IdentitySelector
513
Comment:
|
2995
http://www.bandit-project.org/index.php/Reference_Application
|
Deletions are marked like this. | Additions are marked like this. |
Line 1: | Line 1: |
* '''Launchpad Entry''': https://launchpad.net/distros/ubuntu/+spec/identity-selector * '''Created''': [[Date(2006-11-04T15:30:00Z)]] by NealMcBurnett * '''Contributors''': EricNorman * '''Packages affected''': == Summary == |
|
Line 2: | Line 9: |
based on growing support for "Laws of Identity" and frustration | based on growing support for "Laws of Identity" (see reference below or [http://www.identityblog.com/?page_id=352]) and frustration |
Line 5: | Line 13: |
Users will want OS support for securely selecting identities to use with web services. One promising leader |
To guard against phishing, the identity selection should incorporate a clear and unmistakable signal to the user that she is indeed talking with her own identity selector and not something that just looks like one, provided by a phisherman. == References == For more information about CardSpace (nee InfoCard), a real good place to start is [http://www.identityblog.com] (documents on left side). See also the July 2006 Linux Journal article by Doc Searls: [http://www.linuxjournal.com/article/9049 Progress Report toward Independent Identity] == Rationale == Providing a user interface which makes it clear to the user that they are interacting directly with a layer of the operating system that is more resistant to attack than the browser or other application would increase user confidence and reduce phishing attacks. There is already a Firefox plugin to do this. But implementing this purely in an application like a browser leaves the user's identity information more vulnerable, and the user more confused about when it is ok to type in their password. We will also want to enable more flexible and secure authentication methods for many networked activities besides traditional browsing. == Use cases == == Scope == This spec is focussed on the client side. Besides an Identity Selector, other Ubuntu specs are needed for other InfoCard support services. E.g. probably a Card Store to store a user's cards; a log ala the Microsoft "Ledger" that tracks a user's usage of cards at various sites/services; and a Self-Issued Identity Security Token Service (STS) that can be an identity provider for self-issued cards. Support for the server side (Relying Parties) and for Identity Provider implementations will come through applications such as Apache. == Design == The Identity Selector would probably consist of a protected user interface, and a protocol module to get tokens via interactions with Security Token Services. == Implementation == One promising code base |
Line 11: | Line 62: |
There is also the [http://www.bandit-project.org/index.php/Reference_Application Bandit reference application] == See also == * NetworkAuthentication * AuthenticationInfrastructure * ConsistentLoginScreen ---- CategorySpec |
Launchpad Entry: https://launchpad.net/distros/ubuntu/+spec/identity-selector
Created: Date(2006-11-04T15:30:00Z) by NealMcBurnett
Contributors: EricNorman
Packages affected:
Summary
Identity metasystems are finally beginning to mature, based on growing support for "Laws of Identity" (see reference below or [http://www.identityblog.com/?page_id=352]) and frustration with the problems of userid/password authentication.
To guard against phishing, the identity selection should incorporate a clear and unmistakable signal to the user that she is indeed talking with her own identity selector and not something that just looks like one, provided by a phisherman.
References
For more information about CardSpace (nee InfoCard), a real good place to start is [http://www.identityblog.com] (documents on left side).
See also the July 2006 Linux Journal article by Doc Searls: [http://www.linuxjournal.com/article/9049 Progress Report toward Independent Identity]
Rationale
Providing a user interface which makes it clear to the user that they are interacting directly with a layer of the operating system that is more resistant to attack than the browser or other application would increase user confidence and reduce phishing attacks.
There is already a Firefox plugin to do this. But implementing this purely in an application like a browser leaves the user's identity information more vulnerable, and the user more confused about when it is ok to type in their password.
We will also want to enable more flexible and secure authentication methods for many networked activities besides traditional browsing.
Use cases
Scope
This spec is focussed on the client side.
Besides an Identity Selector, other Ubuntu specs are needed for other InfoCard support services. E.g. probably a Card Store to store a user's cards; a log ala the Microsoft "Ledger" that tracks a user's usage of cards at various sites/services; and a Self-Issued Identity Security Token Service (STS) that can be an identity provider for self-issued cards.
Support for the server side (Relying Parties) and for Identity Provider implementations will come through applications such as Apache.
Design
The Identity Selector would probably consist of a protected user interface, and a protocol module to get tokens via interactions with Security Token Services.
Implementation
One promising code base is OSIS - Open Source Identity Selector, which intends to be at least as functional, and fully compatible, with Microsoft's CardSpace (formerly known as InfoCard) identity selector that will be shipped with Windows Vista.
There is also the [http://www.bandit-project.org/index.php/Reference_Application Bandit reference application]
See also
IdentitySelector (last edited 2008-08-06 16:35:43 by localhost)