<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Igiwydijok</id>
	<title>IIW - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://iiw.idcommons.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Igiwydijok"/>
	<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/Special:Contributions/Igiwydijok"/>
	<updated>2026-06-10T08:53:33Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.6</generator>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=OpenID-Artifact_Binding&amp;diff=3381</id>
		<title>OpenID-Artifact Binding</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=OpenID-Artifact_Binding&amp;diff=3381"/>
		<updated>2010-11-24T10:24:20Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://enececufo.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
'''Session:''' Tuesday Session 4 Space O&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw10 IIW 10]  May 17-19, 2009 this is the complete [http://iiw.idcommons.net/Notes_IIW10 Complete Set of Notes ]&lt;br /&gt;
&lt;br /&gt;
Topic: OpenID Artifact Binding&lt;br /&gt;
&lt;br /&gt;
Convener: Nat, Breno, John.B&lt;br /&gt;
&lt;br /&gt;
* AB designs for scalable and stateless. It works with mobile phones.&lt;br /&gt;
* With AB, OpenID can support up to NIST SP800-63(rev1) L2 - L4 because the assertions are sent in the direct communication channel between OP and RP.&lt;br /&gt;
* Asymmetric key signing and encryption will protect the threat defined in L3 - L4.&lt;br /&gt;
* RP can choose 2 types of the request mode:&lt;br /&gt;
&lt;br /&gt;
1. Push: Encoded request messsage sent to OP (POST)&lt;br /&gt;
&lt;br /&gt;
2. Pull: Prepare RPF(JSON) msg and let know OP only the URL to the msg&lt;br /&gt;
&lt;br /&gt;
* The Assertion is also in JSON instead of key-value form encoding in 2.0.&lt;br /&gt;
* OP implementation in PHP is now around 400 lines of code! RP is 200 including even HTML part.&lt;br /&gt;
* For digital signing, &amp;amp;quot;Magic Signature&amp;amp;quot; is used. (to get LoA 2 - 3).&lt;br /&gt;
* Encryption:&lt;br /&gt;
&lt;br /&gt;
1. Symmetric key encryption for encrypting &amp;amp;quot;Artifact&amp;amp;quot;.&lt;br /&gt;
 &lt;br /&gt;
2. Asymmetric key encryption for encrypting &amp;amp;quot;Assertion&amp;amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* URL for RPF can be published in XRDS.&lt;br /&gt;
* RPF can be cached in OP until updated.&lt;br /&gt;
* The &amp;amp;quot;Holder of Key&amp;amp;quot; parameter in the assertion for storing user's cert used for PKI based authentication. (In order to meet LoA4)&lt;br /&gt;
* The &amp;amp;quot;Pull&amp;amp;quot; mode is required for mobile phone not capable for JavaScript.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Stateless_Distributed_Membership_an_Inquiry&amp;diff=3380</id>
		<title>Stateless Distributed Membership an Inquiry</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Stateless_Distributed_Membership_an_Inquiry&amp;diff=3380"/>
		<updated>2010-11-24T10:24:13Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ocavyle.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
'''Session:''' Wed Session 2 Space E&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw10 IIW 10]  May 17-19, 2009 this is the complete [http://iiw.idcommons.net/Notes_IIW10 Complete Set of Notes ]&lt;br /&gt;
&lt;br /&gt;
Convener: Judi Clark &lt;br /&gt;
&lt;br /&gt;
Note-taker(s): Judi Clark&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' &lt;br /&gt;
&lt;br /&gt;
openID, identity, personal data store, user-managed access, access control, social expectations, how things work, multiple identities, experiment&lt;br /&gt;
&lt;br /&gt;
'''Notes:'''&lt;br /&gt;
&lt;br /&gt;
We explored the possibility of creating a membership site that does not have a traditional membership database (user names, passwords) but instead uses OpenID (or similar) and personal data stores to contribute to the site. A lot of the underlying tools/technology exists already. &lt;br /&gt;
&lt;br /&gt;
* Eve M has spoken about ID data statelessness and this concept is related.&lt;br /&gt;
&lt;br /&gt;
Access to the site (example): OpenID, location to personal data store, and default designation of sharing policy. Sharing policy might include, for example:&lt;br /&gt;
* Sharing: A. Sharing; B. Others in this thread; C. Specific others&lt;br /&gt;
* Storage: 1. cache &amp;amp;amp; call to update, 2. no cache; 3. X days; 4. Permanent until revoked&lt;br /&gt;
&lt;br /&gt;
* Related concept: cache and update&lt;br /&gt;
* Recommended reading: Future of Reputation (Solove)&lt;br /&gt;
&lt;br /&gt;
'''First example: Forum/Conversation'''&lt;br /&gt;
&lt;br /&gt;
My server stores a unique transaction record key, the openID &amp;amp;amp; policy statement, and other pointers relevant to the specific interaction. For example: if visitors are contributing to a forum or ongoing conversation, my server may have a time/date/conversation ID stamp (each contribution is stored on the visitor's own personal data store (PDS); my server assembles the conversation according to stated policies and availability of visitor PDSs. &lt;br /&gt;
&lt;br /&gt;
* Example of distributed conversations: blog posts and trackbacks&lt;br /&gt;
* important underlying concept: Operational Transformation (wikipedia)&lt;br /&gt;
* Might try installing a version of Google Wave/Jupiter to start&lt;br /&gt;
&lt;br /&gt;
'''Second example: Personal RFPs'''&lt;br /&gt;
&lt;br /&gt;
Similar to a job board or public wish list, my server might offer a commons area which points to Personal Requests for Proposal (RFP) for something that someone wants or offers. A common template for an RFP might include a title, description, price, and way to reach requestor, stored on the requestor's PDS. My server tracks the pointer to the PDS that holds the RFP, a community caution flag, the REL button status, and an expiration date. &lt;br /&gt;
&lt;br /&gt;
General consensus that this was an interesting problem from social angle as well as having many tools that might be applicable. Many of the social norms and expectations have to be discovered or developed &amp;amp;amp; discussed.&lt;br /&gt;
&lt;br /&gt;
Thanks for the very constructive questions, suggestions and observations at this session!&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:OpenID-Artifact_Binding&amp;diff=3379</id>
		<title>Talk:OpenID-Artifact Binding</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:OpenID-Artifact_Binding&amp;diff=3379"/>
		<updated>2010-11-24T10:23:53Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://enececufo.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
----&lt;br /&gt;
=[http://enececufo.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Stateless_Distributed_Membership_an_Inquiry&amp;diff=3378</id>
		<title>Talk:Stateless Distributed Membership an Inquiry</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Stateless_Distributed_Membership_an_Inquiry&amp;diff=3378"/>
		<updated>2010-11-24T10:23:46Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ocavyle.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ocavyle.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Distributed_Identity_Based_on_Relationships&amp;diff=3377</id>
		<title>Talk:Distributed Identity Based on Relationships</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Distributed_Identity_Based_on_Relationships&amp;diff=3377"/>
		<updated>2010-11-24T10:22:37Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '=[http://ebytery.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]='&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ebytery.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Browser_Extension_Convergence&amp;diff=3375</id>
		<title>Browser Extension Convergence</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Browser_Extension_Convergence&amp;diff=3375"/>
		<updated>2010-11-24T09:54:50Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ybyfonojot.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
'''Convener and Note Taker:''' Paul Trevithick&lt;br /&gt;
&lt;br /&gt;
We had a session on trying to converge towards a single browser extension for these four browsers: IE, FF, Safari, Chrome. Or, at least that’s how it started off. &lt;br /&gt;
&lt;br /&gt;
Today we’ve got lots of browser extensions for different browsers each of which generally supports a specific protocol (e.g. OpenID or I-Card or…). What we’d like to get to is having one multi-protocol browser extension for each browser–that is, a total of four extensions. And eventually, we’d like to see these built into the browsers themselves. &lt;br /&gt;
&lt;br /&gt;
We started by creating a quick inventory of the existing browser extensions:&lt;br /&gt;
# Firefox: Sxipper (OpenID, UN/PW)&lt;br /&gt;
# Firefox: Higgins: HBX4FF (I-Card)&lt;br /&gt;
# Firefox: OpenInfoCard (I-Card)&lt;br /&gt;
# Firefox: DigitalMe (I-Card)&lt;br /&gt;
# Firefox: OpenLiberty (SAML)&lt;br /&gt;
# Firefox: Verisign Seatbelt (OpenID)&lt;br /&gt;
# Firefox: IDIB (OpenID…)&lt;br /&gt;
# IE: Microsoft’s I-Card built-in&lt;br /&gt;
# IE: Higgins: HBX4IE&lt;br /&gt;
&lt;br /&gt;
We then made a list of protocol “families” that we think each extension should support:&lt;br /&gt;
# Username/Password (Form-based, HTTP Auth, WS-Security)&lt;br /&gt;
# OpenID (OpenID, SAML)&lt;br /&gt;
# I-Card (ISIP‡IMI-TC)&lt;br /&gt;
# Kerberos&lt;br /&gt;
# SAML (SAML SSO, SAML ECP)&lt;br /&gt;
 &lt;br /&gt;
We also made a list of possible “packaging” options for these extensions, though this didn’t really lead to any discussion:&lt;br /&gt;
# Browser-native add-on/extension/plug-in&lt;br /&gt;
# Flash&lt;br /&gt;
# Java&lt;br /&gt;
# Gears&lt;br /&gt;
# Silverlight&lt;br /&gt;
 &lt;br /&gt;
We discovered that there was an opportunity to first agree on the specifications for auth discovery across protocols. This became the next part of the meeting…&lt;br /&gt;
 &lt;br /&gt;
Part 2: Browser Support for RP Auth Discovery&lt;br /&gt;
Everyone agreed that creating common specs for this was a good idea, whether or not they were interested in creating implementations. We saw that we could use XRDS as the basis for discovery of a relying party (RP) site’s authentication support for multiple protocols. The RP site would publish an XRDS document that would allow a “smart client” (well, a browser extension) to discover information about what protocols were supported and how they might be used to authenticate to the site. &lt;br /&gt;
 &lt;br /&gt;
Today I-Card tech embeds an HTML &amp;amp;lt;object&amp;amp;gt; tag, but Axel Nennker has put forward here [1] and here [2] a variation where instead of an embedded &amp;amp;lt;object&amp;amp;gt; tag we use a link/rel approach. Meanwhile, Scott Kventon and other OpenID folks have also been looking at using XRDS to discover RP auth metadata. In a similar manner XRDS SEPs could be defined for SAML, UN/PW and Kerberos. &lt;br /&gt;
&lt;br /&gt;
So the consensus was that we should pursue this common approach to RP Auth Discovery.&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
[1]http://ignisvulpis.blogspot.com/2008/10/information-cards-with-xrds.html&lt;br /&gt;
&lt;br /&gt;
[2]http://iiw.idcommons.net/Iiw2008b_XRDS_for_OpenId_and_Information_Cards_and_other_%22Services%22&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Browser_Extension_Convergence&amp;diff=3374</id>
		<title>Talk:Browser Extension Convergence</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Browser_Extension_Convergence&amp;diff=3374"/>
		<updated>2010-11-24T09:54:25Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ybyfonojot.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ybyfonojot.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Attribute_eXchange&amp;diff=3372</id>
		<title>Attribute eXchange</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Attribute_eXchange&amp;diff=3372"/>
		<updated>2010-11-24T09:26:50Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://imygijesusy.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
OpenID Attribute Exchange v.1.x , 2.0 (2A)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Nat Sakimura, NRI&lt;br /&gt;
'''Notes-taker(s):''' Tatsuki Sakushima, NRI&lt;br /&gt;
&lt;br /&gt;
'''Attendees:'''&lt;br /&gt;
* Nat Sakimura (NRI)&lt;br /&gt;
* Dick Hardt (Microsoft)&lt;br /&gt;
* Henrik Biering (Netamia)&lt;br /&gt;
* Mike Hansen (Mozilla)&lt;br /&gt;
* Andrew Arnott (Microsoft)&lt;br /&gt;
* Will Noris (Internet2)&lt;br /&gt;
* Ragavan Srinivasan (Mozilla) &lt;br /&gt;
* Breno de Medeiros (Google)&lt;br /&gt;
* Ilan Caron (Google)&lt;br /&gt;
* Hannes Tschofenig (Nokia Siemens Networks)&lt;br /&gt;
* Bharath Kumar (Amazon)&lt;br /&gt;
* Tatsuki Sakushima (NRI)&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' &lt;br /&gt;
* OpenID Attribute Exchange Protocol and Syntax&lt;br /&gt;
* Not Schema!&lt;br /&gt;
&lt;br /&gt;
'''Session Slides:''' http://docs.google.com/present/view?id=dhsz4ffx_160d4mqqkc3&lt;br /&gt;
&lt;br /&gt;
'''AX 1.1? and beyond'''=nat (Nat Sakimura)&lt;br /&gt;
&lt;br /&gt;
'''Issues raised in AX 1.0'''&lt;br /&gt;
* Introduce the concept of more generic schema for sending/requesting properties about attributes.&lt;br /&gt;
** '''Class:''' The new attribute property schemas attach to specific attribute types.&lt;br /&gt;
*** Each attribute property schema is bound to a unique attribute-type namespace, can be described by a standard key string (does not need to be defined through a URL value).&lt;br /&gt;
** '''Query-Response:''' Attribute property values can be transmitted within any request or response type, allowing communication of attribute properties in both directions in direct and indirect communication request/response pairs.&lt;br /&gt;
* '''Direct Communication:''' Introduce a direct communication method in both directions (OP&amp;amp;lt;-&amp;amp;gt;RP), supported via discovery, for bulk exchange of attributes about (potentially) multiple users.&lt;br /&gt;
* '''Privacy Policy/Sreg features:''' Update AX to include support for RPs to send a link to their site's privacy policy to the OP. This feature is currently supported in SREG 1.0 and was omitted in AX 1.0.&lt;br /&gt;
&lt;br /&gt;
'''Approach to solve these issues in AX 1.0'''&lt;br /&gt;
&lt;br /&gt;
'''Class'''&lt;br /&gt;
* Now: e.g. &lt;br /&gt;
** ax.type.fname=http://schemas.openid.net/name/first&lt;br /&gt;
** ax.fname.value=Nat&lt;br /&gt;
** ax.type.lname=http://schemas.openid.net/name/last&lt;br /&gt;
** ax.lname.value=Sakimura&lt;br /&gt;
** etc. &lt;br /&gt;
* New: &lt;br /&gt;
** ax.type.name=http://schemas.openid.net/opensocial.name&lt;br /&gt;
** ax.name.family_name=Sakimura&lt;br /&gt;
** ax.name.given_name=Nat&lt;br /&gt;
&lt;br /&gt;
'''Query-Response: Request / Response AX '''&lt;br /&gt;
$ diff openid-attribute-exchange.xml oax1.1.xml &lt;br /&gt;
793a794,796&lt;br /&gt;
&amp;amp;gt; 		 &amp;amp;lt;t&amp;amp;gt;&lt;br /&gt;
&amp;amp;gt; 			In addition, any parameter values may be sent with the Response as in Fetch Response. &lt;br /&gt;
&amp;amp;gt; 		 &amp;amp;lt;/t&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
This one line change will allow us to send data to OP and get back the processed data back in the response. &lt;br /&gt;
&lt;br /&gt;
Or: Parameter to Fetch Request? --&amp;amp;gt; This seems to be better way. &lt;br /&gt;
&lt;br /&gt;
'''Direct Communication'''&lt;br /&gt;
* Solved in Artifact Binding&lt;br /&gt;
* Privacy Policy URL&lt;br /&gt;
* In SREG: openid.sreg.policy_url can be specified in the request. &lt;br /&gt;
* In AX 1.0, it cannot, because you have no way of sending such data in fetch request, nor way to fetch data via Store request. &lt;br /&gt;
* If Store request can also fetch data, the problem is solved: Just the matter of defining standard type URI for privacy policy. &lt;br /&gt;
* i.e., &amp;amp;quot;Bidirectional&amp;amp;quot; solves the problem. &lt;br /&gt;
&lt;br /&gt;
'''Next Steps'''&lt;br /&gt;
Finish Easy things first, then move onto harder topic. &lt;br /&gt;
&lt;br /&gt;
AX 1.1&lt;br /&gt;
* Add parameter to Fetch Request. &lt;br /&gt;
* Privacy Policy Advertisement&lt;br /&gt;
AX 2.0&lt;br /&gt;
* More efficient Schema&lt;br /&gt;
* Data format: XML or JSON?&lt;br /&gt;
&lt;br /&gt;
'''''Discussion:'''''&lt;br /&gt;
* AX Protocol Proposals and Issues from Nat.&lt;br /&gt;
* There are lots of interests in “schema” and “schema registory” but not be covered here.&lt;br /&gt;
* Make it more generic. 4 areas to improve:&lt;br /&gt;
# Class&lt;br /&gt;
# Query Response&lt;br /&gt;
# Direct Communication&lt;br /&gt;
# Privacy Policy&lt;br /&gt;
* Avoid key/value pair(limited capability) and support richer data structures/formats like XML or JSON.&lt;br /&gt;
* Also “direct communication” and “different syntax for request and response” are required to make this happen.&lt;br /&gt;
* Metadata for attributes like “verified email or just email” → a schema issue? But at least a new format and syntax provide spaces for metadata. &lt;br /&gt;
* How to implment a notification service for geolocation in AX? → unsolicited assertion to update_url can be used.&lt;br /&gt;
* Is “Privacy Policy” is metadata? → policy_url for Terms of Conditions of Attributes given to RP like Sreg has. The group agreed on this addition to AX.&lt;br /&gt;
* Should Policy URL is in a signed request or written in XRD to be fetched from RP? → Artifact binding or Contract Exchange for making a signed request.&lt;br /&gt;
* Query Response is used to store and fetch data in the same time. → Need richer syntax for a fetch request.&lt;br /&gt;
	&lt;br /&gt;
'''Next Steps:'''&lt;br /&gt;
# Class. → Go for it! Support XML, JSON not only a key/value pair.&lt;br /&gt;
# Syntax → Make richer.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Horoskop_skorpion_i_lew&amp;diff=3371</id>
		<title>Talk:Horoskop skorpion i lew</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Horoskop_skorpion_i_lew&amp;diff=3371"/>
		<updated>2010-11-24T09:26:49Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ajycyvitik.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ajycyvitik.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=What_are_the_Business_Models_of_ID_Conference&amp;diff=3370</id>
		<title>What are the Business Models of ID Conference</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=What_are_the_Business_Models_of_ID_Conference&amp;diff=3370"/>
		<updated>2010-11-24T09:26:37Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://yjucofi.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
'''Conversants:''' Kaliya Hamlin, Louie Gasperini, Stephen ''who works with Phil'' &lt;br /&gt;
&lt;br /&gt;
We talked about the lack of business people at the conference and the NEED to figure out the business models.&lt;br /&gt;
&lt;br /&gt;
We thought a highly focused 1.5-2 day event this winter could help move this conversation forward. &lt;br /&gt;
&lt;br /&gt;
We decided to go forward with an invitation and finding a place. Likely dates are late Feb early March.&lt;br /&gt;
&lt;br /&gt;
Likely place in the mountains.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Action_Card_Ideas_iiw9&amp;diff=3369</id>
		<title>Action Card Ideas iiw9</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Action_Card_Ideas_iiw9&amp;diff=3369"/>
		<updated>2010-11-24T09:26:35Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://olitudyxej.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
== What is an Action Card? ==&lt;br /&gt;
You can think of an action card as an in-browser, user-centric mashup. Think about augmenting / changing any web page, using some other data source. Here are some examples:&lt;br /&gt;
* '''AAA''' - search results on Google, Yahoo! and Bing are augmented by showing the AAA logo next to listings for businesses that offer AAA discounts. [http://www.azigo.com/demo/aaawa/index.html See Demo]&lt;br /&gt;
* '''Minuteman Library''' - when browsing books on Amazon.com, barnesandnoble.com, or Borders.com, if the book you are browsing (or an ~ equivalent ISBN) is available in your local library, then a notification box is shown, with a link to the online card catalog. [http://www.azigo.com/demo/mln/index.html See Demo]&lt;br /&gt;
* '''WBUR''' - This helps me direct my shopping spending to help support my local NPR station. This Action card augments search results similar to AAA, but also add a box at the top of search results (like a paid search box), with merchants that are WBUR underwriters. In addition, if I go to a competitor of one of WBUR's underwriters, a notification will suggest that I go to the WBUR underwriter instead. [http://www.azigo.com/landing/wbur/demo/index.html See Demo]&lt;br /&gt;
&lt;br /&gt;
== Ideas Submitted at IIW9 &amp;amp;amp; other ==&lt;br /&gt;
* '''Twitter silent unfollow''' - adds a 'silent unfollow' feature (removes tweets from select users from display, without actually un-following them). &lt;br /&gt;
* '''MySpace Facebook Skin''' - reskin MySpace using the Facebook styles. &lt;br /&gt;
* '''Google Paid Search closer''' - Make the paid search box at the top of Google results into an 'accordian' - user can open/close.&lt;br /&gt;
&lt;br /&gt;
== Prize ==&lt;br /&gt;
[[File:Shuffle.jpg]] Green iPod Shuffle Gen 2&lt;br /&gt;
&lt;br /&gt;
This is a classic, no longer widely available. Unlike the Gen 3 Shuffle, this works with standard headphones! Engraved &amp;amp;quot;Thank you from azigo.com&amp;amp;quot;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Selling_to_Consumers&amp;diff=3368</id>
		<title>Selling to Consumers</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Selling_to_Consumers&amp;diff=3368"/>
		<updated>2010-11-24T09:26:30Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ovarynetyv.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ovarynetyv.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
'''Convener:''' Phil Wolff&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Paul Osman&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' &lt;br /&gt;
&lt;br /&gt;
OpenID, Identity, Data Portability, Evangelism, Marketing, Political Activism&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:''' &lt;br /&gt;
&lt;br /&gt;
* Who to evangelize to? B2B or B2C? &lt;br /&gt;
* Most efforts so far have been targeted towards site operators (B2B).&lt;br /&gt;
* B2B evangelism is still beneficial. Rely on them to educate consumers about benefits / value / etc. (Teach the teacher). &lt;br /&gt;
* How to market to consumers? Message is confusing (Too many choices!). &lt;br /&gt;
* How to simplify the stack (easy to implement, easy to use). &lt;br /&gt;
* What distribution / marketing channels to use? &lt;br /&gt;
**  We're an industry. Do we need a foundation (is it OpenID?)&lt;br /&gt;
**  What's been successful? Media (Fear mongering)&lt;br /&gt;
** Inject the message into the user experience (i.e. remember sites directing users to update insecure browsers). &lt;br /&gt;
* Successful case studies (EV Certs, Creative Commons, Privacy Policies)&lt;br /&gt;
* Parallel with history of credit cards (i.e. used to be one per merchant, then VISA and MC convinced users that “membership had benefits”). &lt;br /&gt;
* Progressive disclosure: Don't expose everything to the user at once. Ease them in.&lt;br /&gt;
* Start with low risk but high value (i.e. start with friendfeed, not banks). &lt;br /&gt;
* Messages: &lt;br /&gt;
** “Safe Identity”&lt;br /&gt;
** “Let My Data Go!” - Agit-prop campaign, make consumers demand it&lt;br /&gt;
** “Membership Has Its Benefits!” - VISA and Mastercard approach (it's a club!)&lt;br /&gt;
* Next Steps:&lt;br /&gt;
** Get to the root of the problem (data portability? Identity?)&lt;br /&gt;
** Solve the cognitive gap (Life Identity vs. Accounts)&lt;br /&gt;
** Participants exchanged email addresses, another session proposed.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Design_Team&amp;diff=3367</id>
		<title>Design Team</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Design_Team&amp;diff=3367"/>
		<updated>2010-11-24T09:26:21Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://egebyromedu.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://egebyromedu.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
9AM pacific Day Light time&lt;br /&gt;
&lt;br /&gt;
1 (906) 481-2100&lt;br /&gt;
&lt;br /&gt;
942276&lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Help people connect and to keep the community collaborating.&lt;br /&gt;
&lt;br /&gt;
Moving from &amp;amp;quot;they&amp;amp;quot; to &amp;amp;quot;we&amp;amp;quot; -- Have people feel like they belong to the community, which in turn encourages proactive participation   Want people to co-own things.&lt;br /&gt;
&lt;br /&gt;
* Explain the concrete opportunities for involvement.&lt;br /&gt;
* Clarifying community process (Identity Commons) for moving forward on things. Want it to get adopted to some extent.&lt;br /&gt;
&lt;br /&gt;
Be a valuable experience for both new and old community members.&lt;br /&gt;
&lt;br /&gt;
* Encourage cross-fertilization&lt;br /&gt;
* Get stuff done, but also larger weaving together of things.&lt;br /&gt;
&lt;br /&gt;
More talent at the untalent show.&lt;br /&gt;
&lt;br /&gt;
* Intro to OSIS, marketing messages, state of the industry&lt;br /&gt;
* OSIS Interop - Actual interop with sites still up from Barcelona Catalyst Interop, F2F to continue to resolve both interop connections and deeper dive into specific features; plan for RSA 2008 Interop&lt;br /&gt;
* Meetings between Relying Parties, Card Selectors, Identity Providers&lt;br /&gt;
&lt;br /&gt;
= Community Axes =&lt;br /&gt;
&lt;br /&gt;
Three axes of this:&lt;br /&gt;
&lt;br /&gt;
* shared language&lt;br /&gt;
** shared Map/landscape&lt;br /&gt;
* shared values&lt;br /&gt;
* connectedness&lt;br /&gt;
&lt;br /&gt;
Would help if people self-identified where they were along these axes.&lt;br /&gt;
&lt;br /&gt;
Customers are confused.  industry in a great position to help craft unified message.  We surface coherence when it's there (and incoherence). Don't need full alignment.&lt;br /&gt;
&lt;br /&gt;
= Who do we want to be there? =&lt;br /&gt;
&lt;br /&gt;
What is the Unique Value: Direct interaction with the Experts on this subject at IIW&lt;br /&gt;
meeting with companies 'leading experts' and answer a lot of questions. &lt;br /&gt;
&lt;br /&gt;
* Product Managers&lt;br /&gt;
* Involved in Federated Space&lt;br /&gt;
* Vertical Clusters - Health Care,  Insurance&lt;br /&gt;
* Leading thinkers in this space&lt;br /&gt;
* Architects&lt;br /&gt;
* People not primarily techies&lt;br /&gt;
* Biz dev&lt;br /&gt;
* Bloggers / traditional media folks&lt;br /&gt;
* People who attended &amp;amp;quot;prematurely&amp;amp;quot; in the past&lt;br /&gt;
* Data sharing community&lt;br /&gt;
&lt;br /&gt;
Why aren't they coming?&lt;br /&gt;
&lt;br /&gt;
* Not being publicized through mainstream places.&lt;br /&gt;
* Part of the character of the event is that the invitations are in-person.  We need to honor this.&lt;br /&gt;
&lt;br /&gt;
What blogs should we publicize through?&lt;br /&gt;
&lt;br /&gt;
* Podcast on ReadWriteWeb (via Sean)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What other events can we be talking about this?&lt;br /&gt;
&lt;br /&gt;
* Gartner Identity Show (November 15?)&lt;br /&gt;
* Defrag&lt;br /&gt;
&lt;br /&gt;
Go through previous attendees&lt;br /&gt;
&lt;br /&gt;
* Figure out who they are&lt;br /&gt;
* Ask them to invite someone&lt;br /&gt;
&lt;br /&gt;
= Traditions / Rituals =&lt;br /&gt;
&lt;br /&gt;
'''Orientation for people new to user-centric identity''' on the first day.  Outlining majore initiatives in the community.&lt;br /&gt;
&amp;amp;quot;Where we have come from and where we are at&amp;amp;quot;  this will enable people to participate fully in the Open Space on Tuesday and Wednesday engaging in conversations about &amp;amp;quot;where we are at and where we are going.&amp;amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Speed Geeking''' a way to see a range of working products in the community.  There are demonstration stations throughout the room.  Those not demoing split up into groups of 4-6 and go to a demo station.  Then every 5 min move on to a new station. &lt;br /&gt;
&lt;br /&gt;
'''Technical Interop Sessions''' - extended time to just get stuff to work. &lt;br /&gt;
&lt;br /&gt;
'''Open Space Technology'''  - We collect proposed topics on a wiki ahead of time but actually create the agenda the day we meet. Those wishing to present write the name of the session down on a 8x11 sheet of paper (landscape) anouce it to the group and place it in the time/space grid.&lt;br /&gt;
&lt;br /&gt;
Eating Dinner Together - sharing a meal and socializing is part of being in the community.&lt;br /&gt;
&lt;br /&gt;
'''Un-Talent Show''' - Since we are a community with many talents this is a great opportunity to share.  We invite people to share their real talents - singing, poems, photos, drawings. We also have PPT and real Kareoke.&lt;br /&gt;
&lt;br /&gt;
= 2008b Straw Man Schedule =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Monday Introductory ===&lt;br /&gt;
&lt;br /&gt;
Feedback from last time&lt;br /&gt;
* Improve the 'what is it and why should I care' &lt;br /&gt;
* Have simpler explanations of core elements and explain how they fit together better&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''IDEAS''&lt;br /&gt;
Kaliya's idea about how to do this - invite Ryan Jassen who is a 'newbie' writing an extensive seriese of posts about the overall landscape and contributing to Starting Points page.&lt;br /&gt;
&lt;br /&gt;
Invite the Enterprise Positioning group to put together an introductory presentation.&lt;br /&gt;
&lt;br /&gt;
Perhaps invite VRM to talk about where there project as it is an application. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== One Pagers ===&lt;br /&gt;
&lt;br /&gt;
What projects are 'in' the packet?&lt;br /&gt;
&lt;br /&gt;
How is this decided - what are the criteria?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== All together ====&lt;br /&gt;
&lt;br /&gt;
How do we use this time well together?&lt;br /&gt;
&lt;br /&gt;
What is the big question?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Tuesday ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Wednesday ===&lt;br /&gt;
&lt;br /&gt;
''note that the [http://www.datasharingsummit.com Data Sharing Summit]] is happening the following day.''&lt;br /&gt;
&lt;br /&gt;
= 2007a Straw Man Schedule =&lt;br /&gt;
&lt;br /&gt;
== Monday ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== INTRODUCTION TRACK ===&lt;br /&gt;
&lt;br /&gt;
2.5 hours&lt;br /&gt;
&lt;br /&gt;
# Shared Language/History&lt;br /&gt;
#* Lexicon&lt;br /&gt;
#* Laws of Identity + responses&lt;br /&gt;
&lt;br /&gt;
# Identity landscape overview&lt;br /&gt;
#* triangle/venn diagram&lt;br /&gt;
#* web sso architecture diagram (applicable to OpenID and others)&lt;br /&gt;
#* other attempts to map out the landscape&lt;br /&gt;
#** event landscape&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== MAJOR PROJECTS - Each puts forward one pager.  ====&lt;br /&gt;
&lt;br /&gt;
These will be covered as part of discussing the landscape. There will be a long question and answer.&lt;br /&gt;
&lt;br /&gt;
* Printing: .pdf and wiki form by 11/28 send PDF to Kaliya and Phil. &lt;br /&gt;
&lt;br /&gt;
===== RECOMMENDED OUTLINE for One Pager =====&lt;br /&gt;
* What is it?&lt;br /&gt;
* What is it designed for/how do I apply it?&lt;br /&gt;
* What is the work product / goal / vision.&lt;br /&gt;
* How far along is it? &lt;br /&gt;
* How can I learn more?&lt;br /&gt;
* Who is involved?&lt;br /&gt;
* How can I participate?&lt;br /&gt;
&lt;br /&gt;
===== PROJECTS And Proposed authors =====&lt;br /&gt;
* OSIS - Dale Olds, Johannes Ernst&lt;br /&gt;
** goals&lt;br /&gt;
** current status&lt;br /&gt;
** work items during IIW&lt;br /&gt;
*  OpenID - Bill Washburn, David Recordon, Scott K&lt;br /&gt;
* Foundation&lt;br /&gt;
** technology&lt;br /&gt;
** intellectual property&lt;br /&gt;
* Concordia - Eve Maler, Mike Jones&lt;br /&gt;
* Cardspace - Mike Jones&lt;br /&gt;
* Higgins - Paul Trevithick, Charles Andres&lt;br /&gt;
* XDI - Drummond Reed, Charles Andres&lt;br /&gt;
* XRI - Drummond Reed, &lt;br /&gt;
* Bandit - Dale Olds&lt;br /&gt;
* ID Trust - Abbie Barber?&lt;br /&gt;
* SAML - Eve Maler, Conor Cahill, John Kemp&lt;br /&gt;
* OpenSocial?&lt;br /&gt;
* ID Commons, Kaliya and Eugene&lt;br /&gt;
* The Pamela Project, Pamela Dingle&lt;br /&gt;
&lt;br /&gt;
* Other Initiatives that are relevant to this space and coming to the event. &lt;br /&gt;
Add yourself and get your one pager in.&lt;br /&gt;
&lt;br /&gt;
=== Ongoing Working Groups ===&lt;br /&gt;
&lt;br /&gt;
We will have two 90min sessions. 12:45-2:15 and 2:30-4:00.&lt;br /&gt;
We would like groups to let us know they want to meet.&lt;br /&gt;
These working sessions are only for people who have been to IIW before. &lt;br /&gt;
&lt;br /&gt;
=== WHOLE GROUP CONVERGENCE about 4pm ===&lt;br /&gt;
&lt;br /&gt;
*What Questions were there and have been answered by the community. Kaliya and Johannes will solicit these via a survey/blog outreach.  Present what they discover for 15-20 min.&lt;br /&gt;
&lt;br /&gt;
Break into small groups consider. &lt;br /&gt;
&lt;br /&gt;
1) Landscape is changing - what has happened in the last year (Below are examples)&lt;br /&gt;
&lt;br /&gt;
** Social Graph Portability&lt;br /&gt;
** OpenSocial APIs: Facebook, Google...&lt;br /&gt;
** Is user-centric identity ready for commercial adoption? &lt;br /&gt;
** RealID&lt;br /&gt;
** Facebook open &lt;br /&gt;
** Biometrics emerging in more places (airports, gas stations, grocery stores, school lunches)&lt;br /&gt;
** VRM - enabling buyers and sellers to build mutually beneficial relationships&lt;br /&gt;
*** Customer backlash: Chevy Tahoe Recall Social Network&lt;br /&gt;
** Legal developments (Europe, US etc.)&lt;br /&gt;
2) What are the Open Questions for the Community to grapple with &lt;br /&gt;
&lt;br /&gt;
Closing talking about Identity Commons &lt;br /&gt;
** show list of working groups&lt;br /&gt;
** point to individuals representing those working groups present at IIW&lt;br /&gt;
** how you get involved&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Questions we worked through for Monday Design. ===&lt;br /&gt;
&lt;br /&gt;
Questions that arise &lt;br /&gt;
# Is user-centric identity ready for commercial adoption? (this could be a whole group conversation)&lt;br /&gt;
#* what is available in the market, and what not&lt;br /&gt;
#* business case&lt;br /&gt;
#* obstacles and mine fields&lt;br /&gt;
# Call to Action: Internet Identity is essential to a free and open social order; what are you going to do about it?&lt;br /&gt;
#* Data Protection --&amp;amp;gt; User Control --&amp;amp;gt; Accountability --&amp;amp;gt; Trust&lt;br /&gt;
#* Work together to avoid the icebergs; protocol debates are less important&lt;br /&gt;
#* Interoperability among heterogeneous systems&lt;br /&gt;
&lt;br /&gt;
Who should talk on Monday?&lt;br /&gt;
&lt;br /&gt;
How do you coordinate with community for meeting needs on Monday?&lt;br /&gt;
&lt;br /&gt;
Goal for Monday is surface coherence.  Purpose is to surface shared language.  Show progress.  How can we show this?&lt;br /&gt;
&lt;br /&gt;
* Collective mapping process. &lt;br /&gt;
* common vocabulary&lt;br /&gt;
* cross fertilization activity discussion&lt;br /&gt;
* Give people a grounding and orientation.&lt;br /&gt;
* Intros for newbies -- likely to last several hours; Those who have been through the intro before could have work sessions&lt;br /&gt;
* State of the art for both newbies and experts&lt;br /&gt;
* Mentorship?&lt;br /&gt;
&lt;br /&gt;
== Tuesday ==&lt;br /&gt;
&lt;br /&gt;
For Open Space - &lt;br /&gt;
Articulate different types of sessions - &lt;br /&gt;
* Learning/Teaching Sessions (to get folks up to speed on topics/issues)&lt;br /&gt;
* Working Sessions &lt;br /&gt;
&lt;br /&gt;
=== OSIS Interop in the Afternoon ===&lt;br /&gt;
&lt;br /&gt;
* Hahn Auditorium&lt;br /&gt;
* &amp;amp;quot;BYOR&amp;amp;quot; Bring your own router, Cat V Cables, Power strip&lt;br /&gt;
* Speed Geeking opportunity in conjunction with interop demo&lt;br /&gt;
* Interop planning session for RSA 2008&lt;br /&gt;
&lt;br /&gt;
=== Untalent Show ===&lt;br /&gt;
List your TALENT HERE&lt;br /&gt;
*&lt;br /&gt;
* &lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
== Wednesday ==&lt;br /&gt;
&lt;br /&gt;
Open Space start 8:30 AM this may move to 9AM but not confirmed yet.&lt;br /&gt;
Closing&lt;br /&gt;
&lt;br /&gt;
= Participants =&lt;br /&gt;
There was an open call for participation in helping to design IIW. There were several conference calls and a cc e-mail list. The following folks participated.  This coming IIW we will begin the conversation about the design of the next IIW. &lt;br /&gt;
&lt;br /&gt;
* Kaliya Hamlin&lt;br /&gt;
* Eugene Kim&lt;br /&gt;
* Phil Windley&lt;br /&gt;
* Sean Ammirati&lt;br /&gt;
* Charles Andres&lt;br /&gt;
* Drummod Reed&lt;br /&gt;
* Dale Olds&lt;br /&gt;
* Andy Dale &lt;br /&gt;
* Johannes Ernst&lt;br /&gt;
* Doc Searls&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:What_are_the_Business_Models_of_ID_Conference&amp;diff=3366</id>
		<title>Talk:What are the Business Models of ID Conference</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:What_are_the_Business_Models_of_ID_Conference&amp;diff=3366"/>
		<updated>2010-11-24T09:26:10Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://yjucofi.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://yjucofi.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Attribute_eXchange&amp;diff=3365</id>
		<title>Talk:Attribute eXchange</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Attribute_eXchange&amp;diff=3365"/>
		<updated>2010-11-24T09:26:09Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://imygijesusy.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
----&lt;br /&gt;
=[http://imygijesusy.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Action_Card_Ideas_iiw9&amp;diff=3364</id>
		<title>Talk:Action Card Ideas iiw9</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Action_Card_Ideas_iiw9&amp;diff=3364"/>
		<updated>2010-11-24T09:26:07Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://olitudyxej.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://olitudyxej.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Legal_Layer_of_the_Stack&amp;diff=3363</id>
		<title>Legal Layer of the Stack</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Legal_Layer_of_the_Stack&amp;diff=3363"/>
		<updated>2010-11-24T08:34:30Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://utugijynure.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
'''Attendees:'''&lt;br /&gt;
* Scott David (Convener)&lt;br /&gt;
* J. Trent Adams (Scribe)&lt;br /&gt;
* Judith Bush&lt;br /&gt;
* Rick Smith&lt;br /&gt;
* Julie Martin&lt;br /&gt;
* Mawaki Chango&lt;br /&gt;
* Mason Lee&lt;br /&gt;
* Steve Greenberg&lt;br /&gt;
 &lt;br /&gt;
'''Session Objectives:'''&lt;br /&gt;
* Overview of concepts relating to legal/technology interfaces of identity&lt;br /&gt;
* Identify potential useful work to &amp;amp;quot;Map the Gap&amp;amp;quot; between technology and law/regulation&lt;br /&gt;
* Feed session results into a &amp;amp;quot;Map the Gap&amp;amp;quot; event planned for technologists and lawyers in Washington DC scheduled for February, 2010&lt;br /&gt;
&lt;br /&gt;
'''General Discussion:'''&lt;br /&gt;
* Linked information systems are &amp;amp;quot;porous&amp;amp;quot;&lt;br /&gt;
** it is possible for data to be shared beyond the intended acquisition&lt;br /&gt;
* Rapid technical innovation accelerating rate of information exchange&lt;br /&gt;
** Law and culture lag behind technology advancement&lt;br /&gt;
** Lawyers aren't in the business of predicting the future&lt;br /&gt;
**  Question of how to manage for &amp;amp;quot;social&amp;amp;quot; stability&lt;br /&gt;
* Technology supports what are essentially &amp;amp;quot;social&amp;amp;quot; interactions / transactions&lt;br /&gt;
* Business systems (driven by technology) require people to function&lt;br /&gt;
* Interactions between people are codified by agreements (convention and contractual)&lt;br /&gt;
* Interfaces between people are codified by legal agreements&lt;br /&gt;
** &amp;amp;quot;Lawyers are in the people-programming business&amp;amp;quot; - Scott David&lt;br /&gt;
* Part of effectively &amp;amp;quot;mapping the gap&amp;amp;quot; involves both technologists and lawyers&lt;br /&gt;
* People need to understand both the technologies and laws&lt;br /&gt;
** corollary: people need to understand technologists and lawyers&lt;br /&gt;
** corollary: technologists and lawyers need to understand people (their needs &amp;amp;amp; wants)&lt;br /&gt;
** corollary: technologists and lawyers need to understand each other&lt;br /&gt;
&lt;br /&gt;
'''Identified Needs:'''&lt;br /&gt;
* Common nomenclature and/or translation scheme&lt;br /&gt;
* Agreements for technology interoperability&lt;br /&gt;
* Agreements for data-sharing interoperability&lt;br /&gt;
* Guidelines for:&lt;br /&gt;
** Effective interaction (technical and operational)&lt;br /&gt;
** Violation monitoring / handling&lt;br /&gt;
** Mitigation responses&lt;br /&gt;
** Dispute resolution&lt;br /&gt;
* Identifying cross-jurisdictional issues&lt;br /&gt;
* Research &amp;amp;amp; Evaluate Existing International Work:&lt;br /&gt;
** Policies and regulations (legal)&lt;br /&gt;
** Recommended guidelines (consortia)&lt;br /&gt;
** Best practices (technology)&lt;br /&gt;
&lt;br /&gt;
'''Next Steps:'''&lt;br /&gt;
* Identify pain points&lt;br /&gt;
* Potential solutions for the pain:&lt;br /&gt;
** Taxonomy / common terminology across legal/technology gap&lt;br /&gt;
** Scenario planning to understand long-range needs&lt;br /&gt;
** Simple &amp;amp;quot;test case&amp;amp;quot; solution as starting point&lt;br /&gt;
*** E.g. Legal boiler plate defining the Attribution - Authentication - Authorization process in line with OMB 04-04 and NIST SB 800-63&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Higgins_Cloud_Selector&amp;diff=3362</id>
		<title>Higgins Cloud Selector</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Higgins_Cloud_Selector&amp;diff=3362"/>
		<updated>2010-11-24T08:34:28Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://axuzexy.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
'''Conference [[Notes_iiw8|IIW8]]  Room/Time:''' 3/E&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Markus Sabadello&lt;br /&gt;
&lt;br /&gt;
'''Attendees:'''&lt;br /&gt;
&lt;br /&gt;
'''Technology Discussed/Considered:''' Higgins “Cloud Selector” http://wiki.eclipse.org/Cloud_Selector&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
The Higgins “Cloud Selector” is a web-based application that allows you to access and use your i-cards without the need to install anything on your local machine. It uses OpenID Attribute Exchange as a transport layer to move claims and entire tokens around.&lt;br /&gt;
&lt;br /&gt;
It’s useful in situations in which you don’t have a locally installed selector, but it also has downsides such as reduced security and privacy.&lt;br /&gt;
&lt;br /&gt;
The Cloud Selector can operate in different modes.. It can work with any existing OpenID RP, and it can work with special RPs that take advantage of IMI features.&lt;br /&gt;
&lt;br /&gt;
It tries to internally map IMI claim identifiers to OpenID AX and SREG attribute identifiers.&lt;br /&gt;
&lt;br /&gt;
A question came up on whether the same user experience could be achieved by a traditional OpenID. The answer was that this is mostly true, except that the Cloud Selector also offers the possibility to transport entire tokens (as opposed to just simple claim values).&lt;br /&gt;
&lt;br /&gt;
Next steps:&lt;br /&gt;
*Improve UI&lt;br /&gt;
*Display requested / optional claims to user and let them choose the optional ones they want to send&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Activity_Streams,_Twitter_API,_Facebook,_Open_Social,_Yahoo!_Updates&amp;diff=3361</id>
		<title>Activity Streams, Twitter API, Facebook, Open Social, Yahoo! Updates</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Activity_Streams,_Twitter_API,_Facebook,_Open_Social,_Yahoo!_Updates&amp;diff=3361"/>
		<updated>2010-11-24T08:34:06Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ucozisit.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
'''Conference [[Notes_iiw8|IIW8]]  Room/Time:''' 9/E&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:'''&lt;br /&gt;
&lt;br /&gt;
'''Attendees:'''&lt;br /&gt;
&lt;br /&gt;
'''Technology Discussed/Considered:''' &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
http://activitystreams.pbworks.com/f/1242846192/microformats%20005.JPG&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
At IIW we met with Kevin Marks and a group of folks to discuss the fact that there are multiple publishers and consumers of activities everywhere and how we can actually get compatible representations so we don't lose the semantics around the entires.&lt;br /&gt;
 &lt;br /&gt;
We first detailed the Use Cases for Activities:&lt;br /&gt;
*Reading the feed - aggregators for correlation &lt;br /&gt;
*Need common representation &lt;br /&gt;
*Raising activities (Opensocial , Facebook) &lt;br /&gt;
*With popup &lt;br /&gt;
*Without popup &lt;br /&gt;
*Desktop client pushing updates (activities) &lt;br /&gt;
*Writing sematic entries with simple clients &lt;br /&gt;
*Ingesting feeds and republishing &lt;br /&gt;
*Problems around echoing &lt;br /&gt;
 &lt;br /&gt;
We then proceeded to discuss solutions:&lt;br /&gt;
 &lt;br /&gt;
What if we ingest activities with the current tool by extending out support for microformats ?&lt;br /&gt;
Well the main thing that is missing are the verbs so we can use exisiting microformats and a new microformat which handles the verb &lt;br /&gt;
&amp;amp;lt;pre&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;hentry&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;hcard class=&amp;amp;quot;author&amp;amp;quot;&amp;amp;gt;Steven&amp;amp;lt;/hcard&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;span class=&amp;amp;quot;verb value-title&amp;amp;quot;  title=&amp;amp;quot;post&amp;amp;quot;&amp;amp;gt;Shouted&amp;amp;lt;/span&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;/hentry&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;/pre&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
There is an effort started in the Microformats community to be able to provide metadata to represent activities. See http://microformats.org/wiki/activity-verb-brainstorming &lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Legal_Layer_of_the_Stack&amp;diff=3360</id>
		<title>Talk:Legal Layer of the Stack</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Legal_Layer_of_the_Stack&amp;diff=3360"/>
		<updated>2010-11-24T08:34:03Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://utugijynure.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://utugijynure.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Goals&amp;diff=3359</id>
		<title>Goals</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Goals&amp;diff=3359"/>
		<updated>2010-11-24T08:33:51Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ojiqovam.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ojiqovam.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
== LEGAL IIW: Goals ==&lt;br /&gt;
&lt;br /&gt;
Taking notes from prior Legal IIW conference call, we identified goals as:&lt;br /&gt;
* Own and control/seed their own identities&lt;br /&gt;
* Outline a relatively simple way to reclaim their identity when stolen &lt;br /&gt;
* Articulate the disconnects &lt;br /&gt;
&lt;br /&gt;
An upcoming conference call will allow us time to flesh these goals out, and discuss other possible goals.&lt;br /&gt;
&lt;br /&gt;
== Conference Call Details ==&lt;br /&gt;
&lt;br /&gt;
* Date: Tuesday July 1&lt;br /&gt;
* Time: 10:00 A.M. (1 hour)&lt;br /&gt;
* Dial in: 1-309-946-5100&lt;br /&gt;
* Access Code: 44241&lt;br /&gt;
&lt;br /&gt;
== Invited ==&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Higgins_Cloud_Selector&amp;diff=3358</id>
		<title>Talk:Higgins Cloud Selector</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Higgins_Cloud_Selector&amp;diff=3358"/>
		<updated>2010-11-24T08:33:50Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://axuzexy.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
----&lt;br /&gt;
=[http://axuzexy.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=XRDS_for_OpenID_and_Information_Cards&amp;diff=3357</id>
		<title>XRDS for OpenID and Information Cards</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=XRDS_for_OpenID_and_Information_Cards&amp;diff=3357"/>
		<updated>2010-11-24T08:33:47Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ukusypumi.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
Convener &amp;amp;amp; Notes-taker: Axel Nennker&lt;br /&gt;
&lt;br /&gt;
'''Technology Discussed/Considered:'''&lt;br /&gt;
&lt;br /&gt;
XRDS, Open ID, Information Cards&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
We should use XRDS (Simple) to let a RelyingParty/OpenIdConsumer/Resource/Service express its needs and the services it provides.&lt;br /&gt;
&lt;br /&gt;
Something along these lines is describes here http://ignisvulpis.blogspot.com/2008/10/information-cards-with-xrds.html&lt;br /&gt;
&lt;br /&gt;
    * The relying party (https://xmldap.org/relyingparty/) provides a HTML LINK-rel element in the html code.&lt;br /&gt;
    * A browser extension finds the LINK element and downloads the XRDS document the LINK points to.&lt;br /&gt;
    * The browser extension looks for service types it is willing to support&lt;br /&gt;
    * In the case of Information Cards it retrieve the &amp;amp;quot;policy&amp;amp;quot; of the relyingparty&lt;br /&gt;
    * If the user now chooses to start the card selector the applicability of a card is governed by the RP policy.&lt;br /&gt;
    * After the security token has been generated it is send to the RP service endpoint listed in the XRDS document.&lt;br /&gt;
      This transfers the user's credentials/claims aka &amp;amp;quot;security token&amp;amp;quot; to the RP. &lt;br /&gt;
&lt;br /&gt;
What we should agree on in this session is a set of XRDS types that are suitable for OpenId.&lt;br /&gt;
&lt;br /&gt;
First here are the things for Information Cards:&lt;br /&gt;
&lt;br /&gt;
    * http://infocardfoundation.org/policy/1.0/login Describes where the policy can be retrieved.&lt;br /&gt;
      The scheme in the Uri part of this services SHOULD be https.&lt;br /&gt;
    * http://infocardfoundation.org/service/1.0/login Describes where the security token can be posted to.&lt;br /&gt;
      The scheme in the Uri part of this services SHOULD be https. &lt;br /&gt;
&lt;br /&gt;
What is needed for OpenId?&lt;br /&gt;
&lt;br /&gt;
    * http://openid.org/policy/1.0/login&lt;br /&gt;
    * http://openid.org/service/1.0/login &lt;br /&gt;
&lt;br /&gt;
If these two XRDS types are accepted what is the &amp;amp;quot;policy&amp;amp;quot;?&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=User_Managed_Access_-_UMA&amp;diff=3356</id>
		<title>User Managed Access - UMA</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=User_Managed_Access_-_UMA&amp;diff=3356"/>
		<updated>2010-11-24T08:33:45Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ajycyvitik.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
Issue/Topic:  User-Managed Access (UMA)&lt;br /&gt;
&lt;br /&gt;
Monday – Session 3 - E&lt;br /&gt;
&lt;br /&gt;
Convener: Eve Maler&lt;br /&gt;
&lt;br /&gt;
Notes-taker(s): Tom Holodnik&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' #UMA #authorization #user-centric #OAuth #JSON #Python #policy #claims&lt;br /&gt;
&lt;br /&gt;
'''Discussion Notes:'''&lt;br /&gt;
&lt;br /&gt;
For complete details, please see: http://kantarainitiative.org/confluence/display/uma/Home&lt;br /&gt;
&lt;br /&gt;
The protocol flow is described here: http://kantarainitiative.org/confluence/display/uma/UMA+1.0+Core+Protocol&lt;br /&gt;
&lt;br /&gt;
Here’s a friendly overview: http://kantarainitiative.org/confluence/display/uma/UMA+Explained&lt;br /&gt;
&lt;br /&gt;
Session slides: http://kantarainitiative.org/confluence/download/attachments/37751312/IIW10-UMA-May2010.pdf&lt;br /&gt;
&lt;br /&gt;
History:&lt;br /&gt;
&lt;br /&gt;
ProtectServe evolved into UMA.&lt;br /&gt;
Last IIW, WRAP was presented; it overturned some OAuth dependencies that UMA had had.&lt;br /&gt;
&lt;br /&gt;
UMA:&lt;br /&gt;
&lt;br /&gt;
Influences:&lt;br /&gt;
&lt;br /&gt;
* policy-decision making&lt;br /&gt;
* privacy&lt;br /&gt;
* informational self-determination&lt;br /&gt;
* data portability&lt;br /&gt;
* the &amp;amp;quot;open stack&amp;amp;quot;&lt;br /&gt;
* volunteered personal information&lt;br /&gt;
* personal data stores&lt;br /&gt;
&lt;br /&gt;
outcomes:&lt;br /&gt;
&lt;br /&gt;
* a dashboard that allows you to control access&lt;br /&gt;
* engaged data sharing&lt;br /&gt;
&lt;br /&gt;
* a protocol headed toward IETF applications area&lt;br /&gt;
* a set of draft specs free for anyone to implement&lt;br /&gt;
* multiple implementations under way&lt;br /&gt;
* simple, OAuth-based, identifier agnostic, RESTful, modular, generative (can be used to build more things) and developed rapdily&lt;br /&gt;
* targeting delivery as a spec (to IETF) in the August time frame&lt;br /&gt;
&lt;br /&gt;
The players:&lt;br /&gt;
&lt;br /&gt;
* Authorizing user  - a web user who config's the AM with policies to control how to make access control decisions)&lt;br /&gt;
* Host (protected resource server)  - enforces access to the protected resources it hosts&lt;br /&gt;
* Authorization Manager (AM) - carries out an authorizing users policies&lt;br /&gt;
* Requester  - an entity that wants to access the AU's resources&lt;br /&gt;
&lt;br /&gt;
Compare OAuth and UMA models:&lt;br /&gt;
&lt;br /&gt;
* the UMA model is different from the OAuth model in subtle ways; it establishes a contract for access management&lt;br /&gt;
* the UMA AM may also usefully be co-located with IdP and discovery&lt;br /&gt;
&lt;br /&gt;
participants:&lt;br /&gt;
&lt;br /&gt;
* there is one resource owner and consumer in OAuth; the UMA user may be granting access to an autonomous party&lt;br /&gt;
* resource server respects tokens from its authz server; the host  outsources authz jobs to an authz manager chosen by the user&lt;br /&gt;
* the authz server issues tokens based on the client's ability to authN; the authZ manager ussues tokens based on user policy and clienams coneryned by the requester&lt;br /&gt;
&lt;br /&gt;
provisioning:&lt;br /&gt;
&lt;br /&gt;
* client and server must meet outside the OAuth context to provision trust; the requester can walk up to a protected reseource and attempt to get access without registering first&lt;br /&gt;
&lt;br /&gt;
dynamic trust:&lt;br /&gt;
&lt;br /&gt;
* the resource server meets its authz server ahead of time and is coupled with it;  the authz user can mediate the introduction of each of the hosts to the authz manager we wants to use&lt;br /&gt;
* the resource server validates tokens in an unspecified manner, assumed locally;  the host has the option to ask the authZ manager to validate tokens in real time&lt;br /&gt;
&lt;br /&gt;
protocol:&lt;br /&gt;
&lt;br /&gt;
* OAuth: get a token, use a token;  uma: intro, get token, use token&lt;br /&gt;
* user delegation flows and automous flows; UMA: profiles of OAuth flows&lt;br /&gt;
&lt;br /&gt;
relationship with OAuth: based on OAuth 2.&lt;br /&gt;
&lt;br /&gt;
UMA Protocol Details: (reference the links at the top of the notes)&lt;br /&gt;
&lt;br /&gt;
Establishing trust; passing a handle to the protected resources&lt;br /&gt;
&lt;br /&gt;
* could establish trust on first use (TOFU)&lt;br /&gt;
&lt;br /&gt;
Policies:&lt;br /&gt;
&lt;br /&gt;
* unilateral - e.g. allow access for a week&lt;br /&gt;
* claims-requiring -  &amp;amp;quot;allow anyone access who agrees to my licensing terms&amp;amp;quot;  or allow access to someone who can prove themselves to to bob@mailco.com, or allow access to anyone 18 years old or more.&lt;br /&gt;
&lt;br /&gt;
Claims 2.0 are by default JSON based claims that establish attributes about a user; they don't have to be issued by the requester, but they could be issued by an IdP associated with the requester.&lt;br /&gt;
&lt;br /&gt;
Demos and Implementations in progress:&lt;br /&gt;
&lt;br /&gt;
SMART at Newcastle University: This illustrates how to issue and manage simple kinds of claims:&lt;br /&gt;
http://kantarainitiative.org/confluence/download/attachments/38371737/SMARTOverview.pdf&lt;br /&gt;
http://kantarainitiative.org/confluence/display/uma/SMART+project+user+experience&lt;br /&gt;
&lt;br /&gt;
Christian Scholz:  This illustrates how we might create policies and provision access to resources we want to protect with an UMA AM:&lt;br /&gt;
Prototype: http://bitbucket.org/mrtopf/uma&lt;br /&gt;
Demo:  http://host.clprojects.net/&lt;br /&gt;
&lt;br /&gt;
Comment: if the token does not contain information about the resource (and to whom it was issued), it's vulnerable to confused deputy&lt;br /&gt;
&lt;br /&gt;
claims confirmation could be as simple as &amp;amp;quot;confirm that you are over 18&amp;amp;quot; or &amp;amp;quot;confirm that you will abide by the terms of Creative Commons...&amp;amp;quot;  - enforceable legally, or could be supported by claims issued through CardSpace/InfoCards,   could be a URL of a BBB statement, or a URL pointing to other indepedent assertion of claims.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Activity_Streams,_Twitter_API,_Facebook,_Open_Social,_Yahoo!_Updates&amp;diff=3355</id>
		<title>Talk:Activity Streams, Twitter API, Facebook, Open Social, Yahoo! Updates</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Activity_Streams,_Twitter_API,_Facebook,_Open_Social,_Yahoo!_Updates&amp;diff=3355"/>
		<updated>2010-11-24T08:33:34Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ucozisit.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ucozisit.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:User_Managed_Access_-_UMA&amp;diff=3354</id>
		<title>Talk:User Managed Access - UMA</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:User_Managed_Access_-_UMA&amp;diff=3354"/>
		<updated>2010-11-24T08:33:18Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ajycyvitik.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ajycyvitik.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:XRDS_for_OpenID_and_Information_Cards&amp;diff=3353</id>
		<title>Talk:XRDS for OpenID and Information Cards</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:XRDS_for_OpenID_and_Information_Cards&amp;diff=3353"/>
		<updated>2010-11-24T08:33:15Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ukusypumi.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ukusypumi.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=User_talk:Web2.7&amp;diff=3352</id>
		<title>User talk:Web2.7</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=User_talk:Web2.7&amp;diff=3352"/>
		<updated>2010-11-24T07:58:48Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://acisabukody.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
Publication and redistribution authorised&lt;br /&gt;
&lt;br /&gt;
Web2.7 &lt;br /&gt;
&lt;br /&gt;
Launched an open standard for a Universal Naming System on the 28th May 2010.&lt;br /&gt;
&lt;br /&gt;
We have literally solved the problem of internet identity.&lt;br /&gt;
&lt;br /&gt;
The solution is free and open-source.&lt;br /&gt;
&lt;br /&gt;
pURLid.org&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Spectrum_of_Identity&amp;diff=3350</id>
		<title>Spectrum of Identity</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Spectrum_of_Identity&amp;diff=3350"/>
		<updated>2010-11-24T07:58:16Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://egebyromedu.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
'''Convener:''' Rick Smith/Kailya&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Rick Smith, Jeff Vander Clute&lt;br /&gt;
&lt;br /&gt;
'''Tags:'''&lt;br /&gt;
Sock puppets, anonyminity, pseudonymity, verified identity, socially verified identity, reputation, social versus technical mechanisms, boundaries, privacy, expunging records, under age&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Discussion notes:&lt;br /&gt;
&lt;br /&gt;
Kaliya proposes a range of four types of identities&lt;br /&gt;
&lt;br /&gt;
* Anonymity – &lt;br /&gt;
* Pseudyminity – Gamers, visitors to govt sites that aren’t performing actions on personal legal things&lt;br /&gt;
**  Single site pseudonymity&lt;br /&gt;
**  “Linked” pseudonymity – using a persona in multiple locations&lt;br /&gt;
* Socially verified – Facebook, twitter&lt;br /&gt;
* Verified – tied to one person via checking &amp;amp;quot;official&amp;amp;quot; documents&lt;br /&gt;
&lt;br /&gt;
US govt is looking at OpenID and such because there are sites that do NOT want to explicitly identify their users, but wants to provide a customized experience, which in turn relies on an authenticated identity.&lt;br /&gt;
&lt;br /&gt;
“Limited liability persona” – spin off personas that are linked back to you but don’t really pass liability back to you.&lt;br /&gt;
&lt;br /&gt;
Two separate worlds of identity – I buy something on craigslist, I want to see flickr photos, but I don’t need to see the birth certificate. &lt;br /&gt;
&lt;br /&gt;
“There are lots of people who push for assurance in identity want to push for the “verified” range of identity, and that somehow that makes it all work right. But problems persist.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Some people say that ideal identity is tied heavily to the physical person.&lt;br /&gt;
&lt;br /&gt;
Credit card companies used to care about identity. Today they really don’t care that much. Credit card companies find that it’s not worthwhile to focus on it. Instead they only care about transaction integrity.&lt;br /&gt;
&lt;br /&gt;
Sites are one of the boundaries people create – each site provides a boundary within which people create identities. These may or may not relate to identities on other sites.&lt;br /&gt;
&lt;br /&gt;
Google is a terrific platform for traffic analysis – people would ego-surf and find peoples’ blogs who talk about them, rag about them, and produce unexpected and undesired results.&lt;br /&gt;
&lt;br /&gt;
Identity as aggregated reputation  - your personal events get posted on the Internet, some disappear and others stay on line forever.&lt;br /&gt;
&lt;br /&gt;
A problem today is that we have no process to expunge information about people before they were of legal age. Your youthful indiscretions may follow you and you might not have a way to recover.&lt;br /&gt;
&lt;br /&gt;
France does not have Yahoo groups. Two laws: hosting child porn is illegal, and if the word ‘private’ appears in a site, then the host company is legally forbidden from looking at the group’s contents. The two interact in a bad way: the sites can’t host ANY groups because there’s no way for them to police possibly illegal groups. Ditto for Nazi things.&lt;br /&gt;
&lt;br /&gt;
There isn’t really a “Real” identity, it’s lots of things. It’s a set of transactions and doings that have the same origin in agency. “On your behalf”&lt;br /&gt;
&lt;br /&gt;
“How do I know that I’m chatting with Joe?” There’s no real way to know. At most you might be able to know that you’re chatting with Joe’s agent.&lt;br /&gt;
&lt;br /&gt;
You have this bundle of things that are your agents (user identities) and bundle of transactions with others, which becomes your reputation.&lt;br /&gt;
&lt;br /&gt;
Yahoo Identities are the toilet paper of the Internet – you use it once and then throw it away.&lt;br /&gt;
&lt;br /&gt;
People and social structures tend to protect their kids effectively. It’s almost impossible to implement these things technically. Yahoo was trying to establish mechanisms for kids to interact with the site with parents’ permission. The parents’ actions tended to produce the right result and the mechanized solutions tended to get complicated and counterproductive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''More NOtes'''&lt;br /&gt;
&lt;br /&gt;
Notes from spectrum of identity session&lt;br /&gt;
&lt;br /&gt;
Subjective: The importance of having multiple personas.&lt;br /&gt;
&lt;br /&gt;
Laws of Identity - should be required reading&lt;br /&gt;
&lt;br /&gt;
Limited Liability Personal&lt;br /&gt;
&lt;br /&gt;
Kaliya's proposed spectrum, for the purposes of stimulating a dialogue:&lt;br /&gt;
# Anonymity - used once&lt;br /&gt;
# Pseudonymity - association is opaque (gamer world, handle reality); gov't LOA 1. We don't want to know who you are and we're not going to let you tell us. Types:&lt;br /&gt;
## directed pseudonymity, only works on 1 site, directed OpenId, can't use same pseudonym on multiple sites&lt;br /&gt;
## linked pseudonymity, portable to multiple websites, regular OpenId&lt;br /&gt;
# Socially verified - Facebook (real), Twitter (persona)&lt;br /&gt;
# Verified&lt;br /&gt;
# Verified anonymity: e.g. +18 but NPI&lt;br /&gt;
&lt;br /&gt;
IIW long ago stopped debating the philosophical concept of identity and instead chose to focus on Internet identifiers and how they relate to people.&lt;br /&gt;
&lt;br /&gt;
No one wants an identity, but wants what an identity enables.&lt;br /&gt;
&lt;br /&gt;
Like the Heisenberg Uncertainty Principle: The more precisely you know an identity, the less that person is willing to do, so the system loses important forms of value / interactions. Balancing level of identity on the proposed spectrum against desired forms of interaction.&lt;br /&gt;
&lt;br /&gt;
Twitter is a much easier context to understand because everything's public (unless you protect your tweets) except for DMs.&lt;br /&gt;
&lt;br /&gt;
Tests to determine limits of identity, e.g. Does it continue after you die?&lt;br /&gt;
&lt;br /&gt;
Two different worldviews:&lt;br /&gt;
# Verify using social means, get the vibe (e.g. Flickr photos)&lt;br /&gt;
# Verify using birth certificates&lt;br /&gt;
&lt;br /&gt;
Boo to &amp;amp;quot;Identity assurance&amp;amp;quot;. All forms of identification can be gamed when large transactions are in play. So credit companies care about transaction validity not the person.&lt;br /&gt;
&lt;br /&gt;
Shifting boundaries in public-private conversations... not reflected by the technology.&lt;br /&gt;
&lt;br /&gt;
Sites are boundaries that people create.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;quot;The politician and the chess player.&amp;amp;quot; &amp;amp;quot;Bill Gates on Quake.&amp;amp;quot;&lt;br /&gt;
&lt;br /&gt;
Separation today formed by separate sites, but most people don't realize that pseudonyms are public.&lt;br /&gt;
&lt;br /&gt;
Problem: Not having visibility of the boundaries. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The brain is built to forget things over time. But the Internet is a permanent archive.&lt;br /&gt;
&lt;br /&gt;
Internet identity as aggregated reputation. The history of all you've done online defines your identity.&lt;br /&gt;
&lt;br /&gt;
We don't even have a discussion going about how to expunge. Crimes committed by minors can be expunged from the record, but not online.&lt;br /&gt;
&lt;br /&gt;
Current evil: Graph analysis that collapses identities, which get sold to marketers.&lt;br /&gt;
&lt;br /&gt;
In France there is no Yahoo Groups because of 2 laws: 1) hosting child porn is illegal (of course) and 2) if private appears on the site anywhere by definition the company is not allowed to look at the content for any purpose. Bad interaction between the two laws. Can't monitor for child porn for the purposes of removal.&lt;br /&gt;
&lt;br /&gt;
Cliff: Flaw is to think about identity as a thing. You have lots of identities. The flaw in the frame is that id is not an entity but a set of transactions, actions, and doings that have the same origin in agency (you or your agents that work for you on your behalf). =&amp;amp;gt; identity as history. Also things people say about you.&lt;br /&gt;
&lt;br /&gt;
Identity = capabilities + history. Don't just focus on the capability bundles.&lt;br /&gt;
&lt;br /&gt;
The problem with Yahoo ids: Logins, email addresses, and display name are all the same. You should be able to log in with a Google id. Don't deplete the Yahoo name space when only a unique id is needed. 99% of Yahoo ids don't receive (legitimate) email. Display names but not unique ids on the site.&lt;br /&gt;
&lt;br /&gt;
Back to identity vs. identifier. Sometimes I want to use capabilities without providing an identity.&lt;br /&gt;
&lt;br /&gt;
Proposal: Change the spectrum to classify types of activities?&lt;br /&gt;
&lt;br /&gt;
At Yahoo, we found you got more protection with less verification. We want to hide the email address and IM name, but lawyers were opposed. The verified Yahoo id has too much capability attached to it. The better thing for the kid is the social identifier, but not the verified legal identifier. (We fixed the insanity.)&lt;br /&gt;
&lt;br /&gt;
Rules will never substitute for parents protecting their children.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=De-Confusing:_High_Level_Overview&amp;diff=3349</id>
		<title>De-Confusing: High Level Overview</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=De-Confusing:_High_Level_Overview&amp;diff=3349"/>
		<updated>2010-11-24T07:58:14Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ekygelymib.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
Session: Day – Number - Space Location Tuesday – Session 1 - E&lt;br /&gt;
&lt;br /&gt;
Convener: Kaliya Hamlin&lt;br /&gt;
&lt;br /&gt;
Notes-taker(s): Aaron Bronzan&lt;br /&gt;
&lt;br /&gt;
A.	Tags for the session - technology discussed/ideas considered: &lt;br /&gt;
&lt;br /&gt;
Overview of Identity, Standards Organizations, Acronyms&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
B.	Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:&lt;br /&gt;
&lt;br /&gt;
&amp;amp;quot;De-confusing&amp;amp;quot; Identity (5/18 session 1)&lt;br /&gt;
----------------------------------------&lt;br /&gt;
&amp;amp;quot;On the Internet, nobody knows you're a dog&amp;amp;quot; (IIW logo)&lt;br /&gt;
	- Anonymity is important&lt;br /&gt;
	- But people need the set of tools to be able to represent who they are (at varying levels of granularity/disclosure)&lt;br /&gt;
	&lt;br /&gt;
Communities in attendance&lt;br /&gt;
-------------------------&lt;br /&gt;
- Business&lt;br /&gt;
	- Enterprise Customer&lt;br /&gt;
	- Enterprise Identity Management Product&lt;br /&gt;
	- WebPortals (e.g. Google, Yahoo, MSN, LinkedIn)&lt;br /&gt;
	- Regular websites&lt;br /&gt;
- Government&lt;br /&gt;
	- Europe, BC, DC&lt;br /&gt;
- Standards Development Community&lt;br /&gt;
	- OASIS (InfoCards, SAML, XRI/XDI)&lt;br /&gt;
	- IETF and Internet Society (SMTP)&lt;br /&gt;
	- W3C (HTML)&lt;br /&gt;
	- ITU-T (phone) and ISO&lt;br /&gt;
	- &amp;amp;quot;Floaters&amp;amp;quot;&lt;br /&gt;
		- XMPP - Jabber&lt;br /&gt;
		- OpenID&lt;br /&gt;
- Sysadmins&lt;br /&gt;
- Web Developers&lt;br /&gt;
- Etc. Etc. Etc.&lt;br /&gt;
&lt;br /&gt;
- Enterprise identity management: Where it all sort of started&lt;br /&gt;
	- Provisioning/issuing credentials for use of internal enterprise systems&lt;br /&gt;
	- e.g. username, password, auth token, etc.&lt;br /&gt;
	- SAML (Security Assertion Markup Language): Directory of employees with specific privileges&lt;br /&gt;
	- Authorization, or AuthZ (What you’re allowed to do)&lt;br /&gt;
- Authentication, or AuthN (The identifier – the username you use, etc.)&lt;br /&gt;
- Verification&lt;br /&gt;
- Enrollment into system (new users)&lt;br /&gt;
- Termination from system (ex-users)&lt;br /&gt;
	&lt;br /&gt;
- SAML Federation&lt;br /&gt;
   	- Business to Business sharing (e.g. American Airlines + Boeing)&lt;br /&gt;
   	- Trusting each other's credentials&lt;br /&gt;
   	- Doesn't scale well&lt;br /&gt;
&lt;br /&gt;
OpenID = outsourcing username and password (same &amp;amp;quot;username&amp;amp;quot; or i-name)&lt;br /&gt;
	- Problem is phishing: Fake forms for OpenID providers&lt;br /&gt;
	- Therefore, OpenID is designed for low-security transactions&lt;br /&gt;
&lt;br /&gt;
NASCAR problem: Addresses challenge of usability with OpenID (logos instead of having to remember your OpenID URL)&lt;br /&gt;
&lt;br /&gt;
Info Cards&lt;br /&gt;
	- IDP issues card, or you make your own card&lt;br /&gt;
	- User selects cards&lt;br /&gt;
	- Open Source InfoCard Selector repository: Higgins Project&lt;br /&gt;
	- Send various attributes only, customize the amount of information sent&lt;br /&gt;
	&lt;br /&gt;
OpenID + Information Cards = Open Identity Exchange&lt;br /&gt;
&lt;br /&gt;
XRD is Discovery: A protocol for understanding and discovering services&lt;br /&gt;
&lt;br /&gt;
We then went over a bunch of the organizations and how they relate to each other.  See Kaliya’s flowchart slides for an overview.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Data_Traceability_in_the_cloud&amp;diff=3348</id>
		<title>Data Traceability in the cloud</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Data_Traceability_in_the_cloud&amp;diff=3348"/>
		<updated>2010-11-24T07:58:04Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ycybesav.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
'''Convener:''' Steve Holcombe, Pardalis, Inc.&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Scott David of K&amp;amp;amp;L, Gates&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' Supply chain, Fragmented, Complex, Federated, Products, Trust, “4th Party”, mandate, industry, government, health, safety, liability, traceability&lt;br /&gt;
&lt;br /&gt;
Discussion notes:&lt;br /&gt;
&lt;br /&gt;
Case study examination of USDA’s declaration of mandating animal identification to livestock supply chains following the 2003 mad cow case, early implementation of a market driven (i.e., profit driven) data identity and traceability system by Pardalis, Inc. for small calf producers, and the subsequent collapse of the marketplace because of USDA’s failure in 2006 to introduce their sought-for mandate.&lt;br /&gt;
&lt;br /&gt;
Lack of products and services provided to fragmented beginnings of supply chains due to lack of data (e.g., no “life insurance” for diseased livestock of small farmers because not enough data upon which to do risk analysis); liability concerns as a driver regarding genetically modified crops and/or allergens; and lost opportunities for selling ag products overseas due to lack of authenticated data traceability.&lt;br /&gt;
&lt;br /&gt;
Correlation of cattle and ag commodities to other product supply chains (lead painted toys, melanine laden food), and leveraging the ‘identity’ movement into commercial supply chains.&lt;br /&gt;
&lt;br /&gt;
Misc.: Further discussed the common need for trusted entities along complex supply chains; possible use of info cards (including conditional access to encrypted, individual data elements); and activity streams.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Using_DNS_ENUM&amp;diff=3347</id>
		<title>Using DNS ENUM</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Using_DNS_ENUM&amp;diff=3347"/>
		<updated>2010-11-24T07:58:00Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://azysijogen.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
Issue/Topic: Using DNS and ENUM for Identity Management&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw10 IIW10] May 17-19, 2009 this is the complete [http://iiw.idcommons.net/Notes_IIW10 Complete Set of Notes]&lt;br /&gt;
&lt;br /&gt;
Monday – Session 1 - E&lt;br /&gt;
&lt;br /&gt;
Convener: Esther Makaay &lt;br /&gt;
&lt;br /&gt;
Notes-taker(s): Leon Kuunders &lt;br /&gt;
&lt;br /&gt;
'''Tags:''' #ENUM #DNS #domain-names&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:'''&lt;br /&gt;
&lt;br /&gt;
The mentioning of ENUM in the title triggered a specific response from some attenders. They were interested in what was going on with ENUM and a summary of the developments in the last two years. &lt;br /&gt;
However not everyone present had knowledge about the subject, so we started off with a description of Public User ENUM.&lt;br /&gt;
&lt;br /&gt;
With Public User ENUM you can register your telephone number as a domain name. E.g +31 802233445 → 5.4.4.3.3.2.2.0.8.1.3.e164.arpa.&lt;br /&gt;
With this domainname, you can publish a plethoria of other contact options, e.g. an e-mailaddress, skype account, SIP account, IM, and many more. Telco's are generally not enthousiastic about this, because it changes their monopoly stronghold (you could circumvene PSTN if you know someones SIP-address).&lt;br /&gt;
&lt;br /&gt;
The domain name isn't registered on a first-come-first-serve basis. Only the person or company using the telephone number is allowed to register the number. The registration is periodically validated against the number and its user.&lt;br /&gt;
&lt;br /&gt;
In The Netherlands, we've seen some use cases emerge that were inspired by ENUM, but drift in a different, identity-related direction. The idea was that if you put contact or reachability data into the domain zone, you could also put other kinds of information in the zone. This could be additional information about the phone number (the domain name) or information about the user of that number. &lt;br /&gt;
You could point to a website-URL containing invoicing information or an employee record (with restricted access).&lt;br /&gt;
&lt;br /&gt;
The next step was to think about different domain names. Because you don't per-se need an ENUM-domain, you can do this with any registered domain name. You could work with employeenumber.idm.company.org and only publish the records on your internal network (many companies work with internal DNS servers). You can run your own 'registry' this way.&lt;br /&gt;
&lt;br /&gt;
You can publish information through the domain name, or point to a data source containing more information, like a database, website or server. Although all information in DNS is public, the data source can have restricted access. &lt;br /&gt;
&lt;br /&gt;
Leon is working on a use case to give employees from different departments (physical and organisational) access to each others work environments by working with their employee numbers in a domain name. Since all departments use MS LDAP, it's easy to put that information into the internal DNS servers. The DNS network is already deployed and in use (big overstacked servers that now hardly see any load). Each department can maintain their own information and decide what to publish.&lt;br /&gt;
&lt;br /&gt;
This, as Dave Crocker pointed out repeatedly, shouldn't be called ENUM anymore. ENUM refers to a set of IETF-protocols that are described in RFC 3761 and anything that deviates from this (especially if it deviates this far) simply isn't ENUM. The definition of ENUM should be very precise and there's already lots of discussion going on about the narrow definition (eg in the E2MD IETF wg). Semantics are important!&lt;br /&gt;
&lt;br /&gt;
The conversation dispersed into a broad range of topics, most of them concerning the technology involved. &lt;br /&gt;
* Does a telephone number resolve to a person or a place? &lt;br /&gt;
* Use a particular reference mechanism from your records (concepts/schema's)&lt;br /&gt;
* Business case based on making your IDM implementations more flexible. Also inspired by Phill Windley's “Digital Identity” fourth level of IDM: integrated IDM, IDM is on the infrastructure level.&lt;br /&gt;
* Is this mapping to an IP-addres? DNS is based on a string of names. Traditionally it maps a domain name to an IP address, but a lot of its current usage has to do with pointers that do not (directly) resolve to an IP-adress.&lt;br /&gt;
* Why not use XRI (discovery protocol)? Doesn't that solve these issues already? But everything already uses DNS. What's the current penetration of XRI? The main advantage is to use the infrastructure that is already there.&lt;br /&gt;
* Is the way you get a result from your DNS server rich enough to uses this actually?&lt;br /&gt;
* Are domains and e-mailaddress sufficient as an identifier? Most people have multiple e-mail addresses. Why not use iNames as persistent identifiers?&lt;br /&gt;
* XRI, XRD, Webfinger → should ENUM be integrated with these discovery protocols?&lt;br /&gt;
* DNS calls on the weblayer is that possible? (Javascript sandbox)&lt;br /&gt;
* Does this relate to E2MD discussions? → The telephone carriers are talking about adding attributes as well. (Calling party name, number not in use, attributes needed for handling calls via IP on an infrastructure level.)&lt;br /&gt;
* What about security? → DNSSEC!&lt;br /&gt;
* What about privacy? This depends on your use case, but you should be aware of the public character of DNS and the possibilities to use internal/private networks (like with private ENUM).&lt;br /&gt;
* Telnic works with its own references, is this a standard to follow? Again, depends on the use case. Telnic works with TXT records for labels to go with the contact information (eg work phone, mobile phone), uses extra address and naming fields and works with encrypted records for restricted information (only friends can decrypt).&lt;br /&gt;
* How can you make sure the identifiers will be unique? DNS will only work when unicity is guaranteed? Domain names are unique on the internet.&lt;br /&gt;
* Not everyone has a domain name. Situations differ across different countries in the world. If you don't 'own' your domain name (or a delegation), then you  have no guarantee of the availability of the name as an identifier. Has also to do with the maturity of the internet space (eg in the early days, all websites resided under the providers domain). If there is need and usage for owning your own domain, it will happen.&lt;br /&gt;
* How does somebody who does not have your phone number find you? people have telephone numbers, e-mailaddresses, domain names&lt;br /&gt;
* Laws about portability of mobile phone numbers. There is not such a thing for e-mail.&lt;br /&gt;
* Phone numbers are very public, how do you control access to this? You don't (DNS is public), but it's a voluntary registration. It's different from handing out business cards of course, but the DNS is not a database-lookup system. You cannot do “select * from .com where domain like thisname”. You can only look up records with a domain name, not the other way round. &lt;br /&gt;
* It would be possible to shield information by using proxies.&lt;br /&gt;
* Validation of regular domain names could be helpful for building trust. Validate the WHOIS credentials of the registrant of a domain name. Is this the same as the ex-tended validating from certificate providers? No, those validations apply to SSL-certificates that are used for websites. Validation of a domain name extends to all use of that domain name (eg with e-mail).&lt;br /&gt;
&lt;br /&gt;
The ideas around using DNS and ENUM are very interesting, but since there's so many technical aspects involved (discovery, identifiers, reference-schemes, pointers, usage), it easily gets over-complex and confusing. &lt;br /&gt;
In the end it was decided that Esther will (try to) describe the subject in a tight non-technical manner. It should help to simplify the subject if we leave the technology (however interesting) for a later stage.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Are_there_%22standards%22_for_Registering_to_Call_an_API&amp;diff=3346</id>
		<title>Are there &quot;standards&quot; for Registering to Call an API</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Are_there_%22standards%22_for_Registering_to_Call_an_API&amp;diff=3346"/>
		<updated>2010-11-24T07:57:54Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://isiqilujev.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
&amp;amp;lt;div style=&amp;amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;amp;quot;&amp;amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://yzobiwysac.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://yzobiwysac.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;amp;lt;/div&amp;amp;gt;&lt;br /&gt;
'''Conference [[Notes_iiw8|IIW8]]  Room/Time:''' 6/A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Angus Logan&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Angus Logan&lt;br /&gt;
&lt;br /&gt;
'''Attendees:''' Everyone. Lots from Microsoft, Google, Yahoo, Plaxo, MySpace&lt;br /&gt;
&lt;br /&gt;
'''Technology Discussed/Considered:''' &lt;br /&gt;
*Being able to automatically register for an API key in 2 scenarios:&lt;br /&gt;
*4th party (service provider e.g. DISQUS)&lt;br /&gt;
*Developer not present (e.g. the Portable Contacts problem) &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
0) Are &amp;amp;amp;quot;API Keys&amp;amp;amp;quot; / &amp;amp;amp;quot;Registration&amp;amp;amp;quot; required&lt;br /&gt;
*Why pre-registration (identify app friendly to consumer, good way to shut off or give more permissions, give stats back re. popular *apps)&lt;br /&gt;
*Value add: Statistics / nice UI&lt;br /&gt;
*ToS compliance&lt;br /&gt;
*Business Model&lt;br /&gt;
*Throttling / DoS prevention&lt;br /&gt;
*Varying levels of permissions (read/write)&lt;br /&gt;
*Who is the developer (contact them for issues etc).&lt;br /&gt;
*Can group the API keys together for reasons of blocking etc.&lt;br /&gt;
&lt;br /&gt;
1) Is anyone doing this?&lt;br /&gt;
*Google auth sub allows you to work in unregistered (gives you scary screen) (progression from pre-registration)&lt;br /&gt;
*Unregistered Oauth for Google Friend Connect (no API keys) pass in the domain (no consumer key)&lt;br /&gt;
*OAuth discovery Draft 1 (old and was removed from later drafts)&lt;br /&gt;
*Anonymous/Anonymous - developers can use it (solves the barrier to entry, but doesn't have upside of API Keys)&lt;br /&gt;
*Facebook do the following: you are on 4th party, and pop a window to get the API key (and secret), and copy/paste it to 4th party, and then 4th party can set the properties using a dictionary.&lt;br /&gt;
*Open ID Oauth hybrid has something&lt;br /&gt;
&lt;br /&gt;
2) Is this useful (enough to do the work)&lt;br /&gt;
*Doing something like OAuth to create API keys is a no brainer and is coming next&lt;br /&gt;
*Focusing on non-developer present creation of the API key is what we are focusing on&lt;br /&gt;
&lt;br /&gt;
3) How will people abuse this functionality?&lt;br /&gt;
*Create a ton of API Keys for many phishing sites (to fly under the radar of abuse)&lt;br /&gt;
*When an API key gets shut down for abuse, create a new one automatically&lt;br /&gt;
*ToS violation (terms of service won't be agreed to)&lt;br /&gt;
&lt;br /&gt;
4) What is the current pain?&lt;br /&gt;
*Can't call a new service transparently (PoCo is an example)&lt;br /&gt;
*4th party scenarios are tricky (see password anti-pattern)&lt;br /&gt;
*Need to update code/config for each new provider&lt;br /&gt;
*Can't just copy existing code / use widgets&lt;br /&gt;
*Behind the firewall (before you push to production)&lt;br /&gt;
*Lifecycle is a dev/qa nightmare&lt;br /&gt;
*Similar to certs / b2b problem (agreement of endpoints)&lt;br /&gt;
*Barrier for developers who want to party&lt;br /&gt;
*This is the password anti-pattern for application developers (e.g. RPXNow)&lt;br /&gt;
*Service accounts to get an API Key (need a FB account, or a WLID account&lt;br /&gt;
*Prove you own the domain&lt;br /&gt;
&lt;br /&gt;
5) Solutions?&lt;br /&gt;
*Lightweight unprotected function which requests some pre defined information and returns an API key. Then when end users go through the flow the experience is taxed (UI chunkiness or rate limited)&lt;br /&gt;
*The provider may not know who the consumer is, but the end user may choose to grant permission to them.&lt;br /&gt;
*4th party : have an API to create child API keys (FB have done a lot of thinking about JanRain)&lt;br /&gt;
*Messina: Provide liberal access to the data/system, and when there is abuse, make the system selfheal (e.g. rollback)&lt;br /&gt;
*ToS work around: we need to look at creating the &amp;amp;amp;quot;creative commons&amp;amp;amp;quot; of data exposed via APIs. I.e. the consumer can read the &amp;amp;amp;quot;rights&amp;amp;amp;quot;/&amp;amp;amp;quot;restrictions&amp;amp;amp;quot; around the dataset. Perhaps described as Standardized Terms of Service (is this being looked at by DataPortability) www.sciencecommons.org and www.opendefinition.org. question: will the lawyers be happy with a system accepting ToS?&lt;br /&gt;
&lt;br /&gt;
6) Moving forward&lt;br /&gt;
*Things to work on and next steps&lt;br /&gt;
*4th party (and 5th party) provisioning of child API keys&lt;br /&gt;
*setup and email thread w/ FB and G and Plaxo to riff on this and expand&lt;br /&gt;
*Watch what FB does and the feedback, and also socialized what others are looking at&lt;br /&gt;
*enumerate all of the use cases and post to wiki/blog&lt;br /&gt;
*Walking up to an SP and doing some type of lightweight thing&lt;br /&gt;
*Plaxo and G will riff on this and push out a prototype :: lead by Portable Contacts&lt;br /&gt;
*enumerate all of the use cases and post to wiki/blog&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Wrozba_kreskowa&amp;diff=3344</id>
		<title>Talk:Wrozba kreskowa</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Wrozba_kreskowa&amp;diff=3344"/>
		<updated>2010-11-24T07:57:36Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://azysijogen.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
----&lt;br /&gt;
=[http://azysijogen.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=User_talk:Laurel_Fan&amp;diff=3343</id>
		<title>User talk:Laurel Fan</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=User_talk:Laurel_Fan&amp;diff=3343"/>
		<updated>2010-11-24T07:57:30Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ekygelymib.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ekygelymib.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Are_there_%22standards%22_for_Registering_to_Call_an_API&amp;diff=3342</id>
		<title>Are there &quot;standards&quot; for Registering to Call an API</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Are_there_%22standards%22_for_Registering_to_Call_an_API&amp;diff=3342"/>
		<updated>2010-11-24T07:57:23Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://yzobiwysac.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://yzobiwysac.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
'''Conference [[Notes_iiw8|IIW8]]  Room/Time:''' 6/A&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Angus Logan&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Angus Logan&lt;br /&gt;
&lt;br /&gt;
'''Attendees:''' Everyone. Lots from Microsoft, Google, Yahoo, Plaxo, MySpace&lt;br /&gt;
&lt;br /&gt;
'''Technology Discussed/Considered:''' &lt;br /&gt;
*Being able to automatically register for an API key in 2 scenarios:&lt;br /&gt;
*4th party (service provider e.g. DISQUS)&lt;br /&gt;
*Developer not present (e.g. the Portable Contacts problem) &lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
0) Are &amp;amp;quot;API Keys&amp;amp;quot; / &amp;amp;quot;Registration&amp;amp;quot; required&lt;br /&gt;
*Why pre-registration (identify app friendly to consumer, good way to shut off or give more permissions, give stats back re. popular *apps)&lt;br /&gt;
*Value add: Statistics / nice UI&lt;br /&gt;
*ToS compliance&lt;br /&gt;
*Business Model&lt;br /&gt;
*Throttling / DoS prevention&lt;br /&gt;
*Varying levels of permissions (read/write)&lt;br /&gt;
*Who is the developer (contact them for issues etc).&lt;br /&gt;
*Can group the API keys together for reasons of blocking etc.&lt;br /&gt;
&lt;br /&gt;
1) Is anyone doing this?&lt;br /&gt;
*Google auth sub allows you to work in unregistered (gives you scary screen) (progression from pre-registration)&lt;br /&gt;
*Unregistered Oauth for Google Friend Connect (no API keys) pass in the domain (no consumer key)&lt;br /&gt;
*OAuth discovery Draft 1 (old and was removed from later drafts)&lt;br /&gt;
*Anonymous/Anonymous - developers can use it (solves the barrier to entry, but doesn't have upside of API Keys)&lt;br /&gt;
*Facebook do the following: you are on 4th party, and pop a window to get the API key (and secret), and copy/paste it to 4th party, and then 4th party can set the properties using a dictionary.&lt;br /&gt;
*Open ID Oauth hybrid has something&lt;br /&gt;
&lt;br /&gt;
2) Is this useful (enough to do the work)&lt;br /&gt;
*Doing something like OAuth to create API keys is a no brainer and is coming next&lt;br /&gt;
*Focusing on non-developer present creation of the API key is what we are focusing on&lt;br /&gt;
&lt;br /&gt;
3) How will people abuse this functionality?&lt;br /&gt;
*Create a ton of API Keys for many phishing sites (to fly under the radar of abuse)&lt;br /&gt;
*When an API key gets shut down for abuse, create a new one automatically&lt;br /&gt;
*ToS violation (terms of service won't be agreed to)&lt;br /&gt;
&lt;br /&gt;
4) What is the current pain?&lt;br /&gt;
*Can't call a new service transparently (PoCo is an example)&lt;br /&gt;
*4th party scenarios are tricky (see password anti-pattern)&lt;br /&gt;
*Need to update code/config for each new provider&lt;br /&gt;
*Can't just copy existing code / use widgets&lt;br /&gt;
*Behind the firewall (before you push to production)&lt;br /&gt;
*Lifecycle is a dev/qa nightmare&lt;br /&gt;
*Similar to certs / b2b problem (agreement of endpoints)&lt;br /&gt;
*Barrier for developers who want to party&lt;br /&gt;
*This is the password anti-pattern for application developers (e.g. RPXNow)&lt;br /&gt;
*Service accounts to get an API Key (need a FB account, or a WLID account&lt;br /&gt;
*Prove you own the domain&lt;br /&gt;
&lt;br /&gt;
5) Solutions?&lt;br /&gt;
*Lightweight unprotected function which requests some pre defined information and returns an API key. Then when end users go through the flow the experience is taxed (UI chunkiness or rate limited)&lt;br /&gt;
*The provider may not know who the consumer is, but the end user may choose to grant permission to them.&lt;br /&gt;
*4th party : have an API to create child API keys (FB have done a lot of thinking about JanRain)&lt;br /&gt;
*Messina: Provide liberal access to the data/system, and when there is abuse, make the system selfheal (e.g. rollback)&lt;br /&gt;
*ToS work around: we need to look at creating the &amp;amp;quot;creative commons&amp;amp;quot; of data exposed via APIs. I.e. the consumer can read the &amp;amp;quot;rights&amp;amp;quot;/&amp;amp;quot;restrictions&amp;amp;quot; around the dataset. Perhaps described as Standardized Terms of Service (is this being looked at by DataPortability) www.sciencecommons.org and www.opendefinition.org. question: will the lawyers be happy with a system accepting ToS?&lt;br /&gt;
&lt;br /&gt;
6) Moving forward&lt;br /&gt;
*Things to work on and next steps&lt;br /&gt;
*4th party (and 5th party) provisioning of child API keys&lt;br /&gt;
*setup and email thread w/ FB and G and Plaxo to riff on this and expand&lt;br /&gt;
*Watch what FB does and the feedback, and also socialized what others are looking at&lt;br /&gt;
*enumerate all of the use cases and post to wiki/blog&lt;br /&gt;
*Walking up to an SP and doing some type of lightweight thing&lt;br /&gt;
*Plaxo and G will riff on this and push out a prototype :: lead by Portable Contacts&lt;br /&gt;
*enumerate all of the use cases and post to wiki/blog&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=De-Confusion_Big_Picture&amp;diff=3341</id>
		<title>De-Confusion Big Picture</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=De-Confusion_Big_Picture&amp;diff=3341"/>
		<updated>2010-11-24T07:57:15Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://evicijum.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
Tuesday Session 1 Space E&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw10 IIW 10 ] May 17-19, 2009 this is the complete [http://iiw.idcommons.net/Notes_IIW10 Complete Set of Notes ]&lt;br /&gt;
&lt;br /&gt;
&amp;amp;quot;De-confusing&amp;amp;quot; Identity (5/18 session 1)&lt;br /&gt;
----------------------------------------&lt;br /&gt;
&amp;amp;quot;On the Internet, nobody knows you're a dog&amp;amp;quot; (IIW logo)&lt;br /&gt;
* Anonymity is important&lt;br /&gt;
* But people need the set of tools to be able to represent who they are (at varying levels of granularity/disclosure)&lt;br /&gt;
&lt;br /&gt;
	&lt;br /&gt;
Communities in attendance&lt;br /&gt;
-------------------------&lt;br /&gt;
&lt;br /&gt;
Business&lt;br /&gt;
* Enterprise Customer&lt;br /&gt;
* Enterprise Identity Management Product&lt;br /&gt;
* WebPortals (e.g. Google, Yahoo, MSN, LinkedIn)&lt;br /&gt;
* Regular websites&lt;br /&gt;
&lt;br /&gt;
Government&lt;br /&gt;
* Europe, BC, DC&lt;br /&gt;
&lt;br /&gt;
Standards Development Community&lt;br /&gt;
* OASIS (InfoCards, SAML, XRI/XDI)&lt;br /&gt;
* IETF and Internet Society (SMTP)&lt;br /&gt;
* W3C (HTML)&lt;br /&gt;
* ITU-T (phone) and ISO&lt;br /&gt;
* &amp;amp;quot;Floaters&amp;amp;quot;&lt;br /&gt;
** XMPP - Jabber&lt;br /&gt;
** OpenID&lt;br /&gt;
* Sysadmins&lt;br /&gt;
* Web Developers&lt;br /&gt;
* Etc. Etc. Etc.&lt;br /&gt;
&lt;br /&gt;
** Provisioning/issuing credentials for use of internal enterprise systems&lt;br /&gt;
** e.g. username, password, auth token, etc.&lt;br /&gt;
** SAML (Security Assertion Markup Language): Directory of employees with specific privileges&lt;br /&gt;
** Authorization, or AuthZ (What you’re allowed to do)&lt;br /&gt;
* Authentication, or AuthN (The identifier – the username you use, etc.)&lt;br /&gt;
* Verification&lt;br /&gt;
* Enrollment into system (new users)&lt;br /&gt;
* Termination from system (ex-users)&lt;br /&gt;
	&lt;br /&gt;
* SAML Federation&lt;br /&gt;
** Business to Business sharing (e.g. American Airlines + Boeing)&lt;br /&gt;
** Trusting each other's credentials&lt;br /&gt;
** Doesn't scale well&lt;br /&gt;
&lt;br /&gt;
OpenID = outsourcing username and password (same &amp;amp;quot;username&amp;amp;quot; or i-name)&lt;br /&gt;
* Problem is phishing: Fake forms for OpenID providers&lt;br /&gt;
* Therefore, OpenID is designed for low-security transactions&lt;br /&gt;
&lt;br /&gt;
NASCAR problem: Addresses challenge of usability with OpenID (logos instead of having to remember your OpenID URL)&lt;br /&gt;
&lt;br /&gt;
Info Cards&lt;br /&gt;
* IDP issues card, or you make your own card&lt;br /&gt;
* User selects cards&lt;br /&gt;
* Open Source InfoCard Selector repository: Higgins Project&lt;br /&gt;
*  Send various attributes only, customize the amount of information sent&lt;br /&gt;
	&lt;br /&gt;
OpenID + Information Cards = Open Identity Exchange&lt;br /&gt;
&lt;br /&gt;
XRD is Discovery: A protocol for understanding and discovering services&lt;br /&gt;
&lt;br /&gt;
We then went over a bunch of the organizations and how they relate to each other.  See Kaliya’s flowchart slides for an overview.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Spectrum_of_Identity&amp;diff=3340</id>
		<title>Talk:Spectrum of Identity</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Spectrum_of_Identity&amp;diff=3340"/>
		<updated>2010-11-24T07:57:12Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://egebyromedu.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://egebyromedu.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=SMART_UMA&amp;diff=3339</id>
		<title>SMART UMA</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=SMART_UMA&amp;diff=3339"/>
		<updated>2010-11-24T07:57:06Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://erihybomex.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
----&lt;br /&gt;
=[http://erihybomex.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
'''Session:''' Wed Session 3, Space C&lt;br /&gt;
&lt;br /&gt;
'''Conference:''' [http://iiw.idcommons.net/Iiw10 IIW 10]  May 17-19, 2009 this is the complete [http://iiw.idcommons.net/Notes_IIW10 Complete Set of Notes ]&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Maciej Machulak&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker(s):''' Eve Maler&lt;br /&gt;
&lt;br /&gt;
Tags for the session - technology discussed/ideas considered: &lt;br /&gt;
&lt;br /&gt;
UMA site: http://kantarainitiative.org/confluence/display/uma/Home&lt;br /&gt;
SMART project slides: http://kantarainitiative.org/confluence/download/attachments/38371737/SMARTOverview.pdf&lt;br /&gt;
Screenshots of SMART prototype demo: http://kantarainitiative.org/confluence/display/uma/SMART+project+user+experience&lt;br /&gt;
UMA CV-sharing scenario: http://kantarainitiative.org/confluence/display/uma/cv_sharing_scenario&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Notes:'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The SMART project at Newcastle University is for Student-Managed Access to Online Resources. It's based on UMA, and UMA is based on OAuth 2.0, such that an UMA requester has to present an access token to get access to a user's resources at a host. The user's authorization manager decides whether to hand out access tokens based on user policy.&lt;br /&gt;
&lt;br /&gt;
The SMART project objectives are:&lt;br /&gt;
&lt;br /&gt;
* Define a scenario that focuses on higher ed, and provide a comprehensive requirements analysis&lt;br /&gt;
* Develop an UMA-based solution&lt;br /&gt;
* …&lt;br /&gt;
&lt;br /&gt;
Newcastle University has 4500 staff members and 19,000 students. A lot of data (both personal info -- DOB, address, resumes, etc. -- and resources such as documents) is hosted by Newcastle. It needs an efficient, secure, and usable access management system that supports both data owners and data consumers. E.g., you may want to share your research selectively with some collaborators.&lt;br /&gt;
&lt;br /&gt;
The project team integrates researchers, developers, and information systems management personnel.&lt;br /&gt;
&lt;br /&gt;
The UMA &amp;amp;quot;CV-sharing scenario&amp;amp;quot; is the basis for the scenario being worked on in the project. Today, a student has to manually assemble a set of artifacts to provide to prospective employers. If the student is still in classes, some of this data needs to be refreshed (like their marks from classes they've taken).&lt;br /&gt;
&lt;br /&gt;
Question: What about transitivity? If a professor writes a letter of recommendation for a student, and the student wants to include it in a prospective-employer resource bundle for further sharing, does the professor give access to the student in such a way that the student can then transitively grant access to another party without needing to go back to the professor? Yes, through a system of demanding claims.&lt;br /&gt;
&lt;br /&gt;
In some cases, the materials are digitally signed, or may be packaged software.&lt;br /&gt;
&lt;br /&gt;
Some job search websites have you upload a bunch of data, and then prospective employers go to the job search site to see it.&lt;br /&gt;
&lt;br /&gt;
Question: Can the professor has read/write/append rights to the letter, the student has read/append rights, and others have only read rights? Yes.&lt;br /&gt;
&lt;br /&gt;
The project team did an analysis of the ways resources are being shared in the university, and web applications being used for this. It turned out the web apps didn't support cross-university collaboration groups.&lt;br /&gt;
&lt;br /&gt;
If there are two universities, A and B, each typically serves as an IdP for their own populations and their own web applications that respect that IdP. Some applications are allowed access to the resources of other universities by becoming relying parties to the other IdP. So a student at university B can access certain resources at university A, but only if A's web app can talk to the IdP of B.&lt;br /&gt;
&lt;br /&gt;
So what happens right now is that the Grouper framework is used to manage groups of identities. A cross-university collaboration group could be created at Grouper, and the particular apps that need it are told about the group and how to connect to the Grouper server.&lt;br /&gt;
&lt;br /&gt;
One goal of the project is to eliminate the Grouper entity, and replace it with an UMA authorization manager that works with the Shibboleth higher-ed federation as a repository of policies that govern access.&lt;br /&gt;
&lt;br /&gt;
Another goal is to enhance the eScience system (which stores resources for collaboration with others) to allow it to point to resources &amp;amp;quot;in the cloud&amp;amp;quot; instead. This will allow researchers to use whatever web apps they prefer to create the research but also allow eScience to have access to that research. Today it's sort of like SharePoint :-), where you have to upload files. Through SMART, it will become &amp;amp;quot;just another web app&amp;amp;quot; in the research ecosystem.&lt;br /&gt;
&lt;br /&gt;
The project started about five weeks ago, but they have already got a prototype/demo (shown live in this session and at Tuesday's demo session).&lt;br /&gt;
&lt;br /&gt;
* You store photos on a particular host site.&lt;br /&gt;
* You tell the site that you want it to use &amp;amp;quot;smartam&amp;amp;quot; for protecting the resources hosted there, but giving it the URL of the AM.&lt;br /&gt;
* You get redirected to smartam and are asked to approve the connection between this host and this AM, in an OAuth 2.0 user delegation flow.&lt;br /&gt;
* Thereafter, on the AM, you can browse around a description of the resources that are now protected at that host.&lt;br /&gt;
* You provide the URL of a protected resource to some requester.&lt;br /&gt;
* The requester has to learn where the AM is and go through an UMA dance to get permission to obtain the resource.&lt;br /&gt;
* For the purposes of the demo so far, the requester is asked to log in at the AM to prove their suitability for access, but the ultimate goal of the project is to have them prove this by means that are not tied to AM authentication/identification.&lt;br /&gt;
* In the case of the second protected resource, it demands that the requester agree (by checking checkmarks) that they are over 18 and agree to the further sharing constraints imposed by the authorizing user.&lt;br /&gt;
&lt;br /&gt;
All the code will be open-sourced, and full documentation will be made available. They want to provide a solid set of UMA libraries.&lt;br /&gt;
&lt;br /&gt;
Question: What about CMS's that use LDAP today? Could this software work as a wrapper? A: It wouldn't be a wrapper, but there is a goal to integrate with LDAP.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Proposed_Topics_2008a&amp;diff=3338</id>
		<title>Proposed Topics 2008a</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Proposed_Topics_2008a&amp;diff=3338"/>
		<updated>2010-11-24T07:57:02Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://acisabukody.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://acisabukody.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
Participants at the Internet Identity Workshop create their agenda together face to face on the day of the event. This page captures the ideas people have for sessions and topics before the event.  This gives people an opportunity to share ideas and create opportunity for collaboration ahead of time.&lt;br /&gt;
&lt;br /&gt;
== IDMML ==&lt;br /&gt;
Identity Metasystem Markup Language -- an idea proposed in June 2007 by George Fletcher of AOL and recently discussed more on the OpenID General mailing list:&lt;br /&gt;
* http://practicalid.blogspot.com/2007/06/clients-to-rescue.html&lt;br /&gt;
* http://practicalid.blogspot.com/2007/06/passive-identity-meta-system-markup.html&lt;br /&gt;
There is the potential to do this via a simple convention on the use of [http://en.wikipedia.org/wiki/XRDS] documents.&lt;br /&gt;
&lt;br /&gt;
== Identity Commons Growing Up ==&lt;br /&gt;
A session about how IC is starting to come into its own as a common meeting ground for the Internet identity layer, and how we can all help it help us.&lt;br /&gt;
&lt;br /&gt;
== XRDS Best Practices ==&lt;br /&gt;
A session to discuss best practices for using [http://en.wikipedia.org/wiki/XRDS XRDS] documents, including:&lt;br /&gt;
* How best to configure OpenID service endpoints for OpenID discovery.&lt;br /&gt;
* When to require [http://xrds-simple.net/core/1.0/ XRDS Simple].&lt;br /&gt;
* When/how to use [http://en.wikipedia.org/wiki/XRI XRI] proxy resolution.&lt;br /&gt;
* When/how to use CanonicalIDs.&lt;br /&gt;
* How/where to create new service types and associated service endpoints.&lt;br /&gt;
&lt;br /&gt;
== XDI RDF By Example ==&lt;br /&gt;
A demonstration of a series of XDI RDF utilities by Markus Sabadello, lead developer of [http://wiki.eclipse.org/XDI4j XDI4J (XDI for Java)], that show how you can start sending and receiving XDI data feeds today.&lt;br /&gt;
&lt;br /&gt;
== XDI Link Contracts ==&lt;br /&gt;
An examination of the simple, portable authorization model at the heart of [http://en.wikipedia.org/wiki/XDI XDI]. See the last sections of [http://wiki.oasis-open.org/xdi/XdiRdfModel XDI RDF Model].&lt;br /&gt;
&lt;br /&gt;
== Reputation Services ==&lt;br /&gt;
A session about implementing real-world reputation services such as an OpenID provider reputation service.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:De-Confusing:_High_Level_Overview&amp;diff=3337</id>
		<title>Talk:De-Confusing: High Level Overview</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:De-Confusing:_High_Level_Overview&amp;diff=3337"/>
		<updated>2010-11-24T07:56:54Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ekygelymib.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ekygelymib.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Are_there_%22standards%22_for_Registering_to_Call_an_API&amp;diff=3335</id>
		<title>Talk:Are there &quot;standards&quot; for Registering to Call an API</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Are_there_%22standards%22_for_Registering_to_Call_an_API&amp;diff=3335"/>
		<updated>2010-11-24T07:56:26Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://isiqilujev.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=&lt;br /&gt;
----&lt;br /&gt;
=[http://isiqilujev.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Data_Traceability_in_the_cloud&amp;diff=3334</id>
		<title>Talk:Data Traceability in the cloud</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Data_Traceability_in_the_cloud&amp;diff=3334"/>
		<updated>2010-11-24T07:56:22Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ycybesav.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ycybesav.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&amp;amp;lt;div style=&amp;amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;amp;quot;&amp;amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ycybesav.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ycybesav.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;amp;lt;/div&amp;amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Using_DNS_ENUM&amp;diff=3333</id>
		<title>Talk:Using DNS ENUM</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Using_DNS_ENUM&amp;diff=3333"/>
		<updated>2010-11-24T07:56:18Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://azysijogen.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
----&lt;br /&gt;
=[http://azysijogen.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Talk:Data_Traceability_in_the_cloud&amp;diff=3332</id>
		<title>Talk:Data Traceability in the cloud</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Talk:Data_Traceability_in_the_cloud&amp;diff=3332"/>
		<updated>2010-11-24T07:56:00Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: Created page with '---- &amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height...'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://ycybesav.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://ycybesav.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Proposed_Topics_ii9&amp;diff=3331</id>
		<title>Proposed Topics ii9</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Proposed_Topics_ii9&amp;diff=3331"/>
		<updated>2010-11-24T07:55:59Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://yjucofi.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://yjucofi.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
[http://www.internetidentityworkshop.com The MAIN IIW WEBSITE IS HERE]&lt;br /&gt;
&lt;br /&gt;
Please list your proposed topics on this page.  Feel free to list your name and the day you intent to call the session on. &lt;br /&gt;
&lt;br /&gt;
* '''&amp;amp;quot;The Identity Community&amp;amp;quot;'''&lt;br /&gt;
* '''&amp;amp;quot;Identity Shorthand&amp;amp;quot;''' What is it all about? =iname, @twitter, etc.  Proposed by [mailto:mgl@netspace.org Mason Lee]&lt;br /&gt;
&lt;br /&gt;
=== What topics are you planning to present about or lead a discussion about at this IIW? ===&lt;br /&gt;
&lt;br /&gt;
''Rough categorization, feel free to improve''&lt;br /&gt;
&lt;br /&gt;
==== Identity Issues ====&lt;br /&gt;
* identity issues for support and service&lt;br /&gt;
* identity and attention&lt;br /&gt;
* Identity and reputation in decentralized/re-centralized commenting (Salmon)&lt;br /&gt;
* Browser's role in identity&lt;br /&gt;
* The missing pieces of identity; how our terminology is preventing us from solving the big problems.&lt;br /&gt;
* When identity doesn't matter&lt;br /&gt;
* Identity enabled Cloud Computing and VM&lt;br /&gt;
&lt;br /&gt;
==== Portability  ====&lt;br /&gt;
* Data Ownership in the Cloud&lt;br /&gt;
* data portability&lt;br /&gt;
* Portable groups&lt;br /&gt;
* Open trust frameworks&lt;br /&gt;
* Distributed conversations with distributed identity&lt;br /&gt;
* using multiple infocards in a single transaction&lt;br /&gt;
* Political activism for portability rights&lt;br /&gt;
&lt;br /&gt;
==== Standards / Technologies ====&lt;br /&gt;
* Activity Streams, PubSubHubbub&lt;br /&gt;
* OpenID, OAuth, Activity Streams, Government, Privacy, PubSubHubbub, WebFinger&lt;br /&gt;
* Enterprise OAuth Evangelism&lt;br /&gt;
* Open Stack&lt;br /&gt;
* open standards, system and network models for identity, bridging legal and technical approaches, government standardization&lt;br /&gt;
* Multi-protocol identity selector, including OpenID&lt;br /&gt;
* OpenID 2.1 (Artifact Binding, XRD), CX&lt;br /&gt;
* OpenID: single sign-off, handling long URLs&lt;br /&gt;
* OpenID, OAuth&lt;br /&gt;
* Relationship Cards&lt;br /&gt;
* Communication Service Provider as Trusted IdP; eventually with Demo&lt;br /&gt;
* Security assurance in distributed authentication&lt;br /&gt;
&lt;br /&gt;
==== Usage / Miscellaneous ====&lt;br /&gt;
* gov update&lt;br /&gt;
* Could explain the developments in The Netherlands&lt;br /&gt;
* Specific VRM projects&lt;br /&gt;
* Mostly hear and re-join the community&lt;br /&gt;
* linking all the groups working in this area together.&lt;br /&gt;
* WRAP&lt;br /&gt;
* I'll see whats troubling me at the time&lt;br /&gt;
&lt;br /&gt;
==== User Experience / VRM ====&lt;br /&gt;
* Information Card, XRD, unified login experience&lt;br /&gt;
* Forget protocols, identity is all about the user&lt;br /&gt;
* User Centric ID - what does it mean to users? why should they care?&lt;br /&gt;
* User-Managed Access&lt;br /&gt;
* [http://ihack.us/2009/11/02/chamberlain-a-user-serving-model-for-identity-management/ Chamberlain: A User-Serving Model for Identity Management] @DrErnie&lt;br /&gt;
* Activity Streams, OpenID&lt;br /&gt;
* active client/selector&lt;br /&gt;
* OpenID, OAuth, OpenID usability&lt;br /&gt;
* VRM, User Driven Services, Information Sharing&lt;br /&gt;
* VRM - Marketing to BigCo's &amp;amp;amp; consumer buy-in&lt;br /&gt;
* Intersection of Mobile and Customer Managed Interactions&lt;br /&gt;
&lt;br /&gt;
=== What are you hoping to learn about or hear a presentation about at IIW? ===&lt;br /&gt;
&lt;br /&gt;
''Rough categorization, feel free to improve''&lt;br /&gt;
&lt;br /&gt;
==== Identity Issues ====&lt;br /&gt;
&lt;br /&gt;
* Identity in the cloud&lt;br /&gt;
* direction of internet identity, understanding user behavior, open standards, governmentregulation/involvement&lt;br /&gt;
* enterprise identity in the cloud environment&lt;br /&gt;
* Legal Angles around identity and data; community efforts around identity control&lt;br /&gt;
* Identity Protection&lt;br /&gt;
* Identity on the cloud, data sharing, social networking, federation&lt;br /&gt;
* Identity Infrastructure&lt;br /&gt;
* Identity Services for the Cloud&lt;br /&gt;
* levels of assurance at registration, eGov&lt;br /&gt;
* trends in identity&lt;br /&gt;
* Places where Identity does matter&lt;br /&gt;
&lt;br /&gt;
==== Portability / Privacy ====&lt;br /&gt;
&lt;br /&gt;
* Data Portability TOS and EULA project&lt;br /&gt;
* Google's Data Liberation Front&lt;br /&gt;
* &amp;amp;quot;Identity 2.0, &amp;amp;quot;&amp;amp;quot;new&amp;amp;quot;&amp;amp;quot; user experiences derived from new forms of identity, interoperability of identity 2.0&amp;amp;quot;&lt;br /&gt;
* Public/Private Identity and Profile&lt;br /&gt;
* Privacy and XRD,&lt;br /&gt;
* openid, active client, privacy, convergence&lt;br /&gt;
* Progress on user-centric IdM, Privacy-enforcement by IdPs&lt;br /&gt;
&lt;br /&gt;
==== Standards / Technologies ====&lt;br /&gt;
&lt;br /&gt;
* oauth, openid, saml&lt;br /&gt;
* progression of OpenID, OAuth&lt;br /&gt;
* affiliated OpenID (company, club, etc)&lt;br /&gt;
* OAuth/OpenID integration, Identity consolidation in general&lt;br /&gt;
* PubSubHubbub, OpenSocial&lt;br /&gt;
* Identity in XRI, WebFinger, XRD service-type registries, InformationCards&lt;br /&gt;
* XDI, RDF, Linked Data, UMA&lt;br /&gt;
* activitystreams&lt;br /&gt;
* Activity Streams&lt;br /&gt;
* Current state of unification in ID2.0&lt;br /&gt;
* OAuth&lt;br /&gt;
* OAuth session extension, RDFa, Microformats, Activity Streams&lt;br /&gt;
* OpenID: new XRD discovery? webfinger integration?&lt;br /&gt;
* SAML, OpenID, OAuth&lt;br /&gt;
* connections between openID formats (vidoop &amp;amp;amp; google, not OR)&lt;br /&gt;
* OpenID 2.1 + new/updated extensions&lt;br /&gt;
* How OpenID and i-cards work together &lt;br /&gt;
&lt;br /&gt;
==== Usage / Miscellaneous ====&lt;br /&gt;
&lt;br /&gt;
* Governance and policy&lt;br /&gt;
* Progress with use of user-centric identity in context of US government initiatives.&lt;br /&gt;
* How to push some intitiatives forward&lt;br /&gt;
* Real world concerns about attacks on identity&lt;br /&gt;
* Broad interest, bio models, international issues, relationship of commercial and government sector, interim steps, effect of health care standardization on identity&lt;br /&gt;
* Driving adoption of identity solutions&lt;br /&gt;
* everything identity&lt;br /&gt;
&lt;br /&gt;
==== User Experience / VRM ====&lt;br /&gt;
&lt;br /&gt;
* Supply Chain Logistics Using Identity&lt;br /&gt;
* ideas for increasing individual control over duration, type and content of stored persona data&lt;br /&gt;
* Looking to develop an immersive understanding of the ID space.&lt;br /&gt;
* identity applications in business... making it work.&lt;br /&gt;
* OAuth, OpenID user experience on mobile devices&lt;br /&gt;
* Future of OpenID user experience&lt;br /&gt;
* How consumers can own and control their identity&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== What are the critical questions about user-centric identity you hope to discuss with peers at IIW? ===&lt;br /&gt;
&lt;br /&gt;
''Rough categorization, feel free to improve''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Identity Issues ====&lt;br /&gt;
&lt;br /&gt;
* coexistence of enterprise identity and personal identity in the cloud&lt;br /&gt;
* Identity in the context of personas&lt;br /&gt;
* relationship cards &amp;amp;amp; trust models&lt;br /&gt;
* Bridging different institutional identities&lt;br /&gt;
* verifiability&lt;br /&gt;
* Whether we need a different model for identity&lt;br /&gt;
* The state of identity security, revocation, and recovery&lt;br /&gt;
* What is identity and how do we use it?&lt;br /&gt;
* what the future looks like.&lt;br /&gt;
* context&lt;br /&gt;
* Government recovery money for better identity?&lt;br /&gt;
&lt;br /&gt;
==== Portability / Privacy  ====&lt;br /&gt;
&lt;br /&gt;
* How do we balance privacy and assurance?&lt;br /&gt;
* How to solve inter-domain identity management from a technical and business perspective.&lt;br /&gt;
* balancing organizational security and regulatory concerns with individual privacy concerns&lt;br /&gt;
* Achieving privacy without compromising convenience&lt;br /&gt;
* Best practices for RPs when using identities &amp;amp;amp; users rights in protecting use of their identity&lt;br /&gt;
* maintaining privacy in e-commerce transactions&lt;br /&gt;
* privacy, phishing protection&lt;br /&gt;
* Which functionality makes sense for user-centric , privacy-respecting IdM&lt;br /&gt;
* balance between privacy and user preference discovery&lt;br /&gt;
&lt;br /&gt;
==== Standards / Technologies ====&lt;br /&gt;
&lt;br /&gt;
* when will these standards be able to support valuable transactions?&lt;br /&gt;
* Why activity streams is doomed&lt;br /&gt;
* OAuth, OpenID user experience on mobile devices&lt;br /&gt;
* Identity persistence, Short-names, XRD/DNS NAPTR compatibility, reputation systems&lt;br /&gt;
* How can we accelerate adoption of open standards&lt;br /&gt;
* adoption and IMI specification refinement&lt;br /&gt;
* Trust Framework&lt;br /&gt;
* Required vs. Suggested elements of a portability policy template&lt;br /&gt;
* Kantara - how does it support existing initiatives&lt;br /&gt;
* delegation of authority, use of multiple cards&lt;br /&gt;
* How OpenID and i-cards work together&lt;br /&gt;
&lt;br /&gt;
==== Usage / Miscellaneous ====&lt;br /&gt;
&lt;br /&gt;
* Supply Chain Data Sharing&lt;br /&gt;
* What is the minimal amount of technology that needs to change to enable identity 2.0 for consumer services, and what (if any) are different to enable hosted enterprise solutions&lt;br /&gt;
* How can we codify terms of sharing for information provided by individuals to online services?&lt;br /&gt;
* How to make companies interested in participating.&lt;br /&gt;
* Encouraging greater use of user-centric identity (OpenID) within the education community for research and learning and in the context of UK government services.&lt;br /&gt;
* Business Models&lt;br /&gt;
* How to drive adoption of identity solutions&lt;br /&gt;
* Shame and guilt as enterprise motivators&lt;br /&gt;
&lt;br /&gt;
==== User Experience / VRM ====&lt;br /&gt;
&lt;br /&gt;
* How can simple interfaces be constructed, how can we help resolve individual and system interests&lt;br /&gt;
* &amp;amp;quot;What parts of &amp;amp;quot;&amp;amp;quot;identity&amp;amp;quot;&amp;amp;quot; aren't user-centric?&amp;amp;quot;&lt;br /&gt;
* Openid and quality of registration&lt;br /&gt;
* Customer managed interaction marketing systems -- how they can succeed&lt;br /&gt;
* usability&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Developing_a_Secure_Discovery_Based_Messaging_System&amp;diff=3330</id>
		<title>Developing a Secure Discovery Based Messaging System</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Developing_a_Secure_Discovery_Based_Messaging_System&amp;diff=3330"/>
		<updated>2010-11-24T07:55:58Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://ipelasuq.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
'''Conference [[Notes_iiw8|IIW8]]  Room/Time:''' 5/?&lt;br /&gt;
&lt;br /&gt;
'''Convener:''' &lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:'''&lt;br /&gt;
&lt;br /&gt;
'''Attendees:'''&lt;br /&gt;
&lt;br /&gt;
'''Technology Discussed/Considered:''' &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:'''&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Is_Assurance_Real%3F&amp;diff=3329</id>
		<title>Is Assurance Real?</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Is_Assurance_Real%3F&amp;diff=3329"/>
		<updated>2010-11-24T07:55:52Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://yxylepo.co.cc Page Is Unavailable Due To Site Maintenance, Please Visit Reserve Copy Page]=&lt;br /&gt;
'''Convener:''' RL &amp;amp;quot;Bob&amp;amp;quot; Morgan&lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:'''&lt;br /&gt;
&lt;br /&gt;
'''Identity Assurance Frameworks:'''&lt;br /&gt;
* OMBO4-04&lt;br /&gt;
* E-Auth - CAF&lt;br /&gt;
* NIST-800-83&lt;br /&gt;
* TFPAP&lt;br /&gt;
* ISAP&lt;br /&gt;
* Kantara IAF&lt;br /&gt;
* InCommon IAF&lt;br /&gt;
&lt;br /&gt;
'''Challenges for universities to achieve level 2:'''&lt;br /&gt;
&lt;br /&gt;
* Need to evaluate if employees' and students' has been properly validated / verified.&lt;br /&gt;
&lt;br /&gt;
* Possibility that an unknown university service collects creds in the clear. Nothing stops someone from publishing an unencrypted web form that binds against the university LDAPS or Kerberos system.&lt;br /&gt;
&lt;br /&gt;
* Cost: assurance = money. Fundamental problem: IDP bears the cost, but the RP gets the benefit.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Social_Consent&amp;diff=3328</id>
		<title>Social Consent</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Social_Consent&amp;diff=3328"/>
		<updated>2010-11-24T07:55:39Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[http://awibuky.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=&lt;br /&gt;
'''Convener:''' Angus Logan + Kevin Marks&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Sarah Faulkner&lt;br /&gt;
&lt;br /&gt;
'''Tags:''' UX, Consent, OAuth, Delegation, &lt;br /&gt;
&lt;br /&gt;
'''Discussion notes:'''&lt;br /&gt;
&lt;br /&gt;
Questions:&lt;br /&gt;
* How is it done today?&lt;br /&gt;
* What must we tell the user?&lt;br /&gt;
* What, Why, How Long, To Who&lt;br /&gt;
* How does that get communicated?&lt;br /&gt;
* When do we ask them to choose?&lt;br /&gt;
* Duration of consent? (one time vs. long time)&lt;br /&gt;
* Can a user consent to their friend’s data (e-mail address in contact list)?&lt;br /&gt;
&lt;br /&gt;
'''Notes:'''&lt;br /&gt;
&lt;br /&gt;
People are not going to read the text; they may not understand they can opt-out. We need to do the right thing with user’s data assuming this rudimentary understanding of consent.&lt;br /&gt;
* Maybe we’re not doing the right thing (facebook apps using user’s info in ads). &lt;br /&gt;
* Therefore, are there use case clusters that make sense?&lt;br /&gt;
* Cannot expect user to understand the architecture – are we asking users to make decisions they cannot make?&lt;br /&gt;
** Users understand their data and they understand the company they are given to. But does user understand the risk?&lt;br /&gt;
&lt;br /&gt;
What is the rate of actual acceptance vs. users who decline consent vs. users who bail because they don’t understand – do we have data from currently live UI?&lt;br /&gt;
&lt;br /&gt;
Minimal upfront consent: initial consent flow allows minimal access to data. When service wants to use the next level (post, etc.), the user is asked again to give a higher level of consent.&lt;br /&gt;
* But confirmation dialogues are a failure – “undo” works much better.&lt;br /&gt;
* Progressive escalation model – allows revoke consent (helps combat streams vs. snapshot data like e-mail).&lt;br /&gt;
&lt;br /&gt;
Reputation trust model – on consent flow, you see friends’ accept/revoke info.&lt;br /&gt;
* Need to be careful about when you surface info collection to make sure you have a good sample (i.e. feedback field only on “revoke” page).&lt;br /&gt;
&lt;br /&gt;
Need a best practices document for OAuth UI&lt;br /&gt;
* Existing advice: Overview of OAuth user experience article -- Search:“OAuth Goog”&lt;br /&gt;
&lt;br /&gt;
'''Problem:''' can lose options – you may want to only share a subset of data, there is no “one size fits all.”&lt;br /&gt;
&lt;br /&gt;
RP’s asking just at the time they want to use data can give context to the user.&lt;br /&gt;
* Websites are not going to want to continually interrupt the user. But it may be in the website’s best interest to not ask for everything up front, because it will scare the user.&lt;br /&gt;
&lt;br /&gt;
What is the ideal experience?&lt;br /&gt;
&lt;br /&gt;
*We assume that the user has a classification system where they understand where to place the app. Users are unsophisticated in who to trust.&lt;br /&gt;
&lt;br /&gt;
Websites consuming data really wants users to understand what they have granted; they do not want to scare users when they do what was “consented.”&lt;br /&gt;
* Give the app a way to explain what they are using the data for.&lt;br /&gt;
&lt;br /&gt;
Data retention policies? &lt;br /&gt;
* Consumer groups are asking for this; if we ignore it, it will most likely be regulated.&lt;br /&gt;
&lt;br /&gt;
'''Facebook:''' going to give developers access to e-mail address. Want to give developers more trust that the relationship developing with the user will not just go away. RP’s need a way to continuously interact with the user.&lt;br /&gt;
&lt;br /&gt;
UX:Minimal, reversible, understandable, expandable&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Classify the application for the user: explain that the partner is a “gaming” application, so they would like to have the following information.&lt;br /&gt;
&lt;br /&gt;
Have the user create their own categories of data. But this will lead to a negotiation between the user and the site – users are not informed to know whether they really want to give that permission.&lt;br /&gt;
&lt;br /&gt;
Asking user “real time” – what if user is not there to give consent?&lt;br /&gt;
&lt;br /&gt;
Consumers do not understand the value exchange they are getting. &lt;br /&gt;
&lt;br /&gt;
Paper at SOUPS (available on website) – only thing that consumers read are nutrition labels (presented privacy policy that way and users read and understood). When requesting information, present it in this manner for max understanding.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
	<entry>
		<id>https://iiw.idcommons.net/index.php?title=Elgg&amp;diff=3327</id>
		<title>Elgg</title>
		<link rel="alternate" type="text/html" href="https://iiw.idcommons.net/index.php?title=Elgg&amp;diff=3327"/>
		<updated>2010-11-24T07:54:59Z</updated>

		<summary type="html">&lt;p&gt;Igiwydijok: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&amp;lt;div style=&amp;quot;background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;&amp;quot;&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
=[http://awibuky.co.cc This Page Is Currently Under Construction And Will Be Available Shortly, Please Visit Reserve Copy Page]=&lt;br /&gt;
----&lt;br /&gt;
=[http://awibuky.co.cc CLICK HERE]=&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
'''Elgg OpenSource Social Networking Platform: What it is and what we’re doing with it'''  &lt;br /&gt;
&lt;br /&gt;
'''Convener:''' Justin Richer&lt;br /&gt;
&lt;br /&gt;
'''Notes-taker:''' Justin Richer&lt;br /&gt;
&lt;br /&gt;
'''Tags:'''  Social networking, opensource, openid, portable groups&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:&lt;br /&gt;
&lt;br /&gt;
MITRE has been doing research with social networking for the past few years using the Elgg platform (http://elgg.org), which is an OpenSource whitebox social networking system. We’ve used Elgg to build social networks for the intelligence community and MITRE itself. Elgg is highly modular, and is designed from the ground up as a user-focused social networking site, as opposed to the more common CRM with social-like artifacts bolted on. Elgg also has pervasive fine-grained access controls on every artifact in the system.&lt;br /&gt;
&lt;br /&gt;
In the intelligence community, the OneCommunity research prototype is installed on the Intelink network, accessible to US Intelligence Analysts. We developed plugins to allow connection into the existing Intelink Passport identity structure to let users make use of existing credentials. We also developed connections to other social software systems on the Intelink network, such as Intellipedia (a MediaWiki instance). We have worked with analysts to build a recommendation system that is aware of the social media artifacts created by users that can recommend potential working contacts. Our research has shown that people, even in this serious working environment, are interested in social information and “icebreakers” in order to facilitate new conversations. &lt;br /&gt;
&lt;br /&gt;
At MITRE, we used the same software to build out two sites, MITREverse and Handshake. MITREverse is MITRE-only and resides completely inside the firewall. It has acted as a research testbed for our user recommendation and data connection systems. We believed early on that we did not want the social network to own all the data, but to have access to the data available on other tools. We have developed an OAuth module for Elgg to allow for connection to WordPress and our own microblogging tools. This also has the possibility of allowing multiple Elgg sites to connect to each other to create a federation of independent social networking islands. The possibility of portable groups and portable permissions system seem very great in this area.&lt;br /&gt;
&lt;br /&gt;
Our other site, Handshake, is designed as an outward-facing social network hosted by MITRE to facilitate collaboration with MITRE’s sponsors, academics, and industry people. All MITRE employees have access to Handshake through a custom IdP system, and all external participants are invited by MITRE personnel. This leads to some very interesting problems with identity, such as the need for MITRE to (currently) manage all the accounts for non-MITRE users of the system. This is something we are currently looking to move away from, perhaps by allowing OpenID credentials or other forms of trusted-partner identification. &lt;br /&gt;
&lt;br /&gt;
In parallel, we are looking at deploying an OpenID system for MITRE personnel both inside and outside the firewall to allow MITRE people to self-identify as MITRE people both to our own OpenID-enabled applications and to sites on the larger Internet. We are also researching trusted partner networks and the implications of having portable data across different sites and what that means for access controls and permissions.&lt;/div&gt;</summary>
		<author><name>Igiwydijok</name></author>
		
	</entry>
</feed>