<body>

Hands-on Project 8-5

Date: Monday, August 23, 2010


Hands-on Project 8-5 : Use an OpenID Account



Screenshot of http://www.livejournal.com/openid/
I entered my identity URL(which is yojaeon.pip.verisignlabs.com) in "Your OpenID URL"



After I clicked login, i returned to the Personal Identity Provider OpenID site of Verisign Labs.
(As I did not log out, I do not have to enter Username and passwords again.)
And the URL bar of this page indicates that this is the Verisign site.



I allowed Livejournal to use "yojaeon" as my OpenID and I returned to Livejournal website.



Next I go to http://www.lifewiki.net/login
Same as what I did for Livejournal website, I entered my Identity URL.


Clicked on allow



And i was logged in to Lifewiki


Reflection:
From the last practical (Hands-on Project 8-4) I did, I created an OpenID. So for this practical, I am going to use the account. As you can see from the pictures above, I tested out with LiveJournal and Wikilife website. I simply enter my identity URL and when the website redirects me back to https://pip.verisignlabs.com/. I only have indicates I trusts these websites with my identity, https://pip.verisignlabs.com/ will send me back to the websites and I am then authenticated. Overall, it seemed very easy to use, all that required is my identiy URL. Only if OpenID is supported by more websites, I will recommend it to other users, right now there’s only around 240 websites (according to OpenID Directory) that uses OpenID. Not really worth to have an account.

Next, is the security issue. OpenID has its weakness, it depends on the URL identifier routing to the correct server, which depends on a domain name server (DNS) that has its own security weakness. In this current format, OpenID is not considered strong enough for most banking and e-commerce Web sites. Thus, I will not access my bank information with it. However, for less secure sites, I will still consider to use it.

Labels: ,


林小颍's work ^—^V

Hands-on Project 8-4

Date:


Hands-on Project 8-4 : Create an OpenID Account


First, I go to https://pip.verisignlabs.com/
This is the Personal Identity Provider OpenID site of Verisign Labs.


Next, I clicked on Create account.
This is a screenshot of me filling up requested information.



Sucessfully created an account.



I go to my e-mail account to verify the OpenID account.



I changed my Personal Icon.



Go to My Account>My Information>Personal Profile
Under Personal Profile I can view or edit my information.


Reflection:
For Hands-on Project 8-4, I tried to create an OpenID account on https://pip.verisignlabs.com/, which is the Personal Identity Provider OpenID site of Verisign Labs.

OpenID is defined as a decentralized open source federated identity management system that does not require specific software to be installed on the desktop.

You can refer to the steps above with screenshots to create an OpenID account. Overall, it is very simple. I did not encounter any problem while creating the account. There’s no restriction on what information I must enter, I can also personalize the profile picture, it is very easy to use.

Labels: ,


林小颍's work ^—^V

Hands-on Project 8-1

Date:


Hands-on Project 8-1 : Use Cognitive Biometrics

About Cognitive biometrics
Cognitive biometrics is related to the perception, thought process, and understanding of the user. It is considered to be much easier for the user to remember because it is based on the user’s life experiences. This also makes it very difficult for an attacker to imitate.
- One example of cognitive biometrics is based on a life experience that the user remembers.
- Another example of cognitive biometrics requires the user to identify specific faces.


For this hands-on project, I am going to participate in a demostration of Passfaces.
First, I go to http://www.passfaces.com/demo/.
Under "First Time Users", I entered the requested information.
About Passfaces
Passfaces is a unique strong authentication technology that works with existing security systems to supplement or replace the use of passwords for system access. Passfaces uses human faces rather than alphanumeric entries to validate a user's identity. This patented technology is only available from Passfaces.


After I click to enroll, it shows a Thank You page.



Together with the Thank You page, there is also a pop up screen like this.



This is the demo process. I screenshot the whole steps and make it into a gif.


 
The introduction to Passface.                         This screen shows the steps I'm going to do.


 
Step by step guide.
The STEP 2 allows me to further remember the 3 faces I'm given.
Step 3 tested if I can recall those faces.

 
Lastly, I passed the log on test and managed to log on.


Reflection:
There are a few examples of Cognitive Biometric. This practical introduces Passfaces which uses human faces rather than alphanumeric entries to validate a user's identity. I think this type of Cognitive Biometric is quite effective, at least to me, I prefer this to a password. It is easily recognized, difficult to describe, share, and most importantly, impossible to guess. I tried to look at the screenshot with 9 faces again a day after I did this hands-on project, I’m still able to recognize the faces. This shows that my brain actually works better with graphics, like photos. Thus, I think this Passface technology might be able to replace the current alphanumeric passwords in the later years.

Labels: ,


林小颍's work ^—^V