Wednesday, September 06, 2006

Jamie Murray (1973 - 2006)

I lost my brother-in-law and friend last week. As they say in the Ottawa Valley, he 'took a heart attack'. At 33 years of age. The world seems a whole lot more perverse than before.


I like to argue, learn new things, drink beer, and build things. Jamie was a willing and able partner in all these. He was also the best damn Uncle to my kids that could be spec'd out.



The doctors tell us it could have happened while he was pumping gas or filling out a Web form - neither a fitting end to a life of activity and love. Jamie died in his treasured boat after wake boarding on the river he loved, surrounded by the nieces and nephews that adored him, and close to his wife and family.

I will continue to argue, learn, drink beer and build sheds at the cottage. It just won't be as fun.

My lead feels safe

In his first salvo of the 'Great Blog Readership War', Conor fires off

a) a stirring account of how he fixed his kitchen drawer.
b) a hard & driving story describing his purchase and plans for some computer equipment.

I expect we'll next hear about some problem with his farm tractor that he was able to repair with a USB cable and a patch made from chewed-up Cheerios paste.

Blatant attempt at targetted marketing for those searching on 'hardware'. He can have them - my readers pay their "people" to fix & install things. Much like the distinction between 'Jeopardy' and 'Who Wants to be a Millionaire' demographics.

I think I can safely take the week off from any further posts. Or the month. Maybe just start up again in January. I do need to ensure that I'm active before the Internet makes it to Ireland - Conor's numbers will jump when his relatives get online.

Note: I choose to believe that it was coincidence that Conor chose his blog address to begin with 'C O N' - the same three letters as does mine. Not intentional typo squatting I'm sure. I might have to revisit this opinion if Conor's metrics (number of linking blogs and Technorati rank) pass mine.

Thursday, August 31, 2006

Sometimes I want an account

I just signed my two sons up for hockey camp through an online registration.

I really appreciated having to enter all the same information twice - sometimes I tend to forget my home address and like to be reminded through rote repetition.

Given that I've signed them up in years past, and will be signing them up going forward (untill they come to the realization that they've inherited my skating ability), I would have preferred an account to store the info (in the near term absence of better alternatives).

Hospitality Industry Token Mapping

Just returned from a trip down to Washington for a Liberty TEG meeting.

Leaving the hotel, my NTT colleague Hiroyoshi Takiguchi and I noticed what appeared to be a number of wall safes just outside the front door.

The safes are there for guests who arrive for check-in after the front desk closes at 11 pm. The mechanisms works as follows

1) Before leaving for the night, staff enters the first name of each expected guest into one of the displays
2) Guest, on arriving, enters their last name using the keypad of the appropriate (matching their first name) safe.
3) Safe lock opens, guest retrieves their room swipe key.
4) Guest uses key to enter building and then their room.
5) Hotel staff sleep throughout.

So what if two guests have the same first name ....?

Or if a guest has an easily guessed last name ..?

Or hotel staff mistypes the guest's last name ..? (comparable to somebody, in a fit of pique arrising from poor blog readership, spelling 'Madsooon')

Speaking of pique, Conor suggested that a better model would be for the guest to simply swipe the credit card used to make the booking - that would imply connectivity beyond the safe unit itself.

Nice example of token mapping. The guest exchanges one token (their last name) for another that can be used to access local resources (ie. enter the hotel and room).

Dulles Dialogue

Cast of Characters

  • Security Screener at Washington Dulles Airport (SSWDA)
  • Guy in Front of Me in Line Going Through Security (GFMLGTS)
  • Paul

Scene1

SSWDA: (to GFML as he peers at his scanner screen) So, is this a laptop or a DVD player?

GFMLGTS: I'm in the military and it's classified.

SSWDA: Pardon me?

GFMLGTS: I can't tell you what it is in public.

SSWDA: Supervisor!

Exit Paul. stage left, scurrying over to other line

Tuesday, August 29, 2006

Id (in the Freudian sense)-Centric

Chris Ceppi proposes a new addition to the taxonomy - Ego Centric identity.

* Ego is participant in the ego centric model.

* Claim is statement made by an ego taking credit for an idea. A Claim can be made NotBefore and/or NotOnOrAfter an idea becomes well known.

* Assertion is statement made by an ego either directly or indirectly suggesting the superiority of the subject.

* Subject is always the ego.

* Asserting Party is a gathering of two or more egos to facilitate the exchange of claims and assertions. May be phyiscal or virtual.


Note: The last confuses me, in what sense is the ID Gang an 'asserting party'?

In my opinion, any taxonomy that allows for the 'Ego' but doesn't acknowledge the importance of the 'Id' is lacking.

According to Freud, the Id is that part of the psyche that deals exclusively with the needs of the individual - the Id doesn't care about anything else. It's all me me me.

Sounds super. Consequently, I propose here

Id-centric - a model of identity management in which the user's desires and wishes come before all other factors (business realities, regulations,technical limitations, etc).

Just ask my wife

Apparently, the Japanese government is funding research on automated mechanisms to help surfers assess the validity of online information they read.

Science seems to be missing an obvious resource

Me: I need a new MP3 player
Wife: Bullsh*t!
Me: I couldn't get an earlier flight home from Hawaii
Wife: Bullsh*t!
Me: I read it for the articles
Wife: Bullsh*t!

Monday, August 28, 2006

Name management

Neighbours across the street prefer that our kids to refer to them as 'Mr & Mrs X'. As this is diferent than the pattern of others in the neighborhood (where first names are just fine), my kids occasionally ask about it. I always respond that everybody has the right to choose what name they want other people to use for them.

Kaliya wants to be known as 'Identity Woman'.

Kaliya sees a bias against such titles
I find it interesting there is such a focus on that positional title to have legitimacy in this industry. I really think it is a disservice all around there are people who contribute a lot without positional ‘titles’ who deserve to be on stage some times perhaps more then those on stage who have ‘titles’.
This to me reflects the distinction between self and 3rd-party asserted identity. It's easy to make claims about yourself - but sometimes relying parties want 3rd party assertions.

"Positional Titles" (as Kaliya describes them) are typically names given to us by somebody (a boss) or something (a corporation, a coach, etc) else and, as such, present a different set of criteria for assessing validity than self-asserted claims.

There is of course supporting evidence that lends creedence to Kaliya's chosen moniker (her resume, her history of unconferences facilitated, opinions of colleagues, her Canadianness, etc). It would be hard to get all that across to a conference attendee when reading a list of speakers.

Friday, August 25, 2006

There goes my money-back guarantee

Airport security screeners are likely to be on alert after this.

And I'm travelling tomorrow.

Wednesday, August 23, 2006

QR-Codes for personal identity

In a comment to my post on the Identity Card Concept Project, Roger brought to my attention an application of QR-codes for identity.

Currently, QR-codes are typically used to bridge between the real-world and the digital-world, e.g. a user will use a reader in their phone to scan a paper flyer's QR-code with an embedded discount coupon. They can then use that coupon for an electronic purchase. The QR-code prevents them from having to type in some ugly URL printed on the flyer.

A similar application for identity would have a QR-code printed on my business or name card. The QR-code would facilitate the extraction of the identity into digital form without typing, like OCR but with capacity beyond the text actually printed on the card.

Kaywa's identity application of QR-codes, as shown at Roger's identity page, is interesting as the QR-code is displayed on the screen and not on a paper card (although it still could be). Rather than scanning a business card, your potential contact would use their phone scanner to scan the code from either their screen (while reading your blog etc) or your phone (when face-to-face). Scanning the QR-code bridges the "air gap" between two digital channels in a way that microformats etc can't do (but Infrared can, so perhaps an advantage of the QR-code scanning model is the improved privacy from not broadcasting?).

AFAICT, Japan is leading the way with respect to new uses of QR-codes. I know I've seen some very interesting applications for identity on my visits back to the NTT Mothership.

Extra points for decoding this.

TrackMeNot

TrackMeNot is a Firefox extension that clouds your search history to the major engines with multiple fake searches - the "swamp with noise" model for privacy.

Here is the log of some random queries the extension made on my behalf

*** Log started at Wed, 23 Aug 2006 11:00:49 GMT ***
[ACTION] type: saveOptions=true | Wed, 23 Aug 2006 11:00:49 GMT
[QUERY] engine=google | query='user centric' | 200 | Wed, 23 Aug 2006 11:00:50 GMT
[QUERY] engine=google | query='whatis user-centric' | 200 | Wed, 23 Aug 2006 11:00:52GMT
[QUERY] engine=google | query='defn user-centric' | 200 | Wed, 23 Aug 2006 11:00:53 GMT
[QUERY] engine=google | query='consistent defn user-centric' | 200 | Wed, 23 Aug 2006 11:00:54 GMT
[QUERY] engine=google | query='paul madsen' | 200 | Wed, 23 Aug 2006 11:01:03 GMT
[QUERY] engine=google | query='paul madsen' | 200 | Wed, 23 Aug 2006 11:01:04 GMT
[QUERY] engine=google | query='paul madsen' | 200 | Wed, 23 Aug 2006 11:01:05 GMT
[QUERY] engine=google | query='paul madsen' | 200 | Wed, 23 Aug 2006 11:01:06 GMT

[QUERY] engine=google | query='feel insecure' | 200 | Wed, 23 Aug 2006 11:01:07GMT
[QUERY] engine=google | query='paul madsen' | 200 | Wed, 23 Aug 2006 11:01:08 GMT
[QUERY] engine=google | query='ego surf' | 200 | Wed, 23 Aug 2006 11:01:09 GMT
[QUERY] engine=google | query='britney spears' | 200 | Wed, 23 Aug 2006 11:02:02 GMT
[QUERY] engine=google | query='hide searching' | 200 | Wed, 23 Aug 2006 11:03:03 GMT
[QUERY] engine=google | query='identity manage' | 200 | Wed, 23 Aug 2006 11:03:05 GMT

[QUERY] engine=google | query='halle swim' | 200 | Wed, 23 Aug 2006 11:04:06 GMT
[QUERY] engine=google | query='marriage help' | 200 | Wed, 23 Aug 2006 11:04:07 GMT
[QUERY] engine=google | query='data encryption' | 200 | Wed, 23 Aug 2006 11:04:08 GMT
[QUERY] engine=google | query='private eye' | 200 | Wed, 23 Aug 2006 11:04:09GMT
[QUERY] engine=google | query='divorce lawyer' | 200 | Wed, 23 Aug 2006 11:05:03 GMT
[QUERY] engine=google | query='child custody' | 200 | Wed, 23 Aug 2006 11:06:03 GMT
[QUERY] engine=google | query='dating tips' | 200 | Wed, 23 Aug 2006 11:07:03 GMT
[QUERY] engine=google | query='firm abs' | 200 | Wed, 23 Aug 2006 11:07:04 GMT
[QUERY] engine=google | query='viagra ' | 200 | Wed, 23 Aug 2006 11:07:06 GMT
[ACTION] type: showLog=true | Wed, 23 Aug 2006 11:02:24 GMT

Well this isn't going to help.

Tuesday, August 22, 2006

&x;grrl has photos from &x; Summer School

<!ENTITY x "XML">

Eve has a set up.

I swear this was the coolest place in the whole country.

Dave, it's spelled 'B A N F F'

Dave Kearns commends Pam's article on Cardspace whilst deriding her province of residence.

It may just be that the climate in her home town is more conducive to deep thinking (after all, what else is there to do in Alberta?)
The irony is of course that, at any one time, roughly half of the US population is skiing Alberta's hills.

Passport (the other kind) Proxy

From Lifehacker, Make you own Passport proxy.

Proxy or forgery - tough call. Ultimately it would be in the eye of the beholder (the one with the gun who will likely tend to err on the side of a strict definition of validity).

A proxy for Passport, I thought that's what Windows Live ID was?

What fruit are you?

It seems that your 'Fruit Sign' is a new piece of identity that the various identity systems need account for in their profile schemas - or at least Dasani would have it that way.

Regardless of the results, I already know everything I need to know about anybody who actually spends the time taking such a quiz. "Oh my God, you're an Apple, so am I!"

OASIS IPR Rules for Dummies

The deadline by which existing OASIS Technical Committees must move to one of the three allowed IP modes is fast approaching.

I don't think I'm unique in having trouble understanding the differences between RAND, RF on RAND Terms, and RF on Limited Terms. I love to argue but that doesn't make me a lawyer.

I created the following table to help me. As I see it, the two most important parameters are whether or not the patent holder may be able to charge royalties, and whether or not any terms (other than royalties) are left open to possible negotiation between the patent holder and the licenses or explicitly called out. So, at its most basic (and surely glossing over important subtleties), a 2 by 2 table.



Does beg the question, why was RAND on Limited Terms ruled out?

And if you base any real business decision on this interpretation then the title is a good fit ...

Breaking News: I was very proud of this table. At least until I saw OASIS's version. I swear it wasn't there the last time I looked.

People Service Session at IOS

Apache's Ted Leung reports on the Vancouver IOS (I'm late, not him). He had the following to say on the session I led on the Liberty People Service.
When I saw Kaliya Hamlin at Gnomedex, she told me about the Liberty People Service. This is the kind of thing that would be very useful to integrate into Chandler, so I made sure to attend Paul Madsen's session on the People Service. The session was dominated by technical content as people tried to understand how the service actually worked. Despite being unfamiliar with most of the Liberty specs, I found that I had no trouble following the discussion. I spent a year or so doing some consulting on the WS-* web services stack, and that experience made it possible to follow along. I had also read the People Service whitepaper. which probably also helped. I was disappointed to hear that there are no implementations (other than private prototypes) of the People Service that someone could get a hold of and play with. In this day and age, I expect a spec to be accompanied by a reference implementation or something. Maybe I've just been hanging out with the wrong people.

Two comments:

1) I'm glad Ted got something useful out of the session - his criticism of the lack of an implementation is valid, hopefully the emerging Liberty Open Source initiative will address this.

2) I can't believe I looked this confused this early in the session - later sure but I've only drawn a single user at this point and I look stuck.

Axes in Identity Space

I think there must be some sort of law (not an Identity Law) to the effect that 'Any real world complex phenomena/system can only be adequately modelled with 3 or more parameters'. Chaotic systems notwithstanding, it's typically an artificial simplification to force a model into 2 'dimensions' (e.g. Gartner's quadrants).

Identity systems are an example. They are sufficiently complex that to adequately model and differentiate different systems, three 'axes' seems the bare minimum (4 would be better but ...)

These three seem useful:

Axis 1 - Control Mechanimsms - whether the system enables the user with direct (in the flow) or indirect control (through defined policies enforced by a trusted 3rd party) over the release of their identity.

Axis 2 - Relationships - the nature of the relationship (e.g. trust, legal, etc) between the entity releasing some piece of identity and the entity consuming it. DIfferent systems assume different degrees of coupling.

Axis 3 - Identity - the nature of the identity being shared, e.g. is it an identifier for a subject or other less discriminating attributes.



Different identity systems can be plotted against these co-ordinates. As an example, SAML's Web SSO Profile, when using persistent name identifiers and the HTTP Form POST Binding, can be characterized as:

  1. having the identity flow through the user-agent, and thereby enable direct user-control over its release
  2. typically sharing an identifier for the subject and not extra attributes (although possible)
  3. a symmetric relationship between Identity and Service Provider (the IDP 'knows' the SP as well as the opposite)
When you plot the above characteristics onto the proposed 3D identity space above, you end up with (the torus shape is an artifact of the 3D conversion)
Others to follow.

Monday, August 21, 2006

Yahoo! Sign In Seal

Yahoo! has an anti-phishing mechanism called Sign-In Seal.

It's the little badge in the above, the text and colour of which I chose (private joke).

From the FAQ:
What if I don't see my sign-in seal?

You could be on a fraudulent site, but there might be other reasons why you can't see it. For example, someone else using your computer may have deleted or changed your seal, your cookies or files on your computer may have been deleted, or you're using a partner or international Yahoo! site (like BT Yahoo! or Yahoo! India). To be safe, look for these other clues to make sure you're on a genuine Yahoo! sign-in screen.
Given this sort of guidance (essentially "do all those other checks that this mechanism was designed to replace"), a phisher would be crazy to try and simulate a seal, just don't display anything and count on the user being appropriately conditioned by all the valid exceptions listed above.

If Yahoo! had any guts the above guidance would have been 'Play it safe - do not attempt to log-in'.

Identity Card Concept Project

Note: any temporary boost in readership as a result of possible confusion with a frequently searched project dealing with identity and the card metaphor is purely coincidental.

I searched for 'identity card art' (motivated by this and this) and discovered the Identity Card Concept Project an interesting exploration of possible future variations on today's business card - organized into themes of true identity , digital identity, control, memory, ritual, and branding.

Two of the control proposals, the Perforated and Onion Card feel very user-centric, the owner of a business card would be able to customize his/her card in real time to the context (who, what, where, why, when) in which it was being presented.



For the perforated card, each bit of identity could be punched out if inappropriate for a particular recipient. The idea could be taken one step further with some sort of punch table (like for 3-ring binders) that would, upon appropriate configuration (e.g. turn the 'When' lever to 'Friday Night' and the 'Why' lever to 'Dating'), remove all irrelevant identity. People would want to tailor their 'IdentiStampers' (Copyright Pending) to suit their tastes I'm sure.



I found the description of the Onion Card particularly interesting - it paints a picture of negotiation and progressive disclosure - each participant sharing more information as their partner does. A "You show me yours and I'll show you mine" model. It also implies a connection between the physical world in which the card is presented and the digital world in which the identity is stored (and a market for compact bar code readers). I do think the cards would look much cooler if they used QR-codes.

While in the Perforated model the user holds their identity themself (under the mattress as it were); in the Onion Card model they carry only pointers to the identity, the actual data is held elsewhere on their behalf by some trusted 3rd-party and released upon successful request (with the bar codes acting as bearer tokens).