Monday, September 19, 2011

I refuse to call this 'Baking as a Service'

So the story goes, when Betty Crocker instant cake mixes were initially introduced, they sold poorly. But why? the mixes made trivially easy what had been a long and messy process.

The problem, according to the business psychologists Dr. Burleigh Gardner and Dr. Ernest Dichter, was eggs. They argued that powdered eggs should be left out, so cooks could add a few fresh eggs into the batter, giving them a sense of creative contribution.

Though it would mean more work for the (inevitably aproned) housewives, the hope was that cracking an egg into the bowl would give her some pride of creation in the resultant cake and mitigate any feelings of spousal & maternal guilt.

The premise of combining fresh ingredients with pre-made has been formalized with the 'semi homemade' movement in cooking - the approved ratio is that 70% of fresh ingredients like vegetables or meat supplements the 30% of store bought mix or sauce.

The moral of the story for cloud identity management?

A mix of on-prem & on-demand IdM infrastructure will give to the enterprise the right balance of control and convenience - the store bought on-demand mix means that the (probably less likely to be aproned but hey I don't judge) IT admin need not build a cloud identity solution from scratch, while the on-prem eggs ensures that they can maintain the desired level of ownership that allows them to meet their CISO at the end of each day with a guilt-free conscience (and maybe also a dry martini).

New line of greeting cards

Friday, April 29, 2011

Scoping scope

ReadWriteWeb describes Twitter's new consent UI by which an application asks of a user access to their Twitter account.

Aside: RWW describes this page as the 'OAuth screen', makes just as much sense to call it the 'HTTP screen'. OAuth is the plumbing for this screen, not the (visible) shower curtain.






 RWW points out that the list of allowed actions isn't quite as complete as indicated. Notably omitted from the list is 'Read that DM where you made fun of your boss's new haircut'.

The UI might make a user believe that this list of permissions is unique to Favstar.FM. But that's not the case - these are generic permissions, afforded to all (registered) applications. The only differentiation in permissions that Twitter supports is between 'read' & 'read and write', this selected by the application developer at registration time



Twitter's model ignores a key advantage of the OAuth model (one not supported by the password anti-pattern), namely allowing a user to give differentiated permissions to different applications.

Separately:
  • Red & green text? Really?
  • Does the stuttering repetition of 'Favstar.FM' imply a glitch in the code? or an overzealous registration page?
  • The list of things the app will not be able to perform seems incomplete. I suggest the following additions at minimum