* Access to one's data is hindered when identity providers close up shop
Former Network World colleague John Fontana is now writing about IdM issues for Ping Identity. He recently commented upon an issue that may arise more and more in the future as Identity Providers (specifically OpenID Identity Providers) disappear.
Former Network World colleague John Fontana is now writing about IdM issues for Ping Identity. He recently commented upon an issue that may arise more and more in the future as identity providers (specifically OpenID Identity Providers) disappear.
Later this month (on Sept. 30), Six Apart will officially shut down VOX, a blogging site and an OpenID provider. How does this affect people using VOX as their OpenID Identity Provider (IDP)? Fontana explains: “If you have associated your VOX OpenID with services that you regularly use and where you store data, then there will be no one to validate that VOX OpenID.” In effect, “you don’t exist, and worse yet, you have no access rights to your stuff.”
Another friend from Ping, Pam Dingle, outlines how this scenario unfolds:
“It’s Oct. 1, you go to log into, say LiveJournal, with your VOX OpenID. LiveJournal cannot validate you as a user because the VOX service is no longer online. You get a log-in failed message.
“Now you have no access to your account and you will have to go through some sort of help desk hell trying to validate you are who you say you are or you’ll never see your data, photos, etc. ever again.
“While this event isn’t likely to crush a huge number of users under its wheel, it does start to expose some of the issues around OpenID. Can they be solved? Perhaps. The simple solution may be that OpenID IDPs consolidate into a handful of providers such as Google, which doesn’t appear to be going anywhere soon.
“The VOX situation is the kind of scenario that has not yet been in the hype churn of OpenID, but is one that corporate users should be ponderng in any evaluation of consumer ID technologies.”
In fact, this scenario has been scaring off customers of OpenID since the service was first started. The generally accepted workaround is to (where possible) have two separate logins to a service, both accessing all of your data. If one OpenID IDP fails you still have the second to fall back on. Of course that assumes that the service provider allows two separate logins to have administrative access to the single set of data, which is not always true.
This relates directly to OpenID, but would hold true for almost any third-party single sign-on process, especially one that relies on services away from your home domain, or in the cloud. It’s a serious issue which needs to be addressed by any identity provider service you might be thinking of working with.




