DigiD
From Arnout Engelen
erboract DigiD is supposed to be Open Source, so it'd be nice to do some sort of an audit.
The security of the system seems plausible (and a bit kerberos-like), but the implementation seems to have been done by a relatively small group of people. Even though commercial security audits have been done (i believe by PinkRoccade), it might be fun to poke at it a bit.
- A-Select website with extensive (also technical) documentation.
- php DigiD authentication implementation
- DigiD gateway implementation
