<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Identity Networks</title>
	<atom:link href="http://identitynetworks.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://identitynetworks.wordpress.com</link>
	<description>Identity networks and federations, authentication and security in a changing world</description>
	<lastBuildDate>Tue, 03 Jan 2012 13:03:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='identitynetworks.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Identity Networks</title>
		<link>http://identitynetworks.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://identitynetworks.wordpress.com/osd.xml" title="Identity Networks" />
	<atom:link rel='hub' href='http://identitynetworks.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Secure the web (internet-draft)</title>
		<link>http://identitynetworks.wordpress.com/2012/01/03/secure-the-web-internet-draft/</link>
		<comments>http://identitynetworks.wordpress.com/2012/01/03/secure-the-web-internet-draft/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 13:03:52 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Identity management]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://identitynetworks.wordpress.com/?p=349</guid>
		<description><![CDATA[A memo on securing the web, entitled An Inquiry into the Nature and the Causes of Web Insecurity was published by Mike Hanson, Hannes Tschofenig and Sean Turner as an Internet-Draft in October 2011. This document is well worth reading, and I am looking forward to further work from the authors. The memo points out [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=349&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A memo on securing the web, entitled<a href="http://tools.ietf.org/pdf/draft-tschofenig-secure-the-web-00.pdf" target="_blank"> An Inquiry into the Nature and the Causes of Web Insecurity</a> was published by Mike Hanson, Hannes Tschofenig and Sean Turner as an Internet-Draft in October 2011. This document is well worth reading, and I am looking forward to further work from the authors.</p>
<p>The memo points out that the current security measures on the web are designed for static text-based one-site content, whereas the current web is real-time, multi-site and has moved from documents to mobile code. Some of the issues with passwords are pointed out, and three types of goals are presented:</p>
<ol>
<li>Reduce the number of passwords used</li>
<li>Increase the safety and security of how passwords are used</li>
<li>Broaden the use of other credentials</li>
</ol>
<p>Proposed guiding principles:</p>
<ul>
<li>moving <strong>authentication down into the platform</strong>: Methinks not letting every single web developer reinvent the security wheel is a good thing</li>
<li>design for <strong>growth</strong> and multiple authentication mechanisms and credentials: the world changes,</li>
<li><strong>context matters</strong>: exposing minimal information depends on getting context sorted out</li>
<li>transform long-term password to <strong>short-term credentials</strong>: the sloppy practices of not verifying end points will come back to haunt us</li>
<li>keep the <strong>user experience</strong> in mind: investigate failure scenarios and provide user feedback.</li>
<li>go <strong>from client-server to N-Party</strong>: Federated login and other multiple party solutions</li>
</ul>
<p>Please read the Internet draft and give feedback to the authors!</p>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/identity-management/'>Identity management</a>, <a href='http://identitynetworks.wordpress.com/category/software/'>Software</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/349/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/349/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/349/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/349/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/349/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/349/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/349/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/349/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/349/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/349/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/349/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/349/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/349/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/349/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=349&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2012/01/03/secure-the-web-internet-draft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
		<item>
		<title>My hacked twitter account</title>
		<link>http://identitynetworks.wordpress.com/2011/10/31/my-hacked-twitter-account/</link>
		<comments>http://identitynetworks.wordpress.com/2011/10/31/my-hacked-twitter-account/#comments</comments>
		<pubDate>Mon, 31 Oct 2011 14:29:26 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Curiosa]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[account]]></category>

		<guid isPermaLink="false">http://identitynetworks.wordpress.com/?p=339</guid>
		<description><![CDATA[Friday was a sad day, since my twitter account @imelve was hacked. I opened a webpage, via a pointer in a message from  a trusted source, and then things started going wrong. Within a few minutes, my account started to send malicious messages (se below) And then my friends started to warn me. Luckily one [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=339&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Friday was a sad day, since my twitter account <a href="https://twitter.com/#!/imelve" target="_blank">@imelve</a> was hacked. I opened a webpage, via a pointer in a message from  a trusted source, and then things started going wrong. Within a few minutes, my account started to send malicious messages (se below)</p>
<p><a href="http://identitynetworks.files.wordpress.com/2011/10/badrumor.jpg"><img class="aligncenter size-full wp-image-340" title="badrumor" src="http://identitynetworks.files.wordpress.com/2011/10/badrumor.jpg?w=510" alt=""   /></a>And then my friends started to warn me. Luckily one of them warned me by text message, since Friday night is mostly family time and I am offline. Twitter does not run my life, it is but a small part of my online presence. And snuggling up to the kids take precedence. But the message talked of danger, and I did not know what else was compromised on my PC/mobile/iPad. It was time to take <a href="https://support.twitter.com/groups/33-report-a-violation/topics/122-reporting-violations/articles/31796-my-account-has-been-compromised" target="_blank">back control of twitter</a></p>
<ol>
<li>Change twitter account password</li>
<li>Revoke application privileges (I had 25 apps with privileges registered, only one from the malicious site)</li>
<li>Start tidying up app passwords, since leaving this undone may lead to blocked twitter account due to large number of failed logins</li>
<li>Delete messages with malicious content, wading through all streams I have sent.</li>
</ol>
<div>Taking your life back is never easy. Twitter helped by giving a single page where I could revoke account privileges. Getting the apps to work again afterwards? Not fun. The app privileges were harder to deal with than they should have been, since</div>
<div>
<ul>
<li>I use twitter on PC, mobile phone (Android) and iPad. They have all had multiple renovations and upgrades where apps and web sites get twisted around.</li>
<li>I did not remember which apps I actually use.</li>
<li>I did not remember how to change passwords in all the different user interfaces. (Thank you, Flipboard, for making this easy, including meaningful error messages. The rest of you apps know who you are.)</li>
</ul>
<div>I am still not done with the apps, but my life is back on track. Sort of.</div>
</div>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/curiosa/'>Curiosa</a>, <a href='http://identitynetworks.wordpress.com/category/software/'>Software</a> Tagged: <a href='http://identitynetworks.wordpress.com/tag/account/'>account</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/339/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=339&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/10/31/my-hacked-twitter-account/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>

		<media:content url="http://identitynetworks.files.wordpress.com/2011/10/badrumor.jpg" medium="image">
			<media:title type="html">badrumor</media:title>
		</media:content>
	</item>
		<item>
		<title>Security Usability</title>
		<link>http://identitynetworks.wordpress.com/2011/10/04/security-usability/</link>
		<comments>http://identitynetworks.wordpress.com/2011/10/04/security-usability/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 10:58:30 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[policy]]></category>
		<category><![CDATA[usability]]></category>

		<guid isPermaLink="false">http://identitynetworks.wordpress.com/?p=335</guid>
		<description><![CDATA[Professor Audun Jøssang has formulated some useful principles for security usability. I wish more people would reflect on these, and what their practical implications are for the systems and web pages we offer our users today. And I really wish Facebook would read them. The rough statistics for usability is 35% of the people will understand, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=335&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Professor Audun Jøssang has formulated some useful<a title="Security Usability" href="http://folk.uio.no/josang/su/" target="_blank"> principles for security usability</a>. I wish more people would reflect on these, and what their practical implications are for the systems and web pages we offer our users today. And I really wish Facebook would read them.</p>
<p>The rough statistics for usability is</p>
<ol>
<li>35% of the people will understand, almost no matter what you write or do</li>
<li>40% will have cognitive challenges at some times</li>
<li>25% do have special challenges understanding</li>
</ol>
<p>Given this, and the fact that most web sites aim at the population at large, we really need to rethink the mental load we place on our users.</p>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/policy/'>policy</a> Tagged: <a href='http://identitynetworks.wordpress.com/tag/usability/'>usability</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/335/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=335&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/10/04/security-usability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
		<item>
		<title>Real Names: pseudonyms?</title>
		<link>http://identitynetworks.wordpress.com/2011/08/16/real-names-pseudonyms/</link>
		<comments>http://identitynetworks.wordpress.com/2011/08/16/real-names-pseudonyms/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 19:43:34 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Identity management]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://identitynetworks.wordpress.com/?p=330</guid>
		<description><![CDATA[Google+ is subject to a #nymwar discussion about the requirement to use Real Names. Google+ has shut down a large number of accounts, for example for IdentityWoman. The movement for use of pseudonyms have launched My Name Is Me, where the arguments for pseudonyms are presented. Some arguments are: the right not to be stalked [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=330&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Google+ is subject to a #nymwar discussion about the requirement to use Real Names. Google+ has shut down a large number of accounts, for example for <a href="http://www.identitywoman.net/google-suspension-saga-continues">IdentityWoman</a>. The movement for use of pseudonyms have launched <a href="http://my.nameis.me/">My Name Is Me</a>, where the arguments for pseudonyms are presented. Some arguments are:</p>
<ul>
<li>the right not to be stalked or persecuted (whistle blowers, abuse survivors,  people from small communities, sexual minorities)</li>
<li>wanting to have multiple persona, choosing nick names presenting yourself, celebrities (Lady Gaga, Bob Dylan, Madonna &#8230;)</li>
<li>being able to voice personal opinions without being associated with employer (academics, fans, bloggers, journalists, military)</li>
</ul>
<p>Earlier this year, <a href="http://schedule.sxsw.com/events/event_IAP7315">SXSW</a> discussed <a href="http://snubillofrights.com/">Social Network Users&#8217; Bill of Rights</a>, and there was agreement on most of the points proposed. The one point with most discussion (and least agreement) was the right to use pseudonyms. Kim Cameron commented on his blog that<a href="http://www.identityblog.com/?p=1172"> imposing pseudonyms on all social sites breaks the laws of identity</a>.</p>
<p>In Norway we have a debate about how public online discussion forums may avoid hateful and cesspit discussion. There is a need for participants to be held accountable for their opinions, but in my opinion not necessarily to expose legal identities. The <a href="http://refeds.org">federations in higher education</a> are currently handling both Real Names, nicknames and pseudonymous/anonymous access</p>
<ol>
<li>Real Names are present in the identity management system, because the universities need these names to issue formal credentials (PhDs, MS etc) and bind the formal credentials to formal legally registered names.</li>
<li>Nicknames are present in the attribute definitions, but we are still in the process of sorting out what are the most practical ways of sharing this information. There is ongoing debate about consent and necessity for attribute sharing, and displayName is an attribute we need to think more about. Feide decided to require both legal name (Real Name = norEduLegalName) and preferred name (nick = displayName)</li>
<li>Federations provide anonymous traceable access, based on technology for per service unique identifiers .</li>
</ol>
<p>We need to find a balance online, as we have for other aspects of public space where we do not need to post information about identities for each person, but in many cases require that identity is traceable. Minimal exposure of information is good, but defining minimal is difficult.</p>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/identity-management/'>Identity management</a>, <a href='http://identitynetworks.wordpress.com/category/policy/'>policy</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/330/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=330&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/08/16/real-names-pseudonyms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
		<item>
		<title>Talk us down from the roof, again</title>
		<link>http://identitynetworks.wordpress.com/2011/08/08/talk-us-down-from-the-roof-again/</link>
		<comments>http://identitynetworks.wordpress.com/2011/08/08/talk-us-down-from-the-roof-again/#comments</comments>
		<pubDate>Mon, 08 Aug 2011 20:28:57 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Federation]]></category>
		<category><![CDATA[Identity management]]></category>

		<guid isPermaLink="false">http://identitynetworks.wordpress.com/?p=328</guid>
		<description><![CDATA[David Bantz posted an interesting email Please, somebody talk me down! on the Shibboleth users list, pointing to four issues that crop up over and over again with SSO in higher education: Even if a vendor claim to support SAML, they are unable to consume attributes. And the provisioning of attributes include both sensitive, restricted [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=328&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>David Bantz posted an interesting email <a href="http://marc.info/?l=shibboleth-users&amp;m=131208794614009&amp;w=2">Please, somebody talk me down!</a> on the Shibboleth users list, pointing to four issues that crop up over and over again with SSO in higher education:</p>
<ul>
<li>Even if a vendor claim to support SAML, they are <strong>unable to consume attributes</strong>. And the provisioning of attributes include both sensitive, restricted and open information.</li>
<li><strong>Proprietary extensions </strong>are used for too many of our solutions</li>
<li><strong>Credential relays</strong>, operated by non-trusted third party (or SP). Preferably combined with <strong>non-maintenance of SP software</strong>?</li>
<li><strong>Why not just use AD?</strong> Believing that using AD will automagically  integrate all services.</li>
</ul>
<div>The scary summary is that we as a community are not providing enough direction when it comes to SSO solutions.</div>
<div>For some of these issues (why AD does not solve all problems, credential relays) we need to explain the issues in a language that may be understood, or even better, put into calls for tender. For other issues there are unsolved technical problems, like the integration of web-SSO and non-web-SSO.  The concept of real-time attributes, so beloved of higher education federation, is poorly understood by most vendors. Then again, they are not used to operating in a world where user account lifetime is planned per semester.</div>
<div>I am hoping that <a href="http://refeds.org">REFEDS</a> may be a place to work on some of the issues pointed out, but the bulk of the work will have to be done by each individual university as they call for tender and discuss with their application suppliers and partners.</div>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/federation/'>Federation</a>, <a href='http://identitynetworks.wordpress.com/category/identity-management/'>Identity management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/328/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=328&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/08/08/talk-us-down-from-the-roof-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
		<item>
		<title>Filter bubble and identity</title>
		<link>http://identitynetworks.wordpress.com/2011/07/27/filter-bubble-and-identity/</link>
		<comments>http://identitynetworks.wordpress.com/2011/07/27/filter-bubble-and-identity/#comments</comments>
		<pubDate>Wed, 27 Jul 2011 21:27:53 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Books]]></category>

		<guid isPermaLink="false">http://identitynetworks.wordpress.com/?p=326</guid>
		<description><![CDATA[The Filter Bubble by Eli Pariser shows some of the implications of personalization, especially for the public discussion and our community political discourse. Google is one example, where the search results differ based on geography, previous searches and many many other factors. When we first started work on federated identity and attributes, we thought the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=326&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.amazon.com/Filter-Bubble-Internet-Hiding-ebook/dp/B004Y4WMH2/">The Filter Bubble</a> by Eli Pariser shows some of the implications of personalization, especially for the public discussion and our community political discourse. Google is one example, where the search results differ based on geography, previous searches and many many other factors.</p>
<p>When we first started work on federated identity and attributes, we thought the primary use for attributes would be authorization: granting or refusing access. We were wrong. In the first two years of handing out attributes, we discovered that <strong>personalization is the primary reason for requesting information about a person</strong>. Attributes are used for personalization, and controlling attributes is under-estimated. We need to work more on attributes and how to share enough information without revealing too much. Cross-site scripting is a security threat, <strong>cross-site personalization is a risk to our integrity</strong>.  Personalization is available on most modern web sites.</p>
<p>The Filter Bubble points out some of the dangers for our society as the news streams get fragmented and we slide into ghettos where there is no shared reality anymore. Shared reality is important for democracy, as we need to sort out where our choices are, during a public discussion.</p>
<p>My sister is a public servant, working for the Norwegian government. Someone set off a bomb just outside her office less than a week ago, because he hated the current political regime, killing 8 people. He then went on to the Labor Youth summer camp, killing 68 (current number, there are several missing persons), where he was arrested. All the evidence reported by the media points to a person who has been living in a filter bubble with a strong reinforcing feedback hatred for Muslims, as <a href="http://www.guardian.co.uk/commentisfree/2011/jul/25/anders-behring-breivik-norway-extremists">explained in the Guardian by Thomas Hylland Eriksen</a>. The terrorist has been using anonymous discussion forums online to confirm his ideas and get ideological backing. Conspiracy theories flourish in such environments.</p>
<p>The Filter Bubble on our Internet gets really scary when we encounter:</p>
<ul>
<li>There is no <strong>transparency</strong>, we do not know how reality was altered to fit us</li>
<li>The<strong> invisible ghetto</strong> I live in have walls, and I believe they are the end of the world</li>
<li>We have no interest in our community and <strong>cross-partisan discussion fail</strong> to deal with large (and small) political issues</li>
<li>Personality tests used for job interviews gets replaced by an <strong>interpretation of the bubble</strong> the job applicant live in (there is probably an app for doing this, at least in the US, where such information is for sale). Knowing about your bubble gets more important than knowing you.</li>
<li>Critical thinking is made more difficult by<strong> incongruent information</strong>, since search results and news flow differ significantly</li>
</ul>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/books/'>Books</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/326/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=326&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/07/27/filter-bubble-and-identity/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
		<item>
		<title>google+ circles: bull&#8217;s eye or child&#8217;s play?</title>
		<link>http://identitynetworks.wordpress.com/2011/07/04/google-circles-bulls-eye-or-childs-play/</link>
		<comments>http://identitynetworks.wordpress.com/2011/07/04/google-circles-bulls-eye-or-childs-play/#comments</comments>
		<pubDate>Mon, 04 Jul 2011 20:02:24 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Identity management]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://identitynetworks.wordpress.com/?p=322</guid>
		<description><![CDATA[Google launched testing of google+ last week. One interesting feature is the concept of circles: sorting your friends into friends, family, acquaintances and cool-people-to-follow. The interface for sorting friends is OK, and I may add my own circles. The idea of using circles got me thinking about overlaps and how the circles could overlap. Most [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=322&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Google launched testing of google+ last week. One interesting feature is the concept of circles: sorting your friends into friends, family, acquaintances and cool-people-to-follow. The interface for sorting friends is OK, and I may add my own circles.</p>
<p>The idea of using circles got me thinking about overlaps and how the circles could overlap. Most of the right&#8217;s management we are using today always starts out with a well defined root and hierarchical structure under the root.  I believe we need circles of rights, not hierarchies. I say this having worked both in the enterprise environment, social networks and for cross-organizational solutions. Bull&#8217;s eye is composed of concentric circles, exemplified by True friends within acquaintances/buddies/friends. This is similar to the traditional hierarchies in LDAP servers, who in practice limit us in what is easily done. Even for other services we tend to limit ourselves to this way of thinking, for example are there very few customer relation clouds that let you assign a person to two different organizations. Relations are normally with a person, not with a graph. I need persons assigned to multiple organizations because so many of my customers have more than one job or are in the process of fusion/fission for their organizations.</p>
<p>Child play is what Google+ circles look right now: disjunct circles you can skip around in. There is currently not much more than twitter lists or Facebook lists in the functionality. So why do I bother to spend time thinking about the potential? Because something needs to be done with the user interfaces for sharing information, and the Circles is a new kid on the block.</p>
<p>Some of the functionality I like about circles</p>
<ul>
<li><strong>Visual guide</strong> for who is in what circle</li>
<li>Drag and drop <strong>interface</strong>, still needs quite some work before escaping beta</li>
<li>Ability to put people in <strong>multiple circles</strong></li>
</ul>
<div>I think Google should not aim for the bull&#8217;s eye, but rather aim for something usable in everyday life, something more like child&#8217;s play.</div>
<h2>Do not disturb my circles</h2>
<p>Are we ready to take up the challenge of using flat space for rights management? It depends on the user interface, and the way circles are implemented today are several steps away from what we need</p>
<ul>
<li>Visualization of circles overlap: <strong>Venn diagrams</strong></li>
<li>Ability to <strong>weed out persons</strong>/circles (everybody but my cousin will get the funny pics, I want to closely follow my close friends but not the chatty girl posting too many updates)</li>
<li><strong>Sorting</strong> the list of circles, and adapting the sort to usage patterns</li>
<li><strong>Importing</strong> (and searching) from a variety of circles: people who get the same email, lists from other sources, people who live in my area, teams, my co-workers etc</li>
<li><strong>Automatic updates</strong>, reflected in the search facilities</li>
<li><strong>Scaling</strong>, for those with more than 15 people in their lives</li>
</ul>
<div>And all of this needs to happen without having to think too hard about how to do the right thing for me as an end user. Otherwise I&#8217;ll just not bother. Google has great intelligence for search, they need to apply that same thinking to who-gets-what in the social networks.</div>
<h2>Forget bull&#8217;s eye, give us child&#8217;s play</h2>
<p>If a child can play with the circles and get rights management right, then the solution is good enough. Forget about building the perfect hierarchy with the single root, and get the flow going!</p>
<p><img src="https://lh4.googleusercontent.com/-Duduip_xnIc/ThGDBipJTQI/AAAAAAAAAPM/OCq69hixU-Q/s576/2011-07-04+11.07.19.jpg" alt="" /></p>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/identity-management/'>Identity management</a>, <a href='http://identitynetworks.wordpress.com/category/software/'>Software</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/322/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=322&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/07/04/google-circles-bulls-eye-or-childs-play/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>

		<media:content url="https://lh4.googleusercontent.com/-Duduip_xnIc/ThGDBipJTQI/AAAAAAAAAPM/OCq69hixU-Q/s576/2011-07-04+11.07.19.jpg" medium="image" />
	</item>
		<item>
		<title>SCIMming the surface</title>
		<link>http://identitynetworks.wordpress.com/2011/06/21/scimming-the-surface/</link>
		<comments>http://identitynetworks.wordpress.com/2011/06/21/scimming-the-surface/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 09:56:32 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Identity management]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[scim]]></category>

		<guid isPermaLink="false">https://identitynetworks.wordpress.com/2011/06/21/scimming-the-surface/</guid>
		<description><![CDATA[Provisioning is one of the thorny issues plaguing us, and where there are no good standardized solutions. SCIM is a proposal for&#160; Simple Cloud Identity Management, with the intent to “reduce the cost and complexity of user management operations by providing a common user schema and extension model, as well as binding documents to provide [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=321&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Provisioning is one of the thorny issues plaguing us, and where there are no good standardized solutions. <a href="http://www.simplecloud.info/">SCIM</a> is a proposal for&#160; Simple Cloud Identity Management, with the intent to “reduce the cost and complexity of user management operations by providing a common user schema and extension model, as well as binding documents to provide patterns for exchanging this schema using standard protocols.” </p>
<p>Internet2 has gathered a <a href="https://spaces.internet2.edu/display/macedir/Simple+Cloud+Identity+Management-SCIM">wiki of SCIM resources</a>, to help higher education follow the development.&#160; Some of the advantages of the SCIM proposal seem to be</p>
<ul>
<li>REST-support</li>
<li>standardized API for cloud-ish functions</li>
<li>claims to be simpler, which it really needs to be, but I want to see this IRL before I believe it</li>
</ul>
<p>The main problem is that installing a new interface on core components (local LDAP-servers, identity management solutions) who are crucial for the day-to-day operations of the organizations involved is not an easy undertaking.&#160; The lead time for serious changes to that part of the infrastructure is at least two years, in my experience, even for small changes like updating schema across multiple organizations.</p>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/identity-management/'>Identity management</a> Tagged: <a href='http://identitynetworks.wordpress.com/tag/provisioning/'>provisioning</a>, <a href='http://identitynetworks.wordpress.com/tag/scim/'>scim</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/321/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/321/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/321/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/321/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/321/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/321/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/321/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=321&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/06/21/scimming-the-surface/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
		<item>
		<title>SimpleSAMLphp in a multi-vendor environment, interop testing</title>
		<link>http://identitynetworks.wordpress.com/2011/05/13/simplesamlphp-in-a-multi-vendor-environment-interop-testing/</link>
		<comments>http://identitynetworks.wordpress.com/2011/05/13/simplesamlphp-in-a-multi-vendor-environment-interop-testing/#comments</comments>
		<pubDate>Fri, 13 May 2011 07:41:08 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[simpleSAMLphp]]></category>

		<guid isPermaLink="false">https://identitynetworks.wordpress.com/2011/05/13/simplesamlphp-in-a-multi-vendor-environment-interop-testing/</guid>
		<description><![CDATA[Kantara Initiative announced this week that CA Technologies, IBM Corporation, SAP AG and UNINETT pass Kantara Initiative SAML 2.0 Full-Matrix Interoperability Testing, SimpelSAMLphp was chosen as an open source solution to join in the testing, after submitting a proposal for why it is key federation software. SimpelSAMLphp 1.8 passed Kantara Interoperability testing, and does conform [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=320&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Kantara Initiative announced this week that <a href="http://kantarainitiative.org/wordpress/2011/05/ca-technologies-ibm-corporation-sap-ag-and-uninett-pass-kantara-initiative-saml-2-0-full-matrix-interoperability-testing/">CA Technologies, IBM Corporation, SAP AG and UNINETT pass Kantara Initiative SAML 2.0 Full-Matrix Interoperability Testing</a>, SimpelSAMLphp was chosen as an open source solution to join in the testing, after submitting a proposal for why it is key federation software. </p>
<p><a href="https://rnd.feide.no/2011/05/11/simplesamlphp-1-8-passes-kantara-interoperability-matrix-testing/" target="_blank">SimpelSAMLphp 1.8 passed Kantara Interoperability testing</a>, and does conform to the IdP lite and SP lite profiles of SAML2.0.&#160; This means that our drive to support federated login in a multi-vendor environment has taken another step in the right direction. Many of the federations in higher education operate with a software monoculture (using <a href="http://shibboleth.internet2.edu/" target="_blank">Shibboleth</a>, which is really good software), but I believe that for federated solutions to permeate every necessary application we must work with a plethora of solutions. It is most important for this to happen on the service provider (SP) side, since the variations on implementation for web applications is huge. </p>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/software/'>Software</a> Tagged: <a href='http://identitynetworks.wordpress.com/tag/simplesamlphp/'>simpleSAMLphp</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/320/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=320&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/05/13/simplesamlphp-in-a-multi-vendor-environment-interop-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
		<item>
		<title>Student mobility challenges</title>
		<link>http://identitynetworks.wordpress.com/2011/05/04/student-mobility-challenges/</link>
		<comments>http://identitynetworks.wordpress.com/2011/05/04/student-mobility-challenges/#comments</comments>
		<pubDate>Wed, 04 May 2011 12:12:02 +0000</pubDate>
		<dc:creator>IngridM</dc:creator>
				<category><![CDATA[Identity management]]></category>

		<guid isPermaLink="false">https://identitynetworks.wordpress.com/2011/05/04/student-mobility-challenges/</guid>
		<description><![CDATA[Student mobility is on the rise.&#160; There are a number of different factors interacting, all contributing to the More students in the Erasmus program, now around 200000 students every year Flexible study programs, where part of the education is given by a university not in the same town or even the same country.&#160; The Nordic [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=319&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Student mobility is on the rise.&#160; There are a number of different factors interacting, all contributing to the </p>
<ul>
<li>More students in the <a href="http://ec.europa.eu/education/lifelong-learning-programme/doc80_en.htm" target="_blank">Erasmus program</a>, now around 200000 students every year</li>
<li>Flexible study programs, where part of the education is given by a university not in the same town or even the same country.&#160; The <a href="http://www.siu.no/eng/Front-Page/Programme-information/Neighbouring-countries/Nordic-Master-Programme" target="_blank">Nordic master programme</a> is one example of join Master ‘s programmes of higher education</li>
<li>Project work across institutional borders is rewarded, for example for graduate students involved in research.</li>
<li>Going (back) to college for more education is more common, as the skill sets and the learning we need to be comfortable in a complex world challenge us.</li>
</ul>
<p>Students from outside our universitites need access to both campus services and off-site applications. One challenge we face is how to integrate students from “foreign” origin into our campus identity management systems.&#160; Nothing is more foreign than the institution in the neighbouring town, as their practices confuse us by being similar, yet different. </p>
<p>Some promising work that is ongoing in our community</p>
<ol>
<li>Cross-federations with the same attribute set (<a href="http://middleware.internet2.edu/eduperson/" target="_blank">eduPerson</a>) enable an easy way to add users to an existing service.&#160; Prime examples are Kalmar2 and eduGAIN.&#160; The national federations within each country have mechanisms for sharing attributes based on eduPerson, with several extensions. Kalmar2 has made a <a href="http://www.kalmar2.org/kalmar2web/attributes.html" target="_blank">comparison of key attributes</a> in the participating federations.</li>
<li><a href="http://www.rs3g.org/" target="_blank">RS3G</a> work on exchanging student records on the European level, by feeding information between the student registry systems.&#160; In Feide the student registry systems are the authoritative sources for campus identity management, so if the information is present in the student registry all is well.</li>
<li><a href="http://refeds.org/" target="_blank">REFEDS</a> where the operational federations meet to sort out how federations may help with live scenarios like increasing student mobility.</li>
<li>Technical work on <a href="https://rnd.feide.no/category/idp-discovery/" target="_blank">Identity Provider discovery</a> and in Kantara on <a href="http://kantarainitiative.org/confluence/display/ulx/Home#Home-UniversalLoginExperience%28ULX%29WorkingGroup" target="_blank">Universal Login Experience</a>, attacking the student mobility scenario from the user interface and giving the student tools to sort out rights and identity management.&#160; The other side of this puzzle is the rights management, where there is still work to do.</li>
</ol>
<p>There have also been some work in <a href="https://www.eid-stork.eu/pilots/pilot3.htm" target="_blank">STORK on student mobility</a>, but so far involving individual universities, interacting with national government eID, without reaching the national level.</p>
<p>I believe in running code, and solutions that get used. This will probably involve the formal student registries, and some sort of interaction from the students with the federation functionality. </p>
<br />Filed under: <a href='http://identitynetworks.wordpress.com/category/identity-management/'>Identity management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/identitynetworks.wordpress.com/319/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/identitynetworks.wordpress.com/319/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/identitynetworks.wordpress.com/319/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/identitynetworks.wordpress.com/319/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/identitynetworks.wordpress.com/319/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/identitynetworks.wordpress.com/319/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/identitynetworks.wordpress.com/319/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/identitynetworks.wordpress.com/319/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/identitynetworks.wordpress.com/319/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/identitynetworks.wordpress.com/319/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/identitynetworks.wordpress.com/319/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/identitynetworks.wordpress.com/319/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/identitynetworks.wordpress.com/319/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/identitynetworks.wordpress.com/319/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=identitynetworks.wordpress.com&amp;blog=5034512&amp;post=319&amp;subd=identitynetworks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://identitynetworks.wordpress.com/2011/05/04/student-mobility-challenges/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">IngridM</media:title>
		</media:content>
	</item>
	</channel>
</rss>
