Microsoft announced during last week’s RSA conference that it would not be shipping Windows CardSpace 2.0. A lot of design imperatives weighed on that one deliverable: security, privacy, usability, bridging the enterprise and consumer identity worlds – and being the standard-bearer of the “identity metasystem” and the “laws of identity” to boot. Something had to give. What are the implications for security and risk professionals?The CardSpace model had nice phishing resistance properties that cloud-based identity selectors will find hard to replicate, alas. But without wide adoption on the open Web, that wasn’t going to make a dent anyway. We’ll have to look for other native-app solutions over time for that.More significantly, I think neither CardSpace nor its IMI protocol have lived up to the “claims-based identity” mantra anyway, being too focused on fixed aggregations of claims from a single source. A more productive future path will be the OAuth pattern, of which Facebook Connect and Twitter are familiar examples. In this pattern, relying parties can score user-delegated access directly to each source of truth on a secure back channel, and can continue to pull fresh data even after the user disconnects. Several efforts are building on top of OAuth and JSON Web Tokens to respond to a variety of consumer-scale personalization and authorization use cases, cloud-oriented access management use cases, and even enterprise-strength use cases. Interestingly, Mike Jones of Microsoft – who was an early evangelist for CardSpace and penned the first public reflections on its passing – also has a key role along with other major Web-scale IdP players in drafting these newfangled specs. Check out his blog for lots of relevant links.Eve Maler is a Principal Analyst at Forrester Research where she serves Security & Risk Professionals. Related content opinion Just Let Me Fling Birds At Pigs Already! Thoughts On The Snowden / Angry Birds Revelations By Tyler Shields By Forrester Research Jan 28, 2014 4 mins Mobile Security IT Leadership opinion LG Is Learning An Embarrassing Privacy Lesson In The Age Of The Customer By Rick Holland By Forrester Research Nov 22, 2013 3 mins IT Leadership opinion Rise Of The Second Mobile App War By Tyler Shields By Forrester Research Sep 04, 2013 3 mins Application Security opinion Point Solutions Must Die By Forrester Research Aug 19, 2013 4 mins Data and Information Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe