State of the market or chance to get things right?

Posted on Monday 15 January 2007

Eric Norlin of Digital Identity World comments on my concerns (note:  concerns are not allegations) about the need for client-side anti-spoofing components: 

Every now and then a technical disagreement betrays the state of a marketplace. That phenomenon is currently happening in the user-centric identity trenches.

The players are Kim Cameron (InfoCards/CardSpace) of Microsoft on one side and Dick Hardt (OpenID) of Sxip Identity on the other.  The issue: Kim’s recent allegations that OpenID will make identity *less* secure and possibly result in security breaches that will set the user-centric identity work back in the minds of users.

The debate highlights where we are with user-centric identity.

The technical details all focus around the need (or lack of need) for client-side identity selectors with Kim arguing that its necessary to prevent spoofing, and Dick arguing that the spoofing security threat is acknowledged and defensible via OpenID. But the technical details (and argument) are not the most interesting thing.

Arguments like this, as all engineers know, are common in the world of the engineering. The reason is simple: the “engineer’s mind” (versus the “marketer’s mind”) naturally seeks the “perfect solution.” That’s the blessing of the engineer’s mind. It is, of course, also the curse.

As any student of technology history knows, the “perfect solution” has rarely won the battle of the marketplace. Instead, the solution that solved the problem set using “the principle of good enough”, and *also* attained a critical mass of adoption has won. Does that result in further problems to be solved? Of course it does! That, my friends, is the cycle of innovation.

The current debate between Kim and Dick actually serves to show us where the user-centric identity market actually is. Several years ago, two groups were competing around federation standards (the Liberty Alliance and Microsoft/IBM’s WS-* standards). For what seemed like forever, they held obscure debates about the details of the standards. Eventually, the market moved forward (seemingly without either group’s help), and now today we find ourselves witnessing a new Liberty Alliance President saying that the “gloves are off” and they’d like to find ways to converge with the WS-* standards.

That simple, recent analogy shows us where we are with user-centric identity. We’re on the verge of the market beginning to really adopt some technology. These conversations don’t reach this level unless those involved see this potential.

In the meantime, the engineers will continue to debate the details, and that’s good for all of us.

I want people to understand I’m not against OpenID, and I don’t see this as something that should turn into a war, marketing or other.  We should do everything we can to make OpenID as secure as possible, and that includes integrating it with InfoCards wherever this is possible.

 

 


4 Comments for 'State of the market or chance to get things right?'

  1.  
    January 17, 2007 | 3:08 pm
     

    Identity Management and CardSpace…

    Identity Management is not one of my priorities , but it’s a subject I’ve been interested about for sometime,…

  2.  
    January 18, 2007 | 6:46 am
     

    [...] Recently a discussion between&nbspKim Cameron&nbsp(InfoCards/CardSpace) and Dick Hardt (OpenID) has focussed on the relative anti-phishing merits of Infocards and OpenID. It seems pretty clear that actually neither identity management system&nbsphas any&nbspanti-phishing merit without the use of a client-side log on agent. [...]

  3.  
    January 20, 2007 | 12:17 pm
     

    [...] Kim Cameron sets the record straight: State of the market or chance to get things right? And he has nothing against OpenID.&nbsp But Kin is the god head and groks this shit better than any of us&nbsp- so please listen to him!&nbsp ID is a hell of a lot more than SSO or authentication and if we’re to stop phishing, and spoofing and ID theft - we need severe crypto, locked down, secure ID systems. [...]

  4.  
    January 20, 2007 | 3:45 pm
     

    [...] Someone just pointed out this super strong message&nbspfrom the Energy Field that is Marc Canter: Kim Cameron sets the record straight: State of the market or chance to get things right?&nbsp And he has nothing against OpenID.&nbsp But Kim is the god head and groks this shit better than any of us&nbsp- so please listen to him!&nbsp ID is a hell of a lot more than SSO or authentication and if we’re to stop phishing, and spoofing and ID theft - we need severe crypto, locked down, secure ID systems. [...]

Leave a comment