At the RSA Conference, Microsoft and VeriSign announced that closer integration between CardSpace and OpenID would improve resistance to phishing, which is considered a weakness of OpenID.

VeriSign, Microsoft & Partners to Work together on OpenID + Cardspace

This extends the OpenID protocol to allow a Relying Party (Assertion Consumer) to request phishing-resistant credentials when making an OpenID request.

OpenID’s resistance to phishing has become quite a topic of discussion lately. A proposal related to this issue is two-factor authentication using bookmarks. A representative example is BeamAuth.

BeamAuth’s mechanism is relatively simple and quite interesting. I will cover it in a separate post.