I mentioned last issue a number of proposed identity protocols (Passport, Cardspace, OpenID, DigitalME, et al.) that have either died or, so far, failed miserably. There’s a new entry in the so-called “user-centric” ID space that shows all the signs of following that path.
The folks at Mozilla, the progenitors of the Firefox browser, among other things, have proposed a new protocol to be dubbed BrowserID.
As outlined by Lloyd Hilaiel: “BrowserID is a decentralized identity system that makes it possible for users to prove ownership of email addresses in a secure manner, without requiring per-site passwords.” He goes on: “BrowserID uses asymmetric cryptography and digital signatures to allow browsers to create signed assertions about the user’s identity, and by identity providers to vouch (via signing of a key-email pair) for a user’s identity in a disconnected fashion. BrowserID uses cross document messaging to communicate between documents served from different domains, which makes a usable implementation of BrowserID possible right now without modifications to existing browsers.”
It’s built into the browser and — most importantly — uses an email address as the credential/username. Multiple personas are ridiculously easy — just use multiple email addresses.
IN PICTURES: 10 must-have Firefox extensions
Other than the email address, though, how does this differ from OpenID?
According to Mozilla:
“BrowserID can be smoothly integrated into the browser.
“Web-based login systems may increase the risk of phishing attacks if users become accustomed to typing their password into a dialog that an untrusted website opens up for them. So, eventually, we want the login activity to happen within an easily recognizable, fully trusted browser UI. Because OpenID was designed primarily for use with zero browser intervention, it’s difficult for the browser to step in and provide that more secure login experience: we’ve tried, and haven’t found the right user experience. Mozilla Labs designed BrowserID with the specific goal of making it easy for browser vendors to implement directly, without preventing pure HTML implementations like the one we deployed yesterday. To explore how the integration of a secure BrowserID user interface could work in a browser, we’re developing a Firefox add-on. And, in parallel, we are open to working with other browser vendors who want the same functionality, of course.”
Of course, that’s also one of it’s biggest problems — it only works within a browser designed for BrowserID. So far that’s some yet-to-be-released version of Firefox. Mozilla is begging other browser vendors (e.g., Microsoft) to go along, but don’t hold your breath.
On top of that, too, are all the authentication ceremonies that take place outside the browser box — what of them? (Mozilla is very quiet on that question.)
Will it succeed? OpenID co-founder Dick Hardt looked at the new protocol and tried hard to like it, but concluded: “While BrowserID has many of the right attributes, it may not succeed because it does not solve the new, emerging pain points.” You’re right once again, Dick.




