Epeus' epigone

Edifying exquisite equine entrapments

Showing posts with label Activity Streams. Show all posts
Showing posts with label Activity Streams. Show all posts

Saturday, 9 April 2011

Ev's identity map ignores what we say

Ev Williams wrote a good blog post on identity yesterday, that I suggest you go and read. The odd thing is that he leaves out the publicly articulated thoughts that we use blogs, Twitter and other services to publish as an expression of our identity. Before I get to that, though, I'd like to connect his facets back to the open specs that represent these aspects.

Authentication

Ev mentions OpenID here, and is essentially correct that it is not helpful on its own. It was designed to verify URLs for blog comments. If all you do is use OpenID, you just replace logging into your site with logging into another, adding extra confusion without much benefit. However, once you have a URL for someone, you can then discover further information about them, by examining that URL and its links. Microformats can encode this directly in the webpage, or you can use related links to discover API endpoints for more.

The distinction between Authorization and Authentication is elided by Ev, and in practice OAuth has been winning out over OpenID as it is explicitly an Authorization APi that had Authentication as a side effect. The new OpenID Connect proposals try to remedy both these failing by using OAuth and by standardizing on how to list other endpoints.

Representation

Here Ev is looking for what is commonly called profile information. We have some mature standards for this - vCard is widely used by email clients, and is currently going through another standardization round to add modern features. The hCard microformat gives a simple way to embed profiles in web pages. Also, the rel="me" part of XFN makes it straightforward to link web pages together that represent different aspects fo your public representation. This is supported by Facebook, Twitter and Google, but sadly not by about.me whom Ev praises.

If you want a general data format for profile data, Portable Contacts is what you need.

Communication

Ev's emphasis on email addresses here illustrates the problem with them; they are primarily write-only; though we persist in using them for log-in IDs, they are not readily discoverable. The WebFinger spec gives a way round this - a way to go from an email to endpoints for other readable identity standards. Other communication standards have piggy-backed on email address, such as Jabber and Wave.

Personalization

This hints at the glaring gap in Ev's model, the expression of personal taste and preference. This is commonly done by reviewing, and we have the hReview microformat to express that, but it can also be useful just to track a history of media played or places visited to derive preferences over time. Here Activity Streams are an obvious fit, and it would be good to map such proprietary formats as Amazon purchases, Last.fm scrobbles, iTunes played songs and so on into a common format to derive this.

One model we can use for this is tagging - associating keywords with things. Many feed specs have tagging built in, and the rel="tag" microformat is a way of indicating these publicly.

Reputation

As Ev says, this is problematic, and also often highly contextual; I may trust someone's advice on restaurants without listening to them about which programming language to use. Reputation and trust are subtle, deeply human and very hard to model. The best answer here may be to rely on the power of faces and following; if we attach the face of someone we know to their public statements, we can decide for ourselves how much weight to give them.

Which brings me back to my opening point. When we decide who to pay attention to online, we tend to rely on what they say; if you get an @ reply on twitter, clicking on that person's name to see their most recent comments is hugely useful in deciding how much attention to pay to them. Similarly, the history of public blog posts, or their reviews of movies, music, books or restaurants arre other reasons we may follow them, and our identity is most strongly formed from the stories we tell and retell about ourselves. Feeds, whether in Atom, RSS or hAtom, and Activity Streams give rich representation of our thought, opinions and actions.

Whom we choose to associate with or follow is also an expression of our identity, and a useful signal when deciding how much attention to pay to someone, and XFN and Portable Contacts are both usefule in discovering these connections.

Dare Obasanjo also responded to Ev's Identity post, and added in payment as well as the friends as missed aspects. I'd love to discuss this further with both Ev and Dare at the Internet Identity Workshop next month, which is where many of the specs mentioned above were conceived and agreed. Maybe Ev can bring some others from Twitter with him too; their past contributions to OAuth were highly useful and there is plenty more to get our teeth into, as Ev's post shows.

Posted by Kevin Marks at 18:25 2 comments:
Labels: Activity Streams, hAtom, hcard, hReview, IIW, microformats, OAuth, OpenID, xfn

Saturday, 13 November 2010

Firesheep, enterprise software and other broken models

There has been a lot of fuss about FireSheep, a browser plugin that show how easy it is to intercept packets on the internet, and masquerade as someone else. The idea is nothing new: EtherPeg—which intercepts wifi traffic and shows the JPEGs and other images passing by—is over 10 years old. Annalee Newitz wrote a Wired story on people packet sniffing in coffee shops back in 2004.

The underlying design of the internet means that you don't know who will be able to see any packets you send. If you care about not being snooped on, you need an encrypted connection from your computer to the one serving you at the other end. The best way to do this on the web is to use HTTPS, which all browsers support, and most servers support with configuration changes. It's not perfect, but it's good enough.

However, much of the advice following on from FireSheep was misleading or outright wrong. I saw several articles saying:

  • Avoid Open WiFi
  • Turn on WPA encryption
  • Use a VPN to tunnel the traffic into a server elsewhere

These techniques may protect for a while against those nearby you in the Café, but by not securing the whole connection, they just change who is able to intercept your communications.

The security model here is the firewall one - the notion that there are trusted networks and untrusted networks, and as long as you're inside a trusted one, you'll be OK. This is an obsolete worldview. When computers were large fixed physical entities with software controlled by a specialist, and networks were wires under their control too, this had some correspondence with reality, but it was always tenuous - others within the firewall could be running compromised machines; outbound connections could still leak data.

If you VPN into a company or service to mask your outbound connections, that endpoint is an attractive point of attack, as it has collected a set of people who think their data needs securing. There's a clear example of this in this NYT article about a hacker who lured his friends to use an FBI VPN to track them down and arrest them.

This worldview connects with two other themes. The US Government is trying to pass a law requiring ISPs to enable your communications to be intercepted. The UK government is also working on legislation on retaining all email and web traffic. Similarly, many companies monitor internet traffic within and leaving their secure networks for legal compliance and employee monitoring. Such mandated backdoors, like the VPN tunnel, become attractive targets for other bad actors - remember the Greek government being spied on through a legally mandated interception backdoor in the phones they used?

This week, I spent a couple of days at the Enterprise 2.0 conference, hearing how open standards like Activity Streams and OpenSocial are being used to bridge separate business information systems both within and between companies, with OAuth used to enforce corporate policy.

This seems anathema to old-line IT managers who assume that they dictate who gets to see what, but the pragmatic realisation that many business people have more powerful and connected computing devices in their pockets as phones than on their desks from corporate IT was in evidence at E2.0 at least.

This brought to mind the great conversation we had with Josh Klein on TummelVision last week, discussing his book Hacking Work - breaking stupid rules for smart results:

one of the most common hacks we found: jumping IT’s firewall and working around their restrictions and tools in open computing environments, then bringing the work back over the firewall and presenting it to bosses as if the corporate tools had actually been used.

Ben Horowitz's article on enterprise sales in TechCrunch today tries to justify corporate practices, even as he recognizes the inversion of the innovation flow.

What this misses is the underlying economic justification for the existence of a corporation in the first place - the economic theories that build on Coase's work saying that firms exist because transaction costs are lower within them than external transactions mediated by the marketplaces. Pettifogging internal purchasing rules should be subject to this test: does the internal transaction cost of approving and purchasing something exceed the value of the thing being purchased?

Reading Ben's explanation of how corporate salespeople help institutions negotiate their own labyrinthine processes, I couldn't help but be reminded of John Hagel's Big Shift model, (also discussed on TummelVision), which continues to show a declining return on assets for corporations.

The challenge we have on the web is to maintain the kinds of open-to-all interoperable standards that empower us to work round these creaking bureaucracies. If we delegate our online identities to a few firms operating proprietary APIs, that they can revoke access to, or decide who can call them for reasons of corporate strategy, the lowered transaction costs suddenly get very high again.

Doc Searls's work on VRM (this week's TummelVision) is all about making sure that we can retain agency over our own information. I expect to discuss this in depth at Defrag next week.

Posted by Kevin Marks at 15:21 1 comment:
Labels: Activity Streams, enterprise, firewall, OpenSocial, Tummeling, TummelVision, VRM

Thursday, 2 September 2010

Welcome Apple, seriously

Yesterday's update of iTunes added Ping, a music-focused social network. When I tried it out early in the evening, it had Facebook Connect enabled, and both imported friends from Facebook, and notified me when new ones joined. Shortly afterwards, Mark Zuckerberg joined, and shortly after that the Facebook connection was missing.
This morning, neither company is talking on the record, though Kara Swisher reports that Steve Jobs complained about 'onerous terms' from Facebook.

Supernova This naturally reminds me of the problems we had with Google Friend Connect, where Facebook's accusation of a ToS violation was never backed up by an explanation of what would not violate the terms, leading to the "Data Roach Motel" accusations at Supernova. The underlying issue is whether you should give another company veto power over your application. Last time I wrote on this, it was Apple's veto I was warning about, though at the same time Apple was trying to avoid giving Adobe veto power over their platform again.

The thing is, we have been round this cycle before, and the answer is known too - the way to interoperate with another company without having to have a business agreement with them is to use open standards, not proprietary APIs.

Apple knows this - they have helped lead development of HTML5 and WebKit, along with many other standards in the past, including podcasting and MPEG4. Facebook knows this too, and they have been strong supporters of OAuth and Activity Streams, and even of Portable Contacts, when it's them doing the importing.

Clearly it good for us as users to be able to delegate our contact lists to an existing source - this weeks launch of conference sharing site Lanyrd shows that. It's also in our interests to be able to propagate the actions of playing, liking and purchasing music, videos and anything else between sites of our choosing, so that we can share with our friends, and so we can get more useful recommendations for the future (at minimum, not suggesting things we already have).

This was the core of the discussion at the VRM Workshop last week in Boston - that we should control over who sees what about us, and I think that with these common standards we can solve both problems - the individuals get to save having to re-enter their information everywhere, and control what flows to where, and the companies get the ability to interoperate without bizdev and single source lock-in. Activity Streams (and the associated standards they build on) are our best hope for this.

Posted by Kevin Marks at 12:46 9 comments:
Labels: Activity Streams, standards, Steve Jobs

Monday, 8 February 2010

Standards are the links of the Social Web

Mike Arrington wrote a plea for better social software on Sunday:

The online social landscape today sort of feels to me like search did in 1999. It’s a mess, but we don’t complain much about it because we don’t know there’s a better way.

Everything is decentralized, and no one is working to centralize stuff. I’ve got photos on Flickr, Posterous and Facebook (and even a few on MySpace), reviews on Yelp (but movie reviews on Flixster), location on Foursquare, Loopt and Gowalla, status updates on Facebook and Twitter, and videos on YouTube. Etc. I’ve got dozens of social graphs on dozens of sites, and trying to remember which friends puts his or her pictures on which site is a huge challenge.


What enabled Google to solve the search problem was a common standard for expressing pages and the links between them, so that they could index the webpages and derive a metric for which ones were more important. They didn't do this by replacing the web with a structured database that they curated, they worked with the standards in use to make sense of it.

To solve the social conundrum we need the equivalent - agreed standards in widespread use so that we can generalize across sites. Fortunately, we have these. We have OpenID and OAuth for delegated login; we have XFN, other microformats and Portable Contacts for public and private people connections; we have Feeds and Activity Streams for translating social actions between sites.

This enabling social infrastructure means that we'll be able to have a new generation of sites that enhance our web experience through social filtering without our connections being centralised in a single company's database.

Once we get used to the experience of being able to delegate login, personal connections and activity updates, we'll look askance at developers who insist we create yet another profile and invite all our friends by email to experience their site; it'll be like a website without links.

Posted by Kevin Marks at 22:19 4 comments:
Labels: Activity Streams, OAuth, open web, OpenID, Portable Contacts, Social Cloud, Social Web, sxd, xfn
Older Posts Home
Subscribe to: Posts (Atom)

This is my personal blog. Any views you read here are mine, and not my employers'.

Atom Feed

Support the Open Rights Group
My photoKevin Marks Me on Twitter
Me on G+

People's thoughts I read:

Daily

Rosie
San Jose Young People's Theatre
Dave Weinberger
Doc Searls
Gonzo Engaged
AKMA
Cory & friends
Denise Howell
Charles Wiltgen
Shelley Powers
James Lileks
Suw Charman
Halley Suitt

Weekly

Andrew Marks
Blogsisters
Arts & Letters Daily
Bricklin, Frankston & Reed
Steve Yost
Jeneane Sessum
Brian Micklethwait et al
Tom Matrullo
Gary Turner

Sporadically

Small Pieces
Stuart Cheshire
RageBoy
Nonzero
Neil Gaiman
Thomas Vincent
Brad deLong
Andrew Odlyzko
ProSUA

No to Mickey Mouse Computers

powered by blogger

Blog Archive

  • ▼  2023 (1)
    • ▼  September (1)
      • Plus Theory
  • ►  2017 (2)
    • ►  May (1)
    • ►  April (1)
  • ►  2015 (7)
    • ►  November (2)
    • ►  May (3)
    • ►  April (1)
    • ►  January (1)
  • ►  2014 (3)
    • ►  October (1)
    • ►  April (2)
  • ►  2013 (5)
    • ►  June (1)
    • ►  May (1)
    • ►  April (2)
    • ►  March (1)
  • ►  2012 (8)
    • ►  December (1)
    • ►  May (1)
    • ►  April (1)
    • ►  March (1)
    • ►  January (4)
  • ►  2011 (11)
    • ►  December (1)
    • ►  November (1)
    • ►  September (2)
    • ►  August (2)
    • ►  July (1)
    • ►  April (2)
    • ►  January (2)
  • ►  2010 (16)
    • ►  November (1)
    • ►  October (1)
    • ►  September (3)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (2)
  • ►  2009 (22)
    • ►  November (2)
    • ►  October (2)
    • ►  September (2)
    • ►  August (3)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  April (1)
    • ►  February (2)
    • ►  January (4)
  • ►  2008 (29)
    • ►  December (2)
    • ►  November (3)
    • ►  August (1)
    • ►  July (3)
    • ►  June (3)
    • ►  May (5)
    • ►  April (2)
    • ►  February (3)
    • ►  January (7)
  • ►  2007 (45)
    • ►  November (3)
    • ►  October (4)
    • ►  September (4)
    • ►  August (10)
    • ►  July (3)
    • ►  June (8)
    • ►  April (2)
    • ►  March (6)
    • ►  February (3)
    • ►  January (2)
  • ►  2006 (119)
    • ►  December (13)
    • ►  November (8)
    • ►  October (16)
    • ►  September (10)
    • ►  August (3)
    • ►  July (6)
    • ►  June (24)
    • ►  May (3)
    • ►  April (10)
    • ►  March (7)
    • ►  February (8)
    • ►  January (11)
  • ►  2005 (101)
    • ►  December (10)
    • ►  November (13)
    • ►  October (9)
    • ►  September (8)
    • ►  August (7)
    • ►  July (7)
    • ►  June (8)
    • ►  May (12)
    • ►  April (7)
    • ►  March (6)
    • ►  February (1)
    • ►  January (13)
  • ►  2004 (53)
    • ►  December (8)
    • ►  November (5)
    • ►  October (6)
    • ►  September (7)
    • ►  July (5)
    • ►  June (3)
    • ►  May (2)
    • ►  March (3)
    • ►  February (7)
    • ►  January (7)
  • ►  2003 (196)
    • ►  December (12)
    • ►  November (14)
    • ►  October (21)
    • ►  September (23)
    • ►  August (19)
    • ►  July (11)
    • ►  June (14)
    • ►  May (9)
    • ►  April (22)
    • ►  March (20)
    • ►  February (16)
    • ►  January (15)
  • ►  2002 (224)
    • ►  December (15)
    • ►  November (21)
    • ►  October (22)
    • ►  September (12)
    • ►  August (11)
    • ►  July (28)
    • ►  June (19)
    • ►  May (29)
    • ►  April (18)
    • ►  March (19)
    • ►  February (16)
    • ►  January (14)
  • ►  2001 (13)
    • ►  December (2)
    • ►  November (11)

Contributors

  • Kevin Marks
  • Kevin marks