<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Pushing String</title>
	<atom:link href="http://www.xmlgrrl.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xmlgrrl.com/blog</link>
	<description>XML, cross-stitching, and other tangled musings</description>
	<pubDate>Mon, 12 May 2008 00:50:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
	<language>en</language>
			<item>
		<title>The care and feeding of online relationships</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/05/11/the-care-and-feeding-of-online-relationships/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/05/11/the-care-and-feeding-of-online-relationships/#comments</comments>
		<pubDate>Mon, 12 May 2008 00:50:22 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=364</guid>
		<description><![CDATA[The requirements I&#8217;ve been talking about lately in this space aren&#8217;t impossible to satisfy. What solutions are here today or on the horizon?
For web services that enable reduced data disclosure and can operate when we&#8217;re not around to tell them how, Liberty ID-WSF is a strong match.  And its Interaction Service capabilities are a [...]]]></description>
			<content:encoded><![CDATA[<p>The requirements I&#8217;ve been talking about lately in this space aren&#8217;t impossible to satisfy. What solutions are here today or on the horizon?</p>
<p>For web services that enable reduced data disclosure and can operate when we&#8217;re not around to tell them how, <a href="http://www.projectliberty.org/liberty/content/download/4120/27687/file/idwsf-intro-v1.0.pdf">Liberty ID-WSF</a> is a strong match.  And its Interaction Service capabilities are a strong match for adhering to user-configured ways of obtaining consent or additional info, when doing an action &#8220;silently&#8221; would have been outside my established policy.</p>
<p>For encapsulating an individual&#8217;s policy in a usefully machine-readable way, an interesting <a href="http://www.projectliberty.org/liberty/content/download/4202/28227/file/080423%20igf-openliberty%20-%20P%20Hunt.pdf">technology stack</a> involving XACML, WS-Policy, CARML, and AAPML is starting to appear (including in <a href="http://openliberty.org/">open source</a>) that could turn out to be very helpful (<a href="http://connectid.blogspot.com/2008/05/identity-rights-agreements.html">Identity Rights Agreements</a>, anyone?) &#8212; if we can figure out where in the process human beings can actually apply it and make it stick.</p>
<p>That last &#8220;if&#8221; is where a lot of exciting stuff is happening. Some folks have been working on an approach called &#8220;feeds-based VRM&#8221;, a name reflecting both the VRM use cases it first tackled and the Atom feed-based (lightweight pub/sub) architectural approach it uses. <a href="http://www.crypticide.com/dropsafe/">Alec Muffet</a> published an excellent <a href="http://docs.google.com/View?docid=df9dfsgj_1ghhqgjfq">paper</a> on the subject in February (also see <a href="http://www.mediainfluencer.net/">Adriana Lukas</a>&#8217;s <a href="http://www.mediainfluencer.net/2008/02/power-to-the-persons-redux/">Power to the Persons</a> introductory post) that shows how robust and powerful this model could be.</p>
<p>In my <a href="http://www.xmlgrrl.com/publications/Maler-NZIDConf-Apr2008.pdf">NZ talk</a> I essayed an explanation of the approach using this diagram&#8230;</p>
<p><img src="http://www.xmlgrrl.com/blog/wp-content/uploads/2008/05/feed-based-vrm-small.png" alt="" title="Feed-based VRM mechanism" /></p>
<p>&#8230;and posed these questions: <em>What if&#8230;</em></p>
<ul>
<li>We could host our own digital data, for sharing only with our chosen online partners, on terms we set?</li>
<li>We could create the data however we wish –- once –- then share it &#8220;in bulk&#8221;?</li>
<li>Partners could grab the freshest version at any time?</li>
<li>We could audit usage and cut off &#8220;bad partners&#8221;?</li>
<li>We could combine this with existing identities –- silo-based, traditionally federated, OpenID -– and identity-aware services?</li>
<li>We could build an ecosystem for this on the very thinnest of standard Web technology layers?</li>
</ul>
<p>ID-WSF could do the first few what-ifs, I think, but today provides no solution for cutting off bad partners and today is built on a fairly heavy stack that can&#8217;t be called a &#8220;thin Web layer&#8221; (though the work Hubert has been <a href="http://blogs.sun.com/hubertsblog/">blogging</a> re: RESTful ID-WSF may change that picture).  I believe creating feeds that are (a) custom and (b) access-controlled can <em>potentially</em> satisfy all the what-ifs. It&#8217;s a living embodiment of a relationship-forging stage which, when combined with clever auditing, whitelisting, and the like in a highly usable interface, has the ability to let us modify and even terminate data-sharing relationships over time. User-driven indeed!</p>
<p>(By the way, Alec has said he doesn&#8217;t want to include policy metadata as part of the feed mechanism for now &#8212; he&#8217;s keen to vet the basic technical approach first, which makes sense to me, and let more sophisticated applications emerge later.  In any case, the very act of customizing a feed for a particular recipient contains some policy within its essence, which is one of the exciting things about it.)</p>
<p>It&#8217;s great to see that Adriana et al. have, just today, expounded on their full-size vision in a <a href="http://www.mediainfluencer.net/2008/05/i-haz-a-mine-let-me-show-you-it/">post</a> and public <a href="http://docs.google.com/View?docid=dgc23h2k_397cgqg3xgh">paper</a> that you&#8217;ll definitely want to check out if your interest has been piqued so far.  Note that the personal data store component has been dubbed the &#8220;Mine!&#8221;, and that this component gains new emphasis vs. the &#8220;FeedMe&#8221; on-the-wire component compared to the original paper.  (I&#8217;m not sure I buy the full-size vision for the Mine component, but am keenly interested in the ecosystem effects and UI usability of the FeedMe component &#8212; and I swear it&#8217;s not just &#8217;cause I suggested that as a name! :-) )</p>
<p>No doubt next week&#8217;s <a href="http://iiw.idcommons.net/index.php/Iiw2008a">IIW event</a> will provide great opportunities for digging into all this in more depth.  And the Mine paper advertises the <a href="http://groups.google.com/group/vrm-nea-foundation?lnk=li">mailing list</a> for what will be an open-source Mine project.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F05%2F11%2Fthe-care-and-feeding-of-online-relationships%2F';
  addthis_title  = 'The+care+and+feeding+of+online+relationships';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/05/11/the-care-and-feeding-of-online-relationships/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Practical human-centering and VRM</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/05/11/practical-human-centering-and-vrm/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/05/11/practical-human-centering-and-vrm/#comments</comments>
		<pubDate>Sun, 11 May 2008 18:57:15 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=362</guid>
		<description><![CDATA[Previously, I argued that people are not going to sit still for the heavyweight login-and-consent processes that we IdM professionals are starting to pile on them. They will find ways of getting around the onerous series of screens, clicks, and what-have-you we&#8217;re imposing.
True confession time: I&#8217;m probably the biggest user of Sun&#8217;s OpenID Provider in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.xmlgrrl.com/blog/archives/2008/05/04/imperatives-driving-human-centered-identity/">Previously</a>, I argued that people are not going to sit still for the heavyweight login-and-consent processes that we IdM professionals are starting to pile on them. They will find ways of getting around the onerous series of screens, clicks, and what-have-you we&#8217;re imposing.</p>
<p>True confession time: I&#8217;m probably the biggest user of <a href="http://openid.sun.com">Sun&#8217;s OpenID Provider</a> in the company.  I use it to log in to the <a href="http://projectconcordia.org">Project Concordia wiki</a>, and I&#8217;ve been trying to be a good <a href="http://www.tvacres.com/insects_bees_dobee.htm">do-bee</a> and use it consistently. A while back, the Sun OpenID server went down temporarily, and I had edits to make.  What to do?  I discovered that a local login, set up for me when we were getting the wiki ready to go live, was still around and the cookie was still working, so it would auto-fill my username and password.  Ooh, I can hit Return once, no redirects, no having to say that I <em>really do</em> want to send my info to that RP&#8230;  It&#8217;s like crack.  Even I have a hard time going back to the &#8220;better&#8221; OpenID.</p>
<p>I also argued that people currently have little power in setting up data-sharing relationships with sites, because there&#8217;s no window for them to do anything but accept the data-sharing terms offered (or reject them and not get to use the service).</p>
<p>The Vendor Relationship Management folks were really the first to bring this issue out of the closet. Yes, Liberty ID-WSF tries to enable a marketplace in privacy-respecting personalized services, but it tackles plumbing &#8212; whereas VRM digs into individuals&#8217; needs in an evocative way that flips an &#8220;I want that!&#8221; switch in people&#8217;s heads. Suspecting that few people in the NZ conference audience were familiar with VRM, in my <a href="http://xmlgrrl.com/publications/Maler-NZIDConf-Apr2008.pdf">talk</a> I essayed a quick explanation using a two-part diagram that will be familiar to devotees:</p>
<p><img src="http://www.xmlgrrl.com/blog/wp-content/uploads/2008/05/vrm-small.png" alt="CRM and VRM" title="CRM and VRM"/></p>
<p>A few people actually gasped and applauded when I got to the green arrows &#8212; so I hereby pass the kudos on to Doc Searls and the entire <a href="http://cyber.law.harvard.edu/projectvrm/Main_Page">Project VRM</a> gang! (And congrats on the recent <a href="http://www.id-conf.com/blog/2008/04/25/the-winners/">EIC Special Award</a> as well.)</p>
<p>There&#8217;s a point about timing that I touched on before but wanted to dive deeper on.</p>
<p>The times when I&#8217;m motivated to log in to an online service have a not-hugely-strong relationship to  (a) the times when the service needs to do something interesting on my behalf (such as determining whether to allow Bob into <em>my</em> calendar to see or add information &#8212; he&#8217;s logged in, but why should anyone expect me to be?) and (b) the times when important info about me changes (such as when I move house).</p>
<p>Project VRM has developed &#8220;change of address&#8221; as one of its seminal use cases, and this temporal mismatch helps explain its appeal. Having to do a regular login process to tell fifty online services you&#8217;ve moved is the worst possible architectural choice if we care about usability or fairness or data freshness.</p>
<p>This issue lays more of the groundwork for the requirements I proposed earlier:</p>
<ul>
<li>Services that can provide aggregate value to us even when given a small and disjoint set of our info to work with for privacy reasons</li>
<li>Services that operate according to our data-sharing and -usage preferences all the time without bothering us, but know how to contact us in extraordinary circumstances</li>
<li>A relationship-forging stage or function or ceremony, apart from routine login-time, at which we can craft such policies and get them to stick</li>
</ul>
<p>(Paul, I knew I could count on you to <a href="http://connectid.blogspot.com/2008/05/dont-ask-dont-tell.html">steal</a> my extremely delayed thunder. :-) Continue to steal away while I work on one last post&#8230;)</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F05%2F11%2Fpractical-human-centering-and-vrm%2F';
  addthis_title  = 'Practical+human-centering+and+VRM';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/05/11/practical-human-centering-and-vrm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Another cake of type &#8220;Birthday&#8221;</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/05/09/another-cake-of-type-birthday/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/05/09/another-cake-of-type-birthday/#comments</comments>
		<pubDate>Sat, 10 May 2008 00:04:22 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[XML]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=361</guid>
		<description><![CDATA[Cool! And this one&#8217;s even got I18N support&#8230;
(Thanks to Paul Bryan for the tip!  If you&#8217;re curious, my old one is here.)

  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F05%2F09%2Fanother-cake-of-type-birthday%2F';
  addthis_title  = 'Another+cake+of+type+%26%238220%3BBirthday%26%238221%3B';
  addthis_pub    = '';

]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/chantastic/1590993819/sizes/l/">Cool!</a> And this one&#8217;s even got I18N support&#8230;</p>
<p>(Thanks to Paul Bryan for the tip!  If you&#8217;re curious, my old one is <a href="http://www.xmlgrrl.com/blog/archives/2005/05/01/well-formed-birthday-cake/">here</a>.)</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F05%2F09%2Fanother-cake-of-type-birthday%2F';
  addthis_title  = 'Another+cake+of+type+%26%238220%3BBirthday%26%238221%3B';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/05/09/another-cake-of-type-birthday/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Imperatives driving human-centered identity</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/05/04/imperatives-driving-human-centered-identity/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/05/04/imperatives-driving-human-centered-identity/#comments</comments>
		<pubDate>Mon, 05 May 2008 02:57:22 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=360</guid>
		<description><![CDATA[In my recent talk on everyday identity, I suggested that login-time consent to data sharing is not a great example of human-centered design.
Even if we had already figured out the perfect ceremony for real-time consent or developed the best login interfaces, individuals still tend to be disadvantaged in the federated identity balance of power &#8212; [...]]]></description>
			<content:encoded><![CDATA[<p>In my <a href="http://www.xmlgrrl.com/blog/archives/2008/04/30/everyday-identity-and-human-centered-design/">recent talk on everyday identity</a>, I suggested that login-time consent to data sharing is not a great example of human-centered design.</p>
<p>Even if we had already figured out the perfect ceremony for real-time consent or developed the best login interfaces, individuals still tend to be disadvantaged in the federated identity balance of power &#8212; that big flashing &#8220;I Agree, Here&#8217;s My Data&#8221; button might as well read &#8220;I&#8217;m Over a Barrel, So Go Ahead and Take It Anyway&#8221;.</p>
<p>David Weinberger has <a href="http://www.hyperorg.com/blogger/2008/05/01/keeping-id-hard-shameful-or-at-least-awkward/">this analysis</a> (do read the whole thing):</p>
<blockquote><p>Since just about every vendor on the Web would like to know more about you rather than less, why won’t just about every vendor ask for more information rather than less? It’s all just a button press.
</p></blockquote>
<p>The golfer use case in my <a href="http://xmlgrrl.com/publications/Maler-NZIDConf-Apr2008.pdf">slides</a> highlights this issue as well, using InfoCard flows. In real life, my boss was actually asked for his Social Security Number (!) as a prerequisite for starting a new account while trying to book a tee time over the phone. In that communication mode it&#8217;s easier to just say &#8220;no, thanks&#8221; and hang up the phone; with an information card many people might just press Return to get it all over with.</p>
<p>So how do we get to truly human-centered design? We take into account people&#8217;s real tendencies and desires, and try to bake these into identity ecosystems in a way that redresses the power balance.</p>
<p>Here are three common tendencies: <strong>new-relationship energy</strong> (the conscious effort you&#8217;re willing to invest when something is new vs. familiar), the <strong>efficiency</strong> imperative (the impatience with annoying multi-step interactions that makes you stop paying attention), and the <strong>self-revelation</strong> imperative (accepting that it&#8217;s legitimate to choose to share data about yourself when it gets you something of value).</p>
<p>Based on these, here&#8217;s what I suggest:</p>
<ul>
<li>
<p>Let&#8217;s reduce the routine gathering of data-sharing consent at login time &#8212; it doesn&#8217;t materially empower individuals and, as a bonus, it annoys them. Instead, we should find a way to let people configure data usage policies at the time of establishing relationships with online partners; without this, people are stuck with accepting others&#8217; terms and have no window in which to impose any of their own. In essence, we need to be thinking about the game theory of identity! To quote David Weinberger again:</p>
<blockquote><p>[I]f we’re going to make it easy to give out our personal information, we ought to be thinking about the norms, market forces, or rules that would make it harder to ask for that information.</p></blockquote>
</li>
<li>
<p>We also need to enable applications to get something useful done when handed only a tiny slice of someone&#8217;s personally identifiable information, and use pseudonyms and other privacy measures zealously when coordinating among applications. If we can&#8217;t enable this, we&#8217;ll continue to be asked for way too much information because it&#8217;s the apps&#8217; path of least resistance.</p>
</li>
<li>
<p>Finally, we should reserve user-approval loops for extraordinary circumstances, ideally those dictated by people&#8217;s own preference settings &#8212; which allows identity-based app behavior to go on in the background (e.g., while we&#8217;re sleeping, windsurfing, or whatever) as appropriate and to grab our attention when we need it.</p>
</li>
</ul>
<p>(More thoughts soon on some solution opportunities in all this&#8230;)</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F05%2F04%2Fimperatives-driving-human-centered-identity%2F';
  addthis_title  = 'Imperatives+driving+human-centered+identity';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/05/04/imperatives-driving-human-centered-identity/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Everyday identity and human-centered design</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/04/30/everyday-identity-and-human-centered-design/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/04/30/everyday-identity-and-human-centered-design/#comments</comments>
		<pubDate>Wed, 30 Apr 2008 21:26:51 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Language]]></category>

		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=358</guid>
		<description><![CDATA[The Managing Identity in New Zealand conference has been an amazing experience.  The organizers did a superb job constructing a uniquely valuable event, reflecting the thoughtfulness that&#8217;s present everywhere in the NZ government&#8217;s approach to its citizens&#8217; identity.
I hope to have more time very soon to put together lots more thoughts on the many [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.identityconference.victoria.ac.nz/default.aspx">Managing Identity in New Zealand</a> conference has been an amazing experience.  The organizers did a superb job constructing a uniquely valuable event, reflecting the thoughtfulness that&#8217;s present everywhere in the NZ government&#8217;s approach to its citizens&#8217; identity.</p>
<p>I hope to have more time very soon to put together lots more thoughts on the many talks and conversations, but for now I just wanted to share the slides for the keynote I presented on Tuesday: <a href="http://xmlgrrl.com/publications/Maler-NZIDConf-Apr2008.pdf">The Design of Everyday Identity</a>.</p>
<p>And one additional thought for now: I&#8217;m extremely sympathetic to the views of <a href="http://blogs.law.harvard.edu/vrm/2008/04/28/vrm-is-user-driven/">Doc</a> and <a href="http://www.mediainfluencer.net/2008/04/two-tales-of-user-centricities/">Adriana</a> regarding the oddity of the phrase &#8220;user-centric&#8221;. I&#8217;ve remarked many times on the problems with assuming that <em>people are always online and in front of a user agent</em> (that is, &#8220;users&#8221;), and the very word describes people relative to the systems that are supposed to be helping them, which seems backwards &#8212; especially since the systems don&#8217;t seem to be too inclined to actually help them do what they want to do!</p>
<p>My research for this talk led me back to the classic ideas in <a href="http://jnd.org">Don Norman</a>&#8217;s usability work, where he invoked the phrase &#8220;human-centered design&#8221; starting back in the 80&#8217;s.  I would happily switch to &#8220;human-centered&#8221; from &#8220;user-centric&#8221;, and I suspect it would help us all be more open to the many ways to achieve this goal, particularly if Don Norman&#8217;s cautionary tale is kept in mind.</p>
<p>(As always, you can find my presos and papers and such linked from <a href="http://www.xmlgrrl.com/blog/publications/">my Publications page</a>. See that page if you want a more extensive bibliography for the talk, and keep an eye out for the conference proceedings paper I&#8217;ll be finishing in the next couple of weeks.)</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F04%2F30%2Feveryday-identity-and-human-centered-design%2F';
  addthis_title  = 'Everyday+identity+and+human-centered+design';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/04/30/everyday-identity-and-human-centered-design/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Thoughts on identity services? Submit a paper!</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/04/26/thoughts-on-identity-services-submit-a-paper/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/04/26/thoughts-on-identity-services-submit-a-paper/#comments</comments>
		<pubDate>Sat, 26 Apr 2008 15:33:23 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[XML]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=359</guid>
		<description><![CDATA[It&#8217;s that time again &#8212; we&#8217;re just a month away from the deadline for the ACM Workshop on Digital Identity Management call for papers.
The theme, as always for this series, is timely: &#8220;Services and Identity&#8221;. Might Pat et al. be interested in submitting something on accessing attribute services in SOAP and REST environments?

  addthis_url [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s that time again &#8212; we&#8217;re just a month away from the deadline for the ACM Workshop on Digital Identity Management <a href="http://www2.pflab.ecl.ntt.co.jp/dim2008/">call for papers</a>.</p>
<p>The theme, as always for this series, is timely: &#8220;Services and Identity&#8221;. Might <a href="http://blogs.sun.com/superpat/entry/fetching_user_attributes_with_identity">Pat et al.</a> be interested in submitting something on accessing attribute services in SOAP and REST environments?</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F04%2F26%2Fthoughts-on-identity-services-submit-a-paper%2F';
  addthis_title  = 'Thoughts+on+identity+services%3F+Submit+a+paper%21';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/04/26/thoughts-on-identity-services-submit-a-paper/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Federation in the diminutive</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/04/24/federation-in-the-diminutive/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/04/24/federation-in-the-diminutive/#comments</comments>
		<pubDate>Thu, 24 Apr 2008 23:26:41 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=357</guid>
		<description><![CDATA[The fedlet &#8212; it has arrived!  Actually, it&#8217;s hard to keep things a total surprise when you open-source it all, but Daniel Raskin has finally taken the wraps off the fedlet for real. Check out his video: He demonstrates, during the course of a single Guns &#8216;N&#8217; Roses tune, just how brain-dead easy it [...]]]></description>
			<content:encoded><![CDATA[<p>The fedlet &#8212; it has arrived!  Actually, it&#8217;s hard to keep things a total surprise when you <a href="http://opensso.org">open-source it all</a>, but <a href="http://blogs.sun.com/raskin/">Daniel Raskin</a> has finally <a href="http://blogs.sun.com/raskin/entry/the_fedlet_has_arrived_check">taken the wraps off the fedlet</a> for real. Check out his video: He demonstrates, <em>during the course of a single Guns &#8216;N&#8217; Roses tune</em>, just how brain-dead easy it is to create a fedlet for a SAML2 relying party and get it working correctly on the other side.</p>
<p>As Scott Cantor observed in the recent <a href="http://projectconcordia.org">Project Concordia</a> workshop, we&#8217;re getting to the point where browser-based single sign-on Just Works. Now it&#8217;s going faster, and faster, and faster&#8230; (Hey, don&#8217;t some G&#8217;n'R tunes do that?)</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F04%2F24%2Ffederation-in-the-diminutive%2F';
  addthis_title  = 'Federation+in+the+diminutive';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/04/24/federation-in-the-diminutive/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The whys of igovt</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/04/22/the-whys-of-igovt/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/04/22/the-whys-of-igovt/#comments</comments>
		<pubDate>Wed, 23 Apr 2008 01:22:14 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[Stitching]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=356</guid>
		<description><![CDATA[In keeping with its pragmatic approach to identity, the New Zealand State Services Commission is making its identity services friendlier and more responsive to people&#8217;s real needs. Part of this is a rebranding effort around &#8220;igovt&#8221;.  Good stuff!
I&#8217;ve had the pleasure of working with Colin Wallis, Bill Young, and Danny Mollan of the SSC [...]]]></description>
			<content:encoded><![CDATA[<p>In keeping with its pragmatic approach to identity, the New Zealand State Services Commission is making its identity services friendlier and more responsive to people&#8217;s real needs. Part of this is a <a href="http://blog.e.govt.nz/index.php/2008/04/23/why-igovt/">rebranding effort</a> around &#8220;igovt&#8221;.  Good stuff!</p>
<p>I&#8217;ve had the pleasure of working with Colin Wallis, Bill Young, and Danny Mollan of the SSC on various efforts, such as the recent Project Concordia workshop activity. I&#8217;m really looking forward to the <a href="http://www.identityconference.victoria.ac.nz/">identity conference</a> in Wellington, NZ next week &#8212; not only &#8217;cause I get to experience the locale (though who could resist that??) but also because I&#8217;ll get to meet up with these folks and meet many others I know only as disembodied voices or by reputation.</p>
<p>The only potential downside: I heard today that I might not be able to carry knitting needles onto the plane. I can&#8217;t seem to verify that with an online source; it looks like <a href="http://www.tsa.gov/travelers/airtravel/prohibited/permitted-prohibited-items.shtm">they&#8217;re</a> <a href="http://www.transport.govt.nz/flysmart-frequently-asked-questions-1/">allowed</a>. If anyone can confirm or deny, let me know!  I should probably take heed of this <a href="http://answers.yahoo.com/question/index?qid=20061115162530AA1S6JD">Plan-B advice</a>&#8230;</p>
<p>[UPDATE: Arrgh. Right on my itinerary it says &#8220;In the interest of security and safety we would like to advise customers that sharp items and cutting implements of all types and sizes such as pocket knives, scissors, nail files, corkscrews, letter openers, knitting needles, realistic toy imitation weapons, razor blades etc, must be carried in checked luggage only.&#8221;]</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F04%2F22%2Fthe-whys-of-igovt%2F';
  addthis_title  = 'The+whys+of+igovt';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/04/22/the-whys-of-igovt/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Venn in article form</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/04/22/the-venn-in-article-form/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/04/22/the-venn-in-article-form/#comments</comments>
		<pubDate>Tue, 22 Apr 2008 20:08:55 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=353</guid>
		<description><![CDATA[(BUMPED because the free online copy of the article is now available. Entry originally posted April 10, 2008 @ 10:02 am.)
Drummond Reed and I undertook a fun and productive collaboration over the last few months, co-writing an article on The Venn of Identity for the new special issue of IEEE Security and Privacy magazine (here&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>(BUMPED because the <a href="http://www.xmlgrrl.com/publications/IEEESecPriv-MarApr2008-MalerReed-Venn.pdf">free online copy of the article</a> is now available. Entry originally posted April 10, 2008 @ 10:02 am.)</p>
<p><a href="http://www.equalsdrummond.name/">Drummond Reed</a> and I undertook a fun and productive collaboration over the last few months, co-writing an article on <a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&#038;toc=comp/mags/sp/2008/02/msp02toc.xml&#038;DOI=10.1109/MSP.2008.50">The Venn of Identity</a> for the new <a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&#038;toc=comp/mags/sp/2008/02/msp02toc.xml">special issue</a> of IEEE Security and Privacy magazine (here&#8217;s IEEE S&#038;P <a href="https://newton.computer.org/sssubs.nsf/application?openform&#038;code=sp">subscription info</a>).</p>
<p>The issue as a whole looks to be full of juicy stuff, with a good flow from more general topics (our article is a level-setter) to more specific and technical ones.  Also, don&#8217;t miss the <a href="http://blog.pingidentity.com/blog/ctotalk/2008/03/31/Dynamic-SAML-Article-in-IEEE-Security-Privacy">additional perspective</a> Patrick Harding offers on his &#8220;dynamic SAML&#8221; article.</p>
<p>By special arrangement between Sun and IEEE, I&#8217;m able to make the Venn article available without fee.  I haven&#8217;t gotten a final PDF copy back yet &#8212; the publishers are busy at the RSA conference this week! &#8212; so if you&#8217;re interested to snag it, note that I&#8217;ll update this entry &#8212; as well as my <a href="http://www.xmlgrrl.com/blog/publications/">Publications page</a> &#8212; when I get the file. (Update: <a href="http://www.xmlgrrl.com/publications/IEEESecPriv-MarApr2008-MalerReed-Venn.pdf">Here you go</a>!)</p>
<p>(And one more UPDATE to acknowledge the forebears of the Venn diagram since these wouldn&#8217;t fit in the article: Gary Ellison, Johannes Ernst, and Paul Madsen. More details on this history can be found in my initial <a href="http://www.xmlgrrl.com/blog/archives/2007/03/28/the-venn-of-identity/">post</a> on the subject. Thanks, guys!)</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F04%2F22%2Fthe-venn-in-article-form%2F';
  addthis_title  = 'The+Venn+in+article+form';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/04/22/the-venn-in-article-form/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Project Concordia workshop results</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/04/21/project-concordia-workshop-results/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/04/21/project-concordia-workshop-results/#comments</comments>
		<pubDate>Mon, 21 Apr 2008 23:12:26 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=355</guid>
		<description><![CDATA[It&#8217;s surprising which &#8220;worlds&#8221; can work together given a chance:

(See whole photo essay here)
Paul is onto something with the notion of Project Concordia supporting the formation of creoles where we&#8217;ve been having to make do with pidgin.
It&#8217;s as if the kids, impatient with the limitations of the pidgin, decide to create a real language on [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s surprising which &#8220;worlds&#8221; can work together given a chance:</p>
<p><img width="400" src="http://www.xmlgrrl.com/new-orleans-2001/l0457-kosher-creole.jpg" alt="Creole Kosher Kitchen" /><br />
(See whole photo essay <a href="http://www.xmlgrrl.com/new-orleans-2001/index.htm">here</a>)</p>
<p><a href="http://connectid.blogspot.com/2008/04/creole-cooking.html">Paul is onto something</a> with the notion of <a href="http://projectconcordia.org/index.php/Main_Page">Project Concordia</a> supporting the formation of creoles where we&#8217;ve been having to make do with pidgin.</p>
<blockquote><p>It&#8217;s as if the kids, impatient with the limitations of the pidgin, decide to create a real language on their own.</p></blockquote>
<p>If you were at the recent Concordia workshop, you might have noticed the palpable impatience on the part of deployers there. (If you couldn&#8217;t attend, you can have that special <em>being-there</em> experience by checking out the <a href="http://projectconcordia.org/index.php/Concordia_workshop_RSA_2008_notes">complete workshop notes</a>, which I finally finished typing up last night after returning from my Honolulu Hiatus&#8230;)</p>
<p>We&#8217;ve got a next-steps telecon tomorrow, and if you were thinking about taking part in Concordia discussions, now&#8217;s a great time.  So be <a href="http://www.eyeofhawaii.com/Pidgin/pidgin.htm">akamai</a> and check out the wiki for call info and how to join the email list.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.xmlgrrl.com%2Fblog%2Farchives%2F2008%2F04%2F21%2Fproject-concordia-workshop-results%2F';
  addthis_title  = 'Project+Concordia+workshop+results';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/04/21/project-concordia-workshop-results/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
