Wednesday, September 05, 2007

Have they never been?

From a booking for an upcoming trip to Tokyo



'Having a set of wheels' in Tokyo would most certainly NOT make my trip more fun. It WOULD make it more expensive, stressful & (most likely) litigious.

They should do a little research into local driving conditions before they suggest that a traveller should make the attempt neh?

Just asking

Why don't we use the term 'rhetorical messaging' instead of 'asynchronous', e.g.
'as the messaging pattern is rhetorical, the sender need not wait for a response'
Far more intuitive I think.

Just asking.

Tuesday, September 04, 2007

Nuremburg to Helsinki

The Nuremuburg Code is a set of ethical best-practices for dealing with human subjects in experiments such as clinical trials for drugs. The Code arose in response to the horrors of the so-called experiments of Nazi doctors performed on prisoners.

Not surprisingly given its genesis, consent of the individual involved is the uppermost principle
The voluntary consent of the human subject is absolutely essential. This means that the person involved should have legal capacity to give consent; should be so situated as to be able to exercise free power of choice, without the intervention of any element of force, fraud, deceit, duress, over-reaching, or other ulterior form of constraint or coercion; and should have sufficient knowledge and comprehension of the elements of the subject matter involved as to enable him to make an understanding and enlightened decision.


The Declaration of Helsinki, its first edition appearing in 1964, is in some sense an evolution of the Nuremburg Code. The Declaration more specifically deals with clinical research like drug trials. A key change is that the rule for consent has been wattered down, instead of consent being clearly expressed as 'absolutely essential', we have

In any research on human beings, each potential subject must be adequately informed of the aims, methods, sources of funding, any possible conflicts of interest, institutional affiliations of the researcher, the anticipated benefits and potential risks of the study and the discomfort it may entail. The subject should be informed of the right to abstain from participation in the study or to withdraw consent to participate at any time without reprisal. After ensuring that the subject has understood the information, the physician should then obtain the subject's freely-given informed consent, preferably in writing.


In a sense, this is useful clarification of the basic principle, i.e. calling out the different steps that warrant gathering consent. But, there are a number of SHOULDs in the above that might give those setting up clinical trials inappropriate leeway. At least, this is the argument made by Sonia Shah in her book 'The Body Hunters'. Shah lays out the current outsourcing model in which 'Big Pharma' conducts drug trials in third world countries, but brings any resulting benefits back to those first world customers who can pay.

Those running the trials argue that obtaining informed consent from some impoverished and illiterate non-English speaking subject is, at best, challenging and at worst, pretty much impossible. So, they argue, they shouldn't be held responsible if it turns out that trial participants turn out to not understand what they signed up for. Shah suggests that a simple solution to would be to quiz trial candidates for their understanding before they sign up. If they pass, they can participate. Otherwise, not.

This model might work in other consent contexts.

Thursday, August 30, 2007

Ou est le metro?


To give myself some small sense of how confused users will be when confronted with mashed-up identity systems, I've created an account at OpenID France.

Canadianness notwithstanding, "Je ne parle pas le Francais".

Even though there was only a single system in play, I expect that the frustration I felt from initially trying to present my OpenID there (unsuccessfully, I eventually realized it's a FOP (French OP) and not a FRP) is representative of future user confusion when confronted with new & unfamiliar identity UI (granted that most users will not chant poorly-pronounced French-Canadian curses referencing Catholic icons under their breath in order to deal with said frustration).

Ah, OK, so this card thingy carries my OpenID thingy (which sometimes I just type in?) and its a managed thingy I think whatever that is, and because the card thingy has a pin thingy assigned I have to sign-in to the OpenID thingy both here and when I get sent over to the OpenID place when normally I just do that once but thats OK because I've used my cat's name for both, and by the way WTF is a SAML?


And everyone a password



From 'Ads of the World'

Tuesday, August 28, 2007

Work/home

Filter for Free Porn

From Vikram, news of an interesting initiative from the Australian government.

I know that I personally spend an inordinate amount of time searching for free porn so this filter would definitely be of interest to me (once all preset 'wombat' and 'koala' keywords had been removed).

Monday, August 27, 2007

Structured Information?

From Jeff, a sample of an OpenID token

<openid:OpenIDToken xmlns:openid="http://specs.openid.net/auth/2.0">
openid.ns:http://specs.openid.net/auth/2.0
openid.op_endpoint:https://openidcards.sxip.com/op/
openid.claimed_id:https://openidcards.sxip.com/i/jbohren
openid.response_nonce:2007-08-27T12:13:31Z0
openid.mode:id_res
openid.identity:https://openidcards.sxip.com/i/jbohren
openid.return_to:https://openidcards.sxip.com/demorp/
openid.assoc_handle:e88bb8e5c4577c85
openid.signed:op_endpoint,claimed_id,identity,return_to,response_nonce,assoc_handle
openid.sig:S4TcYfUDeUOIiCg0idtmJYijKGQ=
openid.ns.ext1:http://openid.net/srv/ax/1.0-draft4
openid.ext1.mode:fetch_response
</openid:OpenIDToken>


now that's some XML! With the logical pieces marked up in this manner, I would quickly whip up some XSLT to do some powerful processing of the token contents. For instance, color everything red. Or make it blink.

Challenge

See if you can read this without looking for parallels in today's Identity.

I do my find my identities at different sites getting 'jammed up', and then I have to open up the cover to free them. Ink gets everywhere.

Friday, August 24, 2007

Fluid Rebranding

Motivated by this, I am contemplating updating my brand and market symbol to better reflect what I 'bring to the table'.

Leading candidate right now is BEER. Also considering GIN. More market research is required.

Thursday, August 23, 2007

Notification Spam

Facebook's list of notification-worthy events is quite long. My list is different



Tags:

3KidsIsIt.Fixed.com

From MSNBC, this piece on parents buying domain names for their kids (and even choosing names based on availability).

A little bit of HTML redirection and these kids will be off to the login races as soon as they can say 'user-centric'.

I shouldn't judge. Hell, I named my daughter after an identity protocol. Ophelia Pauline Edna Nicki Irene Daphne loves her name. There is that Samantha kid in the neighborhood that teases for her lack of a certification program though.

Tuesday, August 14, 2007

Wittgenstein

Chris Ceppi questions the appropriateness of using attention data to build profiles.

I believe the Attention Trust equation of

How I Browse + What I Say + What I Read = Me

ignores an important factor - the 'Bullshit Factor'

How I Browse + What I Say + What I Read * (Who I am trying to impress) = Me

I might casually leave a philosophy tome from Wittgenstein out on the coffee table to impress visitors but that doesn't mean I'm going to read it.

Ever insightful, Monty Python had this to say on the issue
I drink, therefore I am.

Thursday, August 09, 2007

Eclectic Avenue

I was reading a LinkedIn profile of somebody who shall remain anon. Under 'Interests', they described their musical taste as 'eclectic' - citing various strangely named artists as evidence.

Why should I believe such a self-assertion, especially when the claimed attribute in question is generally considered a 'good thing'?

It's easy to claim eclectic musical taste, just as it's easy to claim a wide & varied range of reading material (I'm flipping back and forth between Proust & Homer's Iliad as I write this). Both claims are like a personal profile saying 'attractive' - sure, sure, I believe you but show me the head shot anyways.

Now, if the claim for eclectic were supported by demonstrated variety in listening habits, that might be a different situation. For instance, if the user's play list showed they listened to Bjork's Greatest Hits, followed by Debussy, I might start to believe that their taste was indeed eclectic. Bad, but eclectic nevertheless.

Seems to me that this sort of attention data (for which the effort of spoofing would be greater than any value derived therein) is therefore somewhere between self-asserted & 3rd-party asserted identity in terms of it's 'believability' (all else being equal).

Work/Home



Work/Home



Wednesday, August 08, 2007

Sneaky Deity?


The same analysis could spot fused identity URLs and thereby refute ID'ers (Identity Designers).

Social Selectivity

I wish social sites forced me (and others) to apply some level of selectivity in creating my network.

Lots of cell providers are offering plans where the customer gets unlimited calls/chats - but only to a prescribed set of friends/family members. As the size of this social network is constrained (and there is a cost to the customer), the customers will choose its members carefully. Also, knowing that they were selected/invited with care, its members would (might) appreciate the honour.

Would that the same effect applied in social sites, where there is almost no cost for sending an invite. To the sender that is, the cost (of reading the email, trying to remember a relationship, logging in, accepting the invite, etc) is borne by the invitee. I bet few people get invites from un (or barely) known strangers to join such a 'calling circle'.

I predict that, eventually, providers will offer tiered discounts to 'friends of a friend'. For instance, I'd get free calls to my 1st tier 5 friends, 50% off for the 25 members of the 2nd tier, etc. I expect I'll have to pay full rate to call Kevin Bacon.

Tuesday, August 07, 2007

CAPTCHA Context

Are there no standards for Captcha difficulty?

Some are trivial, others (like this one from Facebook) have me squinting at the screen trying out different letters.

Do sites go through a 'Catcha Complexity Review Process' before deciding on the appropriate difficulty?

Do we need syntax to describe the things ala SAML's Authentication Context for describing how users login?

Get your own cool friend


Perhaps I'm imagining things, but I see a definite trend towards establishing Facebook accounts amongst my identity-focussed colleagues.

I can't think why, Facebook offers me nothing I want, or don't already have elsewhere, and just about everybody else I know says they created an account only grudgingly (or for 'research') but hey, you can't fight trends.

Has there ever been a group less like the originally targeted demographic? My little network is geeky with a capital 'G'. We are the anti-thesis of cool college students. We surely understand more about the identity issues Facebook creates than WTF most account holders are even talking about - or the social reality in which they live.

Let's face it, my network is doing nothing to help my 'cool factor' (which will only drop precipitously whenever Conor creates an account). These people are holding me back from reaching my full social potential (admittedly as does my wearing of cardigans and the need to go to bed at 9.30).

Except for Joni, my token cool person. Joni stays up late, is a musician, and drinks martinis. Joni is cool with a capital 'C'.

Joni is my 'bridge' to coolness. Through her, I'm connected to the great unwashed (but socially current) masses. Through Joni, I learn about 'tracks', how to say 'wassup', and when to wear scarfs.

Like at Remagen, I will defend this bridge against any who would see it as their own easy route to the other side. You know who you are.

She's my cool friend, get your own.

Exit Strategy

Perhaps not coincidentally, two key contributors over the years to Liberty Alliance's technical frameworks are stepping away from identity, standards, and HP.

Both are filling their time around thermals, Robert Aarts flying them, Greg Whitehead causing them.

Both obviously had a well-defined exit strategy.

Google Maps Game Idea

Show the same highly zoomed-in, randomly-chosen map to two (or more) people.

The goal is to identify the world locale. Scoring system based on both speed (the faster the better) and zoom (the higher the magnification the better).

IDDY 2.0

Liberty Alliance Announces IDDY Awards Ceremony at DIDW 2007

This is not your normal identity award - it's much bigger than that. I wish there was a word to describe how big. And how unique. And new. A word (or perhaps a prefix) that would make clear that this award transcends boundaries, transcends particular technologies, even transcends politics and competitive standardization strategies.

Oh wait, there is such a prefix. How could I have missed it.

Meta-IDDY.

Fineprint (candidate implementations must use Liberty Alliance-defined protocols)


Sunday, August 05, 2007

I guess I was wrong

As both Dave and Pam disagree with my claim that the Catalyst Cardspace Interopathon was not a demonstration of a metasystem, I defer to their expertise & judgement. I guess I was wrong.

Now I see interoperable metasystems every where I look:
  • Just made myself a pot of metacoffee, using a standardized metafilter in a metabrewer. No metamilk so drinking it black.
  • Kids are watching a metavideo on the metaVCR (using the metaVHS tape standard, metaBeta having been defeated. I wonder what will happen between metaBlu-ray & metaHD DVD)
  • Family likely to ride on a metatrain next weekend, the metagauge wars long ago resolved in favour of 1435 mm.


My wife finds my new habit of prepending 'meta' on the front of every second word both charming & humourous. Perhaps I'll go make up the guest room metabed with the metasheets as a precaution though.

Friday, August 03, 2007

Email security

To: babington@catholics.uk
From: maryregina@scotland.gov

Dear Babington,

I hope this message finds you well (i.e. not diced up into quarters :-) )

It has been pointed out to me that the last message I sent you regarding the 'project' was encrypted using an insufficiently large cryptographic key.

While I am sure there is no cause for concern (Walsingham and his Protestant lackeys couldn't decrypt their way out of a paper sack) I shudder to think what might be the consequences were they able to either read our modify our correspondence....

Consequently, I suggest we increase our security measures. Perhaps move to WEP?

Better safe than headless eh? :-)

Yours

Mary, Queen of Scotland & England

p.s. the 'crypto' reminds me, I heard a good one the other day about my royal cousin, a crypto catholic, and a leper. Remind me to tell you when we next meet.

p.p.s. Might you have that 2 shillings I lent you? Times are tight here....

Modal dialogs

are all the rage for log-in.

Just in the last 2 hours, I came across two, that from Anywhere.FM pictured here



Is there irony in the use of a visual paradigm that might actually simplify a phisher's life (by giving them license to both blur the page details that might alert the user and that removes the burden of building fully functional (i.e. clickable) pages for authentication? If I was a phisher, I'd take a screen capture of the real site, add a grayish & partially-transparent layer in Photoshop, and be off to the races.

Doth not a metasystem make

7 Identity Selectors, 12 IDPs, and 25 RPs ....

Describing the Burton Group User-Centric Identity Interop at the Catalyst Conference in June, Bob Blakly writes

After the event, it can accurately be said that there is a running identity metasystem.

As key a milestone the Catalyst event was for demonstrating interoperability within the Cardspace/WS-Trust world, it demonstrated nothing beyond that world.

Even Microsoft includes 'multiple technologies' in its definition:
The Identity Metasystem is an interoperable architecture for digital identity that assumes people will have several digital identities based on multiple underlying technologies, implementations, and providers.

The event was specific to a single protocol. There have been numerous single protocol demonstrations of similar interoperability for SAML & ID-WSF over the last few years but nobody felt compelled to apply 'meta' as a descriptor (although I expect the marketing people wanted to).

Bob does acknowledge that the metasystem he refers to is early days and that the event identified a number of issues that the community of selectors, IDPs, and RPs need to resolve. My objection to the use of 'meta' is not that what was demonstrated is not fully-formed & complete, rather that, even once these issues are resolved, the result will be 'merely' a system - as the issues he hilites (e.g. card acquisition & presentation) are all specific to the Cardspace 'biosphere'.

These are important issues, but different than those that confront the metasystem.

Wednesday, August 01, 2007

Circularity

There should be a name for this social effect, is there?

Paul Downey
's picture of me in front of a screen shows Eve in the act of taking a picture (of me in front of the same screen).

If only Eve's photo had happened to catch somebody else taking a picture of me in which they captured Paul D. taking his photo of me etc .... we'd have a wonderful little social network (centered on me which is even more wonderful).

Evenning Things Out

From Paul Downey, a pic of Eve talking to the 'Venn of Identity'.

Tuesday, July 31, 2007

Leveraging infrastructure

At last week's (wonderfully mild-weathered) XML Summer School, Jeff Barr gave a great talk on Amazon's Web Services offerings. (Jeff is an 'evangelist', unlike most TV evangelists I'm familiar with Jeff did not call me a sinner and is not, AFAIK, under federal investigation for tax fraud).
Amazon Web Services provides developers with direct access to Amazon's robust technology platform. Build on Amazon's suite of web services to enable and enhance your applications.

Additionally, artfully placed in the room were pen's advertising BT's Web21C program (I'd suspect Paul Downey of dropping the pens except that the services are SOAP-based).
The Web21C SDK is a set of libraries that makes it simple for developers to consume Web Services exposed by BT

Hmmm, I see a trend here. Whatever you aren't fully using, rent out.

I have loads of lawn & garden equipment that I use only occasionally. What if I were to make this surplus infrastructure available to friends & neighbours through web service APIs?

<BorrowFertilizerSpreader>
<PlanOnReturning>unlikely</PlanOnReturning>
</BorrowFertilizerSpreader>

Of course, once all the equipment had been lent out, then I could just sit back with a beer and rest.

Yeah, I'd love to cut the lawn Honey but, hey, the APIs ...

Work/Home



Tags:

Work/Home



Tags:

Sunday, July 29, 2007

Saturday, July 28, 2007

Redirect protocol & Usability

Sequence

1) User joins ticket queue at London's Victoria Coach Station
.
.
2) User directed to ticket booth #14
3) User requests service to Oxford
4) Ticket booth #14 requests payment
5) User presents credit card payment token
.
.
6) Unable to directly process token, ticket booth #14 redirects User to ticket booth #8
7) User presents credit card payment token to ticket booth #8
8) Ticket booth #8 processes credit card payment token, returns receipt token to User
9) Ticket booth #8 redirects User to ticket booth #14
10) User presents receipt token to ticket booth #14
11) Ticket booth #14 returns 'You can ride to Oxford' token to User
12) User exits, looking for nearest pub

Henceforth

I will be using the following multimedia mechanism (rather than the default impersonal 'X wants to be your friend/buddy/colleague/twit etc') to extend social invites.


GALLERY lyrics

I suppose I need something comparable should I actually ever receive such a invite. Cross that bridge when I come to it.

Friday, July 27, 2007

Bladder.com


Any interested angel investors please call, we can have some drinks and see what develops.

At least initially I'm focussed on raising liquid capital.

Tags: ,

Thursday, July 26, 2007

Cardspace Usability Nit

When Cardspace poses the question 'Do you want to send this card to XYZ.com?', it doesn't provide a 'No' button. To answer yes, you click on 'Send', to back-out you click on the blue arrow to the left of the question.

The blue arrow is consistent with the IE 7 interface, (it's the same as the back button) but is inconsistent with the 'Send'. More intuitive would, I think, be a corresponding 'No' button.

Thursday, July 19, 2007

Don't Slip Up (ha!)


Banana for locking your PC.

I wish I had a web cam to try it out.

19 members and going strong

The Facebook group for 'ID Professionals wary of joining groups' is, perversely, continuing to add members.

I confess that when I originally conceived of the idea, I was thinking only of putting out a beta, paying for some nice reviews, and then positioning the group for acquisition by one of the larger anti-social groups. Pocket the proceeds and move on. Totally Group 2.0.

But the fact that people are joining makes me think that maybe this thing has legs and I need to revisit my strategy.

My marketing people are telling me that research into online social trends is clear - NOT joining groups is going to be the next big thing. Any technology that helps people not join social networks (or chat with friends, tell friends what they last ate, etc) can be huge.

And I already have a number of patents that might be relevant, e.g.
  • 'A Mechanism for Causing a Computing Device to Temporarily Cease Operations'
  • 'Unplugging of Wires in Order to Interrupt Digital Communications'

Tags:

Enigmatic

From Boing Boing, an Enigma machine is for sale on eBay.

The article refers to a previous, in which the author wrote

German soldiers issued an Enigma were to make no mistake about their orders if captured: Shoot it or throw it overboard.

Actually the Germans went on the assumption that the Allies had the machines (like modern cryptographers assuming the details of an algorythm being known), it was the day codes that were jealously guarded.

Also like asymmetric crypto used to encrypt the secret key used to actually encrypt a email message, the Enigma day code was used to encrypt a specific one-time code (the scrambler settings) used to encrypt the message.

Given that the Allies were able to consistently obtain the day codes, it seems strange that, as far as I know, the Allies never took advantage in order to send a fake message (I expect that, for the Germans, a properly encrypted message would have had better bona fides that otherwise). Presumably the risk of the Germans clueing in (and changing how Enigma was used) was deemed too great.

Monday, July 16, 2007

Kreepy Krawly


I picked up an automatic vacuuming system for the pool (the boy proving less than reliable for keeping the algae at bay when I'm away)

Most of the time, the thing works great, working on my behalf, it putters around and does its thing. But occasionally, it gets stuck (damn you stairs!) or up-ended and I need to get involved to get it back on track. Typically, this involves me giving a little nudge to get the device back on its merry schlurping way. Even with the hassle of these occasional interventions, the effort the device saves me is, on balance, worth it.

Hmmm, user-mediated operations guiding subsequent automatic transactions. Identity analogy anyone? (even acknowledging that the vacuum's automatic operations are random & mindless, I have accounts with providers that seem to have the same process model).

Some would deny automatic identity transactions any part in a privacy-protecting identity framework, if the user is not directly involved, i.e. right then & there, then they can't be sure that the pool is being cleaned in accordance with their 'pool vacuum preferences'.

Two comments:
  • Sometimes the pool needs to be cleaned at inconvenient times,
  • I've yet to work out a way to stop my drink from spilling while actively vacuuming
For myself, just as I was willing to let our previous pool man Miguel (my wife still talks about him) perform important duties on my behalf, I'm willing to let the Kreepy Krawly do the same (with the occasional correcting nudge).

Friday, July 13, 2007

Brand Abuse


I addition to its beer, Heineken kindly provides a document storage service for users.

Myself, I often temporarily store sensitive health & financial information with the bouncers of the many 'before hours' nightclubs I frequent so this makes perfect sense.

Funnily enough, the site's privacy policy makes no mention of 'My Documents'.

Dad is connected to the Internet

Visiting the parents, I had to resort to using my father's dial-up account. Created a connection and called it 'Dad'.

This pretty much sums it up.



Unlike its namesake, the connection didn't tell me the same jokes over and over and share insightful commentary on diverse topics such as "what's wrong with the world today".

Escape (The Pina Colada Song)

<profile>
<name>Rupert</name>
<likes>
<drink>Pina Colada</drink>
<drink>champagne</drink>
<activity>making love at midnight</activity>
<activity>getting caught in the rain</activity>
</likes>
<dislikes>
<food>health food</food>
<activity>yoga</activity>
</dislikes>
</profile>

Proof

This is what a 4-hour drive with 3 kids listening to the Fabulous 70's on Sirius Radio will get you. Plus a headache.

Wednesday, July 11, 2007

Sent from my Dell

I just received my first email message with 'Sent from my iPhone' as postscript.

I've always found it annoying when I saw the same for BlackBerrys. It always conjured up images of marketing types striding purposefuilly through airports. I've decided to up my annoyance level for iPhones.

Is there any conceivable reason why I should care about the specific device from which a message was sent?

The only justification I can think of (other than misplaced viral marketing) is that the sender wants to explain the brief & cursory messages that typing on such a device requires.

If this is the reason, would not 'Sent from a device with a crappy keyboard' achieve the same?

And wouldn't Apple want this reality downplayed rather than hilited?

Tags:

Tuesday, July 10, 2007

Divine IM

Yahweh22: YT?
Moses88: I am not here right now.
Yahweh22: Moses, I know you're there, I can SEE you.
Moses88: Sorry Boss, I was screening.
Yahweh22: Well don't, it's annoying.
Moses88: Sorry Boss, WU?
Yahweh22: I want to send you a file with a set of instructions for the people. Sort of a "Top 10 of Do's & Don'ts"
Moses88: Great idea Boss, they could use some guidance. I've been seeing some idol worshipping lately.
Yahweh22: OK, sending the file
Yahweh22 wants to send you the file '10-Instructions.pdf', Accept?

Moses88: Did you send it Boss, nothing came through.
Yahweh22: Damn, this never works. I'll try email.
Moses88: Worth a try but your messages are getting caught in my spam folder.
Yahweh22: What?
Moses88: I think it's the 'ever-lasting' in your signature that the viagra rule seems to catch on.
Yahweh22: Well how am I going to get you the instructions?
Moses88: Courier?
Yahweh22: Get real. You seen their prices?
Moses88: True.
Yahweh22: OK, got an idea. Listen up
Moses88: All ears :-)
Yahweh22: I'm going to etch the instructions in a block of stone.
Moses88: LOL! Good one Boss. :-)
Yahweh22: I wasn't joking.
Moses88: Stone? Like a rock?
Yahweh22: Yup, something hard. Granite if I can get a good price.
Moses88: So I'll be showing this big stone to all the people?
Yahweh22: Sure, what's the problem?
Moses88: No problem at all Boss, it's just that I've been having back problems lately and I'm a little worried about carrying this thing around.
Yahweh22: There, that feel better?
Mosees88: Thanks Boss, much. Uhh, I've also had a bad rash on my ...
Yahweh22: Don't push it Moses. I'll send you down the stone ASAP
Moses88: Where will I find it?
Yahweh22: Lets use the burning bush thing again.
Moses88: Will do Boss :-)
Yahweh22: One more for the list. “Thou shall not use 'smileys' indiscriminately.” L8r
Moses88: :-(

Saturday, July 07, 2007

Punch Line

Friend 1: Hey, got a funny one. A guy goes into a bar ...
Friend 2: What's his name?
Friend 1: Why, what's it matter?
Friend 2: It matters alot, how we are identified can be critical, it could ...
Friend 1: OK, OK, lets call him 'Joe'.
Friend 2: 'Joe'? really? Well OK ...
Friend 1: You don't like 'Joe'?
Friend 2: No, no, 'Joe' is fine, It's just, well, you know, pretty common ...
Friend 1: Why is that bad?
Friend 2: Well, I guess I'm just worried about this 'Joe' getting confused with some other 'Joe' and being able to put drinks on his bar tab or something but, no, that's silly, lets move on ...
Friend 1: You sure? I mean, I want you to be happy, we could call him 'Eugene' or something?
Friend 2: 'Eugene'? Dear God no, that's too unique! Different bars that he might go to would be able to work out that he was going to both places, and work out his drinking patterns and stuff. No, lets stick with 'Joe'.
Friend 1: OK, great, so, a guy named 'Joe' goes into a bar and ..
Friend 2: Has be been there before?
Friend 1: Where, the bar? No, he hasn't been there before.
Friend 2: Probably best.
Friend 1: OK, so Joe says to the bartender ... Wait, what do you mean 'probably best?
Friend 2: Well, if Joe has never been there before then the bartender won't be able to ...
Friend 1: You know, I think you're missing the point. It's supposed to be a joke. What the bartender knows about Joe doesn't really matter.
Friend 2: (under his breath) I bet it matters to Joe.
Friend 2: (loudly) You're right, sorry, keep going.
Friend 1: Right, so Joe is in the bar and ...
Friend 2: He went in on his own right?
Friend 1: Yes, of course he went in on his own!
Friend 2: Good, so he wasn't dragged in without his consent or anything.
Friend 1: (through gritted teeth) No, he is absolutely there of his own freakin' consent. Is that clear? Can I go on now?
Friend 2: nods his head contritely
Friend 1: So Joe says to the bartender 'Give me a beer' and he throws a credit card on the bar ...
Friend 2: Credit card? Joe didn't have any cash? .... Hey, where are you going? I want to hear the end .....

Live Earth

Watching Live Earth - love the irony of performers drinking bottled water while advocating environmentally responsible consumerism.

Friday, July 06, 2007

Two hundred dollar bid, now three ....


From dark reading, an article on a marketplace for security vulnerabilities.

WabiSabiLabi describes itself
Our scope is to provide an institutional market place in which security researchers can offer to place their work to the market through a platform designed to maximize their reward.

Could there be a 'privacy in identity standards' category? If nothing else it might serve to move the interminable linkability thread off the ID Gang list.

The philosophy of recognizing imperfection in security is described as
... three simple realities: nothing lasts, nothing is finished, and nothing is perfect.

Sounds like my home improvement projects (as I tell my wife, it's not that the closet isn't finished without doors, I always planned it to be 'open').

Thursday, July 05, 2007

Ford would be proud

An un-named source in Redmond sent me this never before seen picture of the first ever infocards assembly line.


In the front you can see a worker inserting secret keys obtained from the bins below (the punch-card calculating machines on which those keys were generated are in another room). Other workers further down the line can be seen inserting attributes before securing the top of the cards with wrenches.

My source tells me that another line is planned.

Tags:

More US jobs lost to a 3rd world country

Soon it will be 'Cardspace eh'.

And Tim Horton's coffee preference will be one of the built-in attribute types.

Medium Decaf Regular if you're wondering.

Wednesday, July 04, 2007

Family IT department

As an experiment in parental control, I installed Glubble on the family PC's Firefox. It's an extension that enforces whitelists of approved sites for my kids.

I am now being bombarded with emails like the following in which my kids request that I (as the admin) grant them access to specific sites.

Navsafe - New access request from Bommer

Greetings mudman

Bommer has sent you a new access request.

You may login to your Glubble account and see the details of the request there.

Best regards,
The Glubble Team

As yet, I've received no requests for access to this blog - obvious glitch.

Tags:

Found the problem



Reattached a discombobulator wire that had come loose and everything now works fine. Interesting to actually see where the cards are stored.

Pic from cnet.

W5

Julian's post on systems by which users can provide the 'what & where' of their current situation makes me think we'll eventually see the other three 'w's of W5.
  • Who - I'm already sick of the inevitable happy faces
  • When - perhaps relevant for seniors, i.e. 'I'm not dead yet'
  • Why - for the philosophers. But does the answer change?

SAML SSO in China

I know that there is SAML in the mix of this Chinese identity implementation because they conveniently don't translate the acronym

·支持SAML协议的用户身份验证和统一用户登录;

TRS works with Chinese Government agencies, universities, and other IT shops.

Tuesday, July 03, 2007

Grey Screen of Death

Can't use Cardspace at either SignOn.com or Fabrikam Friends (is there an end of life plan for 'fabrikam'? please?).

Cardspace wakes up, screen greys out, and stays that way.

Worked just last week at SignOn.com.

IE 7, WinFX on XP.


Tags:

Saturday, June 30, 2007

Iconic

Given it's similarity to the standard 'i', will not more than a few people be clicking on the Cardspace icon expecting to GET information, rather than provide it?


Friday, June 29, 2007

Schrodinger's SSO


If a user SSOs into an SP, and then some amount of time goes by, during which the user's original session at the IDP has a 50% chance of expiring, is it not the case that, from the SP's PoV, the user can be considered to be in a superposition of signed-in and signed-out states at the IDP?

And, only once the SP asked the IDP for a new authentication assertion (with saml:ForceAuthn='false' or equivalent), would the user's authentication wave collapse into one of the two states - this result manifested in the IDP response?

Stuck on Band-Aids, 'cause Band-Aids ...


From Popular Science, plans to build a medical research system that

will give donors an unprecedented degree of control over their cells

BioTrust's automated process will enable donors to control how their tissue is used and to reap greater benefits from donation. During the consent process, donors will select the studies that they do or do not want done on their tissues, and the computer system will store that data along with the details of their samples.

They'll surely need 'sticky' policies.

Wednesday, June 27, 2007

Provider Purity Ball

Recently, high-school gyms and up-scale hotel ballrooms across the nation are playing host to Provider Purity Balls.

Advocates say that the balls are an innocent ceremony in which IDPs sign commitments to act with integrity in all areas of business ethics and to protect their SPs in their choices for partner selection. SPs themselves vow to remain 'business abstinent' and to be led by their IDPs in choosing parters. Critics of the balls claim they are nothing but a throwback to an age when SPs were nothing but property of IDPs, the value of which could be damaged by early participation in activities like SSO.

'It's not like when we were young SPs growing up' said Merle Jacobs, an IDP who brought his 3 SPs to a recent ball held in Topeka, Kansas. 'I mean, when I was an SP, it was just more innocent. You could talk with an IDP and not feel forced to actually, you know, exchange 'data'. But SPs today see potential federation partners everywhere they look, on TV, in movies, even on the Internet. The pressure for SPs to be promiscuous in picking partners is everywhere. All we're doing is to try to help them make the right decision. And the right decision is to not engage in federation until protected by binding legal contracts.'

A young SP named Mary agreed. 'Its like, you know, just that I want to save those special emotions for the IDP that I eventually sign legal contracts with. I'm in no hurry, it's not like the Internet is going anywhere'.

'For my SP and I, the evening is more just a chance to get dressed up and spend some quality time together' said one IDP who wished to remain anonymous. 'I mean, she's only just out of business school, it's not like I have to be worried about her engaging in indiscriminate partner selection at this point in her lifecycle right?'

One of the most memorable highlights of the balls is the point during the evening when the IDPs stand in the middle of the ballroom and form a circle around their SPs - each standing all aglow in their lovely ball gowns.

Tuesday, June 26, 2007

HP in a hand basket

I was going to leave a comment on a post of HP's Marco Casassa Mont’s Research on Identity Management blog when I saw this


Somebody at HP with a sense of irony? Or are they falling apart with Greg's departure?

SignOn.com

Ping's SignOn.com is a notable OpenID provider because it supports the use of an Infocard for authentication (as well as having an eminently Googlable name). Is it the first public OP to do so?

The process of registering a card is straightforward (at least currently, it seems that you must have a username/password account to which you 'add' cards). I did notice an oddity though.

After registering a card, I edited that same card (adding my postal code). I was hoping that the new info would be communicated to SignOn.com (the next time I presented the card), and used to populate the profile (where it could then be sent to requesting OpenID RPs). This didn't happen.

A peak under the HTML covers shows that this is because SignOn.com isn't asking for the postal code, it's not on the list of 'required' claims


<object id="_xmlToken" type="application/x-informationCard">
<param name="requiredClaims"
value="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"/>
<param name="tokenType" value="urn:oasis:names:tc:SAML:1.0:>
<param name="issuer" value="http://schemas.xmlsoap.org/ws/2005/05/identity/issuer/self"/>
</object>

So SignOn.com isn't willing to ask Cardspace for the postal code (presumably because it fears rejection), but it is willing to ask me (it's on the profile page).

Even though I had entered the postal code into the card, because SignOn.com didn't ask Carddspace for it, I am presented with an empty form field asking to be filled in. Does SignOn.com want it or not?

SignOn.com is of course only asking me for the postal code because they anticipate that they themselves might be asked for it through OpenID. As a result, if I want to ensure that these eventual RPs get my postal code, I will have to enter it a second time beyond the value in the card.

The disconnect here is between the identity demands of the 'application' (the bit of SignOn.com that wants to provide postal code data to RPs) and the multiple 'query mechanisms' by which that data is obtained (both the HTML profile page and the Cardspace 'required claims' parameter). As it stands, the two query mechanisms are asking for different amounts of identity so its impossible to know what the application actually 'wants'. Ideally, the application would be able to indicate what identity it needed, and the query mechanisms would be driven accordingly (e.g. ensuring both sets of HTML were consistent) This is the CARML proposition.

Client Attribute Requirement Markup Language (CARML) is an XML-based language used by application developers to specify what identity information an application needs and how the application will use it.

The issue of course isn't unique to SignOn.com, or to Cardspace, this specific scenario just illustrates the challenges faced when identity flows through multiple providers (especially when intermediate ones collect identity on their own).

Ensuring that the user's privacy policies also flow with the data is a whole different ball game.

Monday, June 25, 2007

Clash of the Titans

Generally, whenever heavyweights like Kim and Conor go at it, I cower in a corner and wait for the storm to blow over before coming out and picking from the debris like some Welsh coastal farmer.

Well the 'storm' turned out to be more of a squall. And so to the looting.

Kim writes
So, returning to the axes for linkability that we set up in Evolving Technology for Better Privacy, we see that from an identity point of view, the identity provider “sees all” - without the requirement for any collusion. Knowing each other’s identity, the relying party and the identity provider can, in the absence of appropriate policy and suitable auditing, exchange any information they want, either through the redirection channel, or through a “back channel” that dispenses with the user and her browser altogether.


Some thoughts

  1. 'sees all' is presumably in quotes because, as Irving had earlier pointed out (and as Kim acknowledged), the IDP doesn't see 'all'.
  2. an IDP 'merely' seeing the RPs to which a user is visiting is not case of collusion. Collusion requires inappropriate cooperation, i.e. two or more entities have to be 'in cahoots'. All else being equal, for the IDP to have this knowledge (where the user goes) when it doesn't need it can be undesirable from a privacy point of view, but it's not collusion, it's leakage (and of course, all else isn't equal as Conor pointed out).
  3. if the RP and the IDP are 'exchanging any information they want' without considering the privacy policies of the user, then the two of them are in cahoots, and colluding against that user. Both RP and IDP have 'turned'. The bar for two providers to go bad and collude against their users/customers is of course higher than for a single provider. How they find each other is one challenge. Do they advertise in the classifieds?
    SP seeks IDP partner for malicious & casual collusion. I enjoy curling up with a good book, stealing identity and walks on the beach. I 'm trying to learn to play the guitar, defraud the government, and snowboard Double Diamond runs. No kinkiness.
  4. 'dispenses with the user and her browser altogether', in the sense of enabling identity flow without the user's active mediation, is of course necessary if you want to support use cases in which the user is 'offline' (as will be the case for many social-sharing use cases). How will active mediation systems like Cardspace support such use cases? Just pile up the requests for identity until such time as the user comes online?

Friday, June 22, 2007

Forced perspective


From Boing Boing, an example of 'forced perspective'.

Forced perspective is a technique that employs optical illusion to make an object appear farther, closer, larger or smaller than it actually is.

For identity operations, it could be used to make some operation appear 'safer' than actual.

Pictures of puppies, babies, or happy people on a log-in screen would qualify.

Too much information

Kim acknowledges the need for standardized information resources for Cardspace users (although the issue is of course not specific to Cardspace).

The research of the psychologist Paul Slovic on how the quantity of information does not guarantee quality predictions would seem relevant.

Slovic performed an experiment in which he gave bookmakers varying amounts of information relating to horses' performances, and then asked them to predict the horses' success in races. He found that the accuracy of the picks remained the same, no matter how much information the bookmaker had - the extra data just served to make the bookmakers more confident in their picks.

Users will soon be presented with skads of information designed to help them understand (and effectively predict) the consequences of their decisions regarding their identity - and its sharing. Will the information help them accurately predict the results of consenting to some identity operation, or simply serve to make them feel comfortable with their choice?

Thursday, June 21, 2007

Shortlisted



A photo I took of HMS Belfast, moored in the Thames in London, has been selected for possible inclusion in a travel guide

Your photo(s) shown below have been short-listed for inclusion in the third edition of our Schmap London Guide, to be published at the end of this month.

While we offer no payment for publication, many photographers are pleased to submit their photos, as Schmap Guides give their work recognition and wide exposure, and are free of charge to readers.

If you would like your short-listed photo(s) to continue to our London Guide final selection phase, please read our 'Terms of Submission' and press the 'Submit' button, no later than our editorial submission deadline – Friday, June 22.
For an artist such as myself, for whom the digital photo muse is the only true arbiter, recognition like this is meaningless.

Wednesday, June 20, 2007

Confused (and not the disingenuous kind)

I'm confused (OK partly the disingenuous kind)

Stefan Brands asserts that I , along with Dave Kearns

wrongly equate unlinkability with anonymity

in a blog thread between ourselves and Kim Cameron.

Try as I might, I find no mention of 'anonymity' or 'anonymous' (and definitely no reference to 'anonymous credentials') in my post?

Dave can look after himself.

Male Brain circa 2010

Tuesday, June 19, 2007

A fellow traveller

Kim (a fellow traveller of mine don't you know) Cameran disagrees

The one statement Paul makes that I don’t agree with is this:

Were an IDP to use transient (as opposed to persistent pseudonymous) identifiers within a SAML assertion each time it asserted to a RP, then not only would RP’s be unable to collude with each other (based on that identifier), they’d be unable to collude with themselves (the past or future themselves)
.

I’ve been through this thinking myself.

Suppose we got rid of the user identifier completely, and just kept the assertion ID that identifies a given SAML token (must be unique across time and space - totally transient). If the relying party received such a token and colluded with the identity provider, the assertionID could be used to tie the profile at the relying party to the person who authenticated and got the token in the first place. So it doesn’t really prevent linking once you try to handle the problem of collusion.

Yes, but then we are no longer talking about 'RP/RP' collusion, in which (by my definition at least), the IDP stays pure and it is only the RPs that cross to the Dark Side. Bringing in the IDP changes everything (as Kim acknowledges by creating the separate 'RP/IP' correlation category.

Irving joins in (and he must be agreeing with me or I wouldn't link to him) to point out a Shib use-case. I was going to (smugly) point out how Sun used SAML/Liberty for enabling employee access to BIPAC as another example but, on digging a bit, it seems that they aren't using transient identifiers. I guess BIPAC wanted to provide employees continuity of service, e.g. no repeated questions like 'Are you now or have you ever been a member of the Communist Party?'

2nd Law of Correlation

This law which belongs to me is as follows.

Ahem. Ahem. Ahem. Ahem. Ahem. Ahem.

This is how it goes. Ahem. The next thing that I am about to say is my law.

Ahem. Ready?

The total correlation potential of two or more contiguous digital identity systems tends to increase over time, eventually approaching a maximum value of which marketing folks dream when they sleep.

Dopplrerati

The Dopplr effect swept through identity space last week (thanks to wave generator David).

I received a low-pitched follow-up this morning. The invite (identity obfuscated to protect the questionably innocent) is below



Dopplr has a list of my planned travel, as well as the same lists of colleagues of mine. In all likelihood, if and when we are going to the same destination at the same time, we are going to the same event (and so associated group logistics (e.g. hotels, shuttle buses, tours, etc) might be offered)

Why wouldn't airlines want this business (to the point of discounting it based on number of travellers)?

Come to think of it, Dopplr should be asking me for my FFF (Frequent Flyer Federation). It's points & upgrades, far more than the chance of an invigorating identity chat back in economy (the part of coach at the very front where they serve you drinks/meals first but otherwise treat you with equal disdain to the group of high-school students going to a band competition at the very back) that will drive my group allegiance.

Tags: ,

Monday, June 18, 2007

Canada's no-fly list

As of today, we get our own list

Should be straighforward to manage

<eh:NoFlyList>

<eh:ListRef uri="https://www.whitehouse.gov/noflylist.xml"/>

<eh:OurOwnGuys>

<eh:Entry>
<eh:Name>Conrad Black</eh:Name>
</eh:Entry>

<eh:Entry>
<eh:Name>Celine Dion</eh:Name>
<eh:Direction allow="exit-only"/>
</eh:Entry>

</eh:OurOwnGuys>

</eh:NoFlyList>


Colluding with yourself

Kim Cameron introduces a nice diagram into his series exploring linkability & correlation in different identity systems.

Kim categorizes correlation as either 'IP sees all', 'RP/RP collusion', or 'RP/IP collusion', depending on which two entities can 'talk' about the user.

A meaningful distinction for RP/RP collusion that Kim omits (at least in the diagram and in his discussion of X.509) is 'temporal self-correlation', i.e. that in which the same RP is able to correlate the same user's visits occurring over time.

Were an IDP to use transient (as opposed to persistent pseudonymous) identifiers within a SAML assertion each time it asserted to a RP, then not only would RP's be unable to collude with each other (based on that identifier), they'd be unable to collude with themselves (the past or future themselves).

I was working on a diagram comparable to Kim's, but got lost in the additional axis for representing time (e.g. 'what the provider knows and when they learned it' when considering collusion potential).

Separately, Kim will surely acknowledge at some point (or already has) that these identity systems, with their varying degrees of inhibiting correlation & subsequent collusion, will all be deployed in an environment that, by default, does not support the same degree of obfuscation. Not to say that designing identity systems to inhibit correlation isn't important & valuable for privacy, just that there is little point in deploying such a system without addressing the other vulnerabilities (like a masked bank robber writing his 'hand over the money' note on a monogrammed pad).

Friday, June 15, 2007

User Dashboard

John Battelle discusses the relevance of a 'Privacy dashboard'.

Is it too much to ask, I keep asking, to ask our online services to provide us:

- Access to a record of all the information they keep on us and how they use it
- The ability to challenge that data's accuracy, and edit it for accuracy
- The ability to opt out (with a clear understanding of the resulting loss of services and opportunities that might result)
- The ability to set permissions as to who else might see the data
- The right to maintain a user copy of that data for archival purposes
- The right to share in the value of that data on negotiated terms

It's not stated but the implication seems to be that there would be such a dashboard for each provider in isolation, e.g. one for Google, another for AOL, etc. Dashboard silos. Beyond the implied management burden for the user are the issues such a model would create for providing a holistic view of their identity operations.

To combat this scenario, the Liberty Alliance is working on a Reporting Service, whereby the 'events' that a user/employee/citizen would wish to track/manage/approve would be communicated to their chosen 'dashboard provider' - thereby making possible a 'single' (the user could always have multiple providers) point of control as well as a comprehensive view of the W5 (who, what, where, when, why) of their identity transactions.

For instance, if Joe's calendar service shared his availability with their best friend Bob (based on Joe's previously set permissions), the calendar service could report this event (not the calendar data itself) to Joe's reporting service (and subsequently made available to Joe through a dashboard interface). If Joe, through the same dashboard, was able to determine that his wife Marie, simultaneous with Bob's query, was asking about Joe's whereabouts through Joe's geo-location service, he might have cause to be concerned (and perhaps avail himself of a 'Private Investigator Service').


Thursday, June 14, 2007

Guns don't kill people

People kill people (albeit with guns alot of the time.)

My identity corollary
Identity protocols aren't 'user-centric', deployments of identity systems are user-centric (or not).

Starpy?

During a discussion of terminology at this week's Liberty Alliance Technology Expert Group meeting, we noted the use of 'OP' (OpenID Provider) by the OpenID community to refer to their flavour of an Identity Provider.

A clear precedent for:
  • 'LP' == 'Liberty Provider (who could hate somebody that increased the amount of liberty in the world?)

  • 'FP' == 'WS-Federation Provider

  • '*P' == 'WS-* Provider


Note: Yes thanks I am aware that LPs are antique technology. But consider the rich sound they give.

Tuesday, June 12, 2007

Today's Bible Lesson

Having finished my novel on the flight yesterday, I had nothing to read when I woke up this morning in the hotel room.

I opened the Gideon Bible to a random page.

Deuteronomy 25

14 "You shall not have in your house differing measures, a large and a small.

15 "You shall have a perfect and just weight, a perfect and just measure, that your days may be lengthened in the land which the Lord your God is giving you.

16 "For all who do such things, all who behave unrighteously, are an abomination to the Lord your God.

Amen to that.

I do hope Concordia is considered to satisfy the spirit of the directive if not the specifics.

Friday, June 08, 2007

When IDPs go bad

Nauru, and it's past indiscriminate issuing of passports to anybody who could pay for one, is an example of 'bad IDP', i.e. one that exercises less than the necessary due diligence in vetting it's users before making assertions about them (there are of course lots of other ways for an IDP to be 'bad')

Clearly, once the scam was recognized, customs officers around the world would have had their internal alarm bells set ringing anytime some traveler presented a Nauruan passport. At that point, it would have been almost better to have no travel documents at all than to have one from Nauru.
Traveller: Sorry Officer, I have no papers.
Customs: Hmm, that's a bit awkward, you see we normally do like to see a passport or something. Perhaps you could write yourself a little note saying where you're from?
Traveller: Sorry, no pen.
Officer: Ahh I see, well, that's probably best actually, we're trying to cut out self-asserted. Now let's think about this ...
Officer: (brightly) Say, you're not from Nauru are you?
Traveller: No sir.
Customs: (pause) Welllll, I guess I can make an exception. Just this time though OK?.

Strangely, I have more trust in Nauru's passport office than I do in its national airline.

Thursday, June 07, 2007

Represent - verb


David Recordon gives his definition of 'represent' in explaining what he will be doing, and what he won't) at next month's Project Concordia panel at Burton Catalyst.

David's interpretation of 'represent' is consistent, I think, with the urban slang definition.

Coincidentally, it was through gangsta idiom that I was directed to represent my own company in Concordia.

Boss: We want you to help square up this identity mess, yo.
Me: So you want me to participate in Concordia?
Boss: Dat would be da hizzy.
Me: O.K.
Boss: Represent.

I do think Concordia needs our own 'gang sign'.

100% Canadian

Unfortunately so.

On the positive side of the Ottawa Senators loss to the Anaheim Ducks in the Stanley Cup finals is that I won't have to listen to the mono-syllabic 'analysis' of Don Cherry for a while.

When the most visible hockey export from Canada is 'All youze kids out there, youze guys, aints, anyhows, anythinks and dat deres', is it any wonder the game can't gain market in the US?

Wednesday, June 06, 2007

Blurring multi-factor

Would this be:
  • Something you know, or
  • Something you are, or
  • Something you have.
Or all three?

I think there is a security loophole. My wife (says she) always knows what I'm thinking so she'd be able to impersonate me.

Surreal


I just used an OpenID (from Vidoop.com) to log in to the (erstwhile Liberty Alliance driven) Project Concordia.

I think there needs to be a Concordia use case along the lines of


Protocol Confusion

Preconditions

1) User knows what OpenID and SAML are

Sequence

1) User visits site at which they expect SAML-based identity protocols.
2) User instead sees OpenID-based identity options.

Pause

3) Confused, user checks their address bar for location confirmation (and vows to stop spiking morning coffee with Kahlua.)
4) User proceeds warily, expecting SAML colleagues to jump out and yell 'April Fools'

Post conditions

The metasystem is a bit closer.

Tags: ,

Vidooping

I received an invite to the Vidoop Beta, so signed up for an account.

The sequence by which you pick your image grid is pretty slick. Below are the categories I chose (completely randomly I assure you)


Once categories are chosen, they help you practice

before eventually presenting you with a real grid to authenticate with



My tests indicate that the order of the characters for the code doesn't matter, e.g. 'AGB' is as good as 'GAB' in the above. Not sure why.

Monday, June 04, 2007

RFJ 2007

Some 25 members of our extended family participated in last weekend's 'Ottawa Race Weekend' - running/walking either the 5k or 10k.

We all wore t-shirts with a picture of my brother-in-law Jamie, who we lost to heart failure last year.



It felt like I was carrying Jamie within me. Maybe that's why my time was so poor - Jamie was a big man.

Saturday, June 02, 2007

Black Swan

I've just started reading 'The Black Swan - The Impact of the Highly Improbable' by Nassim Nicholas Taleb.

According to the prologue, a Black Swan phenomenon is characterized by the fact that it:
  • is an outlier, ie. it's not expected or predicted.
  • has an extreme impact (isn't defining one of the necessary criteria for some event to be considered 'impactful' as 'must have extreme impact' a bit circular?).
  • we attempt to explain its occurrence after the fact.
By the time I finish the book, I vow to have determined an identity Black Swan.

I can think of plenty of identity events that meet 1 or 2 of the above criteria (e.g. Microsoft saying they'd support OpenID wasn't expected, Conor singing Bohemian Rhapsody had an extreme impact (on my GI tract), everybody is trying to explain WS-Federation 'after the fact', etc) but, as yet, no events that meet all 3.

p.s. apparently, Black Swans make what you don't know far more relevant than that which you do. So, I got that going for me.

Friday, June 01, 2007

Lazarus-like

I received the following email this morning
Subject: [security-services-chair] Groups - Mr. Jeff Bohren removed from OASIS Security Services (SAML) TC

Date: 31 May 2007 19:14:53 -0000
From: workgroup_mailer@lists.oasis-open.org
To: security-services-chair@lists.oasis-open.org

Mr. Jeff Bohren from BMC Software has been removed from OASIS Security Services (SAML) TC (user left the group)

Given that I know of an upcoming piece of work that Jeff is spearheading for the SSTC, this came as a surprise. When I asked him for clarification, his response:

The rumors of my death have been greatly exaggerated. To switch from observer to member you have to remove yourself first and then to reapply as a member, which I have done. Since I am now the primary rep for BMC, I also approved my own application. SOD, what SOD?

Would this be an example of reprovisioning?

Separately, I applaud Jeff's usage of 'In Flanders Fields' as a tribute for the recent US Memorial Day. The poem (with associated poppies), is a key piece of our own Remembrance Day here in Canada. I venture that more Canadians can recite it in its entirety than our anthem.

Brute Force Attack

I'm determined to get me one of these (or at least temporarily borrow one) so as to avail myself of the advantages).

Given that I know a number of real Sun employees and, after years of meeting & social exposure, can claim some insight into their personalities, I think its worth my time to try to guess their passwords for logon (I already know their emails).

First attempts
  1. astitchintime
  2. skinnyasasnake
  3. laformulaune
  4. notapat
  5. whenisnexttegmeetinginparis
  6. sarcasmishighestformofwit
  7. isoldmysoultorockandroll
  8. whiskeyisgodselixir
  9. turnofftheairconditioning
  10. youcantpushstring
  11. baguettesandredwine
  12. iregretwssomex
  13. perfidiousalbion
Just a matter of time now.

Tags: ,