<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ronin: Category Identity</title>
    <link>http://blogs.divisibleprime.com/ronin/articles/category/identity</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>Stuff</description>
    <item>
      <title>Estonia OpenID follow up</title>
      <description>&lt;p&gt;In the comments for an earlier &lt;a href="http://blogs.divisibleprime.com/ronin/articles/read/877"&gt;post&lt;/a&gt; &lt;a href="http://martin.paljak.pri.ee/2007/05/25/openid-smart-cards-and-security-risks/"&gt;Martin Paljak&lt;/a&gt; has posted a follow up to the original info about the Estonian OpenID project.&lt;/p&gt;</description>
      <pubDate>Sat, 26 May 2007 14:32:00 +0100</pubDate>
      <guid isPermaLink="false">urn:uuid:cf5ac9fe-5580-46be-9bb2-4a6c3102357d</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/05/26/estonia-openid-follow-up</link>
      <category>Tech</category>
      <category>OpenID</category>
      <category>Identity</category>
      <category>identity</category>
      <category>openid</category>
      <trackback:ping>http://blogs.divisibleprime.com/ronin/articles/trackback/882</trackback:ping>
    </item>
    <item>
      <title>OpenId for every Estonian</title>
      <description>&lt;p&gt;&lt;a href="https://open.id.ee/about/english"&gt;Looks&lt;/a&gt; like there&amp;#8217;s going to be an OpenID for every Estonian.  Cool.&lt;/p&gt;

&lt;p&gt;Simon Willison &lt;a href="http://simonwillison.net/2007/May/24/openid/"&gt;asks&lt;/a&gt; how Smart Cards help with Phishing.  I believe it&amp;#8217;s because they are a form of &lt;a href="http://en.wikipedia.org/wiki/Strong_authentication"&gt;2FA&lt;/a&gt; where only one of the 2 Factors is ever exposed and hence all the credentials can&amp;#8217;t be phished.  &lt;/p&gt;

&lt;p&gt;I&amp;#8217;m not an expert though, and of course a quick google &lt;a href="http://www.google.com/search?q=2%20factor%20authentication%20phishing"&gt;search&lt;/a&gt; turns up some &lt;a href="http://www.theregister.co.uk/2007/04/19/phishing_evades_two-factor_authentication/"&gt;examples&lt;/a&gt; of 2FA being phished.&lt;/p&gt;

&lt;p&gt;btw, I first read this as &amp;#8220;OpenID for all Etonians&amp;#8221;, which I thought was kind of weird, but not totally out of the question.&lt;/p&gt;</description>
      <pubDate>Thu, 24 May 2007 22:10:00 +0100</pubDate>
      <guid isPermaLink="false">urn:uuid:0611c8d5-925b-4d23-aa4c-427002dbda2b</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/05/24/openid-for-every-estonian</link>
      <category>Tech</category>
      <category>OpenID</category>
      <category>Identity</category>
      <category>identity</category>
      <category>openid</category>
      <category>security</category>
      <trackback:ping>http://blogs.divisibleprime.com/ronin/articles/trackback/877</trackback:ping>
    </item>
    <item>
      <title>BeamAuth</title>
      <description>&lt;p&gt;&lt;a href="http://benlog.com/articles/2007/02/06/beamauth-two-factor-web-authentication-with-a-bookmark/"&gt;Ben Adida&lt;/a&gt;: What if a bookmark could be a second factor for authentication?&lt;/p&gt;

&lt;p&gt;Simple and effective.&lt;/p&gt;</description>
      <pubDate>Wed, 07 Feb 2007 09:12:00 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:805da34f-b110-49cb-95d0-34e168e122f8</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/02/07/beamauth</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>OpenID</category>
      <category>Identity</category>
      <category>identity</category>
      <category>openid</category>
      <category>phishing</category>
      <trackback:ping>http://blogs.divisibleprime.com/ronin/articles/trackback/798</trackback:ping>
    </item>
    <item>
      <title>Social Whitelisting with OpenID</title>
      <description>&lt;p&gt;&lt;a href="http://www.plasticbag.org/archives/2007/01/social_whitelisting_w/"&gt;Tom Coates&lt;/a&gt;: Social Whitelisting with OpenID.&lt;/p&gt;</description>
      <pubDate>Thu, 25 Jan 2007 09:35:15 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:77df6ff6-a9a5-47fa-bf1d-84644202f53f</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/01/25/social-whitelisting-with-openid</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>OpenID</category>
      <category>Identity</category>
    </item>
    <item>
      <title>Anti Phishing options at MyOpenId.com</title>
      <description>&lt;p&gt;&lt;a href="http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/"&gt;Scott Kveton&lt;/a&gt;: MyOpenID: New anti-phishing tools available &lt;/p&gt;</description>
      <pubDate>Wed, 24 Jan 2007 15:34:02 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:fa35235a-66b8-4fda-a230-da40ad722b5e</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/01/24/anti-phishing-options-at-myopenid-com</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>OpenID</category>
      <category>Identity</category>
    </item>
    <item>
      <title>Sxipper</title>
      <description>&lt;p&gt;&lt;a href="http://www.sxipper.com/"&gt;Sxipper&lt;/a&gt;: Sxipper is a free plug-in for Firefox that lets you log into any website with a single click&lt;/p&gt;</description>
      <pubDate>Wed, 24 Jan 2007 09:20:32 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:44ef0ebf-78e3-4c42-949b-49441ed6e85b</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/01/24/sxipper</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>OpenID</category>
      <category>Identity</category>
    </item>
    <item>
      <title>Integrating OpenID and Infocard</title>
      <description>&lt;p&gt;&lt;a href="http://www.identityblog.com/?p=659"&gt;Kim Cameron&lt;/a&gt;: Integrating OpenID and Infocard.&lt;/p&gt;</description>
      <pubDate>Wed, 24 Jan 2007 09:13:00 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:f3842029-5936-4d27-886e-dc83b438c187</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/01/24/integrating-openid-and-infocard</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>OpenID</category>
      <category>Identity</category>
      <category>openid</category>
      <category>infocard</category>
    </item>
    <item>
      <title>OpenID yourself</title>
      <description>&lt;p&gt;&lt;a href="http://www.intertwingly.net/blog/2007/01/03/OpenID-for-non-SuperUsers"&gt;Sam Ruby&lt;/a&gt; shows how to get yourself enabled for &lt;a href="http://www.openidenabled.com/openid/about-openid"&gt;OpenID&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;For Typo, I edited app/helpers/article_helper.rb and edited the page_header method to include the 2 links the OpenID delegate requires.&lt;/p&gt;</description>
      <pubDate>Fri, 05 Jan 2007 06:19:00 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:ee593936-5caf-40a7-ab89-b946274ec3e0</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2007/01/05/openid-yourself</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>Identity</category>
      <category>openid</category>
    </item>
    <item>
      <title>InfoCard primer</title>
      <description>&lt;p&gt;&lt;a href="http://www.microsoft.com/technet/technetmag/issues/2006/07/InfoCard/default.aspx"&gt;The InfoCard Identity Revolution&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Quick primer on what InfoCard is about, and how it fulfills &lt;a href="http://www.identityblog.com/?page_id=352"&gt;Kim Cameron&amp;#8217;s&lt;/a&gt; 7 laws of Identity.&lt;/p&gt;</description>
      <pubDate>Thu, 12 Oct 2006 11:42:00 +0100</pubDate>
      <guid isPermaLink="false">urn:uuid:d60837aa-7631-463f-ac4b-6f463e61d55a</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2006/10/12/infocard-primer</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>Identity</category>
    </item>
    <item>
      <title>Yahoo BBAuth</title>
      <description>&lt;p&gt;Yahoo has released a new Web based auth mechanism, &lt;a href="http://developer.yahoo.com/auth/"&gt;BBAuth&lt;/a&gt;.  As far as I can tell it provides SSO, and also access to the User&amp;#8217;s Yahoo data(Yahoo Photos and Yahoo Mail only at the moment).&lt;/p&gt;

&lt;p&gt;&lt;a href="http://identity20.com/?p=79"&gt;Dick Hardt&lt;/a&gt; says: &lt;/p&gt;

&lt;blockquote&gt;
    &lt;p&gt;&amp;#8230;Yahoo is deepening their identity silo&amp;#8230;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="http://www.25hoursaday.com/weblog/PermaLink.aspx?guid=17427571-171e-4199-80cb-55a278ae699c"&gt;Dare Obasanjo&lt;/a&gt; asks: &lt;/p&gt;

&lt;blockquote&gt;
    &lt;ol&gt;
    &lt;li&gt;Are there shipping technologies today that allow me to do what I want in an &amp;#8220;Identity 2.0&amp;#8221; way?&lt;/li&gt;
    &lt;li&gt;Are they as easy to implement as telling mashup developers to include a link to my website in their UI and then process the data they get back when the user is redirected back to their site after signing in? &lt;/li&gt;
    &lt;/ol&gt;
    
    &lt;p&gt;and the answers are No, and Hell No respectively&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I think both views are correct.  Yahoo&amp;#8217;s BBAuth is an identity silo, but there also isn&amp;#8217;t an easy way to plug in a auth mechanism that is easy to use for developers and users.&lt;/p&gt;

&lt;p&gt;This is one of the most interesting areas in development today and I look forward to what the future holds.&lt;/p&gt;

&lt;p&gt;First found via: &lt;a href="http://www.scripting.com/2006/09/29.html#yahooOpensItsIdentitySystem"&gt;Dave Winer&lt;/a&gt;, then &lt;a href="http://jeremy.zawodny.com/blog/archives/007557.html"&gt;Jeremy Zawodny&lt;/a&gt;.&lt;/p&gt;</description>
      <pubDate>Mon, 02 Oct 2006 21:48:00 +0100</pubDate>
      <guid isPermaLink="false">urn:uuid:a78ed74b-f53f-4d95-bc23-ddf60ba80c61</guid>
      <author>Kerry</author>
      <link>http://blogs.divisibleprime.com/ronin/articles/2006/10/02/yahoo-bbauth</link>
      <category>SSO</category>
      <category>Tech</category>
      <category>Identity</category>
      <category>identity</category>
      <category>web</category>
      <category>authorisation</category>
      <category>yahoo</category>
      <category>sso</category>
    </item>
  </channel>
</rss>
