eBay Retires MS Passport Sign-In
fihzy writes "eBay have announced they will retire Microsoft Passport Sign-In and .NET alerts. The Microsoft Passport Directory of Sites has been discontinued, too. Is Microsoft's Single Sign-On vision edging towards oblivion?"
Good Riddance to it!
Tell the truth and you won't have so much to remember.
On one hand its cool if you forget your ID, because you use the site infreqeuently... On the other hand do you trust Microsoft that much?!
Is Microsoft's Single Sign-On vision edging towards oblivion?
It's been dead for a while, people are still cleaning up the carcus.
Michalangelo Progr
As a Webmkaster, I would like to have some simple authentication solution, so that the users dont have to register in forums and what not to post. However, the implementation is just unacceptable:
Small sites who would benefit frim such service don't have $10,000 to throw around, and large sites, which do have the money, just will write their own username+password code.
Why bother to sign in to passport when each user will only run windows longhorn, and each user will have their own account, and the current active account can be queried by the website via some new fancy secure API initiative that will be in longhorn... thus forcing everyone to have to run longhorn in order to do so much as use ebay or amazon...
;)
or perhaps I am suffering from wearing a tinfoil hat too much... but I think I might be on to something... replace passport with something directly tied to windows that users have no choice in, since their machines have unique ID's, as do their accounts... they will not be able to be anonymous on the web, and said info will be used to make browsing easier for average joe q. public, meanwhile identifying every user out on the web... really sneaky...
---
Programming is like sex... Make one mistake and support it the rest of your life.
Well, MS has single sign-in within their MSN zoo, but the idea was outside licensing to sites like eBay. I am not aware of any Yahoo! implementations on the sites outside of its own.
Bad idea, implementation irrelevant.
Instead of having to compromise each site (presumably on a semi-secure server), have just one single entity provide and verify the virutal avatar... based on data resident on a machine administered so incompetently as to have six types of spyware and four spammer worms on it because the underlying operating system is as secure as swiss cheese.
> Small sites who would benefit frim such service don't have $10,000 to throw around, and large sites, which do have the money, just will write their own username+password code.
I've lucky in that got a good "mind" for (secure!) passwords and have no trouble remembering dozens of them.
But even if I didnt... even if I wrote all my userid/password combinations on Post-It notes, a Post-It note resides in an area with reasonably secure physical access controls. Not so with a network-connected PC and a single-signon application.
Passport does have a lot of users, but only for Microsoft stuff. MSN, Hotmail, and Xbox Live, all very popular, use Passport.
(Xbox Live's case is a little more complicated, but it does use Passport at its core.)
Melissa
"Screw Sun, cross-platform will never work. Let's move on and steal the Java language." - Visual J++ Product Manager
Microsoft can trot out a list of companies participating in their latest 'innovation', but no matter how many companies sign up at the start, it really says nothing about the eventual likely success or failure of the system.
Too many people (especially pundits) see such a list and take it as irrefutable evidence that the thing in question is destined to take over the industry.
September 2011: Looking for Cocoa/iOS work in Boston area Cocoa Programmer Quincy, MA
Somehow Microsoft failed to consider that
1) with their record of bad faith toward their own customers and their ongoing security lapses, most knowledgeable end users would not trust Microsoft to manage their personal information, and
2) with their record of bad faith toward their own business partners and their ongoing security lapses, online retailers wouldn't relish the extra burden of sending a monthly tithe to Microsoft.
Luckily Microsoft makes bazillions off Windows and Office and can throw a couple billion here and there on various schemes--gaming, set top boxes, what have you. They know as well as anyone that the commoditization of operating systems and productivity software is underway and they won't be able to maintain their margins forever. If they don't find a cash cow soon they'll be forced to (horrors!) make less money.
The thought of a single web-based logon for access to so many different entities kinda scares me... Especially once it spans across companies.
It's sometimes irritating to remember a number of different logons/passwords, and maybe I'm just paranoid, but I prefer the compartmentalization that separate logons brings.
The Passport concept was, and still is good. I never gave MS's attempt a real chance, because I was annoyed of programs like MSN Messenger and XP Remote Assistance bugging/requiring me to get an account.
Anyway, the idea of a simple username+passport system for the 99% of websites where we care about security "a little" does exist. I think Passport was overengineered. I suspect that a most people will NEVER trust their bank passwords to the same system that holds their Slashdot passwords. Without that level of security, a lot of the engineering and compliance testing and associated costs aren't necessary.
I would imagine that "all" that's needed is a big database, some public key system, and a client-side tool to fill in the login forms. It's not THAT tricky.
I'm imagining someone like Google being able to offer this with relative ease. The GoogleToolbar can handle the client-side for automatic logins, or each site can provide an alternate manual login form. Google can easily handle the distributed database and web services stuff. And the free publicity would be excellent - a lot of smaller sites already have Google Logos for their site search, adding one on the login forms is probably reasonable.
You don't need to use a hotmail.com or msn.com email address to get a Passport. Any email address will work.
I don't want my password to be stored on a computer.
If I did, I would want it to be my computer.
If I didn't want it to be my computer, I wouldn't want it to be on a computer I had to pay for.
And even if I were willing to pay for the inconvience of having someone else be in control of my passwords, I wouldn't want that person to be Microsoft.
Passport was based on a flaw premise;
The reason we don't provide personal information to every site that asks for it isn't because it's too hard to type it in.
-- Should you believe authority without question?
Although MS has suffered from a lot of spectacular failures latelly, anything they do is in danger of becoming main stream. A monopoly on the desktop and office software is a tremendous weapon to wield against the rest of the world.
evil is as evil does
The people at Microsoft are such bullies.. Now give me a bunch of points for being insightful or i'll beat the shit out of you. Now don't tell anyone we had this conversation
This, and the new MS push for signed code as a way of supposedly achieving security (as on the XBox) is all about one thing: MS wants to find a way to own some really important crypto keys. If they own private keys that MUST be used in order for the world to continue functioning, then they get huge amounts of free money with little effort.
For example, take the XBox. To run code on it, you have to have your code signed by Microsoft. For this, they have a private key (whose matching public key every XBox knows). Now they control access to the platform, and if anyone at all wants to sell software that runs on the platform, they must go through Microsoft. And there will be a "small" fee for getting Microsoft to evaluate your code, determine it really is safe, and sign it (or issue a certificate that allows you to sign your own code). Just a nominal fee, not really huge, just enough to make all the people at Microsoft filthy rich.
So, Microsoft is already doing this on the XBox, and their plan is (I think) to spread this wider and wider. Passport failed, but XBox works, and they will at some point try to add this to Windows under the guise of better security (even though it's not -- the XBox has proven that one exploit that allows you to run arbitrary code lets you circumvent the whole system). The goal is to control authentication "on behalf" of other programs, because then you can force everyone who writes any software for the platform to give you money. (All the better if MS can use the RIAA's and MPAA's fears to get them to lobby to restrict individuals' rights to run arbitrary code on their computers.)
email and IM; authenticate using them. this is happening already when you click "forgot password?" and the password is sent to your email. so, in effect your email password is like your only password. changing you email password is kind of like changing ALL your passwords.
why?
the only common communication channel on the internet is email and -a bit less so- IM.
eg.: each time you sign on to a site you can get a different password for each time you log in via email or IM.
--- widget evolution: enhanced, plus, super, ultra, extreme, exxxtreme, ultra-extreme,