Wednesday, January 31, 2007

Commoditisation of Federated Identity software part 2

I blogged about this late last year and outlined a whole bunch of reasons why I thought this would happen sooner rather than later.

I'm bringing this up again because some of the Higgins and Bandit bunch are talking about a proof of concept they will be unveiling at the RSA Conference next week which shows:
how companies can integrate a non-Liberty Alliance identity system and a Liberty Alliance-based federated identity system provided by Novell Access Manager. In particular, the demonstration will have Novell Access Manager authenticate a user via Microsoft's CardSpace using information from an external identity system. In the demonstration, users will be able to access a sample media Wiki and blog using the technology.

The obvious Novell promotional reasons behind this aside, there was a quote from Paul Trevithick (Higgins project lead, amongst other things) which stated:

"One problem in realising the vision of an open-source identity layer is that tends to commoditise existing identity management products, creating a perverse incentive for companies that are in a position to make interoperable identities work."

He goes on to say:

"That may be the reason you hear about interoperability but still haven't seen it. Companies like Oracle and IBM and even Novell have no incentive to do it."

This brings up something I didn't mention previously - the position this puts the big vendors like IBM, Novell, Oracle, Sun etc in. They are all evangelising the need for open standards and interoperability, which is where we all want things to end up. Problem is, the guys holding all the $$$ within the vendors are then put in an interesting position...support these initiatives at the cost of software sales. Because in doing so, they're effectively cannibalising their own market. This is especially prevalent in the Federated Identity space because the whole concept of Federation is built upon open standards.

Like I said before, I don't think they can stop the freight train and the Federated software products look to be next in line for commoditisation.

Monday, January 29, 2007

Today's my 6 year anniversary working for...

Ok, so until now I have not explicitly said which company I work for...not that anyone reading this couldn't have figured it out. My details are out on the web and a Google search for "Ian Yip" will allow one to discover my employer within the first 2 pages of the search results because using your wonderful powers of deduction, you should know I'm not a doctor (do that search and you'll get what I mean), I'm Australian and I live in Australia (at least I do at the moment - more on this in the next paragraph) and I have an interest in all things Identity related. For those still scratching your head, today is my 6 year anniversary working for IBM. For that reason, I've tried to steer clear of talking about anything IBM related unless it was relevant to the topic, both because I don't want to appear biased nor do I want IBM coming after me for anything inflammatory I might say about the company. Those of you who know me understand I'm rather cynical at the best of times...especially towards my current employer. (Aside: So what did I get from IBM for my 6 year anniversary you ask? Well, nothing. Not that I expected anything. For my 5 year anniversary, I received a Selangor Pewter puzzle! I was so thrilled by it I can't even remember what type of puzzle it was...nor can I remember where I put it. I don't remember trying to sell it on eBay? Hmmm.)

Why am I bringing this up you ask? Well, my last official day at IBM Australia is in February. The obvious question most will ask is "what company have you defected to"? The right question to ask is "where are you going"? I'm moving to the UK for a year or 2. Maybe more. Who knows. I've yet to find a job over there for various reasons. Distance being one and Visa hoops to jump through being the other. I may just wait until I get there to find a job if it all gets too difficult. Nothing like being in someone's face rather than speaking over the telephone. Who knows...maybe no one will want to hire me and I'll just spend the time travelling through Europe. Now there's an idea! All I can say is that it'll be interesting to see where I end up.

Guess I'll have to change my blog profile soon to reflect my move...not yet though. I still remain based in Australia for a few more weeks.

Bit of a light month in Identity

I'm all iPhoned out. Seems all the news in January's been about Apple and the iPhone. The announcement at MacWorld, Cisco subsequently suing Apple over the use of the name and the latest being a Canadian company (Comwave) claiming to have the rights (at least in Canada) to the iPhone name. From a marketing standpoint, Apple's done a brilliant job here. Even if the damn phone doesn't end up being called an "iPhone", we'll all know it as "that thing formally known as the iPhone" - the point being that we've all heard about it. There's been much discussion about why Apple even announced it when they knew Cisco had claim to the name in the US (we know this because Apple was in talks with Cisco over licensing the name from them before the iPhone announcement). The most logical conclusion seems to be the publicity. I have also yet to read about any geeks out there who don't want one. They all practically wet themselves over the announcement...maybe that'll change when the hype dies down. I for one, do NOT want one...maybe I'm the only one. I must not be geeky enough.

So in a month where nothing was interesting enough for me to comment about, here's a few main bits of Identity news I came across:
  • The Burton Group followed up a previous post about the Law of Relational Symmetry (which I referenced in an earlier post) with a post relating to the Law of Relational Risk. I for one had a tougher time grasping the concepts here, so I REALLY had to concentrate.
  • The Burton Group also mentioned the "ascension" of authorisation management within enterprise environments of late. Seems this concept just won't go away...and rightly so. But as I mentioned in an earlier post (although at the time I used the term "entitlement management" and made mention of a company called Securant, which started a discussion between myself and Securent's CEO Rajiv Gupta which you can read in the comments section of that post - I should note that he didn't respond to my email following my final comment. I'm sure he had better things to do than debate terminology with me), this is not a new concept. It's just getting more attention of late.
  • EMC talked about leveraging their RSA acquisition to "identity enable" their suite of products. I'll believe it when I see it!
  • Microsoft Windows Vista launched - probably means we'll start to see the advent of more Windows CardSpace enabled solutions.
  • IBM announced the release of Identity Mixer, which is software designed to help people hide or anonymise their personal information on the web. This has been donated to the Higgins project.
  • The Liberty Alliance announced a Portal called OpenLiberty.org to "provide easy access to tools and information to jump start the development of more secure and privacy-respecting identity-based applications based on Liberty Federation and Liberty Web Services standards".
  • Microsoft Architect for Identity and Access and User Centric Identity luminary Kim Cameron gave examples about how one would integrate CardSpace with OpenID.
  • Kim Cameron and Dick Hardt (yes that really is his name), CEO of Sxip had a bit of a friendly stoush over OpenID and what Kim thinks is a susceptibility to phishing unless OpenID adopts some of the more secure concepts behind CardSpace. Dick responds on his blog. The discussion continues in the Identity-sphere.
  • Australian Prime Minister John Howard announced changes in his cabinet making Senator Ian Campbell the new Minister for Human Services. He takes over from Joe Hockey who is now Minister for Employment and Workplace Relations. I mention this because it means that there's now a new guy in charge of Australia's Access Card initiative which has the potential to become our National Identity Card depending on what happens moving forward. It will be interesting to see the direction this takes moving forward with new leadership in place...not to mention the continuation of all the Software Security vendors (one of which I work for - more on this in the next post) and System Integrators salivating at the sheer size and potential $$$ involved with winning even part of the bid to implement this or to provide part of the infrastructure for it.
Note: I think I've just broken my record for the number of outgoing links in a single post.

Monday, January 08, 2007

New year resolution? If you want to call it that...

I was trying to avoid posting any lame "new year resolution" entries as I don't see why anyone needs to pick a symbolic point in time to decide they need to do something. My opinion has always been if you want to do something, make a decision to do it and make it happen! As a result, I don't usually make a new year resolution. It just so happened that I've decided to take some action about something at this time of the year, which I suppose makes it a new year resolution by coincidence.

First a bit of background...

Those that know me well know that I have a bit of an interest in all things entrepreneurial. Hey who doesn't right? Anyway, I'm only posting about this because I need a reference that I can use for myself as a motivational tool to get me to take steps forward. Otherwise, it's just too easy to say "I'll just spend today watching the cricket and do that thing tomorrow when the cricket's over." Problem is, the frigging tennis is on tomorrow and you find yourself saying you'll do it when the tennis is over. It's a vicious cycle of inaction.

I got a news story via one of my RSS feeds (of which I have way too many, but that's another problem for another time) about a new site that lets you order custom music. They seem to be targeting the romantic at heart and lets you order a piece of "tailored custom" music for your loved one for a fee. That's one of the ultimate unique gifts right? Which girl (or guy) wouldn't like a song that was written just for them? Maybe I'm over-generalising here but you get my point. It's a good idea if executed and marketed well. Of course, I'm a bit biased here because this EXACT idea's been floating around in my head for the PAST 2 YEARS! I'm in NO WAY implying that these guys stole my idea. How could they? I never told anyone about my idea! I just always thought it would be a good business. Even worse, I have the skills (at least I think I do - others may think I suck at the skills required) to do what's required. I am a classically trained pianist who dabbles in songwriting occasionally AND I'm in the IT industry and have the skills to build such a site that could service such a business! I even have my own amateur-ish recording studio with a keyboard, external midi device, microphones all hooked into my computer and the Dolby 5.1 surround sound system.

Now for the "new year resolution"...

This has been bugging me for the past week so I've decided that my resolution for the year 2007 is:
Just Do It!

I've always been a big fan of Nike so I guess I should have taken more notice of their slogan. Oh, and I do not and have never worked for Nike so I have nothing to gain from saying any of this other than it's an appropriate mantra for me. Hopefully they don't try to charge me for adopting it otherwise I'll have to find a new one.

Now, I just need a new idea that I think can fly and go for it.

Incidentally...my birthday is coming up this month. Anyone want to buy me a tailored custom song? I didn't think so :-)

Thursday, December 28, 2006

VMWare for Mac in beta

It's about time VMWare got their act together and released a version of their software on Mac (even if it's only in beta release)! Of course, I didn't care about this before I actually bought a Mac.

Previously, there were only 2 ways of running Windows on a Mac:
  1. Using Apple's boot camp (which installs Windows natively on the machine)
  2. Using Parallels Desktop for Mac, which is a VMWare competitor and beat them to the punch in stitching up Mac users who wanted to run a virtualised environment.
Why am I posting about this? Because running a virtualised environment is much easier than installing an OS from scratch natively - not because it's hard to install but because it's annoying having to reboot to change operating systems. In a virtualised environment, it's as simple as firing up the virtualisation software (if you can't tell yet, I'm a long time VMWare user).

Oh, the other thing is that you have to pay for Parallels. VMWare has a free version of their product, and we all LOVE free (although I'm not sure if VMWare intend on charging for the Mac version once it's out of beta).

Friday, December 22, 2006

My first post using my new MacBook Pro

This post isn't really identity related (although one could argue that one's mobile phone and choice of notebook says a lot about one's personality and sense of identity, but I digress), but it is somewhat technology related.

So I decided to buy myself a Christmas present and went for the MacBook Pro 15-inch. And boy is it a powerful piece of technology: Intel Core 2 Duo 2.33GHz processor, 2GB RAM and ATI Mobility Radeon X1600 graphics card with 256MB of GDDR3 SDRAM.

It is by far the best looking notebook on the market as you would expect from Apple. I considered other notebooks but ultimately went for the MacBook Pro because of the power and the looks. Of course, if it didn't contain an Intel chip and wasn't capable of booting up in Windows, I would never have considered it...not because I want to use Windows, but because I need Windows to play games. Games are also the reason I forked out the $$$s for this thing, otherwise the plain old MacBook (at half the price) would have been good enough.

So far, I'm quite impressed. Apart from having to get used to Mac OS X, it's really quite nice. I expected usability and I certainly got it. Initial setup was a breeze. No need for banging my head against the wall or trying to pull my hair out. It was a nice to have technology just work. The only annoying thing so far (and it really is just a little thing) is that the keyboard doesn't have the "End" key that takes you to the end of the line when you're typing. I use that quite often and not having it there is kinda bugging me. Maybe it's there and I need to hit some weird combo of the "apple key" and some other key. For now, I just have to use the mouse or the arrows to move me manually to the end of the line. Apart from that, (Ed Note: I finally found the "End" key. It's on there, I just didn't look closely enough. To use it, I have to use the "apple key" and the right arrow button together). I'll probably be using the Mac OS as my default environment and only use Windows whenever I REALLY have no other option. At this stage, I'm expecting this to only occur when I want to load up my games.

Apple's also made it relatively easy to help load Windows up on a Mac with their Boot Camp beta software...so at least I have a "Mac newbie" way of doing it.

As for why I needed a new notebook when I already had one (I actually had 2)...2 reasons:
  • It's about time I had my own notebook to do my personal things on.
  • I'm about to lose the 2 notebooks in a month or 2 because they are technically not mine. ie. They belong to the company I work for. So I would have been without a machine in the near future if I didn't take a proactive approach to things. Why will I be losing the work notebooks? You can probably guess...but more on that in due time.
Now...I guess I'd better go get that Windows XP CD...

Monday, December 11, 2006

Attempts to consolidate my online identity brand

I've started to take an interest in this concept of a personal online identity brand lately. I first mentioned it a few posts ago here. It's interesting to me because:
  • It's fairly new.
  • It's a form of identity management, but with a very strong marketing focus.
  • It makes one look at identity from a non-technical perspective.
  • It elevates the concept of identity commonly mentioned amongst the technical community to something that the average Joe can identify with.
  • It further "rounds out" the concepts around our "digital identity".
  • One day, someone may offer you a job because of your online identity brand.
  • One day, you may be fired because of your online identity brand.
What got me thinking about this again today was a news story on newsday.com titled "Send us a resume and URL". I'm starting to see this take effect on a more personal level hence heightening my interest.

I get unsolicited emails and phone calls from companies and recruiters asking about my interest in roles they have that they want me to consider. I usually have no idea how they get this information as I'm not applying for any jobs explicitly. Hence they must be doing it some other way. I've started to ask these people where they get my details and it is probably no surprise that a fair few are from personal referrals and people who know me or at least know of me (my day job gives me some level of a public profile in the technical community).

However, there seems to be an increase of people (not just locally, but overseas as well) who say they found my details via online social/business networking sites like LinkedIn.com and the like. It's no surprise that Internet savvy recruiters love business networking sites such as LinkedIn.com as it gives them a new channel and transparency into the masses out there that they would have never dreamed of gaining via traditional means. This trend will only continue as time passes and recruiters research new ways to gain a competitive advantage over their competition for talent.

If recruiters can gain access to potential candidates via publically available information, this obviously has implications with regards to prospective employers and people in general who may want to know something about you. I won't even begin to talk about the privacy implications here, but in most cases you give up a level of privacy if you choose to disclose information about yourself online. In these cases, it's simply your own fault. But what about the information you have no control over and things that have been posted about you without your knowledge? This is the reason we're starting to see an uprising of companies who claim they can "manage your online brand" and help you erase any negative information out there. My question to them is simply how do they expect to have the ability to erase anything about anyone on the public Internet where information you want to erase is more than likely not within your control? Are they really expecting that the site owners will remove the information if they ask nicely? Are they going to threaten legal action? How are they expecting to prove that the information is incorrect? Sites have every right (in most cases) to publish information they deem to be accurate - especially if we've clicked the "I agree to give up all ownership of any information I give you to allow you to publish it however you choose" button that is a pre-requisite to sign up to most sites out there. You know, the terms and conditions text box we NEVER read! Who's going to pick up the bill? The consumer? It's just a legal, potentially costly minefield. In other words, it's a very difficult thing to attempt to do without some form of standardisation.

Let's expand on this and look at identity theft. I'm not talking about the commonly known term you see in the news nowadays where someone steals your details to get access to your bank account or credit card details or whatever else is of value so they can commit fraud and cost someone (hopefully not you) a lot of money and in the process profit from it. I'm talking about stealing your online identity brand. What if someone claims to be you and signs up to all sorts of things all over the place under the guise of claiming to be you? They are never challenged. How can you get that back? Our online identity brands are much easier to steal than our bank account details. The losses we incur may not be financial (at least not directly) but what if we lose a job because of false information out there about ourselves? Can we call it financial loss then? It's certainly personally damaging one way or another.

Companies such as ClaimID are attempting to address some aspects of this issue by giving you a place to point people at for anything and everything you know about yourself online. It's essentially just a page of links that relate to you. Profiles, books, blogs, photos, comments, references to you in articles etc. The thing about ClaimID is that you have to find all the information about yourself, by yourself. No 3rd party is going to do it for you unless you pay them. e.g. InfoSearch media as mentioned in this press release. It's easy to link to information about yourself, meaning I can "claim" information about someone else to be mine. For example, in my case, there's a rather well known doctor who is an expert in nutrition and weight loss with the same name as me. I could simply just link to all the information about him and claim I'm this doctor. I have to give ClaimID some credit in attempting to get around this issue by using the concept of a verified link. The problem I have with the way they do it is that I need to have the authority to edit the web page I'm linking to because the way they do the verification is by searching for a specific unique "MicroID" that tags the page as yours...or at least tags it to be owned by your ClaimID identity/brand. Anyone see the biggest problem here? Well, I really only have control over a handful of pages out there. The other ones I have no say over. Meaning they can never be verified unless I manage to convince the site owner to embed the relevant MicroID into the site. In other words, the problem isn't really solved. Anyone can still say they are anyone else because it's difficult to have a properly verified link and people will simply ignore the "verified link" concept. I'm not trying to put ClaimID down in any way. In fact, I'm quite appreciative that they are at least trying to do something about it. I'm merely pointing out that this is not an easy problem - especially when your online identity brand is so easily stolen. Anyone who can turn on the computer and fire up a browser could do it.

One could argue that Google is the main source of our online identity brand. Most of the world uses it as the starting point for search. Most people have "Googled" themselves at some point. Most importantly, other people have also "Googled" you at some point in time (e.g. employers). How do we attempt to "control" our online identity brand in the more generic sense? Unless ClaimID becomes some sort of standard (I'm sure they'd be extremely happy if that happened) and they improve some of their processes (e.g. the verification step), we've got this potentially large (I won't say huge...yet) problem on the horizon that no one has started to look at solving properly yet. Or to put it another way, we've got a few companies out there trying to do something about this in isolation, but we know what happens when things get done in isolation don't we? They don't get solved...or they take a VERY LONG TIME to come to some sort of resolution because we end up with many different methods to do the same thing.

The point I'm trying to make is that in this case, it's our reputation at stake. One could argue that our reputation is worth more than anything financial. It's MUCH more difficult to recover from a damaged reputation than it is to recover from a financial loss.

I don't claim to have the answers, but I'll continue to ponder the issues and comment on them from time to time. I'm simply stating that this is on the horizon and will need to be looked at. Anyone want to put their hand up? You guys at Google labs reading this (ha! I can only hope) want to volunteer?