{"id":46,"date":"2007-12-02T13:28:09","date_gmt":"2007-12-02T20:28:09","guid":{"rendered":"https:\/\/self-issued.info\/?p=46"},"modified":"2008-02-07T02:08:52","modified_gmt":"2008-02-07T09:08:52","slug":"look-ma-no-passwords","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=46","title":{"rendered":"Look ma!  No passwords!"},"content":{"rendered":"<p>As <a href=\"http:\/\/blogs.msdn.com\/vbertocci\/archive\/2007\/12\/02\/myopenid-supports-the-creation-of-passwordless-accounts.aspx\">Vittorio excitedly pointed out<\/a>, you never have to enter a password to create or use an OpenID at <a href=\"https:\/\/www.myopenid.com\/\">MyOpenID.com<\/a>.  <a href=\"http:\/\/www.identityblog.com\/?p=913\">Kim&#8217;s excited<\/a> about this too.  So am I.  When <a href=\"https:\/\/self-issued.info\/?p=37\">I wrote<\/a>:<\/p>\n<blockquote><p>\nThe JanRain team has done a fantastic job integrating account sign-up, sign-in, and recovery via Information Cards into their OpenID provider. I&#8217;m really impressed by how well this fits into the rest of their high-quality offering.\n<\/p><\/blockquote>\n<p>I should have expanded upon my point &#8220;fantastic job integrating account sign-up&#8221; to explicitly call out that no passwords are needed.  Notice the Information Card button on the sign-up page below.  Thanks Vittorio and Kim, for sharing your excitement about this.  I&#8217;m hoping that as other sites integrate Information Card sign-in to their user experience that they&#8217;ll also follow this example (and the guidance in <a href=\"https:\/\/self-issued.info\/?p=6\">the deployment guide<\/a>) and enable password-less sign-up with Information Cards.<\/p>\n<p><span class=\"plain\"><img decoding=\"async\" src=\"https:\/\/self-issued.info\/images\/myopenid_signup.jpg\" alt=\"MyOpenID.com signup with Information Card\" \/><\/span><\/p>\n<p>Related to this is JanRain&#8217;s earlier announcement that they are including <a href=\"http:\/\/openid.net\/specs\/openid-provider-authentication-policy-extension-1_0-02.html\">PAPE<\/a> support in their widely-used OpenID relying party libraries.  As <a href=\"http:\/\/janrain.com\/blog\/2007\/10\/24\/pape-support-in-janrain-openid-20-libraries\/\">Kevin Fox wrote<\/a>:<\/p>\n<blockquote><p>\nJust a note to let everyone know that we are developing and will release relying party libraries supporting <a href=\"http:\/\/openid.net\/specs\/openid-provider-authentication-policy-extension-1_0-01.html\">PAPE<\/a> once the specification is finalized.<br \/>\nWe have deployed an example relying party available here:<br \/>\n<a href=\"http:\/\/openidenabled.com\/python-openid\/trunk\/examples\/consumer\/\">openidenabled.com\/python-openid\/trunk\/examples\/consumer\/<\/a><br \/>\nThe example fully supports OpenID 2.0 draft 12, and can request phishing-resistant authentication using PAPE. Feel free to use it for testing.<br \/>\nPAPE allows sites that use OpenID 2.0 authentication to get information about the way that the user authenticated to the provider. This is an important step on the way to getting the convenience needed of OpenID authentication for higher-valued transactions. It&#8217;s trivial to implement and will be included in <a href=\"http:\/\/openidenabled.com\/\">JanRain&#8217;s OpenID 2.0 libraries<\/a> as well as <a href=\"http:\/\/code.sxip.com\/\">Sxip&#8217;s libraries<\/a>.\n<\/p><\/blockquote>\n<p><a href=\"http:\/\/janrain.com\/blog\/2007\/10\/24\/pape-support-in-janrain-openid-20-libraries\/#comment-414\">Gary Krall also added<\/a> that:<\/p>\n<blockquote><p>\nVerisign will also be releasing an update to the <a href=\"http:\/\/code.google.com\/p\/joid\/\">JOID library<\/a> which we use on the <a href=\"http:\/\/pip.verisignlabs.com\/\">PiP<\/a> for as you may know we have added PAPE support to the PiP.\n<\/p><\/blockquote>\n<p>And I&#8217;ll add that <a href=\"https:\/\/www.myopenid.com\/\">MyOpenID.com<\/a> and <a href=\"https:\/\/www.signon.com\/\">SignOn.com<\/a> both also support PAPE on their OpenID providers.<\/p>\n<p>Why is this exciting?  Because it means that without use of without any use of passwords, people can create and use OpenIDs with their Information Cards.  And that sites accepting OpenIDs can ask for phishing-resistant authentication when you sign in &#8212; which these OpenIDs will do for you.  All more great steps towards building a convenient, secure, ubiquitous identity layer for the Internet!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As <a href=\"http:\/\/blogs.msdn.com\/vbertocci\/archive\/2007\/12\/02\/myopenid-supports-the-creation-of-passwordless-accounts.aspx\">Vittorio excitedly pointed out<\/a>, you never have to enter a password to create or use an OpenID at <a href=\"https:\/\/www.myopenid.com\/\">MyOpenID.com<\/a>.  <a href=\"http:\/\/www.identityblog.com\/?p=913\">Kim&#8217;s excited<\/a> about this too.  So am I.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,20,14,19],"tags":[],"class_list":["post-46","post","type-post","status-publish","format-standard","hentry","category-information-cards","category-janrain","category-openid","category-phishing-resistance"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/46","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=46"}],"version-history":[{"count":0,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/46\/revisions"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=46"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=46"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=46"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}