<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Welcome to The Metaverse : Identity</title><link>http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx</link><description>Tags: Identity</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>LiveID Announces Beta Support For Information Cards &amp; Windows CardSpace</title><link>http://blogs.msdn.com/richardt/archive/2007/08/28/liveid-announces-beta-support-for-information-cards-windows-cardspace.aspx</link><pubDate>Tue, 28 Aug 2007 19:25:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4615149</guid><dc:creator>richardt</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/richardt/comments/4615149.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=4615149</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=4615149</wfw:comment><description>&lt;p&gt;&lt;a href="http://blogs.msdn.com/angus_logan/archive/2007/08/25/announcement-windows-live-id-adds-beta-support-for-information-cards-with-cardspace.aspx" target="_blank" atomicselection="true"&gt;&lt;img style="margin: 0px 16px 8px 0px" height="198" src="http://blogs.msdn.com/blogfiles/angus_logan/WindowsLiveWriter/ANNOUNCEMENTWindowsLiveIDaddsBetasupport_E73E/clip_image020_2.jpg" width="328" align="left"&gt;&lt;/a&gt;Well, here's the news that many of you have been waiting for! &lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.msdn.com/angus_logan" target="_blank"&gt;Angus Logan&lt;/a&gt;, Technical Product Manager in LiveID has just announced that &lt;a href="http://blogs.msdn.com/angus_logan/archive/2007/08/25/announcement-windows-live-id-adds-beta-support-for-information-cards-with-cardspace.aspx" target="_blank"&gt;LiveID has launched beta support for information cards and Windows CardSpace&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;There's a great webcast and step-by-step instructions on how to associate a personal card with your LiveID account.&lt;/p&gt; &lt;p&gt;We just took one giant leap forward towards a safer internet. &lt;/p&gt; &lt;p&gt;Many congrats to the LiveID and CardSpace teams who worked hard to make this happen.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=4615149" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Dana Epps on RunAs Radio discussing CardSpace</title><link>http://blogs.msdn.com/richardt/archive/2007/07/24/dana-epps-on-runas-radio-discussing-cardspace.aspx</link><pubDate>Tue, 24 Jul 2007 22:32:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4032590</guid><dc:creator>richardt</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/richardt/comments/4032590.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=4032590</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=4032590</wfw:comment><description>&lt;p&gt;Just listened in to Scorpion Software's Dana Epps' great &lt;a href="http://www.runasradio.com/default.aspx?showNum=15" target="_blank"&gt;interview on RunAs Radio&lt;/a&gt;&amp;nbsp;discussing Information Cards, CardSpace and STS', interop and why usernames and password are a pain.&lt;/p&gt; &lt;h2&gt;WS-Trust vs. WS-Federation&lt;/h2&gt; &lt;p&gt;I do want to correct a small but important error: Identity Selectors in the Identity Metasystem use WS-Trust to request tokens representing the user from Identity Providers, not WS-Federation.&lt;/p&gt; &lt;p&gt;This is an easy mistake to make but it's important to understand the difference between WS-Trust and WS-Federation:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;WS-Trust is for scenarios where the user needs to interact with an "identity selector" to decide who they want to be at the beginning of each visit or session. This is a scenario we're all familiar with today when we sign in at our web-based email provider as one user to check our "Friends" mail and then sign out and sign back in to check our "Work" mail, etc. This is why identity selectors in the identity metasystem use WS-Trust&lt;/li&gt; &lt;li&gt;WS-Federation is for scenarios where two organizations wish to closely collaborate and enable users in one organization to access resources within the other organization without having to manually sign-in. Supported by Enterprise-class technologies like &lt;a href="http://msdn.microsoft.com/theshow/episode.aspx?xml=theshow/en/Episode047/manifest.xml" target="_blank"&gt;Microsoft's ADFS&lt;/a&gt;&amp;nbsp;and &lt;a href="http://www.pingidentity.com/products/pingfederate" target="_blank"&gt;PingID's PingFederate&lt;/a&gt;, WS-Federation enables a user's organization to tell a partner organization who the user is and also convey extra information such as the user's role and rights.&lt;/li&gt;&lt;/ul&gt; &lt;h2&gt;Personal Cards vs. Managed Cards&lt;/h2&gt; &lt;p&gt;Dana did a great job of discussing how information cards can be used TODAY instead of using traditional username/password authentication. However, quite some time was spent focusing on managed-card scenarios and I wanted to provide a little perspective on this matter:&lt;/p&gt; &lt;h3&gt;Personal Cards&lt;/h3&gt; &lt;p&gt;In order for you to sign-in to a given relying party (website or application) with information cards, all you need is an Identity Selector such as Windows CardSpace and an information card that is compatible with the relying party's specified policies. &lt;/p&gt; &lt;p&gt;Since relying parties decide what type of information they want from you in order to sign you into their systems, they get to ask you for a particular type of token and a particular set of claims. A common personal card scenario is associating or linking one or more personal cards with a relying party's existing account:&lt;/p&gt; &lt;p&gt;After logging in with your username and password, the relying party may allow you to register one or more personal cards that you can use to sign-in during subsequent visits. Since the relying party already knows you, they only really need you to provide a personal card with a PPID (unique ID for that card at this site) which they can use to generate a UniqueID that they can store in their DB and use to look you up next time you sign into their site using your information card. This enables you to sign in more safely and easily from one or more machines with three mouse-clicks rather than having to remember your username and password.&lt;/p&gt; &lt;p&gt;These&amp;nbsp;"personal card" scenarios are easy to support today, with little developer effort.&lt;/p&gt; &lt;h3&gt;Managed Cards&lt;/h3&gt; &lt;p&gt;Managed cards are issued by identity providers who are willing to assert that a particular set of claims about a person do in fact relate to that person. Examples of organizations who might be interested in issuing a managed card to you are your bank, your employer, your government, your favorite hotel chain or airline, etc.&lt;/p&gt; &lt;p&gt;Where managed cards become extremely exciting and powerful is where a relying party needs some form of information about you that has been corroborated by an organization that they trust. For example: An online wine store might want a confirmation from your state government that you are over 21 and so might ask you to provide a state-issued token containing the "Over21" claim.&lt;/p&gt; &lt;p&gt;Another good example of where managed cards provide great value is when a relying party needs some information about you that is likely to change fairly regularly. For example, imagine if you could sign-in to your favorite online store with your credit card company's member rewards card and the site could show you a list of the products that might interest you that are covered by your available points balance. No usernames, no passwords, no awkward redirection - just a plain and simple, easy to use mechanism that gets you into the site and shows you a list of products that you might want that you can afford!&lt;/p&gt; &lt;h2&gt;Which type of card to support now!&lt;/h2&gt; &lt;p&gt;However, whilst managed cards are exciting, the infrastructure to support them isn't quite there yet. Specifically, you need an STS (Security Token Service) - a service that issues and processes requests for managed identity tokens. Whilst some vendors (such as PingID's PingTrust and Arcot Systems' WebFort) are currently shipping with managed card support, Microsoft, Novell, IBM and many others are currently building STS capabilities into their future product offerings.&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;strong&gt;Until then, if you want to start making your users' lives easier and safer then we urge you to add support for personal cards.&lt;/strong&gt; &lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Supporting personal cards now will also make it much easier for you to support advanced managed card scenarios when the infrastructure becomes available.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=4032590" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Firefox 3.0 (likely) to support Windows CardSpace</title><link>http://blogs.msdn.com/richardt/archive/2007/07/11/firefox-3-0-likely-to-support-windows-cardspace.aspx</link><pubDate>Wed, 11 Jul 2007 20:07:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3817340</guid><dc:creator>richardt</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3817340.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3817340</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3817340</wfw:comment><description>&lt;p&gt;&lt;a href="http://mozillalinks.org/wp/2007/01/planned-features-for-firefox-3/" target="_blank" atomicselection="true"&gt;&lt;img style="border-right: 0px; border-top: 0px; margin: 0px 0px 4px 4px; border-left: 0px; border-bottom: 0px" height="85" alt="image" src="http://blogs.msdn.com/blogfiles/richardt/WindowsLiveWriter/Firefox.0likelytosupportWindowsCardSpace_86F3/image_4.png" width="240" align="right" border="0"&gt;&lt;/a&gt;In case you missed it, &lt;a href="http://mozillalinks.org/wp/2007/01/planned-features-for-firefox-3/" target="_blank"&gt;Mozilla's Percy Cabello&amp;nbsp;has just announced the list of features it's planning on including in Firefox 3.0&lt;/a&gt;. Among these features are integrated support for identity selectors such as Windows CardSpace :)&lt;/p&gt; &lt;p&gt;This is awesome news and I am delighted to see the Mozilla community supporting information cards to help users better manage and control their digital identities online.&lt;/p&gt; &lt;p&gt;As readers of &lt;a href="http://blogs.msdn.com/richardt" target="_blank"&gt;my blog&lt;/a&gt; will know, following &lt;a href="http://blogs.msdn.com/richardt/archive/2006/10/04/Meeting-Mozilla.aspx" target="_blank"&gt;a meeting with several members of the Mozilla team last fall&lt;/a&gt;, we were delighted to &lt;a href="http://blogs.msdn.com/richardt/archive/2006/12/12/firefox-extension-for-windows-cardspace.aspx" target="_blank"&gt;announce Kevin Miller's "Perpetual-Motion"&lt;/a&gt; - a CardSpace extension for Firefox 2.x (&lt;a href="http://www.codeplex.com/IdentitySelector" target="_blank"&gt;source here&lt;/a&gt;). Whilst Perpetual-Motion adds seamless support for Windows CardSpace to Firefox, it is an additional download that users have to go find and install.&lt;/p&gt; &lt;p&gt;By including support for identity selectors such as Windows CardSpace, Mozilla has put a very definite stake in the ground, making it clear that they, along with much&amp;nbsp;of the rest of the industry,&amp;nbsp;believe that information cards offer users an opportunity to enjoy a far safer and simpler online experience.&lt;/p&gt; &lt;p&gt;Congratulations guys - look forward to seeing the release of Firefox 3.0! :)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3817340" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Why don't Microsoft's own sites support CardSpace?</title><link>http://blogs.msdn.com/richardt/archive/2007/07/10/why-don-t-microsoft-s-own-sites-support-cardspace.aspx</link><pubDate>Wed, 11 Jul 2007 01:02:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3803905</guid><dc:creator>richardt</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3803905.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3803905</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3803905</wfw:comment><description>&lt;p&gt;This is a question I am hearing with increasing frequency as I talk to people about why, how and when they might support information cards. Essentially, it comes down to three reasons:&lt;/p&gt; &lt;ol&gt; &lt;li&gt; &lt;div&gt;History&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div&gt;Perceptions &lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div&gt;Timing&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Alas, some of Microsoft's prior forays into the world of online identity (e.g. Passport, Hailstorm, Wallet, etc) are encumbered (rightly or wrongly) with negative perception issues. &lt;/p&gt; &lt;p&gt;Whilst LiveID (formerly Passport) is an enormously successful online authentication engine that performs in excess of a billion authentications each and every day (and yes, that's not a typo - more than a billion a day!), the world made it clear that it doesn't want ONE authentication authority - it wants MANY. Why? Essentially, it comes down to trust. &lt;/p&gt; &lt;p&gt;If you had to store all your identity information in one place, who would you trust with that data? Microsoft? Google? Your bank? Your Government? There is no clear answer here. &lt;/p&gt; &lt;p&gt;It's this one core issue that has led to the creation of identity selectors such as Windows CardSpace and the Identity Metasystem (IDMS) which permits identities federated across a number of identity providers to be managed and exchanged under the user's explicit control. &lt;br&gt;&lt;br&gt;One of the decisions we made early in 2006 was to NOT have LiveID support CardSpace at the outset! We did this deliberately to allow us to clearly demonstrate that CardSpace and LiveID were separate but complementary - just as CardSpace and your bank or CardSpace and your government, etc., are. We wanted to ensure that people could examine and explore CardSpace unencumbered by any negative (and incorrect) preconceptions.&lt;/p&gt; &lt;p&gt;However, this is not to say that we've been sitting idly by. Of course, we knew that once it was clearly established that CardSpace is in no way related to or&amp;nbsp;reliant upon LiveID, the next inevitable question would be "so, when are Microsoft's sites going to support CardSpace?" &lt;/p&gt; &lt;p&gt;Both &lt;a href="http://www.identityblog.com/?p=488" target="_blank"&gt;Kim&lt;/a&gt; and &lt;a href="http://blogs.zdnet.com/microsoft/?p=151" target="_blank"&gt;yours truly&lt;/a&gt; pointed out some time ago, LiveID will (in the future) support Information Cards. In fact, we've spent the last several months working closely with our friends over in the LiveID team to support them in building support for information cards into LiveID. When they're done with their implementation and ready to announce, you'll read it here or on &lt;a href="http://www.identityblog.com/" target="_blank"&gt;Kim's blog&lt;/a&gt;&amp;nbsp;within seconds of sign-off! :)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3803905" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Identity discussion on Run As Radio</title><link>http://blogs.msdn.com/richardt/archive/2007/07/03/identity-discussion-on-run-as-radio.aspx</link><pubDate>Tue, 03 Jul 2007 21:07:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3673898</guid><dc:creator>richardt</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3673898.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3673898</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3673898</wfw:comment><description>&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.runasradio.com/default.aspx?showNum=12" target="_blank" atomicselection="true"&gt;&lt;img style="margin: 0px 0px 4px 10px" height="64" src="http://www.greghughes.net/rant/content/binary/WindowsLiveWriter/RunAsRadioShow4TalkingCompliancewithSimo_6ED4/RaRlogo1%5B8%5D.jpg" width="240" align="right" border="0"&gt;&lt;/a&gt;&lt;/strong&gt;A couple of weeks ago at TechEd 2007, I was invited to discuss the world of identity with Richard Campbell and Greg Hughes for &lt;a href="http://www.runasradio.com/" target="_blank" mce_href="http://www.runasradio.com/"&gt;RunAs Radio&lt;/a&gt;&amp;nbsp;- the Internet audio talk show for IT Professionals.&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.greghughes.net/rant/CardSpaceIdentityAndRelationshipToTheITFieldInterviewWithRichardTurner.aspx" target="_blank" mce_href="http://www.greghughes.net/rant/CardSpaceIdentityAndRelationshipToTheITFieldInterviewWithRichardTurner.aspx"&gt;Greg just announced&lt;/a&gt; that the interview is &lt;a href="http://www.runasradio.com/default.aspx?showNum=12" target="_blank" mce_href="http://www.runasradio.com/default.aspx?showNum=12"&gt;now live for your listening pleasure&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Greg &amp;amp; Rich: Thanks for the opportunity to talk with you guys - looking forward to doing it again soon :)&lt;/p&gt; &lt;p&gt;Enjoy!&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3673898" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Announcing the Information Card Icon</title><link>http://blogs.msdn.com/richardt/archive/2007/06/25/announcing-the-information-card-logo.aspx</link><pubDate>Mon, 25 Jun 2007 19:44:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3522981</guid><dc:creator>richardt</dc:creator><slash:comments>10</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3522981.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3522981</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3522981</wfw:comment><description>&lt;p&gt;&lt;font color="#ff8000"&gt;[Update: 6/25/2007 @ 13:40 PST]&lt;br&gt;&lt;/font&gt;&lt;font color="#ff8000"&gt;Please note:&lt;strong&gt; &lt;/strong&gt;This icon is NOT a Windows CardSpace Icon. It's an icon to symbolize that a site or application supports Information Cards, regardless of the identity selector used to submit an Information Token associated with any Information Card.&lt;/font&gt; &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/richardt/WindowsLiveWriter/AnnouncingtheInformationCardLogo_8842/infocard_114x80.png" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 2px 0px; border-right-width: 0px" height="80" alt="infocard_114x80" src="http://blogs.msdn.com/blogfiles/richardt/WindowsLiveWriter/AnnouncingtheInformationCardLogo_8842/infocard_114x80_thumb.png" width="114" align="left" border="0"&gt;&lt;/a&gt; Ever since announcing Windows CardSpace and introducing the world to the benefits of Information Cards, we’ve been asked repeatedly when there would be a visual icon that could be used by sites and applications that accept Information Cards … &lt;/p&gt; &lt;p&gt;We’re delighted to announce the immediate availability of the Information Card Icon. You’re free to use this icon (in accordance with the accompanying guidelines) to provide a clear, consistent visual cue to your users that your sites and applications support Information Cards. This will make it easier for users to recognize how and where to sign-in to your site and enjoy the ease-of-use and safety of Information Cards.  &lt;p&gt;We encourage you to replace any temporary icons you might have used on your existing sites and demos with an appropriately sized version of the Information Card icon to increase consistency and recognition of your support of Information Cards.  &lt;p&gt;Please &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ce99e033-39a8-4bc5-9014-60ed0b560d0e&amp;amp;displaylang=en"&gt;download the Information Card Icon package&lt;/a&gt; which contains usage guidelines, FAQ, and a series of pre-rendered PNG images in different sizes along with the master Illustrator artwork.  &lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3522981" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>"Phishing Resistant" OpenID spec published</title><link>http://blogs.msdn.com/richardt/archive/2007/06/24/phishing-resistant-openid-spec-published.aspx</link><pubDate>Mon, 25 Jun 2007 01:48:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3506014</guid><dc:creator>richardt</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3506014.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3506014</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3506014</wfw:comment><description>&lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/richardt/WindowsLiveWriter/OpenIDProviderPhishingResistantAuthentic_DC4E/image.png" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 8px 4px 0px; border-right-width: 0px" height="133" alt="image" src="http://blogs.msdn.com/blogfiles/richardt/WindowsLiveWriter/OpenIDProviderPhishingResistantAuthentic_DC4E/image_thumb.png" width="169" align="left" border="0"&gt;&lt;/a&gt; Mike Jones has just posted news that VeriSign's &lt;a href="http://daveman692.livejournal.com/" target="_blank"&gt;David Recordon&lt;/a&gt; has just published a proposed &lt;a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html" target="_blank"&gt;"OpenID Provider Authentication Policy Extension 1.0" spec&lt;/a&gt;. &lt;/p&gt; &lt;p&gt;This spec is essentially the culmination of several months of effort by OpenID community to deliver upon what was promised at RSA 2007 back in February, namely, the introduction of technologies such as Information Cards as a mechanism to protect users&amp;nbsp;from phishing and other identity related attacks.&lt;/p&gt; &lt;p&gt;Congratulations to the OpenID community on this landmark spec.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3506014" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Did the chicken really come first?</title><link>http://blogs.msdn.com/richardt/archive/2007/06/21/did-the-chicken-really-come-first.aspx</link><pubDate>Fri, 22 Jun 2007 01:06:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3448862</guid><dc:creator>richardt</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3448862.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3448862</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3448862</wfw:comment><description>&lt;p&gt;Someone who I'll keep anonymous just mailed me in relation to my post yesterday:&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;I know you didn't ask (nor was it your point) -- but the Egg came first. It was laid by some animal that was really, really genetically close to a chicken.&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;I have to say, I'm not sure I agree. Didn't the creature that gave birth to the first egg have to exist before the egg it laid?&lt;/p&gt; &lt;p&gt;But then, come to think of it, maybe the egg from which the first chicken came was laid by something that was not a chicken and was perhaps formed in some other way than the usual egg 'n' sperm method? Which would mean it would have come first, no?&lt;/p&gt; &lt;p&gt;Q.E.D. the chicken (or other lifeform) came first! ;)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3448862" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>The Chicken and the Egg</title><link>http://blogs.msdn.com/richardt/archive/2007/06/20/the-chicken-and-the-egg.aspx</link><pubDate>Thu, 21 Jun 2007 01:05:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3431847</guid><dc:creator>richardt</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3431847.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3431847</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3431847</wfw:comment><description>&lt;p&gt;You all know the age old question: "who came first, the chicken or the egg". Well, there's been some considerable discussion of late on the subject of how to help foster the growth of adoption of Information Cards and identity selectors such as Windows CardSpace and up-coming selectors such as &lt;a title="Bandit open source identity selector project" href="http://www.bandit-project.org/" target="_blank"&gt;Bandit&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;in one recent discussion I commented that we're in a kind of chicken and egg situation right now - whilst everyone agrees that identity&lt;a href="http://www.cartoonnetworkla.com/english/cowchicken/index.html" target="_new" atomicselection="true"&gt;&lt;img style="margin: 8px 0px 8px 8px" height="200" alt="Cow and Chicken - the funniest cartoon ever! :)" src="http://members.lycos.nl/cownchicken/ep/ep-egg.jpg" width="267" align="right"&gt;&lt;/a&gt; selectors and information cards are a good thing, it's taking some time for people to evaluate the concepts and ideas behind the Identity Metasystem and to look into actually supporting information cards at their sites. Many relying parties we've spoken to say they'll look into adding support to their sites once there are enough people to warrant doing so (and once there's an identity selector for non-Microsoft platforms, and once ...). Then there are the identity providers - many of whom want us to tell them how they can make money on this thing. Finally, we have users like my Mum &amp;amp; Dad - we can't turn the volume up for this audience until there are places to use their cards and identity providers willing to issue cards.&lt;/p&gt; &lt;p&gt;Keith Brown just posted &lt;a title="My comments on the chicken and egg situation" href="http://pluralsight.com/blogs/keith/archive/2007/06/11/47717.aspx" target="_blank"&gt;my comments&lt;/a&gt; on his blog and goes on to say:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;In my opinion, somebody (Microsoft?) needs to break this holding pattern fast. I agree that things aren't going to take off until there are more relying parties.&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;We're doing all we can to break this pattern. We were the first (through &lt;a title="Kim Cameron's Blog" href="http://www.identityblog.com/" target="_blank"&gt;Kim&lt;/a&gt;)&amp;nbsp;to espouse &lt;a title="The 7 Laws of Identity" href="http://www.identityblog.com/?page_id=354" target="_blank"&gt;the principles of the 7 laws&lt;/a&gt; and articulate the need for&amp;nbsp;and &lt;a title="The Identity Metasystem paper" href="http://www.identityblog.com/?page_id=355" target="_blank"&gt;design of an Identity Metasystem&lt;/a&gt;. We were the first to release a viable identity selector - Windows CardSpace - and continue to invest heavily in future versions and supporting technologies. We're educating our field and providing them (and partners) with the resources they need to learn and then tell this story. We are working with a very large number of web-site operators and related businesses to take this fledgling concept and technology and help it grow and flourish into the magnificent creature that it promises to be.&lt;/p&gt; &lt;p&gt;But we can't do it all, and we can't do it all ourselves. In fact, we've already tried doing it all and only doing it ourselves, and the world said "no".&lt;/p&gt; &lt;p&gt;We are just part of this story - our many partners and compatriots in this space (IBM, Novell, PingID, VeriSign, OpenID, sxip, BMC, Sun&amp;nbsp;and many, many&amp;nbsp;others) are all busily beavering away, building support for information cards for a variety of platforms, technologies and products. But all our work is in vein unless there are sites that accept cards and identity providers to issue managed cards.&lt;/p&gt; &lt;p&gt;This is where we welcome you, dear reader, to investigate &lt;a title="The 7 Laws of Identity" href="http://www.identityblog.com/?page_id=354" target="_blank"&gt;the principles&lt;/a&gt;, &lt;a title="The Identity Metasystem paper" href="http://www.identityblog.com/?page_id=355" target="_blank"&gt;the design&lt;/a&gt; and &lt;a title="Introducing Windows CardSpace" href="http://msdn2.microsoft.com/en-us/library/aa480189.aspx" target="_blank"&gt;the implementation&lt;/a&gt; of this Identity Metasystem and, if you believe that it's a "good thing", then take action. Join us and add support for information cards to your sites, systems and&amp;nbsp;app's. &lt;/p&gt; &lt;p&gt;The time for nodding in appreciation but standing by and doing nothing is past. While the industry pontificates about the Identity Metasystem being a "good thing", our users (and that includes ourselves) are continuing to suffer from password fatigue at best and phishing attacks at worst. &lt;/p&gt; &lt;p&gt;Together, we can all help stop the rot.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3431847" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Dominick going CardSpace crazy!</title><link>http://blogs.msdn.com/richardt/archive/2007/06/18/dominick-going-cardspace-crazy.aspx</link><pubDate>Tue, 19 Jun 2007 03:24:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3393359</guid><dc:creator>richardt</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/richardt/comments/3393359.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=3393359</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=3393359</wfw:comment><description>&lt;p&gt;Y'know, sometimes you meet someone who needs a life, but is clearly having so much fun and churning out useful things that you're kinda glad they don't! &lt;a title="Dom's blog" href="http://www.leastprivilege.com/" target="_blank" rel=" "&gt;Dominick&lt;/a&gt; is one such guy! ;)&lt;/p&gt; &lt;p&gt;Over the last couple of weeks, Dominick has churned out not just an &lt;a title="Updated ASP.NET Control for Windows CardSpace" href="http://www.leastprivilege.com/UpdatedCardSpaceControlForASPNET.aspx" target="_blank"&gt;updated ASP.NET control for Windows CardSpace&lt;/a&gt; (and other identity selectors when they start to become available) but has also just published a &lt;a title="GetToken() wrapper" href="http://www.leastprivilege.com/GettingCardSpaceTokensProgrammatically.aspx" target="_blank"&gt;wrapper for the GetToken() method&lt;/a&gt; on the CardSpaceSelector object. This wrapper lets you easily use CardSpace from within your own WinForms apps, and elsewhere in order to integrate CardSpace support into your apps and systems.&lt;/p&gt; &lt;p&gt;Awesome stuff! Now, just make sure you don't barrage Dom with email - we don't want to distract him from his next project now do we? ;) :)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3393359" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Shibboleth to support Information Cards</title><link>http://blogs.msdn.com/richardt/archive/2007/05/29/shibboleth-to-support-information-cards.aspx</link><pubDate>Tue, 29 May 2007 22:38:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2973695</guid><dc:creator>richardt</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/richardt/comments/2973695.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=2973695</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=2973695</wfw:comment><description>&lt;p&gt;&lt;a title="Mike Jones' Blog" href="http://self-issued.info/" target="_blank"&gt;Mike Jones&lt;/a&gt; has &lt;a title="Mike Jones posts the news that Shibboleth is adding support for information cards" href="http://self-issued.info/?p=10" target="_blank"&gt;posted&lt;/a&gt; the news that &lt;a title="About Internet2" href="http://www.internet2.edu/about/" target="_blank"&gt;Internet2&lt;/a&gt;&amp;nbsp;(the advanced networking consortium) announced last week that they are &lt;a title="Shibboleth announces support for information cards" href="https://mail.internet2.edu/wws/arc/i2-news/2007-05/msg00009.html" target="_blank"&gt;adding support for information cards to the Shibboleth federated authentication infrastructure&lt;/a&gt;. This is fantastic news for the millions of people attending or employed by thousands of academic and research establishments around the world as it will enable them to not only authenticate more easily and safely than ever before, but also provide third parties with a signed statement of their affiliation with&amp;nbsp;a given&amp;nbsp;establishment, essentially proving that they are a student or an employee, etc. &lt;/p&gt; &lt;p&gt;This latter scenario could prove to be hugely beneficial capability enabling people to forge stronger relationships with supporting merchants and service providers, helping them enjoy deeper discounts and value-added services than is achievable today.&lt;/p&gt; &lt;p&gt;Congratulations to the Internet2 teams and we look forward to seeing Shibboleth help educational establishments and their partners around the world become "Identity Aware".&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2973695" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>The world's simplest CardSpace demo source code</title><link>http://blogs.msdn.com/richardt/archive/2007/05/09/the-world-s-simplest-cardspace-demo-source-code.aspx</link><pubDate>Thu, 10 May 2007 07:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2516850</guid><dc:creator>richardt</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/richardt/comments/2516850.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=2516850</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=2516850</wfw:comment><description>&lt;p&gt;A few weeks ago I published a couple of screencasts on Channel9. &lt;a title="Channel9 Screencast examining how to add support for informaiton cards to a site" href="http://channel9.msdn.com/Showpost.aspx?postid=291878" target="_blank"&gt;The first&lt;/a&gt; illustrated the Windows CardSpace user experience and how you can add support for information cards to your site with very little code. &lt;a title="Channel9 Screencast illustrating how to configure IIS7 to support information card enabled sites" href="http://channel9.msdn.com/ShowPost.aspx?PostID=295904" target="_blank"&gt;The second&lt;/a&gt; went on to demonstrate how to configure IIS7 to support a site that accepts information cards.&lt;/p&gt; &lt;p&gt;But where is the code you ask? The wait is over - you can find it&amp;nbsp;&lt;a title="The world's simplest Windows CardSpace sample" href="http://www.bitcrazed.com/Downloads/Samples/CardSpaceDemov1.0.zip"&gt;here&lt;/a&gt;! :)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2516850" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Playing with the Windows CardSpace sandbox</title><link>http://blogs.msdn.com/richardt/archive/2007/05/09/playing-with-the-windows-cardspace-sandbox.aspx</link><pubDate>Thu, 10 May 2007 01:54:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2511679</guid><dc:creator>richardt</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/richardt/comments/2511679.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=2511679</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=2511679</wfw:comment><description>&lt;p&gt;&lt;/p&gt; &lt;p&gt;For those that are not aware, several months ago, we launched the &lt;a title="CardSpace Sandbox" href="http://sandbox.netfx3.com/" target="_blank"&gt;Windows CardSpace “Sandbox”&lt;/a&gt; that you can play with to try out the CardSpace experience. Whilst many of you have managed to work out how to&amp;nbsp; register and sign-in, many of you have experienced an issue or two. In order to to make it clear how to sign-in to the Sandbox, please follow these instructions:  &lt;ol&gt; &lt;li&gt;Register:&lt;a href="http://sandbox.netfx3.com/" target="_new" atomicselection="true"&gt;&lt;img style="margin: 0px 0px 0px 8px" height="367" src="http://blogs.msdn.com/blogfiles/richardt/WindowsLiveWriter/PlayingwiththeWindowsCardSpacesandbox_DDE3/image%7B0%7D%5B7%5D.png" width="184" align="right" border="0"&gt;&lt;/a&gt;  &lt;ol&gt; &lt;li&gt;Go to &lt;a href="https://sandbox.netfx3.com/user/CreateUser.aspx"&gt;HTTPS://sandbox.netfx3.com/user/CreateUser.aspx&lt;/a&gt; and hit "Join with an information card"  &lt;li&gt;Windows CardSpace will start up  &lt;li&gt;If this is the first time you've registered at the site, Windows CardSpace will present you with a page introducing you to the site, helping you make sure this is the site you expected it to be. Confirm that you want to submit a card to the site.&amp;nbsp;  &lt;li&gt;If you have no compatible cards (i.e. a card lit up in color), create one making sure to provide data for at least the fields the Sandbox is requesting from you (first name, last name, email). Note that the card name is purely for your use and is never transmitted to a site so you can name the card whatever you like.  &lt;li&gt;Select a compatible card and hit submit  &lt;ol&gt; &lt;li&gt;If this is the first time you’ve submitted this card, you’ll be shown a preview of the data – review and hit submit  &lt;li&gt;You’ll now be asked to create a site-specific user name (note in the top right that the site has already created you a temporary username (first initial+surname[+optional uniquifier]), bit this gives you a chance to call yourself something relevant (or anonymous) to that suite)&lt;/li&gt;&lt;/ol&gt; &lt;li&gt;You’re now signed in.&amp;nbsp;  &lt;li&gt;Sign out of the site (using “logout” button) in the top right &lt;/li&gt;&lt;/ol&gt; &lt;li&gt;Sign back in again. Hit the sign in link  &lt;ol&gt; &lt;li&gt;Hit the “Sign in” with my information card button  &lt;li&gt;Up pops Windows CardSpace  &lt;li&gt;Notice the card you signed in with is sorted to the top of the list, helping you remember which cards you’ve previously submitted to the site&lt;br&gt;Hit this card and hit send  &lt;li&gt;You’re now signed in!&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Hope this helps any of you having problems with the site. If you have any other issues, be sure to let us know through the &lt;a href="https://sandbox.netfx3.com/blogs/feedback/contact.aspx"&gt;”Contact Us” Sandbox feedback mechanism&lt;/a&gt; and one of the team will respond as quickly as we can.  &lt;p&gt;Enjoy! ;)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2511679" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>TSA Looses a hard-drive containing 100,000 names, social security numbers and payroll info</title><link>http://blogs.msdn.com/richardt/archive/2007/05/07/tsa-looses-a-hard-drive-containing-100-000-names-social-security-numbers-and-payroll-info.aspx</link><pubDate>Tue, 08 May 2007 04:48:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2472165</guid><dc:creator>richardt</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/richardt/comments/2472165.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=2472165</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=2472165</wfw:comment><description>&lt;p&gt;Read the story here: &lt;a href="http://www.theregister.com/2007/05/07/tsa_loses_hard_drive/"&gt;http://www.theregister.com/2007/05/07/tsa_loses_hard_drive/&lt;/a&gt;
	&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The TSA doesn't know whether the device is still within headquarters or was stolen.
&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&amp;lt;Snip/&amp;gt;
&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;They are unsure whether the data was encrypted or not. 
&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I don't want to sound blasé, but it's a shame they aren't running Vista and using BitLocker to encrypt their drives. 
&lt;/p&gt;&lt;p&gt;I KNOW how painful this can be – about 4 months before I moved from Microsoft UK to Microsoft US, thieves broke into my car and stole my laptop (and bag containing my camera with pictures of my daughter's 1&lt;sup&gt;st&lt;/sup&gt; day at school &lt;span style="font-family:Wingdings"&gt;L&lt;/span&gt;). My laptop had 2 years' worth of enormously sensitive email as well as a copy of the entire Windows source tree. Thankfully, I'd gotten spooked a year previously when there was a rash of laptops being stolen from employee's cars and decided to take the small perf hit to encrypt my sensitive folders so I knew my data was safe. I was soooo happy I didn't have to go tell my boss and get on the phone with Allchin and Valentine and alert them that the source code for Windows was out there in the wild! 
&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The TSA is investigating to see if proper data security procedures were followed.
&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Personally, I wonder if the people responsible for the TSA's infrastructure might not be more liable and have to answer for THEIR jobs. It seems to me that most clerical staff, knowledge workers, etc. just use the tools they're given and don't want or need to understand the importance of things like data encryption. Surely it's the IT Director and Security Director who should be making sure that their infrastructure is as safe and secure as possible, no?&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2472165" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item><item><title>What happens when Identity goes wrong?</title><link>http://blogs.msdn.com/richardt/archive/2007/05/07/what-happens-when-identity-goes-wrong.aspx</link><pubDate>Tue, 08 May 2007 03:42:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2471352</guid><dc:creator>richardt</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/richardt/comments/2471352.aspx</comments><wfw:commentRss>http://blogs.msdn.com/richardt/commentrss.aspx?PostID=2471352</wfw:commentRss><wfw:comment>http://blogs.msdn.com/richardt/rsscomments.aspx?PostID=2471352</wfw:comment><description>&lt;p&gt;If you ever wondered why &lt;a href="http://www.identityblog.com/"&gt;Kim&lt;/a&gt; worked so hard to form the &lt;a href="http://www.identityblog.com/?page_id=352"&gt;7 Laws of Identity&lt;/a&gt;, you *MUST* watch this short video! 
&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.adcritic.com/interactive/view.php?id=5927"&gt;http://www.adcritic.com/interactive/view.php?id=5927&lt;/a&gt;
	&lt;/p&gt;&lt;p&gt;Whilst funny, it's also shockingly potent.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2471352" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/richardt/archive/tags/Identity/default.aspx">Identity</category></item></channel></rss>