Tuesday, March 27, 2007

What was I about to say?

Short Attention Span System (SASS) does for radio what Cliff's Notes does for literature, condenses.

The value proposition is simple, radio listeners can't pay attention to the epic 4 minute pieces that some artists currently create.

Radio SASS. (Short Attention Span System) takes the playlist and musically condenses songs to their essence. Through time compression, you get the memorable heart of each song, with an average length of aproximately two minutes with NO self indulgent guitar solos, NO long intros, NO repetition of choruses again and again. Radio returns to the snappy song length of the 1960s.


I'd love to see the abbreviated model applied to airline fare rules - an example of which has me currently stumped as to whether I can upgrade or not
Fare rules and restrictions
Please review the rules and restrictions listed below.
When you purchase your ticket, you agree to these rules and restrictions.
Please note that the most restrictive set of rules below applies to your entire itinerary.
1 Rules and restrictions
Air Canada
From: Ottawa, ON (YOW-All Airports)
To: Brussels, Belgium (BRU-All Airports)
Fare Basis Code: Q0MSLWBE

YOWBRU-AC 28MAR07 *RULE DISPLAY* TARIFF 0101 RULE 9422
* ADD APPLICABLE TAX * FED INSP FEES *
-FARE BASIS CAD NUC PTC FT GI
Q0MSLWBE R 940.00 820.76 ADT EX AT
Q0MSLWBE R 960.00 838.23 ADT EX AT
Q0MSLWBE/CH25 R 705.00 615.57 CNN EX AT
Q0MSLWBE/IN25 R 705.00 615.57 INS EX AT
Q0MSLWBE/IN90 R 94.00 82.07 INF EX AT
BOOKING CODES Q
FIRST TRAVEL -12AUG06 LAST TRAVEL -30APR07
LAST TICKETING -30APR07
SEASONS - ORIG BELGIUM 01JAN-12JUN
DEPARTURE FIRST INTERNATIONAL SECTOR
19AUG-15DEC
DEPARTURE FIRST INTERNATIONAL SECTOR
ORIG CANADA
FURTHER RESTR APPLY SEE TEXT RULE
PENALTIES - ORIG CANADA CANCEL-200.00 CAD
CHANGE-200.00 CAD
ORIG AREA 2 CANCEL-100.00 EUR
CHANGE-100.00 EUR
FOR ALL CONDITIONS SEE TEXT RULE
DAY/TIME - TO CANADA FRI THRU SUN ALL DAY
DEPARTURE EACH TRANSATLANTIC SECTOR
FROM CANADA THU THRU SAT ALL DAY
DEPARTURE EACH TRANSATLANTIC SECTOR
ADV RES/TKT - TKTG WITHIN 72 HOURS AFTER RESERVATIONS
WAITLISTING NOT PERMITTED ALL SEGMENTS
MUST BE CONFIRMED
MIN STAY - RETURN FIRST SUNDAY AFTER
DEPARTURE FROM ORIGIN
MAX STAY - 12 MONTHS AFTER DEPARTURE FROM ORIGIN
BLACKOUTS - NO RESTRICTION
SURCHARGES - 10.00 CAD 7.00 USD SECURITY
ADDITIONAL RESTR APPLY SEE TEXT RULE
STOPOVERS - ORIG CANADA
PERMITTED-2 OUTBOUND 1 INBOUND 1 AT
50.00 CAD EACH
DEPARTURE FIRST INTERNATIONAL SECTOR
ORIG BELGIUM
FURTHER RESTR APPLY SEE TEXT RULE
TRANSFERS - UNLIMITED PERMITTED
FLT APPLIC - NO RESTRICTION
CHILD DISC - CNN 2-11 YRS 25 PCT ACCOMPANIED
INS UNDER 2 YRS 25 PCT WITH SEAT
INF UNDER 2 YRS 90 PCT NO SEAT
OTHER DISC - NONE
COMBINABLTY - SEE TEXT RULE
ELIGIBILITY - NO RESTRICTION
ACCOM PSGR - NO RESTRICTION
TRVL RESTR - NO RESTRICTION
SALES RESTR - SEE TEXT RULE
EXTENSION OF TICKET VALIDITY PERMITTED UNDER
GUIDELINES SET FORTH BY CARRIER. CONTACT
CARRIER FOR DETAILS.
NEGOTIATED - NO RESTRICTION
TKT ENDORSE - ORIGINAL TKT - VALID AC TRANSATLATIC ONLY
REISSUED TKT - NON-REF/NON-END
MUST APPEAR IN ENDORSEMENT BOX
APPLICATION - SEE TEXT RULE

Friday, March 23, 2007

You have to feel for the guy

On the Identity Trail reports that 'someone has their identity stolen every 4 seconds'.

They don't provide a name so we can't know for sure what it is that makes this particular individual such an attractive target. Is it just a case of this someone being unusually trusting?

Science is Truly Amazing

Scientists Discover New password in Alaskan Ice

JUNEAU, AK - Alaskan computer scientists are today reporting tentative evidence that they have discovered a new password - extending the number of known unique passwords to 47.

Dr. Peter Lyndstrom and his team of computer scientists at Alaska Tech University have been looking for the so-called 'X password' for 3 years now, using millions of dollars of expensive computer equipment. 'It's been a really long slog', said Dr Lyndstrom 'Sometimes I've even questioned whether the thing actually existed.'

In the end, it wasn't through expensive computers that the new password was discovered. Instead it was good ol' fashioned luck. “We were at a team party and somebody came up with the idea of just sticking existing passwords together, specifically 'm y' onto the end of 'm o m'. And well, after that it just kinda all came together” said team member Gail Svenson. “The frozen daiquiris definitely helped” she added.

Dr Lyndstrom's team is not stopping here. They plan on moving onto variations of the 'first car' theme, historically a rich ground for new passwords but relatively untapped since the car makers trend towards silly names.

Wednesday, March 21, 2007

Putt's Law

Putt's Law was pointed out to me yesterday

Technology is dominated by two types of people: those who understand what they do not manage, and those who manage what they do not understand.

Madsen's Corollary to Putt's Law

Putt's Law applies even when the people of the first type are 'promoted' to become people of the second type.

Just one Number

GrandCentral does for phone numbers what i-names would do for online identity - with the same advantages and risks.

I remember the previous incarnation of the 'Grand Central' identifier - completely different business model. Good thing names can be bought and sold.

Liberty Alliance Advanced Client

The Liberty Alliance Advanced Client specs were actually released for public comment some time ago but the press machine (Hi Russ) has caught up.

Most notable pieces of functionality are IMHO
  1. the over-the-air/wire provisioning of 'root' credentials and other identity into a client
  2. supporting a model of credential presentation in which the IDP need not be involved at run-time (relevant for both privacy value and in support of offline modes)

In the spirit of 'tail-wagging-dog', lots of attention.

I'm thankful Conor wasn't able to slip in his blog URL in his supporting quotes (I guarantee you he would have been thinking about how to do it).

History T'ID'bits

Overheard in Philadelphia

Oh absolutely President Hancock, digital signatures are wonderful technology. But we were actually expecting the old-fashioned ink-and-pen style for the declaration. It's the press you see, they want something nice and visible for the papers.

A says B can do X to Y

Lately, a model whereby some Entity A assigns certain privileges to Entity B with respect to the resources of Entity A is getting lots of discussion.

There are flavours of the above, depending on where the above logic is defined, where it's enforced, and whether all actors are cognizant of what's going on.

If the logic is captured and enforced at the provider hosting the resource in question, then it's a local affair and effectively boils down to an authorization rule at that provider. (Liberty People service is an enabler of this scenario, allowing such local authorization policies to be defined in terms of non-local identities.) In this scenario, even were Entity B to appear at the SP as a result of an SSO from an IDP, that IDP need not be aware of the policy.

If however the resource in question is Entity A's IDP account, then there are potential non-local ramifications should Entity B attempt to use the privileges to access Entity A's resources at other SPs. As an example, if I've specified to my bank that my wife has full access to my account, and that bank account has been federated with other SP accounts (e.g. mutual funds), then 'full access' might mean my wife could access my mutual funds investment account through my bank account if and when she authenticated to the bank.

In this latter case, if the bank IDP creates an assertion for the mutual fund SP that claims my wife is me, that's an impersonation model.

If instead the assertion carries both my wife's identity (even if anonymous) as well as my own and expresses the privileges that have been granted by the latter to the former, then that's delegation.

And of course, depending on the technology, A can always give their credentials to B.

The following lays out these 4 models (the blue dot represents where the 'A says B can do X to Y' rule is enforced.)

I never forget a ...

Of Passfaces, Paul Toal writes
It is common knowledge that the brain can remember images better than anything else.

For myself, better than my ability to remember faces is my ability to remember ways in which I've been slighted - I never forget an insult.

Give me a login system that prompts me to choose particular past snubs from a broad list and I'll never call the Help Desk again. The only difficulty would be in choosing my 'challenge slights' - there are just too many choices, a representative sampling of which is
  • Kindergarten - Eli made fun of my toque.
  • Grade 8 - Keenan mocked my choice of favourite Kiss song.
  • University - Weird Julie claimed I had no physics bona fides in questioning her 'faster than light theory'.
  • Career - Conor (as a category).

History T'ID'bits

Overheard in the Sistine Chapel
Oh yes Maestro, I fully agree that His Holiness stipulated in your contract that you have full artistic control of the project. I am merely suggesting that the sweeping scope and magnificent colours of the work are signature enough, and your blog address in 5ft tall characters might actually be unnecessary? Additionally, I wonder if some of the cardinals might misinterpret the depiction of God reaching out with with His finger to create the URI?

Tuesday, March 20, 2007

Strange Loops

I wanted to try out Highrise - an online contacts manager.

In creating my account, I was given the choice of using an OpenID rather than provide a password. Great! I provided my ProtectNetwork.org OpenID.

After the account was created, I was asked to sign-in.

Saw the normal OpenID screens and redirects etc.

The login failed.

Current situation:
  • I can't use the ProtectNetwork.org OpenID to access Highrise because of above error
  • I can't use another OpenID because Highrise has a record only of the ProtectNetwork one and so refuses to accept another.
  • I can't get in 'locally' because I set up no password at registration time
My huge network of contacts, aching for management, languishes.

Monday, March 19, 2007

History T'ID'bits

Overheard on Tower Green

Yes Mistress Boleyn I do understand that this is not the best time but I'm afraid I have no choice in the matter. It turns out that Lady Seymour is unable to sign-in to the royal account without the password you set. So, it would really make my job much much easier if you could find your way to just writing it down for me. Oh, true, your hands are indeed tied together ... perhaps you might just whisper it then? And, um, the sooner the better I think ...

History T'ID'bits

Overheard on the banks of the Delaware

Yes General, once again I do apologize. I know I promised that you would be able to use the bridge. Unfortunately however the ice has jammed up the card reader for the gate and we're on hold with customer support trying to get a technician out here to get it fixed. Are you absolutely sure there is no other way you can get across?

History T'ID'bits

Overheard under the walls of Troy

C'mon Odysseus, put down the hammer would you? I'm not saying that the horse isn't a really great idea. But maybe, before we spend 3 months building the thing, we could just have a few shots at guessing the password for the gate? I'm thinking 'H E L E N' would be worth a try? or 'H E E L' maybe?

Game as identity analogy

Having just acquired a Sony PSP, I've discovered a new (to me) genre of game.

In both Loco Roco and Mercury Meltdown, you don't directly control a character's movements and actions with the various buttons and joysticks, instead you control the environment that surrounds them. It's by controlling their environment that you indirectly control the character and cause them to move, grab things, expire etc.

In Mercury Meltdown, by tilting floating platforms from side to side, you determine where a shiny blob of mercury rolls. Tilt too much and the blog rolls off the platforms into space - you lose.

In both games the character has no control over its fate - simply rolling passively from one spot to another at the whim and vagaries of its surroundings (the marriage of a 'friend' of mine comes to mind). Whether aware (as in Loco Roco) or not (as in Mercury Meltdown) of their destiny, the main character is manifestly not in charge of it.

These are clearly not user-centric games.

Sunday, March 18, 2007

Live Preview

Microsoft's Jensen Harris posts on the new Live Preview feature in Office 12.

whenever you hover over a formatting option with your mouse cursor, Office shows you what your document would look like if you chose to apply that formatting. For example, say that you drop down the font picker in Word. As you hover over each choice in the font picker, your document updates to show you what it would look like if you chose that font.

Why not apply the model to identity selection in Cardspace?

Hover over a card containing your shipping address and see a video of a package being delivered to your doorstep. Hover over another linked to an IDP with poor security policies and see an animation of a burglar climbing out your window carrying a TV.

Intriguing possibilities for the 'proof of age' card.

Friday, March 16, 2007

Identity sprouts in Brussels

The Liberty Alliance and Internet Identity Workshop (IIW) are organizing another Identity Open Space (IOS) - this time in Brussels.

In preparing for travel to the Liberty meetings directly preceeding the IOS, I must make sure to remember to pack my unconference skepticism (I wonder if Canadian skepticism will work in Belgium or do I need an adaptor?).