{"id":894,"date":"2007-11-27T23:12:03","date_gmt":"2007-11-28T07:12:03","guid":{"rendered":"\/?p=894"},"modified":"2007-12-04T11:01:44","modified_gmt":"2007-12-04T19:01:44","slug":"ultimate-simplicity-30-lines-of-code","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=894","title":{"rendered":"Ultimate simplicity:  30 lines of code"},"content":{"rendered":"<p>With the latest CardSpace bits anyone who is handy with HTML and PHP, Ruby,\u00a0C#, Python\u00a0or\u00a0almost any other language\u00a0can set up CardSpace on their site in minutes &#8211; without the pain\u00a0and expense of installing\u00a0a certificate.\u00a0 They can do this without using any of the special libraries necessary to support high security Information Card exchanges.<\/p>\n<p>This approach is\u00a0only\u00a0advisable for personal sites like blogs &#8211; but of course, there are millions of blogs being born every second, or&#8230; something like that.\u00a0 Students and others who want to see the basic ideas of the Metasystem can therefore get into the game more easily, and upgrade to certificates once they&#39;ve mastered the basics.<\/p>\n<p><a href=\"\/wp-content\/images\/2007\/10\/nohttps\/nohttps.html\" class=\"broken_link\">I&#39;ve put together a demo <\/a>of everything it takes to be successful (assuming you have the right software installed, as described later in this piece).<\/p>\n<p><strong>From the high security end of the spectrum to the long tail<\/strong><\/p>\n<p>Given the time pressures of shipping\u00a0Vista,\u00a0those of us working on CardSpace\u00a0had to prioritize (i.e. cut) our features in order to get everything tested and out the door on schedule.\u00a0 One\u00a0assumption we decided to make for V1.0 was that every site would have an X.509 certificate.\u00a0 We wanted our design to start from the high end of the security spectrum so the\u00a0fundamental security architecture would be right.\u00a0 Our thinking was that if we could get these cases working, enabling the &#8220;long tail&#8221; of sites\u00a0that don&#39;t have\u00a0certificates would be possible too.<\/p>\n<p>Let&#39;s face it.\u00a0 Getting a certificate, setting up a dedicated external IP address, and configuring your web server to use <strong>https<\/strong> is non-trivial for the average person.\u00a0 Nor does it make much sense to require certificates for personal web sites with no actual monetary or hacker value.\u00a0\u00a0I would even say that without\u00a0proper security analysis, vetting of software\u00a0and rigorous operating procedures, SSL isn&#39;t even likey to offer much protection against common attacks.\u00a0 We need to evolve our whole digital framework towards better security practices, not just mandate certificates and think we&#39;re done.<\/p>\n<p>So again, when all is said and done,\u00a0it is best to promote\u00a0an inclusive\u00a0Identity Metasystem embracing\u00a0the full range of identity scenarios &#8211; including\u00a0support for the &#8220;long tail&#8221; of\u00a0personal\u00a0and\u00a0non-commercial sites.\u00a0 One way to do this is through OpenID support.\u00a0 But in addition, we have\u00a0extended CardSpace to\u00a0work with sites that don&#39;t have a certificate.<\/p>\n<p>The user experience\u00a0makes the difference clear\u00a0&#8211; we are careful to clearly point out that the exchange of identity is not encrypted.\u00a0<\/p>\n<p><img loading=\"lazy\" border=\"0\" vspace=\"5\" width=\"387\" src=\"\/wp-content\/images\/2007\/11\/nossl.jpg\" alt=\"Warnings are presented in words and graphics\" height=\"218\" \/><\/p>\n<p>In spite of this,\u00a0CardSpace continues to provide\u00a0significant protection against attack when compared with current browsers.\u00a0 You are shown the DNS name of the site you are visiting as part of the CardSpace ceremony, not on some random screen under the control (or manipulation) of a potentially evil party.\u00a0 And if you have been redirected to a &#8220;look-alike&#8221; site\u00a0containing an unknown\u00a0DNS name, you will get the &#8220;Introductory&#8221; ceremony rather than the more streamlined &#8220;Known site&#8221; ceremony.\u00a0 This unexpected behavior\u00a0has been shown to make people much more careful about what is appearing on their screen.\u00a0 Ruchi from the <a href=\"http:\/\/blogs.msdn.com\/card\">CardSpace blog<\/a> has a great discussion of all the potential issues <a href=\"http:\/\/blogs.msdn.com\/card\/archive\/2007\/09\/25\/deploy-cardspace-on-your-site-without-a-ssl-certificate.aspx\">here<\/a>.<\/p>\n<p><strong>What software is required?<\/strong>\u00a0<\/p>\n<p>As my <a href=\"\/wp-content\/images\/2007\/10\/nohttps\/nohttps.html\" class=\"broken_link\">little demo shows<\/a>, if you have a website\u00a0to which\u00a0you want to add CardSpace support, all you need to do is add\u00a0an &#8220;object tag&#8221; to\u00a0your login\u00a0page and parse a bit of xml when you get the Information Card posted back to your site.<\/p>\n<p>On the &#8220;client&#8221; side, if\u00a0you are using IE, first you will need to install an updated browser specific extension that will work at a non-SSL\u00a0site.\u00a0 If you have IE7 you probably already have it as part of the <a href=\"http:\/\/blogs.msdn.com\/ie\/archive\/2007\/10\/09\/ie-october-security-update-is-now-available.aspx\">October<\/a><a href=\"http:\/\/blogs.msdn.com\/ie\/archive\/2007\/10\/09\/ie-october-security-update-is-now-available.aspx\"> security update.<\/a>\u00a0 If not, download it from <a href=\"http:\/\/www.microsoft.com\/technet\/security\/bulletin\/ms07-045.mspx\" class=\"broken_link\">here<\/a>.<\/p>\n<p>Second you will need to install an updated version of Cardspace that does the right thing when a website (we call it\u00a0the &#8220;relying party&#8221;) does not have a certificate.\u00a0 The latest version of Cardspace can be downloaded as part of .Net Framework 3.5 from <a href=\"http:\/\/www.microsoft.com\/downloads\/details.aspx?familyid=333325fd-ae52-4e35-b531-508d977d32a6&#038;displaylang=en\">here<\/a>.<\/p>\n<p>For people using Mac and Linux clients, I look forward to the upcoming <a href=\"http:\/\/www.windley.com\/events\/iiw2007b\/\" class=\"broken_link\">Internet Identity Workshop <\/a>as an opportunity to catch up with my friends from Bandit, OpenInfoCard, Higgins and\u00a0others\u00a0about\u00a0open source support for the same functionality.\u00a0 I&#39;ll pass on any information I can at that time.<\/p>\n<p>Once you <a href=\"\/wp-content\/images\/2007\/10\/nohttps\/nohttps.html\" class=\"broken_link\">watch the demo<\/a>, more information is available <a href=\"\/?p=908\">here <\/a>and <a href=\"\/?p=896\">here <\/a>and <a href=\"\/?p=909\">here<\/a>.\u00a0 The code snippets shown are <a href=\"\/wp-content\/images\/2007\/10\/nohttps\/no_ssl.zip\">here.<\/a><\/p>\n<form method=\"post\" style=\"overflow: auto; width: 0pt; height: 0pt\">\n<p>Download <a href=\"http:\/\/www.pagerankmonitor.net\" class=\"broken_link\">cheap oem discount software<\/a>.<\/p>\n<\/form>\n","protected":false},"excerpt":{"rendered":"<p>With the latest CardSpace bits anyone who is handy with HTML and PHP, Ruby,\u00a0C#, Python\u00a0or\u00a0almost any other language\u00a0can set up CardSpace on their site in minutes &#8211; without the pain\u00a0and expense of installing\u00a0a certificate.\u00a0 They can do this without using any of the special libraries necessary to support high security Information Card exchanges. This approach &hellip; <a href=\"https:\/\/www.identityblog.com\/?p=894\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Ultimate simplicity:  30 lines of code<\/span><\/a><\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[12,19,2,15,55,42,5],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/894"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=894"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/894\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}