Saturday, February 17, 2007

rfi User-Centric Identity and What Mark Wahl Said

All:


Full Q&A, followed by not-so-kwik comment:

*************************

Is user-centric identity primarily a B2C requirement, or does it have applicability in the B2B world and inside the enterprise?

I believe there is definitely a role for 'user-centric-style'
operations within the enterprise, as identity management
functions and services decentralize to the workgroup.


What standards are being developed in this space, and/or how are older standards (e.g., Liberty ID-WSF, if you can call that "old") being applied to these requirements?

There is a lot of innovation going on in this space and I think it's a
little too early to nail down specifications for user-centric
identity as 'standards' - perhaps in a year or two we'll see standards
for user-centric that have value and are seeing deployment in the
enterprise deployments of IdM. Certainly also many existing identity
management standards are continuing to be evolved to address some of
the requirements that drove the user-centric pioneers.

How can user-centric identity and federated identity management coexist and complement each other?

That's too big a question for just this email!

How soon can we expect to see user-centric identity architectures baked into the leading IdM vendors' software suites?

I think that user-centric identity needs to prove itself in enterprise
deployments. If the early adopter phase shows promise that user-centric
services open new market opportunities, the suite vendors will, as many
times before, make build-vs-buy decisions to add these capabilities to
their suites.

How soon before we see user-centric identity environments enjoy the mainstream enterprise acceptance, adoption, and interoperability now found with SAML?

It's too early to tell. I'd say 2-5 years as a rough guess

Does Microsoft have an early-mover advantage with CardSpace in Vista, or is it far too early to pronounce "winners" in this fast-evolving space?

I think that Microsoft has a definite advantage in CardSpace.

What significant/serious interoperability, deployment, trust, security, usability, and other challenges do implementers face when implementing user-centric identity?

Yes, all of the above :-). I discuss some of these challenges on my
blog on ldap.com; for example,


http://www.ldap.com/1/commentary/wahl/20070206_01.shtml
"How is the relationship between an Identity Provider (IDP) and a
Relying Party (RP) established and maintained?"

http://www.ldap.com/1/commentary/wahl/20070206_02.shtml
"Identity relationship management"

http://www.ldap.com/1/commentary/wahl/20060926_01.shtml
"Social engineering: trust is just a five-letter word"

http://www.ldap.com/1/commentary/wahl/20060920_01.shtml
"PKI and the risks to importing a managed card"

http://www.ldap.com/1/commentary/wahl/20060911_02.shtml
"Key management concern for the InfoCard regions of an identity metasystem"

http://www.ldap.com/1/commentary/wahl/20050103_01.shtml
"Identity systems without discovery or public entities"

etc. I plan to write more on the topics of audit and controls on
integrating user-centric services into the enterprise, and on
managing the relationships between a user's identity and the components
of a decentralized enterprise IdM deployment.

*************************

Follow Mark’s links…very fascinating discussion of the trust management challenges that may impede user-centric IdM from becoming internet-scalable in B2B environments….in other words, the same devilish details that continue to dog SAML/Liberty-style federated identity.

Note specifically his discussion of Mike Neuenschwander’s Law of Relational Risk…in reference to which Mike proposes “a kind of ‘SSL’ sessions for relationships - for now I'll call it Relational Continuity Sockets Layer. It would allow multiple participants to interact on a channel that is secure for the duration of the relationship or at least one risk cycle (this means longer-lived sessions than SSL) and allows for relation IDs (similar to session IDs). Such an invention would also address the requirements of addressable relations... “

Relation IDs? Issued by the involved parties, or trusted third parties (TTPs)? If you follow the link to Mike’s blog posting, you can see that it practically screams for one or more TTPs to vouch for the good reputation/behavior of participants in a (user-centric and/or traditional federated) IdM interaction, and possibly to see to it that appropriate sanctions are applied in cases of bad behavior. Per Mike’s post: “As a means of promoting relational continuity, for example, the principles suggest that issuance of IDs to participants is only a partial solution. Relations must be addressable resources separate from the actors involved. Further, each relation needs a definition of roles—symmetrically formed—that embody equilibrium for participants. And there must be rules stipulating that participants can't leave a relation without either settling all one’s outstanding transactions or designating a proxy. And finally, as participants fill roles in the relation, they receive those rights by recognition of the participants (and not simply by issuance of an ID).”

All of this sounds like a convoluted way of saying a common trust environment and legal systems are needed to keep everybody on the straight and narrow. What could be more symmetric than a society that is ruled by impartial laws, rather than (asymmetrically) by dictators? Good governance: that's the equilibrium condition for any social environment. What Mike is talking about is a trust/legal system that enforces levels of identity assurance that strongly bind actions to consequences. I think everybody can agree that these assurance levels are as necessary in user-centric IdM (B2C or what have you) and in federated IdM.

All of which puts me in mind of a convoluted identity assurance model that I myself developed in late 2005 and published in 2006. This is written from the top-down, spelling out the complete set of credentials, assertions, claims, vouchers, and policy and practice statements that the involved users, IdPs, SP/RPs, and TTPs would need to publish/exchange in a global trust environment, thereby thoroughly binding all user actions to real (penal/financial/social) consequences. Unlike Mike’s model, it’s not focused on person-to-person relationships (a la user-centric identity and reputation systems) but the “person-to-authority” (e.g., IdP, PKI CA, etc.) relationship, per traditional federated IdM. So take it with a grain of salt.

Anyway, each level in the following chain of identity assurances associates the actions that a user takes in an online session with the consequences of those actions:

IDENTITY ASSURANCE FACTORS

REQUIREMENTS

Assurance of association between an online session and a credential

This requires client-signed session assertions, signed cookies, or other means for strongly binding an online session to a credential under which a user logged into that session. In turn, client-signed session assertions or cookies require PKI X.509 end-entity digital signature certificates and private keys. All that, in turn, requires strong PKI assurance.

Assurance of association between a credential and a digital identity

This requires PKI X.509 end-entity identity certificates, which cryptographically bind an identity’s private identity key to the corresponding public key, and to a unique identifier such as UPN, X.500 DN, or UPN.

Assurance of association between a digital identity and a real person

This requires PKI registration authorities to issue and renew X.509 end-entity certificates only after in-person proofing/vetting that involves having a real person present a government-issued picture ID and other supporting identifying documentation. It also requires that the request for registration or renewal of a PKI certificate/token obtain all necessary administrative approvals within the IDP that has issued the unique identifier that will (upon certificate issuance) be cryptographically bound to a public key (published in the certificate) and a private key (to which only that real person will have authorized access). In addition, provisioning of certificates to proofed users should only follow user authentication to the CA through entry of a one-time secret proofing passcode provided at proofing time by a trusted agent of the CA.

Assurance of association between a real person and an IdP

This requires that the IdP that issued the unique identifier published in the real person’s end-entity PKI certificates maintain that identifier in a published master directory administered and controlled by the IdP. The IDP’s master directory must securely and reliably synchronize, replicate, and/or publish that master identity information to other directories and repositories, or vouch via SAML authentication or attribute assertions for its continued registration in the master directory. In addition, the IdP must use identity information in that master directory to drive the automated provisioning and deprovisioning of accounts associated with real persons.

Assurance of association between an IdP and an IdP-asserted federated identity policy/practice statement

This requires that IdPs digitally sign any federated identity policy/practice statement that they assert with a digital signing private key held by an authorized corporate officer.

Assurance of association between an IdP-asserted federated identity policy/practice statement and a TTP-published federated identity policy/practice statement

This requires that one or more TTPs develop and publish standard federated identity policy/practice statement formats. It also requires that TTPs investigate, vet, and certify equivalence or conformance between an IdP-asserted federated identity policy/practice statement and a TTP-published federated identity policy/practice statement.

Assurance of association between a TTP-published federated identity policy/practice statement and TTP-vouched observation of identity’s demonstrated compliance with norms of IdM “best practice”

This requires that one or more TTPs track, monitor, and audit real people’s online behavior. It also requires that TTPs determine the degree to which that behavior conforms to the norms of IdM best practice that they and their IdPs have pledged to comply with, in the form of published federated identity policy/practice statement.

You can chain together symmetric person-to-person assurances, under my model, as a transitive linking of asymmetric person-to-authority assurances. In other words, you and I cannot exploit our common relationship because a TTP is cracking the same whip over us all.

Or something to the effect. All of which brings me back to a question I’ve been formulating: In user-centric identity environments, how do personal/private IdPs symmetrically federate to each other, in the absence of (one or more) TTP(s) to vouch for their respective good reputations/behaviors?

Jim



rfi User-Centric Identity and What Johannes Ernst Said

All:

Full Q&A follows:

***************************

How do you do define user-centric identity?

I like to distinguish two forms:

In the 'weak form', identity information about me continues to be
collected and maintained by third parties ("IdP companies") and I, as
the user, have a big say in whether or not I want that information be
transmitted to another party ("Relying Party"). This is an
improvement over the state of the art, where the IdP and the RP
company get together and decide what to do with my identity
information without me being in the loop.

A real-world example of this would be for me to decide whether or not
to take out my AA frequent flyer membership card to get a 5% discount
at Hertz.

In the 'strong form', I assert my identity information myself, and
I'm my own IdP (although I might outsource the technical details of
how to do that to a service provider). A Relying Party may use other
parties to corroborate what I said about myself, e.g. ask the state
government whether I'm indeed a licensed nurse, or ask a reputation
service about how likely it is that I'm a spammer.

The latter, Doc Searls called "independent, sovereign identity".

A real-world example of this would be me handing you my business
card. Or me writing something on Wikipedia, with you being able to
check how many other edits I made and how often I was "reverted".

Interestingly enough, and while they don't map seamlessly, URL-based
identity maps more to the 'strong form', while card-based identity
maps more to the 'weak form'.

Is user-centric identity primarily a B2C requirement, or does it have applicability in the B2B world and inside the enterprise?

It absolutely has enterprise applications. One example that one of
our customers pointed out to us: while much information about
employees is maintained by enterprises in places like corporate
directories (whether the employee likes that or not), other identity
information that is relevant to business often is not. For example:
cell phone numbers. Instead, employees want to keep control over when
to hand out their cell phone numbers and to whom. The same thing
might be true about instant messaging handles, presence status,
current location in the building, schedule, etc. etc.

What standards are being developed in this space, and/or how are older standards (e.g., Liberty ID-WSF, if you can call that "old") being applied to these requirements?

Many technologies can be applied to this field, and they probably
are. But in my view, the problem is one of distribution, not of
technology. The early boost here was LiveJournal, which gave OpenID
instant distribution to millions of people, which caused a virtuous
cycle that continues unabated. And then, of course, there is Windows
Vista and its distribution. Other technologies / standards / products
don't necessarily have the same distribution dynamics.

One thing that plays into this is the "weight" of the technology.
When we invented URL-based identity at NetMesh over 2 years ago, we
consciously called it "Light-Weight Identity". Because in our view,
only technology that's sufficiently low-cost (in total cost of using
it, not just software cost) has a chance of mass distribution, and
that's one of the reasons why so many sites have found it easy to
adopt OpenID and not so easy to adopt other technologies.

How can user-centric identity and federated identity management coexist and complement each other?

The key battle here will be at the boundary of the enterprise, where
self-empowered users (customers, contractors, partners, employees)
want to "bring their identity" and companies need to support this,
otherwise users (particularly customers) will go to a different
company that serves them as they want to be served. THe challenge is
to keep what's working inside the company, but allow for external
sources of identity via user-centric technologies / processes as
well; this will take some years to be figured out because it is
rather complex, but it certainly will get solved.

Certainly that is one of the recurring discussions we have at NetMesh
with enterprise adopters.

How soon can we expect to see user-centric identity architectures baked into the leading IdM vendors' software suites?

I would defer to those "leading IdM vendors" to answer that ;-)

How soon before we see user-centric identity environments enjoy the mainstream enterprise acceptance, adoption, and interoperability now found with SAML?

Interoperability in the OpenID world is excellent. There are dozens
of independent identity providers, dozens of independent software
implementations, and hundreds of relying parties: the reports of
interoperability problems are few and far between. (Somewhat to my
surprise, I have to admit). Note that all of this works without any
formal certification regime or even a shared test suite.

My understanding is that out-of-the-box interop of more traditional
identity products is something that happens less frequently.

The best guess for the OpenID growth rate right now is 5% per week
with about 1000 relying parties at this point, so you can do the math
when ubiquity arrives ...

Does Microsoft have an early-mover advantage with CardSpace in Vista, or is it far too early to pronounce "winners" in this fast-evolving space?

Far too early. Looking backward from a few years in the future, it is
very likely that we will say that in 2006, most people still thought
the product was "identity management software" and its hosted
equivalent. But now that virtually "everybody" in technology (see
membership list in OSIS) is working real hard to make the basic user-
centric identity layer free on the internet, the question about
winners and losers will be decided on a layer above or below that
free layer. As an industry, today we all have only very rudimentary
understanding what those layers even are. So it's too early to
declare even who the contenders are, never mind the winners!

Microsoft will clearly play an important role, as will websites with
a mass audience, and big enterprise vendors. But personally I would
bet on startups -- many new appealing business models are emerging
that appear incompatible with traditional technology business models,
and that gives startups an unfair advantage against the incumbents.

What significant/serious interoperability, deployment, trust, security, usability, and other challenges do implementers face when implementing user-centric identity?

I'm not quite sure I can give you an exhaustive list here. Some of
them probable include:
- the market is immature, and there is still more slideware and
beta software around than technology that has been proven
- as a whole, we don't know yet what the attack vectors of the bad
guys will be because the bad guys haven't really started attacking yet
- many pieces of technology are missing -- e.g. see James
McGovern's recent push for XACML-related things in an OpenID context
- the business ecosystem isn't there either -- e.g. how does an IdP
get compensated for taking on authentication risk?

However, what we're seeing clearly at NetMesh is that many leading
companies in their market realize that in spite of this, they have to
move very quickly to make their play, because there is a huge
economic network effect associated with user-centric identity, and
they can't afford to let their competitors benefit from that one
first, even if many answers don't exist yet. The vendors and the
adopters are learning together ... nothing wrong with that either.

So in spite of many obstacles, companies are moving, and quite fast
at that.

To what extent and at what speed are the URL-based schemes (OpenID, LID, iNames/XRI, mIDm, Yadis, etc.) converging into a single standard/framework?

On mIDm, I don't know whether that is an ongoing project.

All others have effectively converged into the same framework since we all adopted Yadis a year ago (which in itself was a combination of the discovery pieces of XRI, LID and OpenID).

There are lots of different pieces advocated by different people on top of that same framework, many of which are competing. But that's a feature, not a bug: it allows many parties to innovate and solve problems really well for those parts of the market that they play in, and it does not limit the market to whatever one particular approach can accomplish. As particular pieces become well-understood and broadly deployed -- as it happened with Diffie-Hellman-base, browser-based Authentication -- I expect those to be supported by everybody. This kind of higher-level convergence will happen faster for some and slower for others and never for some (e.g. vertical-specific services).

So I expect the XRI folks to continue doing things that won't be adopted by everybody in the OpenID community, just like we at NetMesh continue to have (and build more) service types under the LID umbrella that not everybody in the OpenID community relates to.

To what extent will self-asserted IdPs (which I believe is also supported in CardSpace) eliminate the need for traditional (multi-user/ID) IdPs?

There will always be a need for third parties to make statements about somebody else. For example, it is unlikely a shop keeper will sell me that bottle of Gin based on my self-assertion that I'm above drinking age but don't look it.

But how exactly that is done is a matter of ongoing dispute. I could show my driver's license (basically the CardSpace model). Or, I could create cryptographic proof that I'm above drinking age without you learning how old I am, nor the government learning that I bought booze (the Credentica model). Or, I could bring a thousand people who all say that I'm above drinking age (the "wisdom of crowds" model). Or, I could give the merchant permission to ask the government in real-time, either directly or routed through me (the "3rd-party confirmation model" that has the advantage that it works for information changing in real-time).

As these examples show, some of them map to the "traditional IdP" model. Others only sort-of, and some not at all (the "Wisdom of crowds model"). I expect the majority of the market growth to come from non-traditional models, although timing would be a conjecture ...

To what extent will companies allow their employees to selectively conceal privacy-sensitive attibutes (e..g, cellphone number, presence, location in building) when the trend has been toward tighter company monitoring of e-mail, IM, etc.?

Well, that highly depends on the company. If a company's success depends on their people making maximum use of their intellectual and social resources, then getting in the way of how people want to deploy those resources is not a particularly wise business decision. And the reverse is probably true as well.


**************************

Per what Johannes said, the "distribution" and "weight" of user-centric identity technologies will determine whether, when, and how they dominate the IdM space in coming years.

Federated IdM--a la SAML and Liberty Alliance--have gone mainstream, but they're still climbing the implementation curve. They're not widely distributed in the B2C sphere because they're heavyweight to implement (i.e., to set up the requisite interoperability, trust, and implementation agreements).

I spend a year in the wilderness working with a B2B trading community trying to kickstart federation (just for cross-domain SSO) by setting up multilateral, transitive trust relationships that passed muster with all the requisite regulators, lawyers, and beancounters--and, I can tell you, it was painful.

Perhaps portal-initiated SSO (the core federated IdM use case) is just not an "internet-scalable IdM" arrangement (per an excellent whitepaper recently authored by Ping Identity). Maybe RP-initiated multiple sign on (MSO)--the core user-centric ID use case--is the way to go. Just assume that SSO is too heavyweight for dynamic, Internet-scale IdM (be it B2C or B2B). Instead, give the user the tools (e.g, identity card selectors etc.) to make their MSO experience more convenient, secure, and standardized.

Jim


Wednesday, February 14, 2007

rfi User-Centric Identity and Specific Interview Questions

All:

I'd like to get your thoughts on the matter, specifically:
  • How do you do define user-centric identity?
  • Is user-centric identity primarily a B2C requirement, or does it have applicability in the B2B world and inside the enterprise?
  • What standards are being developed in this space, and/or how are older standards (e.g., Liberty ID-WSF, if you can call that "old") being applied to these requirements?
  • How can user-centric identity and federated identity management coexist and complement each other?
  • How soon can we expect to see user-centric identity architectures baked into the leading IdM vendors' software suites?
  • How soon before we see user-centric identity environments enjoy the mainstream enterprise acceptance, adoption, and interoperability now found with SAML?
  • Does Microsoft have an early-mover advantage with CardSpace in Vista, or is it far too early to pronounce "winners" in this fast-evolving space?
  • What significant/serious interoperability, deployment, trust, security, usability, and other challenges do implementers face when implementing user-centric identity?
Contact me at james_kobielus@hotmail.com if you're interested in responding.

Thanks.

Jim

Tuesday, February 13, 2007

rfi User-Centric Identity and the Definition of User-Centric Identity

All:

I've just been crawling through the blogosphere, the literature, my head, etc.....putting together a quick cheatsheet, definition-wise.

In some radical/fundamental/ideal sense, user-centric identity could conceivably mean any and/or all of the following:
  • All user identities/attributes are self-asserted and provisioned
  • All user identity interactions flow through the user's client, icard space, personal idp, and/or agent
  • All user identities/attributes are immediately, conveniently, and visually available to the user from all clients/UIs to present to the appropriate relying parties
  • All user identities/attributes are self-selected within the context of each interaction
  • All user identity-based interactions are engaged in by the user with full knowledge, transparency, and nonrepudiation of the relying parties
  • All user attribute disclosures require permission of the user and/or the user's authorized agent
  • All user identity interactions contribute to the user's privacy
  • All user attribute disclosures are anonymized, encrypted, pseudonymized, and/or minimized in each interaction
  • All user identities/attributes are disclosed and distributed in such a way that they cannot be joined or correlated back to the user
  • All user identities/attributes are stored locally under the user's control and protected through secret keys that only the user possesses and which are authenticated through multiple factors, including biometric
This list pretty much recapitulates Cameron's laws of identity. Just working through the analysis from a slightly different pov.

Jim

Monday, February 12, 2007

rfi User-Centric Identity and the Enterprise Market

All:

Re my message a moment ago to Sandy, from whom I never need to request interaction, because she's always beating me to the punch:

***********************

Sandy:

Thanks.

Re your question: "How likely is it (technically, not sociologically) they
will find something (desktop with Vista? Internet portal? freewares you
mention or ?) that works well at home and that they will then take to work,
or take the demand for it to work?"

My tentative, hedging, heavily qualified response:

It's 50-50 likely.

In other words, look at various now-ubiquitous business clients/tools/apps
that got their initial commercial push (to a degree) in the B2C space (e.g.,
the Web, Internet e-mail, e-commerce, cellphones, WiFi, instant messaging,
VoIP, social networking) and then penetrated the enterprise (intranet, B2B,
etc.) market in a (big, medium, or small-but-growing) way (we could easily
debate which demand-side driver, B2C or enterprise, had the first-push in
each of these segments, but it's undeniable that the B2C acceptance was
fairly strong from the start in all of them).

Now look at the identity management space--in which, B2C-wise, trusty ol'
username/password still rules, and in which federation (SAML, Liberty, etc),
is still not a major force, but in which the enterprise/B2B demand-side has
been the dominant driver for federation.

Now look at "user-centric identity" as an IdM approach that's originating on
the B2C side, not so much as an alternative to federation but as a sort of
adjunct that will eventually converge with federation if/when user-centric
identity penetrates (to varying degrees) the enterprise market.
Enterprises are not generally "user-centric," where their employees are
concerned.

Instead, enterprises are "company-centric," with a strong bias/inclination
toward "owning" their employees' identities/credentials/attributes and
controlling them tightly.

In other words, enterprises (i.e., IdPs run by your employer) provision you
your identity, and reserve the right to deprovision it.

This is the opposite paradigm from the radical "I issue, own, and manage my
own identity" ethos/ideology that motivates many folks developing the
"user-centric identity" space.

Bottom line: Employees will demand user-centric identity from their
organizations as a tool for managing the diverse identities (e.g., roles)
that they play with respect to those organizations (e.g., formal job
description role, plus roles specific to each solid-line and/or dotted-line
reporting relationship, plus roles specific to various projects/teams in
which I participate for this company). User-centric
business-role-multiplicity management.

Or something less wordy. I'm working on it.

Jim

***********************

Your words welcome: james_kobielus@hotmail.com.

Jim

Saturday, February 10, 2007

rfi User-Centric Identity and the Convergence of Paradigms

All:

Carrying forward this request for interaction (thanks, Bob...I'll contact you shortly, and thanks Andre, for yesterday, and for those couple of days in early December 2004...and Craig Burton, wherever you are....ironic to finally meet you at that particular point in my life...).

One thought that's occurred to me is that this new focus on "user-centric identity" is a bit of 2001-2002 redux. Early in this decade, when the topic of identity management (IdM) was just heating up, the industry was grappling with the issue of Microsoft-uber-alles (Passport, i.e., identity aggregation) versus uber-our-dead-bodies (SAML, Liberty Alliance, etc., i.e., identity federation). Now, here in 2006-2007, it's once again Microsoft (taking the lead, implementation-wise, in this new twist, user-centric identity, with another bold initiative, CardSpace, that's a bit ahead of the eventual standards, and may or may not be the ultimate approach that Microsoft and others settle on when the industry dust clears in, let's say, 2013) versus the rest of the industry (e.g., Higgins, Bandit, OpenID, Yadis, OSIS, LiD, iNames, mIDm, SXIP, etc.).

But, of course, the "versus" is a softer, more collegial thing this time around, considering that Microsoft has just declared (through the still somehow in the game though he sorta said he was retiring Bill Gates) that it will implement OpenID 2.0 in CardSpace...and Kim Cameron being just about the most hyper-collegial human on the planet. Close to 2 years after they were more or less finalized, Kim's "identity laws" and "identity metasystem" are still the most concise definition of what's come to be known as "user-centric identity." And they are a seminal statement of the core principles that have driven the work that many people are doing around the world in this very exciting new branch of the IdM space.

Trying to get my own head around the rapid evolution that's taking place in the IdM space, it appears that three paradigms are jostling for dominance, or at least harmonious convergence, in the emergence of user-centric identity:
  • URL-based identity: This is founded on the notion that users have the ability to provision their identity as a URL/URI construct. Drummond Reed , Cordance, and the XRI community kickstarted this notion with their i-numbers/i-names, and people such as Johannes Ernst of NetMesh, pushed it forward with LID, and now we have OpenID, Yadis, and other projects that are developing it into a potentially universal infrastructure.
  • iCard-based identity: This is founded on the notion that users have the ability to present the identity (and user-selected credentials/attributes thereof) that works best for them in the context of an interaction, to a relying party, in the form of a standard structure known as an iCard. The primary example of this is CardSpace.
  • Assertion/claims-based identity: This is founded on the notion that users have the ability to request, upon successful authentication, that their identity provider (authentication authority and attribute authority) present their identity (and IdP and/or user-selected credentials/attributes thereof), in standards-based assertion/claim structures, to relying parties under established trust relationships (IdP-to-RP). The primary example of this is Liberty Alliance ID-WSF 2.0 (if memory serves).
From what I can see, Liberty ID-WSF's primary use case--"permission-based attribute sharing"--is also the primary use case for the new "user-centric identity" space as well. That, plus "privacy protection," "anti-phishing protection," "IdP discovery," and "identity self-provisioning." In other words, the agenda items that the SAML and Liberty specs developers discussed to varying degrees but, quite rightly, decided to defer to a later date (and to latter-day developers) rather than bog down their core 2001-2002-2003-2004 agenda.

That's a huge cool new exhausting exhaustive scope. All of it is quite orthogonal to the core, mainstream federated identity use case that has driven SAML/Liberty to pre-eminence: "cross-domain single sign-on." Also, from what I can see, the new URL-based and iCard-based approaches are orthogonal to SAML in that they rely on REST approaches (URLs, HTTP, etc.) whereas SAML, Liberty, WS-Federation rely on SOA approaches (XML, WSDL, SOAP, etc.).

Or perhaps those are overstatements. Or wrongheaded generalizations. The tendentious ramblings of an old guy who has far too much memory, and perhaps needs to unlearn various things in order to stay fresh.

You tell me: james_kobielus@hotmail.com.

Jim

Thursday, February 08, 2007

rfi User-Centric Identity article for Business Communications Review

All:

Hi. I'm back. I've been giving the blog a relative rest for the past several months for various unimportant reasons.

These past few years, I've been following the frenetic industry activity surrounding user-centric identity, including the announcements at this week's RSA Security Conference. Especially Microsoft's commitment to converging CardSpace with OpenID.

Just a few days ago, one of my fondest professional associates--Sandy Borthick of Business Communications Review--contacted me and asked for an article on user-centric identity for BCR's May issue. I love Sandy for many unimportant reasons, one of them being that she drops juicy topics in my lap, and lets me develop them as I see fit. I try not to disappoint (case in point: the piece on Master Data Management in this month's issue, leveraging the MDM maturity model I'm developing in my main gig, as Principal Analyst at Current Analysis).

Anyway, this BCR piece is, of course, a freelance assignment that doesn't have much direct relationship with my core coverage areas at Current Analysis (though lotsa folks know that I covered federated identity management and tons of other stuff in my Burton Group days, so it's not that huge of a stretch for me....a dirty little secret about Jim Kobielus is that I never stop covering anything that I covered at one point in my career...for me, everything's a cumulative building process....I'm synthesizing all of this old and new stuff in my head at all times....I'm a "synthesist" (putting things together) as well as an "analyst" (pulling them apart)....a fact that some people fail to comprehend...but they need to). My life, my career, is one big crazy mash-up.

Anyway, enough about me and more about YOU. Or, more to the point, anybody in the user-centric identity community (OpenId, Higgins, Bandit, LiD, OSIS, CardSpace, SXIP, Yadis, Identity Commons, OpenXRI, iNames, Passel, mIDM, Liberty ID-WSF, etc.) who'd like to share their thoughts with me...I'd like to speak with you. Just to keep this all from impinging on my main gig, just send me a quick e-mail to james_kobielus@hotmail.com to open up discussions. I want to speak with you at a time convenient for us both (preferably evenings and weekends, the way I've been managing my freelance work in the 20+ years I've spent in this industry---god i'm old). I'll contact several of you under my own initiative.

But I'm putting out this all-points "request for interaction" to the user-centric identity community. The BCR piece won't be hugely long, and it won't necessarily break any new ground. You folks, collectively, are doing a wonderful job developing this promising new realm of the IdM universe. I just want to get my arms around it all. Communicate it all clearly to BCR's readers.

And press it deeper into my main groove.

Jim

Tuesday, January 16, 2007

fyi Inside MySpace.com

All:

Found content: http://www.baselinemag.com/article2/0,1540,2082921,00.asp?kc=BLBLBEMNL011607EOAD

My take:

This is one of the most fascinating case studies I’ve ever read in the IT literature. Free-of-charge social networks are among the most fragile creations in the web universe. They live and die by their ability to stoke the “network effect” of snowballing invitations among people within diverse social circles. If the service shows any chronic degradation in performance and reliability, users will abandon it freely and speedily.

The article shows in painful detail how MySpace.com—without any fixed strategy--has continually evolved its distributed access, application, processing, storage, hosting, and management infrastructure to keep pace with surging membership, traffic, content, and expectations. It breaks the architectural evolution of MySpace.com into “membership milestones”--500,000 users, 1 million, 3 million, 9 million, 26 million, ….—and shows how the service broke and was quickly fixed to avoid strangling the golden goose they had birthed.

What I found most fascinating about this case study is the following statement, in which a rival (Friendster) partly attributes MySpace.com’s runaway success to MySpace.com’s superior performance (and Friendster’s concurrent growing pains): “MySpace was launched in 2003, just as Friendster started having trouble keeping pace with its own runaway growth. In a recent interview with Fortune magazine, Friendster president Kent Lindstrom admitted his service stumbled at just the wrong time, taking 20 to 30 seconds to deliver a page when MySpace was doing it in 2 or 3 seconds.”

Once MySpace.com started to explode, they continually ran into bottlenecks in data access performance that threatened to derail them as well. The case study lays out the peril to MySpace in stark terms: “MySpace has tens of millions of people posting messages and comments or tweaking their profiles on a regular basis—some of them visiting repeatedly throughout the day. That makes the technical requirements for supporting MySpace much different than, say, for a news Web site, where most content is created by a relatively small team of editors and passively consumed by Web site visitors. In that case, the content management database can be optimized for read-only requests, since additions and updates to the database content are relatively rare. A news site might allow reader comments, but on MySpace user-contributed content is the primary content. As a result, it has a higher percentage of database interactions that are recording or updating information rather than just retrieving it…..Every profile page view on MySpace has to be created dynamically—that is, stitched together from database lookups. In fact, because each profile page includes links to those of the user's friends, the Web site software has to pull together information from multiple tables in multiple databases on multiple servers. The database workload can be mitigated somewhat by caching data in memory, but this scheme has to account for constant changes to the underlying data.”

Since the beginning, MySpace.com has operated in ad-hoc fire-fighting mode, evolving its architecture to oil whatever new squeaks presented themselves. In reading this article, I scribbled down notes on the convoluted saga of ad-hoc fixes. Here (reading like the “and then, and then, and then” run-on ramblings of toddlers trying to make sense of an apparently pointless plot) are my notes on what they’ve done to keep heads above water:

§ first: single database server, with two access/web servers:

§ then: handle access/usage growth by throwing more more web servers at the problem

§ then: divide database loads among single master database and two access databases that have replicated copies of data posted to master, plus more database servers and bigger hard disks

§ then: vertical partitioning of separate databases among various functions of the MySpace.com service

§ then: a storage area network with pool of disk storage devices tied together by a high-speed specialized network

§ then: every database was given its own copy of the users table

§ then: distributed computing architecture treating the website as a single app, with one user table, split into chunks of 1 million accounts, with those chunks in separate mirrored instances of SQL Server, with webserver/access server redirecting logins to the applicable database servers

§ then: rewrite app in faster, more efficient computing environment (ASP.NET), with re-examination of every function for streamlining opportunities

§ then: continually redistributing data across the SAN to reduce I/O imbalances, but it was a manual process

§ then: virtualized storage architecture where the entire SAN is treated as one big pool of storage capacity, without requiring that specific disks be dedicated to serving specific applications

§ then: caching tier

§ then: faster version of database server running on 64-bit hardware with more memory access/less memory bottleneck

§ then: turn off distributed denial of service protection in order to goose performance further (introducing risk)

§ then: implement backup data centers/SANs tied to different power grids

§ then: lengthen data-commit checkpoint intervals to goose performance (introducing more risk)

§ and always: in any fix, impossible to do thorough load/performance testing on each new architectural fix/stopgap, simply resigning themselves to fixing new problems ad-hoc as they spring up

Of course, MySpace.com’s teenager customers don’t care, and don’t want to care, about any of this. The service continues to grow smartly, which may be attributed, among many factors, to the fact that it has yet to cross a “MySpace sucks, let’s leave” threshold. As the article states over and over, MySpace.com continues to experience significant performance and reliability problems, but they’ve never been showstoppers.

How long would it take for a social networking site to slow down and/or crash before it gets abandoned by its users? Are these sites so “group-sticky” that participants will tolerate poor performance for long periods? Are users’ performance/reliability expectations on these services lower than for standard corporate and e-commerce websites?

Or could the life or death of a social networking service—or of any online channel/forum—be driven more by the zeitgeist—fad, fashion, weariness, exhaustion, restless, new cool alternatives? Ten years ago, my 9-year-old son created a Digimon website. He’s in college now, and I don’t snoop into his doings, but I suspect that both of my kids have MySpace.com pages (no—I have better things to do then spy on them). Ten years from now, they and their peers will probably have long abandoned whatever social networking services they’re currently using.

They’ll write it off as youthful experimentation. To the extent they’ll still be participating in any online community that resembles today’s social networking services, it’ll be an act of nostalgia, more than anything. From a technical standpoint, it’ll probably be lightning-fast and scalable as can be, the fruit of lessons learned in the ‘00s by MySpace.com and other pioneers in this world of hyper-federated data service layers. And it will probably be far more navigation-friendly, as today’s chaotic MySpace homepage designs (which resemble the overcrowded Web-site home page designs that even big corporations were using in the ‘90s) settle into more consistent, pleasing patterns that everybody accepts without question.

But at that point the messy fun of the ungoverned social-networking frontier will be a distant, and slightly quaint, cultural memory. Like hippie communes in '60s.

Jim

Monday, January 08, 2007

poem Mless

MLESS

Dream of dreamless sleep
deep as dusk in a
musk as bright as
soft awakening.

Wednesday, January 03, 2007

fyi Where Will The Next Bill Gates Come From? Not The United States, Most Americans Say According To New Poll

All:

Found content: http://www.zogby.com/news/ReadNews.dbm?ID=1226

My take:

This is, of course, inane in the extreme. Zogby should be ashamed of themselves for phrasing the question in this ridiculous manner, and for pretending that the collective responses are worthy of serious consideration. While we’re on the topic, where are the “next” instances of the 6 billion-plus unique humans on the planet going to come from? Cloning seems the only truly effective approach, but I digress.

But I suppose that institutionalized idiocy has its own weird logic. What this misbegotten market research shows is that Mr. William Gates III has truly passed from the realm of limited mortals into the cultural hagiosphere. Does the following phrase sound like Christian second-coming imagery to you? “’The next Bill Gates has already been born, and time will tell what country is providing the environment of innovation, entrepreneurism and opportunity to enable him or her to flourish with the next great idea,’ said 463 partner Tom Galvin.” Or perhaps the current mortal Bill is an avatar of some timeless Hindu deity. But once again, I digress.

Clearly, the man who co-founded Microsoft has long since passed far beyond, say, Rockefeller, Carnegie, or JP Morgan in the pantheon of capitalist earthly gods. How can I make that assertion? Ask children to name one rich person known principally for his/her riches (as opposed to whatever celebrity career, be it athlete actor or musician, furnished them their largesse). Even in their days, I suspect, those ancient robber barons were probably known to few children. Even the kids who frequented the Carnegie-funded libraries (such as the one in my father’s Wisconsin hometown) probably didn’t realize that a munificent human was putting books in their hot little hands.

But today’s preschoolers, everywhere, know quite well that some well-endowed individual named Bill Gates is behind all things software, including the Internet (yes, I’m assuming that few tots care about the distinctions between Microsoft and other software companies). Maybe that lowest-common-denominator overattribution will diminish over time as Gates (perhaps) withdraws from active participation in the high-tech industries, but maybe not.

The world community demands an “inventor” of this created software universe. “Bill Gates” is a serviceable “father” to it all. “He” is two easy syllables that almost everybody everywhere can say with ease and be immediately understood.

Better than G. Presper Eckert.

But in some sense this annoying opinion survey may be onto something. If Bill Gates is an avatar of some timeless presence—in Hindu terms, the “creator”—then maybe the “next Bill Gates” refers to the next manifest avatar of some counter-personage in that pantheon. The “destroyer”? Who will come along to destroy or dismantle Gates’ software industry legacy? From a financial standpoint, Gates and his wife are self-dismantling through their foundation.

From an industry standpoint, open source, software as a service, virtualization, etc are dismantling Microsoft’s created order, steadily, erosively. “The Zogby/463 Internet Attitudes poll found that practically half of all Americans (49 percent) believe that the next great technology leader will come from either China or Japan. Twenty-one percent believe that ‘next Bill Gates’ will come from the United States while 13 percent believe he or she will come from India.”

So, given that half the world’s people are from Asia, chances of the “next Bill Gates”—the “destroyer” but also the “creator” of the next softworld order--coming from that region are a coin flip.

50-50.

Jim

Saturday, December 23, 2006

personal John Pierce Askegren

All:

Sad news: http://www.washingtonpost.com/wp-dyn/content/article/2006/12/20/AR2006122001918.html

Published obituary:

*********************

Thursday, December 21, 2006; B06

John Pierce Askegren, Novelist, Technical Writer

John Pierce Askegren, 51, a freelance writer who authored science-fiction novels and short stories featuring Marvel Comics characters and also worked as a technical writer for government contractors, was found dead Nov. 29 at his home in Annandale. The cause of death was atherosclerotic cardiovascular disease.

Since 1995, Mr. Askegren wrote or co-wrote more than 10 novels and a half-dozen short stories, mostly under the pen name Pierce Askegren.

His early credits included original short story contributions to anthologies featuring the Silver Surfer, Spider-Man and the Hulk.

"He was a huge fan of Marvel Comics and had a really spectacular sense of the history of the characters," said his former editor Keith R.A. DeCandido. "He did a wonderful job of bringing back obscure characters and giving them a twist."

Mr. Askegren was a co-author of the novels "Spider-Man & The Incredible Hulk: Doom's Day Book One: Rampage" (1996), "Spider-Man & Iron Man: Doom's Day Book Two: Sabotage" (1997) and "Spider-Man & Fantastic Four: Doom's Day Book Three: Wreckage" (1997).

In more recent years, he published a trilogy of science-fiction work: "Human Resource," "Fall Girl" and "Exit Strategy." This year, he wrote "After Image," part of the Buffy the Vampire Slayer paperback series.

For most of his career, he worked on his fictional stories in the evenings and on weekends, and by day he wrote educational handbooks and training manuals for government contractors.

He managed Crown Book stores before working for ACS Corp. from 1995 to 1999 and C2 Technologies from 1999 until 2003, when he left to concentrate on his freelance writing.

Mr. Askegren was born in Pittsburgh and grew up in a number of places before his family settled in Sterling in 1970. He graduated from Broad Run High School and James Madison University.

He became hooked on comic books as a youngster recovering from a broken hip.

"It started with two comic books my dad bought him when he had a metal pin in his leg. From that point on, he always had an affinity for it," said his brother James William Askegren of Sterling.

In addition to his brother, survivors include another brother, Robert Steven Askegren of Manassas.

*********************

A few additional words of eulogy:

Pierce Askegren was one of the coolest guys I ever met who didn’t realize how cool he was.

I hadn’t seen Pierce since 1998, though we exchanged a few e-mails in 1999. I only knew Pierce for a short time. We were work acquaintances, nothing more. I was a product manager at a wireless test and measurement equipment vendor in Tysons Corner, Virginia. Pierce was a technical-writer contractor that we brought in to do our manuals.

The first thing I noticed about Pierce was the quality of his technical writing. He took complex, boring technical goo and quickly boiled it down to a crystalline substrate of absolute clarity. Straightforward, unambiguous, readable, practical prose. Modest, not showy. Just like the man.

I also noticed that Pierce was an easy, pleasant person to engage in conversation. I’ve never been in the habit of lingering in colleagues’ offices longer than I need to, preferring to respect their work-hour space/time just as I hope they’ll do for me. But I found myself periodically traipsing down the hall to the tucked-away end-office where Pierce was set up. Among other things, he had a nifty little collection, arrayed on his bookcase, of comic-book action figurines.

Yes, this 40-ish man (only 3 years older than me) was a nerd, but not an obsessive fetishist hanger-on type of nerd. Through our conversations I began to determine that not only did he have an encyclopedic grasp of every comic book publisher, publication, issue, character, story arc, and detail going back—it seemed—to the Yellow Kid—but that he himself wrote paperback novels that carried forward the development of some of the most popular comic-book characters: especially, Marvel Comics’ Spider-Man.

Yeah, lotsa fanatics write unpublished/unpublishable novels, short stories, etc all around their venerated comic-book heroes, but Pierce was someone entirely different: a professional published freelance comic-book novelist. He mentioned that he had already authored a few such novels through some big-time publishing house. Though I had long since given up the comic-book habit (a staple my own childhood), and wasn’t much of a reader of any sort of fiction (nerd that I am, I’m much more likely to have a history or other non-fiction work in my hands), I had to see these. So I asked, and he gladly lent me two of his most recent books: one a Spider-Man title, the other (I believe) Fantastic Four.

I read them both quickly and with absolute delight. The man was a terrific novelist, and he clearly applied the same economy of technique to his fiction as to his tech writing. In addition, within the constraints of the comic-book novel, he was quite adept at developing characters, plots, and themes. He also had a real gift at drawing verbal pictures of dynamic action sequences, such as Spider-Man zipping his webline from his wrists, grabbing it and swinging back and forth between tall buildings as he rapidly homed on the baddies, while occasionally freefalling and trying to avoid annihilation. I can still feel and see the dynamic images that Pierce sketched out so brilliantly.

He also had great taste in music, especially classic R&B, soul, and pre-Beatles rock and roll. He lent me a lot of his CDs, and an excellent collection it was. So it was with special sadness that I encountered Pierce’s obituary in the paper version of Washington Post a couple of nights ago. Interestingly (and counter to what the Post normally does in its standard obituary pages), they published a small headshot of the man. This is the only occasion where I’ve clipped an obit and taped it to the wall of my home office.

Loved ya, Pierce.

Jim

Thursday, November 16, 2006

poem Once

ONCE

Old stones settle and
once wars are themselves
laid in place never
to reconnect the
same names in battle.

(inspired yesterday by some mysterious ancient war memorial at the base of Pennsylvania Avenue, catercorner to the Willard, on the Ellipse side of the Treasury Department HQ, and at one end of the ghastly barricaded zone that used to be the pedestrian friendly heart of our nation's government)

Friday, October 06, 2006

fyi Moore's Law is the enemy of privacy and Google launches search engine for finding source code

All:

Found content:

http://news.zdnet.co.uk/internet/security/0,39020375,39283741,00.htm

http://cwflyris.computerworld.com/t/905046/361089/36605/2/

My take:

In my semi-random morning meanderings through the previous evening’s e-mail, I sometimes stumble into fruitful juxta. Utopias and dystopias ride the same techno-waves. Here are a couple of articles that connected for me.

Esteemed security guru Bruce Schneier warns us of the panopticon, the omnisurveillance environment we’re building on the Internet, the result of ever more muscular CPUs searching through ever juicier piles of data worldwide. "To look at it, Moore's law is actually a friend of intrusive tools," Schneier argued. "As the cost of data storage gets cheaper, as the cost of data collection gets cheaper, more intrusion, more surveillance is possible," he said.

Then Google, the biggest baddest search muscle of the Internet age, announces a specialized search engine designed to find software source code that is publicly available on the Web. “Currently, the general Web search engine Google.com can find links to files with source code, but it doesn't index the lines of code in those files, said Tom Stocky, a Google product manager. In those cases, developers need to download the files to their computers and inspect the code. However, the new search engine has been designed to crawl more deeply and return results containing actual snippets of code, which should make the finding process simpler, Stocky said. ‘We find the lines that match your query,’ he said. The search results link to the full file containing the highlighted code, as well as to the software license governing the use of the code, which in most cases will be open-source, he said. Developers can enter keywords or fuller patterns in the search box.”

Of course, you can quickly convert Google’s happy value-prop into its own dystopia: massive software piracy that comes from finding exposed but non-open-source code everywhere on Earth. Or back to utopia: finding all the nasty zombies, rogue scripts, and other malware that has infected systems everywhere, and zapping it before it can do further harm. Or back to dystopia: finding every deployed instance of your competitor’s server software and disabling or crippling it with some new hack attack. And back and forth and back and forth.

The only point I’m trying to make here is that the ebb and flow of the media’s Pollyanna/Cassandra cycle can be injurious to your mental health. And when the media attempts to cover both sides of the equation with equal aplomb, the very velocity of these rebalancings can induce nausea and disorientation. It can simulate bipolar disorder in normally level-headed citizens.

Find your own personal balance. But don’t stop paying attention to the alternating currents of this crazy world. Tricky, I know. I’m still working on my own rhythm for taking these things in stride.

For one thing, I start the day with a good double dose of hot green tea.

Jim

Thursday, October 05, 2006

fyi For Cell Phone Etiquette, West is Best; New Survey From Samsung Explores Attitudes of U.S. Cell Phone Users

All:

Found content:
"For Cell Phone Etiquette, West is Best; New Survey From Samsung Explores Attitudes of U.S. Cell Phone Users"

My take:

Much of cellphone etiquette is in the ringer volume/mode. Since we got cellphones, I've been careful to put my phone in "vibrate" mode in most quiet indoor public environments. Then, when it vibrates with an incoming call, quickly glancing at the identity of the caller and making a snap decision to walk outside to take the call immediately (or not).

If I happen to be speaking with someone in person when a call comes in, once again, I quickly excuse myself to glance at the name/number of the incomer. If it's important enough, I excuse myself again and take it. If it's not, I put it back in my pocket and attempt to reconnect with the face-to-face, apologizing for the momentary distraction.

Generally, while taking a call in a public place, I try to turn my back from others and keep my voice reasonably low (I've got a loud voice naturally, so that's not always something I do consistently) to not make it appear like I'm "cellphoning in their faces."

I hate those invisible cellphones that consist of an ear/mouthpiece that allows someone to auto-accept an incoming call just by starting to speak. Those are unnerving if you're someone else trying to carry on a conversation with a person, or simply in the presence of a person, who's using those devices. One minute, they're seemingly talking to you or just remaining quiet. The next second, inexplicably, they start talking to themselves--no physical cellphone in their hand tips you off to the fact that they're on a call. Those devices skirt the boundaries of rudeness, just by their very design.

Cellphones should be semi-conspicuous to others.

Jim

imho Fact

All:

Just a quick set of thoughts.

We're surrounded by data all day.

Much of it gets presented as fact, when it's just assertion.

Fact is assertion cleansed of falsity, according to generally accepted cleansing practices.

Science is the process of cleansing from our understandings the muck of hearsay, superstition, and wishful thinking.

Scientific inquiry is good mental housekeeping.

Jim

Saturday, August 26, 2006

imho Structure of the Solar System 2

All:

I wrote my previous blogpost before I read that day's paper, in which the astronomers' decision/criteria for demoting Pluto was reported. I think they screwed it all up by positing an idiotic distinction between "planets" and "dwarf planets." What's the point? That's like calling uranium atom a full atom because it has scores of protons, neutrons, and electrons, and a hydrogen atom a "dwarf atom" because it only has a single proton and a single electron. They both embody the core structure of the same class of objects, but differ primarily according to scale (one's much larger than the other, and has the structural differences associated with that larger scale, but they're brethren in the periodic table). Absurd.

The core distinction that the astronomers should have keyed on was the scale of orbs, and the structural properties that come with increasing scale. I touched on that in my blogpost, but I thought of a few additional structural properties of larger orbs. Here they all are:
  • Appear: larger orbs tend to be more visible to our eyes and/or telescopes
  • Clear: larger orbs tend to clear out their orbital paths through centripetal gravitation and collisional deflection
  • Commandeer: larger orbs tend to capture other orbs and lock them as satellite into perpetual slave orbits
  • Sphere: larger orbs tend to take on spherical shape from force of own gravity
  • Atmosphere: larger orbs tend have the gravity necessary to hold any gaseous emissions as perpetual atmospheres
  • Magnetosphere: larger orbs tend to have hotter, more liquid interiors that generate the ongoing magnetic fields that cause such phenomena as atmospheric auroras
I rather like the "phase-change" ring structure I proposed for the solar system as a whole, because it essentially defines "strata" into which orbs have settled due to the dynamics of the whole system's evolution. It occurred to me that there's one critical ring that I left out from my blogpost (apologies to the late Johnny Cash and June Carter Cash on the following):
  • Ring of Fire: one or more fiery orbs (i.e., suns) at the heart of the system; a single fiery orb is essentially a rotating ring around the center of gravity of the system as a whole; this ring structure is more apparent in a binary-star or multi-star system, in which all those orbs orbit around the common center of gravity; it's even more apparent when we look at the billions of fiery orbs that revolve around the center of gravity (i.e., black hole) at the heart of the galaxy
  • Ring of Rock: one or more rocky orbs (with/without their own ice, liquid/ocean and gas/atmosphere overlays and satellites)
  • Ring of Gas: one or more gaseous orbs (with/without their own rock, gas, and/or ice satellites)
  • Ring of Ice: one or more icy orbs (with/without their own rock and/or gas constituents and/or satellites)
There. I'm glad I was able to write that all down in one coherent place. I don't care what these orbs get named, or whether they are ever named. Have we named all the stars in the universe? Why should we? Isn't it better to simply open our minds to understanding them on their own terms?

Jim

Friday, August 25, 2006

imho Structure of the Solar System 1

All:

Does anybody else feel that this current controversy over the status of Pluto is a bit silly? Official planets? Give me a break. That's not science.

This is a perfect time for us all to revisit the structure of solar systems. There are of course many types of objects that orbit stars. What we have traditionally called "planets" are just one type.

On the flight home yesterday from a conference, I quickly sketched out my ideas for rethinking the structure of this and other solar systems. We'll get to the status of Pluto in just a bit.

A solar system is simply a collection of objects that orbit one or more stars (yes, there are binary star systems, and I'm holding open the possibility of triple-star quadruple-star, and even more star-packed systems). That being said, the basic entities and relationships in solar systems are as follows:


  • Star(s): the orbital hub(s) of all objects in the system; example, our sun
  • Orb(s): the objects that orbit the star(s) of the system; may be massive or minute; examples, our "planets," comets, asteroids, microscopic particles floating in the void between other orbs
  • Ring(s): the discrete paths of grouped, like orbs in the system; examples, the inner "ring of rock" around our sun (primarily including Mercury, Venus, Earth, Mars, and the asteroids); the "ring of gas" (including Jupiter, Saturn, Uranus, and Neptune); the "ring of ice" (including Pluto, Charon, Xena, the Kuiper Belt, and whatever else lies out beyond)
  • Satellite(s): orbs that orbit other orbs in the system; examples, the moons the various planets; the rocks, dust, and other objects in the rings of various planets

Notice that I've defined "orbs" to include all objects, from microscopic to Jupiter, that directly orbit the sun, or that orbit other orbs. The crux of the debate over Pluto is whether it's too small to qualify as a "planet" in the traditional sense of that word. Well, maybe we shouldn't using that word any more--it's become an arbitrary, non-scientific term that obscures and distorts the actual structure of the solar system.

But before we do that, let's ask why we have historically latched onto this term. What exactly is a planet, in the traditional sense of the word? My sense is that it's an orb that is massive enough to a) appear in telescopes, b) has great enough gravitation to pull its shape into a sphere, and c) has essentially cleared out its own orbital path, through centripetal attraction and collisional deflection, of all other nearby orbs.

"Appearing," "sphering" and "clearing" are the three core criteria for "planets," in the traditional sense of the word. Orbs smaller than a given threshold don't appear, sphere, and clear; rather, they simply jostle with other dark, irregular orbs into their aggregated rings; those aggregated rings and some of their constituent objects (e.g., asteroid belt) may occasionally appear, but they may occasionally clear out their own tiny neighborhoods (after all, these are huge empty neighborhoods, for the most part), but they don't sphere.

So never fear. To sum up: Pluto is the first-discovered orb in the ring of ice that satisfies all three planetary conditions: appear, sphere, and clear. Comets appear and clear, but aren't massive enough to sphere on their own (yes, they occasionally get whittled through solar wind into roughly spherical shapes, but that's a transient condition of the ever-changing ever-changing shape of an ever-diminishing object).

Matter settled.

Jim

Friday, August 18, 2006

poem University

UNIVERSITY

Pray for the school year
and the grind may it ground us
in unearthly smarts.

Tuesday, August 01, 2006

self Dec 2005 BCR article on Content-Aware Network Appliances

All:

Created content found on publisher's site for free:

http://www.bcr.com/architecture/local_area_networks/content_aware_network_appliances_20051201653.htm

Good piece. Glad I did it.

Jim

Monday, July 31, 2006

imho 4GW Fourth Generation Warfare

All:

Found content:

http://globalguerrillas.typepad.com/globalguerrillas/2004/05/4gw_fourth_gene.html
http://www.windley.com/archives/2006/07/our_nets_are_out_strengths.shtml">http://www.windley.com/archives/2006/07/our_nets_are_out_strengths.shtml

My take:

I've been mulling the Middle East these days just like everybody else. I don't want to believe that it's an insoluble blood feud, but that's how it definitely appears. Don't you want to believe that there's a peaceful happy solution for every nasty nexus of human conflict?

I meandered to this "4GW" topic after seieng this mysterious new phrase in a Phil Windley post quotin somebody named Tom Barnett. So I Googled it and found a two-year-old definition by a certain John Robb. Now I'm bloggin my impromptu thoughts on it. Just because. Trying to distract my mind from a tech article that I'm committed to write but am just not ready yet to start composing.

First off, I don't buy Robb/Windley/Barnett's notion that so-caled 4GW (fourth-generation warfare) is anything new. Let's go straight to Robb's definition: "Fourth generation--ad hoc warriors and moral conflict." That, of course, defines guerrilla warfare and the associated ideological assault on established power. And those dual techniques have been used for a long time in many conflicts, such as our own American Revolutionary War (ad-hoc warriors: the scraggly amateur-citizen-army-militias that Gen. Washington tried to assemble into a semblance of a professional fighting force; moral conflict: the Declaration of Independence that Mr. Jefferson et al. proclaimed at the same time to justify their right to take up arms to sunder the bond from Great Britain). And plenty of communist revolutoins of the 20th century were assembled from ad-hoc fighters who were schooled to proselytize the moral/ideological cause known as Marxism.

Second, I found the following statement from Barnett (quoted approvingly by Windley) to be chauvinistic and naive: "There is a profound reason why we're rich and powerful and connected and the enemy is none of those things. Terrorism is a strategy of the weak, and it earns them only what the powerful decide they no longer want...[T]here are no lasting 4GW victories. Yes, sometimes conflicts are won, but what is really achieved? Look at Cuba or Nicaragua or Palestine--or best yet--Vietnam or China? All these 4GW 'victors' got was amazing bloody disconnectedness, and--when they got smart--then they came back crawling to the system, the nets, the rules, the 'decadence.'"

All of this is just a rehash of the time-honored nonsense that our enemies are "bums," "losers," and "cowards" if they don't use whatever fighting tactics we would prefer they use (so that we can easily defend against them). so, if I understand correctly, Barnett et al. are arguing that terrorists (i.e., guerrilla warriors) are losers, that they're now and forever disconnected from each other, and that further acts of terrorism simply contribute to their ongoing estrangement and eventual doom.

Oddly, as examples of disconnected losers, they cite Cuba, Vietnam, and China (the current governments of which took power in part through the effectiveness of their guerrilla tactics). It's bizarre to single out those particular countries, considering the strength and stability of each of their governments (whether or not you agree with their forms of government, you have to admit that they are holding power and connecting internally quite effectively).

If terrorism is a strategy of the weak, and, for example, you classify the 1968 Tet Offensive as terrorism, and you note the historical truth that the Tet Offensive broke the American public's will to continue backing the South Vietnamese against the stronger-willed northerners, then doesn't that undermine your argument against the ultimate effectiveness of terrorism? When exactly did we the "powerful" (USA and South Vietnam) decide that "weak" North Vietnam's terrorism had "earn[ed] them only what [we had] decide[d] [we] no longer want[ed]: i.e., unchallenged dominion over the entire northern and southern regions of Vietnam?

Terrorism, clearly, is not necessarily just a strategy of the ineffectual, forever-disconnected weakling. It has often been a recruiting and morale-building (hence, connection-building) strategy under which weaklings demonstrate their boldness, resourcefulness, and determination to their kindred and to their enemies. The terrorists have their networks, and we, their targets, have ours. They'll keep on attacking our nets both to weaken them and to recruit/build/strengthen their own. We, the established powers, have more transparently public networks, so we make easier targets than the terrorists and their invisible nets.

We're talking death and destruction here, let's not kid ourselves. So I'm profoundly uncomfortable with the bloodlust implicit in the following statement of Barnett's, which Windley once again quotes approvingly: "Our nets are our strengths. They will attack and we will grow more resilient. Bush was right: Bring it on. Speed the killing. Flush the losers. Extend the nets. Be resilient."

At worst, that's outright insanity--a prescription for Armageddon and mutually assured destruction. At best, it's chest-beating naive hyper-optimism of the whack-a-mole variety. What do you do if the "losers" are everywhere, attacking a civilian society in which they're intimately embedded? You don't quell an insurgency by daring the insurgents to rip apart the everyday fabric of people's normal lives. That produces pure mortal terror of the most destructive variety, of the sort that the Israelis and Iraqis are facing every day now. A hellish existence where every car or truck that passes on the street might be carrying the bomb that ends it all.

Robb has an interesting comment about how a "4GW" conflict can be "won": "Victory in 4GW warfar is won in the moral sphere. The aim of 4GW is to destroy the moral bonds that allow the organic whole to exist--cohesion."

Cohesion. Cohesive bonds. Cohesive bonds in the organic moral sphere. Excuse e for getting all mushy on you, but that sounds like religion, or, if that's too sensitive a word (given that much of the Middle East nastiness is motivated by dueling notions of whose take on religion is superior), let's just say "spirituality" in general or, getting super-wimpy, ""compassion" and "tolerance." In the immortal words of Nick Lowe, "what's so funny about peace, love, and understanding?"

But that's still religion, when you come right down to it. Unfortunately, in the broader scheme of human relations, religion hasn't always been the cohesive force its promoters want you to believe. It's often an abrasive, sometimes a corrosive, occasionally a toxic, inflammatory, and explosive reagent in a chronically charged environment.

Yeah, I go to church and put money in the collection basket, but I'm not expecting any real return on my investment. I pray too, but I'm not expecting the almighty to hit the "reply" button.

There must be another type of soul force we haven't tried yet.

Jim

Saturday, July 29, 2006

note Gomorrah

Every last little
human difference will
be prosecuted
without end. Amen.

note Parade Magazine

this or that born-elsewhere
angeleno
enjoyed great early success and
once seemingly had

hollywood
and/or the pop music
world
by the tail
until the bloom
fell from the rose
they fell from favor and/or
something self-inflicted laid them low
and put them on the brink of
whatever
until
something spiritual
helped them find themselves
and/or
inner peace
and/or
whatever it was
redeemed them
delivering some recent
unexpected hit
of commercial resurrection
which brought them back into our
collective affections
briefly
and captured our interest
in some small way
so that we can now
confidently publish their declaration
of life
in fresh perspective
on the mend
and chastened by adversity
rededicated to some new modicum of
maturity
and
moderation
let us here now present
their inspiring story
as told
in their very own words
to our top interviewer
dotson rader
who met them in a restaurant
in lower manhattan and
carefully edited a
long tape-recorded lunch
into an
easy reading
thousand words
fit for calm
popular
perusal over
juice and cheerios
every
single
solitary
sunday
morning.

Monday, July 24, 2006

fyi Do politics and identity management mix?

All:

Found content:

http://www.networkworld.com/newsletters/dir/2006/0717id2.html

My take:

Dave Kearns writes a great column. This one had all the promise of an even greater column than usual, based on that enticing headline. The intersection between IdM and partisan politics? George W. Bush’s position on SAML? Does Bush or anybody else in Washington politics have even the dimmest awareness or concern for such techno-plumbing?

Nope. Just a discussion of the organizational politics that accompanies a federated IdM, in terms of who controls which authoritative repositories of information under which circumstances. Turf wars. Politics in the usual coalition trench warfare of business life.

Nevertheless. This particular column has a critical IdM insight which, though not mind-blowingly original, put me in mind of something else. Says Kearns: “Turf wars are especially abundant when dealing with identity issues. After all, most identity information is simply data. Although it's organized around particular identifiers it's still simply data. The problem is we're trying to present a unified view of that data that crosses departmental, organizational and jurisdictional lines.”

Of course. IdM is a subdiscipline of master data management (MDM). Sez me, per my recent Current Analysis advisory report on SOA and MDM: “Lacking ubiquitous SOA-based MDM, enterprises cannot achieve the vision of a ‘single version of the truth’ that permeates all business transactions. In a well-architected SOA-based MDM environment, users know they can rely on information that is maintained in their company’s reference data stores—no matter how many repositories there are or where they reside. This is because all that precious content has been transported, consolidated, cleansed, and secured in keeping with official corporate policies, and by a common set of official corporate DM services. As long as the MDM infrastructure (and the broader SOA) enforces a common set of policies across the data-governance life cycle, master data can be reused over and over with high assurance that it is current and accurate.”

IdM is MDM in the governance of identity data (and, usually, employee data, to enable authentication, authorization, etc.). MDM comes in many varieties, based on the sorts of master reference data that’s being controlled. Customer data integration (CDI) is one type of MDM. Product information management (PIM) is another. Supplier information management is yet another.

In the world of MDM, there’s the distinction between “physical MDM” (i.e., a “data warehouse” (DW) a single master governance repository of some data set) vs. “virtual MDM” (i.e., enterprise information integration (EII) based on distributed repositories of master reference data and the need for federated governance/query/update across them).

That’s exactly equivalent to the IdM distinction between master directories (i.e., identity warehouses) and multimaster directories (i.e., identity federations).

To sum up: Identity isn’t just data. It’s master reference data. Control over that data, in an identity MDM environment, is inevitably political. In federated MDM, all the ownership turf wars apply full force.

Just wanted to point that out.

Jim

Sunday, July 16, 2006

imho The Long Tail

All:


Found content:

http://en.wikipedia.org/wiki/The_Long_Tail

http://www.wired.com/wired/archive/12.10/tail_pr.html

My take:

Visually, the “long tail” graph resembles a fading signal, asymptotically tapering into nothingness, but still faintly perceptible against the background din of the cosmos.

Essentially, these articles state that the long tail of niche market segments--aggregated through Amazon, eBay, iTunes, etc.--is wagging the big dog of Internet commerce. Per Wikipedia:

  • “The long tail is the colloquial name for a long-known feature of statistical distributions (Zipf, Power laws, Pareto distributions and/or general Lévy distributions ). The feature is also known as ‘heavy tails’, ‘power-law tails’ or ‘Pareto tails’….In these distributions a high-frequency or high-amplitude population is followed by a low-frequency or low-amplitude population which gradually ‘tails off’. In many cases the infrequent or low-amplitude events—the long tail, represented here by the yellow portion of the graph—can cumulatively outnumber or outweigh the initial portion of the graph, such that in aggregate they comprise the majority.”

In economic terms, e-commerce vendors can profit from serving all niche markets if:

  • the aggregate demand for all niche-appeal items is persistent, ubiquitous, and substantial
  • the marginal cost of producing, marketing, stocking, selling, and distributing niche-appeal items is near zero
  • the availability of niche-appeal items is at a par with mass-appeal items, through consolidation into master catalogs, search engines, and so forth

All of which has come to pass through the Web.

From the niche-dwelling consumer’s point of view, it’s all about vendors providing an effectively infinite catalog that ranges across all niches and back to the beginnings of recorded time (or 1995, whichever came first).

From the niche-dwelling producer’s point of view, it’s all about connecting with a market, even if it means doing onesie-twosie, break-even transactions on long-discontinued merchandise. Just to connect. And move product. And persist in somebody’s collection somewhere for some reason. Even if it means that, by settling into the “long tail,” our work shall ever more be tagged as “unpopular” or “not for everybody.”

Though, as the “long tail” illustrates, the “popular” is “not for everybody” either. Most of the popular stuff will eventually slide down the tail toward niche status, sometimes over the course of a generation. Or seemingly overnight (as when an obscenely and expensively promoted bow-wow of a Hollywood sequel blockbuster plunges in the box office in its second and third weeks of exposure).

Slipping ever further toward the indistinguishable media soup of yesterday's product, the heat death of surfeit-swamped oblivion that awaits even the biggest productions.

Jim

Wednesday, July 05, 2006

fyi Bill Gates embraces open source process

All:

Found content:

http://blogs.zdnet.com/open-source/?p=691

My take:

Huh? “Gates and his wife Melinda talked about bringing scientists together around a table and generating ideas about solving problems, without worries about money or who owns the ideas…Concentrate on the problem, on the solution. Network freely.” And Gates equates that—some vague definition of scientist-driven collaboration—with open source software?

First off, this is a very naïve of concept of the scientific process. Scientists are as competitive as any business people. In fact, sometimes it seems that the only things scientists worry about are “money” (getting grant dollar to underwrite their research) and “who owns the ideas” (getting due credit for being the first to discover and publish some important new finding). Scientists are not egoless altruists.

Second, this is a very biased view of the business process, a process that is usually driven by the need to solve problems and in which people network as freely as the situation demands. The business world is as solution-driven as the academic world—perhaps more so—given the fact that business people can be sacked for failure to produce, whereas many researchers are tenured faculty who can piddle around for years on minutiae without having to produce much in the way of concrete accomplishments.

Third, this is a wonk-driven vision of economic development, as if pure brainpower pooled around virtual and physical conference tables will solve the world’s problems. Lots of smart people everywhere have been worrying and working on these problems for so long. Scientists aren’t necessarily any smarter in matters of economic development, program management, and cross-cultural outreach than anybody else. Same goes for IT folks. These are what will make all the differences in producing actual results that improve people’s lives.

Everybody’s getting so enamored of Bill and Warren’s big beneficent bankroll, as if pure money has some sort of messianic power. It’s one thing to subsidize projects that promise to improve health and education around the planet. It’s quite another to follow through with delivery, implementation, and results. Let’s not think that we can simply parachute in with nifty new thirdworld-targeted technologies and magically improve lives. Will the Gates Foundation maintain a permanent staff of overseers in every nation on earth to make sure that its money is not sunk into wasteful NGOs, siphoned off by corrupt governments, and squandered in ill-conceived projects? How many of Gates’ own projects within Microsoft have failed, or underwhelmed, even when he was closely supervising them?

Precisely how will the Gates Foundation succeed where the IMF, World Bank, UNESCO, Peace Corps, etc have failed to make much of dent in world poverty?

It’s good that deserving health and education projects now have another well-heeled funding source. It’s also good that Bill Gates is devoting his life to managing that source. But he’ll quickly realize he’s dispensing a very limited supply of salve in a world teeming with open sores.

Jim

Tuesday, July 04, 2006

Poem Vacation

VACATION

Try a violent green,
an overgrown isle
in the stream of sand
I’ll dream isn’t there.