Tuesday, July 18, 2006

Why not a gramaphone?

It is forbidden to wear head sets connected to a mobile device such as a CD player.
CD player? What percentage of music liseners are playing CDs?

It's time for Air Canada to update their admonishments to reflect current technology.

Friday, July 14, 2006

Tips for Vancouver Travellers

If you are going to Vancouver next week for the Liberty Sponsors meeting or the Identity Open Space, some local knowledge.
  1. Sprinkle 'ehs' liberally throughout your conversation with the Canada Customs officer - as in 'Im just here for an identity conference eh. Beauty eh'. They will appreciate your effort and might even offer you a tour of the 'back rooms' that most tourists don't get to see.
  2. Its 'orrrrnge', not 'or ange'
  3. Canada isn't actually 'the cold Puerto Rico'.
  4. Vancouverite's (and some others) believe their city is the best place in the world to live. They will tell you this over and over. Expect to hear it from the cabbie on the ride from the airport. Expect to hear it from the homeless panhandling for money. When they do, ask them if downtown meets the technical criteria of a rainforest.
  5. Canada has two official languages - Eastern and Western.
  6. To really impress, when you want a coffee ask the Concierge where the nearest "Tim's" is. When at a Tim Horton's, don't fall for the marketing hype and order a flavoured Ice Capp - they are crap and you will regret the waste of your money.
  7. Some stores will take US money at par.
  8. Canadians apologize alot. Sorry about that.
  9. Unfortunately, next week's meetings happen to fall in the middle of the 10 day window in which the league takes a break so you will be unable to see any professional hockey. Even were this not the case you wouldn't be able to see any truly professional hockey in Vancouver.
  10. Gastown offers a complementary 'Dick Hardt Double Decker Bus Tour'. From air conditioned comfort you can see where Dick lives, his favourite coffee shops, and his Porsche dealer. I believe they even have the commentary in different lanaguges e.g. Sxip, SAML, LID etc. A must do.

Wednesday, July 12, 2006

I'm sick of my iPod playlists

I can listen to other people's playlist using Webjay, I should have the same option on my iPod.

Something like:
  1. I upload my library (just the metadata) to a server
  2. I define criteria for a playlist, e.g. # songs, preferred theme
  3. Somebody mixes me a playlist using songs from #1 and meeting criteria of #2
  4. I download said playlist to iTunes where I give it a listen
  5. I bitch about said playlist and question each and every song
  6. I give above feedback to playlist creator for their education, their reputation is adjusted accordingly

Wednesday, July 05, 2006

Litter Kid

My 9 year old son has started a blog.

He gets some money, the neighborhood gets cleaned up a bit, and I get him out of the house for an hour.

He was very excited about his first post. Told his mother that he 'now has a blog' - she told him to clean it up.

Peeps Service - Aldo interviews Conor

Episode 33 of the Story of Digital Identity is up.

Conor, better than anybody, can speak to the design principles and evolution of the Liberty Alliance's identity architectures. Conor's description of Alice & Bob brought back memories of many a whiteboard session.

If you listen closely, you might even hear an opinion sneak through (they'll be the sentences prefaced with 'we'.)

Jibes notwithstanding, I'd have Conor in my Peeps Service anyday (although I expect I'd be selective about who could query that fact).

Friday, June 30, 2006

But can it stop you from blogging?

Which is the greater danger, a single tipsy call to an ex-girlfriend or a ranting blog post that gets syndicated?

Seems there is an opportunity for a social aspect.

Before a post can go live you need to get 2 out of 3 sign-offs from your designated 'review friends'.

The dynamic of a friend saying "C'mon, you don't really want to do this" has saved many a real-world reputation.

Just pick your friends carefully. As always a judicious balance of cautious conservatism and don't give a sh$t would be appropriate.

Wednesday, June 28, 2006

Chillin'

Hubert put me on to MC-DES (mp3)

Can't help but notice he didn't try to rhyme with "modulo". "Yo"?

It's a sad state of affairs that identity has nothing comparable. I'll talk to Snoop.

Out.

PeopleAggregator Authentication Woes

I'm trying to play around with the PeopleAggregator alpha.

PeopleAggregator offers multiple options for logging in.

When I tried to use my mudman.videntity.org OpenID identity I saw this error message from Videntity
openid.mode:error openid.error:Malformed trust_root
No prob, I have others. When I tried my mudman.pip.videntity.org OpenID identity I saw this from Verisign
Application Error - Sorry, it appears that you have found a bug. Our developers have been notified and are at work to correct the situation.
Running out of options, Flickr was next.

When using Flickr, I see a consent message as shown.

So somebody named Test(or is it Phil) wants permission to show me MY pictures?

After giving 'Phil' what he wants I'm successfully logged in.

When I then attempt to modify my PA profile I see the second pic.



But, I used Flickr to log in so that I wouldn't be required to provide a password? Despite the password being indicated as required info for the profile, I was able to save changes.

After logging out, I then tried to log in again using the same Flickr identity. I see



So now it seems I can't delete this profile.

When I created another profile (using a local account name and password) I saw to my surprise that Marc Canter was automatically added as a 'relation' of mine. I have never met Marc so this isn't some incredibly insightful matching engine. This does help to explain why he is already at 126 relations for himself.

Some of these issues have nothing to do with PeopleAggregator. Some are of course because PeopleAggregator is alpha and so will have bugs to be fixed. The interesting ones hilite how difficult it will be to build an experience to explain/convince/assuage the public in Peoria why the fact that they don't have to provide a password is a good thing.

Tuesday, June 27, 2006

Get six-pack ads!

PersonalsTrainer advises the love lorn on how to firm up their personal ads
You know what you want to say, but sometimes the words just don't come out right. We can help. Get a brand-new custom-written profile in your own voice, and see what a difference it can make.
Would this be 3rd party or self-asserted identity?

For phishers with limited HTML skills

The 'View -> Page Source' barrier has kept phishing the domain of the relatively web savvy for too long - now there is WebShot.

Take a screenshot, a little image map magic, and you're in the game.

Sunday, June 25, 2006

Recall of Faulty Identity Selector?

The Inquirer reports on the explosion of a laptop at a 'Japanese conference'.

My source informs me that it was the recent OMA conference in Osaka, it was a meeting on push-to-talk over cellular, and that nobody was hurt.

Rumour has it that the unlucky attendee was using an pre-beta identity selector to share their sushi preferences with a local restaurant.

Friday, June 23, 2006

Personal QR Codes

This blog URL converted into a QR code.

Of course, the conversion tool could be saying anything they want about me. I don't have a phone capable of reading it.

Maybe I could listen to it instead.

Tuesday, June 20, 2006

Cardspace & the local IDP

I've read a number of times (but can't find references) that Microsoft doesn't see the locally hosted IDP as the primary one, but that rather they still expect most identity to come from trusted 3rd party IDPs. I've seen the local IDP described as 'for testing' or 'to get things rolling' etc. Makes sense, self-asserted identity has its limitations.

But, now I see Kim Cameron reference a Mike Beach post (or comment?) with the following

In the privacy space a colleague of my shared an interesting perspective. Most corporations, especially in the B2C space, have considered user/customer identity data to be an asset. Knowledge about their users that could be leveraged for any number of marketing opportunities. With the rising concerns and increasing regulations around privacy this perspective is, or should be, starting to change. This “asset” is now becoming a liability. Data about people (corporate people and consumer people) is always going to be required to do business, but how do we get that while at the same time minimizing liability? Enter the Infocard concept. It would seem we now have a means to establish authoritative data about the user, but give it to the user for safe keeping.
(emphasis mine)
This doesn't jibe with what I know (or misunderstand) of Cardspace.

My interpretation of Mike's description above is that some TTP asserts (and thereby provide the authoritative identity) but the claim then gets cached by Cardspace for later presentation to a RP (the 'give it to the user for safe keeping'). This scenario would appear to be neither the (what I assume to be the default) flow of identity assertion created (at run time) and sent by the trusted 3rd party IDP to Cardspace for forwarding onto the RP, nor a self-assertion created by the local IDP.

Just when I thought I was understanding .....

The Power of Context

Somebody named 'Pamela' left an insightful comment (in addition to that of Gerald) to a previous post of mine on the workings of Microsoft Cardspace.

Without the obvious experience and insight into Cardspace demonstrated by the commenter, I wouldn't have thought to search by combining her name and the qualifier 'identity'.

It's still only a guess but I'm pretty optimistic that the third hit down is the right one.

Adding a Canadian like Pam to Whodentity would skew the North American identity distribution just that little bit more towards the 49th (as was pointed out to me by Dave in a comment to a different post).

Ownership claim mechanisms

A post on the Identity Trail, and my recent experiments with ClaimID's verification mechanism made me think about the general question of "How do I convince somebody that some online resource is mine"?
  • By having the resource in my 'possession' (and the RP having some expectation that such possession is restricted)
  • By making a modification (at the behest of the RP) to the resource
  • By demonstrating my ability to control access to the resource
  • By demonstrating knowledge of some secret associated with the resource
  • By having a trusted 3rd party (or lots of somewhat trusted 3rd parties?) assert to my ownership of the resource
  • By responding to a challenge message sent to the address of the resource
I'm sure there are others.

Related but different, which of the above mechanisms would serve to convince that an identity resource is 'about' me? The second, third and last options would appear to be excluded.

Dial 'N' for NoSig

Jeff Hodges & Scott Cantor have created a proposal for a new SAML Binding - most notable for its optional use of XML Signature.

Jeff's description for the SSTC was
The central thesis is that for various implementation and deployment scenarios, reliance upon XMLdsig is an inhibitor.
I think of this binding as the SAML community turning down the security dials on the protocols (or more accurately ensuring that they can be turned down in an interoperable manner) - lower settings appropriate in some situations.

I don't know just how much effort was expanded by Scott & Jeff on this work - I do know that far more would have been required to be "adding" security at this point.

As is true for haircuts - you get into trouble if you take too much off the first time.

UPDATE - Pete Rowley reminds me that hair grows back. Pete, you obviously have a fine head of hair - I myself am working through what my wife refers to as a 'Kramer period'. Nevertheless, I think we should remain sensitive to the security entitlements of those less fortunate than ourselves.

And with respect to my hairdressing ambitions, I worked through those in my university days cutting my own hair in the mirror to save beer money. As for identity, sometimes its better to delegate to a professional.

Monday, June 19, 2006

A protocol for the people

Pete Rowley presents a nice pithy descriptor for user-centric identity - based on the idea that the prime (sole?) criteria for an identity flow to warrant the term is that it occur 'through' the user - and so Pete suggests 'people in the protocol'.

Works for me. This is consistent with a taxonomy that some Liberty folks have been bandying about - as shown in the diagram.

The idea is that such user-mediated flows are a subset of a broader category in which the user will still have the ability to specify policy and preferences for how their identity is shared, but would not directly mediate any such sharing. Identity would flow by some other route than through the user, but still determined (at least partially) by the user's own policies. In the diagram, these deployments are labelled as "user-controlled" to capture this different level of control compared to the user-centric case.

Such user-controlled scenarios are themselves a subset of more general user-consented scenarios in which the user may not be given the option for specifying their own policies for how their identity is shared - enterprise use cases being an example. Although the user may not be in control, the assumption is that they have still been given the opportunity to give their consent, even if only through their signature on their employment contract.

Additionally:

- User-centric (as typified by the channel by which identity flows) enables but does not guarantee that the user have the final say on the sharing of their identity. I'm sure that enterprise deployments of Cardspace will support administrative policy that will override any preferences the employee user might have over what cards get presented to which RPs.

- Some identity architectures support only the user-centric flows, and do not allow for the user-controlled flows. But many important identity use cases have one of both subjects offline and thereby unavailable to act as a conduit for the flow of their identity. Does the world stop when I'm not sitting in front of a browser?

- User-centric flows are often described as decoupling the RP and the IDP, and thereby supporting cases where neither need 'know' the other beforehand - this leading to 'scale'. While true in principle, in practice there are lots of other factors pushing the two providers towards each other (such as the realities of risk management) that are independent of the specific channel by which the identity flows. So, if the nature of the shared identity or the value of the transaction doesn't require/imply that the two providers 'know' each other, then it can make sense to share identity through a provider-obfuscating user-centric flow. If not, then the value of the user-mediation is diminished.

Any club that would have me ...

Would you link to a list of purported notables that excluded you? Me neither.

Notwithstanding the few exceptions, the geographic weighting of the list makes me hope that the rest of the world will be happy with the identity systems the States provide us.

Separately, it would be interesting to see the relationships (e.g. corporate partnerships, shared specification development, farm equipment riding, etc) that exist between the list members captured and then visualized.

What topoology does identerati space have? To what extent do these relationships (postive and/or negative) impact identity progress?

Friday, June 16, 2006

Top 10 quotes about authority

10) "Authority without wisdom is like a heavy ax without an edge, fitter to bruise than polish" - Anne Bradstreet

9) "Authority is quite degarding" - Oscar Wilde

8) "“There will never be a really free and enlightened State until the State comes to recognize the individual as a higher and independent power, from which all its own power and authority are derived, and treats him accordingly”" - Henry David Thoreau

7) "The ultimate authority must always rest with the individual's own reason and critical analysis." - Dalai Lama

6) "We know, on the authority of Moses, that longer than six thousand years the world did not exist" - Martin Luther

5) "When you make your peace with authority, you become authority." - Jim Morrison

4) "Anyone who conducts an argument by appealing to authority is not using his intelligence; he is just using his memory" - Leonardo Da Vinci

3) "No statement should be believed because it is made by an authority" - Robert Heinlein

2) "All authority belongs to the people" - Thomas Jefferson

and the #1 quote about authority is ...

1) "“To punish me for my contempt for authority, fate made me an authority myself.”" - Albert Einstein