Independent Identity

Note: This is a draft of the September 2005 cover story in Linux Journal. It's longer, more linky and (of course) less tightly edited than the one that appeared in print.

By Doc Searls


Our senior editor gets caught up in a groundswell of development around individual-centered identity systems, looking for help at equipping customers to revolutionize markets.


By tradition I give the closing keynote at Digital ID World (DIDW). I've been doing that since October 2002, when the show began. I've given it five times, so far. From the beginning I've had a case to make. Here it is:

  1. In a truly free marketplace, vendors in a category compete openly for a customer's business, based on information the customer supplies, at his or her discretion, to any or all of them. Customer data isn't isolated in vendor silos, and customers aren't forced to go from one silo to another and interact separately with each vendor's CRM (Customer Relationship Management) system, with its lame marketing agendas and its locked-up data.
  2. Customers won't have full power in any marketplace unless they control their own data (including data about their relationships with vendors), and selectively make private data available to vendors, with explicit permissions regarding each vendors' use of it. Drummond Reed of Cordance and Identity Commons calls this CoRM, or Company Relationship Management.
  3. Personal identity control and CoRM are powers customers have not experienced since the the Industrial Age began and they first became "consumers". As fully-empowered customers, they will blow the CRM blinders off vendors, release a wave of entrepreneurship, differentiation and innovation, and make markets grow in all directions. This won't be a market revolution, but rather the dawn of the first real market -- where demand and supply have equal power.
  4. CoRM requires identity services that do not yet exist. Those services also serve other purposes (SSO, or Single Sign-On, authentication, security, privacy and so on). But whatever those service may be, they share a point of origin: the individual. This invites adjectives such as "grass roots", "lightweight", "user-centric", "next-generation", "human origin", "bottom-up" and "distributed". I like the literal meaning of the word "independent". Every speech I make on this subject is a literal declaration of customer independence.
  5. Independent Identity is a human more than an organizational quality. Establishing and ubiquitizing Independent Identity therefore needs to be a grass roots movement that grows on open standards and with support from the open source community . For that reason it only makes sense for Independent Identity to grow from the bottom up rather than from the top down: from individuals rather than from organizations.

The seeds of this thinking were sown in my brain by Andre Durand, of Ping Identity Corp. (on whose advisory board I now serve), in late 2001, when he was still putting the company together. I wrote about Andre and Ping in "Identity from the Inside Out", in the May 2002 issue of Linux Journal. In it I describe Andre's three-tier view of identity:

At the center is tier one: that's your core identity alone. You're in charge of it. Outside that is tier two. This is the identity issued to you by the government, by retailers, by airlines, by insurance companies, by credit-card companies. Every piece of plastic in your wallet is a tier-two identity. Tier three is the cloud of highly presumptuous identity information held by direct marketers and others who hope you may be the one consumer in 50 who responds to a promotional message.

When Andre laid this out for me the first time, it blew my mind. I knew instantly that we could liberate markets, just by developing the means for individuals to assert their sovereign identities. It was a moment of revelation — like Neo had, just before he said "It's about choice" to the architect of The Matrix. In fact, The Matrix (one of my favorite movies, ever) suddenly made sense as an allegory for the false world invented by marketing, where consumers live in blissful ignorance of their role as batteries whose energy maintains that world.

By the middle of 2004, however, I had begun to lose faith in a rebellion that failed to materialize. Even Ping Identity was caught up with the rest of the supply side in a conversation about "federation", a term that seemed borrowed from The Dark Side of Star Wars. In an Interview last year, Eric Norlin, Director of Marketing at Ping Identity, said federation "leaves the distributed environment as it is, but seeks to let the end user link together those pieces and still have control over their privacy, what gets shared, and how." He said the Liberty Alliance spec, for example, "is purposefully designed to be opaque. (It) tries to accomplish one thing... to allow one end user to link one account to another account. But in order to protect the privacy of the end user... neither side of that account -- either Company A or Company B --would know who the end user is that is being passed between them.

I've summarized this as "large companies having safe sex using customer data".

This is less fair than funny, but it accurately characterizes federation as a big company concern. While federation might protect customers and provide them with certain benefits, it is essentially a silo-to-silo "solution." So far.

Liberty Alliance isn't the only consortium devoted to federation. The other big one is WS-I (where WS stands for Web Services). WS-I was founded by Microsoft, IBM and Verisign, partly in response to the Liberty Alliance, which was founded by Sun, partly in response to Microsoft's Passport, which was part of a scary-sounding centralized identity initiative called "Hailstorm" (of which approximately nothing remains at Microsoft's site, but bits can be found in the "Trojan Storm" entry here.)

Anyway, the more I heard about federation, the more depressed I became about the prospects for Independent Identity.

Then, during LinuxWorld Expo in August 2004, I met Kaliya ("Identity Woman") Hamlin at a San Francisco Giants baseball game. She told me she worked with Identity Commons. I'd never heard of it; but the name alone gave me hope. Right there at the game, Kaliya gave me a tour of Identity Commons and related sites, on her laptop, which was conveniently connected to the Internet via the ballpark's free Wi-Fi (which made me even more of a Giants fan).

What I saw in Identity Commons was a grass roots organization with a market-opening plan that leveraged some standards (notably XRI and XDI), and encouraged new ones, such as i-Names. A series of conversations with various Identity Commons people armed me with plenty of fodder for my keynote at DIDW in October. I wrote up the story behind that keynote in "What's your i-Name?", my column for the January 2005 issue of Linux Journal. In that piece I made something of a bet about Independent Identity:

We're not going to get that from the big vendors, for the same reason we didn't get Linux from big computer makers: Big suppliers in any category have trouble pioneering anything that's good for everybody and not only for them.

I was wrong about that. Because when the conversation started to heat up after DIDW, the Neo role was being played by a character with the unlikely title of "Architect", working inside the most unlikely company of all: Microsoft.

Kim Cameron is his name, and his architecture is the Identity Metasystem. Note that I don't say "Microsoft's Identity Metasystem". That's because Kim and Microsoft are going out of their way to be non-proprietary about it. They know they can't force an Identity system on the world. They tried that already with Passport, and failed miserably.

Kim came to Microsoft by way of acquisition, when Microsoft bought Zoomit, a Toronto company specializing in the "metadirectory" field. I came to know Kim through Craig Burton of The Burton Group, back in the early 1990s. Craig and his organization saw non-interoperable directories as a problem that could only be solved by a system that was intentionally inclusive and respectful toward all directories and their countless differences. Craig labeled the required system a "metadirectory", and called for vendors to fill the market's need for one. Kim and Zoomit stepped forward and developed a metadirectory product, along with a lot of deep thinking about directories and related issues like security and identity. During that time I became good friends with Kim, an occasional consultant to Zoomit.

Microsoft acquired Zoomit at about the time it was becoming clear that Microsoft was failing miserably with Passport -- a centralized identity management system that had the misfortune of launching as part of an initiative that may have had the scariest name in Microsoft's history: "Hailstorm." (I wrote about Passport and Hailstorm in "Whose hand is that in your pocket", for the July 2001 Linux Journal.)

At Microsoft Kim took a leading role in re-thinking the company's approach to identity. It became clear to him that taking a "meta" approach would open a whole new marketplace -- for Microsoft and everybody else. "At first I didn't think it was possible. But while I was scrounging around one day I ran across this one protocol that was so simple I could hardly believe it. I saw how it could work like a conduit for the simple exchange of tokens, and how it could bridge many different identity systems. That's what's 'meta' about it. After that other pieces began falling into place."

Craig Burton took a natural interest in Kim's identity work at Microsoft. Before DIDW/2004, Craig began telling me Kim's (then unmanned) architecture had the potential to seed and support -- in an open way -- the kind of grass roots movement I had been calling for in my Linux Journal columns and DIDW keynotes.

So I made sure Kim got to connect with the other grass-roots advocates attending the conference: Drummond Reed, Fen LaBalme, Mark LeMaitre, Kaliya Hamlin, Jan Hauser and Owen Davis of Identity Commons (and also, for several on that list, of Seattle-based Cordance); Dick Hardt of Sxip, Marc Canter (currently of Broadband Mechanics, but perhaps best known as a founder of Macromind, which later became Macromedia), Simon Grice of MiDentity and Phil Windley of Brigham Young University (also the former CIO of Utah and the author of a new book from O'Reilly on digital identity). All are open source and open standards advocates, and all consider open source involvement essential to the success of whatever it was Kim and Microsoft had in the works, which still wasn't clear at the time.

An informal group began to form. Meetings followed in Seattle and other places. Progress was reported on various mailing lists.

Right after DIDW/2004, Kim also began posting his Seven Laws of Identity. He did this on the installment plan, to give everybody time to talk about each one before moving on to the next. His First Law appeared on November 16, and his Seventh Law appeared on March, 2005. In summary form, here they are:

  1. User Control and Consent:
    Digital identity systems must only reveal information identifying a user
    with the user's consent. (Starts here...)
  2. Limited Disclosure for Limited Use
    The solution which discloses the least identifying information and best
    limits its use is the most stable, long-term solution. (Starts here...)
  3. The Law of Fewest Parties
    Digital identity systems must limit disclosure of identifying
    information to parties having a necessary and justifiable place in a
    given identity relationship. (Starts here...)
  4. Directed Identity
    A universal identity metasystem must support both "omnidirectional"
    identifiers for use by public entities and "unidirectional" identifiers
    for private entities, thus facilitating discovery while preventing
    unnecessary release of correlation handles. (Starts here...)
  5. Pluralism of Operators and Technologies:
    A universal identity metasystem must channel and enable the interworking
    of multiple identity technologies run by multiple identity providers.
    (Starts here...)
  6. Human Integration:
    A unifying identity metasystem must define the human user as a component
    integrated through protected and unambiguous human-machine
    communications. (Starts here...)
  7. Consistent Experience Across Contexts:
    A unifying identity metasystem must provide a simple consistent
    experience while enabling separation of contexts through multiple
    operators and technologies. (Starts here...)1. User Control and Consent:

The Laws serve two purposes. The first is to guide conversation and development in an emerging marketplace. The second to guide conversation and development inside Microsoft. Kim says he often finds himself saying stuff like, "No, that would break the Fifth Law" or "That misses the point of the Seventh Law."

Microsoft is, and will remain, an issue. In October and November, Marc Canter and others wondered out loud about how we could ever trust the company, or its partners (like Sun Microsystems). Craig Burton acknowledged the problem in a December 4 blog posting:

Marc contends that people don't want to get locked into standards owned by Microsoft or Sun. Kim wants to look beyond the past and create a "big bang" of distributed computing that would eclipse the petty Microsoft bashing. In Marc's defense, Microsoft is an unabashed bully. The leaders of Microsoft -- Bill Gates and Steve Ballmer --lead the bully behavior. I have personal experience of this behavior from both of them. Microsoft doesn't and isn't going to play fair anytime in the future--in general.

Perspective: Craig fought Microsoft when he was at Novell in the 1980s. And usually won. One high-level Microsoft executive told me years later that Craig was perhaps the only leader at a competing company that truly understood how to compete and win against Microsoft. Craig continues,

I say "in general" for a reason. There are good people with vision and integrity at Microsoft. Kim Cameron is one of those people. You can't go wrong working with Kim. Further, it is just ludicrous to think that Microsoft is of one voice and has an overarching plan with which to rule everything always and forever... I have said before to Kim that working at Microsoft is like working inside 10 tornadoes. I am changing that to a thousand tornadoes. Each tornado (or hailstorm if you like) has its own path, thinking and objective. They seldom cross paths and are too busy dealing with the issues at hand to even talk to each other. Microsoft is a thousand tornadoes deep.

Microsoft bashing aside, when two people like Marc and Kim get together and collaborate, expect good things to happen that go beyond the history of giants--even the giant of all time--Microsoft.

The most significant push-back we received was from Dave Winer, whom Kim considered an important role model. Dave had success at launching standards, including XML-RPC, SOAP (which Dave and his company, Userland, co-developed with Microsoft) and RSS -- and he made it all happen without the clout of a large organization behind him. RSS was an especially interesting case, because it established a service -- syndication -- that is rapidly moving toward ubiquity.

The December 14 Gillmor Gang podcast focused on digital identity, with Phil Windley as a guest. In that podcast, we waxed optimistic about Independent Identity spreading like RSS. On December 25, Dave responded with this on his blog, Scripting News:

Doc Searls... offered RSS and podcasting as examples of technologies that were simple, therefore successful, and suggests that identity, if it were to be approached the same way, might have similar success. Bzzzt. Wrong. RSS was not easy, it was hard, for exactly the same reasons identity is hard. Too many cooks spoil the broth. Two ways to do identity is one too many.

Politics spoiled identity, and would have spoiled RSS had the major players not converged on RSS 2.0. The difference this time was that there was a Switzerland, me, to guide RSS through its gauntlet, and I clearly wasn't in bed with any of the major publishers or vendors. The Harvard connection didn't hurt because it's a highly respected university that hadn't been involved in tech standards. Had identity had that kind of champion-ship it might not be the mess it is today.

I didn't think Identity was spoiled in the least. But I also realized something, which I said in my weblog on December 29:

...identity needs a Dave Winer: an independent developer and free-range technologist who tirelessly advocates something that will work for everybody -- and for users and developers diggin' together. I'd like to name names, but I'd rather see somebody step forward.

On December 30, Steve Gillmor called. He was hunting up guests for the Gillmor Gang scheduled the next day: New Year's Eve. I suggested bringing in the "Identity Gang" -- or as many as wanted to come on the show. Steve said yes, and I sent out an email to nine people, including Dave Winer, whose experience, example and skepticism I thought were essential. To my surprise, nearly all of them (including Dave) agreed, and took part in the show.

The conversation was all over the place. But it served as a public meeting to which many could listen and link. The "Identity Gang" show was energizing. Starting on January 1, 2005, I saw Independent Identity issues discussed -- not just in blogs and podcasts, but in trade pubs and in halls at conferences -- with considerable optimism. In the past, discussions always seemed to go sideways into energy draining digressions on privacy, crypto and other muddy subjects. Such as Why Microsoft Sucks.

There will always be plenty of distrust for Microsoft, of course; but Kim bled off a lot of steam by publishing his Fifth Law on New Years Day. Craig Burton wrote this about it:

The Law of Pluralism is contrary to the laws of customer control.

Let's be clear: the law of pluralism requires operating system independence--by definition. This means the Microsoft Identity Archtiect is calling for a system that is not necessarily Windows-centric by design. This--of course--is the only way such a system can really work. But consider the implications.

A cross-platfrom identity metasystem is sun-spot hot and--with the other laws being discussed here--changes everything.

Our next big meeting took place just before PC Forum, on March 20, in Scottsdale, Arizona. Much was discussed, but the main agreement was around the need to formalize what we were doing, at least a little bit. Also that our separate efforts were beginning to adapt to the leadership Kim was bringing to the table. The Identity Metasystem looked to each of us -- so far as we could understand it, which wasn't enough -- like it had the makings of a Net-native system that would embrace and accommodate everybody's separate efforts. It helped especially that Drummond Reed and the Identity Commons people were already figuring out ways of working with the Identity Metasystem.

Kim also demonstrated InfoCards, a Microsoft identity implementation that will work within the Metasystem. Everybody was eager to think about, or find, other implementations -- so nobody would confuse the InfoCard implementation with the Identity Metasystem architecture. At one point I asked if it was possible for InfoCards, or anything Microsoft was doing in the Identity Metasystem framework, to plug into FireFox. Kim said "Yes, of course". Mitchell Baker, president of the Mozilla Foundation, happened to be at PC Forum, so I invited her to the next meeting we held at the show. She and Kim spoke for a long time at that meeting; and at the end they agreed that it ought to be workable.

That meeting was also attended by John Clippinger, a Senior Fellow at the Berkman Center for Internet and Society, who approached me earlier with an interest in helping the group, perhaps by providing a "clubhouse" for meetings and for organizing future discussions and projects. At this writing nothing has been formalized, but the informal effect has been to focus conversation and energy. There's a growing wiki and an active mailing list.

The Identity Gang has grown since then. DIDW gave us a room to use on May 8 , the day before the show started. About 40 people met all day around a large table. Kim explained the Identity Metasystem in more detail than we had heard before. There was lots of discussion, including plenty of skepticism, but more than enough positive energy to keep everybody interested.

Since then, Kim and his team have published a white paper titled "Microsoft's Vision for an Identity Metasystem". The paper outlines the architecture in some detail. Here are the key paragraphs:

The encapsulating protocol used for claims transformation is WS-Trust. Negotiations are conducted using WS-MetadataExchange and WS-SecurityPolicy. These protocols enable building a technology-neutral identity metasystem and form the "backplane" of the identity metasystem. Like other Web services protocols, they also allow new kinds of identities and technologies to be incorporated and utilized as they are developed and adopted by the industry.

To foster the interoperability necessary for broad adoption, the specifications for WS-* are published and are freely available, have been or will be submitted to open standards bodies, and allows implementations to be developed royalty-free.

Deployments of existing identity technologies can be leveraged in the metasystem by implementing support for the three WS-* protocols above. Examples of technologies that could be utilized via the metasystem include LDAP claims schemas, X.509, which is used in Smartcards; Kerberos, which is used in Active Directory and some UNIX environments; and SAML, a standard used in inter-corporate federation scenarios.

Here's the graphic illustration:

The Independent Identity would be one of the ID providers - part of the metasystem. It could be hosted locally, or on a linux box in the cloud, or on a phone - wherever someone wanted to put one.

From the looks of it, the Subject bears a heavy weight. In general, that's what the critics are saying. At this writing, the most persistent pushback is coming from Julian Bond, who launched a blog-to-blog dialog with Kim by posting "Why Infocard will fall at the first fence". Here's his latest summary:

...we're talking about building an Identity system on top of a large stack of unfinished protocols on top of a basic communications protocol that still has some interop problems on top of a very common web scripting environment where the bottom level of the stack is not going anywhere. Yup, that'll work.

That was after Kim wrote,

The open source implementations will run on those clients.  And we would urge people to build clients to work with us to ensure interoperability.  These are still the early days of the stack!  Of course the interoperation is patchy!  In the early days of LDAP we couldn't even agree on what to call an email address!" ...

We thought long and hard about how to make the client tremendously open to a plurality of identity technologies and operators.  We've put it out there.  It doesn't require anyone to lay down their existing protocols - use whatever works for interacting with conventional clients.  But let's give the end user a better, safer and more comprehensible mechanism for taking control of her identity. 

In this, Julian, why not work with us?  The laws are not abstract things... Not every aspect of these proposals may be exactly as you would wish.  But please consider the great complexity of "weaving" a solution here, garnering support across all the constituencies, and consider again why you would walk away from this opportunity.

At this writing, there are two open source Independent Identity systems: LID (Lightweight IDentity) and OpenID. The first is by Johannes Ernst and his company, NetMesh. The second is by Brad Fitzpatrick, founder of LiveJournal (the first open source blogging system). By the time you read this a third will be revealed: Mobius, by "Dizzy" Dave Smith, with help from Peter Saint-Andre, Jeremie Miller and other Jabber/XMPP veterans. Dave's work is supported by his employer, Ping Identity, which also created and hosts SourceID, an open source project with an enterprise orientation.

In a comment on Kim's blog, Dave writes,

Kim, I fully appreciate where you are going with this, and understand your request to support WS-Trust as an exchange mechanism. What I fear is not understood by the other implementers however, is the amount of work involved with getting WS-Trust (specifically InfoCards) going. There are dependencies on several other WS-* protocols -- WS-SecureConversation, WS-Policy, WS-Security -- plus XML-Signatures and a few other W3C specs that are not exactly known for their ease of implementation/interoperatbility. All of that said, if WS-Trust was ONLY dependent on the actual WS-Trust protocol + SSL (which should be sufficient), I would be much more willing to _consider_ WS-Trust as a token exchange protocol.

Scott Cantor, a prime author of the widely used SAML, adds this:

I have two relevant points, one of which is to echo Dave Smith above. My concern is less about WS-Trust itself than about both its status as a closed document (Microsoft was very forthright at DIDW in acknowledging that the open OASIS process does not afford them an advantage in influence that their workshop process does, but that's hardly a good thing for the rest of us) and its dependence on so many other equally unfinished specs that it's very hard to evaluate it in isolation, or without an immense amount of time at one's disposal.

Kim's posted answers to both questions were long and detailed, but came down to a claim that things are simpler (and more practical) than they appear. In a conversation the next day I asked Kim to unpack that claim. He replied,

Everybody supports WS-addressing, security and XML signature and
encryption. Take those off the table. Then you have WS-transfer. Shouldn't be on the list, because it's not required. Then you have WS-Trust and WS-Metadata exchange. These are microstandards. Think of microstandards as object orientation applied to standards -- in the sense that they're clearly factored. Instead of being mainlined, it's little pieces being used. Look at them as building materials. Little clamps and things. Once you have the clamps, you can use them in more than one place. All WS-policy does is talk about how you specify the conjunctions ... the ANDS and ORs, as you set up a policy. It's just XML syntax constraints. Nothing more. These are truly microstandards. Take away the boilerplate and the examples and all that's left is a little how-to: this is how you name it, this is where this and that go. WS-policy and WS-Trust are descriptions of how tokens are exchanged in a Web services dialog.

We're doing it first for SOAP, because SOAP is done and everybody's building their services using SOAP. There could potentially be encodings other than SOAP. The question is, do we need to add this additional complexity to the client, or could it be done through an STS gateway -- by which I'm referring to a claims transformer.

WS-Trust has actually come out of the workshop process. It's proved workable. There are some things to be done with WS-Security Policy involving XML statements to be used. The idea is to get as much of that done as possible before it goes into the standards process. It should be stuff that works and is well-described. It's open to change, but there are systems using it already. Lots of people from different companies and communities, including open source, are involved.

You wouldn't want to support all possible protocols everywhere, such as on a cell phone. Something within reason. You can't test a thousand possible protocol variants because you'll have a virus transport system.

Kim followed up in his blog with an examination of WS-Policy. In it he introduces the concept of "microstandards" or "standards objects that can be combined and specialized to define complex distributed systems." From the 22-page WS-Policy spec he subtracts out the formalities (intro, authors, abstract, references) and examples, arriving at "seven pages of discursive specification". Within these he isolates "An XML Infoset called a policy expression that contains domain-specific, Web Service policy information" and "A core set of constructs to indicate how choices and/or combinations of domain-specific policy assertions apply in a Web services environment". After providing a couple examples, he concludes,

So that's it, folks. Building a WS-Policy compliant application means that when you negotiate your policy with another end-point, you use this way of structuring the XML that describes the policy. You likely don't have to write a line of code to comply. In fact, I look at this spec as eliminating a lot of lines of code by giving us a simple way to express our policy alternatives and to evaluate them.

While that may be encouraging, I've also told Kim that he and Microsoft need to do more before my constituency -- the Linux and open source development communities -- take a serious interest in the Identity Metasystem. I said, "If you don't have an open source license, or if you start talking about 'IP Frameworks', my readers will leave the room". (The term 'IP Frameworks' was used by somebody from an other part of Microsoft, in respect to the WS-* standards process.) Kim replied,

It's essential to have the open source community involved. And I wish we were already at some point in the future when we have some of these things cleared up. But we're talking about slow processes here. The standards process is incredibly complicated. You get a bunch of companies together, and the process is like nuclear disarmament. The only way to get a royalty-free standard is to negotiate IP in such a way that nobody can sue because it's a standoff. What an 'IP Framework' means to me -- though I am not a lawyer and can's speak for Microsoft on IP issues -- is that everybody puts their IP in and agrees not to charge royalties. Ironically, the biggest concern may not be each company's IP, but 'submarine patents' that can surface later and screw up everybody.

As for open source licensing, Kim has said encouraging things to me privately; but for now there's nothing to report. I'm hoping, for everybody's sake, there will be an accepted open source license, or licenses, in place by the time you read this.

Meanwhile, everybody in the open source camp seems to be scratching their own itches, each in their own simplifying way.

OpenID says, "This is a distributed identity system, but one that's actually distributed and doesn't entirely crumble if one company turns evil or goes out of business." Its identities are URL-based.

LID's goal is to "empower individuals to keep control over and manage their digital identities, using VCards, FOAF and GPG. It is very REST-ful and fully decentralized. It is also a great mechanism to add accountability to REST-based web services, even if no (human) digital identities are involved." Johannes Ernst, one of LID's creators, says "it's the simplest scheme there is, so simple that, just like a few other folks have done already, you can probably implement it yourself over the weekend and add five new profiles to it that we didn't even think of." There are several LAMP and J2EE implementations available for download.

Sxip is more ambitious, and has several parts. Sxip.net (Sxip Network) is "a simple, secure and open digital identity network that offers a user-centric and decentralized approach to identity management. This key piece of Internet infrastructure, based on a network architecture similar to DNS, can be used by anyone to develop their own identity management solutions, enabling distinct and portable Internet identities." Sxip.com (Sxip Identity) "provides identity management solutions that leverage the Sxip Network and drive Identity 2.0 infrastructure. Sxip empowers individuals to create and manage their online digital identities and enables enterprises to instantly provision and manage their users." Sxip.org provides developer resources, including a Subversion code repository.

Passel "builds on the success of email-based identity systems by adding a few important but incremental improvements while laying the foundation for more advanced identity systems in the future. Passel is more convenient to use, easier to deploy, and safer for all concerned, without requiring expensive investments in new infrastructure or adoption of untried, centralized identity systems."

There are other open source and Linux-related efforts around identity, and I'm sure this essay will flush out those who feel offended by their exclusion. I invite them to join the Identity Gang, or whatever name it uses by the time you read this.

Things are moving so fast, and in so many directions at once, and with so many individuals involved, that it's impossible to cover the subject completely. This piece sets a record of frustration for me, personally. I've been working on it since January, and I've rewritten it countless times. I was going through a series of rewrites when I missed my deadline last month. And I almost decided to make it a Linux Journal website piece several days ago, when I still wasn't sure if Kim and his Identity Metasystem would take the heat from interested skeptics like Julian Bond and Dave Smith. Or from those of us (a percentage that rounds to everybody) who see a lock-in agenda behind every Microsoft move. So I posted some tough public questions on IT Garage. Kim has met every challenge with grace, humor and backbone. I'm sure he needs all three to make this project fly inside Microsoft.

I also want to thank Microsoft for giving Kim a way to apply his genius. If this thing flies, high fives are due, all around.

The best any of us can do is stay true to our own principles and purposes. Kim's are embodied in his "meta" understanding of the world. The man is the best includer I've ever known. Microsoft is lucky in the extreme to have him working there. Mine are embodied in an NEA understanding of the Net -- as something Nobody can own, Everybody can use and Anybody can improve.

There is an improvement I want to see, and it's something only Independent Identities can produce. I describe it partially in the five-point case I make at the beginning of this piece. Here's the rest of it.

I want anybody to be able to pay for anything on a voluntary basis, because I believe the voluntary ability to pay whatever one wants is at the heart of a free and open marketplace. I also believe we haven't experienced that power since the Industrial Revolution put huge suppliers in charge (even of democratic governments). We certainly haven't had it since the invention of the price tag.

I'm not saying I want to turn every store into a commodities pit where everybody haggles over prices. I'm not saying "Let's get rid of fixed prices." I am saying, lets give consumers the power to be customers. I am saying, let's start by making this work in markets where no prices have yet been set, where sellers and buyers don't yet have the means for discovering what their goods are worth, where -- because that mechanism is absent -- most of the good are free (as in beer).

I have two markets in mind: "podsafe" (non-RIAA, Creative Comons licensed) music and podcasts. I would like to be able to express my willingness to pay for music I like, and for podcasts I like, and to do that, at my discretion, quickly and easily. (And, to extend that ability to other services that welcome voluntary payment, such as public radio and TV, churches, charities, and so on).

I would like that capability to be built into my browser (as a plugin? probably) and my RSS aggregator. Later, I'd like to see it in cell phones and other mobile devices.

I would like the open source community to step into those markets with me and say, "We have a way that anybody can pay anybody for anything, on their own or mutually agreeable terms." And free has to be an alternative. Free has to still be okay.

You might say I'm talking about a more robust shareware market here. One where suppliers don't beg or cajole, or make goods scarce, or call those who get goods for free "pirates". I'm talking about making the Net as open and responsible as a farmers market: a place where customers are just as unlikely to filch from an artist's site as they are to take an apple from a farmer's cart. And where artists of all kinds can still give away all they like.

Can this be done? I don't know. I can think of a hundred reasons why it can't. I'm sure the rest of you can think of more. Between the last sentence and this one, Johannes Ernst wrote this to me:

The trouble though, is, that we are miles away from being able to understand what the technical requirements are for such a transformational system, because we haven't thought through the transformational applications that need to be supported.

Yet I feel certain there's a way of doing this, and experimenting with it, and seeing what works and what doesn't, and showing the world how a free and open marketplace can work.

I want to give the old choose-your-silo system a bad case of Innovator's Dilemma. We need something disruptive here. Something simple and new. An invention that mothers necessity.

We won't get it if we get bogged down in long-winded digressions about privacy and crypto and the big awful companies that want to keep their hands (oops, credit and membership cards) in our pockets. Those are legitimate and necessary concerns, but they are secondary to the purpose of establishing methods and protocols and technologies for the assertion of Independent Identity. And for changing the world by saving markets from the producerist mentality that has kept everybody, producers included, in darkness for more than a century.

I also feel certain that forces far more nefarious than Microsoft are hellbent on putting the Net genie back in the telco and cableco bottles -- and turning it into the distribution system for "protected content" they imagined when they made sure the "information superhighway" had asymmetrical driveways to every "consumer's" home.

If we don't want that, we have to show we're customers and not just consumers. And real customers don't just shop in silos.


Resources...

    Grounds for Identity, November 2002: http://www.linuxjournal.com/article/6382

    What's our i-Name? November 2002: http://www.linuxjournal.com/article/7888

    Dave Winer: Last Week's Gillmor Gang. http://archive.scripting.com/2004/12/25#lastWeeksGillmorGang

    Gillmor Gang December 31 2004
    http://www.itconversations.com/shows/detail394.html

    Keynote, DIDW 2003

    Keynote, Digital Identity World, October 27, 2004

    Sewing CoRM

    LID
    http://lid.netmesh.org/

    OpenID
    http://www.danga.com/openid/

    Infocard will fall at the first fence, by Julian Bond
    http://www.voidstar.com/node.php?id=2386

    Wiki from "Identity Gang" meeting at DIDW
    http://wiki.idcommons.net/moin.cgi/DigitalIdWorld

    Identity from the Inside Out