Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Security Hardware

Hardware Based OpenID Service Available 119

An anonymous reader writes "TrustBearer Labs has announced a new service that lets you use various hardware based security tokens like smartcards and biometric devices with OpenID. A hardware based connection to OpenID allows higher levels of security and makes it easier for the end-user to control their credentials. OpenID is a decentralized cross-site authentication system that has been gaining momentum for quite a while now with major supporters like AOL, Google and Microsoft already announced."
This discussion has been archived. No new comments can be posted.

Hardware Based OpenID Service Available

Comments Filter:
  • Emulation? (Score:2, Insightful)

    by KublaiKhan ( 522918 ) on Wednesday February 13, 2008 @05:12PM (#22411398) Homepage Journal
    I can appreciate the notion of a hardware dongle of some kind to prove you are you, but right away I can see an easy way around it.

    Once the key has been reverse-engineered, a software emulation thereof can be constructed, and a bit of clever hacking could substitute the software for the hardware.

    Consider MAC address spoofing for what I see as a corollary.
  • Re:Security risks? (Score:3, Insightful)

    by sloth jr ( 88200 ) on Wednesday February 13, 2008 @06:49PM (#22412612)
    Agreed. However, I think in practice, most users use only one or two passwords to login to the vast majority of websites. OpenID thus seems to simply codify this "truism", if I'm on-base. While a centralized password might make mass ownage of websites possible, it should also be simple to shutdown that account across a wide swath of websites more or less instantly.

    sloth jr
  • Re:Security risks? (Score:3, Insightful)

    by Aladrin ( 926209 ) on Wednesday February 13, 2008 @07:11PM (#22412936)
    And nobody is stopping you from doing that. Get multiple OpenIDs. Get them from different providers, if you like. You can still do it your way while the lazy ones (me included) use single sign-on and makes our lives a little simpler.

"A car is just a big purse on wheels." -- Johanna Reynolds

Working...