<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=IdentityWoman</id>
	<title>IIW - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=IdentityWoman"/>
	<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/Special:Contributions/IdentityWoman"/>
	<updated>2026-05-27T20:16:33Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.6</generator>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IDCollab_Proposed_Topics&amp;diff=3431</id>
		<title>IDCollab Proposed Topics</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IDCollab_Proposed_Topics&amp;diff=3431"/>
		<updated>2010-12-30T03:03:00Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''What topics are you planning to present about or lead a discussion about?'''&lt;br /&gt;
* NSTIC&lt;br /&gt;
* Personal Identity Verification Interoperability (PIV-I)&lt;br /&gt;
* Identity Assurance, Trust Frameworks&lt;br /&gt;
* Higher LOA certificationTrust FrameworksClient agents&lt;br /&gt;
&lt;br /&gt;
'''What are you hoping to hear and learn about and/or discuss?'''&lt;br /&gt;
* harmonization of user and enterprise issues&lt;br /&gt;
* Whatever other people think is important&lt;br /&gt;
* latest version of OpenID ABC&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''What are the critical questions about user-centric, enterprise, government and other forms of identity you hope to discuss with peers?'''&lt;br /&gt;
* Levels of Assurance and the trust models to support them&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=IDCollab_Proposed_Topics&amp;diff=3430</id>
		<title>IDCollab Proposed Topics</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=IDCollab_Proposed_Topics&amp;diff=3430"/>
		<updated>2010-12-30T03:02:36Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: Created page with ''''What topics are you planning to present about or lead a discussion about?''' * NSTIC * Personal Identity Verification Interoperability (PIV-I) * Identity Assurance, Trust Fram...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''What topics are you planning to present about or lead a discussion about?'''&lt;br /&gt;
* NSTIC&lt;br /&gt;
* Personal Identity Verification Interoperability (PIV-I)&lt;br /&gt;
* Identity Assurance, Trust Frameworks&lt;br /&gt;
* Higher LOA certificationTrust FrameworksClient agents&lt;br /&gt;
&lt;br /&gt;
'''What are you hoping to hear and learn about and/or discuss?'''&lt;br /&gt;
* harmonization of user and enterprise issues&lt;br /&gt;
* Whatever other people think is important&lt;br /&gt;
* latest version of OpenID ABC&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''What are the critical questions about user-centric, enterprise, government and other forms of identity you hope to discuss with peers?'''&lt;br /&gt;
* Levels of Assurance and the trust models to support them&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3429</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3429"/>
		<updated>2010-12-30T02:59:36Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* Next Internet Identity Workshops */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;Big&amp;gt; Welcome to the Internet Identity Workshop (IIW) Wiki &amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.internetidentityworkshop.com WE HAVE A WEBSITE/BLOG TOO!] &lt;br /&gt;
&lt;br /&gt;
* To get updates regarding IIW  [http://lists.idcommons.net/lists/info/iiwinfo subscribe here].&lt;br /&gt;
&lt;br /&gt;
[[Subject Specific Note Collections]]&lt;br /&gt;
&lt;br /&gt;
=== Next Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
IIW #12 will be in May 3-5, 2011.  Dates will be announced in December 2010.&lt;br /&gt;
&lt;br /&gt;
We are working on collaborating the Kantara Initiative on a community unconference before RSA on February 14th.&lt;br /&gt;
It will be run like IIW with attendees creating the agenda live the day of the event. &lt;br /&gt;
&lt;br /&gt;
[http://idcolab.eventbrite.com REGISTRATION IS OPEN NOW &amp;amp; MORE INFORMATION]. &lt;br /&gt;
&lt;br /&gt;
[[IDCollab Proposed Topics]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are considering hosting IIW Satellite events on the East Coast of the United States and in Europe in 2011.  Feel free to contact us if you are interested in helping/participating.  (iiwnotes@gmail.com)&lt;br /&gt;
&lt;br /&gt;
We have an [http://lists.idcommons.net/lists/subscribe/iiwinfo announcement list] that you can subscribe to if you would like to get an e-mail when new IIW &amp;amp; IOS events are announced.&lt;br /&gt;
&lt;br /&gt;
=== Previous Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
* #11 Fall 2010 [[iiw11]] Nov 2-4, Tuesday-Thursday at the Computer HIstory Museum in Mountain View California&lt;br /&gt;
** [[Notes IIW11]]&lt;br /&gt;
** [http://www.internetidentityworkshop.com/what-is-iiw/ Responses to IIW is...] [http://www.internetidentityworkshop.com/iiw-values/ Values of IIW]&lt;br /&gt;
&lt;br /&gt;
* [[iiw-europe-1|IIW Europe]] in London Monday October 11 (before RSA Europe) at the University of London&lt;br /&gt;
** [[iiw-europe-1-Notes]]&lt;br /&gt;
** [[iiw-europe-1-Reflection]] As a Result of Today.... &lt;br /&gt;
&lt;br /&gt;
* [[iiw-east-1|IIW East Coast]] in DC September 9-10 Thursday, Friday at the Josephine Butler Parks Center (following the Gov 2.0 Summit) the theme will be ''Open Identity for Open Government'' &lt;br /&gt;
** [[Notes_IIW-East]]&lt;br /&gt;
** [[As a result of day 1 at IIW-East]]&lt;br /&gt;
&lt;br /&gt;
* #10: Spring 2010 [[iiw10]] May 17-19 at the Computer History Museum. &lt;br /&gt;
** [[Notes IIW10]]&lt;br /&gt;
&lt;br /&gt;
* #9: Fall 2009 [[iiw9]] TUESDAY November 3 to THURSDAY November 5. &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #8: Spring 2009 [[iiw8]] - '''May 18-20, 2009''' &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #7: Fall [[iiw2008b]] (2008B)- '''Nov 10-12''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_08b]]&lt;br /&gt;
&lt;br /&gt;
* 6: Spring [[iiw2008a]]  (2008A)- '''May 12-14, 2008''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_2008a]]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.idcommons.net/index.php/Iiw2007b 5: December 3-5, 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop_2007 4: May 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006b 3: December 2006 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006 2: May 2006 - - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://www.socialtext.net/iiw2005/index.cgi?internet_identity_workshop_2005 1: October 2005 - Berkeley, CA]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Open Spaces ===&lt;br /&gt;
&lt;br /&gt;
Identity Open Space events are co-produced by the IIW team (Phil, Kaliya, Doc) in collaboration with other organizations and events. To date we have worked with Digital Identity World and the Liberty Alliance. We are open to working with a variety organizations - if you are interested please don't hesitate to contact us. &lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSF September 2007 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSBrussels May 2007 following a Liberty Alliance Meeting in Brussels, Belgium]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSantaClara September 2006 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSVan July 2006 following a Liberty Alliance Meeting in Vancouver, Canada]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Birds of a Feather Meetings ===&lt;br /&gt;
&lt;br /&gt;
June 2006 [http://www.identitygang.org/ Identity Gang Birds of a Feather Session] at Burton Group Conference, San Francisco&lt;br /&gt;
&lt;br /&gt;
January 2006 [http://www.socialtext.net/iiw2005/index.cgi?identity_speed_geeking_o_reilly_emerging_telephony_conference Identity Speed Geeking Session] at O'Reilly's  Emerging Telephony Conference&lt;br /&gt;
&lt;br /&gt;
December 2005 [http://www.socialtext.net/iiw2005/index.cgi?informational_morning_for_developers Pre-Syndicate Informational Morning for Developers]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3428</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3428"/>
		<updated>2010-12-30T02:59:17Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* Next Internet Identity Workshops */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;Big&amp;gt; Welcome to the Internet Identity Workshop (IIW) Wiki &amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.internetidentityworkshop.com WE HAVE A WEBSITE/BLOG TOO!] &lt;br /&gt;
&lt;br /&gt;
* To get updates regarding IIW  [http://lists.idcommons.net/lists/info/iiwinfo subscribe here].&lt;br /&gt;
&lt;br /&gt;
[[Subject Specific Note Collections]]&lt;br /&gt;
&lt;br /&gt;
=== Next Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
IIW #12 will be in May 3-5, 2011.  Dates will be announced in December 2010.&lt;br /&gt;
&lt;br /&gt;
We are working on collaborating the Kantara Initiative on a community unconference before RSA on February 14th.&lt;br /&gt;
It will be run like IIW with attendees creating the agenda live the day of the event. &lt;br /&gt;
&lt;br /&gt;
[http://idcolab.eventbrite.com REGISTRATION IS OPEN NOW &amp;amp; MORE INFORMATION]. &lt;br /&gt;
&lt;br /&gt;
[IDCollab Proposed Topics]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are considering hosting IIW Satellite events on the East Coast of the United States and in Europe in 2011.  Feel free to contact us if you are interested in helping/participating.  (iiwnotes@gmail.com)&lt;br /&gt;
&lt;br /&gt;
We have an [http://lists.idcommons.net/lists/subscribe/iiwinfo announcement list] that you can subscribe to if you would like to get an e-mail when new IIW &amp;amp; IOS events are announced.&lt;br /&gt;
&lt;br /&gt;
=== Previous Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
* #11 Fall 2010 [[iiw11]] Nov 2-4, Tuesday-Thursday at the Computer HIstory Museum in Mountain View California&lt;br /&gt;
** [[Notes IIW11]]&lt;br /&gt;
** [http://www.internetidentityworkshop.com/what-is-iiw/ Responses to IIW is...] [http://www.internetidentityworkshop.com/iiw-values/ Values of IIW]&lt;br /&gt;
&lt;br /&gt;
* [[iiw-europe-1|IIW Europe]] in London Monday October 11 (before RSA Europe) at the University of London&lt;br /&gt;
** [[iiw-europe-1-Notes]]&lt;br /&gt;
** [[iiw-europe-1-Reflection]] As a Result of Today.... &lt;br /&gt;
&lt;br /&gt;
* [[iiw-east-1|IIW East Coast]] in DC September 9-10 Thursday, Friday at the Josephine Butler Parks Center (following the Gov 2.0 Summit) the theme will be ''Open Identity for Open Government'' &lt;br /&gt;
** [[Notes_IIW-East]]&lt;br /&gt;
** [[As a result of day 1 at IIW-East]]&lt;br /&gt;
&lt;br /&gt;
* #10: Spring 2010 [[iiw10]] May 17-19 at the Computer History Museum. &lt;br /&gt;
** [[Notes IIW10]]&lt;br /&gt;
&lt;br /&gt;
* #9: Fall 2009 [[iiw9]] TUESDAY November 3 to THURSDAY November 5. &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #8: Spring 2009 [[iiw8]] - '''May 18-20, 2009''' &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #7: Fall [[iiw2008b]] (2008B)- '''Nov 10-12''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_08b]]&lt;br /&gt;
&lt;br /&gt;
* 6: Spring [[iiw2008a]]  (2008A)- '''May 12-14, 2008''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_2008a]]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.idcommons.net/index.php/Iiw2007b 5: December 3-5, 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop_2007 4: May 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006b 3: December 2006 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006 2: May 2006 - - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://www.socialtext.net/iiw2005/index.cgi?internet_identity_workshop_2005 1: October 2005 - Berkeley, CA]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Open Spaces ===&lt;br /&gt;
&lt;br /&gt;
Identity Open Space events are co-produced by the IIW team (Phil, Kaliya, Doc) in collaboration with other organizations and events. To date we have worked with Digital Identity World and the Liberty Alliance. We are open to working with a variety organizations - if you are interested please don't hesitate to contact us. &lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSF September 2007 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSBrussels May 2007 following a Liberty Alliance Meeting in Brussels, Belgium]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSantaClara September 2006 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSVan July 2006 following a Liberty Alliance Meeting in Vancouver, Canada]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Birds of a Feather Meetings ===&lt;br /&gt;
&lt;br /&gt;
June 2006 [http://www.identitygang.org/ Identity Gang Birds of a Feather Session] at Burton Group Conference, San Francisco&lt;br /&gt;
&lt;br /&gt;
January 2006 [http://www.socialtext.net/iiw2005/index.cgi?identity_speed_geeking_o_reilly_emerging_telephony_conference Identity Speed Geeking Session] at O'Reilly's  Emerging Telephony Conference&lt;br /&gt;
&lt;br /&gt;
December 2005 [http://www.socialtext.net/iiw2005/index.cgi?informational_morning_for_developers Pre-Syndicate Informational Morning for Developers]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3427</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3427"/>
		<updated>2010-12-30T02:55:30Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* Next Internet Identity Workshops */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;Big&amp;gt; Welcome to the Internet Identity Workshop (IIW) Wiki &amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.internetidentityworkshop.com WE HAVE A WEBSITE/BLOG TOO!] &lt;br /&gt;
&lt;br /&gt;
* To get updates regarding IIW  [http://lists.idcommons.net/lists/info/iiwinfo subscribe here].&lt;br /&gt;
&lt;br /&gt;
[[Subject Specific Note Collections]]&lt;br /&gt;
&lt;br /&gt;
=== Next Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
IIW #12 will be in May 3-5, 2011.  Dates will be announced in December 2010.&lt;br /&gt;
&lt;br /&gt;
We are working on collaborating the Kantara Initiative on a community unconference before RSA on February 14th.&lt;br /&gt;
It will be run like IIW with attendees creating the agenda live the day of the event. &lt;br /&gt;
&lt;br /&gt;
[http://idcolab.eventbrite.com REGISTRATION IS OPEN NOW &amp;amp; MORE INFORMATION]. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are considering hosting IIW Satellite events on the East Coast of the United States and in Europe in 2011.  Feel free to contact us if you are interested in helping/participating.  (iiwnotes@gmail.com)&lt;br /&gt;
&lt;br /&gt;
We have an [http://lists.idcommons.net/lists/subscribe/iiwinfo announcement list] that you can subscribe to if you would like to get an e-mail when new IIW &amp;amp; IOS events are announced.&lt;br /&gt;
&lt;br /&gt;
=== Previous Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
* #11 Fall 2010 [[iiw11]] Nov 2-4, Tuesday-Thursday at the Computer HIstory Museum in Mountain View California&lt;br /&gt;
** [[Notes IIW11]]&lt;br /&gt;
** [http://www.internetidentityworkshop.com/what-is-iiw/ Responses to IIW is...] [http://www.internetidentityworkshop.com/iiw-values/ Values of IIW]&lt;br /&gt;
&lt;br /&gt;
* [[iiw-europe-1|IIW Europe]] in London Monday October 11 (before RSA Europe) at the University of London&lt;br /&gt;
** [[iiw-europe-1-Notes]]&lt;br /&gt;
** [[iiw-europe-1-Reflection]] As a Result of Today.... &lt;br /&gt;
&lt;br /&gt;
* [[iiw-east-1|IIW East Coast]] in DC September 9-10 Thursday, Friday at the Josephine Butler Parks Center (following the Gov 2.0 Summit) the theme will be ''Open Identity for Open Government'' &lt;br /&gt;
** [[Notes_IIW-East]]&lt;br /&gt;
** [[As a result of day 1 at IIW-East]]&lt;br /&gt;
&lt;br /&gt;
* #10: Spring 2010 [[iiw10]] May 17-19 at the Computer History Museum. &lt;br /&gt;
** [[Notes IIW10]]&lt;br /&gt;
&lt;br /&gt;
* #9: Fall 2009 [[iiw9]] TUESDAY November 3 to THURSDAY November 5. &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #8: Spring 2009 [[iiw8]] - '''May 18-20, 2009''' &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #7: Fall [[iiw2008b]] (2008B)- '''Nov 10-12''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_08b]]&lt;br /&gt;
&lt;br /&gt;
* 6: Spring [[iiw2008a]]  (2008A)- '''May 12-14, 2008''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_2008a]]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.idcommons.net/index.php/Iiw2007b 5: December 3-5, 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop_2007 4: May 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006b 3: December 2006 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006 2: May 2006 - - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://www.socialtext.net/iiw2005/index.cgi?internet_identity_workshop_2005 1: October 2005 - Berkeley, CA]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Open Spaces ===&lt;br /&gt;
&lt;br /&gt;
Identity Open Space events are co-produced by the IIW team (Phil, Kaliya, Doc) in collaboration with other organizations and events. To date we have worked with Digital Identity World and the Liberty Alliance. We are open to working with a variety organizations - if you are interested please don't hesitate to contact us. &lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSF September 2007 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSBrussels May 2007 following a Liberty Alliance Meeting in Brussels, Belgium]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSantaClara September 2006 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSVan July 2006 following a Liberty Alliance Meeting in Vancouver, Canada]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Birds of a Feather Meetings ===&lt;br /&gt;
&lt;br /&gt;
June 2006 [http://www.identitygang.org/ Identity Gang Birds of a Feather Session] at Burton Group Conference, San Francisco&lt;br /&gt;
&lt;br /&gt;
January 2006 [http://www.socialtext.net/iiw2005/index.cgi?identity_speed_geeking_o_reilly_emerging_telephony_conference Identity Speed Geeking Session] at O'Reilly's  Emerging Telephony Conference&lt;br /&gt;
&lt;br /&gt;
December 2005 [http://www.socialtext.net/iiw2005/index.cgi?informational_morning_for_developers Pre-Syndicate Informational Morning for Developers]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3426</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=3426"/>
		<updated>2010-12-30T02:53:34Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* Next Internet Identity Workshops */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;Big&amp;gt; Welcome to the Internet Identity Workshop (IIW) Wiki &amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.internetidentityworkshop.com WE HAVE A WEBSITE/BLOG TOO!] &lt;br /&gt;
&lt;br /&gt;
* To get updates regarding IIW  [http://lists.idcommons.net/lists/info/iiwinfo subscribe here].&lt;br /&gt;
&lt;br /&gt;
[[Subject Specific Note Collections]]&lt;br /&gt;
&lt;br /&gt;
=== Next Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
IIW #12 will be in May 3-5, 2011.  Dates will be announced in December 2010.&lt;br /&gt;
&lt;br /&gt;
We are working on collaborating the Kantara Initiative on a community unconference before RSA on February 14th.&lt;br /&gt;
It will be run like IIW with attendees creating the agenda live the day of the event. &lt;br /&gt;
&lt;br /&gt;
[http://idcolab.eventbrite.com REGISTRATION IS OPEN NOW &amp;amp; MORE INFORMATION]. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are considering hosting &amp;quot;Identity Open Space&amp;quot; events on the East Coast of the United States and in Europe in 2011.  Feel free to contact us if you are interested in helping/participating.  (kaliya (at) Mac.com) &lt;br /&gt;
&lt;br /&gt;
We have an [http://lists.idcommons.net/lists/subscribe/iiwinfo announcement list] that you can subscribe to if you would like to get an e-mail when new IIW &amp;amp; IOS events are announced.&lt;br /&gt;
&lt;br /&gt;
=== Previous Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
* #11 Fall 2010 [[iiw11]] Nov 2-4, Tuesday-Thursday at the Computer HIstory Museum in Mountain View California&lt;br /&gt;
** [[Notes IIW11]]&lt;br /&gt;
** [http://www.internetidentityworkshop.com/what-is-iiw/ Responses to IIW is...] [http://www.internetidentityworkshop.com/iiw-values/ Values of IIW]&lt;br /&gt;
&lt;br /&gt;
* [[iiw-europe-1|IIW Europe]] in London Monday October 11 (before RSA Europe) at the University of London&lt;br /&gt;
** [[iiw-europe-1-Notes]]&lt;br /&gt;
** [[iiw-europe-1-Reflection]] As a Result of Today.... &lt;br /&gt;
&lt;br /&gt;
* [[iiw-east-1|IIW East Coast]] in DC September 9-10 Thursday, Friday at the Josephine Butler Parks Center (following the Gov 2.0 Summit) the theme will be ''Open Identity for Open Government'' &lt;br /&gt;
** [[Notes_IIW-East]]&lt;br /&gt;
** [[As a result of day 1 at IIW-East]]&lt;br /&gt;
&lt;br /&gt;
* #10: Spring 2010 [[iiw10]] May 17-19 at the Computer History Museum. &lt;br /&gt;
** [[Notes IIW10]]&lt;br /&gt;
&lt;br /&gt;
* #9: Fall 2009 [[iiw9]] TUESDAY November 3 to THURSDAY November 5. &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #8: Spring 2009 [[iiw8]] - '''May 18-20, 2009''' &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #7: Fall [[iiw2008b]] (2008B)- '''Nov 10-12''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_08b]]&lt;br /&gt;
&lt;br /&gt;
* 6: Spring [[iiw2008a]]  (2008A)- '''May 12-14, 2008''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_2008a]]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.idcommons.net/index.php/Iiw2007b 5: December 3-5, 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop_2007 4: May 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006b 3: December 2006 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006 2: May 2006 - - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://www.socialtext.net/iiw2005/index.cgi?internet_identity_workshop_2005 1: October 2005 - Berkeley, CA]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Open Spaces ===&lt;br /&gt;
&lt;br /&gt;
Identity Open Space events are co-produced by the IIW team (Phil, Kaliya, Doc) in collaboration with other organizations and events. To date we have worked with Digital Identity World and the Liberty Alliance. We are open to working with a variety organizations - if you are interested please don't hesitate to contact us. &lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSF September 2007 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSBrussels May 2007 following a Liberty Alliance Meeting in Brussels, Belgium]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSantaClara September 2006 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSVan July 2006 following a Liberty Alliance Meeting in Vancouver, Canada]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Birds of a Feather Meetings ===&lt;br /&gt;
&lt;br /&gt;
June 2006 [http://www.identitygang.org/ Identity Gang Birds of a Feather Session] at Burton Group Conference, San Francisco&lt;br /&gt;
&lt;br /&gt;
January 2006 [http://www.socialtext.net/iiw2005/index.cgi?identity_speed_geeking_o_reilly_emerging_telephony_conference Identity Speed Geeking Session] at O'Reilly's  Emerging Telephony Conference&lt;br /&gt;
&lt;br /&gt;
December 2005 [http://www.socialtext.net/iiw2005/index.cgi?informational_morning_for_developers Pre-Syndicate Informational Morning for Developers]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=ID_Commons_-IIW_Intro&amp;diff=3408</id>
		<title>ID Commons -IIW Intro</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=ID_Commons_-IIW_Intro&amp;diff=3408"/>
		<updated>2010-12-06T23:11:03Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
Convener: Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
See Slides on SlideShare:http://www.slideshare.net/Kaliya/iiw11introtalk&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Notes_IIW11&amp;diff=3407</id>
		<title>Notes IIW11</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Notes_IIW11&amp;diff=3407"/>
		<updated>2010-12-06T23:06:14Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://iiw.idcommons.net/File:IIW-11-BOP.pdf Here is the complete Book of Proceedings in PDF Form]&lt;br /&gt;
&lt;br /&gt;
= Tuesday =&lt;br /&gt;
&lt;br /&gt;
== Session 1 ==&lt;br /&gt;
&lt;br /&gt;
A: [[Intro to PDS]] (Personal Data Store)&lt;br /&gt;
&lt;br /&gt;
B: [[Trust Frameworks Analogue to Digital Converters]]&lt;br /&gt;
&lt;br /&gt;
D: [[Decline of User-Centric Identity]] an analysis&lt;br /&gt;
&lt;br /&gt;
E: [[OAuth Listening Tour]]&lt;br /&gt;
&lt;br /&gt;
F: [[Activity Streams 101]]&lt;br /&gt;
&lt;br /&gt;
G: [[Verified Identity Claims 1]]&lt;br /&gt;
&lt;br /&gt;
I: [[UMA 101]] User Managed Access&lt;br /&gt;
&lt;br /&gt;
== Session 2 ==&lt;br /&gt;
&lt;br /&gt;
A:  OpenID OAuth - [[Social Networking for online retailers]]&lt;br /&gt;
&lt;br /&gt;
B:  [[ID Commons -IIW Intro]]&lt;br /&gt;
&lt;br /&gt;
C:  [[Open-Federated Social Networking]]&lt;br /&gt;
&lt;br /&gt;
E:  [[Deep Dive OpenID - AB]]&lt;br /&gt;
&lt;br /&gt;
F:  [[VRM Development]]&lt;br /&gt;
&lt;br /&gt;
I:  [[No Base String]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 ==&lt;br /&gt;
&lt;br /&gt;
A:  [[Attenuated Redelegation]]&lt;br /&gt;
&lt;br /&gt;
B:  [[Web inSecurity]]&lt;br /&gt;
&lt;br /&gt;
C:  [[Verified Identity Claims]] &amp;quot;U Prove Intro&amp;quot;&lt;br /&gt;
&lt;br /&gt;
D:  [[Facebook as a Personal Data Store]]&lt;br /&gt;
&lt;br /&gt;
E:  [[JSON Tokens]]&lt;br /&gt;
&lt;br /&gt;
F:  [[Mobile Social Networking]]&lt;br /&gt;
&lt;br /&gt;
I:  [[OpenID Connect Discovery]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 ==&lt;br /&gt;
&lt;br /&gt;
C:  [[Pseudonyms for Privacy]]&lt;br /&gt;
&lt;br /&gt;
F:  [[Rap Leaf]]  Is it a joke?&lt;br /&gt;
&lt;br /&gt;
G:  [[Verified Identity Claims 3]]&lt;br /&gt;
&lt;br /&gt;
I:  [[Handling Unregistered Clients]] in OAuth and OpenID connect&lt;br /&gt;
&lt;br /&gt;
== Session 5 ==&lt;br /&gt;
&lt;br /&gt;
A:  [[Change Notify Proposal]]&lt;br /&gt;
&lt;br /&gt;
B:  [[OAuth Multiple Token]]&lt;br /&gt;
&lt;br /&gt;
C:  [[NSTIC]]&lt;br /&gt;
&lt;br /&gt;
E:  [[OpenID Connect]]&lt;br /&gt;
&lt;br /&gt;
F:  [[Personal Data Ecosystem]]&lt;br /&gt;
&lt;br /&gt;
G:  [[Health and VRM]]&lt;br /&gt;
&lt;br /&gt;
I:  [[Making Security Decisions Disappear]]&lt;br /&gt;
&lt;br /&gt;
= Wednesday =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Session 1 ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A: [[Value Network Mapping]]  Analysis for personal data ecosystem&lt;br /&gt;
&lt;br /&gt;
D: [[Future Phone Device Authorization]]&lt;br /&gt;
&lt;br /&gt;
E: [[Enterprise OAuth BOF Level Set]]&lt;br /&gt;
&lt;br /&gt;
I: [[OpenID Connect Sessn Mgmt]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 ==&lt;br /&gt;
A: [[PDE- Why would anyone adopt?]]&lt;br /&gt;
&lt;br /&gt;
B: [[Fix Session Mgmt Jacking]]&lt;br /&gt;
&lt;br /&gt;
D: [[UMA 201 Q and A]]&lt;br /&gt;
&lt;br /&gt;
E: [[Enterprise OAuth BOF]]&lt;br /&gt;
&lt;br /&gt;
F: [[OAuth2 Exts.]]&lt;br /&gt;
&lt;br /&gt;
G:  [[Poor Man Verified ID]]&lt;br /&gt;
&lt;br /&gt;
H: [[Int'l Presence of OpenID]]&lt;br /&gt;
&lt;br /&gt;
I: [[OAuth for Installed Apps]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 ==&lt;br /&gt;
&lt;br /&gt;
A: [[VERIFIED IDENTITY CLAIMS – Selectors (W3A)]]&lt;br /&gt;
&lt;br /&gt;
E: [[OAuth2 for Devices]]&lt;br /&gt;
&lt;br /&gt;
G: [[Building a CAKE Detector]]&lt;br /&gt;
&lt;br /&gt;
H: [[Shifting Global Economy w-Identity]]&lt;br /&gt;
&lt;br /&gt;
I:  [[OpenID ABC Artifact Binding]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 ==&lt;br /&gt;
&lt;br /&gt;
A:  [[Personal Data Ecosystem Biz Models]]&lt;br /&gt;
&lt;br /&gt;
C:  [[Using a Personal Data Store]]&lt;br /&gt;
&lt;br /&gt;
E:  [[JSON Token Spec - Encryption]]&lt;br /&gt;
&lt;br /&gt;
H:  [[Verified Identity Claims - UX]]&lt;br /&gt;
&lt;br /&gt;
== Session 5 ==&lt;br /&gt;
&lt;br /&gt;
A:  [[Deadly Sins Distributed Authentication]]&lt;br /&gt;
&lt;br /&gt;
B:  [[Personal Data Ecosystem Model 2]]&lt;br /&gt;
&lt;br /&gt;
C:  [[Cloud Directory Standards]]&lt;br /&gt;
&lt;br /&gt;
D:  [[Infrastructure Focus - Relationships Among Things]] &lt;br /&gt;
&lt;br /&gt;
E:  [[JSON Token Spec - Claim Names]]&lt;br /&gt;
&lt;br /&gt;
F:  [[OAuth LEELOO]]&lt;br /&gt;
&lt;br /&gt;
G:  [[What do USERS want?]]&lt;br /&gt;
&lt;br /&gt;
I:  [[OpenID Attrib - Beyond AX-SREG]]&lt;br /&gt;
&lt;br /&gt;
= Thursday =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Session 1 ==&lt;br /&gt;
&lt;br /&gt;
A:  [[Go To Market - PDE]]  Adoption drives for Personal Data Ecosystem&lt;br /&gt;
&lt;br /&gt;
C:  [[Google Sample OpenID]]  RD and RP Best Practices&lt;br /&gt;
&lt;br /&gt;
E:  [[JSON Spec Work continued]]&lt;br /&gt;
&lt;br /&gt;
F:  [[User Managed Permission Interface]]&lt;br /&gt;
&lt;br /&gt;
== Session 2 ==&lt;br /&gt;
&lt;br /&gt;
E:  [[Terms of Use Privacy Policy]]&lt;br /&gt;
&lt;br /&gt;
G:  [[Look Up by Phone Number]]&lt;br /&gt;
&lt;br /&gt;
I:  [[Kitties are Fluffy]]&lt;br /&gt;
&lt;br /&gt;
M:  [[Go To Market PDE 2]]&lt;br /&gt;
&lt;br /&gt;
== Session 3 ==&lt;br /&gt;
&lt;br /&gt;
A:  [[PDE - Go to Market and Community Strategy]]&lt;br /&gt;
&lt;br /&gt;
E:  [[R Button Affordamies]]&lt;br /&gt;
&lt;br /&gt;
F:  [[Adopting OAuth 2 OpenID Connect]]&lt;br /&gt;
&lt;br /&gt;
G:  [[Email is not Dead Yet]]&lt;br /&gt;
&lt;br /&gt;
L:  [[Policy Framework]]&lt;br /&gt;
&lt;br /&gt;
== Session 4 ==&lt;br /&gt;
&lt;br /&gt;
E: [[Best Ways to Connect People to Content]]&lt;br /&gt;
&lt;br /&gt;
F: [[Personal Data Ecosystem Org Role]]&lt;br /&gt;
&lt;br /&gt;
G: [[The Transactional Graph]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Session 5 ==&lt;br /&gt;
&lt;br /&gt;
C: [[Google Usability]]&lt;br /&gt;
&lt;br /&gt;
F: [[Personal Data Ecosystem Org Role]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:IIW-11-BOP.pdf&amp;diff=3406</id>
		<title>File:IIW-11-BOP.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:IIW-11-BOP.pdf&amp;diff=3406"/>
		<updated>2010-12-06T23:05:54Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Trust_Frameworks_Analogue_to_Digital_Converters&amp;diff=3403</id>
		<title>Trust Frameworks Analogue to Digital Converters</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Trust_Frameworks_Analogue_to_Digital_Converters&amp;diff=3403"/>
		<updated>2010-12-06T17:08:54Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ezemitekywe.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
'''Issue/Topic:''' Trust Frameworks as Analog o Digital Converters&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Tuesday 1B &lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Scott David&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Jamie Clark&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' &lt;br /&gt;
&lt;br /&gt;
trust_framework, taxonomy, contracts, risk_allocation, UI&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:'''&lt;br /&gt;
&lt;br /&gt;
[[File:Nov_2_Rethinking_Personal_Data_Workshop.pdf ]]&lt;br /&gt;
&lt;br /&gt;
Facilitating Personal Data Transactions in a Secured Manner on a&lt;br /&gt;
Global Scale&amp;amp;quot;:  part of presentation for WEF (Davos) prep session on&lt;br /&gt;
&amp;amp;quot;Rethinking Personal data&amp;amp;quot; workshop, New York, September 2010;  should&lt;br /&gt;
be posted shortly to OIX website&lt;br /&gt;
&lt;br /&gt;
What's the international law of identity?&lt;br /&gt;
&lt;br /&gt;
There isn't any.&lt;br /&gt;
&lt;br /&gt;
Can we do things with law and/or rules and/or tech to weave together the&lt;br /&gt;
disparate systems that interact?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What should identity systems do?  Meet &amp;amp;quot;system participant&amp;amp;quot; (user) needs.  Such&lt;br /&gt;
as:&lt;br /&gt;
* data subjects need identity integrity&lt;br /&gt;
* replying parties need assurance&lt;br /&gt;
* identity providers need risk reduction&lt;br /&gt;
These high-level 'needs' share some basic lower-level functional requirements&lt;br /&gt;
like, security, reliability, UI, etc.&lt;br /&gt;
&lt;br /&gt;
What can tech and law do about this?&lt;br /&gt;
* technology tools guide data movement &amp;amp;amp; protect data at rest&lt;br /&gt;
* legal rules create duties to incent behavior&lt;br /&gt;
&lt;br /&gt;
-- By far most of the data breaches I've seen (S. David) were human error, not&lt;br /&gt;
tech failure. So the human rules and incentives matter.&lt;br /&gt;
&lt;br /&gt;
A &amp;amp;quot;Trust Framework&amp;amp;quot; is a possible documentation style (&amp;amp;quot;term sheet&amp;amp;quot;?) for the&lt;br /&gt;
agreed risk and reliance arrangements between system participants.&lt;br /&gt;
&lt;br /&gt;
There is some &amp;amp;quot;low hanging fruit&amp;amp;quot; of law and practice guiding these duties:&lt;br /&gt;
* In the US: NSTIC, Levels of Assurance.  In some states, data breach laws.&lt;br /&gt;
* Privacy laws like HIPAA, Gramm-Leach, FICA, etc.&lt;br /&gt;
* Fair Info Practice Principles (originally US DHEW 1973) - levels of&lt;br /&gt;
control&lt;br /&gt;
&lt;br /&gt;
ABA drafting a report on Federated Identity which addresses a taxonomy of&lt;br /&gt;
issues and actors;  OIX doing a &amp;amp;quot;risks wiki&amp;amp;quot;;  some out for public review now;&lt;br /&gt;
posted work product expected early 2011(?)&lt;br /&gt;
&lt;br /&gt;
One difficulty is operationalizing assurance which is mostly processed by&lt;br /&gt;
end-users as emotional states like &amp;amp;quot;trust&amp;amp;quot;, &amp;amp;quot;reliability.&amp;amp;quot; Quantification&lt;br /&gt;
needed, to clear the semantic fog here.&lt;br /&gt;
&lt;br /&gt;
The idea here is to address some recurring liability issues, but not all.&lt;br /&gt;
80/20 approach, not boiling the ocean.  May be industry groups and self-&lt;br /&gt;
regulatory efforts that give rise to the best evolving solutions.&lt;br /&gt;
&lt;br /&gt;
First step is a candidate common analytical framework, to get to &amp;amp;quot;apples-to-&lt;br /&gt;
apples&amp;amp;quot; on some of the risks, practices and concepts&lt;br /&gt;
&lt;br /&gt;
Inspirational vision:  UI simplification - risks and control issues displayed&lt;br /&gt;
simply like red-light-yellow-light-green-light displays.&lt;br /&gt;
&lt;br /&gt;
Audience:  Frameworks generally get developed in a context of siloes -&lt;br /&gt;
non-interoperable specialized cases.  Is there a &amp;amp;quot;metalanguage&amp;amp;quot; for crosswalks&lt;br /&gt;
among the privacy practices of those siloed players?  Or 15% of them, anyway,&lt;br /&gt;
for scalability's sake.&lt;br /&gt;
&lt;br /&gt;
''there is a PPT deck associated with this session: &amp;amp;quot;nov 2 Rethinking Personal Data Workshop.ppt&amp;amp;quot;''&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Social_Networking_for_online_retailers&amp;diff=3402</id>
		<title>Social Networking for online retailers</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Social_Networking_for_online_retailers&amp;diff=3402"/>
		<updated>2010-12-06T17:08:15Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session:''' Tuesday 2A&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Brian Kissel&lt;br /&gt;
&lt;br /&gt;
[[File:OpenID_Foundation_Retail_Advisory_Committee_Overview.pdf]]&lt;br /&gt;
&lt;br /&gt;
OpenID Foundation: Retail Advisory Committee&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Thoughts to Consider…'''&lt;br /&gt;
* Increasingly, consumers want to research and execute purchases on the web, and the trend is accelerating with younger generations&lt;br /&gt;
** In order to gain mindshare and market share, you need to know more about customers&lt;br /&gt;
** With more consumers and retailers interacting via the web, “identity fatigue” is becoming an issue:  “if its too much effort I’ll just buy it from Amazon”&lt;br /&gt;
** How do you get more visitors to register on your website, remain engaged, and login early during each return visit?  How do you ensure that user profile data is complete and up-to-date?&lt;br /&gt;
* Social Commerce is a reality.  What friends recommend is becoming more important than banner ads, search results, or even customer ratings and independent reviews (c|net, Consumer Reports)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Social Marketing'''&lt;br /&gt;
* The trust factor of friends’ suggestions can make a big difference. Loopt’s users are 20X more likely to click on a place their friends had liked or visited than a place that simply ranked higher in search results.&lt;br /&gt;
* “Improving search has always been about improving relevance,” Augie Ray of Forrester said. “But the thinking now is that getting information from your immediate social network is what will really make results more relevant.”&lt;br /&gt;
* “People are likely to find what your friends are saying about the iPhone 4 or a Chinese restaurant more helpful in a Web search,” said Matt Cutts, a software engineer who oversees search quality at Google.&lt;br /&gt;
*   http://www.nytimes.com/2010/09/13/technology/13search.html &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Benefits of 3rd Party ID and Social Networks for Retailers'''&lt;br /&gt;
* '''Higher Registrations:''' Increase conversion of visitor to registered user by 25% to 50%*&lt;br /&gt;
* '''Better Login:''' Reduce forgotten password costs and frustration by up to 50%*&lt;br /&gt;
* '''Increased Referral Traffic, SEO, and Brand Projection:'''  &lt;br /&gt;
** Allow users to share activities (purchases, product reviews, blogs, surveys, video views) with friends on social networks (Facebook, Twitter, Yahoo, Google, MySpace, LinkedIn, Microsoft, etc.) with links back to your websites&lt;br /&gt;
** Customers as advocates, project your brand beyond your website, links back improve SEO&lt;br /&gt;
** Websites seeing anywhere from 5 to 25* referral visits for each social publishing link&lt;br /&gt;
** Referral visitors are highly qualified and come with active identity accounts for easy registration &amp;amp; login&lt;br /&gt;
* '''Collecting Rich Customer Data:''' Build richer customer profiles by using customers’ existing online accounts - name, verified email address, shipping address**, phone**, payment info**, nickname, language, zip code, age, friends lists, address books, personal interests &amp;amp; hobbies, photos, etc.&lt;br /&gt;
* '''Improved Mobile Experience:''' Provide a much quicker and simpler user experience via mobile applications&lt;br /&gt;
* '''Website Federation:''' Single sign-on (SSO) for your customers across multiple web properties and component solutions (commenting, rating and reviews, customer feedback, community, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' OpenID Foundation'''&lt;br /&gt;
* Founded in 2007&lt;br /&gt;
* Non-profit, open-standard technology organization like Linux Foundation&lt;br /&gt;
* Promoting open standards for user-managed identity&lt;br /&gt;
* Board members include folks from Google, Yahoo, Facebook, PayPal, Microsoft, IBM, Sears, NY Times, and NPR&lt;br /&gt;
* OpenID Foundation members include: Google, PayPal, Facebook, Yahoo!, CA, Microsoft, IBM, LexisNexis, VeriSign, BBC, Booz | Allen | Hamilton, GameShop, PingIdentity, JanRain&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Identity Providers and Technologies'''&lt;br /&gt;
[picture]&lt;br /&gt;
&lt;br /&gt;
'''Integrated into Leading Technology Platforms You may already be using one of these on your websites…'''&lt;br /&gt;
''Social Network &amp;amp; Community Platforms''&lt;br /&gt;
KickApps, Viewpoints, Talki, Wetpaint&lt;br /&gt;
&lt;br /&gt;
''Customer Feedback Tools''&lt;br /&gt;
Get Satisfaction, IdealScale, Uservoice&lt;br /&gt;
&lt;br /&gt;
''CMS Turnkey Plug-ins''&lt;br /&gt;
WordPress, Drupal&lt;br /&gt;
&lt;br /&gt;
''Content Communication Platforms''&lt;br /&gt;
Disqus, Echo, Pluck&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sears Sign-in and Social Publishing Demo Visitor arrives at Sears website and clicks sign in…'''&lt;br /&gt;
&lt;br /&gt;
'''Offered choice of 3rd party ID providers…'''&lt;br /&gt;
&lt;br /&gt;
'''Customer selects Google and grants permission…'''&lt;br /&gt;
&lt;br /&gt;
'''Logged in, personalized experience…'''&lt;br /&gt;
&lt;br /&gt;
'''Offered opportunity to write a product review…'''&lt;br /&gt;
&lt;br /&gt;
'''Customer writes personal product review…'''&lt;br /&gt;
&lt;br /&gt;
'''Review received by Sears, offered chance to share… Can be configured for multiple social networks…'''&lt;br /&gt;
&lt;br /&gt;
'''Customizable Sign-in Interfaces: HP Favicons for initial engagement, contextual messages for each ID provider'''&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Trust_Frameworks_Analogue_to_Digital_Converters&amp;diff=3401</id>
		<title>Trust Frameworks Analogue to Digital Converters</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Trust_Frameworks_Analogue_to_Digital_Converters&amp;diff=3401"/>
		<updated>2010-12-06T17:06:29Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ezemitekywe.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
'''Issue/Topic:''' Trust Frameworks as Analog o Digital Converters&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Tuesday 1B &lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Scott David&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Jamie Clark&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' &lt;br /&gt;
&lt;br /&gt;
trust_framework, taxonomy, contracts, risk_allocation, UI&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:'''&lt;br /&gt;
&lt;br /&gt;
[[File:OpenID_Foundation_Retail_Advisory_Committee_Overview.pdf]]&lt;br /&gt;
&lt;br /&gt;
Facilitating Personal Data Transactions in a Secured Manner on a&lt;br /&gt;
Global Scale&amp;amp;quot;:  part of presentation for WEF (Davos) prep session on&lt;br /&gt;
&amp;amp;quot;Rethinking Personal data&amp;amp;quot; workshop, New York, September 2010;  should&lt;br /&gt;
be posted shortly to OIX website&lt;br /&gt;
&lt;br /&gt;
What's the international law of identity?&lt;br /&gt;
&lt;br /&gt;
There isn't any.&lt;br /&gt;
&lt;br /&gt;
Can we do things with law and/or rules and/or tech to weave together the&lt;br /&gt;
disparate systems that interact?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What should identity systems do?  Meet &amp;amp;quot;system participant&amp;amp;quot; (user) needs.  Such&lt;br /&gt;
as:&lt;br /&gt;
* data subjects need identity integrity&lt;br /&gt;
* replying parties need assurance&lt;br /&gt;
* identity providers need risk reduction&lt;br /&gt;
These high-level 'needs' share some basic lower-level functional requirements&lt;br /&gt;
like, security, reliability, UI, etc.&lt;br /&gt;
&lt;br /&gt;
What can tech and law do about this?&lt;br /&gt;
* technology tools guide data movement &amp;amp;amp; protect data at rest&lt;br /&gt;
* legal rules create duties to incent behavior&lt;br /&gt;
&lt;br /&gt;
-- By far most of the data breaches I've seen (S. David) were human error, not&lt;br /&gt;
tech failure. So the human rules and incentives matter.&lt;br /&gt;
&lt;br /&gt;
A &amp;amp;quot;Trust Framework&amp;amp;quot; is a possible documentation style (&amp;amp;quot;term sheet&amp;amp;quot;?) for the&lt;br /&gt;
agreed risk and reliance arrangements between system participants.&lt;br /&gt;
&lt;br /&gt;
There is some &amp;amp;quot;low hanging fruit&amp;amp;quot; of law and practice guiding these duties:&lt;br /&gt;
* In the US: NSTIC, Levels of Assurance.  In some states, data breach laws.&lt;br /&gt;
* Privacy laws like HIPAA, Gramm-Leach, FICA, etc.&lt;br /&gt;
* Fair Info Practice Principles (originally US DHEW 1973) - levels of&lt;br /&gt;
control&lt;br /&gt;
&lt;br /&gt;
ABA drafting a report on Federated Identity which addresses a taxonomy of&lt;br /&gt;
issues and actors;  OIX doing a &amp;amp;quot;risks wiki&amp;amp;quot;;  some out for public review now;&lt;br /&gt;
posted work product expected early 2011(?)&lt;br /&gt;
&lt;br /&gt;
One difficulty is operationalizing assurance which is mostly processed by&lt;br /&gt;
end-users as emotional states like &amp;amp;quot;trust&amp;amp;quot;, &amp;amp;quot;reliability.&amp;amp;quot; Quantification&lt;br /&gt;
needed, to clear the semantic fog here.&lt;br /&gt;
&lt;br /&gt;
The idea here is to address some recurring liability issues, but not all.&lt;br /&gt;
80/20 approach, not boiling the ocean.  May be industry groups and self-&lt;br /&gt;
regulatory efforts that give rise to the best evolving solutions.&lt;br /&gt;
&lt;br /&gt;
First step is a candidate common analytical framework, to get to &amp;amp;quot;apples-to-&lt;br /&gt;
apples&amp;amp;quot; on some of the risks, practices and concepts&lt;br /&gt;
&lt;br /&gt;
Inspirational vision:  UI simplification - risks and control issues displayed&lt;br /&gt;
simply like red-light-yellow-light-green-light displays.&lt;br /&gt;
&lt;br /&gt;
Audience:  Frameworks generally get developed in a context of siloes -&lt;br /&gt;
non-interoperable specialized cases.  Is there a &amp;amp;quot;metalanguage&amp;amp;quot; for crosswalks&lt;br /&gt;
among the privacy practices of those siloed players?  Or 15% of them, anyway,&lt;br /&gt;
for scalability's sake.&lt;br /&gt;
&lt;br /&gt;
''there is a PPT deck associated with this session: &amp;amp;quot;nov 2 Rethinking Personal Data Workshop.ppt&amp;amp;quot;''&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Trust_Frameworks_Analogue_to_Digital_Converters&amp;diff=3400</id>
		<title>Trust Frameworks Analogue to Digital Converters</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Trust_Frameworks_Analogue_to_Digital_Converters&amp;diff=3400"/>
		<updated>2010-12-06T17:06:02Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ezemitekywe.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
'''Issue/Topic:''' Trust Frameworks as Analog o Digital Converters&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Tuesday 1B &lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Scott David&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Jamie Clark&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' &lt;br /&gt;
&lt;br /&gt;
trust_framework, taxonomy, contracts, risk_allocation, UI&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:'''&lt;br /&gt;
&lt;br /&gt;
[[File:OpenID_Foundation_Retail_Advisory_Committee_Overview.pdf]]&lt;br /&gt;
&lt;br /&gt;
[slides]:  &amp;amp;quot;Facilitating Personal Data Transactions in a Secured Manner on a&lt;br /&gt;
Global Scale&amp;amp;quot;:  part of presentation for WEF (Davos) prep session on&lt;br /&gt;
&amp;amp;quot;Rethinking Personal data&amp;amp;quot; workshop, New York, September 2010;  should&lt;br /&gt;
be posted shortly to OIX website&lt;br /&gt;
&lt;br /&gt;
What's the international law of identity?&lt;br /&gt;
&lt;br /&gt;
There isn't any.&lt;br /&gt;
&lt;br /&gt;
Can we do things with law and/or rules and/or tech to weave together the&lt;br /&gt;
disparate systems that interact?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What should identity systems do?  Meet &amp;amp;quot;system participant&amp;amp;quot; (user) needs.  Such&lt;br /&gt;
as:&lt;br /&gt;
* data subjects need identity integrity&lt;br /&gt;
* replying parties need assurance&lt;br /&gt;
* identity providers need risk reduction&lt;br /&gt;
These high-level 'needs' share some basic lower-level functional requirements&lt;br /&gt;
like, security, reliability, UI, etc.&lt;br /&gt;
&lt;br /&gt;
What can tech and law do about this?&lt;br /&gt;
* technology tools guide data movement &amp;amp;amp; protect data at rest&lt;br /&gt;
* legal rules create duties to incent behavior&lt;br /&gt;
&lt;br /&gt;
-- By far most of the data breaches I've seen (S. David) were human error, not&lt;br /&gt;
tech failure. So the human rules and incentives matter.&lt;br /&gt;
&lt;br /&gt;
A &amp;amp;quot;Trust Framework&amp;amp;quot; is a possible documentation style (&amp;amp;quot;term sheet&amp;amp;quot;?) for the&lt;br /&gt;
agreed risk and reliance arrangements between system participants.&lt;br /&gt;
&lt;br /&gt;
There is some &amp;amp;quot;low hanging fruit&amp;amp;quot; of law and practice guiding these duties:&lt;br /&gt;
* In the US: NSTIC, Levels of Assurance.  In some states, data breach laws.&lt;br /&gt;
* Privacy laws like HIPAA, Gramm-Leach, FICA, etc.&lt;br /&gt;
* Fair Info Practice Principles (originally US DHEW 1973) - levels of&lt;br /&gt;
control&lt;br /&gt;
&lt;br /&gt;
ABA drafting a report on Federated Identity which addresses a taxonomy of&lt;br /&gt;
issues and actors;  OIX doing a &amp;amp;quot;risks wiki&amp;amp;quot;;  some out for public review now;&lt;br /&gt;
posted work product expected early 2011(?)&lt;br /&gt;
&lt;br /&gt;
One difficulty is operationalizing assurance which is mostly processed by&lt;br /&gt;
end-users as emotional states like &amp;amp;quot;trust&amp;amp;quot;, &amp;amp;quot;reliability.&amp;amp;quot; Quantification&lt;br /&gt;
needed, to clear the semantic fog here.&lt;br /&gt;
&lt;br /&gt;
The idea here is to address some recurring liability issues, but not all.&lt;br /&gt;
80/20 approach, not boiling the ocean.  May be industry groups and self-&lt;br /&gt;
regulatory efforts that give rise to the best evolving solutions.&lt;br /&gt;
&lt;br /&gt;
First step is a candidate common analytical framework, to get to &amp;amp;quot;apples-to-&lt;br /&gt;
apples&amp;amp;quot; on some of the risks, practices and concepts&lt;br /&gt;
&lt;br /&gt;
Inspirational vision:  UI simplification - risks and control issues displayed&lt;br /&gt;
simply like red-light-yellow-light-green-light displays.&lt;br /&gt;
&lt;br /&gt;
Audience:  Frameworks generally get developed in a context of siloes -&lt;br /&gt;
non-interoperable specialized cases.  Is there a &amp;amp;quot;metalanguage&amp;amp;quot; for crosswalks&lt;br /&gt;
among the privacy practices of those siloed players?  Or 15% of them, anyway,&lt;br /&gt;
for scalability's sake.&lt;br /&gt;
&lt;br /&gt;
''there is a PPT deck associated with this session: &amp;amp;quot;nov 2 Rethinking Personal Data Workshop.ppt&amp;amp;quot;''&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=3399</id>
		<title>OAuth2 for Devices</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=3399"/>
		<updated>2010-12-06T17:03:12Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAuth 2 for Devices&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Wednesday, Session 3, Space E&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Marius S.&lt;br /&gt;
&lt;br /&gt;
'''Note Taker:'''Andrew Wansley&lt;br /&gt;
&lt;br /&gt;
'''Discussion Notes:'''&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf]]&lt;br /&gt;
&lt;br /&gt;
What is a device&lt;br /&gt;
&lt;br /&gt;
A device as we're concerned with it here has a display and a limited or painful input. We're explicitly not talking about headless devices, devices with no display and or no input like a refrigerator. These devices as far as we know just run a webserver locally and do the webserver profile.&lt;br /&gt;
&lt;br /&gt;
What's the flow&lt;br /&gt;
&lt;br /&gt;
From the user's perspective, the device displays a URL and code. User goes to URL and enters the code. The device magically works.&lt;br /&gt;
&lt;br /&gt;
From the device's perspective, the device presents AuthZ server with a clientID and gets back a URL a user code which it displays to the user and a device code used for polling. The device then starts polling the AuthZ server which tells it &amp;quot;not yet&amp;quot; for a while then eventually returns yes and a token or no.&lt;br /&gt;
&lt;br /&gt;
AuthZ server has preregistered a device and replies to the device's requests as described above.&lt;br /&gt;
&lt;br /&gt;
The session fixation attack&lt;br /&gt;
&lt;br /&gt;
Trick the user into approving it from a link. Somewhat of a weakness but not a huge threat.&lt;br /&gt;
&lt;br /&gt;
Other sorts of connections&lt;br /&gt;
&lt;br /&gt;
I've already paired my Playstation with my Sony acct. It would be nice if when I add a netflix app it could just pair with Sony's frontend and then that connection could live across devices. In this case we could just do a webserver flow.&lt;br /&gt;
&lt;br /&gt;
Another way to authorize devices is to do bluetooth sharing of credentials. Like I can authorize my photoframe by connecting my android.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=3398</id>
		<title>OAuth2 for Devices</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=3398"/>
		<updated>2010-12-06T17:02:58Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAuth 2 for Devices&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Wednesday, Session 3, Space E&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Marius S.&lt;br /&gt;
&lt;br /&gt;
'''Note Taker:'''Andrew Wansley&lt;br /&gt;
&lt;br /&gt;
'''Discussion Notes:'''&lt;br /&gt;
&lt;br /&gt;
[[File:File:Device.pdf]]&lt;br /&gt;
&lt;br /&gt;
What is a device&lt;br /&gt;
&lt;br /&gt;
A device as we're concerned with it here has a display and a limited or painful input. We're explicitly not talking about headless devices, devices with no display and or no input like a refrigerator. These devices as far as we know just run a webserver locally and do the webserver profile.&lt;br /&gt;
&lt;br /&gt;
What's the flow&lt;br /&gt;
&lt;br /&gt;
From the user's perspective, the device displays a URL and code. User goes to URL and enters the code. The device magically works.&lt;br /&gt;
&lt;br /&gt;
From the device's perspective, the device presents AuthZ server with a clientID and gets back a URL a user code which it displays to the user and a device code used for polling. The device then starts polling the AuthZ server which tells it &amp;quot;not yet&amp;quot; for a while then eventually returns yes and a token or no.&lt;br /&gt;
&lt;br /&gt;
AuthZ server has preregistered a device and replies to the device's requests as described above.&lt;br /&gt;
&lt;br /&gt;
The session fixation attack&lt;br /&gt;
&lt;br /&gt;
Trick the user into approving it from a link. Somewhat of a weakness but not a huge threat.&lt;br /&gt;
&lt;br /&gt;
Other sorts of connections&lt;br /&gt;
&lt;br /&gt;
I've already paired my Playstation with my Sony acct. It would be nice if when I add a netflix app it could just pair with Sony's frontend and then that connection could live across devices. In this case we could just do a webserver flow.&lt;br /&gt;
&lt;br /&gt;
Another way to authorize devices is to do bluetooth sharing of credentials. Like I can authorize my photoframe by connecting my android.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=3397</id>
		<title>OAuth2 Exts.</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=3397"/>
		<updated>2010-12-06T16:57:19Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAUTH 2 Extensions &lt;br /&gt;
&lt;br /&gt;
'''Session:''' (W2F)&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Justin Richer &amp;amp; Marius Scurtescu &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Marius&lt;br /&gt;
&lt;br /&gt;
'''Discussion:'''&lt;br /&gt;
&lt;br /&gt;
[[File:NativeClientExtension.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;br /&gt;
&lt;br /&gt;
Hosts (and only participants): Justin Richer &amp;amp; Marius Scurtescu&lt;br /&gt;
&lt;br /&gt;
We talked about several proposed OAuth 2 extensions that we worked on or we thought are important:&lt;br /&gt;
* Instance Information&lt;br /&gt;
* XML Encoding&lt;br /&gt;
* UX&lt;br /&gt;
* Unregistered Clients&lt;br /&gt;
* Native Clients&lt;br /&gt;
* Token Types&lt;br /&gt;
&lt;br /&gt;
Instance Information and Unregistered Clients are somewhat related and we explored if they can be combined. In the end we decided that they are orthogonal and should stay as separate extensions.&lt;br /&gt;
&lt;br /&gt;
For Unregistered Clients the proposal is to specify well known values to two existing parameters and add a required and two optional&lt;br /&gt;
parameters:&lt;br /&gt;
* client_id=anonymous&lt;br /&gt;
* client_secret=anonymous&lt;br /&gt;
* client_name - required&lt;br /&gt;
* client_description - optional&lt;br /&gt;
* client_icon - optional&lt;br /&gt;
&lt;br /&gt;
We explored alternate ways to signal an unregistered client, specifically to omit the client_id and client_secret parameters from the request. The problem with this approach is that these two parameters are required by the core spec so generic libraries that are not aware of this extensions will have problems handling messages like these. Also, a potential benefit in providing these parameters with special values is that some code paths in the authz server implementation can stay agnostic to the client type (by hard coding a fake registration for anonymous/anonymous for example).&lt;br /&gt;
&lt;br /&gt;
The only issue with special values is that a client id of &amp;quot;anonymous&amp;quot;&lt;br /&gt;
my collide with a legitimate registered client.&lt;br /&gt;
For Instance Information the two proposed new parameters looks fine:&lt;br /&gt;
* instance_name&lt;br /&gt;
* instance_description&lt;br /&gt;
&lt;br /&gt;
For symmetry we should consider adding a instance_icon, maybe.&lt;br /&gt;
&lt;br /&gt;
For Native Clients we discussed an extension that allows the client to specify that it does not have a redirect URI, and that the authz server should provide a default one in this case. The extension also specifies the that default page should add the response to the &amp;lt;title&amp;gt; tag in a specific way so it shows up in the window title. This allows clients to implement OS specific window title scraping.&lt;br /&gt;
* redirect_uri=oob&lt;br /&gt;
* &amp;lt;title&amp;gt;Success code=123&amp;amp;state=abc&amp;lt;/title&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We also considered adding an optional parameter called &amp;quot;instructions&amp;quot;&lt;br /&gt;
through which the client can provide additional instructions to the end user.&lt;br /&gt;
&lt;br /&gt;
The Token Types extension introduces three new optional request parameters, all are hints from the client for the authz server. These allow the server to issue only the tokens that the client really&lt;br /&gt;
needs:&lt;br /&gt;
- tokens=[access|refresh]&lt;br /&gt;
- expires_in - optional&lt;br /&gt;
- token_usage=single&lt;br /&gt;
&lt;br /&gt;
tokens tells the authz server what tokens it needs. A web based client may not need a refresh token, during refresh a client may want a new refresh token, when swapping an authorization code a client may need only a refresh token.&lt;br /&gt;
&lt;br /&gt;
expires_in allows the authz server to issue access tokens that expire sooner than the default, this allows lowering the load on the server if some clients are asking for a large number of tokens in short periods of time.&lt;br /&gt;
&lt;br /&gt;
token_usage allows clients to ask for access tokens that are single use. This allows reducing load, as before, or reduce the risk if tokens are sent over insecure channels (think One Time Password). We also considered this parameter to take a number as value, instead of &amp;quot;single&amp;quot;, and this number to represent the number of uses allowed for the access token, in this case 1 == single.&lt;br /&gt;
&lt;br /&gt;
We noted that expires_in and token_usage can be approximated by using token revocation endpoint.&lt;br /&gt;
&lt;br /&gt;
XML Encoding should rely on an automatic mapping between the JSON format and the XML format. We considered generalizing this extension and also allow for form encoded responses. One possible issue with form encoded is that it allows only name/value pairs, whereas JSON and XML allow for tree structures. For now all responses are name/value pairs, and maybe it should stay like that, to be similar to requests and in browser responses.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:NativeClientExtension.pdf]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Verified_Identity_Claims&amp;diff=3396</id>
		<title>Verified Identity Claims</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Verified_Identity_Claims&amp;diff=3396"/>
		<updated>2010-12-06T16:52:26Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ojiqovam.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
'''Issue/Topic:''' VERIFIED IDENTITY CLAIMS – An introduction to U-Prove privacy-enhancing technology &lt;br /&gt;
&lt;br /&gt;
'''Session:''' Tuesday 3C&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Craig Wittenberg (Microsoft)&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Ariel Gordon (Microsoft)&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' &lt;br /&gt;
Verified Claims; Identity Attributes; Privacy; Privacy Enhancing Technology; Cryptography; user-centric technology: user control.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participants:'''&lt;br /&gt;
&lt;br /&gt;
*Craig Wittenberg	Microsoft&lt;br /&gt;
*Ariel Gordon	Microsoft&lt;br /&gt;
*Jan Unger	&lt;br /&gt;
*Tim Cole	KuppingerCole&lt;br /&gt;
*Bret Tobey	Assa Abloy&lt;br /&gt;
*John Fontana	Ping Identity&lt;br /&gt;
*Jon Webb	Sony PlayStation network&lt;br /&gt;
*Nishant Kaushix	Oracle&lt;br /&gt;
*Takeshi Kitagawa	NTT Communications&lt;br /&gt;
*Mark Horstmeier	Kynetx&lt;br /&gt;
*Matt Tebo	Proviti&lt;br /&gt;
*Greg Turner	Sierra Systems&lt;br /&gt;
*Mike Min	Booz&lt;br /&gt;
*Guibin Kony	Google&lt;br /&gt;
*Aravmdan Ranga	PayPal&lt;br /&gt;
*Tom Leon	AOL&lt;br /&gt;
*Jim Fenton	Cisco&lt;br /&gt;
*Dale Olds	Novell&lt;br /&gt;
*Ben Goodman	Novell&lt;br /&gt;
*Fady Semaan	AOL&lt;br /&gt;
*Henrik Biering	Peer Craft&lt;br /&gt;
*Stuart Proffitt	Novell&lt;br /&gt;
*Jeff Stollman	Secure Identity&lt;br /&gt;
*Ambarsh Malpar	CA&lt;br /&gt;
*Alex Ran	Intuit&lt;br /&gt;
*Thomas Hardjono	MIT Kerberos&lt;br /&gt;
*Peter Capek	Self&lt;br /&gt;
*Lloyd Burch	Novell&lt;br /&gt;
*Kimberly Little	LexisNexis&lt;br /&gt;
*Frank Travestino	eBay&lt;br /&gt;
*Heather Ford	UC Berkeley&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:'''&lt;br /&gt;
&lt;br /&gt;
[[File:U-Prove_technology_overview-Nov2010.pdf]]&lt;br /&gt;
&lt;br /&gt;
Verified Identity Claims -- Technical introduction &lt;br /&gt;
Craig Wittenberg presented the U-Prove technology&lt;br /&gt;
U-Prove well respected in academia.  Originally created by Credentica; purchased by Microsoft two years ago; incubated as part of the Verified Claims Team .&lt;br /&gt;
 &lt;br /&gt;
Similar characteristics as X.509 certificate but with much better privacy characteristics.&lt;br /&gt;
 &lt;br /&gt;
Craig presented a few scenarios, starting with Alice purchasing wine online and proving that she's over 21 and that she's a resident of WA state.   Other scenarios included leveraging a German eID to access citizen and private services.  &lt;br /&gt;
 &lt;br /&gt;
Many clarification Q&amp;amp;amp;A followed on the technology and its benefits, including:&lt;br /&gt;
 &lt;br /&gt;
Q: Why not do back-end attribute exchange?  Why go through all this trouble for exchanging attributes?&lt;br /&gt;
&lt;br /&gt;
A: There are scenarios with privacy requirements such as un-traceability.  If you take the case where Governments issue identity claims, there are requirements for the government not to be able to trace where the user is using his proof of age (for example).  Depending on the geography, the privacy requirements may come from the government itself or from Privacy Groups.&lt;br /&gt;
 &lt;br /&gt;
Q: If there is a Cloud Service that stores and releases information, does it effectively create a secondary IdP?  &lt;br /&gt;
&lt;br /&gt;
A: If there are no client side bits, there is effectively a “broker” in the cloud that manages the user’s private keys.  Microsoft and its partners are investigating different ways to build the u-prove verified claims agent that mitigates those issues.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''there is a powerpoint deck associated with this session: U-Prove technology overview-Nov2010.pptx''&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:U-Prove_technology_overview-Nov2010.pdf&amp;diff=3395</id>
		<title>File:U-Prove technology overview-Nov2010.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:U-Prove_technology_overview-Nov2010.pdf&amp;diff=3395"/>
		<updated>2010-12-06T16:41:29Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:OpenID_Foundation_Retail_Advisory_Committee_Overview.pdf&amp;diff=3394</id>
		<title>File:OpenID Foundation Retail Advisory Committee Overview.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:OpenID_Foundation_Retail_Advisory_Committee_Overview.pdf&amp;diff=3394"/>
		<updated>2010-12-06T16:39:54Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:Nov_2_Rethinking_Personal_Data_Workshop.pdf&amp;diff=3393</id>
		<title>File:Nov 2 Rethinking Personal Data Workshop.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:Nov_2_Rethinking_Personal_Data_Workshop.pdf&amp;diff=3393"/>
		<updated>2010-12-06T16:38:19Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:NativeClientExtension.pdf&amp;diff=3392</id>
		<title>File:NativeClientExtension.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:NativeClientExtension.pdf&amp;diff=3392"/>
		<updated>2010-12-06T16:27:20Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: uploaded a new version of &amp;quot;File:NativeClientExtension.pdf&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Notes_IIW-East&amp;diff=3391</id>
		<title>Notes IIW-East</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Notes_IIW-East&amp;diff=3391"/>
		<updated>2010-12-06T14:52:56Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://iiw.idcommons.net/File:IIW-East-BOP.pdf Complete Book of Proceedings for IIW-East in PDF form]&lt;br /&gt;
&lt;br /&gt;
== THURSDAY ==&lt;br /&gt;
&lt;br /&gt;
=== Session 1 ===&lt;br /&gt;
&lt;br /&gt;
T1A: [[Role of Government as Identity Oracle (Attribute Provider)]]&lt;br /&gt;
&lt;br /&gt;
T1B: [[B2B and B2C: How to Balance the Difference and Challenges of Each Environment]]&lt;br /&gt;
&lt;br /&gt;
T1C: [[Proofing the Masses]]&lt;br /&gt;
&lt;br /&gt;
F1D: [[NSTIC 101 (wtf?)]]&lt;br /&gt;
&lt;br /&gt;
T1E: [[More Government Employees at IIW Next Time]]&lt;br /&gt;
&lt;br /&gt;
T1F: [[PDX Ecosystem]]&lt;br /&gt;
&lt;br /&gt;
T1G: [[High Assurance Consumer Identity]]&lt;br /&gt;
&lt;br /&gt;
=== Session 2 ===&lt;br /&gt;
&lt;br /&gt;
T2A: [[Certifying Use Location for Politics Governance]]&lt;br /&gt;
&lt;br /&gt;
T2B: [[Useability: Addressing the click - click - click problem]]&lt;br /&gt;
&lt;br /&gt;
T2D: [[Leveraging Identity to Enable and Foster Scientific Collaboration]]&lt;br /&gt;
&lt;br /&gt;
T2C: [[Identity and Cross Domain Systems (multilayer security)]]&lt;br /&gt;
&lt;br /&gt;
T2E: [[Should We Create &amp;quot;Ownership Rights&amp;quot; in Law for Personal Data?]]&lt;br /&gt;
&lt;br /&gt;
T2F: [[Personal Data Vision of Future: Video]]&lt;br /&gt;
&lt;br /&gt;
T2G: [[Attributes Claims - Identify Attributes LOA]]&lt;br /&gt;
&lt;br /&gt;
=== Session 3 ===&lt;br /&gt;
&lt;br /&gt;
T3A: [[Are Mediation Tools Useful in Authentication?]]&lt;br /&gt;
&lt;br /&gt;
T3B: [[Open Identity for Closed Government: NSTIC the Cybersecurity Answer?]]&lt;br /&gt;
&lt;br /&gt;
T3C: [[Wholesale Privacy]]&lt;br /&gt;
&lt;br /&gt;
T3D: [[Building Standards for &amp;quot;Trustable&amp;quot; ID Providers]]&lt;br /&gt;
&lt;br /&gt;
T3E: [[Liability and Financial models for Identity Providers, Attribute Providers and Identity Proofers]]&lt;br /&gt;
&lt;br /&gt;
T3F: [[Personal Data Stores and Context Automation]]&lt;br /&gt;
&lt;br /&gt;
T3D: [[Patient Centric Medical Record Federation - Securing HData]]&lt;br /&gt;
&lt;br /&gt;
T3H: [[How to Make HTTP Authentication Useful Again?]]&lt;br /&gt;
&lt;br /&gt;
=== Session 4 ===&lt;br /&gt;
&lt;br /&gt;
T4A: [[PRIVACY - Did We Solve Privacy for Web Identity Systems (technically already?)]]&lt;br /&gt;
&lt;br /&gt;
T4C: [[Personal Data Store/Archive]]&lt;br /&gt;
&lt;br /&gt;
T4D: [[Service Chaining and Trust]]&lt;br /&gt;
&lt;br /&gt;
T4E: [[Extending OpenID Assertions with SAML+]]&lt;br /&gt;
&lt;br /&gt;
T4F: [[NSTIC - &amp;quot;Identity Ecosystem&amp;quot;]]&lt;br /&gt;
&lt;br /&gt;
T4G: [[Cross Federation Trust w/Meta Data]]&lt;br /&gt;
&lt;br /&gt;
== FRIDAY ==&lt;br /&gt;
&lt;br /&gt;
=== Session 1 ===&lt;br /&gt;
&lt;br /&gt;
F1A: [[OAUTH - What Topics Should We Focus On Next?]]&lt;br /&gt;
&lt;br /&gt;
F1D: [[Liability for ldps, APs, RPs... Continued]]&lt;br /&gt;
&lt;br /&gt;
F1E: [[Getting More .gov @IIW]]&lt;br /&gt;
&lt;br /&gt;
F1F: [[Identity Commons &amp;quot;3.0&amp;quot; Big Tent Creation]]&lt;br /&gt;
&lt;br /&gt;
=== Session 2 ===&lt;br /&gt;
&lt;br /&gt;
F2A: [[Government Relationship Management]]&lt;br /&gt;
&lt;br /&gt;
F2E: [[Enterprise Open ID]]&lt;br /&gt;
&lt;br /&gt;
F2C: [[Identity in the Browser (F2C)]]&lt;br /&gt;
&lt;br /&gt;
=== Session 3 ===&lt;br /&gt;
&lt;br /&gt;
F3B: [[&amp;quot;Today Geekdom, Tomorrow the World&amp;quot;]]&lt;br /&gt;
&lt;br /&gt;
F3D: [[Personal Data Locker? What is it and Why?]]&lt;br /&gt;
&lt;br /&gt;
F3E: [[Ownership Rights in Data Pt2]]&lt;br /&gt;
&lt;br /&gt;
F3F: [[Information Security Standards and &amp;quot;Levels of Protection&amp;quot;]]&lt;br /&gt;
&lt;br /&gt;
F3G: [[Certification Coordination - OIX, Kantara, ID Commons]]&lt;br /&gt;
&lt;br /&gt;
=== Session 4 ===&lt;br /&gt;
&lt;br /&gt;
[[OAUTH Signing #2]]&lt;br /&gt;
&lt;br /&gt;
F4D: [[Making NST IC Open/Making NST IC Happen]]&lt;br /&gt;
&lt;br /&gt;
F4E: [[Hybrid Online/Offline Debate BYO Issue]]&lt;br /&gt;
&lt;br /&gt;
F4F: [[Roadmap for Personal Data Store Ecology: Let's Make One]]&lt;br /&gt;
&lt;br /&gt;
F4G: [[Demo]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:IIW-East-BOP.pdf&amp;diff=3390</id>
		<title>File:IIW-East-BOP.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:IIW-East-BOP.pdf&amp;diff=3390"/>
		<updated>2010-12-06T14:52:10Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Iiw-europe-1-Notes&amp;diff=3389</id>
		<title>Iiw-europe-1-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Iiw-europe-1-Notes&amp;diff=3389"/>
		<updated>2010-12-06T14:45:27Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://iiw.idcommons.net/File:IIW-Europe-BOP.pdf Complete Book of Proceedings from IIW-Europe in PDF]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Session 1 ===&lt;br /&gt;
&lt;br /&gt;
1A: [[What is the MYDEX Prototype?]]&lt;br /&gt;
&lt;br /&gt;
1B: [[Federated Network Access]]&lt;br /&gt;
&lt;br /&gt;
1C: [[Partial Identities Privacy and Credentials]]&lt;br /&gt;
&lt;br /&gt;
1D: [[Privacy and Federated Social Networking w/o Correlation]]&lt;br /&gt;
&lt;br /&gt;
1E: [[OpenID Tiered Providers]]&lt;br /&gt;
&lt;br /&gt;
1F: [[Federated Identity as a Business Model]]&lt;br /&gt;
&lt;br /&gt;
=== Session 2 ===&lt;br /&gt;
&lt;br /&gt;
2A: [[Scoping the Single European Digital Identity Community]]&lt;br /&gt;
&lt;br /&gt;
2C: [[WebID and DNSSEC - combined session]]&lt;br /&gt;
&lt;br /&gt;
2D: [[U-Prove - How Do We Use Privacy Enhancing Crypto?]]&lt;br /&gt;
&lt;br /&gt;
=== Session 3 ===&lt;br /&gt;
&lt;br /&gt;
3A: [[What Do We Actually Mean When We Talk About Identity?]]&lt;br /&gt;
&lt;br /&gt;
3B: [[The Quality of Customer Intelligence (Authenticity/Relevance Correlation)]]&lt;br /&gt;
&lt;br /&gt;
3C: [[Personal Data Store Harmonizing = Project Nori DEMO]]&lt;br /&gt;
&lt;br /&gt;
3D: [[Claims]]&lt;br /&gt;
&lt;br /&gt;
3E: [[Authent-New Tools - Opportunities - Business]]&lt;br /&gt;
&lt;br /&gt;
3F: [[Remonetizing the Web:]] from 'Give privacy, get service' to: A win-win social web ecosystem for customers, Telcos, Banks, Websites&lt;br /&gt;
&lt;br /&gt;
3G: [[Identity Assurance (merges with) Automated Policy Negotiation]]&lt;br /&gt;
&lt;br /&gt;
=== Session 4 ===&lt;br /&gt;
&lt;br /&gt;
4A: [[CardSpace in the Clouds]]&lt;br /&gt;
&lt;br /&gt;
4B: [[Introduction to Digital Death - What Happens to Internet Identity After Death?]]&lt;br /&gt;
&lt;br /&gt;
4C: [[One Social Web . org]]&lt;br /&gt;
&lt;br /&gt;
4D: [[Why do Politicians Understand So Little? Our Fault or Theirs?]]&lt;br /&gt;
&lt;br /&gt;
4E: [[How Do You (we) Manage Heterogeneous Groups?]]&lt;br /&gt;
&lt;br /&gt;
4F: [[Issues About Profiling and Cross-Border Data Stores]]&lt;br /&gt;
&lt;br /&gt;
4G: [[OpenID the Nascar Problem Revisited]]&lt;br /&gt;
&lt;br /&gt;
=== Session 5 ===&lt;br /&gt;
&lt;br /&gt;
5A: [[UK Gov. - They Want To Talk Identity. How Do We Help?]]&lt;br /&gt;
&lt;br /&gt;
5B: [[Embedding Privacy Controls in OnLine Identity Mechanism: How and Why?]]&lt;br /&gt;
&lt;br /&gt;
5C: [[Privacy Dashboard Demo]]&lt;br /&gt;
&lt;br /&gt;
5D: [[Financial Services - distance selling, money laundering, &amp;quot;Know Your Customer&amp;quot;]]&lt;br /&gt;
&lt;br /&gt;
5E: [[Personal Data Ecosystem.org]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Iiw-europe-1-Notes&amp;diff=3388</id>
		<title>Iiw-europe-1-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Iiw-europe-1-Notes&amp;diff=3388"/>
		<updated>2010-12-06T14:41:29Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Complete Book of Proceedings from IIW-Europe in PDF form can be downloaded by clicking on this link &lt;br /&gt;
[Media:IIW-Europe-BOP.pdf‎]&lt;br /&gt;
&lt;br /&gt;
=== Session 1 ===&lt;br /&gt;
&lt;br /&gt;
1A: [[What is the MYDEX Prototype?]]&lt;br /&gt;
&lt;br /&gt;
1B: [[Federated Network Access]]&lt;br /&gt;
&lt;br /&gt;
1C: [[Partial Identities Privacy and Credentials]]&lt;br /&gt;
&lt;br /&gt;
1D: [[Privacy and Federated Social Networking w/o Correlation]]&lt;br /&gt;
&lt;br /&gt;
1E: [[OpenID Tiered Providers]]&lt;br /&gt;
&lt;br /&gt;
1F: [[Federated Identity as a Business Model]]&lt;br /&gt;
&lt;br /&gt;
=== Session 2 ===&lt;br /&gt;
&lt;br /&gt;
2A: [[Scoping the Single European Digital Identity Community]]&lt;br /&gt;
&lt;br /&gt;
2C: [[WebID and DNSSEC - combined session]]&lt;br /&gt;
&lt;br /&gt;
2D: [[U-Prove - How Do We Use Privacy Enhancing Crypto?]]&lt;br /&gt;
&lt;br /&gt;
=== Session 3 ===&lt;br /&gt;
&lt;br /&gt;
3A: [[What Do We Actually Mean When We Talk About Identity?]]&lt;br /&gt;
&lt;br /&gt;
3B: [[The Quality of Customer Intelligence (Authenticity/Relevance Correlation)]]&lt;br /&gt;
&lt;br /&gt;
3C: [[Personal Data Store Harmonizing = Project Nori DEMO]]&lt;br /&gt;
&lt;br /&gt;
3D: [[Claims]]&lt;br /&gt;
&lt;br /&gt;
3E: [[Authent-New Tools - Opportunities - Business]]&lt;br /&gt;
&lt;br /&gt;
3F: [[Remonetizing the Web:]] from 'Give privacy, get service' to: A win-win social web ecosystem for customers, Telcos, Banks, Websites&lt;br /&gt;
&lt;br /&gt;
3G: [[Identity Assurance (merges with) Automated Policy Negotiation]]&lt;br /&gt;
&lt;br /&gt;
=== Session 4 ===&lt;br /&gt;
&lt;br /&gt;
4A: [[CardSpace in the Clouds]]&lt;br /&gt;
&lt;br /&gt;
4B: [[Introduction to Digital Death - What Happens to Internet Identity After Death?]]&lt;br /&gt;
&lt;br /&gt;
4C: [[One Social Web . org]]&lt;br /&gt;
&lt;br /&gt;
4D: [[Why do Politicians Understand So Little? Our Fault or Theirs?]]&lt;br /&gt;
&lt;br /&gt;
4E: [[How Do You (we) Manage Heterogeneous Groups?]]&lt;br /&gt;
&lt;br /&gt;
4F: [[Issues About Profiling and Cross-Border Data Stores]]&lt;br /&gt;
&lt;br /&gt;
4G: [[OpenID the Nascar Problem Revisited]]&lt;br /&gt;
&lt;br /&gt;
=== Session 5 ===&lt;br /&gt;
&lt;br /&gt;
5A: [[UK Gov. - They Want To Talk Identity. How Do We Help?]]&lt;br /&gt;
&lt;br /&gt;
5B: [[Embedding Privacy Controls in OnLine Identity Mechanism: How and Why?]]&lt;br /&gt;
&lt;br /&gt;
5C: [[Privacy Dashboard Demo]]&lt;br /&gt;
&lt;br /&gt;
5D: [[Financial Services - distance selling, money laundering, &amp;quot;Know Your Customer&amp;quot;]]&lt;br /&gt;
&lt;br /&gt;
5E: [[Personal Data Ecosystem.org]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Iiw-europe-1-Notes&amp;diff=3387</id>
		<title>Iiw-europe-1-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Iiw-europe-1-Notes&amp;diff=3387"/>
		<updated>2010-12-06T14:40:12Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Complete Book of Proceedings from IIW-Europe in PDF form can be downloaded by clicking on this link &lt;br /&gt;
[[File:IIW-Europe-BOP.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
=== Session 1 ===&lt;br /&gt;
&lt;br /&gt;
1A: [[What is the MYDEX Prototype?]]&lt;br /&gt;
&lt;br /&gt;
1B: [[Federated Network Access]]&lt;br /&gt;
&lt;br /&gt;
1C: [[Partial Identities Privacy and Credentials]]&lt;br /&gt;
&lt;br /&gt;
1D: [[Privacy and Federated Social Networking w/o Correlation]]&lt;br /&gt;
&lt;br /&gt;
1E: [[OpenID Tiered Providers]]&lt;br /&gt;
&lt;br /&gt;
1F: [[Federated Identity as a Business Model]]&lt;br /&gt;
&lt;br /&gt;
=== Session 2 ===&lt;br /&gt;
&lt;br /&gt;
2A: [[Scoping the Single European Digital Identity Community]]&lt;br /&gt;
&lt;br /&gt;
2C: [[WebID and DNSSEC - combined session]]&lt;br /&gt;
&lt;br /&gt;
2D: [[U-Prove - How Do We Use Privacy Enhancing Crypto?]]&lt;br /&gt;
&lt;br /&gt;
=== Session 3 ===&lt;br /&gt;
&lt;br /&gt;
3A: [[What Do We Actually Mean When We Talk About Identity?]]&lt;br /&gt;
&lt;br /&gt;
3B: [[The Quality of Customer Intelligence (Authenticity/Relevance Correlation)]]&lt;br /&gt;
&lt;br /&gt;
3C: [[Personal Data Store Harmonizing = Project Nori DEMO]]&lt;br /&gt;
&lt;br /&gt;
3D: [[Claims]]&lt;br /&gt;
&lt;br /&gt;
3E: [[Authent-New Tools - Opportunities - Business]]&lt;br /&gt;
&lt;br /&gt;
3F: [[Remonetizing the Web:]] from 'Give privacy, get service' to: A win-win social web ecosystem for customers, Telcos, Banks, Websites&lt;br /&gt;
&lt;br /&gt;
3G: [[Identity Assurance (merges with) Automated Policy Negotiation]]&lt;br /&gt;
&lt;br /&gt;
=== Session 4 ===&lt;br /&gt;
&lt;br /&gt;
4A: [[CardSpace in the Clouds]]&lt;br /&gt;
&lt;br /&gt;
4B: [[Introduction to Digital Death - What Happens to Internet Identity After Death?]]&lt;br /&gt;
&lt;br /&gt;
4C: [[One Social Web . org]]&lt;br /&gt;
&lt;br /&gt;
4D: [[Why do Politicians Understand So Little? Our Fault or Theirs?]]&lt;br /&gt;
&lt;br /&gt;
4E: [[How Do You (we) Manage Heterogeneous Groups?]]&lt;br /&gt;
&lt;br /&gt;
4F: [[Issues About Profiling and Cross-Border Data Stores]]&lt;br /&gt;
&lt;br /&gt;
4G: [[OpenID the Nascar Problem Revisited]]&lt;br /&gt;
&lt;br /&gt;
=== Session 5 ===&lt;br /&gt;
&lt;br /&gt;
5A: [[UK Gov. - They Want To Talk Identity. How Do We Help?]]&lt;br /&gt;
&lt;br /&gt;
5B: [[Embedding Privacy Controls in OnLine Identity Mechanism: How and Why?]]&lt;br /&gt;
&lt;br /&gt;
5C: [[Privacy Dashboard Demo]]&lt;br /&gt;
&lt;br /&gt;
5D: [[Financial Services - distance selling, money laundering, &amp;quot;Know Your Customer&amp;quot;]]&lt;br /&gt;
&lt;br /&gt;
5E: [[Personal Data Ecosystem.org]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:IIW-Europe-BOP.pdf&amp;diff=3386</id>
		<title>File:IIW-Europe-BOP.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:IIW-Europe-BOP.pdf&amp;diff=3386"/>
		<updated>2010-12-06T14:39:03Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: IIW Europe Book of Proceedings. Oct 11, 2010, London.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;IIW Europe Book of Proceedings. Oct 11, 2010, London.&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2935</id>
		<title>Subject Specific Note Collections</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2935"/>
		<updated>2010-11-16T06:48:44Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Personal Data Ecosystem-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OIX and Trust Frameworks-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[UMA-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Information Cards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Security-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OAuth-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[NSTIC-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[EnterpriseID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[SAML-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Email-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Socaial Web Open Standards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[ID and Government-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Claims-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Identifiers-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[JSON-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Browser and Clients-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Assurance-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Law and Policy-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[XRI/XDI-Notes]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=2934</id>
		<title>OAuth2 Exts.</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=2934"/>
		<updated>2010-11-16T04:32:26Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAUTH 2 Extensions &lt;br /&gt;
&lt;br /&gt;
'''Session:''' (W2F)&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Justin Richer &amp;amp; Marius Scurtescu &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Marius&lt;br /&gt;
&lt;br /&gt;
'''Discussion:'''&lt;br /&gt;
&lt;br /&gt;
Hosts (and only participants): Justin Richer &amp;amp; Marius Scurtescu&lt;br /&gt;
&lt;br /&gt;
We talked about several proposed OAuth 2 extensions that we worked on or we thought are important:&lt;br /&gt;
* Instance Information&lt;br /&gt;
* XML Encoding&lt;br /&gt;
* UX&lt;br /&gt;
* Unregistered Clients&lt;br /&gt;
* Native Clients&lt;br /&gt;
* Token Types&lt;br /&gt;
&lt;br /&gt;
Instance Information and Unregistered Clients are somewhat related and we explored if they can be combined. In the end we decided that they are orthogonal and should stay as separate extensions.&lt;br /&gt;
&lt;br /&gt;
For Unregistered Clients the proposal is to specify well known values to two existing parameters and add a required and two optional&lt;br /&gt;
parameters:&lt;br /&gt;
* client_id=anonymous&lt;br /&gt;
* client_secret=anonymous&lt;br /&gt;
* client_name - required&lt;br /&gt;
* client_description - optional&lt;br /&gt;
* client_icon - optional&lt;br /&gt;
&lt;br /&gt;
We explored alternate ways to signal an unregistered client, specifically to omit the client_id and client_secret parameters from the request. The problem with this approach is that these two parameters are required by the core spec so generic libraries that are not aware of this extensions will have problems handling messages like these. Also, a potential benefit in providing these parameters with special values is that some code paths in the authz server implementation can stay agnostic to the client type (by hard coding a fake registration for anonymous/anonymous for example).&lt;br /&gt;
&lt;br /&gt;
The only issue with special values is that a client id of &amp;quot;anonymous&amp;quot;&lt;br /&gt;
my collide with a legitimate registered client.&lt;br /&gt;
For Instance Information the two proposed new parameters looks fine:&lt;br /&gt;
* instance_name&lt;br /&gt;
* instance_description&lt;br /&gt;
&lt;br /&gt;
For symmetry we should consider adding a instance_icon, maybe.&lt;br /&gt;
&lt;br /&gt;
For Native Clients we discussed an extension that allows the client to specify that it does not have a redirect URI, and that the authz server should provide a default one in this case. The extension also specifies the that default page should add the response to the &amp;lt;title&amp;gt; tag in a specific way so it shows up in the window title. This allows clients to implement OS specific window title scraping.&lt;br /&gt;
* redirect_uri=oob&lt;br /&gt;
* &amp;lt;title&amp;gt;Success code=123&amp;amp;state=abc&amp;lt;/title&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We also considered adding an optional parameter called &amp;quot;instructions&amp;quot;&lt;br /&gt;
through which the client can provide additional instructions to the end user.&lt;br /&gt;
&lt;br /&gt;
The Token Types extension introduces three new optional request parameters, all are hints from the client for the authz server. These allow the server to issue only the tokens that the client really&lt;br /&gt;
needs:&lt;br /&gt;
- tokens=[access|refresh]&lt;br /&gt;
- expires_in - optional&lt;br /&gt;
- token_usage=single&lt;br /&gt;
&lt;br /&gt;
tokens tells the authz server what tokens it needs. A web based client may not need a refresh token, during refresh a client may want a new refresh token, when swapping an authorization code a client may need only a refresh token.&lt;br /&gt;
&lt;br /&gt;
expires_in allows the authz server to issue access tokens that expire sooner than the default, this allows lowering the load on the server if some clients are asking for a large number of tokens in short periods of time.&lt;br /&gt;
&lt;br /&gt;
token_usage allows clients to ask for access tokens that are single use. This allows reducing load, as before, or reduce the risk if tokens are sent over insecure channels (think One Time Password). We also considered this parameter to take a number as value, instead of &amp;quot;single&amp;quot;, and this number to represent the number of uses allowed for the access token, in this case 1 == single.&lt;br /&gt;
&lt;br /&gt;
We noted that expires_in and token_usage can be approximated by using token revocation endpoint.&lt;br /&gt;
&lt;br /&gt;
XML Encoding should rely on an automatic mapping between the JSON format and the XML format. We considered generalizing this extension and also allow for form encoded responses. One possible issue with form encoded is that it allows only name/value pairs, whereas JSON and XML allow for tree structures. For now all responses are name/value pairs, and maybe it should stay like that, to be similar to requests and in browser responses.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:NativeClientExtension.pdf]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=2933</id>
		<title>OAuth2 Exts.</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=2933"/>
		<updated>2010-11-16T04:30:45Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAUTH 2 Extensions &lt;br /&gt;
&lt;br /&gt;
'''Session:''' (W2F)&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Justin Richer &amp;amp; Marius Scurtescu &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Marius&lt;br /&gt;
&lt;br /&gt;
'''Discussion:'''&lt;br /&gt;
&lt;br /&gt;
Hosts (and only participants): Justin Richer &amp;amp; Marius Scurtescu&lt;br /&gt;
&lt;br /&gt;
We talked about several proposed OAuth 2 extensions that we worked on or we thought are important:&lt;br /&gt;
* Instance Information&lt;br /&gt;
* XML Encoding&lt;br /&gt;
* UX&lt;br /&gt;
* Unregistered Clients&lt;br /&gt;
* Native Clients&lt;br /&gt;
* Token Types&lt;br /&gt;
&lt;br /&gt;
Instance Information and Unregistered Clients are somewhat related and we explored if they can be combined. In the end we decided that they are orthogonal and should stay as separate extensions.&lt;br /&gt;
&lt;br /&gt;
For Unregistered Clients the proposal is to specify well known values to two existing parameters and add a required and two optional&lt;br /&gt;
parameters:&lt;br /&gt;
* client_id=anonymous&lt;br /&gt;
* client_secret=anonymous&lt;br /&gt;
* client_name - required&lt;br /&gt;
* client_description - optional&lt;br /&gt;
* client_icon - optional&lt;br /&gt;
&lt;br /&gt;
We explored alternate ways to signal an unregistered client, specifically to omit the client_id and client_secret parameters from the request. The problem with this approach is that these two parameters are required by the core spec so generic libraries that are not aware of this extensions will have problems handling messages like these. Also, a potential benefit in providing these parameters with special values is that some code paths in the authz server implementation can stay agnostic to the client type (by hard coding a fake registration for anonymous/anonymous for example).&lt;br /&gt;
&lt;br /&gt;
The only issue with special values is that a client id of &amp;quot;anonymous&amp;quot;&lt;br /&gt;
my collide with a legitimate registered client.&lt;br /&gt;
For Instance Information the two proposed new parameters looks fine:&lt;br /&gt;
* instance_name&lt;br /&gt;
* instance_description&lt;br /&gt;
&lt;br /&gt;
For symmetry we should consider adding a instance_icon, maybe.&lt;br /&gt;
&lt;br /&gt;
For Native Clients we discussed an extension that allows the client to specify that it does not have a redirect URI, and that the authz server should provide a default one in this case. The extension also specifies the that default page should add the response to the &amp;lt;title&amp;gt; tag in a specific way so it shows up in the window title. This allows clients to implement OS specific window title scraping.&lt;br /&gt;
* redirect_uri=oob&lt;br /&gt;
* &amp;lt;title&amp;gt;Success code=123&amp;amp;state=abc&amp;lt;/title&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We also considered adding an optional parameter called &amp;quot;instructions&amp;quot;&lt;br /&gt;
through which the client can provide additional instructions to the end user.&lt;br /&gt;
&lt;br /&gt;
The Token Types extension introduces three new optional request parameters, all are hints from the client for the authz server. These allow the server to issue only the tokens that the client really&lt;br /&gt;
needs:&lt;br /&gt;
- tokens=[access|refresh]&lt;br /&gt;
- expires_in - optional&lt;br /&gt;
- token_usage=single&lt;br /&gt;
&lt;br /&gt;
tokens tells the authz server what tokens it needs. A web based client may not need a refresh token, during refresh a client may want a new refresh token, when swapping an authorization code a client may need only a refresh token.&lt;br /&gt;
&lt;br /&gt;
expires_in allows the authz server to issue access tokens that expire sooner than the default, this allows lowering the load on the server if some clients are asking for a large number of tokens in short periods of time.&lt;br /&gt;
&lt;br /&gt;
token_usage allows clients to ask for access tokens that are single use. This allows reducing load, as before, or reduce the risk if tokens are sent over insecure channels (think One Time Password). We also considered this parameter to take a number as value, instead of &amp;quot;single&amp;quot;, and this number to represent the number of uses allowed for the access token, in this case 1 == single.&lt;br /&gt;
&lt;br /&gt;
We noted that expires_in and token_usage can be approximated by using token revocation endpoint.&lt;br /&gt;
&lt;br /&gt;
XML Encoding should rely on an automatic mapping between the JSON format and the XML format. We considered generalizing this extension and also allow for form encoded responses. One possible issue with form encoded is that it allows only name/value pairs, whereas JSON and XML allow for tree structures. For now all responses are name/value pairs, and maybe it should stay like that, to be similar to requests and in browser responses.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[Flie:NativeClientExtension.pdf]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:NativeClientExtension.pdf&amp;diff=2932</id>
		<title>File:NativeClientExtension.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:NativeClientExtension.pdf&amp;diff=2932"/>
		<updated>2010-11-16T04:29:53Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=2931</id>
		<title>OAuth2 Exts.</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_Exts.&amp;diff=2931"/>
		<updated>2010-11-16T04:28:42Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAUTH 2 Extensions &lt;br /&gt;
&lt;br /&gt;
'''Session:''' (W2F)&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Justin Richer &amp;amp; Marius Scurtescu &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Marius&lt;br /&gt;
&lt;br /&gt;
'''Discussion:'''&lt;br /&gt;
&lt;br /&gt;
Hosts (and only participants): Justin Richer &amp;amp; Marius Scurtescu&lt;br /&gt;
&lt;br /&gt;
We talked about several proposed OAuth 2 extensions that we worked on or we thought are important:&lt;br /&gt;
* Instance Information&lt;br /&gt;
* XML Encoding&lt;br /&gt;
* UX&lt;br /&gt;
* Unregistered Clients&lt;br /&gt;
* Native Clients&lt;br /&gt;
* Token Types&lt;br /&gt;
&lt;br /&gt;
Instance Information and Unregistered Clients are somewhat related and we explored if they can be combined. In the end we decided that they are orthogonal and should stay as separate extensions.&lt;br /&gt;
&lt;br /&gt;
For Unregistered Clients the proposal is to specify well known values to two existing parameters and add a required and two optional&lt;br /&gt;
parameters:&lt;br /&gt;
* client_id=anonymous&lt;br /&gt;
* client_secret=anonymous&lt;br /&gt;
* client_name - required&lt;br /&gt;
* client_description - optional&lt;br /&gt;
* client_icon - optional&lt;br /&gt;
&lt;br /&gt;
We explored alternate ways to signal an unregistered client, specifically to omit the client_id and client_secret parameters from the request. The problem with this approach is that these two parameters are required by the core spec so generic libraries that are not aware of this extensions will have problems handling messages like these. Also, a potential benefit in providing these parameters with special values is that some code paths in the authz server implementation can stay agnostic to the client type (by hard coding a fake registration for anonymous/anonymous for example).&lt;br /&gt;
&lt;br /&gt;
The only issue with special values is that a client id of &amp;quot;anonymous&amp;quot;&lt;br /&gt;
my collide with a legitimate registered client.&lt;br /&gt;
For Instance Information the two proposed new parameters looks fine:&lt;br /&gt;
* instance_name&lt;br /&gt;
* instance_description&lt;br /&gt;
&lt;br /&gt;
For symmetry we should consider adding a instance_icon, maybe.&lt;br /&gt;
&lt;br /&gt;
For Native Clients we discussed an extension that allows the client to specify that it does not have a redirect URI, and that the authz server should provide a default one in this case. The extension also specifies the that default page should add the response to the &amp;lt;title&amp;gt; tag in a specific way so it shows up in the window title. This allows clients to implement OS specific window title scraping.&lt;br /&gt;
* redirect_uri=oob&lt;br /&gt;
* &amp;lt;title&amp;gt;Success code=123&amp;amp;state=abc&amp;lt;/title&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We also considered adding an optional parameter called &amp;quot;instructions&amp;quot;&lt;br /&gt;
through which the client can provide additional instructions to the end user.&lt;br /&gt;
&lt;br /&gt;
The Token Types extension introduces three new optional request parameters, all are hints from the client for the authz server. These allow the server to issue only the tokens that the client really&lt;br /&gt;
needs:&lt;br /&gt;
- tokens=[access|refresh]&lt;br /&gt;
- expires_in - optional&lt;br /&gt;
- token_usage=single&lt;br /&gt;
&lt;br /&gt;
tokens tells the authz server what tokens it needs. A web based client may not need a refresh token, during refresh a client may want a new refresh token, when swapping an authorization code a client may need only a refresh token.&lt;br /&gt;
&lt;br /&gt;
expires_in allows the authz server to issue access tokens that expire sooner than the default, this allows lowering the load on the server if some clients are asking for a large number of tokens in short periods of time.&lt;br /&gt;
&lt;br /&gt;
token_usage allows clients to ask for access tokens that are single use. This allows reducing load, as before, or reduce the risk if tokens are sent over insecure channels (think One Time Password). We also considered this parameter to take a number as value, instead of &amp;quot;single&amp;quot;, and this number to represent the number of uses allowed for the access token, in this case 1 == single.&lt;br /&gt;
&lt;br /&gt;
We noted that expires_in and token_usage can be approximated by using token revocation endpoint.&lt;br /&gt;
&lt;br /&gt;
XML Encoding should rely on an automatic mapping between the JSON format and the XML format. We considered generalizing this extension and also allow for form encoded responses. One possible issue with form encoded is that it allows only name/value pairs, whereas JSON and XML allow for tree structures. For now all responses are name/value pairs, and maybe it should stay like that, to be similar to requests and in browser responses.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=2930</id>
		<title>OAuth2 for Devices</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=2930"/>
		<updated>2010-11-16T04:27:49Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAuth 2 for Devices&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Wednesday, Session 3, Space E&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Marius S.&lt;br /&gt;
&lt;br /&gt;
'''Note Taker:'''Andrew Wansley&lt;br /&gt;
&lt;br /&gt;
'''Discussion Notes:'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What is a device&lt;br /&gt;
&lt;br /&gt;
A device as we're concerned with it here has a display and a limited or painful input. We're explicitly not talking about headless devices, devices with no display and or no input like a refrigerator. These devices as far as we know just run a webserver locally and do the webserver profile.&lt;br /&gt;
&lt;br /&gt;
What's the flow&lt;br /&gt;
&lt;br /&gt;
From the user's perspective, the device displays a URL and code. User goes to URL and enters the code. The device magically works.&lt;br /&gt;
&lt;br /&gt;
From the device's perspective, the device presents AuthZ server with a clientID and gets back a URL a user code which it displays to the user and a device code used for polling. The device then starts polling the AuthZ server which tells it &amp;quot;not yet&amp;quot; for a while then eventually returns yes and a token or no.&lt;br /&gt;
&lt;br /&gt;
AuthZ server has preregistered a device and replies to the device's requests as described above.&lt;br /&gt;
&lt;br /&gt;
The session fixation attack&lt;br /&gt;
&lt;br /&gt;
Trick the user into approving it from a link. Somewhat of a weakness but not a huge threat.&lt;br /&gt;
&lt;br /&gt;
Other sorts of connections&lt;br /&gt;
&lt;br /&gt;
I've already paired my Playstation with my Sony acct. It would be nice if when I add a netflix app it could just pair with Sony's frontend and then that connection could live across devices. In this case we could just do a webserver flow.&lt;br /&gt;
&lt;br /&gt;
Another way to authorize devices is to do bluetooth sharing of credentials. Like I can authorize my photoframe by connecting my android.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
[[File:UnregisteredClientExtension.pdf]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:UnregisteredClientExtension.pdf&amp;diff=2929</id>
		<title>File:UnregisteredClientExtension.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:UnregisteredClientExtension.pdf&amp;diff=2929"/>
		<updated>2010-11-16T04:27:07Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=2928</id>
		<title>OAuth2 for Devices</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=2928"/>
		<updated>2010-11-16T04:25:51Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAuth 2 for Devices&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Wednesday, Session 3, Space E&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Marius S.&lt;br /&gt;
&lt;br /&gt;
'''Note Taker:'''Andrew Wansley&lt;br /&gt;
&lt;br /&gt;
'''Discussion Notes:'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What is a device&lt;br /&gt;
&lt;br /&gt;
A device as we're concerned with it here has a display and a limited or painful input. We're explicitly not talking about headless devices, devices with no display and or no input like a refrigerator. These devices as far as we know just run a webserver locally and do the webserver profile.&lt;br /&gt;
&lt;br /&gt;
What's the flow&lt;br /&gt;
&lt;br /&gt;
From the user's perspective, the device displays a URL and code. User goes to URL and enters the code. The device magically works.&lt;br /&gt;
&lt;br /&gt;
From the device's perspective, the device presents AuthZ server with a clientID and gets back a URL a user code which it displays to the user and a device code used for polling. The device then starts polling the AuthZ server which tells it &amp;quot;not yet&amp;quot; for a while then eventually returns yes and a token or no.&lt;br /&gt;
&lt;br /&gt;
AuthZ server has preregistered a device and replies to the device's requests as described above.&lt;br /&gt;
&lt;br /&gt;
The session fixation attack&lt;br /&gt;
&lt;br /&gt;
Trick the user into approving it from a link. Somewhat of a weakness but not a huge threat.&lt;br /&gt;
&lt;br /&gt;
Other sorts of connections&lt;br /&gt;
&lt;br /&gt;
I've already paired my Playstation with my Sony acct. It would be nice if when I add a netflix app it could just pair with Sony's frontend and then that connection could live across devices. In this case we could just do a webserver flow.&lt;br /&gt;
&lt;br /&gt;
Another way to authorize devices is to do bluetooth sharing of credentials. Like I can authorize my photoframe by connecting my android.&lt;br /&gt;
&lt;br /&gt;
[[File:Device.pdf‎]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=File:Device.pdf&amp;diff=2927</id>
		<title>File:Device.pdf</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=File:Device.pdf&amp;diff=2927"/>
		<updated>2010-11-16T04:25:18Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=2926</id>
		<title>OAuth2 for Devices</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OAuth2_for_Devices&amp;diff=2926"/>
		<updated>2010-11-16T04:23:56Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Title:''' OAuth 2 for Devices&lt;br /&gt;
&lt;br /&gt;
'''Session:''' Wednesday, Session 3, Space E&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw11 IIW-11] November 2-4, Mountain View, [http://iiw.idcommons.net/Notes_IIW11 Complete Notes Page]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Marius S.&lt;br /&gt;
&lt;br /&gt;
'''Note Taker:'''Andrew Wansley&lt;br /&gt;
&lt;br /&gt;
'''Discussion Notes:'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What is a device&lt;br /&gt;
&lt;br /&gt;
A device as we're concerned with it here has a display and a limited or painful input. We're explicitly not talking about headless devices, devices with no display and or no input like a refrigerator. These devices as far as we know just run a webserver locally and do the webserver profile.&lt;br /&gt;
&lt;br /&gt;
What's the flow&lt;br /&gt;
&lt;br /&gt;
From the user's perspective, the device displays a URL and code. User goes to URL and enters the code. The device magically works.&lt;br /&gt;
&lt;br /&gt;
From the device's perspective, the device presents AuthZ server with a clientID and gets back a URL a user code which it displays to the user and a device code used for polling. The device then starts polling the AuthZ server which tells it &amp;quot;not yet&amp;quot; for a while then eventually returns yes and a token or no.&lt;br /&gt;
&lt;br /&gt;
AuthZ server has preregistered a device and replies to the device's requests as described above.&lt;br /&gt;
&lt;br /&gt;
The session fixation attack&lt;br /&gt;
&lt;br /&gt;
Trick the user into approving it from a link. Somewhat of a weakness but not a huge threat.&lt;br /&gt;
&lt;br /&gt;
Other sorts of connections&lt;br /&gt;
&lt;br /&gt;
I've already paired my Playstation with my Sony acct. It would be nice if when I add a netflix app it could just pair with Sony's frontend and then that connection could live across devices. In this case we could just do a webserver flow.&lt;br /&gt;
&lt;br /&gt;
Another way to authorize devices is to do bluetooth sharing of credentials. Like I can authorize my photoframe by connecting my android.&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=2925</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=2925"/>
		<updated>2010-11-16T04:20:06Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* Previous Internet Identity Workshops */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;Big&amp;gt; Welcome to the Internet Identity Workshop (IIW) Wiki &amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.internetidentityworkshop.com WE HAVE A WEBSITE/BLOG TOO!] &lt;br /&gt;
&lt;br /&gt;
* To get updates regarding IIW  [http://lists.idcommons.net/lists/info/iiwinfo subscribe here].&lt;br /&gt;
&lt;br /&gt;
[[Subject Specific Note Collections]]&lt;br /&gt;
&lt;br /&gt;
=== Next Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
IIW #12 will be in May of 2011.  Dates will be announced in December 2010.&lt;br /&gt;
&lt;br /&gt;
We are working on collaborating with our industry organizational peers on a community unconference before RSA on February 14th.&lt;br /&gt;
&lt;br /&gt;
We are considering hosting &amp;quot;Identity Open Space&amp;quot; events on the East Coast of the United States and in Europe in 2011.  Feel free to contact us if you are interested in helping/participating.  (kaliya (at) Mac.com) &lt;br /&gt;
&lt;br /&gt;
We have an [http://lists.idcommons.net/lists/subscribe/iiwinfo announcement list] that you can subscribe to if you would like to get an e-mail when new IIW &amp;amp; IOS events are announced.&lt;br /&gt;
&lt;br /&gt;
=== Previous Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
* #11 Fall 2010 [[iiw11]] Nov 2-4, Tuesday-Thursday at the Computer HIstory Museum in Mountain View California&lt;br /&gt;
** [[Notes IIW11]]&lt;br /&gt;
** [http://www.internetidentityworkshop.com/what-is-iiw/ Responses to IIW is...] [http://www.internetidentityworkshop.com/iiw-values/ Values of IIW]&lt;br /&gt;
&lt;br /&gt;
* [[iiw-europe-1|IIW Europe]] in London Monday October 11 (before RSA Europe) at the University of London&lt;br /&gt;
** [[iiw-europe-1-Notes]]&lt;br /&gt;
** [[iiw-europe-1-Reflection]] As a Result of Today.... &lt;br /&gt;
&lt;br /&gt;
* [[iiw-east-1|IIW East Coast]] in DC September 9-10 Thursday, Friday at the Josephine Butler Parks Center (following the Gov 2.0 Summit) the theme will be ''Open Identity for Open Government'' &lt;br /&gt;
** [[Notes_IIW-East]]&lt;br /&gt;
** [[As a result of day 1 at IIW-East]]&lt;br /&gt;
&lt;br /&gt;
* #10: Spring 2010 [[iiw10]] May 17-19 at the Computer History Museum. &lt;br /&gt;
** [[Notes IIW10]]&lt;br /&gt;
&lt;br /&gt;
* #9: Fall 2009 [[iiw9]] TUESDAY November 3 to THURSDAY November 5. &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #8: Spring 2009 [[iiw8]] - '''May 18-20, 2009''' &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #7: Fall [[iiw2008b]] (2008B)- '''Nov 10-12''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_08b]]&lt;br /&gt;
&lt;br /&gt;
* 6: Spring [[iiw2008a]]  (2008A)- '''May 12-14, 2008''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_2008a]]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.idcommons.net/index.php/Iiw2007b 5: December 3-5, 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop_2007 4: May 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006b 3: December 2006 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006 2: May 2006 - - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://www.socialtext.net/iiw2005/index.cgi?internet_identity_workshop_2005 1: October 2005 - Berkeley, CA]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Open Spaces ===&lt;br /&gt;
&lt;br /&gt;
Identity Open Space events are co-produced by the IIW team (Phil, Kaliya, Doc) in collaboration with other organizations and events. To date we have worked with Digital Identity World and the Liberty Alliance. We are open to working with a variety organizations - if you are interested please don't hesitate to contact us. &lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSF September 2007 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSBrussels May 2007 following a Liberty Alliance Meeting in Brussels, Belgium]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSantaClara September 2006 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSVan July 2006 following a Liberty Alliance Meeting in Vancouver, Canada]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Birds of a Feather Meetings ===&lt;br /&gt;
&lt;br /&gt;
June 2006 [http://www.identitygang.org/ Identity Gang Birds of a Feather Session] at Burton Group Conference, San Francisco&lt;br /&gt;
&lt;br /&gt;
January 2006 [http://www.socialtext.net/iiw2005/index.cgi?identity_speed_geeking_o_reilly_emerging_telephony_conference Identity Speed Geeking Session] at O'Reilly's  Emerging Telephony Conference&lt;br /&gt;
&lt;br /&gt;
December 2005 [http://www.socialtext.net/iiw2005/index.cgi?informational_morning_for_developers Pre-Syndicate Informational Morning for Developers]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2924</id>
		<title>Subject Specific Note Collections</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2924"/>
		<updated>2010-11-16T04:17:18Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Personal Data Ecosystem-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OIX and Trust Frameworks-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[UMA-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Information Cards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Security-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OAuth-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[NSTIC-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[EnterpriseID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[SAML-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Email-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Socaial Web Open Standards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[ID and Government-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Claims-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Identifiers-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[JSON-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Browser and Clients-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Assurance-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Law and Policy-Notes]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2923</id>
		<title>Subject Specific Note Collections</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2923"/>
		<updated>2010-11-16T04:16:32Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Personal Data Ecosystem-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OIX and Trust Frameworks-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[UMA-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Information Cards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Security-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OAuth-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[NSTIC-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[EnterpriseID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[SAML-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Email-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Socaial Web Open Standards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[ID and Government-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Claims-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Identifiers-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[JSON-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Browser and Clients-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Assurance-Notes]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Telco-Web-Data_User_Model_Scenarios&amp;diff=2922</id>
		<title>Telco-Web-Data User Model Scenarios</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Telco-Web-Data_User_Model_Scenarios&amp;diff=2922"/>
		<updated>2010-11-16T04:02:56Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session:''' Wed Session 5 Space F&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw10 IIW 10]  May 17-19, 2009 this is the complete [http://iiw.idcommons.net/Notes_IIW10 Complete Set of Notes ]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Nancy Frishberg&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Christie Grabyan&lt;br /&gt;
&lt;br /&gt;
''' technology discussed/ideas considered:''' &lt;br /&gt;
&lt;br /&gt;
We shared ideas about what the scope of the discussion should be:&lt;br /&gt;
* User scenarios/use cases specific to the Web/Telco interaction discussed previously&lt;br /&gt;
* What scenarios does a personal data store concept enable? &lt;br /&gt;
* What use cases are there to drive adoption by users of a personal data store?&lt;br /&gt;
* What is the narrative/story between a user and scenario (how many players are there? Is there a specific case to delve into?) An overview where parts can be storyboarded&lt;br /&gt;
&lt;br /&gt;
We chose to focus on the perspective of types of users and their interactions with the web and/or Telco infrastructure. We want to discuss both the macro and micro (global vs. local) interactions. &lt;br /&gt;
&lt;br /&gt;
'''Notes:'''&lt;br /&gt;
&lt;br /&gt;
Terminology check:&lt;br /&gt;
User profile = user persona&lt;br /&gt;
Use case = user scenario&lt;br /&gt;
&lt;br /&gt;
Example user scenario: Woman who has a single cell phone in a South American village and she makes a living renting out her cell phone to others in the community to make calls. (We have assumed a one-to-one relationship of person-to-phone). This is not a technical challenge; it is that there is not perceived value by the users to uniquely identify themselves.&lt;br /&gt;
&lt;br /&gt;
Example user scenario: A colleague goes to China and tries to figure out how her product’s companies will fit into the Chinese culture and lifestyle. Not everyone (the China user base) had a computer, but pretty much everyone had at least one phone. Many users had many phones. It is perceived at useful for one person to have multiple devices. Often these phones are pay-as-you-go structure. Different phones are used in different contexts.&lt;br /&gt;
&lt;br /&gt;
Example user scenario: We suspect that usage behavior will vary by age group. For example, younger users may not pay for their service (paid for by parents), and they may text much more than they call. Conversely, different phones and plans are marketed towards different groups/peoples. &lt;br /&gt;
&lt;br /&gt;
One application for the personal data concept is that it limits that monopolization of data (by Facebook, etc). But, for people who are not on any social networks, what is their “personal data store”? &lt;br /&gt;
&lt;br /&gt;
Family historians today share family information, but often “offline”. But if this were digitized, there could be more of a need for personal data store for this population. Marketers and advertisers are interested in data like recent browser searches, not always information considered personal, like the family historian artifacts.&lt;br /&gt;
&lt;br /&gt;
Adoption is usually driven by either ease-of-use. People often don’t trust claims of privacy and security. &lt;br /&gt;
&lt;br /&gt;
Not only “what is the killer app to get people on board with personal data store”? But also what is the killer app to get more people to be “social”? The discussion is that everyone is social, but perhaps not digitally social.&lt;br /&gt;
&lt;br /&gt;
A user might not understand the use of a personal data store until they understand what they will gain from it. They need to understand what scenarios will be the reasons they would want to protect and/or share their personal information.&lt;br /&gt;
&lt;br /&gt;
It’s not just about what data to share, but how easy is it for data that already exists about you to be shared back with you. (i.e. the digitization of medical records in the U.S.). There is also the international scenario of people who move countries, and information (residential, health, etc) is essentially lost or no longer usable. &lt;br /&gt;
&lt;br /&gt;
In Singapore, there are national ID cards that are assigned when born and then that number is used on ID cards when you are an adult. There is efficiency in the system, but obviously a lack of user control over your own information or the aggregation of information.&lt;br /&gt;
&lt;br /&gt;
The aggregation of data is the scary part to users, even if it’s the aggregation of data that already exists. It’s the same political issue as the resistance against the government having a national ID card scheme. There will definitely be an education effort for the average consumer to understand what the personal data store means, and why it is necessary, useful, beneficial, etc. The negative incidents that occur are what will give consumers the awareness required to care about these kinds of issues. It’s not that a bank account has to be compromised, but it’s that someone can take and exploit your aggregation of digital data. The emotional impact on the public/consumer base will drive the adoption of change of behavior. &lt;br /&gt;
&lt;br /&gt;
Scenario: what is your last/recent web searches? How does this interact with or integrate with your personal data store.&lt;br /&gt;
&lt;br /&gt;
If you don’t know what is IN the personal data store, you won’t be in a position to decide what and how to share.&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2921</id>
		<title>Subject Specific Note Collections</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Subject_Specific_Note_Collections&amp;diff=2921"/>
		<updated>2010-11-16T04:02:20Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Personal Data Ecosystem-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OIX and Trust Frameworks-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[UMA-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Information Cards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OpenID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Security-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[OAuth-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[NSTIC-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[EnterpriseID-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[SAML-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Email-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Socaial Web Open Standards-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Browser and Clients-Notes]]&lt;br /&gt;
&lt;br /&gt;
[[Assurance-Notes]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2920</id>
		<title>Personal Data Ecosystem-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2920"/>
		<updated>2010-11-16T03:47:12Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* IIW 11 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW 11 ==&lt;br /&gt;
&lt;br /&gt;
* [[Intro to PDS]] Mon, Session 1A &lt;br /&gt;
* [[Facebook as a Personal Data Store]] Mon Session 3A&lt;br /&gt;
* [[Personal Data Ecosystem]]&lt;br /&gt;
* [[PDE- Why would anyone adopt?]]&lt;br /&gt;
* [[Personal Data Ecosystem Biz Models]]&lt;br /&gt;
* [[Using a Personal Data Store]]&lt;br /&gt;
* [[Value Network Mapping]]&lt;br /&gt;
* [[Personal Data Ecosystem Model 2]]&lt;br /&gt;
* [[Go To Market - PDE]]&lt;br /&gt;
* [[Go To Market PDE 2]]&lt;br /&gt;
* [[PDE - Go to Market and Community Strategy]]&lt;br /&gt;
* [[Personal Data Ecosystem Org Role]]&lt;br /&gt;
&lt;br /&gt;
== IIW Europe ==&lt;br /&gt;
&lt;br /&gt;
* [[What is the MYDEX Prototype?]]&lt;br /&gt;
* [[Federated Identity as a Business Model]]&lt;br /&gt;
* [[ Personal Data Store Harmonizing = Project Nori DEMO]]&lt;br /&gt;
* [[Issues About Profiling and Cross-Border Data Stores]]&lt;br /&gt;
* [[Personal Data Ecosystem.org]]&lt;br /&gt;
&lt;br /&gt;
== IIW East ==&lt;br /&gt;
&lt;br /&gt;
* [[PDX Ecosystem]]&lt;br /&gt;
* [[Personal Data Vision of Future: Video]]&lt;br /&gt;
* [[Personal Data Stores and Context Automation]]&lt;br /&gt;
* [[Personal Data Store/Archive]]&lt;br /&gt;
* [[Personal Data Locker? What is it and Why?]]&lt;br /&gt;
* [[Ownership Rights in Data Pt2]]&lt;br /&gt;
* [[Roadmap for Personal Data Store Ecology: Let's Make One]]&lt;br /&gt;
&lt;br /&gt;
== IIW 10 ==&lt;br /&gt;
&lt;br /&gt;
* [[Personal Data Stores]]&lt;br /&gt;
* [[VRM Parts &amp;amp; Whole]]&lt;br /&gt;
* [[Telco-Web-Data User Model Scenarios]]&lt;br /&gt;
* [[Personal Data Store Ecosystem Design]]&lt;br /&gt;
* [[Telco/Web/Data Meta Story]]&lt;br /&gt;
&lt;br /&gt;
== IIW 9 ==&lt;br /&gt;
&lt;br /&gt;
* [[Information_Sharing]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2919</id>
		<title>Personal Data Ecosystem-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2919"/>
		<updated>2010-11-16T03:38:00Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* IIW 9 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW 11 ==&lt;br /&gt;
&lt;br /&gt;
* [[Intro to PDS]] Mon, Session 1A &lt;br /&gt;
* [[Facebook as a Personal Data Store]] Mon Session 3A&lt;br /&gt;
* [[Personal Data Ecosystem]]&lt;br /&gt;
* [[PDE- Why would anyone adopt?]]&lt;br /&gt;
* [[Personal Data Ecosystem Biz Models]]&lt;br /&gt;
* [[Using a Personal Data Store]]&lt;br /&gt;
* [[Personal Data Ecosystem Model 2]]&lt;br /&gt;
* [[Go To Market - PDE]]&lt;br /&gt;
* [[Go To Market PDE 2]]&lt;br /&gt;
* [[PDE - Go to Market and Community Strategy]]&lt;br /&gt;
* [[Personal Data Ecosystem Org Role]]&lt;br /&gt;
&lt;br /&gt;
== IIW Europe ==&lt;br /&gt;
&lt;br /&gt;
* [[What is the MYDEX Prototype?]]&lt;br /&gt;
* [[Federated Identity as a Business Model]]&lt;br /&gt;
* [[ Personal Data Store Harmonizing = Project Nori DEMO]]&lt;br /&gt;
* [[Issues About Profiling and Cross-Border Data Stores]]&lt;br /&gt;
* [[Personal Data Ecosystem.org]]&lt;br /&gt;
&lt;br /&gt;
== IIW East ==&lt;br /&gt;
&lt;br /&gt;
* [[PDX Ecosystem]]&lt;br /&gt;
* [[Personal Data Vision of Future: Video]]&lt;br /&gt;
* [[Personal Data Stores and Context Automation]]&lt;br /&gt;
* [[Personal Data Store/Archive]]&lt;br /&gt;
* [[Personal Data Locker? What is it and Why?]]&lt;br /&gt;
* [[Ownership Rights in Data Pt2]]&lt;br /&gt;
* [[Roadmap for Personal Data Store Ecology: Let's Make One]]&lt;br /&gt;
&lt;br /&gt;
== IIW 10 ==&lt;br /&gt;
&lt;br /&gt;
* [[Personal Data Stores]]&lt;br /&gt;
* [[VRM Parts &amp;amp; Whole]]&lt;br /&gt;
* [[Telco-Web-Data User Model Scenarios]]&lt;br /&gt;
* [[Personal Data Store Ecosystem Design]]&lt;br /&gt;
* [[Telco/Web/Data Meta Story]]&lt;br /&gt;
&lt;br /&gt;
== IIW 9 ==&lt;br /&gt;
&lt;br /&gt;
* [[Information_Sharing]]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=2918</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Main_Page&amp;diff=2918"/>
		<updated>2010-11-16T03:35:59Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* Previous Internet Identity Workshops */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;Big&amp;gt; Welcome to the Internet Identity Workshop (IIW) Wiki &amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.internetidentityworkshop.com WE HAVE A WEBSITE/BLOG TOO!] &lt;br /&gt;
&lt;br /&gt;
* To get updates regarding IIW  [http://lists.idcommons.net/lists/info/iiwinfo subscribe here].&lt;br /&gt;
&lt;br /&gt;
[[Subject Specific Note Collections]]&lt;br /&gt;
&lt;br /&gt;
=== Next Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
IIW #12 will be in May of 2011.  Dates will be announced in December 2010.&lt;br /&gt;
&lt;br /&gt;
We are working on collaborating with our industry organizational peers on a community unconference before RSA on February 14th.&lt;br /&gt;
&lt;br /&gt;
We are considering hosting &amp;quot;Identity Open Space&amp;quot; events on the East Coast of the United States and in Europe in 2011.  Feel free to contact us if you are interested in helping/participating.  (kaliya (at) Mac.com) &lt;br /&gt;
&lt;br /&gt;
We have an [http://lists.idcommons.net/lists/subscribe/iiwinfo announcement list] that you can subscribe to if you would like to get an e-mail when new IIW &amp;amp; IOS events are announced.&lt;br /&gt;
&lt;br /&gt;
=== Previous Internet Identity Workshops ===&lt;br /&gt;
&lt;br /&gt;
* #11 Fall 2010 [[iiw11]] Nov 2-4, Tuesday-Thursday at the Computer HIstory Museum in Mountain View California&lt;br /&gt;
** [[Notes IIW11]]&lt;br /&gt;
** [http://www.internetidentityworkshop.com/what-is-iiw/ Responses to IIW is...] [http://www.internetidentityworkshop.com/iiw-values/ Values of IIW]&lt;br /&gt;
&lt;br /&gt;
* [[iiw-europe-1|IIW Europe]] in London Monday October 11 (before RSA Europe) at the University of London&lt;br /&gt;
** [[iiw-europe-1-Notes]]&lt;br /&gt;
** [[iiw-europe-1-Reflection]] As a Result of Today.... &lt;br /&gt;
&lt;br /&gt;
* [[iiw-east-1|IIW East Coast]] in DC September 9-10 Thursday, Friday at the Josephine Butler Parks Center (following the Gov 2.0 Summit) the theme will be ''Open Identity for Open Government'' &lt;br /&gt;
** [[Notes_IIW-East]]&lt;br /&gt;
** [[As a result of day 1 at IIW-East]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* #10: Spring 2010 [[iiw10]] May 17-19 at the Computer History Museum. &lt;br /&gt;
** [[Notes IIW10]]&lt;br /&gt;
&lt;br /&gt;
* #9: Fall 2009 [[iiw9]] TUESDAY November 3 to THURSDAY November 5. &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #8: Spring 2009 [[iiw8]] - '''May 18-20, 2009''' &lt;br /&gt;
** [[Notes_iiw9]]&lt;br /&gt;
&lt;br /&gt;
* #7: Fall [[iiw2008b]] (2008B)- '''Nov 10-12''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_08b]]&lt;br /&gt;
&lt;br /&gt;
* 6: Spring [[iiw2008a]]  (2008A)- '''May 12-14, 2008''' - Computer History Museum, Mountain View, CA&lt;br /&gt;
** [[Notes_2008a]]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.idcommons.net/index.php/Iiw2007b 5: December 3-5, 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop_2007 4: May 2007 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006b 3: December 2006 - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://iiw.windley.com/wiki/Workshop2006 2: May 2006 - - Computer History Museum, Mountain View, CA]&lt;br /&gt;
&lt;br /&gt;
* [http://www.socialtext.net/iiw2005/index.cgi?internet_identity_workshop_2005 1: October 2005 - Berkeley, CA]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Open Spaces ===&lt;br /&gt;
&lt;br /&gt;
Identity Open Space events are co-produced by the IIW team (Phil, Kaliya, Doc) in collaboration with other organizations and events. To date we have worked with Digital Identity World and the Liberty Alliance. We are open to working with a variety organizations - if you are interested please don't hesitate to contact us. &lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSF September 2007 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSBrussels May 2007 following a Liberty Alliance Meeting in Brussels, Belgium]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSSantaClara September 2006 at Digital Identity World]&lt;br /&gt;
&lt;br /&gt;
[http://ios.windley.com/wiki/IOSVan July 2006 following a Liberty Alliance Meeting in Vancouver, Canada]&lt;br /&gt;
&lt;br /&gt;
=== Previous Identity Birds of a Feather Meetings ===&lt;br /&gt;
&lt;br /&gt;
June 2006 [http://www.identitygang.org/ Identity Gang Birds of a Feather Session] at Burton Group Conference, San Francisco&lt;br /&gt;
&lt;br /&gt;
January 2006 [http://www.socialtext.net/iiw2005/index.cgi?identity_speed_geeking_o_reilly_emerging_telephony_conference Identity Speed Geeking Session] at O'Reilly's  Emerging Telephony Conference&lt;br /&gt;
&lt;br /&gt;
December 2005 [http://www.socialtext.net/iiw2005/index.cgi?informational_morning_for_developers Pre-Syndicate Informational Morning for Developers]&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2917</id>
		<title>Personal Data Ecosystem-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2917"/>
		<updated>2010-11-16T03:35:12Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* IIW East */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW 11 ==&lt;br /&gt;
&lt;br /&gt;
* [[Intro to PDS]] Mon, Session 1A &lt;br /&gt;
* [[Facebook as a Personal Data Store]] Mon Session 3A&lt;br /&gt;
* [[Personal Data Ecosystem]]&lt;br /&gt;
* [[PDE- Why would anyone adopt?]]&lt;br /&gt;
* [[Personal Data Ecosystem Biz Models]]&lt;br /&gt;
* [[Using a Personal Data Store]]&lt;br /&gt;
* [[Personal Data Ecosystem Model 2]]&lt;br /&gt;
* [[Go To Market - PDE]]&lt;br /&gt;
* [[Go To Market PDE 2]]&lt;br /&gt;
* [[PDE - Go to Market and Community Strategy]]&lt;br /&gt;
* [[Personal Data Ecosystem Org Role]]&lt;br /&gt;
&lt;br /&gt;
== IIW Europe ==&lt;br /&gt;
&lt;br /&gt;
* [[What is the MYDEX Prototype?]]&lt;br /&gt;
* [[Federated Identity as a Business Model]]&lt;br /&gt;
* [[ Personal Data Store Harmonizing = Project Nori DEMO]]&lt;br /&gt;
* [[Issues About Profiling and Cross-Border Data Stores]]&lt;br /&gt;
* [[Personal Data Ecosystem.org]]&lt;br /&gt;
&lt;br /&gt;
== IIW East ==&lt;br /&gt;
&lt;br /&gt;
* [[PDX Ecosystem]]&lt;br /&gt;
* [[Personal Data Vision of Future: Video]]&lt;br /&gt;
* [[Personal Data Stores and Context Automation]]&lt;br /&gt;
* [[Personal Data Store/Archive]]&lt;br /&gt;
* [[Personal Data Locker? What is it and Why?]]&lt;br /&gt;
* [[Ownership Rights in Data Pt2]]&lt;br /&gt;
* [[Roadmap for Personal Data Store Ecology: Let's Make One]]&lt;br /&gt;
&lt;br /&gt;
== IIW 10 ==&lt;br /&gt;
&lt;br /&gt;
* [[Personal Data Stores]]&lt;br /&gt;
* [[VRM Parts &amp;amp; Whole]]&lt;br /&gt;
* [[Telco-Web-Data User Model Scenarios]]&lt;br /&gt;
* [[Personal Data Store Ecosystem Design]]&lt;br /&gt;
* [[Telco/Web/Data Meta Story]]&lt;br /&gt;
&lt;br /&gt;
== IIW 9 ==&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2916</id>
		<title>Personal Data Ecosystem-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2916"/>
		<updated>2010-11-16T03:31:52Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* IIW Europe */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW 11 ==&lt;br /&gt;
&lt;br /&gt;
* [[Intro to PDS]] Mon, Session 1A &lt;br /&gt;
* [[Facebook as a Personal Data Store]] Mon Session 3A&lt;br /&gt;
* [[Personal Data Ecosystem]]&lt;br /&gt;
* [[PDE- Why would anyone adopt?]]&lt;br /&gt;
* [[Personal Data Ecosystem Biz Models]]&lt;br /&gt;
* [[Using a Personal Data Store]]&lt;br /&gt;
* [[Personal Data Ecosystem Model 2]]&lt;br /&gt;
* [[Go To Market - PDE]]&lt;br /&gt;
* [[Go To Market PDE 2]]&lt;br /&gt;
* [[PDE - Go to Market and Community Strategy]]&lt;br /&gt;
* [[Personal Data Ecosystem Org Role]]&lt;br /&gt;
&lt;br /&gt;
== IIW Europe ==&lt;br /&gt;
&lt;br /&gt;
* [[What is the MYDEX Prototype?]]&lt;br /&gt;
* [[Federated Identity as a Business Model]]&lt;br /&gt;
* [[ Personal Data Store Harmonizing = Project Nori DEMO]]&lt;br /&gt;
* [[Issues About Profiling and Cross-Border Data Stores]]&lt;br /&gt;
* [[Personal Data Ecosystem.org]]&lt;br /&gt;
&lt;br /&gt;
== IIW East ==&lt;br /&gt;
&lt;br /&gt;
== IIW 10 ==&lt;br /&gt;
&lt;br /&gt;
* [[Personal Data Stores]]&lt;br /&gt;
* [[VRM Parts &amp;amp; Whole]]&lt;br /&gt;
* [[Telco-Web-Data User Model Scenarios]]&lt;br /&gt;
* [[Personal Data Store Ecosystem Design]]&lt;br /&gt;
* [[Telco/Web/Data Meta Story]]&lt;br /&gt;
&lt;br /&gt;
== IIW 9 ==&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2915</id>
		<title>Personal Data Ecosystem-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2915"/>
		<updated>2010-11-16T03:29:28Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* IIW 11 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW 11 ==&lt;br /&gt;
&lt;br /&gt;
* [[Intro to PDS]] Mon, Session 1A &lt;br /&gt;
* [[Facebook as a Personal Data Store]] Mon Session 3A&lt;br /&gt;
* [[Personal Data Ecosystem]]&lt;br /&gt;
* [[PDE- Why would anyone adopt?]]&lt;br /&gt;
* [[Personal Data Ecosystem Biz Models]]&lt;br /&gt;
* [[Using a Personal Data Store]]&lt;br /&gt;
* [[Personal Data Ecosystem Model 2]]&lt;br /&gt;
* [[Go To Market - PDE]]&lt;br /&gt;
* [[Go To Market PDE 2]]&lt;br /&gt;
* [[PDE - Go to Market and Community Strategy]]&lt;br /&gt;
* [[Personal Data Ecosystem Org Role]]&lt;br /&gt;
&lt;br /&gt;
== IIW Europe ==&lt;br /&gt;
&lt;br /&gt;
== IIW East ==&lt;br /&gt;
&lt;br /&gt;
== IIW 10 ==&lt;br /&gt;
&lt;br /&gt;
* [[Personal Data Stores]]&lt;br /&gt;
* [[VRM Parts &amp;amp; Whole]]&lt;br /&gt;
* [[Telco-Web-Data User Model Scenarios]]&lt;br /&gt;
* [[Personal Data Store Ecosystem Design]]&lt;br /&gt;
* [[Telco/Web/Data Meta Story]]&lt;br /&gt;
&lt;br /&gt;
== IIW 9 ==&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2914</id>
		<title>Personal Data Ecosystem-Notes</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Data_Ecosystem-Notes&amp;diff=2914"/>
		<updated>2010-11-16T03:24:26Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: /* IIW 10 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== IIW 11 ==&lt;br /&gt;
&lt;br /&gt;
== IIW Europe ==&lt;br /&gt;
&lt;br /&gt;
== IIW East ==&lt;br /&gt;
&lt;br /&gt;
== IIW 10 ==&lt;br /&gt;
&lt;br /&gt;
* [[Personal Data Stores]]&lt;br /&gt;
* [[VRM Parts &amp;amp; Whole]]&lt;br /&gt;
* [[Telco-Web-Data User Model Scenarios]]&lt;br /&gt;
* [[Personal Data Store Ecosystem Design]]&lt;br /&gt;
* [[Telco/Web/Data Meta Story]]&lt;br /&gt;
&lt;br /&gt;
== IIW 9 ==&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Personal_Data_Store_Ecosystem_Design&amp;diff=2913</id>
		<title>Personal Data Store Ecosystem Design</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Personal_Data_Store_Ecosystem_Design&amp;diff=2913"/>
		<updated>2010-11-16T03:24:04Z</updated>

		<summary type="html">&lt;p&gt;IdentityWoman: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Session:''' Wednesday, Session 1 Space A&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw10 IIW 10]  May 17-19, 2009 this is the complete [http://iiw.idcommons.net/Notes_IIW10 Complete Set of Notes ]&lt;br /&gt;
&lt;br /&gt;
Convener: Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
We saw 8 different potential/existing models presented&lt;br /&gt;
&lt;br /&gt;
(see photos)&lt;br /&gt;
&lt;br /&gt;
We asked people to articulate what they saw in common between these models and what was different. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
COMMON&lt;br /&gt;
* User control of information “user data vault” or centralized store of personal information&lt;br /&gt;
* Not a technical issue&lt;br /&gt;
* Business Case is the Question&lt;br /&gt;
* Assumption that individual control and privacy is desirable&lt;br /&gt;
* Right to User Activity Digital&lt;br /&gt;
* User owns his/her data&lt;br /&gt;
** user data vault&lt;br /&gt;
** privacy bank&lt;br /&gt;
** personal data store (PDS)&lt;br /&gt;
* Telco as IdP: Nat’s, Christies’ Pauls, Rolf’s Marc’s&lt;br /&gt;
* Dashboard usability?&lt;br /&gt;
* Need to reset control thermostat between service providers + users&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
DIFFERENT&lt;br /&gt;
* User Centric “Identity”&lt;br /&gt;
* Personal Data Store Central or Distributed&lt;br /&gt;
* Not Common: Different Business models - who pays whom&lt;br /&gt;
* Mechanisms to Manage Change&lt;br /&gt;
* To Datastore or not to Datastore?&lt;br /&gt;
* Value-Chain from User Perspective (where is Gov?)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
QUESTION:&lt;br /&gt;
* How is Money $ Made?&lt;br /&gt;
* Best Route to Bootstrap?&lt;br /&gt;
* Regulation&lt;br /&gt;
* Leverage “right” big elephant&lt;br /&gt;
* create the right consortium&lt;br /&gt;
* right business model&lt;br /&gt;
* Personal Data Stored in a “BANK” or under my mattress (&amp;amp; I can still participate)&lt;br /&gt;
* How Many Data Vaults, Exchanges (Competitive?)&lt;br /&gt;
* Telcos or New Org?&lt;br /&gt;
* Which Data?&lt;br /&gt;
* User Value Explain to the average user?&lt;br /&gt;
* People Not on the Grid Yet? (Kenyan Farmer) (Identity Place Holder)&lt;br /&gt;
* Responsibility of user in understanding what is in the PDS and how it will be used. Is that reasonable?&lt;br /&gt;
* Data as “money” to be “exchanged” Except data is more nuanced, which needs to be understood&lt;br /&gt;
* If not understood by the user, it invites explanation by the company.&lt;br /&gt;
* Different Emphasis on AuthN and Attributes (how do telco’s off to others)&lt;br /&gt;
* Role of Regulator?&lt;br /&gt;
* Privacy as a Toxic Asset. But How do we Launder it. (Private data store? Say its dead? or not collect?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
COMMENTS:&lt;br /&gt;
* PDS = User Data Vault&lt;br /&gt;
* Eat their own dogfood?&lt;br /&gt;
* New Rolls - Data Broker, Data Lawyer&lt;br /&gt;
* Economic Power ($ Euro Yen)  (Telco-Webco- Banks) Marketing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ASSUMPTION:&lt;br /&gt;
* The Network is a free cost less ubiquitous resource (not true)&lt;br /&gt;
&lt;br /&gt;
Store - PDS, UDB, “Vault”&lt;br /&gt;
&lt;br /&gt;
Collecting - implicit - behavioral tracking, GPS, Search&lt;br /&gt;
&lt;br /&gt;
Implicit - VPI, Lists&lt;br /&gt;
&lt;br /&gt;
Sharing - PDX/UDE&lt;br /&gt;
&lt;br /&gt;
Rule Set Store&lt;br /&gt;
&lt;br /&gt;
Control and Contract&lt;br /&gt;
&lt;br /&gt;
Interfaces&lt;br /&gt;
&lt;br /&gt;
open standards&lt;br /&gt;
&lt;br /&gt;
regulations&lt;br /&gt;
&lt;br /&gt;
context&lt;br /&gt;
&lt;br /&gt;
granularity&lt;br /&gt;
&lt;br /&gt;
Regulation&lt;br /&gt;
&lt;br /&gt;
Slows things down&lt;br /&gt;
&lt;br /&gt;
Vault does not equal exchange&lt;br /&gt;
&lt;br /&gt;
Personal Data Store&lt;br /&gt;
&lt;br /&gt;
marketing?&lt;br /&gt;
&lt;br /&gt;
on phone?&lt;br /&gt;
&lt;br /&gt;
syncrhonized?&lt;br /&gt;
&lt;br /&gt;
portable? / sharable? templates&lt;br /&gt;
&lt;br /&gt;
Is Data Really Centralized? (not necessarily)&lt;/div&gt;</summary>
		<author><name>IdentityWoman</name></author>
		
	</entry>
</feed>