Mark Dixon's quest to explore the world of Identity Management


Please note:

The primary site for this blog is now located at DiscoveringIdentity.com. While I will continue to shadow-post to the blogs.sun.com site, all new structural changes and innovation will be provided only at the DiscoveringIdentity.com site.

  If you care to follow my postings on the new site, please bookmark the new RSS feed.

feed-icon-16x16


« February 2010
SunMonTueWedThuFriSat
 
1
2
3
5
6
7
8
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
      
       
Today


A few weeks ago, Henry Story posted an excellent comment to my blog about Identity in the Browser, linking to his blog post Global Identity in the iPhone browser, which described the use of foaf+ssl certificates to autheticate access to a website. 

Yesterday, I participated in a somewhat spirited discussion with colleagues about the pros and cons of using certificates in mobile devices to provide better security than common username/password techniques.  Getting away from typing passwords on a cell phone would be very helpful.  The main thing I really like about the method Henry described is the ease in selecting different certificates, which may represent different personas for a user.  Being able to increase security and ease-of-use at the same time is encouraging.

However, I think we need to overcome some other key hurdles to bring this method into the mainstream.  Some issues include:
  • How will certificates be distributed and installed, particularly to people who are not particularly technology savvy?
  • What methods will be used to verify that certificates match a person's real Identity?
  • What will it take to get a critical mass of online sites to adopt this method of authentication?
  • What happens if the phone is lost or stolen?

It will be interesting to seek how these and other relevant issues are resolved.


Technorati Tags: , , , ,

  
Permalink
Trackback Link
10:57 AM MST
Trackback URL: http://blogs.sun.com/identity/entry/security_certificates_on_cell_phones
Comments:

Post a Comment:

Name:
E-Mail:
URL:

Your Comment:

HTML Syntax: NOT allowed
Ask to see my identity at www.Trufina.com

Click here to request a copy of my Trufina-validated identity card and contact information.
Click to see my FOAF card
Click here to see my FOAF Card.






For more widgets please visit www.yourminis.com