Updated: 29.3.2002; 15:59:20.

Security weblog



daily link  Tuesday, February 26, 2002


Schwartz's interview goes on. Federated identity management solution properties and several revelations of devious intentions of Passport. I am too tired to think., but following paragraph sounds interesting:

In a federated world, there has to be some form of trust brokering. In order for United Airlines to accept a user that has logged in to CitiGroup as a user who is verified to engage in transactions, UAL has to trust that CitiGroup has, in fact, performed the necessary authentication and verification. But, if that user isn't going to engage in transactions where there's risk of fraud, then maybe full-blown verification isn't necessary and UAL will trust a lesser form of authentication, maybe without verification [in the credit card sense] from another site. United Airlines, for example, may not care that much, if all you're going to do is go check the levels in your [frequent flyer] account. So, in some instances United Airlines will be in a position to say "We'll trust the authentication that any site passes us, and in other cases, the authentication will only trust certain level of verification." Hopefully, we can standardize that through Project Liberty.

  11:53:29 PM  permalink  

ZDNet: Microsoft's Sohn: 'We won't sell Passport data'. Hmm, almost sounds like MS have developed Passport and .NET My Services out of goodness of their heart. They won't be selling data stored in those services and they provide access to them on open protocols and provide APIs and schemas free of charge so that everybody can tap into them. They will obviously be making money on selling the servers and development tools, won't they. And they are not obviously aware of the fact that in this case thez are dead because, open-source developers copy the concepts and provide the implementation for free. Stupid them.  11:37:17 PM  permalink  

 
February 2002
Sun Mon Tue Wed Thu Fri Sat
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28    
Jan   Mar
News:


Click here to send an email to the editor of this weblog.
jenett.radio.simplicity.1.3R
Radio Userland


Copyright 2002 © .
Last update: 29.3.2002; 15:59:20.