<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Pushing String</title>
	<atom:link href="http://www.xmlgrrl.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xmlgrrl.com/blog</link>
	<description>XML, identity, crafting, and other tangled musings</description>
	<pubDate>Mon, 05 Jan 2009 21:52:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Experience is what you get&#8230;</title>
		<link>http://www.xmlgrrl.com/blog/archives/2009/01/05/experience-is-what-you-get/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2009/01/05/experience-is-what-you-get/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 21:52:41 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[seattle]]></category>

		<category><![CDATA[snow]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=432</guid>
		<description><![CDATA[&#8230;when you didn&#8217;t get what you wanted.

Eli and I went to a potluck dinner in Seattle last night, hosted by Kaliya and also attended by, among others, Drummond and Gabe. That was the good part &#8212; a great time was had by all, and Kaliya was a gracious host not only during the dinner party, [...]]]></description>
			<content:encoded><![CDATA[<p>&#8230;when you didn&#8217;t get what you wanted.</p>

<p>Eli and I went to a potluck dinner in Seattle last night, hosted by <a href="http://www.identitywoman.net/">Kaliya</a> and also attended by, among others, <a href="http://www.equalsdrummond.name/">Drummond</a> and <a href="http://blog.wachob.com/">Gabe</a>. That was the good part &#8212; a great time was had by all, and Kaliya was a gracious host not only during the dinner party, but also when we showed up on her doorstep <em>twice</em> (evening and morning) after failed departure attempts.</p>

<p>Here are some of the many lessons we learned in the last handful of hours:</p>

<ul>
	<li>By all rights, Seattle <em>should</em> be <a href="http://seattlepi.nwsource.com/local/392623_snowphobic18.html">paralyzed by chance of snow</a>.</li>

	<li>It&#8217;s called Capitol Hill for a reason.</li>

	<li>Real snow extraction devices are better, but square Tupperware works pretty well as a shovel.</li>
</ul>

<p>With luck, we&#8217;ll be able to extract our car later today. I didn&#8217;t have the heart to take pictures, but if you want to see dramatic images of the white stuff further north, <a href="http://www.tbray.org/ongoing/When/200x/2009/01/04/Snow-Bitching">try</a> <a href="http://www.penmachine.com/2009/01/vancouvers-blizzards-have-rendered-my">these</a>.</p>

<p>And to think we moved from Boston to Seattle exactly four years ago yesterday for some snow relief. :-)</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2009/01/05/experience-is-what-you-get/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Where should data live? (part two)</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/12/04/where-should-data-live-part-two/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/12/04/where-should-data-live-part-two/#comments</comments>
		<pubDate>Fri, 05 Dec 2008 02:00:22 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=402</guid>
		<description><![CDATA[Yesterday I said &#8220;you might have reasons for choosing different hosts for information that has different levels of sensitivity [or] needs for high-availability access&#8221;. Today I happened to run across a company that makes a business out of this:

The DocuBank Emergency Card provides immediate access to your healthcare directives, any time, anywhere they are needed.

DocuBank [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday I <a href="http://www.xmlgrrl.com/blog/archives/2008/12/03/where-should-data-live/">said</a> &#8220;you might have reasons for choosing different hosts for information that has different levels of sensitivity [or] needs for high-availability access&#8221;. Today I happened to run across a company that makes a <a href="http://www.docubank.com/">business</a> out of this:</p>

<blockquote>The DocuBank Emergency Card provides immediate access to your healthcare directives, any time, anywhere they are needed.

DocuBank provides access to the following critical documents: Living Will, Health Care Power of Attorney, <span class="caps">HIPAA </span>release, organ donation form, hospital visitation forms, burial instructions and more. DocuBank makes your healthcare directives work.</blockquote>

<p>They give you a card for your wallet that acts as the &#8220;discovery service&#8221; to get to the documents, and you need to have authorization to see them: either they&#8217;re about you, or you&#8217;re a healthcare provider who has specially registered to get access to this type of information.</p>

<p>Poking around online, I also just learned about the <a href="http://www.doh.wa.gov/livingwill/">Washington State Living Will Registry</a>, which seems to function much the same except that it&#8217;s run by the state.</p>

<p>I&#8217;m glad there&#8217;s a choice of providers for healthcare directives in break-glass scenarios &#8212; and I&#8217;m also glad I don&#8217;t have to host such information myself on the computer under my desk. After all, I could never offer myself a service-level agreement that I&#8217;d find acceptable&#8230;</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/12/04/where-should-data-live-part-two/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Where should data live?</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/12/03/where-should-data-live/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/12/03/where-should-data-live/#comments</comments>
		<pubDate>Thu, 04 Dec 2008 00:36:28 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[social networking]]></category>

		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=401</guid>
		<description><![CDATA[George Fletcher provides interesting commentary on a good social-web discussion by Om Malik. The issue: Whether aggregation and federation of data are opposite, or complementary.

George says:

[F]or aggregation to work in the &#8220;open web&#8221;, it must be able to access my data whereever I&#8217;ve chosen to place it.

I agree. If we&#8217;re looking to empower people, it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>George Fletcher provides interesting <a href="http://practicalid.blogspot.com/2008/12/is-it-really-aggregation-vs-federation.html">commentary</a> on a good social-web <a href="http://gigaom.com/2008/11/30/social-webs-big-question-federate-or-aggregate/">discussion</a> by Om Malik. The issue: Whether aggregation and federation of data are opposite, or complementary.</p>

<p>George says:</p>

<blockquote>[F]or aggregation to work in the &#8220;open web&#8221;, it must be able to access my data whereever I&#8217;ve chosen to place it.</blockquote>

<p>I agree. If we&#8217;re looking to empower people, it&#8217;s not realistic to insist that all their information live in a single place.  Just as inventing a new identifier type isn&#8217;t sufficient to eliminate all the various identifiers we already have in our lives &#8212; there are good reasons, not just legacy reasons, to have more than one &#8212; solving the problem of storing everything in one place isn&#8217;t sufficient to eliminate all the places information about us is stored. Here are two non-legacy reasons.</p>

<p>First, you should be able to choose (as George says) where to store information you created, and you might have reasons for choosing different hosts for information that has different levels of sensitivity, needs for high-availability access, needs for fine-grained access control specific to certain data types, etc.  There needs to be an option not just to import/export everything en masse from one competing hosting environment to another, but also to tolerate multiple sources of data at once. It almost feels anti-web to prefer an architecture that requires everything to live together on one server.</p>

<p>Second, it doesn&#8217;t make sense to throw information about you for which you&#8217;re <em>not</em> authoritative (like your credit score, or really any reputation data) into one aggregation pile; you can&#8217;t control the value, but it&#8217;s still &#8220;yours&#8221; in lots of other senses.  You might have the right to track who sees it, but a live copy shouldn&#8217;t reside in your one big database where you have write access. (I liked Gerry Gebel&#8217;s <a href="http://identityblog.burtongroup.com/bgidps/2008/10/can-application.html">insight</a> around this: Try to think of any application that relies on data from elsewhere to be <em>stateless</em> with respect to it. Another way to think about it is that you want to achieve a sort of &#8220;first normal form&#8221;, where information properly lives wherever its authoritative source chooses it to live.)</p>

<p>George notes that if you can authorize a relying party to get the data from whatever your preferred source is, you can get the best of both worlds. It&#8217;s aggregating some parts of data provisioning, usage, and auditing, but not the actual residence of the data.</p>

<p>I&#8217;ve become convinced that multi-sourced data access is a requirement for the core <a href="http://www.xmlgrrl.com/blog/archives/2008/09/04/venn-and-the-art-of-data-sharing/">permissioned data sharing</a> issue that&#8217;s common to identity, <span class="caps">VRM, </span>and social networking use cases.</p>

<p>I happened to do a webcast yesterday that describes the <span class="caps">VRM </span>proposition &#8212; you can watch the <a href="http://www.brighttalk.com/webcasts/1704/attend">recording</a> if you register for a free account &#8212; and I went into a bit of detail about the technical requirements I see, along with reviewing some of the architectures at our disposal for achieving them. (The good news is, there are already several&#8230;) [UPDATE: Slides are now available <a href="http://www.xmlgrrl.com/blog/publications/#vrm-bt-dec08">here</a>.] I think I need to start adding this requirement to my list.</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/12/03/where-should-data-live/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Overdue SAML-related news roundup</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/11/12/overdue-saml-related-news-roundup/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/11/12/overdue-saml-related-news-roundup/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 20:31:47 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=400</guid>
		<description><![CDATA[I haven&#8217;t done one of these roundups in a while.  Here&#8217;s the wild thing: The juiciest source of SAML-related news these days is Don Schmidt&#8217;s blog!

Here are some tidbits I&#8217;ve been collecting since I came back from vacation:


	OpenSSO Enterprise 8.0 released &#8212; it covers lots of protocols, and even supports circles of trust that [...]]]></description>
			<content:encoded><![CDATA[<p>I haven&#8217;t done one of these roundups in a while.  Here&#8217;s the wild thing: The juiciest source of <span class="caps">SAML</span>-related news these days is <a href="http://identity-des.com/">Don Schmidt</a>&#8217;s blog!</p>

<p>Here are some tidbits I&#8217;ve been collecting since I came back from vacation:</p>

<ul>
	<li><p><a href="http://blogs.sun.com/superpat/entry/opensso_enterprise_8_0_released">OpenSSO Enterprise 8.0</a> released &#8212; it covers lots of protocols, and even supports circles of trust that mix federation protocols, but this is <span class="caps">SAML</span>-related by virtue of OpenSSO&#8217;s uniquely <em>solid</em> row of <span class="caps">SAML2 </span><a href="http://www.projectliberty.org/liberty/liberty_interoperable/implementations/saml_2_0_test_procedure_v3_0_full_matrix_implementation_table_q407">interop certifications</a>&#8230;</p></li>

	<li><p>Great progress on <a href="http://identity-des.com/2008/10/28/harmonized-federation-metadata-for-ws-federation-and-saml/">leveraging</a> the <span class="caps">SAML2 </span>metadata format in WS-Federation</p></li>

	<li><p>Microsoft&#8217;s announcement of the Geneva server and its <a href="http://identity-des.com/2008/10/28/microsoft-geneva-server-supports-saml-20/">planned <span class="caps">SAML2 </span>support</a> (<a href="http://identity-des.com/2008/11/02/geneva-saml-interop-with-a-lot-of-help-from-our-friends/">further details</a>)</p></li>
</ul>

<p>I first met Don in early 2005, as part of a joint team of Microsoft and Sun folks working on early forms of single sign-on interop (Pat&#8217;s old post <a href="http://blogs.sun.com/superpat/entry/sun_microsoft_press_conference">here</a>, photographic evidence of the Pat and Don show <a href="http://www.xmlgrrl.com/blog/archives/2005/07/06/separated-at-birth/">here</a>). This partnership has deepened over the years in service of our many mutual customers, and Don is a delight to work with. Congrats to him and the Geneva team on taking these steps, and I look forward to continuing our joint interop work.</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/11/12/overdue-saml-related-news-roundup/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What happens in Vegas</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/11/03/what-happens-in-vegas/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/11/03/what-happens-in-vegas/#comments</comments>
		<pubDate>Tue, 04 Nov 2008 06:47:29 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[las vegas]]></category>

		<category><![CDATA[microsoft surface]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[video games]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=399</guid>
		<description><![CDATA[&#8230;could end up anywhere.

On vacation last week in Sin City, I got an offer someone thought I couldn&#8217;t refuse, and was put under surveillance in an interestingly creepy way.

For custom service, you have to pay &#8212; in money, attention, or personal data. The Wynn hotel-casino (which is gorgeous, but has such a useless website that [...]]]></description>
			<content:encoded><![CDATA[<p>&#8230;could end up anywhere.</p>

<p>On vacation last week in Sin City, I got an offer someone thought I couldn&#8217;t refuse, and was put under surveillance in an interestingly creepy way.</p>

<p>For custom service, you have to pay &#8212; in money, attention, or personal data. The Wynn hotel-casino (which is gorgeous, but has such a useless website that I&#8217;m not linking it) desperately wanted me to sign up for its Red Card loyalty club. Here&#8217;s the deal: <em>If</em> I sign up for the card by showing them a valid government ID and giving them my full name, Social Security Number, date of birth, mailing address, email address, <em>and</em> cell phone number, they will give me a buffet meal <em>for free</em>.  This is all listed right on the rather large offer card, and there&#8217;s nothing about privacy policies on there either. The Wynn buffet is a treat, but I&#8217;d rather give them mere dollars for that, thanks. (One person in my traveling party &#8212; a frequent gambler, something I&#8217;m not &#8212; did go for the deal.)</p>

<p>And if you want to be a bit of a coquette in the twenty-first century, apparently you have to be put under close and possibly recorded observation without any notice given or consent obtained whatsoever. Hey, I&#8217;ve watched <span class="caps">CSI </span>&#8211; I realize that in Las Vegas you aren&#8217;t safe from security cameras anywhere except the bathrooms. But then I sat down at the <a href="http://www.microsoft.com/Presspass/press/2008/jun08/06-11HETSurfacePR.mspx">iBar in the Rio</a> and started futzing around with the <a href="http://www.youtube.com/watch?v=CZrr7AZ9nCY">Big-Ass T</a>&#8230;uh, I mean the <a href="http://www.microsoft.com/surface/index.html">Microsoft Surface</a>. At first I didn&#8217;t realize other private citizens could observe me closely from their <span class="caps">B.A.T.&#8217;</span>s elsewhere in the bar. It&#8217;s supposed to be for flirting:</p>

<blockquote>Flirt Vegas style by adding a hip ultra-lounge vibe to the flirting experience. This application allows guests to create an exciting new way to chat and meet people from one Surface to another. Strategically placed video cameras at each Surface add even more energy to the action, allowing guests to interact with old friends, flirt with new acquaintances, and take and send photos across the lounge.</blockquote>

<p>Luckily, this also meant I could observe the action at other <span class="caps">B.A.T.&#8217;</span>s myself, which was useful when I couldn&#8217;t figure out how to find the Virtual Earth app and caught the camera&#8217;s-eye view of the people at the next table using it. Well, honestly I could have just looked over to see that, but using the spy-eye gave me such a sense of power. :)</p>

<p>Eli and I did play a few games of virtual bowling, which was fun in a flashback-y sort of way. It reminded me of one of the bars my first band Sleeper played regularly in &#8216;80-&#8217;81 &#8212; the long-lost <a href="http://www.hawaiistories.com/archives/004969.shtml">23rd Step in Kailua</a>. They had a game table where you could sit across from someone and play <a href="http://en.wikipedia.org/wiki/Galaxian">Galaxian</a>. It was just offstage next to my keyboard setup, and I would lunge for it whenever we finished a set, about the time the other band members were lunging for the next-door 7-Eleven if it was before midnight and beer could still be legally bought. Ah, good times.</p>

<p>(In case anyone else who loves those old games goes to Vegas, check out the dim corners of the Gameworks on the south Strip, where you&#8217;ll find Space Invaders, Centipede, and &#8212; yes &#8212; Moon Patrol.)</p>

<p>Um. And with that, I think I&#8217;ve proven once again that I&#8217;m the queen of <span class="caps">TMI </span>(why does that acronym spring to mind every time I bring up <a href="http://www.xmlgrrl.com/blog/archives/2008/03/05/you-kids-get-off-my-lawn/">video games</a> here?).</p>

<p>Exit question: Are privacy policies positively pointless for someone who just spews random data about themselves on a public website anyway?</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/11/03/what-happens-in-vegas/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Close encounters of the third kind</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/10/18/close-encounters-of-the-third-kind/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/10/18/close-encounters-of-the-third-kind/#comments</comments>
		<pubDate>Sat, 18 Oct 2008 17:11:01 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=398</guid>
		<description><![CDATA[There are three obvious patterns for how humans and identity-enabled apps can interact.

The first pattern is human-initiated. This is when you reach out to an app &#8212; say, visiting a browser bookmark for Dopplr &#8212; in order to use it in real-time. These days, often you log in somewhere else (at some identity &#8220;provider&#8221;) so [...]]]></description>
			<content:encoded><![CDATA[<p>There are three obvious patterns for how humans and identity-enabled apps can interact.</p>

<p>The first pattern is <strong>human-initiated</strong>. This is when you <em>reach out to an app</em> &#8212; say, visiting a browser bookmark for Dopplr &#8212; in order to use it in real-time. These days, often you log in somewhere else (at some identity &#8220;provider&#8221;) so that the app you want to use can &#8220;consume&#8221; information about you to do the job you want. Think single sign-on and login-time transfer of data about you.</p>

<p>The second pattern is <strong>app-to-app</strong>. This is when an app, having been previously introduced to other apps that are sources of info about you, talks <em>to</em> them <em>about</em> you on your behalf, even if you&#8217;re not around &#8212; like when FireEagle and Dopplr share your location info. But it&#8217;s done in a way that&#8217;s privacy-enhanced and sensitive to your preferences. <a href="http://oauth.net/">OAuth</a> has been great for demonstrating why this is valuable, and of course it&#8217;s the central point of <a href="http://www.projectliberty.org/liberty/content/download/4120/27687/file/idwsf-intro-v1.0.pdf">Liberty Identity Web Services</a> too. (Check out Paul Madsen&#8217;s <a href="http://connectid.blogspot.com/2008/10/comparing-oauth-id-wsf-authz-models.html">helpful</a> <a href="http://connectid.blogspot.com/2008/10/another-angle-on-oauth-id-wsf.html">series</a> comparing OAuth and ID-WSF.)</p>

<p>I&#8217;m thinking it&#8217;s time for the pattern of the third kind to get more attention: <strong>app-initiated</strong>. This is when an app needs your attention and reaches out to <em>you</em> to get consent, or data, or an acknowledgment of receipt. Today in the wild, we see lots of notices sent through email and <span class="caps">SMS </span>(package tracking, flight cancellations), but don&#8217;t have a good way to set up our preferences for the way apps <em>request action</em> on our part. The <a href="http://www.projectliberty.org/liberty/content/download/885/6231/file/liberty-idwsf-interaction-svc-v2.0.pdf">Liberty Interaction Service</a> could be a part of the solution.</p>

<p>This third pattern seems absolutely key for managing privacy robustly, assuming you&#8217;re properly auditing the app-to-human contact and its results. Here are some of the scenarios that have come up recently.</p>

<p><strong>Emergency contacts:</strong> When you travel internationally or sign up to get treatment from a doctor or surgeon, you usually have to provide an emergency contact. It would be better to do this by telling apps <em>how to look up</em> how to contact the person in question, rather than giving phone numbers or email addresses that can go stale or be inappropriate (too synchronous or asynchronous, or too unlikely to elicit a response) for a particular purpose. This would also be useful for a variety of delegation-type tasks, like indicating who&#8217;s willing to sign for packages while you&#8217;re away &#8212; especially in conjunction with the <a href="http://www.projectliberty.org/liberty/resource_center/faq/people_service__1">Liberty People Service</a>.</p>

<p><strong>Integrating identity selectors:</strong> This was suggested by <a href="http://eternaloptimist.wordpress.com/">Pamela Dingle</a> (in response to my <a href="http://www.xmlgrrl.com/blog/publications/#catalyst08">critique</a> of &#8220;classic&#8221; identity selector behavior at Burton Catalyst). Provision your Interaction Service to know how to fire up your identity selector when you&#8217;re online, so apps could use it to initiate contact with you to gather consent and get new claims.  Cool idea, and maybe worth exploring a profile someday; I ended up mentioning it at a meeting of <a href="http://wiki.projectliberty.org/index.php/SIG-WSH_Aug_08_Redmond_F2F#Lower-priority">the Web Services Harmonization <span class="caps">SIG</span></a> we we wouldn&#8217;t lose it.</p>

<p><strong>Health research:</strong> Gather consent when new uses of previously collected data arise (aggregating study data in a privacy-sensitive way), and gather more data over time for longitudinal studies. This idea came up at the <a href="http://projectvrm.org">Project <span class="caps">VRM</span></a> workshop in Boston, and it&#8217;s useful for not just health research but pretty much all <span class="caps">VRM</span>-enabled data-sharing scenarios &#8212; it can increase an app&#8217;s ability to gather less data on initial contact (the fewer required fields, the better!), and thus a human&#8217;s comfort level with choosing this vendor.</p>

<p>I get the idea that a lot of my Liberty colleagues haven&#8217;t gotten excited about the potential of the Interaction Service the way I do. Am I nuts? Am I missing other juicy use cases? What would it take to get something like this working in a standard way with things like OAuth?</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/10/18/close-encounters-of-the-third-kind/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Conference goings-on</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/10/01/conference-goings-on/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/10/01/conference-goings-on/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 17:48:00 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Language]]></category>

		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[conference VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=397</guid>
		<description><![CDATA[A roundup of some upcoming meetings and conferences on which I&#8217;ve got my eye, and/or on whose program committee I serve, and/or at which I will appear.  (This preposition-first business is nonsense up with which I have just put&#8230;)


	4th ACM Workshop on Digital Identity Management: This workshop will be held October 31 (pack your [...]]]></description>
			<content:encoded><![CDATA[<p>A roundup of some upcoming meetings and conferences on which I&#8217;ve got my eye, and/or on whose program committee I serve, and/or at which I will appear.  (This <a href="http://www.wsu.edu/~brians/errors/churchill.html">preposition-first business</a> is nonsense up with which I have just put&#8230;)</p>

<ul>
	<li><p><strong>4th <span class="caps">ACM</span> Workshop on Digital Identity Management:</strong> This workshop will be held October 31 (pack your Halloween costume&#8230;) in Fairfax, <span class="caps">VA. </span> Early-bird <a href="http://www.regonline.com/Checkin.asp?EventId=644132">registration</a> ends October 10. You can register for just the workshop if you can&#8217;t attend the <a href="http://www.sigsac.org/ccs/CCS2008/"><span class="caps">ACM CCS2008</span></a> conference with which it&#8217;s colocated.  The <a href="http://www2.pflab.ecl.ntt.co.jp/dim2008">program</a> this year looks really interesting; the theme is &#8220;services and identity&#8221;.</p><p></p></li>


	<li><p><strong>Identity Forum 2008:</strong> I&#8217;m a late addition to the <a href="http://www.identityforum.nl/">program</a> of this conference, speaking on <a href="http://projectconcordia.org">Project Concordia</a> on October 7 in Rotterdam. Should be a great trip. If you&#8217;re planning to be there, I hope you&#8217;ll say hi.</p></li>


	<li><p><strong>Project <span class="caps">VRM</span> Standards Committee:</strong> This group is holding its first proper <a href="http://cyber.law.harvard.edu/lists/arc/projectvrm/2008-10/msg00000.html">face-to-face meeting</a> and coding camp on October 15-16 in Cambridge, <span class="caps">MA.  </span>(I can&#8217;t attend but will be calling in.) <span class="caps">RSVP </span>to <a href="mailto:joe@switchbook.com">Joe Andrieu</a>.  (I have in the past described this group&#8217;s telecon series as &#8220;like crack&#8221; &#8212; if you&#8217;re addicted to rapid-fire idea generation and lots of &#8220;ooh, now I grok it&#8221; moments.)</p></li>


	<li><p><strong>Net-ID 2009:</strong> This conference on identity, trust, privacy, and security is being held February 16-17 in Berlin, and the <a href="http://www.computas.de/html/net-id09.html">Call for Papers</a> is now open.</p></li>
</ul>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/10/01/conference-goings-on/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Almost showtime for OpenSSO and the IdentiCat</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/09/26/almost-showtime-for-opensso-and-the-identicat/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/09/26/almost-showtime-for-opensso-and-the-identicat/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 20:03:48 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=396</guid>
		<description><![CDATA[In keeping with Daniel Raskin&#8217;s &#8212; what did he call it? his Barnum and Bailey style, I believe &#8212; he&#8217;ll be stalking a mythical creature, the IdentiCat, during the unveiling of OpenSSO Enterprise 8.  You won&#8217;t want to miss the show, to be held in Second Life next Tuesday, September 30.  It&#8217;s not [...]]]></description>
			<content:encoded><![CDATA[<p>In keeping with <a href="http://blogs.sun.com/raskin/">Daniel Raskin&#8217;s</a> &#8212; what did he call it? his Barnum and Bailey style, I believe &#8212; he&#8217;ll be stalking a mythical creature, the <a href="http://blogs.sun.com/raskin/entry/meet_mr_winky_the_identicat">IdentiCat</a>, during the unveiling of OpenSSO Enterprise 8.  You won&#8217;t want to miss the show, to be held in Second Life next Tuesday, <strong>September 30</strong>.  It&#8217;s not too late to <a href="https://www2.sun.de/dct/forms/reg_us_0409_733_0.jsp">sign up</a>!</p>

<p>(Has Mr. Winky the IdentiCat met <a href="http://www.mrwinkle.com/diary6pflow-2001.htm">Mr. Winkle</a> the dog?)</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/09/26/almost-showtime-for-opensso-and-the-identicat/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Venn and the art of data-sharing</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/09/04/venn-and-the-art-of-data-sharing/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/09/04/venn-and-the-art-of-data-sharing/#comments</comments>
		<pubDate>Thu, 04 Sep 2008 17:24:53 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[Security/identity]]></category>

		<category><![CDATA[Gnomedex]]></category>

		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=393</guid>
		<description><![CDATA[I come to the VRM world from a tradition (if that&#8217;s the right word) of digital identity management. With so many organizational efforts swirling around trying to create identity layers, data portability, metasystems, and suchlike, I kept noticing that there was a common set of bedrock features involving human beings and the networked apps they [...]]]></description>
			<content:encoded><![CDATA[<p>I come to the <a href="http://projectvrm.org"><span class="caps">VRM</span></a> world from a tradition (if that&#8217;s the right word) of digital identity management. With so many organizational efforts swirling around trying to create identity layers, data portability, metasystems, and suchlike, I kept noticing that there was a common set of bedrock features involving human beings and the networked apps they use. And, yes&#8230;I saw it as a Venn diagram.</p>

<p><a href='http://www.xmlgrrl.com/blog/wp-content/uploads/2008/09/venn.png'><img src="http://www.xmlgrrl.com/blog/wp-content/uploads/2008/09/venn.png" alt="" title="The Venn of data-sharing" width="417" height="510" class="alignnone size-full wp-image-395" /></a></p>

<p>I&#8217;ve been trying this out on folks for a while now, and used it in a couple of recent talks, particularly my <a href="http://www.xmlgrrl.com/blog/publications/#gnomedex08">Gnomedex 8.0</a> one. Here&#8217;s my thinking behind it.  (This is more than a straight Venn because of the metaphorical shadow thingie. Couldn&#8217;t resist! My <a href="http://www.xmlgrrl.com/blog/archives/2007/03/28/the-venn-of-identity/">web services Venn</a> &#8220;cheated&#8221; too.)</p>

<p><strong>Digital identity management</strong> is, at base, about <strong>identification</strong> so app usage can be correlated and audited, <strong>authorization</strong> to provide secure controlled access, and <strong>personalization</strong>, all counterbalanced by <strong>privacy</strong>. It has a strong individual (single-human-to-app) bent, though sometimes it involves <a href="http://en.wikipedia.org/wiki/Shibboleth_(Internet2)">Shibboleth</a>-style scenarios where you mostly track anonymous group members rather than unique people.</p>

<p><strong>Social networking</strong> is about building feelings of <strong>connectedness</strong> and offering the benefits of <strong>collaboration</strong>, such as crowdsourcing. Social apps focus on <em>human-to-human</em> relationships, but to provide infrastructure for this, they have to do plenty of the human-to-app variety. Social networking today stresses revelation of personal details (the <a href="http://code.google.com/apis/opensocial/articles/bestprac.html">OpenSocial best practices doc  </a> is one example) much more than it stresses privacy, though the latter is an increasing concern.</p>

<p><strong><span class="caps">VRM</span></strong> partly involves what could be called <strong>restriction</strong> of data flow &#8212; undoing vendors&#8217; grip on users&#8217; info in a way that&#8217;s familiar to proponents of privacy-enhanced and user-controlled IdM. But other <span class="caps">VRM </span>scenarios involve <strong>enhancement</strong> of individuals&#8217; opportunities to share personal information, for example by issuing a personal <span class="caps">RFP </span>to potential vendors. As Doc Searls has <a href="http://blogs.law.harvard.edu/vrm/2008/04/28/vrm-is-user-driven/">said</a>, <span class="caps">VRM </span>is &#8220;personal first and social second&#8221;, so it seems to have a closer kinship with digital identity but could provide new social opportunities as well.</p>

<p>Each area has its unique features. But all share a common trait &#8212; <strong>differentiated app behavior</strong> depending on special aspects of <em>you</em> (whether this comes from attributes, claims, and transactional details in IdM; social graph data and user-generated content in social apps; or proactive requests and other personal data offered up in <span class="caps">VRM</span>).  And to deliver on this promise they all share a common requirement &#8212; <strong>knowing more about you, with permission</strong>.</p>

<p>By contrast, where apps know about you through <em>improper</em> data gathering or aggregation, you get <strong>digital shadow</strong> effects &#8212; like direct marketing that is distinctly <em>not</em> permissioned or welcomed. Today, permissioning is still something of an art rather than a science, hence the title of this post.</p>

<p>We have a number of infrastructural options that more or less satisfy the requirements of the intersection, and later I hope to provide further thoughts on that. For now, I hope you&#8217;ll let me know what you think of this new instance of <a href="http://en.wikipedia.org/wiki/Venn_Diagram">John Venn&#8217;s invention</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/09/04/venn-and-the-art-of-data-sharing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The swinging shindig that was Gnomedex 8.0</title>
		<link>http://www.xmlgrrl.com/blog/archives/2008/08/26/the-swinging-shindig-that-was-gnomedex-80/</link>
		<comments>http://www.xmlgrrl.com/blog/archives/2008/08/26/the-swinging-shindig-that-was-gnomedex-80/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 02:23:49 +0000</pubDate>
		<dc:creator>Eve</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Gnomedex]]></category>

		<guid isPermaLink="false">http://www.xmlgrrl.com/blog/?p=392</guid>
		<description><![CDATA[What a trip my first Gnomedex was &#8212; I think I&#8217;m hooked.  It&#8217;s Chris&#8217;s happening, baby, and it freaks him out! (Think he can be convinced to dress up full-Austin next time? I did notice a bit of a shiny-jacket trend in the crowd.)

Lots of people have done roundups, so I&#8217;m mostly going to [...]]]></description>
			<content:encoded><![CDATA[<p>What a trip my first Gnomedex was &#8212; I think I&#8217;m hooked.  It&#8217;s <a href="http://chris.pirillo.com/">Chris&#8217;s</a> happening, baby, and it freaks him out! (Think he can be convinced to dress up <a href="http://www.youtube.com/watch?v=NQrVE5bRUsg">full-Austin</a> next time? I did notice a bit of a shiny-jacket trend in the crowd.)</p>

<p>Lots of people have done <a href="http://technorati.com/tag/gnomedex">roundups</a>, so I&#8217;m mostly going to be lazy and point to <a href="http://beth.typepad.com/beths_blog/2008/08/gnomedex-love.html">Beth Kanter</a>&#8217;s, which gives a great sense of the breadth, the depth, the value, and the occasional silliness of this event. I was very glad to meet Beth and to see her <a href="http://beth.typepad.com/beths_blog/2008/08/how-long-does-i.html">demonstrate</a>, right in front of our eyes, the principles she was teaching. Really, the two-plus days were a virtual parade of interesting people, compelling stories, and cool tech.</p>

<p>Speaking of virtual&#8230; Gnomedex&#8217;s sheer level of online+meatspace social connectedness was something new for me. The 8.0 community feeling started early, with the <a href="http://twitter.com/gnomedex">@gnomedex</a> Twitter feed. It continued with the <a href="http://pathable.com/">conference badges</a> that came with a social network. It got really strong while several hundred people watched the conference from home on the video feed (<a href="http://www.ustream.tv/chrispirillo/videos">archive</a>) and hung out on Twitter or in Chris&#8217;s <a href="http://live.pirillo.com">chat room</a>. (I daresay this feeling wouldn&#8217;t have been possible without the single-track setup.) And it continues even now. I mean, I <a href="http://twitter.com/xmlgrrl">tweet</a>, and I speak at conferences, but I&#8217;ve never before sat down after giving a talk to find that dozens of people &#8212; some in the same room and others a world away &#8212; have just started following me. Delighted to meet you all!  (Admittedly, I also exchanged business cards with some folks during coffee breaks, the old-fashioned way.)</p>

<p>I&#8217;ll post some thoughts later about my <a href="http://www.xmlgrrl.com/blog/publications/#gnomedex08">talk</a> on online data-sharing relationships. But, staying &#8220;meta&#8221; for now, I&#8217;ll just send you to one more roundup, Micah Baldwin&#8217;s <a href="http://learntoduck.com/conferences/gnomedex-8.0">3 Rules of Gnomedex 8.0</a>, which I think nicely captures what made it special. Quoting will just spoil it, so just go ye and read&#8230;</p>]]></content:encoded>
			<wfw:commentRss>http://www.xmlgrrl.com/blog/archives/2008/08/26/the-swinging-shindig-that-was-gnomedex-80/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
