[HGI-news-int] Young Researchers from HGI thwart CardSpace Authentication

English Newsletter of the Horst Gö rtz Institute of IT Security in Bochum hgi-news-international at lists.ruhr-uni-bochum.de
Fri May 30 13:16:45 CEST 2008

Two young researchers at Horst Görtz Institute for IT-security, Ruhr 
University Bochum have shown how to break Microsoft's novel identity 
management system CardSpace. They demonstrate not only the theoretical 
feasibility, but also the attack's practicability in of proof of concept 
that CarSpace does not guard against identity theft. More information 
detailing the attack and countermeasures can be found in their Technical 

Various applications can make use of CardSpace including commodity 
browsers like Microsoft Internet Explorer 7 or Firefox 2 (with some 
add-on). Many global players (e.g., Google, Yahoo, Verisign) have 
already announced to work closely with CardSpace, hence CardSpace has 
the potential to become widely deployed on the Internet and replace the 
mature password-based authentication in many promising scenarios from 
eCommerce to eHealth or eVoting applications.


Technical Report and Demo:

Press release:

More information about the HGI-News-International mailing list