Posted By: Joshua Allen | Jul 20th, 2007 @ 5:34 PM

infocard_128x90.png

Last week we discussed OpenID, one of the identity technologies you should care about.  Today we'll talk about "Information Cards", another open standard for identity on the web.  We'll fill out the series by discussing BBAuth and Live ID in future posts.

The quickest way to understand "Information Cards" is to look at this one-minute screen cast.  It demonstrates login without password using both Internet Explorer and Firefox.  The user simply presents an "information card" to the site, and is safely logged in.

image

 

Business Case: if you enable people to use Information Cards to login to your site, your users will be able to login with a safe, consistent phishing-resistant user interface that doesn't require username and password.  People can use a shared "Information Card" across multiple sites for convenience without compromising their login information (similar to using a shared OpenID across multiple sites).  But more importantly, the "Information Cards" protocol is designed for use in high-value scenarios like banking, where phishing-resistance and support for secure authentication mechanisms like smart card are critical.

Protocol: Information Cards are based on open standards.  Anyone can implement, issue, or accept Information Cards.  Information Cards are composed using WS-* specifications instead of HTTP redirect, so the specifications are significantly more complicated than OpenID.

Industry Situation: A number of platforms can easily accept Information Cards for login.  It takes just a few minutes to enable Information Cards on ASP.NET, and code is available for Ruby, Java, and PHP.  Once a web site is configured to accept Information Cards for login, users can login from Windows (using Windows CardSpace), and soon from Mac and Linux.  In fact, just a couple of weeks ago at Burton's Catalyst conference, 11 different clients and 24 different servers participated in an interop demo.

Analysis: Information Cards can be considered to be a "heavier" protocol than the other technologies (LiveID, BBAuth, OpenID).  But when you want password-less login, phishing-resistance, and consistent cross-platform UI; they are essentially the only option.  And Information Cards are complimentary to the other technologies (as we saw with OpenID last week) in that you could use an Information Card in place of username/password to authenticate against one of the other systems.  You should strongly consider Information Cards (end-to-end, or in conjunction with something like LiveID or OpenID) if your scenario isn't one one where you feel comfortable with the security implications of "password reminder e-mails".

Tags:
Rating:
0
0
page 1 of 26
Comments: 232
Although not very understanding of your article, but thank you. Expect you to write better articles..maybe you will like this if you are fashion.Tiffany,Tiffany,Tiffany,links of london,ed hardy  asdfasdf
People can use a shared "Information Card" across multiple sites for convenience without compromising their login information (similar to using a shared OpenID across multiple sites).
Online degree | Bachelors degree | Health science school
Information Cards are composed using WS-* specifications instead of HTTP redirect, so the specifications are significantly more complicated than OpenID.
Psychology School | Social work school
Links of London jewelry at online Links of london UK store, including Links of London Necklaces, Links of London Charms, Links of London Earrings.Links of London - This exquisite range is available from our online shop as well as free delivery on all orders– Visit us now! Links of London, Pandora and Links of London is one of the best online jewelry stores. A wide selection of fine quality gold, silver and diamond Links london tiffany jewelry tiffany co Tiffany Bracelets

wow gold wow gold louis vuitton handbagslouis vuitton handbags ugg bootsugg boots ed hardyed hardy jordan shoesjordan shoes nike shoesnike shoes

Yesterday someone tell me the nike shoes is not as comfortable as the sheepskin shoes likejordan shoes, but I think if you want to feel the best comfortable, ugg boots and basketball shoes will be the good choice.

sgdfhsdfdf

You’ve probably heard, by now, the jordan shoes or UGG Boots for sale online are under a low price. Why not take a pair of Nike Shoes or UGG Slippers for ur friend or yourself? Oh! Nearly forgot the Silver Jewelry, I mean Tiffany, they are so cheap online. You may curious why I talked about these. I’m a fan of Air Jordan and I collect ed hardy for my collection.As you know, the jordan shoes selling in emporium is too expensive for my income. With the aid of getting more ugg boots , shopping online is a choice if you are just a air jordans collector. Maybe some louis vuitton handbags you got wast the real Jordan Shoes, at least we can collect many series of nike shoes.

t
I quite agree with you! the Tiffany Jewellery is the good choose,without the Tiffany,the Abercrombie and Fitch is the necessary,too~
good post,I think so!abercrombie and fitch on Sale, Hoodies, Jeans, T -Shirts, Pants, Polos abercrombie and fitch abercrombie fitch abercrombie cheap abercrombie and fitch Abercrombie Men Tee abercrombie womens polos Abercrombie & Fitch Men, women, and children's clothing and links london accessories edhardylife a famous ed hardy store which sell directly ed hardy clothing, shoes, boots, swim suit and other cheap ed hardy, ed hardy cheap Ed Hardy ed hardy clothing,Providing authentic Ed Hardy Clothing with competitive price and fast,secure delivery.The famous brand by Don Ed Hardy 's Vintage Ed Hardy.Provides the best tiffany jewellery, including Necklaces, Pendants, Bracelets, Earrings, Rings at the lowest prices.Tiffany Jewellery is the best online United Kingdom jewelry stores where you can buy the cheapest tiffany jewellery & Co silver jewelry. Our huge selection of tiffany uk and tiffany jewellery and tiffany jewelry,
page 1 of 26
Comments: 232
Microsoft Communities