CardSpace & OpenID

Mike Jones and Kim Cameron from Microsoft came in for a visit today to the JanRain World Headquarters (if you’ve ever visited here, you’d understand why that’s funny).

The JanRain engineers were interested in learning more about CardSpace. We’ve heard about it, seen Kim talk and even read his proposal on a way to integrate OpenID and CardSpace. However, we didn’t know enough about the technology to comment on it either way. Also, we wanted to hear more than just marketing hype and hand waving; we wanted some code. Kim and Mike did not disappoint … :-)

CardSpace is an identity meta-system that you use to manage InfoCards. InfoCards are like the cards in your wallet except these cards you present to sites that you want to visit to identify yourself with. I really believe that Mike and Kim have their hearts in the right place and the technology looks solid. It looks like Microsoft has learned a lot since their last foray into identity. I think OpenID and CardSpace could really compliment each other quite nicely as well as help address the phishing concerns that have become so prevalent.

The CardSpace InfoCard manager is an interface that comes up when the user is presented with a site that supports InfoCard login. Instead of giving the user a login form in the browser that might be phished, the user is presented with a dialog that allows them to deliver an InfoCard for the site they are trying to login to. This dialog is single-modal; you are locked out of doing anything else unless you complete the task at hand. This follows along with what Mike Beltzner shared on the OpenID general list and the difficulties in fighting phishing:

I can also sum things up for you even more succinctly:

– users are task oriented, driving to complete the goal the
quickest way possible
– users pay more attention to the content area than the browser chrome
– users don’t understand how easy it is to spoof a website

Kim went through several code examples where we could see how it all worked. Forget SOAP, forget complicated. There is no hook back to the mothership with this technology. As a matter of fact, OpenID and CardSpace could work together quite easily.

CardSpace is really good at handling the issues around phishing and personal privacy. But what if I don’t want to be private about certain things? I like that I can identify myself as me to lots and lots of different sites and I don’t mind if people correlate that data. As a matter of fact, I like it. Wouldn’t it be nice to have an OpenID tied to my InfoCard then? One of the greatest reasons OpenID is succeeding is that its a destination. Its a unique place on the Internet where you can learn more about who I am. Coupled with microformats you start to see some interesting possibilities. CardSpace doesn’t do the public side very well and both Kim and Mike admitted this. This is an interesting possibility for OpenID IMHO. Not only that, it could be done without any changes to sites that already support OpenID. You’d get the benefits of OpenID’s strengths while leveraging the anti-phishing and privacy mojo that CardSpace has.

We already have some great technology for changing the chrome in Firefox and discussions are on-going with Mozilla about how we can integrate this further and have it truly baked in (hopefully they’ll look at Dmitry’s thoughts on this). We’ve got the CardSpace code that is now shipping on Vista and available for Windows XP. We’ve got lots of options for fighting phishing and protecting privacy with more on the way. All of these solutions play to each technologies strengths and actually just might be what we need to get to the identity holy land.

About The Author

kveton

Other posts bykveton

Author his web sitehttp://kveton.myvidoop.com

31st

January 2007

1 Comments Add Yours ↓

The upper is the most recent comment

  1. 1

    Awesome! From my point of view – Cardspace and OpenID could compliment each other very very well. I’m really glad to see you guys exploring this. I work for an Aussie Bank – and we have been looking at CardSpace recently for its anti-phishing countermeasures. When you break it down and get underneath the covers, we’ve found it to be really not that complicated…

    You’re right – the point about ‘liking’ your identity to be public, to be correlated, is something where OpenID truly excels. Bolt on some CardSpace magic and you’ve got the best of both worlds.

    I’m really looking forward to unlocking my OpenID with my InfoCard selecter!


3Trackbacks/Pingbacks

  1. The Undevelopment Blog » CardSpace is Imminent 01 02 07
  2. Kim Cameron’s Identity Weblog » Scott Kveton on InfoCard / OpenID convergence 04 02 07
  3. Kim Cameron’s Identity Weblog » Doc Searls on Creator Relationship Management 06 02 07

Your Comment

Note: This post is over 3 years old. You may want to check later in this blog to see if there is new information relevant to your comment.

Additional comments powered by BackType