<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Microsoft Privacy &amp; Safety : Identity</title><link>http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx</link><description>Tags: Identity</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Identity Roadmap Presentation at PDC09 </title><link>http://blogs.technet.com/privacyimperative/archive/2009/11/24/identity-roadmap-presentation-at-pdc09.aspx</link><pubDate>Tue, 24 Nov 2009 19:21:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3296130</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3296130.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3296130</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3296130</wfw:comment><description>Kim Cameron, the Chief Architect of Identity in the Identity and Security Division at Microsoft writes on his Identity Blog: Earlier this week I presented the Identity Keynote at the Microsoft Professional Developers Conference (PDC) in LA. The slide...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/11/24/identity-roadmap-presentation-at-pdc09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3296130" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Microsoft: minimum disclosure about minimum disclosure? </title><link>http://blogs.technet.com/privacyimperative/archive/2009/09/01/microsoft-minimum-disclosure-about-minimum-disclosure.aspx</link><pubDate>Wed, 02 Sep 2009 00:38:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3278575</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3278575.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3278575</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3278575</wfw:comment><description>Microsoft's Kim Cameron on his Identity Blog: Back from vacation and catching up on some blogs I found this piece by Felix Gaehtgens at Kuppinger Cole in Germany: A good year ago, Microsoft acquired an innovative company called U-Prove. That company,...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/09/01/microsoft-minimum-disclosure-about-minimum-disclosure.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3278575" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Windows Live ID OpenID  Status Update </title><link>http://blogs.technet.com/privacyimperative/archive/2009/08/28/windows-live-id-openid-status-update.aspx</link><pubDate>Fri, 28 Aug 2009 02:16:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3277658</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3277658.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3277658</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3277658</wfw:comment><description>Here's an update from the Windows Live Group on integrating Windows Live ID with OpenID from the Windows Live blog: Many people have asked recently about the status of the Windows Live® ID community technology preview (CTP) OpenID endpoints, so here is...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/08/28/windows-live-id-openid-status-update.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3277658" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Introducing the ID Element</title><link>http://blogs.technet.com/privacyimperative/archive/2009/08/10/introducing-the-id-element.aspx</link><pubDate>Tue, 11 Aug 2009 01:49:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3272197</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3272197.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3272197</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3272197</wfw:comment><description>Check out the newest resource on Microsoft's Channel 9, The Id Element : Welcome to The Id Element , your one-stop shop for all things identity on Channel9! In this page you will find all kinds of material on Identity and Access Control : weekly interviews...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/08/10/introducing-the-id-element.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3272197" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Kim Cameron's Proposal for a Common Identity Framework</title><link>http://blogs.technet.com/privacyimperative/archive/2009/06/08/kim-cameron-s-proposal-for-a-common-identity-framework.aspx</link><pubDate>Tue, 09 Jun 2009 01:28:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3252156</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3252156.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3252156</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3252156</wfw:comment><description>From Kim Cameron's blog : Today I am posting a new paper called, Proposal for a Common Identity Framework: A User-Centric Identity Metasystem . Good news: it doesn’t propose a new protocol! Instead, it attempts to crisply articulate the requirements in...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/06/08/kim-cameron-s-proposal-for-a-common-identity-framework.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3252156" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Information Cards in Industry Verticals</title><link>http://blogs.technet.com/privacyimperative/archive/2009/06/04/information-cards-in-industry-verticals.aspx</link><pubDate>Thu, 04 Jun 2009 18:11:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3250396</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3250396.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3250396</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3250396</wfw:comment><description>Kim Cameron,Chief Architect of Identity at Microsoft, writes on his Identity Blog : The recent European Identity Conference , hosted in Munich by the analyst firm Kuppinger Cole , had great content inspiring an ongoing stream of interesting conversations....(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/06/04/information-cards-in-industry-verticals.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3250396" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Privacy &amp; Identity Theft Conference</title><link>http://blogs.technet.com/privacyimperative/archive/2008/12/23/privacy-identity-theft-conference.aspx</link><pubDate>Tue, 23 Dec 2008 23:45:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3172734</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3172734.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3172734</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3172734</wfw:comment><description>I recently delivered a keynote address at the Privacy &amp;amp; Identity Theft Conference in Vancouver, Canada. My keynote was entitled, "The Big Picture: Defining and Redefining Identity Fraud." Below is the major portion of my keynote, along with the relevant...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2008/12/23/privacy-identity-theft-conference.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3172734" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Kim Cameron on Information Cards as a solution to site redirection</title><link>http://blogs.technet.com/privacyimperative/archive/2008/10/27/kim-cameron-on-information-cards-as-a-solution-to-site-redirection.aspx</link><pubDate>Mon, 27 Oct 2008 21:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3142688</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3142688.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3142688</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3142688</wfw:comment><description>&lt;P&gt;Kim Cameron, Chief Architect of Identity in the Connected Systems Division at Microsoft has an interesting post up about at his &lt;A href="http://www.identityblog.com/?p=1017"&gt;Laws of Identity blog on the vulnerability of passwords to "site redirection&lt;/A&gt;", a problem that Information Cards don't have:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;I&gt;The UK's &lt;A href="http://www.theregister.co.uk/"&gt;Register &lt;/A&gt;has been running a a series of articles by &lt;A href="http://search.theregister.co.uk/?author=John%20Leyden"&gt;John Leyden&lt;/A&gt;&amp;nbsp;&amp;nbsp;(&lt;A href="http://www.theregister.co.uk/2008/10/23/vbyv_analysis/"&gt;here&lt;/A&gt;, &lt;A href="http://www.theregister.co.uk/2008/08/07/verified_by_visa_compulsion"&gt;here &lt;/A&gt;and &lt;A href="http://www.theregister.co.uk/2008/10/23/vbyv_password_reset/"&gt;here&lt;/A&gt;) about &lt;A href="http://www.visaeurope.com/merchant/handlingvisapayments/cardnotpresent/verifiedbyvisa.jsp"&gt;Verified By Visa. (VByV)&amp;nbsp;&lt;/A&gt;&amp;nbsp;Verified By Visa uses the same kind of "site redirection" I've written about many times with respect to OpenID and other password-based federation technologies - but in this case it is a banking password that can be stolen.&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;The phishing scenario is simple enough.&amp;nbsp; If you happen onto an "evil" site and are tricked into purchasing something, it can "misdirect" your browser to a counterfeit VByV signon page.&amp;nbsp; As John explains, you have little chance, as a user, of knowing you are being duped, but once you enter your password it is available to the evil site for both instant use an future reuse.&amp;nbsp; Those familiar with this site will understand that this is yet another example of an attack that &lt;/I&gt;&lt;B&gt;&lt;I&gt;cannot be made against Information Card users.&lt;/I&gt;&lt;/B&gt;&lt;I&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;Beyond focusing attention on the phishing problems inherent in "site redirection" approaches,&amp;nbsp;John argues that&amp;nbsp;the system - though&amp;nbsp;claiming to be more secure - is actually&amp;nbsp;just as &lt;/I&gt;&lt;B&gt;&lt;I&gt;vulnerable&lt;/I&gt;&lt;/B&gt;&lt;I&gt; as&amp;nbsp;non-VByV mechanisms.&amp;nbsp;&amp;nbsp;He then&amp;nbsp;argues - and I have know knowledge as to whether this is&amp;nbsp;the case -&amp;nbsp;that the false claims about increased security are being used to&amp;nbsp;reject complaints by end-users about irregularities and fraudulent purchases made in their name.&amp;nbsp; If that were true, it would be scandalous.&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;Friends, this is a case of "The Writing on the Wall".&amp;nbsp; I think people in the industry should see John's work as&amp;nbsp;a sign of what's to come.&amp;nbsp; &amp;nbsp;He is the guy in the fable who is&amp;nbsp;shouting out that&amp;nbsp;"the Emperor has no&amp;nbsp;clothes!"&amp;nbsp;&amp;nbsp;And he's doing it&amp;nbsp;cogently to&amp;nbsp;the wide readership of the Register.&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;If I were an advisor to the emperor at this point&amp;nbsp;I would&amp;nbsp;insist on&amp;nbsp;two things:&amp;nbsp;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/I&gt;&lt;I&gt;admit the vulnerability of all systems based on "site redirection"; and &lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/I&gt;&lt;I&gt;start getting into phishing-resistant technologies like Information Cards while one's modesty&amp;nbsp;can still be protected. &lt;/I&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;A href="http://www.identityblog.com/?p=1017"&gt;There's more...&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3142688" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity+Theft/default.aspx">Identity Theft</category></item><item><title>Digital Playgrounds presentation at the Berkman Center</title><link>http://blogs.technet.com/privacyimperative/archive/2008/09/29/digital-playgrounds-presentation-at-the-berkman-center.aspx</link><pubDate>Mon, 29 Sep 2008 21:01:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3130028</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3130028.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3130028</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3130028</wfw:comment><description>&lt;P&gt;Last week I presented the concepts from Microsoft's paper, "&lt;A href="http://cyber.law.harvard.edu/sites/cyber.law.harvard.edu/files/Microsoft_ISTTFTAB_submission.pdf"&gt;Digital Playgrounds: Creating Safer Online Environments for Children&lt;/A&gt;," at the &lt;A href="http://cyber.law.harvard.edu/node/4635"&gt;Internet Safety Technical Task Force (ISTTF) Open Meeting&lt;/A&gt; at &lt;A href="http://cyber.law.harvard.edu/"&gt;the Berkman Center for Internet &amp;amp; Society&lt;/A&gt; in Cambridge, Mass.&lt;/P&gt;
&lt;P mce_keep="true"&gt;The Digital Playgrounds paper outlines a framework that would enable the creation of optional online "walled gardens," specifically for children and trusted adults. These online sites would only be accessible by folks with trusted and age verified ‘digital identities.' &amp;nbsp;This framework suggests achieving this by allowing trusted offline parties, who have the ability to meet with a parent and child in real life, examine the appropriate documents and then issue extremely secure digital identities based on these in in-person proofing moments. The framework we have outlined is largely a technical solution to the age verification challenge, but we believe that the nontechnical aspects of the problem will be as difficult to solve as the technical ones, if not more so. For example, government and industry will need to work together on designing the necessary criteria for in-person proofing events as well as the subsequent issuing, auditing and revoking of these digital identity cards.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;My presentation was but one of a number of presentations over the day and half long meeting. Facebook, MySpace, VeriSign, and large number of other companies provided interesting solutions of their own to similar and related online safety challenges.&lt;/P&gt;
&lt;P mce_keep="true"&gt;You can read our whole paper here: &lt;A href="http://cyber.law.harvard.edu/sites/cyber.law.harvard.edu/files/Microsoft_ISTTFTAB_submission.pdf"&gt;Digital Playgrounds: Creating Safer Online Environments for Children&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;The rest of the presentations are posted &lt;A href="http://cyber.law.harvard.edu/node/4635"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P mce_keep="true"&gt;--Jules Cohen&amp;nbsp; &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3130028" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category></item><item><title>Identity Crisis? What Crisis?</title><link>http://blogs.technet.com/privacyimperative/archive/2007/06/12/identity-crisis-what-crisis.aspx</link><pubDate>Tue, 12 Jun 2007 21:44:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1227059</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/1227059.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=1227059</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=1227059</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;Jerry Fishenden, National Technology Officer for the UK, here ...&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;&lt;IMG title="Jerry Fishenden" style="WIDTH: 65px; HEIGHT: 87px" height=87 alt="Jerry Fishenden" hspace=1 src="http://blogs.technet.com/photos/microsoft_privacy_team/images/1176559/thumb.aspx" width=65 align=left vspace=1 border=1 mce_src="http://blogs.technet.com/photos/microsoft_privacy_team/images/1176559/thumb.aspx"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;If you think the current problems of online safety and Internet e-crime (or cybercrime if you prefer) appear challenging, what on earth is going to happen when the Internet pervades every aspect of our daily lives? &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;As the Internet beings to power and monitor health and energy saving devices in our homes, enabling us to live richer, fuller lives in our own communities, will problems of cybercrime and threats to identity, security and privacy scale at the same rate: and thwart our aspirations to use technology to improve society? Will we finally reach Internet meltdown?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;Right now, it’s all too likely the answer would be – “Yes.” If we don’t get the foundations right – and address some of the most fundamental issues that currently plague Internet safety – anything else we might construct on top of its inadequate infrastructure is unlikely to be sustainable.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;But the Internet is not some autonomous, sentient, self-evolving life form – even if at times it might feel that way. It’s a by-product of decisions technologists took in the past, are taking now and will take in the future. So the problems we see today are fallout from failures in design – failures in technology design and in human-computer interaction design. And cyber-crooks are of course always amongst the quickest to exploit such flaws. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;After all, the digital world is no different to the real one – and that includes the preponderance of criminal activities based on exploiting weaknesses in both systems and people.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;One of the most obvious contributory causes to our existing Internet problems is the lack of an identity layer. I can’t prove it’s me when I’m online – and I can’t prove to a reasonable level of satisfaction whether the person or thing I’m communicating or transacting with online is who or what they claim to be. Which really isn’t a good place to be. Unless you’re a cyber-crook, in which case, hey, this is great news and highly lucrative with it since it makes online attacks such as phishing and spam email possible.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;If we’re serious about realising the Internet’s true potential we need to act now to fix the identity issues we’re seeing.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These issues need to be resolved before we can seriously contemplate letting the Internet move into far more important areas – such as technology-assisted healthcare at home and the whole idea of assisted-living. After all, how are we going to do that if none of the devices can be certain who or what they’re communicating with? In front of us lies a vision where everything and everyone is linked and joined through an all pervading system. Billions of devices and communications happening every second, a complex mesh of systems communicating within and between each other in real time.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;Now try to convince me you can build that – and trust it – without first fixing the problem of identity. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;Which raises the question: identity, what is it anyway? For the sake of the point I’m making here, identity is about people - and "things": the physical fabric of the Internet and everything in (on) it. And ultimately it’s about safeguarding our security and privacy.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;If we're to avoid exponential growth of the issues that plague the current relatively simple Internet as we enter the pervasive, complex, grid age, what principles do we adhere to? How can we have a secure, trusted, privacy-aware Internet that will be able to fulfil its potential – and have our trust too?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;The good news is that these problems are being addressed: have you heard of the "laws of identity"? The “laws” are a set of design principles evolved over the last few years by some of the most respected authorities on identity using the crucible of the blogosphere. Kim Cameron (father of meta-directories and now Chief Identity Architect at Microsoft) has gathered together these lessons into a set of powerful guidelines. They help ensure that digital systems exhibit better behaviours than today - particularly around digital identity and ensuring security and privacy. They encompass everything learned about the good and the bad of digital identity systems. Lessons learned the hard way over the last 30 years or so of real world experiences. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;And these “laws” are already beginning to gain recognition: the Information and Privacy Commissioner of Ontario for example has issued an independent public endorsement (see &lt;/FONT&gt;&lt;A href="http://www.ipc.on.ca/docs/7laws-whitepaper.pdf" mce_href="http://www.ipc.on.ca/docs/7laws-whitepaper.pdf"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;http://www.ipc.on.ca/docs/7laws-whitepaper.pdf&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt;). &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;Without the application of underlying principles such as these "laws of identity" the future Internet will suffer entropy, massive breaches of security and privacy – and probably make the scale of today’s cybercrimes look like a golden era of online law and order by comparison. But with the “laws”, we may finally be able to realise the truly transformational benefits of the Internet.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;Digital identity - of people and "things" - is a fundamental requirement of the coming pervasive Internet age. Equally clearly, we need consensus on the identity framework required before we go much further. So go and read the “laws” and see what you think: you can find them online at &lt;/FONT&gt;&lt;A href="http://www.identityblog.com/?page_id=354" mce_href="http://www.identityblog.com/?page_id=354"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;http://www.identityblog.com/?page_id=354&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt;. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN-GB&gt;&lt;FONT face=Calibri size=3&gt;And then let’s get moving on fixing these issues – before the whole idea of the benefits of the next generation of Internet developments gets a bad name and our dreams end up as just that: dreams, rather than a reality.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;EM&gt;&lt;SPAN lang=EN-GB style="FONT-FAMILY: 'Calibri','sans-serif'"&gt;&lt;FONT size=3&gt;- Jerry’s personal blog can be found at &lt;/FONT&gt;&lt;A href="http://ntouk.com/" mce_href="http://ntouk.com/"&gt;&lt;SPAN style="COLOR: windowtext; TEXT-DECORATION: none; text-underline: none"&gt;&lt;FONT size=3&gt;http://ntouk.com&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt; &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1227059" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity/default.aspx">Identity</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Identity+Theft/default.aspx">Identity Theft</category></item></channel></rss>