Monday, November 20, 2006

OpenID ceremony

Paul Toal's blog allows readers to use an OpenID for their authentication mechanism.

The ceremony is different than typical. If they wish to use an OpenID URI (as opposed to authenticating with a local account), the user is asked/allowed to specify the identity provider at which they maintain that URI in addition to the URI itself, see graphic

It's not clear to me why a user would need to both supply the URI as well as indicate the IDP through the select list?

It would make sense to me if the user was allowed to either pick their IDP from the list OR enter their own URI - the former being valid if the user wants the 'delayed binding' model of persona selection (this would be valid but seemingly antithetical to the supposed OpenID freewheeling trust model where an RP isn't expected to show any selectivity in its 'favours').

I tried not providing a URI to see if I'd get sent to LiveJournal regardless but the OpenID authentication on Paul's site isn't working.

Evolving Risk

Fidelity Investments has a mutual fund product - the distinguishing feature of which is that
as each Freedom Fund nears its target date, the investment mix gradually gets more conservative.
As you near the time where you will be removing funds, the asset allocation changes to minimize risk.

Why not the same for identity policy, i.e. privacy rules that automatically become more conservative and risk-averse as the user ages?

I expect that I currently allow usages of my identity now that I won't in 20 years, and I'm absolutely sure that the 43 year old me wouldn't allow operations now that a 20 year old me wouldn't think twice about.

I propose a simple formula

For every 2 years of age past 20, allow one less identity operation in a weekly period.

Based on experience with my Dad :
  1. the particular operation being denied should be chosen randomly
  2. whatever decision made in one instance should not impact subsequent decisions
  3. the Fault code cited should place blame on the 'government', and
  4. should be followed by a prolonged rant on how, when the user was a kid, they had to create their own SAML assertions using a Number 2 pencil, use a slide rule to calculate the signature, and deliver them through plain POST operations, unassisted by JavaScript. And it was uphill for both the request and the response.

Friday, November 17, 2006

SAML paired with Skype

Jeff has made available a SAML document he created. It's more than just an overview, but rather 'How to Study and Learn SAML".

As a starting point, Jeff recommends
Begin by studying various SAML Profiles, e.g. those given in [[SAMLProf]] and [SIP-SAML]. One will likely find the SAML Technical Overview whitepaper [[SAMLTechOvw]] helpful in this endeavor. It provides a detailed, illustrated expose of several of the SAML Web SSO profiles.
Interestingly, when I view the document, a plugin Skype (yes Jeff, I know it's proprietary) installed when I recently upgraded renders a phone number in one of the XML examples as a 'click to call'.

Presents some intriguing possibilities for smart clients.



Thursday, November 16, 2006

Big In Japan

My life is downhill from here on.

It's a bit of a stretch for my Nihongo skills but I believe the translation of the text besides my pic is roughly: "His looks are wasted on identity, he should be in the movies".

It's either that or "Who ironed that shirt" (I'm finding verb tense a bit of a challenge).



Ceremonial Trappings

Aldo has an interview with Drummond Reed, Johannes Ernst, and Chris Messina talking about the importance of usability design and user experience to OpenID.

Like Kim, they refer to the importance of ceremony for users around identity transactions. Pam touches on the same.

Chris refers to the possible advantage of, at least initially perhaps, allowing for experimentation. Let different communities try different ceremonies and user interface paradigms and learn from the collective experiences. Fundamentally, recognize that we have much to learn here and we probably shouldn't think we can get it right the first time. This belief (admittedly as well as a recognition that user interface design was a potential differentiator for vendor's offerings) is the primary reason that the Liberty Alliance has never attempted to tackle this aspect of identity.

Separately, from the chat, you might get the impression that mobile clients present no special challenges or opportunities for user ceremony. It's hard enough for me to enter my email address on a phone but I'll take the 5 minutes to type in URL? How many users know how to find the '/'?

Update: I wrote the above before I got to the point of the interview where Johannes does briefly mention devices.

Aside from that, all other ceremonies I attend always end up with me wearing a suit. That's going to significantly slow down my log-in.

I'm not one to judge

But the stats for ths blog do show an increasing number of people arriving here after searching for 'federation promiscuous eve'.

Whatever clubs Eve chooses to belong to are of course a personal matter for her to decide. But perhaps the organization could pay for some search engine optimization to drive their placement up (and mine down).

Nature abhors an (identity) vacuum

The "nature abhors a vacuum" idiom is used to express the idea that empty space is unnatural (or improbable) as it goes against the laws of physics. It was first coined by Aristotle to explain how water pumps work. He theorized that, if you pump air out with the lever, something must flow into the place of where the air was, which is the water.

The pump works because Nature hates the idea of empty space and so fills it with whatever it has at hand. Give Nature enough time, and it will find a way to break the seal of a Thermos bottle and fill the vacuum that keeps soup hot and beer cold.

This idea of an absence of something enjoying only tenuous existence because the environment will always endeavour to provide that missing substance is, I believe, a nice analogy for anonymity.

What is anonymity but an 'identity vacuum' (its etymology means "without a name")? Anonymity refers to a state in which there is insufficient identity information to allow a user to be identifiable within some set. So, like a vacuum, it's a state defined by the absence of something, namely identifying information. Also like a vacuum, anonymity need not be absolute, you can have partial anonymity as you can have partial vacuums.

Importantly, anonymity is a tenuous state. Like air rushing in to a crack in a thermos bottle seal at the first opportunity, identifying information will always (eventually) leak into anonymity from the environment. However well a system is designed to enable anonymity, outside forces are always trying to find a crack through which identity can be pushed. The leakage may come from recognizable facial or voice characteristics in off line interactions, or from an IP address or buying patterns in those engaged in online. But, wait long enough, and it will happen. Anonymity, like a vacuum, is a fragile state of being (and should be recognized as such).

From this exploration, I posit the following (dare I say it) 'Law of Identity':
If there exists a region of anonymity relatively devoid of identity, identifying information from the environment surrounding that region will attempt to redistribute itself so as to fill said void.
As an exercise I leave it to the reader to develop the "'Surfing Adult Sites at Work' Corollary".

Wednesday, November 15, 2006

I'm confused (and that's the problem)

Johannes asks people to consider whether or not a mashup of SAML and OpenID makes sense.

I don't see why the issue is any different than that which motivated a previous convergence between LID, Sxip, DIX, and OpenID - this manifested as OpenID 2.0?

There was duplication between these systems, now there is none (or less?). Less duplication means less confusion (I personally love no longer having to know what Passel does or doesn't do).

Between SAML and OpenID there is more and more duplication - this because:
  1. the OpenID community is adding new functionality to OpenID 2.0 for which there are existing equivalent mechanisms in SAML, and
  2. the SAML community is exploring how to enable SAML for use cases historically the purview of OpenID (and its erstwhile counterparts).
Less duplication would be 'better' because it would mean less confusion (amongst developers, vendors, customers, end-users, wives, etc).

Do we need more justification than the goal of creating a simpler marketplace - one unfragmented by confusion over multiple and incompatible identity systems?

Distributed Transaction Authentication

An interesting discussion of transaction authentication:
Transaction authentication is software residing on the enterprise security servers that monitors, in addition to the successful use of user id and password the:
  • IP address the user is coming in from
  • Users geolocation
  • Computer hardware the user is using
  • Time of day
  • Previous user pattern of behaviour
What if the scope of the 'transaction' were broadened, i.e. to include behaviours performed at an SP after the user SSO'd in from an IDP?

If the user's behaviour at the SP didn't fit previous transactional patterns (such as those listed above), should the SP alert the IDP as to that fact? There are, AFAIK, no protocols that would support such a call.

Or would the SP simply send the user back to the IDP with a request for an new authentication - this time with a mechanism that would better serve to erase the doubt in the SP's mind.

The semantics seem different, a simple request for authentication doesn't allow the SP to express it's reasons for concern and flag these to the IDP - this potentially important if the IDP has to decide to alert other SPs to which it has recently asserted the user's identity.


Chillin' (I think)

Julian's post alerted me to his Last.fm profile.

Last.fm did not have high hopes for our musical compatibility. I'm happy to report them (mostly) wrong.

I can imagine a similar 'Interop-0-Meter' assessing the potential of different identity systems working together.

"You share a few logical functions in common, including: IDP discovery, request for authentication, artifact ...


Complaints from Finland

The Helsinki Complaints Choir is particularly timely for me personally as I deal with errata for the Liberty Alliance People Service.

I've contacted the choirmaster to suggest that the following lyrics be added:
  • "Why on earth is the TargetID Optional?"
  • "I hope this was a typo because otherwise the processing rule makes no sense"
  • "I know I've said it before but I strongly disagree with this approach"
  • "We also regularly lose to Canada in hockey"




HTML to blame for porn

At least, that's the reasoning Johannes seems to use when he expresses doubt about the relevance of SAML to Web 2.0.
I got to say that I'm a sceptic on this. I don't think that there has been an existence proof for the successful combination of SAML and Web 2.0: putting control in the hands of the end user — the essence of Web 2.0 — is not typically compatible with the way SAML projects tend to end up.
The argument appears to be 'because SAML can be deployed in ways that don't directly/explicitly/visibly empower users, it can't be deployed otherwise'. Similiarly, because HTML can display porn, or violence, or politicians, it can't be used for more noble purposes.

Notwithstanding his doubt, Johannes signed up for the Liberty Alliance Open Source Identity Webinar and appears willing to have his SAML notions challenged.

Johannes also points out the irony in Liberty requiring Webinar attendees to create an account. A legitimate objection, and one for which steps are being taken (or at least being discussed). I expect Johannes will appreciate the extra irony in this being pointed out by someone who throws up a not insignificant barrier to anybody wishing to leave a comment on his blog.

Tuesday, November 14, 2006

Get on board

Johannes points out the Open Healthcare Manifesto.

I expect the Liberty Alliance's eHealth Special Interest Group would have an opinion on the relevance of Liberty's architecture to certain of the stated principles, e.g. empowerment, trust, privacy, anonymity. I've even seen occurrences of "civility and respect" at Liberty meetings.

I'm not so sure about using a train as an analogy for identity though. According to the criteria of some, for it to be truly "user-centric", the user would be able to force the railroad lines to lay tracks to any and all desired destinations, irrespective of cost, timeliness, and environmental damage. Such a 'narrow gauge' provides a shaky foundation for high-speed travel.


Sunday, November 12, 2006

Remembering (Canadian style)

My son's hockey team had a game yesterday that spanned the 11th hour of the 11th day of the 11th month.




Friday, November 10, 2006

We need an IIW in Panama

Hypothesis - the level of promiscuity of an SP/RP (measured by its willingness to engage in identity transactions with IDPs) will demonstrate a strong negative correlation with the level of security that SP/RP expects for such transactions.

Highly promiscuous SPs/RPs will expect/require less security, selective SPs/RPS will require more (so, amongst other things, they can be sure they are dealing with the IDPs they think they are). What insight!

A consequence of the above is it's possible to combine 1) high security and promiscuous behaviour and 2) low security and discerning partner selection. Possible but not very logical. For the first combination, you are paying for security you don't need; for the second, you probably have insufficient security for your risk model.

I think OpenID and SAML have successfully found the right (but different) mixes of promiscuity and security. OpenID has focussed on promiscuous providers with an appropriate level of security, SAML on the opposite pairing. This is shown graphically below. Along the horizontal is SP selectivity (the opposite of promiscuity), along the vertical a measure of security.

So, both SAML and OpenID seem to have discovered distinct and valid islands. Nice. But, seems to me that both of late are exploring moving beyond these domains. OpenID is allowing for additional security options to OpenID 2.0, SAML to allowing for less security through the proposed SimpleSign binding.

Problem is, while OpenID is adding security, there is less evidence of that community defining mechanisms in support of less promiscuous partner selection (at least in the core spec and not deferred to extensions). Likewise, while SAML is allowing for security to be more a deployment decision, no mechanisms in support of more promiscuous SP/RP behaviour are being defined in the SSTC (like URI-based IDP discovery or something akin to OpenID's association mechanism). Consequently, OpenID appears to be expanding directly upwards into a zone of 'Pointless Overkill', and SAML straight down into a zone of 'Insufficient Security'.

We need an isthmus stretching from lower-left to upper-right - it's there that the "sweet spot" of convergence lays (and which keeps us well clear of the dangerous shoals threatening to tear a hole in the hulls of each ... blah blah blah).



OpenID Extensibility for Strong Auth

In response to my puzzlement, David points out plans for an extension to OpenID that would allow an IDP to distinguish between the nature of the authentication mechanism - and thereby allow the value of stronger methods to extend down to the RP.

This is good to hear. I'd really hope that the OpenID community, in specing out this extension, look at what SAML has done in the area. Additionally, I think its important that, in addition to the IDP being able to say 'This happened', the RP should be able to say 'I want this to happen'.

Avery also commented on the post. Interestingly, in describing the planned extension, he wrote:

about the method of identification at the point of enrollment and the method used when authenticating
Differentiating between (and accounting for both) how the user was registered and how they were authenticated is something SAML's Authentication Context makes possible, most notable examples of which are the 4 mobile targetted AC class URIs that differentiate based on whether the user has a contracted account or is pay-as-you-go.

In his own comment, Pete suggests:
The RP doesn't have to bother but if it chose to it could keep track of those providers that provide strong auth and act appropriately when those IdP's are the ones doing the authentication.
This could work if an IDP only supported a single authentication mechanism. If not, the RP wouldn't know which was used for any given assertion.

Pete then writes
What higher level value is a claim of strong auth from an IdP when there is no trust between the IdP and the RP anyway?
Indeed, but if the RP doesn't trust the IDP, its unlikely to care about how the IDP authenticated the user. And if the RP doesn't care, why would the IDP go to the extra cost and effort?





Thursday, November 09, 2006

Voice Authentication Value-Add (VAVA)

Just listened to Aldo's interview with Avery Glasser of VXVSolutions, talking about their integration with OpenID.

Interesting 'hear'. But one piece confused me. In describing the sequence by which a user would use their voice authentication to OpenID into LiveJournal, Avery said the following:

So, to LiveJournal, it thinks that you just went to any standard OpenID implementation
.
.
it doesn't know that, instead of just putting in your log-in and your password, that you were actually going through and authenticating yourself by voice.
Tying in Strong Authn to SSO is great - the two pieces complement each other perfectly. Strong Auth gives SSO 'something to do' and provides value to the RP beyond convenience to the end users, and SSO makes Strong Authn practical and cost-effective.

But this only works if the value of the strong authentication can flow to the RPs - this implying that the RP knows that the user actually used something beyond a password to log-in to the IDP. But, OpenID doesn't support anything to allow the IDP to make this distinction (nothing comparable to SAML's Authentication Context).

With OpenID as it is (or AFAIK expected to be in OpenID 2.0), the RP would be unable to provide a voice-authenticated user any different level of service than a password-authenticated user - this because the IDP isn't able to indicate to the RP that something different happened. The value of the strong authentication effectively disappears at the door. So, why would the RP bother?

Pimp my ID

Ping's Ryan Hunter responds to my post describing a morality scale of sorts for identity transactions.

Ryan questions my premise that providers will allow their users to select their partners (I think of this as a pimp-centric model).

In reality, identity providers will never allow users to drive the partners with which they engage in identity transactions, unless the user(s) have leverage in their relationship with the providers and and also the identity provider has leverage over its partners too.
This was actually the point I was trying to make. I think user's can indeed have this sort of leverage over providers, but ultimately it's granted to them at the discretion of the providers.

So, providers could allow the users to direct them to other providers. The point I was trying to make was that the providers will be content doing so right up to the point where they are no longer content doing so - this when the risks of such promiscuous relations outweigh the advantages.

In Ryan's analogy, the 'model' at the bar might allow the bouncer to introduce Brad to her with a 'This is Brad, I think you guys are perfect for each other'. She might see my own introduction in a very different light (better of course).


Seriously?

Jamie Lewis points out Seriosity.
Carbon (Beta) is an enterprise productivity application, inspired by successful interactive games. It creates an economic system with its own currency and market that allows users to better manage their attention and that of others.
Sounds like the model is "Read this email and I'll slip you a fiver".

I'd want to see an on-screen meter showing my 'vacation day status' - this changing daily as I go about my business. Have a productive day, get an hour of vacation added. Spend the morning blogging, lose 30 minutes.

How would I fill up my health (benefits)?

No identity in Web Science?

Tim Berners-Lee and academia have created the Web Science Research Institute.

What appears to be a related publication is 'A Framework for Web Science'.

I find it strange that in a paper of 130 pages that purports to describe the Web and how it works, there are only 13 references to identity.

And no references at all to any of SAML, Liberty Alliance, OpenID, SSO, user-centric, federation, Cardspace, etc.

Perhaps all the work has been done in identity and so there need be no further research? As opposed of course to that frenzy of real-world implementation that is the Semantic Web.