Hi. This is David with Direct Reservations, inviting you help celebrate Disney's...
I hung up.
What this call invited was contempt for Disney, not for the nearly anonymous telespammer whose device placed the call. That's not just because Disney is a "brand", but because to some degree I have a relationship with Disney. My family goes to Disney theme parks, watches Disney movies and buys Disney products. We are also candidates for, say, Disney cruises. Of course, Disney has done a lot of stuff to annoy us as well, but let's not go there. Right now I want to use Disney as an example of a company with which I might like to have a better relationship as a customer rather than as just a "consumer". What will it take for that to happen?
Right now, it's all up to Disney. Our relationship is entirely producer/consumer, which means we don't have a relationship at all. Disney sets all the terms and conditions. I can buy their goods, join their clubs and whatnot; but I can't initiate any kind of relationship that proceeds on my terms, even if that re la to ins hip might be good for them. Same goes for airlines, credit card companies, banks and various other entities whose relationships with me are manifest in the plastic cards that thicken my wallet. In fact, these asymmetrical producer/consumer relationships are so deeply embedded in our economy and culture that we can hardly imagine any kind of truly symmetrical power relationship with a large company -- much less one in which we, as customers, are truly in charge.
So let's imagine one. To do that, we need look at our current identity infrastructure -- what goes on behind the numbers on all these cards we carry -- from our side of the cash register. Instead of waiting for Disney to tell us they're offering vacation cruise deals to consumers of animated movie DVDs, we let Disney -- and other potential providers -- know that we're in the market for a cruise in the Caribbean this coming October. Also that we don't want any more spam phone calls or emailings guessing about what we, as customers, might want. Also that we'd welcome discounts with some of our partners, such as Starbucks, Amazon and the local toy store in our home town.
What this requires is something we don't have right now: a new identity infrastructure -- one provided by open APIs, protocols and other standards that serve no agenda other than to enable useful dealings between buyers and sellers of products and services. Like the Web and email infrastructure that are already part of the Net, this new infrastructure would be a full-fledged service on the Net. And it won't become that unless it's something nobody owns, everybody can use and anybody can improve. Again, like the Web, email and the Net itself.
Since this infrastructure won't be built around any corporations agenda (though it will prove quite handy to corporations wishing to do business with free-range customers in a real marketplace), it will necessarily be centered around customers. After all, we're the ones with the money, right?
What we'll need as customers is what I call a mydentity. Not a yourdentity (which is the limited form of identity companies assign to customers). Not a theirdentity (which is the identity owned by mass annoyers who send junk email, surface mail and other spam in hopes of getting better than a 2% return rate).
A mydentity embodies the attitude of Robert DiNiro's character in "Taxi Driver". Want to do business with me? Cool. Here are my terms. Here are the outfits I already enjoy relationships with. Here are the nature of those relationships. Here's what I'm open and closed to. Here's what I like and don't like. Got it?
(Andre explains all this in Three Tiers of Identity and The Phases of Identity Infrastructure Adoption.)
Now let's go back to that phone call. Here's how it might work (or not work) in a world with real identity infrastructure comprised of countless free-range mydentities:
Having this infrastructure in place will mean three things:
So, is this the kind of stuff that Big Corporations are going to build out in a free and open way? Andre Durand thinks so. Andre is the founder of both Jabber Inc. and PingID (disclaimer: I'm on the advisory boards of both companies), which are both growing around open source .org efforts (Jabber.org in one case and SourceID in the other). The vision I described above is basically Andre's. He was the guy who lit the fire in my brain early last year. Since then I've been I've been urging open source developers to start building out this ID infrastructure, kind of like they've done with Jabber (which seems to be moving along pretty well now). That's what I was up to in this Linux For Suits editorial and this Suitwatch newsletter.
Meanwhile, most of the activity has been on the corporate side of things, which concerns me. Identity infrastructure that fully empowers individual customers will be highly disruptive to companies that are big in the yourdentity business. Big companies naturally treasure their customer databases and their right to control "consumer" relationships from the producer end of things. They are deeply steeped in a power asymmetry that goes back to the Industrial Revolution. All of them are therefore stuck in what Clayton Christensen called The Innovator's Dilemma. Christensen says big "innovative" companies have an iterative development culture devoted to constant but gradual improvement of existing technologies and ways of doing things. They tend to see disruptive technologies as threats rather than opportunities, and find all kinds of good reasons to fight or ignore those disruptive technologies, rather than to embrace them. Hence the dilemma.
There are exceptions. Sometimes, when big companies can't embrace disruption all by themselves, they outsource their affection for disruption to communities of other companies that face the same threats. Consortia are often built to do exactly that: treat threats as opportunities.
That's what the Liberty Alliance is all about. Name a big company that cares about technology (and isn't Microsoft), and there's a good chance it's on Liberty Alliance's roster of members. It's a scary bunch.
The marketing language on the home page seems innocent enough: "The mission of the Liberty Alliance Project is to establish an open standard for federated network identity through open technical specifications," the boilerplate says, right above the "Click here for a Flash demo" link.
Below that link is another link: "Now available: Liberty Alliance Version 1.1 Specification". The whole Liberty spec consists of nine huge .pdf files. Last week I visited a company in Canada that had all nine compiled into a tabbed binder. Inside the binder were little yellow sticky notes, each barfing on some of the language surrounding the spec itself. I'm not quite so shocked. Statements like this one seem innocuous enough to me:
Still, I like the old Mother Jones slogan: "You trust your mother. But you cut the cards."
I'll confess to being the open source contrarian in my relationship with Andre and his cohorts at PingID and SourceID. They're involved with Liberty Alliance, and (at least in PingID's case), they stand to make a lot of money from relationships with Liberty members and other big companies. Which is fine. I'm concerned that these economic relationships will distance them from Andre's original vision, which I think is ultimately the only one that will work on the Net, no matter how much money big companies put into controlling (or even just enabling) the process.
So, in response to feedback from me and from other open source advocates, Andre has come up with a radical suggestion: hijack the protocol. Those are his words. Here he is, in Accelerating Tier 1 (mydentity) Build-Out, on the SourceID site:
Right now there are other moves afoot, too premature to talk about, all intended to build out a mydentity-based infrastructure. I may hear more about these over the next four days, when I attend PC Forum, which combines big company CEOs and presentations with disruptive subjects. Christensenian ironies tend to abound.
As I head for that show (and during the show as well), I'd like to hear from Linux Journal readers about the whole Digital Identity subject. Do you think the Liberty Spec is worth hijacking? Are we at Square One yet, or still at Square Zero (or 0.x)? Do we need a whole new approach to the problem (or the opportunity, depending on your point of view)?
One concern I have is the need for simplicity, for the Principle of Good Enough that accounts not only for the success of the Net, the Web, email and their founding protocols, but for infrastructural building materials like Linux as well. To me, Liberty looks too complicated for that. Yet Craig Burton just told me that the vision I outlined at the top of this piece is actually too complicated for the Liberty Protocol to handle alone. But then, if you take away all the surrounding BS, perhaps the Liberty spec is really quite simple. Again, I don't know.
Maybe some of you do.