From the Department of Duh, really?
Passwords remain weakest link in Web security | Service-Oriented Architecture | ZDNet.com.
Frustrating that with all the focus on SSO without security (I’m talking to you OpenID folks) and all the security technologies available to grant both security and SSO (or Reduced Sign-On for you “SSO is impossible” folks) this hasn’t been addressed. I chalk it up to a lack of vision on certain IP holders and cowardice of those in a position to implement something real vs. never-ending “play projects”. Time for these folks to create some momentum (banks, huge portals, OS providers, large retailers, etc.). Time to get serious about providing real security starting at the point of authentication at which point a huge amount of powerful innovation in services could begin (emergence of the mythical semantic web).
Of course, till the current governmental economic dithering ends (reduce taxes and quit spending us into slavery), who wants to make an admittedly large entrepreneurial bet right now?