Feeds

Microsoft searches for crypto boffin to steer U-Prove tech

Shaken-up identity access group needs new bums on seats

Beginner's guide to SSL certificates

Exclusive Microsoft has quietly been rejigging its identity access group by shunting some of its key engineers out of the way in favour of fresh blood at Redmond's cryptography division, The Register has learned.

Last week the software giant's top identity architect Kim Cameron quit the company, however, Microsoft declined to comment on his departure.

Cameron, too, has so far remained silent about his decision to walk after more than a decade of service at Microsoft.

As we reported last week, Cameron isn't the only potential casualty of a shake-up at the firm. Sources tell us that key players on the identity access team in Redmond, Lee Nackman and Craig Wittenberg, have both been sidelined.

Wittenberg has worked at Microsoft since July 1982, so his removal from the company's ID strategy will likely come as a personal body blow.

Despite the apparent gag applied to Microsoft's current and former employees, who worked in the company's identity and security division, more hints have surfaced that show a new structure is already being put in place.

As we noted last week, Microsoft has been looking to hire "proven top development talent in the areas of identity and access, directory, and cloud platform services (PaaS)". MS technical fellow John Shewchuk's LinkedIn page revealed that particular plan to the world.

El Reg has been busy trying to break the code, and helpfully a job ad from Microsoft has popped up on our radar.

Insert passion here

"The XCG [Microsoft Research's eXtreme Computing Group] Security and Cryptography team is looking for a passionate, strong and experienced cryptography developer to help us improve the U-Prove cryptographic technology to its next level," reads the ad, which was posted by Microsoft on 15 April, a few weeks before ZDNet wrote of Cameron's departure.

"We are combining several anonymous credential technologies and adding new capabilities that will enable users to employ digital credentials for high-value, online transactions while maintaining their privacy; the unlinkability and minimal disclosure capabilities of U-Prove provide an essential basis to meet these needs," the job ad continues.

"The work involves developing cryptographic libraries that implement current and future anonymous credential technologies, and helping a team of applied researchers and developers build more capabilities."

Microsoft said that the ideal candidate for the job would need the obvious high-end developer credentials and, crucially, "the ability to learn new cryptographic algorithms and protocols".

Microsoft bought U-Prove in March 2008 from Credentica, and in recent months the company has blasted its CardSpace tech, which was the brainchild of Cameron and others, into space and released a second preview of U-Prove to help trumpet cloud-based security. The only trouble being that, according to our sources, no one at Microsoft is currently in charge of the U-Prove tech.

Cameron, meanwhile, has tweeted just once since his departure from Microsoft was reported, in which he offers a quotation from Reinhard Posch, the CIO for the Austrian Federal Government, who was speaking at the European Identity Conference.

"The only problem with the cloud is that at some point it will rain." ®

Remote control for virtualized desktops

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.