"Dr Livingston I presume you are aware that it's been over 6 years since I invited you to join my LinkedIn network? Don't mean to sound stuffy old chap but you could have saved me this rather tiring trip if you had just given me the courtesy of a reply what?"
When you don't have anything nice to say, well then perhaps its time consider a career as an analyst.
Wednesday, April 04, 2007
History T'ID'bits
Overheard on the shores of Lake Tanganyika
User-centric tax filing
Yesterday evening, I used an online service to do the family's Canadian personal income taxes.
The mechanism for electronic filing of the returns to the Canada Revenue Agency captures both the benefits and issues of the 'user-mediated' channel for identity flow through the user-agent.
The process is illustrated here:

You download the special .tax file to your desktop, and then in a separate browser session, upload it to the CRA site. Repeat for spouse.
How very empowering! I am in complete control of transfer of our tax/identity information from the tax provider to the CRA. In fact, without my explicit consent and actions, the info just will not flow.
For me personally, I would have much preferred for the tax service provider to interact directly with the CRA to submit the files 'on my behalf' - saving me
The mechanism for electronic filing of the returns to the Canada Revenue Agency captures both the benefits and issues of the 'user-mediated' channel for identity flow through the user-agent.
The process is illustrated here:

You download the special .tax file to your desktop, and then in a separate browser session, upload it to the CRA site. Repeat for spouse.
How very empowering! I am in complete control of transfer of our tax/identity information from the tax provider to the CRA. In fact, without my explicit consent and actions, the info just will not flow.
For me personally, I would have much preferred for the tax service provider to interact directly with the CRA to submit the files 'on my behalf' - saving me
- the effort
- the security risk of having such sensitive information sitting on my laptop.
Tuesday, April 03, 2007
One of these things is not like the others,
Plausible deniability
Webkinz is all the rage for my kids and their friends. It's inane and senseless but I try not to judge it as simply juvenile because, well, Twitter.
From the Webkinz site
The animals are quickly forgotten - it's the 'Secret Codes' that the kids want. Without the code that comes with the pet you can't enter the fun exciting virtual world. Consequently, kids place great value in the codes. Search on the Web and you'll see a whole marketplace for them.
That explains why, when my 7-yr old son was playing at a friend's house the other day, and they were logging into the Webkinz site, my boy left the room when his friend entered the code (as reported to me by the Dad). I asked my son about it before he went to school today. I asked him if he left the room because he wanted to, or because his friend has asked him to. His reply
I wanted to, I never want to know somebody's else code in case something goes wrong and they might think I did it.
Smart boy. I'm all verklempt from pride.
From the Webkinz site
Webkinz pets are lovable plush pets that each come with a unique Secret Code. With it, you enter Webkinz World where you care for your virtual pet, answer trivia, earn KinzCash, and play the best kids games on the net!The 'lovable plush pets' are $2 stuffed animals that sell, when you can find them, for over $10.
The animals are quickly forgotten - it's the 'Secret Codes' that the kids want. Without the code that comes with the pet you can't enter the fun exciting virtual world. Consequently, kids place great value in the codes. Search on the Web and you'll see a whole marketplace for them.
That explains why, when my 7-yr old son was playing at a friend's house the other day, and they were logging into the Webkinz site, my boy left the room when his friend entered the code (as reported to me by the Dad). I asked my son about it before he went to school today. I asked him if he left the room because he wanted to, or because his friend has asked him to. His reply
I wanted to, I never want to know somebody's else code in case something goes wrong and they might think I did it.
Smart boy. I'm all verklempt from pride.
Tuesday, March 27, 2007
What was I about to say?
Short Attention Span System (SASS) does for radio what Cliff's Notes does for literature, condenses.
The value proposition is simple, radio listeners can't pay attention to the epic 4 minute pieces that some artists currently create.
I'd love to see the abbreviated model applied to airline fare rules - an example of which has me currently stumped as to whether I can upgrade or not
The value proposition is simple, radio listeners can't pay attention to the epic 4 minute pieces that some artists currently create.
Radio SASS. (Short Attention Span System) takes the playlist and musically condenses songs to their essence. Through time compression, you get the memorable heart of each song, with an average length of aproximately two minutes with NO self indulgent guitar solos, NO long intros, NO repetition of choruses again and again. Radio returns to the snappy song length of the 1960s.
I'd love to see the abbreviated model applied to airline fare rules - an example of which has me currently stumped as to whether I can upgrade or not
Fare rules and restrictions
Please review the rules and restrictions listed below.
When you purchase your ticket, you agree to these rules and restrictions.
Please note that the most restrictive set of rules below applies to your entire itinerary.
1 Rules and restrictions
Air Canada
From: Ottawa, ON (YOW-All Airports)
To: Brussels, Belgium (BRU-All Airports)
Fare Basis Code: Q0MSLWBE
YOWBRU-AC 28MAR07 *RULE DISPLAY* TARIFF 0101 RULE 9422
* ADD APPLICABLE TAX * FED INSP FEES *
-FARE BASIS CAD NUC PTC FT GI
Q0MSLWBE R 940.00 820.76 ADT EX AT
Q0MSLWBE R 960.00 838.23 ADT EX AT
Q0MSLWBE/CH25 R 705.00 615.57 CNN EX AT
Q0MSLWBE/IN25 R 705.00 615.57 INS EX AT
Q0MSLWBE/IN90 R 94.00 82.07 INF EX AT
BOOKING CODES Q
FIRST TRAVEL -12AUG06 LAST TRAVEL -30APR07
LAST TICKETING -30APR07
SEASONS - ORIG BELGIUM 01JAN-12JUN
DEPARTURE FIRST INTERNATIONAL SECTOR
19AUG-15DEC
DEPARTURE FIRST INTERNATIONAL SECTOR
ORIG CANADA
FURTHER RESTR APPLY SEE TEXT RULE
PENALTIES - ORIG CANADA CANCEL-200.00 CAD
CHANGE-200.00 CAD
ORIG AREA 2 CANCEL-100.00 EUR
CHANGE-100.00 EUR
FOR ALL CONDITIONS SEE TEXT RULE
DAY/TIME - TO CANADA FRI THRU SUN ALL DAY
DEPARTURE EACH TRANSATLANTIC SECTOR
FROM CANADA THU THRU SAT ALL DAY
DEPARTURE EACH TRANSATLANTIC SECTOR
ADV RES/TKT - TKTG WITHIN 72 HOURS AFTER RESERVATIONS
WAITLISTING NOT PERMITTED ALL SEGMENTS
MUST BE CONFIRMED
MIN STAY - RETURN FIRST SUNDAY AFTER
DEPARTURE FROM ORIGIN
MAX STAY - 12 MONTHS AFTER DEPARTURE FROM ORIGIN
BLACKOUTS - NO RESTRICTION
SURCHARGES - 10.00 CAD 7.00 USD SECURITY
ADDITIONAL RESTR APPLY SEE TEXT RULE
STOPOVERS - ORIG CANADA
PERMITTED-2 OUTBOUND 1 INBOUND 1 AT
50.00 CAD EACH
DEPARTURE FIRST INTERNATIONAL SECTOR
ORIG BELGIUM
FURTHER RESTR APPLY SEE TEXT RULE
TRANSFERS - UNLIMITED PERMITTED
FLT APPLIC - NO RESTRICTION
CHILD DISC - CNN 2-11 YRS 25 PCT ACCOMPANIED
INS UNDER 2 YRS 25 PCT WITH SEAT
INF UNDER 2 YRS 90 PCT NO SEAT
OTHER DISC - NONE
COMBINABLTY - SEE TEXT RULE
ELIGIBILITY - NO RESTRICTION
ACCOM PSGR - NO RESTRICTION
TRVL RESTR - NO RESTRICTION
SALES RESTR - SEE TEXT RULE
EXTENSION OF TICKET VALIDITY PERMITTED UNDER
GUIDELINES SET FORTH BY CARRIER. CONTACT
CARRIER FOR DETAILS.
NEGOTIATED - NO RESTRICTION
TKT ENDORSE - ORIGINAL TKT - VALID AC TRANSATLATIC ONLY
REISSUED TKT - NON-REF/NON-END
MUST APPEAR IN ENDORSEMENT BOX
APPLICATION - SEE TEXT RULE
Monday, March 26, 2007
Friday, March 23, 2007
You have to feel for the guy
On the Identity Trail reports that 'someone has their identity stolen every 4 seconds'.
They don't provide a name so we can't know for sure what it is that makes this particular individual such an attractive target. Is it just a case of this someone being unusually trusting?
They don't provide a name so we can't know for sure what it is that makes this particular individual such an attractive target. Is it just a case of this someone being unusually trusting?
Science is Truly Amazing
Scientists Discover New password in Alaskan Ice
JUNEAU, AK - Alaskan computer scientists are today reporting tentative evidence that they have discovered a new password - extending the number of known unique passwords to 47.
Dr. Peter Lyndstrom and his team of computer scientists at Alaska Tech University have been looking for the so-called 'X password' for 3 years now, using millions of dollars of expensive computer equipment. 'It's been a really long slog', said Dr Lyndstrom 'Sometimes I've even questioned whether the thing actually existed.'
In the end, it wasn't through expensive computers that the new password was discovered. Instead it was good ol' fashioned luck. “We were at a team party and somebody came up with the idea of just sticking existing passwords together, specifically 'm y' onto the end of 'm o m'. And well, after that it just kinda all came together” said team member Gail Svenson. “The frozen daiquiris definitely helped” she added.
Dr Lyndstrom's team is not stopping here. They plan on moving onto variations of the 'first car' theme, historically a rich ground for new passwords but relatively untapped since the car makers trend towards silly names.
JUNEAU, AK - Alaskan computer scientists are today reporting tentative evidence that they have discovered a new password - extending the number of known unique passwords to 47.
Dr. Peter Lyndstrom and his team of computer scientists at Alaska Tech University have been looking for the so-called 'X password' for 3 years now, using millions of dollars of expensive computer equipment. 'It's been a really long slog', said Dr Lyndstrom 'Sometimes I've even questioned whether the thing actually existed.'
In the end, it wasn't through expensive computers that the new password was discovered. Instead it was good ol' fashioned luck. “We were at a team party and somebody came up with the idea of just sticking existing passwords together, specifically 'm y' onto the end of 'm o m'. And well, after that it just kinda all came together” said team member Gail Svenson. “The frozen daiquiris definitely helped” she added.
Dr Lyndstrom's team is not stopping here. They plan on moving onto variations of the 'first car' theme, historically a rich ground for new passwords but relatively untapped since the car makers trend towards silly names.
Thursday, March 22, 2007
Product Placement
This time he's gone to far.

The untampered-with Advanced Client overview is available here.

The untampered-with Advanced Client overview is available here.
Tags: Liberty Alliance, Advanced Client
Wednesday, March 21, 2007
Putt's Law
Putt's Law was pointed out to me yesterday
Madsen's Corollary to Putt's Law
Technology is dominated by two types of people: those who understand what they do not manage, and those who manage what they do not understand.
Madsen's Corollary to Putt's Law
Putt's Law applies even when the people of the first type are 'promoted' to become people of the second type.
Just one Number
GrandCentral does for phone numbers what i-names would do for online identity - with the same advantages and risks.
I remember the previous incarnation of the 'Grand Central' identifier - completely different business model. Good thing names can be bought and sold.
I remember the previous incarnation of the 'Grand Central' identifier - completely different business model. Good thing names can be bought and sold.
Liberty Alliance Advanced Client
The Liberty Alliance Advanced Client specs were actually released for public comment some time ago but the press machine (Hi Russ) has caught up.
Most notable pieces of functionality are IMHO
In the spirit of 'tail-wagging-dog', lots of attention.
I'm thankful Conor wasn't able to slip in his blog URL in his supporting quotes (I guarantee you he would have been thinking about how to do it).
Most notable pieces of functionality are IMHO
- the over-the-air/wire provisioning of 'root' credentials and other identity into a client
- supporting a model of credential presentation in which the IDP need not be involved at run-time (relevant for both privacy value and in support of offline modes)
In the spirit of 'tail-wagging-dog', lots of attention.
I'm thankful Conor wasn't able to slip in his blog URL in his supporting quotes (I guarantee you he would have been thinking about how to do it).
Tags: Liberty Alliance, Advanced Client
History T'ID'bits
Overheard in Philadelphia
Oh absolutely President Hancock, digital signatures are wonderful technology. But we were actually expecting the old-fashioned ink-and-pen style for the declaration. It's the press you see, they want something nice and visible for the papers.
A says B can do X to Y
Lately, a model whereby some Entity A assigns certain privileges to Entity B with respect to the resources of Entity A is getting lots of discussion.
There are flavours of the above, depending on where the above logic is defined, where it's enforced, and whether all actors are cognizant of what's going on.
If the logic is captured and enforced at the provider hosting the resource in question, then it's a local affair and effectively boils down to an authorization rule at that provider. (Liberty People service is an enabler of this scenario, allowing such local authorization policies to be defined in terms of non-local identities.) In this scenario, even were Entity B to appear at the SP as a result of an SSO from an IDP, that IDP need not be aware of the policy.
If however the resource in question is Entity A's IDP account, then there are potential non-local ramifications should Entity B attempt to use the privileges to access Entity A's resources at other SPs. As an example, if I've specified to my bank that my wife has full access to my account, and that bank account has been federated with other SP accounts (e.g. mutual funds), then 'full access' might mean my wife could access my mutual funds investment account through my bank account if and when she authenticated to the bank.
In this latter case, if the bank IDP creates an assertion for the mutual fund SP that claims my wife is me, that's an impersonation model.
If instead the assertion carries both my wife's identity (even if anonymous) as well as my own and expresses the privileges that have been granted by the latter to the former, then that's delegation.
And of course, depending on the technology, A can always give their credentials to B.
The following lays out these 4 models (the blue dot represents where the 'A says B can do X to Y' rule is enforced.)
There are flavours of the above, depending on where the above logic is defined, where it's enforced, and whether all actors are cognizant of what's going on.
If the logic is captured and enforced at the provider hosting the resource in question, then it's a local affair and effectively boils down to an authorization rule at that provider. (Liberty People service is an enabler of this scenario, allowing such local authorization policies to be defined in terms of non-local identities.) In this scenario, even were Entity B to appear at the SP as a result of an SSO from an IDP, that IDP need not be aware of the policy.
If however the resource in question is Entity A's IDP account, then there are potential non-local ramifications should Entity B attempt to use the privileges to access Entity A's resources at other SPs. As an example, if I've specified to my bank that my wife has full access to my account, and that bank account has been federated with other SP accounts (e.g. mutual funds), then 'full access' might mean my wife could access my mutual funds investment account through my bank account if and when she authenticated to the bank.
In this latter case, if the bank IDP creates an assertion for the mutual fund SP that claims my wife is me, that's an impersonation model.
If instead the assertion carries both my wife's identity (even if anonymous) as well as my own and expresses the privileges that have been granted by the latter to the former, then that's delegation.
And of course, depending on the technology, A can always give their credentials to B.
The following lays out these 4 models (the blue dot represents where the 'A says B can do X to Y' rule is enforced.)
I never forget a ...
Of Passfaces, Paul Toal writes
For myself, better than my ability to remember faces is my ability to remember ways in which I've been slighted - I never forget an insult.
Give me a login system that prompts me to choose particular past snubs from a broad list and I'll never call the Help Desk again. The only difficulty would be in choosing my 'challenge slights' - there are just too many choices, a representative sampling of which is
It is common knowledge that the brain can remember images better than anything else.
For myself, better than my ability to remember faces is my ability to remember ways in which I've been slighted - I never forget an insult.
Give me a login system that prompts me to choose particular past snubs from a broad list and I'll never call the Help Desk again. The only difficulty would be in choosing my 'challenge slights' - there are just too many choices, a representative sampling of which is
- Kindergarten - Eli made fun of my toque.
- Grade 8 - Keenan mocked my choice of favourite Kiss song.
- University - Weird Julie claimed I had no physics bona fides in questioning her 'faster than light theory'.
- Career - Conor (as a category).
History T'ID'bits
Overheard in the Sistine Chapel
Oh yes Maestro, I fully agree that His Holiness stipulated in your contract that you have full artistic control of the project. I am merely suggesting that the sweeping scope and magnificent colours of the work are signature enough, and your blog address in 5ft tall characters might actually be unnecessary? Additionally, I wonder if some of the cardinals might misinterpret the depiction of God reaching out with with His finger to create the URI?
Tuesday, March 20, 2007
Strange Loops
I wanted to try out Highrise - an online contacts manager.
In creating my account, I was given the choice of using an OpenID rather than provide a password. Great! I provided my ProtectNetwork.org OpenID.
After the account was created, I was asked to sign-in.
Saw the normal OpenID screens and redirects etc.
The login failed.
Current situation:
In creating my account, I was given the choice of using an OpenID rather than provide a password. Great! I provided my ProtectNetwork.org OpenID.
After the account was created, I was asked to sign-in.
Saw the normal OpenID screens and redirects etc.
The login failed.
Current situation:- I can't use the ProtectNetwork.org OpenID to access Highrise because of above error
- I can't use another OpenID because Highrise has a record only of the ProtectNetwork one and so refuses to accept another.
- I can't get in 'locally' because I set up no password at registration time
Monday, March 19, 2007
History T'ID'bits
Overheard on Tower Green
Yes Mistress Boleyn I do understand that this is not the best time but I'm afraid I have no choice in the matter. It turns out that Lady Seymour is unable to sign-in to the royal account without the password you set. So, it would really make my job much much easier if you could find your way to just writing it down for me. Oh, true, your hands are indeed tied together ... perhaps you might just whisper it then? And, um, the sooner the better I think ...
History T'ID'bits
Overheard on the banks of the Delaware
Yes General, once again I do apologize. I know I promised that you would be able to use the bridge. Unfortunately however the ice has jammed up the card reader for the gate and we're on hold with customer support trying to get a technician out here to get it fixed. Are you absolutely sure there is no other way you can get across?
History T'ID'bits
Overheard under the walls of Troy
C'mon Odysseus, put down the hammer would you? I'm not saying that the horse isn't a really great idea. But maybe, before we spend 3 months building the thing, we could just have a few shots at guessing the password for the gate? I'm thinking 'H E L E N' would be worth a try? or 'H E E L' maybe?
Game as identity analogy
Having just acquired a Sony PSP, I've discovered a new (to me) genre of game.
In both Loco Roco and Mercury Meltdown, you don't directly control a character's movements and actions with the various buttons and joysticks, instead you control the environment that surrounds them. It's by controlling their environment that you indirectly control the character and cause them to move, grab things, expire etc.
In Mercury Meltdown, by tilting floating platforms from side to side, you determine where a shiny blob of mercury rolls. Tilt too much and the blog rolls off the platforms into space - you lose.
In both games the character has no control over its fate - simply rolling passively from one spot to another at the whim and vagaries of its surroundings (the marriage of a 'friend' of mine comes to mind). Whether aware (as in Loco Roco) or not (as in Mercury Meltdown) of their destiny, the main character is manifestly not in charge of it.
These are clearly not user-centric games.
In both Loco Roco and Mercury Meltdown, you don't directly control a character's movements and actions with the various buttons and joysticks, instead you control the environment that surrounds them. It's by controlling their environment that you indirectly control the character and cause them to move, grab things, expire etc.
In Mercury Meltdown, by tilting floating platforms from side to side, you determine where a shiny blob of mercury rolls. Tilt too much and the blog rolls off the platforms into space - you lose.
In both games the character has no control over its fate - simply rolling passively from one spot to another at the whim and vagaries of its surroundings (the marriage of a 'friend' of mine comes to mind). Whether aware (as in Loco Roco) or not (as in Mercury Meltdown) of their destiny, the main character is manifestly not in charge of it.These are clearly not user-centric games.
Sunday, March 18, 2007
Live Preview
Microsoft's Jensen Harris posts on the new Live Preview feature in Office 12.
Why not apply the model to identity selection in Cardspace?
Hover over a card containing your shipping address and see a video of a package being delivered to your doorstep. Hover over another linked to an IDP with poor security policies and see an animation of a burglar climbing out your window carrying a TV.
Intriguing possibilities for the 'proof of age' card.
whenever you hover over a formatting option with your mouse cursor, Office shows you what your document would look like if you chose to apply that formatting. For example, say that you drop down the font picker in Word. As you hover over each choice in the font picker, your document updates to show you what it would look like if you chose that font.
Why not apply the model to identity selection in Cardspace?
Hover over a card containing your shipping address and see a video of a package being delivered to your doorstep. Hover over another linked to an IDP with poor security policies and see an animation of a burglar climbing out your window carrying a TV.
Intriguing possibilities for the 'proof of age' card.
Friday, March 16, 2007
Identity sprouts in Brussels
The Liberty Alliance and Internet Identity Workshop (IIW) are organizing another Identity Open Space (IOS) - this time in Brussels.
In preparing for travel to the Liberty meetings directly preceeding the IOS, I must make sure to remember to pack my unconference skepticism (I wonder if Canadian skepticism will work in Belgium or do I need an adaptor?).
In preparing for travel to the Liberty meetings directly preceeding the IOS, I must make sure to remember to pack my unconference skepticism (I wonder if Canadian skepticism will work in Belgium or do I need an adaptor?).
Tags: Liberty Alliance, IIW, IOS, unconference
Da Vinci Code
I just listened to a BBC news article on the upcoming move by the UK National Health Service to electronic health records.
The NHS wants the health data available to medical professionals elsewhere in Europe so that, if a Brit is on holiday in Mallorca, the list of their medications or allergies etc can be accessed by the Spanish emergency room physician.
This was described by an NHS administrator as the 'Holy Grail'.
I expect that in the inevitable sequel to the Da Vinci Code, the plot will have Tom Hanks running around Europe gathering clues in order to decipher
'L I B E R T Y A L L I A N C E'.
Maybe I can get myself into one of the crowd scenes.
The NHS wants the health data available to medical professionals elsewhere in Europe so that, if a Brit is on holiday in Mallorca, the list of their medications or allergies etc can be accessed by the Spanish emergency room physician.
This was described by an NHS administrator as the 'Holy Grail'.
I expect that in the inevitable sequel to the Da Vinci Code, the plot will have Tom Hanks running around Europe gathering clues in order to decipher
'L I B E R T Y A L L I A N C E'.
Maybe I can get myself into one of the crowd scenes.
Thursday, March 15, 2007
Delegation is the new SSO
Delegation seems to have popped up from the identisphere as the hot meme de jour.
I know that just about every use case we discussed at a recent Ipswich (who says UK spring weather sucks?) meeting of the Liberty Alliance Technology Expert Group could be modeled as some form of delegation.
Examples include

As we roughed it out this week, a solution might work something like the following
Importantly, if and when BusinessOwner discovers that the CheckYourBooks CEO has been skimming off the top and has moved with his mistress to the British Virgin Islands, it's easy to shut off access and switch it to the new accounting firm (until such time they feel the call of the sun).
I know that just about every use case we discussed at a recent Ipswich (who says UK spring weather sucks?) meeting of the Liberty Alliance Technology Expert Group could be modeled as some form of delegation.
Examples include
- a client delegating the right to a network provider to serve up identity attributes on a user's behalf if and when the client was unavailable
- an IDP delegating the right to a client to mint assertions on its behalf if and when the IDP was unavailable
- a Mom delegating the right to members of her extended family to view online photos
- a business owner delegating the right to an accounting firm's accountants to view/submit to the business's account at a government tax agency

As we roughed it out this week, a solution might work something like the following
- BusinessOwner adds a group for his accounting firm CheckYourBooks to the company's People Service
- The new group, instead of directly defining a collection of specific individuals, instead points at a different group managed by a CheckYourBooks admin in that company's People Service
- BusinessOwner visits GovernmentTax and sets delegation policy by saying 'Allow members of CheckYourBooks to access my tax account'.
Importantly, if and when BusinessOwner discovers that the CheckYourBooks CEO has been skimming off the top and has moved with his mistress to the British Virgin Islands, it's easy to shut off access and switch it to the new accounting firm (until such time they feel the call of the sun).
Tags: Liberty Alliance, delegation, CCRA
Friday, March 09, 2007
Programmable Google
From the Programmable Web, more on Google's use of SAML for SSO.
It seems only appropriate to dust off one of my first screencap attempts.
(I look at that video now and just shudder. What was I thinking, there is no plot, little character development, and the lighting is just so film noire. I've grown so much as a filmmaker since then.)
Neither of these are ’simple’ APIs in the sense of the Google Maps API, but that makes sense, these are inherently more complex operations.
It seems only appropriate to dust off one of my first screencap attempts.
(I look at that video now and just shudder. What was I thinking, there is no plot, little character development, and the lighting is just so film noire. I've grown so much as a filmmaker since then.)
Thursday, March 08, 2007
Timeshifted Delegation Use-Case
In order to guarantee our 4 yr old daughter a spot in a city run 'Sporty Kids' program, my wife had to stay up till midnight last night as registration did not open till that time. (I had my beeper by the bedside in case I was needed for tech support but fortunately no call came in).
The time difference between Ottawa and India suggests an alternative.
My wife delegates her rights to a 'Municipal Service Registration Provider' based in Mumbai, for which the ungodly hour of 12 EST is a far more civilized mid-morning.
I can see it. Sipping his chai, a MSRP employee navigates through the various pages of the City of Ottawa registration site, referring to my wife's instructions as appropriate, selecting the right program, and providing my wife's credit card information at the end to finalize the transaction. If further interaction with the city were necessary to clarify some point, the representative would be authorized to send emails or IMs on my wife's behalf, or even impersonate her on the phone (existing call center training that teaches operators to use a nondescript mid-West accent would be relevant here, but would need to be localized with some 'eh's peppered indiscriminately throughout).
I see no downside. My wife gets extra sleep, we leverage the bandwidth surplus of deep Pacific submarine cables, and India gets needed exposure to Canadian sports programs (when have they last had a contending curling team?).
A possible alternative would be a Firefox extension that would submit a form at a specific time. I just can't see the desktop having the equivalent identity smarts of a Tata educated Masters student in the forseeable future.
The time difference between Ottawa and India suggests an alternative.
My wife delegates her rights to a 'Municipal Service Registration Provider' based in Mumbai, for which the ungodly hour of 12 EST is a far more civilized mid-morning.
I can see it. Sipping his chai, a MSRP employee navigates through the various pages of the City of Ottawa registration site, referring to my wife's instructions as appropriate, selecting the right program, and providing my wife's credit card information at the end to finalize the transaction. If further interaction with the city were necessary to clarify some point, the representative would be authorized to send emails or IMs on my wife's behalf, or even impersonate her on the phone (existing call center training that teaches operators to use a nondescript mid-West accent would be relevant here, but would need to be localized with some 'eh's peppered indiscriminately throughout).
I see no downside. My wife gets extra sleep, we leverage the bandwidth surplus of deep Pacific submarine cables, and India gets needed exposure to Canadian sports programs (when have they last had a contending curling team?).
A possible alternative would be a Firefox extension that would submit a form at a specific time. I just can't see the desktop having the equivalent identity smarts of a Tata educated Masters student in the forseeable future.
Tuesday, March 06, 2007
Money Markets
O'Reilly's Kevin Farham throws some water on the OpenID rave.
To Kevin's friends' initial objection
Kevin continues
Of course, if you buy one currency at the right time, it can turn out to your advantage. Invest now for arbitrage later.
And some of those 100 Million users are only too aware of the gift that AOL gave them.
To Kevin's friends' initial objection
"I'd never want to use that! What if your password is stolen?"I'd suggest that she consider the security advantages of banks vs mattresses for her money (assuming she banks somewhere other than a payday cheque-cashing outfit)
Kevin continues
So, a currency that is useless in most stores was given to 100 Million Web users, most of whom have no awareness that they now hold this new not-very-useful currency.
Of course, if you buy one currency at the right time, it can turn out to your advantage. Invest now for arbitrage later.
And some of those 100 Million users are only too aware of the gift that AOL gave them.
Signal to Noise
From Johannes, the world generated 161 exabytes of info last year.
I wonder how much of that total consists of
I wonder how much of that total consists of
- blog posts examining the criteria for 'user-centric' identity?
- duplicated account profiles from repeated user form-fill?
- redundant content from misuse of blog copy-and-pasting?
- MySpace profiles of girls named Tiffany?
SordID Thought
Whenever somebody asks me for a definition of 'user-centric' identity, I spin them around, twist their arm up between their shoulder blades and whisper in their ear 'Well it's nothing like this'. By the time the police have arrived most people will have completely forgotten about their original question.
Koi
Received the following e-mail
1-1 Hinodai 3-chome,
Hino-shi,
Tokyo 191-8660.
http://www.hino.co.jp/j/index.html
TO WHOM IT MAY CONCERN
I wish to intimate you with a request that would be of immense Benefit to you. I am Mr Shoji Kondo, Representative Director, President and Board Member of Hino Motors. Hino Motors was Founded 1910 and Established May 1, 1942.
.
The purpose of my contacting you is because you live outside Japan. The reason I seek your assistance is that American and Canadian cheques take a long time to clear here in Japan, thereby holding business down for my associates and me.
.
We would be glad to have you as one of our esteemed Representative in your location and be rest assured that adequate pecuniary and lucrative compensations will be given and other benefits follows.
.
My regards to your family and associate.
Thanks
Shoji Kondo
The President of Hino Motors
Someone with less knowledge of Japanese business customs might have been taken in by this.
But, in my experience, every message sent to me by a Japanese colleague has a postscript of 'Paul-san, I'm still laughing at your pronounciation of "Ohayo Gozaimasu"'. Not seeing it here was the giveaway.
Monday, March 05, 2007
On behalf of Eve
Pete agrees with Kim on the importance of 'user-offline' scenarios.
Minor nitpick, quibble really, I hesitate to bring it up even.
ID-WSF in no way uses an impersonation model. The identity of the requestor is made explicit in any call to a service for some slice of a user's identity, and (in most cases) distinct from that of the user in question. The requestor acts in their own identity, and does not pretend to be something else, i.e. the user. So, like Rich Little at a funeral, no impersonation.
Liberty's model assumes that, as per Pete above, that the user will have previously defined access rules that state 'Service X can do operation Y to identity Z' (importantly, whilst still allowing for the user to add/clarify such policy at run-time).
But, instead of the request carrying a token created by the user (and of course presumably signed by them as well) expressing the delegation rights of the requestor, these access rights are assumed to be stored at the identity service itself. The user specifies policy for Identity Z where Z is held, not at any provider who might request it (privacy alarms sounding here).
As far as I can tell, Kim's misunderstanding is based on his interpretation of 'on behalf of' as used by Eve in a chat with Jim Kobelius. Kim must think that this means impersonation. As Eve is currently vacationing, I'll take the "liberty" of clarifying on her behalf (please note that both our identies were used) - it doesn't.
There really is no big secret to how this stuff is possible - at some point in time an offline user will be online, and during that time instead of ceding their credentials to the service in the sky (or worse, it happens without choice), they spend the time granting access specific to the service that needs access.Pete continues
I have to agree with Kim on the notion of impersonation - at no time should anybody give the required access level for impersonation of themselves, on or offline.Pete is agreeing with Kim's assertion that the (as yet undefined?) WS-Trust delegation mechanism was preferable to Liberty Alliance's ID-WSF 'impersonation' mechanism.
Minor nitpick, quibble really, I hesitate to bring it up even.
ID-WSF in no way uses an impersonation model. The identity of the requestor is made explicit in any call to a service for some slice of a user's identity, and (in most cases) distinct from that of the user in question. The requestor acts in their own identity, and does not pretend to be something else, i.e. the user. So, like Rich Little at a funeral, no impersonation.
Liberty's model assumes that, as per Pete above, that the user will have previously defined access rules that state 'Service X can do operation Y to identity Z' (importantly, whilst still allowing for the user to add/clarify such policy at run-time).
But, instead of the request carrying a token created by the user (and of course presumably signed by them as well) expressing the delegation rights of the requestor, these access rights are assumed to be stored at the identity service itself. The user specifies policy for Identity Z where Z is held, not at any provider who might request it (privacy alarms sounding here).
As far as I can tell, Kim's misunderstanding is based on his interpretation of 'on behalf of' as used by Eve in a chat with Jim Kobelius. Kim must think that this means impersonation. As Eve is currently vacationing, I'll take the "liberty" of clarifying on her behalf (please note that both our identies were used) - it doesn't.
Social Engineering
Somehow the password-protected parental-control feature on our PlayStation was enabled. As we use the console as a DVD player, everytime we want to watch a video that isn't Sponge Bob, we have to log-in.
No problem when I'm home, it's a relatively intuitive interface for character entry. Big problem for my wife when I'm travelling (she is squarely down in the 'Luddite' sector of technological aptitude).
Simple solution, she asks my 10 year old to authenticate for her. She even woke him once for this 'approval' process. He is of course under strict instructions as to not use his knowledge of the password for inappropriate purposes.
In a federated household, there would be no need for a separate credential for the PlayStation. Instead, family members would authenticate to the home gateway IDP, and from there, be able to access all the connected relying party services.
In such a house, my wife would only have to get my son to log-in for her TO THE GATEWAY. Simpler for everybody (and more sleep for my son).
No problem when I'm home, it's a relatively intuitive interface for character entry. Big problem for my wife when I'm travelling (she is squarely down in the 'Luddite' sector of technological aptitude).
Simple solution, she asks my 10 year old to authenticate for her. She even woke him once for this 'approval' process. He is of course under strict instructions as to not use his knowledge of the password for inappropriate purposes.
In a federated household, there would be no need for a separate credential for the PlayStation. Instead, family members would authenticate to the home gateway IDP, and from there, be able to access all the connected relying party services.
In such a house, my wife would only have to get my son to log-in for her TO THE GATEWAY. Simpler for everybody (and more sleep for my son).
Sunday, March 04, 2007
Homo Sapiens Federatesis
Ping ID's Andre Durand has posted a screencast portraying the parallel development of human kind and the tools we've created to assist in dealing with everything 'Nature, red in tooth and claw' has thrown at us.
Post It notes are the latest tool in the series; the corresponding branch in the human family tree is Homo Sapiens Passwordensis.
I do love an evolutionary analogy. I can just see Charles Darwin sitting at his deck muttering to himself trying to authenticate to his publisher's web site.
Evolutionary pressure must be driving us towards Homo Sapiens Federatesis. The downside would appear to be that this species, freed of the requirement to remember countless passwords, will surely be characterized by decreased intellectual capacity.
Hang in there George Dubya! Things could turn around in your popularity numbers.
Post It notes are the latest tool in the series; the corresponding branch in the human family tree is Homo Sapiens Passwordensis.
I do love an evolutionary analogy. I can just see Charles Darwin sitting at his deck muttering to himself trying to authenticate to his publisher's web site.
OK, let's see, is it 'b e a g l e'? Nope, damn it!
Let's try 's e l e c t i o n'. Bloody Hell! Oops sorry Emma .
I have to get in, Wallace is about to publish my ideas!
K, one more try, how about 'g a l a p a g o s'?
.
.
I'm in, why the *@#&^#*@ did I pick something that long?.
Evolutionary pressure must be driving us towards Homo Sapiens Federatesis. The downside would appear to be that this species, freed of the requirement to remember countless passwords, will surely be characterized by decreased intellectual capacity.
Hang in there George Dubya! Things could turn around in your popularity numbers.
Tags: Ping ID, evolution, federation, Darwin
Friday, March 02, 2007
Garden State
The State of New Jersey's Shared IT Architecture lists the open standards on which it builds
This infrastructure will support the following industry standards:
- Java Authentication and Authorization Service
- Kerberos
- Liberty Alliance Phase 2 (Identity-based Web Services Framework (ID-WSF))
- Online Certificate Status Protocol (OCSP)
- SAML 1.1 Specification
- SOAP (Simple Object Access Protocol) 1.1
- SPML (Service Provisioning Markup Language)
- SSL (Secure Sockets Layer)
- XML Digital Signature
- XML Encryption.
- LDAP version 2 and version 3
- X.509 Digital Certificates
Tags: SAML, Liberty Alliance ID-WSF, Garden State
Identity Selector Permutations
In trying to make sense of the various combinations of OS, browser, plugins etc for enabling a client with a Cardspace compatible identity selector, I created the following graphic (click to enlarge)
Caveat: It's almost certainly wrong in places, and doesn't account for Higgins.

Update: Neil Macehiter adds some details.
Caveat: It's almost certainly wrong in places, and doesn't account for Higgins.

Update: Neil Macehiter adds some details.
- Chuck's extension appears to require Firefox 2
- XMLDAP requires Java 1.5
- CardSpace on XP requires .NET Framework 3
- #1 is the all Microsoft scenario
- #2 ties Firefox into the Cardspace identity selector through the selector from Kevin Miller.
- #3 ties Firefox into Cardspace through Kevin's plug-in, but allows for the scenario of a user choosing to use a different identity selector than Cardspace
- #4 is Chuck Mortimer's Firefox plugin as an alternative identity selector to Cardspace.
- #5 is a non-Cardspace identity selector for Safari.
Green identity management
This Wall Street Journal article makes me think that all our efforts to minimize the number of login, form fill etc operations for users are, at best, misguided, and at worst, damaging the planet.
Instead of devising ways to decrease such identity operations for end-users, we should be asking ourselves the more fundamental question - "Can we harness the energy of these identity operations?"
Countless watts from untold mouse movements, key taps, and button clicks go wasted, lost as friction and sound. But it needn't be so. Small generators (patent soon to be pending, details TBD), if attached to our keyboards and mouses (mice?), could tap into this power source.
The math is compelling
1) ~ 1 billion internet users
2) ~ 30 login operations per day
3) unknown amount of power generated per login operation
That's got to be a big number, probably in the 'teraergs' range if I had to guess.
Of course, when every login operation serves to mitigate greenhouse gases, there would no longer be any motivation for SSO or attribute sharing, we'd want to maximize the number of mouse-driven identity operations as much as possible.
We in the Identity Management industry would of course be out of work. I for one would be willing to make this sacrifice - there is also immense untapped power in the motion of the arm as it raises a Gin & Tonic to the mouth.
"Hey Mr. Bartender, make it a double, I'm saving Antartica one drink at a time".
Instead of devising ways to decrease such identity operations for end-users, we should be asking ourselves the more fundamental question - "Can we harness the energy of these identity operations?"
Countless watts from untold mouse movements, key taps, and button clicks go wasted, lost as friction and sound. But it needn't be so. Small generators (patent soon to be pending, details TBD), if attached to our keyboards and mouses (mice?), could tap into this power source.
The math is compelling
1) ~ 1 billion internet users
2) ~ 30 login operations per day
3) unknown amount of power generated per login operation
That's got to be a big number, probably in the 'teraergs' range if I had to guess.
Of course, when every login operation serves to mitigate greenhouse gases, there would no longer be any motivation for SSO or attribute sharing, we'd want to maximize the number of mouse-driven identity operations as much as possible.
- You suspect a phish email? So what, login anyway, it's for the planet.
- You don't want to enter your URI at every site you visit? Suck it up buddy, the ice caps are melting.
- Carpal tunnel syndrome have you contemplating voice recognition software? Sure, go ahead, my kids can learn to breathe CO2.
We in the Identity Management industry would of course be out of work. I for one would be willing to make this sacrifice - there is also immense untapped power in the motion of the arm as it raises a Gin & Tonic to the mouth.
"Hey Mr. Bartender, make it a double, I'm saving Antartica one drink at a time".
Thursday, March 01, 2007
Powerful Anti-phish Security
Hartford Investments Canada has a surefire way to protect their clients from being phished for their account credentials. I for one am confident that there is no way I could be tricked into providing my password to a phisher, even without the benefit of a smart client mediating server authentication for me.
The mechanism works as follows (I confess it took me a while to work out the subtleties):
Ingenious - I can't share what I don't have.
I understand their hesitancy about enabling client access - who knows just whether or not this 'Whole Wide Web' thing is going to take off.
The mechanism works as follows (I confess it took me a while to work out the subtleties):
- Do not allow clients online access to their accounts
- When challenged, respond with 'It's to ensure the safety of your account information'.
Ingenious - I can't share what I don't have.
I understand their hesitancy about enabling client access - who knows just whether or not this 'Whole Wide Web' thing is going to take off.
Wednesday, February 28, 2007
I want a feed
for Conor's 'List of Identities'.
I need more timely updates than every few months. How am I supposed to build a mashup without timely data?
He passed 350 without my even knowing it! So what am I now supposed to do with the balloons I had stocked for the celebration?
I need more timely updates than every few months. How am I supposed to build a mashup without timely data?
He passed 350 without my even knowing it! So what am I now supposed to do with the balloons I had stocked for the celebration?
Tuesday, February 27, 2007
It's bad enough
that ZDNet makes me create an account in order to leave a comment on their identity blog. Worse still is making my ability to turn off their newsletter spam dependent on providing my company name and phone number.
Pam, I respectfully submit this for your consideration .
Pam, I respectfully submit this for your consideration .
Friday, February 23, 2007
Existence proof
AOL's John Panzer responds to my concern over AOL arbitrarily gifting me with another OpenID. John writes
John goes on
Of course, I don't want to use OpenID's delegation mechanism to point at this AOL OpenID - I don't even want the thing, why would I direct RPs to it?
If anything I'd want to instead edit the AOL HTML page to point at my chosen OpenID provider and URI. John suggests that this is now possible
Does John mean that AOL supports OpenID as the delegatee, but not the delagator? A business model peaks through the clouds.
My take is, if you don't actually use the OpenID URL, it doesn't really exist. The same way a Wiki page doesn't exist until you edit it.Well, until you create a link to a Wiki page and then edit it, it actually does not exist, i.e. it's not addressable. My AOL OpenID manifestly does exist and is addressable. What's more, anybody who knows (or can guess) my AIM screenname, can get to it.
John goes on
Another important point is that you can point at the AOL OpenID service from any web page you own in order to turn its URL into an OpenID. The minimal requirements are basically that you have some AOL or AIM account, and that you add a couple of links to your document's HEAD:
Of course, I don't want to use OpenID's delegation mechanism to point at this AOL OpenID - I don't even want the thing, why would I direct RPs to it?
If anything I'd want to instead edit the AOL HTML page to point at my chosen OpenID provider and URI. John suggests that this is now possible
We added this to our blogs product in a few minutes minutes (sic) and it's in beta now.I created a blog at AOL in order to try it out (NBARM - Nothing But a Redirect Mechanism) but I can see no ability to directly edit the HTML header to add the OpenID delegation tags.
Does John mean that AOL supports OpenID as the delegatee, but not the delagator? A business model peaks through the clouds.
Recommendation vs References
Johannes uses a nice employee hiring analogy to argue that both identity flow patterns of 'through the user-agent' and 'around the user-agent' are valid. As proponents of the Liberty Alliance's ID-WSF have been arguing the same for years, I heartily concur (and would argue that Liberty's People Service could be an excellent platform to build a reputation system on).
A slight quibble. The impression from Johannes analogy is that the 'Reference Check' model (comparable to 'around the user-agent') would allow the RP to get a more accurate view of the candidate's qualifications - even perhaps obtaining negative reviews from previous employers. Two points here:
A slight quibble. The impression from Johannes analogy is that the 'Reference Check' model (comparable to 'around the user-agent') would allow the RP to get a more accurate view of the candidate's qualifications - even perhaps obtaining negative reviews from previous employers. Two points here:
- in ID-WSF, the User still knows (but admittedly can't be completely sure) what goes in the 'reference letter'. It is the User that effectively both writes the letters through their interactions with their providers, and controls the advertisement of these letters, through their policy over controlling how such letters can be discovered. In Johannes's employment analogy, the candidate would never see such letters (and indeed would never know if they've been exchanged), and so the previous employer would presumably feel free to express their true opinion. As Johannes points out, in fact laws may still constrain the previous employer, and they definitely also constrain what an IDP will or can say about its Users.
- if a RP asks for the user's 'Frequent Flyer Status' from an IDP, and the User doesn't like the fact that the IDP asserts 'Silver' when the level of desired RP service is 'Gold', the Recommendation Letter model for identity flow would theoretically allow the User to see the assertion and, not liking the consequences, remove it (they can't change it). But of course, this doesn't help the User. Without the frequent flyer information of 'Silver', the RP will likely provide the default 'Bronze' level of service. The User is worse off than if they just let the 'Gold' status claim through. So it is for Recommendation letters - if the User filters out all information they don't wish to be disclosed to the prospective employer, they may be left with nothing at all to show.
Tags: ID-WSF, Liberty Alliance
Thursday, February 22, 2007
Been there, done that
I totally agree. For too long, identity security has been stuffy and serious, let's just have fun with it.
Subscription-based Google Apps
From ZDNet, Google is expected to announce subscription-based web apps for enterprises.
This would be a perfect application of Google's existing SAML support for partner SSO.
This is encouraging
This isn't
This would be a perfect application of Google's existing SAML support for partner SSO.
This is encouraging
Built on open standards: We build our products using open standards when possible, simplifying the integration with or replacement of your existing IT infrastructure.
This isn't
Identity Confusion - the Universal Graphical Language
MasterID is NTT Communication's SAML-based (specifically Liberty Alliance ID-FF) SSO solution with over 4M users.
Tags: NTT, SAML, SSO, Liberty Alliance, ID-FF adoption
Wednesday, February 21, 2007
Parade of Nations
From Eve, It's a SAML World.
Makes me think the SSTC or the Liberty Alliance should hire the Muppets for a remake of the clip below. They could probably use the gig - last I heard the Swedish Chef was flipping burgers and Kermit and Miss Piggy have an 'Inter-species erotica' show in Amsterdam.
The "Parade of Nations" theme seems appropriate given Eve's litany of SAML support amongst government.
Makes me think the SSTC or the Liberty Alliance should hire the Muppets for a remake of the clip below. They could probably use the gig - last I heard the Swedish Chef was flipping burgers and Kermit and Miss Piggy have an 'Inter-species erotica' show in Amsterdam.
The "Parade of Nations" theme seems appropriate given Eve's litany of SAML support amongst government.
Friday, February 16, 2007
Public service phish awareness idea
Absence of evidence
is not Evidence of Absence. Carl said that. He wasn't talking about identity ceremonies as far as I know.
MyOpenID's 'Safe Sign-In' mechanism made me think of the phrase. Safe Sign-In is a feature of MyOpenID whereby users can stipulate that they want the normal OPenID sign-in sequence interrupted - this interruption designed to thwart the much discussed OpenID phish vulnerability.
Because the phish in question relies on a bad RP directing the user to a bad IDP for authentication, the Safe Sign-In option intentionally throws a wrench into the normal OpenID sequence with the GOOD IDP (in which, when arriving at that IDP, the user is asked to log-in if not already in a session). Instead of immediately asking the user to authenticate, the IDP instead displays a screen that basically says "To protect you, I'm not going to ask you to log-in yet. You need to come back on your own through a bookmark or entering my address manually". The MyOpenID screen in question is shown below
If the user enables Safe Sign-In for their IDP account, this is what they see whenever directed to the IDP from an SP. At this point, they would (presumably in a different tab/window) manually go the MyOpenID sign in page and authenticate, secure in the knowledge that they have run an end-around on any phisher. Afterwards, they'd return to the above page and click on 'continue this action' for redirection back to the RP. Note that, when actually being redirected to the valid IDP, this is all just unnecessary hassle for the user - they could have safely logged in as typical. (it's a hassle, but meant to be instructive hassle, no pain no gain etc).
Now, if a site were to want to phish MyOpenID, they would of course not display the above screen - they would instead display the log-in page as per the normal OpenID sequence. It's at this point that the Safe Sign-In mechanism is supposed to demonstrate its worth. The hope is that the user, conditioned by the previous multiple authentications to the valid IDP through the intentionally awkward Safe Sign-In mechanism - will identify (and avoid) the now easier log-in option as offered by the phisher. Alerted by the atypical log-in ceremony, the user would surf quickly away, feeling smug and safe.
The scheme relies on the user making the connection between the 'evidence of absence' (the fact that they see no Safe Sign-In screen) with 'absence of evidence' (a suspicious phish site that gets their spidy-senses tingling). This is the same model of Yahoo!'s Sign-in Seal, in which users are trained to expect to see a particular icon on their log-in page and warned to be suspicious should they not see it. I have doubts about the value of the model, it effectively places the burden of site authentication right on the user. Users make great validation engines of course.
But for OpenID IDPs, the value of such a model appears even more questionable. Remember that OpenID, to a certain extent, stipulates the form and format for the log-in ceremony in order to create a consistent user experience. Remember also that at any other OpenIDs the user will be authenticating to, unless those other IDPs also implement Safe Sign-In (or comparable), the user will be trained by their experiences to expect the normal OpenID log-in sequence of direct password prompt. So, what they are conditioned to expect as normal by these other IDPs is exactly what they would see by the MyOpenID phisher.
I just can't see the occasional 'training session' as delivered by MyOpenID's Safe Sign-In ceremony triumphing in setting user-expectations over the more frequent (and easier) conditioning they will receive everywhere else.
MyOpenID's 'Safe Sign-In' mechanism made me think of the phrase. Safe Sign-In is a feature of MyOpenID whereby users can stipulate that they want the normal OPenID sign-in sequence interrupted - this interruption designed to thwart the much discussed OpenID phish vulnerability.
Because the phish in question relies on a bad RP directing the user to a bad IDP for authentication, the Safe Sign-In option intentionally throws a wrench into the normal OpenID sequence with the GOOD IDP (in which, when arriving at that IDP, the user is asked to log-in if not already in a session). Instead of immediately asking the user to authenticate, the IDP instead displays a screen that basically says "To protect you, I'm not going to ask you to log-in yet. You need to come back on your own through a bookmark or entering my address manually". The MyOpenID screen in question is shown below
If the user enables Safe Sign-In for their IDP account, this is what they see whenever directed to the IDP from an SP. At this point, they would (presumably in a different tab/window) manually go the MyOpenID sign in page and authenticate, secure in the knowledge that they have run an end-around on any phisher. Afterwards, they'd return to the above page and click on 'continue this action' for redirection back to the RP. Note that, when actually being redirected to the valid IDP, this is all just unnecessary hassle for the user - they could have safely logged in as typical. (it's a hassle, but meant to be instructive hassle, no pain no gain etc).Now, if a site were to want to phish MyOpenID, they would of course not display the above screen - they would instead display the log-in page as per the normal OpenID sequence. It's at this point that the Safe Sign-In mechanism is supposed to demonstrate its worth. The hope is that the user, conditioned by the previous multiple authentications to the valid IDP through the intentionally awkward Safe Sign-In mechanism - will identify (and avoid) the now easier log-in option as offered by the phisher. Alerted by the atypical log-in ceremony, the user would surf quickly away, feeling smug and safe.
The scheme relies on the user making the connection between the 'evidence of absence' (the fact that they see no Safe Sign-In screen) with 'absence of evidence' (a suspicious phish site that gets their spidy-senses tingling). This is the same model of Yahoo!'s Sign-in Seal, in which users are trained to expect to see a particular icon on their log-in page and warned to be suspicious should they not see it. I have doubts about the value of the model, it effectively places the burden of site authentication right on the user. Users make great validation engines of course.
But for OpenID IDPs, the value of such a model appears even more questionable. Remember that OpenID, to a certain extent, stipulates the form and format for the log-in ceremony in order to create a consistent user experience. Remember also that at any other OpenIDs the user will be authenticating to, unless those other IDPs also implement Safe Sign-In (or comparable), the user will be trained by their experiences to expect the normal OpenID log-in sequence of direct password prompt. So, what they are conditioned to expect as normal by these other IDPs is exactly what they would see by the MyOpenID phisher.
I just can't see the occasional 'training session' as delivered by MyOpenID's Safe Sign-In ceremony triumphing in setting user-expectations over the more frequent (and easier) conditioning they will receive everywhere else.
Metasystem Permutations & Combinations
Ping's 'Internet Scale Identity' paper looks at the Big 4 (SAML, Cardspace, ID-WSF, and OpenID) of identity systems and analyzes each with respect to their support for (oversimplifying)
2 + (2*3) + (2*3*3) = 2 + 6 + 18 = 26
So, it seems there are 26 different ways to combine the 4 systems into identity transactions. Include X.509-auth direct to RPs and the list only grows.
Higgins has its work cut out for it.
- User authentication (Cardspace & ID-WSF)
- Subsequent front-channel SSO & attribute sharing from IDP to RP (Cardspace, SAML & OpenID)
- Subsequent back-channel Attribute Sharing from AP to SP (ID-WSF, some SAML & emerging OpenID )
- #1 on its own
- #1 followed by #2
- #1 followed by #2 followed by #3
2 + (2*3) + (2*3*3) = 2 + 6 + 18 = 26
So, it seems there are 26 different ways to combine the 4 systems into identity transactions. Include X.509-auth direct to RPs and the list only grows.
Higgins has its work cut out for it.
Please delete my AOL OpenID
George and Conor discuss AOL's new support for OpenID, specifically how best to inform users of their ability to use their AOL ID at other sites. Given that AOL is the first major public IDP to add support for OpenID, it will definitely be interesting to see how they 'brand' it to their, shall we say, less than internet-savvy core customer demographic.
My issue is more fundamental. I did not ask for, and nor do I want, an OpenID from AOL. I use AOL for the following purposes
Some will say 'So what, you don't want to use the AOL OpenID, don't use it, no harm done'. In a sense, they'd be right. If I can get over people seeing the empty ugliness of the above page (accessed simply by using my known AIM identifier) then I can let the AOL OpenID die a slow but natural death through lack of use.
But the real issue for me is not the page (even those pages I do maintain are only slightly less gaudy), it's the presumption on AOL's part that I want to have an OpenID with them, and their automatically enabling one for me without my consent. I already had (more than) enough OpenIDs with other IDPs (I am indeed waiting for a major public IDP to enable standards-based SSO to/from external properties but AOL is not that provider). I had only just recently consolidated on a preferred OpenID IDP (Go ProtectNetwork!) because of their multi-protocol support - I resent AOL coming along and complicating my IDP selection process once more.
Is AOL's enabling OpenID for me even consistent with the Terms of Service for AIM? The clause
Even if so, it's a no brainer that I should be able to turn off unwanted capabilities. Let me turn it off and get back to the business of growing my list of OpenID IDPs of my own choosing.
My issue is more fundamental. I did not ask for, and nor do I want, an OpenID from AOL. I use AOL for the following purposes
- AIM Instant Messaging
- Dulles meeting facilities
- Learning from George
Some will say 'So what, you don't want to use the AOL OpenID, don't use it, no harm done'. In a sense, they'd be right. If I can get over people seeing the empty ugliness of the above page (accessed simply by using my known AIM identifier) then I can let the AOL OpenID die a slow but natural death through lack of use.
But the real issue for me is not the page (even those pages I do maintain are only slightly less gaudy), it's the presumption on AOL's part that I want to have an OpenID with them, and their automatically enabling one for me without my consent. I already had (more than) enough OpenIDs with other IDPs (I am indeed waiting for a major public IDP to enable standards-based SSO to/from external properties but AOL is not that provider). I had only just recently consolidated on a preferred OpenID IDP (Go ProtectNetwork!) because of their multi-protocol support - I resent AOL coming along and complicating my IDP selection process once more.
Is AOL's enabling OpenID for me even consistent with the Terms of Service for AIM? The clause
AOL has the right at any time to change, modify, add to or discontinue or retire any aspect or feature of the AIM Products including, but not limited to, the software, community areas, Content, hours of availability, equipment needed for access or use, the maximum disk space that will be allotted on AOL servers on your behalf either cumulatively or for any particular service or the availability of AIM Products on any particular device or communications service. AOL has no obligation to provide you with notice of any such changes.might appear to give them all the legal leeway they need except how can they argue that OpenID functionality is part of the AIM Products?
Even if so, it's a no brainer that I should be able to turn off unwanted capabilities. Let me turn it off and get back to the business of growing my list of OpenID IDPs of my own choosing.
Thursday, February 15, 2007
How very indulgent
I wouldn't be able to defend my business travel 'carbon footprint' were it not for Air Canada's reliance on solar power and wind turbines for their fleet.
Tags: offsetting, Catholic guilt, Air Canada
People! Pipes
What if the feeds/data sources that Yahoo! Pipes allows you to mash together were identity-based? What cool new social apps could you build? "Find me all single Zither players within 2 km of my current location"
The fact that a search for 'authentication' in the Message Boards returned nothing is telling.
The fact that a search for 'authentication' in the Message Boards returned nothing is telling.
Tags: Yahoo! Pipes
OpenID is not a unicycle
according to (currently) 18 Jyters(?).
So, given the obvious resistance, maybe the unicycle analogy isn't appropriate (and it definitely doesn't capture the momentum that OpenID is enjoying).
What vehicle would best capture the 'really great for building apps like Jyte' semantic? A Moke? open-sided, lightweight, cultish popularity, anti-establishment undertones?
So, given the obvious resistance, maybe the unicycle analogy isn't appropriate (and it definitely doesn't capture the momentum that OpenID is enjoying).
What vehicle would best capture the 'really great for building apps like Jyte' semantic? A Moke? open-sided, lightweight, cultish popularity, anti-establishment undertones?
Wednesday, February 14, 2007
Bootstrap
Discovery is a common challenge for identity systems. Fundamentally, requestors need to know where a bit of identity is located on the network so that a request can be sent there.
In SSO, when a User visits an SP, the SP needs to discover who and where the User's IDP is so that an authentication request can be delivered there. For the SP, the discovery question is 'Where should I redirect the user for them to authenticate?'.
OpenID solves the issue by allowing/requiring the User to provide either a specific identity URI at an IDP, or merely the URI of the IDP (directly or indirectly through delegation). SAML supports a variety of mechanisms (including the 'user-provides' model of OpenID) but standardizes a cookie-based option. Cardspace has the requestor present its identity needs to Cardspace, which then effectively 'discovers' appropriate IDPs.
When moving beyond SSO to attribute sharing, unless the desired attributes happen to be available from the same IDP as made the authentication assertion, discovery rears its head again. For an SP receiving an SSO assertion bu desiring additional attributes, the question becomes 'from which attribute provider can I obtain attribute X?'
The Liberty Alliance has always referred to this switch from the SSO to attribute sharing world as the 'bootstrap', and the bootstrap mechanism as the support that the SSO world can provide to the SP to facilitate this switch and subsequent discovery requirement. For the bootstrap from SAML & ID-FF based SSO to ID-WSF, we defined how the SAML SSO assertion carries the appropriate information (endpoint of a service at which the network location of the relevant user's various identity attributes and credentials to use there) for the SP to use should it wish to discover additional identity attributes.
But, other bootstraps are possible as well. Fundamentally, it's theoretically possible between any SSO protocol and a server-to-server attribute sharing protocol. For instance, you could define a boostrap mechanism from WS-Federation to ID-WSF if you were so inclined.
John Kemp explores mechanisms for boostrapping from OpenID to SAML (and then into ID-WSF). John provides two alternatives by which the OpenID RP could use SAML to retrieve an assertion to supplement the identity that flowed to it through the OpenID protocol. John doesn't mention emphasize subsequent bootstrapping into ID-WSF in his post, but the assertion that John's SAML mechanisms would retrieve could carry the necessary bootstrap information. Graphically
#1 is OpenID SSO, #2 is SAML Assertion retrieval, and #3 is ID-WSF Service discovery and query - now that's convergence! There must be a way to throw in Cardspace for good measure.
In SSO, when a User visits an SP, the SP needs to discover who and where the User's IDP is so that an authentication request can be delivered there. For the SP, the discovery question is 'Where should I redirect the user for them to authenticate?'.
OpenID solves the issue by allowing/requiring the User to provide either a specific identity URI at an IDP, or merely the URI of the IDP (directly or indirectly through delegation). SAML supports a variety of mechanisms (including the 'user-provides' model of OpenID) but standardizes a cookie-based option. Cardspace has the requestor present its identity needs to Cardspace, which then effectively 'discovers' appropriate IDPs.
When moving beyond SSO to attribute sharing, unless the desired attributes happen to be available from the same IDP as made the authentication assertion, discovery rears its head again. For an SP receiving an SSO assertion bu desiring additional attributes, the question becomes 'from which attribute provider can I obtain attribute X?'
The Liberty Alliance has always referred to this switch from the SSO to attribute sharing world as the 'bootstrap', and the bootstrap mechanism as the support that the SSO world can provide to the SP to facilitate this switch and subsequent discovery requirement. For the bootstrap from SAML & ID-FF based SSO to ID-WSF, we defined how the SAML SSO assertion carries the appropriate information (endpoint of a service at which the network location of the relevant user's various identity attributes and credentials to use there) for the SP to use should it wish to discover additional identity attributes.
But, other bootstraps are possible as well. Fundamentally, it's theoretically possible between any SSO protocol and a server-to-server attribute sharing protocol. For instance, you could define a boostrap mechanism from WS-Federation to ID-WSF if you were so inclined.
John Kemp explores mechanisms for boostrapping from OpenID to SAML (and then into ID-WSF). John provides two alternatives by which the OpenID RP could use SAML to retrieve an assertion to supplement the identity that flowed to it through the OpenID protocol. John doesn't mention emphasize subsequent bootstrapping into ID-WSF in his post, but the assertion that John's SAML mechanisms would retrieve could carry the necessary bootstrap information. Graphically
#1 is OpenID SSO, #2 is SAML Assertion retrieval, and #3 is ID-WSF Service discovery and query - now that's convergence! There must be a way to throw in Cardspace for good measure.
More wheels than Detroit
Ping ID's Chris Ceppi updates the (originally Stefan's) transportation taxonomy to reflect recent developments:
We shouldn't forget Stefan, he has a turbocharger that, once we work out how to strap it on, promises a serious boost in power.
- Cardspace is a pickup, reflecting its potential versatility for both work and play. Works for me, captures the uncertain fuel economy. Also begs the question - when shipped to the Midwest, will Cardspace come with gun racks and NRA bumper stickers?
- LID is deprecated in favour of OpenID, but a Unicycle is maintained as metaphor. It's fun to get around on but you can't carry groceries or beer with it.
- the recent Cardspace/OpenID integration is characterized as the OpenID unicycle thrown in the back of the pickup. The mental image I got from this is that the Cardspace truck gets you to the main destination, and then the OpenID unicycle serves as a handy runabout once there (like those tiny cars you see towed behind Winnebago's).
But, this isn't how the Cardspace/OpenID anti-phish integration works - Cardspace mostly stays put, it's OpenID that does the big mileage getting from the Cardspace authenticated IDP (thereby mitigating the phish) to the various SPs. So, it's more like the Cardspace driver dropping off the unicyclist at the freeway ramp, thereafter left to fend for themselves.
- SAML: SAML is a Honda Accord. Tried and tested, and you see them everywhere.
- ID-WSF: As far as I know, there are 4 maybe 5 space shuttles? I'd rather Liberty be considered the 777-300, state of the art and coming to an airline near you.
- WS-Federation: Too many ways to take this, I'm stumped.
We shouldn't forget Stefan, he has a turbocharger that, once we work out how to strap it on, promises a serious boost in power.
Federated blogging
I may drive a Minivan
with child seats and a Dora the Explorer CD on continuous loop, but I have sufficient maleness left to recognize a completely cool convergence of identity and internal combustion when I see it.
I can just imagine.
Child 1: Dad, Quinn took my OTP token, and I can't login to the video server.
Child 2: I did not, and if I did, so what? It's 2-factor you doofus!
Tuesday, February 13, 2007
Subject Confirmation in Action
Last year I lost my package of Aeroplan upgrade certificates when returning from San Francisco. I had been using the envelope containing the upgrade certificates as a bookmark in the book I was reading. I was flying the red eye from SFO to YYZ and, when tiredness overcame me, placed the book in the pocket of the seat in front. And that's where it was when I left the plane.
A book can be easily replaced. But upgrade certificates - they're gold. It's the thought of using them (against all odds) that can make the anticipation of a 14 hour flight to Tokyo bearable. I was not happy when I realized I had lost them.
Coincidentally Aeroplan had just moved to personalized upgrade certs - each had my name printed on it. Aeroplan's motivation was to curtail the thriving black market for the certificates - a market made possible because the certificates were anonymous and so could be easily traded. The new personalized certificates can only be redeemed by the frequent flyer whose name is on the cert - no use selling them because the purchaser won't be able to use them. In order to use the certificates, the required subject confirmation method would have been to separately prove ownership of the subject identity.
If the certificates I had lost were anonymous, I wouldn't have even bothered asking for replacements. Aeroplan would have had no way to ensure that I wasn't double-dipping, e.g. falsely claiming their loss in order to receive replacements for sale. But, because the certificates I lost were personalized, Aeroplan could be at least confident that I wouldn't be able to sell them. And so, I asked for replacements. And, to my surprise, expecting bureaucratic inertia, they gave them to me.
They couldn't be sure I wasn't falsely claiming the loss of the certificates in order to get replacements for my own personal use - I expect they guard against this by watching how many certificates I might try to redeem over the next year.
A book can be easily replaced. But upgrade certificates - they're gold. It's the thought of using them (against all odds) that can make the anticipation of a 14 hour flight to Tokyo bearable. I was not happy when I realized I had lost them.
Coincidentally Aeroplan had just moved to personalized upgrade certs - each had my name printed on it. Aeroplan's motivation was to curtail the thriving black market for the certificates - a market made possible because the certificates were anonymous and so could be easily traded. The new personalized certificates can only be redeemed by the frequent flyer whose name is on the cert - no use selling them because the purchaser won't be able to use them. In order to use the certificates, the required subject confirmation method would have been to separately prove ownership of the subject identity.
If the certificates I had lost were anonymous, I wouldn't have even bothered asking for replacements. Aeroplan would have had no way to ensure that I wasn't double-dipping, e.g. falsely claiming their loss in order to receive replacements for sale. But, because the certificates I lost were personalized, Aeroplan could be at least confident that I wouldn't be able to sell them. And so, I asked for replacements. And, to my surprise, expecting bureaucratic inertia, they gave them to me.
They couldn't be sure I wasn't falsely claiming the loss of the certificates in order to get replacements for my own personal use - I expect they guard against this by watching how many certificates I might try to redeem over the next year.
SPML as Sanitation Custodian?
Ian asks "Is SPML irrelevant in the coming CardSpace/Higgins/OpenID identity world?", citing some work Liberty Alliance has been doing around its Advanced Client provisioning as cause for his question.
Ian points out that the Liberty Provisioning Service specification does not use the Service Provisioning Markup Language (SPML). True, but Ian himself acknowledges that the type of provisioning being addressed here is different than traditional 'account provisioning', for which the SPML defined CRUD operations were designed.
Nevertheless, SPML is very much on Liberty's 'radar', but for a different set of provisioning use cases, ones more in line with Ian's traditional 'enterprise user account provisioning' (albeit with a federated twist). Using Ian's analogy, SPML is poised to move up in the office hierarchy, leaving the mop behind for the exciting world of mail-room cubbyhole creation.
Whether the Cardspace product team or OpenID community thinks about provisioning (and possible relevance of SPML) is a different matter. Is a priori or batch account provisioning even compatible with the hard-line definition of 'user-centric' identity that would have the user checking every packet as it flows by?
Ian points out that the Liberty Provisioning Service specification does not use the Service Provisioning Markup Language (SPML). True, but Ian himself acknowledges that the type of provisioning being addressed here is different than traditional 'account provisioning', for which the SPML defined CRUD operations were designed.
As a user provisioning guy this model of provisioning looked a bit strange to me. Think telephone service provisioning, not enterprise user account provisioning.
Nevertheless, SPML is very much on Liberty's 'radar', but for a different set of provisioning use cases, ones more in line with Ian's traditional 'enterprise user account provisioning' (albeit with a federated twist). Using Ian's analogy, SPML is poised to move up in the office hierarchy, leaving the mop behind for the exciting world of mail-room cubbyhole creation.
Whether the Cardspace product team or OpenID community thinks about provisioning (and possible relevance of SPML) is a different matter. Is a priori or batch account provisioning even compatible with the hard-line definition of 'user-centric' identity that would have the user checking every packet as it flows by?
Tags: Liberty Alliance, SPML, Cardspace, OpenID, SAML
Disconnected Identity
Conor is silent on his key contribution to the Liberty Alliance Advanced Client specifications, the first public draft of which is now available.
A key driver of Advanced Client functionality are so called 'disconnected' use cases. From the overview:
Similar to Cardspace, Advanced Client enables use cases in which a client can present identity claims to an SP without a 3rd-party IDP being directly involved but, importantly, also supports a model in which the client can act as an extension of an IDP, with rights for making claims delegated to it by that IDP.
A key driver of Advanced Client functionality are so called 'disconnected' use cases. From the overview:
The Advanced Client will operate in multiple modes of operation based upon the parties that it is interacting with. The modes are differentiated by the connectivity level of the various actors within a transaction. The two primary modes of operation that we are concerned with here include:
- Connected - the Advanced Client is fully connected to the network and generally all parties to a transaction could communicate with each other if necessary. In this mode, the Advanced Client can choose to act as a simple facilitator of the actual operation or for various reasons (such as privacy, load balancing, etc.) the Advanced Client can take a more active role, providing delegated authentication and/or web services.
- Disconnected - the Advanced Client does not have connectivity to one or more parties in a transaction (such as not having connectivity to the IdP during an authentication transaction). This mode limits the Advanced Client to delegated services and can restrict the availability of services exposed directly by the Advanced Client.
Similar to Cardspace, Advanced Client enables use cases in which a client can present identity claims to an SP without a 3rd-party IDP being directly involved but, importantly, also supports a model in which the client can act as an extension of an IDP, with rights for making claims delegated to it by that IDP.
Tags: Liberty Alliance, Advanced Client, Cardspace
Monday, February 12, 2007
Phish Alert
Watch out for a particularly nefarious new phish that started hitting e-mail boxes in the last little while.
The email purports to be a communication from Conor Cahill.
It asks users to click a link that appears as "http://conorcahill.blogspot.com.".
Unfortunately for the unsuspecting recipient, the link does indeed take them to Conor's blog site - at which they are presented with various posts about gadgets, United Airlines Business Class, and life in rural Virginia.
A clear case of identity theft. Our attention is a valuable thing, and Conor is clearly stealing it away from more useful applications.
Tell anybody you care about not to click on such links.
The email purports to be a communication from Conor Cahill.
It asks users to click a link that appears as "http://conorcahill.blogspot.com.".
Unfortunately for the unsuspecting recipient, the link does indeed take them to Conor's blog site - at which they are presented with various posts about gadgets, United Airlines Business Class, and life in rural Virginia.
A clear case of identity theft. Our attention is a valuable thing, and Conor is clearly stealing it away from more useful applications.
Tell anybody you care about not to click on such links.
Something is smishing
Amidst the praise for the anti-phish potential of sequencing Cardspace authentication to OpenID SSO, perhaps we shouldn't forget this. Or this.
Separately, I've an idea for a new phish attack. Steps follow
Separately, I've an idea for a new phish attack. Steps follow
- Write an article about phishing & identity theft etc.
- Give lots of statistics.
- Provide standard warnings about link clicking.
- Quote Bruce Schneier.
- Have somebody named 'Mike from Tulsa' bemoaning the loss of his identity.
- Provide an example of a phish email. For that example, have two links, one to a screen shot of the phished site, another prefaced with 'compared to the actual PayPal site (click here)'.
- Pay for search engine placement.
- Sit back.
Sunday, February 11, 2007
Andre, Conor; Conor, Andre
Friday, February 09, 2007
Disappointing
An article from RegDeveloper claims that Oracle's submission of its Identity Governance Framework to the Liberty Alliance is 'disappointing'.
There is no justification for the claim, no evidence at all in fact as to why the submission wasn't appropriate or a smart move by Oracle.
The only hint as to why the writer Gavin Clarke was disappointed was a reference to the absence of Oracle's CEO from the show due to illness. Somebody have a little thing for Larry?
There is no justification for the claim, no evidence at all in fact as to why the submission wasn't appropriate or a smart move by Oracle.
The only hint as to why the writer Gavin Clarke was disappointed was a reference to the absence of Oracle's CEO from the show due to illness. Somebody have a little thing for Larry?
Tags: Oracle, IGF, Liberty Alliance
SAML and Cold Fusion
A two part series on an implementation of SAML in Cold Fusion from Phil Duba
Part 1 and Part 2
From a comment in the second, Phil writes
This is quite the exaggeration - there are only 6 (SOAP, PAOS, HTTP Redirect, HTTP POST, HTTP Artifact, URI).
Part 1 and Part 2
From a comment in the second, Phil writes
The hardest part we've found in dealing with SAML is trying to figure out what of the 7 different methods/bindings is best to use.
This is quite the exaggeration - there are only 6 (SOAP, PAOS, HTTP Redirect, HTTP POST, HTTP Artifact, URI).
Tags: SAML, Cold Fusion
MLS & SAML
Rapattoni offers services to the real-estate industry. I had never heard of them until I saw them listed in Liberty Alliance's adoption pages. Rapattoni apparently uses PingFederate for SAML 2.0-based SSO between its various services.
I applaud the attempt (if not the result) to explain how SSO works. It's not often you see actual information (albeit confusing) in a press release.
Just when I thought I understood SAML.
Maybe they could next explain how agents are worth the egregious commissions they charge.
I applaud the attempt (if not the result) to explain how SSO works. It's not often you see actual information (albeit confusing) in a press release.
This new SSO feature is based on the security industry standard Security Assertion Markup Language (SAML) technology. This technology allows the customer to establish "trust" relationships between Web sites. Rapattoni's SSO program will create and send an attached SAML "file" along with a link that can be received by any complying vendor's Web site. This process allows the user to avoid the repeated logon. Further, once the user has gained access to a compliant remote site, they can move freely between Web sites.
Also included in the SAML file is all of the information required by the receiving site to perform a certain function properly.
Just when I thought I understood SAML.
Maybe they could next explain how agents are worth the egregious commissions they charge.
Tags: Rappatoni, MLS, SAML, SSO, Liberty Alliance
One Elgg, Sunny Side Up
Ben Werdmuller and Marc Canter are engaged in a pissing match heated discussion over their respective social network offerings - it's Elgg vs PeopleAggregator.
When criticized for Elgg's supposed lack of FOAF support, Ben responded
Ben might be forgetting something.
When criticized for Elgg's supposed lack of FOAF support, Ben responded
Actually, we've been doing FOAF pretty much since the year dot. Trouble is, nobody actually uses it. Show me the consumer applications. Or, in fact, any significant applications that even produce it. It's a bit like IMS in the educational world; you can shout all you want about it, and tout it as an important commercial feature, but in reality it doesn't really make much of a difference to anything. Ditto, SCORM. Or XFN.
What I do agree is that there needs to be some kind of standard that reliably covers the sort of data FOAF was meant to represent, in a flexible way.
Ben might be forgetting something.
Thursday, February 08, 2007
Tribute #1 - Gizmo of the Week
I picked up this can-opener from eBay for a steal. It was listed as $79.99 but I was able to use 200,000 miles to knock down the price 5 bucks.
It's a big improvement over the previous version, along with the can-opening piece it has 802.11g so I can control it from my office. I hate wasting time for the can to actually open so this way I can get it started before I get to the kitchen.
It came with management software but I didn't like how the menus were on the left-hand side so I wrote my own instead. If anybody is interested in doing some interop testing against my implementation just let me know.
I had earlier tried another manufacturer but found that its frequency interfered with that of the cereal bowl heater I had bought my wife for last years Xmassss. I had originally thought the problem was solar flares so had built a 300-foot tall geodesic dome to shield the house but this turned out to be a mistake (not mine, somebody elses). I had to take it down because it was clear plastic and the girls were always riding their horses into the thing.
My son (who is in a school for enriched students, not sure if I've mentioned that) was eventually able to diagnose the problem by building an interference detection system from Knex, a piece of aluminum foil, and three discarded Qtips.
Now if only Cheerios came in cans.
Tags: geeking out
Let's be fair about this
From the TimesOnline
"New proof that man has caused global warming"
Sure, but it's not as if women didn't also benefit.
"New proof that man has caused global warming"
Sure, but it's not as if women didn't also benefit.
Sampling OpenID RPs
OpenIDDirectory lists a whole bunch of OpenID Relying Parties at which you can use your OpenID.
As an experiment, I picked the New Sites category and attempted to use my ProtectNetwork.org OpenID. Here are the results:
Separately, there were almost as many 'ceremonies' as there were sites. Permutations included:
As an experiment, I picked the New Sites category and attempted to use my ProtectNetwork.org OpenID. Here are the results:
- http://www.fileformat.info/ - no option to log-in (using OpenID or otherwise)
- http://health20.org/ - Received 'The server encountered an internal error () that prevented it from fulfilling this request' after authenticating to my IDP. Interestingly, the site used the LID GUI model (i.e. icon in bottom right corner).
- http://www.phixr.com/photo/ - unable to login, the site indicates you can supply either a user name or OpenID, but still demands a password
- http://www.sylvainbriant.com - no option to log-in (using OpenID or otherwise)
- http://www.suppressionlist.com/ - Received 'Application error' after authenticating to IDP
- http://www.placeengine.com - No option to log-in (using OpenID or otherwise)
- http://www.insanejournal.com/ - Success!
- http://www.donengel.net/ - Partial Success. After successfully being redirected to my IDP, I consented to the release of my email back to the SP. Nonetheless, the SP still asked me for my email.
- http://www.challgren.com/ - Success
- http://www.finnix.org - Success
Separately, there were almost as many 'ceremonies' as there were sites. Permutations included:
- offering OpenID login as a peer to normal local account (e.g. Doxory)
- linking from main log-in page to an OpenID specific page (e.g. Finnix.org)
- variations on 'LogIn', 'Verify', as the etc (e.g. Challgren.com)
- Asking for an OpenID AND a password (e.g. Phixr)
- Describing the OpenID option as 'Blog URL' (e.g. Challgren.com)
Subscribe to:
Posts (Atom)




