Feeds

Friends of Sun rally for Passport-killer

They all agree it would be a jolly good thing

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Sun has been hinting for weeks that it's rustling up support for an alternative to Microsoft's version of single-sign-on for web transactions, and it went public today.

The Liberty Alliance Project's mission is quite a mouthful: to create "an open, federated solution for network identity - enabling ubiquitous single sign-on, decentralized authentication and open authorization from any device connected to the internet, from traditional desktop computers and cellular phones through to TVs, automobiles, credit cards and point-of-sale terminals."

The initial roster of "charter members" is interesting: it includes none of Sun's server infrastructure rivals (IBM, Fujitsu-Siemens and Hewlett Paqard are missing, along with the PC OEM crowd) but has an impressive roster of wireless and cellular manufacturers: numbering handset manufacturers (Nokia and Sony), carriers (Sprint, Vodafone, Cingular) and NTT DoCoMo which is both. Smartcard manufacturers including Schlumberger and Gemplus are there, and a few Sun customers who we imagine thought they were signing up for a Free! Prize Draw! of some kind.

Most interesting on the list is the presence of O'Reilly, Apache Group and Collab.net: they're recruited as conscience-keepers, we guess.

The strong roster of phone interests indicates that Sun recognises that the payment platform is likely to involve a smartphone, not a PC. With smartphones set to outnumber PCs at some point in the next decade, that's a good bet. Even without Sun's server rivals, there's enough of the wireless lobby signed on (no pun intended) to give the initiative momentum.

If the announcement looks like it was hurried out, we suspect it was. Until a couple of hours ago spokesmen were stonewalling enquiries on the Charter List membership, after IDG had gotten an advanced copy. And some of the web pages are still titled "Liberty Template".

Quite what technology is to be used is up for grabs, but it's likely to be Java-based given Sun's role in the group's creation, and religiously standards-based: anything else would provide The Beast with a turkey shoot.

At Santa Clara three weeks ago, we spent much of the morning haranguing Greg Papadopoulos and Marge Breya that Sun's web services pitch was essentially meaningless without an open, industry-standard single-sign on.
And this delivers that. Or at least, is the best chance of such an alternative to Passport.

So why aren't we deliriously happy? Well, there's little emphasis so far on privacy. The word appears once in the 979 word FAQ, five words from the end. And privacy is central to consumer acceptance of any kind of digital ID: without essential privacy guarantees the digital ID that Project Liberty requires becomes a back door to all kinds of database pooling - by marketing departments and governments - that isn't possible today. It could even, if we aren't vigilant, become your token for digital content as envisaged by Senator Hollings' SSSCA.

But it's early days as we say, and apparently it's not too late to change the name, either.

The Liberty Alliance Project sounds like one of those fringe libertarian nut websites that are entirely written using huge blinking Times fonts, that advocate legalising smack and helping protect the unborn by issuing them with handguns.

"Liberty is a code name for this formative initiative," says the press release.

Phew. ®

External Link

Project Liberty

Beginner's guide to SSL certificates

More from The Register

next story
Docker's app containers are coming to Windows Server, says Microsoft
MS chases app deployment speeds already enjoyed by Linux devs
'Hmm, why CAN'T I run a water pipe through that rack of media servers?'
Leaving Las Vegas for Armenia kludging and Dubai dune bashing
'Urika': Cray unveils new 1,500-core big data crunching monster
6TB of DRAM, 38TB of SSD flash and 120TB of disk storage
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
SDI wars: WTF is software defined infrastructure?
This time we play for ALL the marbles
Windows 10: Forget Cloudobile, put Security and Privacy First
But - dammit - It would be insane to say 'don't collect, because NSA'
Oracle hires former SAP exec for cloudy push
'We know Larry said cloud was gibberish, and insane, and idiotic, but...'
Symantec backs out of Backup Exec: Plans to can appliance in Jan
Will still provide support to existing customers
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.