Thursday, January 31, 2008

The new buzz: Open ID

What is Open ID?

OpenID is a decentralized Single single sign-on system. Using OpenID-enabled sites, web users do not need to remember traditional authentication tokens such as username and password. Instead, they only need to be previously registered on a website with an OpenID "identity provider" (IdP). Since OpenID is decentralized, any website can employ OpenID software as a way for users to sign in; OpenID solves the problem without relying on any centralized website to confirm digital identity.


What Problem Open ID is attempting to solve?

OpenID is attempting to solve web-scale single sign-on. The number of sites which require users to sign in continues to explode, while those same users suffer from a severe case of sign-up fatigue. The most severe consequence of this is poor password management - users re-use the same password on many different sites, but this dramatically increases the chance that their password will be compromised - if just one of those sites has a security problem all of the user's accounts might be stolen.
With OpenID, user's just need to set one password with their OpenID provider. They can securely use that account to sign in to many different sites, without needing to manage many different passwords. Rather than having dozens of potential attack targets, they need only focus on securing their relationship with one site.


How does Open ID work?
Coming Soon.....

No comments: