

OpenID Gains Supporters

Posted by Keith McMillan

February 7, 2008 | 1 Comment

IBM, Microsoft, Verisign, Google and Yahoo! have joined the OpenID board, as reported by CSO. OpenID allows a single registry of authentication credentials (login and password) to be used at all participating web sites.

Single registry systems have been around in corporate intranet environments for a while (Microsoft ActiveDirectory, IBM WebSphere IdentityManager, OpenLDAP, etc). They’re a nice tool for a centralized organization to manage user credentials.

The hazard of widespread adoption of such a system are twofold, I believe: a single set of credentials allow you to log in to a variety of sites. If I can compromise your password, then I gain access to all these sites. This may be no worse than today, if you use the same login and password for all the sites anyway, but it does make it more difficult for you to have different logins and passwords, should you so desire.

Secondly, and perhaps more subtle, if I compromise your password, can I register for new sites that support  OpenID  that you don’t even know about? This needs more looking into…


RSS feed | Trackback URI

1 Comment »

2008-02-14 16:17:24

[…] blogged earlier about the addition of some large players to the OpenID board, which makes it an interesting […]

Name (required)
E-mail (required - never shown publicly)
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong> in your comment.
