Advertisement
Promo

Become a member of the ZDNet UK community

Adrian Bridgwater

View blog's RSS Feed

Software application development

This blog is intended to provoke discussion and exchange between like minded software application developers, engineers, architects, project managers - and keen hobbyists too.

Thursday 17 January 2008, 7:24 PM

Does Yahoo! OpenID 2.0 support open up security concerns?

Posted by Adrian Bridgwater

Did you notice that Yahoo! has supported the OpenID 2.0 digital identity framework? OpenID (it says here) is an open framework that allows you to consolidate your Internet identity and thereby eliminate the need to create separate IDs and logins at all of the various web sites, blogs, photo-streams and profile pages you may visit.

OK competition time. If any number of a users’ identities are brought together, what’s the first word that comes to mind?

SECURITY CONCERNS

Alright, so that’s two words – but you get the point.

This is just a public Beta of course, but it will mean that in addition to Yahoo! Services, anyone with a Yahoo! ID will be able to use the same ID for access to any of the 9,000 sites that currently support OpenID.

OK OK I may be looking for problems where they don’t exist. The official line on security is as follows. “Yahoo’s implementation is based on the OpenID 2.0 specification, which was finalised in December 2007 and includes new features that improve the security and usability of OpenID, making it the most user-friendly single sign-on and online user-authentication standard. Yahoo! users who log in with their Yahoo! ID on OpenID sites will have the added protection of Yahoo!’s sign-in seal wherever they go on the web, providing additional security and ensuring that no email or IM addresses are revealed or disclosed as part of any login process, protecting users from phishing or other attacks.”

So that’s alright then? Well, Yahoo! aren’t fools are they? In fact I’m quite a fan and have met co-founder David Filo personally. But if you Google (or indeed if you Yahoo!) the term “OpenID security concerns” you’ll get a list of blog entries from techies everywhere asking questions about security concerns for their own real world implementations of OpenID. A note of caution to end, this blog entry is not meant to be alarmist or deliberately negative – simply to make sure we do discuss these things before they get out of hand. Call it healthy discussion, call it typical British tech journo cynicism or simply call it wariness to knew ‘cure-all’ solutions in an increasingly security-aware world.

Comments on this post

harpless

Its definately food for thought. I do wonder how easy it is for sites to join then Open ID scheme and whether your login details are revealed to all perticipating websites!

Posted by harpless on Jan 17, 2008 11:33 PM

nanyangrose

This comment has been deleted at the users request

Updated by nanyangrose on Jan 20, 2008 1:26 AM

Adrian Bridgwater

This member is ranked #4 in our top 100

  • Adrian Bridgwater
  • Applications Development, London, UK
  • Member since: July 2007

Site Activity Rating 6

CoreTechs

Contacts' Latest Discussions

Number of Tracked Discussions: 2,066

manek manek

Time for your baggage to arrive, then

Monday 30 November 2009, 12:44 PM

1 comment
ator1940 ator1940

Chrome-OS download

Monday 30 November 2009, 12:59 AM

6 comments
ator1940 ator1940

Chrome-OS download

Friday 27 November 2009, 3:30 PM

6 comments
ator1940 ator1940

The real Chrome-OS

Friday 27 November 2009, 2:06 AM

6 comments

Contacts' Latest Blogs

Number of Contacts Blogs: 5

Avatar Jake Rayson

How I create a blog entry

Thursday 26 November 2009, 1:00 PM

2 comments
Avatar manek

Cloud computing guzzles juice: officia...

Thursday 26 November 2009, 12:36 PM

0 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters