src="http://self-issued.info/images/idtheft.accomplished.png" alt="Figure 4: idtheft accomplished" /></span></p>
<p><strong>Figure 4:</strong>  Result after being redirected back to the “relying party”.  Yes, that was my real password.</p>
<p>Next, I tried to attack my account again but was surprised that I wasn’t asked to log in this time.  Of course – the attacker’s session was already logged in!  So I signed out as the man-in-the-middle (that was weird), enabling me to try again. </p>
<p>My next steps looked just like Figures 1 and 2, except instead of typing a password I clicked the purple Information Card button.  This brought me to:</p>
<p><span class="plain"><img src="http://self-issued.info/images/idtheft.cardspace.png" alt="Figure 5: idtheft cardspace" /></span></p>
<p><strong>Figure 5:</strong>  CardSpace informs me that I’ve never sent a card to this site before.  An observant user would realize that they don’t normally see this screen and might decline.  But then, we’ve already discussed how observant users aren’t.  I click “Yes”, choose the card I normally use to log into myopenid.com, and send it.</p>
<p><span class="plain"><img src="http://self-issued.info/images/idtheft.prevented.png" alt="Figure 6: idtheft prevented" /></span></p>
<p><strong>Figure 6:</strong>  Phishing prevented.  “Error processing Information Card token” isn’t the most informative error message I’ve ever seen but behind it is great news:  the phishing attack failed because the token constructed for the imposter site wasn’t usable at the real site.</p>
<p>And thanks to <a href="http://idtheft.fun.de/">idtheft.fun.de</a>, you <strong><em>can</em></strong> try this at home!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=73</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Fun Communication’s Fun Identity Innovations</title>
		<link>http://self-issued.info/?p=72</link>
		<comments>http://self-issued.info/?p=72#comments</comments>
		<pubDate>Mon, 26 May 2008 09:57:24 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=72</guid>
		<description><![CDATA[<span class="plain"><img align="right" src="http://self-issued.info/images/funlogo94x63.gif" alt="Fun Communications logo" />Johannes Feulner of <a href="http://www.fun.de/">Fun Communications</a> recently showed me three different identity sites they’ve created, each fun and valuable in its own way.  The first, <a href="http://www.webcard-loyalty.com/">www.webcard-loyalty.com</a>, lets companies create online loyalty cards for their customers.]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/funlogo94x63.gif" alt="Fun Communications logo" />Johannes Feulner of <a href="http://www.fun.de/">Fun Communications</a> recently showed me three different identity sites they’ve created, each fun and valuable in its own way.  The first, <a href="http://www.webcard-loyalty.com/">www.webcard-loyalty.com</a>, lets companies create online loyalty cards for their customers.  These loyalty Information Cards enable merchants to offer bonuses and discounts when the cards are used, similarly to how physical loyalty cards such as frequent flyer cards and frequent shopper cards are used to provide these benefits in the offline world.  You can read more about “<a href="http://www.fun.de/english/Products/WebCardLoyalty/WebCardLoyalty.asp">virtual loyalty cards</a>” and about the <a href="http://www.fun.de/english/News/Pressemitteilung.asp?id=345">innovation prize</a> they won.</p>
<p>The second, <a href="http://openidbycard.com/">openidbycard.com</a>, dynamically creates a site-specific OpenID to use at an OpenID relying party from any Information Card offering the privatepersonalidentifier (PPID) claim.  Type “openidbycard.com” as your OpenID identifier into any OpenID login form and an OpenID will be created for the site based on the site identity and the PPID returned by the card.  While I understand value of using public identifiers (such as <a href="http://self-issued.info/">self-issued.info</a>) in some contexts, it’s great to also have the choice of using unidirectional identifiers at OpenID sites.</p>
<p>Finally, <a href="http://idtheft.fun.de/">idtheft.fun.de</a> demonstrates the ability of attackers to mount man-in-the-middle attacks against OpenID sites (and lets you try it yourself!).  The site phishes OpenID passwords and other information sent through the browser, all via web pages that look authentic, but that are actually under control of the attacker.  This will be the subject of <a href="http://self-issued.info/?p=73">my next post</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=72</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-Centric Identity Interop at RSA in San Francisco</title>
		<link>http://self-issued.info/?p=68</link>
		<comments>http://self-issued.info/?p=68#comments</comments>
		<pubDate>Tue, 01 Apr 2008 16:25:32 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Bandit Project]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Higgins Project]]></category>
		<category><![CDATA[I-names]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[JanRain]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Pamela Project]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Shibboleth]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=68</guid>
		<description><![CDATA[33 Companies&#8230;
24 Projects&#8230;
57 Participants working together to build an interoperable user-centric identity layer for the Internet!
Come join us!
Tuesday and Wednesday, April 8 and 9 at RSA 2008, Moscone Center, San Francisco, California
Location:  Mezzanine Level Room 220
Interactive Working Sessions:  Tuesday and Wednesday, 11am &#8211; 4pm
Demonstrations: Tuesday and Wednesday, 4pm &#8211; 6pm
Reception: Wednesday, 4pm &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><strong>33 Companies&#8230;<br />
24 Projects&#8230;<br />
57 Participants working together to build an interoperable user-centric identity layer for the Internet!</strong></p>
<p style="text-align:center"><em><strong><a href="http://osis.idcommons.net/wiki/I3_User-Centric_Identity_Interop_through_RSA_2008">Come join us!</a></strong></em></p>
<p style="text-align:center">Tuesday and Wednesday, April 8 and 9 at RSA 2008, Moscone Center, San Francisco, California<br />
Location:  Mezzanine Level Room 220<br />
Interactive Working Sessions:  Tuesday and Wednesday, 11am &#8211; 4pm<br />
Demonstrations: Tuesday and Wednesday, 4pm &#8211; 6pm<br />
Reception: Wednesday, 4pm &#8211; 6pm</p>
<p style="text-align:center"><span class="plain"><img align="center" src="http://self-issued.info/images/RSA_2008_Interop_Participants.jpg" alt="Logos of RSA 2008 Interop Participants" /></span></p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=68</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft Joins the OpenID Foundation and its Board of Directors</title>
		<link>http://self-issued.info/?p=57</link>
		<comments>http://self-issued.info/?p=57#comments</comments>
		<pubDate>Thu, 07 Feb 2008 14:37:18 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=57</guid>
		<description><![CDATA[Today the OpenID Foundation announced that five leading technology companies, Google, IBM, Microsoft, VeriSign, and Yahoo! have joined the OpenID board of directors as its first corporate board members.  This news comes a year and a day after the JanRain/Sxip Identity/Microsoft/VeriSign OpenID/CardSpace collaboration announcement introduced by Bill Gates and Craig Mundie at the RSA [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/openid-logo.png" alt="OpenID logo" /></span>Today the <a href="http://www.marketwire.com/mw/release.do?id=818650">OpenID Foundation announced</a> that five leading technology companies, Google, IBM, Microsoft, VeriSign, and Yahoo! have joined the OpenID board of directors as its first corporate board members.  This news comes a year and a day after the <a href="http://www.identityblog.com/?p=668">JanRain/Sxip Identity/Microsoft/VeriSign OpenID/CardSpace collaboration announcement</a> <a href="http://www.microsoft.com/Presspass/exec/billg/speeches/2007/02-06RSA.mspx">introduced by Bill Gates and Craig Mundie</a> at the RSA Security Conference.</p>
<p>How are these events related, you might ask?  As I see it, they’re both great examples of the industry working together to solve the digital identity problems that all Internet users presently face – in these cases, both in the context of <a href="http://openid.net/">OpenID</a>.</p>
<p>A lot’s happened over that year-and-a-day that’s worth celebrating:</p>
<ul>
<li>The <a href="http://openid.net/foundation/">OpenID Foundation</a> was formed in June “<a href="http://openid.net/foundation/">to help promote, protect and enable the OpenID technologies and community</a>”.</li>
<li>The <a href="http://self-issued.info/?p=15">OpenID Phishing-Resistant Authentication Specification</a> was developed and published in June.</li>
<li>VeriSign and Ping Identity both <a href="http://self-issued.info/?p=24">enabled phishing-resistant login</a> to their OpenID providers using Information Cards in July, soon followed by <a href="http://self-issued.info/?p=37">JanRain</a> and <a href="http://self-issued.info/?p=50">LinkSafe</a>.</li>
<li>The <a href="http://self-issued.info/?p=48">OpenID 2.0 Specifications were declared complete</a> in December and were accompanied by intellectual property contribution agreements from all of the inventors.</li>
<li>The OpenID Foundation’s <a href="http://self-issued.info/?p=53">intellectual property policy and procedures</a>, which had been under development from March through December through a collaborative effort between many companies and individuals, were completed, enabling all to be able to participate in developing and using OpenID specifications.</li>
<li>And of course, OpenID adoption and usage continued to increase.</li>
</ul>
<p>From a personal perspective, I’ve enjoyed working with colleagues from numerous companies (<a href="http://self-issued.info/?p=53">including from my own!</a>) to help get us to today’s announcement, as well as working to bring safer, easier-to-user login and account creation to OpenIDs via Information Cards.  Thus, I’m both pleased and honored to now be representing Microsoft on the OpenID Foundation board of directors.</p>
<p>Of course, today’s announcement is really only the end of the beginning.  The real fun and value is still ahead of us, in the work we’ll do together.  The <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-02.html">draft PAPE specification</a> needs to be completed.  We need to drive relying party adoption of phishing-resistant authentication.  And talk of an OpenID 3.0 that’s both easier and safer to use is already percolating on the mailing lists.</p>
<p>The Internet is still missing a much-needed ubiquitous identity layer.  The good news is that the broad industry collaboration that has emerged around OpenID is a key enabler for building it together!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=57</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Phishing Protection for the Enterprise</title>
		<link>http://self-issued.info/?p=52</link>
		<comments>http://self-issued.info/?p=52#comments</comments>
		<pubDate>Sun, 23 Dec 2007 04:15:17 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=52</guid>
		<description><![CDATA[I was surprised during the recent blogosphere conversation on user-centric identity in the Enterprise, that no one referenced Sxip’s contemporaneous intelligently-written 2-page piece on how the use of Information Cards can help protect enterprise login credentials from being phished.  Using Information Cards to enable safer remote access to hosted enterprise applications makes business sense. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://self-issued.info/images/enterprise_phishing_protection.jpg" align="right" alt="Enterprise Phishing Protection" />I was surprised during the <a href="http://eternaloptimist.wordpress.com/2007/12/11/where-does-philosophy-end-and-problem-solving-begin/">recent blogosphere conversation on user-centric identity in the Enterprise</a>, that no one referenced <a href="http://www.sxip.com/files/pdf/enterprise_phishing.pdf">Sxip’s contemporaneous intelligently-written 2-page piece</a> on how the use of Information Cards can help protect enterprise login credentials from being phished.  Using Information Cards to enable safer remote access to hosted enterprise applications makes business sense.  This seems to me like a perfect example of what <a href="http://eternaloptimist.wordpress.com/2007/12/11/where-does-philosophy-end-and-problem-solving-begin/">Pam wrote</a>: “I would like to see Enterprises adopt technologies such as the Identity Metasystem for no other reason than because it helps their business to succeed.”</p>
<p><a href="http://identity20.com/?p=139">Dick’s introduction to the security bulletin</a> also references a number of recent press articles on phishing attacks against the enterprise that are well worth reading.  I’m with Pam:  user-centric identity technologies will be adopted in the enterprise exactly when they’re perceived as delivering real business value.  This is such a case.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=52</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>I-names without Passwords at LinkSafe</title>
		<link>http://self-issued.info/?p=50</link>
		<comments>http://self-issued.info/?p=50#comments</comments>
		<pubDate>Wed, 19 Dec 2007 07:34:11 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[I-names]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=50</guid>
		<description><![CDATA[I’m pleased to report that <a href="http://ootao.com/">ooTao</a> and <a href="http://linksafe.name/">LinkSafe</a> have recently collaborated to enable you to create and use i-names using Information Cards rather than passwords.  They’ve achieved for <a href="http://linksafe.name/">LinkSafe.name</a> <a href="http://self-issued.info/?p=46">what JanRain did for MyOpenID.com</a>.]]></description>
			<content:encoded><![CDATA[<p>I’m pleased to report that <a href="http://ootao.com/">ooTao</a> and <a href="http://linksafe.name/">LinkSafe</a> have recently collaborated to enable you to create and use i-names with Information Cards rather than passwords.  They’ve achieved for <a href="http://linksafe.name/">LinkSafe.name</a> <a href="http://self-issued.info/?p=46">what JanRain did for MyOpenID.com</a>.  Below is a screen shot of me signing up for an i-name using an Information Card, rather than a password.  Now when you see someone signed in to a site with the OpenID <a href="http://xri.net/=me">=me</a>, you’ll know who it actually is!</p>
<p><span class="plain"><img src="http://self-issued.info/images/LinkSafe_signup.jpg" alt="LinkSafe.name i-name signup with Information Card" /></span></p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=50</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Look ma!  No passwords!</title>
		<link>http://self-issued.info/?p=46</link>
		<comments>http://self-issued.info/?p=46#comments</comments>
		<pubDate>Sun, 02 Dec 2007 20:28:09 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[JanRain]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=46</guid>
		<description><![CDATA[As <a href="http://blogs.msdn.com/vbertocci/archive/2007/12/02/myopenid-supports-the-creation-of-passwordless-accounts.aspx">Vittorio excitedly pointed out</a>, you never have to enter a password to create or use an OpenID at <a href="https://www.myopenid.com/">MyOpenID.com</a>.  <a href="http://www.identityblog.com/?p=913">Kim’s excited</a> about this too.  So am I.]]></description>
			<content:encoded><![CDATA[<p>As <a href="http://blogs.msdn.com/vbertocci/archive/2007/12/02/myopenid-supports-the-creation-of-passwordless-accounts.aspx">Vittorio excitedly pointed out</a>, you never have to enter a password to create or use an OpenID at <a href="https://www.myopenid.com/">MyOpenID.com</a>.  <a href="http://www.identityblog.com/?p=913">Kim’s excited</a> about this too.  So am I.  When <a href="http://self-issued.info/?p=37">I wrote</a>:</p>
<blockquote><p>
The JanRain team has done a fantastic job integrating account sign-up, sign-in, and recovery via Information Cards into their OpenID provider. I’m really impressed by how well this fits into the rest of their high-quality offering.
</p></blockquote>
<p>I should have expanded upon my point “fantastic job integrating account sign-up” to explicitly call out that no passwords are needed.  Notice the Information Card button on the sign-up page below.  Thanks Vittorio and Kim, for sharing your excitement about this.  I’m hoping that as other sites integrate Information Card sign-in to their user experience that they’ll also follow this example (and the guidance in <a href="http://self-issued.info/?p=6">the deployment guide</a>) and enable password-less sign-up with Information Cards.</p>
<p><span class="plain"><img src="http://self-issued.info/images/myopenid_signup.jpg" alt="MyOpenID.com signup with Information Card" /></span></p>
<p>Related to this is JanRain’s earlier announcement that they are including <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-02.html">PAPE</a> support in their widely-used OpenID relying party libraries.  As <a href="http://janrain.com/blog/2007/10/24/pape-support-in-janrain-openid-20-libraries/">Kevin Fox wrote</a>:</p>
<blockquote><p>
Just a note to let everyone know that we are developing and will release relying party libraries supporting <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html">PAPE</a> once the specification is finalized.<br />
We have deployed an example relying party available here:<br />
<a href="http://openidenabled.com/python-openid/trunk/examples/consumer/">openidenabled.com/python-openid/trunk/examples/consumer/</a><br />
The example fully supports OpenID 2.0 draft 12, and can request phishing-resistant authentication using PAPE. Feel free to use it for testing.<br />
PAPE allows sites that use OpenID 2.0 authentication to get information about the way that the user authenticated to the provider. This is an important step on the way to getting the convenience needed of OpenID authentication for higher-valued transactions. It’s trivial to implement and will be included in <a href="http://openidenabled.com/">JanRain’s OpenID 2.0 libraries</a> as well as <a href="http://code.sxip.com/">Sxip’s libraries</a>.
</p></blockquote>
<p><a href="http://janrain.com/blog/2007/10/24/pape-support-in-janrain-openid-20-libraries/#comment-414">Gary Krall also added</a> that:</p>
<blockquote><p>
Verisign will also be releasing an update to the <a href="http://code.google.com/p/joid/">JOID library</a> which we use on the <a href="http://pip.verisignlabs.com/">PiP</a> for as you may know we have added PAPE support to the PiP.
</p></blockquote>
<p>And I’ll add that <a href="https://www.myopenid.com/">MyOpenID.com</a> and <a href="https://www.signon.com/">SignOn.com</a> both also support PAPE on their OpenID providers.</p>
<p>Why is this exciting?  Because it means that without use of without any use of passwords, people can create and use OpenIDs with their Information Cards.  And that sites accepting OpenIDs can ask for phishing-resistant authentication when you sign in – which these OpenIDs will do for you.  All more great steps towards building a convenient, secure, ubiquitous identity layer for the Internet!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=46</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>User-Centric Identity Interop at Catalyst in Barcelona</title>
		<link>http://self-issued.info/?p=39</link>
		<comments>http://self-issued.info/?p=39#comments</comments>
		<pubDate>Wed, 24 Oct 2007 20:10:25 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Bandit Project]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Higgins Project]]></category>
		<category><![CDATA[I-names]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[JanRain]]></category>
		<category><![CDATA[LiveID]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Pamela Project]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Shibboleth]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=39</guid>
		<description><![CDATA[Last night <a href="http://osis.netmesh.org/wiki/Main_Page">OSIS</a> and the <a href="http://www.burtongroup.com/">Burton Group</a> held the third in a series of user-centric identity Interop events where companies and projects building user-centric identity software components came together and tested the interoperation of their software together.  Following on the Interops at <a href="http://self-issued.info/?p=12">IIW in May</a> and <a href="http://self-issued.info/?p=25">Catalyst in June</a>, the participants continued their joint work of ensuring that the identity software we’re all building works great together.
]]></description>
			<content:encoded><![CDATA[<p><img src="http://self-issued.info/images/Barcelona_Interop_2007_Participants.jpg" alt="Logos of Barcelona Interop Participants 2007" /></p>
<p>Last night <a href="http://osis.netmesh.org/wiki/Main_Page">OSIS</a> and the <a href="http://www.burtongroup.com/">Burton Group</a> held the third in a series of user-centric identity Interop events where companies and projects building user-centric identity software components came together and tested the interoperation of their software together.  Following on the Interops at <a href="http://self-issued.info/?p=12">IIW in May</a> and <a href="http://self-issued.info/?p=25">Catalyst in June</a>, the participants continued their joint work of ensuring that the identity software we’re all building works great together.</p>
<p>This Interop had a broader scope along several dimensions than the previous ones:</p>
<ul>
<li>We welcomed <strong>new participants</strong> <a href="http://www.ate-software.net/ATEHome/ATE/ate.aspx">a.t.e Software</a>, <a href="http://www.fokus.fraunhofer.de/home/index.php?lang=en">Fraunhofer</a>, <a href="http://janrain.com/">JanRain</a>, <a href="http://linksafe.name/">LinkSafe</a>, <a href="http://ootao.com/">ooTao</a>, <a href="http://www.sun.com/">Sun Microsystems</a>, <a href="http://w1.siemens.com/en/entry.html">Siemens</a>, and <a href="http://www.thoughtworks.com/">ThoughtWorks</a>.</li>
<li>We tested interoperation of <strong>OpenID</strong> software (including <strong>i-name</strong> software) in addition to Information Card software.</li>
<li>Several kinds of <strong>interop between Information Card and OpenID software</strong> were demonstrated, including:
<ol>
<li>OpenID providers implementing the <a href="http://self-issued.info/?p=15">OpenID phishing-resistant authentication specification</a> using Information Cards to enable phishing-resistant sign-in to OpenIDs, and</li>
<li>using <a href="http://self-issued.info/?p=27">OpenID Information Cards</a> to supply OpenIDs to OpenID relying parties.</li>
</ol>
</li>
<li>Unlike previous Interops, the endpoints and testing results are all <a href="http://osis.netmesh.org/wiki/I2-Barcelona">publicly available</a> so that others can benefit from them.</li>
<li>Many of the participants have committed to keeping their sites up beyond Catalyst to allow for continued public interop testing.  For instance, Microsoft’s sites will remain up at <a href="http://www.federatedidentity.net/">http://www.federatedidentity.net/</a>.</li>
</ul>
<p>An excerpt from <a href="http://identityblog.burtongroup.com/bgidps/2007/10/osis-user-centr.html">Bob Blakley’s insightful-as-always commentary</a> on the Interop is:</p>
<blockquote><p>
The participants have <a href="http://osis.netmesh.org/wiki/I2_Results">posted their results on the wiki</a>, and a few words are in order about these results.  The first thing you’ll notice is that there are a significant number of “failure” and “issue” results.  This is very good news for two reasons.</p>
<p>The first reason it’s good news is that it means enough new test cases were designed for this interop to uncover new problems.  What you don’t see in the matrix is that when testing began, there were even more failures – which means that a lot of the new issues identified during the exercise have already been fixed.</p>
<p>The second reason the “failure” and “issue” results are good news is that they’re outnumbered by the successes.  When you consider that the things tested in Barcelona were all identified as problems at the previous interop, you’ll get an idea of how much work has been done by the OSIS community in only 4 months to improve interoperability and agree on standards of component behavior.
</p></blockquote>
<p>Be sure to read his full post for more details on what the participants accomplished together.  And of course, this isn’t the end of the story.   An even wider and deeper Interop event is planned for the <a href="http://www.rsaconference.com/2008/US/">RSA Conference in April 2008</a>.  Great progress on building the Internet identity layer together!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=39</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>MyOpenID adds Information Card Support</title>
		<link>http://self-issued.info/?p=37</link>
		<comments>http://self-issued.info/?p=37#comments</comments>
		<pubDate>Thu, 18 Oct 2007 11:06:49 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[JanRain]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=37</guid>
		<description><![CDATA[Kevin Fox just announced that JanRain has added Information Card support to MyOpenID.com.]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/janrain.png" alt="JanRain logo" /></span><a href="http://jyte.com/profile/kfox.myopenid.com">Kevin Fox</a> <a href="http://janrain.com/blog/2007/10/17/myopenid-adds-information-card-support/">just announced</a> that <a href="http://janrain.com/">JanRain</a> has added Information Card support to <a href="https://www.myopenid.com/">MyOpenID.com</a>.  As <a href="http://janrain.com/blog/2007/10/17/myopenid-adds-information-card-support/">he wrote</a>:</p>
<blockquote><p>
The <a href="http://openidenabled.com/">JanRain OpenID team</a> is pleased to announce <a href="http://msdn2.microsoft.com/en-us/library/aa480189.aspx">Information Card</a> support has been added to <a href="https://www.myopenid.com/">MyOpenID.com</a>.</p>
<p>What is an <a href="http://visitmix.com/Blogs/Joshua/introduction-to-information-cards/">Information Card</a>?</p>
<p>What can I do with it? With a self-issued Information Card you can sign-in to MyOpenID, as well as sign-up and recover your account, without ever having to enter your password. Anywhere on MyOpenID that you can enter a password will now allow you to use an Information Card instead. With the addition of Information Card support MyOpenID is able to offer another solid option for people wanting to protect their OpenID account from phishing attacks and remember fewer passwords.</p>
<p>We were able to work with Microsoft’s <a href="http://self-issued.info/?cat=14">Mike Jones</a> and <a href="http://identityblog.com/">Kim Cameron</a> who have both been long time proponents of <a href="http://www.identityblog.com/?p=659">OpenID</a> + <a href="http://self-issued.info/?p=27">Information Card support</a>.</p>
<p>As <a href="http://www.identityblog.com/?p=659">noted by Kim Cameron</a> “Cardspace is used at the identity provider to keep credentials from being stolen. So the best aspects of OpenID are retained.” While one of the less desirable aspects (confusing user experience) has been improved for someone using an Information Card to login to their OpenID provider.</p>
<p><a href="http://self-issued.info/?cat=3">Support for Information Cards</a> has <a href="http://www.identityblog.com/?p=869">been growing</a> as more <a href="http://self-issued.info/?p=35">software projects implement the technology</a>. It is important to note that this technology is being supported by many other organizations besides Microsoft. Information Card support is available for Windows platforms (Vista / XP) as well as <a href="http://self-issued.info/?p=29">Mac OS X and Linux</a>.
</p></blockquote>
<p>The JanRain team has done a fantastic job integrating account sign-up, sign-in, and recovery via Information Cards into their OpenID provider.  I’m really impressed by how well this fits into the rest of their high-quality offering.</p>
<p>There’s another kind of integration they also did that makes this even more impressive in my mind:  connecting their new Information Card support with their existing support for the draft <a href="http://self-issued.info/?p=15">OpenID phishing-resistant authentication specification</a>.  This is another significant step in fulfilling the promise of the JanRain/Microsoft/Sxip Identity/VeriSign <a href="http://kveton.com/blog/?p=221">OpenID/Windows CardSpace collaboration announcement</a> <a href="http://www.microsoft.com/Presspass/exec/billg/speeches/2007/02-06RSA.mspx">introduced by Bill Gates and Craig Mundie</a> at the RSA Security Conference this year.  Because of this work, this sequence is now possible:</p>
<ol>
<li>A person goes to an OpenID relying party and uses an OpenID from MyOpenID.com.</li>
<li>The OpenID relying party requests that MyOpenID.com use a phishing-resistant authentication method to sign the user in.</li>
<li>The person signs into his MyOpenID.com OpenID with an Information Card.</li>
<li>MyOpenID.com informs the relying party that the user utilized a phishing-resistant authentication method.</li>
</ol>
<p>This means that MyOpenID users will be able to get both the convenience and anti-phishing benefits of Information Cards at OpenID-enabled sites they visit and those sites can have higher confidence that the user is in control of the OpenID used at the site.  That’s truly useful identity convergence if you ask me!</p>
<div align="center">&#8211; Mike (<a href="http://self-issued.myopenid.com/">http://self-issued.myopenid.com/</a>)</div>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=37</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Information Cards for OpenIDs</title>
		<link>http://self-issued.info/?p=27</link>
		<comments>http://self-issued.info/?p=27#comments</comments>
		<pubDate>Sun, 26 Aug 2007 22:45:27 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=27</guid>
		<description><![CDATA[Sxip Identity just finished a <a href="https://openidcards.sxip.com/spec/openid-infocards.html">draft specification</a> that enables a really useful form of convergence between OpenIDs and Information Cards:  presenting your OpenID as an Information Card you select rather than as a string you type.  Johnny Bufu’s <a href="http://openid.net/pipermail/general/2007-August/003160.html">OpenID general mailing list note</a> introduces this specification for community review.

This combination has several advantages over standard OpenID usage.  First, there’s no OpenID string to type when you use your OpenID, which should make OpenIDs easier for more people to use.  Second, this is a phishing-resistant authentication method.  Finally, it lets you recognize and choose your OpenID visually, based on the card graphics supplied by the OpenID provider.

Sxip also backed this specification by a sample implementation, which you can check out at <a href="https://openidcards.sxip.com/">https://openidcards.sxip.com/</a>.]]></description>
			<content:encoded><![CDATA[<p>Sxip Identity just finished a <a href="https://openidcards.sxip.com/spec/openid-infocards.html">draft specification</a> that enables a really useful form of convergence between OpenIDs and Information Cards:  presenting your OpenID as an Information Card you select rather than as a string you type.  Johnny Bufu’s <a href="http://openid.net/pipermail/general/2007-August/003160.html">OpenID general mailing list note</a> introduces this specification for community review.</p>
<p>This combination has several advantages over standard OpenID usage.  First, there’s no OpenID string to type when you use your OpenID, which should make OpenIDs easier for more people to use.  Second, this is a phishing-resistant authentication method.  Finally, it lets you recognize and choose your OpenID visually, based on the card graphics supplied by the OpenID provider.</p>
<p>Sxip also backed this specification by a sample implementation, which you can check out at <a href="https://openidcards.sxip.com/">https://openidcards.sxip.com/</a>.  Now for some more details….</p>
<p>Here’s how it works:  In this model, the OpenID relying party asks for an OpenID Information Card using an object tag on the page rather than having the user type the OpenID as a string (while probably also giving the user the option to instead type in the string for backwards compatibility).  The user’s Identity Selector then lets the user choose which OpenID card to send to the site.  The card transmits the actual OpenID string to the site as a claim.  From that point on, standard OpenID protocol interactions ensue.</p>
<p>For instance, the <a href="https://openidcards.sxip.com/demorp/">sample relying party</a> page asks you to “<strong>Login with an OpenID InfoCard</strong>” and requests the card using this evocative graphic:</p>
<div align="center"><img src="http://self-issued.info/images/openid_infocard.png" alt="OpenID InfoCard" /></div>
<p>Upon clicking the graphic, my identity selector is invoked, which shows me that I can use this OpenID Information Card at the site (which I’d previously obtained <a href="https://openidcards.sxip.com/TokenService/">here</a>):</p>
<div align="center"><img src="http://self-issued.info/images/Sxip_OpenID_InfoCard.bmp" alt="Sxip OpenID InfoCard" /></div>
<p>After that, the sample performed a standard OpenID attribute exchange and the relying party greeted me with:</p>
<p style="margin-left:.25in">Welcome! You have logged in using your <strong>https://openidcards.sxip.com/i/mbj</strong> OpenID identifier.<br />
<br />
Phone: (omitted)<br />
Country: USA<br />
Email: mbj@microsoft.com<br />
City: Redmond<br />
Address: One Microsoft Way, Building 40/5138<br />
LastName: Jones<br />
FirstName: Mike</p>
<p>Behind the scenes, the relying party had received this OpenID assertion:</p>
<pre style="margin-left:.25in"><code>&lt;openid:OpenIDToken xmlns:openid="http://specs.openid.net/auth/2.0"&gt;openid.ns:http://specs.openid.net/auth/2.0
openid.op_endpoint:https://openidcards.sxip.com/op/
openid.claimed_id:https://openidcards.sxip.com/i/mbj
openid.response_nonce:2007-08-26T20:55:34Z0
openid.mode:id_res
openid.identity:https://openidcards.sxip.com/i/mbj
openid.return_to:https://openidcards.sxip.com/demorp/
openid.assoc_handle:f27d249fc4108198
openid.signed:op_endpoint,claimed_id,identity,return_to,response_nonce,assoc_handle
openid.sig:gKKpDjEbgByJo48Q800Jq4gCJng=
openid.ns.ext1:http://openid.net/srv/ax/1.0-draft4
openid.ext1.mode:fetch_response
openid.ext1.type.attr1:http://axschema.org/contact/phone/default
openid.ext1.value.attr1:(omitted)
openid.ext1.type.attr2:http://axschema.org/contact/country/home
openid.ext1.value.attr2:USA
openid.ext1.type.attr3:http://axschema.org/contact/email
openid.ext1.value.attr3:mbj@microsoft.com
openid.ext1.type.attr4:http://axschema.org/contact/city/home
openid.ext1.value.attr4:Redmond
openid.ext1.type.attr5:http://axschema.org/contact/postalAddress/home
openid.ext1.value.attr5:One Microsoft Way, Building 40/5138
openid.ext1.type.attr6:http://axschema.org/namePerson/last
openid.ext1.value.attr6:Jones
openid.ext1.type.attr7:http://axschema.org/namePerson/first
openid.ext1.value.attr7:Mike
&lt;/openid:OpenIDToken&gt;</code></pre>
<p>One final technical note that will be of interest to some of you:  OpenID Information Cards do not use SAML tokens.  They use one of two variants of openid:OpenIDToken tokens (depending upon whether the OpenID relying party uses OpenID 1.1 or 2.0 authentication).</p>
<p>Go get yourself an OpenID Information Card and <a href="https://openidcards.sxip.com/">give it a spin</a>!  Read and comment on <a href="https://openidcards.sxip.com/spec/openid-infocards.html">the spec</a>.  Or even better yet, implement it and tell us about your experience!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=27</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Information Cards at OpenID Providers</title>
		<link>http://self-issued.info/?p=24</link>
		<comments>http://self-issued.info/?p=24#comments</comments>
		<pubDate>Sat, 28 Jul 2007 06:58:54 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=24</guid>
		<description><![CDATA[This week VeriSign upgraded their Personal Identity Provider (PIP) to support Information Cards.  As David Recordon wrote at VeriSign’s official “Infrablog”:
Last Saturday, we completed the upgrade of our Personal Identity Provider. All accounts have been automatically upgraded and the URL is the same at http://pip.verisignlabs.com. We definitely encourage everyone to come try it out [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://self-issued.info/images/PIP_InfoCards.bmp" align="right" alt="PIP InfoCards" />This week VeriSign upgraded their <a href="https://pip.verisignlabs.com/">Personal Identity Provider</a> (PIP) to support Information Cards.  <a href="http://blogs.verisign.com/infrablog/2007/07/been_a_busy_two_weeks.php">As David Recordon wrote</a> at VeriSign’s official “Infrablog”:</p>
<blockquote><p>Last Saturday, we completed the upgrade of our Personal Identity Provider. All accounts have been automatically upgraded and the URL is the same at http://pip.verisignlabs.com. We definitely encourage everyone to come try it out as we believe it is the best OpenID Provider in existence! Not only does it have all of the features from the PIP we launched last May, but adds support for OpenID 2.0, the ability to manage multiple identities within one PIP account, integration with strong authentication via our VeriSign Identity Protection network, Information Card support as one way to help protect against phishing attacks, and our SeatBelt Firefox add-on which works with a variety of OpenID Providers.</p></blockquote>
<p>PIP supports Information Cards in two ways:</p>
<ul>
<li>Logging into your PIP account:  You can use a managed Information Card to log into your PIP account, providing a phishing-resistant alternative to logging in with a username and password typed into the browser.</li>
<li>Using your PIP Identities at other sites:  PIP issues managed Information Cards for each of your PIP identities, which you can use to sign into sites using Information Cards for login and/or account creation.  (And of course, these same identities are also OpenIDs as well.)</li>
</ul>
<p>Images of my PIP cards for these two use cases are shown at the top of this post.  I can now use my PIP account card to sign into my PIP account and my PIP identity card to sign into other sites.  PIP is doubly cool because I believe it&#8217;s also the first general-purpose identity provider to be secured by an <a href="http://cabforum.org/EV_Certificate_Guidelines.pdf">Extended Validation Certificate</a> (see the green color of the IE7 address bar?).  Great progress!</p>
<p><img src="http://self-issued.info/images/logo_signon_beta.gif" align="right" alt="SignOn.com Logo" />This follows on <a href="http://www.pingidentity.com/about/show/188">last month’s launch</a> of Ping Identity’s <a href="https://www.signon.com/">SignOn.com identity provider</a>.  SignOn.com lets you log into your OpenID account using a self-issued Information Card &#8212; a convenient, password-free, and phishing-resistant authentication mechanism.</p>
<p>Both are fantastic steps towards our shared goal of building a convenient, secure, ubiquitous identity layer for the Internet.  Expect to see lots more developments like this soon!</p>
<p>Yours truly,<br />
mbj.pip.verisignlabs.com and mbj.signon.com</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=24</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing-Resistant Authentication Specification Ready</title>
		<link>http://self-issued.info/?p=15</link>
		<comments>http://self-issued.info/?p=15#comments</comments>
		<pubDate>Sun, 24 Jun 2007 04:05:28 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=15</guid>
		<description><![CDATA[David Recordon just posted a <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html">simple draft OpenID specification</a> enabling OpenID relying parties to request that a phishing-resistant authentication method be used by the OpenID provider and for providers to inform relying parties whether a phishing-resistant authentication method, such as Windows CardSpace, was used.]]></description>
			<content:encoded><![CDATA[<p>David Recordon just posted a <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html">simple draft OpenID specification</a> enabling OpenID relying parties to request that a phishing-resistant authentication method be used by the OpenID provider and for providers to inform relying parties whether a phishing-resistant authentication method, such as Windows CardSpace, was used.  This is a major step forward in fulfilling the promise of the JanRain/Microsoft/Sxip Identity/VeriSign <a href="http://blogs.verisign.com/infrablog/2007/02/verisign_microsoft_partners_to_1.php">OpenID/Windows CardSpace collaboration announcement</a> <a href="http://www.microsoft.com/Presspass/exec/billg/speeches/2007/02-06RSA.mspx">introduced by Bill Gates and Craig Mundie</a> at the RSA Security Conference this year.</p>
<p>In his post “<a href="http://blogs.verisign.com/infrablog/2007/06/bringing_useful_scalable_secur.php">Bringing Useful Scalable Security to OpenID</a>” <a href="http://daveman692.livejournal.com/">David</a> wrote:</p>
<blockquote><p>The integration cost of OpenID as a Relying Party is extremely low, the technology is free and as Brian Ellin and I <a href='http://openid.net/pres/2007_Web2Expo_Implementing_OpenID.pdf'>showed at Web 2.0 Expo</a> the time commitment is also low due to a lot of great Open Source code out there which takes care of the heavy lifting.  So now the RP has successfully integrated OpenID and removed the need for new users to create yet another password for their site, though they no longer have the control over the strength of a user&#8217;s authentication process.  The RP may be a simple Web 2.0 site and not care beyond that the user has a password, it may store marginally sensitive information and want to make sure that the Provider did something to help protect the user from common phishing attacks, or maybe it&#8217;s a site which has truly sensitive information and wants to make sure that a second-factor device, such as a VIP token, was used.</p>
<p>With the <a href='http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html'>OpenID Provider Authentication Policy Extension</a> that I just published, this is now possible.  This extension to OpenID 1.1 and 2.0 allows Relying Parties to express preferences around the authentication, such as &#8220;use technology which is phishing resistant&#8221; (stemming from the <a href='http://blogs.verisign.com/infrablog/2007/02/verisign_microsoft_partners_to_1.php'>collaboration announcement at the RSA conference</a> earlier in the year), for the Provider to inform the user of the request, guide them through the authentication process, and then inform the Relying Party what happened.  By taking advantage of existing specifications from the likes of the National Institute of Standards and Technology (NIST), Providers can also convey information as to the strength of a password or combination of a password and digital certificate or hardware device used.  While the high-end of the specification may be beyond the uses of OpenID today, it certainly fulfills the scalable security vision that we have.  Through this specification not only can I now strongly protect my OpenID identity, but let others know that I&#8217;m doing so and truly take advantage of a reduction in credentials needed when browsing the web.</p></blockquote>
<p>I can’t wait to use the implementations that are sure to follow shortly!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=15</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
