<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Trevor Power &#187; OpenID</title>
	<atom:link href="http://blog.trevorpower.com/index.php/category/openid/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.trevorpower.com</link>
	<description>Software development and other thoughts</description>
	<lastBuildDate>Fri, 20 Aug 2010 07:33:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>OpenId and Rabo Bank</title>
		<link>http://blog.trevorpower.com/index.php/openid-and-rabo-bank/</link>
		<comments>http://blog.trevorpower.com/index.php/openid-and-rabo-bank/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 20:37:00 +0000</pubDate>
		<dc:creator>trevorpower</dc:creator>
				<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://trevorpower.com/blog/?p=17</guid>
		<description><![CDATA[No, you can&#8217;t log into your Rabo Bank account using an OpenID, it is feasable but I suspect it is a few years away.
I am currently implementing OpenID support (as a relying party) to a website I am working on and have become a big fan of the protocol. I was thinking about the different ways that [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.trevorpower.com%2Findex.php%2Fopenid-and-rabo-bank%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.trevorpower.com%2Findex.php%2Fopenid-and-rabo-bank%2F" height="61" width="51" /></a></div><p>No, you can&#8217;t log into your <a href="http://www.rabobank.com/"><span class="blsp-spelling-error" id="SPELLING_ERROR_0">Rabo</span> Bank account</a> using an <a href="http://www.openid.net/"><span class="blsp-spelling-error" id="SPELLING_ERROR_1">OpenID</span></a>, it <span class="Apple-style-span" style="font-style: italic;">is</span> <span class="blsp-spelling-error" id="SPELLING_ERROR_2">feasable</span> but I suspect it is a few years away.</p>
<p>I am currently implementing <span class="blsp-spelling-error" id="SPELLING_ERROR_3">OpenID</span> support (as a relying party) to a website I am working on and have become a big fan of the protocol. I was thinking about the different ways that <span class="blsp-spelling-error" id="SPELLING_ERROR_4">OpenID </span>providers could use to authenticate you such as password, <a href="http://www.phonefactor.com/">phone-call</a> etc&#8230;</p>
<p>It then struck me, when logging into <span class="blsp-spelling-error" id="SPELLING_ERROR_5">Rabo</span> they use a very secure authentication system whereby each user has a special device called a <a href="http://www.rabodirect.ie/help/demos/digipass/default.aspx"><span class="blsp-spelling-error" id="SPELLING_ERROR_6">digipass</span></a> that must be used when logging in. It is like a small calculator but it&#8217;s basically a random number generator. As it requires a PIN to operate, <span class="blsp-spelling-corrected" id="SPELLING_ERROR_7">logging</span> in becomes a two factor authentication system.
<div>
<div></div>
<div>They already use a different number of steps and hence a different level of security depending on the transaction type (<span class="blsp-spelling-error" id="SPELLING_ERROR_8">login</span>, money transfer, large money transfer) so they could easily let the user decide on the level of security they are comfortable with.
<div></div>
<div>They have a big head-start on many of the big openID providers even Microsoft and Google <span class="blsp-spelling-corrected" id="SPELLING_ERROR_9">because</span> they have a user base that already have their hands on the <span class="blsp-spelling-error" id="SPELLING_ERROR_10">digipass</span>. It would be hard for a standalone <span class="blsp-spelling-error" id="SPELLING_ERROR_11">OpenID</span> provider to give away free gadgets.</div>
<div></div>
<div>In the current economic climate, I&#8217;m sure banks have bigger things to worry about but such a feature would be easy to implement and offer their users a bonus feature for banking with them.</div>
<div></div>
<div>But<span class="Apple-style-span" style="font-weight: bold;">, </span>unless you are hyper paranoid the only thing I can think of that you would like that much security for is an online bank&#8230;</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.trevorpower.com/index.php/openid-and-rabo-bank/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

