<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=%3Dmarkus</id>
	<title>IIW - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=%3Dmarkus"/>
	<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/Special:Contributions/%3Dmarkus"/>
	<updated>2026-04-27T14:42:13Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.6</generator>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_26_Session_Notes&amp;diff=21500</id>
		<title>IIW 26 Session Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_26_Session_Notes&amp;diff=21500"/>
		<updated>2018-04-06T15:24:36Z</updated>

		<summary type="html">&lt;p&gt;=markus: Marcus -&amp;gt; Markus&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday April 3, 2018=&lt;br /&gt;
===Session 1===&lt;br /&gt;
11:00 - 12:00&lt;br /&gt;
&lt;br /&gt;
1A/[[3D’s of Identity (agents, relationships, ATTR’s)]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[101 Session / Introduction to OAuth 2.0]]&lt;br /&gt;
&lt;br /&gt;
1D/[[A Primer on Verifiable Credentials and Decentralized Identifiers]]&lt;br /&gt;
&lt;br /&gt;
1F/[[GDPR What (Identity Stuff) is it GOOD for?]]&lt;br /&gt;
&lt;br /&gt;
1H/[[Identity Agents &amp;amp; HUBS: Messaging API’s &amp;amp; the “Layer Model” &amp;amp; Functional Architecture for S.S.I. Blockchain – working session]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
12:00 - 1:00&lt;br /&gt;
&lt;br /&gt;
2A/[[IDPro Organization]]&lt;br /&gt;
&lt;br /&gt;
2B/[[101 Session / Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2C/[[RWOT 6 Biometric Principles White Paper Review]]&lt;br /&gt;
&lt;br /&gt;
2D/[[Identity Wallets are not Crypto Wallets]]&lt;br /&gt;
&lt;br /&gt;
2F/[[Cat Herding – Building Consensus]]&lt;br /&gt;
&lt;br /&gt;
2G/[[Capabilities 101]]&lt;br /&gt;
&lt;br /&gt;
===Lunch===&lt;br /&gt;
1:00 - 2:00&lt;br /&gt;
&lt;br /&gt;
Lunch B/[[Functional Identity 101]]&lt;br /&gt;
&lt;br /&gt;
Lunch H/[[Use = Self Sovereign Bill of Rights = To Update Real Estate Consumer Bill of Rights]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
2:00 - 3:00&lt;br /&gt;
&lt;br /&gt;
3A/[[Self-Sovereign Agent Communication]]&lt;br /&gt;
	&lt;br /&gt;
3B/[[101 Session / Introduction to UMA = User Managed Access]]&lt;br /&gt;
&lt;br /&gt;
3C/[[Yo GDPR: Terms WE Assert and Sites &amp;amp; Services Agree to Check]]&lt;br /&gt;
 &lt;br /&gt;
3D/[[Distributed Social Networks (Activity Pub etc…)]]&lt;br /&gt;
&lt;br /&gt;
3F/[[Could Native Secure Access]]&lt;br /&gt;
&lt;br /&gt;
3I/[[Mobile Driver’s License (mDL)]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
3:00 - 4:00&lt;br /&gt;
&lt;br /&gt;
4A/[[What Are The ‘Wallets’ visions/projects – Do We Need a Working Group?]]&lt;br /&gt;
&lt;br /&gt;
4B/[[101 Session /  NIST Digital Identity Guidelines]]&lt;br /&gt;
&lt;br /&gt;
4C/[[Digital Puerto Rico]]&lt;br /&gt;
&lt;br /&gt;
4D/[[User-Managed Access: The BLT Sandwich – Business, Legal, Technical – Use Cases Mappings]]&lt;br /&gt;
&lt;br /&gt;
4F/[[Intro to DID Auth]]&lt;br /&gt;
&lt;br /&gt;
4G/[[Fedromp High FAL3 + AAL3 What is Required?]]&lt;br /&gt;
&lt;br /&gt;
4H/[[Decentralizing Reputation (with blockchains?)]]&lt;br /&gt;
&lt;br /&gt;
4J/[[The Future Of PRIVACY While Accessing PUBLISHED CONTENT]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
4:00 - 5:00&lt;br /&gt;
&lt;br /&gt;
5A/[[Fast Fed – Making SSO Easier to Set Up. Intro and Looking for Others Who Are Interested]]&lt;br /&gt;
&lt;br /&gt;
5B/[[101 Session / Self-Sovereign Identity (SSI) DID’s, Verifiable Claims etc…]]&lt;br /&gt;
&lt;br /&gt;
5C/[[Building A Sovrin Linked Permissionless Ledger for Data Analytics]]&lt;br /&gt;
&lt;br /&gt;
5E/[[Compatibility JSON-LD &amp;amp; Indy Proof Request Exchange]]&lt;br /&gt;
&lt;br /&gt;
5F/[[Armor Up – The Gravity Wars ~ Real World vs Virtual Reality and the Human OS]]&lt;br /&gt;
&lt;br /&gt;
5G/[[SISA’s = Standard Information Sharing Agreements]]&lt;br /&gt;
&lt;br /&gt;
5H/[[OAuth + SPA (Single Page Apps) Can We Just Use Code Flow Everywhere]]&lt;br /&gt;
&lt;br /&gt;
5I/[[Digital ID for Stateless Refugees]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday April 4, 2018=&lt;br /&gt;
&lt;br /&gt;
[[8:00 - 9:00 Women's Breakfast]]&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
9:30 - 10:30&lt;br /&gt;
&lt;br /&gt;
1A/[[What is Sovrin? How to become a Sovrin Steward. Self Sovereign Identity 102]]&lt;br /&gt;
&lt;br /&gt;
1C/[[WebAuthn + DID Auth]]&lt;br /&gt;
&lt;br /&gt;
1E/[[Agent/Wallet?  What is Agent? What is Wallet? Are They The Same?]]&lt;br /&gt;
&lt;br /&gt;
1F/[[Decoupled Flow for OAuth (AKA CIBA)]]&lt;br /&gt;
&lt;br /&gt;
1G/[[Zero Knowledge Proofs 101]]&lt;br /&gt;
&lt;br /&gt;
1H/[[Native SSO for Mobile Apps]]&lt;br /&gt;
&lt;br /&gt;
1I/[[Agent Communication Message Types + Names Spaces]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
10:30 - 11:30&lt;br /&gt;
&lt;br /&gt;
2A/[[DKMS Demo]]&lt;br /&gt;
&lt;br /&gt;
2C/[[TheOrgBook / Permitify – Bootstrapping SSI Using A Gov DID/Ver Cred Workflow Implementation]]&lt;br /&gt;
&lt;br /&gt;
2D/[[DID Ledger Lightening Talks]]&lt;br /&gt;
&lt;br /&gt;
2F/[[What Do You HATE about OAuth?]]&lt;br /&gt;
&lt;br /&gt;
2G/[[Publishing &amp;amp; /Advertising After 25 May ADPR Day]]&lt;br /&gt;
&lt;br /&gt;
2I/[[Consent As A Service: Making Consent Compliant &amp;amp; Effective]]&lt;br /&gt;
&lt;br /&gt;
2J/[[MyCUID/CU Ledger Update &amp;amp; Workshop]]&lt;br /&gt;
&lt;br /&gt;
2K/[[Path To Adoption for Self-Sovereign Identity &amp;amp; An Idea For Soverin / Use Cases For]]&lt;br /&gt;
&lt;br /&gt;
2L/[[Digital Puerto Rico Part 3]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
11:30 - 12:30&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3A/[[Quest For The Mnemon Seed #1]]&lt;br /&gt;
&lt;br /&gt;
3C/[[Bringing The Best of IIW to India / Making IIW a Global Decentralized Community]]&lt;br /&gt;
&lt;br /&gt;
3D/[[Open ID Foundation – Fast Fed &amp;amp; DIDC Federations = Enough Similarities to Share/Merge?]]&lt;br /&gt;
 &lt;br /&gt;
3E/[[Philosophy of Conscious Body w/Tech, ID Experience &amp;amp; S.O.U. Sovereign Ownership Under Law Prize 10M]]&lt;br /&gt;
&lt;br /&gt;
3F/[[Saving Democracy What Could Happen]]&lt;br /&gt;
&lt;br /&gt;
3G/[[DID Auth Workflows (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
3I/[[IaM and IoT]]&lt;br /&gt;
&lt;br /&gt;
3J/[[Digital Guardianship]]&lt;br /&gt;
&lt;br /&gt;
3K/[[Outsourcing GDPR Using UMA]]&lt;br /&gt;
&lt;br /&gt;
3L/[[IAB Transparency and Consent Framework]]&lt;br /&gt;
&lt;br /&gt;
3M/[[Sovrin – Exploring Building an Alliance Wants &amp;amp; Needs (especially if you  aren’t Evernym)]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
2:30 - 3:30&lt;br /&gt;
&lt;br /&gt;
4A/[[The Business of Self-Sovereign Identity]]&lt;br /&gt;
&lt;br /&gt;
4B/[[Kantara Consent Receipts – Communicating User Consent Between Data Controllers]]&lt;br /&gt;
&lt;br /&gt;
4C/[[The “ID” of KIDS]]&lt;br /&gt;
&lt;br /&gt;
4D/[[Expanding Language = The Identity of Words ~ Amebic / Shape Shifting]]&lt;br /&gt;
&lt;br /&gt;
4E/[[Discussing + Examining CULTURAL BIAS In Specifications and Other Technical Documents]]&lt;br /&gt;
&lt;br /&gt;
4F/[[An Analysis of S.S.I. Using Appreciative Inquiry]]&lt;br /&gt;
 &lt;br /&gt;
4G/[[Mobile APP -  APP OAuth]]&lt;br /&gt;
&lt;br /&gt;
4H/[[SAML Interoperability Deployment Profile]]&lt;br /&gt;
&lt;br /&gt;
4I/[[DID Resolvers &amp;amp; DID JWT]]&lt;br /&gt;
&lt;br /&gt;
4J/[[Easy POST Quantum Signature with Block Chain]]&lt;br /&gt;
&lt;br /&gt;
4K/[[Separable Identifiers &amp;amp; Intersectional Collaboration]]&lt;br /&gt;
&lt;br /&gt;
4M/[[Do-It-Yourself password free! – Cryptographic Authentication for Web Apps]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
3:30 - 4:30&lt;br /&gt;
&lt;br /&gt;
5B/[[Indy 301: Attribute Based Credentials &amp;amp; Zero Knowledge Proofs – Secret Contracts Private Computation]]&lt;br /&gt;
&lt;br /&gt;
5C/[[Secure Elements DICE &amp;amp; TPM]]&lt;br /&gt;
&lt;br /&gt;
5D/[[Communications Words Storytelling For Humans]]&lt;br /&gt;
&lt;br /&gt;
5E/[[GDPR AEORR (requirements + capabilities) Interactive Design Session]]&lt;br /&gt;
&lt;br /&gt;
5F/[[Consequential I.D. – How Not To Reinforce Power Imbalances in the Systems You Implement]]&lt;br /&gt;
&lt;br /&gt;
5G/[[Phone # Global Identifier]]&lt;br /&gt;
&lt;br /&gt;
5H/[[ORCID: What Should It Be Considering?]]&lt;br /&gt;
&lt;br /&gt;
5I/[[Veres One (DID Ledger) Deep Dive]]&lt;br /&gt;
&lt;br /&gt;
5J/[[Open ID v. FIDO v. SSI]]&lt;br /&gt;
 &lt;br /&gt;
5L/[[TLS Flex Expanded Library Support For Alternate Certificate Sources]]&lt;br /&gt;
&lt;br /&gt;
5M/[[How Are You Making Money In The Sovereign Ecosystem?]]&lt;br /&gt;
&lt;br /&gt;
=Thursday April 5, 2018=&lt;br /&gt;
===Session 1===&lt;br /&gt;
9:30 - 10:30&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1A/[[Solving Professional Credentialing – A Dialogue w/Projects &amp;amp; Companies]]&lt;br /&gt;
&lt;br /&gt;
1C/[[Soliciting YOUR Input (help a newbie!) How do You Want To Wield Your Data To Get Things Done?  Commerce &amp;amp; ID]]&lt;br /&gt;
&lt;br /&gt;
1F/[[Zero-Knowledge Prof’s 101 ENCORE – Only Highschool Math]]&lt;br /&gt;
&lt;br /&gt;
1G/[[User-Controlled GDPR Consent Cookie]]&lt;br /&gt;
&lt;br /&gt;
1H/[[Cooperation Among Our Communities Owning Interoperable Identities. A Cooperative?]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
10:30 - 11:30&lt;br /&gt;
&lt;br /&gt;
2A/[[InSide Out SID’s (Standard Immutable Delegation) &amp;amp; Trustless Distributed Computing]]&lt;br /&gt;
&lt;br /&gt;
2C/[[Future of SSI: Tech Scalability &amp;amp; Onboarding Issuers &amp;amp; Identity Holders to Identity Blockchains]]&lt;br /&gt;
&lt;br /&gt;
2D/[[REAL Federation]]&lt;br /&gt;
&lt;br /&gt;
2E/[[PDX – Personal Data Exchanges – Possibilities Why/What]]&lt;br /&gt;
  &lt;br /&gt;
2F/[[Addhaar Pros + Cons]]&lt;br /&gt;
&lt;br /&gt;
2G/[[Contributing to W3C Standards]]&lt;br /&gt;
&lt;br /&gt;
2H/[[Comparing Info Without Revealing It]]&lt;br /&gt;
&lt;br /&gt;
2I/[[Agent-Centric v Data-Centric Reality]]&lt;br /&gt;
&lt;br /&gt;
2J/[[Digital Puerto Rico – Part 4 of 3]]&lt;br /&gt;
 &lt;br /&gt;
2K/[[Beyond Early Adopters – Getting the World to Inform What We Build!]]&lt;br /&gt;
&lt;br /&gt;
2M/[[Identity Hub Personal Data Store – Soverin Agents – The Grand Unification]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
11:30 - 12:30&lt;br /&gt;
&lt;br /&gt;
3A/[[Mydata Movement – Looking at Identity from the Perspective of Human Centric Personal Data Management.]]&lt;br /&gt;
&lt;br /&gt;
3C/[[eIDAS &amp;amp; SSI]]&lt;br /&gt;
3D/[[Self Sovereign – Reputation – Radical – Disintermediation + 2 Sided Networks]]&lt;br /&gt;
&lt;br /&gt;
3E/[[Using Identity Tech To Keep People Safe in the Real World]]&lt;br /&gt;
&lt;br /&gt;
3F/[[How Agents + Decentralized Interfaces Help The De-Siloazation of IoT]]&lt;br /&gt;
&lt;br /&gt;
3G/[[Designing Ourselves Into The Future &amp;amp; Humanizing DID’s + VC’s]]&lt;br /&gt;
&lt;br /&gt;
3H/[[Hyperledger – Who/What/Where/Why Open Source]]&lt;br /&gt;
&lt;br /&gt;
3J/[[Breaking Digital Gridlock – Banking and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
12:30 - 2:00 (Working Lunch)&lt;br /&gt;
&lt;br /&gt;
4D/[[Massively Multiplayer Online Secure Environments (Games!)]]&lt;br /&gt;
&lt;br /&gt;
4F/[[Who Am I?  (story time with Markus)]]&lt;br /&gt;
&lt;br /&gt;
4G/[[A Self Sovereign Technology of Stack HIE of ONE]]&lt;br /&gt;
&lt;br /&gt;
4I/[[Digital Divide &amp;amp; Gender Equality in Indian Emerging Markets]]&lt;br /&gt;
&lt;br /&gt;
4J/[[Value Network Mapping Market Models 4 Self Sovereign Ecosystem]]&lt;br /&gt;
&lt;br /&gt;
4K/[[A Conversation About RECOVERING…. A Forgotten Credential Security]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
2:00 - 3:00&lt;br /&gt;
&lt;br /&gt;
5A/[[CRBAC An Introduction]]&lt;br /&gt;
&lt;br /&gt;
5B/[[The Sovereign Web-Of-Trust Model / Dynamic Web of Trust?&lt;br /&gt;
&lt;br /&gt;
5C/[[ID &amp;amp; Connected Vehicle]]&lt;br /&gt;
&lt;br /&gt;
5F/[[”Machine Readable User Asserted Terms for Privacy” An IEEE Standard Working Group]]&lt;br /&gt;
&lt;br /&gt;
5G/[[Delegation of Authority for Organizations + Services w/DID’s + VerfCreds]]&lt;br /&gt;
&lt;br /&gt;
5K/[[WHAT IS YOUR PROBLEM? (Bring Me Research) ]]&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21169</id>
		<title>DIF – Universal Resolver + Universal Registrar (DID’s across blockchains)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21169"/>
		<updated>2017-10-18T18:29:01Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''App Auth RFC8292 BCP212 Q&amp;amp;A'''  &lt;br /&gt;
 &lt;br /&gt;
'''Wednesday 1D '''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
  &lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
 &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:  '''&lt;br /&gt;
&lt;br /&gt;
Several communities are making progress on specifying &amp;quot;methods&amp;quot; such as '''btcr''', '''sov''', etc. for Decentralized Identifiers (DIDs) in different blockchains, DLTs, and other decentralized storage systems.&lt;br /&gt;
&lt;br /&gt;
The Decentralized Identity Foundation (DIF - http://identity.foundation/) is now working on a &amp;quot;Universal Resolver&amp;quot; that can resolve DIDs to their DID Documents in a unified way, by exposing an abstract interface that is implemented by a &amp;quot;driver&amp;quot; for each DID method.&lt;br /&gt;
&lt;br /&gt;
The Universal Resolver can be deployed as a web service, and drivers can be implemented as docker containers. For some DID methods such as '''btcr''' and '''sov''', a driver has to go through a number of steps to dynamically assemble the DID Document. In other cases such as '''v1''' and '''ipid''', the DID method actually stores the DID Document that can be returned by the Universal Resolver directly.&lt;br /&gt;
&lt;br /&gt;
Right now, preliminary drivers exist for '''btcr''', '''sov''', '''ipid''', '''uport''', '''ipid'''.&lt;br /&gt;
&lt;br /&gt;
Corresponding to the Universal Resolver, there will also be a Universal Registrar that can cover registration (and updates, and revocation) of identifiers, using a similar architecture involving an abstract interface and a set of drivers. Depending on the method, this may require the user to take certain action (e.g. send funds to a Bitcoin address, or contact a Sovrin trust anchor).&lt;br /&gt;
&lt;br /&gt;
* https://github.com/decentralized-identity/universal-resolver/&lt;br /&gt;
* https://github.com/WebOfTrustInfo/rebooting-the-web-of-trust-fall2017/tree/master/draft-documents/UniversalResolver&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21168</id>
		<title>DIF – Universal Resolver + Universal Registrar (DID’s across blockchains)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21168"/>
		<updated>2017-10-18T18:28:28Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''App Auth RFC8292 BCP212 Q&amp;amp;A'''  &lt;br /&gt;
 &lt;br /&gt;
'''Wednesday 1D '''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
  &lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
 &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:  '''&lt;br /&gt;
&lt;br /&gt;
Several communities are making progress on specifying &amp;quot;methods&amp;quot; such as '''btcr''', '''sov''', etc. for Decentralized Identifiers (DIDs) in different blockchains, DLTs, and other decentralized storage systems.&lt;br /&gt;
&lt;br /&gt;
The Decentralized Identity Foundation (DIF - http://identity.foundation/) is now working on a &amp;quot;Universal Resolver&amp;quot; that can resolve DIDs to their DID Documents in a unified way, by exposing an abstract interface that is implemented by a &amp;quot;driver&amp;quot; for each DID method.&lt;br /&gt;
&lt;br /&gt;
The Universal Resolver can be deployed as a web service, and drivers can be implemented as docker containers. For some DID methods such as '''btcr''' and '''sov''', a driver has to go through a number of steps to dynamically assemble the DID Document. In other cases such as v1 and ipid, the DID method actually stores the DID Document that can be returned by the Universal Resolver directly.&lt;br /&gt;
&lt;br /&gt;
Right now, preliminary drivers exist for '''btcr''', '''sov''', '''ipid''', '''uport''', '''ipid'''.&lt;br /&gt;
&lt;br /&gt;
Corresponding to the Universal Resolver, there will also be a Universal Registrar that can cover registration (and updates, and revocation) of identifiers, using a similar architecture involving an abstract interface and a set of drivers. Depending on the method, this may require the user to take certain action (e.g. send funds to a Bitcoin address, or contact a Sovrin trust anchor).&lt;br /&gt;
&lt;br /&gt;
* https://github.com/decentralized-identity/universal-resolver/&lt;br /&gt;
* https://github.com/WebOfTrustInfo/rebooting-the-web-of-trust-fall2017/tree/master/draft-documents/UniversalResolver&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21167</id>
		<title>DIF – Universal Resolver + Universal Registrar (DID’s across blockchains)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21167"/>
		<updated>2017-10-18T18:28:01Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''App Auth RFC8292 BCP212 Q&amp;amp;A'''  &lt;br /&gt;
 &lt;br /&gt;
'''Wednesday 1D '''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
  &lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
 &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:  '''&lt;br /&gt;
&lt;br /&gt;
Several communities are making progress on specifying &amp;quot;methods&amp;quot; such as '''btcr''', '''sov''', etc. for registering Decentralized Identifiers (DIDs) in different blockchains, DLTs, and other decentralized storage systems.&lt;br /&gt;
&lt;br /&gt;
The Decentralized Identity Foundation (DIF - http://identity.foundation/) is now working on a &amp;quot;Universal Resolver&amp;quot; that can resolve DIDs to their DID Documents in a unified way, by exposing an abstract interface that is implemented by a &amp;quot;driver&amp;quot; for each DID method.&lt;br /&gt;
&lt;br /&gt;
The Universal Resolver can be deployed as a web service, and drivers can be implemented as docker containers. For some DID methods such as '''btcr''' and '''sov''', a driver has to go through a number of steps to dynamically assemble the DID Document. In other cases such as v1 and ipid, the DID method actually stores the DID Document that can be returned by the Universal Resolver directly.&lt;br /&gt;
&lt;br /&gt;
Right now, preliminary drivers exist for '''btcr''', '''sov''', '''ipid''', '''uport''', '''ipid'''.&lt;br /&gt;
&lt;br /&gt;
Corresponding to the Universal Resolver, there will also be a Universal Registrar that can cover registration (and updates, and revocation) of identifiers, using a similar architecture involving an abstract interface and a set of drivers. Depending on the method, this may require the user to take certain action (e.g. send funds to a Bitcoin address, or contact a Sovrin trust anchor).&lt;br /&gt;
&lt;br /&gt;
* https://github.com/decentralized-identity/universal-resolver/&lt;br /&gt;
* https://github.com/WebOfTrustInfo/rebooting-the-web-of-trust-fall2017/tree/master/draft-documents/UniversalResolver&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21166</id>
		<title>DIF – Universal Resolver + Universal Registrar (DID’s across blockchains)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=DIF_%E2%80%93_Universal_Resolver_%2B_Universal_Registrar_(DID%E2%80%99s_across_blockchains)&amp;diff=21166"/>
		<updated>2017-10-18T18:27:07Z</updated>

		<summary type="html">&lt;p&gt;=markus: Created page with &amp;quot;'''App Auth RFC8292 BCP212 Q&amp;amp;A'''     '''Wednesday 1D '''  '''Convener:''' Markus Sabadello    '''Notes-taker(s):''' Markus Sabadello   '''Discussion notes, key understandings...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''App Auth RFC8292 BCP212 Q&amp;amp;A'''  &lt;br /&gt;
 &lt;br /&gt;
'''Wednesday 1D '''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
  &lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
 &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:  '''&lt;br /&gt;
&lt;br /&gt;
Several communities are now working on specifying &amp;quot;methods&amp;quot; such as '''btcr''', '''sov''', etc. for registering Decentralized Identifiers (DIDs) in different blockchains, DLTs, and other decentralized storage systems.&lt;br /&gt;
&lt;br /&gt;
The Decentralized Identity Foundation (DIF - http://identity.foundation/) is now working on a &amp;quot;Universal Resolver&amp;quot; that can resolve DIDs to their DID Documents in a unified way, by exposing an abstract interface that is implemented by a &amp;quot;driver&amp;quot; for each DID method.&lt;br /&gt;
&lt;br /&gt;
The Universal Resolver can be deployed as a web service, and drivers can be implemented as docker containers. For some DID methods such as '''btcr''' and '''sov''', a driver has to go through a number of steps to dynamically assemble the DID Document. In other cases such as v1 and ipid, the DID method actually stores the DID Document that can be returned by the Universal Resolver directly.&lt;br /&gt;
&lt;br /&gt;
Right now, preliminary drivers exist for '''btcr''', '''sov''', '''ipid''', '''uport''', '''ipid'''.&lt;br /&gt;
&lt;br /&gt;
Corresponding to the Universal Resolver, there will also be a Universal Registrar that can cover registration (and updates, and revocation) of identifiers, using a similar architecture involving an abstract interface and a set of drivers. Depending on the method, this may require the user to take certain action (e.g. send funds to a Bitcoin address, or contact a Sovrin trust anchor).&lt;br /&gt;
&lt;br /&gt;
* https://github.com/decentralized-identity/universal-resolver/&lt;br /&gt;
* https://github.com/WebOfTrustInfo/rebooting-the-web-of-trust-fall2017/tree/master/draft-documents/UniversalResolver&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_25_Session_Notes&amp;diff=21165</id>
		<title>IIW 25 Session Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_25_Session_Notes&amp;diff=21165"/>
		<updated>2017-10-18T18:14:57Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday October 17, 2017=&lt;br /&gt;
===Session 1===&lt;br /&gt;
11:00 - 12:00&lt;br /&gt;
&lt;br /&gt;
1B/ [[101 Introduction to OAuth2]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[DHS S&amp;amp;T IDM Program’s R&amp;amp;D]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[DIF Technical/Recap and Roadmap Discussion]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[App Auth Q &amp;amp; A RFC 8292 BCP 212]]&lt;br /&gt;
&lt;br /&gt;
1H/ [[Blockchain Democracy]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
12:00 - 1:00&lt;br /&gt;
&lt;br /&gt;
2A/ [[Self-Sovereign Identity #]] &lt;br /&gt;
&lt;br /&gt;
2B/ [[101 Introduction to OpenID Connect]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Is Your Data Legal? Meaningful (oxymoron?) Consent]] &lt;br /&gt;
2D/ [[‘Fixing’ The Consumer IOT/Smart Home User Experience]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[6 Degrees of Identity Freedom]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[DIF Did’s In-Depth (w/Review of Contentious Bits)]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Token Binding for Cookies – OpenID Command OAuth]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[Intro to Hyperledger “So you think you need a Blockchain…”]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
2:00 - 3:00&lt;br /&gt;
&lt;br /&gt;
3A/ [[Mutual OAuth Distributed OAuth]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[101 All Things UMA (user managed access)]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Concerned About Centralized Authority? Let’s Make It Participatory]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[Implications for the End User of How You Design A Blockchain For Digital Identity]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Aadhaar]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Information Sharing Agreements (ISA) – First Party Terms That YOU &amp;amp; I Proffer: V2.0 of the Commercial Web]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[The Big, Big Picture = Identity Money Topology – A Conversation]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Identity Agents: It’s not just what you know, it is what you can DO – Personal Data Stores—Extensible API’s]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
3:00 - 4:00&lt;br /&gt;
&lt;br /&gt;
4A/[[RISC – Working Session]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[101 NIST – Digital Identity Guidelines ‘101’]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[Blockchain Security &amp;amp; Privacy R&amp;amp;D Lessons Learned and Gaps]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Fixing Social Security Numbers = Blockchain, Good Identity, Don’t Break Existing SW]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[Functional Idenity]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Public Blockchains AND – Private UMA) User Managed Access]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Open ID Connect CIBA Explained]]&lt;br /&gt;
&lt;br /&gt;
4I/ [[Identity Concepts Around The World]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
4:00 - 5:00&lt;br /&gt;
&lt;br /&gt;
5A/[[Public Blockchain Addresses FOR User-Centered Digital Signatures]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[101 Introduction to DID’s, Verifiable Claims and Blockchains]] &lt;br /&gt;
&lt;br /&gt;
5E/ [[Blockchain Interop Chameleon Nodes?]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[HOLOCHAIN P2P Apps Without the Blockchains Problems for Scale, Speed, Cost &amp;amp; Governance]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Next Gen Phishing (all your OTP belongs to us)]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Yubikey Usability Study – Results for lab + longitudinal study]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[IDPro = Help Build Next Gen of ID Professionals]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday October 18, 2017=&lt;br /&gt;
&lt;br /&gt;
[[8:00 - 9:00 Women's Breakfast]]&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
9:30 - 10:30&lt;br /&gt;
&lt;br /&gt;
1A/ [[Intro to Sovrin]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Two Short Talks on Capabilities]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Distributed ID System Patterns with Distributed Systems]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[DIF – Universal Resolver + Universal Registrar (DID’s across blockchains)]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Minute Money? A new currency based on A NEW PARADIGM – Time AS Money]]&lt;br /&gt;
&lt;br /&gt;
1H/ [[DNS Based OpenID Connect Discovery]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
10:30 - 11:30&lt;br /&gt;
&lt;br /&gt;
2A/ [[Triple-blind Brokered Identity Federation]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[First Party World: People in charge via GDPR by 25 May 2018 – Calling Lawyers &amp;amp; Geeks]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Ecosystem Map – Explore Where Could It Go – Insight Treasure Hunt]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Estonian ID Cards Internet Voting]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[DIF Identity Hubs Deep Dive &amp;amp; Spec Feedback]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[NO Identity – ID As A Collection of Verifiable Claims]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[Gender and Diversity in the Valley – A Listening Circle to talk about all the stuff]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
11:30 - 12:30&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
2:30 - 3:30&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
3:30 - 4:30&lt;br /&gt;
&lt;br /&gt;
=Thursday October 19, 2017=&lt;br /&gt;
===Session 1===&lt;br /&gt;
9:30 - 10:30&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
10:30 - 11:30&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
11:30 - 12:30&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
12:30 - 2:00 (Working Lunch)&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
2:00 - 3:00&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_23_Demo%27s&amp;diff=20601</id>
		<title>IIW 23 Demo's</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_23_Demo%27s&amp;diff=20601"/>
		<updated>2016-10-20T15:15:14Z</updated>

		<summary type="html">&lt;p&gt;=markus: removing demo entry again and sending info to Heidi instead&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW XXIII #23 DEMO LIST - Wednesday October 26, 2016 ==&lt;br /&gt;
&lt;br /&gt;
'''TABLE #'''&lt;br /&gt;
&lt;br /&gt;
'''1.	Verifiable Claims Ecosystem Demo:''' Manu Sporny&lt;br /&gt;
URL: http://w3c.github.io/webpayments-ig/VCTF/architecture &lt;br /&gt;
See a demo of the Verifiable Claims Ecosystem in action. Part of this&lt;br /&gt;
work is proposed for standardization at W3C. The 5 minute demo covers a&lt;br /&gt;
self-sovereign verifiable claim being issued, stored, and used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''2.	YubiKey Demo:''' Stina Ehrensvard, CEO and Founder &amp;amp; Chris Streeks, Solutions Engineer&lt;br /&gt;
URL: https://www.yubico.com/products/yubikey-hardware&lt;br /&gt;
We'll demo the versatile YubiKey, which supports open standards such as PIV, OATH, OpenPGP and FIDO U2F. Use U2F strong authentication to log into Gmail, Dropbox and now Salesforce among others. See PIV capabilities for MacOS Sierra log in. Use the same YubiKey with Windows Hello to unlock your Windows desktop.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''3.	HIE of One, PBC and HIE of One:''' Adrian Gropper &lt;br /&gt;
URL: http://hieofone.org &lt;br /&gt;
HIE of One is a proof of concept for self-sovereign support technology based on UMA. Using healthcare as the demo domain, Alice operates her own authorization server and manages policies re: OpenID Connect. Soon, we will also include blockchain standards for self-sovereign ID.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''4.	Lumenous, the first credit &amp;quot;non-bureau,&amp;quot;:''' LaVonne Reimer&lt;br /&gt;
URL: http://www.lumenous.net&lt;br /&gt;
The first credit bureau launched in 1841. The model has not been rethought, until now. Lumenous puts business owners in charge of personal and business data used to verify identity and decide on credit terms, loans, and more. See how first user value will turn into trust graph.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''5.	ÆVATAR , your Digital Companion:''' David ROBERT President &amp;amp; Founder ÆTERNAM&lt;br /&gt;
URL: http://www.aevatar.com   http://www.aeternam.eu  ÆTERNAM a “Common Interest Cooperative”&lt;br /&gt;
ÆVATAR is the first self-Sovereign Identity management Companion offered to each EU Citizens, conforming to EU Privacy Regulation ( GDPR, eIDAS) and UN ID2020 recommendations for Self-Sovereign Identities. ÆVATAR is govern by a Common Interest Cooperative (1 person, 1 vote).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''6.	digi.me –current PC/Mac, iOS and Android version application:''' Jim Pasquale &amp;amp; Julian Ranger&lt;br /&gt;
URL: http://get.digi.me for product and https://blog.digi.me/2016/09/29/who-am-i-iamdata-a-new-digi-me-campaign/  for vision&lt;br /&gt;
Demo shows what users can do when they own and control their own data on their own devices(s), initially with social data aggregation of different accounts, which is fully curated – providing peace of mind, flashback perspectives on social interactions with likes, comments and photos including meta data, universal search, customizable widgets for building collections, creating journals, empowering individuals to make better decisions.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_23_Demo%27s&amp;diff=20600</id>
		<title>IIW 23 Demo's</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_23_Demo%27s&amp;diff=20600"/>
		<updated>2016-10-20T15:04:03Z</updated>

		<summary type="html">&lt;p&gt;=markus: line breaks&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW XXIII #23 DEMO LIST - Wednesday October 26, 2016 ==&lt;br /&gt;
&lt;br /&gt;
'''TABLE #'''&lt;br /&gt;
&lt;br /&gt;
'''1.	Verifiable Claims Ecosystem Demo:''' Manu Sporny&lt;br /&gt;
URL: http://w3c.github.io/webpayments-ig/VCTF/architecture &lt;br /&gt;
See a demo of the Verifiable Claims Ecosystem in action. Part of this&lt;br /&gt;
work is proposed for standardization at W3C. The 5 minute demo covers a&lt;br /&gt;
self-sovereign verifiable claim being issued, stored, and used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''2.	YubiKey Demo:''' Stina Ehrensvard, CEO and Founder &amp;amp; Chris Streeks, Solutions Engineer&lt;br /&gt;
URL: https://www.yubico.com/products/yubikey-hardware&lt;br /&gt;
We'll demo the versatile YubiKey, which supports open standards such as PIV, OATH, OpenPGP and FIDO U2F. Use U2F strong authentication to log into Gmail, Dropbox and now Salesforce among others. See PIV capabilities for MacOS Sierra log in. Use the same YubiKey with Windows Hello to unlock your Windows desktop.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''3.	HIE of One, PBC and HIE of One:''' Adrian Gropper &lt;br /&gt;
URL: http://hieofone.org &lt;br /&gt;
HIE of One is a proof of concept for self-sovereign support technology based on UMA. Using healthcare as the demo domain, Alice operates her own authorization server and manages policies re: OpenID Connect. Soon, we will also include blockchain standards for self-sovereign ID.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''4.	Lumenous, the first credit &amp;quot;non-bureau,&amp;quot;:''' LaVonne Reimer&lt;br /&gt;
URL: http://www.lumenous.net&lt;br /&gt;
The first credit bureau launched in 1841. The model has not been rethought, until now. Lumenous puts business owners in charge of personal and business data used to verify identity and decide on credit terms, loans, and more. See how first user value will turn into trust graph.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''5.	ÆVATAR , your Digital Companion:''' David ROBERT President &amp;amp; Founder ÆTERNAM&lt;br /&gt;
URL: http://www.aevatar.com   http://www.aeternam.eu  ÆTERNAM a “Common Interest Cooperative”&lt;br /&gt;
ÆVATAR is the first self-Sovereign Identity management Companion offered to each EU Citizens, conforming to EU Privacy Regulation ( GDPR, eIDAS) and UN ID2020 recommendations for Self-Sovereign Identities. ÆVATAR is govern by a Common Interest Cooperative (1 person, 1 vote).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''6.	digi.me –current PC/Mac, iOS and Android version application:''' Jim Pasquale &amp;amp; Julian Ranger&lt;br /&gt;
URL: http://get.digi.me for product and https://blog.digi.me/2016/09/29/who-am-i-iamdata-a-new-digi-me-campaign/  for vision&lt;br /&gt;
Demo shows what users can do when they own and control their own data on their own devices(s), initially with social data aggregation of different accounts, which is fully curated – providing peace of mind, flashback perspectives on social interactions with likes, comments and photos including meta data, universal search, customizable widgets for building collections, creating journals, empowering individuals to make better decisions.&lt;br /&gt;
&lt;br /&gt;
'''7.	XDI Demos:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
URL: https://xdi2.org/demos.html&lt;br /&gt;
&lt;br /&gt;
Demos of current state-of-the-art of XDI, including:&lt;br /&gt;
&lt;br /&gt;
1. Use of XDI link contracts for GDPR-compliant sharing of personal data of a train passenger traveling through multiple E.U. countries (&amp;quot;European Passenger Record&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
2. Use of XDI connectors for interoperability and data portability between personal data stores (e.g. CozyCloud, Meeco).&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_23_Demo%27s&amp;diff=20599</id>
		<title>IIW 23 Demo's</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_23_Demo%27s&amp;diff=20599"/>
		<updated>2016-10-20T15:02:52Z</updated>

		<summary type="html">&lt;p&gt;=markus: added XDI Demos by Markus Sabadello&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW XXIII #23 DEMO LIST - Wednesday October 26, 2016 ==&lt;br /&gt;
&lt;br /&gt;
'''TABLE #'''&lt;br /&gt;
&lt;br /&gt;
'''1.	Verifiable Claims Ecosystem Demo:''' Manu Sporny&lt;br /&gt;
URL: http://w3c.github.io/webpayments-ig/VCTF/architecture &lt;br /&gt;
See a demo of the Verifiable Claims Ecosystem in action. Part of this&lt;br /&gt;
work is proposed for standardization at W3C. The 5 minute demo covers a&lt;br /&gt;
self-sovereign verifiable claim being issued, stored, and used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''2.	YubiKey Demo:''' Stina Ehrensvard, CEO and Founder &amp;amp; Chris Streeks, Solutions Engineer&lt;br /&gt;
URL: https://www.yubico.com/products/yubikey-hardware&lt;br /&gt;
We'll demo the versatile YubiKey, which supports open standards such as PIV, OATH, OpenPGP and FIDO U2F. Use U2F strong authentication to log into Gmail, Dropbox and now Salesforce among others. See PIV capabilities for MacOS Sierra log in. Use the same YubiKey with Windows Hello to unlock your Windows desktop.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''3.	HIE of One, PBC and HIE of One:''' Adrian Gropper &lt;br /&gt;
URL: http://hieofone.org &lt;br /&gt;
HIE of One is a proof of concept for self-sovereign support technology based on UMA. Using healthcare as the demo domain, Alice operates her own authorization server and manages policies re: OpenID Connect. Soon, we will also include blockchain standards for self-sovereign ID.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''4.	Lumenous, the first credit &amp;quot;non-bureau,&amp;quot;:''' LaVonne Reimer&lt;br /&gt;
URL: http://www.lumenous.net&lt;br /&gt;
The first credit bureau launched in 1841. The model has not been rethought, until now. Lumenous puts business owners in charge of personal and business data used to verify identity and decide on credit terms, loans, and more. See how first user value will turn into trust graph.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''5.	ÆVATAR , your Digital Companion:''' David ROBERT President &amp;amp; Founder ÆTERNAM&lt;br /&gt;
URL: http://www.aevatar.com   http://www.aeternam.eu  ÆTERNAM a “Common Interest Cooperative”&lt;br /&gt;
ÆVATAR is the first self-Sovereign Identity management Companion offered to each EU Citizens, conforming to EU Privacy Regulation ( GDPR, eIDAS) and UN ID2020 recommendations for Self-Sovereign Identities. ÆVATAR is govern by a Common Interest Cooperative (1 person, 1 vote).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''6.	digi.me –current PC/Mac, iOS and Android version application:''' Jim Pasquale &amp;amp; Julian Ranger&lt;br /&gt;
URL: http://get.digi.me for product and https://blog.digi.me/2016/09/29/who-am-i-iamdata-a-new-digi-me-campaign/  for vision&lt;br /&gt;
Demo shows what users can do when they own and control their own data on their own devices(s), initially with social data aggregation of different accounts, which is fully curated – providing peace of mind, flashback perspectives on social interactions with likes, comments and photos including meta data, universal search, customizable widgets for building collections, creating journals, empowering individuals to make better decisions.&lt;br /&gt;
&lt;br /&gt;
'''7.	XDI Demos:''' Markus Sabadello&lt;br /&gt;
URL: https://xdi2.org/demos.html&lt;br /&gt;
Demos of current state-of-the-art of XDI, including:&lt;br /&gt;
1. Use of XDI link contracts for GDPR-compliant sharing of personal data of a train passenger traveling through multiple E.U. countries (&amp;quot;European Passenger Record&amp;quot;).&lt;br /&gt;
2. Use of XDI connectors for interoperability and data portability between personal data stores (e.g. CozyCloud, Meeco).&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_20_Proposed_Topics&amp;diff=19917</id>
		<title>IIW 20 Proposed Topics</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_20_Proposed_Topics&amp;diff=19917"/>
		<updated>2015-03-27T08:51:47Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''What topics are you planning to present about or lead a discussion about at this IIW?'''&lt;br /&gt;
&lt;br /&gt;
*Notification management - Notifs&lt;br /&gt;
*unhosted identity&lt;br /&gt;
*Redelegation of OAuth bearer tokens&lt;br /&gt;
*&amp;quot;OpenID Connect certification&lt;br /&gt;
*Proof of Possession&amp;quot;&lt;br /&gt;
*Trust-elevation (adaptive access)&lt;br /&gt;
*IdM for future scientific collaborations&lt;br /&gt;
*I am a member of the W3C Credentials Community Group (http://opencreds.org) and will present status/progress/goals/roadmap/use cases and how they relate to other identity initiatives.&lt;br /&gt;
*OpenID Connect mobile profile&lt;br /&gt;
*&amp;quot;Consent management  UI and internals International consent issues&amp;quot;&lt;br /&gt;
*consumer consent interoperability&lt;br /&gt;
*&amp;quot;UMA IoT authorization HEART&amp;quot;&lt;br /&gt;
*Looking forward to collaborating on OAuth2 technologies, like OpenID Connect, UMA and multi-party federation.&lt;br /&gt;
*Scoring AuthN&lt;br /&gt;
*Meeco - Life Management Platform&lt;br /&gt;
*distributed governance, sociotechnical controls for sociotechnical systems, hybrid approaches to complexity and risk&lt;br /&gt;
*IoT, scim&lt;br /&gt;
*IDM strategies used successfully by NetIQ customers&lt;br /&gt;
*Privacy protecting discovery&lt;br /&gt;
*Anonymity, security&lt;br /&gt;
*&amp;quot;future of money identity internet of things&amp;quot;&lt;br /&gt;
*Organic governance; Collaborative systems of credit and trust; Data-sharing platforms&lt;br /&gt;
*Lightweight UMA and HEART Authorization Server for Authorization Management and the IoT&lt;br /&gt;
*&amp;quot;Credential Trust Elevation standards @ OASIS ID Ecosystem Steering Group&amp;quot;&lt;br /&gt;
*IoT without the cloud&lt;br /&gt;
*Internet of Things&lt;br /&gt;
*FreedomBox update&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''What are you hoping to learn about or hear a presentation about at IIW?'''&lt;br /&gt;
&lt;br /&gt;
*what's new in identity protocols, VRM, ...&lt;br /&gt;
*Trust Frameworks including Public and Private Sector organizations and international governments&lt;br /&gt;
*http-free protocols http://www.wavis.org/blog/http-free-web-protocols&amp;quot;&lt;br /&gt;
*SCIM, OpenID Connect&lt;br /&gt;
*UMA - VRM - OIDF Certification Threat Management Reputation Management&lt;br /&gt;
*What others are doing&lt;br /&gt;
*OAuth OpenID Connect and FIDO profiles&lt;br /&gt;
*OpenID Connect, OAuth 2.0, UMA&lt;br /&gt;
*Federated and delegated IdM&lt;br /&gt;
*How other technologies overlap and can potentially integrate with the Credential CG standards.&lt;br /&gt;
*&amp;quot;Personal control of data sharing OAuth/OpenID Connect&amp;quot;&lt;br /&gt;
*SCIM extensions or anything SCIM&lt;br /&gt;
*OpenID Connect, UMA, vectors of trust&lt;br /&gt;
*Others working on consent management&lt;br /&gt;
*&amp;quot;OAuth, OpenID Connect, and UMA used together&lt;br /&gt;
*Healthcare use cases for identity&amp;quot;&lt;br /&gt;
*OpenID Connect Logout / OAuth2 for IOT / latest and greatest in new authentication protocols (i.e. FIDO...)&lt;br /&gt;
*OpenPDS, anonymous authentication, XDI, PDS, Personal Data EcoSystem&lt;br /&gt;
*Progress with eco-system &amp;amp; XDI&lt;br /&gt;
*everything !&lt;br /&gt;
*IoT, scim&lt;br /&gt;
*VRM, privacy, secure data access, future of Identity&lt;br /&gt;
*IoT, biometrics&lt;br /&gt;
*All kinds of things!&lt;br /&gt;
*Privacy architectures; Alternative currencies and related ecosystem and trust verification models&lt;br /&gt;
*&amp;quot;VoT/Vectors of Trust OIDC&amp;quot;&lt;br /&gt;
*Truly decentralized social identity&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''What are the critical questions about user-centric identity and data you hope to discuss with peers at IIW?'''&lt;br /&gt;
&lt;br /&gt;
*social physics consensus and collaboration using decentralized mechanisms (e.g. blockchain)&lt;br /&gt;
*How to have identity without subscription to a service. IE How to have a service recognize rather than authenticate.&lt;br /&gt;
*Password management use cases with SCIM OpenID Connect NAPPS Profile&lt;br /&gt;
*User Centric Business Models&lt;br /&gt;
*What are the remaining roadblocks to adoption of higher LOA BYOI&lt;br /&gt;
*&amp;quot;Identity Management as a Service - Use Cases Attribute based credentials - Use casesMulti factor authentication on Mobile Devices&amp;quot;&lt;br /&gt;
*Consent&lt;br /&gt;
*&amp;quot;Multiple authorization servers for access tokens&lt;br /&gt;
*IoT security and authorization&amp;quot;&lt;br /&gt;
*How can I secure all the API's in my household IOT devices?&lt;br /&gt;
*New OAuth Profiles, Personal Data Stores, Privacy Engineering&lt;br /&gt;
*What are folks current challenges?&lt;br /&gt;
*How should data storage systems change to accommodate better Identity models? Castle Wall versus Las Vegas Casino models. The Castle checks the identity at the gate and gives access to the castle. The Casino allows anyone to come inside but monitors every movement, performs facial recognition, etc..&lt;br /&gt;
*Universal IDM taxonomy&lt;br /&gt;
*Can biometrics be used safely and securely in security products?&lt;br /&gt;
*All of above&lt;br /&gt;
*Communication of attributes using metadata for provenance and assurance info&lt;br /&gt;
*How do you enable ad-hoc, quasi spontaneous social networks?&lt;br /&gt;
*I would like to progress the work on OAuth.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Proposed_Topics&amp;diff=19528</id>
		<title>IIW 18 Proposed Topics</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Proposed_Topics&amp;diff=19528"/>
		<updated>2014-04-07T20:16:15Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''What topics are you planning to present about or lead a discussion about at this IIW?'''&lt;br /&gt;
* Authentication&lt;br /&gt;
* Privacy enabled identity solutions&lt;br /&gt;
* Not sure yet. Need to think about this&lt;br /&gt;
* Open Architectures for Personal Clouds&lt;br /&gt;
* Project Eureka&lt;br /&gt;
* XDI and Personal Clouds&lt;br /&gt;
* Diversity, interoperability and standards: how the VRM supply community can work together&lt;br /&gt;
* Extreme Relevancy&lt;br /&gt;
* OpenID Connect, JWT, JOSE, Proof-of-Possession (PoP)&lt;br /&gt;
* Privacy manager deployments and adaptation to other attribute flows &lt;br /&gt;
* Trustmarks 2.0&lt;br /&gt;
* Points of Individual Control in Identity Systems, Outsourcing Moral Authority &lt;br /&gt;
* Derived credentials, secure and private mobile messaging, secure enterprise mobile SSO&lt;br /&gt;
* Use cases for nymity in civic identity systems&lt;br /&gt;
* FreedomBox&lt;br /&gt;
&lt;br /&gt;
'''What are you hoping to learn about or hear a presentation about at IIW?'''&lt;br /&gt;
* NSTIC, FIDO etc...&lt;br /&gt;
* OpenID Connect, Accountchooser, UMA VRM&lt;br /&gt;
* New ideas and updates from many areas&lt;br /&gt;
* Udate on E-ID initiatives&lt;br /&gt;
* Personal Clouds&lt;br /&gt;
* sharing experience with others about actual technology and standards implementations&lt;br /&gt;
* VRM, personal clouds&lt;br /&gt;
* ROI of VPI&lt;br /&gt;
* Identity protocol work&lt;br /&gt;
* OpenID Connect&lt;br /&gt;
* Standards, OpenID, mobile, authN, authZ, NSTIC,&lt;br /&gt;
* Identity&lt;br /&gt;
* Balancing Zero Trust with Cloud Identity.&lt;br /&gt;
* Private compute platforms, unhosted apps, non-sharing uses of personal data &lt;br /&gt;
&lt;br /&gt;
'''What are the critical questions about user-centric identity and data you hope to discuss with peers at IIW.'''&lt;br /&gt;
* Internet of things&lt;br /&gt;
* Personal Clouds&lt;br /&gt;
* Ways in which we can work with others in this space&lt;br /&gt;
* Does an ID document has to play a role in online ID verification&lt;br /&gt;
* Unlocking VRM market&lt;br /&gt;
* Privacy and technology in practice&lt;br /&gt;
* Case Studies&lt;br /&gt;
* OpenID Connect adoption, Proof-of-Possession (PoP)&lt;br /&gt;
* Consent, attribute management, linkability&lt;br /&gt;
* proof of knowledge&lt;br /&gt;
* 2FA, MFA&lt;br /&gt;
* Balancing Zero Trust with Cloud Identity.&lt;br /&gt;
* What are the moral hazards of identity systems?&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_17_Proposed_Topics&amp;diff=19373</id>
		<title>IIW 17 Proposed Topics</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_17_Proposed_Topics&amp;diff=19373"/>
		<updated>2013-10-17T01:01:10Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
'''What topics are you planning to present about or lead a discussion about at this IIW?'''&lt;br /&gt;
* Personal Cloud&lt;br /&gt;
* Alternative concepts to data &amp;quot;ownership&amp;quot;&lt;br /&gt;
* StarTier&lt;br /&gt;
* Attribute Assurance, Publicly Discoverable ePayment Addresses; Private cloud; Revocation issues in globally synchronized registries; Regulatory issues in globally synchronized registries&lt;br /&gt;
* Attribute Exchange&lt;br /&gt;
* Security, Internet of Things, Personal Clouds&lt;br /&gt;
* Privacy of deceased users&lt;br /&gt;
* government use-cases in identity&lt;br /&gt;
* CSPs (Cloud Service Providers) for personal cloudsRespect ConnectPractical XDI&lt;br /&gt;
* Mobile MDM vs Sandbox - Which is best for BYOD?Business-centric Identity Policies - Will IT have to give up control?Identity Cube -Describing multidimensional relationships.Merging Identity rules, policies, entitlements with workflows.Case Study: How the IRS of  Mexico is re-inventing with IdentityBYOD Identity is in it's infancy. What's coming next?&lt;br /&gt;
* OpenID Connect, JWT, JOSE&lt;br /&gt;
* Individual sovereignty over ID, Data and Communication - concepts and technology&lt;br /&gt;
* Using Personal Clouds to remove the need for usercodes/passwordsFinancing Development through issuing interest bearing, inflation adjusted creditsPaying people for personal information&lt;br /&gt;
* OpendID Connect&lt;br /&gt;
* Personal Clouds&lt;br /&gt;
* We'll be presenting our Personal Cloud Appliance.&lt;br /&gt;
* Personal Data @ Rest&lt;br /&gt;
* Personal data monetization models&lt;br /&gt;
* Getting involved in the IDESG - Identity Ecosystem Steering Group/NSTIC &lt;br /&gt;
* How Religion and Cultural Context influence Identity System Architecture and Design&lt;br /&gt;
* Paddy. Private Clouds.&lt;br /&gt;
* verified identityself identity&lt;br /&gt;
* OAuth, especially its security properties&lt;br /&gt;
* personal clouds&lt;br /&gt;
* Alignment Trust Frameworks&lt;br /&gt;
* How to introduce new identity technologies, standards and expectations to 6-20% of the online US population in one fell swoop.&lt;br /&gt;
* FreedomBox, IndieBox, etc.&lt;br /&gt;
 &lt;br /&gt;
'''What are you hoping to learn about or hear a presentation about at IIW?'''&lt;br /&gt;
* vendor relation management personal clouds openid connect account chooser&lt;br /&gt;
* Application architectures for the next internet.&lt;br /&gt;
* Private Cloud; Open Access&lt;br /&gt;
* Trust frameworks,&lt;br /&gt;
* Personal Clouds, Federated Identity&lt;br /&gt;
* trust frameworks; business development, ecosystem operations, socialization of identity ecosystems&lt;br /&gt;
* How to create first class digital citizens&lt;br /&gt;
* The latest trend of identity, privacy and users' behavior&lt;br /&gt;
* I hope to learn about the new trends and ideas in identity management.&lt;br /&gt;
* government use-cases in identity&lt;br /&gt;
* Liability for CSPs&lt;br /&gt;
* Broaden my knowledge of the project in the community.&lt;br /&gt;
* Collaborate with others to advance the state of digital identity&lt;br /&gt;
* Legal/security/international aspects of privacy&lt;br /&gt;
* Cooperation between suppliers of identity servicesMeasuring trust&lt;br /&gt;
* NSTIC, privacy, ID and mobile, OAuth, SCIM, FIDO, OpenID, two-factor authN, authorization,&lt;br /&gt;
* OIX, OpenID Connect, and mostly learning more about what our peers are doing in this space.&lt;br /&gt;
* Find Likeminds and connect with the Personal Cloud movement.&lt;br /&gt;
* anything that will usher in the personal data ecosystem and the API of Me&lt;br /&gt;
* OAuth Interop Requirements Discussion&lt;br /&gt;
* Trends in social login (adoption, consent rejection, etc.); new developments in identity management; consumer sentiment of social logins&lt;br /&gt;
* Emerging technologies in the web federated identity space.&lt;br /&gt;
* Personal data stores, models for personal data monetization&lt;br /&gt;
* Open ID Connect 101Fido Alliance 101OAuth 101SCIM 101Identity Governance and Compliance Regulations&lt;br /&gt;
* 2FA&lt;br /&gt;
* PDEC. Emmet. Personal Clouds.&lt;br /&gt;
* identity issues&lt;br /&gt;
* new initiatives and frameworks&lt;br /&gt;
* personal clouds&lt;br /&gt;
* UMA, OIDC, patient consent, ABAC&lt;br /&gt;
* standards, interop, peer-to-peer solution&lt;br /&gt;
 &lt;br /&gt;
'''What are the critical questions about user-centric identity and data you hope to discuss with peers at IIW.'''&lt;br /&gt;
* how to kickstart user centric solutions&lt;br /&gt;
* Ostracism enabling structures for stronger privacy management.  Graph Databases Management Systems.  Approaches to user controlled indexing in a federated web. &lt;br /&gt;
* How to assert ownership of one's own Digital Breadcrumbs&lt;br /&gt;
* Authentication level&lt;br /&gt;
* How to activate free market for personal data - what could be biggest enablers&lt;br /&gt;
* Who has working code and where can I download/test it?&lt;br /&gt;
* Device centric authentication&lt;br /&gt;
* how to socialize trust frameworks between private corporations and public government?- what are the implications of economy of scale of maturing ecosystem onboarding additional participants in regards to early adopters?&lt;br /&gt;
* How can the current system of walled-garden approach of digital commence be changed to allow for digital identity autonomy and dignity&lt;br /&gt;
* Will new cryptographic technologies, like Attribute Based Credentials (Anonymous Credentials) like U-Prove and Identity Mixer change the picture of identity management? &lt;br /&gt;
* trusted identities, provenance of data&lt;br /&gt;
* What are the best initial apps for personal clouds?What's the best way to drive adoption of personal clouds?&lt;br /&gt;
* How can Identity migrate to business-centric controls?BYOD Identity management is in its infancy. What's next?&lt;br /&gt;
* How can Identity migrate to business-centric controls?&lt;br /&gt;
* OpenID Connect, Account Chooser, JWT, JOSE&lt;br /&gt;
* Nature of identity - it's not your name!&lt;br /&gt;
* All the above&lt;br /&gt;
* The obstacles to adoption of Federated Identity.&lt;br /&gt;
* How to improve the experience around authorized sharing of customer information while maintaining customer trust.&lt;br /&gt;
* Once we build Personal Data Stores, and the ability for individuals to choose how to share there data... what regulations and laws need to be in place to make sure those who the data is shared with don't miss use or use without individual's permission?  What laws/regulations do we as an industry need to be lobbing for now and in the future?&lt;br /&gt;
* IDP/RP longterm relationship&lt;br /&gt;
* How to build apps and business models that don't leak our data into the world.&lt;br /&gt;
* how we can make assertions about ourselves and have them verified&lt;br /&gt;
* personal clouds&lt;br /&gt;
* UMA, OIDC, patient consent, ABAC&lt;br /&gt;
* standards, interop, peer-to-peer&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_17_Proposed_Topics&amp;diff=19372</id>
		<title>IIW 17 Proposed Topics</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_17_Proposed_Topics&amp;diff=19372"/>
		<updated>2013-10-17T01:00:43Z</updated>

		<summary type="html">&lt;p&gt;=markus: FreedomBox, IndieBox, etc.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
'''What topics are you planning to present about or lead a discussion about at this IIW?'''&lt;br /&gt;
* Personal Cloud&lt;br /&gt;
* Alternative concepts to data &amp;quot;ownership&amp;quot;&lt;br /&gt;
* StarTier&lt;br /&gt;
* Attribute Assurance, Publicly Discoverable ePayment Addresses; Private cloud; Revocation issues in globally synchronized registries; Regulatory issues in globally synchronized registries&lt;br /&gt;
* Attribute Exchange&lt;br /&gt;
* Security, Internet of Things, Personal Clouds&lt;br /&gt;
* Privacy of deceased users&lt;br /&gt;
* government use-cases in identity&lt;br /&gt;
* CSPs (Cloud Service Providers) for personal cloudsRespect ConnectPractical XDI&lt;br /&gt;
* Mobile MDM vs Sandbox - Which is best for BYOD?Business-centric Identity Policies - Will IT have to give up control?Identity Cube -Describing multidimensional relationships.Merging Identity rules, policies, entitlements with workflows.Case Study: How the IRS of  Mexico is re-inventing with IdentityBYOD Identity is in it's infancy. What's coming next?&lt;br /&gt;
* OpenID Connect, JWT, JOSE&lt;br /&gt;
* Individual sovereignty over ID, Data and Communication - concepts and technology&lt;br /&gt;
* Using Personal Clouds to remove the need for usercodes/passwordsFinancing Development through issuing interest bearing, inflation adjusted creditsPaying people for personal information&lt;br /&gt;
* OpendID Connect&lt;br /&gt;
* Personal Clouds&lt;br /&gt;
* We'll be presenting our Personal Cloud Appliance.&lt;br /&gt;
* Personal Data @ Rest&lt;br /&gt;
* Personal data monetization models&lt;br /&gt;
* Getting involved in the IDESG - Identity Ecosystem Steering Group/NSTIC &lt;br /&gt;
* How Religion and Cultural Context influence Identity System Architecture and Design&lt;br /&gt;
* Paddy. Private Clouds.&lt;br /&gt;
* verified identityself identity&lt;br /&gt;
* OAuth, especially its security properties&lt;br /&gt;
* personal clouds&lt;br /&gt;
* Alignment Trust Frameworks&lt;br /&gt;
* How to introduce new identity technologies, standards and expectations to 6-20% of the online US population in one fell swoop.&lt;br /&gt;
 &lt;br /&gt;
'''What are you hoping to learn about or hear a presentation about at IIW?'''&lt;br /&gt;
* vendor relation management personal clouds openid connect account chooser&lt;br /&gt;
* Application architectures for the next internet.&lt;br /&gt;
* Private Cloud; Open Access&lt;br /&gt;
* Trust frameworks,&lt;br /&gt;
* Personal Clouds, Federated Identity&lt;br /&gt;
* trust frameworks; business development, ecosystem operations, socialization of identity ecosystems&lt;br /&gt;
* How to create first class digital citizens&lt;br /&gt;
* The latest trend of identity, privacy and users' behavior&lt;br /&gt;
* I hope to learn about the new trends and ideas in identity management.&lt;br /&gt;
* government use-cases in identity&lt;br /&gt;
* Liability for CSPs&lt;br /&gt;
* Broaden my knowledge of the project in the community.&lt;br /&gt;
* Collaborate with others to advance the state of digital identity&lt;br /&gt;
* Legal/security/international aspects of privacy&lt;br /&gt;
* Cooperation between suppliers of identity servicesMeasuring trust&lt;br /&gt;
* NSTIC, privacy, ID and mobile, OAuth, SCIM, FIDO, OpenID, two-factor authN, authorization,&lt;br /&gt;
* OIX, OpenID Connect, and mostly learning more about what our peers are doing in this space.&lt;br /&gt;
* Find Likeminds and connect with the Personal Cloud movement.&lt;br /&gt;
* anything that will usher in the personal data ecosystem and the API of Me&lt;br /&gt;
* OAuth Interop Requirements Discussion&lt;br /&gt;
* Trends in social login (adoption, consent rejection, etc.); new developments in identity management; consumer sentiment of social logins&lt;br /&gt;
* Emerging technologies in the web federated identity space.&lt;br /&gt;
* Personal data stores, models for personal data monetization&lt;br /&gt;
* Open ID Connect 101Fido Alliance 101OAuth 101SCIM 101Identity Governance and Compliance Regulations&lt;br /&gt;
* 2FA&lt;br /&gt;
* PDEC. Emmet. Personal Clouds.&lt;br /&gt;
* identity issues&lt;br /&gt;
* new initiatives and frameworks&lt;br /&gt;
* personal clouds&lt;br /&gt;
* UMA, OIDC, patient consent, ABAC&lt;br /&gt;
* standards, interop, peer-to-peer solution&lt;br /&gt;
 &lt;br /&gt;
'''What are the critical questions about user-centric identity and data you hope to discuss with peers at IIW.'''&lt;br /&gt;
* how to kickstart user centric solutions&lt;br /&gt;
* Ostracism enabling structures for stronger privacy management.  Graph Databases Management Systems.  Approaches to user controlled indexing in a federated web. &lt;br /&gt;
* How to assert ownership of one's own Digital Breadcrumbs&lt;br /&gt;
* Authentication level&lt;br /&gt;
* How to activate free market for personal data - what could be biggest enablers&lt;br /&gt;
* Who has working code and where can I download/test it?&lt;br /&gt;
* Device centric authentication&lt;br /&gt;
* how to socialize trust frameworks between private corporations and public government?- what are the implications of economy of scale of maturing ecosystem onboarding additional participants in regards to early adopters?&lt;br /&gt;
* How can the current system of walled-garden approach of digital commence be changed to allow for digital identity autonomy and dignity&lt;br /&gt;
* Will new cryptographic technologies, like Attribute Based Credentials (Anonymous Credentials) like U-Prove and Identity Mixer change the picture of identity management? &lt;br /&gt;
* trusted identities, provenance of data&lt;br /&gt;
* What are the best initial apps for personal clouds?What's the best way to drive adoption of personal clouds?&lt;br /&gt;
* How can Identity migrate to business-centric controls?BYOD Identity management is in its infancy. What's next?&lt;br /&gt;
* How can Identity migrate to business-centric controls?&lt;br /&gt;
* OpenID Connect, Account Chooser, JWT, JOSE&lt;br /&gt;
* Nature of identity - it's not your name!&lt;br /&gt;
* All the above&lt;br /&gt;
* The obstacles to adoption of Federated Identity.&lt;br /&gt;
* How to improve the experience around authorized sharing of customer information while maintaining customer trust.&lt;br /&gt;
* Once we build Personal Data Stores, and the ability for individuals to choose how to share there data... what regulations and laws need to be in place to make sure those who the data is shared with don't miss use or use without individual's permission?  What laws/regulations do we as an industry need to be lobbing for now and in the future?&lt;br /&gt;
* IDP/RP longterm relationship&lt;br /&gt;
* How to build apps and business models that don't leak our data into the world.&lt;br /&gt;
* how we can make assertions about ourselves and have them verified&lt;br /&gt;
* personal clouds&lt;br /&gt;
* UMA, OIDC, patient consent, ABAC&lt;br /&gt;
* standards, interop, peer-to-peer&lt;br /&gt;
* FreedomBox, IndieBox, etc.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Self-Hosted_Personal_Clouds_(FreedomBox_and_Raspberry_PI)&amp;diff=19298</id>
		<title>Self-Hosted Personal Clouds (FreedomBox and Raspberry PI)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Self-Hosted_Personal_Clouds_(FreedomBox_and_Raspberry_PI)&amp;diff=19298"/>
		<updated>2013-05-16T13:52:14Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Self-Hosted Personal Clouds (FreedomBox and Raspberry PI)&lt;br /&gt;
&lt;br /&gt;
'''Thursday 4F'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
There are still many different ideas around personal clouds, but what everybody agrees on is that they are about giving individuals more control over their personal data and identity online. Therefore it seems logical that it should be possible to self-host personal clouds using appropriate hardware+software at home.&lt;br /&gt;
&lt;br /&gt;
During this lunch session, we looked at two different projects that could be relevant for this purpose.&lt;br /&gt;
&lt;br /&gt;
1. [http://ark-os.org/ http://ark-os.org/] is a Linux image for the Raspberry Pi. On its website it uses language very similar to the personal cloud community (&amp;quot;ensure your privacy&amp;quot;, &amp;quot;decentralize your web&amp;quot;). During the session we got arkOS up and running on a Pi and were able to access its web interface &amp;quot;Genesis&amp;quot;, and we experimented with some of its functionality. We couldn't find a lot of software related to the idea of &amp;quot;personal clouds&amp;quot;, but we agreed that integrating ownCloud or Tent or similar packages with Genesis would be very attractive.&lt;br /&gt;
&lt;br /&gt;
2. We set up a combination of FreedomBox + Unhosted + PageKite. The idea of the Unhosted initiative is that on the web, apps should be separate from data. When using an Unhosted app, then that app doesn't have its own backend storage. Instead, you tell it the location of your storage provider (&amp;quot;remoteStorage&amp;quot;) which you can choose yourself. Several companies currently offer remoteStorage. Your FreedomBox at home can also be your remoteStorage and therefore provide the storage for Unhosted web apps, if it runs appropriate software. In this case, the PageKite tunneling software gives your box a public IP address through which it can be reached from the Internet. During the session, we successfully set up this stack of FreedomBox, remoteStorage and PageKite, and we used the &amp;quot;SharedStuff&amp;quot; Unhosted web app as an example, which allows you to request and offer physical assets for sharing with friends.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Self-Hosted_Personal_Clouds_(FreedomBox_and_Raspberry_PI)&amp;diff=19297</id>
		<title>Self-Hosted Personal Clouds (FreedomBox and Raspberry PI)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Self-Hosted_Personal_Clouds_(FreedomBox_and_Raspberry_PI)&amp;diff=19297"/>
		<updated>2013-05-16T12:51:39Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Self-Hosted Personal Clouds (FreedomBox and Raspberry PI)&lt;br /&gt;
&lt;br /&gt;
'''Thursday 4F'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
There are still many different ideas around personal clouds, but what everybody agrees on is that they are about giving individuals more control over their personal data and identity online. Therefore it seems logical that it should be possible to self-host personal clouds using appropriate hardware+software at home.&lt;br /&gt;
&lt;br /&gt;
During this lunch session, we looked at two different projects that could be relevant for this purpose.&lt;br /&gt;
&lt;br /&gt;
1. [http://ark-os.org/ http://ark-os.org/] is a Linux image for the Raspberry Pi. On its website it uses language very similar to the personal cloud community (&amp;quot;ensure your privacy&amp;quot;, &amp;quot;decentralize your web&amp;quot;). During the session we got ark-os up and running on a Pi and were able to access its web interface &amp;quot;Genesis&amp;quot;, and we experimented with some of its functionality.&lt;br /&gt;
However we couldn't quite understand what it is that qualifies it as a &amp;quot;personal cloud&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
2. We set up a combination of FreedomBox + Unhosted + PageKite. The idea of the Unhosted initiative is that on the web, apps should be separate from data. When using an Unhosted app, then that app doesn't have its own backend storage. Instead, you tell it the location of your storage provider (&amp;quot;remoteStorage&amp;quot;) which you can choose yourself. Several companies currently offer remoteStorage. Your FreedomBox at home can also be your remoteStorage and therefore provide the storage for Unhosted web apps, if it runs appropriate software. In this case, the PageKite tunneling software gives your box a public IP address through which it can be reached from the Internet. During the session, we successfully set up this stack of FreedomBox, remoteStorage and PageKite, and we used the &amp;quot;SharedStuff&amp;quot; Unhosted web app as an example, which allows you to request and offer physical assets for sharing with friends.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Self-Hosted_Personal_Clouds_(FreedomBox_and_Raspberry_PI)&amp;diff=19296</id>
		<title>Self-Hosted Personal Clouds (FreedomBox and Raspberry PI)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Self-Hosted_Personal_Clouds_(FreedomBox_and_Raspberry_PI)&amp;diff=19296"/>
		<updated>2013-05-16T12:38:44Z</updated>

		<summary type="html">&lt;p&gt;=markus: Created page with &amp;quot;'''Session Topic:''' Self-Hosted Personal Clouds (FreedomBox and Raspberry PI)  '''Thursday 4F'''  '''Convener:''' Markus Sabadello  '''Notes-taker(s):''' Markus Sabadello  Th...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Self-Hosted Personal Clouds (FreedomBox and Raspberry PI)&lt;br /&gt;
&lt;br /&gt;
'''Thursday 4F'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
There are still many different ideas around personal clouds, but what everybody agrees on is that they are about giving individuals more control over their personal data and identity online. Therefore it seems logical that it should be possible to self-host personal clouds using appropriate hardware+software at home.&lt;br /&gt;
&lt;br /&gt;
During this lunch session, we looked at two different projects that could be relevant for this purpose.&lt;br /&gt;
&lt;br /&gt;
1. [http://ark-os.org/] is a Linux image for the Raspberry Pi. On its website it uses language very similar to the personal cloud community (&amp;quot;ensure your privacy&amp;quot;, &amp;quot;decentralize your web&amp;quot;). During the session we got ark-os up and running on a Pi and were able to access its web interface &amp;quot;Genesis&amp;quot;, and we experimented with some of its functionality.&lt;br /&gt;
However we couldn't quite understand what it is that qualifies it as a &amp;quot;personal cloud&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
2. We set up a combination of FreedomBox + Unhosted + PageKite. The idea of the Unhosted initiative is that on the web, apps should be separate from data. When using an Unhosted app, then that app doesn't have its own backend storage. Instead, you tell it the location of your storage provider (&amp;quot;remoteStorage&amp;quot;) which you can choose yourself. Several companies currently offer remoteStorage. Your FreedomBox at home can also be your remoteStorage and therefore provide the storage for Unhosted web apps, if it runs appropriate software. In this case, the PageKite tunneling software gives your box a public IP address through which it can be reached from the Internet. During the session, we successfully set up this stack of FreedomBox, remoteStorage and PageKite, and we used the &amp;quot;SharedStuff&amp;quot; Unhosted web app as an example, which allows you to request and offer physical assets for sharing with friends.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_15_Notes&amp;diff=19187</id>
		<title>IIW 15 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_15_Notes&amp;diff=19187"/>
		<updated>2012-10-30T16:54:15Z</updated>

		<summary type="html">&lt;p&gt;=markus: fixed the &amp;quot;XDI Personal Cloud Desktop&amp;quot; entry&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Tuesday, October 23, 2012 =&lt;br /&gt;
&lt;br /&gt;
== Session 1 11:00 – 12:00 == &lt;br /&gt;
&lt;br /&gt;
T1A: [[Identity Clearing House – Loosely Coupled open standards based architecture for Identiy in the extendedenterprise]]&lt;br /&gt;
&lt;br /&gt;
T1B: [[A2P3]]&lt;br /&gt;
&lt;br /&gt;
T1D: [[Rhetoric – How do we talk plain language about Identity and Personal Data?]]&lt;br /&gt;
&lt;br /&gt;
T1C: [[Privacy by Design – New Oasis Tech comm.. for Sotware Engineers]]&lt;br /&gt;
&lt;br /&gt;
T1F: [[Focus on Consumer – Turning fear into excitement, delight about Personal Data]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 12:00 – 1:00 ==&lt;br /&gt;
&lt;br /&gt;
T2A: [[Respect Network Founding Partners]]&lt;br /&gt;
&lt;br /&gt;
T2B: [[IDESG – Mgt Council CAll]]&lt;br /&gt;
&lt;br /&gt;
T2F: [[VRM Challenge: Let’s Fix Subscription Bin from Customer Side]]&lt;br /&gt;
&lt;br /&gt;
T2G: [[IDP - Initiated Layin and Deep Linking for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
T2H: [[Mobile Specific Open ID Connect use Cases]]&lt;br /&gt;
&lt;br /&gt;
T2I: [[Anonymous – political, institutional, cultural and memitc organization without identity]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 2:00 – 3:00 ==&lt;br /&gt;
&lt;br /&gt;
T3A: [[Connect Me and miiCard “Trusted Reputations”]]&lt;br /&gt;
&lt;br /&gt;
T3B: [[Account Chooser Launching – Taking the AC Show on the road this autumn – help write the show]]&lt;br /&gt;
&lt;br /&gt;
T3D: [[Authentication on Mobile Devices – Crypto and]]&lt;br /&gt;
&lt;br /&gt;
T3E: [[Collaboration, Forking, and organic proliferation in the age of the personal cloud]]&lt;br /&gt;
&lt;br /&gt;
T3F: [[Customer Commons plus VRM Brainstorm]]&lt;br /&gt;
&lt;br /&gt;
T3G: [[Death To NSTIC -2- Long Live NSTIC]]&lt;br /&gt;
&lt;br /&gt;
T3H: [[Use Cases for Personal Clouds, Community Clouds, Family Clouds]]&lt;br /&gt;
&lt;br /&gt;
T3I: [[Reputation Consulting .05 cents]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 3:00 – 4:00 ==&lt;br /&gt;
&lt;br /&gt;
T4A: [[OAuth Security (Beyond Bearer Tokens)]]&lt;br /&gt;
&lt;br /&gt;
T4B: [[NSTIC Pilot Overview – Attribute Exchange Network (AXN) / Demo]]&lt;br /&gt;
&lt;br /&gt;
T4C: [[Unleashing the Multimind – What’s next – or could be – in our most personal daily experience and utilization of all this stuff]]&lt;br /&gt;
&lt;br /&gt;
T4D: [[Building the Identity Ecosystem Framework]]&lt;br /&gt;
&lt;br /&gt;
T4F: [[Kynetx – Personal Cloud Prototype]]&lt;br /&gt;
&lt;br /&gt;
T4G: [[Consuming OpenID Connect 101]]&lt;br /&gt;
&lt;br /&gt;
== Session 5 4:00 – 5:00 == &lt;br /&gt;
&lt;br /&gt;
T5A: [[OX Open Source – OpenID Connect and UMA / Demo]]&lt;br /&gt;
&lt;br /&gt;
T5B: [[Personal Analytics and Insight for Consumers – using Personal Data to Enlighten the Individual]]&lt;br /&gt;
&lt;br /&gt;
T5D: [[How will Identity plus VRM Change Real Estate and Mortgage Banking]]&lt;br /&gt;
&lt;br /&gt;
T5F: [[Secure Identity Without Username or Password]]&lt;br /&gt;
&lt;br /&gt;
T5J: [[Location = Control Control = Ownership – How addressing establishes ownership and what to do about it]]&lt;br /&gt;
&lt;br /&gt;
T5H: [[XDI Personal Cloud Desktop]]&lt;br /&gt;
&lt;br /&gt;
= Wednesday Oct 24 = &lt;br /&gt;
&lt;br /&gt;
== Session 1 9:30 -10:30 ==&lt;br /&gt;
&lt;br /&gt;
W1A: [[Sales Force Identity – The Facebook for Business (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
W1B: [[OpenID Connect Session – Management and Login]]&lt;br /&gt;
&lt;br /&gt;
W1C: [[External Browser and Mobile Apps]]&lt;br /&gt;
&lt;br /&gt;
W1F: [[Identity and API Economy plus Privacy by Design]]&lt;br /&gt;
&lt;br /&gt;
W1G: [[The New Privacy]]&lt;br /&gt;
&lt;br /&gt;
W1H: [[Manufacturing, Registration Cards and Digital Birth Certificates]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 10:30-11:30 ==&lt;br /&gt;
&lt;br /&gt;
W2A: [[Sales Force Identity – The Facebook for Business (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
W2B: [[Hybrid Mobile/Nets App Auth With Oauth2 Trickery]]&lt;br /&gt;
&lt;br /&gt;
W2C: [[Liberating Personae from Identity]]&lt;br /&gt;
&lt;br /&gt;
W2E: [[OAOTH 2.0 RS – AS Token Query Flows]]&lt;br /&gt;
&lt;br /&gt;
W2F: [[Customer Commons - The Magic Wand Project]]&lt;br /&gt;
&lt;br /&gt;
W2G: [[Consumers and Public Records]]&lt;br /&gt;
&lt;br /&gt;
W2I: [[Personal Cloud Obstacles (continued from Tuesday)]]&lt;br /&gt;
&lt;br /&gt;
W2J: [[Personal Data Startups Connect and Catalyze – next steps and PDEC StartUp Map (stages, models, patterns)]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 11:30-12:30==&lt;br /&gt;
&lt;br /&gt;
W3A: [[Education Customers and Companies]]&lt;br /&gt;
&lt;br /&gt;
W3B: [[Google Identity Toolkey – What other problems should we research?]]&lt;br /&gt;
&lt;br /&gt;
W3C: [[Mobile SSO Password Proliferation…. Any solutions??]]&lt;br /&gt;
&lt;br /&gt;
W3D: [[SCIM]]&lt;br /&gt;
&lt;br /&gt;
W3G: [[The act1v8 Project (VRM and Trust for Charity and Community Services]]&lt;br /&gt;
&lt;br /&gt;
W3H: [[DATA COOPS and BIZ Models]]&lt;br /&gt;
&lt;br /&gt;
W3I: [[Customer 2 Business – Will Federation Really work?]]&lt;br /&gt;
&lt;br /&gt;
W3J: [[Social Intentions – Private App on Facebook to express your true intentions]]&lt;br /&gt;
&lt;br /&gt;
W3K: [[Personal Cloud Prototype (Reprise)]]&lt;br /&gt;
&lt;br /&gt;
W3L: [[Opportunities for Developers around Personal Cloud Cloudstore]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 2:30-3:30==&lt;br /&gt;
&lt;br /&gt;
W4A: [[Trusted Identities “You are who you say you are”]]&lt;br /&gt;
&lt;br /&gt;
W4B: [[OIX (Axw6) Attribute Exchange Trust Framework – Progress Report]]&lt;br /&gt;
&lt;br /&gt;
W4C: [[Attribute Exchange Technical Overview]]&lt;br /&gt;
&lt;br /&gt;
W4D: [[Health Record Banks – Personal Cloud for Health]]&lt;br /&gt;
&lt;br /&gt;
W4E: [[Investors Corner / Where Investors and Entrepreneurs Come Together]]&lt;br /&gt;
&lt;br /&gt;
W4F: [[MAKE HISTORY – Be the 1st to get a User-centric Next-gen Secure Private Identity]]&lt;br /&gt;
&lt;br /&gt;
W4G: [[Security and Permission in Personal Cloud Connections]]&lt;br /&gt;
&lt;br /&gt;
W4H: [[SCIM – As An ATTRUBUTE Provider?]]&lt;br /&gt;
&lt;br /&gt;
W4J: [[World Economic Forum: Update on ‘Rethinking Personal Data’]]&lt;br /&gt;
&lt;br /&gt;
W4L: [[Freedom Box Workshop]]&lt;br /&gt;
&lt;br /&gt;
== Session 5 3:30-4:30==&lt;br /&gt;
&lt;br /&gt;
W5A: [[OpenID Graph 1.0]]&lt;br /&gt;
&lt;br /&gt;
W5B: [[OIDF Workgroup – Account Chooser]]&lt;br /&gt;
&lt;br /&gt;
W5C: [[Beyond Prophylaxis – Next Steps post ad and tracking blocking]]&lt;br /&gt;
&lt;br /&gt;
W5F: [[KRL – XDI Integration]]&lt;br /&gt;
&lt;br /&gt;
W5G: [[correct house battery staple: Strong Passwords…. Passphrases.. are they still relevant/necessary?]]&lt;br /&gt;
&lt;br /&gt;
W5H: [[Personal Data and Gamification---Consumer use case Brainstorming focus on *Fun *Beneficial *Opt-In]]&lt;br /&gt;
&lt;br /&gt;
W5I: [[OATH 2 Dynamic Client Registration]]&lt;br /&gt;
&lt;br /&gt;
= Thursday Oct 25 =&lt;br /&gt;
&lt;br /&gt;
== Session 1 ==&lt;br /&gt;
&lt;br /&gt;
TH1D: [[Mapping the Identity Ecosystem Framework ‘A Whiter Shade of Gray” – (Input for NSTIC Plenary Next Week)]]&lt;br /&gt;
&lt;br /&gt;
TH1F: [[OAuth2 Chaining and Re-Delegation]]&lt;br /&gt;
&lt;br /&gt;
TH1G: [[Personal.Com Blog Post]]&lt;br /&gt;
&lt;br /&gt;
TH1H: [[11 Models of “Trust”]]&lt;br /&gt;
&lt;br /&gt;
TH1I: [[Education and beyond… How to mamage new Privacy Risks on Rapid Moving trends]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 ==&lt;br /&gt;
&lt;br /&gt;
TH2D: [[IDESG Mapping Prep… Source Documents and SEEDS for Mapps (NSTIC)]]&lt;br /&gt;
&lt;br /&gt;
TH2F: [[Wallets - Ours OR Google, Apple, ? (VRM)]]&lt;br /&gt;
&lt;br /&gt;
TH2G: [[A Trust Framework for Open ID Connect AND beyond…. (with Unicorns)]]&lt;br /&gt;
&lt;br /&gt;
TH2H: [[What is ‘Real Name” ?]]&lt;br /&gt;
&lt;br /&gt;
TH2I: [[High Level Programming]]&lt;br /&gt;
&lt;br /&gt;
TH2J: [[Webfinger]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 ==&lt;br /&gt;
&lt;br /&gt;
TH3F: [[OIDF Board Meeting]]&lt;br /&gt;
&lt;br /&gt;
TH3G: [[UE for ID/PDE or UX plud Tech for IDENTITY across Devices ‘1 Enterprise Experience from Browsers to Washing Machines?]]&lt;br /&gt;
&lt;br /&gt;
TH3H: [[Account Recovery: How can we do better? Without back doors?]]&lt;br /&gt;
&lt;br /&gt;
TH3I: [[Ultimate Realization of User Managed Contract / Terms and Policies Proffered by individuals]]&lt;br /&gt;
&lt;br /&gt;
TH3J: [[FED. SOC. WEB SUM.]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 ==&lt;br /&gt;
&lt;br /&gt;
TH4A: [[OAuth RoadMap (new specs, more interop, additional use cases)]]&lt;br /&gt;
&lt;br /&gt;
TH4F: [[OIDF MTG #2]]&lt;br /&gt;
&lt;br /&gt;
TH4G: [[Interesting Challenges of Bi-Directional Federated and Delegations]]&lt;br /&gt;
&lt;br /&gt;
TH4H: [[Freedom Box Workshop]]&lt;br /&gt;
&lt;br /&gt;
TH4I: [[Open Source Personal Clouds / What, Why, How]]&lt;br /&gt;
&lt;br /&gt;
== Session 5 ==&lt;br /&gt;
&lt;br /&gt;
TH5A: [[Intent Casting Prototype]]&lt;br /&gt;
&lt;br /&gt;
TH5H: [[‘Group Therapy’ Being a Pioneer and Communicating You Vision to Stakeholders]]&lt;br /&gt;
&lt;br /&gt;
TH?: [[REDDIT are there lessons for the Identity Community in recent events?]]&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_15_Notes&amp;diff=19186</id>
		<title>IIW 15 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_15_Notes&amp;diff=19186"/>
		<updated>2012-10-30T16:53:47Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Tuesday, October 23, 2012 =&lt;br /&gt;
&lt;br /&gt;
== Session 1 11:00 – 12:00 == &lt;br /&gt;
&lt;br /&gt;
T1A: [[Identity Clearing House – Loosely Coupled open standards based architecture for Identiy in the extendedenterprise]]&lt;br /&gt;
&lt;br /&gt;
T1B: [[A2P3]]&lt;br /&gt;
&lt;br /&gt;
T1D: [[Rhetoric – How do we talk plain language about Identity and Personal Data?]]&lt;br /&gt;
&lt;br /&gt;
T1C: [[Privacy by Design – New Oasis Tech comm.. for Sotware Engineers]]&lt;br /&gt;
&lt;br /&gt;
T1F: [[Focus on Consumer – Turning fear into excitement, delight about Personal Data]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 12:00 – 1:00 ==&lt;br /&gt;
&lt;br /&gt;
T2A: [[Respect Network Founding Partners]]&lt;br /&gt;
&lt;br /&gt;
T2B: [[IDESG – Mgt Council CAll]]&lt;br /&gt;
&lt;br /&gt;
T2F: [[VRM Challenge: Let’s Fix Subscription Bin from Customer Side]]&lt;br /&gt;
&lt;br /&gt;
T2G: [[IDP - Initiated Layin and Deep Linking for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
T2H: [[Mobile Specific Open ID Connect use Cases]]&lt;br /&gt;
&lt;br /&gt;
T2I: [[Anonymous – political, institutional, cultural and memitc organization without identity]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 2:00 – 3:00 ==&lt;br /&gt;
&lt;br /&gt;
T3A: [[Connect Me and miiCard “Trusted Reputations”]]&lt;br /&gt;
&lt;br /&gt;
T3B: [[Account Chooser Launching – Taking the AC Show on the road this autumn – help write the show]]&lt;br /&gt;
&lt;br /&gt;
T3D: [[Authentication on Mobile Devices – Crypto and]]&lt;br /&gt;
&lt;br /&gt;
T3E: [[Collaboration, Forking, and organic proliferation in the age of the personal cloud]]&lt;br /&gt;
&lt;br /&gt;
T3F: [[Customer Commons plus VRM Brainstorm]]&lt;br /&gt;
&lt;br /&gt;
T3G: [[Death To NSTIC -2- Long Live NSTIC]]&lt;br /&gt;
&lt;br /&gt;
T3H: [[Use Cases for Personal Clouds, Community Clouds, Family Clouds]]&lt;br /&gt;
&lt;br /&gt;
T3I: [[Reputation Consulting .05 cents]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 3:00 – 4:00 ==&lt;br /&gt;
&lt;br /&gt;
T4A: [[OAuth Security (Beyond Bearer Tokens)]]&lt;br /&gt;
&lt;br /&gt;
T4B: [[NSTIC Pilot Overview – Attribute Exchange Network (AXN) / Demo]]&lt;br /&gt;
&lt;br /&gt;
T4C: [[Unleashing the Multimind – What’s next – or could be – in our most personal daily experience and utilization of all this stuff]]&lt;br /&gt;
&lt;br /&gt;
T4D: [[Building the Identity Ecosystem Framework]]&lt;br /&gt;
&lt;br /&gt;
T4F: [[Kynetx – Personal Cloud Prototype]]&lt;br /&gt;
&lt;br /&gt;
T4G: [[Consuming OpenID Connect 101]]&lt;br /&gt;
&lt;br /&gt;
== Session 5 4:00 – 5:00 == &lt;br /&gt;
&lt;br /&gt;
T5A: [[OX Open Source – OpenID Connect and UMA / Demo]]&lt;br /&gt;
&lt;br /&gt;
T5B: [[Personal Analytics and Insight for Consumers – using Personal Data to Enlighten the Individual]]&lt;br /&gt;
&lt;br /&gt;
T5D: [[How will Identity plus VRM Change Real Estate and Mortgage Banking]]&lt;br /&gt;
&lt;br /&gt;
T5F: [[Secure Identity Without Username or Password]]&lt;br /&gt;
&lt;br /&gt;
T5J: [[Location = Control Control = Ownership – How addressing establishes ownership and what to do about it&lt;br /&gt;
&lt;br /&gt;
T5H: [[XDI Personal Cloud Desktop]]&lt;br /&gt;
&lt;br /&gt;
= Wednesday Oct 24 = &lt;br /&gt;
&lt;br /&gt;
== Session 1 9:30 -10:30 ==&lt;br /&gt;
&lt;br /&gt;
W1A: [[Sales Force Identity – The Facebook for Business (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
W1B: [[OpenID Connect Session – Management and Login]]&lt;br /&gt;
&lt;br /&gt;
W1C: [[External Browser and Mobile Apps]]&lt;br /&gt;
&lt;br /&gt;
W1F: [[Identity and API Economy plus Privacy by Design]]&lt;br /&gt;
&lt;br /&gt;
W1G: [[The New Privacy]]&lt;br /&gt;
&lt;br /&gt;
W1H: [[Manufacturing, Registration Cards and Digital Birth Certificates]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 10:30-11:30 ==&lt;br /&gt;
&lt;br /&gt;
W2A: [[Sales Force Identity – The Facebook for Business (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
W2B: [[Hybrid Mobile/Nets App Auth With Oauth2 Trickery]]&lt;br /&gt;
&lt;br /&gt;
W2C: [[Liberating Personae from Identity]]&lt;br /&gt;
&lt;br /&gt;
W2E: [[OAOTH 2.0 RS – AS Token Query Flows]]&lt;br /&gt;
&lt;br /&gt;
W2F: [[Customer Commons - The Magic Wand Project]]&lt;br /&gt;
&lt;br /&gt;
W2G: [[Consumers and Public Records]]&lt;br /&gt;
&lt;br /&gt;
W2I: [[Personal Cloud Obstacles (continued from Tuesday)]]&lt;br /&gt;
&lt;br /&gt;
W2J: [[Personal Data Startups Connect and Catalyze – next steps and PDEC StartUp Map (stages, models, patterns)]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 11:30-12:30==&lt;br /&gt;
&lt;br /&gt;
W3A: [[Education Customers and Companies]]&lt;br /&gt;
&lt;br /&gt;
W3B: [[Google Identity Toolkey – What other problems should we research?]]&lt;br /&gt;
&lt;br /&gt;
W3C: [[Mobile SSO Password Proliferation…. Any solutions??]]&lt;br /&gt;
&lt;br /&gt;
W3D: [[SCIM]]&lt;br /&gt;
&lt;br /&gt;
W3G: [[The act1v8 Project (VRM and Trust for Charity and Community Services]]&lt;br /&gt;
&lt;br /&gt;
W3H: [[DATA COOPS and BIZ Models]]&lt;br /&gt;
&lt;br /&gt;
W3I: [[Customer 2 Business – Will Federation Really work?]]&lt;br /&gt;
&lt;br /&gt;
W3J: [[Social Intentions – Private App on Facebook to express your true intentions]]&lt;br /&gt;
&lt;br /&gt;
W3K: [[Personal Cloud Prototype (Reprise)]]&lt;br /&gt;
&lt;br /&gt;
W3L: [[Opportunities for Developers around Personal Cloud Cloudstore]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 2:30-3:30==&lt;br /&gt;
&lt;br /&gt;
W4A: [[Trusted Identities “You are who you say you are”]]&lt;br /&gt;
&lt;br /&gt;
W4B: [[OIX (Axw6) Attribute Exchange Trust Framework – Progress Report]]&lt;br /&gt;
&lt;br /&gt;
W4C: [[Attribute Exchange Technical Overview]]&lt;br /&gt;
&lt;br /&gt;
W4D: [[Health Record Banks – Personal Cloud for Health]]&lt;br /&gt;
&lt;br /&gt;
W4E: [[Investors Corner / Where Investors and Entrepreneurs Come Together]]&lt;br /&gt;
&lt;br /&gt;
W4F: [[MAKE HISTORY – Be the 1st to get a User-centric Next-gen Secure Private Identity]]&lt;br /&gt;
&lt;br /&gt;
W4G: [[Security and Permission in Personal Cloud Connections]]&lt;br /&gt;
&lt;br /&gt;
W4H: [[SCIM – As An ATTRUBUTE Provider?]]&lt;br /&gt;
&lt;br /&gt;
W4J: [[World Economic Forum: Update on ‘Rethinking Personal Data’]]&lt;br /&gt;
&lt;br /&gt;
W4L: [[Freedom Box Workshop]]&lt;br /&gt;
&lt;br /&gt;
== Session 5 3:30-4:30==&lt;br /&gt;
&lt;br /&gt;
W5A: [[OpenID Graph 1.0]]&lt;br /&gt;
&lt;br /&gt;
W5B: [[OIDF Workgroup – Account Chooser]]&lt;br /&gt;
&lt;br /&gt;
W5C: [[Beyond Prophylaxis – Next Steps post ad and tracking blocking]]&lt;br /&gt;
&lt;br /&gt;
W5F: [[KRL – XDI Integration]]&lt;br /&gt;
&lt;br /&gt;
W5G: [[correct house battery staple: Strong Passwords…. Passphrases.. are they still relevant/necessary?]]&lt;br /&gt;
&lt;br /&gt;
W5H: [[Personal Data and Gamification---Consumer use case Brainstorming focus on *Fun *Beneficial *Opt-In]]&lt;br /&gt;
&lt;br /&gt;
W5I: [[OATH 2 Dynamic Client Registration]]&lt;br /&gt;
&lt;br /&gt;
= Thursday Oct 25 =&lt;br /&gt;
&lt;br /&gt;
== Session 1 ==&lt;br /&gt;
&lt;br /&gt;
TH1D: [[Mapping the Identity Ecosystem Framework ‘A Whiter Shade of Gray” – (Input for NSTIC Plenary Next Week)]]&lt;br /&gt;
&lt;br /&gt;
TH1F: [[OAuth2 Chaining and Re-Delegation]]&lt;br /&gt;
&lt;br /&gt;
TH1G: [[Personal.Com Blog Post]]&lt;br /&gt;
&lt;br /&gt;
TH1H: [[11 Models of “Trust”]]&lt;br /&gt;
&lt;br /&gt;
TH1I: [[Education and beyond… How to mamage new Privacy Risks on Rapid Moving trends]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 ==&lt;br /&gt;
&lt;br /&gt;
TH2D: [[IDESG Mapping Prep… Source Documents and SEEDS for Mapps (NSTIC)]]&lt;br /&gt;
&lt;br /&gt;
TH2F: [[Wallets - Ours OR Google, Apple, ? (VRM)]]&lt;br /&gt;
&lt;br /&gt;
TH2G: [[A Trust Framework for Open ID Connect AND beyond…. (with Unicorns)]]&lt;br /&gt;
&lt;br /&gt;
TH2H: [[What is ‘Real Name” ?]]&lt;br /&gt;
&lt;br /&gt;
TH2I: [[High Level Programming]]&lt;br /&gt;
&lt;br /&gt;
TH2J: [[Webfinger]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 ==&lt;br /&gt;
&lt;br /&gt;
TH3F: [[OIDF Board Meeting]]&lt;br /&gt;
&lt;br /&gt;
TH3G: [[UE for ID/PDE or UX plud Tech for IDENTITY across Devices ‘1 Enterprise Experience from Browsers to Washing Machines?]]&lt;br /&gt;
&lt;br /&gt;
TH3H: [[Account Recovery: How can we do better? Without back doors?]]&lt;br /&gt;
&lt;br /&gt;
TH3I: [[Ultimate Realization of User Managed Contract / Terms and Policies Proffered by individuals]]&lt;br /&gt;
&lt;br /&gt;
TH3J: [[FED. SOC. WEB SUM.]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 ==&lt;br /&gt;
&lt;br /&gt;
TH4A: [[OAuth RoadMap (new specs, more interop, additional use cases)]]&lt;br /&gt;
&lt;br /&gt;
TH4F: [[OIDF MTG #2]]&lt;br /&gt;
&lt;br /&gt;
TH4G: [[Interesting Challenges of Bi-Directional Federated and Delegations]]&lt;br /&gt;
&lt;br /&gt;
TH4H: [[Freedom Box Workshop]]&lt;br /&gt;
&lt;br /&gt;
TH4I: [[Open Source Personal Clouds / What, Why, How]]&lt;br /&gt;
&lt;br /&gt;
== Session 5 ==&lt;br /&gt;
&lt;br /&gt;
TH5A: [[Intent Casting Prototype]]&lt;br /&gt;
&lt;br /&gt;
TH5H: [[‘Group Therapy’ Being a Pioneer and Communicating You Vision to Stakeholders]]&lt;br /&gt;
&lt;br /&gt;
TH?: [[REDDIT are there lessons for the Identity Community in recent events?]]&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Freedom_Box_Workshop&amp;diff=19185</id>
		<title>Freedom Box Workshop</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Freedom_Box_Workshop&amp;diff=19185"/>
		<updated>2012-10-30T11:34:18Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic: FreedomBox Workshop'''&lt;br /&gt;
&lt;br /&gt;
'''Thursday 4H'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
During this relaxed lunchtime session, we looked at the current state of the FreedomBox project, which is about creating a simple plug computer that protects your privacy online and gives you control over your personal data. Among other things, a FreedomBox can be used as a Personal Data Store / Personal Cloud.&lt;br /&gt;
&lt;br /&gt;
We had 2 Dreamplugs, 3 Guruplugs and a Raspberry Pi, which are all potential hardware platforms for the project.&lt;br /&gt;
&lt;br /&gt;
We discussed two basic functions of the FreedomBox:&lt;br /&gt;
&lt;br /&gt;
# The FreedomBox can be used as a gateway between one's home network and an Internet connection. In this case, the purpose of the FreedomBox is to filter Internet traffic, and to remove ads as well as tracking scripts from web pages. This is done using a variant of the Privoxy software.&lt;br /&gt;
# The FreedomBox also aligns well with the Unhosted project, whose idea is to separate applications from data on the Internet. With Unhosted apps, a user is given a &amp;quot;remoteStorage&amp;quot; account (i.e. a kind of personal data store). Unhosted apps then use that remoteStorage for all their data storage needs. RemoteStorages can be chosen from a number of existing providers, or self-hosted. Or in our case, the FreedomBox could be one's remoteStorage, which basically means that you can run applications on the web, but have their associated data stored on your box at home.&lt;br /&gt;
&lt;br /&gt;
Many more plans and ideas for the FreedomBox exist.&lt;br /&gt;
&lt;br /&gt;
We had great discussions about some of these ideas, and we considered the feasibility of productizing the FreedomBox.&lt;br /&gt;
&lt;br /&gt;
[[File:iiw15-freedombox.jpg]]&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:Iiw15-freedombox.jpg&amp;diff=19184</id>
		<title>File:Iiw15-freedombox.jpg</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:Iiw15-freedombox.jpg&amp;diff=19184"/>
		<updated>2012-10-30T11:33:21Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Freedom_Box_Workshop&amp;diff=19183</id>
		<title>Freedom Box Workshop</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Freedom_Box_Workshop&amp;diff=19183"/>
		<updated>2012-10-30T11:32:10Z</updated>

		<summary type="html">&lt;p&gt;=markus: Created page with &amp;quot;'''Session Topic: FreedomBox Workshop'''  '''Thursday 4H'''  '''Convener:''' Markus Sabadello  '''Notes-taker(s):''' Markus Sabadello  During this relaxed lunchtime session, w...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic: FreedomBox Workshop'''&lt;br /&gt;
&lt;br /&gt;
'''Thursday 4H'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
During this relaxed lunchtime session, we looked at the current state of the FreedomBox project, which is about creating a simple plug computer that protects your privacy online and gives you control over your personal data. Among other things, a FreedomBox can be used as a Personal Data Store / Personal Cloud.&lt;br /&gt;
&lt;br /&gt;
We had 2 Dreamplugs, 3 Guruplugs and a Raspberry Pi, which are all potential hardware platforms for the project.&lt;br /&gt;
&lt;br /&gt;
We discussed two basic functions of the FreedomBox:&lt;br /&gt;
&lt;br /&gt;
# The FreedomBox can be used as a gateway between one's home network and an Internet connection. In this case, the purpose of the FreedomBox is to filter Internet traffic, and to remove ads as well as tracking scripts from web pages. This is done using a variant of the Privoxy software.&lt;br /&gt;
# The FreedomBox also aligns well with the Unhosted project, whose idea is to separate applications from data on the Internet. With Unhosted apps, a user is given a &amp;quot;remoteStorage&amp;quot; account (i.e. a kind of personal data store). Unhosted apps then use that remoteStorage for all their data storage needs. RemoteStorages can be chosen from a number of existing providers, or self-hosted. Or in our case, the FreedomBox could be one's remoteStorage, which basically means that you can run applications on the web, but have their associated data stored on your box at home.&lt;br /&gt;
&lt;br /&gt;
Many more plans and ideas for the FreedomBox exist.&lt;br /&gt;
&lt;br /&gt;
We had great discussions about some of these ideas, and we considered the feasibility of productizing the FreedomBox.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:Iiw15-fedsocweb.jpg&amp;diff=19182</id>
		<title>File:Iiw15-fedsocweb.jpg</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:Iiw15-fedsocweb.jpg&amp;diff=19182"/>
		<updated>2012-10-30T08:54:42Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Webfinger&amp;diff=19181</id>
		<title>Webfinger</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Webfinger&amp;diff=19181"/>
		<updated>2012-10-30T08:54:24Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic: Webfinger'''&lt;br /&gt;
&lt;br /&gt;
'''Thursday 2J'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Evan Prodromou&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
Evan gave an overview of the Webfinger process.&lt;br /&gt;
The idea is that you discover information about an entity in a two-step process, which involves retrieving XRD documents from a well-known location.&lt;br /&gt;
Problem: 2 round trips are required.&lt;br /&gt;
&lt;br /&gt;
There's a philosophical difference between Webfinger and Simple Web Discovery (SWD).&lt;br /&gt;
* Webfinger: You retrieve a document.&lt;br /&gt;
* SWD: You ask for a specific thing.&lt;br /&gt;
&lt;br /&gt;
In more recent drafts of Webfinger however, the query parameters &amp;quot;resource&amp;quot; and &amp;quot;rel&amp;quot; are supported, which pushes work to the server and eliminates one roundtrip. This makes it more similar to SWD.&lt;br /&gt;
&lt;br /&gt;
The concern within the OpenID Connect community is that the discovery process must be simple enough.&lt;br /&gt;
&lt;br /&gt;
Likely scenario: Have both in the foreseeable future?&lt;br /&gt;
&lt;br /&gt;
Webfinger has JSON now, but didn't have it when SWD was invented.&lt;br /&gt;
&lt;br /&gt;
Latest Webfinger draft: &lt;br /&gt;
* XRD is moved to appendix, JSON is preferred &lt;br /&gt;
* It's possible to retrieve either host-meta.json or host-meta with &amp;quot;json&amp;quot; Accept header. --&amp;gt; confusing?&lt;br /&gt;
* JRD should be required, XRD optional&lt;br /&gt;
&lt;br /&gt;
Both Webfinger and SWD are likely to co-exist for a while.&lt;br /&gt;
&lt;br /&gt;
Questions about the case when multiple links/locations are discovered:&lt;br /&gt;
&lt;br /&gt;
# Which one should be picked?&lt;br /&gt;
# In the original XRDS format, there was &amp;quot;priority&amp;quot;.&lt;br /&gt;
# Maybe in Webfinger just try the locations sequentially?&lt;br /&gt;
&lt;br /&gt;
Doubts whether major players will support the latest Webfinger?&lt;br /&gt;
&lt;br /&gt;
Major players currently don't support SWD, but will probably in the future.&lt;br /&gt;
&lt;br /&gt;
Kynetx use-case: Need to discover someone's Personal Cloud, which involves an &amp;quot;event channel&amp;quot; GUID. A custom &amp;quot;rel&amp;quot; type is used in the JRD. The GUID is stored as the &amp;quot;href&amp;quot; field in the JRD. You can also have &amp;quot;properties&amp;quot; in an XRD/JRD, i.e. key/value pairs associated with the resource.&lt;br /&gt;
&lt;br /&gt;
Advice: Vision of Webfinger is that you would have many more &amp;quot;rel&amp;quot;s for everything, e.g. blog updates, profile page, etc., rather than just the &amp;quot;event channel&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Reminder: Webfinger addresses are not necessarily e-mail addresses. The idea was to use identifiers that look familiar to users. Internally, they use the acct: URI scheme, but that's not exposed to the user. Webfinger can not only be used with acct: URIs, but with any URI from which you can extract a domain name.&lt;br /&gt;
&lt;br /&gt;
All information in Webfinger is public, which may be a good or bad thing. Is there a need for private discovery? Is there a need to authenticate a client before formulating the Webfinger response?&lt;br /&gt;
&lt;br /&gt;
Another related effort: Dialback Access Authentication, to authenticate HTTP requests based on a Webfinger discovery system. Drawback: A roundtrip is required to verify the request.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Webfinger&amp;diff=19180</id>
		<title>Webfinger</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Webfinger&amp;diff=19180"/>
		<updated>2012-10-30T08:52:23Z</updated>

		<summary type="html">&lt;p&gt;=markus: Created page with &amp;quot;'''Session Topic: Webfinger'''  '''Thursday 2J'''  '''Convener:''' Evan Prodromou  '''Notes-taker(s):''' Markus Sabadello  Evan gave an overview of the Webfinger process. The ...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic: Webfinger'''&lt;br /&gt;
&lt;br /&gt;
'''Thursday 2J'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Evan Prodromou&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
Evan gave an overview of the Webfinger process.&lt;br /&gt;
The idea is that you discover information about an entity in a two-step process, which involves retrieving XRD documents from a well-known location.&lt;br /&gt;
Problem: 2 round trips are required.&lt;br /&gt;
&lt;br /&gt;
There's a philosophical difference between Webfinger and Simple Web Discovery (SWD).&lt;br /&gt;
* Webfinger: You retrieve a document.&lt;br /&gt;
* SWD: You ask for a specific thing.&lt;br /&gt;
&lt;br /&gt;
In more recent drafts of Webfinger however, the query parameters &amp;quot;resource&amp;quot; and &amp;quot;rel&amp;quot; are supported, which pushes work to the server and eliminates one roundtrip. This makes it more similar to SWD.&lt;br /&gt;
&lt;br /&gt;
The concern within the OpenID Connect community is that the discovery process must be simple enough.&lt;br /&gt;
&lt;br /&gt;
Currently: 3rd IETF draft.&lt;br /&gt;
&lt;br /&gt;
Likely scenario: Have both in the foreseeable future?&lt;br /&gt;
&lt;br /&gt;
Webfinger has JSON now, but didn't have it when SWD was invented.&lt;br /&gt;
&lt;br /&gt;
Latest Webfinger draft: &lt;br /&gt;
* XRD is moved to appendix, JSON is preferred &lt;br /&gt;
* It's possible to retrieve either host-meta.json or host-meta with &amp;quot;json&amp;quot; Accept header. --&amp;gt; confusing?&lt;br /&gt;
* JRD should be required, XRD optional&lt;br /&gt;
&lt;br /&gt;
Both Webfinger and SWD are likely to co-exist for a while.&lt;br /&gt;
&lt;br /&gt;
Questions about the case when multiple links/locations are discovered:&lt;br /&gt;
&lt;br /&gt;
# Which one should be picked?&lt;br /&gt;
# In the original XRDS format, there was &amp;quot;priority&amp;quot;.&lt;br /&gt;
# Maybe in Webfinger just try the locations sequentially?&lt;br /&gt;
&lt;br /&gt;
Doubts whether major players will support the latest Webfinger?&lt;br /&gt;
&lt;br /&gt;
Major players currently don't support SWD, but will probably in the future.&lt;br /&gt;
&lt;br /&gt;
Kynetx use-case: Need to discover someone's Personal Cloud, which involves an &amp;quot;event channel&amp;quot; GUID. A custom &amp;quot;rel&amp;quot; type is used in the JRD. The GUID is stored as the &amp;quot;href&amp;quot; field in the JRD. You can also have &amp;quot;properties&amp;quot; in an XRD/JRD, i.e. key/value pairs associated with the resource.&lt;br /&gt;
&lt;br /&gt;
Advice: Vision of Webfinger is that you would have many more &amp;quot;rel&amp;quot;s for everything, e.g. blog updates, profile page, etc., rather than just the &amp;quot;event channel&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Reminder: Webfinger addresses are not necessarily e-mail addresses. The idea was to use identifiers that look familiar to users. Internally, they use the acct: URI scheme, but that's not exposed to the user. Webfinger can not only be used with acct: URIs, but with any URI from which you can extract a domain name.&lt;br /&gt;
&lt;br /&gt;
All information in Webfinger is public, which may be a good or bad thing. Is there a need for private discovery? Is there a need to authenticate a client before formulating the Webfinger response?&lt;br /&gt;
&lt;br /&gt;
Another related effort: Dialback Access Authentication, to authenticate HTTP requests based on a Webfinger discovery system. Drawback: A roundtrip is required to verify the request.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=FED._SOC._WEB_SUM.&amp;diff=19179</id>
		<title>FED. SOC. WEB SUM.</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=FED._SOC._WEB_SUM.&amp;diff=19179"/>
		<updated>2012-10-30T08:41:08Z</updated>

		<summary type="html">&lt;p&gt;=markus: Created page with &amp;quot;'''Session Topic: Federated Social Web Summit'''  '''Thursday 3J'''  '''Convener:''' Evan Prodromou  '''Notes-taker(s):''' Markus Sabadello  Goal: Provide social web functiona...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic: Federated Social Web Summit'''&lt;br /&gt;
&lt;br /&gt;
'''Thursday 3J'''&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Evan Prodromou&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
Goal: Provide social web functionality without dependency on a single system. In other words, have a topology like e-mail.&lt;br /&gt;
&lt;br /&gt;
Functions of the federated social web:&lt;br /&gt;
# identity&lt;br /&gt;
# profile information&lt;br /&gt;
# social graph (friends, etc.)&lt;br /&gt;
# content (blog, documents, rich media)&lt;br /&gt;
# activity stream&lt;br /&gt;
# publication and subscription model&lt;br /&gt;
&lt;br /&gt;
Technologies: FOAF, XFN, RSS/Atom/..., &lt;br /&gt;
&lt;br /&gt;
Projects: StatusNet, Diaspora, Appleseed, tent.io&lt;br /&gt;
&lt;br /&gt;
Current mentality: Build one piece of software that can do everything, with its own protocol, extensions, etc. This approach has resulted in some disappointment.&lt;br /&gt;
&lt;br /&gt;
Better approach? Agree on an extensible protocol supported by multiple implementations. This was the idea behind OStatus (= a suite of protocols: OStatus, Webfinger, ActivityStreams, PubSubHubbub, Salmon). This is different from earlier &amp;quot;monolithic&amp;quot; approaches. OStatus has been successful and is widely supported, e.g. by Wordpress.&lt;br /&gt;
&lt;br /&gt;
Problems of current OStatus? &lt;br /&gt;
* E.g. PubSubHubbub doesn't support private feeds.&lt;br /&gt;
* Immediate spam on publicly hosted StatusNet instances.&lt;br /&gt;
* Onboarding: How do I get my existing social graph from e.g. Facebook into my StatusNet instance?&lt;br /&gt;
* Operations requiring a &amp;quot;global view&amp;quot; on the system, e.g. monitoring a global hashtag.&lt;br /&gt;
* Make it look better for the user.&lt;br /&gt;
&lt;br /&gt;
StatusNet and Diaspora are AGPL: Nice for free software, but less nice for people who want to make incremental improvements while protecting intellectual property.&lt;br /&gt;
&lt;br /&gt;
Important feature for broader adoption: Introduce a notion of groups on the protocol level that is independent of a specific implementation.&lt;br /&gt;
&lt;br /&gt;
Goal should be not just to build a replacement for Facebook, but to build something that can do more. The Federated Social Web may look different from what we currently think of as social networking. E.g. just like blogs evolved into social networking, a federated social web may be quite different from &amp;quot;traditional&amp;quot; social networking.&lt;br /&gt;
&lt;br /&gt;
Advice for our everyday life: Use decentralized software as much as possible, e.g. publish your social content on Wordpress, support existing projects, keep experimenting.&lt;br /&gt;
&lt;br /&gt;
POSSI: Publish, Own, Site, Syndicate, Everywhere&lt;br /&gt;
&lt;br /&gt;
[[File:iiw15-fedsocweb.jpg]]&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Demo_with_Freedom_Box_(you_can_participate!)&amp;diff=5582</id>
		<title>Demo with Freedom Box (you can participate!)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Demo_with_Freedom_Box_(you_can_participate!)&amp;diff=5582"/>
		<updated>2012-05-12T01:42:01Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' FreedomBox Demo (T3C)&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello  &lt;br /&gt;
 &lt;br /&gt;
In this demo, 5 plug computers (Guruplugs by GlobalScale Technologies) were handed out to volunteer participants and connected to power outlets.&lt;br /&gt;
&lt;br /&gt;
Upon being plugged in, these small personal servers booted their Debian operating system and custom demo software.&lt;br /&gt;
&lt;br /&gt;
Each volunteer of the demo was able to control one of the boxes via a web interface.&lt;br /&gt;
&lt;br /&gt;
The first step was to connect one's box to the other boxes.&lt;br /&gt;
&lt;br /&gt;
The second step was to sign in to the network with an identifier, in order for boxes to be able to find each other.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After being connected and identified, the demo allowed participants to do the following:&lt;br /&gt;
* 1. Enter personal data which is stored in an XDI-based Personal Data Store on the box (first name, last name, email, etc.)&lt;br /&gt;
* 2. Establish a relationship with other participants, which allowed access to the personal data on their boxes via XDI Messaging.&lt;br /&gt;
* 3. Sending text messages from one box to another.&lt;br /&gt;
* 4. Sending an &amp;quot;intent&amp;quot; to all boxes on the network, indicating what one would be willing to buy at a given price.&lt;br /&gt;
* 5. Viewing &amp;quot;intents&amp;quot; received from the network.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There was a lot of good discussion about the potential of such a personal server for the Personal Data Ecosystem and Vendor Relationship Management.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The general idea behind the FreedomBox is to enable data sharing, communication and social networking that can not be monitored or censored.&lt;br /&gt;
&lt;br /&gt;
This demo was neither created nor endorsed by the FreedomBox Foundation, but was simply meant to demonstrate what its idea is about.&lt;br /&gt;
&lt;br /&gt;
The actual software used during the demo was developed by Project Danube.&lt;br /&gt;
&lt;br /&gt;
http://blog.projectdanube.org/2012/05/freedombox-at-the-internet-identity-workshop/&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Demo_with_Freedom_Box_(you_can_participate!)&amp;diff=5581</id>
		<title>Demo with Freedom Box (you can participate!)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Demo_with_Freedom_Box_(you_can_participate!)&amp;diff=5581"/>
		<updated>2012-05-12T01:41:49Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' FreedomBox Demo (T3C)&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello  &lt;br /&gt;
 &lt;br /&gt;
In this demo, 5 plug computers (Guruplugs by GlobalScale Technologies) were handed out to volunteer participants and connected to power outlets.&lt;br /&gt;
&lt;br /&gt;
Upon being plugged in, these small personal servers booted their Debian operating system and custom demo software.&lt;br /&gt;
&lt;br /&gt;
Each volunteer of the demo was able to control one of the boxes via a web interface.&lt;br /&gt;
&lt;br /&gt;
The first step was to connect one's box to the other boxes.&lt;br /&gt;
&lt;br /&gt;
The second step was to sign in to the network with an identifier, in order for boxes to be able to find each other.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After being connected and identified, the demo allowed participants to do the following:&lt;br /&gt;
* 1. Enter personal data which is stored in an XDI-based Personal Data Store on the box (first name, last name, email, etc.)&lt;br /&gt;
* 2. Establish a relationship with other participants, which allowed access to the personal data on their boxes via XDI Messaging.&lt;br /&gt;
* 3. Sending text messages from one box to another.&lt;br /&gt;
* 4. Sending an &amp;quot;intent&amp;quot; to all boxes on the network, indicating what one would be willing to buy at a given price.&lt;br /&gt;
* 5. Viewing &amp;quot;intents&amp;quot; received from the network.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There was a lot of good discussion about the potential of such a personal server for the Personal Data Ecosystem and Vendor Relationship Management.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The general idea behind the FreedomBox is to enable data sharing, communication and social networking that can not be monitored or censored.&lt;br /&gt;
&lt;br /&gt;
This demo was neither created nor endorsed by the FreedomBox Foundation, but was simply meant to demonstrate what its idea is about.&lt;br /&gt;
&lt;br /&gt;
The actual software used during the demo was developed by Project Danube.&lt;br /&gt;
&lt;br /&gt;
[[http://blog.projectdanube.org/2012/05/freedombox-at-the-internet-identity-workshop/]]&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_14_Proposed_Topics&amp;diff=5395</id>
		<title>IIW 14 Proposed Topics</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_14_Proposed_Topics&amp;diff=5395"/>
		<updated>2012-04-29T22:27:13Z</updated>

		<summary type="html">&lt;p&gt;=markus: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==What topics are you planning to present about or lead a discussion about at this IIW?==&lt;br /&gt;
* Multi-assertion authentication&lt;br /&gt;
* Attribute Exchange Trust Frameworks.  Attribute Provider Networks.&lt;br /&gt;
* OpenID Connect, OAuth, FICAM, NSTIC&lt;br /&gt;
* SCIM&lt;br /&gt;
* XDI, OpenID Connect 1.0&lt;br /&gt;
* Roadmap for rapidly advancing VRM adoption.&lt;br /&gt;
* OpenID Connect, OIX, OAuth, Identity Provider Businessmodels&lt;br /&gt;
* VRM&lt;br /&gt;
* Customer Care for federated identities&lt;br /&gt;
* customer commonsuser-driven personal data&lt;br /&gt;
* Trust Framework Meta Model&lt;br /&gt;
* NSTIC, Identity Ecosystem Business Models, Identity Attributes&lt;br /&gt;
* OpenID ConnectOAuthJSON Cryptography&lt;br /&gt;
* Step-up authentication, mobile 2-factor AuthN&lt;br /&gt;
* Customer Care for federated identities&lt;br /&gt;
* customer commonsuser-driven personal data&lt;br /&gt;
* Trust Framework Meta Model&lt;br /&gt;
* NSTIC, Identity Ecosystem Business Models, Identity Attributes&lt;br /&gt;
* OpenID ConnectOAuthJSON Cryptography&lt;br /&gt;
* Step-up authentication, mobile 2-factor AuthN&lt;br /&gt;
* Backplane 2.0&lt;br /&gt;
* standards/techniques for proxy authentication&lt;br /&gt;
* NSTIC - pre secretariat effort&lt;br /&gt;
* ACBio&lt;br /&gt;
* Personal data stores: cloud based? Local based? mix? level of security? ... &amp;lt;-&amp;gt; Benefits to individuals&lt;br /&gt;
* Personal data tagging: an utopia? what would be the requirements? the benefits?&lt;br /&gt;
* In a VRM world, how to manage the transparency of the relationship? Trusted identities?&lt;br /&gt;
* SCIM, OAuth, OpenID Connect&lt;br /&gt;
* UMAAPI access control&lt;br /&gt;
* Metadata for scalability in OpenID Connect&lt;br /&gt;
* Interested in business opportunities associated with user-centric identity, personal data stores, VRM.&lt;br /&gt;
* explaining identity to non-technical stakeholders&lt;br /&gt;
* SCIM&lt;br /&gt;
* Standard Information Sharing Labels&lt;br /&gt;
* Building a VRM Startup&lt;br /&gt;
* The effect of identity and privacy polices on people in marginalized communities&lt;br /&gt;
* accessibility, disability, and identity online&lt;br /&gt;
* Initiatives for distributed networks (e.g. FreedomBox) and their role in PDE and VRM&lt;br /&gt;
&lt;br /&gt;
==What are you hoping to learn about or hear a presentation about at IIW?==&lt;br /&gt;
* AttributeExchange, OpenIdConnect, OAuth2, UMA, NSTIC, OIX&lt;br /&gt;
* Roadmap for rapidly advancing VRM adoption.&lt;br /&gt;
* SCIM, BYOI&lt;br /&gt;
* SCIM&lt;br /&gt;
* Current standards and new directions and ideas.&lt;br /&gt;
* VRM and Personal Data Ecosystem efforts, OpenID Connect, Account Chooser, Backplane Exchange&lt;br /&gt;
* Business value of an IDP&lt;br /&gt;
* NSTIC&lt;br /&gt;
* OpenID Connect, OAuth 2&lt;br /&gt;
* Customer Care for federated identities&lt;br /&gt;
* customer commonsuser-driven personal data&lt;br /&gt;
* Trust Framework Meta Model&lt;br /&gt;
* NSTIC, Identity Ecosystem Business Models, Identity Attributes&lt;br /&gt;
* OpenID ConnectOAuthJSON Cryptography&lt;br /&gt;
* Step-up authentication, mobile 2-factor AuthN&lt;br /&gt;
* Giving users control of their data, building tools that access that data without giving it to another service provider.&lt;br /&gt;
* NSTIC, OpenID Directions, Personal Data Directions, Real Privacy for Everyone&lt;br /&gt;
* ImplementationsInterop&lt;br /&gt;
* 2-factor AuthN, interested in NSTIC&lt;br /&gt;
* OAuth2, SCIM, OpenID Connect&lt;br /&gt;
* Federation&lt;br /&gt;
* actual technology privacy problems and trends for solving these issues, both theoretical as well as practical&lt;br /&gt;
* transitioning large organizations to standards based identity&lt;br /&gt;
* OAuth, OpenID Connect, NSTIC, Privacy, enterprise awareness, cutting edge advancements&lt;br /&gt;
* identity provisioning, identity sync&lt;br /&gt;
* Networking, VRM, User-Centric Identity, Networking, Networking&lt;br /&gt;
* OAuth2 future steps/4th party auth/Auth in mobile platforms/Auth for e-commerce sites&lt;br /&gt;
* Lots been said and promoted about Identity Trust Frameworks. Are there any alternatives to Trust Frameworks that can help enforce&lt;br /&gt;
compliance with agreements amongst IDM players (IDP, Attribute Provider, RP, User) and also liability in case of non-performance?&lt;br /&gt;
* Interoperability standards (between browsers, databases, companies and organizations)-Identity standards-VRM interoperabilty with CRM?&lt;br /&gt;
* OAuth OpenID etc.  NSTIC. Identity business models.&lt;br /&gt;
* OAuth, OpenID Connect, JWT futuresNSTIC and FICAM news&lt;br /&gt;
* AccountChooser&lt;br /&gt;
* Use cases of how OpenID/Connect is being used&lt;br /&gt;
* Use cases of online identity verification and what organizations are looking for in these solutions.  Including challenges; leading technologies/services being implemented and; what’s working and what’s not.  Additionally, any updates on any of the identity verification Pilots that are being discussed and/or taking place.&lt;br /&gt;
* Better understand the state-of-the-art and future direction in IDM, PDS, user-centric identity, personal data ecosystems, VRM...&lt;br /&gt;
* secure authentication strategies for distributed identity management&lt;br /&gt;
* OAuth, SCIM&lt;br /&gt;
* SCIM&lt;br /&gt;
* Challenges, opportunities and informed investors for startups implementing VRM principles and user centric identity&lt;br /&gt;
* How technology development is affecting identity and privacy standards….&lt;br /&gt;
&lt;br /&gt;
==What are the critical questions about user-centric identity and data you hope to discuss with peers at IIW?==&lt;br /&gt;
* How to get VRM on wheels&lt;br /&gt;
* locus of control&lt;br /&gt;
* Verification of user-provided identity attributes.  How can we know that what users tell us about themselves is true?&lt;br /&gt;
* Customer Care for federated identities&lt;br /&gt;
* customer commonsuser-driven personal data&lt;br /&gt;
* Trust Framework Meta Model&lt;br /&gt;
* NSTIC, Identity Ecosystem Business Models, Identity Attributes&lt;br /&gt;
* OpenID ConnectOAuthJSON Cryptography&lt;br /&gt;
* Step-up authentication, mobile 2-factor AuthN&lt;br /&gt;
* How can we build client web applications that access a distributed social data network, which do not require each user to copy their data to the &lt;br /&gt;
* company that built the client application? &lt;br /&gt;
* shortcomings of identity as the uniting metaphor for trust frameworks&lt;br /&gt;
* Claims ProvidersBusiness Models&lt;br /&gt;
* Is there a market for user controlled mobile phone based 2-factor AuthN?&lt;br /&gt;
* responsibility, whose responsibility is privacy, who is liable for what, etc.&lt;br /&gt;
* how to choose when to use cloud based identity credentials versus client based credentials&lt;br /&gt;
* Define the intersection of user-centric, enterprise, relying parties, who, when, how? Define OAuth in layman's terms.&lt;br /&gt;
* standards and security related to interop between identity providers and identity consumers&lt;br /&gt;
* privacy and security&lt;br /&gt;
* To make timely progress on solutions based on open standards, it seems essential that user-centric identity requirements are debated in the community,&lt;br /&gt;
* solidified and then formalized in an appropriate standards body to drive technical specifications development.&lt;br /&gt;
* Identity recognition and management: where are we today? Where are we going tomorrow?&lt;br /&gt;
* How VRM companies can become supportive of each other&lt;br /&gt;
* I’d be interested in examples of levels of assurance.&lt;br /&gt;
* User-centric ID is the focus here and the right thing to do, but funding and the big winners on the business side are FB, Google, LI and so on. &lt;br /&gt;
* How can user-centric ID be commercially successful? What can we do as an industry to move the needle?&lt;br /&gt;
* Identity management for minors&lt;br /&gt;
* Why are we still talking &amp;quot;user-centric&amp;quot;?&lt;br /&gt;
8 User experience&lt;br /&gt;
* What kind of control can people have over their own data?&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Europe_vs_Facebook_(TH4J)&amp;diff=5086</id>
		<title>Europe vs Facebook (TH4J)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Europe_vs_Facebook_(TH4J)&amp;diff=5086"/>
		<updated>2011-10-23T22:16:56Z</updated>

		<summary type="html">&lt;p&gt;=markus: Created page with &amp;quot;'''Session Topic:''' Europe vs Facebook (TH4J)  '''Convener:''' Markus Sabadello  '''Notes-taker(s):''' Markus Sabadello  '''Tags for the session - technology discussed/ideas con...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Europe vs Facebook (TH4J)&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered: '''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
According to the [http://europe-v-facebook.org/ Europe vs. Facebook] initiative, which was started by a group of young law students from Vienna, the Facebook legal structure subjects Facebook users outside of the US and Canada to EU privacy law, especially the well-known &amp;quot;Data Protection Directive&amp;quot;. The group has successfully requested and received a set of personal data stored by Facebook, filed a complaint with the responsible regulator (the Irish Data Protection Commission), and generated a large amount of attention in European media. By now, Facebook offers an automatic web form where users can request a copy of their data, however, the group pushes for further action, claiming that Facebook's reaction is insufficient. The group, which is intimately familiar with both US and EU privacy law, demands more transparency and the use of open standards, and explains that a world-wide solution to online privacy must consist of both legal and technological measures. As of now, the investigation against Facebook is still ongoing. On the website http://europe-v-facebook.org/, a detailed list of complaints and the history of the effort are documented.&lt;/div&gt;</summary>
		<author><name>=markus</name></author>
		
	</entry>
</feed>