Featured articles
Archive
Category: Identity
Call for Presentations Opens for OpenID Summit Tokyo 2015
On November 10, OpenID Summit Tokyo 2015 will be held in Iidabashi, Tokyo. The Call for Presentations has now opened[1]. Each presentation will be allotted 20 minutes (15 minutes p…
HTC Smartphone Vulnerability Allows Anyone to Read Fingerprint Images, Sending Share Price Plunging
According to an article in The Guardian, it appears that an HTC smartphone stored users’ fingerprint images in a form that anyone could read. The issue was discovered by 4 FireEye…
Internet Identity Timeline
As it seems that the number of people who know this history may soon start dwindling, I have begun compiling an Internet Identity timeline. I am including events that I personally…
The XARA Vulnerabilities in MacOS X and iOS
This afternoon (June 18), GigaZine published a sensational article titled “Vulnerability Found That Allows iCloud, Email, and Browser-Saved Passwords to Be Stolen on iOS and OS X;…
How “Numbers” Should Be Designed: Reflections on the Pension Number Leak
Regarding the pension number leak, apparently “all leaked numbers will be changed”. Personally, all I can think is, “Oh dear.” As I wrote in yesterday’s article, if operated approp…
Is It Dangerous When an “Identifier Number” Leaks?
We are entering a summer at the height of the My Number compliance bubble. How is everyone doing? As it happens, pension numbers have leaked on a massive scale People say this migh…
U.S. Real Estate Industry Adopts OpenID Connect for Web API Authentication
According to a report by Peter Williams[1], the U.S. real estate industry appears to have decided to adopt OpenID Connect for Web API authentication. I did not know this, but the r…
JWS and JWT Are Now RFCs!
It took a very long time[1], but JSON Web Signature (JWS) and JSON Web Token (JWT) have finally become Standards Track RFCs[2]. They are [RFC 7515] and [RFC 7519], respectively. Fo…
Implementations by Google, Microsoft, PayPal, Nomura Research Institute, and Others Pass OpenID Connect Conformance Tests
(Figure 1) OpenID Certified logo On the 22nd local time, the U.S.-based OpenID® Foundation announced its self-certification program for the conformance of OpenID Connect implementa…
【Amendment of the Act on the Protection of Personal Information】Obligation to Keep Records of Third-Party Provision【Part 2】
Now, regarding the obligation to keep records of third-party provision that I pointed out on 3/12[1], I subsequently learned a great deal from people at the Cabinet Secretariat…

You must be logged in to post a comment.