<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenID &#187; News</title>
	<atom:link href="http://openid.net/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>http://openid.net</link>
	<description>Home of the OpenID community</description>
	<lastBuildDate>Tue, 31 Jan 2012 01:01:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<atom:link rel='hub' href='http://openid.net/?pushpress=hub'/>
		<item>
		<title>OpenID Connect in a Nutshell</title>
		<link>http://openid.net/2012/01/24/openid-connect-in-a-nutshell/</link>
		<comments>http://openid.net/2012/01/24/openid-connect-in-a-nutshell/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 06:29:37 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9722</guid>
		<description><![CDATA[Nat Sakimura has written a valuable post describing OpenID Connect in a nutshell. It shows by example how simple it is for relying parties to use basic OpenID Connect functionality. If you’re involved in OpenID Connect in any way, or are considering becoming involved, his post is well worth reading.]]></description>
			<content:encoded><![CDATA[<p><a href="http://nat.sakimura.org/">Nat Sakimura</a> has written a valuable post describing <a href="http://nat.sakimura.org/2012/01/20/openid-connect-nutshell/">OpenID Connect in a nutshell</a>. It shows by example how simple it is for relying parties to use basic <a href="http://openid.net/connect/">OpenID Connect</a> functionality. If you’re involved in OpenID Connect in any way, or are considering becoming involved, his post is well worth reading.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2012/01/24/openid-connect-in-a-nutshell/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OpenID Foundation 2012 Community Board Member Election</title>
		<link>http://openid.net/2012/01/03/openid-foundation-2012-community-board-member-election/</link>
		<comments>http://openid.net/2012/01/03/openid-foundation-2012-community-board-member-election/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 17:36:20 +0000</pubDate>
		<dc:creator>jfe</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[board election]]></category>
		<category><![CDATA[vote]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9452</guid>
		<description><![CDATA[This is to announce the 2012 election of OpenID Foundation community board members. The Foundation plays an important role in the evolution of Internet identity technologies. Those elected will help determine what role the OIDF should play in helping facilitate faster and broader adoption of open standard identity systems. Last year four community board members [...]]]></description>
			<content:encoded><![CDATA[<p>This is to announce the 2012 election of OpenID Foundation community board members. The Foundation plays an important role in the evolution of Internet identity technologies. Those elected will help determine what role the OIDF should play in helping facilitate faster and broader adoption of open standard identity systems.</p>
<p>Last year four community board members were elected to 2-year terms and so are not standing for election:<br />
•	Nat Sakimura<br />
•	Mike Jones<br />
•	John Bradley<br />
•	Kick Willemse</p>
<p>Other current community board members may seek re-election. They are:<br />
•	Allen Tom<br />
•	Axel Nennker<br />
•	Chris Messina</p>
<p>Brian Kissel has indicated he will likely not be a candidate.  This is a good time to thank Brian, and all the current board members, for their time, attention and leadership over the last year.  </p>
<p>For the purposes of the 2012 election, there are 5 confirmed sustaining members: Google, Microsoft, PayPal, Ping Identity, and Symantec.  Thus, we will be electing 2 community members to the Board of Directors for 2-year terms.  In order to be eligible for election, your candidacy must have been seconded by at least three other members. </p>
<p>The election will be conducted on the following schedule:<br />
Nominations open:  Monday, January 9<br />
Nominations close:  Monday, January 23<br />
Election begins:  Wednesday, January 25<br />
Election ends: Wednesday, February 8<br />
Results announced by: Wednesday, February 15<br />
New board terms start: Thursday, March 1</p>
<p>Times for all dates are Noon, U.S. Pacific Time.</p>
<p>All members of the OpenID Foundation are eligible to nominate themselves, second the nominations of others who self-nominated, and vote for candidates.  If you’re not already a member of the OpenID Foundation, we encourage you to join now at <a href="https://openid.net/foundation/members/registration">https://openid.net/foundation/members/registration</a>. </p>
<p>Voting and nominations are conducted using the OpenID you registered when you joined the Foundation.  Log in at <a href="https://openid.net/foundation/members/">https://openid.net/foundation/members/</a> with your OpenID to participate in the nomination and voting. If you are already a member, you will receive an email advising you the election is open and how to participate. If you experience problems participating in the election or joining the foundation, please send an email to help@oidf.org.  </p>
<p>Board participation requires a substantial ongoing investment of time and energy.  It is a volunteer effort that should not be undertaken lightly. Should you be elected, expect to be called upon to serve both on the board and on its committees where the work of the foundation is conducted.  If you’re committed to OpenID and advancing open digital identity and are a person who works well with others, we encourage your candidacy.  The OIDF’s Executive Committee has suggested a few questions candidates may want to publicly address in their candidate statements:</p>
<p>1.	What is you view of the opportunity of the OpenID Foundation?<br />
2.	What are the key opportunities you see for the OpenID Foundation in 2012?<br />
3.	How will you demonstrate your commitment to the work of the foundation in terms of resources, focus and leadership?<br />
4.	What would you like to see accomplished over the next year, and how do you personally plan to make these things happen?<br />
5.	What resources can you bring to the foundation to help the foundation attain its goals?<br />
6.	What current or past experiences, skills, or interests will inform your contributions and views?</p>
<p>Candidates can address these questions in their election statements on various community mailing lists and at http://openid.net – especially openid-general@lists.openid.net, and via blog@oidf.org. Please forward questions, comments and suggestions to me.</p>
<p>Don Thibeau<br />
Executive Director<br />
The OpenID Foundation</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2012/01/03/openid-foundation-2012-community-board-member-election/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Review of Proposed OpenID Connect Implementer’s Drafts</title>
		<link>http://openid.net/2011/12/23/review-of-proposed-openid-connect-implementer%e2%80%99s-drafts/</link>
		<comments>http://openid.net/2011/12/23/review-of-proposed-openid-connect-implementer%e2%80%99s-drafts/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 14:41:12 +0000</pubDate>
		<dc:creator>John Bradley</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>
		<category><![CDATA[Implementer's Draft]]></category>
		<category><![CDATA[OpenID Connect]]></category>
		<category><![CDATA[spec]]></category>
		<category><![CDATA[specification]]></category>
		<category><![CDATA[vote]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9248</guid>
		<description><![CDATA[The OpenID AB+Connect Working Group recommends approval of the following specifications as OpenID Implementer’s Drafts: Basic Client Profile – Simple self-contained specification for a web-based Relying Party.  (This spec contains a subset of the information in Messages and Standard.) Discovery – Defines how user and provider endpoints can be dynamically discovered. Dynamic Registration – Defines [...]]]></description>
			<content:encoded><![CDATA[<p>The OpenID AB+Connect Working Group recommends approval of the following specifications as OpenID Implementer’s Drafts:</p>
<ul>
<li>Basic Client Profile – Simple self-contained specification for a web-based Relying Party.  (This spec contains a subset of the information in Messages and Standard.)</li>
<li>Discovery – Defines how user and provider endpoints can be dynamically discovered.</li>
<li>Dynamic Registration – Defines how clients can dynamically register with OpenID Providers.</li>
<li>Messages – Defines all the messages that are used in OpenID Connect.  (These messages are used by the Standard binding.)</li>
<li>Standard – Complete HTTP binding of the Messages, for both Relying Parties and OpenID Providers.</li>
<li>Multiple Response Type Encoding – Registers OAuth 2.0 response_type values used by OpenID Connect.</li>
</ul>
<p>An Implementer’s Draft is a stable version of a specification providing intellectual property protections to implementers of the specification.  This note starts the 45 days public review period for the specification drafts in accordance with the OpenID Foundation IPR policies and procedures.  This review period will end on Monday, February 6, 2012.</p>
<p>Unless issues are identified during the review that the working group believes must be addressed by revising the drafts, this review period will be followed by a seven day voting period during which OpenID Foundation members will vote on whether to approve these drafts as OpenID Implementer’s Drafts.</p>
<p>The specifications are posted at these locations:</p>
<ul>
<li><a href="http://openid.net/specs/openid-connect-basic-1_0-15.html">http://openid.net/specs/openid-connect-basic-1_0-15.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-discovery-1_0-07.html">http://openid.net/specs/openid-connect-discovery-1_0-07.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-registration-1_0-08.html">http://openid.net/specs/openid-connect-registration-1_0-08.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-messages-1_0-07.html">http://openid.net/specs/openid-connect-messages-1_0-07.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-standard-1_0-07.html">http://openid.net/specs/openid-connect-standard-1_0-07.html</a></li>
<li><a href="http://openid.net/specs/oauth-v2-multiple-response-types-1_0-03.html">http://openid.net/specs/oauth-v2-multiple-response-types-1_0-03.html</a></li>
</ul>
<p>A description of OpenID Connect can be found at <a href="http://openid.net/connect/">http://openid.net/connect/</a>. The working group page is <a href="http://openid.net/wg/connect/">http://openid.net/wg/connect/</a>.</p>
<p>Information on joining the OpenID Foundation can be found at <a href="https://openid.net/foundation/members/registration">https://openid.net/foundation/members/registration</a>.  Foundation members will be asked to vote on approving these specifications as Implementer’s Drafts.</p>
<p>You can send feedback on the specifications in a way that enables the working group to act on your feedback by</p>
<ol>
<li>signing the contribution agreement at <a href="http://openid.net/intellectual-property/">http://openid.net/intellectual-property/</a> to join the AB+Connect working group,</li>
<li>joining the working group mailing list at <a href="http://lists.openid.net/mailman/listinfo/openid-specs-ab">http://lists.openid.net/mailman/listinfo/openid-specs-ab</a>, and</li>
<li>sending your feedback on that list.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/12/23/review-of-proposed-openid-connect-implementer%e2%80%99s-drafts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon, Building the Foundation for a Safe, Security Identity Ecosystem</title>
		<link>http://openid.net/2011/12/07/verizon-building-the-foundation-for-a-safe-security-identity-ecosystem/</link>
		<comments>http://openid.net/2011/12/07/verizon-building-the-foundation-for-a-safe-security-identity-ecosystem/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 22:37:13 +0000</pubDate>
		<dc:creator>Don Thibeau</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9194</guid>
		<description><![CDATA[Verizon announced today an important milestone in the Open Identity arena. Verizon announced that it is the first ever identity provider to achieve a Level 3 US Government certification in providing identity credentials and access management to relying parties. The importance of building a standardized framework that protects valuable personal data from Internet security risks [...]]]></description>
			<content:encoded><![CDATA[<p>Verizon announced today an important milestone in the Open Identity arena.</p>
<p>Verizon announced that it is the first ever identity provider to achieve a Level 3 US Government certification in providing identity credentials and access management to relying parties. The importance of building a standardized framework that protects valuable personal data from Internet security risks is being recognized and addressed on a global scale and national level. </p>
<p>Verizon has established itself as a leader that is building a foundation for an open and secure Internet-identity ecosystem that people and business can trust. Beyond providing a safeguard for digital identities, certified identity providers will help speed conversations, interactions and transactions for people, businesses and relying parties now and in the future.</p>
<p>As one of the pioneers in building the trust frameworks, Verizon’s leadership as an identity provider is at the heart of building this new identity ecosystem. Verizon was one of the founding members of the Open Identity Exchange (OIX) an organization that now includes the leaders in internet, telco and data aggregation industries.</p>
<p>Today’s password-focused website login process is unsafe and risky and has led to personal information and data being compromised through phishing and hacking attacks on weak systems. The potentially devastating consequences associated with the hijacking and theft of digital identities highlights the need for a trusted and certified framework that relying parties can depend on for identity authentication.</p>
<p>OIX, its member companies and Verizon aim to provide an open framework that standardizes the security, privacy, and operation policies of identity service providers that people, businesses and governments can trust.</p>
<p>The Internet identity ecosystem is quickly evolving with companies playing many different roles. The OIX is focused on the roles of attribute providers, identity providers, and relying parties. Verizon is playing an important role as a leader and advocate for OpenID. We congratulate Verizon on this significant achievement. </p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/12/07/verizon-building-the-foundation-for-a-safe-security-identity-ecosystem/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Sony’s Weakest Link Hijack</title>
		<link>http://openid.net/2011/10/13/sony%e2%80%99s-weakest-link-hijack/</link>
		<comments>http://openid.net/2011/10/13/sony%e2%80%99s-weakest-link-hijack/#comments</comments>
		<pubDate>Thu, 13 Oct 2011 17:03:10 +0000</pubDate>
		<dc:creator>Don Thibeau</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://openid.net/?p=7927</guid>
		<description><![CDATA[Sony announced today that a large number of accounts were hijacked using an attack based on the fact that people reuse passwords across websites. These “weakest link hijackings” are an evolution of the phishing attacks that have become so well known over the last few years. These attacks are referred to as “weakest link hijackings” [...]]]></description>
			<content:encoded><![CDATA[<p>Sony announced today that a large number of accounts were hijacked using an attack based on the fact that people reuse passwords across websites. These “weakest link hijackings” are an evolution of the phishing attacks that have become so well known over the last few years.</p>
<p>These attacks are referred to as “weakest link hijackings” because the hackers attack websites with the weakest security, and then collect user passwords. Since it is common for users to reuse passwords across websites, hackers can then try those collected passwords against other websites like Sony as well as social network accounts, email accounts, work accounts, etc. When hackers take over the user’s social network or email account, they frequently change the user&#8217;s password on the account to lock the real user out, then use it to try to trick the user&#8217;s friends into sending money. One scam claims the person was stuck while travelling and needs money wired to them. Imagine losing access to all your contacts, email, photos, etc. and then having your friends lose thousands of dollars.</p>
<p>Unfortunately it is extremely difficult for websites to protect themselves against the weaker security of these other websites. Only some of the largest websites with the most sophisticated security tools can detect these types of attacks and try to automatically reduce their impact on their own accounts as Sony has done. Some of those websites offer users the option to add an additional layer of security to their account, for example by sending a code to their phone number each time they want to login. However if every website took that approach, users would revolt because of the pain it would create for them.</p>
<p>It&#8217;s time for website owners to wake up and realize they are probably the “weakest link.” Most websites need to stop trying to run their own login system and instead rely on third-party tools and websites that provide users with highly secure login systems. This type of login approach has become popular with websites that want to integrate with social networks, but it can also be used by any website by simply letting users choose an identity provider that runs a secure login system. It also has the advantage of making it easier for users to register for a new website on a mobile device and we all know what a hassle that can be.</p>
<p>Consortiums of companies such as the OpenID Foundation are working together to solve the problem of passwords and weak login systems, and are making great strides on security, usability, and privacy. With so much of our digital identities and information at stake, it’s critical that we create a better, more secure system before we see more victims of the “weakest link”.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/10/13/sony%e2%80%99s-weakest-link-hijack/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>OpenID Connect Specs Incorporating Developer Feedback</title>
		<link>http://openid.net/2011/09/12/openid-connect-specs-incorporating-developer-feedback/</link>
		<comments>http://openid.net/2011/09/12/openid-connect-specs-incorporating-developer-feedback/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 18:50:41 +0000</pubDate>
		<dc:creator>Nat Sakimura</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>
		<category><![CDATA[Summit Events]]></category>
		<category><![CDATA[connect]]></category>
		<category><![CDATA[interop]]></category>
		<category><![CDATA[spec]]></category>
		<category><![CDATA[specification]]></category>

		<guid isPermaLink="false">http://openid.net/?p=7513</guid>
		<description><![CDATA[Since we posted in July about the availability of preliminary OpenID Connect specifications, developers have been building implementations and submitting feedback on the specs.  The specs have been revised to incorporate their feedback.  A new map of the specs is as follows: The biggest difference you’ll notice is that there is now only one spec to implement for “Minimal” [...]]]></description>
			<content:encoded><![CDATA[<p>Since we <a href="http://openid.net/2011/07/15/current-map-for-openid-connect/" target="_blank">posted in July</a> about the availability of preliminary <a href="http://openid.net/connect/" target="_blank">OpenID Connect</a> specifications, developers have been building implementations and submitting feedback on the specs.  The specs have been revised to incorporate their feedback.  A new map of the specs is as follows:</p>
<map name="GraffleExport">
<area shape="rect" coords="221,193,336,245" href="http://openid.net/specs/openid-connect-messages-1_0.html" />
<area shape="rect" coords="56,193,172,245" href="http://openid.net/specs/openid-connect-standard-1_0.html" />
<area shape="rect" coords="387,193,502,245" href="http://openid.net/specs/openid-connect-session-1_0.html" />
<area shape="rect" coords="143,339,205,376" href="http://self-issued.info/docs/draft-jones-json-web-token.html" />
<area shape="rect" coords="223,339,280,376" href="http://self-issued.info/docs/draft-jones-json-web-signature.html" />
<area shape="rect" coords="378,339,435,376" href="http://self-issued.info/docs/draft-jones-json-web-key.html" />
<area shape="rect" coords="298,339,360,376" href="http://self-issued.info/docs/draft-jones-json-web-encryption.html" />
<area shape="rect" coords="453,339,515,376" href="http://self-issued.info/docs/draft-jones-simple-web-discovery.html" />
<area shape="rect" coords="33,339,125,401" href="http://tools.ietf.org/html/draft-ietf-oauth-v2" />
<area shape="rect" coords="221,48,336,100" href="http://openid.net/specs/openid-connect-discovery-1_0.html" />
<area shape="rect" coords="387,48,502,100" href="http://openid.net/specs/openid-connect-registration-1_0.html" />
<area shape="rect" coords="56,48,172,100" href="http://openid.net/specs/openid-connect-basic-1_0.html" /> </map>
<p><img class="aligncenter size-full wp-image-7495" title="OpenID Connect Protocol Suite" src="http://openid.net/wordpress-content/uploads/2011/08/OpenIDConnect-Map-v22.png" alt="OpenID Connect Protocol Suite" width="550" height="483" usemap="#GraffleExport" /></p>
<p>The biggest difference you’ll notice is that there is now only one spec to implement for “Minimal” clients (rather than previously three).  A number of people had asked that there be a single, simple, self-contained spec that basic relying parties could implement.  That spec is the <a href="http://openid.net/specs/openid-connect-basic-1_0.html" target="_blank">OpenID Connect Basic Client Profile</a>.  That’s all you need for a web-based relying party utilizing a pre-configured set of OpenID Providers.</p>
<p>For “Dynamic” configurations, where the set of OpenID Providers is not pre-configured, <a href="http://openid.net/specs/openid-connect-discovery-1_0.html" target="_blank">Discovery</a> and <a href="http://openid.net/specs/openid-connect-registration-1_0.html" target="_blank">Dynamic Client Registration</a> capabilities are added to enable RPs to discover OP endpoints and to connect with the OP selected.  This functionality is needed for “open” OpenID Connect interactions.</p>
<p>OpenID Providers, native client applications, and clients needing more functionality than that provided by the Basic Client Profile implement the <a href="http://openid.net/specs/openid-connect-standard-1_0.html" target="_blank">OpenID Connect Standard </a>binding for the <a href="http://openid.net/specs/openid-connect-messages-1_0.html" target="_blank">OpenID Connect Messages</a>.  Finally, OPs and RPs needing session management capabilities, including logout, also implement <a href="http://openid.net/specs/openid-connect-session-1_0.html" target="_blank">OpenID Connect Session Management</a>.</p>
<p>As you can see, the current organization remains highly modular, where implementations can build and deploy only what they need.  Now that modularity is even better reflected in the way that the specs are written – particularly that there is a single, self-contained basic client specification.</p>
<p>In closing, we’d like to thank developers for the valuable feedback provided to date.  Your input has both improved the technical content of OpenID Connect, and possibly even more importantly, made the specs simpler and easier to understand.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/09/12/openid-connect-specs-incorporating-developer-feedback/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Current Map for OpenID Connect</title>
		<link>http://openid.net/2011/07/15/current-map-for-openid-connect/</link>
		<comments>http://openid.net/2011/07/15/current-map-for-openid-connect/#comments</comments>
		<pubDate>Sat, 16 Jul 2011 01:00:26 +0000</pubDate>
		<dc:creator>Nat Sakimura</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>
		<category><![CDATA[connect]]></category>
		<category><![CDATA[developer]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[spec]]></category>
		<category><![CDATA[specification]]></category>

		<guid isPermaLink="false">http://openid.net/?p=6019</guid>
		<description><![CDATA[There is now a set of functionally complete specifications for OpenID Connect.  The diagram below shows the relationships between the current specs and contains links to each of them.  These specifications are ready for early developer feedback and prototype implementation work.  Please send feedback on them to the OpenID Artifact Binding Working Group Mailing List. [...]]]></description>
			<content:encoded><![CDATA[<p>There is now a set of functionally complete specifications for OpenID Connect.  The diagram below shows the relationships between the current specs and contains links to each of them.  These specifications are ready for <em><strong>early developer feedback</strong></em> and prototype implementation work.  Please send feedback on them to the <a title="OpenID Artifact Binding Working Group Mailing List" href="http://lists.openid.net/mailman/listinfo/openid-specs-ab">OpenID Artifact Binding Working Group Mailing List</a>.</p>
<p>OpenID Connect uses the best practices of widely used OAuth/REST/JSON based APIs to define a <em><strong>standard and interoperable</strong></em> way to authenticate users.  Developers should care because rather than having to learn an new and slightly different version of essentially the same API every time they want to integrate with a different identity provider, they can just do it in a standard way using a consistent interface.  In the long run, OpenID Connect will make the web more interoperable, because it makes it easier for developers to integrate with multiple services.</p>
<p>FYI, the working group *is* <strong><em>planning to reorganize the specs</em></strong> to have the minimal set of OpenID Connect functionality be contained in a single document, although this will likely not be in place for a few weeks.  Even before that is done, we wanted to make people aware of this set of specs now so early implementation work and technical feedback can occur.  Remaining edits to the specs should consist of corrections, clarifications, and reorganization, rather than additions of significant new functionality.  For now, developers should <span style="font-weight: bold; color: #ff0000;">start with the</span> (admittedly awkwardly named) <a href="http://openid.net/specs/openid-connect-http-redirect-1_0.html">OpenID Connect HTTP Redirect Binding spec</a>.</p>
<p>Let the feedback and prototyping begin! [*1]</p>
<map name="GraffleExport">
<area shape="rect" coords="182,385,244,422" href="http://self-issued.info/docs/draft-jones-json-web-token.html" />
<area shape="rect" coords="255,385,312,422" href="http://self-issued.info/docs/draft-jones-json-web-signature.html" />
<area shape="rect" coords="395,385,462,422" href="http://self-issued.info/docs/draft-jones-json-web-key.html" />
<area shape="rect" coords="322,385,384,422" href="http://self-issued.info/docs/draft-jones-json-web-encryption.html" />
<area shape="rect" coords="470,385,532,431" href="http://self-issued.info/docs/draft-jones-simple-web-discovery.html" />
<area shape="rect" coords="72,385,164,447" href="http://tools.ietf.org/html/draft-ietf-oauth-v2" />
<area shape="rect" coords="327,60,442,112" href="http://openid.net/specs/openid-connect-discovery-1_0.html" />
<area shape="rect" coords="458,60,573,112" href="http://openid.net/specs/openid-connect-registration-1_0.html" />
<area shape="rect" coords="114,135,229,187" href="http://openid.net/specs/openid-connect-userinfo-1_0.html" />
<area shape="rect" coords="390,135,506,187" href="http://openid.net/specs/openid-connect-session-1_0.html" />
<area shape="rect" coords="180,60,296,112" href="http://openid.net/specs/openid-connect-core-1_0.html" />
<area shape="rect" coords="53,60,168,112" href="http://openid.net/specs/openid-connect-http-redirect-1_0.html" />
<area shape="rect" coords="244,243,360,295" href="http://openid.net/specs/openid-connect-framework-1_0.html" /> </map>
<p><img usemap="#GraffleExport" src="http://openid.net/wordpress-content/uploads/2011/07/OpenIDConnect-Map-13jul2011-v3.png" border="0" alt="" /></p>
<p>[*1] The easiest way to do is to join the AB list at <a href="http://lists.openid.net/mailman/listinfo/openid-specs-ab" target="_blank">http://lists.openid.net/mailman/listinfo/openid-specs-ab</a>, submit the contribution agreement from <a href="http://openid.net/intellectual-property/" target="_blank">http://openid.net/intellectual-property/</a> (which you can now do online!), and then send comments to the <a href="mailto:openid-specs-ab@lists.openid.net">openid-specs-ab@lists.openid.net</a> .</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/07/15/current-map-for-openid-connect/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OpenID Foundation Welcomes Intel as Newest Member</title>
		<link>http://openid.net/2011/05/05/openid-foundation-welcomes-intel-as-newest-member/</link>
		<comments>http://openid.net/2011/05/05/openid-foundation-welcomes-intel-as-newest-member/#comments</comments>
		<pubDate>Thu, 05 May 2011 19:10:20 +0000</pubDate>
		<dc:creator>jfe</dc:creator>
				<category><![CDATA[Press Releases]]></category>

		<guid isPermaLink="false">http://openid.net/?p=5749</guid>
		<description><![CDATA[The OpenID Foundation (OIDF), the open standard community dedicated to driving the development and broad adoption of OpenID technology, today announced that the Intel Application Security and Identity Products Group has joined the Foundation. By joining the OIDF, Intel is demonstrating their support for OpenID as a solution of choice for Internet digital identity. Intel [...]]]></description>
			<content:encoded><![CDATA[<p>The OpenID Foundation (OIDF), the open standard community dedicated to driving the development and broad adoption of OpenID technology, today announced that the Intel Application Security and Identity Products Group has joined the Foundation.  By joining the OIDF, Intel is demonstrating their support for OpenID as a solution of choice for Internet digital identity. </p>
<p>Intel joins a diverse set of industry leaders including Google, Facebook, Yahoo, Microsoft, PayPal, Symantec, and Ping Identity, reflecting the growing support for OIDF’s open standards approach to digital identity. The broadening influence and impact of OpenID is demonstrated by the active engagement of these organizations and in the markets where they operate and illustrates the importance of identity solutions like OpenID across a wide ranging set of needs and use cases.</p>
<p>OIDF members are dedicated to accelerating open options for securely managing digital identities and are committed to extending the functionality of Internet single sign-on across a growing number of critical corporate and consumer communication channels.  </p>
<p>“As a market leader Intel understands the importance of an open standard approach to digital identity” said Don Thibeau, executive director of the OpenID Foundation. “We are excited to have the opportunity to share in the unique expertise and the key market insights they bring to the Foundation.” </p>
<p>“Seamless interoperability between the Enterprise, their partners, and cloud service provider platforms starts with safe, secure, federated identity exchange,” said Girish Juneja, director, Application Security and Identity Products at Intel . “OpenID is focused on solving the identity interoperability challenge by delivering a simplified access protocol. Intel is actively engaged to further develop this standard and our Intel® Expressway Cloud Access 360 Single Sign-on product helps scale &#038; manage OpenID deployments. </p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/05/05/openid-foundation-welcomes-intel-as-newest-member/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Identity System Said Readied by Obama</title>
		<link>http://openid.net/2011/01/08/internet-identity-system-said-readied-by-obama/</link>
		<comments>http://openid.net/2011/01/08/internet-identity-system-said-readied-by-obama/#comments</comments>
		<pubDate>Sun, 09 Jan 2011 01:41:41 +0000</pubDate>
		<dc:creator>Amanda Richardson</dc:creator>
				<category><![CDATA[government]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://openid.net/?p=4501</guid>
		<description><![CDATA[Internet Identity System Said Readied by Obama Administration 2011-01-07 05:00:01.9 GMT By James Sterngold Jan. 7 (Bloomberg) &#8212; The Obama administration plans to announce today plans for an Internet identity system that will limit fraud and streamline online transactions, leading to a surge in Web commerce, officials said. While the White House has spearheaded development [...]]]></description>
			<content:encoded><![CDATA[<p>Internet Identity System Said Readied by Obama Administration<br />
2011-01-07 05:00:01.9 GMT</p>
<p><em style="font-weight: normal;">By James Sterngold</em></p>
<p>Jan. 7 (Bloomberg) &#8212; The Obama administration plans to<br />
announce today plans for an Internet identity system that will<br />
limit fraud and streamline online transactions, leading to a<br />
surge in Web commerce, officials said.</p>
<p>While the White House has spearheaded development of the<br />
framework for secure online identities, the system led by the<br />
U.S. Commerce Department will be voluntary and maintained by<br />
private companies, said the officials, who spoke on condition of<br />
anonymity ahead of the announcement.</p>
<p>A group representing companies including Verizon<br />
Communications Inc., Google Inc., PayPal Inc., Symantec Corp.<br />
and AT&amp;T Inc. has supported the program, called the National<br />
Strategy for Trusted Identities in Cyberspace, or NSTIC.<br />
“This is going to cause a huge shift in consumer use of<br />
the Internet,” said John Clippinger, co-director of the Law Lab<br />
at Harvard’s Berkman Center for Internet and Society in<br />
Cambridge, Massachusetts. “There’s going to be a huge bump and<br />
a huge increase in the amount and kind of data retailers are<br />
going to have.”</p>
<p>Most companies have separate systems for signing on to e-<br />
mail accounts or conducting secure online transactions,<br />
requiring that users memorize multiple passwords and repeat<br />
steps. Under the new program, consumers would sign in just once<br />
and be able to move among other websites, eliminating the<br />
inconvenience that causes consumers to drop many transactions.</p>
<p>Fewer Passwords</p>
<p>For example, once the system is in place, Google would be<br />
able to join a trusted framework that has adopted the rules and<br />
guidelines established by the Commerce Department. From that<br />
point, someone who logged into a Google e-mail account would be<br />
able to conduct other business including banking or shopping<br />
with other members of the group without having to provide<br />
additional information or verification.</p>
<p>Bruce McConnell, a senior counselor for national protection<br />
at the Department of Homeland Security, said NSTIC may lead to a<br />
big reduction in the size of Internet help desks, which spend<br />
much of their time assisting users who have forgotten their<br />
passwords. Because the systems would be more secure, he said, it<br />
may also result in many transactions that are now done on paper,<br />
from pharmaceutical to real estate purchases, to be done online<br />
faster and cheaper.</p>
<p>A draft paper outlining NSTIC was released for comment by<br />
the White House in June.</p>
<p>‘Who Do You Trust?’</p>
<p>“NSTIC could go a long way toward advancing one of the<br />
fundamental challenges of the Internet today, which is &#8212; Who do<br />
you trust?” said Don Thibeau, chairman of the Open Identity<br />
Exchange, an industry group based in San Ramon, California,<br />
representing companies that support development of the new<br />
framework.</p>
<p>“What is holding back the growth of e-commerce is not<br />
technology, it’s policy. This gives us the rules, the policies<br />
that we need to really move forward.”</p>
<p>The new system will probably hasten the death of<br />
traditional passwords, Clippinger said. Instead, users may rely<br />
on devices such as smartcards with embedded chips, tokens that<br />
generate random codes or biometric devices.</p>
<p>“Passwords will disappear,” said Clippinger. “They’re<br />
buggy whips. The old privacy and security conventions don’t<br />
work. You need a new architecture.”</p>
<p>Secure, Efficient</p>
<p>Development of a more advanced security system began in<br />
August 2004, when President George W. Bush issued a Homeland<br />
Security Presidential Directive that required all federal<br />
employees be given smartcards with multiple uses, such as<br />
gaining access to buildings, signing on to government websites<br />
and insuring that only people with proper clearances would have<br />
access to restricted documents. The system was intended to be<br />
more secure and more efficient.</p>
<p>The Obama administration advanced the process when it<br />
issued its “Cyberspace Policy Review” in 2009. One of the 10<br />
priorities was the security identification system.<br />
The federal government is facilitating what it calls a<br />
“foundational” system in two ways. It is developing the<br />
framework for the identification plan, and it will make a large<br />
number of government agencies, services and products available<br />
through the secure system, from tax returns to reserving<br />
campsites at national parks.</p>
<p>“Innovation is one of the key aspects here,” said Ari<br />
Schwartz, a senior adviser for Internet policy at the Department<br />
of Commerce. “There’s so much that could be done if we could<br />
trust transactions more.”</p>
<p>Schwartz said use of the system, once companies voluntarily<br />
choose to participate, may spur a range of efficiencies and e-<br />
commerce similar to the way ATM machines transformed banking,<br />
opening the way to a growing number of services little by<br />
little.</p>
<p>Privacy Concerns</p>
<p>Civil libertarians have expressed concern that the system<br />
may not protect privacy as well as the government is promising.<br />
“If the concept were implemented in a perfect way it would<br />
be very good,” said Jay Stanley, a senior policy analyst for<br />
privacy and technology at the New York-based American Civil<br />
Liberties Union. “It’s a convenience. But having a single point<br />
of failure may not be good for protecting privacy. The devil’s<br />
really in the details.” He said the ACLU would “vehemently<br />
oppose” anything that resembled a national ID card.</p>
<p>Aaron Brauer-Rieke, a fellow at the Center for Democracy &amp;<br />
Technology in Washington, a civil liberties group, said it was<br />
important that the system would be operated by private<br />
companies, not the government. He said he was concerned about<br />
how the data on consumer online transactions would be used.<br />
“New identity systems will allow moving from one site to<br />
another with less friction and open up data flows, but might<br />
also enable new kinds of targeted advertising,” he said. “We<br />
have to make sure privacy doesn’t get lost in this.”</p>
<p>Schwartz and McConnell said the new system wouldn’t be a<br />
national identity card and that companies, not the government,<br />
would manage the data being passed online.<br />
“There will not be a single data base for this<br />
information,” McConnell said.</p>
<p>For Related News and Information:<br />
Internet shopping stories: TNI INTERNET RET &lt;GO&gt;<br />
Top retail stories: RTOP &lt;GO&gt;<br />
Top government stories: GTOP &lt;GO&gt;</p>
<p>&#8211;Editors: Elizabeth Wollman, Joe Winski</p>
<p>To contact the reporter on this story:<br />
James Sterngold in New York at +1-212-617-4946 or<br />
<a href="mailto:jsterngold2@bloomberg.net" target="_blank">jsterngold2@bloomberg.net</a></p>
<p>To contact the editor responsible for this story:<br />
David Scheer at +1-212-617-2358 or <a href="mailto:dscheer@bloomberg.net" target="_blank">dscheer@bloomberg.net</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/01/08/internet-identity-system-said-readied-by-obama/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
		<item>
		<title>OpenID Foundation Retail Summit</title>
		<link>http://openid.net/2010/10/20/openid-retail-summit/</link>
		<comments>http://openid.net/2010/10/20/openid-retail-summit/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 22:14:36 +0000</pubDate>
		<dc:creator>Amanda Richardson</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[retail]]></category>
		<category><![CDATA[retail advisory committee]]></category>

		<guid isPermaLink="false">http://openid.net/?p=3523</guid>
		<description><![CDATA[by Brian Kissel In Q1 of 2011 PayPal, the OpenID Foundation and Janrain will be facilitating the OpenID Retail Summit hosted by PayPal in Silicon Valley. We are also in discussions with the National Retail Foundation (NRF) about their possible participation. The meeting date is tentatively being scheduled around the NRF Innovate 2011 Conference in San Francisco March [...]]]></description>
			<content:encoded><![CDATA[<p>by <a href="http://www.linkedin.com/in/briankkissel">Brian Kissel</a></p>
<p>In Q1 of 2011 PayPal, the OpenID Foundation and Janrain will be facilitating the OpenID Retail Summit hosted by PayPal in Silicon Valley. We are also in discussions with the <a href="http://www.nrf.com/" target="_blank">National Retail Foundation</a> (NRF) about their possible participation. The meeting date is tentatively being scheduled around the <a href="http://events.nrf.com/innovate11/public/MainHall.aspx?ID=8138" target="_blank">NRF Innovate 2011 Conference</a> in San Francisco March 8<sup>th</sup>-10<sup>th</sup>.</p>
<p>Over the last few years, many industries and market segments have been embracing social sign-on and publishing solutions to increase customer engagement through online channels.  Open standard technologies including OpenID, OAuth, Portable Contacts, Activity Streams, and OpenSocial are enabling organizations to better serve their customers and members while increasing the return on investment (ROI) of their online initiatives.</p>
<p>One market segment which is demonstrating accelerated adoption are online retailers. For example, earlier this year <a href="http://www.janrain.com/blogs/sears-openid-ux-summit-retrospective">Sears hosted an OpenID Summit</a> at their headquarters in Chicago.  In order to serve this segment better, the OpenID Foundation has established a Retail Advisory Committee (RAC).  More information about the RAC can be found at</p>
<ul>
<li><a href="http://www.slideshare.net/bkkissel/openid-foundation-retail-advisory-committee-overview-5193852" target="_blank">Slideshare PowerPoint Overview</a></li>
<li><a href="http://wiki.openid.net/OpenID-Retail-Advisory-Committee" target="_blank">OpenID Foundation Wiki</a></li>
<li><a href="http://tech.groups.yahoo.com/group/openid_RAC/" target="_blank">Retail Advisory Committee Yahoo Group</a></li>
</ul>
<p>Prior to the Q1 OpenID Retail Summit, there are two planning sessions where retailers can participate in the development of the agenda for the event.</p>
<ul>
<li><a href="http://www.janrain.com/blogs/social-commerce-and-paypal-innovate-2010-conference">PayPal Innovate 2010 Conference</a> – San Francisco, Oct 26<sup>th</sup>-27th.  We will be having a planning session on Oct 26<sup>th </sup>at this event.  Anyone can sign up and get a $100 discount for the event.</li>
<li><a href="http://www.internetidentityworkshop.com/iiwxi-11-in-mountain-view/">Internet Identity Workshop</a> – Mountain View, CA Nov 2<sup>nd</sup>-4<sup>th.</sup> There will be several sessions here on leveraging social sign-on and publishing, the underlying technologies (OpenID, OAuth, Portable Contacts, Activity Streams, OpenSocial, etc.), benefits for retailers and their customers, and another opportunity to contribute to the agenda for the Retail Summit at PayPal.  There will be representatives attending from Facebook, Twitter, Google, Yahoo, AOL, MySpace, Microsoft, LinkedIn, Verisign, PayPal and many other identity and social networking providers.</li>
</ul>
<p>We hope you will consider participating in either or both of the planning events and also attending the Retail Summit at PayPal in Q1 of next year.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2010/10/20/openid-retail-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

