<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ebgross</id>
	<title>IIW - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ebgross"/>
	<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/Special:Contributions/Ebgross"/>
	<updated>2026-06-04T17:06:40Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.6</generator>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:IIWXVIII_-18_Book_of_Proceedings_a.pdf&amp;diff=19700</id>
		<title>File:IIWXVIII -18 Book of Proceedings a.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:IIWXVIII_-18_Book_of_Proceedings_a.pdf&amp;diff=19700"/>
		<updated>2014-06-27T16:08:10Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19690</id>
		<title>Start-Up’s Pitching</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19690"/>
		<updated>2014-06-02T14:43:14Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: video link added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Startups Pitching to VC Panel&lt;br /&gt;
&lt;br /&gt;
Thursday 4 &amp;amp; 5 A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Nathan Schor&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Nathan Schor, Video of Pitches&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
A total of eleven (11) companies made pitches to the VC Panel.&lt;br /&gt;
&lt;br /&gt;
Here is a link to video of these pitches:  &lt;br /&gt;
https://vimeo.com/channels/iiw18investorpanels&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''''Panelists'''''&lt;br /&gt;
*	Noah Doyle [mailto:noah@javelinvp.com noah@javelinvp.com] http://www.javelinvp.com&lt;br /&gt;
*	Keith Teare  [mailto:keith@teare.com keith@teare.com] http://www.archimedeslabs.com/&lt;br /&gt;
*	Derek Anderson [mailto:derek@startupgrind.com derek@startupgrind.com] http://www.startupgrind.com&lt;br /&gt;
*	Kayvan Baroumand [mailto:kayvan@nestgsv.com kayvan@nestgsv.com] http://www.nestgsv.com&lt;br /&gt;
*	Dan Gordon, [mailto:dan@valhallapartners.com dan@valhallapartners.com], http://www.valhallapartners.com/ &lt;br /&gt;
*	Amit Shah, Aritman Ventures, [mailto:amit@artiman.com amit@artiman.com] http://www.artiman.com/ &lt;br /&gt;
*	Anandan Jayaraman [mailto:anandan.jayaraman@gmail.com anandan.jayaraman@gmail.com]&lt;br /&gt;
&lt;br /&gt;
'''''Companies Pitching'''''&lt;br /&gt;
&lt;br /&gt;
'''Respect Network Founding Partners''' &lt;br /&gt;
&lt;br /&gt;
Respect Network 				&lt;br /&gt;
&lt;br /&gt;
Emmett Global				&lt;br /&gt;
&lt;br /&gt;
URQUi					&lt;br /&gt;
&lt;br /&gt;
inWebo					&lt;br /&gt;
&lt;br /&gt;
'''Independent'''&lt;br /&gt;
&lt;br /&gt;
Glome					&lt;br /&gt;
&lt;br /&gt;
HIE of One					&lt;br /&gt;
&lt;br /&gt;
MePIN /Meontrust				&lt;br /&gt;
&lt;br /&gt;
Pomcor 					&lt;br /&gt;
&lt;br /&gt;
Tozny  					&lt;br /&gt;
&lt;br /&gt;
Traitware 					&lt;br /&gt;
&lt;br /&gt;
Welcomer 					&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''''Respect Network Founding Partners'''''&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Respect Network  '''Website:''' http://respectnetwork.com/	'''Location:''' Seattle&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Drummond Reed, Co-Founder and CEO&lt;br /&gt;
*	Gary Rowe, Executive Chairman&lt;br /&gt;
*	Katherine Singson, CMO&lt;br /&gt;
*	Andy Dale, CTO&lt;br /&gt;
*	Matthew Sutton, VP Products &lt;br /&gt;
*	Mark Timbrell, Head of Respect Network EU&lt;br /&gt;
&lt;br /&gt;
Bios and links are all listed at http://respectnetwork.com/executive-team/ &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Respect Network is the world’s first global private network of personal and business clouds. Respect Network is based on an award-winning trust framework developed over 3 years by leading Internet architects and 50 Founding Partner companies from around the world. As a decentralized, multi-provider network similar to the global banking or email networks, the Respect Network will enable members anywhere in the world to share sensitive private data with strong assurance that their privacy will always be respected. In fact, Respect Network is the only global data sharing network engineered from the ground up around ''Privacy by Design.'' &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''  50 founding partners who have already signed up. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' Respect Network Corporation is currently raising a $3M Series A round. On Friday April 25 we held a first closing for $1.325M. We anticipate the second closing will be the first week of June.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Emmett Global	'''Website:''' http://www.EmmettGlobal.com 	'''Location:''' New York /Israel&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Kenneth J Lefkowitz, CEO    &lt;br /&gt;
*	Lionel A Wolberger, Architect&lt;br /&gt;
*	Joshua Zieman, CMO&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Emmett Global distributes best of class open source solutions that enable true Personal Data management. Three included solutions are; &lt;br /&gt;
&lt;br /&gt;
1) Cloud service provider on the Respect Network &lt;br /&gt;
&lt;br /&gt;
2) Browser extension bundle for Chrome and &lt;br /&gt;
&lt;br /&gt;
3) Mobile tablet device.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $950,000 to complete our seed funding&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' URQUi		'''Website:'''  http://www.urqui.com		'''Location:''' BCCanada&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Jonathan Bell, President, Computer Consultant –  &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/jonathan-bell/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Ken Jennings, [mailto:kjennings@urqui.com kjennings@urqui.com] @kwjennings, https://www.linkedin.com/pub/ken-jennings/0/7a2/602 &lt;br /&gt;
[http://skkynet.com/investors/directors/ Board of Directors Skkynet Cloud Systems Inc.] Skky OTC.bb  - &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/kenneth-jennings/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Dr. Jose M. Fernandez  P.Eng, Ph.D., Assistant Professor of Computer and Software Engineering, [http://www.polymtl.ca/recherche/rc/en/professeurs/details.php?NoProf=299 Polytechnique Montreal] [http://www.niccanada.com/EN/Speakers/Jos%C3%A9Fernandez.aspx Frequent Speaker on IT Security &amp;amp; Cryptography]  -  [http://www.privacybydesign.ca/index.php/ambassador/jose-fernandez-ph-d/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' URQUi“Your Key” is a secure, patent-pending, network or SaaS password alternative. URQUi One Time Passwords eliminate the need to store static passwords on servers. Users need not remember passwords. Using URQUi, a FREE app, individuals control their privacy, secure their online presence and protect themselves from identity theft. User-centric URQUi embodies &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/about-pbd/ Privacy by Design]. The Heartbleed bug could not have breached accounts using URQUi! ~ URQUi’s Business model is disruptive. URQUi is a multi-sided recurring revenue SaaS business. URQUi is free for individuals; free SaaS for government and non-profit servers; billable recurring revenue SaaS for commercial servers. URQUI’s pricing to commercial SaaS customers will be disruptive at 15% of comparable services (RSA SecureID). Distribution to individuals is done through iTunes et al. Distribution to server owners is done through resellers and vertical market partners. URQUi expects processing margins in the area of 50% - 60%&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' URQUi has not yet achieved traction in the market, however URQUi has developed significant partnerships. [http://www.privacybydesign.ca/index.php/ambassador/urqui/ Ambassador of Privacy by Design] Founding Partner of the Respect [http://www.thecene.org/#!cta-boston/c1v1m NetworkCTA@Boston, Fall 2014 Cohort]&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''$1,750,000 https://angel.co/urqui&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' inWebo 	'''Website:''' http://www.inwebo.com	 '''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Didier Perrot, CEO and founder, [mailto:didier.perrot@inwebo.com  didier.perrot@inwebo.com] &lt;br /&gt;
http://www.linkedin.com/pub/didier-perrot/0/72/b9/&lt;br /&gt;
&lt;br /&gt;
Bruno Abramatic, CTO and co-founder&lt;br /&gt;
&lt;br /&gt;
Olivier Perroquin, SVP Sales and co-founder, http://fr.linkedin.com/pub/olivier-perroquin/0/424/240&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' inWebo provides a Cloud-based authentication platform and a password management service to help enterprises, businesses and service providers protect users' online access and transactions in a highly secure yet non-intrusive way.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' 3M$ https://angel.co/inwebo &lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''''Independent Startups'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Glome  	'''Website:''' http://www.glome.me	'''Location:''' Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Edi Immonen – Co-founder &amp;amp; CEO [mailto:edi@glome.me edi@glome.me]  https://www.linkedin.com/in/jemiweb&lt;br /&gt;
&lt;br /&gt;
Ferenc Szekely – Co-founder &amp;amp; CTO https://www.linkedin.com/in/ferencszekely&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Glome has created an anonymous personalisation platform (an API) for businesses where individuals own, control and benefit from their digital footprint with full anonymity.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Glome had a soft launch in Finland and we targeted a few key players with great success. Now we have partnered with:&lt;br /&gt;
&lt;br /&gt;
1) A top-10 media in Finland with close to 1M unique weekly users&lt;br /&gt;
&lt;br /&gt;
2) A leading Scandinavian web shop company&lt;br /&gt;
&lt;br /&gt;
3) A leading Finnish consultancy &amp;amp; big data company &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' A total of 1.8m€ in steps in year 2014 so that: 300k€ for finishing the product-market-fit phase ( Q3&amp;amp;Q4 / 2014 )    ~ ~ ~ 1.5m€ for launching and expanding ( Q4/2014 -&amp;gt;  )&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:'''HIE of One		'''Website:''' N/A		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Adrian Gropper, MD –[mailto:agropper@healthurl.com agropper@healthurl.com] https://www.linkedin.com/pub/adrian gropper/1/665/691&lt;br /&gt;
&lt;br /&gt;
Josh Mandel, MD –https://www.linkedin.com/pub/joshua-mandel/35/472/883&lt;br /&gt;
&lt;br /&gt;
Adam Powell, PhD –https://www.linkedin.com/in/adamcpowell&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' HIE of Onewill sell a personal data store (hardware or cloud) and live support to consumers to enable the coordination of family care teams for the elderly and seriously ill. Our service uses open source software to create a platform for patient-directed health information exchange that will be preferred by app and services developers because it is verifiably privacy-preserving, verifiably secure, free to the developers, and, as a community open source project, carries no risk of vendor lock-in. HIE of One is a public benefits for-profit corporation designed to appeal to both financial and strategic investors.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' HIE of One has limited traction. We won one of the major prizes at an MIT health hackathon a a short time ago and we have a commitment from Smart911 to participate provide an API and participate in a demo this summer. We've also got three separate collaborating groups in the San Diego and San Francisco areas. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $2 M&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' MePIN /Meontrust	'''Website:'''https://www.mepin.com	'''Location:'''Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Markku Mehtala, CEO, [mailto:markku.mehtala@meontrust.com markku.mehtala@meontrust.com] http://fi.linkedin.com/in/markkum/&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''MePIN provides smart security for consumer online services, protecting the services and their users against password phishing, account hijacking, transaction fraud and privacy problems. &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We just raised a round, so looking for contacts for future rounds.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Pomcor		'''Website:'''http://www.pomcor.com		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Karen Pomian Lewison, CEO, [mailto: kplewison@pomcor.com kplewison@pomcor.com], http://www.linkedin.com/profile/view?id=28011537&lt;br /&gt;
&lt;br /&gt;
Francisco Corella, CTO    [mailto: fcorella@pomcor.com fcorella@pomcor.com], http://www.linkedin.com/profile/view?id=78440530&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''Pomcor is developing an Enterprise Mobility Management (EMM) solution to help an enterprise protect data stored in a mobile device with a patent-pending technique that prevents an adversary who steals the device from mounting an offline attack against an activation PIN.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We don't have a product, so we don' have traction yet.  We do have a no.1 position in Google for one of the market segments, even without a product.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We are looking for a letter of interest to support an NSF SBIR Phase I grant application, followed by an investment of $60,000, conditional on our getting the SBIR Phase I grant of $150,000.  The $60,000 investment would be matched by a Phase IB grant of up to $30,000.  Successful phases I and IB would give us a very good chance of getting a Phase II grant of up to $750,000, which in turn would allow us to get a Phase IIB grant of up to $500,000 matching an additional investment of $1,000,000.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''  Tozny		'''Website:'''   http://tozny.com	'''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Isaac Potoczny-Jones, President [mailto:ijones@tozny.com@SyntaxPolice ijones@tozny.com@SyntaxPolice] &lt;br /&gt;
http://www.linkedin.com/pub/isaac-potoczny-jones/4/b64/23b&lt;br /&gt;
&lt;br /&gt;
Leah Daniels, VP Business Development    http://www.linkedin.com/in/leahcdaniels&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Digital authentication - proving who we are - is a constant necessity on modern networks. Users are buried under the weight of too many passwords, and are faced with a conundrum: good passwords are impossible to remember, and bad passwords are easy to guess.&lt;br /&gt;
Tozny replaces passwords with a cryptographic app on your smart phone, making login both easier and more secure than passwords. Alternately, use Tozny to augment passwords with multi-factor authentication. Tozny helps enterprises and web sites stay secure and gives users an easier way to log in. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We have a customer in the government who is funding our work under a small business innovation program, and we have strong leads with a few large consumer-facing organizations in banking, health care, and telecommunications.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''  $500K&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Welcomer     '''Website:''' http://www.welcomer.me    '''Location:'''Australia&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Kevin Cox - [mailto:kevin@welcomer.me kevin@welcomer.me] http://au.linkedin.com/in/kevinrosscox Kevin is an Identity domain expert who has deep understanding of how organisations can benefit from giving people access to their own information. Kevin previously founded identity verification company Edentiti which was acquired in late 2013. &lt;br /&gt;
&lt;br /&gt;
Paul Marando - [mailto:paul@welcomer.me paul@welcomer.me] http://au.linkedin.com/pub/paul-marando/4/111/486 Paul comes across from Edentiti bringing with him a deep understanding of identity technology and a track record developing scalable architecture. Paul looks after the technology as well as leading the engineering team.&lt;br /&gt;
&lt;br /&gt;
Rory Ford -  [mailto:rory@welcomer.me rory@welcomer.me] http://au.linkedin.com/in/roryford/ Rory brings a background in online marketing and product management. Previously he established a portfolio of websites bringing in online sales across more than 120 countries. Rory also worked within Edentiti, looking at new product opportunities that have formed the basis for Welcomer. &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Welcomer provides an identity verification solution to small and medium organizations by utilizing a person’s access to their own information. Based on proven Enterprise technology, already used by banks, Welcomer makes money from each successful verification. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Company has raised ~$450K seed funding. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $300,000&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''Traitware	   '''Website:'''http://www.traitware.com     '''Location:''' San Francisco &lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Harlan Hutson President - Mr. Hutson is a serial entrepreneur now on his third start-up. Harlan has been fascinated with online transactions and security since the creation of his second start-up, an online event ticketing company that was sold in 2010&lt;br /&gt;
&lt;br /&gt;
Dr. Herbert w. Spencer CTO -  Dr. Spencer has been a developer of new technologies since building a computer from pinball machine parts in junior high school. He received a Ph.D. in plasma physics from Auburn University and started EC&amp;amp;C Technologies, Inc.&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' TraitWare™ delivers 2-factor authentication making mobile and web computing more secure and enjoyable. Our patent pending process authenticates both user and device, binding them together to create a secure signature. When combined with PhotoAuth™, TraitWareID™ eliminates the need to enter a PIN, OTP or “out-of-band” SMS codes for authentication.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' TraitWare is fully operational is now being used in pilot tests by companies that have been signed as partners. TraitWare is bundling its authentication with software to solve customer needs in the areas of finance, payments, and health care.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=What%E2%80%99s_it_Take_to_get_a_Customer-Centric_Startup_to_Win_Funding%3F_(VC_Panel_Discussion)&amp;diff=19689</id>
		<title>What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=What%E2%80%99s_it_Take_to_get_a_Customer-Centric_Startup_to_Win_Funding%3F_(VC_Panel_Discussion)&amp;diff=19689"/>
		<updated>2014-06-02T14:38:36Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' What It Takes to Get a Customer-Centric Startup to Win Funding? &lt;br /&gt;
&lt;br /&gt;
Thursday 3A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Nathan Schor &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Panel Discussion Video&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
An accomplished group of investors were invited to discuss challenges to funding startups building privacy, identity and customer-empowerment solutions, as well as to hear founders pitching specific business model.&lt;br /&gt;
To the best of our knowledge, this is the first ever investor event focused exclusively on funding user-centric business models. &lt;br /&gt;
&lt;br /&gt;
Here is who participated:&lt;br /&gt;
* Noah Doyle  -  [http://javelinvp.com javelinvp.com] &lt;br /&gt;
* Keith Teare  -  [http://archimedeslabs.com archimedeslabs.com/] &lt;br /&gt;
* Derek Anderson  -  [http://startupgrind.com startupgrind.com] &lt;br /&gt;
* Kayvan Baroumand  - [http://nestgsv.com nestgsv.com] &lt;br /&gt;
* Dan Gordon - [http://valhallapartners.com valhallapartners.com/] &lt;br /&gt;
* Amit Shah - Aritman Ventures [http://artiman.com artiman.com/] &lt;br /&gt;
* Anandan Jayaraman  &lt;br /&gt;
&lt;br /&gt;
Here is a link to video of the Panel Discussion:  &lt;br /&gt;
https://vimeo.com/channels/iiw18investorpanels&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=NSTIC_%E2%80%93_Update_From_NIST_and_Roundtable&amp;diff=19688</id>
		<title>NSTIC – Update From NIST and Roundtable</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=NSTIC_%E2%80%93_Update_From_NIST_and_Roundtable&amp;diff=19688"/>
		<updated>2014-06-02T14:33:17Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' NSTIC: Update from NIST &amp;amp; Roundtable &lt;br /&gt;
&lt;br /&gt;
Tuesday 4E&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' James Sheire&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
NSTIC = National Strategy for Trusted Identities in Cyberspace&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
It is the National Strategy to form an Ecosystem ~ where people can voluntarily choose and ID and login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Privacy, Interoperability, User-Friendly, More Secure ---&amp;gt; User have to create dozens of account.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Problems it seeks to address - Re-Use over and over of passwords.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
They (the NPO) is facilitating a private sector lead group.&lt;br /&gt;
&lt;br /&gt;
The purpose is to create the policies, rules and standards and framework that governs the interactions in the ecosystem.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Getting Federal Government Programs to get being early adopters and use 3rd party credentials. &lt;br /&gt;
&lt;br /&gt;
Access to government services, file a medicare claim.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
FCCX (pronounced F6) service users login approved credentials. Choose from IDP's that are approved.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Q: Do any of them let them control their ID.&lt;br /&gt;
&lt;br /&gt;
A: At higher level of assurances must have it be bound.&lt;br /&gt;
&lt;br /&gt;
Vouch for Individual&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What about allowing users vouch self where the individual holds externally vouched for attributes?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Dialogues will emerge on different efforts.&lt;br /&gt;
&lt;br /&gt;
LOA - 1, 2, 3, 4&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Digital Certificates of Proof&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The hardest part is the business process - record keeping etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Robin: HIS model where brokering system where credentials themselves come from bank.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Update: become independent entity with its own capabilities.  501( c )3&lt;br /&gt;
*        -comment from crowd - &amp;quot;so it is a charity&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
IDESG will have funding through Grants&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
FCCX (USPS) (Contract with Secure key) to build the HUB - processes for ID and for departments who will pulg in.&lt;br /&gt;
&lt;br /&gt;
It has better privacy capabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
It will have a consistent experience for citizens. &amp;lt;---starts new behavior&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What is the business model for FCCX&lt;br /&gt;
*        Cost reduction&lt;br /&gt;
*        Agencies will/do subscribe&lt;br /&gt;
&lt;br /&gt;
*     Tired of paying for proofing vs. authentication again and again.&lt;br /&gt;
*     Payment for Authentication.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Question: States? get involved?&lt;br /&gt;
*        Legislation to expand&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Struggling with attempts to integrate access via single ID&lt;br /&gt;
&lt;br /&gt;
Citizen authentication strategy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Virginia DMV&lt;br /&gt;
&lt;br /&gt;
others HHS (Health and Human Services)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Hurdle 1 - create place for 1 credential&lt;br /&gt;
&lt;br /&gt;
Then 2 - accepting third party&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
requirements - verify eligibility.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ken K. 700 Credential service providers&lt;br /&gt;
*        not approached about getting $&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Jims comment Agencies want Identity proofing - wants to be stateless&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Tensions and Challenges - ID Resolution - Do I have right dataset?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
As CSP (credential service provider)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
They don't have all the attributes they need - even if we had moving them in back.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The way NSTIC coordinate ONC&lt;br /&gt;
&lt;br /&gt;
see potential&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
TrustedID = better proofing of ID better security + privacy options&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
How same patient @one place is another place.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Inora Healthcare 3rd party private access - Google, MSFT.&lt;br /&gt;
&lt;br /&gt;
Personal Health Records&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Tools&amp;quot;&lt;br /&gt;
&lt;br /&gt;
What does that mean?&lt;br /&gt;
* Standards?&lt;br /&gt;
* how you do it?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Direct Protocol - well established&lt;br /&gt;
&lt;br /&gt;
Digitally signed email&lt;br /&gt;
&lt;br /&gt;
RESTful health exchange&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Feature Speaker ONC&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Awarded 12 pilots to catalyze  2 states 10 innovations&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NSTIC.gov&lt;br /&gt;
&lt;br /&gt;
greatw ay to meet pilots&lt;br /&gt;
&lt;br /&gt;
Round 3 is being announced in early fall.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Might have a 4th round.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Question to facilitate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Market 2011 - when issue, where now?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Mobile Device&lt;br /&gt;
&lt;br /&gt;
OpenID Connect is the answer&lt;br /&gt;
&lt;br /&gt;
of course privacy a lot of attention.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Real marketplace competition&lt;br /&gt;
&lt;br /&gt;
Wanted to stimulate broad spectrum of identities to choose from.  greater level of offering&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In coming year - write framework requirments&lt;br /&gt;
* work&lt;br /&gt;
* intention&lt;br /&gt;
* resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Its a &amp;quot;round table&amp;quot; always looking for feedback.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2 schools of thought - credit agency, VRM Proofs&lt;br /&gt;
&lt;br /&gt;
look at Scandinavian model&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The truth about NSTIC - what is a trusted (verified) ID&lt;br /&gt;
&lt;br /&gt;
Financial services - IDProofing/Authentication&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Three aspects&lt;br /&gt;
* Session&lt;br /&gt;
* Authentication&lt;br /&gt;
* ID&lt;br /&gt;
&lt;br /&gt;
They are different&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Pilot in NY with Broadridge&lt;br /&gt;
&lt;br /&gt;
IdP -&amp;gt; KYC&lt;br /&gt;
* attribute&lt;br /&gt;
* exchange&lt;br /&gt;
* networks&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
timeframework 2010-2011 IdP &amp;quot;do&amp;quot; everything&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
My thought while listening - what to do to create a real learning community&lt;br /&gt;
&lt;br /&gt;
Power / Info Asymmetry&lt;br /&gt;
&lt;br /&gt;
with IdP / AP / Relying Party&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Why FB make change, fine grain&lt;br /&gt;
&lt;br /&gt;
Indepth privacy assessment&lt;br /&gt;
&lt;br /&gt;
one for internal / one for external&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
they are now enabling anonymous login - sell in aggregate form to the later&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NSTIC language &amp;quot;unobtrusively&amp;quot; IdP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
FCCX - double blind unobservability&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
still a lot to be done have consumers fully participate. In value of data&lt;br /&gt;
&lt;br /&gt;
Privacy enhancing workshop series at NIST&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Full value exchange&lt;br /&gt;
&lt;br /&gt;
How to leverage against include services&lt;br /&gt;
&lt;br /&gt;
changing user expectations&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Free_People_Beyond_the_Next_10_Years_%E2%80%93_(Continuation_from_Wed_Session/Manifesto_Writing)&amp;diff=19687</id>
		<title>Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Free_People_Beyond_the_Next_10_Years_%E2%80%93_(Continuation_from_Wed_Session/Manifesto_Writing)&amp;diff=19687"/>
		<updated>2014-05-30T19:11:02Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: Created page with &amp;quot;'''Session Topic:''' “We Are The Last Generation of Free People”   Wednesday 1G &amp;amp; Thursday 4G  '''Convener:''' Kaliya Hamlin  '''Notes-taker(s):''' Kaliya Hamlin  '''Tags ...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' “We Are The Last Generation of Free People” &lt;br /&gt;
&lt;br /&gt;
Wednesday 1G &amp;amp; Thursday 4G&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
This session was called by Kaliya Hamlin to discuss the statement Julian Assange made in Dec 2013 at CCC in Germany.  He said paraphasing - ''we are the last generation of free people and there is about 10 years left to resist the trends that are proceeding and to make sure we don’t loose our freedom.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We began the session by articulating the things we were afraid of (these were subsequently clustered into 8 broad categories.  Each post-it note was written by one person and the read first set of bullets under each is are the text of those. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The next set of of bullets in blue were the solutions (which subsequently were clustered to with the 8 problem categories, but clearly some of the solutions are applicable to more then one problem cluster). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Inbetween articluating the problem and articulating the solution we also discussed how things were different now with technology. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Syping on Snail Mail happened - but was costly and more time consuming + potentially obvious that it was happening. &lt;br /&gt;
&lt;br /&gt;
We had tyrany - lack of freedom and the Divine right of Monarchy. &lt;br /&gt;
&lt;br /&gt;
Can law adapt to extreme power of technology?&lt;br /&gt;
&lt;br /&gt;
New: Economics - beyond reasonable - open field.  GPS v. Police &lt;br /&gt;
&lt;br /&gt;
Anonymity is related to cost of de-anonymizing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''ILLUMINATI - elite control'''&lt;br /&gt;
*	American Dominance / Imperialism &lt;br /&gt;
*	State controlled narrative of what is right/wrong, current events&lt;br /&gt;
*	Lack of randomness in the world&lt;br /&gt;
*	Invisible ubiquitous control of the powers of state by the monied elite&lt;br /&gt;
*	Breakaway civilization in space of elites lead by Musk and Theil &lt;br /&gt;
*	Centralized actors control decision making. This results in portions of society being increasingly marginalized - violence continues to be the primary regulatory tool. &lt;br /&gt;
*	What does unfreedom look like? what are we most concerned about? Loss of individual rights of choice to exist or function in a society you have to X or there will be Y punishment. &lt;br /&gt;
*	Elyseum, Hunger Games, Small ruling elite have total control over the vast majority of people. &lt;br /&gt;
*	Total subjugation to an arbitrary / involuntary collective. &lt;br /&gt;
&lt;br /&gt;
**	No Money in Politics&lt;br /&gt;
**	More local connectivity and empowerment&lt;br /&gt;
**	Community Rights Movement Ordinances&lt;br /&gt;
**	More Local Connectivity and Empowerment&lt;br /&gt;
**	No Money in Politics&lt;br /&gt;
**	Consumer Co-Ops as Tech Platforms&lt;br /&gt;
**	Deliberative Democratic Processes for all levels of government in systems&lt;br /&gt;
**	Transform Culture through institutional structures and processes&lt;br /&gt;
**	Disruption of Current Electorate Habits&lt;br /&gt;
**	Figure out how to “clear” issues triggering of collective shame and vulnerability &lt;br /&gt;
**	Insist that state systems be simply explained to regular citizens&lt;br /&gt;
**	Invest in “schools early” stage engagement in tech vs. lawsuits later&lt;br /&gt;
**	Stop Policy Laundering &lt;br /&gt;
**	Atoms are different then Bits &lt;br /&gt;
**	Bounties for whistle blower info&lt;br /&gt;
**	Producer Consumer healing - relational capitalism?&lt;br /&gt;
**	Sharing Economy - supporting it digitally in real way&lt;br /&gt;
**	Better democracy - measurable feedback systems - quantifiable plurality &lt;br /&gt;
**	Wealth / power transparency &lt;br /&gt;
&lt;br /&gt;
'''Online Tracking -&amp;gt; Offline Oppression'''&lt;br /&gt;
*	UN-Freedom “online” more and more affecting the “real world.&lt;br /&gt;
*	Organizing....collective action is practically inhibited to prevent change and social dissent. &lt;br /&gt;
&lt;br /&gt;
'''Violence / Accountability''' &lt;br /&gt;
*	Widespread unaccountable market for violence &lt;br /&gt;
*	Violent suppression of nonviolent dissent&lt;br /&gt;
**	Police / Military Accountability and Regulation&lt;br /&gt;
**	Empathy / Peaceful parenting&lt;br /&gt;
&lt;br /&gt;
'''Hivemind/Lack of Discourse''' &lt;br /&gt;
*	No divers and critical thinking&lt;br /&gt;
*	Total loss of individual autonomy&lt;br /&gt;
*	No disagreement = no diversity =no resilience&lt;br /&gt;
*	Death of Political Dissent&lt;br /&gt;
*	Hivemind by Radio Telepathy&lt;br /&gt;
*	Censored Content based on Political/Religious Ideology &lt;br /&gt;
*	Sock Puppetry + Astroturf-auto-matic detection mechanisms. &lt;br /&gt;
&lt;br /&gt;
'''Apathy'''&lt;br /&gt;
*	Indifference (People Accepting Surveillance, Censorship, etc as Normal). &lt;br /&gt;
**	Agorism&lt;br /&gt;
**	P2P Economy - crypto currencies, distributed exchange, local and personal production. &lt;br /&gt;
&lt;br /&gt;
'''Computer - Control'''&lt;br /&gt;
*	Algorithmic enforcement of societal norms.&lt;br /&gt;
**	Build respectful software for the world we want. &lt;br /&gt;
**	Distributed, Anonymous, Encrypted Mesh Cloud Networks and Storage&lt;br /&gt;
**	Search and seizure laws catch up with technology&lt;br /&gt;
**	Web protocols and application that empower individuals both in their access to synthesized information and in their control over distribution of information. Goal: Self-Balance&lt;br /&gt;
&lt;br /&gt;
'''Government Opacity'''&lt;br /&gt;
*	Lack of government transparency / punishment of whistleblowers&lt;br /&gt;
**	Government Transparency &lt;br /&gt;
**	Open Data is Not Enough - Citizen Tools public tools to sense make address challenges&lt;br /&gt;
**	MayOne SuperPAC&lt;br /&gt;
&lt;br /&gt;
'''Privacy'''&lt;br /&gt;
*	Privacy for the powerful, transparency for the weak &lt;br /&gt;
&lt;br /&gt;
*	No Privacy. &lt;br /&gt;
**	= no safe space &lt;br /&gt;
**	= no places/times where we can make ourselves vulnerable&lt;br /&gt;
**	= no diversity of ideas/behaviors ways of living.&lt;br /&gt;
**	= no resilience&lt;br /&gt;
&lt;br /&gt;
*	Privacy goes away completely. Government knows everything. &lt;br /&gt;
	Oops! It’s happened already!&lt;br /&gt;
&lt;br /&gt;
*	Unfreedom - There is no longer a safe space anywhere (on your person, in your home, in the cloud, etc) where individuals can store their personal info and data without the reis of it being seized, searched and compromised by an authoritative body. &lt;br /&gt;
&lt;br /&gt;
*	Ubiquitous Surveillance - by government &amp;amp; of each other.&lt;br /&gt;
&lt;br /&gt;
*	The Details of our lives are wholly-owned assets of third party entities. &lt;br /&gt;
&lt;br /&gt;
**	Data is recognized as property owned by the individual. &lt;br /&gt;
**	Work on technologies that improve privacy and security on the internet. &lt;br /&gt;
**	Other forms of violence - economic, psychological are acknowledged&lt;br /&gt;
**	Resistance the government systems of surveillance via local political bodies - city, county and state. &lt;br /&gt;
**	Breakdown Tight Hierarchy towards Decentralized. &lt;br /&gt;
&lt;br /&gt;
????&lt;br /&gt;
*	On facebook no one will hear me scream&lt;br /&gt;
**	Buy a Microphone &lt;br /&gt;
**	I don’t know the solution, but it has to be social, technical, political, economic legal etc. all in one.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=We_Are_The_Last_Generation_of_Free_People&amp;diff=19686</id>
		<title>We Are The Last Generation of Free People</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=We_Are_The_Last_Generation_of_Free_People&amp;diff=19686"/>
		<updated>2014-05-30T19:09:57Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' “We Are The Last Generation of Free People” &lt;br /&gt;
&lt;br /&gt;
Wednesday 1G &amp;amp; Thursday 4G&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
This session was called by Kaliya Hamlin to discuss the statement Julian Assange made in Dec 2013 at CCC in Germany.  He said paraphasing - ''we are the last generation of free people and there is about 10 years left to resist the trends that are proceeding and to make sure we don’t loose our freedom.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We began the session by articulating the things we were afraid of (these were subsequently clustered into 8 broad categories.  Each post-it note was written by one person and the read first set of bullets under each is are the text of those. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The next set of of bullets in blue were the solutions (which subsequently were clustered to with the 8 problem categories, but clearly some of the solutions are applicable to more then one problem cluster). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Inbetween articluating the problem and articulating the solution we also discussed how things were different now with technology. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Syping on Snail Mail happened - but was costly and more time consuming + potentially obvious that it was happening. &lt;br /&gt;
&lt;br /&gt;
We had tyrany - lack of freedom and the Divine right of Monarchy. &lt;br /&gt;
&lt;br /&gt;
Can law adapt to extreme power of technology?&lt;br /&gt;
&lt;br /&gt;
New: Economics - beyond reasonable - open field.  GPS v. Police &lt;br /&gt;
&lt;br /&gt;
Anonymity is related to cost of de-anonymizing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''ILLUMINATI - elite control'''&lt;br /&gt;
*	American Dominance / Imperialism &lt;br /&gt;
*	State controlled narrative of what is right/wrong, current events&lt;br /&gt;
*	Lack of randomness in the world&lt;br /&gt;
*	Invisible ubiquitous control of the powers of state by the monied elite&lt;br /&gt;
*	Breakaway civilization in space of elites lead by Musk and Theil &lt;br /&gt;
*	Centralized actors control decision making. This results in portions of society being increasingly marginalized - violence continues to be the primary regulatory tool. &lt;br /&gt;
*	What does unfreedom look like? what are we most concerned about? Loss of individual rights of choice to exist or function in a society you have to X or there will be Y punishment. &lt;br /&gt;
*	Elyseum, Hunger Games, Small ruling elite have total control over the vast majority of people. &lt;br /&gt;
*	Total subjugation to an arbitrary / involuntary collective. &lt;br /&gt;
&lt;br /&gt;
**	No Money in Politics&lt;br /&gt;
**	More local connectivity and empowerment&lt;br /&gt;
**	Community Rights Movement Ordinances&lt;br /&gt;
**	More Local Connectivity and Empowerment&lt;br /&gt;
**	No Money in Politics&lt;br /&gt;
**	Consumer Co-Ops as Tech Platforms&lt;br /&gt;
**	Deliberative Democratic Processes for all levels of government in systems&lt;br /&gt;
**	Transform Culture through institutional structures and processes&lt;br /&gt;
**	Disruption of Current Electorate Habits&lt;br /&gt;
**	Figure out how to “clear” issues triggering of collective shame and vulnerability &lt;br /&gt;
**	Insist that state systems be simply explained to regular citizens&lt;br /&gt;
**	Invest in “schools early” stage engagement in tech vs. lawsuits later&lt;br /&gt;
**	Stop Policy Laundering &lt;br /&gt;
**	Atoms are different then Bits &lt;br /&gt;
**	Bounties for whistle blower info&lt;br /&gt;
**	Producer Consumer healing - relational capitalism?&lt;br /&gt;
**	Sharing Economy - supporting it digitally in real way&lt;br /&gt;
**	Better democracy - measurable feedback systems - quantifiable plurality &lt;br /&gt;
**	Wealth / power transparency &lt;br /&gt;
&lt;br /&gt;
'''Online Tracking -&amp;gt; Offline Oppression'''&lt;br /&gt;
*	UN-Freedom “online” more and more affecting the “real world.&lt;br /&gt;
*	Organizing....collective action is practically inhibited to prevent change and social dissent. &lt;br /&gt;
&lt;br /&gt;
'''Violence / Accountability''' &lt;br /&gt;
*	Widespread unaccountable market for violence &lt;br /&gt;
*	Violent suppression of nonviolent dissent&lt;br /&gt;
**	Police / Military Accountability and Regulation&lt;br /&gt;
**	Empathy / Peaceful parenting&lt;br /&gt;
&lt;br /&gt;
'''Hivemind/Lack of Discourse''' &lt;br /&gt;
*	No divers and critical thinking&lt;br /&gt;
*	Total loss of individual autonomy&lt;br /&gt;
*	No disagreement = no diversity =no resilience&lt;br /&gt;
*	Death of Political Dissent&lt;br /&gt;
*	Hivemind by Radio Telepathy&lt;br /&gt;
*	Censored Content based on Political/Religious Ideology &lt;br /&gt;
*	Sock Puppetry + Astroturf-auto-matic detection mechanisms. &lt;br /&gt;
&lt;br /&gt;
'''Apathy'''&lt;br /&gt;
*	Indifference (People Accepting Surveillance, Censorship, etc as Normal). &lt;br /&gt;
**	Agorism&lt;br /&gt;
**	P2P Economy - crypto currencies, distributed exchange, local and personal production. &lt;br /&gt;
&lt;br /&gt;
'''Computer - Control'''&lt;br /&gt;
*	Algorithmic enforcement of societal norms.&lt;br /&gt;
**	Build respectful software for the world we want. &lt;br /&gt;
**	Distributed, Anonymous, Encrypted Mesh Cloud Networks and Storage&lt;br /&gt;
**	Search and seizure laws catch up with technology&lt;br /&gt;
**	Web protocols and application that empower individuals both in their access to synthesized information and in their control over distribution of information. Goal: Self-Balance&lt;br /&gt;
&lt;br /&gt;
'''Government Opacity'''&lt;br /&gt;
*	Lack of government transparency / punishment of whistleblowers&lt;br /&gt;
**	Government Transparency &lt;br /&gt;
**	Open Data is Not Enough - Citizen Tools public tools to sense make address challenges&lt;br /&gt;
**	MayOne SuperPAC&lt;br /&gt;
&lt;br /&gt;
'''Privacy'''&lt;br /&gt;
*	Privacy for the powerful, transparency for the weak &lt;br /&gt;
&lt;br /&gt;
*	No Privacy. &lt;br /&gt;
**	= no safe space &lt;br /&gt;
**	= no places/times where we can make ourselves vulnerable&lt;br /&gt;
**	= no diversity of ideas/behaviors ways of living.&lt;br /&gt;
**	= no resilience&lt;br /&gt;
&lt;br /&gt;
*	Privacy goes away completely. Government knows everything. &lt;br /&gt;
	Oops! It’s happened already!&lt;br /&gt;
&lt;br /&gt;
*	Unfreedom - There is no longer a safe space anywhere (on your person, in your home, in the cloud, etc) where individuals can store their personal info and data without the reis of it being seized, searched and compromised by an authoritative body. &lt;br /&gt;
&lt;br /&gt;
*	Ubiquitous Surveillance - by government &amp;amp; of each other.&lt;br /&gt;
&lt;br /&gt;
*	The Details of our lives are wholly-owned assets of third party entities. &lt;br /&gt;
&lt;br /&gt;
**	Data is recognized as property owned by the individual. &lt;br /&gt;
**	Work on technologies that improve privacy and security on the internet. &lt;br /&gt;
**	Other forms of violence - economic, psychological are acknowledged&lt;br /&gt;
**	Resistance the government systems of surveillance via local political bodies - city, county and state. &lt;br /&gt;
**	Breakdown Tight Hierarchy towards Decentralized. &lt;br /&gt;
&lt;br /&gt;
????&lt;br /&gt;
*	On facebook no one will hear me scream&lt;br /&gt;
**	Buy a Microphone &lt;br /&gt;
**	I don’t know the solution, but it has to be social, technical, political, economic legal etc. all in one.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19685</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19685"/>
		<updated>2014-05-30T18:55:28Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Wednesday May 7, 2014 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Engaging End Users – How Do We Get Consumers to Participate in Identity]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Join the Indieweb]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[We Are The Last Generation of Free People]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Engaging_End_Users_%E2%80%93_How_Do_We_Get_Consumers_to_Participate_in_Identity&amp;diff=19684</id>
		<title>Engaging End Users – How Do We Get Consumers to Participate in Identity</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Engaging_End_Users_%E2%80%93_How_Do_We_Get_Consumers_to_Participate_in_Identity&amp;diff=19684"/>
		<updated>2014-05-30T18:51:34Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Engaging End Users: How do we get consumers to participate in identity discussion?&lt;br /&gt;
&lt;br /&gt;
Tuesday 3Cå&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Eno Jackson&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Eno Jackson&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
[[File:IIW18_TU3C_Engaging_End_Users.jpg ‎]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:IIW18_TU3C_Engaging_End_Users.jpg&amp;diff=19683</id>
		<title>File:IIW18 TU3C Engaging End Users.jpg</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:IIW18_TU3C_Engaging_End_Users.jpg&amp;diff=19683"/>
		<updated>2014-05-30T18:49:59Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Engaging_End_Users_%E2%80%93_How_Do_We_Get_Consumers_to_Participate_in_Identity&amp;diff=19682</id>
		<title>Engaging End Users – How Do We Get Consumers to Participate in Identity</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Engaging_End_Users_%E2%80%93_How_Do_We_Get_Consumers_to_Participate_in_Identity&amp;diff=19682"/>
		<updated>2014-05-30T18:47:41Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: Created page with &amp;quot;'''Session Topic:''' Engaging End Users: How do we get consumers to participate in identity discussion?  Tuesday 3Cå  '''Convener:''' Eno Jackson  '''Notes-taker(s):''' Eno J...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Engaging End Users: How do we get consumers to participate in identity discussion?&lt;br /&gt;
&lt;br /&gt;
Tuesday 3Cå&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Eno Jackson&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Eno Jackson&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=19681</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=19681"/>
		<updated>2014-05-30T18:38:19Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;Big&amp;gt; Welcome to the Internet Identity Workshop (IIW) Wiki &amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.internetidentityworkshop.com WE HAVE A WEBSITE/BLOG TOO!] &lt;br /&gt;
&lt;br /&gt;
* To get updates regarding IIW  [http://lists.idcommons.net/lists/subscribe/iiwinfo subscribe here].&lt;br /&gt;
&lt;br /&gt;
* To join the identity commons community list and dialoguing about user-centric and other identity initiatives [http://lists.idcommons.net/lists/subscribe/community you can do so here].&lt;br /&gt;
&lt;br /&gt;
* To learn more about identity commons linking together efforts and supporting innovation in user-centric digital identity [http://www.idcommons.net/ visit the website]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Next Internet Identity Workshops ===&lt;br /&gt;
* '''IIW 19 is October 28-30, 2014'''&lt;br /&gt;
**[[Note Form]]&lt;br /&gt;
&lt;br /&gt;
=== Previous Internet Identity Workshops &amp;amp; Satellite Events ===&lt;br /&gt;
* '''IIW 18 May 6-8, 2014'''&lt;br /&gt;
**[[IIW 18 Proposed Topics]]&lt;br /&gt;
**[[IIW 18 Notes]]&lt;br /&gt;
&lt;br /&gt;
* '''IIW 17 October 22-24, 2013''' &lt;br /&gt;
** [[IIW 17 Proposed Topics]]&lt;br /&gt;
** [[IIW 17 Notes]]&lt;br /&gt;
** [http://iiw.idcommons.net/File:IIW17_BookofProceedings_2103B.pdf IIW17 Book of Proceedings]&lt;br /&gt;
&lt;br /&gt;
* '''IIW #16 May 7-9 2013&lt;br /&gt;
** [[IIW 16 Proposed Topics]]&lt;br /&gt;
** [[IIW 16 Notes]]&lt;br /&gt;
** [http://iiw.idcommons.net/images/1/13/IIW16_Book_of_Proceedings.PDF IIW 16 Book of Proceedings]&lt;br /&gt;
&lt;br /&gt;
* '''IIW #15 October  23-25 2012'''&lt;br /&gt;
** [[IIW 15 Proposed Topics]]&lt;br /&gt;
** [[IIW 15 Notes]]&lt;br /&gt;
** [http://iiw.idcommons.net/File:IIW15_Book_of_Proceedings.pdf IIW 15 Book of Proceedings]&lt;br /&gt;
&lt;br /&gt;
* '''IIW #14 May 1-3 2012'''&lt;br /&gt;
**[[IIW 14 Proposed Topics]]&lt;br /&gt;
**[[IIW 14 Notes]]&lt;br /&gt;
**[http://iiw.idcommons.net/images/5/51/IIW14_BOP_PDF.pdf IIW 14 Book of Proceedings]&lt;br /&gt;
&lt;br /&gt;
* IIW-Satellite Sydney&lt;br /&gt;
** [[IIW Satellite Sydney Notes]]&lt;br /&gt;
&lt;br /&gt;
* IIW-Satelite DC&lt;br /&gt;
** [http://iiwsatellitedc2012.eventbrite.com/ Attendee List]&lt;br /&gt;
** [[IIW Satelite DC Proposed Topics]]&lt;br /&gt;
** [[IIW Satellite DC Notes]]&lt;br /&gt;
&lt;br /&gt;
* IIW #13 October 18-20 2011&lt;br /&gt;
** [[iiw13 Proposed Topics]]&lt;br /&gt;
** [[IIW 13 Notes]]&lt;br /&gt;
** [[&amp;quot;NSTIC Day&amp;quot; Proposed Agenda]]&lt;br /&gt;
** [[http://iiw.idcommons.net/File:IIW13_BOP_PDF.pdf IIW 13 Book of Proceedings]]&lt;br /&gt;
&lt;br /&gt;
* IIW #12 May 3-5, 2011 at the &amp;lt;span class=&amp;quot;plainlinks&amp;quot;&amp;gt;[http://itshumour.blogspot.com/2009/09/top-10-hilarious-quotes.html &amp;lt;span style=&amp;quot;color:#000000;font-weight:normal; text-decoration:none!important;background:none!important; text-decoration:none;&amp;quot;&amp;gt;hilarious quotes&amp;lt;/span&amp;gt;] Computer HIstory Museum in Mountain View California [http://www.casinoluckywin.com/en/games/slot_games/ best online slots]&lt;br /&gt;
** [[iiw12 Proposed Topics]]&lt;br /&gt;
** [[IIW 12 Notes]]&lt;br /&gt;
&lt;br /&gt;
* Identity Collaboration Day, Feb 14, 2011 - Day before RSA, for discussion of user-centric, enterprise [http://www.hockeychamp2014.com/world-hockey-championships.html IIHF Hockey] and government identity initiatives. &lt;br /&gt;
** [http://www.idcolab.eventbrite.com ID Collaboration Day Registration/Description]&lt;br /&gt;
** [[IDCollab Proposed Topics]]&lt;br /&gt;
** [[IDCollab Day Notes]]&lt;br /&gt;
&lt;br /&gt;
* IIW #11 Fall 2010 [[iiw11]] Nov 2-4, Tuesday-Thursday at the Computer HIstory Museum in Mountain View California&lt;br /&gt;
** [[Notes IIW11]]&lt;br /&gt;
** [http://www.internetidentityworkshop.com/what-is-iiw/ Responses to IIW is...] [http://bit.ly/dt3ruz Values of IIW]&lt;br /&gt;
&lt;br /&gt;
* [[iiw-europe-1|IIW Europe]] in London Monday October 11 (before RSA Europe) at the University of London [http://www.imcredo.com/services/ppc/ Adwords Management]&lt;br /&gt;
** [[iiw-europe-1-Notes]]&lt;br /&gt;
** [[iiw-europe-1-Reflection]] As a Result of Today.... &lt;br /&gt;
&lt;br /&gt;
* [[iiw-east-1|IIW East Coast]] in DC September 9-10 Thursday, Friday at the Josephine Butler Parks Center (following the Gov 2.0 Summit) the &amp;lt;span class=&amp;quot;plainlinks&amp;quot;&amp;gt;[http://www.thefunnyquotessayings.com/cool-hilarious-funny-quotes-sayings/ &amp;lt;span style=&amp;quot;color:black;font-weight:normal; text-decoration:none!important; background:none!important; text-decoration:none;&amp;quot;&amp;gt;funny quotes sayings&amp;lt;/span&amp;gt;] theme will be ''Open Identity for Open Government'' &lt;br /&gt;
** [[Notes_IIW-East]]&lt;br /&gt;
** [[As a result of day 1 at IIW-East]]&lt;br /&gt;
&lt;br /&gt;
* #10: Spring 2010 [[iiw10]] May 17-19 at the Computer History Museum. &lt;br /&gt;
** [[Notes IIW10]]&lt;br /&gt;
&lt;br /&gt;
* #9: Fall 2009 [[iiw9]] TUESDAY November 3 to THURSDAY November 5. &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #8: Spring 2009 [[iiw8]] - '''May 18-20, 2009''' &lt;br /&gt;
** [[Notes_iiw8]]&lt;br /&gt;
&lt;br /&gt;
* #7: Fall [[iiw2008b]] (2008B)- '''Nov 10-12''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_08b]]&lt;br /&gt;
&lt;br /&gt;
* 6: Spring [[iiw2008a]]  (2008A)- '''May 12-14, 2008''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_2008a]]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.idcommons.net/index.php/Iiw2007b 5: December 3-5, 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop_2007 4: May 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006b 3: December 2006 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006 2: May 2006 - - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://www.socialtext.net/iiw2005/index.cgi?internet_identity_workshop_2005 1: October 2005 - Berkeley, CA]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Open Spaces ===&lt;br /&gt;
&lt;br /&gt;
Identity Open Space events are co-produced by the IIW team (Phil, Kaliya, Doc) in collaboration with other organizations and events. To date we have worked with Digital Identity World and the Liberty Alliance. [http://www.grabcasinobonus.com/casino-bonuses/ Mobile Casino Bonus] We are open to working with a variety organizations - if you are interested please don't hesitate to contact us. [http://ios.windley.com/wiki/IOSSF September 2007 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSBrussels May 2007 following a Liberty Alliance Meeting in Brussels, Belgium]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSantaClara September 2006 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Birds of a Feather Meetings ===&lt;br /&gt;
&lt;br /&gt;
June 2006 [http://www.identitygang.org/ Identity Gang Birds of a Feather Session] at Burton Group Conference, San Francisco&lt;br /&gt;
&lt;br /&gt;
January 2006 [http://www.socialtext.net/iiw2005/index.cgi?identity_speed_geeking_o_reilly_emerging_telephony_conference Identity Speed Geeking Session] at O'Reilly's  Emerging Telephony Conference&lt;br /&gt;
&lt;br /&gt;
December 2005 [http://www.socialtext.net/iiw2005/index.cgi?informational_morning_for_developers Pre-Syndicate Informational Morning for Developers]&lt;br /&gt;
/span&amp;gt;] commons linking together efforts and supporting innovation in user-centric digital identity [http://t.co/rRM74eb Visit the website]&lt;br /&gt;
&lt;br /&gt;
=== Books of Proceedings ===&lt;br /&gt;
&lt;br /&gt;
[[ALL Book of Proceedings PDFs]]&lt;br /&gt;
&lt;br /&gt;
[[Subject Specific Note Collections]]&lt;br /&gt;
&lt;br /&gt;
=== Previous Attendees Lists ===&lt;br /&gt;
 &lt;br /&gt;
* IIW 18: http://www.eventbrite.com/event/10266396067/efbnen&lt;br /&gt;
* IIW 17: http://iiw17.eventbrite.com/&lt;br /&gt;
* IIW 16: http://iiw16.eventbrite.com/&lt;br /&gt;
* IIW 15: http://www.eventbrite.com/event/3926801168/efbnen&lt;br /&gt;
* IIW 14: http://www.eventbrite.com/event/2785843533/efbnen&lt;br /&gt;
* IIW 13: http://www.eventbrite.com/e/internet-identity-workshop-xiii-13-2011b-tickets-1923616589&lt;br /&gt;
* IIW 12: https://www.eventbrite.com/e/internet-identity-workshop-xii-12-2011a-tickets-1189831819 &lt;br /&gt;
* IIW 11: http://www.eventbrite.com/event/785398147/efbnen&lt;br /&gt;
* IIW 10:  http://www.eventbrite.com/e/internet-identity-workshop-10-2010a-tickets-499632414&lt;br /&gt;
* IIW 09: http://www.eventbrite.com/e/internet-identity-workshop-9-2009b-tickets-394204075&lt;br /&gt;
* IIW 08: http://www.eventbrite.com/e/internet-identity-workshop-8-2009a-tickets-288845946&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=VRM_Adoption_Case_Study_%E2%80%93_MYDEX&amp;diff=19679</id>
		<title>VRM Adoption Case Study – MYDEX</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=VRM_Adoption_Case_Study_%E2%80%93_MYDEX&amp;diff=19679"/>
		<updated>2014-05-16T17:18:45Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' VRM Adoptions Case Study:  MYDEX cic (How we tell it; where we are; what Mydex looks like including: peek at UK IDAP)&lt;br /&gt;
&lt;br /&gt;
Wednesday 2A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' William Heath&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' William Heath&lt;br /&gt;
&lt;br /&gt;
'''Tags for this session – Technology discussed/ideas considered:'''&lt;br /&gt;
PDS Personal clouds trust frameworks VRM&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Mydex CIC is a social-enterprise VRM platform, live at http://pds.mydex.org and with contracts in UK market including UK government ID assurance provider. Having a national government agreeing to contract with individuals based on credentials held by the individual is potentially a significant VRM breakthrough. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First we heard how Mydex presents the big VRM picture to the uninitiated (which is still the majority). “Personal control over personal data” does not much resonate with consumers but there is a real political consensus about the fact there is a problem and personal control over personal data is a policy each British political party is committed to. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
All the pols agree on that. But what they don’t get is how to implement personal control over personal data, and what the implications of it be. Aim is to set this out and to explain why it is a win-win for all parties: it’s a global problem, which affects organisations and individuals. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What Mydex does &lt;br /&gt;
&lt;br /&gt;
Mydex offers personal data stores and connections, wrapped in a legal &amp;amp; technical trust framework. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The community needs diversity and interoperability in PDS providers. Key differentiating determinants of trust will be&lt;br /&gt;
&lt;br /&gt;
1. governance &amp;amp; legal form: Mydex takes the legal form of Community Interest Company, limited by shares, highly transparent, asset locked and regulated in the returns it can offer shareholders. &lt;br /&gt;
&lt;br /&gt;
2. Commercial (or business) model: Mydex is free in perpetuity to individuals, making a small micropayment charge to connecting organisations and apps&lt;br /&gt;
&lt;br /&gt;
3. Legal basis: Mydex uses contract law and places the individual in the role of “data controller” in data protection law&lt;br /&gt;
&lt;br /&gt;
4. Technical: Mydex has turned away from esoteric and untested tech and moved pretty much entirely to open course tech and standard tools, supporting multiple ID protocols (OpenID, Mozilla Persona, SAML, Shibboleth)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Market adoption has started with contracts in finance, media, local government and housing; also a potentially very significant contract for UK government ID assurance services. The proposition to individuals is convenence, control, trust and value. To organisations it’s cost savings, reduced regulatory overhead and opening the path to new services.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What Mydex does&lt;br /&gt;
&lt;br /&gt;
We did a live walkthrough of the sandbox site (which replicates the live service) populate with dummy data. This showed data entry, management, connections, visualisations of the data and account management including “download my data” to enable switching to a different service. &lt;br /&gt;
&lt;br /&gt;
The live sites are:&lt;br /&gt;
 &lt;br /&gt;
- [http://www.sbx.mydex.org sbx.mydex.org]: the Mydex sandbox where you can use dummy data&lt;br /&gt;
&lt;br /&gt;
- [http://dev.mydex.org dev.mydex.org] - developer resources eg data schema, new data schema requests, API resources&lt;br /&gt;
&lt;br /&gt;
- [http://pds.mydex.org pds.mydex.org] where people can get a personal data store.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Place in the market&lt;br /&gt;
&lt;br /&gt;
The contracted connections are still in the process of implementation. For this reason user numbers are still only in the hundreds (ie people curious to see what Mydex looks like, even though they are not yet able to use it to connect). We also saw an outline of the UK government ID assurance service user journey, based on a mixed information set keyed in by the user. The UK government ID assurance programme rolls out in the course of 2014.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19678</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19678"/>
		<updated>2014-05-16T17:17:25Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Session 4 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Engaging End Users – How Do We Get Consumers to Participate in Identity]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Join the Indieweb]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OpenID_Connect_%E2%80%93_Logout/Session_Mgmt_(Part_1)&amp;diff=19677</id>
		<title>OpenID Connect – Logout/Session Mgmt (Part 1)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OpenID_Connect_%E2%80%93_Logout/Session_Mgmt_(Part_1)&amp;diff=19677"/>
		<updated>2014-05-16T17:15:28Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Open ID Connect: Session Management / Logout Discussion&lt;br /&gt;
(Part 1 &amp;amp; Part 2) &lt;br /&gt;
&lt;br /&gt;
Tuesday 4A &amp;amp; 5A&lt;br /&gt;
&lt;br /&gt;
'''Convener:'''  Mike Jones; John Bradley; Naveen Agarwal	&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s)''': Mike Jones&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Participants also included:&lt;br /&gt;
 &lt;br /&gt;
Torsten Lodderstedt&lt;br /&gt;
&lt;br /&gt;
Chuck Mortimore&lt;br /&gt;
&lt;br /&gt;
Brian Campbell&lt;br /&gt;
&lt;br /&gt;
Alan Karp&lt;br /&gt;
&lt;br /&gt;
Breno de Medeiros&lt;br /&gt;
&lt;br /&gt;
John Pinter&lt;br /&gt;
&lt;br /&gt;
Bill Mills&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Back channel logout&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Multiple RP sessions might be logged in at once&lt;br /&gt;
&lt;br /&gt;
OP doesn't have session identifiers&lt;br /&gt;
&lt;br /&gt;
Torsten - back channel logout has been shown to cause problems&lt;br /&gt;
&lt;br /&gt;
Chuck - the session-based SAML logout doesn't work well and isn't supported&lt;br /&gt;
&lt;br /&gt;
Brian - requiring JavaScript on every page a non-starter in enterprise contexts&lt;br /&gt;
&lt;br /&gt;
Alan Karp - Better UI could help users better understand what's actually going on&lt;br /&gt;
&lt;br /&gt;
John - one requirement can be extending session lifetimes across sessions&lt;br /&gt;
&lt;br /&gt;
Chuck - The only session state typically present is the session cookie&lt;br /&gt;
&lt;br /&gt;
Brian - SAML has fragile redirect chain&lt;br /&gt;
*                Another means is for the IdP to do a GET to each RP endpoint&lt;br /&gt;
*               Ping is currently implementing something like that&lt;br /&gt;
&lt;br /&gt;
Naveen - Unless the browser tab is active, the JavaScript logout doesn't work&lt;br /&gt;
&lt;br /&gt;
Naveen - Yahoo had a variant where they stored state for all sessions in a single cookie&lt;br /&gt;
&lt;br /&gt;
Brian - Doing GETs to single-pixel images, which trigger logouts&lt;br /&gt;
&lt;br /&gt;
John - The RP could check the referer if it wants to secure the logout&lt;br /&gt;
*                But in general, not protectable against XSRF&lt;br /&gt;
&lt;br /&gt;
Chuck - Browsers are getting better about preventing cookie state manipulation in iframes&lt;br /&gt;
&lt;br /&gt;
Torsten - Will check what DT is doing&lt;br /&gt;
&lt;br /&gt;
John - ID Token &amp;quot;exp&amp;quot; claim doesn't trigger logout in practice&lt;br /&gt;
&lt;br /&gt;
Naveen - We could just document both front channel mechanisms as optional&lt;br /&gt;
*                Enterprises might choose one method, the Web might choose another&lt;br /&gt;
*                We should document both as a next step&lt;br /&gt;
&lt;br /&gt;
Mike - If we support multiple mechanisms, the RPs would get to decide&lt;br /&gt;
&lt;br /&gt;
John - Back channel notification is yet a third mechanism&lt;br /&gt;
&lt;br /&gt;
David Pinter - The front channel won't always be available&lt;br /&gt;
&lt;br /&gt;
Bill Mills - Security policy may require ability to kill all sessions&lt;br /&gt;
&lt;br /&gt;
John - A compromise back channel mechanism is notifying RPs on the back channel of a state change&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Mechanisms:&lt;br /&gt;
*                postMessage:&lt;br /&gt;
**                              Pro: RPs get notifications, minimal web traffic&lt;br /&gt;
**                              Con: Requires RP JavaScript&lt;br /&gt;
***                                   Doesn't work when RP tab not active&lt;br /&gt;
*               image/iframe GETs:&lt;br /&gt;
**                              Pro: Doesn't require JavaScript&lt;br /&gt;
***                                   Still uses session cookies&lt;br /&gt;
**                              Con: IdP needs to track active RP sessions&lt;br /&gt;
***                                   Ugly logout page&lt;br /&gt;
***                                   All RPs might not be notified before the browser is closed&lt;br /&gt;
*               backchannel notifications:&lt;br /&gt;
**                              Pro: Works even when RP tab not active&lt;br /&gt;
**                              Con: Requires RP logic to identify and communicate with session to logout&lt;br /&gt;
***                                   IdP scaling issues&lt;br /&gt;
 &lt;br /&gt;
Chuck - Current spec doesn't work for enterprise use cases because of JavaScript requirement&lt;br /&gt;
*               and because the RP must be active for the logout to work&lt;br /&gt;
&lt;br /&gt;
Chuck - We didn't put &amp;quot;jti&amp;quot; in the ID Token - we could for enabling logout&lt;br /&gt;
*               That would enable correlating back channel notifications received to active sessions&lt;br /&gt;
*               Open questions about whether to use the same ID in multiple responses to same RP&lt;br /&gt;
*               Probably use a separate session identifier that is not &amp;quot;jti&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Dale - Back channel notification is effectively ID Token revocation&lt;br /&gt;
&lt;br /&gt;
Chuck - The OP wants to be authoritative for the session ID&lt;br /&gt;
&lt;br /&gt;
Chuck - Revoking a session could be done like an OAuth revocation&lt;br /&gt;
*               OAuth revocation supports CORS and JSONP&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Actions:&lt;br /&gt;
*               Add image/iframe description to Session Management&lt;br /&gt;
*               Also describe back channel mechanism&lt;br /&gt;
*               Then we decide what to do after that&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Naveen, Breno - Google is planning to build a token caching layer&lt;br /&gt;
*               It would get tokens at login time and clear them at logout&lt;br /&gt;
*               It would send notifications when things change&lt;br /&gt;
*               It would communicate internally with postMessage&lt;br /&gt;
*               postMessage requires a security layer&lt;br /&gt;
&lt;br /&gt;
George - How is this like the Trusted Agent in the Native Applications work?&lt;br /&gt;
&lt;br /&gt;
Naveen - It's a lot like that&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OpenID_Connect_%E2%80%93_Logout/Session_Mgmt_(Part_2)&amp;diff=19676</id>
		<title>OpenID Connect – Logout/Session Mgmt (Part 2)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OpenID_Connect_%E2%80%93_Logout/Session_Mgmt_(Part_2)&amp;diff=19676"/>
		<updated>2014-05-16T17:15:02Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: Created page with &amp;quot;'''Session Topic:''' Open ID Connect: Session Management / Logout Discussion (Part 1 &amp;amp; Part 2)   Tuesday 4A &amp;amp; 5A  '''Convener:'''  Mike Jones; John Bradley; Naveen Agarwal	  '...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Open ID Connect: Session Management / Logout Discussion&lt;br /&gt;
(Part 1 &amp;amp; Part 2) &lt;br /&gt;
&lt;br /&gt;
Tuesday 4A &amp;amp; 5A&lt;br /&gt;
&lt;br /&gt;
'''Convener:'''  Mike Jones; John Bradley; Naveen Agarwal	&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s)''': Mike Jones&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Participants also included:&lt;br /&gt;
 &lt;br /&gt;
Torsten Lodderstedt&lt;br /&gt;
&lt;br /&gt;
Chuck Mortimore&lt;br /&gt;
&lt;br /&gt;
Brian Campbell&lt;br /&gt;
&lt;br /&gt;
Alan Karp&lt;br /&gt;
&lt;br /&gt;
Breno de Medeiros&lt;br /&gt;
&lt;br /&gt;
John Pinter&lt;br /&gt;
&lt;br /&gt;
Bill Mills&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Back channel logout&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Multiple RP sessions might be logged in at once&lt;br /&gt;
&lt;br /&gt;
OP doesn't have session identifiers&lt;br /&gt;
&lt;br /&gt;
Torsten - back channel logout has been shown to cause problems&lt;br /&gt;
&lt;br /&gt;
Chuck - the session-based SAML logout doesn't work well and isn't supported&lt;br /&gt;
&lt;br /&gt;
Brian - requiring JavaScript on every page a non-starter in enterprise contexts&lt;br /&gt;
&lt;br /&gt;
Alan Karp - Better UI could help users better understand what's actually going on&lt;br /&gt;
&lt;br /&gt;
John - one requirement can be extending session lifetimes across sessions&lt;br /&gt;
&lt;br /&gt;
Chuck - The only session state typically present is the session cookie&lt;br /&gt;
&lt;br /&gt;
Brian - SAML has fragile redirect chain&lt;br /&gt;
*                Another means is for the IdP to do a GET to each RP endpoint&lt;br /&gt;
*               Ping is currently implementing something like that&lt;br /&gt;
&lt;br /&gt;
Naveen - Unless the browser tab is active, the JavaScript logout doesn't work&lt;br /&gt;
&lt;br /&gt;
Naveen - Yahoo had a variant where they stored state for all sessions in a single cookie&lt;br /&gt;
&lt;br /&gt;
Brian - Doing GETs to single-pixel images, which trigger logouts&lt;br /&gt;
&lt;br /&gt;
John - The RP could check the referer if it wants to secure the logout&lt;br /&gt;
*                But in general, not protectable against XSRF&lt;br /&gt;
&lt;br /&gt;
Chuck - Browsers are getting better about preventing cookie state manipulation in iframes&lt;br /&gt;
&lt;br /&gt;
Torsten - Will check what DT is doing&lt;br /&gt;
&lt;br /&gt;
John - ID Token &amp;quot;exp&amp;quot; claim doesn't trigger logout in practice&lt;br /&gt;
&lt;br /&gt;
Naveen - We could just document both front channel mechanisms as optional&lt;br /&gt;
*                Enterprises might choose one method, the Web might choose another&lt;br /&gt;
*                We should document both as a next step&lt;br /&gt;
&lt;br /&gt;
Mike - If we support multiple mechanisms, the RPs would get to decide&lt;br /&gt;
&lt;br /&gt;
John - Back channel notification is yet a third mechanism&lt;br /&gt;
&lt;br /&gt;
David Pinter - The front channel won't always be available&lt;br /&gt;
&lt;br /&gt;
Bill Mills - Security policy may require ability to kill all sessions&lt;br /&gt;
&lt;br /&gt;
John - A compromise back channel mechanism is notifying RPs on the back channel of a state change&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Mechanisms:&lt;br /&gt;
*                postMessage:&lt;br /&gt;
**                              Pro: RPs get notifications, minimal web traffic&lt;br /&gt;
**                              Con: Requires RP JavaScript&lt;br /&gt;
***                                   Doesn't work when RP tab not active&lt;br /&gt;
*               image/iframe GETs:&lt;br /&gt;
**                              Pro: Doesn't require JavaScript&lt;br /&gt;
***                                   Still uses session cookies&lt;br /&gt;
**                              Con: IdP needs to track active RP sessions&lt;br /&gt;
***                                   Ugly logout page&lt;br /&gt;
***                                   All RPs might not be notified before the browser is closed&lt;br /&gt;
*               backchannel notifications:&lt;br /&gt;
**                              Pro: Works even when RP tab not active&lt;br /&gt;
**                              Con: Requires RP logic to identify and communicate with session to logout&lt;br /&gt;
***                                   IdP scaling issues&lt;br /&gt;
 &lt;br /&gt;
Chuck - Current spec doesn't work for enterprise use cases because of JavaScript requirement&lt;br /&gt;
*               and because the RP must be active for the logout to work&lt;br /&gt;
&lt;br /&gt;
Chuck - We didn't put &amp;quot;jti&amp;quot; in the ID Token - we could for enabling logout&lt;br /&gt;
*               That would enable correlating back channel notifications received to active sessions&lt;br /&gt;
*               Open questions about whether to use the same ID in multiple responses to same RP&lt;br /&gt;
*               Probably use a separate session identifier that is not &amp;quot;jti&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Dale - Back channel notification is effectively ID Token revocation&lt;br /&gt;
&lt;br /&gt;
Chuck - The OP wants to be authoritative for the session ID&lt;br /&gt;
&lt;br /&gt;
Chuck - Revoking a session could be done like an OAuth revocation&lt;br /&gt;
*               OAuth revocation supports CORS and JSONP&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Actions:&lt;br /&gt;
*               Add image/iframe description to Session Management&lt;br /&gt;
*               Also describe back channel mechanism&lt;br /&gt;
*               Then we decide what to do after that&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Naveen, Breno - Google is planning to build a token caching layer&lt;br /&gt;
*               It would get tokens at login time and clear them at logout&lt;br /&gt;
*               It would send notifications when things change&lt;br /&gt;
*               It would communicate internally with postMessage&lt;br /&gt;
*               postMessage requires a security layer&lt;br /&gt;
&lt;br /&gt;
George - How is this like the Trusted Agent in the Native Applications work?&lt;br /&gt;
&lt;br /&gt;
Naveen - It's a lot like that&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19675</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19675"/>
		<updated>2014-05-16T17:13:18Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Session 3 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Engaging End Users – How Do We Get Consumers to Participate in Identity]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Join the Indieweb]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[ID Web/Literacy and Leverage – Sovereign By Design]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19674</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19674"/>
		<updated>2014-05-16T17:11:00Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Session 3 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Join the Indieweb]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[ID Web/Literacy and Leverage – Sovereign By Design]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Ethical_Data_Handling&amp;diff=19673</id>
		<title>Ethical Data Handling</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Ethical_Data_Handling&amp;diff=19673"/>
		<updated>2014-05-16T17:06:36Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Ethical Data Handling:  What is it? What are the obstacles? What is success?&lt;br /&gt;
&lt;br /&gt;
Tuesday 3E&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Robin Wilton&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Robin Wilton&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:''' &lt;br /&gt;
Personal data, ethics, privacy, harm&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
We used four topics relating to personal data processing, as a framework for the discussion:&lt;br /&gt;
&lt;br /&gt;
* The principle of “no surprises” (if users found out what you were doing with their data, would they be unpleasantly surprised?)&lt;br /&gt;
* The idea of “ethical dilution” (that the more data passes from one controller to another, the less responsible any of them feels towards the data subject)&lt;br /&gt;
* Ethical issues in multi-stakeholder cases&lt;br /&gt;
* Ethical issues in multi-context cases&lt;br /&gt;
&lt;br /&gt;
Some ethical factors appeared across several topics – for instance,&lt;br /&gt;
&lt;br /&gt;
* User expectations, and informedness&lt;br /&gt;
* Predictability and determinism, and their role as a trust factor&lt;br /&gt;
* Power imbalances (including economic imbalances)&lt;br /&gt;
* Cost/risk assessment, harm as a privacy metric&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19672</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19672"/>
		<updated>2014-05-16T17:06:20Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Session 3 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
3K/ [[Join the Indieweb]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[ID Web/Literacy and Leverage – Sovereign By Design]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19671</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19671"/>
		<updated>2014-05-16T17:06:08Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Session 3 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Ethical Data Handling]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
3K/ [[Join the Indieweb]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[ID Web/Literacy and Leverage – Sovereign By Design]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Ethical_Data_Handling&amp;diff=19670</id>
		<title>Ethical Data Handling</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Ethical_Data_Handling&amp;diff=19670"/>
		<updated>2014-05-16T17:05:40Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: Blanked the page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=VRM_Adoption_Case_Study_%E2%80%93_MYDEX&amp;diff=19669</id>
		<title>VRM Adoption Case Study – MYDEX</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=VRM_Adoption_Case_Study_%E2%80%93_MYDEX&amp;diff=19669"/>
		<updated>2014-05-16T17:04:34Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' VRM Adoptions Case Study:  MYDEX cic (How we tell it; where we are; what Mydex looks like including: peek at UK IDAP)&lt;br /&gt;
&lt;br /&gt;
Wednesday 2A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' William Heath&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' William Heath&lt;br /&gt;
&lt;br /&gt;
'''Tags for this session – Technology discussed/ideas considered:'''&lt;br /&gt;
PDS Personal clouds trust frameworks VRM&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Mydex CIC is a social-enterprise VRM platform, live atpds.mydex.org and with contracts in UK market including UK government ID assurance provider. Having a national government agreeing to contract with individuals based on credentials held by the individual is potentially a significant VRM breakthrough. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First we heard how Mydex presents the big VRM picture to the uninitiated (which is still the majority). “Personal control over personal data” does not much resonate with consumers but there is a real political consensus about the fact there is a problem and personal control over personal data is a policy each British political party is committed to. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
All the pols agree on that. But what they don’t get is how to implement personal control over personal data, and what the implications of it be. Aim is to set this out and to explain why it is a win-win for all parties: it’s a global problem, which affects organisations and individuals. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What Mydex does &lt;br /&gt;
&lt;br /&gt;
Mydex offers personal data stores and connections, wrapped in a legal &amp;amp; technical trust framework. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The community needs diversity and interoperability in PDS providers. Key differentiating determinants of trust will be&lt;br /&gt;
&lt;br /&gt;
1. governance &amp;amp; legal form: Mydex takes the legal form of Community Interest Company, limited by shares, highly transparent, asset locked and regulated in the returns it can offer shareholders. &lt;br /&gt;
&lt;br /&gt;
2. Commercial (or business) model: Mydex is free in perpetuity to individuals, making a small micropayment charge to connecting organisations and apps&lt;br /&gt;
&lt;br /&gt;
3. Legal basis: Mydex uses contract law and places the individual in the role of “data controller” in data protection law&lt;br /&gt;
&lt;br /&gt;
4. Technical: Mydex has turned away from esoteric and untested tech and moved pretty much entirely to open course tech and standard tools, supporting multiple ID protocols (OpenID, Mozilla Persona, SAML, Shibboleth)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Market adoption has started with contracts in finance, media, local government and housing; also a potentially very significant contract for UK government ID assurance services. The proposition to individuals is convenence, control, trust and value. To organisations it’s cost savings, reduced regulatory overhead and opening the path to new services.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What Mydex does&lt;br /&gt;
&lt;br /&gt;
We did a live walkthrough of the sandbox site (which replicates the live service) populate with dummy data. This showed data entry, management, connections, visualisations of the data and account management including “download my data” to enable switching to a different service. &lt;br /&gt;
&lt;br /&gt;
The live sites are:&lt;br /&gt;
 &lt;br /&gt;
- [http://www.sbx.mydex.org sbx.mydex.org]: the Mydex sandbox where you can use dummy data&lt;br /&gt;
&lt;br /&gt;
- [http://dev.mydex.org dev.mydex.org] - developer resources eg data schema, new data schema requests, API resources&lt;br /&gt;
&lt;br /&gt;
- [http://pds.mydex.org pds.mydex.org] where people can get a personal data store.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Place in the market&lt;br /&gt;
&lt;br /&gt;
The contracted connections are still in the process of implementation. For this reason user numbers are still only in the hundreds (ie people curious to see what Mydex looks like, even though they are not yet able to use it to connect). We also saw an outline of the UK government ID assurance service user journey, based on a mixed information set keyed in by the user. The UK government ID assurance programme rolls out in the course of 2014.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=VRM_(Vendor_Relationship_Management)_Progress_Report&amp;diff=19668</id>
		<title>VRM (Vendor Relationship Management) Progress Report</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=VRM_(Vendor_Relationship_Management)_Progress_Report&amp;diff=19668"/>
		<updated>2014-05-16T17:03:31Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: Blanked the page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Silicon_Valley_%E2%80%9CCulture_of_Youth%E2%80%9D&amp;diff=19667</id>
		<title>Silicon Valley “Culture of Youth”</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Silicon_Valley_%E2%80%9CCulture_of_Youth%E2%80%9D&amp;diff=19667"/>
		<updated>2014-05-16T17:02:19Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Silicon Valley “Culture of Youth” :Experiences; Lessons &amp;amp; Effects; Predicotrs &amp;amp; Steps&lt;br /&gt;
&lt;br /&gt;
Tuesday 3I&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Randy Farmer&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):'''  Randy Farmer&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
There is a problem with what to do with all the no-longer-young former programmers that are now overqualified for the number of level-appropriate positions available.&lt;br /&gt;
&lt;br /&gt;
Dick Hardt suggested that anecdotally, many of his 50+ friends are now in enterprise software positions.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=The_Maker_Economy_and_Identity&amp;diff=19666</id>
		<title>The Maker Economy and Identity</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=The_Maker_Economy_and_Identity&amp;diff=19666"/>
		<updated>2014-05-16T17:00:26Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:'''The Maker Economy &amp;amp; Identity&lt;br /&gt;
&lt;br /&gt;
Thursday 2I&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Brent Shambaugh&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Brent Shambaugh&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:''' #Biometrics   #arduino   #objectandartifactidentity   #identityawaredevices&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
Maker – Chris Anderson&lt;br /&gt;
*           - Open Source Hardware&lt;br /&gt;
&lt;br /&gt;
3: Aspects&lt;br /&gt;
&lt;br /&gt;
(1)	Scruffy Hackerism&lt;br /&gt;
&lt;br /&gt;
“If you can't open it, you don't own it”&lt;br /&gt;
&lt;br /&gt;
* Element of Artistic Self-Expression ==&amp;gt; Long Tail Art&lt;br /&gt;
&lt;br /&gt;
(2)	Revolutionary Manufacturing ==&amp;gt; Most interesting&lt;br /&gt;
&lt;br /&gt;
(3)	Value Youth&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Refrigerator Art ==&amp;gt; Kids make drawings ==&amp;gt; long tail&lt;br /&gt;
&lt;br /&gt;
−	inefficient autos&lt;br /&gt;
&lt;br /&gt;
* important as anything else&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Maker movement and 3D Printing lots&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New Tech 3D Systems&lt;br /&gt;
&lt;br /&gt;
−	linked&lt;br /&gt;
&lt;br /&gt;
Physics dance in desktop publishing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
(talking about the indie song movement)&lt;br /&gt;
&lt;br /&gt;
Easy library from Groups&lt;br /&gt;
&lt;br /&gt;
Word processing – Make it interesting to write&lt;br /&gt;
&lt;br /&gt;
---&amp;gt; Decent production Low&lt;br /&gt;
&lt;br /&gt;
Do not need different &lt;br /&gt;
&lt;br /&gt;
Not flooded with quality music low? (paraphrase: but is indie music really that bad, it appeals to someone?)&lt;br /&gt;
&lt;br /&gt;
So much....hard to find quality …&lt;br /&gt;
&lt;br /&gt;
+ People I know ( Social Recommendation)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So much … hard to find quality …&lt;br /&gt;
&lt;br /&gt;
•	People I know (Social Recommendation)&lt;br /&gt;
&lt;br /&gt;
•	Like Reputation ...(Good Enough) …. Established Social Network&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Reputation as Maker … Wireless Device Controlling &lt;br /&gt;
&lt;br /&gt;
EC were (?)...&lt;br /&gt;
&lt;br /&gt;
Get indentity layer … &lt;br /&gt;
&lt;br /&gt;
Where to add identity? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Reputation Systems can and will be gamed&lt;br /&gt;
&lt;br /&gt;
−	Robot had version of someone elses router (?)&lt;br /&gt;
&lt;br /&gt;
−	1000's of reviews &lt;br /&gt;
&lt;br /&gt;
−	Routing i-bay(?) transaction&lt;br /&gt;
&lt;br /&gt;
−	Reddit – Investigative Journalism&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
How do [you] aggregate based on similar tastes&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Model … Master Running Raspberri Pi&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Kickstarter and Indiegogo …&lt;br /&gt;
&lt;br /&gt;
Do everything where able …&lt;br /&gt;
&lt;br /&gt;
Brain states … IQ … Skeptics &lt;br /&gt;
&lt;br /&gt;
Why ...Reputation Systems&lt;br /&gt;
&lt;br /&gt;
Never Gained … Upside &amp;amp; Downside...&lt;br /&gt;
&lt;br /&gt;
Respect Network as an example&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Implementation System&lt;br /&gt;
&lt;br /&gt;
Different Respect Network&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Somehow Art is Aware of them &lt;br /&gt;
&lt;br /&gt;
It knows me in some way I think&lt;br /&gt;
&lt;br /&gt;
Identity … Does FB recognition&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Are there platforms and standards&lt;br /&gt;
&lt;br /&gt;
Lot of Mercury[?] to get out of phone&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
GAP in Maker Space ….&lt;br /&gt;
&lt;br /&gt;
No Shield … identity iterator shield …&lt;br /&gt;
&lt;br /&gt;
std[?] way … broad costs … very [?] … open standard...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Think other way around … identity in the cloud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your device can interact ...extrapolate to borrowing car&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
some other attribute ...on his key start … his car&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Zip car Dcerive [?]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Not [?]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Going to MakerBot&lt;br /&gt;
&lt;br /&gt;
Fungible [?] … Put on Arduino&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What UI to use … Plyn[?] Identity&lt;br /&gt;
&lt;br /&gt;
OAuth … it does not exist&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
−	A lot of preses there …&lt;br /&gt;
&lt;br /&gt;
−	Sheild … Oauth Presentation Layer&lt;br /&gt;
&lt;br /&gt;
−	not in Arduino ...Sheild … Oauth Presentation[?] layer&lt;br /&gt;
&lt;br /&gt;
−	not in Arduino … Do not have screen to show transaction&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
−	Display list devices … SMS challenge...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Bridge to trusted device &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Hard to Identifier&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Same to send to Oauth server&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Web Browser … in Done 4 Years  …. [?]&lt;br /&gt;
&lt;br /&gt;
Oauth … Hard to Launch Business to Platform&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Open Browser w/ HTTP stuff...&lt;br /&gt;
&lt;br /&gt;
See more elegant ways w/ Oauth 3 &amp;amp; 4&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Standard Biometric Data … a lotd[?] phone up to&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
your eye … Did investment in company...&lt;br /&gt;
&lt;br /&gt;
worst bad stays connection [?] .. Per Auth using ECG&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ECG must give permission … &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
20 second record ...take awhile … (writers comment: to hack right?) … skin elevation …&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Not as accurate yet … Interesting application&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
−	Tesla App&lt;br /&gt;
&lt;br /&gt;
−	Mastercard use 4 Payment Authentication&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Arythmia[?] … stay[?] w/Name of Company&lt;br /&gt;
&lt;br /&gt;
Biomen&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Identity … Sovereignty of data … do I[?] own it?&lt;br /&gt;
&lt;br /&gt;
Take pictures …&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Identity problem&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Bother … makes treat us as user names and not passwords...however anything … not a big deal&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If some are sterling[?] ..do I need a new heart … 9 password resets to fill out? 19?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
As username … totally fair … &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
stole from … take credit …&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Start 4 Username + Presenting[?] ...DII[?] ...you want...notion of username...like...notion of username … something real...still get participate[?] as &lt;br /&gt;
opposed to steal signatures...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
All security lead pipe&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Can You create audiences...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Facilitate...A lot of stuff..&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Built 4 its own sake...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Chuck off in&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
About creating connection&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
writter's annotation main topics:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 -Make device identity ware&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-use identity to connect objects and artifacts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
7 Bit Hero … Show up … MIDI is a 7 Bit Protocol ...Show up at concert...Scan at beginning of concert … Everyone[?]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Proximity...You could add virtual participants into concerts … get Kinetic sculpture...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
fascinating possibilities … beginning needs to be explored...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
−	Participants generate wate...&lt;br /&gt;
&lt;br /&gt;
−	This is a co-creation – structure and Artist&lt;br /&gt;
&lt;br /&gt;
The Artists Makes to Rules&lt;br /&gt;
&lt;br /&gt;
Theote[?] component changes&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Another thing is … what happens if 15 or 150 interacting...visual representation...Good thing calle&lt;br /&gt;
&lt;br /&gt;
dranondage[?] other play in to&lt;br /&gt;
&lt;br /&gt;
How musical transitions&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Some sets the wise...&lt;br /&gt;
&lt;br /&gt;
A good D.J. ….sets up the &lt;br /&gt;
&lt;br /&gt;
some ...D.J. Will change it up&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Definition … any[?] the tranditional--&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Identity is very personal –&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Identity may be a bundle of attributes … stages[?] of heart beats … Good performance Art...&lt;br /&gt;
&lt;br /&gt;
Eyes Beating ….lighting[?] build by w/Art piece&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Have Biometric Reading Glasses...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Trippy to watch interaction...&lt;br /&gt;
&lt;br /&gt;
What happens..do people synchronize&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Switch to another person's heartbeat&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ocular...break open an egg...&lt;br /&gt;
&lt;br /&gt;
several different latencies...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
show...latencies(?) of the[?] internet work&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Throws you off on a cell phone conversation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Have to increase...&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Sovereign_Design&amp;diff=19665</id>
		<title>Personal Sovereign Design</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Sovereign_Design&amp;diff=19665"/>
		<updated>2014-05-16T15:53:39Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:'''Personal Sovereign Design &lt;br /&gt;
&lt;br /&gt;
Tuesday 5B  &lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Devon Loffreto @NZN&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Devon Loffreto  &lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
#VRM  #SovereignSourceAuthority&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
http://www.moxytongue.com/2014/05/iiw18-personal-sovereign-design.html&lt;br /&gt;
&lt;br /&gt;
'''Abstract: A discussion on the nature of personal Sovereign data structures and identity structures useful for the expression of information of relative value to Individual people and organizations of people.'''&lt;br /&gt;
&lt;br /&gt;
Reference: &amp;quot;[http://www.moxytongue.com/2012/02/what-is-sovereign-source-authority.html What is Sovereign Source Authority]?&amp;quot; and associated information [http://www.moxytongue.com/ conveyed here].&lt;br /&gt;
&lt;br /&gt;
Led By: [https://www.twitter.com/NZN @NZN]&lt;br /&gt;
&lt;br /&gt;
___&lt;br /&gt;
&lt;br /&gt;
Society is administered, Administration is Society. Access to and control of participatory context is an administered Sovereign event that we exercise upon Human babies. This administrative context defines the tools we use to transact authority in Society.&lt;br /&gt;
&lt;br /&gt;
So long as Individual people must register 'within a system' in order to receive legal authority to represent oneself in subsequent legal transactions, [http://www.moxytongue.com/2013/01/administrative-precedence.html administrative precedence] defines the nature of this data relationship between asset managers and data-subjects structured as social liabilities with increasing costs/debts leveraged against their respective Rights of life, liberty and pursuits of happiness.&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Personal Sovereign Design&amp;quot; begins with risk management considerations. The foundation of integrity within Society is the Individual people that stand up freedom and security in every context required. &amp;quot;We the People&amp;quot; can not be contrived by an administered process, nor managed by administrative methods alone successfully... for every natural or man made emergency that threatens the lives of people in our communities requires Individual people to act with integrity and courage to produce opportunities for both survival and continued prosperity. We celebrate entrepreneurs of all types... social and commercial heroes that act.&lt;br /&gt;
&lt;br /&gt;
Personal Sovereignty is the structure of the United States of America by 'Declaration' (ref: [http://en.wikipedia.org/wiki/Signature John Hancock]), and the lack of a recursive signatory part to the US Constitution allowing for generational stewardship of the Rights that make our Union strong represents an &amp;quot;error of omission&amp;quot; causing structural concerns highlighted by an Internet-based administrative framework of Society.&lt;br /&gt;
&lt;br /&gt;
Can an Individual self-provision identity? Can a family self-provision asset structures? When? Birth Registration, Kindergarten Registration, Voting Registration, Health Care Enrollment, Genetic Profiling, every transaction...?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Human -vs- Systems (context considerations)&lt;br /&gt;
&lt;br /&gt;
Meatspace realities versus Virtual aspirations&lt;br /&gt;
&lt;br /&gt;
Ebay repuation system - absolute control of context value&lt;br /&gt;
&lt;br /&gt;
Local reputation has much more dynamic and subtle means of evaluating context values within Human relationships. Freedom itself requires &lt;br /&gt;
absolute local control... local to the Individual. The 1st and 2nd Amendment were constructed so that a Government &amp;quot;of and by the People&amp;quot; would &lt;br /&gt;
always contrive authority accurately. Individuals administer our governed Rights. Individuals standing Free, Individuals standing Brave.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A story was told of the character 'Rabbit&amp;quot; from the book [http://en.wikipedia.org/wiki/Rainbows_End Rainbows End by Vernor Vinge] describing a character that was ultimately controllable by &amp;quot;Revocation of  Certificate Authority&amp;quot; and an analogy was drawn to the current nature of freedom from within an &amp;quot;Administered State&amp;quot;, where the structure of personal Sovereignty is not implied by design, and requires central administration.&lt;br /&gt;
&lt;br /&gt;
Additional conversation pointed to subsequent introduction of httpsy://algorithm:fingerprint@domain:port/path1/!redactedPath2/…......... protocol by MStiegler.&lt;br /&gt;
&lt;br /&gt;
'''Later Session Title: Self ID'''&lt;br /&gt;
&lt;br /&gt;
Provoked related conversation around self provisioning identity by Individuals serving role of IDP. Self-authorization methods considered against backdrop of risk management considerations (LOA 1, 2, 3...)&lt;br /&gt;
&lt;br /&gt;
Enterprise requirements and security requirements exist in context.&lt;br /&gt;
&lt;br /&gt;
Individual requirements exist in context.&lt;br /&gt;
&lt;br /&gt;
Can a risk management regime change the administrative precedence of the IDP role to enable self-provisioning identity with capabilities of increasing levels of assurance being exchanged as needed?&lt;br /&gt;
&lt;br /&gt;
Very lively and engaging conversation with many capable and interesting people in room.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19664</id>
		<title>Start-Up’s Pitching</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19664"/>
		<updated>2014-05-16T15:43:30Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Startups Pitching to VC Panel&lt;br /&gt;
&lt;br /&gt;
Thursday 4 &amp;amp; 5 A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Nathan Schor&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
'''''Panelists'''''&lt;br /&gt;
*	Noah Doyle [mailto:noah@javelinvp.com noah@javelinvp.com] http://www.javelinvp.com&lt;br /&gt;
*	Keith Teare  [mailto:keith@teare.com keith@teare.com] http://www.archimedeslabs.com/&lt;br /&gt;
*	Derek Anderson [mailto:derek@startupgrind.com derek@startupgrind.com] http://www.startupgrind.com&lt;br /&gt;
*	Kayvan Baroumand [mailto:kayvan@nestgsv.com kayvan@nestgsv.com] http://www.nestgsv.com&lt;br /&gt;
*	Dan Gordon, [mailto:dan@valhallapartners.com dan@valhallapartners.com], http://www.valhallapartners.com/ &lt;br /&gt;
*	Amit Shah, Aritman Ventures, [mailto:amit@artiman.com amit@artiman.com] http://www.artiman.com/ &lt;br /&gt;
*	Anandan Jayaraman [mailto:anandan.jayaraman@gmail.com anandan.jayaraman@gmail.com]&lt;br /&gt;
&lt;br /&gt;
'''''Companies Pitching'''''&lt;br /&gt;
&lt;br /&gt;
'''Respect Network Founding Partners''' &lt;br /&gt;
&lt;br /&gt;
Respect Network 				&lt;br /&gt;
&lt;br /&gt;
Emmett Global				&lt;br /&gt;
&lt;br /&gt;
URQUi					&lt;br /&gt;
&lt;br /&gt;
inWebo					&lt;br /&gt;
&lt;br /&gt;
'''Independent'''&lt;br /&gt;
&lt;br /&gt;
Glome					&lt;br /&gt;
&lt;br /&gt;
HIE of One					&lt;br /&gt;
&lt;br /&gt;
MePIN /Meontrust				&lt;br /&gt;
&lt;br /&gt;
Pomcor 					&lt;br /&gt;
&lt;br /&gt;
Tozny  					&lt;br /&gt;
&lt;br /&gt;
Traitware 					&lt;br /&gt;
&lt;br /&gt;
Welcomer 					&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''''Respect Network Founding Partners'''''&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Respect Network  '''Website:''' http://respectnetwork.com/	'''Location:''' Seattle&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Drummond Reed, Co-Founder and CEO&lt;br /&gt;
*	Gary Rowe, Executive Chairman&lt;br /&gt;
*	Katherine Singson, CMO&lt;br /&gt;
*	Andy Dale, CTO&lt;br /&gt;
*	Matthew Sutton, VP Products &lt;br /&gt;
*	Mark Timbrell, Head of Respect Network EU&lt;br /&gt;
&lt;br /&gt;
Bios and links are all listed at http://respectnetwork.com/executive-team/ &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Respect Network is the world’s first global private network of personal and business clouds. Respect Network is based on an award-winning trust framework developed over 3 years by leading Internet architects and 50 Founding Partner companies from around the world. As a decentralized, multi-provider network similar to the global banking or email networks, the Respect Network will enable members anywhere in the world to share sensitive private data with strong assurance that their privacy will always be respected. In fact, Respect Network is the only global data sharing network engineered from the ground up around ''Privacy by Design.'' &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''  50 founding partners who have already signed up. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' Respect Network Corporation is currently raising a $3M Series A round. On Friday April 25 we held a first closing for $1.325M. We anticipate the second closing will be the first week of June.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Emmett Global	'''Website:''' http://www.EmmettGlobal.com 	'''Location:''' New York /Israel&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Kenneth J Lefkowitz, CEO    &lt;br /&gt;
*	Lionel A Wolberger, Architect&lt;br /&gt;
*	Joshua Zieman, CMO&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Emmett Global distributes best of class open source solutions that enable true Personal Data management. Three included solutions are; &lt;br /&gt;
&lt;br /&gt;
1) Cloud service provider on the Respect Network &lt;br /&gt;
&lt;br /&gt;
2) Browser extension bundle for Chrome and &lt;br /&gt;
&lt;br /&gt;
3) Mobile tablet device.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $950,000 to complete our seed funding&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' URQUi		'''Website:'''  http://www.urqui.com		'''Location:''' BCCanada&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Jonathan Bell, President, Computer Consultant –  &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/jonathan-bell/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Ken Jennings, [mailto:kjennings@urqui.com kjennings@urqui.com] @kwjennings, https://www.linkedin.com/pub/ken-jennings/0/7a2/602 &lt;br /&gt;
[http://skkynet.com/investors/directors/ Board of Directors Skkynet Cloud Systems Inc.] Skky OTC.bb  - &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/kenneth-jennings/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Dr. Jose M. Fernandez  P.Eng, Ph.D., Assistant Professor of Computer and Software Engineering, [http://www.polymtl.ca/recherche/rc/en/professeurs/details.php?NoProf=299 Polytechnique Montreal] [http://www.niccanada.com/EN/Speakers/Jos%C3%A9Fernandez.aspx Frequent Speaker on IT Security &amp;amp; Cryptography]  -  [http://www.privacybydesign.ca/index.php/ambassador/jose-fernandez-ph-d/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' URQUi“Your Key” is a secure, patent-pending, network or SaaS password alternative. URQUi One Time Passwords eliminate the need to store static passwords on servers. Users need not remember passwords. Using URQUi, a FREE app, individuals control their privacy, secure their online presence and protect themselves from identity theft. User-centric URQUi embodies &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/about-pbd/ Privacy by Design]. The Heartbleed bug could not have breached accounts using URQUi! ~ URQUi’s Business model is disruptive. URQUi is a multi-sided recurring revenue SaaS business. URQUi is free for individuals; free SaaS for government and non-profit servers; billable recurring revenue SaaS for commercial servers. URQUI’s pricing to commercial SaaS customers will be disruptive at 15% of comparable services (RSA SecureID). Distribution to individuals is done through iTunes et al. Distribution to server owners is done through resellers and vertical market partners. URQUi expects processing margins in the area of 50% - 60%&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' URQUi has not yet achieved traction in the market, however URQUi has developed significant partnerships. [http://www.privacybydesign.ca/index.php/ambassador/urqui/ Ambassador of Privacy by Design] Founding Partner of the Respect [http://www.thecene.org/#!cta-boston/c1v1m NetworkCTA@Boston, Fall 2014 Cohort]&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''$1,750,000 https://angel.co/urqui&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' inWebo 	'''Website:''' http://www.inwebo.com	 '''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Didier Perrot, CEO and founder, [mailto:didier.perrot@inwebo.com  didier.perrot@inwebo.com] &lt;br /&gt;
http://www.linkedin.com/pub/didier-perrot/0/72/b9/&lt;br /&gt;
&lt;br /&gt;
Bruno Abramatic, CTO and co-founder&lt;br /&gt;
&lt;br /&gt;
Olivier Perroquin, SVP Sales and co-founder, http://fr.linkedin.com/pub/olivier-perroquin/0/424/240&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' inWebo provides a Cloud-based authentication platform and a password management service to help enterprises, businesses and service providers protect users' online access and transactions in a highly secure yet non-intrusive way.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' 3M$ https://angel.co/inwebo &lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''''Independent Startups'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Glome  	'''Website:''' http://www.glome.me	'''Location:''' Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Edi Immonen – Co-founder &amp;amp; CEO [mailto:edi@glome.me edi@glome.me]  https://www.linkedin.com/in/jemiweb&lt;br /&gt;
&lt;br /&gt;
Ferenc Szekely – Co-founder &amp;amp; CTO https://www.linkedin.com/in/ferencszekely&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Glome has created an anonymous personalisation platform (an API) for businesses where individuals own, control and benefit from their digital footprint with full anonymity.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Glome had a soft launch in Finland and we targeted a few key players with great success. Now we have partnered with:&lt;br /&gt;
&lt;br /&gt;
1) A top-10 media in Finland with close to 1M unique weekly users&lt;br /&gt;
&lt;br /&gt;
2) A leading Scandinavian web shop company&lt;br /&gt;
&lt;br /&gt;
3) A leading Finnish consultancy &amp;amp; big data company &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' A total of 1.8m€ in steps in year 2014 so that: 300k€ for finishing the product-market-fit phase ( Q3&amp;amp;Q4 / 2014 )    ~ ~ ~ 1.5m€ for launching and expanding ( Q4/2014 -&amp;gt;  )&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:'''HIE of One		'''Website:''' N/A		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Adrian Gropper, MD –[mailto:agropper@healthurl.com agropper@healthurl.com] https://www.linkedin.com/pub/adrian gropper/1/665/691&lt;br /&gt;
&lt;br /&gt;
Josh Mandel, MD –https://www.linkedin.com/pub/joshua-mandel/35/472/883&lt;br /&gt;
&lt;br /&gt;
Adam Powell, PhD –https://www.linkedin.com/in/adamcpowell&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' HIE of Onewill sell a personal data store (hardware or cloud) and live support to consumers to enable the coordination of family care teams for the elderly and seriously ill. Our service uses open source software to create a platform for patient-directed health information exchange that will be preferred by app and services developers because it is verifiably privacy-preserving, verifiably secure, free to the developers, and, as a community open source project, carries no risk of vendor lock-in. HIE of One is a public benefits for-profit corporation designed to appeal to both financial and strategic investors.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' HIE of One has limited traction. We won one of the major prizes at an MIT health hackathon a a short time ago and we have a commitment from Smart911 to participate provide an API and participate in a demo this summer. We've also got three separate collaborating groups in the San Diego and San Francisco areas. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $2 M&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' MePIN /Meontrust	'''Website:'''https://www.mepin.com	'''Location:'''Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Markku Mehtala, CEO, [mailto:markku.mehtala@meontrust.com markku.mehtala@meontrust.com] http://fi.linkedin.com/in/markkum/&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''MePIN provides smart security for consumer online services, protecting the services and their users against password phishing, account hijacking, transaction fraud and privacy problems. &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We just raised a round, so looking for contacts for future rounds.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Pomcor		'''Website:'''http://www.pomcor.com		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Karen Pomian Lewison, CEO, [mailto: kplewison@pomcor.com kplewison@pomcor.com], http://www.linkedin.com/profile/view?id=28011537&lt;br /&gt;
&lt;br /&gt;
Francisco Corella, CTO    [mailto: fcorella@pomcor.com fcorella@pomcor.com], http://www.linkedin.com/profile/view?id=78440530&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''Pomcor is developing an Enterprise Mobility Management (EMM) solution to help an enterprise protect data stored in a mobile device with a patent-pending technique that prevents an adversary who steals the device from mounting an offline attack against an activation PIN.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We don't have a product, so we don' have traction yet.  We do have a no.1 position in Google for one of the market segments, even without a product.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We are looking for a letter of interest to support an NSF SBIR Phase I grant application, followed by an investment of $60,000, conditional on our getting the SBIR Phase I grant of $150,000.  The $60,000 investment would be matched by a Phase IB grant of up to $30,000.  Successful phases I and IB would give us a very good chance of getting a Phase II grant of up to $750,000, which in turn would allow us to get a Phase IIB grant of up to $500,000 matching an additional investment of $1,000,000.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''  Tozny		'''Website:'''   http://tozny.com	'''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Isaac Potoczny-Jones, President [mailto:ijones@tozny.com@SyntaxPolice ijones@tozny.com@SyntaxPolice] &lt;br /&gt;
http://www.linkedin.com/pub/isaac-potoczny-jones/4/b64/23b&lt;br /&gt;
&lt;br /&gt;
Leah Daniels, VP Business Development    http://www.linkedin.com/in/leahcdaniels&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Digital authentication - proving who we are - is a constant necessity on modern networks. Users are buried under the weight of too many passwords, and are faced with a conundrum: good passwords are impossible to remember, and bad passwords are easy to guess.&lt;br /&gt;
Tozny replaces passwords with a cryptographic app on your smart phone, making login both easier and more secure than passwords. Alternately, use Tozny to augment passwords with multi-factor authentication. Tozny helps enterprises and web sites stay secure and gives users an easier way to log in. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We have a customer in the government who is funding our work under a small business innovation program, and we have strong leads with a few large consumer-facing organizations in banking, health care, and telecommunications.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''  $500K&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Welcomer     '''Website:''' http://www.welcomer.me    '''Location:'''Australia&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Kevin Cox - [mailto:kevin@welcomer.me kevin@welcomer.me] http://au.linkedin.com/in/kevinrosscox Kevin is an Identity domain expert who has deep understanding of how organisations can benefit from giving people access to their own information. Kevin previously founded identity verification company Edentiti which was acquired in late 2013. &lt;br /&gt;
&lt;br /&gt;
Paul Marando - [mailto:paul@welcomer.me paul@welcomer.me] http://au.linkedin.com/pub/paul-marando/4/111/486 Paul comes across from Edentiti bringing with him a deep understanding of identity technology and a track record developing scalable architecture. Paul looks after the technology as well as leading the engineering team.&lt;br /&gt;
&lt;br /&gt;
Rory Ford -  [mailto:rory@welcomer.me rory@welcomer.me] http://au.linkedin.com/in/roryford/ Rory brings a background in online marketing and product management. Previously he established a portfolio of websites bringing in online sales across more than 120 countries. Rory also worked within Edentiti, looking at new product opportunities that have formed the basis for Welcomer. &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Welcomer provides an identity verification solution to small and medium organizations by utilizing a person’s access to their own information. Based on proven Enterprise technology, already used by banks, Welcomer makes money from each successful verification. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Company has raised ~$450K seed funding. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $300,000&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''Traitware	   '''Website:'''http://www.traitware.com     '''Location:''' San Francisco &lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Harlan Hutson President - Mr. Hutson is a serial entrepreneur now on his third start-up. Harlan has been fascinated with online transactions and security since the creation of his second start-up, an online event ticketing company that was sold in 2010&lt;br /&gt;
&lt;br /&gt;
Dr. Herbert w. Spencer CTO -  Dr. Spencer has been a developer of new technologies since building a computer from pinball machine parts in junior high school. He received a Ph.D. in plasma physics from Auburn University and started EC&amp;amp;C Technologies, Inc.&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' TraitWare™ delivers 2-factor authentication making mobile and web computing more secure and enjoyable. Our patent pending process authenticates both user and device, binding them together to create a secure signature. When combined with PhotoAuth™, TraitWareID™ eliminates the need to enter a PIN, OTP or “out-of-band” SMS codes for authentication.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' TraitWare is fully operational is now being used in pilot tests by companies that have been signed as partners. TraitWare is bundling its authentication with software to solve customer needs in the areas of finance, payments, and health care.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19663</id>
		<title>Start-Up’s Pitching</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19663"/>
		<updated>2014-05-16T15:41:40Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Startups Pitching to VC Panel&lt;br /&gt;
&lt;br /&gt;
Thursday 4 &amp;amp; 5 A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Nathan Schor&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
'''''Panelists'''''&lt;br /&gt;
*	Noah Doyle [mailto:noah@javelinvp.com noah@javelinvp.com] http://www.javelinvp.com&lt;br /&gt;
*	Keith Teare  [mailto:keith@teare.com keith@teare.com] http://www.archimedeslabs.com/&lt;br /&gt;
*	Derek Anderson [mailto:derek@startupgrind.com derek@startupgrind.com] http://www.startupgrind.com&lt;br /&gt;
*	Kayvan Baroumand [mailto:kayvan@nestgsv.com kayvan@nestgsv.com] http://www.nestgsv.com&lt;br /&gt;
*	Dan Gordon, [mailto:dan@valhallapartners.com dan@valhallapartners.com], http://www.valhallapartners.com/ &lt;br /&gt;
*	Amit Shah, Aritman Ventures, [mailto:amit@artiman.com amit@artiman.com] http://www.artiman.com/ &lt;br /&gt;
*	Anandan Jayaraman [mailto:anandan.jayaraman@gmail.com anandan.jayaraman@gmail.com]&lt;br /&gt;
&lt;br /&gt;
'''''Companies Pitching'''''&lt;br /&gt;
&lt;br /&gt;
'''Respect Network Founding Partners''' &lt;br /&gt;
&lt;br /&gt;
Respect Network 				&lt;br /&gt;
&lt;br /&gt;
Emmett Global				&lt;br /&gt;
&lt;br /&gt;
URQUi					&lt;br /&gt;
&lt;br /&gt;
inWebo					&lt;br /&gt;
&lt;br /&gt;
'''Independent'''&lt;br /&gt;
&lt;br /&gt;
Glome					&lt;br /&gt;
&lt;br /&gt;
HIE of One					&lt;br /&gt;
&lt;br /&gt;
MePIN /Meontrust				&lt;br /&gt;
&lt;br /&gt;
Pomcor 					&lt;br /&gt;
&lt;br /&gt;
Tozny  					&lt;br /&gt;
&lt;br /&gt;
Traitware 					&lt;br /&gt;
&lt;br /&gt;
Welcomer 					&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''''Respect Network Founding Partners'''''&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Respect Network  '''Website:''' http://respectnetwork.com/	'''Location:''' Seattle&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Drummond Reed, Co-Founder and CEO&lt;br /&gt;
*	Gary Rowe, Executive Chairman&lt;br /&gt;
*	Katherine Singson, CMO&lt;br /&gt;
*	Andy Dale, CTO&lt;br /&gt;
*	Matthew Sutton, VP Products &lt;br /&gt;
*	Mark Timbrell, Head of Respect Network EU&lt;br /&gt;
&lt;br /&gt;
Bios and links are all listed at http://respectnetwork.com/executive-team/ &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Respect Network is the world’s first global private network of personal and business clouds. Respect Network is based on an award-winning trust framework developed over 3 years by leading Internet architects and 50 Founding Partner companies from around the world. As a decentralized, multi-provider network similar to the global banking or email networks, the Respect Network will enable members anywhere in the world to share sensitive private data with strong assurance that their privacy will always be respected. In fact, Respect Network is the only global data sharing network engineered from the ground up around ''Privacy by Design.'' &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''  50 founding partners who have already signed up. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' Respect Network Corporation is currently raising a $3M Series A round. On Friday April 25 we held a first closing for $1.325M. We anticipate the second closing will be the first week of June.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Emmett Global	'''Website:''' http://www.EmmettGlobal.com 	'''Location:''' New York /Israel&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Kenneth J Lefkowitz, CEO    &lt;br /&gt;
*	Lionel A Wolberger, Architect&lt;br /&gt;
*	Joshua Zieman, CMO&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Emmett Global distributes best of class open source solutions that enable true Personal Data management. Three included solutions are; &lt;br /&gt;
&lt;br /&gt;
1) Cloud service provider on the Respect Network &lt;br /&gt;
&lt;br /&gt;
2) Browser extension bundle for Chrome and &lt;br /&gt;
&lt;br /&gt;
3) Mobile tablet device.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $950,000 to complete our seed funding&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' URQUi		'''Website:'''  http://www.urqui.com		'''Location:''' BCCanada&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Jonathan Bell, President, Computer Consultant –  &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/jonathan-bell/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Ken Jennings, [mailto:kjennings@urqui.com kjennings@urqui.com] @kwjennings, https://www.linkedin.com/pub/ken-jennings/0/7a2/602 &lt;br /&gt;
[http://skkynet.com/investors/directors/ Board of Directors Skkynet Cloud Systems Inc.] Skky OTC.bb  - &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/kenneth-jennings/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Dr. Jose M. Fernandez  P.Eng, Ph.D., Assistant Professor of Computer and Software Engineering, [http://www.polymtl.ca/recherche/rc/en/professeurs/details.php?NoProf=299 Polytechnique Montreal] [http://www.niccanada.com/EN/Speakers/Jos%C3%A9Fernandez.aspx Frequent Speaker on IT Security &amp;amp; Cryptography]  -  [http://www.privacybydesign.ca/index.php/ambassador/jose-fernandez-ph-d/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' URQUi“Your Key” is a secure, patent-pending, network or SaaS password alternative. URQUi One Time Passwords eliminate the need to store static passwords on servers. Users need not remember passwords. Using URQUi, a FREE app, individuals control their privacy, secure their online presence and protect themselves from identity theft. User-centric URQUi embodies &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/about-pbd/ Privacy by Design]. The Heartbleed bug could not have breached accounts using URQUi! ~ URQUi’s Business model is disruptive. URQUi is a multi-sided recurring revenue SaaS business. URQUi is free for individuals; free SaaS for government and non-profit servers; billable recurring revenue SaaS for commercial servers. URQUI’s pricing to commercial SaaS customers will be disruptive at 15% of comparable services (RSA SecureID). Distribution to individuals is done through iTunes et al. Distribution to server owners is done through resellers and vertical market partners. URQUi expects processing margins in the area of 50% - 60%&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' URQUi has not yet achieved traction in the market, however URQUi has developed significant partnerships. [http://www.privacybydesign.ca/index.php/ambassador/urqui/ Ambassador of Privacy by Design] Founding Partner of the Respect [http://www.thecene.org/#!cta-boston/c1v1m NetworkCTA@Boston, Fall 2014 Cohort]&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''$1,750,000 https://angel.co/urqui&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' inWebo 	'''Website:''' http://www.inwebo.com	 '''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Didier Perrot, CEO and founder, [mailto:didier.perrot@inwebo.com  didier.perrot@inwebo.com] &lt;br /&gt;
http://www.linkedin.com/pub/didier-perrot/0/72/b9/&lt;br /&gt;
&lt;br /&gt;
Bruno Abramatic, CTO and co-founder&lt;br /&gt;
&lt;br /&gt;
Olivier Perroquin, SVP Sales and co-founder, http://fr.linkedin.com/pub/olivier-perroquin/0/424/240&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' inWebo provides a Cloud-based authentication platform and a password management service to help enterprises, businesses and service providers protect users' online access and transactions in a highly secure yet non-intrusive way.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' 3M$ https://angel.co/inwebo &lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''''Independent Startups'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Glome  	'''Website:''' http://www.glome.me	'''Location:''' Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Edi Immonen – Co-founder &amp;amp; CEO [mailto:edi@glome.me edi@glome.me]  https://www.linkedin.com/in/jemiweb&lt;br /&gt;
&lt;br /&gt;
Ferenc Szekely – Co-founder &amp;amp; CTO https://www.linkedin.com/in/ferencszekely&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Glome has created an anonymous personalisation platform (an API) for businesses where individuals own, control and benefit from their digital footprint with full anonymity.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Glome had a soft launch in Finland and we targeted a few key players with great success. Now we have partnered with:&lt;br /&gt;
&lt;br /&gt;
1) A top-10 media in Finland with close to 1M unique weekly users&lt;br /&gt;
&lt;br /&gt;
2) A leading Scandinavian web shop company&lt;br /&gt;
&lt;br /&gt;
3) A leading Finnish consultancy &amp;amp; big data company &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' A total of 1.8m€ in steps in year 2014 so that: 300k€ for finishing the product-market-fit phase ( Q3&amp;amp;Q4 / 2014 )    [[User:Ebgross|Ebgross]] ([[User talk:Ebgross|talk]])   1.5m€ for launching and expanding ( Q4/2014 -&amp;gt;  )&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:'''HIE of One		'''Website:''' N/A		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Adrian Gropper, MD –[mailto:agropper@healthurl.com agropper@healthurl.com] https://www.linkedin.com/pub/adrian gropper/1/665/691&lt;br /&gt;
&lt;br /&gt;
Josh Mandel, MD –https://www.linkedin.com/pub/joshua-mandel/35/472/883&lt;br /&gt;
&lt;br /&gt;
Adam Powell, PhD –https://www.linkedin.com/in/adamcpowell&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' HIE of Onewill sell a personal data store (hardware or cloud) and live support to consumers to enable the coordination of family care teams for the elderly and seriously ill. Our service uses open source software to create a platform for patient-directed health information exchange that will be preferred by app and services developers because it is verifiably privacy-preserving, verifiably secure, free to the developers, and, as a community open source project, carries no risk of vendor lock-in. HIE of One is a public benefits for-profit corporation designed to appeal to both financial and strategic investors.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' HIE of One has limited traction. We won one of the major prizes at an MIT health hackathon a a short time ago and we have a commitment from Smart911 to participate provide an API and participate in a demo this summer. We've also got three separate collaborating groups in the San Diego and San Francisco areas. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $2 M&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' MePIN /Meontrust	'''Website:'''https://www.mepin.com	'''Location:'''Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Markku Mehtala, CEO, [mailto:markku.mehtala@meontrust.com markku.mehtala@meontrust.com] http://fi.linkedin.com/in/markkum/&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''MePIN provides smart security for consumer online services, protecting the services and their users against password phishing, account hijacking, transaction fraud and privacy problems. &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We just raised a round, so looking for contacts for future rounds.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Pomcor		'''Website:'''http://www.pomcor.com		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Karen Pomian Lewison, CEO, [mailto: kplewison@pomcor.com kplewison@pomcor.com], http://www.linkedin.com/profile/view?id=28011537&lt;br /&gt;
&lt;br /&gt;
Francisco Corella, CTO    [mailto: fcorella@pomcor.com fcorella@pomcor.com], http://www.linkedin.com/profile/view?id=78440530&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''Pomcor is developing an Enterprise Mobility Management (EMM) solution to help an enterprise protect data stored in a mobile device with a patent-pending technique that prevents an adversary who steals the device from mounting an offline attack against an activation PIN.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We don't have a product, so we don' have traction yet.  We do have a no.1 position in Google for one of the market segments, even without a product.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We are looking for a letter of interest to support an NSF SBIR Phase I grant application, followed by an investment of $60,000, conditional on our getting the SBIR Phase I grant of $150,000.  The $60,000 investment would be matched by a Phase IB grant of up to $30,000.  Successful phases I and IB would give us a very good chance of getting a Phase II grant of up to $750,000, which in turn would allow us to get a Phase IIB grant of up to $500,000 matching an additional investment of $1,000,000.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''  Tozny		'''Website:'''   http://tozny.com	'''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Isaac Potoczny-Jones, President [mailto:ijones@tozny.com@SyntaxPolice ijones@tozny.com@SyntaxPolice] &lt;br /&gt;
http://www.linkedin.com/pub/isaac-potoczny-jones/4/b64/23b&lt;br /&gt;
&lt;br /&gt;
Leah Daniels, VP Business Development    http://www.linkedin.com/in/leahcdaniels&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Digital authentication - proving who we are - is a constant necessity on modern networks. Users are buried under the weight of too many passwords, and are faced with a conundrum: good passwords are impossible to remember, and bad passwords are easy to guess.&lt;br /&gt;
Tozny replaces passwords with a cryptographic app on your smart phone, making login both easier and more secure than passwords. Alternately, use Tozny to augment passwords with multi-factor authentication. Tozny helps enterprises and web sites stay secure and gives users an easier way to log in. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We have a customer in the government who is funding our work under a small business innovation program, and we have strong leads with a few large consumer-facing organizations in banking, health care, and telecommunications.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''  $500K&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Welcomer     '''Website:''' http://www.welcomer.me    '''Location:'''Australia&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Kevin Cox - [mailto:kevin@welcomer.me kevin@welcomer.me] http://au.linkedin.com/in/kevinrosscox Kevin is an Identity domain expert who has deep understanding of how organisations can benefit from giving people access to their own information. Kevin previously founded identity verification company Edentiti which was acquired in late 2013. &lt;br /&gt;
&lt;br /&gt;
Paul Marando - [mailto:paul@welcomer.me paul@welcomer.me] http://au.linkedin.com/pub/paul-marando/4/111/486 Paul comes across from Edentiti bringing with him a deep understanding of identity technology and a track record developing scalable architecture. Paul looks after the technology as well as leading the engineering team.&lt;br /&gt;
&lt;br /&gt;
Rory Ford -  [mailto:rory@welcomer.me rory@welcomer.me] http://au.linkedin.com/in/roryford/ Rory brings a background in online marketing and product management. Previously he established a portfolio of websites bringing in online sales across more than 120 countries. Rory also worked within Edentiti, looking at new product opportunities that have formed the basis for Welcomer. &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Welcomer provides an identity verification solution to small and medium organizations by utilizing a person’s access to their own information. Based on proven Enterprise technology, already used by banks, Welcomer makes money from each successful verification. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Company has raised ~$450K seed funding. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $300,000&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''Traitware	   '''Website:'''http://www.traitware.com     '''Location:''' San Francisco &lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Harlan Hutson President - Mr. Hutson is a serial entrepreneur now on his third start-up. Harlan has been fascinated with online transactions and security since the creation of his second start-up, an online event ticketing company that was sold in 2010&lt;br /&gt;
&lt;br /&gt;
Dr. Herbert w. Spencer CTO -  Dr. Spencer has been a developer of new technologies since building a computer from pinball machine parts in junior high school. He received a Ph.D. in plasma physics from Auburn University and started EC&amp;amp;C Technologies, Inc.&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' TraitWare™ delivers 2-factor authentication making mobile and web computing more secure and enjoyable. Our patent pending process authenticates both user and device, binding them together to create a secure signature. When combined with PhotoAuth™, TraitWareID™ eliminates the need to enter a PIN, OTP or “out-of-band” SMS codes for authentication.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' TraitWare is fully operational is now being used in pilot tests by companies that have been signed as partners. TraitWare is bundling its authentication with software to solve customer needs in the areas of finance, payments, and health care.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19662</id>
		<title>Start-Up’s Pitching</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Start-Up%E2%80%99s_Pitching&amp;diff=19662"/>
		<updated>2014-05-16T15:41:12Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Startups Pitching to VC Panel&lt;br /&gt;
&lt;br /&gt;
Thursday 4 &amp;amp; 5 A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Nathan Schor&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
''''Panelists''''&lt;br /&gt;
*	Noah Doyle [mailto:noah@javelinvp.com noah@javelinvp.com] http://www.javelinvp.com&lt;br /&gt;
*	Keith Teare  [mailto:keith@teare.com keith@teare.com] http://www.archimedeslabs.com/&lt;br /&gt;
*	Derek Anderson [mailto:derek@startupgrind.com derek@startupgrind.com] http://www.startupgrind.com&lt;br /&gt;
*	Kayvan Baroumand [mailto:kayvan@nestgsv.com kayvan@nestgsv.com] http://www.nestgsv.com&lt;br /&gt;
*	Dan Gordon, [mailto:dan@valhallapartners.com dan@valhallapartners.com], http://www.valhallapartners.com/ &lt;br /&gt;
*	Amit Shah, Aritman Ventures, [mailto:amit@artiman.com amit@artiman.com] http://www.artiman.com/ &lt;br /&gt;
*	Anandan Jayaraman [mailto:anandan.jayaraman@gmail.com anandan.jayaraman@gmail.com]&lt;br /&gt;
&lt;br /&gt;
''''Companies Pitching''''&lt;br /&gt;
&lt;br /&gt;
'''Respect Network Founding Partners''' &lt;br /&gt;
&lt;br /&gt;
Respect Network 				&lt;br /&gt;
&lt;br /&gt;
Emmett Global				&lt;br /&gt;
&lt;br /&gt;
URQUi					&lt;br /&gt;
&lt;br /&gt;
inWebo					&lt;br /&gt;
&lt;br /&gt;
'''Independent'''&lt;br /&gt;
&lt;br /&gt;
Glome					&lt;br /&gt;
&lt;br /&gt;
HIE of One					&lt;br /&gt;
&lt;br /&gt;
MePIN /Meontrust				&lt;br /&gt;
&lt;br /&gt;
Pomcor 					&lt;br /&gt;
&lt;br /&gt;
Tozny  					&lt;br /&gt;
&lt;br /&gt;
Traitware 					&lt;br /&gt;
&lt;br /&gt;
Welcomer 					&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''''Respect Network Founding Partners'''''&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Respect Network  '''Website:''' http://respectnetwork.com/	'''Location:''' Seattle&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Drummond Reed, Co-Founder and CEO&lt;br /&gt;
*	Gary Rowe, Executive Chairman&lt;br /&gt;
*	Katherine Singson, CMO&lt;br /&gt;
*	Andy Dale, CTO&lt;br /&gt;
*	Matthew Sutton, VP Products &lt;br /&gt;
*	Mark Timbrell, Head of Respect Network EU&lt;br /&gt;
&lt;br /&gt;
Bios and links are all listed at http://respectnetwork.com/executive-team/ &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Respect Network is the world’s first global private network of personal and business clouds. Respect Network is based on an award-winning trust framework developed over 3 years by leading Internet architects and 50 Founding Partner companies from around the world. As a decentralized, multi-provider network similar to the global banking or email networks, the Respect Network will enable members anywhere in the world to share sensitive private data with strong assurance that their privacy will always be respected. In fact, Respect Network is the only global data sharing network engineered from the ground up around ''Privacy by Design.'' &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''  50 founding partners who have already signed up. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' Respect Network Corporation is currently raising a $3M Series A round. On Friday April 25 we held a first closing for $1.325M. We anticipate the second closing will be the first week of June.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Emmett Global	'''Website:''' http://www.EmmettGlobal.com 	'''Location:''' New York /Israel&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
*	Kenneth J Lefkowitz, CEO    &lt;br /&gt;
*	Lionel A Wolberger, Architect&lt;br /&gt;
*	Joshua Zieman, CMO&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' &lt;br /&gt;
&lt;br /&gt;
Emmett Global distributes best of class open source solutions that enable true Personal Data management. Three included solutions are; &lt;br /&gt;
&lt;br /&gt;
1) Cloud service provider on the Respect Network &lt;br /&gt;
&lt;br /&gt;
2) Browser extension bundle for Chrome and &lt;br /&gt;
&lt;br /&gt;
3) Mobile tablet device.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $950,000 to complete our seed funding&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' URQUi		'''Website:'''  http://www.urqui.com		'''Location:''' BCCanada&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Jonathan Bell, President, Computer Consultant –  &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/jonathan-bell/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Ken Jennings, [mailto:kjennings@urqui.com kjennings@urqui.com] @kwjennings, https://www.linkedin.com/pub/ken-jennings/0/7a2/602 &lt;br /&gt;
[http://skkynet.com/investors/directors/ Board of Directors Skkynet Cloud Systems Inc.] Skky OTC.bb  - &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/ambassador/kenneth-jennings/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
Dr. Jose M. Fernandez  P.Eng, Ph.D., Assistant Professor of Computer and Software Engineering, [http://www.polymtl.ca/recherche/rc/en/professeurs/details.php?NoProf=299 Polytechnique Montreal] [http://www.niccanada.com/EN/Speakers/Jos%C3%A9Fernandez.aspx Frequent Speaker on IT Security &amp;amp; Cryptography]  -  [http://www.privacybydesign.ca/index.php/ambassador/jose-fernandez-ph-d/ Ambassador of Privacy by Design]&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' URQUi“Your Key” is a secure, patent-pending, network or SaaS password alternative. URQUi One Time Passwords eliminate the need to store static passwords on servers. Users need not remember passwords. Using URQUi, a FREE app, individuals control their privacy, secure their online presence and protect themselves from identity theft. User-centric URQUi embodies &lt;br /&gt;
[http://www.privacybydesign.ca/index.php/about-pbd/ Privacy by Design]. The Heartbleed bug could not have breached accounts using URQUi! ~ URQUi’s Business model is disruptive. URQUi is a multi-sided recurring revenue SaaS business. URQUi is free for individuals; free SaaS for government and non-profit servers; billable recurring revenue SaaS for commercial servers. URQUI’s pricing to commercial SaaS customers will be disruptive at 15% of comparable services (RSA SecureID). Distribution to individuals is done through iTunes et al. Distribution to server owners is done through resellers and vertical market partners. URQUi expects processing margins in the area of 50% - 60%&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' URQUi has not yet achieved traction in the market, however URQUi has developed significant partnerships. [http://www.privacybydesign.ca/index.php/ambassador/urqui/ Ambassador of Privacy by Design] Founding Partner of the Respect [http://www.thecene.org/#!cta-boston/c1v1m NetworkCTA@Boston, Fall 2014 Cohort]&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''$1,750,000 https://angel.co/urqui&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' inWebo 	'''Website:''' http://www.inwebo.com	 '''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Didier Perrot, CEO and founder, [mailto:didier.perrot@inwebo.com  didier.perrot@inwebo.com] &lt;br /&gt;
http://www.linkedin.com/pub/didier-perrot/0/72/b9/&lt;br /&gt;
&lt;br /&gt;
Bruno Abramatic, CTO and co-founder&lt;br /&gt;
&lt;br /&gt;
Olivier Perroquin, SVP Sales and co-founder, http://fr.linkedin.com/pub/olivier-perroquin/0/424/240&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' inWebo provides a Cloud-based authentication platform and a password management service to help enterprises, businesses and service providers protect users' online access and transactions in a highly secure yet non-intrusive way.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' 3M$ https://angel.co/inwebo &lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''''Independent Startups'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Glome  	'''Website:''' http://www.glome.me	'''Location:''' Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Edi Immonen – Co-founder &amp;amp; CEO [mailto:edi@glome.me edi@glome.me]  https://www.linkedin.com/in/jemiweb&lt;br /&gt;
&lt;br /&gt;
Ferenc Szekely – Co-founder &amp;amp; CTO https://www.linkedin.com/in/ferencszekely&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Glome has created an anonymous personalisation platform (an API) for businesses where individuals own, control and benefit from their digital footprint with full anonymity.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Glome had a soft launch in Finland and we targeted a few key players with great success. Now we have partnered with:&lt;br /&gt;
&lt;br /&gt;
1) A top-10 media in Finland with close to 1M unique weekly users&lt;br /&gt;
&lt;br /&gt;
2) A leading Scandinavian web shop company&lt;br /&gt;
&lt;br /&gt;
3) A leading Finnish consultancy &amp;amp; big data company &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' A total of 1.8m€ in steps in year 2014 so that: 300k€ for finishing the product-market-fit phase ( Q3&amp;amp;Q4 / 2014 )    [[User:Ebgross|Ebgross]] ([[User talk:Ebgross|talk]])   1.5m€ for launching and expanding ( Q4/2014 -&amp;gt;  )&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Company:'''HIE of One		'''Website:''' N/A		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Adrian Gropper, MD –[mailto:agropper@healthurl.com agropper@healthurl.com] https://www.linkedin.com/pub/adrian gropper/1/665/691&lt;br /&gt;
&lt;br /&gt;
Josh Mandel, MD –https://www.linkedin.com/pub/joshua-mandel/35/472/883&lt;br /&gt;
&lt;br /&gt;
Adam Powell, PhD –https://www.linkedin.com/in/adamcpowell&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' HIE of Onewill sell a personal data store (hardware or cloud) and live support to consumers to enable the coordination of family care teams for the elderly and seriously ill. Our service uses open source software to create a platform for patient-directed health information exchange that will be preferred by app and services developers because it is verifiably privacy-preserving, verifiably secure, free to the developers, and, as a community open source project, carries no risk of vendor lock-in. HIE of One is a public benefits for-profit corporation designed to appeal to both financial and strategic investors.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' HIE of One has limited traction. We won one of the major prizes at an MIT health hackathon a a short time ago and we have a commitment from Smart911 to participate provide an API and participate in a demo this summer. We've also got three separate collaborating groups in the San Diego and San Francisco areas. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $2 M&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' MePIN /Meontrust	'''Website:'''https://www.mepin.com	'''Location:'''Finland&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Markku Mehtala, CEO, [mailto:markku.mehtala@meontrust.com markku.mehtala@meontrust.com] http://fi.linkedin.com/in/markkum/&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''MePIN provides smart security for consumer online services, protecting the services and their users against password phishing, account hijacking, transaction fraud and privacy problems. &lt;br /&gt;
&lt;br /&gt;
'''Traction:'''&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We just raised a round, so looking for contacts for future rounds.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
 &lt;br /&gt;
'''Company:''' Pomcor		'''Website:'''http://www.pomcor.com		'''Location:'''Boston&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Karen Pomian Lewison, CEO, [mailto: kplewison@pomcor.com kplewison@pomcor.com], http://www.linkedin.com/profile/view?id=28011537&lt;br /&gt;
&lt;br /&gt;
Francisco Corella, CTO    [mailto: fcorella@pomcor.com fcorella@pomcor.com], http://www.linkedin.com/profile/view?id=78440530&lt;br /&gt;
&lt;br /&gt;
'''Business Model:'''Pomcor is developing an Enterprise Mobility Management (EMM) solution to help an enterprise protect data stored in a mobile device with a patent-pending technique that prevents an adversary who steals the device from mounting an offline attack against an activation PIN.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We don't have a product, so we don' have traction yet.  We do have a no.1 position in Google for one of the market segments, even without a product.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' We are looking for a letter of interest to support an NSF SBIR Phase I grant application, followed by an investment of $60,000, conditional on our getting the SBIR Phase I grant of $150,000.  The $60,000 investment would be matched by a Phase IB grant of up to $30,000.  Successful phases I and IB would give us a very good chance of getting a Phase II grant of up to $750,000, which in turn would allow us to get a Phase IIB grant of up to $500,000 matching an additional investment of $1,000,000.&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''  Tozny		'''Website:'''   http://tozny.com	'''Location:'''&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Isaac Potoczny-Jones, President [mailto:ijones@tozny.com@SyntaxPolice ijones@tozny.com@SyntaxPolice] &lt;br /&gt;
http://www.linkedin.com/pub/isaac-potoczny-jones/4/b64/23b&lt;br /&gt;
&lt;br /&gt;
Leah Daniels, VP Business Development    http://www.linkedin.com/in/leahcdaniels&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Digital authentication - proving who we are - is a constant necessity on modern networks. Users are buried under the weight of too many passwords, and are faced with a conundrum: good passwords are impossible to remember, and bad passwords are easy to guess.&lt;br /&gt;
Tozny replaces passwords with a cryptographic app on your smart phone, making login both easier and more secure than passwords. Alternately, use Tozny to augment passwords with multi-factor authentication. Tozny helps enterprises and web sites stay secure and gives users an easier way to log in. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' We have a customer in the government who is funding our work under a small business innovation program, and we have strong leads with a few large consumer-facing organizations in banking, health care, and telecommunications.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''  $500K&lt;br /&gt;
&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:''' Welcomer     '''Website:''' http://www.welcomer.me    '''Location:'''Australia&lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Kevin Cox - [mailto:kevin@welcomer.me kevin@welcomer.me] http://au.linkedin.com/in/kevinrosscox Kevin is an Identity domain expert who has deep understanding of how organisations can benefit from giving people access to their own information. Kevin previously founded identity verification company Edentiti which was acquired in late 2013. &lt;br /&gt;
&lt;br /&gt;
Paul Marando - [mailto:paul@welcomer.me paul@welcomer.me] http://au.linkedin.com/pub/paul-marando/4/111/486 Paul comes across from Edentiti bringing with him a deep understanding of identity technology and a track record developing scalable architecture. Paul looks after the technology as well as leading the engineering team.&lt;br /&gt;
&lt;br /&gt;
Rory Ford -  [mailto:rory@welcomer.me rory@welcomer.me] http://au.linkedin.com/in/roryford/ Rory brings a background in online marketing and product management. Previously he established a portfolio of websites bringing in online sales across more than 120 countries. Rory also worked within Edentiti, looking at new product opportunities that have formed the basis for Welcomer. &lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' Welcomer provides an identity verification solution to small and medium organizations by utilizing a person’s access to their own information. Based on proven Enterprise technology, already used by banks, Welcomer makes money from each successful verification. &lt;br /&gt;
&lt;br /&gt;
'''Traction:''' Company has raised ~$450K seed funding. &lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:''' $300,000&lt;br /&gt;
------	------	------	------	------	-------  ------	------	------&lt;br /&gt;
&lt;br /&gt;
'''Company:'''Traitware	   '''Website:'''http://www.traitware.com     '''Location:''' San Francisco &lt;br /&gt;
&lt;br /&gt;
'''Management Team:''' &lt;br /&gt;
&lt;br /&gt;
Harlan Hutson President - Mr. Hutson is a serial entrepreneur now on his third start-up. Harlan has been fascinated with online transactions and security since the creation of his second start-up, an online event ticketing company that was sold in 2010&lt;br /&gt;
&lt;br /&gt;
Dr. Herbert w. Spencer CTO -  Dr. Spencer has been a developer of new technologies since building a computer from pinball machine parts in junior high school. He received a Ph.D. in plasma physics from Auburn University and started EC&amp;amp;C Technologies, Inc.&lt;br /&gt;
&lt;br /&gt;
'''Business Model:''' TraitWare™ delivers 2-factor authentication making mobile and web computing more secure and enjoyable. Our patent pending process authenticates both user and device, binding them together to create a secure signature. When combined with PhotoAuth™, TraitWareID™ eliminates the need to enter a PIN, OTP or “out-of-band” SMS codes for authentication.&lt;br /&gt;
&lt;br /&gt;
'''Traction:''' TraitWare is fully operational is now being used in pilot tests by companies that have been signed as partners. TraitWare is bundling its authentication with software to solve customer needs in the areas of finance, payments, and health care.&lt;br /&gt;
&lt;br /&gt;
'''Amount funds seeking:'''&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Respect_Network_LAUNCH&amp;diff=19661</id>
		<title>Respect Network LAUNCH</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Respect_Network_LAUNCH&amp;diff=19661"/>
		<updated>2014-05-16T14:54:30Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Respect Network Launch &lt;br /&gt;
&lt;br /&gt;
Tuesday 1A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Drummond Reed &amp;amp; Les Chasen&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Drummond Reed&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Link to Respect Network Launch and Lunch Events Schedule&lt;br /&gt;
&lt;br /&gt;
World’s First Global Private Network:&lt;br /&gt;
&lt;br /&gt;
http://finance.yahoo.com/news/privacy-revolution-starts-now-130000306.html &lt;br /&gt;
&lt;br /&gt;
Privacy Revolution Starts Now!&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Respect_Network_LAUNCH&amp;diff=19660</id>
		<title>Respect Network LAUNCH</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Respect_Network_LAUNCH&amp;diff=19660"/>
		<updated>2014-05-16T14:54:08Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Respect Network Launch &lt;br /&gt;
&lt;br /&gt;
Tuesday 1A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Drummond Reed &amp;amp; Les Chasen&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Drummond Reed&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Link to Respect Network Launch and Lunch Events Schedule&lt;br /&gt;
World’s First Global Private Network:&lt;br /&gt;
&lt;br /&gt;
http://finance.yahoo.com/news/privacy-revolution-starts-now-130000306.html &lt;br /&gt;
Privacy Revolution Starts Now!&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Data_Inequality_$_%3D_$_Income_Inequality&amp;diff=19646</id>
		<title>Data Inequality $ = $ Income Inequality</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Data_Inequality_$_%3D_$_Income_Inequality&amp;diff=19646"/>
		<updated>2014-05-09T16:58:52Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:'''Data Inequality / Income Inequality&lt;br /&gt;
&lt;br /&gt;
Wednesday 2E&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Kris Alman&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Kris Alman &amp;amp; Matt Berry&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
 &lt;br /&gt;
[[File:IIW18_WED2E.jpg‎]]&lt;br /&gt;
&lt;br /&gt;
Income inequality/ Data inequality&lt;br /&gt;
 &lt;br /&gt;
If data is concentrated in fewer hands, will income inequality grow?&lt;br /&gt;
And will this further tilt power structures?&lt;br /&gt;
Can we measure data inequality, like Gini coefficient does to measure income inequality?&lt;br /&gt;
 &lt;br /&gt;
21st century post-industrial economy called knowledge or information economy.&lt;br /&gt;
Influence on education: STEM careers (STEAM acknowledges art—creativity/innovation—as important.) Compared to industrial revolution where people were stripped of land and were unaware what happened &amp;amp; how livelihoods changed.  Will middle class “knowledge workers” (doctors, teachers, IT, musicians, etc.) become devalued as data is gleaned and monetized by big corporations?&lt;br /&gt;
 &lt;br /&gt;
“Privacy is a nonrenewable resource. Once it gets consumed, it is gone.” Frank McSherry of Microsoft Research Silicon Valley in Mountain View, Calif.&lt;br /&gt;
http://www.simonsfoundation.org/quanta/20121210-privacy-by-the-numbers-a-new-approach-to-safeguarding-data/&lt;br /&gt;
http://www.scientificamerican.com/article/privacy-by-the-numbers-a-new-approach-to-safeguarding-data/&lt;br /&gt;
 &lt;br /&gt;
Controversial concept. With each birth, privacy is a renewable resource!&lt;br /&gt;
&lt;br /&gt;
Pandora’s Box is open and data collected without our ability to opt-in or out.&lt;br /&gt;
*	'''Decentralization with Peer to Peer connections important.'''&lt;br /&gt;
*	'''Demand education and transparency of data collected by both business &amp;amp; government.''' We should not have different standards for government and private sector as they have merged.&lt;br /&gt;
*	'''Consentualized data''' can occur through:&lt;br /&gt;
**	Anonymous transactions (using public/private keys) &lt;br /&gt;
**	Privacy by design&lt;br /&gt;
 &lt;br /&gt;
Transparency is limited by bad laws. E.g. transparency of prices in health care and trade secret laws that prevent disclosure of negotiated rates for services.&lt;br /&gt;
 &lt;br /&gt;
There is a difference between explicit and inferred data.&lt;br /&gt;
Marketing surveillance comes from explicit info shared on sites like facebook.&lt;br /&gt;
&lt;br /&gt;
Example of inferred data. Defense Intelligence Agency took photographs of and analyzed protests with Topsy. Determined that adding food carts decreased violence.&lt;br /&gt;
http://topsy.com/&lt;br /&gt;
 &lt;br /&gt;
Predictive analytics with data collected over which we have no control (or know exists) is concerning.&lt;br /&gt;
 &lt;br /&gt;
Trade agreements like TPP and TTIP impact data inequality (such as who controls data for international companies; how might net neutrality be impacted). Secret trade agreements (corporations writing them) are writing them without transparency to public. Could this impact net neutrality or data ownership/access?&lt;br /&gt;
How does this impact governance? Acknowledgement that we are an oligarchy. Recent Huff Post article that demonstrates 83% of legislation is contrary to public opinion.&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Good resource:&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Ecology International,''' Attending and mending the knowledge ecosystem (KEI): http://keionline.org/about&lt;br /&gt;
&lt;br /&gt;
“a not for profit non governmental organization that searches for better outcomes, including new solutions, to the management of knowledge resources. KEI is focused on social justice, particularly for the most vulnerable populations, including low-income persons and marginalized groups. There are probably 5 billion people who live in the margins of the global economy, and an entire planet that depends upon knowledge for economic and personal development, education and health, political power and freedom, culture and fun.”&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Joseph Stiglitz, economist and a professor at Columbia University, is an advisor.  He won Nobel Prize in Economics for his analyses of markets with asymmetric information.http://keionline.org/node/18&lt;br /&gt;
 &lt;br /&gt;
Recommended book: Who Owns the Future?http://www.amazon.com/Who-Owns-Future-Jaron-Lanier/dp/1451654960&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:IIW18_WED2E.jpg&amp;diff=19645</id>
		<title>File:IIW18 WED2E.jpg</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:IIW18_WED2E.jpg&amp;diff=19645"/>
		<updated>2014-05-09T16:58:23Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Shopping_for_Identity_Providers_%E2%80%93_What_do_I_need_to_know_before_I_put_my_identity_in_your_provider&amp;diff=19644</id>
		<title>Shopping for Identity Providers – What do I need to know before I put my identity in your provider</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Shopping_for_Identity_Providers_%E2%80%93_What_do_I_need_to_know_before_I_put_my_identity_in_your_provider&amp;diff=19644"/>
		<updated>2014-05-09T16:55:55Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Shopping for an Identity Providers: What do I need to know before I put my identity in your provider?&lt;br /&gt;
&lt;br /&gt;
Wednesday 3E  &lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Matt Berry&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):'''  Dan Sanford  &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
 &lt;br /&gt;
[[File:IIW18_Wed3E.jpg]]&lt;br /&gt;
&lt;br /&gt;
Things to consider&lt;br /&gt;
&lt;br /&gt;
nsio&lt;br /&gt;
&lt;br /&gt;
strong authentication&lt;br /&gt;
&lt;br /&gt;
privacy policy&lt;br /&gt;
&lt;br /&gt;
protocols&lt;br /&gt;
&lt;br /&gt;
guarantees&lt;br /&gt;
&lt;br /&gt;
operational security&lt;br /&gt;
&lt;br /&gt;
scopes and types of information&lt;br /&gt;
&lt;br /&gt;
relevancy&lt;br /&gt;
&lt;br /&gt;
information required for identity proofing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
How do I measure it?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Could certify operational security and privacy policy&lt;br /&gt;
&lt;br /&gt;
Lots of discussion - what is an IDP (e.g. )&lt;br /&gt;
* abiility to export data&lt;br /&gt;
* ability to provide data to a third party'&lt;br /&gt;
&lt;br /&gt;
how (when and why) will privacy policy change? Lots of discussions about who measures, what and how much IdP describes this information? Are we willing to pay for it?&lt;br /&gt;
&lt;br /&gt;
Government or others can monitor changes and/or validating that entities do what they intend to, or possibly even meet some standard (e.g. w3c recommended policy standards for website - has gone nowhere)&lt;br /&gt;
&lt;br /&gt;
Lots of discussion of standards for these things to consider that we would want that don't exist right now - which is something that we would want to consider if they were available.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:IIW18_Wed3E.jpg&amp;diff=19643</id>
		<title>File:IIW18 Wed3E.jpg</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:IIW18_Wed3E.jpg&amp;diff=19643"/>
		<updated>2014-05-09T16:55:10Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=An_Introducing_to_IndieWeb&amp;diff=19642</id>
		<title>An Introducing to IndieWeb</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=An_Introducing_to_IndieWeb&amp;diff=19642"/>
		<updated>2014-05-09T16:42:44Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' An Introduction to the INDIEWEB    &lt;br /&gt;
&lt;br /&gt;
Tuesday 2H&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Ben Werdmuller&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Kevin Marks &amp;amp; Ben Werdmuller&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Find notes from this session here: &lt;br /&gt;
http://indiewebcamp.com/2014-05-06-iiw-intro-indieweb&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Further Notes:'''&lt;br /&gt;
&lt;br /&gt;
[http://www.werd.io/ Ben Werdmüller]:&lt;br /&gt;
&lt;br /&gt;
we talk a lot in #indieweb about &amp;quot;silos&amp;quot; - dropbox, facebook etc who make money by locking up our data&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
facebook is a fantastic proof of concept of a social network, but they take control away from you&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#indieweb is about having your own space on the web - your own domain as your primary identity&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
the #indieweb goal is for you not to lose anything by not being in the silos, by connecting to them&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I haven't posted directly to facebook or twitter for a year, I post to my site and share to them instead&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
the #indieweb community practices what we preach - we build for our own sites not making standards for other people&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
there are lots of small building blocks that we use to build the #indieweb - microformats are how we add meaning to web pages&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
another building block is webmentions http://indiewebcamp.com/webmention that tell sites when you have linked to them&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
by using these buliding blocks we can have likes, retweets, replies, and RSVPs on our own #indieweb sites&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
currently this is mostly about publicly visible data, but we add authentication with [http://www.indieauth.com indieauth.com]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
we are not trying to establish a huge standards organisation, but instead a community of people who implement and discuss&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
how many people have their own websites? [most] how many post regularly [fewer]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.aheadrobot.com Stefan Magdalinski]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
does posting once a year count as regularly?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.aaronparecki.com/ Aaron Parecki]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
twitter can be almost to easy - you need an interface that is as easy to us as twitter for your own site&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
there is an opportunity for &amp;quot;twitter apps&amp;quot; for your own site - use other people's apps to post to your own #indieweb site&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.kevinmarks.com Kevin Marks]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
shows off noterlive, which is a way to post these kind of live tweets and keep them for posting on my own site&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.werd.io/ Ben Werdmüller]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://www.twitter.com/aaronpk @aaronpk] has posted a photo on his site - I can reply to that using idno's firefox plugin and it shows on my site&lt;br /&gt;
&lt;br /&gt;
I can also reply to [https://www.twitter.com/kevinmarks @kevinmarks]'s tweet using the Firefox plugin, and it posts on my site and shares it to twitter too&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There's an event tomorrow night in SF called Homebrew Website Club - I can RSVP to that on my site + share to Facebook&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
creating the twitter and facebook integrations for idno too about an hour and a half each&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I'd love to create a way to upload HTML5 games and post them to your site and send highscores by webmentions&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
it's an open community - there's an IRC channel: http://indiewebcamp.com/IRC and a wiki http://indiewebcamp.com- all are welcome&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
other sites could shut down apis, but at least you don't lose your own posts when that happens&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
with silo'd sites there is na ethnocentric design as they're all made here in SF - indieweb is less SV dominated&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.aheadrobot.com Stefan Magdalinski]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
this is interesting from a hacker perspective, but how big can it go? this blogging will never catch on&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.aaronparecki.com Aaron Parecki]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
there is a page on the wiki for wider adoption: http://indiewebcamp.com/generations (there's a page for everything)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.werd.io/ Ben Werdmüller]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
we're more likely to get to mainstream by iterating on working code and consensus&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.aheadrobot.com Stefan Magdalinski]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I've run lots of my servers at home (and fax machines) -what happens when they're all botnets?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.kevinmarks.com Kevin Marks]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
not necessarily hoem servers, can be in cloud, or even static sites that can be synced&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.aaronparecki.com Aaron Parecki]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
there are ways that we can do this with a wholly static site and services that build the communication parts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.sbw.org Steve Williams]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
the other way is to run an unhosted app that posts to a static server and have the data locally in the browser&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.werd.io/ Ben Werdmüller]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
one advantage of making this web-centric is that we don't have to impose any architecture on anyone else to communicate&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
how to get started? one list is at [http://indiewebify.me indiewebify.me]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.aaronparecki.com Aaron Parecki]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
first get your own domain and put up a page that links to your existing profiles elsewhere, so you have your own space&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.tantek.com Tantek Çelik]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
also look at http://indiewebcamp.com/Getting_Started to see where to go&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.erinjorichey.com Erin Jo Richey]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
we're hoping by the end of the summer to have idno be a one-click install http://idno.co/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
the idno code is all on github at https://github.com/idno/idno tomorrow it will be called &amp;quot;known&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.werd.io/ Ben Werdmüller]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
we're going to switch to MySQL from mongo on idno to make it run where wordpress runs&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
we're not quite there yet to be able to deploy a dynamic site anywhere&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
do come to Homebrew Website Club meetings on wednesdays in SF, Portland, Chichago + sunnyvale http://indiewebcamp.com/events/2014-05-07-homebrew-website-club&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Received from Ben Werdmuller:'''&lt;br /&gt;
''Notes by Aaron Parecki''&lt;br /&gt;
''These are permanently hosted at: http://indiewebcamp.com/2014-05-06-iiw-intro-indieweb''&lt;br /&gt;
&lt;br /&gt;
the real promise of the web is that we can all connect and learn from each other and you're not giving up control of your data and identity [http://indiewebcamp.com/selfdogfooding selfdogfooding] - get something up and running for yourself and live it. if you expect people to live by a standard or principle, live it yourself first &lt;br /&gt;
&lt;br /&gt;
[http://indiewebcamp.com/building_blocks building blocks] - make it easy to get started quickly &lt;br /&gt;
*	[http://indiewebcamp.com/microformats microformats] - encode machine-readable data into HTML, rather than trying to create huge backend system for things &lt;br /&gt;
*	[http://indiewebcamp.com/webmention webmention] - has become one of the key building blocks of the indieweb - people are using this today and forgetting about the technology and actually having real site-to-site conversations &lt;br /&gt;
&lt;br /&gt;
Because each of the building blocks are so small, people can pick up one of them and experiment and build something that works in a day. &lt;br /&gt;
&lt;br /&gt;
how many people have their own domain name? all but 2 raised their hand [nice! -t] &lt;br /&gt;
&lt;br /&gt;
how many people post regularly? most - does annual count? &lt;br /&gt;
&lt;br /&gt;
&amp;quot;i used to&amp;quot; - 'why did you stop?' - [http://indiewebcamp.com/twitter twitter], it's faster &lt;br /&gt;
&lt;br /&gt;
benwerd: I get to choose to syndicate to twitter and other [http://indiewebcamp.com/silos silos] &lt;br /&gt;
&lt;br /&gt;
aaronpk: one of the challenges is to have a user interface to post to your own site that is as easy as Twitter. Some folks have built user interfaces on their own sites as &lt;br /&gt;
simple as Twitter. &lt;br /&gt;
&lt;br /&gt;
aaronpk: not everyone wants to build their own user interface. [http://indiewebcamp.com/micropub micropub] lets apps post to indieweb sites. &lt;br /&gt;
&lt;br /&gt;
kevinmarks demonstrating noterlive &lt;br /&gt;
*	put in a [http://indiewebcamp.com/hashtag hashtag] and speaker name &lt;br /&gt;
*	posting to twitter, but also collecting HTML into the page &lt;br /&gt;
*	when he finishes, copies the HTML to his site &lt;br /&gt;
*	wants to add micropub to automatically post the HTML to his site instead of manual copy/pate &lt;br /&gt;
*	this interface is *more useful* than twitter for tweeting &lt;br /&gt;
&lt;br /&gt;
benwerd demoing his site &lt;br /&gt;
*	showing aaron's photo of this session &lt;br /&gt;
*	clicking reply button in firefox plugin for Known &lt;br /&gt;
*	typing a [http://indiewebcamp.com/reply reply], hit save &lt;br /&gt;
*	posted it first as a [http://indiewebcamp.com/comment comment] on his own site &lt;br /&gt;
*	automatically shows up at the bottom of my photo as a comment &lt;br /&gt;
*	url: http://aaronparecki.com/notes/2014/05/06/4/iiw-indieweb &lt;br /&gt;
*	http://werd.io/2014/great-to-see-so-many-people-here &lt;br /&gt;
*	demoing [http://indiewebcamp.com/RSVP RSVPing] to tomorrow's homebrew website club indie [http://indiewebcamp.com/event event] &lt;br /&gt;
*	these plugins took about an hour to build each &lt;br /&gt;
&lt;br /&gt;
would love to find a way to post HTML5 games so indie game developers could quickly host games. high scores could be received back with webmentions. &lt;br /&gt;
&lt;br /&gt;
There's the IndieWebCamp wiki and IRC channel. Everyone is welcome. &lt;br /&gt;
*	http://indiewebcamp.com/ &lt;br /&gt;
*	http://indiewebcamp.com/IRC &lt;br /&gt;
&lt;br /&gt;
There is no mailing list: http://indiewebcamp.com/FAQ#Is_there_an_IndieWeb_mailing_list &lt;br /&gt;
&lt;br /&gt;
Q: can the &amp;quot;big guys&amp;quot; withdraw the APIs? A: of course! but it's not like they can disable an API key and the whole indieweb goes down. but it's also useful to note that we don't necessarily need them to have indieweb conversations. also they can't turn off their own HTML. &lt;br /&gt;
&lt;br /&gt;
Q: if [http://indiewebcamp.com/Google%2B Google+] doesn't have an API, do they even really exist? &lt;br /&gt;
&lt;br /&gt;
... Freedom box ... from Austria ... just got back from ouishare in Paris following indieweb on the sidelines ever since FSWS one of the powerful ideas of the indieweb is that it's loosely defined, so it's easy to get going and start using building blocks &lt;br /&gt;
&lt;br /&gt;
Q: this is really interesting from a hacker perspective, but how mainstream can it go? &lt;br /&gt;
&lt;br /&gt;
A: aaronpk, pretty much every question has an answer on the wiki. E.g. for this, see https://indiewebcamp.com/generations - right now we're mostly a hacker &lt;br /&gt;
community. We saw the internet go from a hacker community and go completely mainstream. This is how it starts. &lt;br /&gt;
&lt;br /&gt;
A: benwerd: 10 years ago, social web, people would say what? it's not mainstream. ... We're more likely to get there by iterating on working code. &lt;br /&gt;
&lt;br /&gt;
KevinMarks: one of the arguments is, how much can you push statically? a bunch of us are doing this. &lt;br /&gt;
&lt;br /&gt;
Aaronpk: when your website is a pile of HTML files and you can put it on any FTP server and still communicate with other sites? You end up with using a webmention service. &lt;br /&gt;
&lt;br /&gt;
[12:37] &amp;lt;bretttt&amp;gt; its key to eventually get that service data INTO the html file itself. working on that now &lt;br /&gt;
&lt;br /&gt;
KevinMarks: part of the point here is to NOT just build a monoculture. https://indiewebcamp.com/monoculture &lt;br /&gt;
&lt;br /&gt;
because we started with 6 people writing their sites in 6 different programming languages, it made &lt;br /&gt;
[http://indiewebcamp.com/monoculture monoculture] way less likely to happen &lt;br /&gt;
&lt;br /&gt;
[http://indiewebcamp.com/Getting_Started Getting Started]: &lt;br /&gt;
*	buy a domain &lt;br /&gt;
*	find space to host it &lt;br /&gt;
*	put up a simple home page with an h-card with your name and links to other profiles &lt;br /&gt;
&lt;br /&gt;
Known - currently PHP + MongoDB. going to be PHP+MySQL.&lt;br /&gt;
&lt;br /&gt;
known / withknown.com (sp?) &lt;br /&gt;
&lt;br /&gt;
benwerd: As Kevin said, monocultures are bad. This only going to work if there are a number of platforms out there. Idno is one. [http://indiewebcamp.com/p3k p3k] is another. Interesting things &lt;br /&gt;
with [http://indiewebcamp.com/WordPress WordPress] plugins. [http://indiewebcamp.com/Taproot Taproot]. See https://indiewebcamp.com/projects &lt;br /&gt;
&lt;br /&gt;
If anyone is here in this area, or Portland, or Chicago, there's a [http://indiewebcamp.com/Homebrew_Website_Club Homebrew Website Club] every two weeks. &lt;br /&gt;
&lt;br /&gt;
SF one is 18:30 on Wednesday: &lt;br /&gt;
*	http://indiewebcamp.com/events/2014-05-07-homebrew-website-club &lt;br /&gt;
&lt;br /&gt;
Portland one is usually hosted by ESRIPDX or MozPDX but not this week. &lt;br /&gt;
&lt;br /&gt;
Chicago one is usually at Intelligentsia. &lt;br /&gt;
&lt;br /&gt;
KevinMarks: Do we want a satellite one here in MV? &lt;br /&gt;
&lt;br /&gt;
Benwerd: not looking forward to driving back in rush hour &lt;br /&gt;
&lt;br /&gt;
KevinMarks: we can grab a table at the Firehouse and make that the MV HWC&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IndieAuth_%E2%80%93_Turn_Your_Personal_Domain_Into_An_OAUTH_Provider&amp;diff=19641</id>
		<title>IndieAuth – Turn Your Personal Domain Into An OAUTH Provider</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IndieAuth_%E2%80%93_Turn_Your_Personal_Domain_Into_An_OAUTH_Provider&amp;diff=19641"/>
		<updated>2014-05-09T16:21:57Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:'''IndieAuth:  Turn Your Personal Domain Into An OAuth Provider  &lt;br /&gt;
&lt;br /&gt;
Tuesday 4H&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Aaron Parecki&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Kevin Marks &amp;amp; Ben Werdmuller&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Find notes from this session here: &lt;br /&gt;
http://indiewebcamp.com/2014-05-06-iiw-indieauth&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Further Notes&lt;br /&gt;
[http://www.sbw.org Steve Williams]:&lt;br /&gt;
&lt;br /&gt;
is indieauth what I used to log into the wiki? [https://www.twitter.com/aaronpk @aaronpk]: yes [https://www.twitter.com/sbw @sbw]: I have a bug report&lt;br /&gt;
&lt;br /&gt;
[http://www.aaronparecki.com/ Aaron Parecki]:&lt;br /&gt;
&lt;br /&gt;
if you have signed into [http://www.indiewebcamp.com indiewebcamp.com] you have used indieauth already&lt;br /&gt;
&lt;br /&gt;
If you link from your site to and form a silo with rel=&amp;quot;me&amp;quot; that is relMeAuth -you delegate authentication to a silo&lt;br /&gt;
&lt;br /&gt;
this lets you use your own domain as the identifier, but other sites as authentication&lt;br /&gt;
&lt;br /&gt;
[http://www.indieauth.com indieauth.com] is a little confusing as it is doing two things&lt;br /&gt;
&lt;br /&gt;
[http://www.indieauth.com indieauth.com] came from wanting to add relMeAuth to mediawiki on [http://www.indiewebcamp.com indiewebcamp.com]&lt;br /&gt;
&lt;br /&gt;
instead of getting down in mediawiki code to add auth, I made indieauth.com do to auth as service&lt;br /&gt;
&lt;br /&gt;
by making [http://www.indieauth.com indieauth.com] a service, I could add a small plugin to mediawiki to talk to indieauth&lt;br /&gt;
&lt;br /&gt;
I initially didn't expect anyone else to use [http://www.indieauth.com indieauth.com] originally&lt;br /&gt;
&lt;br /&gt;
one of the things that OAuth2 did different from OAuth1 was separating auth as an internal service&lt;br /&gt;
&lt;br /&gt;
after I made it work with the wiki, I made it work with my own site hosting p3k&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
we need to find an OAuth2 provider agreed on between indieauth and the user&lt;br /&gt;
&lt;br /&gt;
I had the same problem with posting to my own site - I needed authZ to post to my own site&lt;br /&gt;
&lt;br /&gt;
http://ownyourgram.com/ is a way to post to your micropub endpoint when you send photos to instagram&lt;br /&gt;
&lt;br /&gt;
as OAuth2 doesn't specify discovery, we have OpenID Connect, and no other spec.&lt;br /&gt;
&lt;br /&gt;
I used rel=authorization-endpoint and rel=token-endpoint from existing specs and made up rel=micropub&lt;br /&gt;
&lt;br /&gt;
one of my goals is to avoid crypto and rely on TLS like OAuth2 did (it seemed like a good idea at the time)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.kevinmarks.com Kevin Marks]:&lt;br /&gt;
&lt;br /&gt;
well, the SSL code has had a lot of people look at it closely recently&lt;br /&gt;
&lt;br /&gt;
[Justin Richer http://www.justin.richter.org]:&lt;br /&gt;
[https://www.twitter.com/aaronpk @aaronpk] should look up token introspection as an OAuth spec (which I wrote) - similar to IndieAuth token factoring&lt;br /&gt;
&lt;br /&gt;
[http://www.aaronparecki.com/ Aaron Parecki]:&lt;br /&gt;
&lt;br /&gt;
indieuath can be an internal part of the wiki, or it can be service that the user's micropub site uses&lt;br /&gt;
&lt;br /&gt;
[http://www.justin.richter.org Justin Richer ]:&lt;br /&gt;
&lt;br /&gt;
UMA is a protocol built on OAuth2 and OpenID connect to introduce the client to the auth services&lt;br /&gt;
&lt;br /&gt;
there's a lot of potential synergy between UMA and what the Indieauth delegation is trying to do&lt;br /&gt;
&lt;br /&gt;
there is a profile of OpenID Connect that lets you defer verifying the signature, but implementations do it anyway&lt;br /&gt;
&lt;br /&gt;
what if you don't have an HTML parser?&lt;br /&gt;
&lt;br /&gt;
[http://www.kevinmarks.com Kevin Marks]:&lt;br /&gt;
&lt;br /&gt;
we have an HTML parser service in the cloud that will make it into JSON for you #indieweb&lt;br /&gt;
&lt;br /&gt;
'''Received from Ben Werdmuller:'''&lt;br /&gt;
&lt;br /&gt;
''Notes by Ben Werdmuller''&lt;br /&gt;
''These are permanently hosted at: http://indiewebcamp.com/2014-05-06-iiw-indieauth''&lt;br /&gt;
&lt;br /&gt;
If you have signed into the indiewebcamp.com wiki, then you've already used IndieAuth. In this session, Aaron will get into the guts of it. &lt;br /&gt;
&lt;br /&gt;
[http://indiewebcamp.com/RelMeAuth RelMeAuth]: Your site &amp;lt;----&amp;gt; Multiple silos &lt;br /&gt;
&lt;br /&gt;
[http://indiewebcamp.com/Your_domain Your domain] is the identifier for the thing you're logging into; you're delegating the actual authentication to a third-party service (e.g. a service) &lt;br /&gt;
&lt;br /&gt;
E.g., aaronparecki.com logs in using RelMeAuth using Aaron's [http://indiewebcamp.com/GitHub GitHub] account (github.com/aaronpk) to actually do the authentication. &lt;br /&gt;
&lt;br /&gt;
Aaron apologizes for a slightly confusing indieauth.com site. &lt;br /&gt;
&lt;br /&gt;
Initially, he wanted to write authentication for the indiewebcamp.com wiki. MediaWiki has a very convoluted codebase, and he was dreading diving into it. He knew &lt;br /&gt;
that for every new authentication method he had to add, he'd have to do it all again. So instead he decided to write the integration code once, using indieauth.com as an integration point, and write all of the other authentication integrations for indieauth.com, which had a much cleaner codebase (as he was starting from scratch). &lt;br /&gt;
&lt;br /&gt;
The integration mechanism is OAuth-like. &lt;br /&gt;
&lt;br /&gt;
There is some discussion between Justin Richer at MITRE and Aaron Parecki about whether the indiewebcamp.com authentication mechanism is effectively siloed authentication. Aaron defended on the basis that OAuth 2.0 explicitly featured the ability to separate the auth service from identity. (It's a tactical decision to have a proprietary link between indiewebcamp.com and indieauth.com, although it's a little more exposed because the communication happens over HTTP. Justin notes that it would be better to use existing authentication protocols that are designed for security.) &lt;br /&gt;
&lt;br /&gt;
Aaron discusses using IndieAuth with [http://indiewebcamp.com/micropub micropub], an API for using third-party apps to post to indieweb sites. The micropub-compatible app needs to be able to log into your personal site. &lt;br /&gt;
&lt;br /&gt;
[http://indiewebcamp.com/OwnYourGram OwnYourGram].com: you log in via IndieAuth, authorize the app, and it reads your [http://indiewebcamp.com/Instagram Instagram] feed and autoposts it to your indieweb site using micropub. &lt;br /&gt;
*	[me] -&amp;gt; (rel) -&amp;gt; [authorization endpoint] &lt;br /&gt;
*	[me] -&amp;gt; (rel) -&amp;gt; [token endpoint] &lt;br /&gt;
*	[me] -&amp;gt; (rel) -&amp;gt; [resource server, micropub] &lt;br /&gt;
&lt;br /&gt;
Aaron took authorization &amp;amp; token endpoints from [http://indiewebcamp.com/OAuth OAuth] / [http://indiewebcamp.com/OpenID OpenID] connect; micropub is new. &lt;br /&gt;
&lt;br /&gt;
A question came up about why this uses HTML vs using a .well-known address. The answer is that it's easier to code on a wider variety of platforms. &lt;br /&gt;
&lt;br /&gt;
A further issue was brought up re: OAuth separating authorization and token endpoints, which is not something that is actually supported in OAuth. Aaron points out that you _can_ have them on separate servers, as long as they are tightly coupled - as is the case here. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Aaron: &amp;quot;avoid crypto&amp;quot;. He likes the idea of signed tokens, but nobody can agree on the signing mechanism. Conversations tend to disappear down unproductive rabbitholes ..... &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Aaron discussed the OAuth workflow and how it relates to IndieAuth. IndieAuth assumes clients that have a web presence. It can be an internal part of the indieweb site, or it can be an adjacent service that the site delegates to.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth_SASL_(OAuth_for_non-web_apps,_ep.IMAP)&amp;diff=19640</id>
		<title>OAuth SASL (OAuth for non-web apps, ep.IMAP)</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth_SASL_(OAuth_for_non-web_apps,_ep.IMAP)&amp;diff=19640"/>
		<updated>2014-05-09T16:04:29Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' OAuth SASL (OAuth for Non-Web Apps, ep.IMAP)&lt;br /&gt;
&lt;br /&gt;
Wednesday 4F&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Hannes Tschofenig&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Roshni Chan&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''&lt;br /&gt;
OAuth, SASL&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
OAuth SASL&lt;br /&gt;
&lt;br /&gt;
Presentation here: http://www.tschofenig.priv.at/oauth/IETF-SASL-Kitten.pptx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Presented work done by the IETF KITTEN WG.&lt;br /&gt;
&lt;br /&gt;
SASL (Simple Authentication and Security Layer - RFC 4422)&lt;br /&gt;
* middleware&lt;br /&gt;
* generic security services (GSS API)&lt;br /&gt;
* SASL and GSSAPI sort of merged, but the mechanisms in the RFC only specify SASL mechanisms.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Typical challenge - authentication mechanisms chosen by some may not be appropriate for some other people, therefore SASL provides a container within which to &lt;br /&gt;
run an authentication framework. SASL messages need to be dumped in an application layer protocol to be useful - these protocols are called SASL profiles. Email &lt;br /&gt;
based examples provided in the slides from spec.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
High Level SASL Exchange&lt;br /&gt;
&lt;br /&gt;
Client requests authentication exchange. The server initiates a challenge and then initiates the actual exchange with the authentication protocol specified and eventually responds with an outcome. The outcome depends on the SASL mechanism used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In the IMAP example from the presentation, the keywords used were AUTHENTICATE=OAUTHBEARER where the client uses the AUTHENTICATE keyword to specify &lt;br /&gt;
what mechanism it wishes to use, and the server can list what mechanisms it supports using the AUTH keyword. The client and server exchange blobs till success or &lt;br /&gt;
failure.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
TLS: The server/client can request TLS. The problem with using TLS is that the security mechanisms are now in the underlying layer and not known to SASL.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Standard OAuth SASL architecture:&lt;br /&gt;
&lt;br /&gt;
 	OAuth Authorization Server (access token obtained here)&lt;br /&gt;
 		|&lt;br /&gt;
 		|&lt;br /&gt;
 		|&lt;br /&gt;
 	SASL OAuth Client (email client) ----------------- SASL server (Resource Server)&lt;br /&gt;
 							    IMAP Server&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Different from popular OAuth in that the client is not pre-provisioned with any information. Some bootstrapping is required for the server to learn about the client ID and metadata, and the client doesn’t know which Authz server to use.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Actual Client-Resource Server interaction&lt;br /&gt;
&lt;br /&gt;
Two OAuth SASL Mechanisms&lt;br /&gt;
*	- bearer tokens RFC 6750&lt;br /&gt;
*	- OAuth1.0a RFC 5849&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Q. OAuth1.0 has a list of vulnerabilities listed in the appendix as unaddressed flaws, so why are we still using it?&lt;br /&gt;
&lt;br /&gt;
OAuth1.0a is being used to show how we would use this for a signed profile. OAuth2 doesn’t mention signed messages, but supports PoP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Q. Why not use TLS and then recommend relying on something else later.&lt;br /&gt;
&lt;br /&gt;
A.  GSS API requires mutual authentication and TLS is outside the GSS layer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Discovery&lt;br /&gt;
* - missing in the spec.&lt;br /&gt;
*  manual config needed, which isn’t the best user experience.&lt;br /&gt;
&lt;br /&gt;
Possible Options&lt;br /&gt;
*  in-band discovery (the IMAP server provides some data to bootstrap with)&lt;br /&gt;
*  Webfinger, and then retrieve a JSON based doc to get config parameters&lt;br /&gt;
*  Dynamic Client Registration&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Implementations of SASL in email clients&lt;br /&gt;
* Google has SASL with OAuth2 (server-side)&lt;br /&gt;
* Amazon Kindle clients, Blackberry clients and the Microsoft Nokia phones use Gmail IMAP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Next steps&lt;br /&gt;
* spec discussion in the KITTEN WG&lt;br /&gt;
* issues like Discovery&lt;br /&gt;
* error messages for revoked/expired tokens&lt;br /&gt;
**	use simple error messages and require a second call to check whether token was&lt;br /&gt;
revoked/expired (deterministic behavior by client).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Some discussion about the GSS Header.&lt;br /&gt;
&lt;br /&gt;
Tunneling an HTTP-like mechanism to use it within SASL seems like we’re forcing an HTTP convention instead of using a JSON Convention - should be discussed further.&lt;br /&gt;
&lt;br /&gt;
SASL-SAML does discovery by getting the client to talk to the IMAP server to get the IDP from the username. (email address -&amp;gt; IMAP server address. IMAP server -&amp;gt; authz server address)&lt;br /&gt;
* in-band discovery in SASL (by separating out discovery of IMAP server and authz server)&lt;br /&gt;
* authz server ID (URL) + attach a trusted component -- hit discovery endpoint and download config param document.&lt;br /&gt;
** Type OAUTHBEARER + 1 URL -- if for authz server&lt;br /&gt;
** add a trusted pth, fetch the doc with endpoint info&lt;br /&gt;
** OR send the username and the actual discovery doc is a f(username).&lt;br /&gt;
&lt;br /&gt;
Reference: draft-ietf-kitten-sasl-oauth-14&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth_Security_%E2%80%93_Proof_of_Possession&amp;diff=19639</id>
		<title>OAuth Security – Proof of Possession</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth_Security_%E2%80%93_Proof_of_Possession&amp;diff=19639"/>
		<updated>2014-05-09T16:03:01Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' OAuth Security:  Proof of Possession&lt;br /&gt;
&lt;br /&gt;
Wednesday 1B&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Hannes&lt;br /&gt;
&lt;br /&gt;
'''Notes-takers):''' Roshni&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''&lt;br /&gt;
OAuth2, PoP&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Presentation here: http://www.tschofenig.priv.at/oauth/IETF-OAuth-PoP.pptx&lt;br /&gt;
&lt;br /&gt;
Presented status of various specs for provided security better than bearer token security.&lt;br /&gt;
&lt;br /&gt;
JWT 	&lt;br /&gt;
* uses JSON based encoding to describe claims&lt;br /&gt;
* “security token” but may also be used as an access token&lt;br /&gt;
&lt;br /&gt;
 Two cases:&lt;br /&gt;
 	1. Asymmetric Key&lt;br /&gt;
 	2. Symmetric Key (JWK encrypted in JWE)&lt;br /&gt;
 &lt;br /&gt;
 		    Authzn Server&lt;br /&gt;
 	I	   /	       \ 	III&lt;br /&gt;
 	          /    II	 \&lt;br /&gt;
 	Client----------Resource Servier&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Motivation:&lt;br /&gt;
* 1. Desire to have E2E security at the application level.&lt;br /&gt;
* 2. To disallow a resource server from reusing an access token in other services. (single use tokens)&lt;br /&gt;
&lt;br /&gt;
''Q. PoP almost a factor of client authentication''&lt;br /&gt;
&lt;br /&gt;
Discussed methods of binding the secret:&lt;br /&gt;
* 1. secret bound to token&lt;br /&gt;
* 2. secret bound to client&lt;br /&gt;
* 3. secret bound to client instance&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I. Client - Authzn server interaction&lt;br /&gt;
&lt;br /&gt;
Reference:&lt;br /&gt;
&lt;br /&gt;
Key distribution at client registration (draft-jones)&lt;br /&gt;
&lt;br /&gt;
Key distribution at access token issuance (draft-bradley)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Followed up with an example of the symmetric key case:&lt;br /&gt;
* (i) The client sends a request for an access token along with some indication that says “I support PoP tokens”.&lt;br /&gt;
* (ii) AS then creates a PoP enabled access token&lt;br /&gt;
* (iii) AS sends access token to client along with the key. The key is also included in the token.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Discussion:&lt;br /&gt;
&lt;br /&gt;
The symmetric key is produced by the AS.&lt;br /&gt;
&lt;br /&gt;
For the asymmetric key case, the client generates public private key pairs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What is the motivation for letting the client ask for PoP enabled tokens?&lt;br /&gt;
&lt;br /&gt;
“I can handle PoP” is different from explicitly asking for a PoP enabled token. The server must have some way of knowing that the client can handle these tokens. Should therefore not be a runtime request (some ambiguity about runtime requests spec’d in the reference draft)&lt;br /&gt;
-- reason for question: limit giving more options to potential attackers.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Does this work if the access token is not in a JWT?&lt;br /&gt;
&lt;br /&gt;
Yes, but this example made 4 assumptions:&lt;br /&gt;
*  i. symmetric key&lt;br /&gt;
*  ii. JWT&lt;br /&gt;
* iii. No token introspection between AS and RS&lt;br /&gt;
* iv. Long term key shared between AS and RS.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Repeat:&lt;br /&gt;
&lt;br /&gt;
PoP key should not be tied to JWT.&lt;br /&gt;
&lt;br /&gt;
ACK. Need to follow up.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For asymmetric keys, the draft currently supports both key creation at the client and by the AS.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
II. Client-RS interaction&lt;br /&gt;
* i) Proof of possession of PoP key&lt;br /&gt;
* ii) Message integrity + channel binding&lt;br /&gt;
* iii) RS to client authentication&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The authenticator is a keyed message type computed over the request (contains access token and channel binding). Client generates JOSE object (JWS) - covers access token + some secret component --&amp;gt; access token identifier, and then submits the whole structure with the HTTP message, does the above (i), (ii), (iii).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are problems with not signing everything. There was some discussion about mobility of headers and ordering. If the ordering of the headers matters for the API, then the app needs to be aware of that.&lt;br /&gt;
&lt;br /&gt;
Suggestion: use existing RFCs for canonicalization of requests affected by mutability under HTTP and proxies.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Or -- use channel binding (more to follow in the next talk).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The RS then uses the shared long term key (with the AS) to unwrap / decrypt the access token and verify the authenticator.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Channel Bindings:&lt;br /&gt;
&lt;br /&gt;
Ways to get the application layer security into the transport layer security&lt;br /&gt;
&lt;br /&gt;
Options include using a public key in the TLS or use tls-unique and tls-server-end-point.&lt;br /&gt;
&lt;br /&gt;
Warning: new attacks identified with the TLS based channel binding.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
III. RS-AS interaction&lt;br /&gt;
&lt;br /&gt;
Token introspection -- get claims and keying material from the AS to verify the authenticator, but the RS needs to identify itself first.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Next steps:&lt;br /&gt;
&lt;br /&gt;
slides to be shared on the OAuth mailing list.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=I_o_T_%3D_Identity_of_Things&amp;diff=19638</id>
		<title>I o T = Identity of Things</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=I_o_T_%3D_Identity_of_Things&amp;diff=19638"/>
		<updated>2014-05-09T16:01:14Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' IoT: Internet of Things Unintended &amp;amp; Unexpected Consequences&lt;br /&gt;
 &lt;br /&gt;
Tuesday 2F &lt;br /&gt;
&lt;br /&gt;
'''Convener:'''   Jeff Stollman&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:'''  Dave Sanford&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''  &lt;br /&gt;
&lt;br /&gt;
Presentation here: http://www.secureidentityconsulting.com/unanticipated-consequences-in-the-internet-of-things-iot/&lt;br /&gt;
&lt;br /&gt;
Presentation by Jeff, IoT components:&lt;br /&gt;
* 1) sensors&lt;br /&gt;
* 2) processors&lt;br /&gt;
* 3) actuators&lt;br /&gt;
* 4) combinations of above&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Lots of use cases described, with associated abuse cases&lt;br /&gt;
&lt;br /&gt;
Starting to include Scada&lt;br /&gt;
&lt;br /&gt;
Includes home appliances, Nest,&lt;br /&gt;
&lt;br /&gt;
Irrigation and flood control &lt;br /&gt;
&lt;br /&gt;
Limited ensuring data integrity - not always clear whose responsibility.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Dave Sanford - for any new use case, one or more new abuse cases.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Lots of discussion about gaming systems (e.g. fitbit users sending apparent physical exercise to health insurance company)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Who owns the data you collect?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Phil Windley - power of distributed systems to create robustness in book 'Honeybee Democracy' bee swarming and finding a new place - may be somewhat like 'unit of work' in bit coin.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Who is controlling your vehicle?  Phil - V2V (vehicle to vehicle), collision avoidance systems for cars, may allow governmental entities (or hackers) to shutdown multiple cars at the same time.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Lots of discussion about security and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Smart packaging - tell you what drugs to take.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Physical security devices - home surveillance cameras&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Electric grid - security and liability&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So issues raised include security, privacy, ownership and liability&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Blue boxes that tell lights that emergency vehicle is coming through.  Originally easy to clone and use.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Lots of talk about Arduino and approaches for IoT design.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Jeff will also send slides&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=FUSE_Architecture_%E2%80%93_PICOS_and_Connected_Cars&amp;diff=19637</id>
		<title>FUSE Architecture – PICOS and Connected Cars</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=FUSE_Architecture_%E2%80%93_PICOS_and_Connected_Cars&amp;diff=19637"/>
		<updated>2014-05-09T15:59:04Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Fuse Architecture Picos &amp;amp; Connected Cars   &lt;br /&gt;
&lt;br /&gt;
Tuesday 4F &lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Phil Windley&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Phil Windley&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
Received from Phil (link to presentation notes)&lt;br /&gt;
&lt;br /&gt;
http://www.slideshare.net/windley/fuse-2&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Mozilla_Listens_to_IIW&amp;diff=19636</id>
		<title>Mozilla Listens to IIW</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Mozilla_Listens_to_IIW&amp;diff=19636"/>
		<updated>2014-05-09T15:56:43Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Mozilla Listens to IIW  &lt;br /&gt;
&lt;br /&gt;
Wednesday 3A&lt;br /&gt;
&lt;br /&gt;
'''Convener:'''  Sean Bohan &amp;amp; Brian Warner &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Sean Bohan&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
Agenda: Mozilla has been to IIW before, but this is Sean and Brian’s first time. We want to engage the community and start discussions around what Mozilla is doing in Privacy/Identity and what the community needs. Brian had deck slides and they will be posted.&lt;br /&gt;
&lt;br /&gt;
Notes:&lt;br /&gt;
*	Mozilla is an Ecosystem of multiple platforms (desktop, android browser, $25 smartphone OS)&lt;br /&gt;
*	We are working on Persona, Accounts, Sync &lt;br /&gt;
*	Marketplace for apps and small-scale storage are also a part of that and critical needs&lt;br /&gt;
*	Mozilla is using symmetric encryption keys&lt;br /&gt;
*	Not an not an Identity Provider for 3rd party services, our work right now is aimed at mozilla services&lt;br /&gt;
*	We need to know browser has rights to modify or read and the auth mechanisms as well&lt;br /&gt;
*	sync/storage accept browser id insertions&lt;br /&gt;
*	Client creating data -using KeyB because server should not see it&lt;br /&gt;
*	Use case - Firefox marketplace to buy html applications&lt;br /&gt;
*	run from any desktop browser&lt;br /&gt;
*	receipts tied to Firefox account&lt;br /&gt;
*	greet you by name&lt;br /&gt;
&lt;br /&gt;
Crowd: &lt;br /&gt;
*	Have we looked at UMA?&lt;br /&gt;
*	UMA on top of OAuth &lt;br /&gt;
&lt;br /&gt;
Mozilla:&lt;br /&gt;
*	We dont know much about UMA - and will look into it&lt;br /&gt;
*	User Managed Access - more for user controlling policies for access to the data&lt;br /&gt;
*	We are thinking of whitelisting specific apps and the marketplace can learn without asking&lt;br /&gt;
*	3rd parties have to get permission&lt;br /&gt;
&lt;br /&gt;
Crowd: &lt;br /&gt;
*	UMA for the person to control&lt;br /&gt;
*	good opportunity - who wouldn't want to use PDS for some requirement&lt;br /&gt;
*	wonderful opportunity&lt;br /&gt;
*	mechanisms like that - share specific data - separate keys&lt;br /&gt;
*	share keys with diff recipients&lt;br /&gt;
&lt;br /&gt;
Adrian - &lt;br /&gt;
*	MIT has 2 camps looking at oAuth&lt;br /&gt;
*	one camp - pds users must use it as part of the big data thing&lt;br /&gt;
*	second camp -make sure the server, encrypt, so server can't be controlled and keys to the server are handed out specific to the query&lt;br /&gt;
*	service based system - payment serv or shipping serv&lt;br /&gt;
*	legal recourse if it's required&lt;br /&gt;
&lt;br /&gt;
Crowd:&lt;br /&gt;
&lt;br /&gt;
doing purpose built value add vert integrated verison of YAS?&lt;br /&gt;
&lt;br /&gt;
Mozilla:&lt;br /&gt;
*	Firefox accounts - our intention right now is to solve the needs that we have, to solve for issues we have - also to get to be a bigger player in this space by bringing more to the space&lt;br /&gt;
*	Right now the only rps supported would be mozilla services&lt;br /&gt;
*	The Profile stuff we are working on is new&lt;br /&gt;
*	User Personalization is related&lt;br /&gt;
&lt;br /&gt;
Drummond:&lt;br /&gt;
*	Gen question - whole ecosystem, interop, doesn't it make sense for that what we are building be an interoperable personal cloud&lt;br /&gt;
*	These questions are the questions for all uses of personal clouds: encryption, how to encrypt? etc.&lt;br /&gt;
*	If best pract/interop are developed and Firefox is a user agent  - then it seems we cross into new space&lt;br /&gt;
&lt;br /&gt;
Brian:&lt;br /&gt;
*	what features you want in the browser to support it? &lt;br /&gt;
*	things we thought of - before Accounts was &amp;quot;profile int he cloud&amp;quot; - should be retrievable from any device - interesting ways to combine 2 factor stuff, kiosks, flight, etc.&lt;br /&gt;
*	&amp;quot;pickle&amp;quot; - get browser profile to be cloud and not local drive&lt;br /&gt;
*	extend from that - other things kept in synch with other cloud services&lt;br /&gt;
*	bookmarks synch with other cloud services&lt;br /&gt;
bookmark synch - provide better framework - synch server one choice&lt;br /&gt;
&lt;br /&gt;
adrian:&lt;br /&gt;
*	Wants to see on the slide is a cert authotity –&lt;br /&gt;
*	agrees with asa and drummond - if moz would use it's leverage to put the 3 things together - demand issues desire to evolve consistent steppingstone and the splice point into the reality of pki with all of it's faults&lt;br /&gt;
*	wants mozilla to solve user experience prob for PKI&lt;br /&gt;
&lt;br /&gt;
Drummond:&lt;br /&gt;
*	adoption of pclouds and user recogntion of clouds&lt;br /&gt;
*	mozilla listening - big deal&lt;br /&gt;
&lt;br /&gt;
Asa:&lt;br /&gt;
*	Uses chrome - because it has users he can switch from and testing&lt;br /&gt;
*	If Firefox were not conflating concepts of accounts and who I am that would be great&lt;br /&gt;
*	Better: there would be a hard and fast - this cand that can learn and see how behavior models diff personalities that would be grt&lt;br /&gt;
*	ideal - go to banking site and not worry cookies or connections would be needed&lt;br /&gt;
*	dont need a plugin or ridiculous chrome profiles&lt;br /&gt;
&lt;br /&gt;
Brian:&lt;br /&gt;
*	Big thing to fix and nail down the UI for that&lt;br /&gt;
*	Thinks we need to have aspects of Firefox Accounts that afect the behavior of the browser  - ties to Sync&lt;br /&gt;
*	website signing into withother identities&lt;br /&gt;
*	remembers set of emails you have control over&lt;br /&gt;
*	remembers last email - defaults to that&lt;br /&gt;
*	set of addresses persona knows about&lt;br /&gt;
*	mapping rp to address&lt;br /&gt;
*	ID given to a given website - enables within that profile&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ping Identity person:&lt;br /&gt;
*	killer feature to be secure discovery service&lt;br /&gt;
*	introduce to the right services (federation or somethign else) pds - if we can be central place that stores pointers but gives usability and ability to plug things in&lt;br /&gt;
*	not just an ask for PDS integration - ask for this to be a theme and a system others can plug into&lt;br /&gt;
*	BETTER IF browser delivered privacy exp they want&lt;br /&gt;
&lt;br /&gt;
Drummond:&lt;br /&gt;
*	Early features - ironic &amp;quot;what can browser do for me&amp;quot;&lt;br /&gt;
*	from his perspective - privacy prob&lt;br /&gt;
*	private browsing modes one aspect&lt;br /&gt;
*	new aspect control over info and releasing - lot picking up on it&lt;br /&gt;
*	html 5 meta referrer none&lt;br /&gt;
&lt;br /&gt;
Brian thinks it's great&lt;br /&gt;
&lt;br /&gt;
Sean says Mozilla is definitely coming back to IIW&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19635</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19635"/>
		<updated>2014-05-09T15:53:25Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Engaging End Users – How Do We Get Consumers to Participate in Identity]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
3K/ [[Join the Indieweb]]&lt;br /&gt;
 &lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[ID Web/Literacy and Leverage – Sovereign By Design]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Reputation&amp;diff=19634</id>
		<title>Reputation</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Reputation&amp;diff=19634"/>
		<updated>2014-05-09T15:51:42Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Open Reputation Framework   &lt;br /&gt;
&lt;br /&gt;
Wednesday 1G&lt;br /&gt;
http://iiw.idcommons.net/Main_Page&lt;br /&gt;
'''Convener:'''  Dave Sanford&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):'''  Dave Sanford&lt;br /&gt;
 &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
Dave started by giving an architectural overview of a proposed Open Reputation system that would allow individuals to assert reputations to individuals, their knowledge and possibly lots of other things (e.g. products, etc.).  Mostly this is not self-assertion of their own reputation, while that should probably be allowed - it has very little weight outside itself.&lt;br /&gt;
&lt;br /&gt;
Dave also suggested that to be decentralized this should be build on top of a decentralized consensus algorithms like block chain or ripple.&lt;br /&gt;
&lt;br /&gt;
The model includes an individual's ability to define their preferences for their own use in curating and weighting the value of information sources, etc.  so that they can filter information coming in.  By feeding these weighted preferences to:&lt;br /&gt;
&lt;br /&gt;
Aggregate reputation modes - which use various weighting algorithms (pagerank?, Bayesian) to create weightings of reputations which are available to individuals.&lt;br /&gt;
&lt;br /&gt;
Individuals and reputation nodes will have reputations that are created about the quality of the reputations that they produce, which change over time.&lt;br /&gt;
&lt;br /&gt;
There were various discussions about how reputation information is defined and communicated - that included discussions about comments and context.  This led to the discussion of information being communicated via graphs and XDI.&lt;br /&gt;
&lt;br /&gt;
?  asserted that this becomes communicated like X has a reputation for Y among Z.&lt;br /&gt;
&lt;br /&gt;
Lots more discussion - common protocol is clearly required.  Is a common reputation algorithm required for individual and/or aggregate reputation nodes?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Extra Notes'''&lt;br /&gt;
* is a complex space&lt;br /&gt;
* concrete use cases for killer app needed&lt;br /&gt;
* Reputation score is original number&lt;br /&gt;
* Lots of paper to read&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Reputation&amp;diff=19633</id>
		<title>Reputation</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Reputation&amp;diff=19633"/>
		<updated>2014-05-09T15:51:23Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:'''' Open Reputation Framework   &lt;br /&gt;
&lt;br /&gt;
Wednesday 1G&lt;br /&gt;
&lt;br /&gt;
'''Convener:'''  Dave Sanford&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):'''  Dave Sanford&lt;br /&gt;
 &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
Dave started by giving an architectural overview of a proposed Open Reputation system that would allow individuals to assert reputations to individuals, their knowledge and possibly lots of other things (e.g. products, etc.).  Mostly this is not self-assertion of their own reputation, while that should probably be allowed - it has very little weight outside itself.&lt;br /&gt;
&lt;br /&gt;
Dave also suggested that to be decentralized this should be build on top of a decentralized consensus algorithms like block chain or ripple.&lt;br /&gt;
&lt;br /&gt;
The model includes an individual's ability to define their preferences for their own use in curating and weighting the value of information sources, etc.  so that they can filter information coming in.  By feeding these weighted preferences to:&lt;br /&gt;
&lt;br /&gt;
Aggregate reputation modes - which use various weighting algorithms (pagerank?, Bayesian) to create weightings of reputations which are available to individuals.&lt;br /&gt;
&lt;br /&gt;
Individuals and reputation nodes will have reputations that are created about the quality of the reputations that they produce, which change over time.&lt;br /&gt;
&lt;br /&gt;
There were various discussions about how reputation information is defined and communicated - that included discussions about comments and context.  This led to the discussion of information being communicated via graphs and XDI.&lt;br /&gt;
&lt;br /&gt;
?  asserted that this becomes communicated like X has a reputation for Y among Z.&lt;br /&gt;
&lt;br /&gt;
Lots more discussion - common protocol is clearly required.  Is a common reputation algorithm required for individual and/or aggregate reputation nodes?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Extra Notes'''&lt;br /&gt;
* is a complex space&lt;br /&gt;
* concrete use cases for killer app needed&lt;br /&gt;
* Reputation score is original number&lt;br /&gt;
* Lots of paper to read&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19632</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19632"/>
		<updated>2014-05-09T15:50:26Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Session 1 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Engaging End Users – How Do We Get Consumers to Participate in Identity]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
3K/ [[Join the Indieweb]]&lt;br /&gt;
 &lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Open Reputation Framework]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[ID Web/Literacy and Leverage – Sovereign By Design]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management]] – &lt;br /&gt;
like SCADA and ME&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Channel_Binding_for_Open_ID_Connect&amp;diff=19631</id>
		<title>Channel Binding for Open ID Connect</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Channel_Binding_for_Open_ID_Connect&amp;diff=19631"/>
		<updated>2014-05-09T15:35:25Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Channel Binding for Open ID Connect&lt;br /&gt;
&lt;br /&gt;
Wednesday 2G&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Mike Jones/Breno&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Roshni Chandras&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''&lt;br /&gt;
OpenID Connect, Channel ID, Channel Binding&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
 &lt;br /&gt;
'''TLS'''&lt;br /&gt;
Mutual authentication&lt;br /&gt;
*	end-user auth technology&lt;br /&gt;
*	certificate for user identity&lt;br /&gt;
*	no relationship to server user authentication&lt;br /&gt;
*	should involve user content&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Because of these assumptions, it is not practical for user-facing actions, but is now used in server-server communication -- this works well in a closed environment where you control large parts of the stack.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''TLS Channel Binding'''&lt;br /&gt;
&lt;br /&gt;
Authenticate device (context) rather than the user&lt;br /&gt;
&lt;br /&gt;
- public keys / no trust chain requirement&lt;br /&gt;
&lt;br /&gt;
- no steps by the user for provisioning since your machine can now autogenerate a binding.&lt;br /&gt;
&lt;br /&gt;
- isolation of which keys are used to communicate with each server based on same-origin policy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The same privacy model that browsers currently have in place for cookies will work well for keys/TLS Channel IDs&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Side-note:&lt;br /&gt;
&lt;br /&gt;
TLS Raw Public Keys&lt;br /&gt;
&lt;br /&gt;
- public keys / not bound to the same origin&lt;br /&gt;
&lt;br /&gt;
- bound to access token or some other oauth construct&lt;br /&gt;
&lt;br /&gt;
- uses same container TLS uses for certificates (certificate pay-load container)&lt;br /&gt;
&lt;br /&gt;
(No need to define a separate field in TLS)&lt;br /&gt;
&lt;br /&gt;
- but doesn’t solve the problem of certificate hinting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Back to TLS Channel Binding:&lt;br /&gt;
&lt;br /&gt;
'''TLS Session Resumption'''&lt;br /&gt;
&lt;br /&gt;
another feature of TLS Channel IDs.&lt;br /&gt;
&lt;br /&gt;
- server recognizes when it sees the device again&lt;br /&gt;
&lt;br /&gt;
- provides the ability to manage sessions ~ cookie memcache infrastructure&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''TLS Channel ID'''&lt;br /&gt;
&lt;br /&gt;
- automatically managed by TLS infrastructure&lt;br /&gt;
&lt;br /&gt;
(if we rekey the same cert, this breaks - requires reauth, WAI)&lt;br /&gt;
&lt;br /&gt;
You can now bind artifacts to this context.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Application layer code on both sides of the connection are able to inspect Channel ID and use it in protocol messages (signed or encrypted) - the recipient pulls out the channel ID and ties application layer state to a particular channel setup so that if the message arrives on the wrong channel, it can be tossed (example, capture and replay)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The channel ID can be used in application/protocol state - the server could create an integrity protected cookie with channel ID in it. If the cookie leaks, this context cannot be reused.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Q. Can you clear cookies and keys separately?&lt;br /&gt;
&lt;br /&gt;
Yes, but you’ll need new cookies if you reset keys.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can use channel binding without protocol support if UA supports Channel IDs and the client and Authzn server have the same origin. If they do not, we need &lt;br /&gt;
protocol support.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''IETF Cross Certifying Channels'''&lt;br /&gt;
&lt;br /&gt;
secure and ID token E2E from an OpenID provider or Oauth server.&lt;br /&gt;
&lt;br /&gt;
Refer to diagram:&lt;br /&gt;
 &lt;br /&gt;
[[File:IIW18_Wed2G.png‎]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Naive method:&lt;br /&gt;
&lt;br /&gt;
Put channel ID available to browser and the server in the ID token. Won’t work. Client compares channel ID received to the one used and they don’t match.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
However, there is an authoritative party that knows both channel IDs - the browser, where the communication is moving through, typically by a redirect, is in possession of the private key material for both channels.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So, we create a message containing each channel ID signed using the other channel ID. Having both signatures is the cryptographic proof that the same party holds the information for both channels.&lt;br /&gt;
&lt;br /&gt;
If the 302 redirect to the client had a flag that said “please emit channel pari proof as a param, possibly in an HTTP header to the client”, the client would then look in the ID token, see the channel ID (ch1) and look in the header -- “do I have proof that ch1 is paired with ch2 (my channel ID)?” and accepts the ID token as coming &lt;br /&gt;
from 2 channels transiting the same device.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The TLS channel binding is not aware of user consent to give information to the server, since channel binding should be independent of the application. The browser also does not need to know what is being protected by the channel ID, therefore, we can’t use raw public keys alone.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Q. Is it sufficient to include Channel ID (ch2) in the request to the server?&lt;br /&gt;
&lt;br /&gt;
A. This still allows MITM attacks, diminishing the value of the channel binding. It also does not provide E2E proof.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Q. What about browsers talking to an app on a phone?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Open Q with room for discussion:&lt;br /&gt;
&lt;br /&gt;
How do we extend this exercise to the code flow?&lt;br /&gt;
&lt;br /&gt;
There’d be a 3rd channel ID. Handling the client-browser-server issue is harder to solve and the expectation is that the code flow won’t be as hard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Note about the 302 redirect and cross-certification:&lt;br /&gt;
&lt;br /&gt;
The 302 redirect is one of 3 mechanisms in modern browsers that cause cross-domain communication in a controlled manner&lt;br /&gt;
&lt;br /&gt;
- location reference from one origin causes a message to be sent to a different origin&lt;br /&gt;
&lt;br /&gt;
- there are limited ways to do this, and at the same time as the cross-origin communication is occurring, with the consent of the parties involved, you can cross-&lt;br /&gt;
certify the channel IDs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
However, there are two other mechanisms: POST message and CORS. If we have a cross-certification mechanism, both W3C and the browser community will want it to &lt;br /&gt;
be applicable to all 3 cross-domain communication mechanisms.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Open_Reputation_Framework&amp;diff=19630</id>
		<title>Open Reputation Framework</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Open_Reputation_Framework&amp;diff=19630"/>
		<updated>2014-05-09T15:31:11Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: notes content added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Open Reputation Framework   &lt;br /&gt;
&lt;br /&gt;
Wednesday 1G&lt;br /&gt;
&lt;br /&gt;
'''Convener:'''  Dave Sanford&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):'''  Dave Sanford&lt;br /&gt;
 &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
Dave started by giving an architectural overview of a proposed Open Reputation system that would allow individuals to assert reputations to individuals, their knowledge and possibly lots of other things (e.g. products, etc.).  Mostly this is not self-assertion of their own reputation, while that should probably be allowed - it has very little weight outside itself.&lt;br /&gt;
&lt;br /&gt;
Dave also suggested that to be decentralized this should be build on top of a decentralized consensus algorithms like block chain or ripple.&lt;br /&gt;
&lt;br /&gt;
The model includes an individual's ability to define their preferences for their own use in curating and weighting the value of information sources, etc.  so that they can filter information coming in.  By feeding these weighted preferences to:&lt;br /&gt;
&lt;br /&gt;
Aggregate reputation modes - which use various weighting algorithms (pagerank?, Bayesian) to create weightings of reputations which are available to individuals.&lt;br /&gt;
&lt;br /&gt;
Individuals and reputation nodes will have reputations that are created about the quality of the reputations that they produce, which change over time.&lt;br /&gt;
&lt;br /&gt;
There were various discussions about how reputation information is defined and communicated - that included discussions about comments and context.  This led to the discussion of information being communicated via graphs and XDI.&lt;br /&gt;
&lt;br /&gt;
?  asserted that this becomes communicated like X has a reputation for Y among Z.&lt;br /&gt;
&lt;br /&gt;
Lots more discussion - common protocol is clearly required.  Is a common reputation algorithm required for individual and/or aggregate reputation nodes?&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19629</id>
		<title>IIW 18 Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IIW_18_Notes&amp;diff=19629"/>
		<updated>2014-05-09T15:30:16Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: /* Session 1 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tuesday May 6, 2014=&lt;br /&gt;
&lt;br /&gt;
===Session 1===&lt;br /&gt;
&lt;br /&gt;
1A/ [[Respect Network LAUNCH]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[Social ID’s in Enterprise]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Indie BOX – Let’s Bring Our Data Home]]&lt;br /&gt;
&lt;br /&gt;
1F/ [[Covert Redirect – What It Is/What It Ain’t]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Improving the Mobile Federation Sign-In Experience]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[Phishing Blend Authentication and Authorization]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
&lt;br /&gt;
2A/ [[JOSE Can You See – A Technical Overview of JWT]]&lt;br /&gt;
&lt;br /&gt;
2B/ [[Collaboration For Collective Impact]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[Me Depot – Serving Billions]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[Intentions vs Identity]]&lt;br /&gt;
&lt;br /&gt;
2F/ [[I o T = Identity of Things]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Customer Support for Personal Data Stores]]&lt;br /&gt;
&lt;br /&gt;
2H/ [[An Introducing to IndieWeb]]&lt;br /&gt;
&lt;br /&gt;
2I/ [[“SCIM” Next Steps]]&lt;br /&gt;
&lt;br /&gt;
2J/ [[New OAuth 2-wg – Multi-Party Federation]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
&lt;br /&gt;
3A/ [[OpenID Connect – Interop Testing Details]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[It’s NAPPS – Enabling SSO for Native APPS]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Engaging End Users – How Do We Get Consumers to Participate in Identity]]&lt;br /&gt;
&lt;br /&gt;
3D/ [[“Privacy Lens”]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Platform Deep-Dive of: Qredo]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Open ID Connect 101 – How it Works/What is it for]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Ethical Data Handling]]&lt;br /&gt;
&lt;br /&gt;
3I/ [[Silicon Valley “Culture of Youth”]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Your Digital Traits for STRONG Auth]]&lt;br /&gt;
&lt;br /&gt;
3K/ [[Join the Indieweb]]&lt;br /&gt;
 &lt;br /&gt;
===Session 4===&lt;br /&gt;
&lt;br /&gt;
4A/ [[OpenID Connect – Logout/Session Mgmt (Part 1)]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[How Do We Preserve and Protect Identity / Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[CAN’T BE EVIL]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[FUSE Architecture – PICOS and Connected Cars]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[NSTIC – Update From NIST and Roundtable]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[IndieAuth – Turn Your Personal Domain Into An OAUTH Provider]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Practice Session for Investor Panel]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
&lt;br /&gt;
5A/ [[OpenID Connect – Logout/Session Mgmt (Part 2)]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Personal Sovereign Design]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[4th Parties – Use Cases for Others Besides the User, IDP and Relying Party]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[DOXING as Vigilante Justice]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Respect Network plus XDI]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[Aging plus Caregivers plus Post Death Identity Mngt]]&lt;br /&gt;
&lt;br /&gt;
=Wednesday May 7, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[VRM (Vendor Relationship Management) Progress Report]]&lt;br /&gt;
&lt;br /&gt;
1B/ [[OAuth Security – Proof of Possession]]&lt;br /&gt;
&lt;br /&gt;
1C/ [[Privacy Metrics – What Could They Be? What Should They Measure? Should They Exist?]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Home Owner Personal Data]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Open Reputation Framework]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2A/ [[VRM Adoption Case Study – MYDEX]]&lt;br /&gt;
&lt;br /&gt;
2C/ [[HTTPSY – Leave the Certificate Authority Behind]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[SAFEnet]]&lt;br /&gt;
&lt;br /&gt;
2E/ [[Data Inequality $ = $ Income Inequality]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Channel Binding for Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
2K/ [[ADHOC: UMA Interop Testing Session Thing]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[Mozilla Listens to IIW]]&lt;br /&gt;
&lt;br /&gt;
3C/ [[Real Estate Use Cases]]&lt;br /&gt;
&lt;br /&gt;
3E/ [[Shopping for Identity Providers – What do I need to know before I put my identity in your provider]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Functional Model Elements from NSTIC – Personal Cloud Review]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Self ID]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[Mobile Connect]]&lt;br /&gt;
&lt;br /&gt;
3J/ [[Clarify and Learn About Web Payments and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[New Book – Extreme Relevancy]]&lt;br /&gt;
&lt;br /&gt;
4B/ [[IoT and Open Standards – Oauth2, UMA…]]&lt;br /&gt;
&lt;br /&gt;
4C/ [[ID Web/Literacy and Leverage – Sovereign By Design]]&lt;br /&gt;
&lt;br /&gt;
4D/ [[Gettign WC3 People to come to IIW19]]&lt;br /&gt;
&lt;br /&gt;
4E/ [[Mobile SSO – How We Did It/USIMG/OAuth, Open ID Connect]]&lt;br /&gt;
&lt;br /&gt;
4F/ [[OAuth SASL (OAuth for non-web apps, ep.IMAP)]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Post Life Identity Privacy]]&lt;br /&gt;
&lt;br /&gt;
4H/ [[Root of Trust]]&lt;br /&gt;
&lt;br /&gt;
4J/ [[Investor Pitch Practice (Pt 1)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Be Ready for the AUTHpocalypse – Lightweight/Dynamic Client Registration for IMAP/SASL]]&lt;br /&gt;
&lt;br /&gt;
5B/ [[Identity Ecosystems plus the IDESG]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Google – Recent Update and Input on OAuth DevX]]&lt;br /&gt;
&lt;br /&gt;
5D/ [[ID Things You Can Do With A “FREEDOM BOX”]]&lt;br /&gt;
&lt;br /&gt;
5E/ [[The ID – Lobrary/Film Fest and Anthology – ‘this Community Cannon’]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[Help us do Social Media Marketing for the Respect Network Launch]]&lt;br /&gt;
&lt;br /&gt;
5G/ [[How To Deal With The Case When The Intended Audience Is Not The Releasing Party]]&lt;br /&gt;
&lt;br /&gt;
5H/ [[Lost Dog! User Centric ID Management (FIDO and Other Opts…]]&lt;br /&gt;
&lt;br /&gt;
5I/ [[Bitcoin and Identity]]&lt;br /&gt;
&lt;br /&gt;
5J/ [[Investor Pitch Practice (Pt 2)]]&lt;br /&gt;
&lt;br /&gt;
5K/ [[NAAPS Working Group]]&lt;br /&gt;
&lt;br /&gt;
=Thursday May 8, 2014=&lt;br /&gt;
===Session 1===&lt;br /&gt;
1A/ [[In 5min or less – Tell me a Happy Future Story About “IDENITY”]]&lt;br /&gt;
&lt;br /&gt;
1D/ [[Let’s create some -Partinent Art – that speaks to our condition and Brainstorming ides about topics for books for children and management – &lt;br /&gt;
like SCADA and ME]]&lt;br /&gt;
&lt;br /&gt;
1G/ [[Reputation]]&lt;br /&gt;
&lt;br /&gt;
1J/ [[DNSSEC 101 – intro how it works/my war stories]]&lt;br /&gt;
&lt;br /&gt;
===Session 2===&lt;br /&gt;
2B/ [[DARASHA XDI app – Music Library]] &lt;br /&gt;
&lt;br /&gt;
2C/ [[AWS QandA]]&lt;br /&gt;
&lt;br /&gt;
2D/ [[ACE = Authentication and Authorization for Constrained Environments]]&lt;br /&gt;
&lt;br /&gt;
2G/ [[Help Doc prep for the VC Panel]]&lt;br /&gt;
&lt;br /&gt;
2I/  [[The Maker Economy and Identity]]&lt;br /&gt;
&lt;br /&gt;
===Session 3===&lt;br /&gt;
3A/ [[What’s it Take to get a Customer-Centric Startup to Win Funding? (VC Panel Discussion)]]&lt;br /&gt;
&lt;br /&gt;
3B/ [[Kitties are Fluffy!!]]&lt;br /&gt;
&lt;br /&gt;
3F/ [[Icons for Privacy]]&lt;br /&gt;
&lt;br /&gt;
3G/ [[Where Are the RP’s?]]&lt;br /&gt;
&lt;br /&gt;
3H/ [[HOW CSP’s (cloud service providers) and Authentication Providers Fit Together on the RESPECT NETWORK]]&lt;br /&gt;
&lt;br /&gt;
===Session 4===&lt;br /&gt;
4A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
4G/ [[Free People Beyond the Next 10 Years – (Continuation from Wed Session/Manifesto Writing)]]&lt;br /&gt;
&lt;br /&gt;
===Session 5===&lt;br /&gt;
5A/ [[Start-Up’s Pitching]]&lt;br /&gt;
&lt;br /&gt;
5C/ [[Murder via Google Maps]]&lt;br /&gt;
&lt;br /&gt;
5F/ [[CAMBRIAN – A User-Centric de-centralized platform for entrepreneurs]]&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Kitties_are_Fluffy!!&amp;diff=19628</id>
		<title>Kitties are Fluffy!!</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Kitties_are_Fluffy!!&amp;diff=19628"/>
		<updated>2014-05-09T15:28:50Z</updated>

		<summary type="html">&lt;p&gt;Ebgross: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session Topic:''' Kitties are Fluffy!   &lt;br /&gt;
&lt;br /&gt;
Thursday 3B  &lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Justin Richer&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:'''  David Pinter&lt;br /&gt;
&lt;br /&gt;
'''Tags for the session - technology discussed/ideas considered:'''  multiple personas, corporate identity, personal identity, anonymity, outing,   &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:''' &lt;br /&gt;
&lt;br /&gt;
BYOD is evolving into BYO Id&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
How does a corporate interest get impacted by action made from within a personal context?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Aggregate reputation/impact of employees _is_ the company reputation:  The higher up the employee in the org, the greater the impact&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Corporations (as employers) are NOT managing ID.  Employees are bringing their IDs into the enterprise (ex:  Forwarding corporate email to personal Gmail b/c that's where the employee's email lives, and where they &amp;quot;do&amp;quot; email).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Posts/comments are a reflection of personal State when made by individuals using company-provided IDs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Comments made under a Company provided ID have a greater weight than a personal ID&lt;br /&gt;
Employees are at risk posting under company ID&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Is there a safe harbor on the Net for Real Personas?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To what extend does an IDP stand behind the individual?  It's different when the individual is an Agent of the IDP (employee) or customer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Young people today have always HAD the internet, and are used to the concept of multiple identities/personas and can manage them natively (like children who grow up speaking multiple languages)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Tools, comfort, and calluses develop over time.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Internet lacks a richness of context; sometimes the wrong persona is used on line.  But when in Grandma's living room, it's not possible to switch out of the &amp;quot;grandma context&amp;quot; (vs. the school or friend or parent context)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Internet doesn't forget or integrate.  Transcripts are available for replay, but overall impressions formed in personal interactions (facial expression and body language, etc) add to human to human conversations that ultimately make the experience something greater than the recorded transcript.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Systems can now correlate contributions and recognize individuals using multiple personas, have the ability to &amp;quot;out&amp;quot; posters using different IDs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We use different pathways when we speak than when we write.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Some individuals are better able to manage separate personas than others, kids in particular are inherently better at this.&lt;/div&gt;</summary>
		<author><name>Ebgross</name></author>
		
	</entry>
</feed>