About RSS
Search for: in 
Tim Anderson
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Tim Anderson

Are credit agency's plans credible?

Credit reference agency Experian will struggle to win trust for its plans to become an identity provider

IT Week, 29 Nov 2007
ADVERTISEMENT

I was fascinated to learn of Experian’s plans to become an identity provider. In about a year’s time, the company intends to launch a new service, provisionally called My Life, aimed at individuals looking for a more secure way of logging on to web sites such as retailers, banks and government services.

Users will register once with Experian, and then authenticate on third-party sites using Microsoft’s CardSpace, which is part of .NET Framework 3.0 and Internet Explorer 7.0. There is no need for a password, and confidential information such as a credit card number is not sent directly from the user’s PC to the third-party site.

nstead, the user submits a digital token that gives the third-party permission to get the information from Experian. The service is paid for by the third party.

The system makes phishing more difficult, since Experian as the identity provider will only send data to sites it recognises, and individual users no longer have to figure out if the site is genuine. Another advantage is that the CardSpace user interface is part of the browser, rather than part of a web page, so cannot be faked. In addition, the third party has Experian’s assurance that the user is who they claim to be.

Criminals will still find ways to attack CardSpace users, but, even so, it is superior to flimsy username/password authentication.

Can Experian and Microsoft make the web safer? Possibly, but there are reasons for caution. First, there are cross-platform concerns. Microsoft and Experian insist that this is a cross-industry initiative, and point to CardSpace client implementations on Linux, Mac and FireFox, but deployment of CardSpace is currently limited ­ even on Windows.

That problem may fix itself in time, but the second issue is whether Experian can command sufficient trust from users that they will be willing to give the company this key role in their financial affairs.

Experian is best known as a credit reference agency, and has a poor image among individuals who have struggled with bad credit ratings, sometimes because of administrative mistakes rather than genuine risks. There is an obvious potential conflict of interest. Would Experian as a credit reference agency draw on its knowledge of an individual’s transactions with third parties, gained as an identity provider, to inform its credit reports?

Experian insists that it will not, and that these services will be run entirely separately. That may be so, but a credit reference agency is simply the wrong organisation to run an identity provider business. A non-profit industry consortium would be more reassuring.


Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
RELATED ARTICLES
M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
LYTHAM ST ANNES, Lancashire, United Kingdom | EDS
About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve their business performance. EDS' core portfolio comprises information-technology and business process outsourcing services, as well as information-technology ... more >
London, United Kingdom | MI5
Programme Managers - Project Managers -Project Support Staff - Competitive Salary + Excellent Benefits - London   Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use ... more >
London, United Kingdom | The Moving Picture Company
Web Developer - London   MPC's continued success is dependent on a continued investment in technology so that its clients continue to enjoy the highest possible quality of work and service. Key to MPC's offering is ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
More job opportunities
Join our fight for a fair deal when shopping online