« Out of Context | Main | A Call for Participation: The Next User-centric Interop »

August 20, 2007

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83420ad7a53ef00e54ee20dc18834

Listed below are links to weblogs that reference Some Predicted OpenID Weaknesses:

Comments

Jesse

Great job on the OpenID writeup - the concerns you specified are very real and I agree that this technology is on the right track but still needs to mature a bit.

It will be somewhat difficult to come up with an acceptable method for Internet SSO - usually an in-house scenario makes use of an RSA token or other similar tool to provide much stronger authentication and verification of identify.

In this case, perhaps something along the lines of a "sign-in seal" on the OpenID site would be beneficial in providing an anti-phishing mechanism to protect online subscribers. This is only one piece of the puzzle as the other concerns you mentioned - specifically the WHAT users are allowed access to would still need to be solved.

JV.
www.securasys.net
"Information Security Solutions for an ever changing business environment"

The comments to this entry are closed.

  • Burton Group Free Resources Stay Connected Stay Connected Stay Connected Stay Connected



Blog powered by TypePad