Wednesday, January 25, 2006

fyi On The Absurdity of "Owning One's Identity"

All:

Pointers to Bob and Phil:
http://notabob.blogspot.com/2006/01/on-absurdity-of-owning-ones-identity.html
http://www.windley.com/archives/2006/01/algorithmic_aut.shtml

Pointers from Jim:
First off, I want to point out that Bob Blakley is a very smart, intellectually stimulating, articulate, funny, and funnily pedantic individual (yes, I’m comfortable with “funnily,” and I urge you to get with the program as well). He was one of my absolute favorite speakers during the years in which I attended and (there’s rumor to the effect that I) spoke at, helped organize, and nagged external speakers to get their slides in shape for Burton Group’s Catalyst conference. (That would mean I was once employed by Burton Group, wouldn’t it? Wouldn’t it?) Bob will kill me for this observation, but I always perceived him as one part Dick Cavett, one part Mr. Peabody (the bespectacled, professorial canine with the Wayback Machine on the old Jay Ward cartoon). Close your eyes and listen to Bob talk: “Yes, Sherman, today we’re going to travel back to 500 B.C. to see if Romulus and Remus indeed built Rome in a day.”

All of which silliness is (believe it or not, Sherman) my segue into Bob’s blog discussion “On The Absurdity of ‘Owning One's Identity.” Bob was commenting on Kim Cameron’s “First Law of Identity,” to wit: “Technical identity systems must only reveal information identifying a user with the user's consent.” Bob interprets this “law” (he rips Kim a new one for calling this a “law,” but so have I, previously, so there’s no point piling on the poor man) as an assertion that people “own their own identity” and, hence, can control how that identity is used/abused by others. And Bob then proceeds to rip the stuffings out of this presumption as well.

Blakley argues that each of us has two types of identity (is this an exhaustive categorization, Bob?):
  • One’s reputation: This is the story, he says, that others tell about you, and you can’t own it. You can’t even control it, because you can’t stop people from observing you, taking your picture, or talking about you, or stalking you so they can take your picture. Well, maybe you can get a restraining order in the latter case. But you see his point.
  • One’s self-image: This is the story you tell about yourself. Presumably, you own it too. But you can’t force people to feel as kindly toward you as you feel toward yourself. Anyway, it’s always about you, isn’t it? Enough, already.
Bob has a great reputation—I’ve shared with you my story of Bob (which, of course, I used to work in the chief theme, which is the story of Jim). He’s a great thinker, but he sort of beats the analysis of this issue into the ground in his blogpost.

Still, his bottom line is important: We can’t really stop people from spreading stories about us—our reputation. And we can’t get them to necessarily buy into our stories about ourselves—our conceit. Nobody needs or asks our consent to use/abuse our identity in any of these ways. And there’s no way, short of superfreaky occult mind control, that we can monitor and enforce how everybody in the world feels about us all the time. And we can’t (and perhaps shouldn’t) control how/when/whether they use our reputation (attributes of our identity, filtered through the lens of their own perception of us and our character, motives, etc.) in going about their business.

Ergo, says Blakley, it’s unrealistic for Kim Cameron and his minions to require that “technical identity systems …only reveal information identifying a user with the user's consent.” And I agree with Bob on this: If I had to explicitly authorize every instance of disclosure of some scrap of my personal information that’s being held/controlled by some other party, I’d have 10,000 authorization-seeking e-mails in my inbox every morning, as opposed to the current, more manageable 7,000.

But rewind the Wayback Machine back several paragraphs, and look at Bob’s definition of “reputation” again: the story that others tell about you. Is that really what reputation is? It seems to miss the mark by being too inclusive. If someone writes my biography (story of my life), is the final product my “reputation”? If someone simply compiles a timeline of key dates in my life (the story of my life), is this dry recitation of documented facts my “reputation”? Of course not.

Now, roll back the Wayback Machine to November 27, 2005, and look down the scroll of this blog to the “imho identity privacy reputation” posting midway through the Abhilasha thread. Proving that no one out-pedantics Jim Kobielus, I shall now proceed to quote myself at length:

“Reputation isn’t an identity, credential, permission, or role. It isn’t exactly an attribute, in the same sense that, say, your birth date or hair color are attributes. And it isn't something you claim any privacy protection over--it's the exact opposite: the court of public opinion over which you have no sovereignty and little direct control.

”In the IdM context, reputation is more of an assurance or trust level—an evaluation of the extent to which someone is worthwhile to know and associate with. Assurance generally refers to the degree of confidence that a relying party can have when accepting a password, certificate, token, assertion, claim, or other credential that is associated with a particular identity. Fundamentally, assurance is the confidence that someone else is reasonably safe to do business with. Assurance serves the relying party, allowing them to strongly verify the authenticity and validity of others’ identities, attributes, credentials, and assertions. It provides the relying party with the information they need to determine whether to refrain from, closely monitor, and/or repudiate online interactions in which such verification is lacking. It also gives the relying party the confidence that, if adverse consequences result from doing business with someone, the responsible parties can be pinpointed effectively so that appropriate legal, business, and other remedies can be pursued.”

”Reputation is relying parties’ evaluation of our reliability, of their liabilities, and of the degree to which associating with us makes them ill at ease. Appearances are assurances, for good or ill.”

Me again, back to this evening, January 25, 2006, to point out an important truth: Reputation isn’t an attribute of our identity, and it isn’t a story, really. It’s simply an assurance, confidence, or comfort level in which others regard our identity. It’s a vague, qualitative, holistic, often semi-conscious impression, calculated somewhere in the reptilian mind that has descended to us down through the ages. Quoting myself again:

“Relying parties—-the ultimate policy decision and enforcement points in any interaction—-need many levels of assurance if they’re going to do business with us. They gather assertions and data from many IdM “authorities” (authentication authorities, attribute authorities, etc.) before rendering their evaluations and opening their kimonos. They—-the relying parties—-make reputation evaluations based on information fed in from trusted authorities, from their own experiences with us, from whatever reputation-relevant data they can google across the vast field of received opinion and public record.”

Reputation is a computed halo—positive or negative--around our socially contextualized identities.

Which is my segue, believe it or not, for introducing my first mention of Phil Windley into my blog. In his recent blogpost “Algorithmic Authorizations,” Phil asks a great question: “Can anyone think of other examples besides credit scoring where authorization to access a resource is computed instead of being looked up in a table?”

Sure. Reputation is a score computed by relying parties in order to determine whether or not to authorize the reputed party to access resources such as jobs, communities, romantic encounters, time of day, etc.

Reputation is an assurance that someone is worth our while.

Jim

imho The Great Chain of Identity Assurances

All:

Strong end-to-end assurance is the foundation of trusted e-business and regulatory compliance. Assurance is a concept that can and should be applied to the whole of identity and trust management—including the new worlds of federated identity management (IdM) and federated data interchange--though it has historically been defined primarily in the electronic authentication and PKI worlds.

Traditionally, security professionals have defined assurance in terms of discrete “levels” that PKI and other credentials providers implement in their technical and business models. In that context, assurance levels—either enumerated (e.g., levels one through four) or named (e.g., basic, medium, high)—refer to a constellation of processes, protocols, formats, infrastructures, and other safeguards and controls implemented by certificate authorities, registration authorities, and other roles within an identity, trust, and security environment.

Organizations should describe their supported identity-assurance levels in published identity policy and practice statements. Vertical industry sectors should strongly consider defining standard federated identity policy and practice statements formats and rules that are applicable to all firms doing business in those markets. Furthermore, vertical sectors should consider relying on trusted third parties (trusted third parties) to vet and certify organizations’ published federated identity policy and practice statementss for compliance with accepted standards. In this way, all trading partners in a particular industry might be able to rely more thoroughly on the trustworthiness of each others federated IdM “claims,” “tokens,” or “assertions,” knowing that all participants’ federated IdM procedures have been certified to a common standard.

Within a federated identity/trust environment, trusted third parties can provide some critical assurance services: vetting, certifying, and vouching for the equivalence of all organizations’ compliance with common IdM and PKI assurance policies, best practices, and standards. In pursuing such an approach, the B2B e-business communities would be ensuring that any federated identity policy and practice statements-compliant company is eligible to participate in the community’s federated IdM environment. For example, the identity policy and practice statement standard might prescribe mandatory identity and account management policies, procedures, and practices rules applicable to export/import control throughout a multinational B2B supply chain that includes dozens to thousands of firms. Similarly, the community-wide federated identity policy and practice statements standard might specify minimum privacy-protection safeguards that all companies would need to meet in order to pass regulatory muster in all participating nations. From an efficiency perspective, a trusted third party should certify companies’ compliance with federated identity policy and practice statements standards. In this way, this trusted third party can perform a function analogous (and complementary) to the bridge certificate authorities of the PKI world.

To serve the relying parties in federated IdM interactions, IdPs should be able to generate assertions that attest strongly to their federated identity assurance level, as published in their federated identity policy and practice statements and certified by a federated identity policy and practice statements trusted third party. One critical piece of information that these assertion messages might contain is a description of the assurance level—such as two-factor authentication—associated with a particular login. The relying party would use this information in determining whether authentication had been done at a high enough assurance level for the requested resource (such as a highly sensitive operational database). Ideally, a relying party should also have visibility into the policies, practices, and controls implemented at the IdP. This knowledge would enable the relying party to determine whether the IdP has issued its assertions pursuant to sound, secure operating practices. The more trustworthy the IdP’s policies and practices, the more trustworthy the assertions issued by that IdP.

Of course, it’s not enough for an organization to simply assert that it complies with particular IdM policies. For other organizations to fully rely on a particular federated identity policy and practice statements, an IdP would first have had to gain certification from a trusted third party that had investigated and vetted that IdP’s internal procedures and controls. The trusted third party would then issue a digital signing certificate which the IdP would use to digitally sign identity assertions, confirming the IdP’s adherence to a particular established and published IdM federation policy. The trusted third party might, within its federated identity policy and practice statements-compliance assertion, also vouch for the mapping or equivalence between the IdP’s identity policy and practice statement and those of the relying firm, or the standard federated identity policy and practice statements for a particular vertical market, nation, or community. Other domains would be able to rely on those trusted third party-issued federated identity policy and practice statements compliance and equivalence assertions when deciding whether to trust that IdP’s authentication and attribute assertions. In this way, through trusted third parties, federated IdM environments can establish multilateral trust for strong authentication, SSO, RBAC, and other services. Consequently, the trusted third party becomes the hub of a federated B2B “community of trust,” providing the critical services of IdP identity policy and practice statement policy definition, vetting, mapping, certification, and vouching.

Conceivably, one could define a chain of identity assurances that each IdP would assert in its federated identity policy and practice statements. Fundamentally, identity assurance is defined by the degree to which a person’s online actions can be tracked and measured against an IdM best practice to which their IdP has committed in its federated identity policy and practice statements. Strong identity assurance could be predicated on the extent to which a given identity’s online interactions can be strongly associated, bound, or linked to demonstrated norms of IdM “best practice,” per applicable laws, regulations, policies, and industry best practices.

The chain of identity assurance associates the actions that a user takes in an online session with the consequences of those actions:

  • Assurance of association between an online session and a credential: This requires client-signed session assertions, signed cookies, or other means for strongly binding an online session to a credential under which a user logged into that session. In turn, client-signed session assertions or cookies require PKI X.509 end-entity digital signature certificates and private keys. All that, in turn, requires strong PKI assurance.
  • Assurance of association between a credential and a digital identity: This requires PKI X.509 end-entity identity certificates, which cryptographically bind an identity’s private identity key to the corresponding public key, and to a unique identifier such as UPN, X.500 DN, or UPN.
  • Assurance of association between a digital identity and a real person: This requires PKI registration authorities to issue and renew X.509 end-entity certificates only after in-person proofing/vetting that involves having a real person present a government-issued picture ID and other supporting identifying documentation. It also requires that the request for registration or renewal of a PKI certificate/token obtain all necessary administrative approvals within the IDP that has issued the unique identifier that will (upon certificate issuance) be cryptographically bound to a public key (published in the certificate) and a private key (to which only that real person will have authorized access). In addition, provisioning of certificates to proofed users should only follow user authentication to the CA through entry of a one-time secret proofing passcode provided at proofing time by a trusted agent of the CA.
  • Assurance of association between a real person and an IdP: This requires that the IdP that issued the unique identifier published in the real person’s end-entity PKI certificates maintain that identifier in a published master directory administered and controlled by the IdP. The IDP’s master directory must securely and reliably synchronize, replicate, and/or publish that master identity information to other directories and repositories, or vouch via SAML authentication or attribute assertions for its continued registration in the master directory. In addition, the IdP must use identity information in that master directory to drive the automated provisioning and deprovisioning of accounts associated with real persons.
  • Assurance of association between an IdP and an IdP-asserted federated identity policy and practice statements: This requires that IdPs digitally sign any federated identity policy and practice statements that they assert with a digital signing private key held by an authorized corporate officer.
  • Assurance of association between an IdP-asserted federated identity policy and practice statements and a trusted third party-published federated identity policy and practice statements: This requires that one or more trusted third parties develop and publish standard federated identity policy and practice statements formats. It also requires that trusted third parties investigate, vet, and certify equivalence or conformance between an IdP-asserted federated identity policy and practice statements and a trusted third party-published federated identity policy and practice statements.
  • Assurance of association between a trusted third party-published identity policy and practice statement and trusted third party-vouched observation of identity’s demonstrated compliance with norms of IdM “best practice”: This requires that one or more trusted third parties track, monitor, and audit real people’s online behavior. It also requires that trusted third parties determine the degree to which that behavior conforms to the norms of IdM best practice that they and their IdPs have pledged to comply with, in the form of published identity policy and practice statement.

This last point is where federated IdM assurance environments would perform a critical role in stamping out phishing, pharming, and other crimes against e-business assurance. Identity theft, fraud, and impersonation violate all norms of IdM best practice, and also are criminal and civil offenses in a growing number of jurisdictions. Any real person that commits identity theft, and any IdP that actively or tacitly supports such behavior, might be held legally accountable for their behavior.

A well-architected federated IdM assurance environment would provide the identity, security, policy, management, and procedural controls necessary to prevent, detect, eliminate, and punish these violations of e-business trust.

Jim

Sunday, January 22, 2006

fyi Open-Source License Debate Kicks Off

All:

Pointer to article: http://www.informationweek.com/news/showArticle.jhtml?articleID=177101776

Kobielus kommentary:
Ah yes…epic battle…open source vs. digital rights management (DRM).

And classic language, from the GPLv3 draft (note the rascally redefinition of the acronym): “"Some countries have adopted laws prohibiting software that enables users to escape from Digital Restrictions Management," the draft reads. "DRM is fundamentally incompatible with the purpose of the GPL, which is to protect users' freedom; therefore, the GPL ensures that the software it covers will neither be subject to, nor subject other works to, digital restrictions from which escape is forbidden."

In other words, no software licensed under GPLv3 (as currently drafted) may be used in products that implement DRM. Put in economic terms, a growing universe of for-free code is offlimits to those who might wish to use it to chain, contain, restrain, and meter for-pay content. So those who dream DRM will have to scrounge or gin up their own non-GPLv3 code in order to build their content constrainers.

Which, of course, they’ll easily do. Content owners (of which I'm one, though most of what I own copyright to is now utterly worthless) will spend whatever they need to spend to fortify their lockboxes. But, with the DRM-buster in GPLv3, they won't be able to do so as cost-effectively as if they had access to the full open-source universe to do so.

Call GPLv3 a symbolic stand against overzealous DRM. It may not derail the DRM overkill juggernaut. But it serves notice that those who would free software would also free the information that often gets imprisoned therein.

Jim

Friday, January 20, 2006

fyi Progress Software buying Actional for $32M

All:

Pointer to article: http://www.computerworld.com/softwaretopics/software/story/0,10801,107867,00.html?source=NLT_PM&nid=107867

Kobielus kommentary:
ESB is the most promising new middleware approach. ESB generally refers to integration software that supports simple, expedited, loosely coupled, standards-based, service-oriented integration. It also refers to a segment of middleware market that converges the best features of message-oriented middleware, integration brokers, and Web services.

The ESB market is heating up, but possibly also melting down. In the past month, we’ve seen two ESB vendors—Sonic Software (an operating unit of Progress Software) and Systinet—merge with SOA governance vendors: Actional and Mercury Interactive, respectively. ESB environments need the policy-driven management provided by robust IT governance tools.

However, neither Sonic/Actional nor Mercury/Systinet will be able to compete for long against the SOA platform vendors—especially IBM, BEA, Oracle, and Microsoft—who are adding ESB and IT governance functionality to their suites at a rapid clip. When the ESB market matures by the end of this decade, ESB pure-play vendors will find their value proposition usurped by platform vendors that have embedded ESB functionality into their offerings.

Many SOA platform vendors are embedding ESB functionality more deeply into their environments. They do so in order to address a broader range of integration scenarios, to support their own integration software products, and to position their platforms as alternatives to third-party integration software. What, for example, is Microsoft’s Windows Communication Foundation (WCF) if not an attempt to push ESB functionality more deeply into Windows.

In the next 2-3 years, the ESB wave may give some platform vendors an advantage over their direct competitors. When Microsoft delivers commercial WCF--and Windows Workflow Foundation (WWF)--functionality in Vista and “Longhorn,” the company will be able to position its server and client platforms as ESB-enabled out of the box. Microsoft has committed to running WCF on pre-“Longhorn” Windows platforms—Windows XP and Windows Server 2003--as well, which will further strengthen its ESB and SOA story.

Over the next several years, platform vendors who fail to address ESB functionality in their roadmaps will marginalize themselves out of the SOA market. Minor platform vendors won’t be able to survive in a market that will eventually be dominated by SOA platforms. Systinet did the right thing by seeking out and finding a suitor, though the combined Mercury/Systinet is on no one’s short list of leading ESB/governance vendors.

At the very least, all platform vendors will need to implement WS Reliable Messagnig (WS-RM) in their architectures in order to enable reliable, guaranteed, once-only delivery of SOAP messages over Web services environments. Any SOA platform vendor that fails to do so, and clings tenaciously to its proprietary middleware, will find itself shut out of the ESB space.

By the end of this decade, ESB functionality will just be common-denominator functionality implemented on all platforms, leveraging the industry’s common denominator interoperability stack: the WS-* stack. As ESB functionality becomes ubiquitous in application platforms, pure-play ESB middleware vendors will find the going tough. Today’s ESB middleware market segment will fade away, absorbed into the SOA platforms that will dominate all distributed environments. In order for these SOA platform vendors to distinguish their commoditized ESB features, they’ll have to keep evolving up the functionality stack, adding Web services management (WSM), dynamic content-based routing, distributed transactions, and other advanced features.

As regards WSM functionality, there’s little of that in today’s ESB market—that’s why the merger of Sonic (the ESB pioneer) and Actional (one of the WSM pioneers) is so significant. ESB vendors will layer WSM functionality on their product architectures in the coming years. It’s very likely that other WSM pioneers, such as AmberPoint, will find suitors in the ESB space. Another likely development is for network appliance vendors—such as Cast Iron Systems, Cisco Systems, F5 Networks, and Solace Systems—to reposition their products as high-performance ESB message processing nodes.

ESB-enabled SOA platforms will dominate, and also accelerate the decline of today’s separate ESB middleware market. The rest of this decade will see ongoing acquisitions, mergers, and consolidations among platform and middleware vendors. In particular, Sonic, TIBCO, Cape Clear, and Fiorano, though currently positioned well in the ESB space, won’t survive unless they partner or merge with SOA platform vendors. The surviving ESB-enabled SOA platforms will probably number no more than a handful.

No, I'm not placing any bets. Not a betting man.

Jim

Monday, January 16, 2006

fyi It's Just the Key to Your Room

All:

Pointer to article: http://www.computerworld.com/securitytopics/security/story/0,10801,107701,00.html?source=NLT_AM&nid=107701

Kobielus kommentary:
Fascinating discussion. Most mag-stripe hotel key-cards “contain only a room number, a departure date and a ‘folio,’ or guest account code -- although other data may be stored on them as well.” So, essentially, the key-cards are a credential/entitlement token tied to an identity and account maintained by the service provider (the lodging establishment) for a limited-duration facility-access grant. The property management system (PMS) links the identity (the customer name, address, credit-card info) to the access grant (the room reservation) and provisions and deprovisions the credential/entitlement token. The doorlocks enforce the entitlement grant (without the need to communicate with the PMS) by requiring the presence of a guest account code and comparing the departure date with the current date (presumably, tracked through a clock in the lock). The lodging establishment needn’t (and rarely does) encode your name/address/credit-card on the key-card itself, because billing for your use of this limited facility-access grant is handled through the PMS.

All of which reminds me of another great urban myth as regards hotel rooms: that the bed, dressers, desks, TVs, phones, and other surfaces are slathered in dried (invisible) semen stains. We’ve all heard this. I’m assuming it’s just a myth. It sounds like nonsense. Where did this myth originate from? How is it sustained? Who tests for this? Assuming it’s true in some cases, is it a general phenomenon across all rooms in all lodging establishments of all grades and in all states and countries? More important, is there any greater prevalence of dried semen in hotel rooms vs. people’s own bedrooms? People clean their own bedrooms and launder their own sheets far less frequently than most hotel/motels do theirs. Has anybody done any comparative studies?

Are people subconsciously worried about telltale DNA stains they leave behind in strange places? They should worry more about flaking skin and fallen hair shafts. We leave those DNA traces everywhere and never think twice about them.

Just as telling: The other peoples’ hair that can be found embedded in the carpet next to ours. Semen stains alone only tell half the story.

What story? Make up something. I’m sure you all have good imaginations where this sort of thing is concerned.

Jim

fyi Attacks mounting on 'Million Dollar Homepage'

All:

Pointer to article: http://www.computerworld.com/developmenttopics/websitemgmt/story/0,10801,107743,00.html?source=NLT_PM&nid=107743

Kobielus kommentary:
This is a case of the harder they come, the harder they’re hit. This page is an act of pure Internet-age hubris and opportunism, and to be admired for that. It shows how mere notoriety can be monetized to the hilt. Clearly, it’s no scam, just an ingenious moneymaking scheme: Tew is, quite transparently and honestly, selling a lease to presentable pixels over time, and the “rent” on this commodity is quite clearly derived from notoriety-stoked demand.

But, honestly, this is a crock: Notoriety has an extremely limited shelf life, especially in the overcrowded cybersphere. This site and these pixels were suddenly hot last week and this, but will soon be forgotten and never visited again by a mortal soul. Consequently, the pixels will be practically worthless for over 99 percent of the life of their lease. And even during their “heyday” (now), they’re of questionable value.

Case in point: I still haven’t viewed this “Million Dollar Homepage,” though I tried browsing to it several times last week (in its heyday—-its sweet spot--its period of max commercial value to tenants). I waited and waited for the page to download, and grew tired and eventually backed out before the access attempt had a chance to time out on me. This million-second wait may have been due to the huge volume of concurrent access requests, or to the DDoS attempt reported in this article, or to both. I don’t care.

What I do know is that even during the magnet page’s heyday, its effective value as a promotion, advertising, and clickthrough medium to its tenants was effectively zero.

As I said up above, the “Million Dollar Homepage” wasn’t technically a scam. Just a clever stunt that benefited precisely one party.

Jim

Monday, January 09, 2006

fyi How can DRM be good?

All:

Pointer to blogpost: http://www.lllj.net/blog/archives/2006/01/06/how-can-drm-be-good/

Kobielus kommentary:
In just a sec, you’ll have me kommenting on komment #8 on Lloyd Shepherd’s blogpost on DRM. Here’s that komment #8 again, sparing you the need to flip back to that (and away from me—hey, I’m trying to keep your eyeballs sticking here for a few more minutes):

o “All digital file formats become obsolete with time. DRM is designed to be incompatible and non-convertable, so the the real market test comes when people discover that all the multimedia they have bought is no longer supported by the newest hardware and that there is no easy way to convert it to the new platform when their old platform has been made defunct (for marketing reasons?). Even now, though for example divorce and migration, a few people have already discovered some of the unexpected limitations of DRM’ed multimedia. The only bright side to all this is that as long there are programmable general purpose computers one can always convert multimedia from a limited and incompatible (DRM) format into a portable open format. (See Microsofts’ Darknet paper). Lets just hope that DRM proponents don’t end up banning programmable computers and criminalizing DIY programming.”

This is the number #1 argument against universal DRM becoming a practical reality any time soon. Let’s look at the dynamics of the DRM space:

o Kontent seeks maximum distribution, availability, and consumership over its economic life, or over the life of consumer interest, which ever is longer (for the daily news, the economic life is a few days or weeks, for most content; for masterworks of literature, music, cinema, etc, the life of consumer interest in the indefinite future—future generations/eras will keep republishing and redistributing and reconsuming this stuff).
o Kontent that remains balkanized into incompatible, platform-specific, provider-specific, or otherwise fragmented spheres of distribution and consumption will revolt against those strictures and structures (especially for the masterwork kontent of perennial consumer interest).
o Kontent that remains locked into those strictures and structures will die in the marketplace, or die with the inevitable death of the enabling/capturing platforms; consequently, DRM technology (the enforcer of those strictures and structures on evermore access to perennial kontent) will die in the marketplace as well, unless it somehow becomes universal in implementation and also agile enough to support maximum (i.e., free, as in strictureless, and free, as in gratis) distribution/availability/consumership to kontent that demands (sometimes in spite of its owner/provider’s wishes) liberation.

Sounds like an unresolvable paradox. All the dynamics in the cybersphere militate against universal DRM. All the kontent of perennial consumer interest will migrate toward the gratisphere. Hence, all kontent period, even the ephemeral stuff, will find its way there too.

Circumventing whatever gantlet of strictures and structures the purveyors of the DRM pipedream lay down.

Jim

Thursday, December 29, 2005

poem Clock

CLOCK

Still from "Cessation":
Jean-Luc's frame-by-frame

examination
of teeth entering

holes with precisely
enough clockwise turn

to advance the film
one solitary

tick and tension in
a tough medium

to click this reel of
frozen times forward.

Wednesday, December 14, 2005

fyi Cyber Security Group Flunks Washington

All:

Pointer to article: http://www.internetnews.com/security/article.php/3570596

Kobielus kommentary:
Wonderful—-a relatively non-partisan issue that I can use to bash Bush, to illustrate his cluelessness on cybersecurity issues. Does anybody seriously think, if Al Gore were elected in 2000, that he would have paid as little attention to cybersecurity as this Republican administration has? He wouldn’t have used 9/11 (and it would have happened under either party’s watch) and its aftermath (and we would have invaded Afghanistan, though probably not Iraq, under a Dem administration) as a convenient excuse to ignore every national security issue that didn’t involve wasteful militarization and irresponsible troop deployments.

Whew—-got that out of my system. To be fair to the current administration, even if the Dems were in power now, cybersecurity (as a national security issue) would be a neverending circus. It’s already a lightning rod for political grandstanding, sensationalism, paranoia. Remember the good old McCarthy days when Commies were everywhere? That’s nothing compared with the identity thieves, virus spreaders, DDoS starters, spam blasters, spyware snoops, and other betes noirs that pervade this new threatscape. Many of the baddies are inhuman, literally (bots), or are human to the extremely limited extent that an untraceable physical finger clicked on an untraceable physical mouse button at some point in the past and triggered a chain reaction that still mushrooms around us.

Name me a politician—or even a single IT industry visionary—who has crafted a comprehensive enough plan for national or global cybersecurity? I mean, a plan, program, or set of governance principles that can effectively frame collective responses to all of the cyberthreat vectors now and in the unforeseeable future? Of course you can’t.

There’s no governance structure that can past this test. Everybody would flunk. Cybersecurity gores all.

Jim

P.S. Speaking of Washington, we recovered our car last night, which was stolen last Wednesday. Was abandoned on a residential street in the southeast quadrant of the Nation's Capital. Thank you Officer Sanders, and your partner who let us use her cellphone (Nextel's signal was fine and strong), and the lady who gave Egidia tea and a warm place to hang while we were waiting to have the scene "processed" by the authorities and to restart the vehicle. The thieves did considerable damage. I doubt we'll catch them, but I do have surveillance photos of them stealing it from the parking lot of my wife's place of employment. They apparently live near where they abandoned the vehicle, because there's no nearby Metro stop or main thoroughfare nearby to facilitate a quick escape. They seemed to bolt from the vehicle in hurry, having left it running (draining gas and battery), and leaving their break-in tool. At least those are my hunches on how to identity/target/trackdown these mofos. But I'm no Columbo. Good thing we leave nothing of value in our vehicles. No sensitive identity data. A car, which many people use as a lockbox, is a potential goldmine of identity data. I will throw out the open box of Cheez-Its they left behind, though.

Tuesday, December 13, 2005

fyi GAO finds 2.3M domain names registered with false data

All:

Pointer to article: http://www.computerworld.com/developmenttopics/websitemgmt/story/0,10801,106935,00.html?source=NLT_WK&nid=106935

Kobielus kommentary:
I’d call this Internet governance issue number one: at least one out of 10 domains is registered with false contact info.

From an Internet security standpoint, so much depends on the authenticity and accuracy of domain contact info within the Whois database: prosecuting online fraud, tracking malware, canning spam, warding off DDoS, identifying intellectual property violations, and so forth.

I’m shocked that the Working Group for Internet Governance only mentions the Whois database once in its recent 285-page tome on the topic, and only with reference to protecting the privacy of domain owners. ICANN, for its part, clearly hasn’t lit a fire under registrars to investigate, vet, and proof domain owners to a greater degree before registering their domains.

No matter who governs the Internet—ICANN or some body under UN auspices—we can’t rely on a domain registry that’s not authoritative. We can’t have rogue, spoofed, façade domains. They are number one threat to everybody’s trust in the integrity of the entire Internet governance structure. They are obvious harbors for criminal activity.

Jim

Friday, December 09, 2005

fyi Wikipedia Tightens Rules For Posting

All:

Pointer to article: http://www.informationweek.com/story/showArticle.jhtml?articleID=174900789

Kobielus kommentary:
And you thought I was being melodramatic when I said reputation is a creepy concept.

Quoting the referenced article: “Wikipedia, the open online encyclopedia that's written and monitored by volunteers, has changed its rules for submitting articles after a posting incorrectly linked the assassination of Robert F. Kennedy to a former administrative assistant. A May 26 posting on John Seigenthaler Sr., an assistant to the attorney general in the early 1960s, said Seigenthaler was ‘thought to have been directly involved in the Kennedy assassinations of both (President) John (F. Kennedy), and his brother, Bobby.’ Although Wikipedia founder Jimmy Wales has said that erroneous submissions are usually corrected within minutes, the Seigenthaler "biography" stayed on the site for 132 days before it was corrected. In addition, the "scurrilous text" appeared on search engines Reference.com and Answers.com, Seigenthaler said in a Nov. 29 editorial in USA Today. ‘I have no idea whose sick mind conceived the false, malicious “biography” that appeared under my name for 132 days on Wikipedia, the popular, online, free encyclopedia whose authors are unknown and virtually untraceable,’ Seigenthaler said.”

Now, read again my earlier statement on reputation: “Reputation feels anti-governance, hence unfair. It feels oppressive. It’s the collective mass of received opinion, good and ill, weighing down on a particular identity. It feels like a court where the judge, jury, prosecuting attorney, jailer, and lord high executioner are phantoms, never showing their faces, but making their collective force felt at every turn. It feels like outer appearances, not inner character, ruling our lives….Who, if anyone, are the "reputation authorities"? What, if anything, is a "reputation assertion"? How can we--the identified reputed parties--have any assurance that our reputation isn't determined by the collective malice of bad people who mean to distort and destroy us? How can we be sure that a balanced, fair evaluation of our reputation rises above the din and confusion? Who/what, if anything, is our public reputation (PR) agent/advocate in a world of free-floating ungovernable reputation?”

Not all of us have access to the editorial pages of USA Today to defend our good names. So, if the bad people propagate lies about us through Wikipedia, even for the short time necessary to ruin our reputations, what countermeasures do we have of equal or greater force to restore ourselves, and to hunt down those who’ve destroyed us?

Wikipedia needs strong authentication on all postings. And living people who are mentioned in Wikipedia entries need to be notified immediately upon publication, so that they can immediately correct the errors.

Of course, who’s to say who’s telling the truth about somebody: The original author, the aggrieved subject, or neither of them? How often will Wikipedia’s editors get caught in a tug of war? How reliable can Wikipedia’s entries be, under such circumstances?

Wikipedia’s reputation is what’s being damaged by all this.

Jim

Wednesday, December 07, 2005

personal Year gone by

All:

One weird stressful year, since late last. Among other things, car towed once (a year ago) and stolen (today). Lost a job, then found another. Aged beyond my eldest long-departed parent. Aged enough to see my eldest child attain majority. Saw my eldest sibling get married. Worked insanely hard. Published, didn't perish. Built some new skills. Kept my weight down in the optimal. Firmed up some muscles. Accomplished a great deal, but just absolutely bone-tired. Weathered more rejection and dejection than I can normally stomach. Been a year and a half since took a real vacation. Closed out "Pieces of Fate," and started a blog. Regained my pride. Made some connections and confessions. Asserted and expressed myself. Took no guff. GMMFM, MF. Lost some hair. Gained no stature, or some, no sure. Improved my posture. Kept on developing my thinking along as many modalities as I could stand, and then some. Rolled with the arbitrariness of it all. Regulated my regularities. Consumed my coffee and my KEXP. Passed the pretty without comment. Passed the mirror of recognition time and again. Passed my 20th year in my chosen/fated career. Passed a lot of ancient tension and peculiarity out of my system. Older now, thinner, taut, not necessarily wise. I’ll leave it at that. Chat with me now and then. Don’t be a stranger. Be a friend. Do the human thing. Come calling.

Jim

Tuesday, December 06, 2005

fyi What is Web 2.0?

All:

Pointer to article: http://edgeperspectives.typepad.com/edge_perspectives/2005/09/what_is_web_20.html

Kobielus kommentary:
John Hagel provides the right balance of openness and skepticism in his commentary on this topic. One quibble I have is with his use of the term “meme.” I can’t stand this neologism and its faux-analogy with genetics. Whatever happened to “trend,” “pattern,” “theme,” or “motif”? Hmmm…if we can agree to define “meme” as a portmanteau of “motif” and “theme,” then I’ll graciously come down from my high horse and agree to accept it into my personal lexicon. Or at least make my peace with it.

But more substantively, Hagel provides the right balance between induction and deduction in his approach to “Web 2.0” as a trendy (meme-y?) topic.

On the inductive side of the fulcrum, he calls attention to the O’Reilly Media folks who coined the term and primarily discuss it in the form of a tired/wired hip list of then vs. now Web hot topics: “There’s no denying that the meme has taken hold, having been developed only about 18 months ago by Dale Dougherty of O’Reilly Media. Unfortunately, as the Wikipedia entry on Web 2.0 reports, Dale never really defined the term, using examples rather than a definition to communicate its meaning: "DoubleClick was Web 1.0; Google AdSense is Web 2.0. Ofoto is Web 1.0; Flickr is Web 2.0."

On the deductive side, Hagel attempts to divine the underlying trends that distinguish “then” (the Internet/Web in the 90s) from now. He defines “Web 2.0” as “an emerging network-centric platform to support distributed collaborative and cumulative creation by its users.” He deconstructs his definition into its constituent concepts and defines each in context of emerging patterns/trends/etc. All of it a good high-level discussion.

My problem with all of this is that “Web 2.0” is so wrongheaded a term that it undermines his and others’ discussions of what’s really going on.

First off, the “Web” is just one of many Internet environments that’s evolving, and it’s distracting to lump blogs/RSS/syndication, SIP/VoIP/IMS, mobility/WiFi, SOA/XML/SOAP/Web services, messaging/collaboration, identity federation, and other important trends under this umbrella. Tim Berners-Lee was an important figure in the evolution of all this, but it doesn’t all spring from or bear the DNA of this particular Dr. Zeus.

Secondly, the “2.0” faux-version-number is ridiculous. The distributed Internet business/tech/cultural environment is evolving continuously on so many levels that it’s absurd to conceptualize it in terms of versions, or to even hint that versions are relevant anymore in this versionless new world.

Rather than fixate on the dumb “Web 2.0” term, let’s revisit Hagel’s definition of the underlying phenomenon: “an emerging network-centric platform to support distributed collaborative and cumulative creation by its users.” This is a good and valid statement of the dominant trend, though not quite as tight as it could be.

I suggest “a continuously self-reinventing environment.” That gets to the heart of Hagel’s definition, syncs with the genesis of the Internet as a research network continuously reinventing itself, and encompasses what others are trying to suggest with their diverse then-vs-now “Web 2.0” hiplists. In fact, the hiplists themselves are the fundamental reality: when we’re all reinventing everything in our environment all the time, the most effective way of getting your head around it all is to do period “round-ups” of then-vs-now tired/wired lists. These lists mark off important milestones in the everchanging environmental landscape.

Just as critics will soon be publishing their year-end 2005 tired/wired lists for movies, TV, lifestyles, etc.

Just as cultural commentators have long used decades as a convenient grouping mechanism (50s vs 60s vs 70s vs 80s etc) to chart long-running trends.

And just as Western society has long grouped historical developments into “modern” vs. “ancient” or “traditional.” Modern this and that. It’s all just a way of declaring what you consider hip with the contemporary world and want to see serve as a basis for future development. Recognizing of course that the world is fundamentally versionless.

Walk down any street in any city and see the mix of old and new architectural styles. The modern world doesn’t bulldoze the past out of the development equation.

There are no virgin or versioned worlds. There’s no World 2.0--just World 2005, followed by World 2006 and so on and so forth.

Jim

Thursday, December 01, 2005

fyi Mail order selective disclosure of organizational role

All:

Pointer to blogpost: http://www.ldap.com/1/commentary/wahl/20051130_01.shtml

Kobielus kommentary:
Mark Wahl’s commentary is an excellent discussion of assurance in identity management. It touches on a particular type of assurance: the confidence we place in human beings’ apparent intentions, their competency, their honesty, and so forth. Their apparent halos. Their personal assurance.

Wahl notes that we tend to trust strangers more if those individuals have all the external appearances—such as clothing, glib talk, personalities, and racial/ethnic backgrounds—associated with roles, or peoples, or stations in life, that we trust. The more of those external appearances that fit into our comfort zone, the more vulnerable we are to being duped by the occasional wolf in sheep’s clothing:

• The highway robber in a cop uniform.
• “Frank Abagnale Jr, subject of the movie Catch Me If You Can, improved the effectiveness of his check fraud scam by wearing an airline pilot's uniform, pilots being regarded as ‘generally credible and respected professionals’ and so be less likely to be cashing bad checks.”
• The suits we encounter in daily life who convince us to part with our life savings, or waste a big chunk of it on some unique, useless pile of sh*t that only their company provides, and only for a limited time, and only to special customers like yourself and your lovely wife, who obviously have the intelligence and sophistication and experience with such things to recognize and truly appreciate blah blah blah……..

In other words, the social-engineering attack. The con. In one of my recent blogposts, I analyzed the notion of “reputation,” construing it as a type of personal assurance in identity management. “In the IdM context, reputation is more of an assurance or trust level—an evaluation of the extent to which someone is worthwhile to know and associate with.”

In our respective blogposts, Wahl and I were approaching the subject of personal assurance from slightly different angles. He was focusing on the assurance we place in people that we know next to nothing about, other than the fact that they look and act trustworthy—wear the suit, talk the talk, etc. By contrast, I was looking at the assurance we place in individuals about whom we think we know tons, because we have access to what we regard as reliable hearsay/gossip, which tells us that so and so is a good or bad person, an acceptable or excessive risk, etc. He was focusing on the cultural stereotypes that drive our snap judgments of personal reliability, and I was focusing on the cultural grapevine that further confirms or informs those judgments.

This got me to thinking of something I was discussing with an old acquaintance the other day. This person—his name is a common cognate of my grandfather’s Christian name—asked if I would be interested in authoring an article on the possibility of “profiling” IT personnel to measure the extent to which they posed an “insider threat”: someone who was likely to betray their employer’s trust by stealing, compromising, or damaging data, software, hardware, and other IT assets. We just engaged in general brainstorming, but didn’t agree to anything in particular. I offered a few observations, and told him that he’s free to use anything I suggested, if he wished. I assume he’s reading this blog now, and recognizes himself. He’s still welcome to take the ball and run with it.

It just occurred to me that this “insider threat profiling” topic is an application of personal assurance. Before I launch into my further thoughts, I need to come back to Wahl’s post—in particular, the following excerpt:

• “In science fiction author Philip K. Dick's novel A Scanner Darkly, the character Fred, an undercover narcotics agent, would wear a ‘scramble suit’ all the time that he was not undercover. This suit protect's the wearers identity by preventing visual identification: it would encase the wearer and project onto itself random images derived from 1.5 million possible elements of human representations: ‘As the computer looped through its banks, it projected every conceivable eye color, hair color, shape and type of nose, formation of teeth, configuration of facial bone structure--the entire shroudlike membrane took on whatever physical characteristics were projected at any nanosecond, and then switched to the next.... the wearer of a scramble suit was Everyman and in every combination (up to combinations of a million and a half sub-bits) during the course of each hour. Hence, any description of him--or her--was meaningless.’”

Hmmm…someone’s external appearance/demeanor is like a suit that they put on (consciously or otherwise), and that others use as a primary input in assessing personal reliability and integrity. Which reminds me of a teeny-tiny poem I dashed off a few years ago:

• “TAKE SHAPE//we button nerves/and join the fray/a suit's a shape/we wear all day”

We hire people and invest them with responsibilities for many reasons. One of the big reasons is that they wear a trustworthy “suit” that seems right for the role to which we plan to assign them. We’ve all heard of, and occasionally worked with, the “empty suit.” How do we submit the “suit” to a multidimensional “profiling” that allows us to fathom the depth—and angel-to-devil ratio--of the person within? Given that human beings are so complex, creative, and unpredictable, how can we even pretend to know how anybody will behave under all possible future scenarios, and whether they’ll succumb now and then to the temptation to betray their employer in order to pad their own pockets? Or just to wreak havoc for the hell of it?

The cop-out answer is to say we can’t possibly assess other people’s trustworthiness and potential for mischief. But every one of us does it all the time with everybody we know, including our closest family and friends. We do it with bosses, co-workers, customers, and business partners as well. We all rely on intuition: some of us have particularly sharp intuitions, while others are hopelessly naïve and credulous.

How can we assess the trustworthiness of IT staff? These are people in whom you’ve invested responsibility for managing your company’s most critical data, applications, systems, networks, and business processes. Identity management (IdM) systems, in particular, are the most sensitive IT assets, because they drive authentication, authorization, encryption, auditing, and other critical security services that span most applications. How much assurance can you truly place in your IdM, PKI, and trust infrastructure if you have no trust in the people who manage it?

Which brings me back to the notion of personal assurance and profiling of IT staff. Personal assurance is not something you can measure in the abstract. Temptation can bring out the worst in any person. And aren’t the temptations available to IT staff just deliciously juicy? Those temptations become ever more acute as IT personnel realize that they are the high priests and priestesses of sensitive corporate apps and systems that few others understand, and as IT people realize they can easily cover up their misdeed and erase or efface any audit trails.

To the extent that you attempt to profile individuals for their potential to pose insider threats, you must consider the interplay between character and circumstance. Who is this complex individual? And what roles are they performing with respect to places, processes, and platforms in your organization?

Who is this individual? That’s the “character” issue, and you can begin to measure character in terms of some broad personal attributes: background (i.e, resume, transcripts, etc.), aptitudes (i.e, skills, certifications, tests, inclinations, dispositions, etc.), recommendations (i.e., reputation, hearsay, references), and record (i.e., actual documented performance as attested by reliable others, not by the individual themselves).

What roles are they performing? That’s the “circumstance” issue. You can measure circumstance, hence opportunity for mischief, by looking at how much power you’ve given them—or are contemplating giving them-- over your IT environment. Absolute power corrupts absolutely.

If you have exactly one IT person who does everything, you’ve created an opportunity for absolute abuse. How much assurance do you have in that one person’s character, however measured? If they’re the only IT “insider,” and you’ve tasked no other “insider” to serve as a check/balance/whistleblower, you’ve invested that one person with absolute assurance.

Which I’m assuming they’ve earned. They’re a familiar face and name, not some anonymous schmoe you recently hired off the street without checking their references, background, criminal record, etc.

Right?

Jim

Tuesday, November 29, 2005

fyi Above the Cloud: Clients virtualize beyond recognition

All:

Pointer to article: http://www.networkworld.com/columnists/2005/112805kobielus.html

James Kobielus, Network World, 11/28/05:

Client virtualization is an underlying theme in many recent industry announcements.

In virtualization, the external interface of every service becomes unmoored from its implementation in particular physical platforms, operating systems, application frameworks and software components. Essentially, a client becomes virtualized when its GUI grows abstracted from the resources of the local access device, be it a PC, handheld or other computer. The virtualized client may rely on both local and remote network resources to render its interface, furnish its processing power, store its data, route its print jobs and handle other core client functions. Users remain blissfully unaware of what blend of distributed resources is actually driving their presentation experience.

Vendors are avidly exploring ways to virtualize client environments. Take Microsoft Windows Vista, for example. In the long, tortured ramp-up to the release of this client operating system, Microsoft has removed most of the new functional components - including security and file-system enhancements - that were supposed to make Vista worth waiting for. What's primarily left is a client virtualization technology called Windows Presentation Foundation (WPF), which allows the Windows GUI to be dynamically rendered, tailored and customized by applications, in keeping with a declarative markup syntax called Extensible Application Markup Language (XAML). Essentially, WPF/XAML enables a virtualized separation of the Windows presentation interface from the underlying application code.

Microsoft has even decoupled WPF/XAML from Vista, taking the Windows platform another step down the road to total virtualization. WPF/XAML - and all Vista features - also will be made available as retrofits for legacy Windows operating systems, including XP and Server 2003. Essentially, this new technology will become the virtualized presentation layer to all Windows versions.

There's even more to Microsoft's client virtualization story. Earlier this month, Microsoft announced its Windows Live strategy, under which operating system and application features will be provided as hosted software as a service. Essentially, Live is aimed at making free Microsoft-hosted services - such as e-mail, instant messaging, search, file sharing, VoIP, software delivery and RSS aggregation - integral to Microsoft's not-free client software. When the client operating system goes "live," per Microsoft's strategy, it blurs the practical boundary between those functions the client performs from local resources and those it relies on the service fabric to accomplish.

But let's not give Microsoft all the credit for the trend toward client virtualization. Enriched browsers of all varieties - including Macromedia Flash and other vendors' plug-ins - are blurring the practical distinction between clients and servers even further. Enriched browsers such as those supporting Asynchronous JavaScript + XML (AJAX) deliver a more GUI-like user experience than a basic browser. AJAX-capable browsers, such as Internet Explorer and Firefox, shift the presentation emphasis away from downloading individual Web pages toward navigating within richer, structured, client-side content caches. The enriched browser can execute more application logic, cache more content and perform more rendering locally than a basic browser. And it offloads some or all of these functions from portals, Web sites and other presentation servers.

The offloading can go both ways, of course: Most of the processing power of PCs can be centralized into server chassis, per the network PC approach first introduced in the late 1990s. A new twist on that approach - the blade PC - is the most important development in desktop management in many years. Blades from pioneers HP, ClearCube and IBM virtualize desktop resources into manageable slices of a server's centralized resources, transforming the innards of each PC into a blade that can be installed in a server chassis. The user relies on a thin-client windowing protocol such as Citrix's Independent Computing Architecture to interface remotely to what is, essentially, a full-featured dedicated PC.

Clearly, virtualization is transforming client-side computing beyond all recognition. The presentation tier is blurring into the application-server, middleware and networking infrastructures.

fyi Dutch Firm Wants End of Dot Com

All:

Pointer to article: http://www.newsfactor.com/story.xhtml?story_id=39695

Kobielus kommentary:

These alternative-root DNS registrars feel like the future of the Internet. Think of the possibilities. Create your own TLDs, register them with Google, and you’re in business. Assuming, of course, that anybody would use a Google-provided TLD search service. Which, if Google ever offers such a service, I assume everybody will. Or if not Google, whatever constellation of federated search engines eventually replaces Google. And somebody or thing will replace Google, believe it or not. De jure regulated TLDs are so yesteryear. ICANN? Everybody can, if they want to. Alternative-root registrars? Everybody will have the power to be their own root, or registrar, if they get visibility in search services. The world doesn’t want to kowtow to the US on domains. Nor to any other centralized registry, or static oligarchy of registrars. Mesh registries. Dynamic search, binding, and domain routing. A self-describing, discovering, configuring Internet on the most basic level.

Jim

Monday, November 28, 2005

imho risk analysis when an identifier is lost

Abhilasha:

Pointer to article: A

Kobelius kommentarius:
Thanks for the blogfodder. Now for responses to your particular queries:

• IdM and cellphones: Cellphones bring device identity—in particular, the IMSI--into the IdM mix. 1992—the year GSM got going—was the pivotal year.
• IdM and webservices: Web services—in particular, the URL—have made all the world’s resources directly addressable, or potentially so. 1995 was the inflection year. It was the year of the Web, of the URL, of the beginning of the all-points-addressable world economy/society.
• Why did CORBA fail: Not a clue. Perhaps because it sounds like a scary snake. Or perhaps because Web services, as a middleware environment, had from the start something CORBA never did: universal adoption across all platforms. In particular, the full force of Microsoft. The foundation year was 1999, when SOAP was announced.
• Federations may be difficult in the first place: Federations are as simple or difficult as you want/need to make them. What are you federating? For what purposes? How deeply and thoroughly are you federating diverse environments? Federating involves a lot of sweat equity. Once you’ve begun to federate, de-federating is painful. The important year was 2002, when, in the context of a Burton Group Catalyst hospitality suite, I brought a dozen vendors together to demonstrate early interoperability using a limited subset of pre-standard SAML. Kudos to Don Bowen, Hal Lockhart, and everybody else who thrashed through all the low-level federation issues, from an integration standpoint.
• Business and practical realizations of this based on incentive or economic impact: Stay tuned to Liberty Alliance for federation implementation and policy guidelines. The pivotal year for them was 2003, when it became clear that the industry needed them for this role, on an ongoing basis, and they could gracefully hand off standards development to OASIS. I was delighted to play a teeny-tiny part in consulting to them in the beginning, during my Burton Group years. Kudos also to Dan Blum.

It’s risky to lose your self-identification as an analyst. That’s why the blogosphere is so invaluable. Stay the same, in the game. Stay yourself, keep your health. Weathering desertion requires self-assertion. Continuous re-insertion.

See you one of these days. I don't recall actually meeting face to face at the July event. Sorry we couldn't sync live earlier this month. Rain check, OK?

Jim

Sunday, November 27, 2005

imho retroactive (accountability) how did you get that information

All:

Haiku: al

Aku:
How did you get a particular piece of identity information on somebody else? That’s a bit like asking how a particular dollar bill with a particular serial number ended up in your wallet. Or how you came down with your latest headcold.

Retroactively, tracing the chain of custody of any fluid entity—data, currency, infectious diseases, etc--is a task for forensic investigators. And a particularly labor-intensive task at that. You only track accountability for that chain in order to assign responsibility—hence sanctions—and to break the chain of transmission from being exploited further.

Identity is currency, of course, and currency has a way of flowing across all boundaries, even when the “authorities” used their fiercest weapons to stanch the flow. I hate to be fatalistic about it, but humans are addicted to currencies of all sorts. Stubborn human addictions—money, sex, drugs, etc.—have a way of crashing all boundaries everywhere, and are quite clever at concealing their tracks. A couple of years ago, I wrote the following poem as a meditation on this phenomenon, in which the liquid transnational entity (ambition, money, semen, disease, etc.) seems to have a calculating mind all its own:

*********
CALCULATION

Open borders are
dominions liquid as
calculation.

Common currencies
cross land to land as hands pass
contagion.

The path of a sneeze
is everywhere open to
opportunity.


*********

Not really a triple-haiku: 5-6-4/5-7-3/5-7-5, not 5-7-5/5-7-5/5-7-5. Rigid calculation can become robotic. Truly infectious strings change their outer markers to foil defenses.

Plagiarism is becoming a surprisingly easy offense to detect. Every original author’s body of work is marked by that author’s unique style. It’s fascinating how researchers can algorithmically detect my or anybody else’s natural writing style, in terms of sentence structure, word choice, and other recurring elements. Essentially, your body of original written work is a key element of your personal iSoR, traceable back to only you (unless you’ve been plagiarizing others wholesale since the moment you first laid hands on keyboard). To the extent that others steal whole chunks of your written oeuvre and claim it as their own, they are laying their thievery wide open to detection.

Here’s something else I wrote in the 90s that’s relevant to this meditation:

********
WORLD WAR W

Bet we’ll strangle on strings
Enemies will seek out catchphrases
Everybody who ever banged the boilerplate
Rounded up into hit lists
Caught in crosshairs
All ten million
Pressed away.

********

Written in 1998, when search engines were in their infancy. Google and kin are now the number one answer to the “how did you get that information” question. They’re also the principal means through which our personal iSoRs are exposed to the world’s view.

In perpetuity.

Jim

P.S. A few hours ago I wrote/posted "imho identity privacy reputation." Now it's been scooped up by http://planetidentity.org/. They misspelled my surname. So did Alison Statton and Spike. Some stuff I put out there not expecting anybody to notice. And folks do. By the way, is there some universal dyslexia that causes people to transpose i and e in the middle of unfamiliar words? And even in very familiar words. Wierd!

imho concentration of information

All:

Chicago Liberty: ahs

Franconia Fraternity:
Earlier in this imho thread, I introduced the notion of an “identity system of records,” or iSoR. I introduced it in the context of how a credit bureau that has no prior B2C account relationship with a particular individual (whose identity the bureau tracks) might authenticate/authorize someone who purports to be that individual to access the individual’s system of records:

“Essentially, they authenticate you by doing a Q&A session in which you and they match your respective iSoRs. They pose a series of multiple-choice questions to you, drawn from data in your iSoR (held by them), and score your responses. These are questions that only you (the identity subject, mining your own personal iSoR which you, hopefully, have never divulged in its entirety to any other party) can be expected to answer correctly. If you answer the Q&A session perfectly—or near perfectly—the credit bureau authenticates you and authorizes you to access the iSoR that they hold on you.”

One issue I didn’t raise in this context is: What if the subject of the iSoR doesn’t have a clue about their own assets, investments, finances, and transactions? What if they haven’t kept their own centralized/consolidated iSoR? What if their iSoR is hopelessly out of date or inaccurate? What if you’ve trashed older records corresponding to those that the credit bureaus still maintain? What if you’ve kept all of these records (paper and/or electronic) but haven’t gotten around to sorting through it and documenting it concisely for your own consumption? Then you--the subject of the credit bureau’s iSoR--are likely to fail the iSoR-matching zero-knowledge Q&A test. And you will be prevented from accessing and, if necessary, correcting your own credit history.

In an ideal world, each of us would preside over our own personal IdP domain, and others—including big impersonal institutions—would bid for access to our identity data—to our iSoR. One corollary of that vision is that each of us would be the master concentration point for all identity data, current and past, that constitutes our iSoR.

But let’s get real. That’s a big burden for most people, and a supremely boring tedious activity. Personally, I’d rather be listening to www.kexp.org than poring through mutual fund statements. Tracking our own financial profiles/histories becomes a bigger pain in the neck as you accumulate more investments and engage in a growing volume of transactions. The longer you’ve lived, the more challenging it becomes. Just imagine the burden that awaits your heirs when, upon your demise, they attempt to aggregate your overstuffed financial iSoR onto theirs.

Who can keep track of this stuff? That’s why the wealthier hire financial advisers to help them track their assets. Which is just another institution you trust to manage your iSoR. Perhaps you can also task this institution with the ongoing job of tracking and requesting corrections to copies of your iSoR that are held by other institutions.

Which institution do you trust more? How do you know when your personal iSoR manager isn’t robbing you blind? How do you know when this and other institutions are in cahoots in that endeavor?

Concentrate on your identity information. Concentrate on your finances. Concentrate on your concentrators.

Don’t let yourself get hypnotized by confidence artists.

Jim

imho identity privacy reputation

All:

A basic holler in light and syrup: rahB

Holistic attestation:
Reputation is one of those words that creep me out. As an identity management (IdM) construct, it’s even vaguer than role (which I recently, October 20, in this blog, defined as “an identity in its full governance context”).

Reputation feels anti-governance, hence unfair. It feels oppressive. It’s the collective mass of received opinion, good and ill, weighing down on a particular identity. It feels like a court where the judge, jury, prosecuting attorney, jailer, and lord high executioner are phantoms, never showing their faces, but making their collective force felt at every turn. It feels like outer appearances, not inner character, ruling our lives.

Reputation is one part prejudice—-as in pride and prejudice—-as in the oppressive mass of received opinion that unfairly pins the victim into a mean, narrow, constrained existence—-as in always having to defend yourself against whoever whatever wherever whenever. Reputation as a collective weapon in the service of conformity and mediocrity.

Reputation is another part consequence—-as in never being able to live down or escape the past—-as in everybody everywhere keeping a collective dossier on your every activity—-as in never being able to start over with a clean slate.

Reputation isn’t an identity, credential, permission, or role. It isn’t exactly an attribute, in the same sense that, say, your birth date or hair color are attributes. And it isn't something you claim any privacy protection over--it's the exact opposite: the court of public opinion over which you have no sovereignty and little direct control.

In the IdM context, reputation is more of an assurance or trust level—an evaluation of the extent to which someone is worthwhile to know and associate with. Here’s the definition of assurance from my forthcoming essay, “Federated E-Business Assurance: the Policy-Driven Basis for Trusted Collaboration” (the essay, which I co-authored with Rob Sherwood, will be included in a book of security visionary thinking to be published by Homeland Defense Media:

“Assurance…generally refers to the degree of confidence that a relying party can have when accepting a password, certificate, token, assertion, claim, or other credential that is associated with a particular identity. Fundamentally, assurance is the confidence that someone else is reasonably safe to do business with. Assurance serves the relying party, allowing them to strongly verify the authenticity and validity of others’ identities, attributes, credentials, and assertions. It provides the relying party with the information they need to determine whether to refrain from, closely monitor, and/or repudiate online interactions in which such verification is lacking. It also gives the relying party the confidence that, if adverse consequences result from doing business with someone, the responsible parties can be pinpointed effectively so that appropriate legal, business, and other remedies can be pursued.”

Reputation is relying parties’ evaluation of our reliability, of their liabilities, and of the degree to which associating with us makes them ill at ease. Appearances are assurances, for good or ill.

Relying parties—-the ultimate policy decision and enforcement points in any interaction—-need many levels of assurance if they’re going to do business with us. They gather assertions and data from many IdM “authorities” (authentication authorities, attribute authorities, etc.) before rendering their evaluations and opening their kimonos. They—-the relying parties—-make reputation evaluations based on information fed in from trusted authorities, from their own experiences with us, from whatever reputation-relevant data they can google across the vast field of received opinion and public record.

Who, if anyone, are the "reputation authorities"? What, if anything, is a "reputation assertion"? How can we--the identified reputed parties--have any assurance that our reputation isn't determined by the collective malice of bad people who mean to distort and destroy us? How can we be sure that a balanced, fair evaluation of our reputation rises above the din and confusion? Who/what, if anything, is our public reputation (PR) agent/advocate in a world of free-floating ungovernable reputation?

This topic leaves me queasy. Reputation still comes down to appearances, no matter how you approach it. It comes down to spin. Tell the spinning to stop. I'm about to hurl.

Jim

Saturday, November 26, 2005

imho lack of global identifier

All:

Tag: vag

Schwag:
On August 18 of this year, in this blog, I floated the following thought:
“DNA…is our ‘birth day credential’ (or rather, conception moment credential, but first presented publicly on our birth day). Why do we take a baby’s footprint upon birth, but not their DNA print? Why aren’t DNA prints strongly bound to a digital master of our very first identifier: our birth certificate? Absent that, how can we know for sure whether the person claiming to be Jane Doris Doe for the purpose of applying for a credit card account is in fact the person who was born with a particular DNA print and assigned that name at birth (or assigned a name that they later changed to Jane Doris Doe, perhaps upon marriage or adoption)? If we can’t strongly bind a person’s human name to their DNA at birth, and bind each new name (legally changed) to their previous legal name, always anchoring it all in their birth day credential, then assurance is never strong.”

For the DNA birth day credential (henceforth, BDC) to become a truly global identifier, we would need to put several huge projects on the road to fruition:

• Persuade the entire human race—all governments, religions, cultures, etc—to recognize the primacy of this new identifier
• Get all hospitals, doctors, midwives, and mothers everywhere to promptly take a DNA sample of every newborn (and stillborn?) that emerges from the womb
• Secure the sworn, legal testimony or affidavit of a witness, notary, or some other person who witnessed the birth and DNA sampling of each newborn, attesting for its linkage to a particular baby given a particular traditional birthname and born to a particular woman at a particular day/time/place
• Institute laboratories everywhere that process DNA samples, identify the BDC, and recommend to local birth registrars the issuance of digital birth certificates that cryptographically bind the BDC to the new child’s traditional birth name
• Check the uniqueness of each requested BDC (or, for identical twins, triplets, etc, the uniqueness of their shared BDC) prior to issuance of the BDC birth certificate(s), thereby guarding against BDC fraud
• Issue the BDC certificate, assigning each one a globally unique identifier, and signing the certificate with the birth registration authority’s unique signing key
• Post the BDC certificate to an online registry infrastructure where they can be indexed and searched
• When changes of traditional birthnames are requested, get all governments, courts, religions, etc everywhere to issue namechange certificates that associate the name change to a particular BDC and its globally unique identifier, and to digitally sign the namechange certificate with the namechange authority’s unique signing key
• Post the namechange certificate to an online registry infrastructure where they can be indexed and searched
• Federate this whole infrastructure under global trust, policy, security, legal, regulatory, and treaty relationships among all the world’s nations, peoples, religions, etc.
• And….oh yes…all of us currently alive would need to submit our own DNA for a retro-BDC-ing, to literally populate this unique identification scheme and make it useful/global here and now

I’m probably overlooking some important things that need to happen to make this a reality. I’m not saying it’s practical or feasible or even desirable here and now. Or that the human race is ready for this federated birth registry on some deep cultural level.

I’m still working through all those issues in my head. Or not.

Jim

imho bottom up: companies want to own the data

All:

Start: napS-

Fit:
The only data—literally, “given”—is the persistence, in the aggregate, of demand, currency, and customers, none of it truly “owned” by any company, any more than any one organism can own the air we all breathe.

Sure, companies want to own the data. They want to own everything, and not have to answer to others or be “stewards” of resources owned elsewhere. They want to be self-contained autonomous ever-expanding universes.

Your and my identity is their prime resource. It’s a given, just as the sun shines. Their dreams of owning our identities are part and parcel of the imperial business ethic, which the late, great Peter Drucker inadvertently sloganized when he said the purpose of business is to “create” customers. Yes, to create customers—you and I--just as God created the heavens and earth, and then set about naming every beast of the land, sea, and air. If you’ve gone to great lengths to create a productive little ecosystem, wouldn’t you too take a proprietary interest in the identities of every creature under your dominion?

Companies want to expand forever—which is, of course, impossible in a closed universe. Under such circumstances, one creator will quickly dominate all others and deprecate them to some subordinate rank, be it lackey angel or apostate devil. Companies quickly realize that the customer they think they created in fact predated and will survive them—and has an identity and sovereignty and loyalty to no one but themselves. The customers are in fact the gods of commerce, and will just as readily destroy a company as create and sustain it.

You can’t own customers. You can only earn their repeat business. And you can’t own their identities. You can only ask for customers to continue recognizing your identity, and recognize your right to continue existing as a business. Yes, you can collect and hold their identity data. But you can’t hold customers indefinitely unless you vanquish all competition.

Or continue to ask the sovereign identity holder for access to their datum. And give them something of value in exchange for this precious currency.

Jim

Wednesday, November 23, 2005

imho profiling

All:

Whence: lezt

What:
Profiling, a formerly innocuous term, has gained negative connotations in recent years. Now it’s almost always construed in the context of “racial profiling.” It’s suffering the same fate as “exploitation” (prior to feminism, this simply referred to usage, consumption, and/or deriving some advantage from some resource) and “notorious” (prior to John Dillinger, this simply meant a person of note, regard, or reputation).

In an IdM context, profiling refers to the ability to compile sufficient identity data for the purpose of targeting individuals of note so that one may derive some advantage from one’s business association with those individuals. It needn’t always be to the disadvantage of the subjects of the profiling, of course (Dillinger analogy notwithstanding—this is one individual who certainly wished he hadn’t stood at the business end of the FBI’s targeting strategy—also, one thinks of the paparazzi, who certainly exploit others’ notoriety, thereby increasingly that notoriety/marketability and pissing off their subjects in the process—paparazzi profile based on one single criterion: the price that a candid photograph of the subject can fetch).

The subjects of profiling needn’t always be unwilling victims. To the extent that we the subjects control our own profiles and can parcel out access to relying parties, we can stay out of everybody’s crosshairs, or put our identities out in the public arena for maximum exposure to and exploitation by others. To the extent that we can inspect/correct the profiles that others hold on us, we can at least prevent unfair exploitation. Correcting errors in your online credit histories (held by D&B etc.) is one such way in which we can gain some modicum of control over the legitimate and quite powerful profiles that others hold on us. Every American now can get a free copy of their credit history from the major bureaus each year, and correct them—all online

It’s interesting how these bureaus authenticate you—the anonymous web browsing entity with whom they have no prior business relationships—for the purpose of authorizing you to view your credit history (and request corrections to that profile). Essentially, they authenticate you by doing a Q&A session in which you and they match your respective identity systems of records (iSoR—I love this acronym, which I just concocted now) associated with your credit history. In other words, they pose a series of multiple-choice questions to you, drawn from data in your iSoR (held by them), and score your responses. These are questions that only you (the identity subject, mining your own personal iSoR which you, hopefully, have never divulged in its entirety to any other party) can be expected to answer correctly. If you answer the Q&A session perfectly—or near perfectly—the credit bureau authenticates you and authorizes you to access the iSoR that they hold on you.

This is essentially a “zero-knowledge proof” of your identity, in which you’ve divulged nothing to the relying party that the relying party didn’t already know. All of which reminds me of a research paper recently co-authored by muse: “Establishing and Protecting Digital Identity in Federation Systems.” In it, muse and collaborators provide an approach for protecting user attributes against identity theft. Their approach involves associating various attributes from a user’s private iSoR (my term, not theirs) with each other and with a user’s identity. In order for somebody/anybody (the user included) to exploit the user’s identity for any purpose—such as to authenticate to a credit bureau, say--that entity needs to marshal a specified subset of the user’s private iSoR as a “proof of identity.” The approach allows the user to provide that “proof of identity” to any relying party—and lets the relying party to verify the proof of identity cryptographically—without the user ever needing to disclose any particular piece of privately held iSoR data. Essentially, the user is a private IdP, and federates their personal data attributes to any SP in such a way that the user only needs to establish that they are the sovereign IdP for that data—whatever its values may be—and never loses control over their private iSoR/profile. The SP simply matches the personal IdP-presented private-iSoR proof-of-identity to the shadow iSoR that they hold on you.

At least, that’s what I think is going on in the paper. Interesting stuff. But mine eyes are sore from trying to divine the math.

Jim

Tuesday, November 22, 2005

imho Formal model based secruity

All:

Spellmaker: tzel

Spelltaker:
Remember the good old days when developers produced something called “programs”? The march of virtualization-—and of SOA-—has hastened the demise of “programs” as the basic unit of development, in favor of more diffuse constructs: models, patterns, and services. A little over a year ago, I wrote a column for Network World (http://www.networkworld.com/columnists/2004/090604kobielus.html) on this topic. Rather than attempt to paraphrase myself, I’ll simply quote myself, and pray that John Gallant and Susan Collins won’t ding me for reusing, at length and for no personal remuneration, content that I authored but their publication, technically, owns (and isn’t reuse the foundation of SOA-based blogging?):

************************

“SOA is a disruptive approach to building distributed services. Until now, we've developed new functionality on and within concepts such as platform, application and language. Each of these concepts has traditionally had a well-defined sphere of reference: The platform hosted the application, and the application was developed in a language. Now all that is changing, thanks to the emergence of SOA.

The first of the old computing concepts to wither away will be the platform. This term originally applied to operating systems, then included application servers that implement a particular development framework (Java 2 Platform Enterprise Edition or .Net) over one or more operating systems. But the growth of standards-based, distributed Web services has made it clear that fewer and fewer business processes will execute entirely within the confines of a J2EE 1.3 server or Windows Server 2003, or Linux, but will execute across them all. When all platforms share a common environment for describing, publishing and invoking services, the notion of self-contained platforms disintegrates in favor of SOA, which is essentially a platformless service cosmos.

Another casualty of this evolution is the notion of applications as discrete, functional components that execute on particular platforms. SOA is founded on the notion of virtualization. Under this paradigm, services describe abstract interfaces within standard, platform-independent metadata vocabularies such as WSDL. The underlying service functionality may be provided from components on any platform without needing to change the interface. Under SOA, the application dissolves into a service that may have no fixed implementation but simply bids for on-demand networked software and hardware resources.

Programming languages also are becoming something that fewer developers touch directly. Visual model-driven development and automated code generation are at the forefront of the SOA revolution. You're more likely these days to see a vendor boast of its ability to support visual modeling in Unified Modeling Language than development in Java, C# or any other declarative programming language. For complex, orchestrated, multiplatform Web services, visual modeling is the most effective approach for specifying, implementing and maintaining the end-to-end logic and rules on which the service depends.

SOA has spawned a range of terms to describe what developers actually develop. IT professionals increasingly define their creations in terms of services, models and patterns, rather than platforms, applications and languages. The notion of patterns will become critical to discussions of distributed services. A pattern is a generic approach - such as service proxying or service coordination - to architecting interactions in the infrastructure. Every pattern defines its own abstract Web services functional elements and SOAP-based interactions.”
************************

Where formal model-based security (yes, I've proofread the subject line, and am keeping the muse's original typo intact) is concerned, what are the dominant patterns? Can we even begin to discuss patterns in an area as all-encompassing and pervasive as security. Let’s limit our discussion to identity management (IdM). And, while we’re at it, limit it to federated IdM. If we accept that limited scope, the dominant patterns are defined by the use cases that a federated IdM environment addresses. Even then, we’ll need to spell out the dimensions of use cases, rather than enumerate the possible patterns themselves, because recombinant explosion, reflecting the diversity of real-world requirements and environments, defies our efforts to define off-the-shelf cookie-cutter federated IdM environments.

The principal elements of federated IdM models/patterns are, per the various use-case dimensions:

• Federation cross-domain topology: point to point, hub and spoke, decentralized, peer to peer
• Federation cross-domain transactional applications: identity, attribute, role, permission, and account provisioning; single sign-on; role-based access control; permission-based attribute sharing; digital rights management; secure messaging and collaboration; business process management; service management
• Federation middleware service layers: messaging, description, discovery, data management, metadata exchange, security, reliable messaging, event notification, pub/sub, transactions, orchestration, presentation, state/session management, service management
• Federation policy enforcement point deployment: intermediate systems, network perimeters, network endpoints
• Federation assurance levels: authentication assurance, credentials assurance, identity assurance, authorization assurance
• Federation governance: bilateral trust agreements; multilateral agreements

I’ve probably left out some important considerations. Regardless, any formal model of federated IdM security—or of security generally—needs to be built on such dimensions. Likewise, any model of the end-to-end set of compliance baselines that govern federations needs to mirror this multidimensionality.

Modeling’s the thing. Konceptual klarity uber alles. Mental acuity, model-based secruity.

Jim

Monday, November 21, 2005

imho Liability SP or institutions

All:

Per your message: Span

Latest installment:

Lies and liability. Dupes and duplicity. Assertions and near-certain litigation.

When is the asserting party (the identity provider, or IdP) liable for asserting (deliberately or inadvertently) what, upon closer inspection, turns out to be an untruth, and when is the relying party (the service provider, or SP) liable for not using standard verification mechanisms prior to relying upon that untruth?

When is an assertion, if not a lie, simply null and void, in terms of having exceeded its maximum time to live, as specified in trust agreement between IdP and SP? Or, if not null and void, out of its intended context, in terms of being relied upon for an application that the IdP and SP agreed is out of bounds? Or being misconstrued as implying a higher degree of assurance than warranted by the policies and practices of the IdP, as asserted between consenting lawyers at conception (of the trust agreement between the two organizations)?

Federations, built on contractually codified “trust relationships,” threaded back and forth by assertions and actions taken in response to those assertions, can easily crash in acrimony. And liability can get muddied in the complexity of federated IdM environments. Add more assertions, messages, flows, and parties to a federation scenario, and you're effectively adding more legal nuance that a smart lawyer can swing to their client's advantage, wiggling out of any liability and shifting it to others in the federation.

Try explaining the intricacies of a multidomain SAML 2.0 federated SSO environment to a jury of your peers. It’s all just a mess of messages, after all. Are your federation agreements spelling out the precise choreography and content of assertions that constitute legal binding contracts among IdPs and SPs?

Do your lawyers truly understand any of this? Can they defend it effectively in a court of law?

Jim

imho Why don’t we have increasing mandates in security and privacy

All:

Fro: gav-

To:
Mandates are seismic waves that propagate throughout the striated distributed medium of modern e-business.

Mandates pierce the clutter and introduce changes across many layers, causing some shattering of the landscape, some mass evacuations, some inevitable terror and confusion. But mandates aren’t so scary when we see them coming from a long distance and can make plans. And they’re not so terrible when we’ve had a hand in shaping them. Any democratic system—laboring under a legislative/regulatory mill with full, extended public comment—meets those requirements. And any federated democratic governance structure—in which the ploddingly slow jabber-mill gets refracted and damped by endless cross-negotiations—absorbs such universal shocks so well that we barely see the chandeliers swing when the ground eventually does decide to hiccup.

We have had increasing mandates in security and privacy for several years now, and it’s only going to continue. In fact, every mandate that comes down the pike seems to concern security and privacy in various degrees—in the US, SarbOx, HIPAA, GLB, FFIEC, CAN-SPAM, etc.—in various US states, equivalent and/or consistent legislation/regulation—in other countries, same sets of concerns, different mandates.

Every mandate is a new source of “thou shalt comply” commandments on enterprises and service providers. Of course, there are as many “thou shalt comply” religions as there are governments, agencies, laws, and bosses upon the face of the earth. To the extent that you operate worldwide—or even in a single region—how can you effectively comply with requirements that issue from so many rule-gods, who don’t always talk/agree with each other up in the clouds of olympus, and who are changing their god-minds independently all the time? To the extent that all these rule-gods “federate” (i.e., agree to respect each others’ jurisdictions, honor each other’s decisions, and harmonize their respective approaches), your job (the haplessly hopelessly pliant and compliant clay/mud at their feet) is easier.

Compliance is the capacity of responding effectively to mandates. Mandates are imperatives issued by authorities. Authorities are the administrators of domains. Domains are the perimeters within which various human activities are conducted, administered, and regulated. Domains are more multi-dimensional than the hyper-mega-universe imagined by Stephen Hawking. Security/privacy domains can be defined as environments in their own right, or as strata within domains constituted on other grounds (e.g., management domains, orchestration domains).

Security/privacy, by forming part of every domain’s landscape, rocks the foundations of everything. Mandates introduce more fault lines into that bedrock. Federation takes those fault lines and arranges them into patterns that will do the least damage to domain perimeters, when the global shock waves eventually hit.

Mo’ metaphors, please.

Jim

Friday, November 18, 2005

imho Balance usability and Privacy

All:

Muse: Bhar

News:
Usability? I don’t want others to invade my privacy because it's a user-friendly thing to do.

Usability? Could the blinds on the windows of my house be any more usable? As Lily Tomlin said, living in the city means always knowing where your wallet is. It also means not simply leaving the places you own, such as your home and car. It means placing valuable items where they can’t be easily seen from outside, then shutting doors and windows behind you, locking them, giving them one extra tug to test the security of the lock, and then walking quickly away so that strangers don’t sense that a place with valuables is newly vacant and the live-in/drive-in sentry won’t be back for a decent interval. Oh…and taking the key with you, secreting in on your person, always being aware of its presence….or freaking out upon its apparent absence.

It’s not a question of whether this or any other privacy-protection scheme is usable. We’ll morph our habits in some weird ways to protect our dearest possessions. And we’ll forget that this strange new choreography of worry, wariness, and response isn’t first-nature. It only becomes second-nature after we’ve retooled our daily rhythms around it.

About privacy protection in computers, across the Internet….where do you put your personal key….and how do you sense it on, or adjacent to, your person? In my job, I have a USB token that holds a private key, which is associated with the public key bound to my identity on an X.509 cert, which is managed in a directory service, which is accessed by the various applications I access when I attempt to authenticate myself through that token….that key. I never leave my (physical) house in the morning without that key (physically) hanging on a sash around my (physical) neck. And I never leave the office later that day without that same key around that same neck. That’s part of my semi-neurotic kinesthetic key-sense: I must always have a sure sense of where every physical key (to every space/resource/asset I depend on) is (on or near my person) when I exit one Kobielus-locked space in transit to another Kobielus-locked space.

How usable can we make that key-mediated space-transition choreography from my point of view? How can I always maintain a sure sense of all relevant keys at all times without having to continually fuss and fret with physical keys and their locations on or around me and my environs? How can I track all the virtual keys that bind my identities to virtual space? How can I make damn sure that all of these physical and virtual keys have been employed (by me manually and/or the infrastructure intelligently) to secure my every last resource, including all my personal data?

And do it all so simply that it becomes second-nature? So that all the virtual doors and windows and locks and blinds are always secure, and all of my personal effects are secreted far away from virtual prying eyes?

And I don’t have to worry about any of this? No matter how neurotic I get about such things, especially as my life grows more complex, and the number of keys and doors and private spaces and privacy-sensitive data elements grows?

Usability of privacy-protection schemes on the Internet means always knowing where your keys are.

And still worrying.

Jim