Wednesday, June 25, 2008

Cart                   Horse

On visiting a geographically eponymous retailer, was welcomed by

They don't even know why I'm there, why presume to need my postal code?

Idiot

Hearing a song I liked on Sirius Satellite yesterday, I went onto iTunes to buy it. Couldn't find it. Searched on the Web. Nope. Searched music sites. No trace of either artist name or track anywhere.

After about an hour I realized that I had been searching on the text of the message that Sirius used to notify users that the channels had been updated and they could proceed with listening

Sub updated
Press any Key

Once more. Idiot.

The name 'Press Any Key' would be great for a band, except for the fact that, as the string occurs in just about every software/hardware manual out there, the band site would never be found on the Web , flooded into obscurity by false hits.

Tuesday, June 24, 2008

Outsourcing Assurance

HealthVault whitelists two (and only two) OPs.

Liberty Alliance announces Identity Assurance Framework.

What's the connection?

Microsoft whitelisted the Verisign and TrustBearer OPs after (presumably) their own review of the processes and authentication mechanisms of those OPs.

Will this scale if they want to assess other OPs (who will presumably clamor for the chance to assert to a big Microsoft RP)? Not well.

Just as OpenID allows HealthVault to outsource the authentication of users to OPs, Liberty IAF allows HealthVault to outsource the assessment of those same OPs to accredited 3rd parties (or at least provide a common assessment framework should Microsoft want to continue to perform the job)

SHOULD NOT, not MUST NOT

SAML recommends against this, but doesn't rule it out.

Who are we to judge different regulatory domains right?

Pressure

Simon Willison defends HealthVault's choice of OPs.

I disagree. It is I, as a user, that should be able to dictate to HealthVault the OPs from which they are to accept identity assertions through OpenID.

Just as I, as a user of Vista, should be able to dictate to Microsoft which software partners they work with to bundle into the OS (I particularly like the Slow Down to Crawl install).

Just as I, as a Zune user ... oh wait, there are no Zune users....

The mechanism by which I (the user) am able to indicate to HealthVault, or Vista, my preferences for their partners is called 'the market'.

Monday, June 23, 2008

Physician, heal thyself

Microsoft's HealthVault will accept 2 factor based OpenID authentication from an outside OP, but doesn't expect the same level of assurance from its own in-house authentication system.

What are the other factors that somehow balance out the 'assurance equation'?

The SSO protocol used, i.e. OpenID vs LiveID? Identity proofing? Insurance?

Holiday in Amsterdam

Just got my invite for FireEagle.

FireEagle touts its privacy controls, one of which is to allow the user to temporarily hide their location from any and all otherwise authorized applications.


Similar to the 'Break Glass' use case for medical emergencies, this scenario is known as the 'Red Light District Vacation' use case.

Another mechanism allows the user to purge the Yahoo! database of their location info


With respect to the final caveat, why not? This permission page for authorizing Dopplr to access FireEagle makes it clear that applications can both read and write.



So presumably FireEagle itself doesn't expect the applications to themselves offer up endpoints to which FireEagle could send a 'purge' message.

SAML puts users closer to their identity

Pictures don't lie.

Friday, June 20, 2008

Choices Choices

iOptOut is a Canadian service that allows me to manage a personal 'do not call' list.

The Canadian government passed legislation in 2005 mandating the creation of a do-not-call registry. The registry is scheduled to take effect in mid-2008, yet many Canadians may be disappointed to learn about the exemption of a wide range of organizations (registered charities, business with prior relationships, political parties, survey companies, and newspapers). Under the law, exempted organizations are permitted to make unsolicited telephone calls despite the inclusion of the number in the do-not-call registry. However, organizations must remove numbers from their lists if specifically requested to do so.

IOptOut takes advantage of this approach by allowing Canadians to create and manage a personal do-not-call list that begins where do-not-call legislation ends.

Once you create your account, you can pick and choose from categorized lists of services you do not wish to receive calls from



iOptOut then sends an email notification to each organization requesting that your name, email address and phone number(s) be removed from their active marketing lists.

My only objection is that the opposite of 'do not call' is not 'do call', but simply 'I wont hang up if you do call'.

And you thought XRIs created complex identifiers?

Check out the rules for coats of arms

To provide for contrast and visibility, metals (generally lighter tinctures) must never be placed on metals, and colors (generally darker tinctures) must never be placed on colors. Where a charge overlays a partition of the field, the rule does not apply.

The field of a shield in heraldry can be divided into more than one tincture, as can the various heraldic charges. Many coats of arms consist simply of a division of the field into two contrasting tinctures. Since these are considered divisions of a shield the rule of tincture can be ignored. For example, a shield divided azure and gules would be perfectly acceptable. A line of partition may be straight or it may be varied. The variations of partition lines can be wavy, indented, embattled, engrailed, nebuly, or made into myriad other forms.

Two or more coats of arms are often combined in one shield to express inheritance, claims to property, or the occupation of an office. Marshalling can be done in a number of ways, but the principal mode is impalement, which replaced the earlier dimidiation which simply halves the shields of both and sticks them together.

Thursday, June 19, 2008

Cut 'n' paste identity

Travesty

It would be a travesty were this ACM meeting, solely because of geographic distance, to not garner sufficient attendees.

I, for one, will do all that I can to ensure that this travesty does not happen.

Aloha.

Tuesday, June 17, 2008

(Not) the Biggest Drawing in the World

This is brilliant.

Here is my projected summer well-trodden path. You won't need GPS to track me.

For myself


more useful than 'appearing to be in the office while working from home' is appearing to be working from home while working from the cottage.

Liberty Alliance contemplates name change

Focus group studies (an example of which Robin stumbled upon in Sapporo and snapped the below) have determined that 82% of people (if forced to give an answer) prefer the name 'Betsy' to the existing choice.



The 'Veronica Alliance' was also considered but the connotations of promiscuous relationships were deemed incompatible with the organization's exclusive enterprise & eGov focus. Consequently the name is available should another identity organization desire it.

Monday, June 16, 2008

Phishus Interuptus

Where are the points at which you can throw a spanner into the works of a federated phish (fphish?) (that for which OpenID gets attacked but other browser-redirect SSO protocols are vulnerable).

0) in the email app
- this is status quo
1) at the initiating RP?
- the phish presumes the RP is bad.
2) at the client?
- by having sufficient client smarts to either passively recognize (and warn) or actively circumvent (by not allowing the client to be sent to the phish site) a phish
3) at the IDP?
- by the IDP using an authentication mechanism that is phishing proof/resistant, i.e not reliant on a shared secret (Infocard)
- by the IDP using an authentication mechanism that constrains the damage of a phish (OTP)
- by recognizing the presentation of phished credentials (pattern analysis?)
4) at a secondary (authentic) RP?
- by recognizing a federated claim arising from the presentation of phished credentials? Good luck.

My money is on the client.

Friday, June 13, 2008

A Firmo handshake


NTT's Firmo transmits data across the surface of user's skin to let them communicate with electronic devices simply by touching them (or sitting on them I guess).

Firmo consists of a card-sized transmitter that the user would carry. The card would convert stored data (e.g. credentials, personal profile, favourite TV shows, etc) into a weak AC electric field that extends across the body. When the user touches a device or object embedded with a compatible receiver, the electric field is converted back into a data signal that can be read by the receiver. Firmo is based on NTT's RedTacton HAN technology.

Comments

1) I was not involved in the naming of Firmo.
2) The bar scene will never be the same again.
3) NTT Canada (Ottawa Division) not being granted a demo device, I tried to rig up my own version with a car battery and a coathanger wire. Thanks for all your cards, the burns are healing quite nicely.