<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0cm;
        mso-margin-bottom-alt:auto;
        margin-left:0cm;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page Section1
        {size:612.0pt 792.0pt;
        margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.Section1
        {page:Section1;}
/* List Definitions */
@list l0
        {mso-list-id:127403980;
        mso-list-template-ids:-2100628026;}
@list l1
        {mso-list-id:505483797;
        mso-list-template-ids:-1087896082;}
@list l2
        {mso-list-id:1540437232;
        mso-list-template-ids:1259875372;}
@list l3
        {mso-list-id:2089034964;
        mso-list-template-ids:128752396;}
ol
        {margin-bottom:0cm;}
ul
        {margin-bottom:0cm;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=FR link=blue vlink=purple>
<div class=Section1>
<p class=MsoNormal><span lang=EN-US style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Oh yes ! the link is </span><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif";color:#1F497D'><a href="http://www.proto.in"><span
lang=EN-US>www.proto.in</span></a></span><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif";color:#1F497D'> <span lang=EN-US><o:p></o:p></span></span></p>
<p class=MsoNormal><span lang=EN-US style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=IT style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>“Pronto” mean “Allo” in Italian! :)<o:p></o:p></span></p>
<p class=MsoNormal><span lang=IT style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=IT style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Thanks<o:p></o:p></span></p>
<p class=MsoNormal><span lang=IT style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=IT style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>-Snorri<o:p></o:p></span></p>
<p class=MsoNormal><span lang=IT style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm'>
<p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>De :</span></b><span
style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> Jeetendra
Mirchandani [mailto:jeetum@gmail.com] <br>
<b>Envoyé :</b> mercredi 25 juin 2008 10:36<br>
<b>À :</b> Snorri<br>
<b>Objet :</b> Re: [OpenID] OpenID in India - What stops you from using
OpenID?<o:p></o:p></span></p>
</div>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal style='margin-bottom:12.0pt'>Hey Snorri, that should have
been <a href="http://proto.in">proto.in</a>, not pro<b><u>n</u></b><a
href="http://to.in">to.in</a><br>
<br>
Regards,<br>
Jeetu<o:p></o:p></p>
<div>
<p class=MsoNormal>On Wed, Jun 25, 2008 at 2:01 PM, Snorri
<snorri@snorri.eu> wrote:<o:p></o:p></p>
<div>
<div>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'>Interesting comments
Eddy,</span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'> </span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'>I copy also here the
answer of Vijay Anand, the founder of <a href="http://www.pronto.in"
target="_blank">www.pronto.in</a> </span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'>It's a platform with
important Indian start-ups:</span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'> </span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'>Who can answer?</span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'> </span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'>Thanks</span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'> </span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'>-Snorri</span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'> </span><o:p></o:p></p>
<p><span lang=EN-US>Rajan represents a firm that works in the secure identity
space. When asked how it measures with OpenID, he mentioned a few remarks. I
wanted to run it through you to get your feedback. </span>What do you think?<br>
<br>
Vijay<o:p></o:p></p>
<p><span lang=EN-IN style='font-size:10.0pt'>For Point 4 Open ID – Open id is a
good concept, but very much different to XeQure. We have taken into
consideration the shortcomings of Open ID in development of XeQure. Please
visit <span style='color:#00B0F0'><a
href="http://idcorner.org/2007/08/22/the-problems-with-openid/" target="_blank"><span
style='color:#00B0F0'>http://idcorner.org/2007/08/22/the-problems-with-openid/</span></a>
</span>to get an idea where Open ID stops being user friendly and secure.
Few salient points are as below:</span><o:p></o:p></p>
<p><span lang=EN-IN style='font-size:10.0pt'> </span><o:p></o:p></p>
<p style='margin-left:18.0pt;text-indent:-18.0pt'><span lang=EN-IN
style='font-size:10.0pt'>1) Prone to phishing – Open ID
workflow and architecture is such that it is easy to phish into as any person
can create a website and become an Open ID provider. Causing a great threat to
user security and hence confidence in application. If you use one OpenID
account to go to two hundred sites, the thief who steals your OpenID
credentials gains access to any of the 200 sites.</span><o:p></o:p></p>
<p style='margin-left:18.0pt;text-indent:-18.0pt'><span lang=EN-IN
style='font-size:10.0pt'>2) Privacy issue – With open
ID the identity provider can track all your login and usage history. This in
itself is a grave concern for internet users. XeQure architecture is different
and it does not control the way user moves on a third party website.</span><o:p></o:p></p>
<p style='margin-left:18.0pt;text-indent:-18.0pt'><span lang=EN-IN
style='font-size:10.0pt'>3) No Patent –Open ID is a
free framework (without any patent ), which can be implemented by anyone (even
hackers and phishers), this makes it very vulnerable for hackers and users tend
to have limited trust in such applications. No wonder the user base is still
very low for it. </span><o:p></o:p></p>
<p style='margin-left:18.0pt;text-indent:-18.0pt'><span lang=EN-IN
style='font-size:10.0pt'>4) Usability issues – Open Id
is too cumbersome to use. It has three entities the user, Identity provider
e.g. Claim ID, and Consumer e.g. LiveJournal.com, <a href="http://pbwiki.com"
target="_blank">pbwiki.com</a>, etc. They all have to synchronize to make this
functional. Too many parties involved for user ease. It has many steps on each
login and it is not a true single click sign on unlike XeQure. This Open ID
framework needs to be implemented for each website which requires time and cost
to be incurred to do so.</span><o:p></o:p></p>
<p style='margin-left:18.0pt;text-indent:-18.0pt'><span lang=EN-IN
style='font-size:10.0pt'>5) Multiple user account login
– What if user has multiple accounts to say Google. He/she will still have to
remember all the URIs to login to different accounts. Open ID falls short of a
true SSO(Single sign on) to all user accounts.</span><o:p></o:p></p>
<p style='text-indent:-18.0pt'><span lang=EN-IN style='font-size:10.0pt'>6)
6) Limited operation in major players – Open ID is not being
provided as a login method on major websites like Gmail, Orkut, Myspace, etc.
Although majors like Google, Microsoft, etc. expressed their willingness
to provide support for Open ID more than 6 months back, but have done nothing
to make it functional as of yet. It seems that OpenID will take a very long
time to be used as a standard on the World Wide Web.</span><o:p></o:p></p>
<p><span lang=EN-IN style='font-size:10.0pt;color:#1F497D'> </span><o:p></o:p></p>
<p><span lang=EN-US style='font-size:11.0pt;color:#1F497D'> </span><o:p></o:p></p>
<div>
<div style='border:none;border-top:solid windowtext 1.0pt;padding:3.0pt 0cm 0cm 0cm;
border-color:-moz-use-text-color -moz-use-text-color'>
<p><b><span style='font-size:10.0pt'>De :</span></b><span
style='font-size:10.0pt'> <a href="mailto:general-bounces@openid.net"
target="_blank">general-bounces@openid.net</a> [mailto:<a
href="mailto:general-bounces@openid.net" target="_blank">general-bounces@openid.net</a>]
<b>De la part de</b> Eddy Nigg (StartCom Ltd.)<br>
<b>Envoyé :</b> mercredi 25 juin 2008 07:55<br>
<b>À :</b> Jeetendra Mirchandani<br>
<b>Cc :</b> <a href="mailto:general@openid.net" target="_blank">general@openid.net</a><br>
<b>Objet :</b> Re: [OpenID] OpenID in India - What stops you from using
OpenID?</span><o:p></o:p></p>
</div>
</div>
<div>
<div>
<p> <o:p></o:p></p>
<p>Jeetendra Mirchandani: <o:p></o:p></p>
<p><span lang=EN-US>This is a question for all those website owners in India, who
have been around for a while, and those who have started new ventures recently.
Let me list down possible reasons I can think of, as if I were to own a website
targeted towards Indians</span><o:p></o:p></p>
<p style='margin-bottom:12.0pt'><br>
All of the above might be correct (from the point of view of the web site
owners of course). Here my $0.02....<br>
<br>
<o:p></o:p></p>
<ol start=1 type=1>
<li class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
mso-list:l1 level1 lfo1'><span lang=EN-US>Indian users dont know what
OpenID is</span><o:p></o:p></li>
</ol>
<p style='margin-bottom:12.0pt'><br>
Very likely! Isn't this the reason for your foundation and mission thereof?<br>
<br>
<o:p></o:p></p>
<ol start=1 type=1>
<li class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
mso-list:l3 level1 lfo2'><span lang=EN-US>Your traffic is reluctant to use
a URL as a username, they are just more comfortable with the old
traditional way of having a user name and password</span><o:p></o:p></li>
<li class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
mso-list:l3 level1 lfo2'><span lang=EN-US>You, the website owner, wants to
build a user base. And users signing in via an OpenID aren't really users
that you own (Or atleast thats what you think?)</span><o:p></o:p></li>
</ol>
<p style='margin-bottom:12.0pt'><br>
>From the user perspective that's certainly not really valid. For OpenID users,
when offered OpenID login on a site they are more willing to register then
without. It's only the authentication which is "outsourced" not the
user base itself. That's a point which needs education perhaps.<br>
<br>
<o:p></o:p></p>
<ol start=1 type=1>
<li class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
mso-list:l2 level1 lfo3'><span lang=EN-US>You don't trust that OpenID
provider is secure enough. You are responsible for any user data, and
don't want the third-party provider to be involved in how secure your user
data is</span><o:p></o:p></li>
</ol>
<p style='margin-bottom:12.0pt'><br>
Allow only providers you trust. It's easy as that.<br>
<br>
<o:p></o:p></p>
<ol start=1 type=1>
<li class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
mso-list:l0 level1 lfo4'>OpenID implementation is very complicated<o:p></o:p></li>
</ol>
<p style='margin-bottom:12.0pt'><br>
This is a valid point and most popular blogs, forums require some extra work to
have OpenID login. Certainly for implementing your own login facility. Until
the big web applications don't ship OpenID built-in (like WordPress, Phpbb
forum, wikimedia) this is a hurdle.<br>
<br>
<o:p></o:p></p>
<p><span lang=EN-US>With the same argument, point 4 is also not totally valid!
A user understands who to trust, and build up that trust over time. With big
players like </span><a href="http://openid.yahoo.com/" target="_blank"><span
lang=EN-US>Yahoo providing OpenID</span></a><span lang=EN-US>, I think this
barrier is gone.</span><o:p></o:p></p>
<p style='margin-bottom:12.0pt'><br>
I don't view Yahoo as a secure provider, sorry.<br>
<br>
<o:p></o:p></p>
<p><span lang=EN-US>And if you say OpenID implementation is complicated, you
need to look around. The </span><a href="http://openid.net/developers/"
target="_blank"><span lang=EN-US>developers section on openid.net </span></a><span
lang=EN-US>could be a good starting point.</span><o:p></o:p></p>
<p style='margin-bottom:12.0pt'><br>
That's a lame argument. For many implementation is impossible or very
burdensome. See above...the most popular web applications need to ship OpenID
built-in!<o:p></o:p></p>
<div>
<table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0>
<tr>
<td colspan=2 style='padding:0cm 0cm 0cm 0cm'>
<p>Regards <o:p></o:p></p>
</td>
</tr>
<tr>
<td colspan=2 style='padding:0cm 0cm 0cm 0cm'>
<p> <o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0cm 0cm 0cm 0cm'>
<p>Signer: <o:p></o:p></p>
</td>
<td style='padding:0cm 0cm 0cm 0cm'>
<p>Eddy Nigg, <a href="http://www.startcom.org" target="_blank">StartCom Ltd.</a><o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0cm 0cm 0cm 0cm'>
<p>Jabber: <o:p></o:p></p>
</td>
<td style='padding:0cm 0cm 0cm 0cm'>
<p>startcom@startcom.org<o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0cm 0cm 0cm 0cm'>
<p>Blog: <o:p></o:p></p>
</td>
<td style='padding:0cm 0cm 0cm 0cm'>
<p><a href="http://blog.startcom.org" target="_blank">Join the Revolution!</a><o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0cm 0cm 0cm 0cm'>
<p>Phone: <o:p></o:p></p>
</td>
<td style='padding:0cm 0cm 0cm 0cm'>
<p>+1.213.341.0390<o:p></o:p></p>
</td>
</tr>
<tr>
<td colspan=2 style='padding:0cm 0cm 0cm 0cm'>
<p> <o:p></o:p></p>
</td>
</tr>
</table>
<p> <o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</div>
<p class=MsoNormal><br>
<br clear=all>
<br>
-- <br>
Regards,<br>
Jeetu<br>
<a href="http://www.cse.iitb.ac.in/~jeetu">http://www.cse.iitb.ac.in/~jeetu</a><br>
<a href="http://apps.facebook.com/myorkut/">http://apps.facebook.com/myorkut/</a><br>
<br>
"Reality is merely an illusion, albeit a very persistent one." <o:p></o:p></p>
</div>
</body>
</html>