Tuesday, June 30, 2009

Phishing for numbers

Please sign-in by entering the grid numbers corresponding to your previously selected pattern (and indicate which site you believe you are signing in to. Not that we don't ourselves know, we're just testing you)

Contextual reputation metrics

I received an invite to connect from a friend - this time from TripIt - the online travel organizer (which I love).

Presumably to encourage me to accept, the invite includes the phrase
X has traveled 31,102 km to 9 locations

Well that's good, cuz there is absolutely no way I would friend-up with anybody below the 30k threshold.

Vertical networks like TripIt of course have an advantage over horizontal networks in being able to offer such metrics  - all they have to offer is # connections.
 

Monday, June 29, 2009

I swear this was not a set-up

Eve's insight notwithstanding, I've seen no better application of Venn than this from my 7 yr-old daughter



Just think what she could have accomplished with some saran wrap....

Friday, June 12, 2009

Open letter to my (lazy ass) neighbours

Dear neighbour, 


Hey no, let me pick that litter up for you. Yes I know it fell out from the garbage cans you placed at the bottom of your driveway 2 days ago and is technically still on your driveway but, still, let me get it. I know you are far too busy being important for such matters - I'm more than happy to help.

Pardon me, what's that? Toilet paper? Sure, here it is. Can I help you with that too?

Sincerely yours

Paul

p.s. I have my dog pee on your lawn.

Sensing a meme

Just in the last few days, I've noticed two different ad campaigns (one for a coffee, another for a travel broker) that go something like this

'In these tough times, we decided not to spend money on a glitzy and expensive ad. Instead we made this cheap ad and used the money to do X '
where X is something altruistic or green.

It would seem that marketing research shows that the recently laid off find ostentatious and frivolous commercials offensive - go figure.

I can see an IdP trying it

'In these tough times, we decided not to spend money on an expensive identity proofing process.....'

Wednesday, June 10, 2009

Drinks, keys, and computers

It seems a safe time for me to report that my MyVidoop image grid categories were drinks, keys/locks, and computers. K, B, and E in the below.

You might have even already guessed that (I'd guess I wasn't unique in the industry to make those choices)



 
 

Hmm, online access .... Now there's a thought

Hartford Canada does not give individual investors online access to their accounts.

I played the 'user-centric card' in my complaint
Can you please explain why I am not given online access to my account? Is it that Hartford believes I am insufficiently intelligent or financially educated to understand the numbers? Must my advisor interpret them for me?

Their response

Thank you for your inquiry regarding online access for investors.

We are in the process of building our online presence and are investigating
how we can enhance our site to make it more useful to investors. Online
account access is one of several enhancements we are investigating
Well yes, allowing access is definitely one option for making the site more useful. Perhaps deprecate the flashing text and animated gifs as well?

I hope the fund managers show more insight and vision that does the Hartford CIO.

My technical analysis is showing a strong sell signal.

Wednesday, May 27, 2009

A Mathematical Model for Risk Scaling

We posit that the risk (R) for identity leakage from some authority is proportional to both the volume (V) of identity data held and the surface area (A) by which identity can leak.
Therefore, we can deduce

Figure 1: Risk as function of size

where r is a measure of size as determined by number of users.

Conclusions

We can therefore see that risk scales with the fifth power of size. As an example, an OP with twice as many users as another is 32 times more vulnerable to identity leakage.

Acknowledgements

This research was made possible by generous financial assistance from TAPPOP (The Association of Pure Play OpenID Providers).

Monday, May 25, 2009

Burnt Sienna?

That is Orange with a red tint isnt it?

I don't know whether the vulnerability is real or not, but if so, the ramifications don't stop there.

I expect there might be some French RPs temporarily taking down those cute square Orange buttons from their sign-in pages.

Tracking Chip Provenance

No, not from Intel, the other kind of chips. It seems that consumers feel less guilt in gobbling down a bag of crisps once they determine that the potatoes were 'local grown'.

'Locally grown' reminds me another trendy term for which there is no agreed upon definition.

Deployment stats

Some surprises here

Thursday, May 21, 2009

Playing with Flock browser

Liking the Facebook & Twitter integration.

Under the guise of a 'Normal' & 'Advanced' setup choice, the installer tries to sneak in

  • making Flock default browser
  • sending anonymous usage stats

Are these choices really only relevant to 'advanced' users? I can see proxy configuration ....
Blogged with the Flock Browser

Tuesday, May 19, 2009

Assurance-based RP decision tree

Click on image for zoom

I believe the term is 'wacked'

I was sent a Facebook friend request intended for a relative with a similar name.

Check out what I was forced to concede just so I could send a message explaining to the sender why I was declining the invite



A 4-corner model for risk

Monday, May 18, 2009

Violent agreement

I'm sure the sounds of confirmation from this panel must have been deafening.




Photo from Trent.

Sunday, May 17, 2009

IIW Submission

While I may not be attending in person, I do feel that there are still significant contributions I can make towards identity progress - specifically the following idea for a skit for the IIW Untalent show.

The following idea for a skit for the IIW UnTalent show is licensed under Creative Commons as 'Ignore & Forget'.

Here follows my idea for a skit for the IIW Untalent Show.

My idea for a skit for the IIW UnTalent Show is a take-off on the Dating Game. On stage will be an RP/SP (I see somebody from eGov or Health in the role, ideally in a dress for comic effect) asking all sort of hilarious and probing questions of the 3 candidate issuing parties (an IdP, OP, & STS) also on stage.

Questions such as

1) #1, there is nothing I find more romantic than a moonlight stroll down an audit trail. What parts of assurance do you find romantic?
2) #3, have you ever been proprietary? Are you still taking medication for it?
3) #2, My girlfriends say I'm a risk taker when it comes to choosing partners. How would you describe your own attitude towards risk, using, oh lets say, a scale from 1 to 4?
3) #3, Pop-up or redirect - I go both ways, what about you?
4) All, if you want to 'do business' with me, its WS-Federation or nothing. Ha ha just joking, just wanted to see if you were listening.

And of course the answers to the questions will be filled with all sorts of identity innuendo and protocol double-meanings. I'm laughing already. A guaranteed riot.

Thursday, May 14, 2009

A pain in the neck

Johannes has a pain in the neck.

As someone who has had a headache (the same one, to varying intensity) for approximately 12 years now, I am totally with Johannes on the importance of posture, neck, back & abs strength to fighting back.

My headache began one week after I started a job which had me at a desk the whole day. I will not bore you with the countless fixes I tried over the years (suffice to say Neti pot). It's only the fact that I now work from home, with the flexibility for work location, integrated stretching/exercise, G&Ts etc that has given me control.

I do all the same neck stretches that Johannes describes. Ultimately though, for myself, the only thing that can effectively kill a headache in its tracks are pressure point massagers that I found in the Tokyu Hands department store in Tokyo (the Japanese take stress reduction very seriously). If you have neck pain and find yourself anywhere west of San Francisco, make a trip to Tokyu Hands.

Early friend request

A letter from Prince Henry (future Henry VIII) to King Philip of Castile


n,To PHILIP, KING OF CASTILE
RlGMT EXCELLENT, RIGHT HIGH AND MIGHTY PRINCE,
I commend myself unto you in most hearty and affectuous
manner. And because the Chamberlain of my dear and best-
beloved consort, the princess my wife, goeth presently to you,
for certain matters which, as he says, concern him there, he has
besought and required me that I should write to you in his
behalf. Right excellent, right high and mighty Prince, very
cordially I pray you that you will hold him recommended in
these his affairs; and that from time to time you will ascertain
me and let me know of your good health and prosperity, the

which most singularly and with all my heart I do desire to be
of long continuance as in manner mine own. And tor my part,
whensoever I may find fit bearer, I am entirely resolved to do the

like for you.
Furthermore, on your signifying if there he anything here,
in the which I may do you honour and pleasure, I will take the
pains to satisfy you therein with all my heart, with the help of
our Lord, whom I pray, right high, right excellent and mighty
Prince, give you good life and long.

Written at the manor of Greenwich, the yih day of April,
Your humble cousin,

HENRY, PRINCE OF

Tuesday, May 12, 2009

Choices choices

On Twitter today I saw a thread between Nishant and others bemoaning the negative impact of Twitter on their blog statistics (posting not readers).

I see the effect on my blogging as well. Why go to the effort of a 1 minute blog post when a 30 sec tweet can scratch the itch?

For myself, I think I need to define some criteria to help me assess when a given topic warrants the 'weight & complexity' of a full blog post, or is such that the 'lightweight & open' Twitter will suffice.

Hmmm. Might be able to apply those sort of criteria elsewhere....

Monday, May 11, 2009

AA not AAA

Hey Phil, how about a variation of this for a KNX use case?

Problem drinker (intentionally) gets a card from AA, KNX scripts filter his web content to remove any ads for booze.

All the other 12 step programs would issue their own cards to their members.

Addictive personalities could get hybrid cards as an efficiency.

Thursday, May 07, 2009

Buy page area, they aren't making any more of it (well not enough)

Phil responded to my post with his own balanced analysis comparing GreaseMonkey and the KNX model for page augmentation/customization. I don't doubt that the KNX model is more powerful, secure and flexible than GreaseMonkey - my original point was only that it was evolutionary more than .... well you know.

Whatever mechanism you use to augment/annotate the page at the browser, there is only so much page real-estate to go around.

I upgraded my version of Xmarks, a Firefox extension that syncs bookmarks across multiple browsers and afterwards saw the following on Google's search page.





The blue icon is the extension's 'Smart Search', appending its own links to Google's search results page based on some criteria I know not what. It snuck onto my page.

Makes me wonder how many different extensions, GreaseMonkey scripts, and information cards/selectors are going to be fighting for those precious few square centimetres (even fewer square inches) of real-estate besides the search results.

How will the user manage these? Cards, if grouped into personas (e.g. I'm in shopping mode), could be useful.

Also makes me think there is a market for SAO - search augmentation optimization.

Reuse

Wednesday, May 06, 2009

OAuth & OpenID CX

Nat Sakimura lays out the similarities and differences between OAuth and the proposed OpenID Contract Exchange extension, and argues that CX, even though using a similar protocol flow, is not vulnerable to OAuth's Session Fixation attack - this because CX makes identities explicit where OAuth doesn't.

Of course, making identities explicit is pretty straight forward when you're using a global identifier - gets alot messier if you want to inhibit correlation through pairwise pseudonyms.

Question 3

Concordia's survey on federation technologies & deployments is here.

I find the results for the third question most interesting
3. How many identity-based federated relationships do you have?
A. As a Service Provider / Relying Party?
                 a. One     7
                 b. Two to Ten   42 
                 c. More than Ten    21
B. As an Identity Provider?
                 a. One      11
                 b. Two to Ten   34
                 c. More than Ten  27
21 and 27 respondents have more than 10 federation partners, when acting as an SP and IDP respectively. So much for small deployments with limited numbers of partners.

It would be interesting to see how many OPs participated in the survey as that could skew the 'as an Identity Provider' number. Regardless, it's the comparably high 'as a Service Provider' value that indicates federation is passing the ultimate test.

One aspect of Question 4 confuses me. What does it mean to have a 'federation operator' when the federation topology is 'bilateral/explicit'? What value does the federation operator provide when agreements are bilateral? Legal templates? Dispute resolution?

What would the deductible be?

On the Concordia call yesterday, we discussed the relevance of a survey around assurance (e.g. what do people understand it to be, what are the preferred frameworks, etc) - motivated in part to determine whether the poster child of LOA, NIST 800 63, is actually the assurance model that RPs would choose (if other pressures didn't impose it).

NIST 800 63 is meant to provide (indirectly) to SP/RPs information about the processes and technologies used by the IdP making some claim/statement about a subject - this info presumably useful to the RP deciding whether or not to accept the claim.

What other sort of information would help to convince an RP to accept the assertions of an IdP, if not an (abstracted) glimpse into the IdP's identity infrastructure?

If an RP felt it was adequately protected against any damages that would arise from a 'bad' claim, would it care about the IdP's processes? Claim insurance (filing a claim could get confusing)?

A number of analogies with sexual partner selection, undesirable consequences, and protection mechanisms spring to mind.

Tuesday, May 05, 2009

Breakfast in bed? Pah!

Well I know two mothers who are going to be pretty darn happy come this Sunday morning.

Friday, May 01, 2009

Snakes and Ladders

The level of assurance  (LoA) an SP/RP can ascribe to the assertions of an IDP/OP is determined by a number of factors- some of which, with respect to an SPs ability to ask for them to be changed, are fixed, and some mutable.

The fixed factors are those that the IdP, even if asked by an SP to modify in order to increase assurance, can't realistically change. Things like how the identity was proofed, how the credentials were issued, how the certification audit was performed etc.  While on any given SAML Authn Request, an SP can ask that the IdP follow greater rigor in the identity proofing process for a given identity, it shouldn't hold its breath waiting for the response (as it will take some time to get the user to come to the office and show their passport).

The mutable factors that impact assurance are those for which it is meaningful for the SP to ask for the OP to do something differently in order to increase the resultant assurance. How the user authenticates to the OP is the best (perhaps only?) example. Maybe asking to switch to a different federation protocol is another.

LoA depend on both fixed and mutable factors.

 


Because in run-time (ie at the time of the authentication request) an SP can only ask for (by definition) changes to the mutable factors, any run-time movement in the above 'assurance space' can only be along the horizontal axis. There are snakes to take you sideways, but no ladders to move you higher.

The fact that you can only move sideways in assurance space at run-time has consequences for LoA. If you want to be able to transition from one level to a higher level at run-time, the point in assurance space from where you start must already meet the criteria of the higher level (because there is no 'ladder' you can climb at run-time to move up).

You can see this in the following diagram. Starting point 1 exceeds the threshold of LoA 1 for both the fixed and mutable factors. But, after we move sideways in assurance space (by the SP requesting and getting a stronger authentication etc) so that the threshold for the mutable factors exceeds LoA2, the assurance from the fixed factors has not changed. Consequently, the ending position in assurance space does not meet the fixed threshold for LoA2, nor consequently the combined threshold.

Even though the assurance from the mutable factors increased, that of the fixed factors prevents the combination from jumping to the next LoA.





Starting point #2 however, because it already exceeds the fixed threshold for LoA2, does not prevent a transition from LoA1 to LoA2 if a move sideways along the mutable axes allows it.

The moral of the story? Ayn Rand said it for me

"The ladder of success is best climbed by stepping on the rungs of opportunity."

Thursday, April 30, 2009

A friend is planning a trip

The new math

Self worth = Twitter (# Followers - # Following/# Followers)

I posit that a score exceeding, oh I dunno, let's say 1.4834, means the individual is both friendly and insightful - with a tweet stream to match.

If your score is negative, you are pathetic. Or a successful web marketer. Or both.

Federation?

In my deck at the RSA Workshop, I referred to all of OpenID, SAML, ID-WSF, cards, OAuth etc as federated technologies.

Even as I made the statement, I was prepared to duck, wincing mentally in anticipation of objections as many disagree with the generalization, liking to use 'federation' to distinguish the various protocols.

Nice to see I'm not alone.

Wednesday, April 29, 2009

Me Tarzan

In 'The Unfolding of Language - an evolutionary your of mankind's greatest invention', linguist Guy Deutscher presents a theory as to the processes and mechanisms by which human language might have evolved to it's current power and complexity (as best exemplified by Shakespeare's sonnets, Japanese haikus, and Twitter streams).

According to the theory, human language evolved through opposing forces of destruction (our natural tendency to save effort by shortening and compressing words) & creation (new words).

Deutscher starts with a simple story, told without the structures such as prepositions, tenses, cases, conjunctions etc that give current language its expressiveness

girl fruit pick     turn        mamoth see
girl run        tree reach        climb     mammoth tree shake
girl yell yell             father run        spear throw
mammoth roar       fall

Justifying the above simple 'Me Tarzan' scaffolding as a legitimate starting point on which his evolutionary forces would have operated, Deutscher presents 4 'natural and transparent principles' (e.g. keep things that are close together in time close together in the story, etc) that, he argues, are sufficient.

The third principle is "Don't be a bore", i.e. those parts of the narrative which are less important, or can be understood from the context, need not be restated. For instance, reworking the story's first part and repeating the actor involved

girl fruit pick    girl turn    girl mammoth see    girl run     girl tree reach    girl tree climb

Because listeners can work out from the context that it was the girl that turned around, and not the mammoth, there is no need to restate it every time. To do so is wasted effort. The identities need only be made explicit when there are multiple possibilities, e.g. either the girl or the mammoth might have run away. At other times, identities may be safely left implicit (or replaced with time and effort-saving references such as the pronouns 'she' & 'it'.)

As a warning, Deutscher writes

Of course, speakers cannot always assume that the identity of the participants will be obvious to the listener.

Ahem.

Tuesday, April 28, 2009

Explicit assurance disclaimer

So I got that goin' fer me

I am happy to report that Canadian Tony Mandarich, ex NFLer, is following me on Twitter.

Apparently, his tweet stream is free of any illegal substance (unlike his urine stream of the past).

Which is nice.

A failed experiment

Motivated by Twitter's brilliantly inefficient 'reply' mechanism ( i.e. you reply to a person, the burden of determining which of their Tweets motivated you to do so falls on them), I began this morning an experiment in applying this model to other communication channels.

Word to the wise, busy women balancing the demands of a young family, an immature husband and a nursing career may not appreciate the value of a conversational model in which your participation manifests itself as randomly replying to previous statements or queries of your partner.

Calling it 'paradigm shifting' will fall on deaf ears.

Friday, April 24, 2009

Oops

After forgetting I last signed into Twitter as one of my alter-egos, the 'following' I did this morning all inadvertently occurred under the purview of that identity.

Error: Selector is jammed

I have to believe these would get stuck.

Something to chew on while we wait for RPs though.

Thursday, April 23, 2009

Turns out it was a rant

Update: my people tell me that existing Liberty members will have to go through a membership registration process, i.e. it will not be an automatic transfer.

In a comment, Dave clarifies
It was a rant, Paul.

Thanks Dave, if there was a standard for semantic blog tagging, we could avoid confusion like this (and I could  apply a useful filter to my RSS reader).

Dave goes on
But it seems you (unlike those of us on the outide) have access to the KI members list - could you please post all of it (or did you)?

What was announced on Monday at the workshop was a call for participation - not the actual launch. There wasn't even a press release AFAIK. The public faq has this to say about membership
Kantara Initiative has been co-formed by the DataPortability Project, the Concordia Project, Liberty Alliance, the Internet Society (ISOC), the Information Card Foundation (ICF), OpenLiberty.org and XDI.org. All of these organizations are now members of Kantara Initiative. The name of the organization was announced during the April 20 Identity Workshop at RSA Conference 2009, at which time the co-founders introduced key goals, benefits to the industry, and issued a formal call for participation. Many other individuals and organizations have also become members of Kantara Initiative. Kantara Initiative will release a full list of members once industry stakeholders have the opportunity to respond to the April 20 call for participation.

By default, those companies that are currently members of Liberty will become members of KI (and I acknowledge that, at least initially, some may do so if only because their fees are covered. I expect we will winnow these types out through the rigorous hazing process).

With respect to VRM representation in KI, I recommend reading the most recent (public) call minutes of the the VPI (Volunteered Personal Information) SIG.

With respect to OpenID Japan interest in KI, please check out Nat Sakimura's (public) message to the OpenID list.

With respect to whether KI offers mutual benefit, clearly some communities agree with Dave and don't see it that way. Maybe that will change in the future. If not, meh...

Is this right?

The alert for the recent OAuth vulnerability has the following text

After the victim grants approval, the attacker can use the saved Request Token to complete the authorization flow, and access whatever Protected Resources are exposed by the (honest) Consumer site as part of its service.

As I understand the attack, when complete, the attacker will be able to sign-in as normal to his (honest) Consumer account and, in so doing, be able to (indirectly) access the Protected Resources that the honest (Service Provider) exposes (through OAuth). In other words, it's not the User's Consumer site resources that are compromised (as the above text suggests), but rather their SP resources.

Separately, I think the recommended warning text would have users running for the hills if they understood it. Why not piggy-back on whatever accumulated wisdom users have for detecting a phish?

Wednesday, April 22, 2009

Would that assurance was this easy

 



Can't quite see an RP saying 'Well I'd like Level 4 but I can get by with 3'.

Liberty 2.0

Only a matter of time before a somebody goes to the '2.0' meme in describing the Kantara Initiative. The 'Yet Another' meme is already being worked to death. Think of the title as a pre-emptive strike.

Of course, the fact that KI has already attracted the likes of ICF, DataPortability, XDI, and ISOC, with strong (publicly declared) interest from OpenID Japan and VRM's VPI will be brushed aside - can't let facts interfere with a good rant (or was it a rave or musing, it's so hard to tell).

I don't know if KI will succeed. I do know that its formation is just the last in a series of attempts by one identity community to establish mutually beneficial relationships with others. From where I sit I can think of precious few examples where the reverse happened.

This changes everything?

In the ICF session of Monday's RSA worskhop, Drummond described the new 'action card' concept (as enabled by Kynetx and demonstrated by the AAA and ChoixVert) with the phrase 'this changes everything'.

While the idea of client-side personalization of search results is undeniably cool, I would question its 'changing everythingness' - not because it's not a powerful idea but simply because everything changed a while ago with GreaseMonkey.

With GreaseMonkey already installed in Firefox, I installed a script (found by searching on 'environment' at UserScripts) that augments Google Finance pages with the environmental scores of the companies searched for - the 'hue' pulled from GreenerOne.com.

For instance, below is the results page for Nike




Google didn't serve up the text in green, it was appended by GreaseMonkey, as specified by the script. Beyond the above simple script, there is even a whole project dedicated to the idea - the Web Browser Environmental Sustainability Toolkit.


WebBEST was built to address the world's sustainability issues. We feel that people are ill informed of their impact in the environmental, perhaps because of the lack of environmental information in popular online services. With the system in place, people no longer need to go out of their way to find environmental information. Instead, people need only install our scripts and that information is brought to them directly though the online service they frequent, relative to the content they are viewing.

The ChoixVert whitepaper argues that Kynetx's system is unique

There are many scripting languages and web augmentation
technologies out there. All of these are interesting but don’t hold a
candle to KNS. Here is why.


1. KNS is selector driven.
2. KNS is accessible. The Kynetx Rules Language is based on a
human readable programming paradigm.
3. KNS glues any accessible data to any service or application—
anywhere on the Internet—and it does so securely and with
the user’s consent. This has never been done before. 


I expect being 'selector driven' offers both advantages and disadvantages. As a possible example of the latter, can I the user customize the ChoixVert card, managed card that it is? I can see the card in the Azigo selector but don't seem to have any means to edit? A definite example of the latter is that there is but one 'GreaseMonkey Script Chooser' so the user doesnt have to deal with 'Script Chooser Chooser' windows.




The fact that the rules are human readable will reassure my mother I'm sure - she does worry so about being able to read code....

Separately, I find 'action card' as a descriptor somewhat strange, from the user's PoV, a typical 'sign in' card involves far more 'action' than this quiet personalization operation.

Getting warmer

Monday, April 20, 2009

See me about a t-shirt

 

Unfortunately, I am told the coffee mugs and mouse pads are already sold-out.

Thursday, April 16, 2009

Choice choices

I'm reading about the early days of submarine telegraph cables - this in the context of the eruption of Krakatoa in 1873 , as authored by Simon Winchester in Krakatoa - The Day the World Exploded.

Apparently, when sending a telgraph from Java to Europe, senders had a choice


It could either go, slowly and insecurely, via the long chain of landlines that had been established midcentury, ... or it go "Via Eastern". A customer could in those days specify on the telegram forms which cable should be used, and pay the costs that particular cable company charged. Specify Via Eastern, and it made most of its long journey by sea. Leave the cable-routing box blank, and the message went the long and slow way, and for most of its length, by land.


Clearly there are a number of ways I could go with this.

Monday, April 13, 2009

Fake

My nephew posing with his fake ID.

 


He had another but I can't see it working too well.



Clearly fake. No way would a real license would allow sunglasss to be worn.

Friday, April 10, 2009

Calling all gays

This Boing Boing article 'outing' a video created by this organization prompted me to grab this Twitter account in a preemptive land grab.

Let's keep hate off the Web - keep it in the home where it belongs!

Thursday, April 09, 2009

Reunited

My Archos 5 and I have decided to give it another try. She's back from repair and, so far, our relationship is back to how it started.

Some 'wiseacre' friend of mine decided to formalize the reunion through Facebook.






I'd pay real $ for an OpenID from

here (as reported by Scott).

I'd sign up early to ensure I got 'andeggs' as a username. Or 'lettuceandtomato'.

Wednesday, April 08, 2009

Clever (not so much)

This service will let you create a unique OpenID

For instance

http://uǝspɐɯlnɐd.myopenid.com/

unfortunately, when I present the above at an RP, it gets (somehow?) resolved into

http://xn--usplnd-38b63gca12a.myopenid.com/


I may need to write this one down.

That hairy character writes

Well, to be specific, Vittorio writes, in discussing OpenID's (and other redirect protocols) challenge for OP/IDP discovery,

The nice part about the home realm discovery is that it has a simple & elegant solution, which happens to work well on the internet too: information cards.

A nit - the solution to the problem is smarter clients and/or user-agents - information cards are but one instantiation.

All things are possible when the User's client is smart enough to store identity (either attributes or location) and to engage in transactions on their behalf.

With respect to Chris's original point about the 'nascarization' of OpenID UI, I suggest a more global (and one more likely to resonate with those not living in trailer parks) example of the phenomena of 'branding gone bad' than Nascar is the jerseys of European hockey players.

Tuesday, April 07, 2009

Lucky

Identifiable?

Readable is a cool script that allows you to view page content in a format more conducive to reading.You specify how you want text formatted, drag a button to your bookmarks bar, and then use it on any page you want formatted.

The user is not constrained by whatever formatting decisions the page designer made.

Why not a similar (user-customizable) script that rendered existing identity UI components in the page how the user wanted them?

For myself, I've always thought log-in buttons should be blinking. And purple.

Monday, April 06, 2009

Maybe I'm overthinking

In a tweet, Brett praises the OAuth-based UX between WeFollow and Twitter.

Personally, I find it confusing in a couple of places.

First, on the WeFollow (OAuth Consumer) side, I'm getting mixed messages.

'Authorize WeFollow' tells me that I'm in the driver seat and have control over WeFollow. But 'need to verify your identity on Twitter' gives the impression that it's WeFollow doing me the favour, and not the other way around.

Once I get sent over to Twitter (the OAuth SP), I stay confused

 

If I'm presenting my password (or other credential), I expect to see a 'LogIn' button, not an 'Allow'.

This UI confused Sxipper as well. When I allowed Sxipper to fill in and submit the form, the result wasn't what I expected.


Damn, damn, damn!

Friday, April 03, 2009

Uncertainty

Division of Roles

The ProtectServe proposal (I'd attribute it to Eve but I think she has been lionized enough recently) separates out the PDP (Policy Decision Provider) role from the PEP (Policy Enforcement Provider) role - this compared to default OAuth which collapses the two.

This made me think of a possibly useful way to look at different identity systems for permissions-based attribute sharing.

I posit that any given request for some user's identity attributes can have associated with it the following actors/roles

1) on behalf of which actor the request is being sent
2) which actor's identity attribute is being sought
3) which actor is sending the query
4) which actor holds the identity attribute (PEP)
5) which actor makes the authz decision (PDP)




ProtectServe distinguishes itself from default OAuth by introducing the Relationship/Authorization (which is it going to be) Manager. The SP holds the identity attributes, but the AM holds the corresponding authorization policy for the release of those attributes to specific Consumers. The AM provides a single policy management point for the User, hopefully simplifying for the User that burden.

Neither OAuth nor ProtectServe explicitly support 'social identity requests', i.e. a Consumer sends to an SP a request for Alice's attributes on behalf of Bob'. Liberty's SOAP Binding does allow this scenario, by allowing both Alice's and Bob's identities to be carried on a request. Bob would be the 'invoking identity' (ie that on whose behalf the request it sent) and Alice would be the 'target identity' (i.e. that that 'owns' the attribute).



In this scenario, the WSC sends a request on behalf of Bob to a WSP that carries some identity attribute of Alice's. The WSP looks at the policy that Alice has defined for her friend's abilities to access those attributes, and decides whether the request should be authorized.

Through the People Service, ID-WSF also allows the User to effectively separate out the above PDP role (probably more a PIP) from the WSP.


Instead of Alice defining her 'social authorization rules' at the WSP that holds her attributes, she can specify them in terms of a social structure maintained at her People Servicee, e.g. 'Allow any member of the group 'Family' to access my private calendar'. By so doing, Alice can leverage that same social structure for defining authorization at other WSPs, e.g. 'Allow any member of the group 'Family' to view my current location', etc.

Ultimately, I think User's need to be able to define authorization rules for their identity attributes in terms of both

1) the requesting actor (Consumer in OAuth/ProtectServe, WSC in ID-WSF)
2) an individual with some defined social relationship to themselves

ProtectServe's AM is designed to simplify for User's the definition and management of the first type of authz rules, Liberty's People Service the second. 

Wednesday, April 01, 2009

The dog has been dead for 35 years

But Intuit Canada would have me change his name.



Don't worry Fred, I picked a different question.

Good boy.

Just because I can

This Twitter account is in no way affiliated with this other site with a somewhat similar name.

Things are looking up

I tested my new WiMax modem at the cottage yesterday.

Strong signal, plenty of speed. Bye-bye dial-up.

Must look into getting a long extension cord. And a waterproof laptop.

Social weave?

Axel suggests that Mozilla Weave should sync Infocards.

The Weave graphic that Axel adds Infocards to makes reference to 'friends & family' - implying some social aspect to Weave.

Hopefully that doesn't mean using Weave to share site credentials with your social network. Social sharing needs to be more granular than the 'all or nothing' that impersonation enables.

I've yet to hear the Infocards social story. One thing for sure, I do not want to be tracking & managing cards given to me by my friends & family - each card reflecting some set of 'sharing rights' assigned me by the owner. That way leads to madness.

Tuesday, March 31, 2009

Good thing there is no federation agreement

between Ontario and New South Wales.

A Sydney parking ticket from 1988.



My defense? The sign was in Australian!

Bottom feeders

This feels like fishing for carp - not much fun and you're going to throw back anything you catch.

I do like that Twitter's response is to encourage suspicious users to change their password - after first presenting the old one of course...

Down to the wire

By my count, IIW has approximately 50 of the required 75 attendees - with the deadline tomorrow.

C'mon people, I will be needing a NorCal sunshine break from Ottawa spring showers right about mid-May. Let's make this happen.

Monday, March 30, 2009

Calorie burner

Garbage in, garbage out

Thought of a perfect use case for the Twitter model.

Litter.com, i.e. tracking the where, when and how much of people picking up litter in their neighborhoods.

Form teams, compete etc.

A niche demographic admittedly.

Punctuation is Key

MyID.is Certified prepends some identity verification on OpenID-based authentication.

MyID.is also an OpenIDprovider, but a certified OpenID provider as we have previously certifed the Microformats embeded in your OpenID

The string 'Certified OpenID Provider' in the above can be interpreted in two different ways - distinguished by what gets certified.

MyID.is is a 'Provider of Certified OpenIDs' - this not the same as a 'Certified Provider of OpenIDs'. It's the OpenIDs that MyID.is issues that are certified, not MyID.is itself.

Consequently, any RP for which 'certified OpenIDs' is important will need to trust MYID.is's own claims as to the rigor of the verification process. But how will the RP know?

I'm sensing some more assurance math, something along the lines of 'the amount of assurance in the process that certified the OP must be greater than or equal to the amount of assurance in the process that certified the OpenID....'

Ultimately, MyID.is needs to be a 'Certified Provider of Certified OpenIDs'......


Separately, I do like the idea of a 'random fee as shared secret'


You will also need a credit card with the same namethat you are certifying. We will charge you only once a random certification fee between €2 and €5. Then you will have to check your bank statement and fill in on the MyID.is site the exact amount in Euro you’ve been charged.

Although actually checking the statement would make for a slow process.

Quizzical

Friday, March 27, 2009

Captcha

I was orderling internet service the other day. As I was selecting the plan options, a new browser frame appeared, with a hello from 'Sara' asking if I needed help.

For the initial part of our conversation, I honestly couldn't tell if Sara was human or scripted.



Maybe Sara's conversations are all this stilted.



She definitely had her eyes firmly set on the 'Proceed to Checkout' goal.

Separately, what do I care if she didn't want to friend me on Facebook? Her loss right?

Thursday, March 26, 2009

How Concordia like

From SEED magazine, an article on the need for shared terminology amongst the nuclear powers.

At the height of the Cold War, American and Soviet scientists wrote handbooks for each other that attempted to bridge their language gap. Helping to explain some of the era’s more arcane nuclear terminology, these handbooks were a crucial diplomatic tool that helped prevent potentially disastrous misunderstandings.

Having a forum for talking through sensitive issues, like the meaning of “limited deterrence,” he says, is worthwhile for building trust.
While the glossary is an important first step for improved relations, Li says more bilingual security experts are ultimately necessary