Is OpenID the Solution to Online Identity Theft?

In March, Dubner and Levitt tackled the realities of identity theft. Now, with phishing scams getting ever cleverer, state government databases leaving sensitive private information accessible to the world, and identity thieves expanding their schemes into Web giants like Facebook, it’s worth asking: how will the problem of identity theft be solved?

Technology innovators have been plugging away, of course, to develop programs that safeguard sensitive information from prowling hackers. One product touted as a possible solution is OpenID, an online protocol that manages a user’s web identity by offering single sign-on for any participating Web site. Surfers never have to enter a username or password to access sites that demand registration, and can navigate between different sites without logging in or out — the equivalent of an online driver’s license. While the program has yet to hit the mainstream, reports estimate that it and similar products are “two to five years away from mainstream adoption.”

On its face, OpenID seems to offer solution-oriented options for managing identity, like allowing users to identify themselves as part of a demographic (i.e. “35-year-old single man in financial services”) instead of typing in birth dates or employment information during registration. Users can add plugins for extra protection like the “SeatBelt Extension,” which lets you know that you’re visiting phishing site like this one. Other benefits include an automatic age verification system for purchases (making online liquor stores a possibility in the U.S.) and the erection of additional spam barriers (though, as countless filters have found, the spammers find a way).

Fans of OpenID have leaped on its bandwagon, including online giants like AOL, Microsoft, and VeriSign, all of which publicly endorse the product. Dick Hardt, the CEO of the Internet security firm Sxip Identity, called it “the next generation of how we manage identity on the Internet.”

Still, the concept has one glaring weakness that even a non-computer science expert can figure out: reduce the number of names and passwords you use on the Internet, and you reduce the amount of information a thief needs to steal. This line of thinking led online security giant Ben Laurie to famously dub OpenID a “Phishing Heaven.” Mike Neuenschwander, vice president and research director of identity and privacy at the
Burton Group, explained Laurie’s logic as follows: “Today, phishers have to set up a site that mimics a legitimate site a user frequents, and then trick the user into offering credentials and other information. With OpenID, such mimicry isn’t even necessary — the user need only be motivated to log into a site using an OpenID.”

With pro and con arguments flying back and forth, the protocol has become a polarizing force in the technology community, as tech bloggers take sides and rarely miss an opportunity to sound off on the debate. Respected figures like Laurie are working with the OpenID community to help solve its problems, but in the short term, this supposed I.D. theft solution won’t be revolutionizing the Internet any time soon.

What does it all mean for the average consumer? As Dubner and Levitt pointed out in their column, almost three-quarters of identity theft victims incur no damages from the crime. Still, until the security community can reach a consensus, it’s worth triple-checking every time you enter your name and personal information into a “Sign In” box. Even if the site looks like CNN.

Leave A Comment

Comments are moderated and generally will be posted if they are on-topic and not abusive.

 

COMMENTS: 44

  1. discordian says:

    A fool and his ID are soon parted.
    hail eris.

    Thumb up 0 Thumb down 0

  2. discordian says:

    A fool and his ID are soon parted.
    hail eris.

    Thumb up 0 Thumb down 0

  3. Drew says:

    If someone with the name Dick Hardt tried to send me an e-mail, it would probably end up being deleted by my spam filter.

    You had a recent column about Aptonyms. How about one for people whose name is glaringly inappropriate for the profession they are in. The CEO of an Internet security firm shouldn’t have a name that looks like the purveyor of pornography or “herbal Viagra.”

    Thumb up 0 Thumb down 0

  4. Drew says:

    If someone with the name Dick Hardt tried to send me an e-mail, it would probably end up being deleted by my spam filter.

    You had a recent column about Aptonyms. How about one for people whose name is glaringly inappropriate for the profession they are in. The CEO of an Internet security firm shouldn’t have a name that looks like the purveyor of pornography or “herbal Viagra.”

    Thumb up 0 Thumb down 0

  5. Michael Hessling says:

    It’s not so easily cracked, Melissa. My OpenID is the address of my web site. I can use it to sign in to any site that supports OpenID, and because I’m the only person with control over my homepage I’m the only person who can use that identity.

    If someone else tries to use my web site address, they’ll be redirected to a page which will ask them to log in. This page merely provides a URL, which you must copy and paste into the address bar, and does not actually let you sign in. This helps prevent, to a great degree, any phishing attempt.

    Simon Willison has a ton of useful articles about OpenID on his blog: http://simonwillison.net/search/?q=openID

    Thumb up 0 Thumb down 0

  6. Michael Hessling says:

    It’s not so easily cracked, Melissa. My OpenID is the address of my web site. I can use it to sign in to any site that supports OpenID, and because I’m the only person with control over my homepage I’m the only person who can use that identity.

    If someone else tries to use my web site address, they’ll be redirected to a page which will ask them to log in. This page merely provides a URL, which you must copy and paste into the address bar, and does not actually let you sign in. This helps prevent, to a great degree, any phishing attempt.

    Simon Willison has a ton of useful articles about OpenID on his blog: http://simonwillison.net/search/?q=openID

    Thumb up 0 Thumb down 0

  7. Bob says:

    Didn’t Microsoft already try this concept several years ago? I think it was called .NET Passport and it failed after a couple years of no one adopting it. Why is OpenID going to be any different?

    Thumb up 0 Thumb down 0

  8. Bob says:

    Didn’t Microsoft already try this concept several years ago? I think it was called .NET Passport and it failed after a couple years of no one adopting it. Why is OpenID going to be any different?

    Thumb up 0 Thumb down 0