Back in the Vietnam War era a popular slogan was, “Suppose they gave a war and no one came?” Well, suppose they created an identity client and no one used it?
Back in the Vietnam War era a popular slogan was “Suppose they gave a war and no one came?” Well, suppose they created an identity client and no one used it?
That’s the sad fate of Windows CardSpace, aka InfoCard. Launched with much fanfare back in 2005, the client technology for Microsoft‘s claims-based identity metasystem was latched onto by many (see, e.g., the Information Card Foundation) as the best solution for a widely available, secure, user-centric identity system. Well, they were mostly right.
HISTORY: Microsoft’s client identity technology now Windows CardSpace
“Widely available” wasn’t how best to describe the system. Microsoft delayed shipping the client and then, when they did, put off for over a year shipping instructions on how to connect to the server. Microsoft wasn’t using the technology in Windows platforms so didn’t want to give others a “leg up.”
Unfortunately, in my opinion, the uppermost management in Redmond once again didn’t take identity technologies (see Active Directory in the late ’90s or the Passport saga) seriously. Not that they’re alone in this. The last few years have seen promising identity technologies judged simply on the merits of their security and/or privacy policies.
Some of us felt (ad still do) that the real benefit of identity technology is the ability to ease the burden of digital existence for users. To allow users to customize their experience, to channel different personas and to personalize what they do. The CardSpace paradigm was ideal for these purposes.
But Microsoft is seemingly blind to that. The announcement of CardSpace’s demise notes that “… we are not abandoning the idea of a user agent for exchanging claims. As part of our work on claims-based identity we are releasing a new technology preview of U-Prove.” U-Prove is very good for protecting privacy, and quite good at securing exchanges — but it isn’t a persona-designing, identity-sharing technology (as CardSpace was) any more than PKI is an e-mail system.
The InfoCard technology is still available. A number of independent projects are still ongoing. But the odds are against these ever progressing past their current state. All the money will go to back security and privacy projects, none will be available for personalization and personification. And that’s a sad state of affairs.




