Microsoft Finds Unlikely InfoCard AllyBy Ryan Naraine | Print
At the RSA Conference, Verisign announces that its new identity protection network would work seamlessly with InfoCard, dispelling the notion of a brewing rivalry.
SAN JOSE, Calif.Microsoft has found an unlikely backer for its ambitious InfoCard online ID management system.
At the RSA Conference here, Verisign dispelled the notion of a rivalry with Microsoft over identity management and announced that its new VIP (Verisign Identity Protection) networkwhich is backed by Yahoo and eBaywill work seamlessly with InfoCard in Windows Vista and Internet Explorer 7.
The surprising partnership is a big boost to Microsoft's efforts to use authentication technologies to strengthen online transaction security and thwart the escalating phishing scourge.
Verisign chief executive Stratton Sclavos used the spotlight of his keynote to outline how the two authentication technologies would work together to allow users to access both systems without complications.
The partnership clears the way for new technology to handle what is described as "mutual authentication" on the Internet.
Mutual authentication requires that both the destination site and the consumer positively identify each other.
It promises authentication that cannot be phished or spoofed because users aren't tricked into entering personal information on fake sites.
On stage, the company showed how a Web surfer could sign on to Microsoft's InfoCard and gain access to Verisign's VIP network using a password created by a cell phone or a USB key made by VIP hardware partners.
With full support, a customer would be able to use Microsoft's technology to access Web sites that support Verisign's authentication network.
"If we make [identity management] too hard, users will choose less security every time. We have to get to a place where we've created one network and all of this just works," Sclavos said.
The idea that the two companies would be hard-nosed competitors in the space was driven by Verisign's recent announcement that VIP would allow customers to use a single authentication credential across Web sites that support VIP.
eBay and its PayPal transaction service will enable VIP along with Yahoo's e-commerce properties.
Verisign said SanDisk and Motorola had already signed on to support the project with USB devices and cell phones.
Verisign's announcement comes less than 24 hours after Microsoft chairman Bill Gates urged an industry-wide push toward trust-based, multifactor authentication systems to help solve the clutter of dealing with multiple passwords for different Web-based accounts.
Gates described existing password systems as a major "weak link" and promised technology to help businesses move away from depending on complex password management policies.
"Password systems [today] just aren't cutting it," Gates said. "I'm not pretending that we're going to move away from passwords overnight, but for corporate systems, this change can happen over three to four years."
The Redmond, Wash.-based software maker is working on a set of technologies built on an identity metasystem, starting with InfoCard, which is to be delivered as part of WinFX, the company's managed code programming model.
InfoCard will support Windows Internet Explorer 7 on Windows Vista, Windows XP Service Pack 2, and Windows Server 2003 Service Pack 1 and R2.
Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.