{"id":707,"date":"2007-03-06T00:33:25","date_gmt":"2007-03-06T08:33:25","guid":{"rendered":"\/?p=707"},"modified":"2007-03-06T07:55:44","modified_gmt":"2007-03-06T15:55:44","slug":"services-should-use-their-own-credentials-not-mine","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=707","title":{"rendered":"Services should use their own credentials, not mine"},"content":{"rendered":"<p>Dave Kearns, who is&nbsp;usually not without wisdom, <a href=\"http:\/\/vquill.com\/2007\/03\/eve-1-kim-0.html\" class=\"broken_link\">takes on <\/a>my &#8220;bold and forceful&#8221; assertion:&nbsp;<\/p>\n<blockquote><p>Aided by <a href=\"http:\/\/jkobielus.blogspot.com\/2007\/03\/rfi-user-centric-identity-and-what-eve.html\"><font color=\"#0069c3\">Jim Kobielus<\/font><\/a>, <a href=\"\/?p=701\"><font color=\"#0069c3\">Kim Cameron<\/font><\/a> and <a href=\"hhttp:\/\/www.xmlgrrl.com\/blog\/archives\/2007\/03\/02\/identity-jim-kobielus-and-coffee\/\"><font color=\"#0069c3\">Eve Maler<\/font><\/a> are having a snit. Well, Eve&#39;s taking potshots at CardSpace and Kim&#39;s defending his baby&#8230;.<\/p>\n<p>As part of the exchange, Cameron states categorically: &#8220;<em>No one and no service should ever act in a peron\u00e2\u20ac\u2122s [sic] identity or employ their credentials when they\u00e2\u20ac\u2122re not present.<\/em> Ever.&#8221; Bold and forceful, certainly. But also as wrong as wrong can be.<\/p>\n<p>We all (even Kim) often ask services to do things on our behalf &#8211; and don&#39;t sit around watching to be sure they do it! The most obvious example is my email inbox &#8211; it patiently logs in (as me) to multiple servers periodically 24 hours a day, seven days a week, 52 weeks a year. From time to time I visit the inbox to see what&#39;s there, but no way can I be said to be &#8220;present&#8221; at all times it&#39;s acting for me.<\/p><\/blockquote>\n<p>Dave is missing the point &#8211; maybe I wasn&#39;t clear enough.&nbsp;<\/p>\n<p>I&#39;m not saying you have to &#8220;stand around and watch&#8221; while your&nbsp;mail client picks up your mail.&nbsp; I&#39;m saying your mail client should identify itself as a particular instance of a mail client, and present an authorization from you allowing it to pick up your mail.&nbsp;<\/p>\n<p><strong>They&#39;re all ME<\/strong>&nbsp;<\/p>\n<p>If you share identity (even, in some cases, secrets and credentials) the way Dave is proposing, &nbsp;<em>we don&#39;t know what process is accessing what resource<\/em> because all the the services I run are ME.&nbsp;<\/p>\n<p>That&#39;s really the computing model we have had until now.&nbsp; Where has it led?&nbsp; Well, for example, my email client is ME, and a trojan on my desktop is ME,&nbsp; and&nbsp;the resources they access can&#39;t tell the difference, because they&#39;re all ME.<\/p>\n<p>So any trojan that gets into my environment can get my email addresses and send worms to my friends, or pick up my mail and feed it to spam machines.&nbsp; My mail server&nbsp;and other resources&nbsp;don&#39;t know the diffference.<\/p>\n<p><strong>Things don&#39;t have to be this way<\/strong><\/p>\n<p>We can instead build systems where&nbsp;my mail client will identify itself as my email client (e.g. be iteself), and present an authorization token from me&nbsp;saying it can&nbsp;pick up my mail.&nbsp;&nbsp;<\/p>\n<p>On&nbsp;such a&nbsp;system,&nbsp;my trojan&nbsp;will have&nbsp;to&nbsp;identify itself as &#8220;trojan&#8221;, and&nbsp;will thus&nbsp;have no authorization coupon to present at all!&nbsp; It is harder to build systems that behave this way, but given what we now understand, it is doable.&nbsp; Wouldn&#39;t we want actual auditability and proper factoring?<\/p>\n<p>That&#39;s why I say:<\/p>\n<blockquote><p>&#8220;<em>No one and no service should ever act in a peron\u00e2\u20ac\u2122s identity or employ their credentials when they\u00e2\u20ac\u2122re not present.<\/em> Ever.&#8221;<\/p><\/blockquote>\n<p>The&nbsp;approach&nbsp;Dave describes was fine when we all lived in the Garden of Eden.&nbsp; But we&#39;ve been&nbsp;sent out of it into the grown-up world of virtual reality, where there are evil processes as well as good ones, and we need to be able to distinguish one from the other.&nbsp; This metaphor&nbsp;&#8211; and&nbsp;the whole discussion &#8211; doesn&#39;t come from a &#8220;snit with Eve&#8221;&#8230;&nbsp;&nbsp;It results from&nbsp;the vulnerabilities of&nbsp;the current generation of software and distributed architecture &#8211; regardless of platform &#8211; and&nbsp;a desire&nbsp;to make sure we don&#39;t repeat the same mistakes going forward.&nbsp;&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Services and processes should have their own identities, and we should be able to delegate to them.  This doesn&#39;t mean we have to stand around and watch<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[12,6,23,5],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/707"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=707"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/707\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}