<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Pushing String &#187; OAuth</title>
	<atom:link href="http://www.xmlgrrl.com/blog/tag/oauth/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xmlgrrl.com/blog</link>
	<description>Tangled musings on identity, privacy, trust, and suchlike</description>
	<lastBuildDate>Mon, 24 Oct 2011 15:38:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>New: Report contemplating OAuth and &#8220;Zero Trust identity&#8221;</title>
		<link>http://www.xmlgrrl.com/blog/2011/07/15/new-report-contemplating-oauth-and-zero-trust-identity/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/07/15/new-report-contemplating-oauth-and-zero-trust-identity/#comments</comments>
		<pubDate>Fri, 15 Jul 2011 20:49:19 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Forrester]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Forr2Legs]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[OAuth]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2974</guid>
		<description><![CDATA[<p>Is it possible for an enterprise to turn itself inside-out? Apparently so. I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-07-15-in_cloud_friendly_web_services_security_there_is_no_enterprise_wait_what">post</a> up on the Forrester blogs that discusses the &#8220;Zero Trust&#8221; aspect of enterprise security that a number of companies are addressing with various clever uses of OAuth.</p>
]]></description>
			<content:encoded><![CDATA[<p>Is it possible for an enterprise to turn itself inside-out? Apparently so. I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-07-15-in_cloud_friendly_web_services_security_there_is_no_enterprise_wait_what">post</a> up on the Forrester blogs that discusses the &#8220;Zero Trust&#8221; aspect of enterprise security that a number of companies are addressing with various clever uses of OAuth.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/07/15/new-report-contemplating-oauth-and-zero-trust-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New: &#8220;Participating In Markets For Portable Identities In The Cloud: What’s The Coin Of Your Realm?&#8221;</title>
		<link>http://www.xmlgrrl.com/blog/2011/06/10/new-participating-in-markets-for-portable-identities-in-the-cloud-what%e2%80%99s-the-coin-of-your-realm/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/06/10/new-participating-in-markets-for-portable-identities-in-the-cloud-what%e2%80%99s-the-coin-of-your-realm/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 19:17:58 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Forrester]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Venn]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[SAML]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2964</guid>
		<description><![CDATA[<p>I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-06-10-participating_in_markets_for_portable_identities_in_the_cloud_whats_the_coin_of_your_realm">post</a> up on the Forrester blogs, discussing a &#8220;markets for portable identity&#8221; angle on my latest <a href="http://www.forrester.com/rb/Research/venn_of_federated_identity/q/id/59161/t/2">research report</a> (which is full of Venn goodness!), and how SAML, OAuth, and OpenID are &#8220;hard currencies.&#8221;</p>
<p>You could take this theme pretty far. Does SAML-OAuth bridging have any elements of arbitrage about it? Is assurance leakage in protocol translation like the lousy currency exchange rates at those little van kiosks in airports? Maybe that&#8217;s far enough&#8230;</p>
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-06-10-participating_in_markets_for_portable_identities_in_the_cloud_whats_the_coin_of_your_realm">post</a> up on the Forrester blogs, discussing a &#8220;markets for portable identity&#8221; angle on my latest <a href="http://www.forrester.com/rb/Research/venn_of_federated_identity/q/id/59161/t/2">research report</a> (which is full of Venn goodness!), and how SAML, OAuth, and OpenID are &#8220;hard currencies.&#8221;</p>
<p>You could take this theme pretty far. Does SAML-OAuth bridging have any elements of arbitrage about it? Is assurance leakage in protocol translation like the lousy currency exchange rates at those little van kiosks in airports? Maybe that&#8217;s far enough&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/06/10/new-participating-in-markets-for-portable-identities-in-the-cloud-what%e2%80%99s-the-coin-of-your-realm/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New: &#8220;Protecting Internal APIs &#8211; Is OAuth Ready For Its Closeup?&#8221;</title>
		<link>http://www.xmlgrrl.com/blog/2011/05/10/new-protecting-internal-apis-is-oauth-ready-for-its-closeup/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/05/10/new-protecting-internal-apis-is-oauth-ready-for-its-closeup/#comments</comments>
		<pubDate>Tue, 10 May 2011 18:28:47 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Forrester]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Forr2Legs]]></category>
		<category><![CDATA[IIW]]></category>
		<category><![CDATA[IIW12]]></category>
		<category><![CDATA[OAuth]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2957</guid>
		<description><![CDATA[<p>Check out my new <a href="http://blogs.forrester.com/eve_maler/11-05-10-protecting_internal_apis_is_oauth_ready_for_its_closeup">post</a> on the Forrester blog, looking to hear about your experience and opinions on the use of OAuth to secure your internal app landscape. You know you have stories. I know you have stories. So why not share them??</p>
<p>I hosted a session at IIW last week to start collecting data around this topic, impishly/illicitly called <a href="http://iiw.idcommons.net/Two_Legs_Good%3F_“Client-Server”_OAUTH_Usage">Two Legs Good?</a> (since the OAuth community keeps trying to quit the &#8220;legs&#8221; habit but can&#8217;t seem to&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/05/10/new-protecting-internal-apis-is-oauth-ready-for-its-closeup/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Check out my new <a href="http://blogs.forrester.com/eve_maler/11-05-10-protecting_internal_apis_is_oauth_ready_for_its_closeup">post</a> on the Forrester blog, looking to hear about your experience and opinions on the use of OAuth to secure your internal app landscape. You know you have stories. I know you have stories. So why not share them??</p>
<p>I hosted a session at IIW last week to start collecting data around this topic, impishly/illicitly called <a href="http://iiw.idcommons.net/Two_Legs_Good%3F_“Client-Server”_OAUTH_Usage">Two Legs Good?</a> (since the OAuth community keeps trying to quit the &#8220;legs&#8221; habit but can&#8217;t seem to manage it). Session notes are at the link. IIW totally rocked this time; thanks to the organizers and all who contributed to making it great!</p>
<p>In order to encourage you to comment over on the other site, I&#8217;ve turned off comments here (boy, does that feel weird&#8230;). If you prefer to weigh in with 140 characters&#8217; worth of wisdom, just be sure to use the hashtag <a href="http://twitter.com/#%21/search/%23Forr2Legs">#Forr2Legs</a> so I&#8217;ll see it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/05/10/new-protecting-internal-apis-is-oauth-ready-for-its-closeup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How UMA deals with scopes and authorization</title>
		<link>http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/#comments</comments>
		<pubDate>Sun, 01 May 2011 22:58:22 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[IIW]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2938</guid>
		<description><![CDATA[<p>The <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> group has been quite busy of late. Like several other efforts (don&#8217;t miss John Bradley&#8217;s <a href="http://openid.net/2011/04/29/a-map-for-openid-abc/">OpenID ABC</a> post or anything <a href="http://self-issued.info/">Mike Jones</a> has been blogging in the last few months), we&#8217;ve been gearing up for <a href="http://iiw12.eventbrite.com/">IIW 12</a> as a great place to try out our newest work, figure out the combinatorial possibilities with all the other new stuff going on, and get feedback.</p>
<p>Newcastle University&#8217;s <a href="http://smartam.net/">SMART project team</a> will be in Mountain View&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA</a> group has been quite busy of late. Like several other efforts (don&#8217;t miss John Bradley&#8217;s <a href="http://openid.net/2011/04/29/a-map-for-openid-abc/">OpenID ABC</a> post or anything <a href="http://self-issued.info/">Mike Jones</a> has been blogging in the last few months), we&#8217;ve been gearing up for <a href="http://iiw12.eventbrite.com/">IIW 12</a> as a great place to try out our newest work, figure out the combinatorial possibilities with all the other new stuff going on, and get feedback.</p>
<p>Newcastle University&#8217;s <a href="http://smartam.net/">SMART project team</a> will be in Mountain View again, discussing their UMA implementation and UX work. And vice-chair Maciej Machulak and I plan to convene a session to share our draft solution for <strong>loosely coupling</strong> an OAuth authorization server and resource server to solve for <strong>externalized authorization</strong> and <strong>interoperable scoped access</strong> in the UMA context.</p>
<p>Back in February, a bunch of us tried discussing this very subject in Twitter and got pretty far, but it took Paul Madsen to put the whole story together in his blog post <a href="http://connectid.blogspot.com/2011/02/way-more-than-140-and-loving-it.html">Way more than 140. And loving it</a>. Check it out.</p>
<p>Essentially, UMA is choosing to give the host (resource server) more autonomy than it would typically have in a tightly coupled environment, so that it&#8217;s not entirely accurate to say it&#8217;s a mere policy enforcement point (PEP) and the authorization manager (authz server) is a full policy decision point (PDP). This seems to make good sense in a totally open-Web environment. However, &#8220;the full PDP&#8221; is an optional feature we could probably add if there&#8217;s interest.</p>
<p>The really interesting thing is that, to make externalized authorization work, we&#8217;ve had to go &#8220;radically claims-based&#8221;. The model seems very powerful and generative &#8212; it gives the power to upgrade and downgrade granted scopes at will! But it does take a step or two back from pure OAuth 2.0 as a result. This is something I&#8217;m keen to discuss with folks in and around IIW; we&#8217;ll be presenting <a href="http://www.xmlgrrl.com/publications/IIW12-UMA-ScopedAccess-May2011.pdf">these slides</a> to that end.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/05/01/how-uma-deals-with-scopes-and-authorization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New: &#8220;CardSpace Is Dead. Long Live Back-Channel Access.&#8221;</title>
		<link>http://www.xmlgrrl.com/blog/2011/02/24/new-cardspace-is-dead-long-live-back-channel-access/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/02/24/new-cardspace-is-dead-long-live-back-channel-access/#comments</comments>
		<pubDate>Thu, 24 Feb 2011 15:16:06 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[CardSpace]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[InfoCard]]></category>
		<category><![CDATA[OAuth]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2883</guid>
		<description><![CDATA[<p>I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-02-24-cardspace_is_dead_long_live_back_channel_access">post</a> up on my Forrester blog, commenting on CardSpace and the important trends to pay attention to at this juncture.</p>
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve got a new <a href="http://blogs.forrester.com/eve_maler/11-02-24-cardspace_is_dead_long_live_back_channel_access">post</a> up on my Forrester blog, commenting on CardSpace and the important trends to pay attention to at this juncture.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/02/24/new-cardspace-is-dead-long-live-back-channel-access/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New: &#8220;OpenID, Successful Failures And New Federated Identity Options&#8221;</title>
		<link>http://www.xmlgrrl.com/blog/2011/02/03/new-openid-successful-failures-and-new-federated-identity-options/</link>
		<comments>http://www.xmlgrrl.com/blog/2011/02/03/new-openid-successful-failures-and-new-federated-identity-options/#comments</comments>
		<pubDate>Fri, 04 Feb 2011 01:07:19 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Forrester]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Venn]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[SAML]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2858</guid>
		<description><![CDATA[<p>Though there&#8217;s still a creepy fuzzy anonymous head where my picture is supposed to be, I&#8217;ve got my first post up on the Forrester Research Security &#038; Risk blog. It <a href="http://blogs.forrester.com/eve_maler/11-02-03-openid_successful_failures_and_new_federated_identity_options">discusses</a> the recent 37signals decision to stop using OpenID and the larger &#8220;button-based login&#8221; environment in which OpenID can be considered a positive influence. As a bonus, it provides a new Venn diagram comparing features of OpenID + attribute exchange, the SAML web browser SSO profile, and OAuth +&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2011/02/03/new-openid-successful-failures-and-new-federated-identity-options/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Though there&#8217;s still a creepy fuzzy anonymous head where my picture is supposed to be, I&#8217;ve got my first post up on the Forrester Research Security &#038; Risk blog. It <a href="http://blogs.forrester.com/eve_maler/11-02-03-openid_successful_failures_and_new_federated_identity_options">discusses</a> the recent 37signals decision to stop using OpenID and the larger &#8220;button-based login&#8221; environment in which OpenID can be considered a positive influence. As a bonus, it provides a new Venn diagram comparing features of OpenID + attribute exchange, the SAML web browser SSO profile, and OAuth + &#8220;connect&#8221;-style login.</p>
<p><strong>Later:</strong> Neat, it&#8217;s been cross-posted to the <a href="http://blogs.csoonline.com/1373/openid_successful_failures_and_new_federated_identity_options">CSO Online blog</a> as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2011/02/03/new-openid-successful-failures-and-new-federated-identity-options/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Wishing you a happy, healthy, user-managed new year</title>
		<link>http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/#comments</comments>
		<pubDate>Sun, 26 Dec 2010 02:34:18 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[Kantara]]></category>
		<category><![CDATA[leeloo]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[UMA]]></category>
		<category><![CDATA[UMAnitarian]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2772</guid>
		<description><![CDATA[<p><a href="http://kantarainitiative.org/confluence/display/uma/Home"><img src="http://kantarainitiative.org/confluence/download/attachments/17760302/UMA_christmas.jpg" alt="UMA Christmas tree 2010" width="425" /></a></p>
<p>Thanks to <a href="http://identitycube.blogspot.com/">Domenico Catalano</a> (<a href="http://twitter.com/#!/domcat">@DomCat</a>) for putting together this lovely and geeky holiday message! And thanks to all the <a href="http://kantarainitiative.org/confluence/display/uma/Participant+Roster">UMAnitarians</a> for their contributions of passion, business problem-solving, and technical know-how to the User-Managed Access work.</p>
<p>The end of 2010 has brought new progress on several fronts. The UMA-friendly Java-based <a href="http://smartjisc.wordpress.com/2010/09/30/oauth-leeloo-v0-1-released/">OAuth leeloo</a> implementation was released as open source; we&#8217;ve begun solving some hard problems in defining <a href="http://kantarainitiative.org/confluence/display/uma/UMA+Resource+Registration">interoperable interfaces</a> between OAuth authorization servers and resource servers;&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://kantarainitiative.org/confluence/display/uma/Home"><img src="http://kantarainitiative.org/confluence/download/attachments/17760302/UMA_christmas.jpg" alt="UMA Christmas tree 2010" width="425" /></a></p>
<p>Thanks to <a href="http://identitycube.blogspot.com/">Domenico Catalano</a> (<a href="http://twitter.com/#!/domcat">@DomCat</a>) for putting together this lovely and geeky holiday message! And thanks to all the <a href="http://kantarainitiative.org/confluence/display/uma/Participant+Roster">UMAnitarians</a> for their contributions of passion, business problem-solving, and technical know-how to the User-Managed Access work.</p>
<p>The end of 2010 has brought new progress on several fronts. The UMA-friendly Java-based <a href="http://smartjisc.wordpress.com/2010/09/30/oauth-leeloo-v0-1-released/">OAuth leeloo</a> implementation was released as open source; we&#8217;ve begun solving some hard problems in defining <a href="http://kantarainitiative.org/confluence/display/uma/UMA+Resource+Registration">interoperable interfaces</a> between OAuth authorization servers and resource servers; we&#8217;ve been teasing out the implications of <a href="http://kantarainitiative.org/confluence/display/uma/User+Experience#UserExperience-UMATrustedClaims">trusted claims</a> as the basis for user-centric access control; and we saw two significant submissions in response to the UMA validation <a href="http://kantarainitiative.org/confluence/display/uma/UMA+Validator+Bounty+Program">bounty program</a>. We&#8217;re grateful to submitters <a href="http://testingsaas.blogspot.com/">Cordny Nederkoorn</a>, whose interest in UMA grew as a result of his explorations into cloud identity, and <a href="http://www.projecthdata.org/">Project hData</a>, a unique and important effort that seeks to make electronic health data amenable to RESTful web app treatment.</p>
<p>We&#8217;ve got lots more developments in store for the coming months, and we welcome your involvement. From our Kantara <a href="http://kantarainitiative.org/confluence/display/uma/Home">home page</a> you can join the group (no membership fees!), subscribe to our mailing list, and check out the latest news, and don&#8217;t forget to follow us on <a href="http://twitter.com/#!/umawg">Twitter</a>.</p>
<p>Happy holidays!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/12/25/wishing-you-a-happy-healthy-user-managed-new-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Making identity portable in the cloud</title>
		<link>http://www.xmlgrrl.com/blog/2010/09/10/making-identity-portable-in-the-cloud/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/09/10/making-identity-portable-in-the-cloud/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 17:38:54 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[GData]]></category>
		<category><![CDATA[hostmeta]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[MDX]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[OData]]></category>
		<category><![CDATA[OITF]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[SAML]]></category>
		<category><![CDATA[trust framework]]></category>
		<category><![CDATA[UMA]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2604</guid>
		<description><![CDATA[<p>Yesterday I had the opportunity to contribute to BrightTALK&#8217;s day-long <a href="http://www.brighttalk.com/summit/1544">Cloud Security Summit</a> with a webcast called <strong>Making Identity Portable in the Cloud</strong>.</p>
<p>Some 30 live attendees were very patient with my Internet connection problems, meaning that the slides (large <a href="http://xmlgrrl.com/publications/BrightTALK-Maler-PortableID-Sep2010.pdf">PDF</a>) didn&#8217;t advance when they were supposed to and I couldn&#8217;t answer questions live. However the good folks at BrightTALK fixed up the <a href="http://www.brighttalk.com/webcast/22150">recording</a> to match the slides to the audio, and I thought I&#8217;d offer thoughts&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/09/10/making-identity-portable-in-the-cloud/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Yesterday I had the opportunity to contribute to BrightTALK&#8217;s day-long <a href="http://www.brighttalk.com/summit/1544">Cloud Security Summit</a> with a webcast called <strong>Making Identity Portable in the Cloud</strong>.</p>
<p>Some 30 live attendees were very patient with my Internet connection problems, meaning that the slides (large <a href="http://xmlgrrl.com/publications/BrightTALK-Maler-PortableID-Sep2010.pdf">PDF</a>) didn&#8217;t advance when they were supposed to and I couldn&#8217;t answer questions live. However the good folks at BrightTALK fixed up the <a href="http://www.brighttalk.com/webcast/22150">recording</a> to match the slides to the audio, and I thought I&#8217;d offer thoughts here on the questions raised. </p>
<p><strong><em>&#8220;Framework provider &#8211; sounds suspiciously like an old CA (certificate authority) in the PKI world! Why not just call it a PKI legal framework?&#8221;</em></strong> Yeah, there&#8217;s nothing new under the sun.  The circles of trust, federations, and trust frameworks I discussed share a heritage with the way PKIs are managed. But the newer versions have the benefit of lessons learned (compare the <a href="http://www.idmanagement.gov/fpkia/">Federal Bridge</a> and the <a href="http://www.idmanagement.gov/drilldown.cfm?action=openID_openGOV">Open Identity Solutions for Open Government</a> initiative) and are starting to avail themselves of technologies that fit modern Web-scale tooling better (like the <a href="http://lists.iay.org.uk/listinfo.cgi/mdx-iay.org.uk">MDX</a> metadata exchange work, and my new favorite toy, <a href="http://hueniverse.com/2009/11/host-meta-aka-site-meta-and-well-known-uris/">hostmeta</a>). PKI is still quite often part of the picture, just not the whole picture.</p>
<p><strong><em>&#8220;How about a biometric binding of the individual to the process and the requirement of separation of roles?&#8221;</em></strong> I get nervous about biometric authentication for many purposes because it binds to the bag of protoplasm and not the digital identity (and because some of the mechanisms are actually rather <a href="http://www.schneier.com/blog/archives/2008/04/german_minister.html">weak</a>).  If different roles and identities could be separated out appropriately and then mapped, that helps.  But with looser coupling come costs and risks that have to be managed.</p>
<p><strong><em>&#8220;LDAP, AD, bespoke, or a combination?&#8221;</em></strong> Interestingly, this topic was hot at the recent <a href="http://www.cloudidentitysummit.com/">Cloud Identity Summit</a> (a F2F event, unlike the BrightTALK one). My belief is that some of today&#8217;s tiny companies are going to outsource all their corporate functions to SaaS applications; they will thrive on RESTfulness, NoSQL, and eventual consistency; and some will grow large, <em>never having touched traditional directory technology</em>. I suspect this idea is why Microsoft showed up and started talking about what&#8217;s coming after AD and touting <a href="http://www.odata.org/">OData</a> as the answer. (Though in an OData/<a href="http://code.google.com/apis/gdata/">GData</a> deathmatch, I&#8217;d probably bet on the latter&#8230;)</p>
<p>Thanks to all who attended, and keep those cards and letters coming.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/09/10/making-identity-portable-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Where web and enterprise meet on user-managed access</title>
		<link>http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/#comments</comments>
		<pubDate>Sun, 18 Jul 2010 20:10:40 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[ProtectServe]]></category>
		<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[cis2010]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[ID-WSF]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[UMA]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2559</guid>
		<description><![CDATA[<p>Phil Hunt shared some <a href="http://independentidentity.blogspot.com/2010/07/uma-and-oauth-2-first-impressions.html">musings</a> on OAuth and UMA recently. His perspective is valuable, as always. He even coined a neat phrase to capture a key value of UMA&#8217;s authorization manager (AM) role: it&#8217;s a user-centric <strong>consent server</strong>. Here are a couple of thoughts back.</p>
<p>In the enterprise, an externalized <strong>policy decision point</strong> represents classic access management architecture, but in today&#8217;s Web it&#8217;s foreign. UMA combines both worlds with the trick of letting Alice craft her own access authorization&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>Phil Hunt shared some <a href="http://independentidentity.blogspot.com/2010/07/uma-and-oauth-2-first-impressions.html">musings</a> on OAuth and UMA recently. His perspective is valuable, as always. He even coined a neat phrase to capture a key value of UMA&#8217;s authorization manager (AM) role: it&#8217;s a user-centric <strong>consent server</strong>. Here are a couple of thoughts back.</p>
<p>In the enterprise, an externalized <strong>policy decision point</strong> represents classic access management architecture, but in today&#8217;s Web it&#8217;s foreign. UMA combines both worlds with the trick of letting Alice craft her own access authorization policies, at an AM she chooses. She&#8217;s the one likeliest to know which resources of hers are sensitive, which people and services she&#8217;d like to share access with, and what&#8217;s acceptable to do with that access. With a single hub for setting all this up, she can reuse policies across resource servers and get a global view of her entire access landscape. And with an always-on service executing her wishes, in many cases she can even be offline when an access requester comes knocking. In the process, as Phil observes, UMA &#8220;supports a federated (multi-domain) model for user authorization not possible with current enterprise policy systems.&#8221;</p>
<p>Phil wonders about privacy impacts of the AM role given its centrality. In earlier federated identity protocol work, such as Liberty&#8217;s Identity Web Services Framework, it was assumed that enterprise and consumer IdPs could never be the authoritative source of all interesting information about a user, and that we&#8217;d each have a variety of attribute authorities. This is the reality of today&#8217;s web, expanding &#8220;attribute&#8221; to include &#8220;content&#8221; like photos, calendars, and documents. So rather than having an über-IdP attempt to aggregate all Alice&#8217;s stuff into a single personal datastore &#8212; presenting a pretty bad <strong>panoptical identity</strong> problem in addition to other challenges &#8212; an AM can manage access relationships to all that stuff sight unseen. Add the fact that UMA lets Alice set conditions for access rather than just passively agree to others&#8217; terms, and I believe an AM can materially enhance her privacy by giving her meaningful control.</p>
<p>Phil predicts that OAuth and UMA will be useful to the enterprise community, and I absolutely agree. Though the <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA group</a> has taken on an explicitly non-enterprise scope for its initial work, large-enterprise and small-business use cases keep coming up, and cloud computing models keep, uh, fogging up all these distinctions. (Imagine Alice as a software developer who needs to hook up the OAuth-protected APIs of seven or eight SaaS offerings in a complex pattern&#8230;) Next week at the <a href="http://www.cloudidentitysummit.com/program/July21-1035.cfm">Cloud Identity Summit</a> I&#8217;m looking forward to further exploring the consumer-enterprise nexus of federated access authorization.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/07/18/where-web-and-enterprise-meet-on-user-managed-access/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>OpenID and OAuth: As the URL Turns</title>
		<link>http://www.xmlgrrl.com/blog/2010/05/25/openid-and-oauth-as-the-url-turns/</link>
		<comments>http://www.xmlgrrl.com/blog/2010/05/25/openid-and-oauth-as-the-url-turns/#comments</comments>
		<pubDate>Wed, 26 May 2010 05:47:59 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
				<category><![CDATA[Security/identity]]></category>
		<category><![CDATA[IIW]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[UMA]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=2389</guid>
		<description><![CDATA[<p>In Phil Windley&#8217;s initial <a href="http://www.windley.com/archives/2010/05/iiw_wrapup_moving_past_loginsort_of.shtml">IIW wrap-up</a>, he alluded to the soap-opera nature of the OpenID wrangling that went on last week. It&#8217;s an apt description.</p>
<p><center><a href="http://www.soapoperadigest.com/"><img class="alignright" title="soap" src="http://cdn.xmlgrrl.com/blog/wp-content/uploads/2010/05/soap.jpg" alt="soap" width="250" /></a></center></p>
<p>In the spirit of real ones:</p>
<blockquote><p>Margo wanted Parker to get an attorney before making a confession but he insisted on telling the truth anyway. Margo quickly called Jack with the latest development so he and Carly rushed to the station. Jack ordered his son to keep quiet but Parker said he was</p></blockquote><p>&#160;[&#8230;]<br /> <a href="http://www.xmlgrrl.com/blog/2010/05/25/openid-and-oauth-as-the-url-turns/" class="read_more">Read more</a></p>]]></description>
			<content:encoded><![CDATA[<p>In Phil Windley&#8217;s initial <a href="http://www.windley.com/archives/2010/05/iiw_wrapup_moving_past_loginsort_of.shtml">IIW wrap-up</a>, he alluded to the soap-opera nature of the OpenID wrangling that went on last week. It&#8217;s an apt description.</p>
<p><center><a href="http://www.soapoperadigest.com/"><img class="alignright" title="soap" src="http://cdn.xmlgrrl.com/blog/wp-content/uploads/2010/05/soap.jpg" alt="soap" width="250" /></a></center></p>
<p>In the spirit of real ones:</p>
<blockquote><p>Margo wanted Parker to get an attorney before making a confession but he insisted on telling the truth anyway. Margo quickly called Jack with the latest development so he and Carly rushed to the station. Jack ordered his son to keep quiet but Parker said he was going through with his confession. Carly was brokenhearted that Parker couldn&#8217;t be silenced and Margo took Jack off the case. [<a href="http://soapoperadigest.com/recaps/as-the-world-turns/2010/051710/index4.html">ATWT</a>]</p></blockquote>
<p>&#8230;I present the soap-opera synopsis of the goings-on:</p>
<blockquote><p>David showed up at the Mountain View party with <a href="http://openidconnect.com/">OpenID Connect</a>, which had been hanging around with OAuth in a way that seemed <a href="http://paulmadsen.posterous.com/new-line-of-greeting-cards-iiw">promiscuous</a>.  Having <a href="http://self-issued.info/?p=256">insisted</a> last year that it was ready to change, OpenID quickly <a href="http://lists.openid.net/pipermail/openid-specs/2010-May/006869.html">got busy</a>. OpenID Artifact Binding was <a href="http://lists.openid.net/pipermail/openid-specs/2010-May/006831.html">brokenhearted</a> that its quiet yet effective <a href="http://iiw.idcommons.net/OpenID-Artifact_Binding">nature</a> wasn&#8217;t enough to get it noticed. <a href="http://lists.openid.net/pipermail/openid-specs/2010-May/007059.html">UMA</a> and <a href="http://us1.sakimura.org/en/modules/wordpress/essence-of-contract-exchange/">CX</a> couldn&#8217;t help putting in their two cents when they heard what the <a href="http://lists.openid.net/pipermail/openid-specs/2010-May/007023.html">problem</a> was.</p></blockquote>
<p>The OpenID specs list <a href="http://lists.openid.net/pipermail/openid-specs/2010-May/thread.html">discussion</a> is now hopping, and so far it&#8217;s been relatively free of pique and getting more productive as people understand each other&#8217;s use cases and requirements better. Now we just need to come up with a <a href="http://lists.openid.net/pipermail/openid-specs/2010-May/007053.html">list</a> of in-scope ones&#8230;and realize that the best ideas for solving each one could come from anywhere.</p>
<p>So: Can we try and combine the grand vision and breadth of community of the OpenID.next process, the rigor and security of OpenID AB, and the speed and marketing savvy of OpenID Connect &#8212; rather than (ahem) the speed and rigor of the OpenID.next process, the grand vision and marketing savvy of OpenID AB, and the security and breadth of community of OpenID Connect?</p>
<p>UPDATE on 10 July 2010: This post has been translated into <a href="http://pc.de/pages/openid-be">Belorussian</a> by <a href="http://pc.de/">PC</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/2010/05/25/openid-and-oauth-as-the-url-turns/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using apc (Feed is rejected)
Page Caching using apc
Database Caching using apc
Object Caching 1043/1224 objects using apc
Content Delivery Network via Amazon Web Services: CloudFront: cdn.xmlgrrl.com

Served from: www.xmlgrrl.com @ 2012-02-07 10:14:26 -->
