{"id":1166,"date":"2011-02-22T13:08:55","date_gmt":"2011-02-22T21:08:55","guid":{"rendered":"\/?p=1166"},"modified":"2011-02-27T09:56:54","modified_gmt":"2011-02-27T17:56:54","slug":"a-change-in-user-behavior","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=1166","title":{"rendered":"A &#8220;change in user behavior&#8221;"},"content":{"rendered":"<p>Farhang Kassaei is lead architect for platform and systems at eBay Inc and blogs at <a href=\"http:\/\/softwareforallseasons.blogspot.com\/\">Software For All Seasons<\/a>.\u00a0 He <a href=\"http:\/\/softwareforallseasons.blogspot.com\/2011\/02\/it-is-finally-official-end-of-msft.html\">makes\u00a0a great point\u00a0<\/a>about\u00a0one key factor\u00a0that blocked CardSpace deployment:<\/p>\n<p style=\"padding-left: 30px;\">Having worked on a authentication concept with MSFT for eBay sellers, I had mixed feelings about this [Microsoft&#39;s decision not to ship CardSpace 2.0 &#8211; Kim]. On one hand I was on the record <strong>not<\/strong> supporting the use of CardSpace for eBay sellers (or buyer). On the other hand I am concerned that technical community discounts the significance of Claim Based identity altogether and concludes that &#8220;FaceBook Conncet&#8221; is all we&#39;ll ever need.<\/p>\n<p style=\"padding-left: 30px;\">There is a good reflection (from an insider&#39;s point of view) on Card Space <a href=\"http:\/\/self-issued.info\/?p=458\"><span style=\"color: #004b91;\">here.<\/span><\/a> (courtesy <a href=\"http:\/\/1raindrop.typepad.com\/\" class=\"broken_link\"><span style=\"color: #004b91;\">Gunnar Peterson<\/span><\/a>)\u00a0\u00a0 My personal view (and the reason I didn&#39;t support the adoption of Card Space at eBay) though centers around the challenges of &#8220;Change of Behavior&#8221; required by Card Space.<\/p>\n<p style=\"padding-left: 30px;\">Basically, CardSpace failed b\/c it requied uses to change their behavior. See, the &#8220;User name and password&#8221; protocol (a simple challenge and response) IS a protocol, one where a human being (a normal user) is a participant in. It has taken about 20-30 years (depending on how you count) to train users what to do when they see a &#8220;login panel&#8221; , the &#8220;login panel&#8221; contract is so widely understood that despite all of its short coming is the most viable remote authentication protocol we have today. It is flawed, it is costly, it is not secure, but it is a widely understood by users on the other end of the protocol. CardSpace, despite all its advantages, was not understood, would (and did) make people confused, they did not know what to do when the CardSpace screen popped up &#8230; a technology whose adoption depends on change of a strongly learned behavior is unlikely to succeed (or at least I didn&#39;t think eBay sellers &#8211; not the early adopters of technology &#8211; would learn and accept it).<\/p>\n<p style=\"padding-left: 30px;\">It also didn&#39;t help that a lot of browsers didn&#39;t support it (installing a plug-in does not count), and the fact that developers didn&#39;t know how to issue cards (or validate, update or revoke them).<\/p>\n<p style=\"padding-left: 30px;\">Having said that, I did like the idea of decentralized identity provider and not having any one identity provider to be THE identity provider that everyone else had to rely on (putting user in control of their own identity). Compare this with a world where one identity provider (be it facebook or Google or twitter or anyone else) is the dominant identity provider because it is easy for RPs to embed a simple button\u00a0 and for users to click on it.<\/p>\n<p>Reading Farhang&#39;s post, here&#39;s what I find most interesting.\u00a0 It was never that users decided they didn&#39;t want\u00a0&#8220;a change of behavior&#8221;\u00a0around passwords.\u00a0 Instead it was web properties like eBay (and a thousand others) who\u00a0came to this conclusion.\u00a0\u00a0Many of the people designing those properties worried\u00a0that\u00a0providing users <em>the option<\/em> of changing their behavior was too dangerous &#8211; especially since it was not essential&#8230;\u00a0<\/p>\n<p>In the history of computing there have actually\u00a0been plenty of cases where users DID change their behavior &#8211; even though at first only a few people could understand or use the new alternatives.\u00a0 But those &#8220;early adopters&#8221;\u00a0were able to\u00a0try\u00a0the new inventions\u00a0<em>on their own.<\/em>\u00a0 They didn&#39;t need anyone else to approve something or decide they would like it first.\u00a0 Once convinced, they could show\u00a0the new\u00a0ideas\u00a0to others.<\/p>\n<p>When\u00a0Visicalc appeared, I don&#39;t know how many people in IT would have bet that every accountant in the world would soon be throwing out his pencils and starting to\u00a0use spreadsheets for things no one can even now\u00a0believe\u00a0are possible!\u00a0\u00a0The same is true\u00a0for a thousand other\u00a0applications\u00a0people came to love.\u00a0<\/p>\n<p>But because authentication doesn&#39;t stand on its own, users\u00a0never got\u00a0the chance\u00a0to start using Information Cards &#8220;just because they felt like it&#8221;.\u00a0 They needed web sites to make\u00a0the same bet they did\u00a0by implementing Information Card support\u00a0as an option.\u00a0\u00a0<\/p>\n<p>Web sites didn&#39;t want to bet.\u00a0 They wanted to keep to &#8220;the matter at hand&#8221; and prevent their users from getting lost or distracted.\u00a0\u00a0The result:\u00a0a preemptive chill settled over the technology, and we never really got to see what users would make of it.<\/p>\n<p>My conclusion:\u00a0\u00a0regardless of what new features they support, user centric identity solutions need to be built so they work with as many existing\u00a0web sites\u00a0as possible.\u00a0\u00a0They can&#39;t require\u00a0buy-in from\u00a0the all the big web sites\u00a0in order to be useful.\u00a0<\/p>\n<p>I think we should have included a way for Information Cards to support password-based sites.\u00a0 It was possible.\u00a0 I personally avoided it because I was worried it would be unreliable and not work at all sites.<\/p>\n<p>Yet a\u00a0lot of password managers do this, and <a href=\"http:\/\/dickhardt.org\" class=\"broken_link\">Dick Hardt&#39;s SXIP system\u00a0<\/a>combined this approach with support for new protocols.\u00a0 I think\u00a0that aspect of his work was probably right.<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Regardless of what new features they support, future user centric identity solutions need to be built so they work with existing web sites too.<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[16,7,41],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1166"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1166"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1166\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}