Thursday, August 29, 2013

The Agency Balancing Act... Part 1

Having read this New York Times posted a while back I thought "I want one!"
http://bits.blogs.nytimes.com/2013/02/10/disruptions-apple-is-said-to-be-developing-a-curved-glass-smart-watch/?_r=0
OK so I want one, but probably more important I want control of the Personal Data Store that it will fill up with, as the device I want will be capable of gathering a lot of data about me, the wearer. 

While I am at it, I also want the ability to point Apps at my data, all my current Apps have their own data, more often than not, in the control of the App publisher, "What's up with that?".

For those that remember an earlier mobile device and its special approach to storing data, I dream of us getting back to the Newton Soup. The soup though, will be MY soup, not Apple's soup or Googles soup.
(Sadly if you really did follow the evolution of the Newton all of the App developers back then kept their soup in their own soup bowls... Doh!)

My soup will be chunky and very valuable, to me and others, as all of the chunks will have descriptors (meta data)... which means I need a way of looking after my soup, so my Chunks will also have Rules that will manage who has access to which chunks and how much they have to pay for it. My Soup will have Agency and be pretty Smart at it!

I don't want the hassle of having to manage all that on a day to day basis, so I want an Entitlement Agent, in fact I want lots of different sorts of agents over which I have dominion! But that's another post.

And so should you! You should be standing shouting from the rooftops.

We want Cyber Agency, and we want it Now!

Before it is too late...

By the way if you are an Enterprise you should be shouting 
"They want Cyber Agency and they want it Now!"
The folks who win will be the ones that OWN your Customers data, and if it is not your Customers, where do you think that puts you, Oh dear!, that will mean that you will be a customer too!
We all know that Disintermediation sucks, especially if you are the one being disintermediated! 
(Now Mr or Mrs Enterprise person into your bat cave and ask yourself what's the chances of us being able to persuade all our customers to let us own their data? Be honest with yourself!)

Best put your Customers in control then!

So Cyber Agency is the new balancing act:

 - give them their data before they can sensibly and easily maintain control of it and someone else will snarf it!
 - keep it for too long and they will move their custom elsewhere, to someone who does give them control.

<

Life's hard!

Wednesday, July 31, 2013

Changing face of Security in an increasingly Collaboration oriented world

While I agree the title is a handfull, there is much behind this topic. It recognises that Deperimeterisation is more than just an IT Security phenomena, and much more about the increasing business need for collaboration, both with other partners and also with customers. Innovation is increasingly externally powered. Organisations that try and survive inside their silo, peeking out to sell their shiny new product or service will find that the world has changed significantly, since they last peeked!

This new business frame requires a complete RETHINK of Information Security, moving to incorporate the enablement and assurance of Positive Value, by replacing security tools designed solely to protect / control / stop / monitor ; with a new breed of tools designed to ensure, promote, enable, and prove.  Imagine SMART DATA that not only did not allow the inappropriate entity from accessing it, but actively seeked out an appropriate entity, and reported when it had found one.

In short, the discipline of Information Security will take off its peaked cap, put down its STOP sign , and actively engage in understanding and ensuring that Business Goals and Business Rules are met.

From Security = Bolt On Braking Device

To Security = Built In Hybrid Motor that acts as both Engine and Brake!

Perhaps we will need to change our functions name to Information Asset Management?
Which by identifying the Opportunities and Risks associated with information assets under an enterprises control, can maximise the value of said Assets, reduce the potential for threats or losses, while ensuring real time compliance. The toolset will be completely different!

Like moving from the old world of Photography which required the creation of a "Negative" in order to then create the final Image (Which always involved loss of Quality!)
To the modern world which involves sensors directly capturing the positive image.


When InfoSec teams change their primary goal from one that involves disabling inappropriate access to one that ensures appropriate access, the outcomes will undoubtedly be more positive.

Perhaps the harder question is: How do we get the Infosec tool creators to re-tool! They like selling using Fear, Uncertainty and Doubt! It is so much easier for them. Worse, building security in will be very hard, especially as the first question is: WHAT ARE THE BUSINESS RULES?

In most organisations they are Implicit, Assumed, or worse in the heads of just a few folks who think that keeping them to themselves gives them power! But that is a whole other post.

Tuesday, April 16, 2013

Agency and the Internet of Things / Everything (IoT or IoE.. You choose!)

As the word Agency starts to gain credence and regain it's original meaning, the state of being in control, we are starting to understand it's importance. Sentient entities have the capacity to have agency. I gave my Smart TV (made dumb) another chance the other day, the first thing it did after I gave it a glimpse of the Internet was to delete two of it's Apps. I had not made this request, clearly Samsung thinks the device is theirs and not mine, I have no means of controlling how it uses it's Smarts, thus it was disconnected again. At the same time Apple are making a veiled attempt to give me control over my iPhone. They have introduced a means of controlling Advertising on the device. "Your challenge should you accept it, is to find the control... this tape will self destruct in 10 seconds" OK, clearly the mission isn't actually impossible, but give yourself 1000 points if you opened settings and went straight to the "About" section.

Agency is something we should work hard to retain, for when it is lost, it will be very difficult to regain. Put at its most basic; Freedom is a result of having Agency. Many of the worlds constitutions aim to keep their citizens safely in control of their lives. (That word "safely" has many implications)

As the number of Things in our worlds gain the ability to behave in an apparently sentient manner we should be very wary of who is actually in control of those Things.

A recent experience in our conservatory got me into hot water, the conservatory lights are controlled by X10 switches. My wife started complaining that the lights had started to have "a mind of their own" (a very agency laden phrase!) After two weeks I tracked down the issue to a subtly hidden infra-red detector that had previously been programmed to switch on the lights if movement had been detected. No names, but I had shown the controlling device to another member of my family, who presumably thought it would be fun to hide the detector in the lounge, facing in such a way that the conservatory lights would be triggered at seemingly random intervals.

In an old episode of StarTrek: The Next Generation, based solely on the concept of Agency. "Data" was triggered by his creator to return home, and he used his Cyber Hacking skills to take over the Starship Enterprise, over-riding any number of security controls to take on the Identity of the Captain and add his own security layer that locked the Captain from taking control of his own vessel. Data's creator had even gone to the lengths of locking "Data" out of his own memories of the event.

Agency will become a very important aspect of the Internet of Things or Everything depending which hype laden article you read, and thus Identity and Entitlement services will be crucial. Sadly just as with all things related to Safety and Security they are generally added after the fact, rather than built in.

If I had my druthers (an 1870's American term for Agency, being a contraction of "would-rathers") I would ensure that everything I owned was in my control, and as the things become harder to control I would have an Agent acting on my part to help me deliver the control required.

Any one remember having to manipulate the choke on the carburettor? My guess is that few of the Nintendo generation will have experienced the joys of flooding a petrol engine, especially not under the withering look of a father, who being ever so competent at all things mechanical, could manipulate the choke in his sleep.

The interfaces involved in controlling complex machinery reduce to fewer and simpler. Designing natural interface, or controls that offer Affordance, another key aspect of Agency, is not as simple as it looks.

Services in the Internet of Everything world must offer Agency to the right folks at the right time with the right degree of Affordance. (Not the affordability that pertains to the cost of the service... look it up!) After all you don't want to be like Jean-Luc having to separate the saucer section while travelling at warp speed in order to regain some semblance of control.

So all you folks designing Everything that will connect to the Internet, design Agency in, and be very careful about assuming that your clients don't want any of it....

Appendix
Perhaps more importantly to all folks designing Agents here is my list in order of importance of the Agents that I want

Software Update Agent: Allows for the automated update or deletion of software under my control, not the control of Samsung or Apple.
Security Agents (I suspect there will be more than one) My use of the OpenDNS service best exemplifies this service, good luck trying to access pornography from my household!. I have four buttons to press to select how aggressive the filtering is, note to self don't use the highest level again, as it stops key folks in the household accessing Social Media! Bad Idea!
Identity Agents
Agency Agent (This one makes my head hurt but think of it as the Butler that manages all the other Servants to ensure a smoothly run life!)
Entitlement Agents: Manage my Entitlements, both those bestowed on me as well as those I bestow on others.
Contract Agents: Arguably a join of Identity and Entitlement agents. Would manage all the contracts that cost me or gain me wealth.
Energy Agent : Would manage the energy hungry devices in my world to consume at cheaper rates, or lower levels.
Home Automation Agents: We've touched on these...
Garden Agents: Water my greenhouse when it needs it, I am fed up of withering or waterlogged seedlings!

Agents, are in my mind like Fire and Forget weapons, rather than the Fire, Ready, Aim wire guided missiles that still need the continued involvement of their operator.

Monday, February 25, 2013

Tyre Frustration: Where do I put the data?

The Prius needed an MOT, apparently according to the newly published data, tyres and brakes cause the most MOT failures in my particular model of Prius. Hurrah to the DVLA for finally releasing the data. But that's another Blog "The value of joining public and personal data"

So anyway I checked the tyres, and lo I found damage to a sidewall a possible MoT fail. I then spent an inordinate amount of time researching the tyres I should put on the Prius. There is now a whole section in "mybrain" devoted to the data gathering effort. Thanks to the EU we have new data on Fuel Efficiency, Braking and Noise created by tyres, sadly they have not furnished us with the the missing Rate of Wear data. (I suspect the industry fought hard to keep that from us, or perhaps it is inversely proportional to the Fuel Efficiency impact and governments are keeping the data from us) No matter how hard I looked I could'nt find the data. Frustration growing... Data should be easier to get than this I should be able to just ask my agent. What are the tyres that will give me, great braking, the best fuel efficiency to wear ratio, and who is the cheapest supplier?

I eventually found the tyre I've gone for a set of Falken ZE914s C/B/70dB from ctyres.co.uk, they have now been fitted. I also had the car serviced they found two of the wiper blades split, (note to self check the wiper blades before the next service) They gave me a piece of paper with lots of very useful data printed on it relating to the safety of the Prius, including 12 point depth check of the tires. Try as I might I could not find an A/A/70 !!

But all that is the build up. I now have a lot of potentially linked data most of which is embedded in the text above, that will be useful to me later and some of which I would be very happy to make public. But where the heck do I put it all...

If I don't store it all now how will I be able to ask my personal agent...

"How long did those first Falkens last?"
or
"How many miles did the last set of tyres do?

The answer is clearly that I won't be able to....

So I want a personal data store, and I want it now!!!!

Otherwise it's going to take a while longer for my personal agent to be useful to me, just asked SIRI he didn't have a clue. But then what should I have expect from a cyber butler whose only focus is pleasing it's real employer: Apple, and who clearly doesn't have access to my personal data.

Regulators skating to where the puck never was!

In ice skating the trick is apparently to skate to where the puck will be, I suspect the same is true of developing regulations. Naturally, though a regulator wants to reduce the impact of the last pain point that cost them votes. So we should not be surprised by the fact that not only are they not skating to where the puck will be, they rarely skate to where the puck is!

This is especially true in the fast moving world of the internet. We might think about the controls needed in the future being about where the puck will be. The need for agency, as where the puck is at present, and the desire to solve Privacy issue as where the puck was, while the "Right to be Forgotten!?" as some confusion on the part of an as yet unidentified individual, for the puck was never there!

I fear the regulators are putting far too much energy and focus into Privacy and not enough on Agency or the Capacity to Control our environment. Primacy, Transparency, and Privacy all result from having Agency, which means in the sociological sense; the ability to control one's environment, which in turn relies on having access to usable controls.

All Entities should be concerned about maintaining their Agency, whether they are Governments, Enterprises or Individuals

I wonder whether in the race to secure the internet, we are not rushing headlong towards a world where we ALL lose Agency, apart of course from those that manage to grab it. I see this next phase as the great Cyber Agency Land Grab.

Google, Amazon, Facebook and perhaps to a lesser extent Paypal, all understand this.

Hopefully our regulators will make the switch in time....



An example: Facebook, having become masters of moving the curtains to the their side of our windows,  have now quietly moved the ability to protect one's Identity out of our control to a less easy to find, and impossible to control location, ie on our friends Facebook page! Worse they have set the default to "expose" or as I say to my students "Promiscuous Mode". With the upcoming Facebook Graph Search, understanding and applying the controls we do have, will be even more important.

The outcome is that we as individuals have lost control of how we expose our identities, the responsibility or agency was moved to our friends and the control is not placed in the obvious Privacy enhancing location.  Agency Fail = Loss of Privacy

There are many more examples; Enterprises of the future will find that they have been disintermediated, and that the internet storefronts of the future will be owned by a small number of powerful corporations. We may achieve cyber security, but at what cost?

If I were in control of an Enterprises' Information Technology Strategy, I would be looking hard to find solutions that allowed an Outside-In approach to Identity, that kept the my enterprise in control of it's assets, and my customers in control of theirs. Easier said than done! I would also be encouraging the regulators to look to solutions that enabled growth of the economy and stop them making regulations that encouraged citizens to believe that they ever could be forgotten, let alone have the "Right to be Forgotten!"


Tuesday, January 29, 2013

Is the Identity Iceberg Toppling?


Posit 1: The future includes a time when entities own their own Identity.
Posit 2: In that future the focus on Privacy expands to the more important concept of Agency

River's regularly change course, without the landscape fundamentally changing. However, the landscape on the Identity Iceberg given it does topple would change dramatically. The challenge seems to be that intellectually even some of the identity 2.0 protagonists are looking at the opportunity apparently assuming that the landscape is not going to radically change. Perhaps they believe that the forces at work aiming to strengthen and maintain the new status quo. This would result in the Amazons, Googles and the Facebooks (AGFs) succeeding in owning our personal data. While it is clear that individual enterprises should give up now on the idea that they can each own our individual identities, for they are rapidly being marginalised by the AGFs, with Linked-In, and more recently Salesforce making a late attempt to join the Entity Identity grab. Linked-In and Salesforce entry into the space further counter the forces that could topple the Iceberg. Unless of course any of these switch to becoming a true Identity Service provider with the Individual and their devices as their main users, and enterprises as the Payors.

I first realised the possibilities behind a dramatic shift in the Identity landscape, when sitting behind a one way mirror listening to a diabetologist responding to questions about Identity on the Internet with the immortal phrase: "I need another Identity from a pharmaceutical company, like I need a hole in the head!" In the pharma sector this tension was resolved with DocCheck, an organisation that had pharma companies pay to know that a doctor was actually a doctor. This need was triggered by a German Law that required pharma companies to ensure that only doctors could access their medical websites. This is an Identity Service model that took a step towards the future world by giving doctors the opportunity of controlling an Identity that would be trusted (and paid for) by multiple pharmaceutical companies. Thus DocCheck started extending the monetisation of Attribute claims, from the "You will get paid" claim, which was already in place with Credit Cards.

Even the UK Governments innovative Midata program is seemingly just looking at giving individuals "access" to their data which has been collected by others. 

There are clearly folks looking at things from an entity centric perspective. At present I am not betting either way, though I am clear which way I do want it to go. I want to benefit from the value in my information / attributes either from services I value, but occasionally from a monetary sense.

The most important aspect I want from this world is that desire to be in control of how my information / attributes are used, in short I want to have Agency. (Actually I want Agents that will do that for me... but that's another blog....)
Agency defined as "the capacity, condition, or state of acting or of exerting power."

Given that there is a tectonic shift in play, enterprises have a number of options.
1) Try and maintain the status quo (which would be like trying to super glue the San Andreas fault)
2) Give up and let the new Identity players take control of their clients Identities and Attributes 
3) Be part of a movement that ensures individuals have Cyber Agency, help create a Cyber Trust Ecosystem that will enable individuals organisations access to their Identities and Attributes

Readers who also engage with my LEF persona will know that Consumerisation has been a interest of mine for years. Indeed Doug and I created the original topic on Wikipedia.  Chris Weisinger of CSC identified that this shift towards Cyber Agency, involves Consumerisation.  I had previously toyed with the concept of Identity being consumerized, but he spotted that actually we are talking about the "Consumerisation of Power". A Blog topic in itself that also alludes to Doc Searles Intention Economy

I will be coming back to tighten up this Blog but I want to put it out there...
Apologies for the weak grammar and poor structure and flow.




Some relevant Links

Monday, January 28, 2013

"An Englishman's Data is his Chattel"


<\\SOAP BOX MODE: ON> 

"An Englishman's Data is his Chattel" :- We seem to have forgotten this important point, which is often mistaken for a lesser statement about homes and castles!

I believe that it is down to the lawmakers of England to reinstate this key right, not just for us Brits, but the whole world. In fact we need an addition to the UN Declaration of Human Rights. A declaration of Digital Rights.

e-Trust can only come from a base of clear data ownership, "big data" is confounding this key legal concept. There are whole businesses being founded on the idea that acquiring my data, using it and selling it on without my express permission is legitimate.

Yesterday I received an email offering me 1.6 Million email addresses for $450
I was affronted as they were clearly likely to be selling one of my email addresses gained by theft or fraud. The particular email it was sent to was one of my many ghost email addresses "twitterdeck @ s-mail.me.uk" one that I never use and only gave out to one supplier. Late last year ALL my ghost emails where "acquired/stolen" from somewhere in one go. I could only assume my ISP 1and1, either sold them onto someone, or they were stolen from the 1and1 servers. I never did discover which.

My data is My Data!  Whether it is my current weight measured by my wifi weighing machine, the amount of wine in my house, or my home address. We need to stop the theft and misuse of personal data before the great british public gets used to the idea that they do NOT own their own data.

I feel very strongly that we have allowed whole business models to be formed on the premise that Personal Data Theft and Misuse is OK. It is NOT OK!

Who, but the Brits can get this back under control? (Actually the Brits alone can't but at least we can start a movement!!)

Finally as a reminder, it is not about Privacy, it is about AGENCY!

Agency, or being in control, is what gives rise to the privacy outcome not the other way round.

The good news is that those that have "acquired" our data by fair means or foul are starting to understand that there is a growing demand for cyber agency. Take a look at the data controls in the latest Apple IO6. The growing power of the screams that occur each time Facebook opens our metaphorical privacy curtains also shows that the public is starting to get the need to be in control.


------
I wrote this Blog a while ago and felt it was missing something, now having read +Michael Koster's post  on User Agency and IoT, I finally realised what it was.... the importance of both Affordance and the "Things" and the sheer impossibility of accomplishing control in this new world without a great deal of help from Content Curation Agents as well Thing Management Agents that operate on our behalf.

I need mine now, before it is too late!!! And no I do not mean Application by Application I mean an integrated Content Curation Agent that will fight "Data Entropy" while extracting the maximum value from our data, and set of Thing Agents, likely to operate in a heirarchy under the Content Curation Agent.  See earlier post.... 

<\\SOAP BOX MODE: OFF>  :-)

Monday, November 26, 2012

Friday, September 21, 2012

"The Politics of Sharing"

I attended a very interesting discussion this week at Microsoft, about the politics of information sharing. The topic was being explored from a local government perspective. It became clear that under the guise of "we are not allowed to because of the Data Protection Act" many local government departments and services avoid sharing information about citizens with other organisations, often to the disadvantage of the very citizens they are responsible for serving and protecting.  The real reasons for this was far simpler! The seagulls in Nemo are good exemplars!

It became clear that many of the representatives of the various bodies, organisations and advisors had missed two key points!
1) Not sharing causes more harm than good, (though there were some present who understood the dangers of not sharing, and that effective sharing can be good for citizens)
2) The information that they were refusing to share, was owned more often than not, by the very citizens that they were elected or paid to serve!

We had a number of discussions about some important mechanisms that need to be in place to enable sharing, such as the standardisation of definitions and standardisation of API's. We recognised that a more effective means of virtial identity was required, and that asset owners would also need to be able more effectively and efficiently manage entitlement and access to their data. One excellent point that was made involved the "value" flow in the transaction. Individuals would either be paid in cash for giving access to their personal information, or could benefit other ways that they would value. (I would allow the police to have access to my home alarm system information, if that meant they would respond quicker to an incident. I wouldn't expect them to pay me for access to such data!).

There was apparently begrudging agreement in the room around the concept of citizen centric data stores, there were however far too many individuals who preferred the idea of creating Government controlled citizen "Big Data" stores shared across multiple agencies, "All the better to control you with my dear!". The recent World Economic Forum's paper on the subject effectively signals an important shift. 

Imagine a local authority that provides each of it's citizens a personal data store and helps them create wealth from this personal data store (likely taking a portion of the income for providing the service and as a means of reducing local tax,) while at the same time using the data store to enhance the safety and security of those same citizens. Information stored in such local government personal data stores would only be data that relates to the business of local government. Other more sensitive data would be in more 'personal' Personal Data Stores. There are many businesses that would love to gain access to such local government information that for example details which houses have double glazing installed. This data may not always be used for wealth creation, as an example it might also be used in the context of supporting the  infirm and aged.

Imagine the "politics of sharing", in the light of an ecosystem that creates wealth for the individual citizen, reduces their local taxes and gives local business access to accurate and timely data that helps drive the local economy. 

Human Agency can be even further enhanced by the full and complete realisation of exactly whose data it is. Politicians and Regulators will do well to recognise that their focus should shift from being overly concerned about the details of privacy law, to the more fundamental and far more important issue of Cyber Agency.

After all it is the control over the curtain that gives privacy. Privacy is simply the result of being in control. So laws that encourage increasing the control by the citizen over their own data, and the development of Personal Data Stores, will be good for the economy, the individual, and society. So why are we not seeing such laws being enacted. My belief is simply that the power is in the hands of those that currently create wealth from our personal data, citizens rarely pay lobbyists!

What to do? The answer is simple : Ensure value flows to the individuals and organisations that created or own the data. Anything else is Data Usury.
Doing so will involve taking on those that would lose out from such a redirected flow, and remember, voters, the economy and society can all benefit.

The web will finally be able to do what it was designed for, creating a more open and egalitarian society. 

Wednesday, September 19, 2012

Data Entropy, my new battleground

In a recent Blog Simon Wardley was bemoaning the inappropriate use of the terms Structured and Unstructured as they pertained to data, I started writing a comment that turned into this Blog.

I believed the words that he was exploring also pointed to the power Entropy has over data. The simplified post (I didn't see the EP/LP version of his Blog, he had reduced its length b4 I read it) seemed to assume an inexorable flow from Unstructured to Structured. As humans we are in a constant battle to bring structure, order, form meaning to the world around us, this especially applies to data.

History is still only what we believe happened, as we have yet to gain dominion over data. A key difference between energy and data is that data can be destroyed and far too frequently is destroyed, as the non-existance of many historic records can attest!

I was trying to find the word equivalent to exergy, which applies to energy, in the world of data, when it struck me the lack of its existence maybe because that with data there is no "maximal value". Which on reflection is obvious as when one uses data or information and take nothing from it, far from it more often than not combining data can create new data/information plus there is no natural friction in the world of data just entropy. This in itself was on obvious realisation, but then I already knew that the more I knew the more I realised I did not know!

In our journey of transformation, fighting data entropy all the way
- with data (bits) to information (informs) we add form to create new facts or "informs"
- with "informs" to knowledge (knogs) we discover new forms, & meaning 
- to achieve the highest form we make the right use knowledge and attain wisdom!

Aside: It strikes me that with data, entropy reduces the value of data with the square of time, like gravity reduces with the square of distance.

This is shown very well when I look at the graphical data that I have stored about my life, I can readily access images from a month ago, but many of the images taken a decade ago are lost to my iPhoto album, or of they exist in the Album have lost meaning. The majority of images from my childhood are lost with a few hanging on by their finger tips in physical photo albums, the meta data around even older photos makes them all but meaningless; Who is that man in a soldiers uniform in that fading sepia photo?

Thus my final comment after the mind storm that Simon's Blog evoked is:-

Thankyou I created this Blog as a direct result of your post Simon
I enjoyed the journey and find myself even more motivated to fight data entropy, and add or maintain the order, structure/form and meaning of my personal data. 



Which makes me even hungrier for the Linked Data tools I can only envision but have not the skills or time to create. ORAC is sounding more important and desirable every day, Blakes Seven has a lot to answer for! 

Monday, September 17, 2012

Wot d'ya mean "Digital Exhaust", it's gold & Mine!

or "Asserting my Human Digital Rights is pretty hard if they are not defined!"

Sadly no matter how hard I read the Declaration of Human Rights, I can no-where in them find the provision of my Digital Rights. Admittedly Article 8.1 - "Everyone has the right to respect for his private and family life, his home and his correspondence." provides very effective right to Privacy especially if we assume the definition of correspondence, to include all data communicated between myself and others, including machines.  This does not however give me ownership, or control over my data, whether it be the data that I deliberately create and store, or the data deliberately leaked from my devices, often called data exhaust or even data that judges or regulators try and call theirs! The data that defines location of my digital devices is mine, or at least it should be! There should be no doubt that anyone that wants to access and/or use that data should have my express permission to do either. Though there may be just cause to gain a court order to gain access to the data without my permission.

Dear Politicians and NGO bureaucrats,
  Please can you turn your attention to defining the Digital Rights of Individuals, including their agents.

Perhaps our friends in WIPO might see there remit expand to include the Data of Individuals, not just the "Intellectual Property related to Corporations and Artists? There is likely to be a better way, than simply re-purposing a current organisation whose role is becoming greyer as the Internet makes Transparency the new reality.

What that is remains to be seen....

Thank you

A very concerned Cyber Citizen

Tuesday, September 04, 2012

From Paper to Plastic to Silicon based Credentials

Digital Wallets are the new Identity battleground, who can get you to put more of your Identity into their Digital Wallet?... Google's "Wallet" , Apple's Passbook, to be launched in their new iPhone next month, or Microsoft's relaunched e-Wallet with their new Windows 8 Phone this Autumn. NFC will become just the underlying technology.  Mastercard and Visa are both getting in on the act with with Digital Wallets, though mostly payment focussed. 

Initial Reactions

What do you mean I can't get digital receipts? 
How can I stop stores from rifling through my Digital Wallet and harvesting info? 
How do I know what information they did get? 
Can they keep all the info or did they just get a "One Time" glimpse? 

These are just a few of the natural questions people will ask in order to get an understanding of the state of the key elements of Agency, Trust, Useability and Manageability in the Digital Wallet space. It is early days and there is a lot of issues to resolve, barriers to remove and most importantly cash flows to figure out. 

The Bottom Line of the Digital Wallet Service Provider:   Who is going to get paid for what?

Contents of a Leather Wallet

As you can see I had 17 "Paper and Plastic" credentials" in one of my Leather Wallets, that I'd want to include in a Digital Wallet with a few more that I don't normally carry around with me that I would happily include.

My Bottom Line: 

My wallet supports more than simple cash transactions
I don't want a Wallet Service for every Identity I own
I want ONE "Virtual Wallet" that is secure and very easy to control, but I want access to it on every device I own.
A few important architectural questions :

When will Ubiquity occur?
A difficult one to answer!

Are the better solutions Proprietary or Open?
I have my bias!



Can "credentials" be easily moved from one Digital Wallet to another?
Today.. no! Tomorrow.. a must have!

Will users want to trust their device as the sole credential repository?
Would you?

Will digital wallet silos, ie a wallet service that only stores ONE credential, really work?
Some are betting yes, at least in the short term.

Things to watch:

The Trust Nexus A network of cloud based identity repositories

Square & Starbucks An innovative location based Identity approach

Question for Organisations to ask themselves

Will my organisation have the ability to enact transactions with these emerging Digital Wallets?
Will my organisation have the ability to put "credentials" into these emerging Digital Wallets?
What will be the advantages of doing so?
What will be the disadvantages of not being able to do so?
Are the solutions adhering to the Jericho Forum IdEA Commandments?

Question a smart consumer should ask: 

Why didn't the organisations making the shift to Silicon based Identity know about the Jericho Forum Identity, Entitlement and Access Management Commandments or watch the Jericho Forum IdEA Videos?


Identity Video #1 - Identity First Principles.   
Identity Video #2 - Operating with Personas.    
Identity Video #3 - Trust and Privacy.    
Identity Video #4 - Entities & Entitlement.   
Identity Video #5 - Building a Global Identity Ecosystem.   


Is this the beginning of the end of Paper/Plastic Credentials for your organisation, or the beginning of the end of your organisation? For there are some very raw and powerful tectonic identity forces at work under the covers of this simple sounding shift. Do you understand them?

Wednesday, August 15, 2012

Controlling consumers; eyeballs or wrists

It has been understood for a long time that the eyeball is the pathway to control an individual. The trick is that in the past the war for the consumer eyeballs have been played out quite openly, in adverts on the TV. Adverts have always relied on both subliminal and supraliminal stimuli. More recent behaviours have taken the war to control consumers both mobile and underground, out of the scrutiny of regulators or indeed often the consumers themselves. Signs have been surfacing, the challenge is for us to identify and  interprete these signs, and react before it is too late.
(cf gently bringing a live frog to the boil, first it goes to sleep in the nice warm water!)

George Orwell made part of the leap in 1948 when he realised that controlling the populace was likely to be achieved through taking control of the media for messaging and the television set in the home for monitoring. However he did not have the benefit of hindsight, nor did he predict the amazing advances that mobile technology would bring.  How could we expect him to, when we are in the here and now and apparently are not spotting the emerging issues.  George in his book 1984 represented states which were reducing the agency of their citizens.  Some people might relate this to human rights, but sadly we have no human rights when it comes to Cyber Agency, (which is whole separate Blog topic). I want to keep it simple, I believe I should be able to control my destiny, and control devices and information related to my journey towards this destiny. There are folks out there who want to wrest that control from me, and worse they are making rapid progress, especially in the Wild West of Cyber Space.

Some of the signs:

Carrier IQ: US Phone Carriers inserted spyware on US Mobile phones
Mobile Spyware Services are being made publicly available that allows anyone to do it!
Samsung Smart TV Terms and Conditions
(If you have a Samsung Smart TV you should seriously read the ToS)

Despite much searching I cannot find them on the internet, so here are a few interesting pages: This page gives the right to Block Access to Samsung Smart TV for any reason.

As an aside, just after powering up and connecting "my" Samsung Smart TV to the internet, Samsung took control of "their"? device and started deleting applications from it and replacing applications with others. I was powerless to stop them.

If you own a Samsung Smart TV I hope you didn't think you would be in control of it!

If this is not bad enough, later parts of the ToS define, what Samsung believe to be, non-personal data, anonymous data, including your IP address, and your search terms!? 

An IP address can easily be used to identify a household and from there it is not difficult to identify occupants.
In later parts of the ToS, Samsung give themselves the rights to ship your data anywhere in the world they want to, and basically to whom they want to. 

During the sign in process Samsung also appear to gain access to and control of your FaceBook identity, if you choose to use the Facebook App.

Then on this page the European regulatory discussions about citizens managing their right to be forgotten is well and truly squashed.

The latest Samsung Smart TV comes with a built in camera, any body spot a similarity with George Orwells world?

The battle is now officially joined, especially as Samsung appear to have realised what George did not, the future is Mobile! Therein lies the key to gaining control of consumers. I believe they have realised that the trick to controlling consumers is not just to be in front of their eyeballs but from where you are doing it, the corner of their room, their laptop, or to be with them in their pockets. We can extrapolate that the next key step will be a piece of real estate more valuable than eyeballs, pockets or diamonds, their wrist. Watch as the power problems are resolved and a small wrist mounted computer becomes a reality. The winners will be the ones that own the device on the wrist.

I predict their will be two camps, with a naive few in the centre of the battle stating that it all doesn't matter and all information should be free. The low ground will be quickly taken by those intending to grasp all forms of Cyber Agency from their Customers and/or Citizens. They will prosper for a while, and are prospering in these early Cyber years. Until a more internet savvy generation emerges to state their agency expectations more clearly, we can expect the current Internet sheep to head down for free food into the warm and green pastures. The second camp can only really emerge when a demand for their services comes clear, those that take the high ground will build services that allow the consumer/user to regain cyber agency. (This does not mean that the providers need to give up control of their assets/services.)

Posit: This may sound like a scary world for providers, who expect to make money from their Customers, until they realise that by actually giving their Customers more control there is more chance for Profit if their Customers feel that their interests are also at the heart of any transaction.

Having your assets and services out of control is clearly a bad idea... the answer in 2 dimensions (where the Asset or Service is conflated with the Consumer) is obvious Gain Control as Close to the Consumer as Possible,
Once the parties can get to the high ground they will gain a more complete perspective, empowering clients while maintaining control of an organisations assets/services becomes a more beneficial play.  Many organisations are assuming that in order to control their assets and services they have to gain control of the Consumer. The value of empowering the Consumer will not occur to these organisations.
Those that do will also note that a new set of Trust Services will need to be implemented.

These might also start to become known as Agency Services, and they will be Agents operating in the interests  of the Consumer. (Hopefully following Asimov's 3 Laws of Robotics)



So let's watch as the race to control customers shifts from the corner of the room, to the laptop, to the pocket, to the wrist, then when this achieved watch as organisations struggle to put the consumer back in control, while maintaining control of their assets and services. Those that head straight for mutual control, close to the individual consumer have the highest chance of long term success.






















Saturday, March 10, 2012

From concern about Privacy, through Primacy, to Egency.

Well I've slept on it and the change is on! Whilst Primacy, the first word I was trying to propose to explain the concept, does indicate the state of being "Number One", "Agency" as used primarily by philosophers is really closer to the concept of being in control of one's data and therefore being in control of one's virtual self.  However "Agency" does not convey the data or the virtual aspects of the crucial concept we are trying to convey.  It was in conversation with Mike Nelson at 15:00 on Friday the 9th of March , in a Google Hangout conversation, that he lead me to "Egency", a neologism that will, hence forth, mean "the state of being in control of (one's) information assets".  Egency (the more flowery? amongst you may chose to apply a hyphen to get e-gency, though I am not in favour) can be applied to all entities, (organisation, human, device or code).  Egency will become an important thing to regulate, as humanity starts to realise that "Egency" is in fact a Human Right.  More-over we will recognise that it is the true economic life blood of this virtualising economy of ours.  There will be courses on "How to become more egent".  We will come to realise that egency and transparency are in fact good bed fellows, Wiki-Leaks will be seen as an early major shift towards egency.  Artists will recognise that the prior business model, where their agents became more egent than themselves, and their publishers even more so, was a massive egency #fail!  Publishing and Piracy are in fact both theft or misappropriation of egency.  We will finally come to understand how we are sleep walking into a world, where our egency is being sucked from us all, authors, artists, and consumers alike.

Here's hoping that at least one large corporation will come to understand that removing egency from it's users is, in fact, "Doing Harm!"  Do we really want to become the energy source of the internet, cf "The Matrix".  Will we wake up soon enough?  For "Egency" is the oil in the coming centuries economic engine; egency both powers and lubricates.  We cannot let it leak away, or be syphoned off!  To enable and protect egency we will need an open and transparent e-trust ecosystem, but that is another post!

My primary fear is one best articulated in the April 11th New Yorker cartoon by Mick Stevens... "What if the meek don't want it?"

You can purchase a copy here: http://www.condenaststore.com/-sp/What-if-the-meek-don-t-want-it-New-Yorker-Cartoon-Prints_i8472845_.htm

My thanks to Merlin, Lord Erroll, my LEF colleagues, including Mike Nelson, Doug Neal, Simon Wardley, Jim Ginsburgh, and all my colleagues in the Jericho Forum (especially Paul Simmonds, Steve Whitlock, Andrew Yeoman), and Chris Wiesinger of CSC for helping me to this mind-state.  I am sure that there are others who have also influenced my thinking, I hope they will forgive not being mentioned.

Related Concepts to explore
Commoditisation of Publishing = Egent Positive
Consumerization of Identity = Egent Positive
Micro-perimeterisation = Egent Positive
What is the antonym of "Egency"?

Friday, March 18, 2011

Is 1984 a step closer?


A debate this week in the House of Lords, does not appear to have hit the UK broad sheets. Some may think that it was of little consequence, as it was simply the UK choosing to sign up for the idea that Passenger Name Records should be kept for ALL Pan-European flights in a massive European Travel Register. Lord Hannay in his own opening speech, promoting the motion, stated that it was a "considerable invasion of privacy".
The declared goal is the standard "protect us from terrorists" mantra, the negative or unexpected consequences of such a large database being available to all European Governments are not apparently being included in the decision. This is especially concerning as it is also likely that the US Government and other Foreign States may gain access to the database by fair means or foul.

Let's consider a few "Abuse Cases":
Simply by tracking the flights of the CEO's of all the major European companies a Foreign State, could glean significant information about potential mergers and acquisitions.

As The Earl of Erroll pointed out in the debate a Foreign State could acquire information about the travel companions of key leaders of Industry, or other Foreign States, that could in turn be used to blackmail or pressure said leaders.

Given the attributes to be stored will include passenger financial data, the database could be the cause of a massive exposure of Credit Card details.

As The Earl of Erroll also points out if we were concerned about the dangers of a National Identity Register, why would we not be concerned about the dangers of a European Travel Register that arguably will hold even more detailed information.

The record of large government organisations when it comes to protecting the private records of its citizens have not been shown to be the highest. Just how access to such sensitive data would be limited to those exploring Terrorism or Organised Crimes is not clear.

What's next? The recording of all train journeys across borders, and then car journeys, and then...?

Should we not all be as concerned the Earl of Erroll?

Sunday, February 27, 2011

I was in a EURIM meeting last week discussing the importance of establishing an Identity Governance Framework that would help set the direction of regulations and other key components that would enable the development of an e-Identity Infrastructure. All those present believed in the importance and value of such an Infrastructure, there was whoever one aspect that did not seem to have universal agreement.

Basically it came down to the need for a Universal Identifier that would be owned by Governments.

In this case we were talking primarily of the identity of Citizens. I responded very clumsily to what seemed to be a proposal to tie such an Identifier to the Identity used for voting, it turned out to have been tied through the Registration process, my visceral reaction remained. I mumbled my concern without clarity.

Today I was in reminded of the Lord of the Rings and its relationship to this problem. I declare myself to be a Hobbit who sees the creation of the Rings (of Identity?) as something to be feared, especially the One Ring, the one that binds all the others together.

The forces that would have us believe that a Universal Identifier should be created by governments in order to protect us from thieves and terrorists, are not being fully transparent with the potential negative impacts, partly because the law of unintended consequences is so relevant in this space, but also they don't want to declare their own intents.

Let's remember what was inscribed inside the "One Ring"

http://en.wikipedia.org/wiki/File:One_Ring_inscription.svg


One Ring to rule them all,
One Ring to find them,
One Ring to bring them all,
And in the darkness bind them.''

A chilling reminder, for those that understand the message that Tolkien was sharing with us.

Basically it is a question of Primacy, who owns the Identity of an Individual?
Some would say the State, I would say the mature and sane Individual
I was sure this right would be enshrined in "The Universal Declaration of Human Rights" but despite reading and re-reading the articles I found no clear declaration, while Articles Three and Six touch on the concept. The right to own ones Identity is not explicitly stated.

The first Jericho Forum Identity Principle (under development) addresses this topic it currently reads:
PRIMACY: Invisible Root Identity – The privacy and integrity of a core “Identity” is ALWAYS safeA Root Identity must be uniquely and permanently connected with an Entity/Principal and must NEVER need to be disclosed.

Rewritten as a new Article 31 of the The Universal Declaration of Independence it would read:
Everyone has the right of primacy over their Identity, no State, group or person may usurp that right.

Tuesday, January 11, 2011

From Silo to .....

The shift from being a silo focussed Enterprise, to a Deperimeterised one is NOT a simple task. The primary reason for this is that it involves a tectonic shift in all the key components of an organisation, including all those that relate to each of the major domains of People, Process and Technology, in short everything must change.
The Culture of the organisation must change from top to bottom, this shift involves moving from a "Do It Ourselves" to a "Do It Collaboratively" approach. In Information terms this means moving from keeping Information to ourselves, to sharing information with others. This leads to the need of a fundamental shift in governance systems, meaning that the systems that govern the direction of, and behaviours in an organisation often need to be reversed, and certainly re-designed. The implications of the importance of this part of the "shift" can be seen in the failure of many organisations trying to make the shift. Business Leaders making this change understandably feel nervous and as a result resort to taking up the governance reins, hoping that they will be able to effectively steer their organisation throughout the change. Empowerment is the first thing to suffer with this approach, as this behaviour is observed and replicated down through the leadership ranks, and yet Empowerment is one of the most important success factors in making this change. This results in a failure to appreciate which of the many unknown processes in an organisation are key and which can be eliminated. My own view of the failure of Michael Hammer's Re-Engineering of Enterprises in the 1980's stemmed from the basic fact that the Leaders of an organisation of any reasonable size have no way of being able to understand all of it's processes. Especially as so many of those processes are "unknown" and certainly undocumented. (The most successful re-engineering exercise I was ever involved in occurred in France, where an enlightened leader, whilst using an external consultant, insisted that all of his staff were involved in the re-engineering exercise, unfortunately the effort were supplanted by a "Top Down" change that was Global resulting in a 400% loss of productivity.) Changing the business processes of a silo based organisation to deliver the needs of a Deperimetersed one, is not a trivial exercise, and certainly not one that can be achieved incrementally. For few organisations understand all the processes that they operate, let alone the Information Assets that are key to these processes. Our inability to manage the vast amounts of information that modern Enterprises produce inevitably leads to the use of Information Technology, and here-in lies the tail that wags the Corporate Dog. Advances Information Technology has lead to an amazingly powerful tension driving organisations towards Deperimeterisation. Cloud based services, being simply the latest of these advances. Consumerisation is another of these technology mediated tensions.

I am reminded of a challenge in one of the many corporate team building exercises that I have had the pleasure of engaging in. This one had me dressed up in massive amounts of padding, connected to bungy cord and then told run up a padded aisle to see how far I could get. The weird experience of having the bungy cord decide that I had come far enough and drag me flailing back to the start must have been designed to teach me something, though I can't remember what.
in the case of the Silo based Enterprise, the bungy cord is Deperimeterisation, and no, it is not connected to the other side of the Grand Canyon but to the Moon. in the words of Eric and Ernie, "Get out of THAT without moving!"

The good news is that Mankind has demonstrated our ability to get to the Moon and back. Is your organisation ready to demonstrate the capabilities needed to achieve this shift? If it is small and agile, then likely yes, if you are in a large organisation here's hoping you have a charismatic leadership team with Vision, who believe in Empowerment.

To those expecting the word security to appear in the body of this article, on September 12th 1962 did Kennedy use the word Security in announcing the endeavour that relied upon Security at every step?

"We choose to go to the moon. We choose to go to the moon in this decade and do the other things, not because they are easy, but because they are hard, because that goal will serve to organize and measure the best of our energies and skills, because that challenge is one that we are willing to accept, one we are unwilling to postpone, and one which we intend to win, and the others, too.". http://www.historyplace.com/speeches/jfk-space.htm

Will your organisation choose to go to the Moon or will it be dragged there flailing? One thing I will say is; your ability to treat Information as a valuable asset is going to be fundamental to your success, with a rethink of "Identity, Entitlement and Access Management" being a crucial early step, but that's another blog!

Sunday, January 09, 2011

Mac App Store introduces the opposite of Shop Lifting

The opposite of Shop Lifting would be called something like Wallet Snatching.

With the new functionality introduced by the 10.6.6 upgrade the Mac App Store introduces the unwary to a new means of losing their money. The App Store used by iPhone, iPod, and iPad owners has a two click to purchase interface. With Mac App Store, Apple have introduced, an arguably devious, means of increasing sales by eliminating the "Are you sure?" Click.

This seems like a minor deal, but you must remember that the Terms and Conditions of App Store basically says when you have bought it it's yours and there is NO means of getting your money back apart from going to the developer of the software.

I am not a lawyer but I believe that Apple have successfully driven a coach and horses through the sale and purchase of goods Act, which clearly states that it is the seller, not the manufacturer, who is responsible if goods do not conform to contract.

This coupled with the fact that the App Store was not built to be secure from the developers perspective is a reason for developers who value their brand and their profit to steer clear from the App Store.

A recent incident I experienced with the SlingBox App has damaged Sling Medias brand in my eyes and certainly means I will be doing no more business with them. I also aim to stop as many of my friends as possible from buying Slingboxes. This arguably all stemmed from Sling Media's use of App Store, and hiding behind the Apple's decision to ignore the Sale and Purchase of Goods Act.

CAVEAT EMPTOR is even more important when it comes to doing business with Apple.
I think that may be assuming that they are above the law!

Yippee! End to End Secure FaceBook

"A step towards being my Identity Service Provider"

In the wake of FireSheep and the ability of coffee shop squatters to harvest authentication cookies from insecure WiFi Networks, and gain "one click" access to FaceBook accounts, FaceBook have started up a new way of accessing FaceBook. With the launch of https://ssl.facebook.com/ one can now have their authentication cookie, and all other data, securely transferred to and from FaceBook. While this does not solve all of FaceBook's security issues, (after all they still use Username and Password for account access!) it is a very important step. All FaceBook users should shift to this means of accessing FaceBook. Currently, it is still in a testing phase the service will be more broadly promoted in coming months.

So to benefit from "end to end secure FaceBook" change your FaceBook bookmarks now, I have!
Now all I have to do is figure out which of the many applications I use to access FaceBook use this secure protocol.
Anyone have a list?

This is a welcome step, and if FaceBook continues in this vein, I will be happy to expand my use of them as my Identity Service Provider. Recently they are more openly about positioning themselves as an Identity Service Provider, they are choosing to gain the position by slowly on FaceBook App at a time. More importantly they have the potential to gain the trust of Enterprises as an Identity Services Provider. They are more likely to achieve this status, if they comply with all the Jericho Forum Commandments.

There are some additional services and capabilities that would help me make this step. What am I missing ?

1) A revised authentication infrastructure that eliminates the use of Username and Password as the prime method of Authentication to FaceBook

2) An easy to manage Security Dashboard that allows me simple oversight and control over my web based Identities

3) A Security Monitoring Service that has the capacity to alert me when my data is being harvested, or misused

4) A means of more finely selecting which of my data I want to share with specific services that use FaceBook Connect
(Currently it is a binary decision, often "All or Nothing", with little ability to negotiate)

5) Methods of enhanced authentication, which I can choose to use for specific services that I may choose to use FaceBook Connect with.

6) Various Methods of warning when specific events, of my choosing occur. I would see three levels "Alert Ferocity"
a) Poodle: Just giving you the heads up
b) Jack Russel: Seriously annoying until you accept the alert
c) Pit Bull: Will fight to the death to get the alert through to you, no matter the cost

7) An ability to apply varied levels of friction to information flows that I can select for different types of data, or specific data elements.
a) Open = No friction, Anyone has access
b} Closed = Limited Friction, Many have access, though it is easy to share with others
c) Combination Locked = Serious Friction, fewer have access, but it is difficult to share with others
d) Key Locked = Ultimate Friction, few have access, and I am informed when they access

8) A Transaction Dashboard that allows me oversight and control of my ALL web transactions, this service will only be possible after FaceBook has really proven their ability to look after my interests.

Clearly, I expect others, not just FaceBook, to be aiming to provide these identity services and this list equally applies to them. Some providers will have more complete and robust services, others will not provide the complete range of robust and trustworthy


Source of key elements in this blog
http://technologyreview.com/printer_friendly_article.aspx?id=27027

Saturday, December 18, 2010

Abstract Thoughts on "Information Friction"

The problem appears to be growing worse! Information Technology is becoming like a silicon spray reducing Information Friction to the lowest levels ever. The issue is simply that it is easier than ever to accumulate vast amounts of information and distribute it globally and instantly with little effort. The consequences of the reduction in Information Friction, are both positive and negative. The dilemma is that while individuals are pleased to give up their information to a specific organisation for a specific gain, the organisations do not always keep their side of the bargain. On the other hand the more Enterprises are intent on keeping information restricted, the more valuable it is for Insiders to share it, with the resulting phenomena of Insider Senioritisation

As was recently identified by the ISSA in their http://www.issa-uk.org/whitepapers/ISSA-UK-InformationSecurity-TheNextDecade.pdf chaired by David Blunkett at the Houses of Parliament and commented upon in David Lacey's Blog; The world needs much more innovation in Information Security. Perhaps it is time to look to the Jericho Forum Command,emts for inspiration; how might they suggest we should approach putting the friction back into Information Flow, and who should be in control of the lever that applies said friction?

I will be researching these questions in my work on Next Generation Identity (or should that be Access?) Management for the Leading Edge Forum


I am very interested to hear from those who has some ideas.

The main three problems
Behaviour Change, Behaviour Change, and Behaviour Change as it is truly "all about them" where "them" are the users!

How does one mke it :
Harder to accumulate large amounts of information
Tougher to deny ignorance of knowledge
More difficult to distribute large amounts that your are not supposed to have

In short how can we put the Resource Owner in charge of the resource. nigh on in real time


UNDER CONSTRUCTION, but feedback welcome