Skip Links

Network World

  • Social Web 
  • Email 
  • Close

The real deal about IBM, Novell and Project Higgins

A tempest in a teapot
Security: Identity Management Alert By Dave Kearns , Network World , 03/06/2006
Kearns
Sign up for this newsletter now!

Dave Kearns provides the information you need to evaluate, install and maintain your corporate identity management system.

  • Share/Email
  • Comment
  • Print

You must have seen at least one of these headlines last week:

* "Project Higgins: IBM's response to Microsoft InfoCard?"

* "IBM developing online ID system similar to Microsoft's InfoCard"

* "Open Source Higgins Project Takes On Microsoft's InfoCard"

* "IBM And Open Source Allies Prepare To Take On MS' Infocard"

* "IBM Bucks Microsoft's Infocard"

And my personal favorite "Passport's heir gets open source competition"

The one thing they all had in common is that they were all wrong, misleading even. The Higgins Project (as you read here last fall) is a "framework to build user-centric, ID-enabled services." InfoCard, on the other hand, is an application or services for the Windows platform enabling a user to plug their identity into what's called the "identity metasystem," a loosely defined, constantly morphing fabric allowing ID providers and ID consumers to transact ID activity in a secure, privacy-protecting way using the worldwide IP network.

It would be possible to use the Higgins framework to construct a service that participated in the identity metasystem, though it wouldn't necessarily compete with Microsoft's InfoCard but, rather, be complementary to it.

The flap all started when IBM and Novell issued a press release announcing that they would contribute software to the Higgins Project and that IBM would "incorporate Higgins technology within its Tivoli identity management software." This is interesting, because Higgins really is a framework that allows developers to incorporate identity-based services into their applications. Hasn't IBM already integrated identity into its applications?

The situation was further muddled by this quote in the press release from Tony Nadalin, distinguished engineer and chief security architect at IBM: "Open source ensures... that customers won't be locked into a proprietary architecture when they adopt user-centric identity management systems." Reporters and editors took that to be a direct slap at Microsoft. But, as Nadalin explained (via e-mail): "Joining this project was a direct result of customers coming to IBM wanting interoperability with Microsoft Infocards and IBM software (along with interoperability with other identity systems like SXIP, LID, OpenID, etc), so we needed a framework with service interfaces that would allow this to occur and IBM believes it's best if this is done in an open source community."

Dave Kearns is a consultant and editor of IdM, the Journal of Identity Management.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Stock Spam: A Classic Scam

Ever since there have been stocks and shares there have been so called "pump 'n' dump" scams. This...

Spyware: Know Your Enemy

Like Macavity, the fictional feline in T. S. Eliot's well-known poem, spyware may be considered to...

The Online Shadow Economy: A Billion Dollar Market For Malware Authors

Malware, meaning computer viruses, trojans and spyware, is about money. The teenagers who wrote...

Webcasts

SQL Server Consolidation: Insights from customers, analysts & HP

Microsoft SQL Server has enjoyed phenomenal success as a database server. Its relatively low cost,...

Minimizing the Risk of Information Security Breaches: Best Practices for SOA Governance and Compliance - Live October 21

Today's enterprises face more information security risks and vulnerabilities than ever before....

Migrating to Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Special Reports

Unified Threat Management from CheckPoint

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.