<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>danielmiessler.com &#187; OpenID</title>
	<atom:link href="http://danielmiessler.com/categories/openid/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com</link>
	<description>grep understanding</description>
	<lastBuildDate>Thu, 24 May 2012 04:36:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Government and OpenID</title>
		<link>http://danielmiessler.com/blog/government-and-openid</link>
		<comments>http://danielmiessler.com/blog/government-and-openid#comments</comments>
		<pubDate>Thu, 10 Sep 2009 04:44:23 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/government-and-openid</guid>
		<description><![CDATA[Awesome news. Related ContentClickpassGoogle Doing Federated OpenID for Google Apps NowWhat Are You Guys Using For OpenID?Facebook Now Supports OpenIDDISQUS 3 Embraces OpenID]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.techcrunch.com/2009/09/09/us-government-to-embrace-openid-courtesy-of-google-yahoo-paypal-et-al/" title="US Government To Embrace OpenID, Courtesy Of Google, Yahoo, PayPal Et Al.">Awesome news</a>.</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/clickpass" rel="bookmark" class="crp_title">Clickpass</a></li><li><a href="http://danielmiessler.com/blog/google-doing-federated-openid-for-google-apps-now" rel="bookmark" class="crp_title">Google Doing Federated OpenID for Google Apps Now</a></li><li><a href="http://danielmiessler.com/blog/what-are-you-guys-using-for-openid" rel="bookmark" class="crp_title">What Are You Guys Using For OpenID?</a></li><li><a href="http://danielmiessler.com/blog/facebook-now-supports-openid" rel="bookmark" class="crp_title">Facebook Now Supports OpenID</a></li><li><a href="http://danielmiessler.com/blog/disqus-3-embraces-openid" rel="bookmark" class="crp_title">DISQUS 3 Embraces OpenID</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/government-and-openid/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DISQUS 3 Embraces OpenID</title>
		<link>http://danielmiessler.com/blog/disqus-3-embraces-openid</link>
		<comments>http://danielmiessler.com/blog/disqus-3-embraces-openid#comments</comments>
		<pubDate>Wed, 26 Aug 2009 01:17:52 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/disqus-3-embraces-openid</guid>
		<description><![CDATA[Wow, I&#8217;m really enjoying the latest version of the DISQUS comment system. I&#8217;m especially pleased to see support for OpenID added in, and it actually worked exactly as expected. I linked my OpenID URL (danielmiessler.com) to my DISQUS account, and then elected to post a comment to DISQUS using an OpenID profile. Well, since I [...]]]></description>
			<content:encoded><![CDATA[<p>Wow, I&#8217;m really enjoying the latest version of the <a href="http://disqus.com/">DISQUS</a> comment system. I&#8217;m especially pleased to see support for <a href="http://danielmiessler.com/blog/federated-id-openid-and-oauth-a-web-authentication-primer" title="Federated ID, OpenID, and OAuth: A Web Authentication Primer | danielmiessler.com">OpenID</a> added in, and it actually worked exactly as expected.</p>

<p style="text-align:center"><img width="500" height="" src="http://danielmiessler.com/wp-content/uploads/2009/08/disqusopenid.png" alt="disqusopenid" /></p>

<p>I linked my OpenID URL (danielmiessler.com) to my DISQUS account, and then elected to post a comment to DISQUS using an OpenID profile. Well, since I was already logged into my OpenID provider, once I supplied my OpenID I was transparently logged in <em>as my DISQUS account</em>.</p>

<p>Very slick.</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/facebook-now-supports-openid" rel="bookmark" class="crp_title">Facebook Now Supports OpenID</a></li><li><a href="http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail" rel="bookmark" class="crp_title">How to Sign In to Facebook Using Google</a></li><li><a href="http://danielmiessler.com/blog/what-are-you-guys-using-for-openid" rel="bookmark" class="crp_title">What Are You Guys Using For OpenID?</a></li><li><a href="http://danielmiessler.com/blog/google-doing-federated-openid-for-google-apps-now" rel="bookmark" class="crp_title">Google Doing Federated OpenID for Google Apps Now</a></li><li><a href="http://danielmiessler.com/blog/w00t-i-just-posted-my-first-comment-using-openid-2" rel="bookmark" class="crp_title">W00t! I Just Posted My First Comment Using OpenID</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/disqus-3-embraces-openid/feed</wfw:commentRss>
		<slash:comments>160</slash:comments>
		</item>
		<item>
		<title>Password Reset Mechanisms: The Online Security Threat Nobody&#8217;s Talking About</title>
		<link>http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about</link>
		<comments>http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about#comments</comments>
		<pubDate>Tue, 25 Aug 2009 17:24:28 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/?p=6487</guid>
		<description><![CDATA[Humans are notoriously poor at weighing risk. We use emotion, rather than reason, to judge what&#8217;s truly dangerous, which is why most Americans being afraid of handguns in the home more than swimming pools when it comes to child safety. And it&#8217;s the same with online security. People worry about scary hackers penetrating through firewalls [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="200" height="200" src="http://danielmiessler.com/wp-content/uploaded_content/2008/09/security-lock.jpg" alt="securitylock" /></p>

<p>Humans are notoriously poor at weighing risk. <a href="http://www.schneier.com/blog/archives/2007/08/perceptions_of.html">We use emotion, rather than reason, to judge what&#8217;s truly dangerous</a>, which is why most Americans being afraid of handguns in the home more than swimming pools when it comes to child safety.</p>

<p>And it&#8217;s the same with online security. People worry about scary hackers penetrating through firewalls and stealing passwords for websites they use, but the reality&#8211;just like with swimming pools&#8211;is usually much more mundane (and dangerous).</p>

<h2>The Real Threat</h2>

<p>Most people&#8211;and I dare say even most security professionals&#8211;don&#8217;t realize that the greatest vulnerability to online account security doesn&#8217;t come from having multiple passwords spread out over many sites, or even from proposed identity consolidation systems like <a href="http://openid.net/">OpenID</a>. It actually comes from the mother of all single points of failure&#8211;<strong>the email-based password reset mechanism</strong>.</p>

<p>Systems like OpenID are <em>potential</em> points of failure, for some subset of online users, at some point in the future. Email, on the other hand, is a single point of failure for almost everyone&#8211;r<em>ight now</em>.</p>

<p class="offset">Think about it: when you forget your password, how do you reset it for the majority of the sites you use? Right, email. That means that the way into virtually <em>all</em> those different websites is through your email account. In other words, the single most important password you have is the password to your email account.</p>

<h2>The Mother of All Backdoors</h2>

<p>Unfortunately, gaping holes exist in our current online password security systems&#8211;including those on email accounts. The hole comes in the form of question-answer reset systems, whereby you are asked some questions like, &#8220;What&#8217;s the name of your favorite pet?&#8221;, or &#8220;What was the name of your first High School?&#8221; in order to reset your password. These systems constitute a major weakness in online security for the simple reason that <strong>guessing these answers is often much easier than guessing your actual password.</strong></p>

<p>So the bottom line is that if someone can backdoor your email account through a weak reset mechanism, they will then own your single point of failure for all your other online accounts. This is the swimming pool of online attacks because it yields way more passwords per year than super-hackers, but it gets far less attention.</p>

<h2>So What Can We Do?</h2>

<p>Here are the things you can do immediately to improve your online security posture:</p>

<ol>
<li><p><strong>Go, right now, and change your email password.</strong> Make it as complex as possible and don&#8217;t use a scheme or pattern that you&#8217;ve used in the past. Make it around 8 characters (you get diminishing returns beyond that) and make sure to use upper-case, lower-case, numbers, and at least one special character.</p></li>
<li><p><strong>Modify your password reset questions and answers for your email account</strong> (if you have them). If you have the option, create your own questions, and use answers that only you would know. Don&#8217;t be like Sarah Palin (solid advice on a number of levels) and use something that can be looked up (she got her email hacked by using her High School name). If you&#8217;re forced to use canned questions, be tricky: consider answering &#8220;Friday&#8221; for favorite food, or &#8220;7129&#8243; for your favorite pet&#8217;s name.</p></li>
<li><p><strong>Sign up for an OpenID account</strong>. I suggest <a href="http://pip.verisignlabs.com/">PIP from VerisignLabs</a> because they offer a number of two-factor options (I use their soft token). Make this password a good one, and don&#8217;t base it off of any patterns you&#8217;ve used in the past. Pay special attention to your reset mechanisms (see numbers 1 and 2), and enable the two-factor option if at all possible. Enable the requirement on  your OpenID account (PIP) to require that you be signed in before the incoming authentication request be granted.</p></li>
<li><p><strong>For your sensitive accounts (I&#8217;d say this includes social networking sites in most cases) use your OpenID account wherever you can</strong>. And where you do, be sure to change your local, website-based password (which you&#8217;ll be mapping your OpenID to) to something complex. Consider using a password-generator tool for generating and managing those passwords&#8211;something like 1Password or Password Safe. You hopefully won&#8217;t have to use them much, as you&#8217;ll be using your OpenID in most cases.</p></li>
</ol>

<p>These four things should enhance your online security significantly, and doing just the first two will get you a solid measure of the benefits. In an upcoming article I&#8217;ll be looking at some of the password reset mechanisms used by major services, and evaluating the strength of each. ::</p>

<h3>Links</h3>

<p>[ <a href="http://openid.net/" title="OpenID Foundation website">OpenID | openid.net</a> ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security" rel="bookmark" class="crp_title">From Password Reset Mechanisms to OpenID: A Brief Discussion of Online Password Security</a></li><li><a href="http://danielmiessler.com/blog/paypal-and-two-factor-authentication-a-weakest-link-case-in-point" rel="bookmark" class="crp_title">PayPal and Two-Factor Authentication: A &#8220;Weakest Link&#8221; Case in Point</a></li><li><a href="http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication" rel="bookmark" class="crp_title">The Connected Web: Why It&#8217;s Time For Strong Authentication</a></li><li><a href="http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail" rel="bookmark" class="crp_title">How to Sign In to Facebook Using Google</a></li><li><a href="http://danielmiessler.com/blog/lame-online-password-logic" rel="bookmark" class="crp_title">Lame Online Password Logic</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>From Password Reset Mechanisms to OpenID: A Brief Discussion of Online Password Security</title>
		<link>http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security</link>
		<comments>http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security#comments</comments>
		<pubDate>Mon, 24 Aug 2009 05:50:50 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/from-openid-to-email-resets-a-discussion-of-online-password-security</guid>
		<description><![CDATA[For those not familiar, OpenID is a system that allows you to sign in to multiple websites using one identity. So, rather than have a different username and password for each site, you would just sign into each one using your OpenID credentials. In addition to the convenience this offers, there&#8217;s a security benefit in [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="200" height="200" src="http://danielmiessler.com/wp-content/uploaded_content/2008/09/security-lock.jpg" alt="securitylock" /></p>

<p>For those not familiar, <a href="http://openid.net/" title="OpenID Foundation website">OpenID</a> is a system that allows you to sign in to multiple websites using one identity. So, rather than have a different username and password for each site, you would just sign into each one using your OpenID credentials. In addition to the convenience this offers, <strong>there&#8217;s a security benefit in that the websites you use OpenID with don&#8217;t ever see the password you entered to gain access to their site</strong>.</p>

<p>This works by delegating the authentication out to the OpenID provider. Essentially, <strong>OpenID-enabled websites trust OpenID providers</strong>, so when you go to a given OpenID website it redirects you to your provider, where you log in with your OpenID credentials. You are then seamlessly redirected back to the site, and your provider tells the site in the background, &#8220;This person is good to go&#8230;&#8221;</p>

<p>So at that point you&#8217;re authenticated to the site without it ever having seen your password, and you didn&#8217;t have to click around to multiple sites: it all happened with a single login. This is stellar, but there&#8217;s a downside.</p>

<h2>The &#8216;Eggs and Baskets&#8217; Counterargument</h2>

<p>While the scenario above keeps websites from getting your OpenID password during legitimate website logins, many have raised a valid question:</p>

<blockquote>If you are logging into all these websites with one set of credentials, doesn&#8217;t that increase the damage that can be done if your OpenID password is compromised?</blockquote>

<p>Without question, the answer is yes. But that doesn&#8217;t mean necessarily that consolidating on an OpenID identity is less secure; the risk assessment is more complex than that. And that&#8217;s where the discussion gets interesting.</p>

<h2>Tradeoffs</h2>

<p>So, we&#8217;ve established that OpenID keeps indvidual websites from having access to your passwords. We know that is good, so we&#8217;ll mark that as a positive. We also know that putting all one&#8217;s security eggs in one password basket increases the impact of a password compromise&#8211;so that&#8217;s a negative.</p>

<p>We can also add the following assumptions pretty safely:</p>

<ol>
<li>users tend to use poor passwords</li>
<li>users share these poor passwords across websites and services</li>
<li>therefore, a compromise at one site often leads to a compromise at others</li>
</ol>

<p>So the question really becomes:</p>

<blockquote>Which presents more risk: weak and/or similar passwords used across multiple sites that have different security measures protecting those passwords&#8211;meaning one or more is likely to be guessed and
compromised, <strong>or</strong> a stronger, single OpenID that&#8217;s protected in a known and trusted way yet  resents a single point of failure?</blockquote>

<p>There&#8217;s also another downside to OpenID that must be factored in: <em>the phishing threat</em>. This is where a user <em>thinks</em> he/she is being redirected to log into their OpenID provider, when in fact they are being shown an attacker&#8217;s website. So, when they enter their credentials the bad guy has just stolen the password not just to one site, but to every site they use OpenID with.</p>

<p style="text-align:center"><img width="200" height="200" src="http://danielmiessler.com/wp-content/uploads/2009/08/phishing.jpeg" alt="phishing" /></p>

<p>But again, we don&#8217;t want to give the impression that OpenID is any more prone to phishing than any other service&#8211;it&#8217;s not. The issue isn&#8217;t an increased ease of compromise of OpenID credentials (there isn&#8217;t any), but rather the increased damage that could result if they <em>were</em> compromised.</p>

<p>But if you think that&#8217;s bad, it&#8217;s nothing compared to the danger we already face today.</p>

<h2>The Weakest Link: Email Password Reset Mechanisms</h2>

<p>Most people&#8211;and I dare say even most security professionals&#8211;don&#8217;t realize
that the greatest vulnerability to website password security doesn&#8217;t come
from having multiple passwords spread out over many sites. It actually
comes from the mother of all single points of failure&#8211;the email-based
password reset mechanism.</p>

<p>OpenID is a <em>potential</em> single point of failure, for some subset of
online users, at some point in the future. Email, on the other hand, is a
single point of failure for almost everyone&#8211;right now.</p>

<p class="offset">Think about it: when you forget your password, how do you
reset it for the majority of the sites you use? Right, email. That means
that the way into virtually <em>all</em> those different websites is
through your email account. This leads us to a startling conclusion: the
absolute most important password you have is the password to your email
account.</p>

<p>The other backdoor into your accounts is the question-answer system whereby
you are asked some questions like, &#8220;What&#8217;s the name of your favorite pet?&#8221;,
or &#8220;What was the name of your first High School?&#8221; These systems constitute
a major weakness in online security for the simple reason that
<strong>guessing these answers is often much easier than guessing your
password.</strong></p>

<p class="banner_ad">
<script type="text/javascript"><!--
google_ad_client = "pub-2677272500934866";
/* Blog_Content_468x60 */
google_ad_slot = "2329464279";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</p>

<h2>A Risk Discussion</h2>

<p>Ok, so now we&#8217;ve laid some things out on the table: multiple weak passwords spread across sites, single points of failure, etc.&#8211;let&#8217;s look at them, and see where the risk tradeoffs lead us. Keep in mind: while I am experienced in information security this analysis definitely subject to interpretation. Follow me along in my logic and let me know if you disagree.</p>

<h3>Many Weak Passwords vs. Single Point of Failure with OpenID</h3>

<p>First off, I&#8217;d say that using an OpenID with a solid provider, a strong password (preferably with two-factor authentication) is going to yield an overall more secure posture for the average user than that same person using weak passwords (which are often shared) on individual websites. The key here is that if any of those passwords on those multiple sites are cracked, via whatever method, it&#8217;s likely to lead to the cracking of other sites as well.</p>

<h3>Phishing</h3>

<p>The phishing narrative, which is often relayed in order to dissuade people  from considering OpenID, is not nearly as compelling as it appears. This is because that same attack would work today, for those same users who&#8217;d be vulnerable to an OpenID phish, if they were to be sent to a fake GMail or Yahoo! Mail login. That attack is rather trivial, and looks something like this:</p>

<ol>
<li>Capture the victim&#8217;s email password via phishing</li>
<li>Use the password reset mechanism at the various sites you want to crack of theirs</li>
<li>Collect and reset those passwords from the compromised email account</li>
</ol>

<p>In other words, this attack is nearly identical to the hypothetical OpenID single-point-of-failure (SPOF) attack, but email account phishing is a single point of failure that most everyone has, so it&#8217;s a threat <em>right now</em>.</p>

<p style="text-align:center"><img width="200" height="150" src="http://danielmiessler.com/wp-content/uploads/2009/08/keylock.jpeg" alt="keylock" /></p>

<h2>So What Do We Do?</h2>

<p>So here are the things you can do immediately to improve your online security posture:</p>

<ol>
<li><p><strong>Go, right now, and change your email password.</strong> Make it as complex as
possible and don&#8217;t use a scheme or pattern that you&#8217;ve used in the past.
Make it around 8 characters (you get diminishing returns beyond that) and
make sure to use upper-case, lower-case, numbers, and at least one special
character.</p></li>
<li><p><strong>Modify your password reset questions and answers for your email account</strong>
(if you have them). If you have the option, create your own questions, and
use answers that only you would know. Don&#8217;t be like Sarah Palin (solid advice on a number of levels) and use something that can be looked up (she got her email hacked by using her High School name). If you&#8217;re forced to use canned questions, be tricky: consider answering &#8220;Friday&#8221; for favorite food, or &#8220;7129&#8243; for your favorite pet&#8217;s name.</p></li>
<li><p><strong>Sign up for an OpenID account</strong>. I suggest <a href="http://pip.verisignlabs.com/">PIP from VerisignLabs</a> because they offer a number of two-factor options (I use their soft token). Make this password a good one, and don&#8217;t base it off of any patterns you&#8217;ve used in the past. Pay special attention to your reset mechanisms (see numbers 1 and 2), and enable the two-factor option if at all possible. Enable the requirement on  your OpenID account (PIP) to require that you be signed in before the incoming authentication request be granted.</p></li>
<li><p><strong>For your sensitive accounts (I&#8217;d say this includes social networking sites in most cases) use your OpenID account wherever you can</strong>. And where you do, be sure to change your local, website-based password (which you&#8217;ll be mapping your OpenID to) to something complex. Consider using a password-generator tool for generating and managing those passwords&#8211;something like 1Password or Password Safe. You hopefully won&#8217;t have to use them much, as you&#8217;ll be using your OpenID in most cases.</p></li>
</ol>

<p>These four things should enhance your online security significantly, and doing just the first two will get you a solid measure of the benefits. Also, if you have anything to add to this analysis, or if you think I&#8217;ve mishandled or omitted something, please do let me know in the comments. ::</p>

<h3>Links</h3>

<p>[ <a href="http://openid.net/" title="OpenID Foundation website">OpenID</a> ]<br />
[ <a href="http://en.wikipedia.org/wiki/Phishing" title="Phishing - Wikipedia, the free encyclopedia">Phishing</a> ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about" rel="bookmark" class="crp_title">Password Reset Mechanisms: The Online Security Threat Nobody&#8217;s Talking About</a></li><li><a href="http://danielmiessler.com/blog/implementing-openid" rel="bookmark" class="crp_title">Implementing OpenID</a></li><li><a href="http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail" rel="bookmark" class="crp_title">How to Sign In to Facebook Using Google</a></li><li><a href="http://danielmiessler.com/blog/federated-id-openid-and-oauth-a-web-authentication-primer" rel="bookmark" class="crp_title">Federated ID, OpenID, and OAuth: A Web Authentication Primer</a></li><li><a href="http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication" rel="bookmark" class="crp_title">The Connected Web: Why It&#8217;s Time For Strong Authentication</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to Sign In to Facebook Using Google</title>
		<link>http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail</link>
		<comments>http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail#comments</comments>
		<pubDate>Mon, 17 Aug 2009 02:34:29 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail</guid>
		<description><![CDATA[&#160;&#160; So you have a Facebook account, right? And you use Google Mail, right? Good, then this is for you. It&#8217;s just recently become possible for you to sign into Facebook automagically, i.e. without entering your Facebook username and password, just because you&#8217;re already signed into GMail. It&#8217;s full of win. The wholesomeness that allows [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="90" height="90" src="http://danielmiessler.com/wp-content/uploads/2009/08/facebook_square_icon.png" alt="facebook_square_icon" /> &nbsp;&nbsp;<img width="85" height="85" src="http://danielmiessler.com/wp-content/uploads/2009/08/google_icon.png" alt="google_icon" /><br />
<img width="180" height="60" src="http://danielmiessler.com/wp-content/uploads/2009/08/openid_logo.gif" alt="openidlogo" /></p>

<p>So you have a <a href="http://www.facebook.com/" title="Facebook">Facebook</a> account, right? And you use <a href="http://www.google.com/mail">Google Mail</a>, right? Good, then this is for you. It&#8217;s just recently become possible for you to sign into Facebook automagically, i.e. without entering your Facebook username and password, just because you&#8217;re already signed into GMail. It&#8217;s full of win.</p>

<p><span style="float: left; margin: 0px 10px 10px 0px;"><img width="75" height="75" src="http://danielmiessler.com/wp-content/uploads/2009/08/eyedentity.png" alt="identity" /></p>The wholesomeness that allows this to happen is called <a href="http://openid.net/" title="OpenID Foundation website">OpenID</a>, which is a powerful technology that you probably want to start paying attention to. It allows you to use one online identity on many different websites, and it keeps you from having to give your password to the sites you use. Basically, it offers:</p>

<ol>
<li><strong>Convenience:</strong> faster registration on new sites: get setup in seconds</li>
<li><strong>Simplicity:</strong> a single username and password to remember</li>
<li><strong>Security:</strong> you don&#8217;t give websites your password</li>
</ol>

<p>If you&#8217;re interested in more details, I just finished a piece on web auth technologies <a href="http://danielmiessler.com/blog/federated-id-openid-and-oauth-a-web-authentication-primer" title="Federated ID, OpenID, and OAuth: A Web Authentication Primer | danielmiessler.com">here</a>, but the point is that OpenID is blowing up. Everyone&#8217;s getting into it: Google, Yahoo, Facebook, Verisign&#8230;<em>everyone</em>. The big players who aren&#8217;t there now will be soon.</p>

<h2>Facebook + Google = OpenID</h2>

<p><span style="float: right; margin: 0px 0px 5px 5px;"><img width="100" height="100" src="http://danielmiessler.com/wp-content/uploads/2009/08/handshake.png" alt="handshake" /></p>So, two of the companies that are embracing OpenID the most are Facebook and Google, but in different roles. Within the OpenID system you can be an <em>Identity Provider</em> (someone that websites trust to provide authenticated users), or a <em>Relying Party</em> (a website that has services and wants to accept users from an Identity Provider).</p>

<p>Well, Google is now the behemoth of Identity Providers, and Facebook is now the Grand Pubah of OpenID Relying Parties. It&#8217;s a phenomenal combination for users. In other words, Facebook is saying to the world:</p>

<blockquote>We accept Google users as valid users, so if you show up to Facebook and you&#8217;re already signed into Google, you&#8217;re considered legitimate to us, and we don&#8217;t need to authenticate you further.</blockquote>

<h2>Setup</h2>

<p style="text-align:center"><img width="400" height="" src="http://danielmiessler.com/wp-content/uploads/2009/08/settings.png" alt="settings" /></p>

<p>So here&#8217;s how to get going&#8211;in like two minutes. First, sign into Facebook normally&#8211;using your Facebook username and password&#8211;and go to your Settings. On the default, left-most tab you&#8217;ll have a section called &#8220;Linked Accounts&#8221;. Click &#8220;Change&#8221; there to add an account.</p>

<p style="text-align:center"><img width="400" height="" src="http://danielmiessler.com/wp-content/uploads/2009/08/add_account.png" alt="add_account" /></p>

<p>Select &#8220;Google&#8221; from the pull down menu and you&#8217;ll be asked to allow Facebook and Google to interact. Once you&#8217;ve authorized the connection your two accounts are linked! Now sign out of Facebook (but stay logged in to your Google account) and then go to the Facebook homepage. <strong>You&#8217;ll see some trickery taking place in the URL bar, and then you&#8217;ll be logged into Facebook without having to enter anything!</strong></p>

<p style="text-align:center"><img width="400" height="" src="http://danielmiessler.com/wp-content/uploads/2009/08/linked.png" alt="linked" /></p>

<p class="offset">The way this works is just like when you enter an OpenID identity manually on a site: you&#8217;re getting transparently redirected to the OpenID provider (Google, in this case) where Facebook confirms that you&#8217;re already logged in and subsequently lets you into the site.<br /><br />The only difference is, instead of you providing an OpenID through a login form, Facebook already knows where to redirect you based on the previous &#8220;Linked Accounts&#8221; step.</p>

<p>Notice that you can also add a number of other account links as well, including various OpenID providers, and Yahoo! My favorite, however, is Verisign PIP, because it allows me to use <a href="http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" title="Verisign VIP for Two-Factor Authentication, and PIP for OpenID | danielmiessler.com">two-factor authentication</a> to access my OpenID provider.</p>

<p>Anyway, enjoy your new transparent login to Facebook through Google, and keep your eye out for more OpenID developments around the web. ::</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/facebook-now-supports-openid" rel="bookmark" class="crp_title">Facebook Now Supports OpenID</a></li><li><a href="http://danielmiessler.com/blog/disqus-3-embraces-openid" rel="bookmark" class="crp_title">DISQUS 3 Embraces OpenID</a></li><li><a href="http://danielmiessler.com/blog/federated-id-openid-and-oauth-a-web-authentication-primer" rel="bookmark" class="crp_title">Federated ID, OpenID, and OAuth: A Web Authentication Primer</a></li><li><a href="http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication" rel="bookmark" class="crp_title">The Connected Web: Why It&#8217;s Time For Strong Authentication</a></li><li><a href="http://danielmiessler.com/blog/implementing-openid" rel="bookmark" class="crp_title">Implementing OpenID</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail/feed</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>Facebook Now Supports OpenID</title>
		<link>http://danielmiessler.com/blog/facebook-now-supports-openid</link>
		<comments>http://danielmiessler.com/blog/facebook-now-supports-openid#comments</comments>
		<pubDate>Tue, 19 May 2009 03:52:31 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/facebook-now-supports-openid</guid>
		<description><![CDATA[Exciting stuff&#8211;Facebook is rolling out full support for OpenID. Once it&#8217;s done being pushed to all users, you&#8217;ll be able to log in seamlessly to Facebook if you&#8217;re already logged into your OpenID provider. Combine this with two-factor authentication from PIP, and things are shaping up nicely. Oh, and they&#8217;re supporting seamless logon from Google [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="200" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/vip.jpg" alt="pip" /></p>

<p>Exciting stuff&#8211;Facebook is rolling out full support for OpenID. Once it&#8217;s done being pushed to all users, you&#8217;ll be able to log in seamlessly to Facebook if you&#8217;re already logged into your OpenID provider.</p>

<p>Combine this with <a href="http://dmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" title="Verisign VIP for Two-Factor Authentication, and PIP for OpenID | dmiessler.com">two-factor authentication from PIP</a>, and things are shaping up nicely.</p>

<p>Oh, and they&#8217;re supporting seamless logon from Google as well. Very cool stuff. ::</p>

<p class="post_update">[ 2009-05-19 : Confirmed--I just logged out of Facebook and re-visited the homepage while logged into my OpenID provider (with two-factor, mind you). It seamlessly logged me in. Totally sick. ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/sign-in-to-facebook-transparently-just-by-being-signed-into-google-gmail" rel="bookmark" class="crp_title">How to Sign In to Facebook Using Google</a></li><li><a href="http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" rel="bookmark" class="crp_title">Verisign VIP for Two-Factor Authentication, and PIP for OpenID</a></li><li><a href="http://danielmiessler.com/blog/disqus-3-embraces-openid" rel="bookmark" class="crp_title">DISQUS 3 Embraces OpenID</a></li><li><a href="http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication" rel="bookmark" class="crp_title">The Connected Web: Why It&#8217;s Time For Strong Authentication</a></li><li><a href="http://danielmiessler.com/blog/paypal-and-two-factor-authentication-a-weakest-link-case-in-point" rel="bookmark" class="crp_title">PayPal and Two-Factor Authentication: A &#8220;Weakest Link&#8221; Case in Point</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/facebook-now-supports-openid/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Verisign PIP OpenID Delegation Code</title>
		<link>http://danielmiessler.com/blog/verisign-pip-openid-delegation-code</link>
		<comments>http://danielmiessler.com/blog/verisign-pip-openid-delegation-code#comments</comments>
		<pubDate>Mon, 14 Apr 2008 20:11:26 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/verisign-pip-openid-delegation-code</guid>
		<description><![CDATA[So I just started using the PIP service from Verisign to handle my OpenID. It&#8217;s a pretty solid OpenID implementation from what I&#8217;ve seen and has the added bonus of supporting two-factor authentication via the token seen above. But I was having a problem with delegation, which is where you can enter your own URL [...]]]></description>
			<content:encoded><![CDATA[<p>So I just started using the <a href="http://pip.verisignlabs.com/">PIP</a> service from <a href="http://www.verisign.com/" title="VeriSign - Security (SSL Certificates), Intelligent Communications, Domain Name Services, and Identity Protection">Verisign</a> to handle my <a href="http://openid.net/" title="OpenID">OpenID</a>. It&#8217;s a pretty solid OpenID implementation from what I&#8217;ve seen and has the added bonus of supporting two-factor authentication via the token seen above. </p>

<p>But I was having a problem with delegation, which is where you can enter your own URL for your identifier (think username) when signing in to an OpenID-enabled site.</p>

<p>I was told to use this:</p>

<p>[html]<link rel="openid.server" href="https://pip.verisignlabs.com/server/" />
<link rel="openid.delegate" href="http://username.pip.verisignlabs.com/" />
<meta http-equiv="X-XRDS-Location" content="http://pip.verisignlabs.com/user/username/yadis" />
<meta http-equiv="X-YADIS-Location" content="http://pip.verisignlabs.com/user/username/yadis" />[/html]</p>

<p>&#8230;but that doesn&#8217;t work when signing into certain sites, such as <a href="http://idgang.idcommons.net/" title="Identity Gang - IdCommons">the Identity Gang Wiki</a>. You can sign into it using your full PIP URL, but not using delegation with the code seen above.</p>

<p>So I talked to the nice folks at Verisign and was put in touch with Gary Krall. He was most helpful. We determined that my delegation code wasn&#8217;t quite what it needed to be. </p>

<p>He suggested the following, which worked great:</p>

<p>[html]<link rel="openid.server" href="http://pip.verisignlabs.com/server" /> 
<link rel="openid.delegate" href="http://username.pip.verisignlabs.com" />
<link rel="openid2.server" href="http://pip.verisignlabs.com/server" />
<link rel="openid2.local_id" href="http://username.pip.verisignlabs.com" />
<meta http-equiv="X-XRDS-Location" content="http://pip.verisignlabs.com/user/username/yadisxrds" />[/html]</p>

<p>That worked for me and should for you as well, but I got curious and decided to see if I could optimize that at all. As it turns out, <a href="http://openid.net/specs/openid-authentication-2_0.html" title="Final: OpenID Authentication 2.0 - Final">the OpenID 2.0 Spec located here</a> allowed me to trim down the required code significantly:</p>

<p>[html]<link rel="openid2.provider openid.server" href="http://pip.verisignlabs.com/server"/>
<link rel="openid2.local_id openid.delegate" href="http://username.pip.verisignlabs.com"/>
<meta http-equiv="X-XRDS-Location" content="http://pip.verisignlabs.com/user/username/yadisxrds" />[/html]</p>

<p>This also works and has the added benefit of the first two lines coming from <a href="http://openid.net/specs/openid-authentication-2_0.html" title="Final: OpenID Authentication 2.0 - Final">the official spec</a>. Plus, it&#8217;s only three lines total. The third line might still be a bit of an imperfect hack, but I couldn&#8217;t get it to work using the official recommendation.</p>

<p>Anyway, that last snippet should get you working with delegation and <a href="https://pip.verisignlabs.com/">Verisign PIP</a> with the least amount of the most compliant code possible. That is, at least until I figure out how to do the XRDS bit properly according to the 2.0 spec.</p>

<p class="post_update">[ <strong>Edit: Please note that some sites like LiveJournal still use the 1.0 specification and will fail with the trimmed down version. I re-added the 1.0 bits and the code below is the final version I have running.</strong>  ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" rel="bookmark" class="crp_title">Verisign VIP for Two-Factor Authentication, and PIP for OpenID</a></li><li><a href="http://danielmiessler.com/blog/rsa-day-1" rel="bookmark" class="crp_title">RSA: Day 1</a></li><li><a href="http://danielmiessler.com/blog/implementing-openid" rel="bookmark" class="crp_title">Implementing OpenID</a></li><li><a href="http://danielmiessler.com/blog/facebook-now-supports-openid" rel="bookmark" class="crp_title">Facebook Now Supports OpenID</a></li><li><a href="http://danielmiessler.com/blog/disqus-3-embraces-openid" rel="bookmark" class="crp_title">DISQUS 3 Embraces OpenID</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/verisign-pip-openid-delegation-code/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>W00t! I Just Posted My First Comment Using OpenID</title>
		<link>http://danielmiessler.com/blog/w00t-i-just-posted-my-first-comment-using-openid-2</link>
		<comments>http://danielmiessler.com/blog/w00t-i-just-posted-my-first-comment-using-openid-2#comments</comments>
		<pubDate>Fri, 14 Mar 2008 04:00:13 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/w00t-i-just-posted-my-first-comment-using-openid-2</guid>
		<description><![CDATA[I just posted my first comment using OpenID (that worked). I&#8217;ve tried a few other things that use OpenID with my own server as my endpoint and I&#8217;ve had limited success. But Blogspot seems to be on top of things. Related ContentWhat Are You Guys Using For OpenID?DISQUS 3 Embraces OpenIDImplementing OpenIDFacebook Now Supports OpenIDGoogle [...]]]></description>
			<content:encoded><![CDATA[<p>I just posted <a href="http://gdfisk.blogspot.com/2008/03/digital-immigrants-and-digital-natives.html/">my first comment</a> using <a href="http://openid.net/" title="OpenID">OpenID</a> (that worked). I&#8217;ve tried a few other things that use OpenID with my own server as my endpoint and I&#8217;ve had limited success. But <a href="http://blogspot.com/" title="Blogspot">Blogspot</a> seems to be on top of things.</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/what-are-you-guys-using-for-openid" rel="bookmark" class="crp_title">What Are You Guys Using For OpenID?</a></li><li><a href="http://danielmiessler.com/blog/disqus-3-embraces-openid" rel="bookmark" class="crp_title">DISQUS 3 Embraces OpenID</a></li><li><a href="http://danielmiessler.com/blog/implementing-openid" rel="bookmark" class="crp_title">Implementing OpenID</a></li><li><a href="http://danielmiessler.com/blog/facebook-now-supports-openid" rel="bookmark" class="crp_title">Facebook Now Supports OpenID</a></li><li><a href="http://danielmiessler.com/blog/google-doing-federated-openid-for-google-apps-now" rel="bookmark" class="crp_title">Google Doing Federated OpenID for Google Apps Now</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/w00t-i-just-posted-my-first-comment-using-openid-2/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

