One

I isnt' abouyt the movememnt of power from the center to the edge, or the large to the samall, or the corporate to the indivisdual. It's about the continued and inevitable developemnet of a world where he individual is in the bext t ppsition...

linux didn't begin with a company. It began with an individual. More importantly, an independent individual. Many, perhaps most, of the

the internet was built so you didn't know who or what you're connecting to.

we want a fabric of identity.

we've gravitated toward the simplest options, forms filling . We've taught billions of people to put a ll kinds of data in a form in a screen.

We know that digital identity is related to contexts. And that manyh of the peoploe involved gjaloously guard the identities that exist in them. Enterprises, goverm=nments. Businesses. You talk to pepoe, and they prefer a one=-off to some kind of a system that is beyond their control. what's required is a system that leaves thgem in control but allows them . the indivisual is also a player. They key player.

a system in which all of the parties are served.

no simplistic solution is realistic.

the identityt metasystem .

look at display screensl, In the old days we hnd to know what kind of display screen we were writing to. We had to change the program to

we had an abstraction layer called device drivers. made it easieer to write new applications.

tcpip didn't make ethernet, token ring, frame relay dissappear.

hou could write applications without havbing to kmnow.

we need the same kind of metaysstem do exactly what it didd in other cases allow didital ID to e loo

an ecology

need to structure our understandinof didgital identity.

i call myself the hair on the end of the long tail.

we all have to agree there is a unifying essence. A context. We have to be able to talk about these thigs, these laws.

Wheat they need isa system that leaves them in control.

Dizzy:

Jabber IM with dizzyd <[email protected]>.
8:08 PM
I know you're busy, but if you have any questions about the whitepaper, or any areas that could be clarified, feel free to ping me
ok. I;'m, on two IMs and a pho9ne call now... arg.
will do, though.
INterested in yr. concerns about WS-* and the bits of it that Kim's using. Although it's not a big deal at this point. I'm just eworking on a piece for the august issue.
8:10 PM
ok
8:20 PM
at the heart of my concerns with WS-Trust (and the WS-* stack in general) is the reliance on XML-Signatures (a W3C standard). From an implementation standpoint, it's not something that "normal" developers can implement. To my knowledge, there are only two implementations of XML-Signatures -- a C version and a Java version. So it's not like there are a lot of choice out there for developers to build on. Open protocols (source code aside) simply have to be sufficiently implementable that "normal" people can implement them. In the case of the XML-Sig spec, there just aren't implementations in PHP, Perl, etc. so those people are sort of left out in the cold. So relying on XML-Sigs is something (in my mind) that discourages widespread adoption. A secondary concern with WS-Trust is that it's so generic that I'm not sure how useful the actual spec is -- it's sort of like SOAP for identity token exchanges. The last thing we need in the identity space is another "meta" protocol.
Don't know if all that helps
8:40 PM
dizzyd has gone offline.
dizzyd is now online.
9:10 PM
You left the chat by logging out or being disconnected.