<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://ideas.4brad.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Brad Ideas - openid - Comments</title>
 <link>http://ideas.4brad.com/tags/openid</link>
 <description>Comments for &quot;openid&quot;</description>
 <language>en</language>
<item>
 <title>Legislation doesn&#039;t cut it</title>
 <link>http://ideas.4brad.com/paradox-identity-management#comment-5297</link>
 <description>&lt;p&gt;Legislation is not impotent, but it&amp;#8217;s very far from omnipotent.   Information flows around the rules, if you let it out.  Regularly we see stories how how you can buy all sorts of records from corrupt government employees.   I doubt we can stop corruption.&lt;/p&gt;

&lt;p&gt;In addition, we can&amp;#8217;t solve the problem of future surveillance technologies that most people have not dreamed of.   Today there is not adequate AI to understand all this data we&amp;#8217;ve let out, but there will be, and laws won&amp;#8217;t stop it.&lt;/p&gt;
</description>
 <pubDate>Tue, 06 May 2008 11:40:11 -0700</pubDate>
 <dc:creator>brad</dc:creator>
 <guid isPermaLink="false">comment 5297 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>Yes and No</title>
 <link>http://ideas.4brad.com/paradox-identity-management#comment-5293</link>
 <description>&lt;p&gt;Although I can agree that the way OpenID folk is heading is wrong, I cannot agree with everything. I do not agree that making the information sharing easier will inevitably lead to the massive disclose of personal data. I think that proper legislation and a good reputation mechanism can lead to a suitable equilibrium between privacy and disclose.&lt;br /&gt;
I strongly recommend you the books by Daniel Solove, especially &quot;The Digital Person&quot;. You can find many answers there.&lt;/p&gt;
</description>
 <pubDate>Tue, 06 May 2008 10:27:11 -0700</pubDate>
 <dc:creator>Radovan Semancik</dc:creator>
 <guid isPermaLink="false">comment 5293 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>&quot;BEPSI&quot;</title>
 <link>http://ideas.4brad.com/rename-data-portability-bepsi#comment-5234</link>
 <description>&lt;p&gt;People should have a choice of names.&lt;/p&gt;
&lt;p&gt;One could be based on your QID proposal:  QID Option to Keep Exporting.&lt;/p&gt;
&lt;p&gt;People would then be able to choose between BEPSI and QOKE.&lt;/p&gt;
</description>
 <pubDate>Fri, 25 Apr 2008 15:59:33 -0700</pubDate>
 <dc:creator>Rohan Jayasekera</dc:creator>
 <guid isPermaLink="false">comment 5234 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>Nice turn of phrase</title>
 <link>http://ideas.4brad.com/portable-identity-vaseline#comment-5026</link>
 <description>&lt;p&gt;Top-notch rhetoric-Fu:&lt;/p&gt;
&lt;p&gt;&lt;cite&gt;While some portable data advocates think of the portability systems as “vaseline” that will grease the skids of smooth interoperation, the truth is it may assist another function of vaseline.&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;F, as they say, TW!&lt;/p&gt;
</description>
 <pubDate>Wed, 19 Mar 2008 17:46:03 -0700</pubDate>
 <dc:creator>Josh McHugh</dc:creator>
 <guid isPermaLink="false">comment 5026 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>Still has user choice</title>
 <link>http://ideas.4brad.com/portable-identity-vaseline#comment-5017</link>
 <description>&lt;p&gt;Your document still talks about user choice and configuration of what information is given out.&lt;/p&gt;
&lt;p&gt;This reflects the common mistake here.  You think of technologies like this as ways to control how your information is given out.  They also need to be thought of as technologies that facilitate the giving out of information.&lt;/p&gt;
&lt;p&gt;Unfortunately, you just can&#039;t facilitate the giving out of information without causing information to be given out more often. &lt;/p&gt;
&lt;p&gt;The only way I can see to make it work is if you don&#039;t give out information.   Instead you receive tasks to be done with your information, and do them for the outside application.&lt;/p&gt;
&lt;p&gt;However, the problem is you can only do tasks that have been defined.   Alternately, you can import generic code to do tasks, but you need a way to trust that code, since it could of course just suck in all your information and export it.&lt;/p&gt;
</description>
 <pubDate>Fri, 14 Mar 2008 18:48:17 -0700</pubDate>
 <dc:creator>brad</dc:creator>
 <guid isPermaLink="false">comment 5017 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>A proposed solution to identity issues/paradox</title>
 <link>http://ideas.4brad.com/portable-identity-vaseline#comment-5016</link>
 <description>&lt;p&gt;I emailed you with an earlier version of this idea about a year ago. Check out &lt;a href=&quot;http://thetrustednet.org&quot; title=&quot;http://thetrustednet.org&quot;&gt;http://thetrustednet.org&lt;/a&gt; to see if this iteration overcomes your previous objections. It involves organizations that are set up with the sole purpose of being identity service providers, dubbed here &quot;Privacy Providers&quot;.&lt;/p&gt;
</description>
 <pubDate>Fri, 14 Mar 2008 05:52:35 -0700</pubDate>
 <dc:creator>Trey Tomeny</dc:creator>
 <guid isPermaLink="false">comment 5016 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>Trip-codes</title>
 <link>http://ideas.4brad.com/paradox-identity-management#comment-4143</link>
 <description>&lt;p&gt;If you need authenticity without identification (&quot;only the real Mr Anonymous could have written this comment&quot;) there is a solution called &quot;trip-codes&quot;, used in parts of the web. Basically, the user enters an arbitrary password which is hashed and the hash value is displayed alongside the user name. It&#039;s hard to fake, because you&#039;d have to guess the password. However it makes no intrusive assertions about real identity.&lt;/p&gt;
</description>
 <pubDate>Sat, 30 Jun 2007 05:47:40 -0700</pubDate>
 <dc:creator>Julian Morrison</dc:creator>
 <guid isPermaLink="false">comment 4143 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>But my son doesn&#039;t understand</title>
 <link>http://ideas.4brad.com/paradox-identity-management#comment-4142</link>
 <description>&lt;p&gt;You and I understand the value of privacy, but my son is just out of college . . . he&#039;s immortal still. He&#039;s been on a computer since he was three, and he&#039;s never been in danger in any world. The young men and women he went to university with and the young men and women who visit my blog are flattered when programs offer to track their slightest preferences. &lt;/p&gt;
&lt;p&gt;The folks at CVS don&#039;t understand what they are giving away when they get that 10% discount, so why should my son with no experience understand?&lt;/p&gt;
&lt;p&gt;It&#039;s not only that easy to go along with giving away the information. It&#039;s also that often an ego boost comes with the giving -- look there&#039;s my picture on the MyBlogLog widget, isn&#039;t that cool? Watch them track me all over the Internet. &lt;/p&gt;
&lt;p&gt;It seems that many folks just can&#039;t see below the surface. Some days I feel that it could be too late for most of us already.&lt;/p&gt;
</description>
 <pubDate>Sat, 30 Jun 2007 00:49:38 -0700</pubDate>
 <dc:creator>Liz Strauss</dc:creator>
 <guid isPermaLink="false">comment 4142 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>Sure</title>
 <link>http://ideas.4brad.com/paradox-identity-management#comment-4141</link>
 <description>&lt;p&gt;Those of us in the tin-foil hat community (and I include myself)  can do a lot with the more advanced identity control tools in OpenID.  Though we already can do that, and many of us already do, with the old fashioned password reminder tool in the browser or various plugins.&lt;/p&gt;
&lt;p&gt;Again, as I said, the easier you make it to hand over identity info, the easier it is to demand it.&lt;/p&gt;
</description>
 <pubDate>Fri, 29 Jun 2007 21:07:53 -0700</pubDate>
 <dc:creator>brad</dc:creator>
 <guid isPermaLink="false">comment 4141 at http://ideas.4brad.com</guid>
</item>
<item>
 <title>Directed identity in OpenID 2.0</title>
 <link>http://ideas.4brad.com/paradox-identity-management#comment-4140</link>
 <description>&lt;p&gt;Hi Brad,&lt;/p&gt;
&lt;p&gt;Great post, lots of stuff to think about here. Are you aware of the directed identity stuff going on to OpenID 2.0? Essentially it will let you enter the URL to your OpenID provider (rather than your specific OpenID) - your provider will then generate a one-time OpenID that only works for you on that particular site, preventing that site from correlating your accounts. Your provider will still know which accounts you are using, but  at least you can chose your provider based on their privacy policy.&lt;/p&gt;
</description>
 <pubDate>Fri, 29 Jun 2007 17:48:35 -0700</pubDate>
 <dc:creator>Simon Willison</dc:creator>
 <guid isPermaLink="false">comment 4140 at http://ideas.4brad.com</guid>
</item>
</channel>
</rss>
