AGL 40.21 Increased By ▲ 0.18 (0.45%)
AIRLINK 127.64 Decreased By ▼ -0.06 (-0.05%)
BOP 6.67 Increased By ▲ 0.06 (0.91%)
CNERGY 4.45 Decreased By ▼ -0.15 (-3.26%)
DCL 8.73 Decreased By ▼ -0.06 (-0.68%)
DFML 41.16 Decreased By ▼ -0.42 (-1.01%)
DGKC 86.11 Increased By ▲ 0.32 (0.37%)
FCCL 32.56 Increased By ▲ 0.07 (0.22%)
FFBL 64.38 Increased By ▲ 0.35 (0.55%)
FFL 11.61 Increased By ▲ 1.06 (10.05%)
HUBC 112.46 Increased By ▲ 1.69 (1.53%)
HUMNL 14.81 Decreased By ▼ -0.26 (-1.73%)
KEL 5.04 Increased By ▲ 0.16 (3.28%)
KOSM 7.36 Decreased By ▼ -0.09 (-1.21%)
MLCF 40.33 Decreased By ▼ -0.19 (-0.47%)
NBP 61.08 Increased By ▲ 0.03 (0.05%)
OGDC 194.18 Decreased By ▼ -0.69 (-0.35%)
PAEL 26.91 Decreased By ▼ -0.60 (-2.18%)
PIBTL 7.28 Decreased By ▼ -0.53 (-6.79%)
PPL 152.68 Increased By ▲ 0.15 (0.1%)
PRL 26.22 Decreased By ▼ -0.36 (-1.35%)
PTC 16.14 Decreased By ▼ -0.12 (-0.74%)
SEARL 85.70 Increased By ▲ 1.56 (1.85%)
TELE 7.67 Decreased By ▼ -0.29 (-3.64%)
TOMCL 36.47 Decreased By ▼ -0.13 (-0.36%)
TPLP 8.79 Increased By ▲ 0.13 (1.5%)
TREET 16.84 Decreased By ▼ -0.82 (-4.64%)
TRG 62.74 Increased By ▲ 4.12 (7.03%)
UNITY 28.20 Increased By ▲ 1.34 (4.99%)
WTL 1.34 Decreased By ▼ -0.04 (-2.9%)
BR100 10,086 Increased By 85.5 (0.85%)
BR30 31,170 Increased By 168.1 (0.54%)
KSE100 94,764 Increased By 571.8 (0.61%)
KSE30 29,410 Increased By 209 (0.72%)

One single password for the whole internet? It's a dream many have. But reality looks quite different. Usually, every new registration requires a new login and password. Before long, half the time one spends online is used up remembering passwords.
But now, systems like OpenID, Google Friend Connect and Facebook Connect have been created to provide a little help and do away with the never-ending registrations. To do so, they've presented themselves as kinds of skeleton keys for the web. But there is good and bad to these systems.
All the systems are based on the same idea: making sure users no longer have to register a new account for each online service. Instead, these connection services operate on a single sign-on principle, with only one logon needed.
"The idea is to bring your own identity along with you," says Axel Nennker, member of the directorate of the OpenID Foundation, whose day job is with Deutsche Telekom.
It's not just a memory aid, it also boosts security. If a person only needs to remember one password, it can be made more complicated, thus enhancing security.
Amongst the various single sign-on initiatives, OpenID has long been considered the industry standard. Giants like Google, Yahoo, Microsoft and Paypal use the protocol, which was developed in 2005, as do a series of smaller companies. The true number of users is unknown, but likely very large.
The system is designed to be decentralized. Users can set up their OpenID account with a number of sites, whether Google, Yahoo or specialist sites like MyOpenID. Indeed, anyone interested can register on any website that supports the standard. According to numbers released by the OpenID Foundation in 2009, that includes nine million sites world-wide.
Small users overwhelmingly allow access via OpenID, while most larger entities limit themselves to distributing IDs.
Members have to look for the OpenID logo, a gray half-circle with a pointer at one end. When registering, they are asked to enter their OpenID URL. Here, it's best to enter the web address of the entity where the OpenID account was created: yahoo.com, for example.
This opens a window, where access data is entered, as usual - in this case, that for the Yahoo account. The server generates an internet address, or URL and sends it to the destination website, where registration then occurs automatically.
Some websites ask for some basic data, like name and mailing address. Some forums allow anonymous registration.
"Providers like Google only confirm that 'An OpenID user is registering now,'" says Nennker.
Having one identity for multiple websites may sound great, but the system still hasn't made the breakthrough to mainstream use. One problem is that the service remains relatively unknown.
"A lot of users don't even know that they have an OpenID," says Nennker. Google, Yahoo and the others only passively direct users - if they do so at all - to the option. If you don't look for it, you won't find it.
The OpenID Foundation hopes to overhaul the standard. OpenID Connect should be easier to integrate for developers and also provide some improvements for users - such a logins with basic email addresses. There are also plans to expand the service to other technical platforms, like mobile phone apps.
But the competition is picking up, especially since Facebook Connect is coming online.
"Everyone knows what Facebook is. And it's a lot easier to understand that Facebook can manage your identity than it is to believe the same of an unknown entity named OpenID," noted US magazine Wired recently.
Superficially, Facebook Connect and OpenID resemble one another. Clicking on either's icon opens a new window where data is to be entered.
But the US company goes further. Unlike OpenID, as soon as they register - in a discussion forum for example - users can see who else from their social network is already there. Additionally, comments about activities elsewhere can be posted on one's Facebook page for friends to see.
That's one reason why a lot of groups are leaning toward Facebook Connect: "They get a piece of the user pie."
Regardless of Facebook Connect or OpenID, data privacy experts advise using caution.
"Services like Facebook Connect that offer a single sign-on solution can help users save time. But a successful attack on a user account makes the potential of these attacks that much more dangerous and allows the misuse of all data that the user has saved with various services," says Johannes Caspar, data security commissioner for the German city-state of Hamburg. Just looking at some of that access data could open the door for identity theft.

Copyright Deutsche Presse-Agentur, 2011

Comments

Comments are closed.