{"id":528,"date":"2006-08-13T04:59:27","date_gmt":"2006-08-13T12:59:27","guid":{"rendered":"\/?p=528"},"modified":"2006-08-14T23:36:49","modified_gmt":"2006-08-15T07:36:49","slug":"528","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=528","title":{"rendered":"Anonymity is the substrate"},"content":{"rendered":"<p>Ben Laurie at Links, contemplating the&nbsp;&#8220;identity as a default&#8221; debate, argues &#8220;<a href=\"http:\/\/www.links.org\/?p=123\">Anonymity is the substrate<\/a>&#8220;:<\/p>\n<blockquote><p><a href=\"\/?p=525\"><font color=\"#003399\">Kim Cameron\u00e2\u20ac\u2122s blog<\/font><\/a> draws my attention to a couple of articles on anonymity. <a href=\"http:\/\/www.strumpette.com\/archives\/162-Cluetrain-author-dispels-absolute-transparency-myth.html\" class=\"broken_link\"><font color=\"#003399\">The first<\/font><\/a> argues for anonymity to be the default. <a href=\"http:\/\/blogs.zdnet.com\/digitalID\/?p=60\" class=\"broken_link\"><font color=\"#003399\">The second<\/font><\/a> misses the point and claims that wanting anonymity to be the default makes it a binary thing, whereas identity is a spectrum.<\/p>\n<p>But the point is this: unless you have anonymity as your default state, you don\u00e2\u20ac\u2122t get to choose where on that spectrum you lie.<\/p>\n<p>Eric Norlin says<\/p>\n<div style=\"margin-left: 20px\">Further, every \u00e2\u20ac\u0153user-centric\u00e2\u20ac\u009d system I know of doesn\u00e2\u20ac\u2122t seek to make \u00e2\u20ac\u0153identity\u00e2\u20ac\u009d a default, so much as it seeks to make \u00e2\u20ac\u0153choice\u00e2\u20ac\u009d (including the choice of anonymity) a default.<\/div>\n<p>as if identity management systems were the only way you are identified and tracked on the \u00e2\u20ac\u02dcnet. But that\u00e2\u20ac\u2122s the problem: the choices we make for identity management don\u00e2\u20ac\u2122t control what information is gathered about us unless we are completely anonymous apart from what we choose to reveal.<\/p>\n<p>Unless anonymity is the substrate choice in identity management gets us nowhere. This is why I am not happy with <em>any<\/em> existing identity management proposal &#8211; none of them even attempt to give you anonymity as the substrate.<\/p><\/blockquote>\n<p>Ben has a valid point in terms of the&nbsp;network substrate.&nbsp; There are a number of hard issues intertwined here.&nbsp; But from a practical point of view, here is how I approach it:<\/p>\n<ol>\n<li>You can&#39;t solve every problem everywhere simultaneously.&nbsp;&nbsp;Solving one problem may leave others to be dealt with.&nbsp; But&nbsp;with one problem gone, the others are easier to tackle.<\/li>\n<li>There are interesting technologies like <a href=\"http:\/\/www.onion-router.net\/\">onion routing<\/a> and <a href=\"http:\/\/tor.freehaven.net\/\" class=\"broken_link\">tor<\/a> that could be combined with the evolving identity framework to offer a more secure overall solution (Ben is&nbsp;better versed in these matters than I am).<\/li>\n<li>If society mandates storage of network addresses under certain circumstances, as it seems to be doing, a much&nbsp;more secure&nbsp;approach to&nbsp;this storage could and should be adopted.&nbsp;&nbsp;Any legislation that calls for auditing should also require&nbsp;that&nbsp;the audit trail&nbsp;be encrypted under keys available only to vetted authorities and then only through well-defined legal procedures with public notification and in an off-line setting.&nbsp; This would have a huge impact in preventing the ravages of <a href=\"\/?p=525\">Norlin&#39;s Maxim<\/a>.<\/li>\n<\/ol>\n<p>Network issues aside, in keeping with the second law of identity (minimal disclosure), users should by default release&nbsp;NO identifying information at all.&nbsp;<\/p>\n<p>You can call this anonymity, or you can call this &#8220;not needlessly blabbing everything about yourself&#8221;.&nbsp;<\/p>\n<p>Sites should only ask for identifying information when there is some valid and defensible reason to do so.&nbsp; They&nbsp;should always ask for the minimum possible.&nbsp; They should&nbsp;keep it for the shortest possible time.&nbsp; They should encrypt it&nbsp;so it is only available to&nbsp;systems that&nbsp;must access it.&nbsp; They should ensure as few parties as possible have access to&nbsp;such systems.&nbsp; And if possible, they should only allow it to be decrypted on systems not connected to the internet.&nbsp; Finally, they should audit their conformance with these best practices.<\/p>\n<p>Once you accept&nbsp;that release of identifying information should be proportionate to well-defined needs &#8211; and that such needs vary according to context &#8211; it&nbsp;follows that identity <strong>must<\/strong> &#8220;be a spectrum&#8221;.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In keeping with the second law of identity (minimal disclosure), users should by default release NO identifying information at all<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,3,11],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/528"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=528"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/528\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}