The company is presenting a proof-of-concept demonstration and collaboration between its Windows CardSpace initiative and the OpenID 2.0 specification at the RSA Security Conference in San Francisco this week. The relationship is expected to help eliminate what's sometimes known as the "man-in-the-middle" attack, where a third party can read and modify messages between two unsuspecting parties.
"Those were the days when we talked mostly about the 'I Love You' virus," Gates said during his keynote address at RSA.
Fast-forward to today, where Microsoft itself is acknowledging that attacks are more focused on areas other than the network, such as the application level.
"We realized that we still needed to create a GUI for credentials and for situations that were more on an ad hoc basis," Mundi said during the morning keynote. "It should be no more difficult for a person to identify themselves online as it is to walk in person and take a driver license and credit card for identification."
Developed by Brad Fitzpatrick of LiveJournal, OpenID is fast gaining market acceptance by Web 2.0 groups such as Wikipedia and Technorati, as well as computer security firms like Symantec.
Windows CardSpace -- formerly InfoCard -- is part of Microsoft's .Net 3.0 framework and integrates with Microsoft's Windows Communication Foundation, Windows Workflow Foundation, and Windows Presentation Foundation.
Gates noted also that the OpenID 2.0 spec would help support Microsoft's own Web security protocols, which are widely used in Web services transactions.
"There are reputation and trust issues involved that this helps solve," Gates said.
Gates and Mundi said the CardSpace/OpenID proof-of-concept demonstration is expected to be implemented in the Windows Longhorn Server product, currently in beta testing and due out later this summer.
In addition to testing OpenID in its architecture, Microsoft announced Tuesday security-related products and partner initiatives, including the launch of its Identity Lifecycle Manager 2007, the release of a public beta for its Forefront Server Security Management Console, and additional support of Extended Validation SSL Certificates in Internet Explorer 7.
Microsoft also recently announced other key security-related initiatives, including the general availability of the Intelligent Application Gateway 2007, a Microsoft Network Access Protection 100-partner milestone, and the launch of Windows Live OneCare.
Stay connected and informed by visiting our Enterprise IT Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government, Retail and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.