Friday, September 21, 2012

"The Politics of Sharing"

I attended a very interesting discussion this week at Microsoft, about the politics of information sharing. The topic was being explored from a local government perspective. It became clear that under the guise of "we are not allowed to because of the Data Protection Act" many local government departments and services avoid sharing information about citizens with other organisations, often to the disadvantage of the very citizens they are responsible for serving and protecting.  The real reasons for this was far simpler! The seagulls in Nemo are good exemplars!

It became clear that many of the representatives of the various bodies, organisations and advisors had missed two key points!
1) Not sharing causes more harm than good, (though there were some present who understood the dangers of not sharing, and that effective sharing can be good for citizens)
2) The information that they were refusing to share, was owned more often than not, by the very citizens that they were elected or paid to serve!

We had a number of discussions about some important mechanisms that need to be in place to enable sharing, such as the standardisation of definitions and standardisation of API's. We recognised that a more effective means of virtial identity was required, and that asset owners would also need to be able more effectively and efficiently manage entitlement and access to their data. One excellent point that was made involved the "value" flow in the transaction. Individuals would either be paid in cash for giving access to their personal information, or could benefit other ways that they would value. (I would allow the police to have access to my home alarm system information, if that meant they would respond quicker to an incident. I wouldn't expect them to pay me for access to such data!).

There was apparently begrudging agreement in the room around the concept of citizen centric data stores, there were however far too many individuals who preferred the idea of creating Government controlled citizen "Big Data" stores shared across multiple agencies, "All the better to control you with my dear!". The recent World Economic Forum's paper on the subject effectively signals an important shift. 

Imagine a local authority that provides each of it's citizens a personal data store and helps them create wealth from this personal data store (likely taking a portion of the income for providing the service and as a means of reducing local tax,) while at the same time using the data store to enhance the safety and security of those same citizens. Information stored in such local government personal data stores would only be data that relates to the business of local government. Other more sensitive data would be in more 'personal' Personal Data Stores. There are many businesses that would love to gain access to such local government information that for example details which houses have double glazing installed. This data may not always be used for wealth creation, as an example it might also be used in the context of supporting the  infirm and aged.

Imagine the "politics of sharing", in the light of an ecosystem that creates wealth for the individual citizen, reduces their local taxes and gives local business access to accurate and timely data that helps drive the local economy. 

Human Agency can be even further enhanced by the full and complete realisation of exactly whose data it is. Politicians and Regulators will do well to recognise that their focus should shift from being overly concerned about the details of privacy law, to the more fundamental and far more important issue of Cyber Agency.

After all it is the control over the curtain that gives privacy. Privacy is simply the result of being in control. So laws that encourage increasing the control by the citizen over their own data, and the development of Personal Data Stores, will be good for the economy, the individual, and society. So why are we not seeing such laws being enacted. My belief is simply that the power is in the hands of those that currently create wealth from our personal data, citizens rarely pay lobbyists!

What to do? The answer is simple : Ensure value flows to the individuals and organisations that created or own the data. Anything else is Data Usury.
Doing so will involve taking on those that would lose out from such a redirected flow, and remember, voters, the economy and society can all benefit.

The web will finally be able to do what it was designed for, creating a more open and egalitarian society. 

Wednesday, September 19, 2012

Data Entropy, my new battleground

In a recent Blog Simon Wardley was bemoaning the inappropriate use of the terms Structured and Unstructured as they pertained to data, I started writing a comment that turned into this Blog.

I believed the words that he was exploring also pointed to the power Entropy has over data. The simplified post (I didn't see the EP/LP version of his Blog, he had reduced its length b4 I read it) seemed to assume an inexorable flow from Unstructured to Structured. As humans we are in a constant battle to bring structure, order, form meaning to the world around us, this especially applies to data.

History is still only what we believe happened, as we have yet to gain dominion over data. A key difference between energy and data is that data can be destroyed and far too frequently is destroyed, as the non-existance of many historic records can attest!

I was trying to find the word equivalent to exergy, which applies to energy, in the world of data, when it struck me the lack of its existence maybe because that with data there is no "maximal value". Which on reflection is obvious as when one uses data or information and take nothing from it, far from it more often than not combining data can create new data/information plus there is no natural friction in the world of data just entropy. This in itself was on obvious realisation, but then I already knew that the more I knew the more I realised I did not know!

In our journey of transformation, fighting data entropy all the way
- with data (bits) to information (informs) we add form to create new facts or "informs"
- with "informs" to knowledge (knogs) we discover new forms, & meaning 
- to achieve the highest form we make the right use knowledge and attain wisdom!

Aside: It strikes me that with data, entropy reduces the value of data with the square of time, like gravity reduces with the square of distance.

This is shown very well when I look at the graphical data that I have stored about my life, I can readily access images from a month ago, but many of the images taken a decade ago are lost to my iPhoto album, or of they exist in the Album have lost meaning. The majority of images from my childhood are lost with a few hanging on by their finger tips in physical photo albums, the meta data around even older photos makes them all but meaningless; Who is that man in a soldiers uniform in that fading sepia photo?

Thus my final comment after the mind storm that Simon's Blog evoked is:-

Thankyou I created this Blog as a direct result of your post Simon
I enjoyed the journey and find myself even more motivated to fight data entropy, and add or maintain the order, structure/form and meaning of my personal data. 



Which makes me even hungrier for the Linked Data tools I can only envision but have not the skills or time to create. ORAC is sounding more important and desirable every day, Blakes Seven has a lot to answer for! 

Monday, September 17, 2012

Wot d'ya mean "Digital Exhaust", it's gold & Mine!

or "Asserting my Human Digital Rights is pretty hard if they are not defined!"

Sadly no matter how hard I read the Declaration of Human Rights, I can no-where in them find the provision of my Digital Rights. Admittedly Article 8.1 - "Everyone has the right to respect for his private and family life, his home and his correspondence." provides very effective right to Privacy especially if we assume the definition of correspondence, to include all data communicated between myself and others, including machines.  This does not however give me ownership, or control over my data, whether it be the data that I deliberately create and store, or the data deliberately leaked from my devices, often called data exhaust or even data that judges or regulators try and call theirs! The data that defines location of my digital devices is mine, or at least it should be! There should be no doubt that anyone that wants to access and/or use that data should have my express permission to do either. Though there may be just cause to gain a court order to gain access to the data without my permission.

Dear Politicians and NGO bureaucrats,
  Please can you turn your attention to defining the Digital Rights of Individuals, including their agents.

Perhaps our friends in WIPO might see there remit expand to include the Data of Individuals, not just the "Intellectual Property related to Corporations and Artists? There is likely to be a better way, than simply re-purposing a current organisation whose role is becoming greyer as the Internet makes Transparency the new reality.

What that is remains to be seen....

Thank you

A very concerned Cyber Citizen

Tuesday, September 04, 2012

From Paper to Plastic to Silicon based Credentials

Digital Wallets are the new Identity battleground, who can get you to put more of your Identity into their Digital Wallet?... Google's "Wallet" , Apple's Passbook, to be launched in their new iPhone next month, or Microsoft's relaunched e-Wallet with their new Windows 8 Phone this Autumn. NFC will become just the underlying technology.  Mastercard and Visa are both getting in on the act with with Digital Wallets, though mostly payment focussed. 

Initial Reactions

What do you mean I can't get digital receipts? 
How can I stop stores from rifling through my Digital Wallet and harvesting info? 
How do I know what information they did get? 
Can they keep all the info or did they just get a "One Time" glimpse? 

These are just a few of the natural questions people will ask in order to get an understanding of the state of the key elements of Agency, Trust, Useability and Manageability in the Digital Wallet space. It is early days and there is a lot of issues to resolve, barriers to remove and most importantly cash flows to figure out. 

The Bottom Line of the Digital Wallet Service Provider:   Who is going to get paid for what?

Contents of a Leather Wallet

As you can see I had 17 "Paper and Plastic" credentials" in one of my Leather Wallets, that I'd want to include in a Digital Wallet with a few more that I don't normally carry around with me that I would happily include.

My Bottom Line: 

My wallet supports more than simple cash transactions
I don't want a Wallet Service for every Identity I own
I want ONE "Virtual Wallet" that is secure and very easy to control, but I want access to it on every device I own.
A few important architectural questions :

When will Ubiquity occur?
A difficult one to answer!

Are the better solutions Proprietary or Open?
I have my bias!



Can "credentials" be easily moved from one Digital Wallet to another?
Today.. no! Tomorrow.. a must have!

Will users want to trust their device as the sole credential repository?
Would you?

Will digital wallet silos, ie a wallet service that only stores ONE credential, really work?
Some are betting yes, at least in the short term.

Things to watch:

The Trust Nexus A network of cloud based identity repositories

Square & Starbucks An innovative location based Identity approach

Question for Organisations to ask themselves

Will my organisation have the ability to enact transactions with these emerging Digital Wallets?
Will my organisation have the ability to put "credentials" into these emerging Digital Wallets?
What will be the advantages of doing so?
What will be the disadvantages of not being able to do so?
Are the solutions adhering to the Jericho Forum IdEA Commandments?

Question a smart consumer should ask: 

Why didn't the organisations making the shift to Silicon based Identity know about the Jericho Forum Identity, Entitlement and Access Management Commandments or watch the Jericho Forum IdEA Videos?


Identity Video #1 - Identity First Principles.   
Identity Video #2 - Operating with Personas.    
Identity Video #3 - Trust and Privacy.    
Identity Video #4 - Entities & Entitlement.   
Identity Video #5 - Building a Global Identity Ecosystem.   


Is this the beginning of the end of Paper/Plastic Credentials for your organisation, or the beginning of the end of your organisation? For there are some very raw and powerful tectonic identity forces at work under the covers of this simple sounding shift. Do you understand them?

Wednesday, August 15, 2012

Controlling consumers; eyeballs or wrists

It has been understood for a long time that the eyeball is the pathway to control an individual. The trick is that in the past the war for the consumer eyeballs have been played out quite openly, in adverts on the TV. Adverts have always relied on both subliminal and supraliminal stimuli. More recent behaviours have taken the war to control consumers both mobile and underground, out of the scrutiny of regulators or indeed often the consumers themselves. Signs have been surfacing, the challenge is for us to identify and  interprete these signs, and react before it is too late.
(cf gently bringing a live frog to the boil, first it goes to sleep in the nice warm water!)

George Orwell made part of the leap in 1948 when he realised that controlling the populace was likely to be achieved through taking control of the media for messaging and the television set in the home for monitoring. However he did not have the benefit of hindsight, nor did he predict the amazing advances that mobile technology would bring.  How could we expect him to, when we are in the here and now and apparently are not spotting the emerging issues.  George in his book 1984 represented states which were reducing the agency of their citizens.  Some people might relate this to human rights, but sadly we have no human rights when it comes to Cyber Agency, (which is whole separate Blog topic). I want to keep it simple, I believe I should be able to control my destiny, and control devices and information related to my journey towards this destiny. There are folks out there who want to wrest that control from me, and worse they are making rapid progress, especially in the Wild West of Cyber Space.

Some of the signs:

Carrier IQ: US Phone Carriers inserted spyware on US Mobile phones
Mobile Spyware Services are being made publicly available that allows anyone to do it!
Samsung Smart TV Terms and Conditions
(If you have a Samsung Smart TV you should seriously read the ToS)

Despite much searching I cannot find them on the internet, so here are a few interesting pages: This page gives the right to Block Access to Samsung Smart TV for any reason.

As an aside, just after powering up and connecting "my" Samsung Smart TV to the internet, Samsung took control of "their"? device and started deleting applications from it and replacing applications with others. I was powerless to stop them.

If you own a Samsung Smart TV I hope you didn't think you would be in control of it!

If this is not bad enough, later parts of the ToS define, what Samsung believe to be, non-personal data, anonymous data, including your IP address, and your search terms!? 

An IP address can easily be used to identify a household and from there it is not difficult to identify occupants.
In later parts of the ToS, Samsung give themselves the rights to ship your data anywhere in the world they want to, and basically to whom they want to. 

During the sign in process Samsung also appear to gain access to and control of your FaceBook identity, if you choose to use the Facebook App.

Then on this page the European regulatory discussions about citizens managing their right to be forgotten is well and truly squashed.

The latest Samsung Smart TV comes with a built in camera, any body spot a similarity with George Orwells world?

The battle is now officially joined, especially as Samsung appear to have realised what George did not, the future is Mobile! Therein lies the key to gaining control of consumers. I believe they have realised that the trick to controlling consumers is not just to be in front of their eyeballs but from where you are doing it, the corner of their room, their laptop, or to be with them in their pockets. We can extrapolate that the next key step will be a piece of real estate more valuable than eyeballs, pockets or diamonds, their wrist. Watch as the power problems are resolved and a small wrist mounted computer becomes a reality. The winners will be the ones that own the device on the wrist.

I predict their will be two camps, with a naive few in the centre of the battle stating that it all doesn't matter and all information should be free. The low ground will be quickly taken by those intending to grasp all forms of Cyber Agency from their Customers and/or Citizens. They will prosper for a while, and are prospering in these early Cyber years. Until a more internet savvy generation emerges to state their agency expectations more clearly, we can expect the current Internet sheep to head down for free food into the warm and green pastures. The second camp can only really emerge when a demand for their services comes clear, those that take the high ground will build services that allow the consumer/user to regain cyber agency. (This does not mean that the providers need to give up control of their assets/services.)

Posit: This may sound like a scary world for providers, who expect to make money from their Customers, until they realise that by actually giving their Customers more control there is more chance for Profit if their Customers feel that their interests are also at the heart of any transaction.

Having your assets and services out of control is clearly a bad idea... the answer in 2 dimensions (where the Asset or Service is conflated with the Consumer) is obvious Gain Control as Close to the Consumer as Possible,
Once the parties can get to the high ground they will gain a more complete perspective, empowering clients while maintaining control of an organisations assets/services becomes a more beneficial play.  Many organisations are assuming that in order to control their assets and services they have to gain control of the Consumer. The value of empowering the Consumer will not occur to these organisations.
Those that do will also note that a new set of Trust Services will need to be implemented.

These might also start to become known as Agency Services, and they will be Agents operating in the interests  of the Consumer. (Hopefully following Asimov's 3 Laws of Robotics)



So let's watch as the race to control customers shifts from the corner of the room, to the laptop, to the pocket, to the wrist, then when this achieved watch as organisations struggle to put the consumer back in control, while maintaining control of their assets and services. Those that head straight for mutual control, close to the individual consumer have the highest chance of long term success.






















Saturday, March 10, 2012

From concern about Privacy, through Primacy, to Egency.

Well I've slept on it and the change is on! Whilst Primacy, the first word I was trying to propose to explain the concept, does indicate the state of being "Number One", "Agency" as used primarily by philosophers is really closer to the concept of being in control of one's data and therefore being in control of one's virtual self.  However "Agency" does not convey the data or the virtual aspects of the crucial concept we are trying to convey.  It was in conversation with Mike Nelson at 15:00 on Friday the 9th of March , in a Google Hangout conversation, that he lead me to "Egency", a neologism that will, hence forth, mean "the state of being in control of (one's) information assets".  Egency (the more flowery? amongst you may chose to apply a hyphen to get e-gency, though I am not in favour) can be applied to all entities, (organisation, human, device or code).  Egency will become an important thing to regulate, as humanity starts to realise that "Egency" is in fact a Human Right.  More-over we will recognise that it is the true economic life blood of this virtualising economy of ours.  There will be courses on "How to become more egent".  We will come to realise that egency and transparency are in fact good bed fellows, Wiki-Leaks will be seen as an early major shift towards egency.  Artists will recognise that the prior business model, where their agents became more egent than themselves, and their publishers even more so, was a massive egency #fail!  Publishing and Piracy are in fact both theft or misappropriation of egency.  We will finally come to understand how we are sleep walking into a world, where our egency is being sucked from us all, authors, artists, and consumers alike.

Here's hoping that at least one large corporation will come to understand that removing egency from it's users is, in fact, "Doing Harm!"  Do we really want to become the energy source of the internet, cf "The Matrix".  Will we wake up soon enough?  For "Egency" is the oil in the coming centuries economic engine; egency both powers and lubricates.  We cannot let it leak away, or be syphoned off!  To enable and protect egency we will need an open and transparent e-trust ecosystem, but that is another post!

My primary fear is one best articulated in the April 11th New Yorker cartoon by Mick Stevens... "What if the meek don't want it?"

You can purchase a copy here: http://www.condenaststore.com/-sp/What-if-the-meek-don-t-want-it-New-Yorker-Cartoon-Prints_i8472845_.htm

My thanks to Merlin, Lord Erroll, my LEF colleagues, including Mike Nelson, Doug Neal, Simon Wardley, Jim Ginsburgh, and all my colleagues in the Jericho Forum (especially Paul Simmonds, Steve Whitlock, Andrew Yeoman), and Chris Wiesinger of CSC for helping me to this mind-state.  I am sure that there are others who have also influenced my thinking, I hope they will forgive not being mentioned.

Related Concepts to explore
Commoditisation of Publishing = Egent Positive
Consumerization of Identity = Egent Positive
Micro-perimeterisation = Egent Positive
What is the antonym of "Egency"?

Friday, March 18, 2011

Is 1984 a step closer?


A debate this week in the House of Lords, does not appear to have hit the UK broad sheets. Some may think that it was of little consequence, as it was simply the UK choosing to sign up for the idea that Passenger Name Records should be kept for ALL Pan-European flights in a massive European Travel Register. Lord Hannay in his own opening speech, promoting the motion, stated that it was a "considerable invasion of privacy".
The declared goal is the standard "protect us from terrorists" mantra, the negative or unexpected consequences of such a large database being available to all European Governments are not apparently being included in the decision. This is especially concerning as it is also likely that the US Government and other Foreign States may gain access to the database by fair means or foul.

Let's consider a few "Abuse Cases":
Simply by tracking the flights of the CEO's of all the major European companies a Foreign State, could glean significant information about potential mergers and acquisitions.

As The Earl of Erroll pointed out in the debate a Foreign State could acquire information about the travel companions of key leaders of Industry, or other Foreign States, that could in turn be used to blackmail or pressure said leaders.

Given the attributes to be stored will include passenger financial data, the database could be the cause of a massive exposure of Credit Card details.

As The Earl of Erroll also points out if we were concerned about the dangers of a National Identity Register, why would we not be concerned about the dangers of a European Travel Register that arguably will hold even more detailed information.

The record of large government organisations when it comes to protecting the private records of its citizens have not been shown to be the highest. Just how access to such sensitive data would be limited to those exploring Terrorism or Organised Crimes is not clear.

What's next? The recording of all train journeys across borders, and then car journeys, and then...?

Should we not all be as concerned the Earl of Erroll?

Sunday, February 27, 2011

I was in a EURIM meeting last week discussing the importance of establishing an Identity Governance Framework that would help set the direction of regulations and other key components that would enable the development of an e-Identity Infrastructure. All those present believed in the importance and value of such an Infrastructure, there was whoever one aspect that did not seem to have universal agreement.

Basically it came down to the need for a Universal Identifier that would be owned by Governments.

In this case we were talking primarily of the identity of Citizens. I responded very clumsily to what seemed to be a proposal to tie such an Identifier to the Identity used for voting, it turned out to have been tied through the Registration process, my visceral reaction remained. I mumbled my concern without clarity.

Today I was in reminded of the Lord of the Rings and its relationship to this problem. I declare myself to be a Hobbit who sees the creation of the Rings (of Identity?) as something to be feared, especially the One Ring, the one that binds all the others together.

The forces that would have us believe that a Universal Identifier should be created by governments in order to protect us from thieves and terrorists, are not being fully transparent with the potential negative impacts, partly because the law of unintended consequences is so relevant in this space, but also they don't want to declare their own intents.

Let's remember what was inscribed inside the "One Ring"

http://en.wikipedia.org/wiki/File:One_Ring_inscription.svg


One Ring to rule them all,
One Ring to find them,
One Ring to bring them all,
And in the darkness bind them.''

A chilling reminder, for those that understand the message that Tolkien was sharing with us.

Basically it is a question of Primacy, who owns the Identity of an Individual?
Some would say the State, I would say the mature and sane Individual
I was sure this right would be enshrined in "The Universal Declaration of Human Rights" but despite reading and re-reading the articles I found no clear declaration, while Articles Three and Six touch on the concept. The right to own ones Identity is not explicitly stated.

The first Jericho Forum Identity Principle (under development) addresses this topic it currently reads:
PRIMACY: Invisible Root Identity – The privacy and integrity of a core “Identity” is ALWAYS safeA Root Identity must be uniquely and permanently connected with an Entity/Principal and must NEVER need to be disclosed.

Rewritten as a new Article 31 of the The Universal Declaration of Independence it would read:
Everyone has the right of primacy over their Identity, no State, group or person may usurp that right.

Tuesday, January 11, 2011

From Silo to .....

The shift from being a silo focussed Enterprise, to a Deperimeterised one is NOT a simple task. The primary reason for this is that it involves a tectonic shift in all the key components of an organisation, including all those that relate to each of the major domains of People, Process and Technology, in short everything must change.
The Culture of the organisation must change from top to bottom, this shift involves moving from a "Do It Ourselves" to a "Do It Collaboratively" approach. In Information terms this means moving from keeping Information to ourselves, to sharing information with others. This leads to the need of a fundamental shift in governance systems, meaning that the systems that govern the direction of, and behaviours in an organisation often need to be reversed, and certainly re-designed. The implications of the importance of this part of the "shift" can be seen in the failure of many organisations trying to make the shift. Business Leaders making this change understandably feel nervous and as a result resort to taking up the governance reins, hoping that they will be able to effectively steer their organisation throughout the change. Empowerment is the first thing to suffer with this approach, as this behaviour is observed and replicated down through the leadership ranks, and yet Empowerment is one of the most important success factors in making this change. This results in a failure to appreciate which of the many unknown processes in an organisation are key and which can be eliminated. My own view of the failure of Michael Hammer's Re-Engineering of Enterprises in the 1980's stemmed from the basic fact that the Leaders of an organisation of any reasonable size have no way of being able to understand all of it's processes. Especially as so many of those processes are "unknown" and certainly undocumented. (The most successful re-engineering exercise I was ever involved in occurred in France, where an enlightened leader, whilst using an external consultant, insisted that all of his staff were involved in the re-engineering exercise, unfortunately the effort were supplanted by a "Top Down" change that was Global resulting in a 400% loss of productivity.) Changing the business processes of a silo based organisation to deliver the needs of a Deperimetersed one, is not a trivial exercise, and certainly not one that can be achieved incrementally. For few organisations understand all the processes that they operate, let alone the Information Assets that are key to these processes. Our inability to manage the vast amounts of information that modern Enterprises produce inevitably leads to the use of Information Technology, and here-in lies the tail that wags the Corporate Dog. Advances Information Technology has lead to an amazingly powerful tension driving organisations towards Deperimeterisation. Cloud based services, being simply the latest of these advances. Consumerisation is another of these technology mediated tensions.

I am reminded of a challenge in one of the many corporate team building exercises that I have had the pleasure of engaging in. This one had me dressed up in massive amounts of padding, connected to bungy cord and then told run up a padded aisle to see how far I could get. The weird experience of having the bungy cord decide that I had come far enough and drag me flailing back to the start must have been designed to teach me something, though I can't remember what.
in the case of the Silo based Enterprise, the bungy cord is Deperimeterisation, and no, it is not connected to the other side of the Grand Canyon but to the Moon. in the words of Eric and Ernie, "Get out of THAT without moving!"

The good news is that Mankind has demonstrated our ability to get to the Moon and back. Is your organisation ready to demonstrate the capabilities needed to achieve this shift? If it is small and agile, then likely yes, if you are in a large organisation here's hoping you have a charismatic leadership team with Vision, who believe in Empowerment.

To those expecting the word security to appear in the body of this article, on September 12th 1962 did Kennedy use the word Security in announcing the endeavour that relied upon Security at every step?

"We choose to go to the moon. We choose to go to the moon in this decade and do the other things, not because they are easy, but because they are hard, because that goal will serve to organize and measure the best of our energies and skills, because that challenge is one that we are willing to accept, one we are unwilling to postpone, and one which we intend to win, and the others, too.". http://www.historyplace.com/speeches/jfk-space.htm

Will your organisation choose to go to the Moon or will it be dragged there flailing? One thing I will say is; your ability to treat Information as a valuable asset is going to be fundamental to your success, with a rethink of "Identity, Entitlement and Access Management" being a crucial early step, but that's another blog!

Sunday, January 09, 2011

Mac App Store introduces the opposite of Shop Lifting

The opposite of Shop Lifting would be called something like Wallet Snatching.

With the new functionality introduced by the 10.6.6 upgrade the Mac App Store introduces the unwary to a new means of losing their money. The App Store used by iPhone, iPod, and iPad owners has a two click to purchase interface. With Mac App Store, Apple have introduced, an arguably devious, means of increasing sales by eliminating the "Are you sure?" Click.

This seems like a minor deal, but you must remember that the Terms and Conditions of App Store basically says when you have bought it it's yours and there is NO means of getting your money back apart from going to the developer of the software.

I am not a lawyer but I believe that Apple have successfully driven a coach and horses through the sale and purchase of goods Act, which clearly states that it is the seller, not the manufacturer, who is responsible if goods do not conform to contract.

This coupled with the fact that the App Store was not built to be secure from the developers perspective is a reason for developers who value their brand and their profit to steer clear from the App Store.

A recent incident I experienced with the SlingBox App has damaged Sling Medias brand in my eyes and certainly means I will be doing no more business with them. I also aim to stop as many of my friends as possible from buying Slingboxes. This arguably all stemmed from Sling Media's use of App Store, and hiding behind the Apple's decision to ignore the Sale and Purchase of Goods Act.

CAVEAT EMPTOR is even more important when it comes to doing business with Apple.
I think that may be assuming that they are above the law!

Yippee! End to End Secure FaceBook

"A step towards being my Identity Service Provider"

In the wake of FireSheep and the ability of coffee shop squatters to harvest authentication cookies from insecure WiFi Networks, and gain "one click" access to FaceBook accounts, FaceBook have started up a new way of accessing FaceBook. With the launch of https://ssl.facebook.com/ one can now have their authentication cookie, and all other data, securely transferred to and from FaceBook. While this does not solve all of FaceBook's security issues, (after all they still use Username and Password for account access!) it is a very important step. All FaceBook users should shift to this means of accessing FaceBook. Currently, it is still in a testing phase the service will be more broadly promoted in coming months.

So to benefit from "end to end secure FaceBook" change your FaceBook bookmarks now, I have!
Now all I have to do is figure out which of the many applications I use to access FaceBook use this secure protocol.
Anyone have a list?

This is a welcome step, and if FaceBook continues in this vein, I will be happy to expand my use of them as my Identity Service Provider. Recently they are more openly about positioning themselves as an Identity Service Provider, they are choosing to gain the position by slowly on FaceBook App at a time. More importantly they have the potential to gain the trust of Enterprises as an Identity Services Provider. They are more likely to achieve this status, if they comply with all the Jericho Forum Commandments.

There are some additional services and capabilities that would help me make this step. What am I missing ?

1) A revised authentication infrastructure that eliminates the use of Username and Password as the prime method of Authentication to FaceBook

2) An easy to manage Security Dashboard that allows me simple oversight and control over my web based Identities

3) A Security Monitoring Service that has the capacity to alert me when my data is being harvested, or misused

4) A means of more finely selecting which of my data I want to share with specific services that use FaceBook Connect
(Currently it is a binary decision, often "All or Nothing", with little ability to negotiate)

5) Methods of enhanced authentication, which I can choose to use for specific services that I may choose to use FaceBook Connect with.

6) Various Methods of warning when specific events, of my choosing occur. I would see three levels "Alert Ferocity"
a) Poodle: Just giving you the heads up
b) Jack Russel: Seriously annoying until you accept the alert
c) Pit Bull: Will fight to the death to get the alert through to you, no matter the cost

7) An ability to apply varied levels of friction to information flows that I can select for different types of data, or specific data elements.
a) Open = No friction, Anyone has access
b} Closed = Limited Friction, Many have access, though it is easy to share with others
c) Combination Locked = Serious Friction, fewer have access, but it is difficult to share with others
d) Key Locked = Ultimate Friction, few have access, and I am informed when they access

8) A Transaction Dashboard that allows me oversight and control of my ALL web transactions, this service will only be possible after FaceBook has really proven their ability to look after my interests.

Clearly, I expect others, not just FaceBook, to be aiming to provide these identity services and this list equally applies to them. Some providers will have more complete and robust services, others will not provide the complete range of robust and trustworthy


Source of key elements in this blog
http://technologyreview.com/printer_friendly_article.aspx?id=27027

Saturday, December 18, 2010

Abstract Thoughts on "Information Friction"

The problem appears to be growing worse! Information Technology is becoming like a silicon spray reducing Information Friction to the lowest levels ever. The issue is simply that it is easier than ever to accumulate vast amounts of information and distribute it globally and instantly with little effort. The consequences of the reduction in Information Friction, are both positive and negative. The dilemma is that while individuals are pleased to give up their information to a specific organisation for a specific gain, the organisations do not always keep their side of the bargain. On the other hand the more Enterprises are intent on keeping information restricted, the more valuable it is for Insiders to share it, with the resulting phenomena of Insider Senioritisation

As was recently identified by the ISSA in their http://www.issa-uk.org/whitepapers/ISSA-UK-InformationSecurity-TheNextDecade.pdf chaired by David Blunkett at the Houses of Parliament and commented upon in David Lacey's Blog; The world needs much more innovation in Information Security. Perhaps it is time to look to the Jericho Forum Command,emts for inspiration; how might they suggest we should approach putting the friction back into Information Flow, and who should be in control of the lever that applies said friction?

I will be researching these questions in my work on Next Generation Identity (or should that be Access?) Management for the Leading Edge Forum


I am very interested to hear from those who has some ideas.

The main three problems
Behaviour Change, Behaviour Change, and Behaviour Change as it is truly "all about them" where "them" are the users!

How does one mke it :
Harder to accumulate large amounts of information
Tougher to deny ignorance of knowledge
More difficult to distribute large amounts that your are not supposed to have

In short how can we put the Resource Owner in charge of the resource. nigh on in real time


UNDER CONSTRUCTION, but feedback welcome

Wednesday, July 21, 2010

FaceBook & Privacy

I hate how FaceBook thinks that people's actions are theirs to share!!!
=========================
"Adrius, Who's Missing?
Willie, Freda and Hollie have tried the
automatic Friend Finder and found out."
=========================

Funny how I know the three of them. This is FaceBook basically "telling" me that they are inconsiderate individuals who think that sharing the contents of their address book with FaceBook is not a Privacy issue.

I bet they thought that they were doing it quietly.... you know under the radar ....no such luck folks!!!

"FaceBook sneaked on you!!!"

At least I didn't post your photos here... like FaceBook did, to make it really clear WHO was being inconsiderate!!!

Doh! I bet you suspect I just made the same mistake as FaceBook....

Actually, I changed the names to protect the innocent, I mean inconsiderate!!!

Wednesday, July 14, 2010

Where do I interact on the web?

No, seriously! Where? This morning I awoke with a nagging thought that somewhere on the web, I was in the middle of a conversation, in fact, a number of conversations. Clearly by losing track of these conversations, I was potentially being rude, but worse wasting my time and the time of others! Then it struck me that is one of the meanings of "weak ties", not only do the "weak ties" relate to the strength of the link between individuals, it can relate to the strength of the link between an individual and the application or service in which they start a conversation. Ultimately, it relates to the weak ties between an individual and the conversations that are started, What has this to do with the Jericho Forum? I have only just realised that Deperimeterisation is a much broader force being caused by the inexorable evolution of the world wide web, than I had previously grasped. A force very strongly related to that word I can never remember but happily have for this blog: ENTROPY! It does NOT just relate to an Enterprise or Organisation, the force can and does apply to a much broader set of domains. Some examples that are broader than Organisational Deperimeterisation:
Individual Deperimeterisation
The result or implications of information boundaries dissolving around an individual.
Geographic Deperimeterisation
The result or implications of information boundaries dissolving around specific geographic areas (Home, City, County, Country, group of Nations)
Conceptual Deperimeterisation
The result or implications of information boundaries dissolving around Trusted Concept Containers.
News Deperimeterisation
The result or implications of information boundaries dissolving around Trusted News Containers.
What are concept or news containers?
I can answer what they used to be, in their perimeterised form, much more easily than describing their evolving future !
Encyclopaedia Britannica was an old example of a concept container that could be trusted. They are exemplified by a number of old style "publications": Books, Peer Reviewed Papers, Magazines
Whereas News Containers or the recording of current history is also easier to exemplify in their perimetrised form. The Times or the Washington Post being two examples of perimeterised News Containers. Julian Assange's WikiLeaks being an example of an evolving deperimetrised news container?
(Read Stephen Moss article in G2 14.07.10 Darn that's one of those perimeterised containers, so you will find it hard!)
Deperimerisation is occurring across MANY domains simultaneously, we are in a massive transition!
I don't envy the lawmakers as they try and legislate for this change.
So finally back to my realisation that my conversations were being deperimeterised. I have come to understand that my deperimeterised conversations are not solely my responsibility! Which is certainly not where I started this blog. For such is the power of weak ties, it brings such things as concepts together good ideas naturally clump! So conversations that are important will take on a life of their own, though I have a sneaking suspension that another force is at work in this space that lowers the tone and import of conversations. So an important question for our future will also be: In a deperimeterised world how will we keep avoid sinking to the lowest common denominator. That has always been a challenge for humanity. SO I must own the type and level of conversations I join in.
Thus our challenge as Human Beings is to BE the concept! But that still leaves me with this nagging doubt that I am part way through many conversations, but there-in lies the power of "Weak Ties!" It's perhaps part of the reason I will be drawn back to them, for like all good weak forces they work over tremendous distances!!! Considering the different types of Deperimeterisation, each of the types have different implications that need to be handled by the relevant "authorities"???
But hold on isn't Authority being deperimeterised also? Yes, but that is a topic bigger than this blog!

.... Come to think of it Lawmaking is being deperimeterised also, what will THAT mean?

In the meantime, how can I better manage my virtual conversations?

Tuesday, July 06, 2010

It is NOT all about the devices and the Networks!

It's actually about connecting the right people, groups, and enterprises to the appropriate data, informs, knogs and services! It's ages since I've seen or heard those words. For the life of me I cannot remember who wrote them. It wouldn't surprise me to find that it was something to do with Index, and the folks surrounding Michael Hammer. But Google has let me down, I only get stuff about a cycling or a Spanish radio station! Back then we had the idea of knowledge management; the hierarchy of data, informs and knogs were clear (informs are units of information, where-as knogs are units of knowledge, often described as all the elements needed to make a fundamental decision), services were still hazy back then too! The problem was that we hadn't really figured out that the devices and networks were crucial foundation pieces. Knowledge Management on a "green screen" in a data center didn't really hack it. However, now that we have the devices and the networks largely in place, that should allow us to start thinking again about moving our application development thinking from the application or silo mode of IT to the knog and service mode. So, why do we seem to be stuck in the old frame. Many moons ago I was introduced to a concept called "soup". Does anyone remember the Apple Newton? It was trying to be a ubiquitous device that could connect people to knogs. It failed for a number of reasons, not least the jokey battery life, and its inappropriate focus on handwriting recognition, heck!, I can't even read my own handwriting! What it DID have was this concept of a "soup" that applications and services could dip into, create and manipulate. At least, that's what I hoped it was, until I watched how the app developers turned the knogs back into their own, proprietary like, stagnant ponds of stunted and partially formed knogs. Of course it's easier to write apps when only your app needs to understand its own data. The very idea of every app being able to, or needing to understand all data is clearly ludicrous, but surely every app should understand data relevant to all apps like it, or similar. Why do developers insist on storing data that only their apps can understand. Oh, wait a minute you don't mean that they do it for app or vendor lock in purposes do you...Or is there another reason?? I guess they just don't understand the power of the Ocean! For the "Ocean" is a new mega collection of Soups, and is far more powerful, and for that matter far more primeval! Especially as this new huge Ocean is growing a set of Informs that are increasingly described by RDFa, that can be accessed by these huge new and ever expanding Social Groups that could be described by FoaF. I don't have Martin Birbecks dream of having ever more people writing apps, I just want the ones that do, to write apps that understand the Ocean of Informs and can connect to the ever expannding Social Groups. (Assuming of course we don't all lock ourselves into FaceBook.) There are solutions that are starting to be populated in this emerging Semantic Layer by knogs described in RDFa and People described by FoAF. (Perhaps Diaspora will show the way?)

Now all we have to do is help folks make the shift.... Doh!!! I just realised that quite apart from the new application development mind set we need to engender, we can't yet make the shift, as there IS still another layer needed above the Devices & Networks, and above the Semantic Layer, before we can start connecting the People & Knogs. A ubiquitous Entitlement Layer, for it is a MUST, as that would be the bit that made the initial statement possible. As it did not read connecting ANY people, groups, and enterprises to ANY data, informs knogs and services!

This reminds me of a Vison I once helped write:

Extend Human Capability and
Promote Global Collaboration by
Providing Continual Natural Access to
People and Knowledge

It should have read:

Extend Human Capability and
Promote Global Collaboration by
Providing Continual Natural Access by the right
People to the appropriate Knowledge


But I was younger back then, and a lot less wise....


.. but I am still not yet wise enough to wave a magic wand and have ubiquitous autonomous knogs in play today!

Monday, March 15, 2010

Unclean!, Unclean!, Unclean!


There is something very wrong with the currently proposed legislation, which focuses on the actions of the citizens at the end of the digital pipe. The greater crimes, being enabled by the ISP's, are not those being focused on by the special interest groups.

Let's jump back in time to a famous water pump near a London Pub, this particular pump was contaminated with the Cholera bacterium and was killing off the citizens of London. If the currently proposed approach were to have been taken in 1854, then those that had caught Cholera from the Broad Street pump would have been denied the right to take further water from the pump. Clearly anyone not yet infected would be welcome to drink from the poisoned source. The death toll would have been horrendous!

Similarly, the flow of unclean bits is the root of the most critical problems we face on the internet, a fact that is clearly not the focus of those that would protect the wealth of the old "Publishers". Unclean bits are those bits that carry the malware, that create botnets, that steal our privacy, often our identities, and worse our wealth, but always our bandwidth! Legislation should focus on ensuring clean bits, just like the legislation of Clean Water after the Cholera Outbreak. The basic fix back in 1854 was the clearing out of the cesspools, which improved the cleanliness of the water from the pumps.

We can learn from history, the 1852 Metropolitan Water Act and "The Grand Experiment" maybe useful. Perhaps if we connect a large number of citizens to the fetid internet connections they currently enjoy, and an equal number to a connections that are "e-pure" and evaluate the results. We will come to the similar conclusion to that John Snow spent his life campaigning for, "Clean Bits are good for the citizens of cyber space"!

It is likely if we have the ISP's focus on the digital cesspools and not the activities of the citizenry, then the internet will continue to grow to be the greatest revenue generator we have ever known. It will not, however, if we try and constrain it with copyright rules designed for previous centuries. The Jericho Forum would call this thinking Macro-Perimeterisation, moving the management of information risk out into the Clouds.

The music industry should be enabling the flow of clean bits, for as figures are now showing the growth in digital music is now more than offsetting the loss of CD sales. The Featured Artists Coalition are the beginnings of moving the power and finances back to the creators and artists. The death throws of the old publishing industry and their attempt to impose their old models need to be managed with care.

Let's hope our legislators look to history for clues to solve this situation.

Tuesday, January 19, 2010

Two Corners of the Cloud Cube


One interesting effect that can be observed at present is the polarisation occurring in the two extreme corners of the JF cloud cube.

In the Blue Corner characterised by the elements; Internal, Proprietary, and Perimeterised are the Infrastructure teams of many organisations who are saying
"We can do Cloud! look a Virtual server called into being in less than 5 minutes....
clever us... you don't need the outside Cloud anymore stick with us!"
(Oh and by the way the outside cloud is a scary place if you stay inside our silo you can "feel" more secure!)
These are often called Private Clouds, the US Govt G-Cloud is a prime example, watch out for the emergence of the term E-Clouds, meaning Enterprise Clouds.

In the Green Corner characterised by the elements; External, Open (Though there are still substantial remnants of Proprietary) and Deperimeterised are the advocates of Consumerisation who are saying
"The Cloud is out there!, lets use it!
Why call into being a server when you can have a service?
Imagine how easy it will be to collaborate with the outside world!"

Why does this polarisation have such a critical impact on the collaboration opportunities offered by the Cloud.
The answer is simple if too many organisations are suckered into the Blue Corner then the powerfull collaboration opportunities of the Green Corner will be killed off.
There will be less reason for External Cloud based Identity Provider Services to be launched. All the enabling services will only be viable if the larger enterprises make the move to the deperimeterised parts of the cloud. It is clearly in the interest of the current providers to keep the Cloud Private.

The unfortunate result of the growing number of Private Clouds will be that the evolutionary leap will not occur the "mud skip will crawl back into the slime and continue to rely on its gills for oxygen".
We will all need to stick in our own little corporate ponds and the progress towards freeing Information and extending human capability will be stymied once again.

Happily the power of Consumerisation will likely provide a force for change, the Customers of these silo based organisations, have a voice and they are starting to learn how to use it.

Friday, December 25, 2009

FaceBook Privacy "<"NOT!">"

The dastardly folks at FaceBook have repeated the same trick they have tried before, to take control of YOUR information! They have exposed the names of your friends to the world... They should be STOPPED!

If you are a teenager, then the folks at FaceBook have taken one of the most effective pieces of information that "nasty" folks could use to befriend you and made it available to them with out any warning.

They have made your Friends Lists available to those same "nasty" folks, despite how you had previously set the lists privacy! In effect THEY decided that everybody should share the names of their friends so they changed the roolz!

Happily a hue and cry from the great FaceBook Public persuaded them to enable your ability to make your Friends Lists sort of "Private".

HOWEVER you will not find the means of changing the Privacy of your friends list in the Settings page!!! You will need to click the pencil on the Home Page by the Friends List section. Then un-select the show friend list to everybody box that our FaceBook friends so kindly to set to YES!

Happily there is a website that explains it more clearly than I just did...

Thanks Avinash!

But if I were you I would look around for a Social Media site with a little more ethics!.

PARENTS
Think carefully about letting your offspring use FaceBook or for that matter MySpace
If you choose to let them, help them make sensible choices about their privacy settings. The reason is simple : Keep them Safe!

This problem is not new as this news report shows!
July 2006 CNET Page

CHILDREN
You will know some very security unaware Parents! Please help your Parents use Social Media sites carefully. For one very simple reason it will save you future embarrassment! Seriously!!! Do you really want that photo of your (Fill in the Blank) shared with the world.

Thursday, November 19, 2009

Identity and the Black Hole

There are many reasons for us to drive the e-Trust frame onwards and upwards, not least the implications of the loss of electronic trust. The impact of a catastrophic failure in e-Trust would be profound. Leaving the recent financial melt-down looking like a mere blip. I predict that one of the reasons for such a failure also provides the means of protecting against that same failure. That reason is the failure of electronic identity to appropriately protect the users of the internet from their fears. Identity Theft and other identity failures are occurring at an astonishingly more rapid rate. I posit that the public's ability to accept such failures has a very finite level and once the level is passed e-Trust will rapidly start to collapse. I propose that the response is very similar to the ability of Ethernet to accept "collisions", it works fine up to a point but once that point is exceeded the knee of the curve creates a sudden and precipitous drop in the networks responsiveness. A large number of users will accept a surprisingly large number of identity incidents but at a certain point the willingness to "e-Trust" will collapse in the populous.

This positited phenomena, simply positions the importance of expanding our ability to protect e-trust by enhancing identity across 5 domains: Applications, Enterprises, Devices, Users and Information as crucial to our economic well being..

In dialogue with Steve Greenham, I have developed a model for ascertaining "Identity" using the Digital Shadow of Users. Coupled with a shift to claims or attribute based access management we have the potential of creating a robust means of protecting e-trust.

In the same way that the location of a Black Hole can be identified, so to can the identity of a human be identified. In the case of the black hole it is by observing the phenomena that the existence of the black hole in a specific location creates. In the case of a human being, one can observe the "Digital Shadows" of the user and predict to the required level of confidence the identity of the user.

There are a number of intriguing challenges that will be documented later in this blog.

The present challenge is how to rapidly enable this approach. It will require the partnership of a large number organisations to put in place the capabilities that will allow us to avoid the precipitous collapse of e-Trust. For who knows where we are on the e-trust curve? Humanity has not been here before!

Tuesday, April 21, 2009

From Identity Service Provider to Identity Provider Service!

I had the pleasure of meeting one of my identity heros at ESAF on Monday; Kim Cameron. It went well and truly made up for my trip to PARSIFAL, where I had been told he was going to present, I did however meet the EU Information Commissioner at PARSIFAL though, and discussed with him the importance of Cloud Based Identity. This initiated the seed growing.

At ESAF I also bumped into a number of other potential Cloud Based Identity Players. The result of the interaction with Kim created a massive brain explosion. The result two words swapped places. Seems such a minor result when stated like that! :-(
But Identity Service Provider became Identity Provider Service! (IPS)

Definition: An Identity Provider Service, is a Cloud Based Identity Service Model that allows any individual, leader of a group or organisation to create identities for themselves or their members. Allowing the management of the Identities in such a manner that they can be simply used by and within the group or organisation, or can be raised to a level of trust whereby they can be consumed by third parties, and as a result the Identity Provider and Identity Provider Service can recieve a revenue.

The following Graphic attempts to capture the concepts that were borne in my mind, undoubtedly the result of reading what many others have written on the topic and watching the Dick Hardts Identity 2.0 Video (he's my other Identity Hero, how can I properly cite all the folks who helped create conditions for the two words to swap! My friends at the Jericho Forum undoubtedly played a key part, especially Steve, Paul and Andrew. I am confident that the LEF Cloud Study Tour also had an impact. So I lay these out for the world to consume in an OPEN Manner. In the hope that a new Identity Provider Service Model will result.



Imagine the three Customer, Professional and Organisation components as Blimps floating atop the Identity, Claims, & Access Management landscape. They will be populated with Personas with Claims that need to be verified. These claims could either be self asserted or verified in the "New Cloud based Identity Provider Service" approach ie the Scout Leader or the BMA said they were they accurate claims!

I see the Identity Provider Service being delivered at varying levels of trust, Self Asserted (Free), Group Leader Asserted (Free with Certificates), or Organisational Assertion (One Off Fee with Certificates), and Authenticated Organisational Assertion (higher One Off fee with additional means of authentication) Payment is made by the consumer of the identity in the latter two cases on a transaction basis (think credit card transactions) and this payment is split between the Identity Provider Service and the Identity Provider.

Expanding the example the Boy Scouts of America may choose to allow each Troop Leader to publish their own Troops Identity or negotiate a higher Trust Level with IPS and issue Certificated Authenticated Identities for which they will receive revenue when the Identities are used/trusted by third parties. The Identity Provider Service would operate like Mastercard/Visa charging a verification fee that rises dependant upon the the level of Claims being Made and the Risks involved in the transaction.

The British Medical Association could choose to issue an electronic identity to its Doctors using this Identity Provider Service approach and recieve a revenue from the organisations that consumed the Doctors Identities that naturally came with a verified Claim that they were a Practising Doctor (Meta Data of the Claim to be determined)
NB In this new IPS Model all parties would need to determine HOW the Identity Risk is shared. The BSA would be the Identity Provider. IBM, PayPal, Microsoft, RSA could provide the Identity Provider Service following a standard approach. Lots of legal and compliance stuff to be sorted!

But in the meantime it could start small, I would use the service to publish Information Cards (for that feels like the best form in which to create the Identities) for my friends and family so that we could all safely interact on the Web.

I wouldn't buy a "Geneva Server" to do that but I would certainly sign up to the first IPS that would allow me to publish such Information Cards.

After the concept takes off, I predict an early explosion of Identity Provider Services followed by a shake out that would reduce to 3 maybe 4 providers within 3-5 Years. The number of Identity Providers would remain large. In comparison to the Credit Card Model, I can get a Credit Card from the Royal Society for the Protection of Birds! Why? because they earn revenue from it... I'd quite like an RSPB Identity for my Twitcher Persona!!!!

Alternatively we could continue populating the Blimps from the Enterprise Centric Model, more costly and less effective. Please NO!

I propose the population of the Group, Organisation and Professional Blimps ahead of the population of the Customer Blimp, ultimately these three Blimps will merge. Initially Enterprises will think they want Enterprise issued Identities to fill the Customer Blimp using this new Cloud Identity Service Model but eventually we will get that the other Identities are cheaper and more reliable!

Needs far more thought, for 'tis early in the morning...

But I just had to share!!!