identity 2.0 - openid and user centric identity

100
Identity 2.0 OpenID & User Centric Identity Martin Strandbygaard Open Source Days, 4th October 2008

Upload: martin-strandbygaard

Post on 27-May-2015

1.969 views

Category:

Technology


4 download

TRANSCRIPT

Page 1: Identity 2.0 - OpenID And User Centric Identity

Identity 2.0OpenID & User Centric Identity

Martin StrandbygaardOpen Source Days, 4th October 2008

Page 2: Identity 2.0 - OpenID And User Centric Identity

?How Many Have Used OpenID

Page 3: Identity 2.0 - OpenID And User Centric Identity

?How Many Use It Regularly

Page 4: Identity 2.0 - OpenID And User Centric Identity

Who Am I

Page 5: Identity 2.0 - OpenID And User Centric Identity

“Martin Strandbygaard”

Page 6: Identity 2.0 - OpenID And User Centric Identity
Page 7: Identity 2.0 - OpenID And User Centric Identity
Page 9: Identity 2.0 - OpenID And User Centric Identity

All Part Of My Identity

Page 10: Identity 2.0 - OpenID And User Centric Identity

Something I Claim

Something I Say

Page 11: Identity 2.0 - OpenID And User Centric Identity
Page 12: Identity 2.0 - OpenID And User Centric Identity
Page 13: Identity 2.0 - OpenID And User Centric Identity

This Is Also Part Of My Identity

Page 14: Identity 2.0 - OpenID And User Centric Identity

What Others Say About Me

Page 15: Identity 2.0 - OpenID And User Centric Identity

(What Others Say = More Trusted)

Page 16: Identity 2.0 - OpenID And User Centric Identity

Identity = Reputation

Page 17: Identity 2.0 - OpenID And User Centric Identity

How Do I Prove It?

Page 18: Identity 2.0 - OpenID And User Centric Identity

= “Martin Strandbygaard”

Page 19: Identity 2.0 - OpenID And User Centric Identity

I control it.I choose when to use it.

Issuer doesn’t know when I do so.

Page 20: Identity 2.0 - OpenID And User Centric Identity

Asymmetric trust = scalability

Page 21: Identity 2.0 - OpenID And User Centric Identity

-

Page 22: Identity 2.0 - OpenID And User Centric Identity

... Proves Your A Database Entry

Page 23: Identity 2.0 - OpenID And User Centric Identity

Doesn’t Say Anything About You

Page 24: Identity 2.0 - OpenID And User Centric Identity
Page 25: Identity 2.0 - OpenID And User Centric Identity

Identity 1.0- Dick Hardt, OSCON 2005

Page 26: Identity 2.0 - OpenID And User Centric Identity

OpenID Gives You A Digital Passport

Page 28: Identity 2.0 - OpenID And User Centric Identity

“Proves You Are You”

Page 29: Identity 2.0 - OpenID And User Centric Identity

“Internet Users Either Distrust Or Snore Over Microsoft Passport Live ID”

- Gartner, 2001

Page 30: Identity 2.0 - OpenID And User Centric Identity

OpenID is a simple, open, and decentralized authentication system

Page 31: Identity 2.0 - OpenID And User Centric Identity

OpenIDLive ID/Google/

Adobe/....

Open ! !

Decentralized ! !

Simple ! !

Free ! !

Page 32: Identity 2.0 - OpenID And User Centric Identity

What’s It Good For?

Page 33: Identity 2.0 - OpenID And User Centric Identity

! “Too Many Usernames and Passwords”

Page 34: Identity 2.0 - OpenID And User Centric Identity

We all know this ...

Page 35: Identity 2.0 - OpenID And User Centric Identity
Page 36: Identity 2.0 - OpenID And User Centric Identity

! “Too Many Usernames and Passwords”

! “Someone else took my username”

Page 37: Identity 2.0 - OpenID And User Centric Identity

“martin” is already taken. What about “martin325”?

Page 38: Identity 2.0 - OpenID And User Centric Identity

! “Too Many Usernames and Passwords”

! “Someone else took my username”

! “Not another registration form”

Page 39: Identity 2.0 - OpenID And User Centric Identity
Page 40: Identity 2.0 - OpenID And User Centric Identity
Page 41: Identity 2.0 - OpenID And User Centric Identity
Page 42: Identity 2.0 - OpenID And User Centric Identity
Page 43: Identity 2.0 - OpenID And User Centric Identity
Page 44: Identity 2.0 - OpenID And User Centric Identity
Page 45: Identity 2.0 - OpenID And User Centric Identity

Text

Page 46: Identity 2.0 - OpenID And User Centric Identity
Page 47: Identity 2.0 - OpenID And User Centric Identity
Page 48: Identity 2.0 - OpenID And User Centric Identity
Page 49: Identity 2.0 - OpenID And User Centric Identity
Page 50: Identity 2.0 - OpenID And User Centric Identity
Page 51: Identity 2.0 - OpenID And User Centric Identity
Page 52: Identity 2.0 - OpenID And User Centric Identity
Page 53: Identity 2.0 - OpenID And User Centric Identity

! “Too Many Usernames and Passwords”

! “Someone else took my username”

! “No more registration form”

! “Identity scattered all over the Internet”

Page 54: Identity 2.0 - OpenID And User Centric Identity

!=

Page 55: Identity 2.0 - OpenID And User Centric Identity

Who has one?

Page 56: Identity 2.0 - OpenID And User Centric Identity

> 500 million

“... bringing the grand total of OpenID enabled users on the Internet to well over 500 million users.”

Bill Washburn, July 2008CEO, OpenID Foundation

Page 57: Identity 2.0 - OpenID And User Centric Identity

Come again?

Page 58: Identity 2.0 - OpenID And User Centric Identity

That’s 7,5% of everyone!

Page 59: Identity 2.0 - OpenID And User Centric Identity

Probably far fewer in Africa ....

Page 60: Identity 2.0 - OpenID And User Centric Identity

And far more in Europe and the US

Page 61: Identity 2.0 - OpenID And User Centric Identity

Where’d They All Come From?

Hype?

~250 million

~100 million

~65 million

~10 million

Page 62: Identity 2.0 - OpenID And User Centric Identity

What About Google and Microsoft??

Page 63: Identity 2.0 - OpenID And User Centric Identity
Page 64: Identity 2.0 - OpenID And User Centric Identity
Page 65: Identity 2.0 - OpenID And User Centric Identity
Page 66: Identity 2.0 - OpenID And User Centric Identity
Page 67: Identity 2.0 - OpenID And User Centric Identity
Page 68: Identity 2.0 - OpenID And User Centric Identity
Page 69: Identity 2.0 - OpenID And User Centric Identity

?

Page 70: Identity 2.0 - OpenID And User Centric Identity

?

Page 71: Identity 2.0 - OpenID And User Centric Identity

How Do I Get One?

Page 72: Identity 2.0 - OpenID And User Centric Identity

Less Than A Minute

! Pick A Provider

Page 73: Identity 2.0 - OpenID And User Centric Identity

OpenID Providers

Page 74: Identity 2.0 - OpenID And User Centric Identity

Less Than A Minute

! Pick A Provider

! Sign Up

Page 75: Identity 2.0 - OpenID And User Centric Identity

Less Than A Minute

! Pick A Provider

! Sign Up

! Use It

Page 76: Identity 2.0 - OpenID And User Centric Identity

How Does It Work?

Page 77: Identity 2.0 - OpenID And User Centric Identity

4. Authenticate

2. Associate

1. Go to site

3. Redirect to

OpenID provider5. Redirect back to site

Page 78: Identity 2.0 - OpenID And User Centric Identity
Page 79: Identity 2.0 - OpenID And User Centric Identity
Page 80: Identity 2.0 - OpenID And User Centric Identity
Page 81: Identity 2.0 - OpenID And User Centric Identity

Can I switch OpenID provider and keep my

OpenID.?

Page 82: Identity 2.0 - OpenID And User Centric Identity
Page 83: Identity 2.0 - OpenID And User Centric Identity

So what’s not so great?

Page 84: Identity 2.0 - OpenID And User Centric Identity

4. Authenticate

2. Associate

1. Go to site

3. Redirect to

OpenID provider5. Redirect back to site

A Malicious Relying Party

Page 85: Identity 2.0 - OpenID And User Centric Identity

Leads To ....

Bad Site

Page 86: Identity 2.0 - OpenID And User Centric Identity
Page 87: Identity 2.0 - OpenID And User Centric Identity

Untrusted site redirects you to the trusted provider.

Page 88: Identity 2.0 - OpenID And User Centric Identity

Who Else Does This?

Page 89: Identity 2.0 - OpenID And User Centric Identity

........

Page 90: Identity 2.0 - OpenID And User Centric Identity
Page 91: Identity 2.0 - OpenID And User Centric Identity

! BrittleOpenID is all eggs in one basket.

Page 92: Identity 2.0 - OpenID And User Centric Identity

“I forgot my password”

Page 93: Identity 2.0 - OpenID And User Centric Identity

! Identity Provider Is Single Point Of Failure

Page 94: Identity 2.0 - OpenID And User Centric Identity

4. Authenticate

2. Associate

1. Go to site

3. Redirect to

OpenID provider5. Redirect back to site

Your Identity Provider Knows Where you take It.

Page 95: Identity 2.0 - OpenID And User Centric Identity

Where Can I Take It?

Page 96: Identity 2.0 - OpenID And User Centric Identity

It’s on the rise

Page 97: Identity 2.0 - OpenID And User Centric Identity

“We expect more than 50.000 OpenID enabled sites by then end of 2008.”

Bill Washburn, July 2008CEO, OpenID Foundation

Page 98: Identity 2.0 - OpenID And User Centric Identity
Page 99: Identity 2.0 - OpenID And User Centric Identity

I Want To Know More

Dick Hardt @ OSCON 2005http://identity20.com/media/OSCON2005/

The implications of

Simon WillisonGoogle Tech Talk, 25th June 2007

Simon Willison @ Google Tech Talkhttp://www.youtube.com/watch?v=DslTkwON1Bk

Page 100: Identity 2.0 - OpenID And User Centric Identity

Any Questions?