Thursday, March 26, 2009

Translation oddity

Sun's Kimimasa Sato posts on identity management challenges and progress.

Sato-san courteously provides links to 3 translation services for non-Nihongo speakers - Yahoo!. Google, and Microsoft.

I was comparing the three translations to see if any was appreciably better (my conclusion, no) when I noticed an oddity in Yahoo!'s text.

See if you can notice the difference in the three as to how they translate the final bits of the post. Look carefully, it is admittedly quite subtle.

Google




Microsoft



Yahoo!



I wonder if Yahoo!'s translation engine was written in Australia?

May look into this.

I've actually always thought of myself as ducal.

With a Title in front of your name you will experience a difference in people's attitudes. The moment they know you are a "Sir, Lady, Lord, etc", you will be treated like some sort of Royalty or famous Film star.

About bloody time I say.

I wonder if they'll throw in a corresponding Openid so I could enjoy the same privileged treatment online......

Wednesday, March 25, 2009

Get an OpenID, live forever

This article makes me think that OpenID should be playing UP the usability issues.
"transhumanism," is premised on the idea that people degenerate and die in part because they live in spaces that are too comfortable. The artists' solution: construct abodes that leave people disoriented, challenged and feeling anything but comfortable.

C'mon Asa, I need this

Update: Asa came through!




Currently narrowing down laser implant locales. The eyes are just so 90s Terminator.


Tuesday, March 24, 2009

God Bless Amerka

Dear Last.Fm

I applaud your decision to charge non-Americans for your service. For too long the people of the non-American parts of the world have been riding our coat tails and enjoying our cultural exports (e.g. Britney, that whimpy guy from American Idol, the non-racist Mel Gibson, etc) for free.

That has to change.

Keep America Free! (by charging the non-Americans)

Signed

                                 A Proud (North) American

                                 Paul Madsen
----------------------------------------
You can have my gun when you tear it from my cold dead hands.

Identifier confusion

Hey I drink beer!

and have an Internet connection too.

Will I get a badge?

And what is the policy on mistreating prisoners? No, not the official policy, the real one.

From Jeff.

ProtectServe

Eve introduces what she and some Sun colleagues (dare I describe it as a 'Sun-led initiative'?) are calling ProtectServe -  what appears to be a set of extensions to (and around) OAuth to allow users to define permissions centrally, and yet maintain their identity in a distributed manner.

In 'classic' OAuth, a user:

1) facilitates a Consumer and Service Provider establishing  keying material in the context of him/herself so that the Consumer can subsequently use those keys when requesting from the SP the user's attributes
2) can define permissions at the SP specific to the Consumer (i.e. read not write etc) - these access rules stored at the SP against the keys of 1)

From the 'access control management' PoV, the above model has the user making lots of access control management decisions - one each time a given Consumer wants identity from a given SP. What's more, subsequent management of all those decisions will be tough because the rules are spread out all over the place (at all the various SPs).

ProtectServe keeps the data distributed, but centralizes the access control management. Rather than directly collecting, storing, and managing a user's access control decisions for the attributes it stores, an SP will abdicate these duties to what Eve calls a 'Relationship Manager'. The Relationship Manager itself holds no identity attributes, only permission sets for identity attributes stored elsewhere (at the user's SPs).

User's create, manage (and hopefully can reuse) access rules at the Relationship Manager, rather than at the various and disparate SPs.

The implication is that, if and when an SP gets a request for a user's identity attributes from some Consumer, the SP, rather than looking at some locally stored access rule, instead queries the user's Relationship Manager for the decision (this query seemingly protected by Oauth as for any other identity query). Upon receipt of such a query, the Relationship Manager would

a) check to see if the SP (acting as an OAuth Consumer) was 'OK', i.e. that the User had introduced the two
b) check to see if the original request from the original Consumer to the SP should be approved based on the rules the User had defined
c) return the results of b) to the SP

Some thoughts

1) Because the Relationship Manager gets lots of queries of the sort

'Consumer1 is trying to access Alice's calendar at SP3'

the RM would be able to get quite the glimpse into Alice's online activities. Some creative crypto might help

2) Eve didn't describe the mechanism by which Alice, when visiting 3rd National Visa (an OAuth Consumer) would get over to CopMonkey (her RM) to specify permissions for Visa accessing her calendar at schedewl. Perhaps something like

i) Alice helps OAuth between Visa and Schedewl
ii) Schedewl responds back with a 'Talk to CopMonkey'
iii) Alice helps with Oauth between Visa and Copmonkey
iv) CopMonkey records the access rule for Visa accessing schedewl
v) later, when Visa asks schedwel for Alice's calendar, schedewl knows to ask CopMonkey before granting

3) Most powerful would be for the Relationship Manager to also track (or be able to access) the user's social relationships - thereby allowing Alice to define rules like

Visa can access my work calendar at schedewl if doing so on behalf of my Boss, but can also access my personal calendar if doing so on behalf of my sisters.

4) The Liberty Alliance has recently been collecting use cases around the idea of a  'Citizen Dashboard', the hypothetical place where a citizen could go and see (amongst other things) a record of all the queries for their identity made from one government department to another - and the results of those queries. Such an application would be a key piece of a Relationship Manager.

Liberty has also toyed for some time with the idea of defining protocols in support of such a centralized policy point - but never did anything with it. So, no duplication here! Huzzah.

A close race

According to WeFollow, President Obama has more followers than Britney Spears.




Barely.

An RSS feed of the delta would provide an indicator of society's ebb and flow between the trivial and the meaningful.

When she passes him, the end is surely nigh.

Brand awareness

Jeff questions Nico's assertion that it is a given that OpenID needs a visible brand.

Jeff would have the particular OP brand front and center on any UI, with OpenID itself de-emphasized. Nico would do the opposite, i.e. deemphasize the individual OP in favour of the protocol.

Some random thoughts

1) If you believe that there needs to be a brand above that of the particular OPs, is 'OpenID' the best choice for that brand? 'Interac' is a valuable brand, but it's not named after the protocols that enable it.

2) If the protocol brand is hilited when the protocol is OpenID, what of federated operations when the protocol is not OpenID, i.e. SAML? How confusing will it be for users to sometimes see a protocol brand, and sometimes not?

3) why spend time arguing when some usability tests would verify whether users find federated operations more or less intuitive with the various (OP first, OpenID first, hybrid, neither) branding options?

Monday, March 23, 2009

I love you, man!

Say it without the copious amounts of precursor booze with these macho "man cards".

I'd like one of these as a card graphic for my 'Ballcap wearing, spitting, and swearing' persona. Definitely not some mamby-pamby flower arrangement or beach scene.

For the record, my frequent references to Dale on this blog (which he never ever responds to!) merely reflect my great professional respect for him and should in no way be interpreted as some sort of 'bromance'.

Unless he wants them to.

Information is power

Through Facebook, I just learned that my talented pianist nephew was accepted into an excellent music program at a nearby college.

Without Facebook, I would have learned of this tidbit of family gossip only at the whim of my wife. Some months down the road we'd have a conversation along the lines of

Me: I wonder if nephew got accepted...
Wife: What! Of course he was accepted, you knew that!
Me: No I didn't.
Wife: Oh you definitely did. My sister told me back in March and I told you right away. Don't be stupid!
Me: Yes dear, I'm sure you are right.

As it is, I know the news and my wife, not having talked to her sister in the past 2 hours (a record), doesn't.

Going to be a good day.

Tuesday, March 17, 2009

Unprecedented defense

From Wired, the developer of a (way cool) Android app for initiating torrent downloads through a phone barcode scanner defends himself against possible (i.e. certain) illegal use

"I could feel bad about creating a tool that could be used for piracy," says the 23-year-old Holmes, a Bournemouth University software systems student. "However if I didn't create the tool, someone else would have."

If I didn't point out that this defense against immorality has been seen before, someone else would have.

Separately, the use case would benefit from an identity/security layer as provided by Multi-Device SSO.

Monday, March 16, 2009

Etiquette 2.0

I was happy to receive a LinkedIn invite to connect from Trent Adams.

Even happier because Trent spent the extra time to perform the following laborious process

1) use mouse to select default invite text
2) backspace
3) type new slightly more personal invite text



If you care enough to ask me to connect, you should care enough to personalize the invitation.

We need a Miss Manners 2.0.


My brothers and I

are not what you might call 'huggy'.

 


Even this outpouring of emotion will have him wondering if I've gone soft.

Saturday, March 14, 2009

By analogy

with

A language is a dialect with an army and navy

        often attributed to linguist Max Weinreich

I propose

An open standard is a community spec with a Google implementation and its own web domain

Friday, March 13, 2009

Kitchen sink optional

If ever there is an ID Award for most inclusive scenario, I nominate Asa, Iain, Markus and co for their PoC of a VPI scenario involving XRI, OpenID, Cards, and ID-WSF.

Asa, I do not mean to quibble but, cmon, where's the Passel?

Assurance Math

A thread on the OpenID list is exploring the capability of OpenID to meet the requirements of different  NIST LOAs, and thereby be relevant for SSO to US government services.

I submit the following 

where

Areq = the level of assurance requried by a given RP for a given resource
Aid = the level of assurance engendered by the OP/IDP's  identification & registration processes
Aauthn =  the level of assurance engendered by the OP/IDP's authentication mechanism
Aprotocol = the level of assurance engendered by the protocol by which the IDP delivers 'assertions' to the RP\

So, the smallest of the factors that determine assurance (i.e. Aid, Aauthn, and Aprotocol) must be greater than the level of assurance required by the RP (i.e. Areq). Nothing  more than the 'weakest link' principle as formula.

Notes:

1) For the sake of simplicity, Aid is a catch-all factor for any process the OP follows that is not authentication   
2) Any of  Aid, Aauthn, and Aprotocol serve to constrain the maximum assurance possible. Consequently, there is no benefit in any one factor being significantly greater than the others - it's just wasted cost. The corollary to this is that no one assurance factor is more critical than another.

Thursday, March 12, 2009

SAMLWow!

I fear that Eve`s blatant ShamWow bait-and -switch will have organizers (i.e. Britta) dealing with many disappointed guests expecting a miracle of absorbency.

Nevertheless, come to my presentation at RSA Conference`s Harnessing the Power of Digital Identity: 2009 and the Promising Road Ahead on `Bridging Assurance between OpenID & SAML` and you`ll be saying WOW everytime!

Disclaimer: SAML does not easily removes cola, wine and pet stains, nor is OpenID machine washable and bleachable.

Tsk Tsk

Searching for an 'identity podcast', I came across Mike's post regarding an interview he and Kim did for MySuccessGateway.

In trying to access the podcast, Firefox warned me with





Gentlemen, you didn't need to resort to this. If you had just asked I would have been happy to install the new Cardspace.

When worlds collide

The fact that my Facebook friends list is an aggregation of both work and non-work hit home yesterday.

On what started as an innocuous thread on the relative merits of curling and football, comments were made by a non-work friend that, while completely appropriate to the relationship between myself and the commenter (we having a long history of questioning each other's masculinity and mental health), were not appropriate for a work context (or 98% of any other contexts it must be said).

Facebook allows me to create lists but not, AFAICT, use those lists to compartmentalize through differentiated permissions, e.g. allow members of one list to participate in a thread and not another.

If I had that ability, there wouldn't have been a problem. Nothing fancy, just something like

- those friends who find playground potty humour hilarious
- those who pay income tax

Fortunately, Facebook provides a delete function.

Cloud 'Eh Weather

Jackson questions the viability of cloud jingoism - specifically of the Canadian type
Frankly, I'm not quite sure how you prove the nationality of the cloud. If I look at a server can I see what cloud is sitting on or in it? When I look at a cloud can I see what nationality that cloud is? How do your prove the cloud is a certain nationality?

I propose a simple test - ask the cloud the following questions

- what is a timbit?
- Paul Henderson, good or bad?
- standup or butterfly?
- would you like to apologize for something?

A Canadian cloud's answers will be unequivocal.

Wednesday, March 11, 2009

Twitter & SAML in a single sentence

Really

Socialcast also integrates with the actual Twitter, Del.icio.us, and other social networks like YouTube, Digg, Facebook, and Google (NSDQ: GOOG) Reader.

According to Young, Socialcast will integrate with 45 public services in all as well as certain wiki's that companies might be running on their own. For single sign-on, Socialcast integrates with directory services likeMicrosoft (NSDQ: MSFT)'s Active Directory via the Security Assertion Markup Language, aka SAML.

OK, well two sentences.

New SOAP Fault

<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
 <env:Body>
  <env:Fault>
   <env:Code>
     <env:Value>env:Sender</env:Value>
     <env:Subcode>
      <env:Value>m:WTF</env:Value>
     </env:Subcode>
   </env:Code>
  </env:Fault>
 </env:Body>
</env:Envelope>

It's the redirects

that make travel so tiring

The times, changing they are

One of my best friends from high school and university informed me last week that he and his wife of 17 years were 'deprovisioning' (he didn't call it that) their marriage.

He used Facebook to inform his wedding party of the news.

I grant you that it's more personal than the alternative.

Tuesday, March 10, 2009

That'll teach me

Trying to register for RSA 2009 in order to attend the Concordia, DataPortability, ICF, and OpenID pre-conference workshop.

Used the password reminder mechanism. Saw this screen.




1 hour? They expect me to sit patiently for an hour before registering? Is somebody hand typing the emails?

Ended up creating a new account, with username 'paulmadsenyetagain'. Saw this screen



Then, when registering and providing more info, saw this



Ah yes, of course they need to know whether I'm a 'Ms', 'Mrs' or 'Miss'.

Must remember, it's a security conference, not a usability conference.

Just out of spite, I made up spurious answers for their mandatory survey questions.

Time to short 3M

How much money do you think 3M makes from its Post-it Notes division?

And how much of that comes from the notes used for writing down passwords and stuck to the monitor?

And how much of that business will disappear as users buy into federated authentication?

Clear sell.

If 3M were as visionary as me, they'd adapt their digital notes product to be a visual front-end to an identity selector. Users already think of the notes as a paradigm for differentiating their online identities.

p.s. I also expect monitor frames to get smaller as the need for note mounting surface area decreases. Start to offload your plastic holdings.

Monday, March 09, 2009

Placeholder quotation

A placeholder, in anticipation of hopefully using it at some point in the future to mock some markup protocol/syntax.

Basque is really a strange language . . .
It is said that they understand one another,
but I don't believe any of it.
Joseph Justus Scaliger (1540-1609)

Too good to risk forgetting.

And yes of course I considered the semantic web. It just seemed too easy.

Sovereignty

EdgeKeep  introduces a new term (AFAIK) for what feels very VRMish.

Our tagline, Securing the Edge™, reflects our corporate mission: to maximize user sovereignty and minimize business risk at the edge of network space where users and businesses meet.

Maximizing user sovereignty drives our focus on privacy. Minimizing business risk drives our comprehensive, innovative approaches to policy and procedure development and to security inspections and audits.

The distinction between de jure and de facto sovereignty is noteworthy, i.e. between the user having theoretical or real control.

Friday, March 06, 2009

My hitch-hiking days are over thank

PickupPal is a ride-sharing service, i.e. matching drivers and passengers.

The economic model sounds wonderfully flexible
Passenger pays the Driver the agreed amount in cash (or otherwise, if agreed upon) at the end of the ride.
'Otherwise' would seem to encompass a whole range of payment options.

Separately, the 'Help' pages add a new dimension to trust mechanisms

Send them a message via our messaging system and get a sense of who they are – a simple message will give you a good idea if they are someone you can start to trust.
Sit in the front passenger seat, if you can. Rear doors often have child locks on them, meaning they cannot be opened from the inside. If you must sit in the back, check the child lock is off before you close the door.
Note the vehicle licence plate, and its make, model, and color before you take ride. If you have a cellphone, text this information to a friend and have them confirm they got your text. For example (AYDL 098, VW GOLF, Black) - do not be shy to tell the driver you are texting this information -
Have these people heard of a little thing called 'public transportation'? In which passengers need not worry about child-locks?

All the reputation systems in the world aren't getting me in a car if I need to text a license plate to feel safe.

Tuesday, March 03, 2009

IP (irritating poetry)

There once was a standards body from Tobermory
Whose IP policy was nothing if not discriminatory
Reasonable? licensees would ask "A definition please"
The licensors response? "Don't worry, we'll talk later about the fees"
And as to fairness, well that's an entirely different story. 

Wednesday, February 25, 2009

Hybrid messaging protocol

My wife and her sisters have come up with their own hybrid protocol - it goes something like this

S1->S2 (email): Hi, here is a funny joke (joke will involve any or all of set of perceived husbandly foibles & limitations).
S1->S2:(phone): Hi, just sent you an email. Also, did you hear that Mom ....... (subsequent conversation typically lsts 45 minutes)
S2: checks email, reads joke
S2->S1 (phone): Yes, that joke was so true. Men are so like that. Ha ha. Also, did you hear that Mom ....(subsequent conversation typically lasts 45 minutes)
S2->S3 (phone): Hi, did you check your email? S1 sent a funny joke. Also, did you hear that Mom ...... (subsequent conversation typically lsts 45 minutes)

Don't you just hate

those XACML folks and their sense of entitlements?

Tuesday, February 24, 2009

Can't hurt to ask right?

Welcome Lucy & Trent

Trent notes that the Internet Society has joined the Liberty Alliance as a Management Board member.

Trust me, you made the right decision. Being on the Management Board is sweet. Free coffee at meetings, nice pens & pencils - it's all good.

Deprovisioning



Or at least I hope so.

Monday, February 23, 2009

Overheard on the Santa Maria

No no Captain, please don't misunderstand - it's not me that has doubts. It's the men that are all saying that their Garmins and Tom Toms are saying we should be going South and not due East to get to the Indies, and that the projected travel time is 11 months and not the 6 weeks you've been saying.

Overheard on a desert isle

Well yes Friday, of course I could use the cell phone. But I just refuse on principle to pay those exorbitant roaming charges. And I'm sure that a rescue boat will sail by any day now....

Thursday, February 19, 2009

Mosaic

Black-listing (yourself)

Integrity offers what they call a Self-Exclusion List designed to protect problem gamblers from themselves.

The individual (or a legal guardian) adds themselves to the list so that, if they ever attempt to create an account at a gambling site that uses Integrity for age-verification, the account creation will be denied (or at least Integrity will not give the OK, the site can still ignore the advice).
Should an individual whose name is on the list attempt to open an account with a participating gaming site, Integrity would not return a match (approval) code to the merchant, thus blocking the user’s access to the site. 

Unlike a common dynamic from TV & movie, once a gambler has added themself to the SEL, they can just as easily perform deprovisioning (albeit with a 7 day delay).

The identity world spends most of its time worrying about use cases in which attribute flow enables some experience for users, not actively disables.

I'll give you 5 to 1 odds that the Integrity age verification protocol is proprietary. Unnecessarily so.

Wednesday, February 18, 2009

Secure Pizza

Domino's Pizza uses Voltage IBE encryption for secure conversations with its customers.

<order>Yeah, I'd like a large combination with extra
<EncryptedData xmlns="http://www.w3.org/2001/04/xmlenc#" Type="http://www.w3.org/2001/04/xmlenc#Element">
<EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
</KeyInfo>
<CipherData>
<CipherValue>WXlDyktaADlUe+PywKwS3KdKlahCteEKxi/hRlHcXNQlGwNGrYKy8aQ6dLtX1bKg
IgL/XoAQN3B27zD91b1ZLGh6QQ9CjnVD98+hYJ9TPp4piPnII4vGUA==</CipherValue>
</CipherData>
</EncryptedData> and a side order of wings.</order>

Mission critical security.

Tuesday, February 17, 2009

Missed standardization opportunity

I was watching a nature documentary last night. It seems that several species of monkey (e.g. Diana monkeys, Spot Nose Guenons, Campbell's monkeys, and others) in the Tai forest of West Africa  move together through the canopy in what is called a 'monkey alliance'.

Like many monkeys, each species within the Alliance has its own set of predator-specific alarm calls, i.e. 'Holy sh%t, big eagle coming in', etc. The interesting twist of these Alliances is that the different alarms calls are understood by the other species too. So, if a Diana spots a leopard and sounds the alarm, not only the other Dianas go on alert but also monkeys from the other species.

Pretty inefficient. I'm a young Guenon and I'm expected to not only learn my own species' calls but those of every other species I hang around with? And what happens when a new Alliance member joins up? Adult education classes?

Barring some sort of cross-species standard for alarm calls (you'd never get each species to give up their own calls, you know how primates are), you would have thought the different monkeys could have at least got together in a non-partisan location and thrashed out some  basic guidelines for reconciling the various call systems. Maybe something as simple as high-pitched calls for threats from above, low pitched calls for threats from the ground.

Monkey alliances are viable because each species within generally obtains food in different ways (e.g. at different levels within the forest canopy, flowers versus fruit, etc) so they don't directly compete with each other. Hmmm.

Monday, February 16, 2009

Update: When is a log-in not a log-in?

Update: Bob was gracious enough to send me a copy of the paper. I guess he already has an account with Burton.

When you are trying to 'Access Complimentary Content' from Burton, such as Bob Blakley's relationship whitepaper.



I'll leave it to somebody else (who may not have the same great amount of respect for Bob that I have) to point out the irony of Burton trying to establish a 'relationship' with me based on justification as tenuous as downloading a whitepaper.

Can somebody send me a copy of the paper?

Wednesday, February 11, 2009

Connectid now available through the Cloud

Hey, I can spot a trend when I see one.

95% success rate!

Plaxo is bragging about a 92% success rate for users of the OpenID/OAuth Hybrid extension.

Let me see if I have this right.

When you offer users a single combined OP & attribute provider (thereby removing from the equation the difficult part of having the user enable discovery of arbitrary providers), things are suddenly easy?


Monday, February 09, 2009

Geographically qualified claims

KFC has a new ad in which they must say 'fresh' 5 times.

If you look closely at the fine print, the freshness of the chicken is somewhat qualified.





Fresh claim is applicable to its Original Recipe thighs, drumsticks, breasts and wings. Not applicable in Alaska, Hawaii and due to supply outages

In SAML, this sort of thing in an assertion would go in the <Conditions> element. Probably in a child <CoverOurCorporateAsses> element.

De facto standards

From BoingBoing, comic book standards.

All identity assertions should end with an exclamation mark - why trust a claim if the IdP isn't confident enough to emphasize?

Friday, February 06, 2009

Fire and forget

I set an Thunderbird filter rule years ago.
if message contains 'Moliere', move to trash

After lying dormant for all those countless emails since then, it triggered today.

Initial set-up effort vindicated!

Tuesday, February 03, 2009

Embargo

In response to the blatantly protectionist "Buy American" clause in the US stimulus package, I encourage all Canadians to boycott American IdP/OPs in favour of local alternatives.

They can have their steel, there is more margin in identity infrastructure.

Saturday, January 31, 2009

Wasteful

For myself, anything more than 3 million square feet is just plain wasteful.

Shame on you Australia. Shame on you.

Wednesday, January 28, 2009

I'd be alot more excited

about this news if it were somehow tied in with an email offer I received today from the SP in question

 


Is it too much to ask that Paypal's different divisions all sit down together in the cafeteria and work out a single cohesive 'go to market' story?

Tuesday, January 27, 2009

You are either in, or you're out

LinkedIn has a new (beta) feature that allows you to categorize your connections.

I edited the default set, deleting generic tags like 'friend', 'colleague' etc and adding tags that seemed more tuned to my situation.




The sorting is turning out to be quite enjoyable.

This is so fake

Really it is.

At first I thought that a service that creates fake bank statements and utility bills was a wee bit shady, but it turns out it's all just good fun.

You agree that all novelty documents this website, or any of its employees or owners produce are for novelty and fun purposes only. You agree in ordering any novelty documents from us, that without exception they are not to be used for financial gain, fraud, deception or any other criminal actvivity. You understand and agree that ReplicaDoc does not take, or will not accept any liability for your actions and/or decisions.

A sister site.

Monday, January 26, 2009

Moving On

After spending longer in one place than at any previous time in my working history,  I've come to the conclusion that it is time for a change of pace and scenery.

A tough decision for sure but, after talking it over with my family and advisors, I've realized that sometimes you just have to shake things up.

Yup, I'm going to take a break from the home office and go work at the kitchen table for a bit.

Who knows, maybe the sofa after that.  In tough times like these you have to be flexible.

Sunday, January 18, 2009

How timely

Watching the NFC championships. Eagles wide receiver Avant was called for offside.

Avant.

Thursday, January 15, 2009

He started it

Place blame where blame is due.
Cardspace, SAML, and OpenID go into a bar.

The bartender says to Cardspace 'I'm gonna have to see some ID before I serve you'. Cardspace shows its ID and then orders a beer.

Bartender says the same thing to SAML, which also orders a beer.

When the bartender sees OpenID, he says 'Im sorry but you are going to have to leave'.

'But why' says OpenID 'Im of legal drinking age and I have ID to prove it.'

'Im sure you do' says the bartender, 'but I don't know how to ask you for it'.

Monday, January 12, 2009

A crisis of faith

It tears at my very soul to even contemplate this.


Must look into renting some buses.

Justified Party?

Vittorio points out a new  Microsoft 2D bar code technology

A line from the FAQ is interestingly vague

 

Requires an internet connection? Data charges? Is it conceivable that a Microsoft server somewhere plays a role in interpreting the codes?

Suspicion confirmed by another review
Unlike other tag technologies too, the Microsoft Tags don’t actually store the information. You see, all it stores is a unique ID which it then sends to Microsoft’s servers. This way, you can include much more information, and more variety of information, then if it was just on the tag itself. A nice side-effect of this is also the ability for publishers to gather reporting data on how many times it was seen.
So Microsoft sits in the middle between 'those that create tags' and 'those that read tags' with privileged access to which tags that users access (it's not clear whether they authenticate the users' access), and so consequently indirect insight into the user's visits (isn't there a name for this?) to non-Microsoft sites.

To be fair, the FAQ does have a token privacy section

Token. The fact that the tag is actually resolved off the phone is left to the user to determine. 

I wonder if the tag interpretation API uses WS-Trust.

Sunday, January 11, 2009

Celebrate good times

Watching the touchdown dances of wide-receivers in the NFL playoffs makes me think there should be something similar for successful federated online transactions.

The chances of success are roughly similar - shouldn't we encourage users to enthusiastically celebrate those rare events should they happen?

I propose the federated identity industry hire a choreographer to design us some shakin' moves for the various operations, e.g.  federation, SSO, and attribute sharing etc.

Something really hot for successfully using an i-name (something that rare deserves special recognition).

Of course, there would have to be penalties for excess, we don't want things to get out of hand.

Monday, January 05, 2009

Off-topic

In anticipation of Canada beating Sweden in tonite's gold medal game for the World Junior Hockey Championships, could any Swedish readers leave me contact details so as to allow me to rub it in tomorrow AM in a more personalized manner?

For American readers, no need to do anything (likely ever).

Thanks

More hockey trivia

Another interac email transfer for morning hockey


My son or his?

Could we not standardize these sorts of questions? 

Social Organisms

Why should the power of Web 2.0 applications be reserved for the higher life forms and not be available to all?

Been there done that

The relationship between Charles Darwin and Alfred Russel Wallace is typically presented as having begun with the 1858 letter from Wallace to Darwin that briefly outlined a theory of natural selection very similar to that which Darwin had been working on for many years. So the story goes, it was Wallace's letter arriving "out of the blue" that prompted Darwin to get off his highly-evolved rear and publish his own work.

In fact, the two were already corresponding on the topic. At one point during this exchange Darwin appeared to try to gently warn Wallace off the subject of natural selection by claiming prior art
This summer will make the 20th year (!) since I opened my first-note-book, on the question how & in what way do species & varieties differ from each other.— I am now preparing my work for publication, but I find the subject so very large, that though I have written many chapters, I do not suppose I shall go to press for two years.

Wallace missed (or ignored) the warning.

Reminds me of the OpenID and SAML relationship, i.e. upstart ignores work of established authority, but nevertheless adds valuable variations.

Sunday, January 04, 2009

Perfect Password (only 14 years out of date)

This book will teach you how to cope with the world of password policies, password crackers, and human predictability. It teaches specific password patterns that will meet even the most unyielding security policy requirements but that users will remember in a snap. If you deal with passwords, you need this book.


From BoingBoing.

Friday, January 02, 2009

A reasonable guess

A friend sent me an email money transfer to pay for his share of our morning hockey.

For security, I had to respond to his challenge question


Hmmm. Canada.... Winter time....

Let me think.. Jai alai?

Plumbing the Depths of Identity

Jeff's screwy post reminded me of a recent home renovation.

Finishing off a basement bathroom, I had to connect the shower/tub drain to the roughed in pipe (dirty work, but I got to use a jack hammer so that was cool).

Standing in home depot in front of the PVC pipe fittings, I struggled to visualize how to use the variety of adapters, 90 corners, and angle pieces to make the connection.

Ending up buying a few of every fitting ever made to ensure I had the flexibility I needed when I got back home.

Of course, there are some pieces left over.


Just make sure you keep the receipts for you identity plumbing purchases.

Thursday, January 01, 2009

Trusted Traveller

I received a new Nexus card by registered mail yesterday.

It came with a little envelope in which I'm supposed to store the card when not in use. The envelope's interior has been metalicized.

Keep the card in its protective sleeve at all times unless you are presenting it at the border. This will help prevent the RFID chip from being read by an unauthorized reader.



Using duct tape and aluminum foil, I have created a prototype of a similar safeguard for my other identities. Seems effective, albeit hard to see out of.

Saturday, December 27, 2008

Panspermia

Panspermia is to the origin of life as Web SSO is to authentication - it doesn't address the issue but rather just outsources it.

Super Hero

Visiting in-laws for Xmas, I asked my brother-in-law what his wireless network password was. His best guess turned out to be inaccurate. But clearly it was a guess that resonated for him.

So I snuck in through the router's admin page and reset the password to what he had guessed. And then went around to all his laptops and desktops to change them accordingly.

Password Man to the rescue.

Sunday, December 21, 2008

Thursday, December 18, 2008

I have seen the future of home media entertainment

and it looks like an Archos 5.

Wifi, web, email, video, music, flash, web TV, DVR, HD, pics ....

More to follow (with an almost certainly tenuous connection to identity).

Better left unsaid

Eve put me on to this cool UML app.

Started me thinking about how identity protocol swim-lane diagrams often have the various endpoints mulling over policy and authz decisions to themselves, completely separate from what goes out on the wire.

Something like this.

Wednesday, December 17, 2008

Better get a bucket

I'm gonna throw up ( before you follow the link,  play the embedded video - it will put you in the right frame mind of mind)

Low-tech but effective

Chris Messina's email signature uses a simple mechanism for expressing rights
Chris Messina
Citizen-Participant & Open Technology Advocate-at-Large
factoryjoe.com # diso-project.org
citizenagency.com # vidoop.com
This email is:   [ ] bloggable    [X] ask first   [ ] private
Of course,  when the thing you want to blog about is the signature itself and not the content of the email, it's unclear how to proceed.....

As I understand the mechanism, Chris uses a Thunderbird AI extension that analyzes the content of outgoing emails for key words and phrases before automatically setting the appropriate privacy switches.

Or maybe something simpler
Yep, I set those manually. Nothing like ASCII for utter UI simplicity and data portability!

Wouldn't it be nice if there were other (enforceable) switches...

This email is: [ ] non-forwardable
                        [ ] non-repliable
                        [ ] non-startsomeinterminablethreadabout"whatisidentity"able

Monday, December 15, 2008

5 is enough

Usability guru Jakob Nielson argues that you don't need large numbers of testers to gather useful data about an interface. 5 users is sufficient - providing the right trade-off between spotting issues and economy & efficiency.

As you add more and more users, you learn less and less because you will keep seeing the same things again and again. There is no real need to keep observing the same thing multiple times,

Jeez, a whole 5 users?

I guess we'll have to wait a bit before conducting Infocard usability tests.

Thursday, December 11, 2008

Like I need to be told

Some Identity bloggers are abuzz about Typealyzer.

Until such time as different sectors of the brain are associated with scorn, sarcasm, and derision I will not partake in such personality analysis - it would only demonstrate science's current limitations.

Temporal phishing

If the phisher has an idea of the timing of legitimate mailings that the user expects to receive, it will be that much easier to fool them.

Case in point, I recently achieved Elite status for my frequent flyer program (said status resulting in my pretzel packages being pre-opened as well as being allowed to use public washrooms in the airport).

Air Canada sent me the below asking me to login in order to customize which perks I want.


As far as I know, Air Canada does this for all Elite users at this same time each year.

Even if hadn't reached Elite status and got this mail, I'd be inclined to log-in to see if I could take advantage of their mistake.

Franchise Opportunity

The OpenID Board vote.

Tuesday, December 09, 2008

Facebook Connect is the new panopticon

Some interesting reading in the Facebook Connect Terms of Use.

In order to make Connect possible, you agree to allow Facebook to check your Facebook cookies when you are visiting participating third party websites, and allow Facebook to receive information concerning the actions you take on those third party websites. In addition, once you allow a participating third party website to connect with Facebook, you agree to allow Facebook and such third party website to generate and publish news feed and other stories about actions you take on the website without any additional permission. In the event you no longer want the third party website to publish stories about you, you can always disable this feature by changing your application settings.

I used to think that SAML & Liberty could enable a pretty-good panopticon model (or at least that's what I was told) but we have nothing on this.

SLO

Facebook Connect has single log-out.

Comparing functionality would suggest that it's SAML that should feel threatened.

Giggle.

Monday, December 08, 2008

Perhaps a bailout criteria?

Chris Saad has a proposal to make OpenID competitive with Facebook Connect.

As a bonus, Chris suggests


If you provide OpenID but do not consume it you need to be named and shamed. There should be a 2 month grace period, then The OpenID Foundation, the DataPortability Project and everyone else who is interested should participate.

Absolutely. And the the Big Three car manufacturers should be forced to buy cars as well as sell them.

And why cannot I sell my own homemade burgers to fast-food chains?

Oh right, business models.

The more things stay the same

the more they change ... or something.

It seems FaceBook Connect is the new Passport.

So would that make the 'O' (i.e. OpenID, OAuth, Open Social, etc) stack the new Liberty Alliance, i.e. advocating decentralized standards-based identity in opposition to a centralized & proprietary model?

This 'convergence' is for me an early Xmas gift of hilarious incongruity wrapped up in sweet sweet irony.

Friday, December 05, 2008

Well I do declare

Phil Hunt will be giving a webinar on the ArisID API.

ArisID de-couples developers from having to make protocol, schema, and architecture decisions that would limit the usability and deployability of their application in an evolving and ever complex enterprise network, where a large number of identity sources and protocols are used. By relying on intelligent ArisID libraries, developers can now ensure maximum flexibility and use of their applications while significantly reducing development time.

Fundamentally, rather than an application developer coding 'Use protocol X to obtain identity attribute Y', ArisID would have them express 'My application needs identity attribute Y' using an XML syntax

The CARML specification is an XML document that developers use to describe the identity data and transactions used by a service or application. The data types may include identity attributes, predicates (e.g. “Is an Adult”), and roles (e.g. “Manager,” “Business Class Flier”) that an application requires.  

The burden of determining the how (ie LDAP, SAML, OAuth etc) and from where  (i.e. dealing with discovery) to obtain the attribute is taken off the application, and assumed by the identity infrastructure.

I have been experimenting with profiling CARML in a slightly different manner - each morning, I create a CARML file with my food and drink expectations for that day (i.e. cold beer @ 5pm) and then upload it to my blog so that the home infrastructure can retrieve and process.

As in any intra-enterprise project there are political battles to be fought - the food and drink adminstrators have as yet refused to acknowledge the value of the new paradigm and cling stubbornly to clearly obselete modalities.

Thursday, December 04, 2008

Precedent

I'm reading a biography of Charles II, who seemed to prorogue parliament with a frequency exceeded only by that of the turnover amongst his mistresses.

There is a clear historical precedence for this move.

Now it's personal

Finding $25 tucked down amongst the couch cushions, I just joined the OpenID Foundation.

The criteria for my vote for the upcoming board election is simple - I will NOT vote for any candidate that uses either 'philosophy' or 'spirit' in their platform. Separately, an open bar at IIW would be nice.

Whatever the result, let's just hope that everybody has confidence in those elected.

Turnabout

is fair play. As I often speak condescendingly to my children, hockey referees, and shop keepers, I can't rightfully complain when Ben directs it at me, in his rebuttal of my (and a plethora of others) criticism of his 'phishability' post.

Ben's argument hinges on a definition (my interpretation, he never comes right out with it) of 'unphishable' as
unphishable: a security characteristic enabled by an authentication protocol in which the password is never sent to the authentication server but presented by the user only to a secure device - the device then authenticating to the server on their behalf.

With this definition, I don't disagree (and you wont't hear me diminishing the critical importance of small mobile communication devices to security). If passwords aren't delivered over the wire (and all the other necessary 'utopian' conditions that Ben after the fact stipulates are met) then users could use the same password everywhere.

But of course, this is Ben's definition for unphishable and so perhaps we shouldn't be surprised that it works out nicely for him.

Another definition (one that it appears all of those who had an issue with the original post prefer) looks something like this

unphishable : impossible to phish, see phish.
.
.
phish: a fraudulent attempt to acquire sensitive information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication

A phish depends on the fact that the user bears the burden of spotting the fraudulent site (notwithstanding visual cues designed to assist them). Any (mutual) authentication protocol that removes that burden from the user could warrant the unphishable descriptor (with similar utopian caveats as Ben stipulates).

This more inclusive definition does not guarantee (for some mechanisms, this would be the case) that there will be nothing on the authentication server that could be used by a insider to impersonate the user elsewhere. And so, this type of unphishable does not inevitably mean that it is appropriate to use the same credential everywhere.

Wednesday, December 03, 2008

For an OpenID from here I'd wait

Total Prestige is a social network for the super-rich.

It seems they white-list.


Well that's just friggin' great! So when Paris wants to show me her holiday pics she'll have to email them to me.

Personal Best

Bedposted
is a personal web application that will give you some insight into your sex life.

For me personally,  November was a good month.



Oh wait, I just noticed the 'partners' tab - that puts a different spin on my numbers


Tuesday, December 02, 2008

I don't follow

On the scaling of passwords, Ben Laurie writes
If your password is unphishable, then it is obviously the case that it can be the same everywhere. Or it wouldn’t be unphishable.

I don't follow.

Because I can't be fooled into divulging some credential where I shouldn't means that it is appropriate that I use it everywhere? Are there not other attack vectors that would drool at the thought?

Conversely, that the fact that I can use the same credential everywhere is somehow a necessary aspect of 'unphishability'? 

Client-based authz?

Flying to Toronto this morning for an ISWG meeting, I used 'mobile check-in', in which a link to a QR code was emailed to my phone.

Of course, at Ottawa airport there is no infrastructure to read the code (and I so desparately wanted to swipe it somewhere) - I ended up instead showing the email to security and at the gate.

When I later tried to access the link from my laptop, I saw the following



Who made Air Canada the authority in charge of defining what is mobile and what is not?

My laptop is pretty mobile, but if I had tried to use it to show the QR code I would have been stuck.