Kim Cameron - Identity Laws
- Posted: Jul 06, 2005 at 5:38 PM
- 65,472 Views
- 16 Comments
Download
How do I download the videos?
- To download, right click the file type you would like and pick “Save target as…” or “Save link as…”
Why should I download videos from Channel9?
- It's an easy way to save the videos you like locally.
- You can save the videos in order to watch them offline.
- If all you want is to hear the audio, you can download the MP3!
Which version should I choose?
- If you want to view the video on your PC, Xbox or Media Center, download the High Quality WMV file (this is the highest quality version we have available).
- If you'd like a lower bitrate version, to reduce the download time or cost, then choose the Medium Quality WMV file.
- If you have a Zune, WP7, iPhone, iPad, or iPod device, choose the low or medium MP4 file.
- If you just want to hear the audio of the video, choose the MP3 file.
Right click “Save as…”
- Mid Quality WMV (Lo-band, Mobile)
- WMV (WMV Video)
So, we went over and talked about, what else, identity online. It's important for developers (and companies) to think about.
Comments Closed
Comments have been closed since this content was published more than 30 days ago, but if you'd like to continue the conversation,
please create a new thread in our Forums,
or
Contact Us and let us know.
Follow the Discussion
Thanks for the tip on the phone! Is that the fourth time you've had it on camera?
Hash: SHA1
ah... identity confirmed...
-----BEGIN PGP SIGNATURE-----
Comment: pub key http://matthew.vaneerde.com/pgp-public-key.asc
iD8DBQFCzLbfUQQr0VWaglwRAssXAKCtMLQ2XEioQzbG1ihRiZbJx/qwgACg3GTf
tlWlW5dfc3/QiduD3jyaLH0=
=N3cQ
-----END PGP SIGNATURE-----
Passport isn't used outside of Microsoft because it was too expensive, and difficult to develop with.
I really wanted to use it, but these two problems stopped me.
rasx - I have absolutely no idea what you are talking about.
If markets at present can be bent to the will of say Wallmart and their RF-ID stratergy then won't the old ideas of 'well get you along with everyone else' prevail anyway?
I see that this guy is preparred to go for at least 10 years into the project, and only to get the stone rolling. Well I hope something materialises before then, but what? And how will this ID concept compare to what is going to be in Longhorn?
You said I can eventually "be the same person" on my
Xp box, my phone, my linux box, my electronic underwear, etc.
Computer identity at its core has to do with posessing a secret. I have a key that nobody else has. The details are just in what do I have to do to prove to you that I actually have the key, and who knows that its my key, and how do they know.
In order to be "me" on two devices I either have to have the same secret key on two devices or I have to convince you that two separate keys are really the same person. so you have two choices 1) Have some protocool to transfer my identity to another, arbitrary device, or 2 have some way to say that the same me has two keys. (I don't thank that manually entering a 512 bit identity key is something my grandma could do.)
It seems like either of these two possibilities is just rife with social engineering potential if not technical attacks.
I know a lot of people have thought about this a lot more than me. Are there easy answers? what is the current best ideas?
Write the sentence "I am John Melville, MD" and sign it with both keys. Extensible to n keys. Post all signatories on your blog or other public presence point.
Two problems:
1) Most people don't have a "public presence point," and would not know if a fabricated "public presence" had been made it their name. This is easily solved by making the "public presence point" a respected keyserver with a good identify verification mechanisim.
2) The second problem is the point of the post.
If I let people link 2 keys to the same identity, then a trivial pfishing attack becomes "to avoid loosing your pay-pal account validate the following as your public key." or "a worm that exploits a hole in windows to validate another key in your name." If there is only one private key there are relatively cheep (hardware) ways to make it impossible for even a worm to discover it. (Although I worm could use your key, it couldn't steal it by registering another identity in your name.)
So if I let one identity have multiple keys then I open up a huge attack surface to both social and technological attacks. Furthermore a vulnerability in any one client, which may not be the best designed, can compromise the trust in the whole system. Is this a vulnerability that we want built into the identity system?
Maybe my bank should decide if they want to believe that John's Computer and John's Cellphone are the same person? I bet Channel9 doesn't care how many people John Melville really is. I bet my bank does.
Great video,
Everyone agrees that this needs to be addressed but nobody wants to agree to any single soultion. And who do you want to trust your ID with. ( Or a device, IE: smartcard or Cell Phone ) And how can a person keep control over thier ID.
Im just staying with just a basic cell phone, for the reasons of security and privacy, No bluetooth for me, it isnt secure enough. And I dont want my cell phone to be hacked into.
Like most people I try to use as little personally identifiable information on the internet as possible. What has credit cards got to do with identity? When I use a credit card on the net it is a secure communication between myself and the credit card company. What you guys should be working on is making sure the fields I type the numbers into don't autocomplete from last time!!!!
People have the right to refuse to use their real identities on the net. My "real" net identity has no personally identifiable information. How are you going to secure that, and make sure others don't steal it, while making sure the governments dont prevent me from using it?
There would be nothing technologically preventing the delivery company from retaining these records (linking tokens with addresses, for example). I don't know if there's any good solution to that.
This is just a start on how (permanent) identifiying information can be limited in its distribution. I'm sure much more could be said here.
So I think infocard is a super implementation of globally reusable credentials (not Microsoft specific, other than as a potentially trusted provider). This is true regardless of what kind of identity claims are tied to any given credential. Infocard enables but does not require use as a simpler way to type identity info like a ship-to address, and that can work regardless of whether it's always the same or not.
However, I do strongly agree with concerns about scope and timeframe of valid reuse fo both credentials and identity claims. I'd very much like to see standard capability to easily checkmark and timestamp user-authorized valid reuse of both credentials and claims information for use at a given site. Sites cooperating in their own self-interest with this mechanism will automatically recognize their local copy of claim info is marked as invalid due to expiration stamp and ask via standard infocard prompts whether you want to recertify or update the site's copy of previously authorized info, based on your currently chosen infocard claims data. Haven't seen anything on this yet, if not there please get it into next release cycle.
Reasonable opinions, it is quite necessary to consider this kind of issues.
<a href="http://www.freerpgsite.com/">free rpg games</a>
Reasonable opinions, it is quite necessary to consider this kind of issues.
[url=http://www.freerpgsite.com/]free rpg games[/url]
Remove this comment
Remove this thread
close