One step closer to a single sign-on for the web

A new alliance should make it a bit easier to get around the web without accumulating yet more usernames and passwords.

The Open Identity Exchange will enable users of PayPal, Google and Equifax to sign into certain US government websites using their credentials from those sites.

The National Institutes of Health (NIH) is the first government website accepting these credentials. Once signed into the NIH website with, say, a PayPal ID, users can perform customized library searches, access training resources, register for conferences, and contribute to medical research wikis.

Announced today at the RSA Conference in San Francisco, the Open Identity Exchange is funded with initial grants from the OpenID Foundation (OIDF) and Information Card Foundation (ICF).

A number of companies in the private sector already allow the sharing of credentials. The OpenID alliance includes Google, PayPal and others. Facebook is allowing its users to log into thousands of sites with Facebook Connect. And while this is a limited rollout for the government to begin with, it’s another small step in the direction of a single sign-on.

The merits of a single sign-on — one username and password you can use across the web — are debatable. While the convenience might seem appealing, there are serious security concerns. Already, most people use the same password for multiple sites, leaving themselves vulnerable to identity thieves.

The Open Identity Exchange believes it has addressed these concerns by implementing a “trust framework” — a stricter verification process — to comply with the tight security standards of government websites.

“Trusted identities and consumer control of personal information are essential to the effectiveness of transactions on the Internet,” said Andrew Nash, senior director of identity services for PayPal. “Trusted frameworks that provide identity assurance are a critical factor in the success of the digital identity ecosystem.”

FT techfeed

Tech Blog

Analysis & reviews

About this blog Blog guide
Richard Waters, Chris Nuttall and April Dembosky in the FT's San Francisco bureau share their views - plus tech insights from Tim Bradshaw and Maija Palmer in London and Robin Kwong in Taipei.



Read about the authors


To comment, please register for free with FT.com and read our policy on submitting comments.

All posts are published in UK time.

Contact the FT Tech Hub team: richard.waters@ft.com, chris.nuttall@ft.com, april.dembosky@ft.com, maija.palmer@ft.com, robin.kwong@ft.com and tim.bradshaw@ft.com.

See the full list of FT blogs.

Archive

« Feb Apr »March 2010
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  

Tech analysis and reviews

Coding for dummies

Execs learn geek techniques

Time for smartwatches?

Sony synchronises watches with smartphones

Tags

advertising android apple AT&T Electronic Arts Europe Facebook funding google hacking hewlett-packard HP htc instagram intel iPad iphone IPO Jawbone Lenovo London megaupload microsoft Mobile Netflix Nintendo nokia nokia lumia patents privacy samsung smartphones social media social networking Sony SOPA Spotify story of the week Tablets Toshiba twitter venture capital Wikipedia Yahoo Zynga