<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenID</title>
	<atom:link href="http://openid.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://openid.net</link>
	<description>Home of the OpenID community</description>
	<lastBuildDate>Tue, 31 Jan 2012 01:01:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<atom:link rel='hub' href='http://openid.net/?pushpress=hub'/>
		<item>
		<title>OpenID Connect in a Nutshell</title>
		<link>http://openid.net/2012/01/24/openid-connect-in-a-nutshell/</link>
		<comments>http://openid.net/2012/01/24/openid-connect-in-a-nutshell/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 06:29:37 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9722</guid>
		<description><![CDATA[Nat Sakimura has written a valuable post describing OpenID Connect in a nutshell. It shows by example how simple it is for relying parties to use basic OpenID Connect functionality. If you’re involved in OpenID Connect in any way, or are considering becoming involved, his post is well worth reading.]]></description>
			<content:encoded><![CDATA[<p><a href="http://nat.sakimura.org/">Nat Sakimura</a> has written a valuable post describing <a href="http://nat.sakimura.org/2012/01/20/openid-connect-nutshell/">OpenID Connect in a nutshell</a>. It shows by example how simple it is for relying parties to use basic <a href="http://openid.net/connect/">OpenID Connect</a> functionality. If you’re involved in OpenID Connect in any way, or are considering becoming involved, his post is well worth reading.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2012/01/24/openid-connect-in-a-nutshell/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OpenID Foundation 2012 Community Board Member Election</title>
		<link>http://openid.net/2012/01/03/openid-foundation-2012-community-board-member-election/</link>
		<comments>http://openid.net/2012/01/03/openid-foundation-2012-community-board-member-election/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 17:36:20 +0000</pubDate>
		<dc:creator>jfe</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[board election]]></category>
		<category><![CDATA[vote]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9452</guid>
		<description><![CDATA[This is to announce the 2012 election of OpenID Foundation community board members. The Foundation plays an important role in the evolution of Internet identity technologies. Those elected will help determine what role the OIDF should play in helping facilitate faster and broader adoption of open standard identity systems. Last year four community board members [...]]]></description>
			<content:encoded><![CDATA[<p>This is to announce the 2012 election of OpenID Foundation community board members. The Foundation plays an important role in the evolution of Internet identity technologies. Those elected will help determine what role the OIDF should play in helping facilitate faster and broader adoption of open standard identity systems.</p>
<p>Last year four community board members were elected to 2-year terms and so are not standing for election:<br />
•	Nat Sakimura<br />
•	Mike Jones<br />
•	John Bradley<br />
•	Kick Willemse</p>
<p>Other current community board members may seek re-election. They are:<br />
•	Allen Tom<br />
•	Axel Nennker<br />
•	Chris Messina</p>
<p>Brian Kissel has indicated he will likely not be a candidate.  This is a good time to thank Brian, and all the current board members, for their time, attention and leadership over the last year.  </p>
<p>For the purposes of the 2012 election, there are 5 confirmed sustaining members: Google, Microsoft, PayPal, Ping Identity, and Symantec.  Thus, we will be electing 2 community members to the Board of Directors for 2-year terms.  In order to be eligible for election, your candidacy must have been seconded by at least three other members. </p>
<p>The election will be conducted on the following schedule:<br />
Nominations open:  Monday, January 9<br />
Nominations close:  Monday, January 23<br />
Election begins:  Wednesday, January 25<br />
Election ends: Wednesday, February 8<br />
Results announced by: Wednesday, February 15<br />
New board terms start: Thursday, March 1</p>
<p>Times for all dates are Noon, U.S. Pacific Time.</p>
<p>All members of the OpenID Foundation are eligible to nominate themselves, second the nominations of others who self-nominated, and vote for candidates.  If you’re not already a member of the OpenID Foundation, we encourage you to join now at <a href="https://openid.net/foundation/members/registration">https://openid.net/foundation/members/registration</a>. </p>
<p>Voting and nominations are conducted using the OpenID you registered when you joined the Foundation.  Log in at <a href="https://openid.net/foundation/members/">https://openid.net/foundation/members/</a> with your OpenID to participate in the nomination and voting. If you are already a member, you will receive an email advising you the election is open and how to participate. If you experience problems participating in the election or joining the foundation, please send an email to help@oidf.org.  </p>
<p>Board participation requires a substantial ongoing investment of time and energy.  It is a volunteer effort that should not be undertaken lightly. Should you be elected, expect to be called upon to serve both on the board and on its committees where the work of the foundation is conducted.  If you’re committed to OpenID and advancing open digital identity and are a person who works well with others, we encourage your candidacy.  The OIDF’s Executive Committee has suggested a few questions candidates may want to publicly address in their candidate statements:</p>
<p>1.	What is you view of the opportunity of the OpenID Foundation?<br />
2.	What are the key opportunities you see for the OpenID Foundation in 2012?<br />
3.	How will you demonstrate your commitment to the work of the foundation in terms of resources, focus and leadership?<br />
4.	What would you like to see accomplished over the next year, and how do you personally plan to make these things happen?<br />
5.	What resources can you bring to the foundation to help the foundation attain its goals?<br />
6.	What current or past experiences, skills, or interests will inform your contributions and views?</p>
<p>Candidates can address these questions in their election statements on various community mailing lists and at http://openid.net – especially openid-general@lists.openid.net, and via blog@oidf.org. Please forward questions, comments and suggestions to me.</p>
<p>Don Thibeau<br />
Executive Director<br />
The OpenID Foundation</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2012/01/03/openid-foundation-2012-community-board-member-election/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Review of Proposed OpenID Connect Implementer’s Drafts</title>
		<link>http://openid.net/2011/12/23/review-of-proposed-openid-connect-implementer%e2%80%99s-drafts/</link>
		<comments>http://openid.net/2011/12/23/review-of-proposed-openid-connect-implementer%e2%80%99s-drafts/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 14:41:12 +0000</pubDate>
		<dc:creator>John Bradley</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>
		<category><![CDATA[Implementer's Draft]]></category>
		<category><![CDATA[OpenID Connect]]></category>
		<category><![CDATA[spec]]></category>
		<category><![CDATA[specification]]></category>
		<category><![CDATA[vote]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9248</guid>
		<description><![CDATA[The OpenID AB+Connect Working Group recommends approval of the following specifications as OpenID Implementer’s Drafts: Basic Client Profile – Simple self-contained specification for a web-based Relying Party.  (This spec contains a subset of the information in Messages and Standard.) Discovery – Defines how user and provider endpoints can be dynamically discovered. Dynamic Registration – Defines [...]]]></description>
			<content:encoded><![CDATA[<p>The OpenID AB+Connect Working Group recommends approval of the following specifications as OpenID Implementer’s Drafts:</p>
<ul>
<li>Basic Client Profile – Simple self-contained specification for a web-based Relying Party.  (This spec contains a subset of the information in Messages and Standard.)</li>
<li>Discovery – Defines how user and provider endpoints can be dynamically discovered.</li>
<li>Dynamic Registration – Defines how clients can dynamically register with OpenID Providers.</li>
<li>Messages – Defines all the messages that are used in OpenID Connect.  (These messages are used by the Standard binding.)</li>
<li>Standard – Complete HTTP binding of the Messages, for both Relying Parties and OpenID Providers.</li>
<li>Multiple Response Type Encoding – Registers OAuth 2.0 response_type values used by OpenID Connect.</li>
</ul>
<p>An Implementer’s Draft is a stable version of a specification providing intellectual property protections to implementers of the specification.  This note starts the 45 days public review period for the specification drafts in accordance with the OpenID Foundation IPR policies and procedures.  This review period will end on Monday, February 6, 2012.</p>
<p>Unless issues are identified during the review that the working group believes must be addressed by revising the drafts, this review period will be followed by a seven day voting period during which OpenID Foundation members will vote on whether to approve these drafts as OpenID Implementer’s Drafts.</p>
<p>The specifications are posted at these locations:</p>
<ul>
<li><a href="http://openid.net/specs/openid-connect-basic-1_0-15.html">http://openid.net/specs/openid-connect-basic-1_0-15.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-discovery-1_0-07.html">http://openid.net/specs/openid-connect-discovery-1_0-07.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-registration-1_0-08.html">http://openid.net/specs/openid-connect-registration-1_0-08.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-messages-1_0-07.html">http://openid.net/specs/openid-connect-messages-1_0-07.html</a></li>
<li><a href="http://openid.net/specs/openid-connect-standard-1_0-07.html">http://openid.net/specs/openid-connect-standard-1_0-07.html</a></li>
<li><a href="http://openid.net/specs/oauth-v2-multiple-response-types-1_0-03.html">http://openid.net/specs/oauth-v2-multiple-response-types-1_0-03.html</a></li>
</ul>
<p>A description of OpenID Connect can be found at <a href="http://openid.net/connect/">http://openid.net/connect/</a>. The working group page is <a href="http://openid.net/wg/connect/">http://openid.net/wg/connect/</a>.</p>
<p>Information on joining the OpenID Foundation can be found at <a href="https://openid.net/foundation/members/registration">https://openid.net/foundation/members/registration</a>.  Foundation members will be asked to vote on approving these specifications as Implementer’s Drafts.</p>
<p>You can send feedback on the specifications in a way that enables the working group to act on your feedback by</p>
<ol>
<li>signing the contribution agreement at <a href="http://openid.net/intellectual-property/">http://openid.net/intellectual-property/</a> to join the AB+Connect working group,</li>
<li>joining the working group mailing list at <a href="http://lists.openid.net/mailman/listinfo/openid-specs-ab">http://lists.openid.net/mailman/listinfo/openid-specs-ab</a>, and</li>
<li>sending your feedback on that list.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/12/23/review-of-proposed-openid-connect-implementer%e2%80%99s-drafts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon, Building the Foundation for a Safe, Security Identity Ecosystem</title>
		<link>http://openid.net/2011/12/07/verizon-building-the-foundation-for-a-safe-security-identity-ecosystem/</link>
		<comments>http://openid.net/2011/12/07/verizon-building-the-foundation-for-a-safe-security-identity-ecosystem/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 22:37:13 +0000</pubDate>
		<dc:creator>Don Thibeau</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://openid.net/?p=9194</guid>
		<description><![CDATA[Verizon announced today an important milestone in the Open Identity arena. Verizon announced that it is the first ever identity provider to achieve a Level 3 US Government certification in providing identity credentials and access management to relying parties. The importance of building a standardized framework that protects valuable personal data from Internet security risks [...]]]></description>
			<content:encoded><![CDATA[<p>Verizon announced today an important milestone in the Open Identity arena.</p>
<p>Verizon announced that it is the first ever identity provider to achieve a Level 3 US Government certification in providing identity credentials and access management to relying parties. The importance of building a standardized framework that protects valuable personal data from Internet security risks is being recognized and addressed on a global scale and national level. </p>
<p>Verizon has established itself as a leader that is building a foundation for an open and secure Internet-identity ecosystem that people and business can trust. Beyond providing a safeguard for digital identities, certified identity providers will help speed conversations, interactions and transactions for people, businesses and relying parties now and in the future.</p>
<p>As one of the pioneers in building the trust frameworks, Verizon’s leadership as an identity provider is at the heart of building this new identity ecosystem. Verizon was one of the founding members of the Open Identity Exchange (OIX) an organization that now includes the leaders in internet, telco and data aggregation industries.</p>
<p>Today’s password-focused website login process is unsafe and risky and has led to personal information and data being compromised through phishing and hacking attacks on weak systems. The potentially devastating consequences associated with the hijacking and theft of digital identities highlights the need for a trusted and certified framework that relying parties can depend on for identity authentication.</p>
<p>OIX, its member companies and Verizon aim to provide an open framework that standardizes the security, privacy, and operation policies of identity service providers that people, businesses and governments can trust.</p>
<p>The Internet identity ecosystem is quickly evolving with companies playing many different roles. The OIX is focused on the roles of attribute providers, identity providers, and relying parties. Verizon is playing an important role as a leader and advocate for OpenID. We congratulate Verizon on this significant achievement. </p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/12/07/verizon-building-the-foundation-for-a-safe-security-identity-ecosystem/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PayPal Access Uses OpenID 2.0</title>
		<link>http://openid.net/2011/10/19/paypal-access-uses-openid-2-0/</link>
		<comments>http://openid.net/2011/10/19/paypal-access-uses-openid-2-0/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 17:57:19 +0000</pubDate>
		<dc:creator>jfe</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://openid.net/?p=8275</guid>
		<description><![CDATA[PayPal Access provides a way for users to log into your web site using interfaces based on the OpenID 2.0 protocol, an open specification produced by the OpenID community. More information View a video replay of a recent PayPal Access presentation]]></description>
			<content:encoded><![CDATA[<p>PayPal Access provides a way for users to log into your web site using interfaces based on the OpenID 2.0 protocol, an open specification produced by the OpenID community. </p>
<p><a href="https://www.x.com/developers/x.commerce/documentation-tools/quick-start-guides/standard-openid-integration-paypal">More information</a></p>
<p><a href="https://www.youtube.com/embed/eAGLpx6k340?html5=1">View a video replay of a recent PayPal Access presentation</a></p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/10/19/paypal-access-uses-openid-2-0/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>October is National Cybersecurity Month</title>
		<link>http://openid.net/2011/10/17/october-is-national-cybersecurity-month/</link>
		<comments>http://openid.net/2011/10/17/october-is-national-cybersecurity-month/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 20:05:05 +0000</pubDate>
		<dc:creator>jfe</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://openid.net/?p=8227</guid>
		<description><![CDATA[October is National Cybersecurity month so a shout out goes to our colleagues at The National Cyber Security Alliance NCSA&#8217;s mission is to educate and therefore empower a digital society to use the Internet safely and securely at home, work, and school, protecting the technology individuals use, the networks they connect to, and our shared [...]]]></description>
			<content:encoded><![CDATA[<p><strong>October is National Cybersecurity month</strong> so a shout out goes to our colleagues at The National Cyber Security Alliance NCSA&#8217;s mission is to educate and therefore empower a digital society to use the Internet safely and securely at home, work, and school, protecting the technology individuals use, the networks they connect to, and our shared digital assets. NCSA builds strong public/private partnerships to create and implement broad reaching education and awareness efforts to empower users at home, work and school with the information they need to keep themselves, their organizations, their systems, and their sensitive information safe and secure online and encourage a culture of cybersecurity.</p>
<p><strong>OASIS launched the Electronic Identity Credential Trust Elevation Methods (Trust Elevation) Technical Committee</strong> <a href=" http://www.oasis-open.org/committees/trust-el/charter.php"> http://www.oasis-open.org/committees/trust-el/charter.php</a>. The initial deliverable is a comprehensive list of current methods to authenticate identities online to the degree necessary for high value and sensitive transactions. This is expected to be a key input to new real world solutions that use a step-up approach to multi-factor authentication. The Technical Committee is Co Chaired by Abbie Barbir, Senior Vice President Bank of America and Don Thibeau of OIX and OpenID Foundation.</p>
<p><strong>OIX Member AT&#038;T has come out with Personal Levels of Assurance (PLOA)</strong>, a white paper that introduces a new approach for determining transaction-based assurance.PLOA White Paper – v1. This fresh new thinking focuses on determining the lifecycle of LOA settings for an individual based on the current condition of all attribute declarations whether they are validated or not.  One of the most significant suggestions in At&#038;t&#8217;s approach to federated assurance is de-coupling enforcement points from decision points by adoption of a standard, open protocol.  This is the kind of open identity protocol organizations like the OpenID Foundation consider as part of its mission.  Even though the technology being implemented may resemble authorization, it is truly speaking to the assurance of the authentication and therefore should be considered a new element to the three A’s.The At&#038;t team postulates that there should be a fourth A added to the typical security list of AAA – Authentication, Authorization, and Audit (AAA) shall be joined by their new sibling Assurance.  OIX provides legal and best practices research in online identity particularly in the area of trust frameworks. </p>
<p>Content and contributors to work like this will be featured at <strong>the Open Identity Exchange Attribute Summit</strong> upcoming meetings in Washington DC on November 9 and 10OIX, Booz Allen Hamilton and Experian to present a panel noting OIX&#8217;s growing interaction with EU and UK initiatives like those in the UK Government Cabinet Office, iScheme, federatedbusiness.org,   The OIX board will take up the question of how best to engage with tScheme in the UK and discuss the value of  a ‘formal partnership’. tScheme was formed over ten years ago as an industry body but with UK Government observers on its board, which gave rise to the term co-regulatory body that is used when describing tScheme’s function.  The Government observers  are Cabinet Office, Business Information and Skills, department of Work and Pensions and the department for Education.  tScheme has thus a long history working with and supporting the UK Government, hence is heavily involved in the current Cabinet Office Identity Assurance Program, as well as the role as the UK’s assurance regime for the Oil &#038; Gas Trust Scheme; the Employee Authentication Scheme for access to Government data by local Authority employees; and the Identity &#038; Access Management program supporting the access to databases relating to Police Intelligence by members of UK Police Forces.  </p>
<p>We are entering the implementation phase for one of the most mature and value adding initiatives the <strong>Publish Trust Framework</strong> in the Open Identity Exchange.  We have posted the project update at <a href="http://www.PublishTrust.org">www.PublishTrust.org</a> for your review.The Publish Trust Project examines the feasibility of adding trust values to online identities for authors of scholarly publications, thus enabling them to reliably aggregate previous and current works and connect with other experts in their field. The first experiment uses VIVO as a semantic identity platform with the OIX Trust Framework to produce two-factor assertions of authorship from scholarly publishers of peer-reviewed works and authors.</p>
<p>The OpenID Foundation and the Open Identity Exchange are sponsoring an <strong>Open Identity Summit in Tokyo Japan</strong> on December 1.  The event is taking place as part of Japan&#8217;s Internet week and will feature technical discussions about OpenID Connect and Account Chooser as well as policy and rule making in Japan&#8217;s identity ecosystem.  The Japanese and South Korean government has initiatives underway similar to the US NSTIC. Please note Howard Schmidt comments at </p>
<p>Advancing the National Strategy for Trusted Identities in &#8230;<br />
The White House<br />
The solution proposed by NSTIC is a user-centric “Identity Ecosystem” built on the foundation of private-sector identity providers.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/10/17/october-is-national-cybersecurity-month/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Events for website owners who want to get out of the password business</title>
		<link>http://openid.net/2011/10/17/events-for-website-owners-who-want-to-get-out-of-the-password-business/</link>
		<comments>http://openid.net/2011/10/17/events-for-website-owners-who-want-to-get-out-of-the-password-business/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 20:02:29 +0000</pubDate>
		<dc:creator>jfe</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://openid.net/?p=8209</guid>
		<description><![CDATA[The recent Sony incident was another wake up call for website owners about the problems with passwords as discussed in the recent OIDF blog post. One of the purposes of the OpenID Foundation blog is to help identify events that website owners can attend to learn more about alternatives to passwords. There was one such [...]]]></description>
			<content:encoded><![CDATA[<p>The recent Sony incident was another wake up call for website owners about the problems with passwords as discussed in the recent <a href="http://openid.net/2011/10/13/sony%E2%80%99s-weakest-link-hijack/">OIDF blog post</a>.  One of the purposes of the OpenID Foundation blog is to help identify events that website owners can attend to learn more about alternatives to passwords.</p>
<p>There was one such event, called the Cloud Identity Summit, earlier this year that was so popular that a smaller version of the event is being run in four cities in the next few weeks.<br />
 • 10/24/11 New York, NY<br />
 • 10/25/11 Washington, DC<br />
 • 11/2/11 Chicago, IL<br />
 • 11/3/11 San Francisco, CA</p>
<p>You can learn more or register to attend at <a href="http://www.cloudidentitysummit.com/">www.cloudidentitysummit.com</a></p>
<p>The event will cover a number of topics that the OpenID Foundation is involved with including:<br />
 • Emerging standards such as <a href="http://openid.net/connect/">OpenID Connect</a> and its relation to OAuth<br />
 • User friendly ways to eliminate passwords using the <a href="http://accountchooser.com/">Account Chooser</a> technique<br />
 • Adoption of cloud identity standards in enterprise and citizen-government scenarios</p>
<p>If you&#8217;re a security architect, IT manager, SaaS product manager, eBusiness leader, CSO, CTO, or CIO leveraging the Cloud to change your business, it&#8217;s a day of identity security best practices you don&#8217;t want to miss.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/10/17/events-for-website-owners-who-want-to-get-out-of-the-password-business/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Sony’s Weakest Link Hijack</title>
		<link>http://openid.net/2011/10/13/sony%e2%80%99s-weakest-link-hijack/</link>
		<comments>http://openid.net/2011/10/13/sony%e2%80%99s-weakest-link-hijack/#comments</comments>
		<pubDate>Thu, 13 Oct 2011 17:03:10 +0000</pubDate>
		<dc:creator>Don Thibeau</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://openid.net/?p=7927</guid>
		<description><![CDATA[Sony announced today that a large number of accounts were hijacked using an attack based on the fact that people reuse passwords across websites. These “weakest link hijackings” are an evolution of the phishing attacks that have become so well known over the last few years. These attacks are referred to as “weakest link hijackings” [...]]]></description>
			<content:encoded><![CDATA[<p>Sony announced today that a large number of accounts were hijacked using an attack based on the fact that people reuse passwords across websites. These “weakest link hijackings” are an evolution of the phishing attacks that have become so well known over the last few years.</p>
<p>These attacks are referred to as “weakest link hijackings” because the hackers attack websites with the weakest security, and then collect user passwords. Since it is common for users to reuse passwords across websites, hackers can then try those collected passwords against other websites like Sony as well as social network accounts, email accounts, work accounts, etc. When hackers take over the user’s social network or email account, they frequently change the user&#8217;s password on the account to lock the real user out, then use it to try to trick the user&#8217;s friends into sending money. One scam claims the person was stuck while travelling and needs money wired to them. Imagine losing access to all your contacts, email, photos, etc. and then having your friends lose thousands of dollars.</p>
<p>Unfortunately it is extremely difficult for websites to protect themselves against the weaker security of these other websites. Only some of the largest websites with the most sophisticated security tools can detect these types of attacks and try to automatically reduce their impact on their own accounts as Sony has done. Some of those websites offer users the option to add an additional layer of security to their account, for example by sending a code to their phone number each time they want to login. However if every website took that approach, users would revolt because of the pain it would create for them.</p>
<p>It&#8217;s time for website owners to wake up and realize they are probably the “weakest link.” Most websites need to stop trying to run their own login system and instead rely on third-party tools and websites that provide users with highly secure login systems. This type of login approach has become popular with websites that want to integrate with social networks, but it can also be used by any website by simply letting users choose an identity provider that runs a secure login system. It also has the advantage of making it easier for users to register for a new website on a mobile device and we all know what a hassle that can be.</p>
<p>Consortiums of companies such as the OpenID Foundation are working together to solve the problem of passwords and weak login systems, and are making great strides on security, usability, and privacy. With so much of our digital identities and information at stake, it’s critical that we create a better, more secure system before we see more victims of the “weakest link”.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/10/13/sony%e2%80%99s-weakest-link-hijack/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>OpenID Connect Specs Incorporating Developer Feedback</title>
		<link>http://openid.net/2011/09/12/openid-connect-specs-incorporating-developer-feedback/</link>
		<comments>http://openid.net/2011/09/12/openid-connect-specs-incorporating-developer-feedback/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 18:50:41 +0000</pubDate>
		<dc:creator>Nat Sakimura</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>
		<category><![CDATA[Summit Events]]></category>
		<category><![CDATA[connect]]></category>
		<category><![CDATA[interop]]></category>
		<category><![CDATA[spec]]></category>
		<category><![CDATA[specification]]></category>

		<guid isPermaLink="false">http://openid.net/?p=7513</guid>
		<description><![CDATA[Since we posted in July about the availability of preliminary OpenID Connect specifications, developers have been building implementations and submitting feedback on the specs.  The specs have been revised to incorporate their feedback.  A new map of the specs is as follows: The biggest difference you’ll notice is that there is now only one spec to implement for “Minimal” [...]]]></description>
			<content:encoded><![CDATA[<p>Since we <a href="http://openid.net/2011/07/15/current-map-for-openid-connect/" target="_blank">posted in July</a> about the availability of preliminary <a href="http://openid.net/connect/" target="_blank">OpenID Connect</a> specifications, developers have been building implementations and submitting feedback on the specs.  The specs have been revised to incorporate their feedback.  A new map of the specs is as follows:</p>
<map name="GraffleExport">
<area shape="rect" coords="221,193,336,245" href="http://openid.net/specs/openid-connect-messages-1_0.html" />
<area shape="rect" coords="56,193,172,245" href="http://openid.net/specs/openid-connect-standard-1_0.html" />
<area shape="rect" coords="387,193,502,245" href="http://openid.net/specs/openid-connect-session-1_0.html" />
<area shape="rect" coords="143,339,205,376" href="http://self-issued.info/docs/draft-jones-json-web-token.html" />
<area shape="rect" coords="223,339,280,376" href="http://self-issued.info/docs/draft-jones-json-web-signature.html" />
<area shape="rect" coords="378,339,435,376" href="http://self-issued.info/docs/draft-jones-json-web-key.html" />
<area shape="rect" coords="298,339,360,376" href="http://self-issued.info/docs/draft-jones-json-web-encryption.html" />
<area shape="rect" coords="453,339,515,376" href="http://self-issued.info/docs/draft-jones-simple-web-discovery.html" />
<area shape="rect" coords="33,339,125,401" href="http://tools.ietf.org/html/draft-ietf-oauth-v2" />
<area shape="rect" coords="221,48,336,100" href="http://openid.net/specs/openid-connect-discovery-1_0.html" />
<area shape="rect" coords="387,48,502,100" href="http://openid.net/specs/openid-connect-registration-1_0.html" />
<area shape="rect" coords="56,48,172,100" href="http://openid.net/specs/openid-connect-basic-1_0.html" /> </map>
<p><img class="aligncenter size-full wp-image-7495" title="OpenID Connect Protocol Suite" src="http://openid.net/wordpress-content/uploads/2011/08/OpenIDConnect-Map-v22.png" alt="OpenID Connect Protocol Suite" width="550" height="483" usemap="#GraffleExport" /></p>
<p>The biggest difference you’ll notice is that there is now only one spec to implement for “Minimal” clients (rather than previously three).  A number of people had asked that there be a single, simple, self-contained spec that basic relying parties could implement.  That spec is the <a href="http://openid.net/specs/openid-connect-basic-1_0.html" target="_blank">OpenID Connect Basic Client Profile</a>.  That’s all you need for a web-based relying party utilizing a pre-configured set of OpenID Providers.</p>
<p>For “Dynamic” configurations, where the set of OpenID Providers is not pre-configured, <a href="http://openid.net/specs/openid-connect-discovery-1_0.html" target="_blank">Discovery</a> and <a href="http://openid.net/specs/openid-connect-registration-1_0.html" target="_blank">Dynamic Client Registration</a> capabilities are added to enable RPs to discover OP endpoints and to connect with the OP selected.  This functionality is needed for “open” OpenID Connect interactions.</p>
<p>OpenID Providers, native client applications, and clients needing more functionality than that provided by the Basic Client Profile implement the <a href="http://openid.net/specs/openid-connect-standard-1_0.html" target="_blank">OpenID Connect Standard </a>binding for the <a href="http://openid.net/specs/openid-connect-messages-1_0.html" target="_blank">OpenID Connect Messages</a>.  Finally, OPs and RPs needing session management capabilities, including logout, also implement <a href="http://openid.net/specs/openid-connect-session-1_0.html" target="_blank">OpenID Connect Session Management</a>.</p>
<p>As you can see, the current organization remains highly modular, where implementations can build and deploy only what they need.  Now that modularity is even better reflected in the way that the specs are written – particularly that there is a single, self-contained basic client specification.</p>
<p>In closing, we’d like to thank developers for the valuable feedback provided to date.  Your input has both improved the technical content of OpenID Connect, and possibly even more importantly, made the specs simpler and easier to understand.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/09/12/openid-connect-specs-incorporating-developer-feedback/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>REMINDER &#8211; OpenID “Connect Tech” Summit &#8211; September 12-13, 2011</title>
		<link>http://openid.net/2011/08/22/openid-%e2%80%9cconnect-tech%e2%80%9d-summit-september-12-13-2011/</link>
		<comments>http://openid.net/2011/08/22/openid-%e2%80%9cconnect-tech%e2%80%9d-summit-september-12-13-2011/#comments</comments>
		<pubDate>Mon, 22 Aug 2011 19:15:48 +0000</pubDate>
		<dc:creator>Karinhanson</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[Summit Events]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[events]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[summit]]></category>

		<guid isPermaLink="false">http://openid.net/?p=6925</guid>
		<description><![CDATA[The OpenID Foundation is launching its third OpenID Summits for 2011. This event is co-sponsored by Microsoft and will be held at the Microsoft Research Campus in Mountain View.  The OpenID Foundation&#8217;s 2011 series of OpenID Summits focuses on use cases and topics of interest to key developers, executives and analysts in the online identity [...]]]></description>
			<content:encoded><![CDATA[<p align="left">The OpenID Foundation is launching its third OpenID Summits for 2011. This event is co-sponsored by Microsoft and will be held at the Microsoft Research Campus in Mountain View.  The OpenID Foundation&#8217;s 2011 series of OpenID Summits focuses on use cases and topics of interest to key developers, executives and analysts in the online identity industry.</p>
<p align="left">This OpenID summit gives web site developers and technologists a closer look at the OpenID Connect protocol, its use cases and adoption plans by leading companies. We will introduce &#8220;Account Chooser&#8221; its implementation and user experience and provide interop testing and feedback for next generation OpenID adoption.</p>
<p align="left"> Please join us on Monday, September 12, 2011 from 12:00 Noon until 5:00pm PDT and Tuesday, September 13, 2011 from 10:00am to 5:00pm PDT.</p>
<p align="left"> Registration is now open at the following link: <a title="REGISTER NOW!" href="http://openidsummitsept2011.eventbrite.com/" target="_blank">REGISTER NOW!</a></p>
<p style="text-align: left;" align="left"> Location:<br />
<strong>Microsoft Research Silicon Valley Campus &#8211; 1288 Pear Avenue, Mountain View, CA  94043</strong></p>
<p><strong>OpenID Connect Tech  Summit </strong></p>
<p align="left"><strong>AGENDA: Monday,<br />
September 12, 2011 &#8211; 12:00pm-5:00pm</strong></p>
<p><strong>Noon: Lunch will be provided for attendees </strong></p>
<p align="left">12:00-12:20<strong> &#8211; Welcome</strong><br />
Don Thibeau, Executive Director, The OpenID Foundation</p>
<p><strong>Technical Sessions</strong></p>
<p>12:20-1:00 &#8211; <strong>Overview and Update of OpenID Connect and OAuth 2.0</strong>, Mike Jones, Microsoft,<br />
Director of Identity Partnerships</p>
<p>1:00-3:00<strong> &#8211; OpenID Connect Spec development</strong> (Working Group Review led by Allen Tom and Mike Jones)<br />
[2 hours]</p>
<ul>
<li>Timing goals for ratification</li>
<li>Core protocol</li>
<li>Dynamic RP registration and IDP discovery</li>
<li>Claims</li>
<li>Session Management</li>
<li>Artifact Binding</li>
<li>US Government OpenID Connect profile</li>
</ul>
<p>3:20-4:00 &#8211; <strong>Open time for Technical Interop, </strong> Allen Tom &amp; Mike Jones [60 min]</p>
<p>4:00-4:40 &#8211; <strong>OpenID Connect: Building Test Infrastructure, </strong>Roland Hedberg</p>
<p>4:40-5:00 &#8211; <strong>Wrap-up</strong>, Don Thibeau, Executive Director, The OpenID Foundation</p>
<p align="left"><strong>AGENDA: Tuesday, September 13, 2011 &#8211; 10:00am-5:00pm</strong></p>
<p align="left"><strong>Business Session</strong></p>
<p>10:00-10:20 <strong>- Welcome</strong> Don Thibeau, Executive Director, The OpenID Foundation</p>
<p align="left">10:20-11:00 <strong>- Feedback Review OpenID Connect</strong> Mike Jones, Microsoft<br />
and Allen Tom, Directors, The OpenID Foundation</p>
<p align="left">11:00-11:40 - <strong>Overview and Update of Account Chooser,  </strong>A presentation on a new sign in experience for the web, how to get involved, and an update on the legal status of related IP. Scott David, K&amp;L Gates,  Basheer Tome,  Independent &amp; Eric Sachs, Google</p>
<p align="left">11:40-12:20 &#8211; <strong>Migrating Users to Identity Providers From Email/Password Logins&#8221;,  </strong>A Summary of the experience of websites, including Google, that have started to migrate users from traditional logins to identity providers.  Eric Sachs,  Google, Product Manager</p>
<p align="left">12:20-1:00 &#8211; <strong>Lunch</strong></p>
<p align="left">1:00-1:40 &#8211; <strong>Microsoft as an RP and IDP</strong>, Speaker (TBD)</p>
<p align="left">1:40-2:20 &#8211; <strong>Way Beyond Single Sign On,</strong> Greg Keegstra, Janrain</p>
<p align="left">2:20-3:00 &#8211; <strong>The Value Proposition for OpenID Connect &amp; Account Chooser in the Enterprise</strong>, Pam Dingle, Ping Identity</p>
<p align="left">3:00-3:20 &#8211; Break</p>
<p align="left">3:20-4:00 &#8211; <strong>Open Identity and Online Adoption</strong>, A discussion on trends in the adoption of social login among online businesses. Patrick Salyer, Gigya</p>
<p align="left">4:00-4:40 &#8211; <strong>OpenID Connect &amp; UMA Synergies</strong>, OpenID Connect and User-Managed Access (UMA) solve interestingly complementary problems.  This session will explore use cases and proposals for combining them.  Macie Machulak</p>
<p align="left">4:40-5:00 -<strong> Wrap up</strong> Don Thibeau, Executive Director, The OpenID Foundation</p>
<p align="left">Best regards,</p>
<p>Don Thibeau, Executive  Director<br />
OpenID Foundation</p>
<p style="text-align: left;"><strong>Additional information is available at:</strong></p>
<p style="text-align: left;" align="left"><a title="OpenID Connect" href="http://openid.net/connect/" target="_blank">http://openid.net/connect/</a></p>
<p style="text-align: left;" align="left"><a title="Accountchooser" href="http://accountchooser.com/" target="_blank">http://accountchooser.com/</a></p>
<p>&nbsp;</p>
<p style="text-align: center;">Hosted by:</p>
<p style="text-align: center;"><a href="http://openid.net/wordpress-content/uploads/2011/08/oIDF_Msft-logos.jpg"><img class="aligncenter size-full wp-image-6943" title="oIDF_Msft logos" src="http://openid.net/wordpress-content/uploads/2011/08/oIDF_Msft-logos.jpg" alt="" width="288" height="93" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/08/22/openid-%e2%80%9cconnect-tech%e2%80%9d-summit-september-12-13-2011/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>

