{"id":924,"date":"2008-02-25T12:29:58","date_gmt":"2008-02-25T20:29:58","guid":{"rendered":"\/?p=924"},"modified":"2008-02-25T14:13:40","modified_gmt":"2008-02-25T22:13:40","slug":"from-screen-names-in-bondage-to-openid","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=924","title":{"rendered":"From &#8220;Screen-Names in Bondage&#8221; to OpenID"},"content":{"rendered":"<p>Google&#39;s Ben Laurie <a href=\"http:\/\/www.links.org\/?p=297\">proposes using &#8220;functions of passwords&#8221;<\/a> rather than plain passwords as a way to avoid phishing:\u00a0<\/p>\n<blockquote><p>Kim Cameron writes about <a href=\"https:\/\/www.identityblog.com\/blog.php\/#post-923\" class=\"broken_link\">fixing OpenID\u2019s phishing problems by using Cardspace<\/a>. Certainly I agree that using strong authentication to the OpenID provider fixes the phishing problem &#8211; but if you have strong authentication, why bother to use OpenID at all? Why not strongly authenticate to the site you are really trying to log into, instead?<\/p>\n<p>Of course, Cardspace is a pretty heavyweight solution for this, so perhaps that\u2019s what Kim\u2019s getting at? It also doesn\u2019t work well if you have more than one machine &#8211; moving your credentials around is not something Cardspace does well.<\/p>\n<p>In my view, there\u2019s a sweeter spot for solving this problem than Cardspace (or OpenID, obviously) &#8211; and that is to do strong authentication based purely on a password. That way, you can use the same password everywhere, so no problem with moving between machines, but can still resist phishing attacks and don\u2019t have to make yourself linkable across all sites. Obviously supporting this would be way easier than taking the whole of Cardspace on board, but would have all of the immediate advantages. Clearly it would get you nowhere with advanced identity management, but its not like we don\u2019t already have protocols for that and nor does there seem to be much demand for it yet.<\/p><\/blockquote>\n<p>I take it Ben is talking about having a toolbar that asks for your password, and transforms it based on the site&#39;s identity so you can use the same password everywhere.\u00a0 Perhaps he is even thinking about a digest protocol where this transformed password would be used to calculate a &#8220;proof&#8221; rather than transported over the wire.<\/p>\n<p><strong>Phished\u00a0or Pharmed<\/strong>\u00a0<\/p>\n<p>Problem is,\u00a0such a toolbar is as\u00a0easily &#8220;<em><a href=\"http:\/\/en.wikipedia.org\/wiki\/Pharming\">pharmable<\/a><\/em>&#8221; as OpenID is phishable.<\/p>\n<p>How does a user know she is typing her password into\u00a0the legitimate toolbar &#8211; rather than an &#8220;evil replica&#8221;?\u00a0 Our experience with toolbars teaches us that is easy to trick a\u00a0LOT of people into using fakes.\u00a0 In fact, sometimes the fakes have propagated faster than the real thing!\u00a0 Once people get used to typing passwords into a toolbar you have truly opened <a href=\"http:\/\/en.wikipedia.org\/wiki\/Pandora&#39;s_Box\">Pandora&#39;s Box<\/a>.<\/p>\n<p>Let&#39;s\u00a0look at what happens when\u00a0the kind of\u00a0&#8220;common password&#8221; Ben proposes is stolen.\u00a0In fact, let&#39;s compare it to\u00a0having money stolen.\u00a0<\/p>\n<p>If\u00a0you go into a store and\u00a0are short-changed,\u00a0you just lose money in one store.\u00a0 If\u00a0you are\u00a0pick pocketed,\u00a0you just lose what&#39;s in\u00a0your wallet &#8211;\u00a0you can cancel your cards.\u00a0 But if\u00a0your &#8220;common\u00a0password&#8221; is intercepted, it is as though you have lost money in ALL the stores you have been in.\u00a0\u00a0\u00a0And sadly, you will have lost a lot more than money.<\/p>\n<p>The ultimate advantage of moving beyond passwords is that there is then NO WAY a user can inadvertantly give them away.<\/p>\n<p><strong>Is CardSpace too heavy-weight?<\/strong>\u00a0<\/p>\n<p>CardSpace\u00a0should be a lighter-weight experience than it is today.\u00a0 We&#39;re\u00a0working on\u00a0that,\u00a0making it less &#8220;in-your-face&#8221; while actually <em>increasing its safety<\/em>.\u00a0 I also agree with Ben that it needs to be easier to roam credentials.\u00a0 We&#39;re\u00a0working on\u00a0that too.\u00a0<\/p>\n<p>The point is, let&#39;s\u00a0evolve CardSpace &#8211; and the interoperable software being developed by others &#8211; to whatever is needed to really solve\u00a0the relevant privacy and security\u00a0problems, rather than introducing more half-measures that won&#39;t be effective.<\/p>\n<p><strong>So why OpenID?<\/strong><\/p>\n<p>If that&#39;s all true, Ben wonders why we bother with OpenID at all&#8230;<\/p>\n<p>The most important reason is that OpenID gives us <em>common identifiers for public personas that we can use across multiple web sites &#8211; and a way to prove that we really own them.<\/em><\/p>\n<p>That is huge.\u00a0 Gigantic.\u00a0 Compare it to the cacophony of\u00a0&#8220;screen-names&#8221; we have today &#8211; screen-names in bondage, prisoners of each site.<\/p>\n<p>Technology people are sometimes\u00a0insulted when you imply they haven&#39;t solved the world&#39;s problems.\u00a0 But to be really important, OpenID doesn&#39;t have to solve the world&#39;s problems.\u00a0 <strong>It just has to do this one common-identifier thing really well.<\/strong>\u00a0 And it does.\u00a0 That&#39;s what I love about it.<\/p>\n<p>CardSpace doesn&#39;t\u00a0address the same\u00a0problem.\u00a0 CardSpace plus OpenID solve it together.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Common identifiers that accrue reputation across social networking and blog sites will knock your socks off. <\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[24,8,15,22,4],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/924"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=924"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/924\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=924"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=924"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}