<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Estonia issuing Smart-cards for OpenID logins?</title>
	<atom:link href="http://blog.ironkey.com/?feed=rss2&#038;p=119" rel="self" type="application/rss+xml" />
	<link>http://blog.ironkey.com/?p=119</link>
	<description>A blog by Dave Jevans</description>
	<lastBuildDate>Sun, 08 Aug 2010 18:07:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Martin Paljak</title>
		<link>http://blog.ironkey.com/?p=119&#038;cpage=1#comment-6103</link>
		<dc:creator>Martin Paljak</dc:creator>
		<pubDate>Thu, 08 Jul 2010 11:28:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ironkey.com/?p=119#comment-6103</guid>
		<description>OT: I just received an ironkey (s200 personal), it would be nice if some of the identity functionality worked on Mac as wel.</description>
		<content:encoded><![CDATA[<p>OT: I just received an ironkey (s200 personal), it would be nice if some of the identity functionality worked on Mac as wel.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve pepple</title>
		<link>http://blog.ironkey.com/?p=119&#038;cpage=1#comment-1337</link>
		<dc:creator>steve pepple</dc:creator>
		<pubDate>Wed, 13 Feb 2008 17:00:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ironkey.com/?p=119#comment-1337</guid>
		<description>A combination of multi-factor authentication and OpenID is a good way to prevent many types of phishing attacks.

I work with a team that is developing a beta implementation of strong authentication for OpenID using a number of different authentication devices,
&lt;a href=&quot;http://openid.trustbearer.com&quot; rel=&quot;nofollow&quot;&gt;TrustBearer OpenID&lt;/a&gt;. 

We&#039;ve found that this infinitely decreases the possibility of someone fraudulently accessing another persons&#039; account. We&#039;ve found some compelling ways to thwart phishing here, as well. We use a web browser add-on to manage the authentication process, and we actually check the validity of sites here. A user&#039;s private data also remain private during OpenID authentication.

We&#039;ve been concentrating on simple user experience at this point, 
and we are interested to learn what sort of features user will look 
for in this type of openID implementation.

With our OpenID, you basically just set-up a strong authentication device 
and then link the device to your OpenID URL.</description>
		<content:encoded><![CDATA[<p>A combination of multi-factor authentication and OpenID is a good way to prevent many types of phishing attacks.</p>
<p>I work with a team that is developing a beta implementation of strong authentication for OpenID using a number of different authentication devices,<br />
<a href="http://openid.trustbearer.com" rel="nofollow">TrustBearer OpenID</a>. </p>
<p>We&#8217;ve found that this infinitely decreases the possibility of someone fraudulently accessing another persons&#8217; account. We&#8217;ve found some compelling ways to thwart phishing here, as well. We use a web browser add-on to manage the authentication process, and we actually check the validity of sites here. A user&#8217;s private data also remain private during OpenID authentication.</p>
<p>We&#8217;ve been concentrating on simple user experience at this point,<br />
and we are interested to learn what sort of features user will look<br />
for in this type of openID implementation.</p>
<p>With our OpenID, you basically just set-up a strong authentication device<br />
and then link the device to your OpenID URL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carsten PÃ¶tter</title>
		<link>http://blog.ironkey.com/?p=119&#038;cpage=1#comment-461</link>
		<dc:creator>Carsten PÃ¶tter</dc:creator>
		<pubDate>Sun, 27 May 2007 18:09:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ironkey.com/?p=119#comment-461</guid>
		<description>Small correction: I have claimed it in the title (in order to have a short one) but was more clear in the article.</description>
		<content:encoded><![CDATA[<p>Small correction: I have claimed it in the title (in order to have a short one) but was more clear in the article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carsten PÃ¶tter</title>
		<link>http://blog.ironkey.com/?p=119&#038;cpage=1#comment-460</link>
		<dc:creator>Carsten PÃ¶tter</dc:creator>
		<pubDate>Sat, 26 May 2007 21:10:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ironkey.com/?p=119#comment-460</guid>
		<description>Surely I have had to realise that smart cards don&#039;t prevent phishing completely, but I have not claimed that every Estonian will have an OpenID. ;)</description>
		<content:encoded><![CDATA[<p>Surely I have had to realise that smart cards don&#8217;t prevent phishing completely, but I have not claimed that every Estonian will have an OpenID. <img src='http://blog.ironkey.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin Paljak</title>
		<link>http://blog.ironkey.com/?p=119&#038;cpage=1#comment-459</link>
		<dc:creator>Martin Paljak</dc:creator>
		<pubDate>Sat, 26 May 2007 20:50:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ironkey.com/?p=119#comment-459</guid>
		<description>And there are no smart cards *issed* for OpenID specifically - there is just a strong electronic identity infrastructure that allows such add-ons like OpenID authentication to be implemented. They just happen to use the strong authentication methods provided with the identity infrastructure already in place (that powers applications like secure online banking and secure online voting as well)</description>
		<content:encoded><![CDATA[<p>And there are no smart cards *issed* for OpenID specifically &#8211; there is just a strong electronic identity infrastructure that allows such add-ons like OpenID authentication to be implemented. They just happen to use the strong authentication methods provided with the identity infrastructure already in place (that powers applications like secure online banking and secure online voting as well)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin Paljak</title>
		<link>http://blog.ironkey.com/?p=119&#038;cpage=1#comment-458</link>
		<dc:creator>Martin Paljak</dc:creator>
		<pubDate>Sat, 26 May 2007 20:44:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ironkey.com/?p=119#comment-458</guid>
		<description>To be precise: This is NOT a government activity. Watch my blog (http://martin.paljak.pri.ee) for different posts that shall be posted about this service now and in the future.</description>
		<content:encoded><![CDATA[<p>To be precise: This is NOT a government activity. Watch my blog (<a href="http://martin.paljak.pri.ee" rel="nofollow">http://martin.paljak.pri.ee</a>) for different posts that shall be posted about this service now and in the future.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
