Friday, September 28, 2007

Congrats to Prateek

Although I haven't seen an official announcement, I'll go out on a limb and offer my congratulations to Oracle's Prateek Mishra on the big news - undeniably well-deserved.

Oh, and there is also that DIDW thing for IGF. That's nice too.

Tags: ,

Encrypted Protocol Messages


Zlango defines a 'universal icon language', emoticons having been deemed to provide insufficient cuteness for real business messaging.

At the top is a SAML protocol message translated into Zlango-ese. Undeniably way more fun than plain ol' XML.

Any guess as to the message?

Hint: Below is the same message with captions turned on.


Answer: it's an <AuthnRequest> in which the SP is stipulating that the IDP should not actively interact with the user for authentication, and username/password is unacceptable.

Tags: ,

Thursday, September 27, 2007

It takes a village

Andy Dale ponders the 'juju' that OpenID has, in comparison to SAML. He uses the analogy of a village to tease out differences.

My thoughts
  1. OpenID is designed for 'fun' use cases. It's just more fun to talk about Twitter than an enterprise employee accessing their health records.
  2. Inversely correlated to their 'fun' level is the value of the applications being accessed through OpenID SSO. With low value apps, OPs & RPs need not overly concern themselves with the mundane issues of business relationships, contracts, and lawyers (which would be the opposite of fun).
  3. Because of #2, there are more visible places for users to play with OpenID. Being able to play with a technology is key. It's highly likely that you have benefited from SAML-based operations, but you were unaware of it.
  4. OpenID has a video.
  5. OpenID has a logo.

Personally, I enjoy the infrastructure services (e.g. water, sewage, electricity, cable, etc) that modern city living provides me. Actually I live in the suburbs, perhaps that's the ideal compromise?

p.s. Andy throws in an evolutionary twist to his analogy
If two teams of engineers looked out over an early version earths eco-system and one designed ‘the perfect organism’ and the other designed an ameba capable of rapid reproduction and innovation which would you bet on for long time survival?


This sounds too much like Intelligent Design.

A Tangled Web (not so much)

Johannes compiles a nice list of identity initiatives.

There is some 'appling & oranging' going on, I think more useful would be to categorize the various groups & initiatives. Here is my stab at a taxonomy:

Specifications

OpenID, SAML, WS-*, ID-WSF, ID-FF, Shibboleth, YADIS, XRI/XDI, OAuth, XACML

Spec Definition Bodies

OASIS, OpenID community, Liberty Alliance, IETF, W3C, ID Commons, ITU, Internet 2, Google groups

OpenSource Software

Bandit, Higgins, OpenLiberty, OpenID for PHP, OpenSAML, ZXID, SimpleSAMLphp

Discussion Forums

ID Gang

Metasystem initiatives

Concordia, Cardspace & OpenID 'partnership'

Conferences/Meetings

Catalyst, RSA, DIDW, IOS

Use cases

User-centric, VRM, enterprise, mobile

With this we can write sentences like

[Specification], defined by the [Spec definition Body] has been optimized to support [Use Case] identity. Work is underway to create software libraries at [Open Source Software]. There will be an interop demonstration of [Specification] and [Specification] working together, as profiled at [Metasystem initiative] at [Conference/Meeting]. Meanwhile, bickering continues on the [Discussion Group].

Maybe we could even standardize the above boiler plate to ensure consistency of PR?

Co-opted

CoScripter is a Firefox extension from IBM (a real Web 2.0 company):

for recording, automating, and sharing processes performed in a web browser such as printing photos online, requesting a vacation hold for postal mail, or checking bank account information. Instructions for processes are recorded and stored in easy-to-read text here on the CoScripter web site, so anyone can make use of them. If you are having trouble with a web-based process, check to see if someone has written a CoScript for it!

As I have to assume that the recent alarming drop in readership of this blog is due to my erstwhile readers now having trouble with the surfing process (e.g. scrolling and clicking), I have created a Coscripter script to automate the steps.


I must remember to upgrade my account in anticipation of the surge in traffic.

Wednesday, September 26, 2007

Biblical Proportions


I wonder if a year of living by the Laws of Identity would have the same effect on facial hair as did a year following the Old Testament's MUSTs & MUST NOTs (very few SHOULDs & MAYs if I recall).

Not at all equine-centric

Slate reports on the practices of the thoroughbred horse naming authority.

But who speaks for the horses?

Tuesday, September 25, 2007

An IDDY BIDDY award

NTT was awarded one of the 'proof of concept' IDDY awards for our development of a smart identity client for mobile phones - SASSO.

Monday, September 24, 2007

<foaf:thesisAdvisorOf>

A genealogy of theoretical physicists.

It looks like Enrico Fermi wins the 'Kevin Bacon' award.

And yes thanks I am aware that FOAF doesn't define a <thesisAdvisorOf>.

Thursday, September 20, 2007

What I did, and how I did it

For an SP accepting an IdP's assertion that some user has authenticated, the 'what & how' will often matter. All else being equal, an assertion issued after the user authenticated with an OTP is 'better' that one resulting from presentation of a password, better in the degree of confidence that the SP can ascribe to it.

Frameworks that enable the SP & the IDP to have the discussion of the 'what & how' (whether that discussion happens in a board room with the suits or 'on the wire') can be categorized as:
  1. those that simply provide a syntax for describing technologies & processes that impact assurance, (e.g. SAML 2.0 Authentication Context)
  2. those that define buckets into which combinations of technologies & processes can be placed, (e.g. SAML 2.0 AC classes)
  3. those that define buckets into which combinations of technologies & processes can be placed, distinguished by the security characteristics they can provide (e.g OpenID PAPE)
  4. those that define buckets into which combinations of technologies & processes can be placed, distinguished by the level of assurance they can provide (e.g NIST 800-63 combined with OMB 04-04
I'd argue that 1) is the most powerful/flexible, 4) is the simplest.

Identity Pop-up Video

If you wanted to play around with a new video annotation service, and you wanted to pick a video that everybody in 'identityland' would know and recognize, what video would you pick?

Anything come immediately to mind? Anything?



Or here.

My experiments end at 2.42 in.

Even Bob has covered it.

Tuesday, September 18, 2007

How ironic

Identity assertions would benefit from markup to express undertones of meaning. Imagine how much richer would an IdP's claims to an SP be if they could express the following:

"She is a Senior VP"

"His credit rating is average"

"She has a wonderful personality" ¡

Topcoder & SAML

Topcoder runs software competitions in order to bring companies together with programmers and to create a library of software components.

Presumably a previous competition resulted in their SAML Framework.

If only there were a competitive category for 'snideness'. Is it even possible to code snidely?

Monday, September 17, 2007

You know you're old

when your social network provides games designed to maintain your brain.



Maybe there needs to be a Twitter designed specifically for Seniors, a place where they can bitch about their sore backs and tell their friends when they last moved their bowels.

Wednesday, September 12, 2007

Liberty Certification --> GSA Certification

GSA E-Authentication news

GSA will accept applications from SAML 2.0 providers for interoperability testing based on the SAML 2.0 technical architecture and interface specifications. As a pre-requisite for such testing, GSA requires that providers complete the Liberty Alliance SAML 2.0 interoperability testing requirements for the Liberty Interoperable certification program.

HRM (Hooker Relationship Management)

Phone rings

John: Hello
Babs: Hi Sugar, this is Babs calling. I saw your RFI on your blog.
John: (puzzled) RFI?
Babs: 'Request for Intercourse'. Did'ya forget about putting that up?
John: Oh jeez, I was drunk, I didn't think I actually hit the submit button.
Babs: Gotta luv those microformats - they do sneak out. But never mind that, I still think I can make you an offer that will meet your intercourse criteria.
John: OK, well I guess it wouldn't hurt to talk ....
Babs: Not a bit honey. Now, are you thinking about a long-term relationship? I can give a volume discount
John: Err, I think I'll wait and see ...
Babs: Fair enough, now the RFI didn't mention toys, you like them?
John: Toys? Like in Webkinz?
Babs: Oh my, you are the kinky one, sure we can work something out for Webkinz....But, that'll be extra.
John: Hey, you know, I uh, this doesn't feel right, I'm not interested..
Babs: Oh, that's too bad Sugar, But maybe you have some friends that might be?
John: Just grab the FOAF from my blog, but don't tell them I sent you OK.

Tuesday, September 11, 2007

Chiro


I grudgingly believe that chiropractic can offer real value & benefit to sufferers of back-pain. While it never did anything for me when I had back troubles, others swear by it. So, I concede there is probably something real going on, whether it's the relaxation of 'subluxations' or something else.

What I find to be complete quackery are those assertions by some that chiro has benefits far beyond the spine & vertebrae. There are claims for fixing sleep apnea, the common cold, allergies, Erectile Dysfunction (which by the way is a serious issue for many men - normal every-day young healthy men who should not be mocked) etc.

When I hear these claims for chiro, I think to myself 'They're over-reaching', i.e. attempting to apply a therapy beyond a valid & justifiable scope. Ultimately, these claims do more harm than good, tainting the reputation of the profession for more legitimate applications as they do.

I think the same thing when I hear OpenID described as possibly appropriate for high-value applications like banking - it's over-reaching, claiming scope that is unsupported by the security characteristics that the protocol affords (irrespective of how the user was initially registered or subsequently authenticated). And ultimately, like for chiro and cancer, the reputation of the valid application is damaged.

Kim seems to agree (on the over-reaching thing, I'm not sure where he stands on ED). Stefan clearly thinks that even claims that OpenID can help mitigate back pain are quackery.

Monday, September 10, 2007

Persona Roulette

urlsplit allows you to map multiple URLs into a single.

I created http://www.urlsplit.com/KXOpyy8v for 3 of my OpenIDs. Each time you try the URL you'll get one of the 3 OpenIDs (or a mystery link).

I think this service could be really useful for someone suffering from multiple personalities. Provide the split URL to an OpenID RP and sit back and wait to see which persona you get.

Identity Session KIller

David, on Dilbert, on the term 'Web 2.0', and its ability to derail meetings.

'User-centric' will just as effectively kill the productivity of a session at an identity together. 'Trust' is a close second in lethality.

I must remember that the next time my slides aren't done in time. Just put up a single slide with 'User-centrism & Trust - diametrically opposed?' in a big font and sit back.

'The bar is open' has also been known to work

Sunday, September 09, 2007

Full Points

to someone named 'Anonymous' (is this a Greek name?) for decoding my QR riddle.

Hey, faith is a very personal thing.