FREE Subscription to Dr. Dobb’s Digest: Same Great Content, New Digital Edition
Site Archive (Complete)
Windows/.NET
Email
Print
Reprint

add to:
Del.icio.us
Digg
Google
Furl
Slashdot
Y! MyWeb
Blink
February 06, 2007
Microsoft Courts OpenID

Bill Gates touts collaboration with an open source identity framework to augment Microsoft's Windows CardSpace initiative and Web security standards.
Despite recent security improvements to its next generation of software, Microsoft announced plans Tuesday to augment its own identity authentication standards with the OpenID framework.

The company is presenting a proof-of-concept demonstration and collaboration between its Windows CardSpace initiative and the OpenID 2.0 specification at the RSA Security Conference in San Francisco this week. The relationship is expected to help eliminate what's sometimes known as the "man-in-the-middle" attack, where a third party can read and modify messages between two unsuspecting parties.

Microsoft chairman Bill Gates and chief research and strategy officer Craig Mundi said the company would be adopting the decentralized identity management system because it realized that authentication was needed at the application layer for many Web 2.0 products. The announcement comes five years after Gates issued to Microsoft employees his "Trusted Computing" directive, which stressed security as the company's highest priority.

"Those were the days when we talked mostly about the 'I Love You' virus," Gates said during his keynote address at RSA.

Fast-forward to today, where Microsoft itself is acknowledging that attacks are more focused on areas other than the network, such as the application level.

"We realized that we still needed to create a GUI for credentials and for situations that were more on an ad hoc basis," Mundi said during the morning keynote. "It should be no more difficult for a person to identify themselves online as it is to walk in person and take a driver license and credit card for identification."

Developed by Brad Fitzpatrick of LiveJournal, OpenID is fast gaining market acceptance by Web 2.0 groups such as Wikipedia and Technorati, as well as computer security firms like Symantec.

Windows CardSpace -- formerly InfoCard -- is part of Microsoft's .Net 3.0 framework and integrates with Microsoft's Windows Communication Foundation, Windows Workflow Foundation, and Windows Presentation Foundation.

Gates noted also that the OpenID 2.0 spec would help support Microsoft's own Web security protocols, which are widely used in Web services transactions.

"There are reputation and trust issues involved that this helps solve," Gates said.

Gates and Mundi said the CardSpace/OpenID proof-of-concept demonstration is expected to be implemented in the Windows Longhorn Server product, currently in beta testing and due out later this summer.

In addition to testing OpenID in its architecture, Microsoft announced Tuesday security-related products and partner initiatives, including the launch of its Identity Lifecycle Manager 2007, the release of a public beta for its Forefront Server Security Management Console, and additional support of Extended Validation SSL Certificates in Internet Explorer 7. Microsoft also recently announced other key security-related initiatives, including the general availability of the Intelligent Application Gateway 2007, a Microsoft Network Access Protection 100-partner milestone, and the launch of Windows Live OneCare.

RELATED ARTICLES
No Related Articles
TOP 5 ARTICLES
No Top Articles.
DR. DOBB'S CAREER CENTER
Looking for a new job? open | close
Search jobs on Dr. Dobb's TechCareers
Function:

Keyword(s):

State:  
  • Post Your Resume
  • Employers Area
  • News & Features
  • Blogs & Forums
  • Career Resources

    Browse By:
    Location | Employer | City
  • Most Recent Posts:



    MICROSITES
    FEATURED TOPIC

    ADDITIONAL TOPICS

    INFO-LINK



     




    Techweb
    Informationweek Business Technology Network
    InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
    Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
    Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
    space
    TechWeb Events Network
    InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
    Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
    space
    Light Reading Communications Network
    Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
    Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
    space
    Financial Technology Network
    Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
    space
    Microsoft Technology Network
    MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
    space