Sunday, August 20, 2006

NYC allows babies into after hours clubs


Or there could be a more mundane explanation.

Babies doing math. Wow, what a revelation. I'm guessing the researchers have never seen a baby breast-feeding.

Identity Keyboard

The Optimus Keyboard uses mini OLED displays on each key in order to dynamically customize the layout and function of a keyboard suitable to the application at hand.

Makes me think of something like the following for identity transactions, with some typical identity operations thrown in (with a little but not much thought to logical organization). The purple keys are meant to represent operations performed at the user's Identity Provider. The greeen, yellow, and red keys for responding to identity requests (with some representative answers). Other "non-identity" keys are greyed out, reproducing the visual effect of the similar Cardspace behaviour.



When not warranted by some request for identity, the keys would show whatever other letter/function/operation was appropriate.

400 years too early

When I was in Oxford last month for the XML Summer School, in between dodging gangs of colour-coordinated teenagers in the city for English instruction , I picked up a 3-pack of biographies of English notables.

I started with Cromwell, Our Chief Of Men (warts and all) and am now thoroughly enjoying King Charles II (still anticipating the debauchery - you're a King man, use the power!).

A conversation between Charles (post-Restoration) and his advisor Clarendon jumped out at me. The two are discussing (through notes passed during a Council meeting) an upcoming trip of the King:

Clarendon: I suppose you will go with a light Train

Charles: I intend to take nothing but my night bag

Clarendon: Yes, you will not go without forty or fifty horse?

Charles: I count that part of my night bag ...

There, but for the medium, is an IM log (wit and all). I'm sure Charles felt the lack of a smiley for his last  :-)

Oxford was good (but not good enough) to Charles's father, as it was to me. I do hope the Royal apartments had air conditioning though.

Friday, August 18, 2006

You know you're a parent when ....


.... you're getting ready for a mountain bike ride and you can't find your water bottle and you think of an alternative.

Thank God we're past the bottle stage, who would burp me out on the trails?

So where are the scars?


Kim Cameroon responds and clarifies.

Kim had previously showed a Ping ID demo that he asserted nicely demonstrated how 'user-centric' and 'federated' were compatible but orthogonal.

I think the demo is undeniably cool and shows a perfectly valid use-case. What I question is Kim's claim that it displays some clear and fundamental distinction between user-centric and federated identity.

According to Kim, the user-centric piece of the demo (where the user authenticates to the portal with Cardspace) helps 'people get through their day' and the federated piece (in which the user is SSO'ed into various services) is 'tieing portals together'.

For the demo, this seems an accurate description. It is only when authenticating to the portal that the user appears to have any control over the release of their identity (by selecting and reviewing an Identity Card). Once signed-in to the portal, the demo suggests that the 'user-centric experience' is over, from here on the portal and the services decide what identity gets shared, and the user's ability to control this boils down to clicking on the relevant service 'Sign On' button or not. This piece of the demo doesn't appear very user-centric at all.

But of course the demo could well have shown the portal offering the user the same sort of fine-grained control over identity release to the various services - what gets shared needn't be a done deal between the portal and the services and out of the user's control.

Put another way, if user control over the sharing and use of their identity is the prime criteria for user-centricity (which I believe is the case), then there is no reason why user-centricity cannot extend into the identity exchanges between the portal and the services - the user can have meaningful control over these exchanges just as they did for the exchanges between their local IDP and the portal.

Hubert has another demo that shows "federation" technologies used in this manner.

I take the following from this thread (and another that Kim engaged in with Conor).

User-centric identity requires:

1) a philosophy of user-empowerment +
2) technology (protocols, UI, consent mechanisms, etc) in support of #1.


If an identity system has the first(who would claim anything less), but the technology can't back it up, then it's not user-centric. Conversely, technology (any) can always be applied in a non user-centric manner if not deployed in a manner consistent with the philosophy of empowerment.

The other end of the anonymity scale

Lots (here, here, here ) of blog discussion on anonymity lately.

Amazon's Real Name mechanism goes to the other extreme. In order to establish confidence (dare I say 'trust') in people's online activities at Amazon (e.g. reviews), these activities are bound to their real life identity (as verified by the credit card infrastructure). Presumably, I'm less likely to do a hack job on some book if I have my real identity attached to the review.

Interesting that such real name attribution is given less weight than reputation in determining the score for a given review.

I guess the old saying "It's not who you are but who knows you" holds true.

Confirm your account

Don Park proposes generalizing the email mechanism (email gets sent to provided address, user clicks on embedded link) often used at registration and/or password recovery time into a true authentication mechanism.

Rather than do this only initially and then subsequently as occasionally necessary, the user would authenticate this way every time (or at least when cookie expiry made it necessary). No password necessary at the site, and so it's a kind of SSO based on the authentication to the email server. Nice.

Message delivery lags and spam filters could make the system impractical. In my experience, the 'Confirm Account' mail can arrive long after I try to register, which isn't an issue if the site lets me proceed in the interim, but would be an issue if it prevented me signing-in.

More fundamentally, it seems a step backwards. Current reality is that just about every site already has my email, and so Don's scheme wouldn't change the nature or scope of the info that I need share with sites in order to get service. But, I don't like this current reality. I don't want to have to give my email(s) out to all these sites, constantly doing the mental computation 'I'm never going to be back here so I'll use an email address with a high disposability factor'. Don's model reinforces this status quo.

As an aside, Don's model fits the pattern of challenge-response authentication - the site's challenge is 'Can you access this email account?' and the user's response is 'You bet (and proves it by clicking on the link)'. I'm surprised to see that SAML doesn't appear to provide an Authentication Context to describe this basic pattern. The only support for challenge-response in the Authentication Context schema is the SharedSecretChannelResponse element, and in Don's scheme, the email address is probably no secret.

Thursday, August 17, 2006

It's not just us

In a post from downloadsquad on a new version of the file-sharing app BearShare, comes this line

It sounds like iMeshToGo and BearShareToGo will offer a long awaited solution to the problem of illegal file-sharing, and the other problem of no way for people to buy music in an effective way that is user-centric.
"User-centric" music sounds too much like I'd be listening to my neighbour's twangy rendition of blue grass classics. No thanks.

Let's not forget the Powerpoint!

Just came across this.

It fills an important niche in the SSO space, namely the 'Monthly SSO system claiming to be simpler than SAML' niche.

The idea of sharing your Identity Provider account password with random Service Providers seems attractive. After all, if I'm presenting it to every site I interact with I'm less likely to forget it. As they say in the Guiness ads, "Brilliant!".

The following sentence particularly caught my attention.

The Liberty Alliance has churned out a number of PDFs but that seems to be the extent so far of their effort.

I don't know why people are constantly scoping the Liberty Alliance down to the publication of just PDF documents - we are far more than just that. It seems that just because the best known examples of our published material are in PDF, then somehow we get typed as only publishing in PDF.

Fundamentally, the Liberty Alliance defines a marketing framework, a platform on which can be built systems capable of publishing in a variety of formats appropriate to different marketing applications. Any particular publishing run is able to use the Liberty framework in a manner that suits the sort of marketing campaign being targetted. Examples of particular file formats supported by the Liberty framework include Powerpoint, HTML, JPEG, Flash etc and of course, yes, PDF.

There are lots of publishing frameworks that support one or two of the above formats, LAP is, AFAIK, unique in its "publishing format breadth".

Update: Conor reminds me that Liberty has also published in plaintext. I also forgot WML. This just reinforces my point about the flexibility of the Liberty publishing engine.

Conor also implies that, in my eagerness to deride, I missed the point. Ah my constantly green-clad Irish friend, I knew full well that others would make the 'billion Liberty-enabled identities' & 'countless deployments' argument (as well as dig deeper than I did in an actual security & privacy assessment of the proposed SSO solution).

Wednesday, August 16, 2006

A new FOAF tool

FOAFGen.net is a FOAF generator.

Unlike other such tools, this one allows FOAF files to be created in batch mode from vCard and LDIF inputs.

Problem remains as to what to do with the thing once you've created it. And how to keep it synchronized with your contacts.

Judging IDDY

Strictly speaking, these should be the LAPIDDY Awards - for Liberty Alliance Project Identity Deployments of the Year. Rolls off the tongue too.

I think of the stated criteria (e.g. demonstrable ROI and benefits, etc) as loose 'best-practices' for judging rather than normative MUSTs and SHOULDs.

Any deployment that uses a spec I have an emotional attachment to might just have an advantage. Show me a People Service implementation, even if only sketched out with lipstick on a cocktail napkin and coded in Fortran, and start planning what you'll wear on stage when you accept (assuming I can sway the others).

Monday, August 14, 2006

Shouldn't there be a Web 2.0'ish app for this?

I need to track hot tub jet replacement.

I've experimented with permanent markers to identify the replaced jets - it seems 'permanent' doesn't apply to hot chemical baths. Tape gums up. I'd lose any record on my PC. Consequently ....

Public Key (chains)

Just over 4 years ago, the Liberty Alliance had a meeting in Paris. My wife had given birth to our daughter Sophie just 6 days before I had to travel. While in Paris, in a mood of homesick nostalgia, I popped for an over-priced key chain (the sort of kitch that tourist shops make their margin on) as a small gift for my new girl.

I've been popping for similarly over-priced key chains for Sophie at every location I've since travelled to. Her first question when I return from a trip is inevitably 'Did you get me a key chain?' She has even created a taxonomy for the different styles, e.g. the 'turny' ones are her favourites (three of them visible at lower left below).



As Liberty Technology Expert Group is returning to Paris next month, it seems an appropriate time for a status report.

Sunday, August 13, 2006

Commentwary

User-centrification

Kim Cameron has a screen cap movie of a demo created by Ping ID.

Kim asserts that the demo illustrates (paraphrasing) "user-centric technologies like Information Cards are not in any way counterposed to federation technologies".

I completely agree with the sentiment, but question whether the scenario portrayed by the demo actually demonstrates it.

In the demo, a user authenticates to a portal using CardSpace. Once authenticated, they are presented with a list of applications available to them for which SSO is possible (this presumably dependent n which I-Card they selected). For Kim, the user-centric piece (CardSpace) somehow ends at the portal, and from then on federation (SAML etc) takes over.

So, user-centric and federated technologies are shown as working together - but not at the same time. The user-centric piece hands off to the the federation piece. Federation is presented as a lower-level piece of infrastructure (which it can be) that doesn't seem to touch the user.

This interpretation is reinforced by Kim

To my way of thinking, you have two more or less orthogonal technology efforts - that oriented around federation issues, and that oriented around the user’s experience.

This ignores the possibility for SAML-based technologies to provide the very same user-experience (i.e. real-time identity sharing control, IDP selection etc) that I-Cards enables. Is SAML's Enhanced Client or Proxy (ECP), as it enables similar control mechanisms, then user-centric?

Probably not, as Kim also hilites the common UI of Cardspace and its relevance

Should my experience therefore be totally discontinuous as I move from one portal to another, being organized by the portal rather than by my own system

If the phone manufacturers (or those of set top boxes) were to come together and agree on user-interface standards - would that be user-centric?

Friday, August 11, 2006

Upcoming flight restrictions a boon to online services

Robin Wilton links to some tips for business travellers dealing with the risk of checking in a laptop.

Makes the Google OS model more and more attractive. Maybe they should be marketing a $100 laptop at business travellers rather than the masses.

Tuesday, August 08, 2006

Girls Gone Wild - why of course it's about identity

and people watch the videos for the sparkling conversations

On the Identity Trail

If this title doesn't push my stats through the roof (i.e. 20/day) I will be very disappointed.

Sunday, August 06, 2006

Who speaks for the trees?

Kim Cameron ponders on the MySpace 'salute' mechanism for identity verification (of sorts).

In MySpace's FAQ, the answer to 'Someone is pretending to be me - what do I do?' includes:

In order to verify your identity, please send us a "salute". This means we will need an image of yourself holding a handwritten sign with the word "MySpace.com" and your Friend ID

Beyond the environmental trajedy of the trees that will be cut down to supply paper for these signs, Kim points out the difficulties with this scheme, arising I think from the fact that the MySpace staffers aren't at all qualified to say which face (unless some celebrity) goes with an identity. The people who are qualified to make this distinction are those that know the person outside of MySpace and so can say 'Uhh, Bob doesn't have red hair and breasts ...'

Maybe the mechanism should require that there be two people in the picture, one claiming 'I am Bob' and one attesting 'I am Tony and this (pointing) is indeed Bob'. But, then who attests to the attestor's identity? Ok, three people in the photo ....

I have to wonder why they stipulate that the URL on the sign be hand written. To prevent automated machine salutes?

Wednesday, August 02, 2006

No fault of mine

I have to wonder at which sort of users the below fault message (from Yahoo's AJAXy mail beta) is targetted at.

Will the fact that 'There was no XML in the response' be helpful to Roy in Saskatchewan?

'Ahh, yes, that makes sense, I thought the problem might be the XML response status ...'.