94
VIEWS
At the RSA Conference, Microsoft and VeriSign announced that closer integration between CardSpace and OpenID would improve resistance to phishing, which is considered a weakness of OpenID.
VeriSign, Microsoft & Partners to Work together on OpenID + Cardspace
This extends the OpenID protocol to allow a Relying Party (Assertion Consumer) to request phishing-resistant credentials when making an OpenID request.
OpenID’s resistance to phishing has become quite a topic of discussion lately. A proposal related to this issue is two-factor authentication using bookmarks. A representative example is BeamAuth.
BeamAuth’s mechanism is relatively simple and quite interesting. I will cover it in a separate post.
