{"id":530,"date":"2006-08-14T21:13:46","date_gmt":"2006-08-15T05:13:46","guid":{"rendered":"\/?p=530"},"modified":"2006-08-14T22:51:56","modified_gmt":"2006-08-15T06:51:56","slug":"dave-kearns-takes-on-anonymity","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=530","title":{"rendered":"Dave Kearns takes on anonymity"},"content":{"rendered":"<p>&nbsp;Dave Kearns of <a href=\"http:\/\/vquill.com\/\">The Virtual Quill<\/a> (and many other venues) has <a href=\"http:\/\/vquill.com\/2006\/08\/more-on-privacy-vs-anonymity.html\" class=\"broken_link\">joined<\/a> the anonymity scrum (even though he was <a href=\"http:\/\/vquill.com\/2006\/08\/anonymity-identity-and-privacy.html\" class=\"broken_link\">already in it<\/a>)&nbsp;:<\/p>\n<blockquote><p>&#8220;Anonymity as default,&#8221; which I mentioned in the previous post, is taking on a life of it&#39;s own. Now Tom Maddox has <a href=\"http:\/\/blog.opinity.com\/2006\/08\/ben_laurie_on_a.html\" class=\"broken_link\"><font color=\"#0069c3\">posted<\/font><\/a> in his Opinity weblog, commenting on Ben Laurie&#39;s <a href=\"http:\/\/www.links.org\/?p=123\"><font color=\"#0069c3\">commentary<\/font><\/a> about Kim Cameron&#39;s <a href=\"\/?p=525\"><font color=\"#0069c3\">mention<\/font><\/a> of Eric Norlin&#39;s <a href=\"http:\/\/blogs.zdnet.com\/digitalID\/?p=60\" class=\"broken_link\"><font color=\"#0069c3\">post<\/font><\/a> concerning David Weinberger&#39;s original <a href=\"http:\/\/www.strumpette.com\/archives\/162-Cluetrain-author-dispels-absolute-transparency-myth.html\" class=\"broken_link\"><font color=\"#0069c3\">thought<\/font><\/a> that &#8220;Anonymity should be the default.&#8221;<\/p>\n<p>(I&#39;ll just sit here and whistle for a moment while you follow that set of links)<\/p>\n<p>The point I wanted to mention was Maddox&#8217; statement:<\/p>\n<div style=\"margin-left: 20px\">&#8220;<span style=\"font-style: italic\">We need to begin with anonymity\/pseudonymity as the default, Laurie&#39;s &#8216;substrate choice&#8217;. Otherwise, whatever identity system we employ, we&#39;ll always be trying to get the cat back in the bag (or the scrambled egg back in the shell)<\/span>&#8220;<\/div>\n<p>The fallacy here is that he seems to believe that there can be an &#8220;identity system&#8221; in which anonymity is a choice! And not only a choice, but the default choice. But without a unique identifier for each object in the system, there is no identity system. And with a unique identifier there is no anonymity <span style=\"font-weight: bold\">within the system<\/span>. Rather, the default should be PRIVACY for all objects, with any dispersal or publishing of identity attributes only done with the consent of the entity if it&#39;s sentient, and the entity&#39;s controller if it isn&#39;t.<\/p>\n<p>Maddox is correct that once the data is published you can&#39;t unpublish it completely. That argument shouldn&#39;t be overlooked. But it&#39;s equally as important to realize that the &#8220;anonymity bandwagon&#8221; is out of control and headed for the cliff. Privacy is the key, and privacy should be the issue.<\/p><\/blockquote>\n<p>I have trouble with Dave&#39;s use of the phrase, &#8220;within the system&#8221;.&nbsp; What is &#8220;the system&#8221; in a multi-centered world with an interpenetrating mesh of domains?&nbsp; Put another way, just because an object&nbsp;has a unique identifier, do entities dealing with the object have to know that?<\/p>\n<p>Things may have unique identifiers that are known to some&nbsp;identity authority \/ domain&nbsp;(even infinitesimilly small ones)&nbsp;but&nbsp;these authorities&nbsp;don&#39;t <em>have to release them <\/em>when identifying things to other parties.&nbsp;<\/p>\n<p>Would&nbsp;an example help?&nbsp;<\/p>\n<p>Suppose some company &#8211; let&#39;s call it Contoso.com &#8211; runs Active Directory as its local identity infrastructure.&nbsp; Active Directory identifies all of&nbsp;the machines and people in&nbsp;Contoso&#39;s &#8220;domain&#8221; with a Security&nbsp;IDentifier (SID) &#8211; basically a&nbsp;unique id\/domain pair.&nbsp; But when I am&nbsp;<strong>dealing<\/strong> with someone from Contoso.com, I probably don&#39;t give a darn about their&nbsp;SID, no matter how&nbsp;useful it may be to their local AD system.&nbsp; Dave, do you care about my SID? Knowing you and loving you, I think you&#39;ve got better things to worry about!<\/p>\n<p>In the world of web services,&nbsp;which will be a vast mesh where identity reaches beyond domain boundaries, the definition of what is &#8220;within the system&#8221; becomes very ambiguous.&nbsp;<\/p>\n<p>The SID makes sense &#8220;within the system&#8221; thought of a narrow domain manager.&nbsp; It&nbsp;normally doesn&#39;t make sense &#8220;within the system&#8221; thought of as a connecting mesh of entities that happen to&nbsp;interact with many&nbsp;domains.&nbsp;<\/p>\n<p>In this bigger world, I may be interested in the fact that someone is an employee of Contoso, byt totally uninterested in anything that uniquely identifiers them as an&nbsp;employee &#8211; even if such unique identification is necessary for some other purpose.<\/p>\n<p>For example, if I call 411, I speak with a representative of the phone company.&nbsp; I don&#39;t know her or his name, or number, or location, or anything else.&nbsp; I just know&nbsp;the person I&#39;m talking with works&nbsp;on behalf&nbsp;of Verizon &#8211; and that is all I really <em>want<\/em> to know.<\/p>\n<p>Yet&nbsp;knowing they are an official employee is still a matter of&nbsp;identity!&nbsp;<\/p>\n<p>Is this anonymous?&nbsp; I would say so.&nbsp; It &#8220;has an unknown or unacknowledged name&#8221;, as my pathetic online dictionary puts it (I&#39;m travelling).&nbsp; So it is anonymous, but it is identity.<\/p>\n<p>This is all part of the notion that an authority can make&nbsp;claims about&nbsp;a subject &#8211; and that this is done through a set of assertions.&nbsp;&nbsp;Given this,&nbsp;we need a name for the &#8220;empty set&#8221; of&nbsp;assertions.&nbsp;<\/p>\n<p>So far,&nbsp;we call it&nbsp;anonymity.&nbsp; We believe this will ring a bell in more peoples&#8217; heads than &#8220;empty set of assertions&#8221;.<\/p>\n<p>If we now combine this thinking with the second law (minimal disclosure) &#8211; we come to the notion that if more is not needed, the identity set should be the empty set.&nbsp; This is what I think people are talking about when they say the default should be anonymous.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is &#8220;the system&#8221; in a multi-centered world with an interpenetrating mesh of domains?<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[6,10,3,11],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/530"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=530"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/530\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}