{"id":895,"date":"2007-11-19T22:56:47","date_gmt":"2007-11-20T06:56:47","guid":{"rendered":"\/?p=895"},"modified":"2007-11-19T23:11:19","modified_gmt":"2007-11-20T07:11:19","slug":"hunky-dory","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=895","title":{"rendered":"Hunky-Dory"},"content":{"rendered":"<p>\u00a0Paul Madsen at ConnectID <a href=\"http:\/\/connectid.blogspot.com\/2007\/11\/more-display-token.html\">writes<\/a>:<\/p>\n<blockquote><p>Kim <a href=\"\/?p=892\"><font color=\"#6699cc\">defends<\/font><\/a> CardSpace on the issue of the Display Token.<\/p>\n<p>Personally, I think it&#39;s a UI issue. The concern would be mitigated if the identity selector were to simply preface the display token with a caveat:<\/p>\n<blockquote><p><span style=\"font-weight: bold\">The following attributes are what the IDP claims to be sending. If you do not trust your IdP, do not click on &#8220;Send&#8221;.<\/span><\/p><\/blockquote>\n<p><span style=\"font-weight: bold\"><\/span>If the UI doesn&#39;t misrepresent the reality of what the DisplayToken is (and isn&#39;t), then we&#39;re <a href=\"http:\/\/www.worldwidewords.org\/qa\/qa-hun2.htm\"><font color=\"#666699\">hunky-dory<\/font><\/a>.<\/p>\n<p>And of course, CardSpace is not the only WS-Trust based identity selector in town. The other selectors are presumably under no constraints to deal with DisplayToken in the same way as does CardSpace?\u00a0<\/p><\/blockquote>\n<p>Paul has a good point and I buy the &#8220;general idea&#8221;.\u00a0 I guess my question would be, should\u00a0this\u00a0warning be presented each time an Information Card is used, or just when\u00a0making the initial decision to depend on a new card?\u00a0<\/p>\n<p>I think the answer should come from\u00a0&#8220;user studies&#8221;:\u00a0 let&#39;s find out what approach is more effective.\u00a0\u00a0I hear a lot of\u00a0user interface experts telling us to reduce user communication to what is\u00a0essential at any specific point in time so that what is\u00a0communicated is effectively conveyed.<\/p>\n<p>Despite this notion,\u00a0identity providers should be held accountable for ensuring that the contents of information tokens correspond to the contents of their associated display tokens.\u00a0 This should be mandated in the digital world.<\/p>\n<p>By the way, I\u00a0love Paul&#39;s recollection of the word\u00a0&#8220;Hunky-Dory&#8221;.\u00a0 He gives a <a href=\"http:\/\/www.worldwidewords.org\/qa\/qa-hun2.htm\">nice reference<\/a>.\u00a0 Funny &#8211; I always thought it referred to a &#8220;<a href=\"http:\/\/www.ratebeer.com\/beer\/hydes-hunky-dory\/31220\/6832\/\" class=\"broken_link\">certain beverage<\/a>&#8220;.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If the UI doesn&#39;t misrepresent the reality of what the DisplayToken is (and isn&#39;t), then we&#39;re hunky-dory.<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[17,46,7,4],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/895"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=895"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/895\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}