blog

Uncategorized

{0}

Sun's OpenID programme: definitely something to watch

Sun yesterday announced: a new initiative around support for OpenID, a decentralized, web-friendly single sign-on mechanism that allows consumers to reuse a single login across different websites, tackling the “login explosion” problem. OpenID is currently limited to facilitating low-risk transactions such as blog comments. Through its new initiative, Sun is exploring what changes and practices [...]

Posted on Tuesday, May 8, 2007 by

Uncategorized

{0}

Liberty is serious about clients

The Liberty Alliance today announced its Advanced Client specifications which are designed to allow enterprise users and consumers to manage identity information on devices such as cameras, handhelds, laptops, printers and televisions For those of you that are so inclined, you can read the specifications here but, in a nutshell, the Advanced Client relies on [...]

Posted on Tuesday, March 20, 2007 by

Uncategorized

{6}

BEA announces strategic partnerhsip with CA: but where does that leave AquaLogic Enterprise Security?

BEA today announced a stategic partnership with CA, which will see the latter’s access and identity management solutions (SiteMinder and Identity Manager) integrated with the former’s WebLogic and AquaLogic application and service infrastructure platforms. I agree completely with Wai Wong’s (BEA’s executive vice president of products) statement in the press release that Identity and Access [...]

Posted on Tuesday, March 6, 2007 by

Our first identity management assessment

Excuse the use of the blog to highlight our own research but I wanted to let any of you out there who are interested in identity management know that the first of our identity management infrastructure assessments – Novell – has just been published. Here’s the summary to whet your appetites: Novell has exploited its [...]

Posted on Friday, March 2, 2007 by

Uncategorized

{2}

Internet-scale identity systems

If you’re interested in what’s happening (and there’s a lot) in the world of user-centric and federated identity you’ll want to know about Microsoft’s CardSpace, OASIS’ SAML, OpenID and the Liberty Alliance’s ID-Web Services Framework (ID-WSF), all of which I have discussed here in one way or another. Given recent developments, it’s also important to [...]

Posted on Thursday, February 8, 2007 by

Uncategorized

{0}

Bill Gates says goodbye to the RSA conference – and announces ILM

Bill Gates’ keynote yesterday at the RSA Conference was his last. He is handing over to chief research and strategy officer, Craig Mundie, with whom he shared the stage yesterday. Gates marked his departure with a couple of significant identity-related announcements: one primarily focussed at the consumer, the other at the enterprise. The first concerned [...]

Posted on Wednesday, February 7, 2007 by

Uncategorized

{0}

A couple of interesting CardSpace snippets

A couple of interesting CardSpace items of note. The first comes via Kim Cameron, Microsoft’s Identity Architect, and highlights how Otto (a German online retailer) is using CardSpace for its rich client shopping application. The post should of interest to any organisations considering CardSpace-based authentication since it explains the process through which individuals get a [...]

Posted on Tuesday, February 6, 2007 by

Uncategorized

{0}

Symantec's Norton gets all user-centric

I highlighted (with more than a little cynicism) Symantec’s Security 2.0 vision back in October. Yesterday, at the DEMO conference, the company announced one element of that vision – its Identity Initiative – and demonstrated the Norton Identity Client. This is good news for those promoting user-centric identity, given Symantec’s solid footprint in the consumer [...]

Posted on Thursday, February 1, 2007 by

Uncategorized

{0}

Interesting developments in open source user-centric identity

A couple of interesting stories related to open source user-centric identity came my way, courtesy of CNET. The first concerns a donation to the Higgins Project from IBM and the second is about some important interoperability announcements to come at this week’s RSA Conference. The Higgins Project, which I have been following closely for the [...]

Posted on Monday, January 29, 2007 by

Uncategorized

{6}

Identity meets SOA

I just came across (well, Neil pointed me to it) this post from Todd Biske, an SOA Enterprise Architect at MomentumSI in which he discusses the implications of a service-oriented approach for identity. Todd raises an important question: what “identity” is in the context of service security This is something I discuss in our identity [...]

Posted on Wednesday, November 22, 2006 by