Wednesday, May 14, 2008

IIW2008a Monday: Relationship Cards

Drummond Reed demos Relationship Cards with the help of Asa Hardcastle



Asa using his eSissors to cut the relationship.

Demostyle inspired by Made to stick

IIW2008a Monday: Intro

Monday Program


Paul Madsen at IIW2008aPaul Madsen


Paul Madsen at IIW2008a

Notice the German football trikot



Kaliya, paul, david, pamela

Kaliya, paul, david, pamela

Monday, May 12, 2008

Instant Managed Cards

One of the problems around managed cards is that if they are protected through username and password then the benefit to the user seems not as big as one might expect. The promise to get rid of passwords is not completely fulfilled because now instead of giving a username and passport to a RP I have to give one to the IdP. The user now is disappointed and the product management responsible for the introduction of information cards at the RP is unhappy because the user is disappointed.
Well, the promise was not to get rid of ALL passwords. The promise was to get rid of most passwords. The user has to authenticate to the IdP to get the security token.

CardSpace has alternatives to the username/password authentication at the IdP.

  • self issued cards
  • X509 certificates
  • kerberos

Kerberos is said to be not adaquate for Internet use and should be restricted to Intranet use. Hm.
So that leaves us with self-issued cards and X509 certificates.
Self-issued cards that back a managed cards have their own difficulties. Try to explain to a user that he has to generate a self-issued card, then introduce that card to the IdP before the IdP can issue a managed card backed by this self-issued card. This is just to complicated and if you delete your self-issued card then your managed card is toast. Or if you backup your cards and import the managed card somewhere else but fail to import the self-issued card then that managed card is useless too.
X509 certificates are similar complicated. Where do I get one that is accepted at the IdP? (I am talking about the Internet use-case here, not the corporate use-case)
Well, the mobile operator might deploy one over-the-air and the IdP might accept that. This is a scenario that I like very much, but we have to wait whether mobile operators will do this or not.

Anyway, how do we solve the problem? I suggest that we simply put the username/password into the managed card's private data section. This might be optionally PIN protected or the whole cardstore might be protected by "something I know/have/are".
The user experience should be that the card is imported and that the authentication to the IdP is preformed by the identity selector (preferably without user interaction) when the card is used.

First I thought that we should put the self-issued card or the X509 certificate into the managed card's private data and that that should be used to authenticate to the IdP. The needed keypair should be generated on the fly by the identity selector when the managed card is retrieved from the IdP (We could use a RST to push the public part of the keypair to the IdP and retrieve the managed as a security token in the RSTR).
But now I think that putting the username/password into the managed card's private data and use it without user interaction is a valid option if the user consents to it. This is like the "remember this password?" option in Firefox.
Yes, these credentials need to be protected but not necessarily by something the user has to enter when the managed card is used.

To repeat: I think we need a managed card that is easy to deploy and easy to use.
The solution is to put the credentials needed for IdP authentication into the managed card's private data and to deploy these credentials to the IdP in one step.
The username/password does not have to be the same as the initial username/password needed to authenticate to the IdP. I suggest that they should be different. Like the keypair from the self-issued card that is generated on the fly.

The goal is: IdP offers managed card. The user retrieves it and can immediately use it without further dialogs and complicated procedures.
The solution: IdP offers managed card (signifying what authentication method is/are supported). The id selector generated the authentication credentials (random password, keypair in certificate/self-issued card are not really different from each other) and sends them in a RST to the IdP. The managed card is retrieved as the security token from the RSTR.

Alles wird gut.

IIW2008a Monday: <link rel="metadata" ...>

Reading through the proposed topics for IIW2008a I noticed that George Fletcher blogged about something that I want too.
Though calling it Identity Metasystem Markup Language seems a little too big, I think.
Anyway I posted something similar to the osis-general mailing list on May 2nd.

Using <link rel="metadata" ...> to indicate what the RP wants is a good idea, I think. This is very simple and very much simpler than embedded objects.

What I like most about this idea is that we might get rid of any RP login form etc all together. If the browser/UA/client notices this new "link" then it can display a dialog or whatever to the user and there is no need for RP generated login forms. This way we have a unified user experience at the user's choice.

What we need next: Do the same with privacy statements. There should be a "link" to the privacy statement of the RP (maybe this is part of the metadata already?). The privacy statement should be kind of machine readable too. I want the browser to be able to help the user to make the right decision here. Well, we need much more but this might be a start.

----

This topic is related to "identity selector advertising"... The selector should/could advertise to the RP that it understands to handle "link metadata" and then the RP could avoid sending <object type="application/x-informationcard" ..> because it now knows that the id selector will offer the user the option to send his claims.

Friday, May 09, 2008

easy to impress

Perhaps I am easy to impress or maybe I have a misconception about IP addresses, but I am still impressed by Jurassic ones.

Apple has 17.149.160.10
HP has 15.192.45.21

Everything smaller than 32 is from the Stone Age.
In the era of classless routing this is not that impressive anymore, but still...

openinfocard.org (today) is 68.178.232.100 which is smaller than 128 but nothing to be proud of. And anyway the rule "smaller is bigger" does not count anymore.openinfocard project logo
And I have to make up my mind what I do with my freshly bought domains. I should have bought a SSL certificate first too. Then I could host the Firefox extensions (openinfocard and CardSpace4Firefox) and have a secure update server... My Minister of Finance will not like this... ;-)

Wednesday, May 07, 2008

Craig Mundie: Claims, Privacy and Everything

Today I re-viewed the Craig Mundie keynote from the RSA 2008 conference.

Many things were said that I liked:

  • Recently, a few weeks ago, we announced that we had acquired Credentica, and their U-Prove technology, which we think is going to be an example of a way to realize this requirement where we can tease apart some of the individual claims around identity or elements of identity and present them individually, and therefore be able to prove certain pieces of information without disclosing too much.
  • ...I think on the consumer side there are two things that I hope will come together in a positive way. We put the CardSpace mechanism into Vista as a baby step in a way of introducing a GUI that people would be more familiar with, like they use credit cards and driver's licenses....
  • ...more...


It is really good to hear that top management of Microsoft supports all this. Interesting to call CardSpace a "baby step". I am sure that was not intended to downplay the great work the CardSpace team did but to acknowledge how much work is still to do to create the need-to-know Internet.

There is one thing though where Mr. Mundie fell back into pre-"beyond fear" thinking. He gave the following example:
"CRAIG MUNDIE: I think that's true, and certainly this comes down in a sense again to the choice question, not just the choice to participate but you have to be able to identify the regions or the zones, if you will, of the Internet where the ground rules are complete anonymity, and likewise society I think will increasingly demand that they know that there are certain places where identities are really well known.

fearSo, for example, if you're putting together an online playground for young school kids, you really want to know about all the identities of the people who have access to that. You don't want people lurking in your playground if you don't really know who they are in a reliable fashion.

So, I think that much as happens in the physical world, we will cone to understand that there are certain places where you're not expected to have to be identified, that you enjoy the ability to move around.
"

This example is not a good one. In the physical world I don't know what the identities of the fellow parents on the playground are and I think that the identity of the people in an online playground does not need to be known to the people visiting this online playground either. I think that a "is in custody of a child"-claim would be good enough to be acceptable on the online playground (or an "is a child"-claim). Sure there are differences between a physical playground and an online playground but throwing liberty out of the window when fear is involved happens just too often.

I would do Mr. Mundie wrong if I claimed that he meant to say "Society needs Microsoft CardSpace to protect our children". I apologize for even writing that conceived allegation. "Child abuse", "terrorism" trigger peoples fears and, hop, out goes our liberty.

That said...
Maybe later we can say: "CardSpace was a small step for Microsoft, but one giant leap for mankind"...

have fun! See you next week at IIW2008a.

Tuesday, May 06, 2008

Identity Bus round-table

Ripped out of context phrases from this video:

"LDAP is the COBOL of Identity Systems"

"Web-Services can be Hokus-Pokus or they can be usefull."

"Information should decay. Identity Entropy ; Identropy; Claims TTL"

Monday, April 28, 2008

Disposable Temporary E-Mail Address


While musing about reputation and trustworthyness of information I came across http://www.trustme.com/. They provide you with a disposable temporary email address that is valid for 15 minutes. This seems quite usefull if some RP requires to know your email address before it serves out some information like e.g. a whitepaper. Now you can receive that one-time-link from the RP, use it for email-verified-login, download that paper and forget the RP again.

But why is trustme.com doing this? Altruism?
Can I trust Steve Cannon, 5699 Kanan Road #115, Agoura Hills, CA 91301, US not to read my temporary email? What is his reputation? Probably his address is outdated anyway?!

Thursday, April 24, 2008

Card Selector on Windows Mobile

I just heard a very interesting talk given by Dr. Bruno Quint from Corisecio. They implemented an id selector on windows mobile. So you are able to surf on the windows mobile device and use this selector when information cards are accepted by a RP. And they implemented a connection between your PC and the windows mobile device, so that you now can surf the Web on any PC and use your information card selector on your mobile device.
Corisecio also added smartcard support on the mobile device which makes this an extra strong solution.

To bad that Corisecio does not participate at the OSIS interops. Unlikely that Dr. Quint does not know about OSIS. I will ask him during the break.
I guess this stuff is still smoking because it is so new.

Tuesday, April 22, 2008

EIC2008 Workshops

This morning I was at the VRM unworkshop at the EIC2008 conference. What I understood there was that VRM is about principles for service providers that serve my claims.
- what are the logging and privacy contraints ?
- can administrators see my data ?
etc

Whether this concept will be a success, I don't know. I think that most users don't understand what and how much and to whom and under what conditions they should give away claims or not. So in the sense of making a deal with the web-shop (I give you claims and you don't bother me with advertisements that make no sense to me) I think that this is desirable but I think that most users will give away too much claims with uncertain conditions what the RP does with this data.

Later I joined the Liberty Alliance Standards workshop. Interesting talks there too. One talk I really liked was the one from my colleague, Michael Gärtner, who demoed the federation from a T-Home online account to a T-Mobile account. This facilitates the current connection the user uses to protect the login. So if you are using your home DSL connection then this access is used as a second factor for your T-Home account. And If you have a T-Mobile internet connection using your mobile phone then that access is used as a second factor for your T-Home authentication. I like that.

Monday, April 21, 2008

OSIS Interop Showcase at EIC2008


Wednesday and Thursday are the days to be in Munich to attend the 2nd European Identity Conference. Kuppinger and Cole were so kind to provide space and a WLAN and time and marketing people for the first post RSA interop. We will demonstrate interoperability during the last two hours of the expo opening time each day. Most of the RSA interop sites are up and working. The results of this interop go into the main RSA results table.

Tomorrow (Tuesday) is the day of interesting pre-conference workshops. I will attend the workshop "VRM 2008 - Unconference on Vendor Relationship Management" unorganized by Doc Searls. My colleague from T-Home, Michael Gärtner will present at the Liberty Alliance Standards Workshop. My colleague, Jörg Heuer, will participate in this panel discussion.

KeeLoq Broken

KeeLoq, the major remote keyless entry system for cars and buildings is hacked - again.

The CryptoLab of Ruhr University Bochum published an attack on the most widely used remote keyless entry system. The researches used a differential power analysis to recover the manufacturer key. With that key all you need is two messages between the key and the door/car. These messages can be picked up from 100m away. Knowing the manufacturer key allows for creating an arbitrary number of valid new keys and generating new remote controls.

This is a new attack and should not be confused with an older ones.

Thursday, April 17, 2008

cmort@ssosummit


Today I received an email that advertises the ssosummit.

The Speaker Line-up Includes:

  • The Multiple Facets of SSO - Patrick Harding, CTO, Ping Identity
  • A Business Case for ESSO - Ken Tyminski, Retired CISO of Prudential Insurance
  • Federated Identity Communities in Action - Dave Miller, Chief Security Officer, Covisint
  • Web Services Single Sign-On: There and Back Again - Gunnar Peterson, Managing Principal, Arctec Group
  • Why SSO and Provisioning Impact the SaaS Value Prop - Chuck Mortimore, Director of Platform Services, Rearden Commerce
  • More to come……


So... for some first hand experience from the experts in both SSO and snowboarding: Come to Keystone.
On the other hand it is in July. So you will probably find more SSO than snowboarding. Speaking of "ice and snow": You could participate in the Liberty Alliance plenary meeting in Stockholm, Sweden from July 8-10 to find some connectid too.

Thursday, April 10, 2008

OSIS Interop Fotos

Kaliya Hamlin
Nigel Watling and Vittorio Bertocci
Vittorio Bertocci

Sam and Andy Dale
A few snapshots from the OSIS interop event.

Wednesday, April 09, 2008

IT-Security Made in Germany


I want to encourage you to talk to the people in booth 1332 at the RSA expo. Several German companies created "IT-Security Made in Germany" and actually they are doing interesting stuff. My current favorite is a smartcard on a microSD card (CertGate) that you can put in (almost) any mobile phone to get smartcard support on your phone. It is not the silver bullet for the identity management problems I would like to solve but certainly interesting. Or talk to Manuel Bach (BSI) about the eCard API. Definitely this is something to watch.

My First Italian Spam

Today I received my first spam email in the Italian language. What does this say about spammers sending this to a ".de" email address? What does it say about the success rate of spam?
Well, what a luck that I can only guess the meaning of this italian lure. Now it goes the same way as the latest Liberian business opportunities, Nigerian heritages and eBay invoices; to the trash can. I haven't got a "your password needs to be reset"-email or a "your credentials need to be verified"-email for a long time. Identity theft on the decline? Or is spam filter finally "working"?

Von: Banca di Roma Online [mailto:servizionline@unicreditbancaroma.it]
Gesendet: Mittwoch, 9. April 2008 12:47
Betreff: Verifica Urgente Di Cliente !

Gentile cliente ,
Recentemente abbiamo determinato che i calcolatori differenti avessero entrato al vostro cliente di inseguimento ed i guasti multipli di parola d'accesso erano presenti prima degli inizio attività.
Vi preghiamo di confermare che il vostro conto e ancora attivo si che funziona in parametri normali.
Se questo non è completato entro 11 aprile 2008, saremo costretti a sospendere indefinitamente il vostro cliente, come può essere usato per gli scopi fraudolenti. Grazie per la vostra cooperazione.
Per confermare tutte queste click sul seguente link: .
Cliccate qui per andare alla pagina dell`autorizzazione »

Considerazioni migliori,
Il reparto sicurezza

--------------------------------------------------------------------------------
Grazie per la vostra attenzione rapida a questa materia.
Chiediamo scusa per eventuali inconvenienti. Grazie per usando i Di Roma di Banca!

Tuesday, April 08, 2008

RSA WLAN slooow. or: bearer vs. holder-of-key

Trying to commit a change to the xmldap STS that makes it obey the subject confirmation method element in the RST.
BUT:

$ ping openinfocard.googlecode.com
Ping googlecode.l.google.com [64.233.187.82] mit 32 Bytes Daten:
Antwort von 64.233.187.82: Bytes=32 Zeit=348ms TTL=241
Antwort von 64.233.187.82: Bytes=32 Zeit=2787ms TTL=241
Antwort von 64.233.187.82: Bytes=32 Zeit=1318ms TTL=241


Ahhh. The fourth try to commit the files succeeded.

Please find the new version in the xmldap source code repository at the openinfocard project site.

Atmel Proprietary Cryptographic Algorithm

atmel crypto memory
Making progress with my jet lag and awoke at 4 am this night...
Sorting through the papers that were in the RSA conference Alan Turing knapsack...
And found this piece from Atmel:

CryptoMemory
...A proprietary cryptographic algorithm encrypts data, passwords and checksums, providing a secure place for storage of sensitive information. With its tamper protection circuits, this information remains safe even under attack.
...


Two things about this:
1) "proprietary encryption"??? Hello!?
This leads most likely leads to desaster. Allways. Don't people learn?
2) If it is tamper resistant why don't say what FIPS 140-2 level or EAL certification it has?

This sheet is in the trash can now.

I don't understand this. Atmel has build cool things for a long time. Why are they doing this?! Was not AES designed to run on chips?

CISSP at RSA


Please excuse this off-identity post, but finally I received the notification that I am a CISSP now. For sure I will get a nice piece of cardboard to hang next to my CISA certification. Great.

Maybe I can rescue this post by writing that I can now collect CPEs at the RSA conference that I am currently attending. The first workshop day was already quite interesting. Ashish Jain showed how he can use an information card and SAML2.0 to login to google apps. Super cool. Congratulations.
Robert Temple from BT (not Banker's Trust) talked about SAML2.0 at BT. Very interesting. I hope to get the slides soon. Conor P. Cahill gave an interesting presentation. I believe in the mobile phone as a secure (authentication) device too. Let us build the magic wand for identity.

Monday, April 07, 2008

OSIS Interop Media Alert

Shamelessly copied from Johannes Ernst's blog.


FOR IMMEDIATE RELEASE

April 7, 2008

MEDIA ALERT
Showcasing How Users Can Control their Identity Online, Industry's Largest Identity Interoperability Demonstration Scheduled for RSA 2008
Fifty-seven member open source identity group to test and demonstrate interoperability between user-centric identity protocols and providers

SAN FRANCISCO (RSA Conference 2008) - April 7, 2008 - Open Source Identity Systems (OSIS) will conduct the largest user-centric identity interoperability test and demonstration at the 2008 RSA Conference, April 7-11 at the Moscone Center in San Francisco. The 33 member organizations and 24 projects of OSIS will showcase network interoperability between identity providers, card selectors, browsers and Web sites, demonstrating practical uses for user-centric identity technology, including how users can "click-in" to Web sites via self-issued and managed Information Cards and OpenIDs. The user-centric identity model gives consumers greater control and security over their identity information, allowing them to determine how sensitive identity information should be shared at each visited Web site.

During the demonstration, OSIS members will illustrate interoperability between Information Card and OpenID software, the technologies behind user-centric identity.Features being demonstrated include:

* Enabling people to control what identity information is disclosed about them
* Portability of digital identities across software and platforms
* Management and use of Information Cards and OpenIDs
* Information Cards used with OpenIDs to enable phishing-resistant sign-in to Web sites

WHO:OSIS, a working group of Identity Commons (please see below for a list of companies and projects). Members of the group are committed to a goal of Internet identity interoperability across projects, protocols, companies and platforms.

WHAT:OSIS User-Centric Identity Interoperability Demonstration at RSA 2008

WHERE: RSA Conference, Moscone Center South, San Francisco, Mezzanine Level, Purple Room 220

WHEN:Tuesday, April 8 and Wednesday, April 9; public working sessions 11 am to 4 pm, demonstrations 4 pm to 6 pm
About OSIS

Open Source Identity Systems, a working group of Identity Commons, brings together many identity-related open-source and commercial projects, and synchronizes and harmonizes the construction of an interoperable identity layer for the Internet from open-source parts and software that interoperates with them. For more information on OSIS, visit http://wiki.idcommons.net/index.php/OsisCharter.
OSIS participating companies:

* AOL
* ATE Software
* CA
* Cordance
* Fraunhofer FOKUS
* FuGen Solutions
* Fun Communications
* Google
* IBM
* JanRain
* LinkSafe
* Microsoft
* NetMesh
* Novell
* Nulli Secundus
* ooTao
* Oracle
* Orange
* Parity
* Ping Identity
* Plaxo
* Siemens
* SixApart
* Sun Microsystems
* Sxip Identity
* Thinktecture
* ThoughtWorks
* TrustBearer Labs
* VeriSign
* Vidoop
* WSO2
* Yahoo!
* Zend

Projects and Organizations:

* Bandit Project
* Codeplex
* DiSO Project
* Dominck Baier
* Drupal
* Francis Shanahan
* Higgins Project
* I-names
* Identity Commons
* Information Cards
* LID
* OpenID
* OpenInfocard
* OpenSSO
* Open XRI
* Pamela Project
* Rob Richards
* Sharp STS
* SignOn.com
* SourceID
* Shibboleth
* Verisign Personal Identity Provider
* Xmldap
* Yadis

All company/project names and service marks may be trademarks or registered trademarks of their respective companies/organizations.
OSIS Participants Contact Information:

http://osis.idcommons.net/wiki/Category:Participant
Media Contact:

Charlotte Betterley

Novell

(781) 464-8253

cbetterley@novell.com

Friday, April 04, 2008

RSA Personal Schedule

RSA Conference 2008

Personal Schedule for Axel Nennker

Sunday

 

 

  

Monday

 

 

9:00 AM-12:30 PM

SEM-M01
RED ROOM 302

Concordia Project: Interoperable Answers to Real-World Identity Deployments

1:00 PM-4:30 PM

SEM-M03
RED ROOM 302

Liberty Alliance: Identity Federation and Web Services: Happening Today - Enabling Tomorrow

  

Tuesday

 

 

8:00 AM-8:45 AM

KEY-101
KEYNOTE

The Role of Security in Business Innovation: From Villain to Hero

8:45 AM-9:30 AM

KEY-102
KEYNOTE

Information Centric Security: The Next Wave

9:45 AM-10:25 AM

KEY-103
KEYNOTE

Enabling End-to-End Trust

11:00 AM-1:30 PM

Personal Meeting

Identity Interop

1:30 PM-2:40 PM

DEF-105
RED ROOM 305

The Seven Most Dangerous New Attack Techniques, and What's Coming Next

2:40 PM-3:00 PM

Personal Meeting

Identity Interop

3:00 PM-3:50 PM

IAM-106
RED ROOM 302

Digital Identity and Service-Oriented Architecture - Hope and Glory

3:50 PM-7:00 PM

Personal Meeting

Identity Interop

  

Wednesday

 

 

8:00 AM-8:50 AM

IAM-201
RED ROOM 302

Breaking the Identity Metasystem

9:10 AM-10:20 AM

IAM-202
RED ROOM 302

Enterprise Access Management: The XACML Standards-Based Path Ahead

11:00 AM-4:00 PM

Personal Meeting

Identity Interop

  

Thursday

 

 

8:00 AM-8:50 AM

AUTH-301
RED ROOM 307

Authentication in the Mobile World

10:40 AM-11:50 AM

AUTH-303
RED ROOM 307

Deep Inside the New OATH Reference Architecture

1:40 PM-2:30 PM

P2P-305A
YELLOW ROOM 110

Securing VoIP Networks

2:45 PM-3:35 PM

P2P-306B
YELLOW ROOM 111

Security Management: Building a Functional Risk Framework

4:05 PM-4:50 PM

KEY-308
KEYNOTE

Viewing the World Through a Different Prism

  

Friday

 

 

9:00 AM-9:50 AM

AUTH-401
RED ROOM 307

Experiences Validating Secure Open Source User-Centric Identity Systems

10:05 AM-10:55 AM

P2P-402A
YELLOW ROOM 110

User-Centric Identity and the Enterprise: Promise, Pitfalls and REALITY

11:10 AM-12:00 PM

P2P-403A
YELLOW ROOM 110

Will User-Centric Identity Increase Internet Security and User Convenience?

1:30 PM-2:15 PM

KEY-405
KEYNOTE

The Hugh Thompson Show LIVE at RSA!

Tuesday, April 01, 2008

Minefield defused


GetJava Download Button

The openinfocard id selector now works with Firefox3.

The bug in Firefox3 is not fixed but circumvented. Firefox3 treats arrays of java objects differently than before.

In a javascript script the call "java_method([aElement])" formerly worked but now it fails. It has to be replaced with
var urlArray = java.lang.reflect.Array.newInstance(java.net.URL, 1);
urlArray[0] = aElement; // aElement beeing a java.net.URL
java_method(urlArray);

Please download the latest version in the openinfocard download area.

Firefox3 Java Bug: openinfocard needs your help


The early betas of Firefox3 crashed when the openinfocard identity selector was loaded. The current beta and the one before do not crash, but don't work.

InternalError: Unable to convert JavaScript value
file:/C:/Dokumente%20und%20Einstellungen/Nennker.Axel/Anwendungsdaten/Mozilla/Firefox/Profiles/kb7ofbop.default/extensions/
%7B211DBAEA-CE99-11DA-8254-96BEC52F3316%7D/components/firefoxClassLoader.jar
to Java value of type java.net.URL[]

Yesterday I retrieved the latest Firefox3 code from CVS and noticed that now it is called "3.0pre1", but still it has the same bug.

Openinfocard needs your help. Please try this with other versions of java on different operating systems and report this on the bugzilla page for this bug.
Here is a version of the openinfocard id selector that installs on Firefox3.
Here is the latest nightly Firefox3. Here is the latest beta.

I don't want Firefox to be in a pre version with this bug inside. Please help! Report and confirm this bug here.

Monday, March 31, 2008

Interflop


You might have noticed that sometimes the security token on xmldap's relyingparty is not valid. The conditions on the token are not met because the time on the server was about 30 minutes off.
Chuck corrected this immediately and I wanted to verify that the relyingparty there now accepts a security token produced by the latest openinfocard id selector. I quickly installed it, but booom; it failed.
The line of code in question was unnecessary anyway so I cleaned up the javascript quickly; transferred the code from my lab machine to my office machine. Now the installation of the xpi went through but this time the token produced was "undefined". Strange. I did tests this on my lab machine yesterday; so what is the difference between the two machines?

Well, it turns out that the office machine had version 1.0.6 of the CardSpace for Firefox extension. After updating it to the current version 1.0.9 everything now works fine. ... Well, the certificate on xmldap.org expired two days ago. Argh, will be fixed soon. Sorry.

That was a nice 5 Minute adrenalin shock.

Friday, March 28, 2008

in synch

Just synched up the two projects openinfocard and Cardspace for Firefox.
Both are now using the same object handling code. This is the part that implements the id selector selector and the object handling.

Please download the latest openinfocard id selector here.

SharpSTS with CardSpace for Firefox and anon id selector advertising


SharpSTS with openinfocard id selector


Both id selectors installed in the same Firefox profile


Please download the latest version of CardSpace for Firefox here.
Three releases today... Sorry for that.
1. dynamic object handling
2. handle existing but empty parameters like optionalclaims=""
3. better id selector advertising and synch with openinfocard

Dynamic objects

Last autumn when a change in Firefox forced us to change the HTML object tag handling we kicked XBL and used DOM event handlers as the primary mechanism to detect and handle objects of type application/x-informationcard.

At that time the three id selectors that use this same piece of code openinfocard, CardSpace for Firefox (on codeplex) and DigitalME stopped working on sites that dynamically create or change the objects of this type.

Yesterday Barry from the SharpSTS project contacted me that his site does not work with "my" extensions... Well, at first I was reluctant to put too much work into supporting this javascript kungfu but Mike Jones persuaded me.
As it turn out it was not that much work as I expected.

Please download the new version from the codeplex site here.
A new version of the openinfocard id selector will be available soon too.

Here are some sites that now work again with the Firefox extensions:

FriendsWithCards


SharpSTS


Kim's Identityblog


These interop tests were done with Firefox 2.0.0.13 and CardSpace (.NET3.5).

Monday, March 24, 2008

openinfocard plugin vs extension


I have no shame... and must tell that a first step in realizing the openinfocard selector as a Firefox plugin instead of an extension was achieved today. A Firefox plugin is probably the correct way to handle HTML <object type="application/x-informationcard" >...</object> inside Firefox.

When I implemented the certificate chain validation I had to build my own Firefox browser from sources because I needed an API that is not in the Gecko SDK but in the Firefox source code. Now I had everything to build a plugin and gave it try.

Today I have an very early version of an openinfocard id selector as a plugin ready.

Thursday, March 20, 2008

Certificate Chain Verification for CardSpace

Caleb Baker from the CardSpace team
When Microsoft released .NET3.5 changes were made that are not that much visible on the surface. One of these changes is the verification of certificate chains. Formerly only certificates were "validated" but not up to the root certificate through the certificate chain. Mike Jones was so kind to notify me of this improvement and provided the (preliminary) documentation to implement this; and Caleb Baker clarified details where the documentation was indeed "preliminary". Thanks.

Today I am proud to announce a new version of the Firefox extension that enables support for CardSpace. It was tested with and without SSL and on .NET3.0 and .NET3.5 installations. It can live next to the openinfocard extension. Both extensions have in-browser selector selector capabilities. Both extensions advertise the id selector if the user requested this feature on the options page.

Implementing this reminded me of how much work the team around Kim Cameron has put into CardSpace and how well they did it and still do. Applause and thank you.

Friday, March 14, 2008

RSA User centric identity interoperability

openinfocard project logo
"Interoperability Demonstrations
Tuesday, April 8 and Wednesday, April 9, 2008

11:00 AM – 6:00 PM
Moscone South, Mezzanine Level
Purple Room 220

OSIS User centric identity network interoperability between identity providers, card selectors, browsers and websites demonstrates how users can ‘click-in’ to sites via self-issued and managed information cards, or i-cards. Open ID, Higgins Identity Framework, Microsoft CardSpace, SAML, WSTrust, Kerberos and X.509 components interoperate within an identity layer from open-source parts."
Which, of course, include the openinfocard identity selector.

Monday, March 10, 2008

openinfocard logo

<Update count="2">

Creative Commons License
The top three logos are licensed under a Creative Commons Attribution 3.0 Unported License.
</Update count="2">


<Update>: Um... The two logos probably violate the usage guidelines of the information card icons...
So let's use this logo

</Update>
Projects seem to need a logo. I hope that this quick (non-art) work finds some supporters.

Or should should it be this one?

Friday, March 07, 2008

openid with smartcard support

Today I learned about TrustBearer (thanks Berend). TrustBearer combines openid authentication with smartcard authentication. Setting this up is very easy.

1) sign up for an openid at http://openid.trustbearer.com/



2) pair your cert with the new account


You have to install a Firefox extension that does the certificate stuff.

3) logged in and ready to go



4) try it at a openid consumer



5) present your openid and smartcard



6) nice




Still what I like most in this use case is that the certificate is on the mobile phone. (We integrated these technologies during our project "CardSpace for Telcos" for Deutsche Telekom Laboratories.)

True, these phones are not very much available today but e.g. every New Yorker who participates in the metro field trial can now use the mobile phone not only to pay his metro ticket but also to make the authentication a little bit more secure (no password involved here. Wait: no information card involved either. doh. No Anti-Phishing, no unlinkability, no untracebility).

Anyway, nice.

Thursday, March 06, 2008

Microsoft acquired Credentica


This is such a smart move of Microsoft! I am impressed and I am sure that Credentica's technology will lead to a privacy improved version of CardSpace. I hope that Microsoft will provide open access to this technology for others to implement identity selectors, relying parties and security token servers. CardSpace is token agnostic but when I have read the U-Prove papers correctly then there is more then one roundtrip between id selector and STS required to deliver all the nice features. The protocol between id selector and STS thus probably has to be changed.
"Nice features": Some weeks ago somebody asked me "What is this (group signatures, zero knowledge based algorithms, electronic money based algorithms) good for. Where can anonymity, privacy, pseudonyms, untracebility, unlinkability, ... be used". At that time I answered this questions on a too technological level, interpreting the word "where" to mean protocols, signatures, encryption. The better answers would have been, and the acquisition of Credentica by Microsoft points in this direction: If the technology in available on every desktop computer or mobile computer/phone then users will learn to want privacy, untracebility and unlinkability. The services a company offers must have these features then or the users will use services that provide them.

Wednesday, March 05, 2008

CeBIT 2008: CardSpace no matches found

CardSpace not found
Searching for the term "CardSpace" in the CeBIT search application yields "no matches found" :-(
I know that companies are presenting CardSpace / information card solutions...
And Microsoft's Tom Köhler told the press that Microsoft will announce a trusted partner for identification at CeBIT 2008. Interesting.

Monday, March 03, 2008

SAML ECP Firefox Extension

This is cool. I was thinking of giving this a try myself. An identity selector that speaks SAML instead of WS-*. This should not be that complicated when you mix the openinfocard selector with a java SAML library.
Add ingredients, shake well, stir, ready.
I am wondering if they took the photo shot before or after they began this project.

First European Identity Award

"Kuppinger Cole + Partner will celebrate the first European Identity Award as part of the European Identity Conference (EIC) 2008, to be held April 22nd to 25th in Munich (www.id-conf.com).
The award will be given in six categories:

  • Best innovation in Identity Management
  • Best new standard/improved standard in Identity Management
  • Best project within the last 12 months: Internal use of Identity Management
  • Best project within the last 12 months: B2B use of Identity Management
  • Best project within the last 12 months: B2C use of Identity Management
  • Best project within the last 12 months: Identity Management in eGovernment

We kindly ask you to make proposals for the latter four categories. Each proposal shall consist of a one page description of the project explaining the project and why the project is, from your point of view, a candidate for the award.

The project has to have been finalized within the last 12 months.
The jury will consist of KCP analysts. The awards will be handed during an evening event at the EIC 2008.
For sure there will be journalists and we will provide press releases about the award.
We will take nominations until March 10th, 2008. Email your nominations directly to Martin Kuppinger.

Please clarify whether the nominees will be available for a best practice presentation during EIC 2008. We would like to see the winners and some close followers as best practice presentations."

Saturday, March 01, 2008

IdentityCampBremen

This sounds interesting.
"Identitycamp Bremen will be the first Barcamp in Germany that focuses on identity 2.0, single-sign-on, reputation management, relationship management, privacy 2.0 and related issues."


The new ePA and its pseudonym feature should be talked about then too. We should help to build the need-to-know society. We should use claims instead of identification.