* Microsoft reaches out to the open source community
It was amazing, a revelation really. I’ve said in the past that Bill Gates didn’t really understand the whole “identity thing” but evidently he’s been taking lessons privately. In case you missed it, during his keynote address at last week’s RSA conference, Gates said:
“And so we actually saw some of the people who were working out in the Web 2.0 land were thinking about these issues of trust, and they came up with this OpenID 2.0. At the same time, we, with a lot of partners, were working on the WS-Security standards. And what we’ve seen is that these two things, one sort of growing up from the blog Web 2.0 world, and one from the enterprise space about federated applications, that they really are very, very complementary, and, in fact, that’s one thing we’re announcing today is that we’re going to support this OpenID 2.0, and there extending what they’ve done so that this credential capability moving beyond passwords, the CardSpace capability, they’re going to have that as a standard capability, partly because they see that it solves some problems, some attacks and some complexity for the user that a pure password approach is always going to have.”
Just last week I mentioned the potential for man-in-the-middle attacks on OpenID. That hasn’t gone unnoticed by others and during the same RSA keynote Microsoft Chief Research and Strategy Officer Craig Mundie addressed it directly:
“So I think with this decision today to really work to bring together formally the OpenID 2.0 plus CardSpace capability, this gives us a tool that where people will say, look, if I have assets that are not super valuable in a Web browser access environment, I can use traditional means. If I actually want a bit more security, but I’m still in a Web browser environment for access, then this marriage of CardSpace and OpenID 2.0 actually is a big step forward, because it eliminates the potential for the man in the middle attack, which was one of the fundamental issues in the OpenID protocol, and we think that’s a really good thing.”
The OpenID community is closely tied to the open-source software movement and some of these folks will be aghast at Microsoft’s embrace – and OpenID hugging right back. Some might try to do to this agreement what they’re trying to do to the Microsoft-Novell agreement (see “Fallout from the Microsoft-Novell agreement continues”) – thwart it at every turn. That would be a big mistake.
There are people inside Microsoft who now believe that Windows will never have 100% penetration and that there’s a need for interoperability with things other than legacy Windows operating systems. These people are in the ascendancy right now, and they should be encouraged. We need to support the meshing of CardSpace and OpenID.
Editor’s Note: Check out Networkworld.com’s latest feature, Microsoft Subnet
Every day, our editors scour the Web to collect the most interesting and important Microsoft-related blogs, news, discussion forums and security alerts and present them to you on one page. At Microsoft Subnet, readers can create their own blogs and comment on the Microsoft news and issues of the day.




