Monday, May 29, 2006

poem Worn

WORN

The weight of weight worn
whole, heavily, drags
the soul, cruel as wool
that keeps within the
heart wrapped in sin as
wet as pent-up sweat.

Monday, May 22, 2006

imho Arch of Governance part 5 of 5

All:

Found content: “Google’s China Problem (And China’s Google Problem,” Clive Thompson, The New York Times Magazine, April 23, 2006, pp. 64-71, 86, 154-156.

My take:

Governance is self-regulation. Sometimes, it’s the defensive crouch of an industry or community warding off the nasty stick of Big G Government, the ultimate uber-authority, which may step in and assert its sway when it feels the inmates can no longer run the asylum.

Self-regulation often involves self-censorship. Learning the limits of the tolerated is what any speaker, publisher, common carrier, or (in the case of the referenced article) search engine must do to survive in an authoritarian system—in other words, in any system in which speech is only as free as Big G Government wishes it to be.

Here, for example, is the self-censorship (hence, omni-censorship) regime that Google has had to internalize in order to do business in China (I’ve bulletized the text to call out the core thesis of the piece):

  • “American Internet firms typically arrive in China expecting the government to hand them an official blacklist of sites and words they must censor. They quickly discover that no master list exists. Instead, the government simply insists the firms interpret the vague regulations themselves. The companies must do a sort of political mind reading and intuit in advance what the government won’t like….
  • “The penalty for noncompliance with censorship regulations can be serious….’You have to understand, these people are terrified, just terrified. They’re seriously worried about slipping up and going to jail. They think about it every day they go into the office.’ As a result, Internet executives in China most likely censor far more material than they need to.
  • “The Chinese system relies on a classic psychological truth: self-censorship is always far more comprehensive than formal censorship. By having each private company assume responsibility for its corner of the Internet, the government effectively outsources the otherwise unmanageable task of monitoring the billions of e-mail messages, news stories, and chat postings that circulate every day in China.
  • “The government’s preferred method seems to be to leave the companies guessing, then to call up occasionally with angry demands that a Web page be taken down in 24 hours….’There’s a randomness to their enforcement, and that creates a sense that they’re looking at everything.”

Notice the word “noncompliance” in the second bullet. Within that is the word “compliance,” which is a hot theme in the IT world now. Compliance is, of course, a measure of the efficacy of governance. And governance, of course, is driven by Big G Government mandates.

As I noted several months ago in this blog, every mandate is a new source of “thou shalt comply” commandments on enterprises and service providers. There are as many “thou shalt comply” religions as there are governments, agencies, laws, and bosses upon the face of the earth. To the extent that you operate worldwide—or even in a single region—how can you effectively comply with requirements that issue from so many rule-gods, who don’t always talk/agree with each other up in the clouds of Olympus, and who are changing their god-minds independently all the time? To the extent that all these rule-gods “federate” (i.e., agree to respect each others’ jurisdictions, honor each other’s decisions, and harmonize their respective approaches), your job (the haplessly hopelessly pliant and compliant clay/mud at their feet) is easier.

What this article makes clear is that the world’s oldest state, largest nation, and fastest growing economy has no single censorship regime. Instead, it has many government bureaucracies who don’t speak with a single voice or wield a single censor stick. An Olympus of squabbling demi-gods. All of them have access to the police apparatus to enforce their multifarious dictates. All sustain a Confucian culture and ideology that prides itself on the righteousness of authoritarian censorship. All insist on small g governance among their subjects, on self-censorship and self-regulation, as a way of keeping the nasty stick sheathed. So, in that sense, all the authorities in China are “federating” with each other.

Governance. Compliance. These are dominant themes in the post-9/11 world economy, interpreted, applied, and enforced in diverse ways in various nations. Here’s my favorite excerpt from this article: “In contrast to the confusion most Americans experience, Chinese businessmen would often just laugh when I asked whether the government’s censorship regime was hard to navigate. ‘I’ll tell you this, it’s not more hard than dealing with Sarbanes and Oxley,’ said Xin Ye, a founding executive of Sohu.com, one of China’s biggest Yahoo-like portals.”

We often joke that the purpose of SarbOx is to keep your CEO out of prison. That’s our Big G Government holding its nasty stick in abeyance.

Yes, there are bad compliance/governance/regulation regimes and not-so-bad ones. I’d place corporate accountability and financial integrity regulations in the latter category. But truly global businesses can’t pick and choose nations in which to operate. And they can’t impose their home country’s political systems and cultural values on the countries in which they are guests.

Global compliance is founded on global compromise and flexibility, not on ideological crusades. Your internal governance regime(s) must conform to the Big G regimes at whose pleasure you remain within their borders.

Jim

Thursday, May 18, 2006

imho Arch of Governance part 4 of n

All:

Found content: http://www.computerworld.com/newsletter/0,4902,110766,00.html?nlid=APP

My take:

Governance of anything is a workflow, of course. But don’t take the word “workflow” in the limited sense of “sequential process.” I use it in the broader sense of “policy-driven flow of content, context, and control throughout a distributed process.” That definition allows the flow to be sequential, parallel, conditional, etc. Allows the flow to be the collaborative give-and-take of human beings hooking up through e-mail, phone, travel, etc.

But of course I have other definitions of workflow that I whip out when the need arises. Another definition indulges my delight in alliteration, characterizing (oversimplifying?) workflow as a set of roles, routes, and rules (i.e., all of which constitute the envelope of “policies” that govern the driving of the flow, per the above definition).

Notice that I place “role” first in that list. The notion of a “role” is the foundation of any business process. In many workflow models, roles are the (actual or virtual) dots that are connected by the routes, which are in turns qualified by the rules that govern the whole process.

Govern the process. Governance. A few months back in this blog, I characterized role as “identity defined in its full governance context,” qualified by the broad attributes of “place,” “process,” and “permission.”

Re SOA governance, it’s clear that roles—human roles—play a critical (gulp!) role in design-time and run-time. In my upcoming Network World feature article on SOA governance, I make the following point: “One of the most effective approaches for SOA governance is to restrict what sorts of new services may be published to the master registry, by whom, with whose approvals, and under what conditions. Increasingly, registries are integrated with workflow features that govern how services are approved, designed, developed, published, versioned, and retired.”

Most of the registry/repository vendors provide varying degrees of support for configurable design-time administrative/approval workflows, based on clear role definitions among developers, SOA architects, etc.

The referenced found-content provides a good discussion of how SOA governance design-time (and optimize-time) roles are changing. I quote it at length: “Business architect. Process analyst. SOA enterprise architect. These are the job titles various organizations are applying to an emerging role being filled by those well versed in business and technology to oversee service-oriented architecture projects. The holder of the new job will be charged with identifying services that can be reused across an enterprise, finding services in a repository, simulating scenarios for the processes to run and determining metrics to measure the effectiveness of an organization's processes. The position will be part of either central IT or a line of business, depending on the company.”

I had a discussion on this same topic yesterday with Aiaz Kazi of SAP, here at SAPPHIRE ’06 in Orlando. Many of their customers are grappling with the proper definition of the diverse roles in governance of SOA that leverages SAP’s Enterprise Services Architecture (ESA), which is implemented in its NetWeaver platform components, mySAP applications, and diverse composite, vertical, and horizontal apps and business processes.

What Aiaz was describing is a new SOA governance design-time role that sits halfway between the IT process architects and the business process analysts (i.e., the tech and business wonks who use their respective visual development and flowcharting tools to specify SOA-enabled business processes at various levels). This intermediate role essentially catalyzes consensus between the business process analysts and the IT process analysts concerning the eventual process, but doesn’t actually get involved in the fine-grained architecting of the processes.

Instead, this role is more of a “process steward” (my term) who makes sure, whatever new process emerges, that it reuses existing business processes to the maximum extent feasible. The process steward cracks the whip and just says no when IT process architects and business analysts attempt to create new, end-to-end, stovepipe workflows that overlap with existing processes, either in their entirety or in significant roles, routes, and/or rules.

In other words, the process steward role enforces reuse of existing business processes—SOA-style—when developing new processes. The process steward oversees the SOA governance process—the design-time workflow or collaborative process--under which business governance structures—as defined by IT process and business process architects—are crafted, revised, and optimized.

Jim

Saturday, May 13, 2006

poem Toast

TOAST

Through these remarks we
mark this moving moment and
bless the bubbly bliss.

Saturday, April 29, 2006

poem Geo

GEO

Face to face behind
pointed pistols we shake and
resume discussions.

Monday, April 24, 2006

imho Arch of Governance pt 3 of n

All:

Found content:
http://www.dataflux.com/blog/archives/2006/04/10/defective-definitions-of-data-governance/
http://www.dataflux.com/blog/archives/2006/03/27/some-general-tips-on-data-governance/
http://www.dataflux.com/blog/archives/2006/04/07/roi-for-information-governance-think-strategically/

My take:
Here’s where I attempt to discuss governance as it relates to my core coverage domain: data management.

Data governance is a new buzzphrase with legs. I notice that three other industry analysts are posting to a blog sponsored by a data management vendor, and that they’re all tap-dancing around the topic of data governance…none of them has produced (in that blog) a clear definition of the term, though they’ve gone on at some length regarding the value of data governance, the “what’s it’s not” of data governance, the “what it sorta overlaps with” of data governance, and so forth.

I’ll back into my own definition of data governance. First, I’ll revisit my definition of federation, as one broad category of governance structures:
  • “Federation is a governance structure in which autonomous domains choose to honor each other’s decisions and accept each other’s assertions in some realm of human endeavor—such as identity management, data management, or SOA management--subject to business contracts, trust relationships, interoperability agreements, and local policies.”

I implicitly describe “data management” as a “realm of human endeavor” to be governed (i.e., controlled). And I define governance in another post as:

  • “Control structures on human and automated interactions, some of which emerge from the blur of decentralized, autonomous decision agents, and some of which are imposed by centralized authorities.”

Leveraging, converging, and extending these definitions, I define data governance as:

  • A control structure on human and automated interactions within and among data management domains, addressing the full life cycle of functions necessary for comprehensive management of data as a business asset.

I have spun my own alliterative string of verbs to describe the various life cycle functions managed by a data governance environment:

  • Mapping, modeling, and marking up data
  • Moving and migrating data
  • Massaging and manipulating data
  • Massing and mastering data
  • Monitoring and measuring data
  • Mobilizing and extracting meaning from data

And so forth. Mmmmmmmmmmmmmmmmmmnemonics. Governing anything involves getting your head around a single conceptual model of the entire domain. I parse every data management vendor, architecture, approach, product, etc with this ontology in mind. ETL? (that’s primarily moving and migrating data). Data warehousing? (that’s primarily moving and migrating, massaging and manipulating, massing and mastering data). Business intelligence? (that’s primarily mobilizing and extracting meaning from data). DBMSs? (a bit of everything, actually). And so on and so forth.

Data governance is being used in the same breath as master data management (MDM) to describe this entire life cycle of data management functions. Now, repeat the mantra: mdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdmdm.

Jim

Tuesday, April 18, 2006

imho Arch of Governance pt 2 of n

All:

Found content: http://www.computerworld.com/managementtopics/management/story/0,10801,110436,00.html?source=NLT_APP&nid=110436

My take:
Hard to tell whether we’re twisting the concept of “governance” beyond its natural breaking point…but here I’m testing the tensile strength of the concept in yet another context.

Governance is control, implemented by hook or crook, proactively and/or reactively. The referenced article--“Why achieving SOA quality can be so difficult” by Shridhar Mittal--is an excellent discussion of software QA challenges in the “composite…distributed…heterogeneous….dynamic” SOA world. Here’s the graf that jumped out at me: “Application quality is fast becoming the primary governor for achieving companywide SOA success and deployment. With so many interconnected parts making up applications that can be delivered virtually anywhere, testing no longer becomes a mere matter of finding bugs within the developer's code or problems that occur on a given user interface. Software quality processes must evolve with the architecture to genuinely test a business process and maintain context across the entire workflow.”

Governor…governance….hmmmm. In the previous post, I implicitly defined governance as “different control structures on human interactions, some of which emerge from the confusion of decentralized self-interested interactions … and some of which are imposed by very visible iron hands.” Perhaps I should generalize this discussion to refer to “control structures on human and automated interactions, some of which emerge from the blur of decentralized, autonomous decision agents, and some of which are imposed by centralized authorities.” Yeah…that’s the ticket.

Governance is often event-driven: you see an exception condition (such as a software glitch or DDoS) in development or operations, and you implement a remediation and/or enforcement action to address it. In my discussions with the industry, everybody keeps bringing up the following lifecycle of SOA governance activities: design-time, deploy-time, run-time, change-time (or optimize-time, which is essentially a return to design-time, but incorporating SOA operational metrics from run-time into tweaking the production SOA).

Ideally, QA should be an activity that transcends all of these “times.” You should look for glitches and bugs continually—in development, when the software is being deployed, and in normal operations—and address it continually, sometimes fixing it on the fly, sometimes decommissioning a software component so that it can be fixed “out-of-band” while you implement a workaround. Your SOA governance toolset (i.e., Web services management in operations + visual design and policy administration tools in development shop) should provide you with the ability to test for, detect, and fix these issues at any “time.”

SOA governance involves continuous interaction testing that permeates the entire environment at all “times.” As the article states: “Comprehensive regression testing and runtime monitoring across this distributed environment is critical to maintain the integrity of the application….When teams truly collaborate and continuously automate tests against every layer of the SOA, companies can more reliably wrest value from today's complex, service-oriented business software.”

QA-driven SOA governance, then, is both an automated background activity and a very human collaboration operation that never sleeps.

Jim

Monday, April 17, 2006

imho Arch of Governance pt 1 of n

All:

The current meditation started when I accepted the position of principal analyst with Current Analysis.

Surveying the vast domain of my focus area (data management) and just following a long DRM sequence, it occurred to me that DRM is what you might call a use case of “data governance”: “flexible deployment of content-control policy-enforcement logic throughout networks” (hence sort of under my current coverage scope; in fact, you may notice this in the previous post: “governance of … distributed data…in the form of a corporate-standard master data management (MDM) environment”).

But governance sprawls across many coverage areas, including information security (“heavyweight content security, policy, trust, and key management infrastructure that will inevitably be embedded everywhere”), which is the province of my colleagues Andrew Braunberg and Charlotte Dunlap. It also fits squarely into the SOA governance province of my colleague Shawn Willett.

Regardless…no need to feather my overcrowded nest any further…this concept of governance keeps creeping into my thinking on many topics. Federated identity, for example. In a November 22, 2005 post, I list one of the elements of federated IdM patterns as “federation governance,” with the alternatives of “bilateral trust agreements” and “multilateral agreements.” (Yes, I am using my blog as a memory aid).

And on January 27, 2005, I posited the following “laws” (normative) of “identity governance”:

  • Law of identity federation: Domains must be able to establish trust relationships under which they can choose to accept each other’s identity assertions and honor each other’s identity decisions--or reject them--subject to local policies.
  • Law of identity assurance: Entities must be able to unambiguously ascertain, resolve, and verify each other’s identities, and reserve the right to refrain from or repudiate interactions in which such assurance is lacking.
  • Law of identity self-empowerment: Humans must be able to self-assert their identities, and reveal or conceal as much or little of their identity as they wish, at any time, for any reason, from any other party, for any duration, and also to unlaterally defederate from any domain that deliberately or inadvertently compromises or violates these rights.

All of which brings us to the core issue (of this post at least). What exactly is “governance”? And what exactly distinguishes it from “management,” “administration,” “access control,” “federation,” and other related terms of art in this industry? Is “governance” simply another empty fuzzword coined to give the false impression of new substance?

It occurs to me that, in IT contexts, “governance” is usually used in the same breath as “federation.” And both terms are used in contexts in which responsibility for some functions (e.g., authentication, authorization, etc.) is decentralized across two or more autonomous peer sibling domains. In other words, governance as barely controlled anarchy. As an alternative to centralized, command-and-control environments, in which there is a parent/child relationship between domains (in other words, hierarchy, aka big G Government).

But of course, some use “governance” to characterize all options on the spectrum from anarchy to hierarchy. All of it describing the different control structures on human interactions, some of which emerge from the confusion of decentralized self-interested interactions (e.g., Adam Smith’s “invisible hand”) and some of which are imposed by very visible iron hands.

If we take the most global definition of “federation,” we can describe it as one type of governance structure, to wit:

  • “Federation is a governance structure in which autonomous domains choose to honor each other’s decisions and accept each other’s assertions in some realm of human endeavor—such as identity management, data management, or SOA management--subject to business contracts, trust relationships, interoperability agreements, and local policies.”

Or you can characterize federation as governance built up from contracts, and the alternative (hierarchy) as governance handed down from constitutions and covenants. Contracts vs. constitutions: horizontal vs. vertical policy envelopes: negotiated vs. decreed governance environments.

All a part of the art of governance. Or the arch of covenants.

Jim


Saturday, April 15, 2006

poem Character

CHARACTER

Character is caricature.
It exaggerates, and becomes.
Becoming your blunt summation
in the act of unbecoming.

Saturday, April 01, 2006

fyi German Bank Fights Phishing With Electronic Signatures

All:

Found content: http://www.computerworld.com/securitytopics/security/story/0,10801,110054,00.html?source=NLT_SEC&nid=110054

My take:
Fight phishing with common sense, not electronic signatures on e-mails and websites….OK, use the latter as well, if you wish…but if you’re like me, you’ll:
  • Use online banking as little as possible….direct deposits for regular paychecks and direct debits for regular bill payments are totally automated…which eliminates most of the need to visit a physical or online bank
  • Believe no e-mail that purports to come from a financial institution, including those in which you have accounts…and doubt whether there might ever be legitimate circumstances under which a financial institution would ever send you an e-mail to notify you of some account-related event or anomaly….and tell all of your financial institutions in no uncertain terms that monthly statements and all other official communications must come from them via postal mail, printed at their expense, on their letterhead, and on a regular schedule, to your permanent street address.
  • Tell your legitimate financial institutions that, if there’s a serious event-driven issue concerning your account (e.g., overdraft), they will have to contact you via phone…so at least you have some evidence that somebody somewhere spent sufficient resources (to print and mail paper and/or to have a human being call and talk) to discuss something of critical importance to both them and you….even though scams also make use of the phone system on occasion.
Make the scammers really work if they want to separate you from your assets, through online or other approaches.

Asking you to periodically “verify” existing account information online is a crock….you verify it implicitly every day by going about your life as usual and not noticing anything out of the ordinary with your checking or brokerage accounts….accept that you’re responsible for checking your statements every month, and that no legitimate institution will prompt you to exercise that responsibility….banks don’t call you to ask if you received and have reviewed your printed-out monthly statements…or balanced your checkbook register….do they?

Asking you for your password so that they, the “institution” that supposedly manages that account, can manage it is also a crock…if their “employee” or “representative” doesn’t already have full access to your account information, that’s their problem, not yours…they’ll have to prove that they have sufficient information on you already before you even begin to speak to them…if it seems like they know nothing about you, clam up…if they can’t even tell you what your current mailing address is for the purpose of verifying it over the phone, then they have never mailed you a paper statement…which means they have never actually established a real relationship with you…which means they’re a fraud…they don’t have the nucleus of an “identity system of records” on you, or can’t match up the data in their iSoR with the equivalent data that only you have possession of…they’re obviously fishing/phishing for that data…don’t give it to them…close your browser and/or hang up…

Asking you to verify an electronic signature on a financial institution’s e-mail or website strikes me as a bad idea. They're putting the burden on you, the customer, to verify the authenticity of the institution that purports to have sent you a message or operates a website that you’re visiting. You have to do all the work, per the referenced article: “Under the Postbank certification system, users can verify an e-mail by clicking a certification symbol, which, when opened, provides details about the signature. A warning symbol appears if any inconsistencies arise during the signature authentication process.”

When the customer has to do any work at all to verify an electronic signature, you can best believe that most customers will do nothing. Which means that there will still be plenty of scams that use electronic signatures to convey the illusion of legitimacy, and that verify few customers will actively “verify” these signatures. And that few users who do attempt to verify the signatures will know what to do with the information that the signature system presents to them.

The more I stare at the following two statements from the article, the more they bother me:
  • “users can verify an e-mail by clicking a certification symbol, which, when opened, provides details about the signature.”
  • “a warning symbol appears if any inconsistencies arise during the signature authentication process”
What “details” are presented about the signature? Will it tell me that a certain “E_Trade” (scammer) that signed a message or webpage is not the same as the “E*TRADE Securities LLC” that actually manages my accounts? Would I pay attention even if it told me? Who actually keeps track of these typographic differences between alternate possible versions of these concocted corporate names anymore (Yahoo vs. Yahoo!...yeesh)?

What “inconsistencies” might arise during the signature authentication process that would make the recipient have second thoughts about trusting a message? Pharming thrives because people blithely ignore the inconsistencies or discrepancies between an authentic financial institution’s URL and the one that pops up in their browser (to which they’ve been redirected, possibly, by a virus planted on their PC). Might malware also hijack your PC’s electronic signature software and produce bogus “everything’s cool” messages that hide any “inconsistencies” in the signature verification process?

So, in summary: Paper is safer. Letterhead is a better bet. When an institution commits ink to pulp and regularly sends it out, it shows that it holds your master account data. That it’s working hard to hold your confidence and continued patronage. That it isn’t waiting for technologists and lawyers to get the kinks out of electronic signatures.

Jim

Friday, March 31, 2006

personal Kobielus joins Current Analysis as Principal Analyst for Data Management

All:

I'm pleased to announce that I have joined Current Analysis (Sterling VA) as Principal Analyst in the Data Management module. My coverage area includes business intelligence, master data management, data integration, data warehousing, data mining, data quality, DBMSs, EII, ETL, metadata management, semantics, and compliance.

You can reach me at jkobielus@currentanalysis.com. My work phone numbers are 703-340-8134 and 703-788-3729.

I look forward to speaking with you.

Jim

Wednesday, March 29, 2006

fyi IDC: Data Centers Becoming Smaller, Faster

All:

Found content: www.internetnews.com/ent-news/article.php/3594871

My take:

Wha?...wha hoppen?...oh, yeah…the drm sequence….intense….where was I?....oh yeah….that out of the way…did it really?....oh, auntie em....oh well…push the pillow…onto the next….

The term “data center” is becoming more of an oxymoron every day. A vestige of the big iron days. Every corporate IT resource—data, storage, compute power, etc—is becoming more decentralized through SOA, ESBs, platform virtualization, and compute and data grids.

Even those corporations that continue to centralize some mission-critical IT resources are consolidating into increasingly inconspicuous “data centers.” As the referenced article states: “U.S. data centers are starting to look trimmer and run faster thanks to virtualization and automation tools...The number of pieces of data center equipment is also slimming down to include fewer machines. For example, with virtualization, customers can run multiple operating systems on one machine, reducing the number of machines they need to run their businesses.

And these data centers are, when you pry their lids open, becoming internally decentralized through blades and virtualization. Once again, the article states: “Customers concerned about using software to consolidate and automate their computer networks are interested in products from VMware, SWSoft, Xen and Virtual Iron. Blade server systems are another prime example of the shift to more condensed data centers. Where mainframes once ruled the data center roost almost exclusively, smaller blades that slide in and out of chassis are becoming more prevalent these days.”

Increasingly, what we’re seeing is the rise of the virtual data center in most organizations. In this new environment, the data (and storage, CPU, etc.) is decentralized from the get-go, and will often remain that way (never to radically consolidate on a single storage node or location). But the governance of that distributed data—in the form of a corporate-standard master data management (MDM) environment—will tighten.

Data centers have always had a core competency: moving, massing, and mastering corporate operational data. As centers decentralize, the moving and massing of data will permeate every niche of the corporate environment. And it will all--the ubiquiflow of precious content--be tracked, managed, channeled, optimized, and quality-controlled every step of the way through MDM.

All of which is prelude to….

Jim

Tuesday, March 21, 2006

personal Jim's Theory of Careers


James Gerard Kobielus. Age 47. Alexandria VA.



Jim’s Theory of Careers

I’ve actually got two theories of careers. One is that careers are just one damn job after another (which sort of sums up my career thus far). Another is that careers are all that—all the zigzags, accidents, and contingencies of opportunities that presented themselves at various points of our lives—but also the story you tell about what it all means, what it’s all amounting to, and what you yourself are amounting to. If anything. I’ve been wondering about this “amounting to” a lot recently. What my accumulated investments are amounting to? What my resume is amounting to, in terms of notches on my demonstrated experience belt? What my bibliography (yes, I’m a much-published technology author) is amounting to in terms of discrete articles, books, and other items under my byline? What my stature in the eyes of my almost-grown children is amounting to? I don’t get a sense, though, that it, my career, is amounting to anything in particular—not in the sense of culminating in some grand flowering accomplishment for all the world to behold. It’s simply spooling out like I’ve always known it would. I’m aging, balding. I’ve had a career, children, a wife. A life.

Sunday, March 05, 2006

imho DRM1

All:

Found content: http://www.pcworld.com/news/article/0,aid,124527,00.asp

My take:

DRM is another name for content, culture, and commerce coursing the crazy channels of cash and control in this the extremely early third millennium.

Nobody’s purely on one side or the other in the commerce/content/culture craze that’s consuming our every waking moment. Everybody’s a potential publisher who wants, rightfully, to maintain perpetual control over their creations. And everybody’s a potential consumer who wants free, unfettered access to the whole cornucopic world of overflowing code and content largesse.

Anybody who takes a purely ideological stand against DRM should heed the words of somebody whose commitment to open code/content is unimpeachable: Linux kernel developer Linus Torvalds. In January, Torvalds went on record as opposing the anti-DRM restrictions that have been proposed for GNU General Public License v3, which is used in many open-source projects. Some had proposed that GPLv3 prevent GPL-licensed open-source software from being used in DRM copy-protection software.

Fundamentally, Torvalds—being a software developer—is essentially a publisher. A publisher’s primary interest is in ensuring that their consumers can verify the authenticity and integrity of their published works. That, of course, depends on a crypto feature called “digital signatures.” So the following statement from Torvalds, from his newsgroup, makes perfect sense:
  • "I think it's insane to require people to make their private signing keys available, for example. I wouldn't do it," he wrote. "So I don't think the GPL v3 conversion is going to happen for the kernel."

DRM will soon be everywhere, especially on open-source platforms. And much of the technology we use to control access to our published contents will issue from open-source DRM projects. The “committers” on open-source projects will be the number one proponents of DRM safeguards to ensure that their licenses (however structured—and open-source licenses are among the most complex and byzantine in existence) are enforced everywhere and anywhere their software components roam in cyberspace. And that their authorship of these components is always and everywhere visible, even if they never make a dime from their work. Because creators always insist on due credit being paid for their precious creations.

As creators have done since time immemorial.

Jim

imho DRM2

All:

Found content: http://www.theinquirer.net/?article=29140

My take:

DRM is another name for the doctoral research motherlode that this topic has unleashed.

Everybody’s developing their own DRM dissertation, or so it seems. The referenced article presents Wendy Grossman’s self-described “manifesto,” which consists of several (prescriptive and proscriptive, rather than descriptive) “principles of responsible DRM,” which appear to have been inspired by what she describes as Sony’s “damn-fool rootkit” and “evil deed” (what would the DRM-bashing community do without this new whippingboy media/electronics giant?). Her principles (all of which primarily apply to DRM only in its B2C content license management and anti-piracy application, not to the equally important B2B federated identity and access management side of this topic, which some have referred to as “enterprise rights management” or “identity rights management”) are as follows (I’ve chosen to number them for the sake of easily referring back to individual principles):
  1. “DRM should not violate the user’s computer…. By "violate", I mean the software should not: hide its presence, send back information about either the user or the computer without permission (and what gets sent should be fully auditable by the user), or do other things that, if Sony were a teenaged hacker dressed in black working out of a back bedroom would send it to jail.”
  2. “A company whose DRM breaks the law ought to be fined and treated exactly like a wanton environmental polluter.”
  3. “DRM should respect the public domain. That means it should automatically expire, leaving the content freely accessible, on the date when the work enters the public domain.”
  4. “DRM should not be allowed to apply more restrictions to a work than that same work would have in the analog world.”
  5. “Circumventing DRM should not be a crime (as of course it is under the US's Digital Millennium Copyright Act) in and of itself.”
  6. “Rightsholders who do not incorporate features to allow disabled access should be required to allow third parties to do so.”
  7. “When a new format is adopted and new work begins being released on it, the technical specifications for how to build a reader (and a copy of the player) should be filed in the copyright libraries.”

I’m looking at these responsible-DRM principles and trying to find some core principle that underlies them all. Principles #1 and #2 simply articulate principles of responsible computing, which should cover DRM and other infrastructure and applications technologies. Principles #3, #4, #5, #6, and #7 address aspects of the DRM dilemma: the equitable balancing of the rights of content publishers vs. the rights of content consumers. And, fundamentally, they all derive from a common DRM (prescriptive/proscriptive) principle:

  • Principle of Minimal and Diminishing Restrictions: Content publishers must, to the extent they apply DRM, always license and implement the minimal set of necessary access restrictions on authorized consumers, apply a similar set of restrictions to those enforced in other content-distribution channels, and allow consumers to progressively diminish these restrictions as time, fair-use, and other extenuating circumstances permit.

All of which puts me in mind again of Kim Cameron’s “laws of identity.” Don’t they posit a set of DRM-like laws? Summarizing them again (I first touched on them early in this blog’s life, in December 2004, and then again throughout the first half of 2005), they are (to requote myself paraphrasing Kim):

  • “According to Microsoft/Cameron, IdM systems must gain user consent prior to revealing information identifying the user; disclose the minimum amount of identifying information necessary; limit that disclosure to parties with a need to know; provision public and private identifiers for pointing to users’ identity data; and provide user interfaces that help people avoid revealing personal information to phishing and pharming scams.”

In an “identity metasystem” (Kim’s phrase), who are the “publishers” and “consumers” of this particular type of content (i.e., identity info)? Are the identity providers (IdPs)—in other words, those who register, manage, make assertions about other people’s identities—the “publishers” or “consumers” of identities? IdPs certainly publish identities, and certainly consume this information in order to authenticate users, make assertions about those users, personalize presentation of information to those users? Are the people who the identifiers identify the “publishers” of their identities (in the sense that they opt to let the IdPs republish this info) or “consumers” (in the sense that they use their identity info to login to systems and access various resources by proving possession of information about themselves that many would assert, including Kim Cameron, that they “own”)?

At some fundamental level, we can construe Kim’s principles as being based on the notion that the individual owns, hence publishes, his or her own identity info, and that everybody (the IdPs and the service providers, or relying parties) consumes this info. In which case, Kim’s principles seem diametrically opposed to Grossman’s DRM principles: the “publisher/owner” of identity content (i.e., the identity subject) always reserve the right to apply a maximal and never-diminishing set of restrictions on “consumer/IdP/relying party” access to this content.

Or perhaps both Cameron’s identity-metasystem principles and Grossman’s DRM principles derive from a common, unspoken principle:

  • Principle of Sticking it to "The Man": Each of us should have maximum leverage over resources—such as our own identity information or other people’s published content—that is controlled by big, impersonal, “evil,” “greedy” institutions.

If you believe in demonizing the economic system that sustains us all, and allows all productive classes—including content publishers—to make a decent living from the sweat of brows that squint at monitors all the livelong day.

Jim

Saturday, March 04, 2006

imho DRM3

All:

Found content: http://www.itarchitect.com/shared/article/showArticle.jhtml;jsessionid=MEKV5X5YPUNFSQSNDBCCKH0CJUMEKJVN?articleId=177100842&classroom=

My take:

DRM is another name for a new brand of all-pervading FUD. God, I thought spyware was bad enough. It’s not just the rootkits (a term you can now expect to see evermore preceded by the qualifier “evil” and used as a cultural shorthand for media mind control). It’s something that Andy Dornan alerts us to in his IT Architect column from last month, something that may be the same (I’m not sure) as the “DRM-equipped monitors” that Michel Labelle warns us about (without further details) in another point this DRM blogpost thread. Here’s how Dornan describes a DRM enforcement mechanism that will operate at the device-driver level in Microsoft Windows Vista (an article in which he, incidentally, refers to DRM as something forced upon us all by “those greedy media companies”):
  • “The greatest long-term threat is a hypervisor that enforces DRM, combining the code extensions in Intel's VT or AMD's Pacifica with Trusted Platform Module (TPM) hardware. In the short term, Vista will ‘protect’ video content through driver revocation: Whenever the DRM in a particular model of graphics card is cracked, a security update will disable that card's driver. Anyone who happens to be using the same type of graphics card as a DRM hacker will be left in the dark until a new driver can be written and certified as DRM-compliant.”
Oh...thanks for the detail…let’s parse this now for the benefit of us analytical geeks (I’m just operating from the info presented by Dornan—I haven’t delved deeper into this Vista feature):
  • Microsoft will be able to selectively and unilaterally “revoke” Vista support for graphics-card device drivers.
  • Microsoft may revoke Vista support for a particular model of a graphics-card device driver in cases where somebody/somewhere has “cracked” the Vista-based DRM protections implemented in that card and/or its driver.
  • Microsoft’s partner ecosystem of graphics-card manufacturers are building card and drivers that implement publisher-driven DRM controls governing paying- and non-paying user display of video and other licensed visually-oriented content objects on monitors configured into machines that run Vista.
  • Microsoft is implementing a DRM-busting surveillance program under which it will determine the degree to which particular graphics-card manufacturers’ device/driver DRM approach has been “cracked” and, thereby, poses an imminent vulnerability/threat to video content publishers (including, I suppose Microsoft itself as a publisher) that demands immediate emergency action by Microsoft itself.
  • Microsoft will be able to selectively punish graphics-card manufacturers, their partners, and their customers suddenly, unilaterally, from a central point, and in bulk (i.e., potentially, millions of computers everywhere suddenly/mysteriously “going black") by “turning off” their monitors, for no fault of their own, but, rather, due solely to the fact that some pimple-faced kid in Kazakhstan got too smart for his own good and cracked manufacturer X’s DRM driver technology one lazy Sunday afternoon as part of high-school science-class project.
  • Microsoft is prepared to face the universal wrath of all the aggrieved parties, their lawyers, and the media for this action.

Or...so I gather or infer from what Andy tells us.

Ponder all of that for a moment. Just think of universal computer blackout. Fear and Uncertainty, in the Dark (FUD). Yeah, that’s what the world needs now, FUD sweet FUD.

Jim

Thursday, March 02, 2006

imho DRM4

All:

Found content: www.vnunet.com/2146367

My take:

DRM is another name for the latest perennial news-generating horserace in the IT industry’s daily grind.

DRM is so beautiful from a news fodder standpoint. It gives the intellectual property lawyers, the civil libertarians, the radicals, the anarchists, the “information longs to be free,” the iPod jockeys, the crypto/cipher spooks, and others an issue, technology, trend, lifestyle, etc to flog to death. “DRM is evil.” “No, you’re naïve and irresponsible—DRM is good—DRM is inevitable--get with the program.”

Absolutely perfect, if you own, publish, write for, broadcast for, or otherwise participate in the dissemination of current news that touches on tech-qua-tech and/or tech-qua-lifestyle. It gives you a never-ending polarized emotional semi-irrational quasi-high-stakes controversy to cover in perpetuity. And it gives the mouse potatoes of the world an abstract issue whose payoff to them is clear and visceral. “Wow…free music…free movies…free porn….free……..”

Years ago, when I entered this industry, I started compiling a mental list of the IT news-cycle “horseraces” that kept getting press coverage. Here are some of the principal entries on the horserace list: sysops vs. hackers, virus spreaders vs. anti-virus, spammers vs. anti-spam, spyware vs. anti-spyware, closed source vs. open source, Microsoft vs. world, and codemakers vs. codebreakers.

To that list I’ll have to add DRM-builders vs. DRM-busters. Most of the press coverage I’ve seen lately highlights the efforts of the DRM-busters. Such as the referenced article: “Gartner: piece of tape defeats any CD DRM.” Guess what—it’s flogging Sony yet again for the evil XCP rootkit, and pointing out that music on the company’s DRM-protected CDs could be liberated through a common household adhesive strip applied to the outer track. I’m not sure how he could make this claim, but some unnamed Gartner analyst said that “the use of a piece of tape will defeat any future DRM system on audio CDs designed to be played on a stand-alone CD player.” Any future DRM system? How can the analyst be so confident about the inefficacy of all future DRM innovations (does he/she have some sort of supermagical quadrant to consult on techno-futures)?

How about those DRM technologies that leverage whatever miracles (or disasters) come when humanity masters quantum computing (which will inaugurate a codemaking vs. codebreaking horserace the likes of which will blow everybody’s minds, and render public-key cryptography absolutely powerless)?

Can a piece of Scotch tape factor an arbitrarily long number into its prime factors instantaneously? If so, it can defeat any future crypto-based DRM technology.

Jim

imho DRM5

All:

Found content (found in my “Sent Items” folder, I’d forwarded it from one of my e-mail accounts to another a few months ago—persistent personal content-of-interest store—an analyst is only as productive as his/her personal library-caches): AnalystViews Weekly Report for Week of 12.22.2005, “Two Rights: The Restriction and Management of Digital Rights”

My take:

DRM is another name for flexible deployment of content-control policy-enforcement logic throughout networks.

The referenced article references another article (September 20005 EContent magazine) that wraps DRM into a larger phenomenon called “enterprise rights management (ERM).” According to the source article (as paraphrased in the referenced article), the “primary objective of these systems is to protect the intellectual property of an enterprise; in the field this is seen as having two components. The first of these is access to the digital asset itself, in the past systems were able to restrict access, but once the material was legally accessed there was little in place to restrict it. Thus maintaining post-access security becomes the second component. Many systems currently in place implement a number of various methods to address the first part of the challenge, asset access, and these range from simple password protection to biometric user verification. More advanced systems are beginning to apply controls which will protect the document post-access, these can prevent electronic screen capturing and the forwarding of files via email, and some can even be linked to peripheral devices to impede the printing or scanning of protected files.”

This brings us back to a notion I introduced earlier in this thread (DRM7, which is actually/paradoxically later in this thread if you follow the virtual scroll from top to bottom, numerically from 1—and you know I’m working up to DRM1—down to the alpha/omega of DRM9—got that?): “DRM is another name for cryptographic containers that wrap content in persistent policies under the control of the content’s creator and/or owner.” That’s another name for “advanced systems are beginning to apply controls which will protect the document post-access, these can prevent electronic screen capturing and the forwarding of files via email, and some can even be linked to peripheral devices to impede the printing or scanning of protected files.” My earliest exposure to these “post-access security” crypto-content-containers was a few years back, in the form of “self-destructing e-mail” systems from the likes of Authentica, Sigaba, and others whose names have self-destructed in my ancient memory.

Which brings me to a critical functional/architectural distinction in DRM (or ERM, whatever you like):

  • Policy enforcement points (PEPs): This refers to any access management portal/proxy/front-end (e.g., CA SiteMinder, IBM Tivoli Access Manager) that authenticates and authorizes users to access/retrieve content “into the clear,” but doesn’t have any power to control what users do with the content once it’s been retrieved into users’ perpetual possession—in other words, this refers to identity and access management (I&AM) as it’s normally understood.
  • Policy enforcement containers (PECs): This refers to (here’s the phrase of mine again): “cryptographic containers that wrap content in persistent policies under the [perpetual] control of the content’s creator and/or owner”—in other words, DRM (and “self-destructing e-mail”) as it’s normally understood.

It’s clear that these architectural approaches differ primarily in where they deploy the access control logic. Which explains why I&AM vendors are, as I blogged on November 4, 2005:

  • “targeting DRM as the next great frontier beyond federation? Or, perhaps, they hope, DRM will leverage and extend their increasingly federated security infrastructures into a distributed permissioning infrastructure where the access-control policy enforcement points (PEPs) are more closely bound to the resources—apps, data, etc.—being protected? Epok’s federated data interchange environment—leveraging XRI and XDI--is one such example. Sun’s “storage encryption” or “storage security” roadmap (see article) is another. As soon as the morning coffee decompresses my wound-up nightfunk, I’m sure I’ll recall the other three dozen vendors I’ve come across recently who have similar roadmaps.DRM drifts and diffuses itself far and wide throughout IdM, security, e-commerce, content publisher, and storage vendors’ end-of-decade dreams. I think a lot of the renewed attention to DRM recently comes from the rash of identity-theft “data breaches” that have grabbed front-page attention. All that data in storage is sitting ducks and buried treasure for those intrepid identity pirates who find the buried map and go with flashlights in the night down into the caverns guarded by semi-reliable genies. Suddenly, encrypting all that stuff in situ—on piled-high disks and tapes and whatnot--becomes the absolute imperative for storage managers everywhere, dictated by the lawyers, bosses, and regulators.To make encryption—an ancient technology that has been used in storage systems for years in various capacities—seem suddenly cool—not simply mandatory--the vendors have started to lump it into the growing DRM umbrella. Acronym creep, equivalent to the vastly expanded scope of SOA in recent years. It’s not storage encryption anymore. It’s storage DRM. It’s breach-busting DRM. It’s federated DRM. It’s a new pipe DRM.”

If this blogpost is getting too self-referential for its own good. If you’re getting dizzy or disturbed by the ever-shifting context. Then I’m with you. I’ve had enough for now. Till DRM4 suggests itself. And it will. I can feel it.

Jim

imho DRM6

All:

Found content: http://www.sdtimes.com/article/story-20060101-06.html

My take:

DRM is another name for heavyweight (or heavy, in the Jack Palance sense of the term) content security, policy, trust, and key management infrastructure that will inevitably be embedded everywhere. It’s the “inevitably” and “everywhere” parts of the DRM dynamic that freak out so many people. The issue is not so much whether some proprietary (Microsoft, Sony, etc.) or standards-based brand of DRM (and federated IdM and access management) infrastructure will provide that inevitably everywhere infrastructure (IEI—an all-long-vowel acronym I just coined to sound like what the skull-boy in Edvard Munch’s “The Scream” is vocalizing).

Some DRM (good and/or bad) IEI will prevail (not going to wager what/when/how, but it’s going to happen). The reason why is because the need for discretionary publisher-driven rights management is perennial and universal, across all platforms, applications, and code/content sources/channels. When a need is this ubiquitous for infrastructure this fundamental, industry forces will push everyone everywhere toward a common reference architecture, which includes general convergence on common functional models, standards, and (increasingly) codebases.

And nothing says IEI and ubiquitous codebases these days better than open source (a la Linux, Apache, etc.), so it’s no surprise that there are several DRM open-source software development projects underway, as the referenced article points out. SunLabs has its DReaM project, and some related projects: Java Stream Assembly and DRM Opera (perhaps it’ll come out with a PsychoDRMa, or Sturm-und-DRM codebase as well).

I haven’t delved into the details of these projects, but I’m encouraged by what someone at SunLabs said to the reporter who wrote the article: “[Glenn Edens, a senior vice president of communications media and entertainment at Sun and director of Sun Labs] sees a bright future for DRM, and said that uses range from personalized management to business uses to medical records to Sarbanes-Oxley compliance. Edens hopes that his company’s open DRM initiative, embodied in DReaM, spreads to the entertainment industry at large, replacing outdated and invasive systems like the one Sony used….’We’ve started a very fruitful dialog with the EFF [Electronic Frontier Foundation],’ [said Edens]. ‘We have been working on a white paper to describe a possible solution to the fair-use issues. The hard question is: ‘How can you have an access and authentication system that also respects fair use?’”

That is exactly the right question to be asking. DRM isn’t evil, any more than password-protected access controls on traditional document management systems are evil. Get over it. And start to investigate how the emerging DRM IEI can be developed with the flexibility to allow [code and/or content] publishers to protect their rights while also allowing [code and/or content] consumers to protect their equally valid rights to those same digital resources.

What’s a fair balance of rights to code/content among publishers and consumers? What’s “fair use”? How can a DRM IEI allow publishers and consumers to continually negotiate the tricky fine line of “fair use,” a concept that will continue to evolve legally and culturally, and will continue to differ, everywhere and always, on a case-by-case basis?

Jim

Tuesday, February 28, 2006

imho DRM7

All:

Found content: http://www.itarchitectmag.com/shared/article/showArticle.jhtml;jsessionid=1QXBNWQSDF4GUQSNDBECKH0CJUMEKJVN?articleId=174400783

My take:

DRM is another name for cryptographic containers that wrap content in persistent policies under the control of the content’s creator and/or owner. It’s also another name for whatever bad dream all that crypto conjures in your fevered imagination. For some folks, it’s hard to look at crypto without a post-9/11 night sweat: as another type of dangerous munition that may be wielded by swaggering world-dominating maniacs, unless we find and defang them promptly.

Think of all of the content that’s created in Microsoft’s software products. I’m writing this blogpost in Microsoft Word 2002 (my other two computers have two more current versions of that program). When I’m done writing this, I’ll copy/paste it into an HTML e-form at http://www.blogger.com/ by means of my Microsoft Internet Explorer 6.0 browser. If I get tired before I’m finished writing, and before I post, I’ll e-mail the unfinished text from my Microsoft Outlook Express client through my Microsoft HotMail account to another e-mail account (on Microsoft Exchange) that I’ll access in the morning through Microsoft Outlook. Of course, all of that software is running on the several versions of Microsoft Windows that I run on my various computers.

Think of all the potential for Microsoft to wrap its DRM tentacles around my content and your content—or rather, to give us the tools to wrap our personal tentacles around our own content, but with Microsoft-proprietary DRM technologies, including (especially) Windows Rights Management Server. The author (Michel Labelle) of the referenced article (Microsoft’s DRM Conspiracy) thinks a bit too much about it, or so it seems. Doesn’t the following article excerpt sound perhaps just a wee bit alarmist?:

  • “Microsoft has been quietly introducing a number of dubious technologies. First came Windows Rights Management Services (RMS). Digital Rights Management (DRM) is always bad, and it just doesn’t go well with business data. Losing the keys to the DRM store could lock an organization out of all its data….Vista goes so far as to prevent you from viewing DRM content unless you’re using a DRM-equipped monitor….It doesn’t take much of a leap of faith to see that Microsoft is setting us up as a captive market….Once a business goes down the DRM route for security its corporate data store, there’s no getting out. It will be impossible to effectively extract intellectual property that’s locked into a Microsoft proprietary format with Microsoft-specific DRM technology….Unless we heed the alarm, this could turn into a real nightmare.”

Now, I haven’t investigated Microsoft RMS in any great detail, but I take issue with several points in Labelle’s rambling argument.

First, DRM is not always bad—in fact, it’s usually a good thing—especially in the corporate world that is Labelle’s focus. DRM is another name for content and/or code license management technology. As such, DRM doesn’t differ in principle from the discretionary access controls supported in many operating environments, database management systems, and document repositories. Call it discretionary rights management.

Second, DRM, in the corporate world, isn’t usually implemented as a centralized “store” that has a specific set of “keys” that are in danger of being lost and thereby locking away all corporate data in perpetual irretrievable cold storage. DRM is a set of technologies that--depending on approach, vendor, and product—relies on various cryptographic techniques (involving asymmetric/public and/or symmetric/secret keys). More to the point, only an insane corporate database, document, or content manager would centralize all DRM-protected content and DRM keys, and then fail to backup any of this content or crypto material in off-site storage.

Third, what is a “DRM-equipped monitor,” how in the world would it operate, and why exactly would Microsoft design the next version of its client OS to prevent somebody from viewing some DRM-protected content if they don’t happen to be using this strange new display technology? That’s the first I’ve ever heard of a display technology that’s been built to selectively opaque data that the user has retrieved from storage, been loaded in memory, and processed by that node’s CPU. Is it sort of like the “V-chip”? Will it be factory-equipped to conceal data that’s embarrassing to Microsoft?

Fourth, what’s this jazz about DRM as a vortex that sucks businesses down to some hideous abyss, never to be seen from again? You can, of course, use DRM technologies to unlock/liberate data and display/store it in the clear—if that’s the policy you choose for a particular piece of DRM-protected data—or for an entire data set. You can liberate your data from Microsoft’s DRM technology, if you wish, only to lock it up again in SealedMedia or any competitor’s DRM containers.

Finally, was Labelle’s editor paying attention when the following sentence appeared on his or her display (or was the editor viewing Labelle’s draft through one of those magical selective-text-opaquing displays that chose to approve this nonsensical statement)?:

  • “It will be impossible to effectively extract intellectual property that’s locked into a Microsoft proprietary format with Microsoft-specific DRM technology.”

Huh? Come again? So, Microsoft specifically designed its DRM technology to irrevocably lock up any content that is created in a Microsoft proprietary format (.doc, .ppt, .xls, etc.)?

Surely, the Redmond gods must be crazy. Sound the alarm. The bad DRM dream is upon us.

Whew—got that blogpost done—now time to hit the hay. If I dare.

Jim

Monday, February 27, 2006

imho DRM8

All:

Found content: http://www.sdmagazine.com/documents/s=9961/sdm0602b/0602b.html

My take:

DRM is another name for content and/or code license management technology. As such, DRM doesn’t differ in principle from the discretionary access controls supported in many operating environments, database management systems, and document repositories. Call it discretionary rights management.

DRM has gained an ideological black eye in the B2C space due to recent PR fiascos such as Sony’s desktop-security-violating XCP rootkit. But DRM has gained a significant and growing niche in the business world as a tool for binding access controls persistently to corporate documents. As the referenced article points out, DRM is being used to enforce security classifications on internally distributed materials within organizations; to keep tabs on who accesses what information; and to prevent users from performing certain document functions (such as printing, copy/pasting, and forwarding) that content owners prohibit. Nothing terribly sinister about any of that. All of this is well within the controls that security-sensitive organizations have long enforced on paper documents. Principal vendors of DRM for corporate content management include Adobe, Microsoft, SafeNet, and SealedMedia.

Software activation is another hot area where DRM-like technologies are being applied in the corporate world. Software activation tools (which look, walk, and quack like DRM, but in a different pond from content DRM) allow developers to enforce a dizzying range of controls on distribution, installation, and usage of their products: automatic, secure, connected, or disconnected software activation; trial, perpetual, subscription, metered usage-based, rental, superdistribution, upgrade, or other licenses; automatic node-locking by hardware serial numbers, BIOS signatures, OS product identifiers, MAC addresses, and vendor hidden cryptographic hashes; fixed expiration or set number of program executions; etc etc etc. Check out software activation/licensing/metering tools from Agilis, Aladdin, Bysses, CrypKey, Macrovision, Nalpeiron, SafeNet, Sofpro, Pingram, and SoftwareKey

Once again, software publishers have been doing software-activation DRM—by various names--since the dawn of computing. Nothing controversial about any of this.

Of course, no two DRM (content or code) vendors implement the same approach. All of these tools embody proprietary DRM approaches. Each DRM environment is its own self-contained virtual fortress. Every real-world customer deployment of these tools adds another disconnected island of self-protecting license-aware walled-off content/code to your corporate information architecture. More virtual barriers preventing you and your colleagues from sharing, reusing, leveraging, mashing, mixing, slicing, dicing, and recombining data and code in the service of corporate agility. And service-oriented everything.

Not that there’s anything wrong with that.

Jim

Sunday, February 26, 2006

imho DRM9

All:

Found content (had to search Google’s cache for this article, though it’s only a little over three months old—perishable content—had already perished—only the persistent can dig it out—but dig I did): http://64.233.179.104/search?q=cache:xjgTm2Pq8aoJ:channelweb.com/sections/allnews/article.jhtml%3FarticleId%3D174400380+Sony+Blunder+Shows+Digital+Rights+May+Be+Doomed&hl=en&gl=us&ct=clnk&cd=4

My take:

DRM is another name for anti-piracy technology. The original anti-piracy technologies were armor, fortresses, ramparts, moats, and sharp swords. All of which leads the mind toward the basic economic situation that fosters organized piracy: booty is concentrated, but desire is distributed.

DRM is an acronym that invites mockery: defensive rearguard maneuvers by desperate restriction mongers. The more persistent and distributed the desire for whatever booty Sony and other copyright holders hold, the more defensive and desperate these fortresses will grow. All of which makes me think that Inside Digital Media analyst Phil Leigh just totally misses the mark. According to the referenced article, Leigh “believes that rather than adopting technological methods to try to stop unauthorized copying of music, record companies need to do more to remove the incentive for piracy.”

Like what? How are the Sonys of the world going to extinguish people’s desire for music, movies, TVs, video games, and art and culture in general? At what point in the development of the human species will people no longer crave these forms of creative stimulation? If you can’t snuff out people’s desire (and, along with that, all demand for Sony’s products, hence Sony’s continuing existence), then the only ways to remove the incentive for piracy are:

  • Give away all content for free (and thereby also kill the gander that gathered the golden eggs), or
  • Trust that some customers will pay for some content some of the time, if you keep the virtual shelves continually well-stocked with fresh goodies; don’t overprice the wares; supply it all through channels and packages that are easy, convenient, and pleasant to find, access, and consume; and allow consumers to actually take ownership in the content, to copy, backup, mix, mash, and generally have their way with the material to their hearts’ delight
Trust the consumers. Believe it or not, they want to encourage artists to continue making great music, movies, books, etc., and they will compensate artists according to the reasonable value of their works. But they will seek less expensive (and less legal) alternatives when the artists’ precious outputs are overpriced. That’s just a basic, inevitable fact of any economic order.

Respect the consumers and don’t treat them like potential shoplifters. As the article states: “The challenge has been to find an anti-piracy tool that works well enough to please the industry without overly annoying users, many of whom want to make legitimate backup copies of their CDs and don't like being assumed to be criminals.” The article presents a smattering of annoying anti-copy techniques that the recording industry has inflicted on users (in addition to Sony’s notorious XCP rootkit):

  • “recording labels commonly sent music critics promotional material in portable players glued shut to prevent copying.”
  • “discs that included digital watermarks — extra encoding designed to lock the recordings, or at least their high-resolution portions — on the disc.”
  • “discs that contained data near the perimeter of the CD instructing a computer's hard drive not to look for audio tracks…[b]ut blocking that technology merely required drawing a line with a marker near the edge of the CD.”

The number one mistake that Sony made with its XCP rootkit was to imagine that they owned not just the music, but could also, without asking permission, arrogate their own persistent footprint on the computers of the consumers of that music. That was going too far down the spyware rathole.

DRM isn’t doomed, but it won’t usher in an age of absolute, perpetual institutional control over all content everywhere. Different content fortresses will continue to build their digital ramparts. But the digital hordes will continue to scale, trash, and torch every new barrier, as long as there’s fresh booty indoors.

DRM will be ignored completely in the new paradigm of consumer-created content, of which blogs are a harbinger. It’s ridiculous to imagine that any set of institutions can control even a tiny portion of the fount of creativity that springs from people’s souls and lives everywhere. In this new world order, few of us make a direct living from our self-published content, which we provide gratis to all comers. Instead, more and more of us are finding creative ways to leverage our self-published content into money-making endeavors of various sorts. Or simply self-subsidizing our creative selves with funds from “real jobs.”

Like creators have done since time immemorial.

Jim

Saturday, February 25, 2006

poem Freq

FREQ

A friend is present.

A friend responds,
frequently frequents
whatever planet you're on.

Thursday, February 23, 2006

fyi Don't Let Mashups Smash Up

All:

Pointers to this that and the other:
http://www.eweek.com/article2/0,1759,1921743,00.asp http://www.eweek.com/article2/0,1895,1929486,00.asp
http://www.ebizq.net/blogs/column2/

Kobielus kommentary:

Eric Lundquist’s definition of “mashup” is a good enough launching point for what I’m about to say: “Blended applications, or mashups, are the hottest topic in application development. A mashup is usually a Web application built from many sources but combined into a seamless interface that provides a new user experience.”

Excuse me, Eric, but for the past several years this same definition, without modification, could have been applied to another trendy term: “portal.” It’s fairly close to one of my personal operating definitions for “portal”: a browser-accessible, server-based platform that aggregates links to and composes a new interface for interacting with content and functionality hosted elsewhere (OK—I just made up this unwieldy definition, but it’s sort of close to the shorter phrase I’m always wandering around mumbling). Is “mashup” just another example of this industry’s tendency to proliferate unnecessary new terms for still-valid older terms? What if anything is new that merits a new term?

If “mashup” has any new meaning (over and above “portal”), it refers to a growing trend under which Web applications are slapped together hastily from links to disparate services from diverse sources. It connotes a more ad-hoc, anarchic, slapdash, composite development approach than we normally associate with portals. “Seamless interface that provides a new user experience”? Ha! The term “mashup” comes from the hip-hop music world, and refers to a compositional approach under which heterogeneous audio is sampled and spliced from all over creation with all seams showing—syncopating your brain and body into rave overdrive. That’s what “mashup” actually connotes: user interface presented as funky compost, not as fussy composition.

There’s a place for everything, and I rather like a rhapsody, which is what a mashup is: a musical composition of irregular form having an improvisatory character (http://www.m-w.com/dictionary/rhapsody). So I chuckle to read Mary Jo Foley’s piece in Microsoft Watch: “Microsoft Business Apps Unit Readies New Web 2.0 Mashups.” The article says: “In December 2005, Microsoft posted to GoDotNet [Microsoft’s shared-source hosting site] a mashup of Dynamics 3.0 and MapPoint, its online mapping service. Such a mashup could allow customers to customize the Dynamics CRM contact form to show a MapPoint map displaying a contact’s address.”

Wait just a sec, Mary Jo. That doesn’t sound particularly heterogeneous, anarchic, or improvisatory: one vendor integrating software components from two of its existing product/services in order to extend/expand the functionality of both. Suddenly, mashup is treading on the semantic territory claimed by another familiar software industry term: feature enhancement.

Mashup is throwing its verbal weight around in the blogosphere too. Sandy Kemsley makes the following statement implying that mashup is now a synonym for SOA (service-oriented architecture): “To be fair, many IT departments need to put themselves in the position of both the API providers and the developers that I met at Mashup Camp, since they need to both wrap some of their own ugly old systems in some nicer interfaces and consume the resulting APIs in their own internal corporate mashups.”

“Wrap some of their own ugly old systems in some nicer interfaces…consume the resulting APIs”? You mean WSDL, SOAP, and the whole WS-* suite of standards, right? And, of course, where building portal-based mashups is concerned, WSRP as well, right? That’s SOA, pure and simple (er, it’s still complex, let’s not kid ourselves).

Is mashup simply SOA-based rapid application development, cobbling together “found external content” into a bold new synthesis in the presentation tier? A quasi-artistic endeavor? A semi-political faux-libertarian statement on the manifest destiny of “information needs to be free” and all that?

Or what?

Jim

Wednesday, February 22, 2006

fyi Gates: Passwords Aren’t Enough

All:

Pointers to articles:
http://www.crn.com/nl/crndailynews/showArticle.jhtml?articleId=180204041
http://www.microsoft.com/windowsserversystem/CLM/overview.mspx

Kobielus kommentary:
The headline of this piece isn’t news, nor is its substance. Everybody knows passwords aren’t enough for strong authentication. And anybody who’s been paying attention knows that Microsoft has been beefing up Windows’ smartcard and certificate lifecycle management tools. Microsoft acquired Alacris last year and has been integrating its credential management workflow and provisioning tools into Windows Vista and “Longhorn.”

But it’s clear that Microsoft, with Certificate Lifecycle Manager (CLM), isn’t implementing any functionality different from entrenched card/credential management vendors, such as GemPlus, Schlumberger, and Siemens. Yes, card/credential management integration with the InfoCard feature of Vista/Longhorn is news, until you realize that InfoCard is just another type of soft token in which PKI and other credentials will be stored—Microsoft’s not an innovator in that regard either.

Let’s not confuse a Bill Gates marketing-ish announcement with an actual vision of anything new--from a PKI, IdM, or trust management perspective—coming out of Microsoft. It would have been more interesting if Microsoft had let Kim Cameron discuss identity metasystem from the stage at RSA Security. But that would be a PR no-go for Microsoft. Only IdM wonks like myself would have paid attention. Also, Kim is a semi-autonomous vision guy, not someone that Microsoft would ever consider as a heavy-hitting marketing mouthpiece.

Gates is Microsoft’s marketeer-in-chief. And you can’t ask for a better one. He’s iconic, smart, current, in-depth, articulate. However, he’s not usually someone who communicates anything that you haven’t heard before, expressed more memorably by others.

In this instance, I find Gates’ statements on the issue of authentication factors--passwords vs. smartcards/certs--a tad stale, and off the mark.

First off, he focuses on the need to simplify smartcard/certificate issuance, renewal, and revocation, rather than the need to increase assurance (hence trust) surrounding these critical lifecycle processes. “Having the revocation and issuance work as easily as passwords do today is a critical element here,” says Gates. Wait just a second, Bill. The primary purpose of smartcards/certs is to enable stronger authentication than you can get with plain ID/passwords. And strong authentication demands strong assurance implemented acrosss the entire lifeycle of smartcard/cert enrollment, approval, proofing, provisioning, management, and validation. It all comes down to trusted workflows and trusted roles implemented across a company’s smartcard/cert/credential management process. If somebody can impersonate me and get a smartcard/cert in my name without undergoing the necessary administrative approvals and in-person proofing necessary to prove that they’re me, then what’s being gained? Just a new way to steal my identity and “authenticate” as me and gain “authorized” access to my world. Simplifying the smartcard/credential management process often means gutting whatever assurance the provisioned tokens/certs might otherwise have had.

Second, he says that most companies can and should (implication: they will) move away from password authentication toward smartcard/cert authentication by the end of this decade. Of course, that prediction is predicated on Microsoft and other smartcard/cert/credential management vendors making greater headway in customer acceptance than they have in the past. It’s still not clear that Microsoft’s CLM will appreciably simplify the complex PKI workflow and technical infrastructure needed to make this happen (ignoring, for the sake of discussion, the negative impact that such “simplification” might have on smartcard/certificate assurance levels).

If you want authentication simplicity, you can’t beat passwords. For authentication assurance, though, passwords are almost always the weak link in the trust chain, owing to boundless opportunities to hack, guess, and steal passwords, and also to the fact that users are rarely proofed in-person prior to issuance of passwords.

Consequently, the password being presented in an authentication session may or may not be presented by the identity that purports to be presenting it. You have no strong assurance that it’s not being presented by an impostor.

But then again, without an enrollment, approval, proofing, and provisioning workflow that ensures strong binding of the smartcard/cert to a particular human being, you have no strong assurance with multifactor authentication either. And without a trust web and certificate validation infrastructure, you have no assurance that a cert being presented is still valid. How often do people rely on someone else’s PKI cert without checking to see whether it’s been revoked, or simply expired? Without that validity check, how secure is that cert?

CLM assurance (implemented through infrastructure and workflow) is the “x-factor” in multifactor authentication. Without that x-factor, digital certs aren’t appreciably more secure than passwords. Under most circumstances (and these aren’t likely to change by the end of this decade, regardless of what Gates claims), digital certs are more costly, complex, and cumbersome than passwords. Yes, the smartcard/PKI industry needs to embed their infrastructure in platforms (e.g., Windows) and needs to expand the opportunities for user self-service in enrollment, renewal, revocation, and other lifecycle functions.

But, inherently, strong credentials assurance can’t rely on user self-service alone. Users must run the gantlet of company approvers, background vetters, in-person proofers, and other trusted “administrators” in order to obtain their trusted certs. And to renew them. And to ensure that, when other people’s certs are revoked, that the appropriate certificate revocation lists are kept up to date.

Yes, passwords aren’t enough. But smartcards and certs without a strong-assurance-enabling infrastructure aren’t enough either.

Jim

Thursday, February 16, 2006

lol Study: Dolphins Not So Intelligent On Land

All:

Pointer to fresh Onion peeling:
http://www.theonion.com/content/node/45360&rss=1

Kobielus kollapsing into katatonic kondition of koughing and konvulsing from Onion-induced kackling:

First off, let me once again quote an excerpt from a recent blogpost, and then relate it to the insanely funny pretext of this Onion piece. First, me again:
  • “A [sentient being’s] perceived intelligence depends totally on context. Intelligence is primarily the capacity of a [being] to respond (continually, appropriately, effectively, articulately, and successfully) to various challenges (tests, tasks, and problems) that the world (fate, society, colleagues, teachers, friends, and adversaries) place in front of them. The evaluation of the success of a [sentient entity’s] ongoing/evolving responsiveness to the never-ending parade of new challenges is that [being’s] "intelligence." The [beings] doing that evaluation include the individual him/her/[it]self, plus the [being]’'s family/friends/colleagues/contemporaries/[aquarium/jailer/zookeepers], plus the [being]'s posterity (descendants/historians/etc.). The context for the "smart vs. stupid" determination, then, is the entire frame of reference that involves diverse challenges and different evaluators. Nobody is inherently smart or stupid--they must continually "prove" themselves as one or the other, and could just as easily (on their next challenge, in the eyes of their next self- or external-evaluation) flip-flop [or jump 10 feet into the air] toward [a dangled salmon held by an attractive blonde positioined at] either pole. The bottom line is that [beings squeak] smart things on some occasions on some topics, and stupid things on other occasions/topics….. The evaluator of a [being’'s intelligence may be particular individuals, or a community of individuals, or a particular individual deferring to the collective/received opinions of the community (contemporaneous/posterity).”

That said, this Onion slice made me cry tears of recognition:

  • “Despite their failures in the initial series of tests, the animals were given further opportunities to demonstrate their intelligence on land. The dolphins were unable to display novel behaviors, use a map to pinpoint their location on campus (spatial reasoning), or complete a simple obstacle course and wall climb….’Their learning curve was actually negative,’ Lindell said. ‘The more time we gave them to complete basic land-based tests, the more pitiful their efforts became, with many of them opting to bask in the sun rather than perform a simple task. In some cases," Lindell added, ‘the dolphins appeared to be looking directly into our eyes, as if pleading with us to help them perform better in these tests.’ Many scientists believe these findings may help to explain why dolphins, for all their vaunted intelligence, have never developed technology or agriculture, or harnessed the power of fire—skills still exclusively in the domain of Homo sapiens.”

All of which makes me want to point to the SETI folks and urge them to rename their initiative: Search for Extraterrestrial Anthropomorphism.

We’re always searching “others” for mirrors of our own “intelligence” (i.e., our own very particular human adaptation-conditioned responsiveness to situations, as expressed through our own very particular human brain, body, behaviors, and culture). When we don’t find those signs of “intelligence,” we declare others stupid.

You try navigating the briny murky deep night and day with just your smell, hearing, and kinesthetic senses. A life-or-death task we’re not adapted to. See how smart you appear.

Jim

Tuesday, February 14, 2006

imho Most influential in networking over past 20+ years

All:

Beth Schultz of Network World recently asked me and other columnists to list up to 20 people who have been most influential in networking over the past 20 or so years. This is convenient timespan, because it coincides with my entire career in IT. So it gave me a chance to trip down memory lane.

I started a list of industry-transforming "roles," and then quickly filled in the names that came first to mind. My list:
  • Visionary: George Gilder. His vision of the future of unlimited, no-cost bandwidth and any-to-any connectivity still exerts a powerful influence on everybody's vision of the Internet's potential.
  • Investor: Bill Gates. His longtime patient capital has built Microsoft into the unchallenged platform and application vendor, but his greatest legacy will be the William and Melinda Gates Foundation's ongoing grants to rid the developing world of infectious diseases.
  • Inventor: Tim Berners-Lee. His invention of the World Wide Web truly revolutionized human society by turning the world into an open book, introducing a new addressing scheme that could be applied to any information or application anywhere, and a new protocol that allows us all to meander endlessly throughout the global cornucopia of human creativity.
  • Engineer: Linus Torvalds. His graceful stewardship over Linux has started open-source software on its inevitable path to industry dominance in all categories.
  • Enterpreneur: William McGowan. His principled persistence in the face of massive Bell System obstruction helped usher in the present age of freewheeling competition throughout the global telecommunications industry.
  • Executive: Lou Gerstner. He kept IBM at the industry forefront by successfully evolving the former mainframe monolith into a global professional services powerhouse, just in time for the emergence of platform-agnostic service-oriented architecture.
  • Legislator: Al Gore. As US Senator in Spring 1991, he spearheaded the passage of a bill to fund the National Research and Education Network (NREN), which was a bridge project that sought to transform the R&D-focused Arpanet into the commercialized Internet. Gore's legislation had the desired catalyst efffect. I distinctly recall 10am, June 5, 1991, in room H-137 of the U.S. Capitol Building--when Sen. Gore and three other legislators took the initiative to stimulate the development of the commercial Internet. I was there, in attendance when they announced the legislation, and spoke to the then-senator, who was the acknowledged leader in pushing for this initiative. Let the record note. I still have my notes.
  • Regulator: Harold Greene. The judge who presided over the AT&T divestiture stuck to his guns as long as he could, and gave the newly competitive telecommunications industry just enough breathing room to flourish in the interregnum between Ma Bell and the rapidly reconsolidating Baby Bells.
  • Agitator: Shawn Fanning. He ran a massive civil disobedience service that helped musicians everywhere to find their audiences, overcoming obstructionist record companies, restrictive radio station programmers, and others who try to deny the people easy access to their soul grooves.
  • Standardizer: Jon Postel. He was the maestro who coordinated the development of many of the most fundamental open standards without which the Internet and World Wide Web would never have risen so fast and spread so wide.
  • Lobbyist: Marc Rotenberg. His single-issue focus on privacy protection has kept the lawmakers, regulators, telcos, and others in positions of power in the networking industry continually on the defensive, and kept us all vigilant against encroachments on our civil liberties.
  • Marketer: Steve Jobs. His tiny little iPod has invaded the popular culture so fast that it's almost subcutaneous--and ushered in the age of podcasting--the portable all-in-one entertainment medium.

I realized I have close personal "degrees of separation" from several of these individuals:

  • Gates: My wife, before she moved to the US and met me, dated an American guy who later went on manage the Gates Foundation's finances for a while.
  • McGowan: I once worked for him. During the period in the late 80s when he had his heart transplant, he came into our office conference room one day and told us that "I haven't had a change of heart" re whether he'd keep our unit operating. Not true. But I liked him anyway.
  • Gore: I've actually met him twice, once as senator and once as VP. Nice guy, well-read (read at least one of my Network World columns). Didn't seem wooden at all. Someone I would trust with the keys to the car.
  • Fanning: The guy who temporarily managed Napster after Fanning left was in the senior honors seminar in economics at the University of Michigan with me in 1979-80.
  • Rotenberg: My wife currently works with his wife.

Yeah, I said "degrees of separation," not buddy-buddy. I haven't met Kevin Bacon. But I have met Jason Kobielus.

Jim

Saturday, February 11, 2006

imho The Giulio thread

All:

Giulio Cesare Solaroli e-mailed me to say he enjoyed my blogpost on his and Marco Barulli’s computational reputation model for blog comments, but to point out that I’d misconstrued several details regarding the interactions among functional components in their model. I refer you all to http://www.clipperz.net/ (Giulio and Marco’s blog) for further details on their model (as those details get posted).

What I’m doing in this blogpost is responding to the core assumption of Giulio/Marco’s computational reputation model, as stated by Giulio in our e-mail thread:

  • "What we hope, is that the merit of the comment and the reputation of the author could be some how (indirectly) bounded. Smart people tend to be smart; troll tend to be troll. This regardless of the context where you observe them."

As I responded to Giulio in the e-mail thread, here's my philosophical perspective on this issue:

  • A person's perceived "intelligence" depends totally on context. Intelligence is primarily the capacity of an individual to respond (continually, appropriately, effectively, articulately, and successfully) to various challenges (tests, tasks, and problems) that the world (fate, society, colleagues, teachers, friends, and adversaries) place in front of them. The evaluation of the success of a person's ongoing/evolving "responsiveness" to the never-ending parade of new challenges is that person's "intelligence." The persons doing that evaluation include the individual him/herself, plus the person's family/friends/colleagues/contemporaries, plus the person's posterity (descendants/historians/etc.). The context for the "smart vs. stupid" determination, then, is the entire frame of reference that involves diverse challenges and different evaluators. Nobody is inherently smart or stupid--they must continually "prove" themselves as one or the other, and could just as easily (on their next challenge, in the eyes of their next self- or external-evaluation) flip-flop toward either pole. The bottom line is that people say smart things on some occasions on some topics, and stupid things on other occasions/topics. People tell me I'm smart, but I'm quite aware when I've said or done something stupid (or my wife makes me aware of it).
  • The evaluator of a person's intelligence may be particular individuals, or a community of individuals, or a particular individual deferring to the collective/received opinions of the community (contemporaneous/posterity). Your model is based on the latter intelligence (reputation)-evaluation model: a particular individual (blog author) deferring to the collective/received opinions of contemporaries (other blog authors, as filtered through a "reputation manager").

As I stated in my recent blogpost on their model, I base my decision to reference somebody else's inputs in my blog on whether they pass a certain "intelligence" challenge in the eyes of one particular evaluator: the "it's interesting to Jim" test. I'm not so interested in whether they pass the "intelligence" challenges of other evaluators (such as a circle/community of blog authors). It's not that I necessarily disparage the opinions of other blog authors. But they run their own fiefdoms, and I run mine. I'm president, king, emperor, and grand vizier of my own idio-domain.

I'm always skeptical of "received community opinion" (aka "reputation"). As I said in my blog this past November:

  • "Reputation feels anti-governance, hence unfair. It feels oppressive. It’s the collective mass of received opinion, good and ill, weighing down on a particular identity. It feels like a court where the judge, jury, prosecuting attorney, jailer, and lord high executioner are phantoms, never showing their faces, but making their collective force felt at every turn. It feels like outer appearances, not inner character, ruling our lives."

Giulio responded with another e-mail in which he expressed some doubts about whether “reputation” is really the concept they’re trying to capture in their model. I said that, in the context of their application, I don't think "reputation" is the right term or concept for the assurance level that the "reputation manager" (wrong term for that functional component) is asserting with respect to a blog commenter. What the blog commenter asserts (across one or more comments made to one or more blog authors) is their "commentary" (the sum total of their comments, as an outward manifestation of their analytical and expressive powers).

I proposed that Giulio/Marco think in terms of the following roles:

  • Commenters:
    • Blog authors: These are as Giulio/Marco define them. But it's important to recognize that a blog is simply a stream of commentary from one or more blog authors (e.g., Marco, Giulio, et al.) and (optionally) blog visitors (who may or may not be able to post their commentary to a blog author's site, or, if invited, must be approved by the blog authors prior to posting).
    • Blog visitors: These are Giulio/Marco’s "blog commenters." They don't own the site that they're visiting. They're just guests. They knock on the door and may or may not be invited to post directly.
  • Reviewers:
    • Blog authors: Yes, this is a second role (reviewing submissions from blog visitors) that blog authors perform. Blog authors may also publish their "reviews" (or thumbs-up/thumbs-down decisions) to a blog review hub.
    • Blog review hub: This is Giulio/Marco’s "reputation manager." It's job is to compile, aggregate, weight, and score blog reviews from various blog authors pertaining to various blog visitors.

Blog review hubs don't score blog visitors' "reputation." They score the community (of blog authors) reported evaluations of the quality of blog visitors' submitted comments.

It's not reputation. It's "commentary quality" (of blog visitors) that's being scored by a blog review hub.

And that's what blog visitors (that subset of them who simply visit to read commentary) are implicitly scoring through their browsing/attention and return visits. Do they respond to the quality of Marco/Giulio, Jim Kobielus, Phil Windley, or other people's blog-asserted commentary? And to the quality of the blog visitors who those blog authors have opted to let post to their blogs?

The blog review hub must always be scoped to a particular commentary community. Any measure of “commentary quality” is always relative to the yardstick (i.e., set of values) that a particular community (e.g., technogeeks, feminists, right-wingers, conservative Muslims) holds in common. It’s not enough to scope it to the “blogosphere” (as if that were a community). Your blog review hub may be associated with a particular community of interest. Or a particular congregation of idiots. As blog author, you choose which blog review hub(s) you wish to federate/affiliate with. Whatever clique you click with.

Essentially, then, a blog author may wish to consider a blog commenter’s commentary quality score, as reported by a particular blog review hub, prior to posting that commenter’s comment to their blog.

Or take the simpler, more direct route. Actually read the submitted comment. Then hit “post” if so moved. Or process the comment through your own gray matter and blog on it.

Jim