150 likes | 247 Views
‘Lord’ was a click away from £229m. “They installed software on the company computers allowing them to steal [Sumitomo bank] staff user names and passwords”. Security vs Usability. Too many web sites, so Weak, memorable passwords Single passwords across multiple sites Undervalued accounts.
E N D
‘Lord’ was a click away from £229m “They installed software on the company computers allowing them to steal [Sumitomo bank] staff user names and passwords”
Security vs Usability • Too many web sites, so • Weak, memorable passwords • Single passwords across multiple sites • Undervalued accounts
Site Site Site Site Site Site Site SECURITY THREAT
Record high Phishing levels Source: Anti Phishing Working Group (non-profit run by David Jevans - IronKey CEO)
Threat Landscape Includes • Keyloggers • XSS vulnerabilities on shared hosting • Nefarious sys admins • Web application security scanners • Your digital identity can be under attack • 24 x 7 x 365
What is OpenID? An open source standard for a free & easy to use digital identity across multiple sites • It is a protocol that OpenID compliant web sites use to talk to OpenID providers • Used by Symantec, Microsoft, AOL, Verisign, Sun, IBM, Yahoo, Google, facebook, the entire population of Estonia
OpenID Demo https://pip.verisignlabs.com/
What about Drupal • OpenID authentication support • D5 via contrib • D6 in core • D7 in core, planned with Oauth • OpenID provider • 6.x-1.x-dev by walkah • Drupalcon DC OpenID code Sprint
Site Provider SECURITY THREAT Site Site Site Site Site
Swekey Demo <site used for talk is taken down> You can try http://blog.to.it
? Site SECURITY THREAT Site Site Site Site Site Provider Multifactor authentication
OpenID benefits • Reduces site registration barrier • Reduces account management overhead • Increases usability and security • Reduces trust required of site admins (multiply by number of accounts) Barriers?
Resources • Anti Phishing Working Group (APWG) • http://www.antiphishing.org • OpenID • http://openid.net • http://wiki.openid.net/Libraries • http://openiddirectory.com • Drupal OpenID Provider module (Walkah) • http://drupal.org/project/openid_provider • Swekey • http://drupal.org/project/swekey • http://www.swekey.com/ • Walkah’s dc2009 talk • http://dc2009.drupalcon.org/session/openid-drupal-and-open-web • http://www.archive.org/details/DrupalconDc2009-OpenidDrupalAndTheOpenWeb • Chris Messina, Lullabot discuss OpenID, opennes, identity • http://www.lullabot.com/audiocast/podcast-71-chris-messina-and-open-identity