| Updated: 29.3.2002; 19:25:47. |
| Security weblog Doc steps on thin ice of defining identity and articulating how the system to manage it should look like in cyberspace: But it wasn't until one of the late panels, "Identity on the Frontier" (with heavies from Microsoft, Sun and General Motors), that a problem and its solution became clear to me. There was a missing party at this table: the *customer*. All these guys were looking for ways to impose yet another identity management system on "the consumer". Yet our most personal identities, like the Net itself, are unmanageable.
First thing is that the primary identity, Doc is talking about, is constituted internally in human psyche. As cases of people with identity disorders indicate, it is not a thing that can be managed easily and hence his comment seems not to bear much substance. As far as secondary identities are concerned, we are not entirely in possession of them in the meatspace either. Let's take following two scenarios:
What can be said based on them?
The fact is that when dealing with businesses, customer are usually disadvantaged in the physcial world. Sellers are better informed about the product, have more money etc, etc. Although there are government-set or voluntary standards limiting the imbalance, customer is usually in disadvantage and more often than not is doing business on seller's terms than his own. If you are interested in this topic, Lawrence Lessig's Code and Other Laws of Cyberspace is the book you should read. IMO, one of the objectives of building digital identity infrastructure should be to for it ro reflect relationships from the real world as reflected in law and fair business practice. Any changes in balance of power should be done with the genral consent of both parties conducting the transaction. Doc is critisising BigCos and he thinks that when building the new infrastructure, they are trying to shift the power on their side. Judging from current architectures and public appeearances, this maz apply partially to Microsoft Passport or to the similar service from AOL. Liberty Alliance approach, according to presentations and various interviews that has been published, seems to respect the real world balance of power, customer's right of choice etc. Because LI specs are not out yet and very little information has been publicised, it is still possible that the infrastructure coming from Project Liberty will disadvantage the customer, any open-source public identity management effort would be indeed beneficial. Howver, an area where open-source project could be important, is infrastructure to support non-commerce transactions that is generally not of an interest to commercial vendors. 1:28:51 PMHurray! Sorting information out of background noise becomes easier with this new security oriented weblog. Financial Applications Security Weblog is produced by Europe-resident financial industry insider Pelle Braendgaard. He's definitely not one of those who think security is about making noise about latest Microsoft bugs; his selection of news is very rasonable and is comment-rich. Together with Securityfocus, Infosecuritymag, and Digital Identity Weblog, definitely a must read. 12:36:33 PM
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||