{"id":866,"date":"2007-10-04T01:09:33","date_gmt":"2007-10-04T09:09:33","guid":{"rendered":"\/?p=866"},"modified":"2007-11-28T09:08:58","modified_gmt":"2007-11-28T17:08:58","slug":"what-if-we-fail","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=866","title":{"rendered":"What if we fail?"},"content":{"rendered":"<p>As innovators we need to think about what happens if our systems fail.\u00a0 I&#39;ve argued, for example, that the starting point for designing a secure system is to recognize it will be breached.<\/p>\n<p>So I took Ben Laurie&#39;s <a href=\"http:\/\/www.links.org\/?p=258\">recent piece on CardSpace <\/a>as an invitation to review one more time what can go wrong with Information Cards and CardSpace.\u00a0<\/p>\n<p>For those who don&#39;t know him, Ben has been a leading innovator in terms of open source SSL, and currently works at Google.\u00a0 In his piece he writes that OpenID isn&#39;t gaining much traction.\u00a0 Then he turns to CardSpace, which he says &#8220;appears to be supported only by Microsoft products.&#8221;<\/p>\n<p>A number of people gagged on this, including <a href=\"http:\/\/virtualsoul.org\/blog\/2007\/09\/28\/100-open-source-information-cards-and-how-ben-might-win-an-iphone\/\">Dale Olds of Novell <\/a>(who none the less retained his unflappable charm).\u00a0 Dale had just released his new <a href=\"https:\/\/cards.bandit-project.org\/BanditIdP\/index.jsp\">DigitalMe product <\/a>providing <a href=\"http:\/\/www.bandit-project.org\/index.php\/Digital_Me_Download\">Information Card support for Mac <\/a>and Linux.\u00a0 In fact, at Digital ID World, the open source Bandit Project had launched a \u00e2\u20ac\u0153<a href=\"http:\/\/www.novell.com\/news\/press\/novell-led-bandit-project-launches-control-your-identity-campaign\">Control Your Identity\u00e2\u20ac\u009d campaign<\/a> to promote awareness and use of information card technology. Hmmm.\u00a0 I wonder if Linux is a Microsoft product?\u00a0<br \/>\n<!--more--><br \/>\nDale ended his response to Ben by saying, &#8220;Ben, please check it out. You might win an iPhone. You can use information cards to access the site, or even deploy your own identity provider or consumer using 100% open source software.&#8221;\u00a0<\/p>\n<p>That phone might actually be a good idea because Ben could stay in closer touch with all the people working on information cards&#8230;\u00a0 But hey &#8211; let&#39;s give credit where it&#39;s due:\u00a0 the next thing Ben did was to roll up his sleeves and start to compile his own BSD version of Digital Me.\u00a0 Cool.\u00a0\u00a0 He <a href=\"http:\/\/www.links.org\/?p=261\">writes about it here<\/a>.<\/p>\n<p>Analyst Neil Macehiter <a href=\"http:\/\/www.mwdadvisors.com\/blog\/2007\/09\/has-cardspace-become-passport.html\" class=\"broken_link\">gets into the fray <\/a>by pointing out the obvious:\u00a0 current rates of uptake for OpenID and CardSpace are &#8220;to be expected given that we are still in the early stages of both.&#8221;\u00a0<\/p>\n<p>After all, where do you get your relying party and identity provider software?\u00a0 At the corner store?\u00a0 <a href=\"\/?p=865\">Even the CardSpace <\/a>team finds itself on a Microsoft blog where, although it&#39;s definitely part of the plan, Information Card support hasn&#39;t been released yet.\u00a0 Windows Live ID&#39;s beta is still bleeding edge.<\/p>\n<p>The strangest part of Ben&#39;s post is a speculative paragraph worrying that if no one but Microsoft adopts CardSpace, and if people just use CardSpace to connect to Microsoft,\u00a0 then it will be no better than Passport.\u00a0<\/p>\n<p>Beyond being convoluted, the premise is all wrong.\u00a0 The original Passport was aimed at employing a single identity across many different sites.\u00a0 This problem simply doesn&#39;t arise in Ben&#39;s failure scenario,\u00a0the scenario in which only one site has adopted the technology.\u00a0\u00a0 If there are multiple sites, Ben&#39;s failure premise goes away&#8230; (There are good reader comments explaining all this <a href=\"http:\/\/virtualsoul.org\/blog\/2007\/09\/28\/100-open-source-information-cards-and-how-ben-might-win-an-iphone\/\">here<\/a>).<\/p>\n<p>The bottom line:\u00a0 if CardSpace were to be used only at one site, it would still be no worse than Google or Yahoo or Live ID &#8211; or any other system that is only used at one site.\u00a0 And\u00a0as it succeeds across more sites, it provides progressively more advantages.<\/p>\n<p>Will Ben&#39;s alternate future come to pass?\u00a0 No.\u00a0 Because CardSpace will be integrated into many enterprise and web products, it will offer significant advantages to the organizations that adopt it, including the ability to mix and mash personal, enterprise and hosted solutions through multiple shared identities.\u00a0<\/p>\n<p>As the number of CardSpace and DigitalMe and other Card Selector sockets grows towards a tipping point; as the software for building relying parties becomes widely available and understood;\u00a0 as the early software\u00a0put out by Microsoft and others is\u00a0refined and perfected; as leading applications raise the competitive bar by adopting the technology;\u00a0 CardSpace and its sister implementations\u00a0will be used across many different contexts and their ability to support minimal disclosure and prevent the use of universal identifiers will become increasingly valued and apparent.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ben&#39;s alternate future will not come to pass.<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[6,46,10,7,4],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/866"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=866"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/866\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=866"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=866"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=866"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}