<?xml version="1.0" encoding="utf-8"?><rss version="0.92">
<channel>
	<title>Pushing String</title>
	<link>http://www.xmlgrrl.com/blog</link>
	<description>Tangled musings on identity, privacy, trust, and suchlike</description>
	<lastBuildDate>Mon, 24 Oct 2011 15:38:46 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.2.1" -->

	<item>
		<title>New: Musings on SCIM after IIW</title>
		<description><![CDATA[<p>Over on the Forrester blogs, I <a href="http://forr.com/nxdu7h">talk about</a> the latest progress on Simple Cloud Identity Management (SCIM), as seen and discussed at IIW.</p>
<p>(I&#8217;ll be at <a href="http://www.forrester.com/events/eventdetail/0,9179,2563,00.html">Forrester Security Forum</a> November 9-10, in lovely Miami &#8212; you going?)</p>
]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/10/24/new-musings-on-scim-after-iiw/</link>
			</item>
	<item>
		<title>New: Report contemplating OAuth and &#8220;Zero Trust identity&#8221;</title>
		<description><![CDATA[<p>Is it possible for an enterprise to turn itself inside-out? Apparently so. I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-07-15-in_cloud_friendly_web_services_security_there_is_no_enterprise_wait_what">post</a> up on the Forrester blogs that discusses the &#8220;Zero Trust&#8221; aspect of enterprise security that a number of companies are addressing with various clever uses of OAuth.</p>
]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/07/15/new-report-contemplating-oauth-and-zero-trust-identity/</link>
			</item>
	<item>
		<title>New: &#8220;Participating In Markets For Portable Identities In The Cloud: What’s The Coin Of Your Realm?&#8221;</title>
		<description><![CDATA[<p>I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-06-10-participating_in_markets_for_portable_identities_in_the_cloud_whats_the_coin_of_your_realm">post</a> up on the Forrester blogs, discussing a &#8220;markets for portable identity&#8221; angle on my latest <a href="http://www.forrester.com/rb/Research/venn_of_federated_identity/q/id/59161/t/2">research report</a> (which is full of Venn goodness!), and how SAML, OAuth, and OpenID are &#8220;hard currencies.&#8221;</p>
<p>You could take this theme pretty far. Does SAML-OAuth bridging have any elements of arbitrage about it? Is assurance leakage in protocol translation like the lousy currency exchange rates at those little van kiosks in airports? Maybe that&#8217;s far enough&#8230;</p>
]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/06/10/new-participating-in-markets-for-portable-identities-in-the-cloud-what%e2%80%99s-the-coin-of-your-realm/</link>
			</item>
	<item>
		<title>New: &#8220;Protecting Internal APIs &#8211; Is OAuth Ready For Its Closeup?&#8221;</title>
		<description><![CDATA[<p>Check out my new <a href="http://blogs.forrester.com/eve_maler/11-05-10-protecting_internal_apis_is_oauth_ready_for_its_closeup">post</a> on the Forrester blog, looking to hear about your experience and opinions on the use of OAuth to secure your internal app landscape. You know you have stories. I know you have stories. So why not share them??</p>
<p>I hosted a session at IIW last week to start collecting data around this topic, impishly/illicitly called <a href="http://iiw.idcommons.net/Two_Legs_Good%3F_“Client-Server”_OAUTH_Usage">Two Legs Good?</a> (since the OAuth community keeps trying to quit the &#8220;legs&#8221; habit but can&#8217;t seem to&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/05/10/new-protecting-internal-apis-is-oauth-ready-for-its-closeup/" class="read_more">Read more</a></p>]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/05/10/new-protecting-internal-apis-is-oauth-ready-for-its-closeup/</link>
			</item>
	<item>
		<title>How UMA deals with scopes and authorization</title>
		<description><![CDATA[<p>The <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> group has been quite busy of late. Like several other efforts (don&#8217;t miss John Bradley&#8217;s <a href="http://openid.net/2011/04/29/a-map-for-openid-abc/">OpenID ABC</a> post or anything <a href="http://self-issued.info/">Mike Jones</a> has been blogging in the last few months), we&#8217;ve been gearing up for <a href="http://iiw12.eventbrite.com/">IIW 12</a> as a great place to try out our newest work, figure out the combinatorial possibilities with all the other new stuff going on, and get feedback.</p>
<p>Newcastle University&#8217;s <a href="http://smartam.net/">SMART project team</a> will be in Mountain View&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/" class="read_more">Read more</a></p>]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/</link>
			</item>
	<item>
		<title>New: &#8220;Identity Assurance Means Never Having To Say &#8216;Who Are You, Again?&#8217;&#8221;</title>
		<description><![CDATA[<p>Does having published my first Forrester research report and done my first quarterly teleconference mean I&#8217;ve made my analyst bones? Hmm. You can read about my identity assurance coverage <a href="http://blogs.forrester.com/eve_maler/11-03-29-identity_assurance_means_never_having_to_say_who_are_you_again">here</a>. (Regular readers may recall that I wrote about identity assurance on Pushing String last <a href="http://www.xmlgrrl.com/blog/2009/12/31/how-to-rest-assured/">fall</a>, batting around ideas with <a href="http://connectid.blogspot.com/2010/01/taxonomy-of-federated-applications.html">Paul Madsen</a> and others.)</p>
]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/03/29/new-identity-assurance-means-never-having-to-say-who-are-you-again/</link>
			</item>
	<item>
		<title>Baseline health and Paleo 2.0</title>
		<description><![CDATA[<p>With Gary Taubes blogging and the extended low-carb/paleo community hopping, I feel less of that ol&#8217; carbgrrl blogging pull, but I follow all the goings-on with keen interest.</p>
<p>One recent post over on <a href="http://high-fat-nutrition.blogspot.com/2011/03/fasting-insulin-and-weight-loss.html">Hyperlipid</a> analyzes fasting insulin and &#8212; get this &#8212; accidental weight loss among the obese. Here are some excerpts that may be mind-blowing to the nutritionally uninitiated:</p>
<blockquote><p>[O]ut of only five subjects, one obese person became a food refusenick. Various studies have had similar compliance problems,</p></blockquote><p>&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/03/27/baseline-health-and-paleo-2-0/" class="read_more">Read more</a></p>]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/03/27/baseline-health-and-paleo-2-0/</link>
			</item>
	<item>
		<title>New: &#8220;CardSpace Is Dead. Long Live Back-Channel Access.&#8221;</title>
		<description><![CDATA[<p>I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-02-24-cardspace_is_dead_long_live_back_channel_access">post</a> up on my Forrester blog, commenting on CardSpace and the important trends to pay attention to at this juncture.</p>
]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/02/24/new-cardspace-is-dead-long-live-back-channel-access/</link>
			</item>
	<item>
		<title>The most productive thing possible</title>
		<description><![CDATA[<p>With a schedule that&#8217;s suddenly become insane, I keep thinking about this poster I found a few years ago. Kidding &#8212; or serious?</p>
<p><a href="http://cdn.xmlgrrl.com/blog/wp-content/uploads/2011/02/Sign_07Feb05.jpg"><img src="http://cdn.xmlgrrl.com/blog/wp-content/uploads/2011/02/Sign_07Feb05.jpg" alt="" title="Sign_07Feb05" width="400" class="aligncenter size-full wp-image-2871" /></a></p>
<p>I know. Maybe <a href="http://www.xmlgrrl.com/blog/2006/04/11/power-lunch-with-fluffy/">Kitty&#8217;s datebook</a> could help!</p>
]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/02/08/the-most-productive-thing-possible/</link>
			</item>
	<item>
		<title>New: &#8220;OpenID, Successful Failures And New Federated Identity Options&#8221;</title>
		<description><![CDATA[<p>Though there&#8217;s still a creepy fuzzy anonymous head where my picture is supposed to be, I&#8217;ve got my first post up on the Forrester Research Security &#038; Risk blog. It <a href="http://blogs.forrester.com/eve_maler/11-02-03-openid_successful_failures_and_new_federated_identity_options">discusses</a> the recent 37signals decision to stop using OpenID and the larger &#8220;button-based login&#8221; environment in which OpenID can be considered a positive influence. As a bonus, it provides a new Venn diagram comparing features of OpenID + attribute exchange, the SAML web browser SSO profile, and OAuth +&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/02/03/new-openid-successful-failures-and-new-federated-identity-options/" class="read_more">Read more</a></p>]]></description>
		<link>http://www.xmlgrrl.com/blog/2011/02/03/new-openid-successful-failures-and-new-federated-identity-options/</link>
			</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using apc (Feed is rejected)
Page Caching using apc
Database Caching using apc
Object Caching 486/599 objects using apc
Content Delivery Network via Amazon Web Services: CloudFront: cdn.xmlgrrl.com

Served from: www.xmlgrrl.com @ 2012-02-07 10:03:14 -->
