{"id":790,"date":"2007-05-31T21:11:59","date_gmt":"2007-06-01T05:11:59","guid":{"rendered":"\/?p=790"},"modified":"2007-05-31T21:23:00","modified_gmt":"2007-06-01T05:23:00","slug":"nick-shelness-on-cardspace","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=790","title":{"rendered":"Nick Shelness on CardSpace"},"content":{"rendered":"<p>The strangest thing just happened.&nbsp;&nbsp;I was following a link that&nbsp;had just appeared from <a href=\"http:\/\/vowe.net\">vowe.net&nbsp;<\/a>&nbsp;&#8211; a site published by <a href=\"http:\/\/vowe.net\/about.php\" class=\"broken_link\">Volker Webe<\/a>.&nbsp; An interesting site, for sure &#8211;&nbsp;and on it, I&nbsp;read <a href=\"http:\/\/vowe.net\/archives\/008479.html\">this piece <\/a>by <a target=\"_blank\" href=\"http:\/\/www.linkedin.com\/in\/nickshelness\">Nick Shelness<\/a>:&nbsp;&nbsp;<\/p>\n<blockquote><p>Establishing identity and authenticating on the web are a mess. I doubt I\u00e2\u20ac\u2122m alone in using the same user id and password over and over again. If they\u00e2\u20ac\u2122re hacked once they can be employed a hundred times over. Yeah, some sites make you change your password at regular intervals, but how do you remember them? I write them down, and carry them with me. OK, they\u00e2\u20ac\u2122re somewhat encoded, but &#8230;<\/p>\n<p>For some time now, there has been the possibility of improvement under the \u00e2\u20ac\u0153Identity 2.0\u00e2\u20ac\u009d banner. To the surprise of some (many?), a significant chunk of Identity 2.0 innovation has come from Microsoft, and no, no, no, it\u00e2\u20ac\u2122s not \u00e2\u20ac\u0153Passport\u00e2\u20ac\u009d. It is expressed in two seminal papers: <a href=\"\/?p=354\" title=\"The Laws of Identity\">The Laws of Identity <\/a>and <a href=\"\/?p=355\" title=\"The Identity Metasystem\">The Identity Metasystem<\/a>, both by <a href=\"\/?p=360\" title=\"Kim Cameron\">Kim Cameron<\/a>.<\/p>\n<p>But this is not all. There is a Microsoft product. It\u00e2\u20ac\u2122s called \u00e2\u20ac\u0153<a href=\"http:\/\/msdn2.microsoft.com\/en-us\/library\/aa480189.aspx\" title=\"Introducing Windows CardSpace\">CardSpace<\/a>\u00e2\u20ac\u009d (it used to be called \u00e2\u20ac\u0153Info Card\u00e2\u20ac\u009d). It ships as part of Vista. It also ships as an automatic XP upgrade, and there are a host of alternatives, including open source ones.<\/p>\n<p>CardSpace and its analogues, on their own, are not a solution. They are a component, albeit a key one, of an Identity Metasystem. What needs to come next is for web sites (\u00e2\u20ac\u0153Relying Parties\u00e2\u20ac\u009d) to start requesting and employing CardSpace-managed security assertions. This in turn will create a demand for Identity Provision (yes, this is where ActiveDirectory and son of Passport come in).<\/p>\n<p>Will this happen? It\u00e2\u20ac\u2122s too early to say. But by seeding the digital world with CardSpace, Kim and Microsoft have taken us a long first step down this path, and IMHO done us all a big favor.<\/p><\/blockquote>\n<p>It took me a minute to click in to the name Nick Shelness.&nbsp; He is&nbsp;a&nbsp;great visionary &#8211;&nbsp;CTO at Lotus and later an IBM fellow (now with his own practice in the UK).&nbsp; His support means a lot to me.&nbsp;<\/p>\n<p>As for&nbsp;his &#8220;will it happen?&#8221; question,&nbsp;I&#39;ve asked&nbsp;it too on a hundred &#8216;bleak and dreary days&#8217;.&nbsp; But I continue to think there are historical inevitabilities at work here.&nbsp;&nbsp;<\/p>\n<p>Distributed computing is dammed up behind a wall of identity friction.&nbsp;&nbsp;The one good thing about the friction is that it&nbsp;limits phishing and&nbsp;cyber crime as much as it&nbsp;limits business.&nbsp; Remove the friction with something like single sign-on and you massively increase the attraction of the digital honeypot, providing a one-stop attack surface for evil.&nbsp; The more consolidated&nbsp;identity initiatives succeed, the more they&nbsp;will fail &#8211; unless there is a paradigm change like&nbsp;CardSpace that compensates for risk aggregation.&nbsp;&nbsp;<\/p>\n<p>Few&nbsp;may understand these dynamics through theory alone, but Professor Reality will come to tutor them before too long.&nbsp; Meanwhile, there are more and more people with enough vision that they don&#39;t have to &#8220;go over Niagra Falls in a barrel to know it hurts.&#8221;&nbsp;<\/p>\n<p>Day after day, week after week, month after month, CardSpace &#8220;sockets&#8221; are appearing on desktops.&nbsp; One day&nbsp;&#8211;&nbsp;not too far into the future &#8211;&nbsp;it will&nbsp;be present on&nbsp;50% of them.&nbsp; Then on 75%!&nbsp; Meanwhile the software will get slicker and slicker,&nbsp;with multiple versions and choices by people like our friends at Higgins running on&nbsp;Mac and Linux.&nbsp; This is a historic thing we are doing together, and we&nbsp;can&#39;t be&nbsp;impatient.&nbsp; But this baby is going to light up big time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It took me a minute to click in to the name Nick Shelness.  He is a great visionary &#8211; CTO at Lotus and an IBM fellow<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[16,24,8,15,3],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/790"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=790"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/790\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}