| 
 60 Identity Problems that OneID can help solve 
	- “I forgot my username”
 
	- “I forgot my password”
 
	- The need to create new username and password at each new site
 
	- Having to type in or remember usernames
 
	- Having to type in
Passwords
 
	- Typing in information that has already been typed in; repetitive form filling
 
	- CAPTCHAs (you should only have to do that once if at all)
 
	- Repetitive
E-mail and/or SMS verifications of your phone number and/or email
 
	- Having to disclose credit card to a merchant
 
	- Having to fill out forms to create an account
 
	- Not being able to use US credit card at UK site
 
	- Risk of CNP transactions
 
	- Forced password changes
 
	- Password standards
 
	- Temporary passwords
 
	- Picking usernames
 
	- Shared secrets
 
	- Mass breaches of other sites database allowing attacker to login to your site 
with the same username and password
 
	- Mass breach of password databases
 
	- “I forgot my loyalty program #”
 
	- I have too many loyalty cards
 
	- Takes too long to fill out the application for a loyalty card
 
	- Denied credit card charges
 
	- Knowledge-based authentication security questions
 
	- Need to share secrets over the phone or web with a server or person 
	 
 
	- The risk of using a public terminal or a friend’s computer
 
	- Usernames that are your old email and cannot be changed
 
	- Break-ins of your accounts caused by theft of a password database at 
	that site or another site on the Internet where you used the same password
 
	- Fear of an attacker stealing your identity and wiping you out
 
	- The pain of changing your credit card everywhere when it is lost, stolen, or 
expires
 
	- The pain of changing your email everywhere when you get a new job or new email
 
	- Remembering screen names
 
	- The privacy risk (OneID can’t decrypt your data)
 
	- The risk your IdP can pose as you
 
	- No use of PKI so no DigiNotar
 
	- Single point of compromises
 
	- The incentive to phish
 
	- Account lock outs due to:
		- Inactivity  
 
		- New devices
 
		- Invalid password guesses
 
		- Use from strange locations
 
		- Or any other reason
 
		 
		 
		- Having to contact all appropriate vendors when any of your contact or billing 
information changes
 
		- The inability for RoboForm, etc. to fill out logins or forms on certain devices 
and certain websites
 
		- The need to change your password or PIN when one is compromised (phished or 
break into the site or another site)
 
		- The need to ever have to talk to a customer service representative about 
authentication issues
 
		- The need to remember who you gave your SMS to so in the event your phone is 
stolen, you can revoke the SMS verification.  
 
		- The pain you have to endure when you try to convince the bank that they really 
did steal your phone
 
		- MITM, MITB attacks where you can’t trust what you see, even if you are using 
SecurID (which is not out-of-band)
 
		- LoA is set exclusively by the RP (user can’t get a higher LoA)
 
		- The need to re-type authentication (password or PIN) within a short interval
 
		- The ability to set LoA on a per transaction basis (no more having to approve a 
free app purchase if YOU think it is silly)
 
		- Malware threats including Citadel and 
		Eurograbber
 
		- Problem with user forgetting he’s logged in when he leaves the computer so 
someone else can make transactions as him
 
		- User ambiguity where system needs to disambiguate from clever attacker and 
legitimate owner
 
		- Having to change ALL your passwords if malware on your machine and you are using 
a password manager
 
		- When your air carrier forgets your reservation, if they had stored the 
confirmation code in your OneID, even when they make a mistake, you are still 
covered because you can go to Account in OneID and retrieve the data
 
		- The chance that you might have typed in the wrong passport number when you made 
your plane reservations (because OneID can auto fill this info)
 
		- Having to remember the answer to all the KBA ambiguous questions
 
		- The risk that your account can be phished (no username or password to phish)
 
		- Having to know about and manage digital certificates (these are all hidden)
 
		- Having to remember which offer you want to associate with each merchant (e.g., 
you can associate the Virgin America miles offer with you Hertz reservation)
 
		- Having to manage all those usernames and pwds, especially those tied to your old 
email that you can no longer access!
 
		- You changed your cell phone number. Now all those out of band verifications 
don’t work (like at Microsoft)
 
		- The insecurity of SMS;
Australian Telcos Declare SMS Unsafe For Bank (OneID never used SMS because it 
is unsafe)
 
		- Not being able to set a cumulative dollar limit on your identity so 
		you can secure your purchase
 
	- You can't purchase on Best Buy and other sites with 
	RoboForm and other form fillers because the autofill doesn't trigger a 
	manual type-in, so users are completely baffled as to why their purchase 
	fails
 
	- Being able to purchase from multiple Internet sites 
	and seeing all your tracking numbers and receipts in one place
 
		 
		
See also:  
OneID documentation guide |