Thesis Project on Open ID with Martijn Oostdijk at Novay, Enschede

At Novay (formerly Telematics Institute) people are interested in the OpenID standard for identity management.

Even Microsoft looks like adopting OpenID Microsoft looks like adopting OpenID and the US goverment is building a trust framework to use OpenID for e-government services The result will undoubtably also incorporate aspects of the other two frameworks in the area: Information Card and SAML. These already collaborate with OpenID in here and written up in a more readable form here. Note that it is all built on top of open W3C standard, so that for the end user only requires a standard web brower.

There are some complaints and rumours about the security of OpenID, see for instance

A student of Mads Dam already used some tools on OpenID protocols and software, the authN protocol and a .NET implementation, to be precise:

Questions to be investigated include

Or, to sum us: is the myth that OpenID is unsafe true, and when/where/how could is be safely used?

The intended result should be on overview of security issues and possible measures. Ideally things should be demonstratable, so there's scope for some practical work.

For more info, contact