<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Pushing String &#187; ProtectServe</title>
	<atom:link href="http://www.xmlgrrl.com/blog/categories/protectserve/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xmlgrrl.com/blog</link>
	<description>Tangled musings on identity, privacy, trust, and suchlike</description>
	<lastBuildDate>Mon, 24 Oct 2011 15:38:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>How UMA deals with scopes and authorization</title>
		<link>http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/#comments</comments>
		<pubDate>Sun, 01 May 2011 22:58:22 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[IIW]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2938</guid>
		<description><![CDATA[<p>The <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> group has been quite busy of late. Like several other efforts (don&#8217;t miss John Bradley&#8217;s <a href="http://openid.net/2011/04/29/a-map-for-openid-abc/">OpenID ABC</a> post or anything <a href="http://self-issued.info/">Mike Jones</a> has been blogging in the last few months), we&#8217;ve been gearing up for <a href="http://iiw12.eventbrite.com/">IIW 12</a> as a great place to try out our newest work, figure out the combinatorial possibilities with all the other new stuff going on, and get feedback.</p>
<p>Newcastle University&#8217;s <a href="http://smartam.net/">SMART project team</a> will be in Mountain View&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> group has been quite busy of late. Like several other efforts (don&#8217;t miss John Bradley&#8217;s <a href="http://openid.net/2011/04/29/a-map-for-openid-abc/">OpenID ABC</a> post or anything <a href="http://self-issued.info/">Mike Jones</a> has been blogging in the last few months), we&#8217;ve been gearing up for <a href="http://iiw12.eventbrite.com/">IIW 12</a> as a great place to try out our newest work, figure out the combinatorial possibilities with all the other new stuff going on, and get feedback.</p>
<p>Newcastle University&#8217;s <a href="http://smartam.net/">SMART project team</a> will be in Mountain View again, discussing their UMA implementation and UX work. And vice-chair Maciej Machulak and I plan to convene a session to share our draft solution for <strong>loosely coupling</strong> an OAuth authorization server and resource server to solve for <strong>externalized authorization</strong> and <strong>interoperable scoped access</strong> in the UMA context.</p>
<p>Back in February, a bunch of us tried discussing this very subject in Twitter and got pretty far, but it took Paul Madsen to put the whole story together in his blog post <a href="http://connectid.blogspot.com/2011/02/way-more-than-140-and-loving-it.html">Way more than 140. And loving it</a>. Check it out.</p>
<p>Essentially, UMA is choosing to give the host (resource server) more autonomy than it would typically have in a tightly coupled environment, so that it&#8217;s not entirely accurate to say it&#8217;s a mere policy enforcement point (PEP) and the authorization manager (authz server) is a full policy decision point (PDP). This seems to make good sense in a totally open-Web environment. However, &#8220;the full PDP&#8221; is an optional feature we could probably add if there&#8217;s interest.</p>
<p>The really interesting thing is that, to make externalized authorization work, we&#8217;ve had to go &#8220;radically claims-based&#8221;. The model seems very powerful and generative &#8212; it gives the power to upgrade and downgrade granted scopes at will! But it does take a step or two back from pure OAuth 2.0 as a result. This is something I&#8217;m keen to discuss with folks in and around IIW; we&#8217;ll be presenting <a href="http://www.xmlgrrl.com/publications/IIW12-UMA-ScopedAccess-May2011.pdf">these slides</a> to that end.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ch-ch-ch-ch-changes</title>
		<link>http://www.xmlgrrl.com/blog/2011/01/16/ch-ch-ch-ch-changes/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/01/16/ch-ch-ch-ch-changes/#comments</comments>
		<pubDate>Mon, 17 Jan 2011 04:51:53 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Music]]></category>
		<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Eve Maler]]></category>
		<category><![CDATA[Forrester]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[UMAnitarian]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2836</guid>
		<description><![CDATA[<p>I&#8217;ve just made a big change, joining Forrester Research as a Principal Analyst, and this new adventure is sure to be exciting. It&#8217;s an honor to join this stellar organization and work with so many talented folks. I&#8217;ll be serving <a href="http://www.forrester.com/rb/AllAnalysts.jsp?cm_re=Navigation_010710-_-analysts_tab-_-analysts">security and risk professionals</a> and will focus primarily on identity and access management, so this move feels like a natural outgrowth of work I&#8217;ve been involved in for more than ten years now.</p>
<p>My tenure at PayPal was a&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/01/16/ch-ch-ch-ch-changes/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve just made a big change, joining Forrester Research as a Principal Analyst, and this new adventure is sure to be exciting. It&#8217;s an honor to join this stellar organization and work with so many talented folks. I&#8217;ll be serving <a href="http://www.forrester.com/rb/AllAnalysts.jsp?cm_re=Navigation_010710-_-analysts_tab-_-analysts">security and risk professionals</a> and will focus primarily on identity and access management, so this move feels like a natural outgrowth of work I&#8217;ve been involved in for more than ten years now.</p>
<p>My tenure at PayPal was a great learning experience; I&#8217;ll never forget my time there, nor the good friends I made. I also managed to learn a few things while &#8220;catching up on life&#8221; in the few weeks between gigs. Here are some questions folks have been asking me, with answers:</p>
<p><strong>Q:</strong> Are you moving back to the east coast?</p>
<p><strong>A:</strong> Nope, I&#8217;m still based in the Pacific Northwest, but I will likely be out Boston-way somewhat more often. As for other appearances, you&#8217;ll definitely be able to find me at <a href="http://www.forrester.com/events/eventdetail/0,9179,2512,00.html">Forrester&#8217;s IT Forum 2011</a> in May, and I&#8217;ll be figuring out the situation with other events shortly.</p>
<p><strong>Q:</strong> Will you continue to blog here?</p>
<p><strong>A:</strong> Yes, though the mix of topics will likely change, as I&#8217;ll be contributing industry-related posts to the <a href="http://blogs.forrester.com/security_and_risk">Forrester blog</a>. I&#8217;ll post pointers to those here, and my hope is to step up my writing activity on other topics of interest at Pushing String. And I hope you&#8217;ll continue to follow my doings at <a href="http://twitter.com/#!/xmlgrrl">@xmlgrrl</a> (where the <a href="http://twitter.com/#!/search/%23forrester">#forrester</a> tag will likely make lots of appearances).</p>
<p><strong>Q:</strong> What about User-Managed Access and other innovation-oriented work?</p>
<p><strong>A:</strong> The plan is for me to continue in my role as &#8220;chief UMAnitarian&#8221; and to participate in certain other tech leadership activities as time allows. In the last couple of months we&#8217;ve gotten a big influx of active <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> contributors, and we&#8217;ve had a burst of progress in the last few weeks on defining how to loosely couple &#8220;user-centric&#8221; policy enforcement points and policy decision points. So I think we&#8217;re well on our way to meeting the goals and timing stated in our <a href="http://kantarainitiative.org/confluence/display/uma/Charter">charter</a>.</p>
<p><strong>Q:</strong> So what <em>did</em> you do on your winter vacation?</p>
<p><strong>A:</strong> One of my goals was to &#8220;learn one big thing&#8221;, so I started learning how to play guitar, under the tutelage of my dear old friend <a href="http://en.wikipedia.org/wiki/Klingon_Language_Institute#Rich_Yampell">Rich</a>. My original use cases were around communicating better with my <a href="http://tinyurl.com/mudjunket">Mud Junket</a> bandmates who are actual guitarists, but Rich doesn&#8217;t fool around: I have to learn good technique and not take any shortcuts. Luckily, the fret-hand callus crop has finally started to come in.</p>
<p>I also read a great book called <strong><a href="http://thetalentcode.com/">The Talent Code</a></strong>, which describes what goes on neurologically in people who seem like once-in-a-lifetime geniuses, and discusses how any skill (like guitar-playing!) can be honed more rapidly through &#8220;deep practice&#8221; that stimulates myelin growth.</p>
<p>With all this plus a healthy dose of R&#038;R, it feels like I&#8217;m <em>learning how to learn</em> all over again.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/01/16/ch-ch-ch-ch-changes/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Wishing you a happy, healthy, user-managed new year</title>
		<link>http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/#comments</comments>
		<pubDate>Sun, 26 Dec 2010 02:34:18 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Kantara]]></category>
		<category><![CDATA[leeloo]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[UMAnitarian]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2772</guid>
		<description><![CDATA[<p><a href="http://kantarainitiative.org/confluence/display/uma/Home"><img src="http://kantarainitiative.org/confluence/download/attachments/17760302/UMA_christmas.jpg" alt="UMA Christmas tree 2010" width="425" /></a></p>
<p>Thanks to <a href="http://identitycube.blogspot.com/">Domenico Catalano</a> (<a href="http://twitter.com/#!/domcat">@DomCat</a>) for putting together this lovely and geeky holiday message! And thanks to all the <a href="http://kantarainitiative.org/confluence/display/uma/Participant+Roster">UMAnitarians</a> for their contributions of passion, business problem-solving, and technical know-how to the User-Managed Access work.</p>
<p>The end of 2010 has brought new progress on several fronts. The UMA-friendly Java-based <a href="http://smartjisc.wordpress.com/2010/09/30/oauth-leeloo-v0-1-released/">OAuth leeloo</a> implementation was released as open source; we&#8217;ve begun solving some hard problems in defining <a href="http://kantarainitiative.org/confluence/display/uma/UMA+Resource+Registration">interoperable interfaces</a> between OAuth authorization servers and resource servers;&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://kantarainitiative.org/confluence/display/uma/Home"><img src="http://kantarainitiative.org/confluence/download/attachments/17760302/UMA_christmas.jpg" alt="UMA Christmas tree 2010" width="425" /></a></p>
<p>Thanks to <a href="http://identitycube.blogspot.com/">Domenico Catalano</a> (<a href="http://twitter.com/#!/domcat">@DomCat</a>) for putting together this lovely and geeky holiday message! And thanks to all the <a href="http://kantarainitiative.org/confluence/display/uma/Participant+Roster">UMAnitarians</a> for their contributions of passion, business problem-solving, and technical know-how to the User-Managed Access work.</p>
<p>The end of 2010 has brought new progress on several fronts. The UMA-friendly Java-based <a href="http://smartjisc.wordpress.com/2010/09/30/oauth-leeloo-v0-1-released/">OAuth leeloo</a> implementation was released as open source; we&#8217;ve begun solving some hard problems in defining <a href="http://kantarainitiative.org/confluence/display/uma/UMA+Resource+Registration">interoperable interfaces</a> between OAuth authorization servers and resource servers; we&#8217;ve been teasing out the implications of <a href="http://kantarainitiative.org/confluence/display/uma/User+Experience#UserExperience-UMATrustedClaims">trusted claims</a> as the basis for user-centric access control; and we saw two significant submissions in response to the UMA validation <a href="http://kantarainitiative.org/confluence/display/uma/UMA+Validator+Bounty+Program">bounty program</a>. We&#8217;re grateful to submitters <a href="http://testingsaas.blogspot.com/">Cordny Nederkoorn</a>, whose interest in UMA grew as a result of his explorations into cloud identity, and <a href="http://www.projecthdata.org/">Project hData</a>, a unique and important effort that seeks to make electronic health data amenable to RESTful web app treatment.</p>
<p>We&#8217;ve got lots more developments in store for the coming months, and we welcome your involvement. From our Kantara <a href="http://kantarainitiative.org/confluence/display/uma/Home">home page</a> you can join the group (no membership fees!), subscribe to our mailing list, and check out the latest news, and don&#8217;t forget to follow us on <a href="http://twitter.com/#!/umawg">Twitter</a>.</p>
<p>Happy holidays!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>People and online services: leaving value on the table</title>
		<link>http://www.xmlgrrl.com/blog/2010/11/14/leaving-money-on-the-table/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/11/14/leaving-money-on-the-table/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 03:51:10 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[data portability]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2701</guid>
		<description><![CDATA[<p>The recent Google-Facebook <a href="http://techcrunch.com/2010/11/04/facebook-google-contacts/">flap</a> demonstrates that the hottest battleground for users&#8217; control of the data they pump into these online services is the sites&#8217; Terms of Service. Why? Because when you&#8217;re not a paying customer, you&#8217;re not in a hugely strong bargaining position. As I put it to ReadWriteWeb in their <a href="http://www.readwriteweb.com/archives/google_vs_facebook_the_battle_over_your_data.php">piece</a> on data portability implications of the debate: <strong>Facebook&#8217;s end-users are not its customers; they&#8217;re the product.</strong> (Or as my Data Without Borders pal <a href="http://stevenwonders.com/">Steve Greenberg</a>&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/11/14/leaving-money-on-the-table/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>The recent Google-Facebook <a href="http://techcrunch.com/2010/11/04/facebook-google-contacts/">flap</a> demonstrates that the hottest battleground for users&#8217; control of the data they pump into these online services is the sites&#8217; Terms of Service. Why? Because when you&#8217;re not a paying customer, you&#8217;re not in a hugely strong bargaining position. As I put it to ReadWriteWeb in their <a href="http://www.readwriteweb.com/archives/google_vs_facebook_the_battle_over_your_data.php">piece</a> on data portability implications of the debate: <strong>Facebook&#8217;s end-users are not its customers; they&#8217;re the product.</strong> (Or as my Data Without Borders pal <a href="http://stevenwonders.com/">Steve Greenberg</a> sometimes puts it, users are crops&#8230;getting harvested. Oh dear.)</p>
<p>For all &#8220;free&#8221; online services, it&#8217;s worthwhile to ask: What am I paying instead? If it&#8217;s not money, is it attention to ads? &#8230;behavioral cues about myself and my preferences? &#8230;personally identifiable data? &#8230;beta-testing time? &#8230;what, exactly? Payment for services rendered isn&#8217;t a bad thing. But it&#8217;s <em>always something</em>, and you might as well not be a chump.</p>
<p>That&#8217;s why I like Frank Catalano&#8217;s new <a href="http://www.techflash.com/seattle/2010/11/personal-information-economy-how-to.html">TechFlash post</a> viewing personal data sharing through an economic lens and discussing how to barter your data more equitably. Regarding his second point, &#8220;hide&#8221;: I&#8217;d actually be thrilled if more online services that were marketed to individuals offered a premium for-pay option; it would keep out the riff-raff and give people more meaningful control over their relationships with the companies offering the services.</p>
<p>It&#8217;s not just individuals who are leaving something on the table, though. I think there&#8217;s a big untapped market in <strong>selective sharing</strong>, which is like &#8220;privacy&#8221; (poor abused word), without the assumption that minimal disclosure is the be-all and end-all. What would you <em>start sharing</em> with a <em>selective</em> set of people and businesses, if you could have confidence that your expectations around context, control, choice, and respect would be met?</p>
<p>That&#8217;s why I think Dave McClure has it right with his notion of <a href="http://500hats.typepad.com/500blogs/2010/10/how-to-take-down-facebook.html">intimacy</a> as a market opportunity Facebook currently has no idea how to address. (&#8220;maybe I only want to tell a few close buddies about that episode with the VERY BAD bean burrito&#8221; &#8212; yeah, thanks for keeping this sharing episode VERY selective. :-)</p>
<p>And that&#8217;s why I think Esther Dyson doesn&#8217;t quite have it right in saying <a href="http://gigaom.com/2010/10/19/esther-dyson-privacy-is-a-marketing-problem/">privacy is a marketing problem</a>. Her exhortation to &#8220;Know your customer, and talk to that person as an individual, not as someone in a bucket&#8221; has a natural barrier: Facebook and others are serving their actual customers very well indeed by, uh, making more product.</p>
<p>And that&#8217;s why I think <a href="http://www.xmlgrrl.com/blog/2010/10/06/aiming-for-data-usage-control/">User-Managed Access</a> could help: Becoming paying customers of services that need our data is good. But becoming, in addition, <em>producers</em> of data products as peers in a selective data-sharing network, and dictating our own Terms of Access for getting to them, is even better.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/11/14/leaving-money-on-the-table/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UMA validator bounty program announced</title>
		<link>http://www.xmlgrrl.com/blog/2010/10/19/uma-validator-bounty-program-announced/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/10/19/uma-validator-bounty-program-announced/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 02:20:02 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Kantara]]></category>
		<category><![CDATA[UMA]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2691</guid>
		<description><![CDATA[<p>Are you a software developer or tester? You might be interested in the new $4000 bounty program just <a href="http://kantarainitiative.org/wordpress/2010/10/kantara-initiative-uma-validator-bounty-program/">announced</a> by the Kantara Initiative for:</p>
<blockquote><p>Develop[ing] material that assists in validating the compliance of implemented authorization manager, host, requester, and authorizing user/user agent endpoints to the <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> draft specifications (and their referenced external specifications).</p></blockquote>
<p>The first deadline, to express submission interest, is <strong>November 1</strong> &#8212; which happens to be the day we&#8217;re hosting a F2F <a href="http://www.xmlgrrl.com/blog/2010/10/12/uma-meeting-co-located-with-iiw-and-other-news/">meeting</a> just ahead&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/10/19/uma-validator-bounty-program-announced/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Are you a software developer or tester? You might be interested in the new $4000 bounty program just <a href="http://kantarainitiative.org/wordpress/2010/10/kantara-initiative-uma-validator-bounty-program/">announced</a> by the Kantara Initiative for:</p>
<blockquote><p>Develop[ing] material that assists in validating the compliance of implemented authorization manager, host, requester, and authorizing user/user agent endpoints to the <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> draft specifications (and their referenced external specifications).</p></blockquote>
<p>The first deadline, to express submission interest, is <strong>November 1</strong> &#8212; which happens to be the day we&#8217;re hosting a F2F <a href="http://www.xmlgrrl.com/blog/2010/10/12/uma-meeting-co-located-with-iiw-and-other-news/">meeting</a> just ahead of IIW.</p>
<p>You can keep an eye on the status of the program at its dedicated <a href="http://kantarainitiative.org/confluence/display/uma/UMA+Validator+Bounty+Program">UMA wiki page</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/10/19/uma-validator-bounty-program-announced/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>UMA meeting co-located with IIW and other news</title>
		<link>http://www.xmlgrrl.com/blog/2010/10/12/uma-meeting-co-located-with-iiw-and-other-news/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/10/12/uma-meeting-co-located-with-iiw-and-other-news/#comments</comments>
		<pubDate>Wed, 13 Oct 2010 01:23:00 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[IIW]]></category>
		<category><![CDATA[Kantara]]></category>
		<category><![CDATA[leeloo]]></category>
		<category><![CDATA[SMART project]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[UMAnitarian]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2668</guid>
		<description><![CDATA[<p>Thanks to <a href="http://www.windley.com/">Phil</a> and <a href="http://www.identitywoman.net/">Kaliya</a> and the gang, I&#8217;m happy to say we&#8217;re holding an UMA face-to-face meeting at the Computer History Museum on the Monday just prior to <a href="http://www.internetidentityworkshop.com/iiwxi-11-in-mountain-view/">IIW XI</a> (pronounced &#8220;yewksie&#8221;?).</p>
<p>This follows close on the heels of a face-to-face in Paris at the <a href="http://kantarainitiative.org/confluence/display/GI/Kantara+Initiative+Conferences">Kantara conference</a>, so I hope we&#8217;ll be able to crank through a lot of work in the next few weeks. What work, you ask? We&#8217;re shooting for draft completion of&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/10/12/uma-meeting-co-located-with-iiw-and-other-news/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Thanks to <a href="http://www.windley.com/">Phil</a> and <a href="http://www.identitywoman.net/">Kaliya</a> and the gang, I&#8217;m happy to say we&#8217;re holding an UMA face-to-face meeting at the Computer History Museum on the Monday just prior to <a href="http://www.internetidentityworkshop.com/iiwxi-11-in-mountain-view/">IIW XI</a> (pronounced &#8220;yewksie&#8221;?).</p>
<p>This follows close on the heels of a face-to-face in Paris at the <a href="http://kantarainitiative.org/confluence/display/GI/Kantara+Initiative+Conferences">Kantara conference</a>, so I hope we&#8217;ll be able to crank through a lot of work in the next few weeks. What work, you ask? We&#8217;re shooting for draft completion of some key items in the upper box shown here (click to get to a full-size site-mapped version on our Working Drafts page):</p>
<p><a href="http://kantarainitiative.org/confluence/display/uma/Working+Drafts"><img src="http://cdn.xmlgrrl.com/blog/wp-content/uploads/2010/10/spec-modules.png" alt="" title="spec-modules" width="400" /></a></p>
<p>I&#8217;ve already gotten several requests for more info about the IIW meeting.  These will be working meetings, not public transfer-of-information workshops, and we always welcome new participation.  You can become a participant (voting/frequently attending or non-voting/attend at will, totally up to you) by filling out <a href="http://signup.kantarainitiative.org/?selectedGroup=11">this form</a>. I&#8217;ve put up some very preliminary agendas (<a href="http://kantarainitiative.org/confluence/display/uma/UMA+F2F+2010-10-20">Paris</a>, <a href="http://kantarainitiative.org/confluence/display/uma/UMA+F2F+2010-11-01">Mtn View</a>); they tend to be responsive to work done in weeks prior, so check back.</p>
<p>(UPDATE: There&#8217;s no formal registration process for the IIW meeting as long as you&#8217;re already signed up as an UMA participant; just send me an RSVP. Contact info is under my Welcome section in the right sidebar.)</p>
<hr />
<p>Did you know our <a href="http://smartjisc.wordpress.com/">Newcastle University UMAnitarians</a> have begun open-sourcing their Java implementation?  The first big piece from the SMART Project covers UMA-friendly OAuth 2.0 and has the lovely name <a href="http://www.xmlgrrl.com/blog/2010/02/28/the-economist-and-ecto-gammat/">leeloo</a>. They promise more to come soon, and I bet we&#8217;ll see some swank demos at IIW. <a href="http://leeloo.smartam.net">Check it out!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/10/12/uma-meeting-co-located-with-iiw-and-other-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aiming for data usage control</title>
		<link>http://www.xmlgrrl.com/blog/2010/10/06/aiming-for-data-usage-control/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/10/06/aiming-for-data-usage-control/#comments</comments>
		<pubDate>Wed, 06 Oct 2010 23:31:01 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[claims]]></category>
		<category><![CDATA[DRM]]></category>
		<category><![CDATA[liability]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[W3C]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2647</guid>
		<description><![CDATA[<p>Earlier this week, W3C held a <a href="http://www.w3.org/2010/policy-ws/">workshop</a> on privacy and data usage control. Among the submitted <a href="http://www.w3.org/2010/policy-ws/papers.html">position papers</a> are quite a few interesting thoughts, and though I couldn&#8217;t attend the workshop, it will be good to see the eventual report from it.</p>
<p>I did manage to submit a <a href="http://www.w3.org/2010/policy-ws/papers/18-Maler-Paypal.pdf">paper</a> that explores the contributions of <a href="http://kantarainitiative.org/confluence/display/uma/Home">User-Managed Access</a> (UMA) to letting people control the usage of their personal data. It was a chance to capture an important part&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/10/06/aiming-for-data-usage-control/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Earlier this week, W3C held a <a href="http://www.w3.org/2010/policy-ws/">workshop</a> on privacy and data usage control. Among the submitted <a href="http://www.w3.org/2010/policy-ws/papers.html">position papers</a> are quite a few interesting thoughts, and though I couldn&#8217;t attend the workshop, it will be good to see the eventual report from it.</p>
<p>I did manage to submit a <a href="http://www.w3.org/2010/policy-ws/papers/18-Maler-Paypal.pdf">paper</a> that explores the contributions of <a href="http://kantarainitiative.org/confluence/display/uma/Home">User-Managed Access</a> (UMA) to letting people control the usage of their personal data. It was a chance to capture an important part of the philosophy we bring to our work, and the challenges that remain. From the paper&#8217;s introduction:</p>
<blockquote><p>&#8230;UMA allows a user to make demands of the requesting side in order to test their suitability for receiving authorization. These demands can include requests for information (such as “Who are you?” or “Are you over 18?”) and promises (such as “Do you agree to these non-disclosure terms?” or “Can you confirm that your privacy and data portability policies match my requirements?”).</p>
<p>The implications of these demands quickly go beyond cryptography and web protocols and into the realm of agreements and liability. UMA values end-user convenience, development simplicity, and web-wide adoption, and therefore it eschews such techniques as DRM. Instead, it puts a premium on user visibility into and control over access criteria and the authorization lifecycle. UMA also seeks at least a minimum level of enforceability of authorization agreements, in order to make the act of granting resource access truly informed, uncoerced, and meaningful. Granting access to data is then no longer a matter of mere passive consent to terms of use. Rather, it becomes a valuable offer of access on user-specified terms, more fully empowering ordinary web users to act as peers in a network that enables selective sharing.</p></blockquote>
<p>Some of the challenges are technical, some legal, and some related to business incentives. The paper approaches the discussion with what I hope is a sense of realism, along with some justified optimism about near-term possibilities.</p>
<p>(Speaking of which, I like the realism pervading Ben Laurie&#8217;s recent <a href="http://www.links.org/?p=1007">criticism</a> of the EFF&#8217;s suggested bill of privacy rights for social network users. He cautions them to stay away from implicitly mandating mechanisms like DRM &#8212; and, in focusing on broader aims, to be careful what they wish for.)</p>
<p>If you&#8217;re so inclined, I hope you&#8217;ll check out the paper and the other workshop inputs and outputs.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/10/06/aiming-for-data-usage-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where web and enterprise meet on user-managed access</title>
		<link>http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/#comments</comments>
		<pubDate>Sun, 18 Jul 2010 20:10:40 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[cis2010]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[ID-WSF]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[UMA]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2559</guid>
		<description><![CDATA[<p>Phil Hunt shared some <a href="http://independentidentity.blogspot.com/2010/07/uma-and-oauth-2-first-impressions.html">musings</a> on OAuth and UMA recently. His perspective is valuable, as always. He even coined a neat phrase to capture a key value of UMA&#8217;s authorization manager (AM) role: it&#8217;s a user-centric <strong>consent server</strong>. Here are a couple of thoughts back.</p>
<p>In the enterprise, an externalized <strong>policy decision point</strong> represents classic access management architecture, but in today&#8217;s Web it&#8217;s foreign. UMA combines both worlds with the trick of letting Alice craft her own access authorization&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Phil Hunt shared some <a href="http://independentidentity.blogspot.com/2010/07/uma-and-oauth-2-first-impressions.html">musings</a> on OAuth and UMA recently. His perspective is valuable, as always. He even coined a neat phrase to capture a key value of UMA&#8217;s authorization manager (AM) role: it&#8217;s a user-centric <strong>consent server</strong>. Here are a couple of thoughts back.</p>
<p>In the enterprise, an externalized <strong>policy decision point</strong> represents classic access management architecture, but in today&#8217;s Web it&#8217;s foreign. UMA combines both worlds with the trick of letting Alice craft her own access authorization policies, at an AM she chooses. She&#8217;s the one likeliest to know which resources of hers are sensitive, which people and services she&#8217;d like to share access with, and what&#8217;s acceptable to do with that access. With a single hub for setting all this up, she can reuse policies across resource servers and get a global view of her entire access landscape. And with an always-on service executing her wishes, in many cases she can even be offline when an access requester comes knocking. In the process, as Phil observes, UMA &#8220;supports a federated (multi-domain) model for user authorization not possible with current enterprise policy systems.&#8221;</p>
<p>Phil wonders about privacy impacts of the AM role given its centrality. In earlier federated identity protocol work, such as Liberty&#8217;s Identity Web Services Framework, it was assumed that enterprise and consumer IdPs could never be the authoritative source of all interesting information about a user, and that we&#8217;d each have a variety of attribute authorities. This is the reality of today&#8217;s web, expanding &#8220;attribute&#8221; to include &#8220;content&#8221; like photos, calendars, and documents. So rather than having an über-IdP attempt to aggregate all Alice&#8217;s stuff into a single personal datastore &#8212; presenting a pretty bad <strong>panoptical identity</strong> problem in addition to other challenges &#8212; an AM can manage access relationships to all that stuff sight unseen. Add the fact that UMA lets Alice set conditions for access rather than just passively agree to others&#8217; terms, and I believe an AM can materially enhance her privacy by giving her meaningful control.</p>
<p>Phil predicts that OAuth and UMA will be useful to the enterprise community, and I absolutely agree. Though the <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA group</a> has taken on an explicitly non-enterprise scope for its initial work, large-enterprise and small-business use cases keep coming up, and cloud computing models keep, uh, fogging up all these distinctions. (Imagine Alice as a software developer who needs to hook up the OAuth-protected APIs of seven or eight SaaS offerings in a complex pattern&#8230;) Next week at the <a href="http://www.cloudidentitysummit.com/program/July21-1035.cfm">Cloud Identity Summit</a> I&#8217;m looking forward to further exploring the consumer-enterprise nexus of federated access authorization.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>SMART UMA application: call for testers</title>
		<link>http://www.xmlgrrl.com/blog/2010/07/16/smart-uma-application-call-for-testers/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/07/16/smart-uma-application-call-for-testers/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 19:14:03 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[SMART project]]></category>
		<category><![CDATA[UMA]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2546</guid>
		<description><![CDATA[<p>The <a href="http://research.ncl.ac.uk/smart">SMART project</a> (Student-Managed Access to Online Resources) at Newcastle University has <a href="http://groups.google.com/group/kantara-initiative-uma-wg/browse_frm/thread/609e891cce553e8d">issued</a> a call for user experience testers for the <strong>smartam</strong> component of the UMA-based applications they have been building. Participation should take less than a half-hour; if you&#8217;re interested, check out the <a href="http://kantarainitiative.org/confluence/download/attachments/41026357/SMART-UX-study-July2010.pdf">flyer</a> for instructions. To keep up with general news on the project (there&#8217;s lots), follow the SMART JISC <a href="http://smartjisc.wordpress.com/">blog</a>.</p>
<p>This is an exciting milestone in UMA development. Congratulations to the SMART team!&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/07/16/smart-uma-application-call-for-testers/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://research.ncl.ac.uk/smart">SMART project</a> (Student-Managed Access to Online Resources) at Newcastle University has <a href="http://groups.google.com/group/kantara-initiative-uma-wg/browse_frm/thread/609e891cce553e8d">issued</a> a call for user experience testers for the <strong>smartam</strong> component of the UMA-based applications they have been building. Participation should take less than a half-hour; if you&#8217;re interested, check out the <a href="http://kantarainitiative.org/confluence/download/attachments/41026357/SMART-UX-study-July2010.pdf">flyer</a> for instructions. To keep up with general news on the project (there&#8217;s lots), follow the SMART JISC <a href="http://smartjisc.wordpress.com/">blog</a>.</p>
<p>This is an exciting milestone in UMA development. Congratulations to the SMART team!</p>
<p>UPDATE: The SMART blog now has an entry that <a href="http://smartjisc.wordpress.com/2010/07/17/smart-user-experience-study-is-open/">describes</a> the exciting directions <strong>smartam</strong> is going. Don&#8217;t miss it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/07/16/smart-uma-application-call-for-testers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tofu, online trust, and spiritual wisdom</title>
		<link>http://www.xmlgrrl.com/blog/2010/07/06/tofu-online-trust-and-spiritual-wisdom/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/07/06/tofu-online-trust-and-spiritual-wisdom/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 01:48:13 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Buddhism]]></category>
		<category><![CDATA[cis2010]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[EIC]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[TOFU]]></category>
		<category><![CDATA[trust framework]]></category>
		<category><![CDATA[UMA]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2518</guid>
		<description><![CDATA[<p>At the European Identity Conference a little while back, <a href="http://www.andredurand.com/">Andre Durand</a> gave a downright spiritual keynote on Identity in the Cloud. His advice for dealing with the angst of moving highly sensitive identity information into the cloud? Ancient Buddhist wisdom.</p>
<blockquote><p>All experiences are marked by suffering, disharmony, and frustration.</p>
<p>Suffering and frustration come from desire and clinging.</p>
<p>To achieve an end to disharmony, <strong>stop clinging</strong>.</p></blockquote>
<p>(I can&#8217;t wait to hear his pearls of wisdom at the <a href="http://www.cloudidentitysummit.com/">Cloud Identity</a>&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/07/06/tofu-online-trust-and-spiritual-wisdom/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>At the European Identity Conference a little while back, <a href="http://www.andredurand.com/">Andre Durand</a> gave a downright spiritual keynote on Identity in the Cloud. His advice for dealing with the angst of moving highly sensitive identity information into the cloud? Ancient Buddhist wisdom.</p>
<blockquote><p>All experiences are marked by suffering, disharmony, and frustration.</p>
<p>Suffering and frustration come from desire and clinging.</p>
<p>To achieve an end to disharmony, <strong>stop clinging</strong>.</p></blockquote>
<p>(I can&#8217;t wait to hear his pearls of wisdom at the <a href="http://www.cloudidentitysummit.com/">Cloud Identity Summit</a> later this month&#8230; <a href="http://www.cloudidentitysummit.com/program/Agenda-at-a-Glance.cfm">I&#8217;ll be there</a> speaking on UMA. You going?)</p>
<p>This resonated with another plea I&#8217;d just heard from <a href="http://noncombatant.org/">Chris Palmer</a> at the <a href="https://www.isecpartners.com/forum.html">iSEC Partners Open Security Forum</a>, in his talk called <a href="http://docs.google.com/present/view?id=df9sn445_206ff3kn9gs"><strong>It&#8217;s Time to Fix HTTPS</strong></a>.</p>
<p>Chris&#8217;s message could be described as &#8220;Stop clinging to global PKI for browser security because it is disharmonious.&#8221; He reviewed the perverse incentives that fill the certificate ecosystem, and demonstrated that browsers therefore act in the way that will help ordinary users <em>least</em>.</p>
<p>Why, he asked, can&#8217;t we convey more usable security statements to users along the lines of:</p>
<blockquote><p>&#8220;This is almost certainly the same server you connected with yesterday.&#8221;</p>
<p>&#8220;You&#8217;ve been connecting to almost certainly the same server all month.&#8221;</p>
<p>&#8220;This is <strong>probably</strong> the same server you connected with yesterday.&#8221;</p>
<p>&#8220;Something seems fishy; this is probably not the same server you connected with yesterday. You should call or visit your bank/whatever to be sure nothing bad has happened.&#8221;</p></blockquote>
<p>Perhaps I was the only one not already familiar with his names for the theory that can make these statements possible: TOFU/POP, for Trust On First Use/Persistence of Pseudonym. Neither of these phrases gets any serious Google search love, at least not yet. But I love TOFU, and you should too. (N.B.: I&#8217;m not a big fan of lowercase tofu.)  The basic idea is that you can figure out whether to trust the <em>first</em> connection with a nominally untrusted entity by means of out-of-band cues or other met expectations &#8212; and then you can just work on keeping track of whether it&#8217;s really them the next time.</p>
<p>The neat thing is, we do this all the time already. When you meet someone face-to-face and they say their Skype handle is KoolDood, and later a KoolDood asks to connect with you on Skype and describes the circumstances of your meeting, you have a reasonable expectation it&#8217;s the right guy ever after. And it&#8217;s precisely the way persistent pseudonyms work in federated identity: as I&#8217;ve pointed out <a href="http://www.xmlgrrl.com/blog/2009/12/31/how-to-rest-assured/">before</a>, a relying-party website might not know you&#8217;re a dog, but it usually needs to know you&#8217;re the same dog as last time.</p>
<p>Knowing of the desire to cling to global PKI in an environment where it&#8217;s simply not working for us, Chris proposes letting go of trust &#8212; and shooting for &#8220;trustiness&#8221; instead.  If it successfully builds actual Internet trust relationships vs. the theoretical kind, hey, I&#8217;m listening. There&#8217;s a lot of room for use cases between perfect trust frameworks built on perfect certificate/signature mechanisms and plain old TOFU-flavored trustiness, and UMA and lots of other solutions should be able to address the whole gamut.</p>
<p>Surely inner peace is just around the corner.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/07/06/tofu-online-trust-and-spiritual-wisdom/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using apc (Feed is rejected)
Page Caching using apc
Database Caching using apc
Object Caching 1058/1239 objects using apc
Content Delivery Network via Amazon Web Services: CloudFront: cdn.xmlgrrl.com

Served from: www.xmlgrrl.com @ 2012-02-03 21:25:18 -->
