Recently a few service providers initiated their Real Name policy. They require their users to use their real name in order to be able to use the services. Google+ and Facebook prohibit the use of an alias as a name. One of the most famous victims is Identity Woman. The service providers claim that the use of the real name of users helps creating more trust on the Internet. There are several reasons why this reasoning looks invalid, it looks as if there's another agenda. I will get to that later on in this post.
Of course these service providers allow you to use services like email, chat, socializing and so on. And until a few months ago these features seem to work for the Internet community. I can chat with other people. And I connect with them based on the information from within my network (about the reputation of these new connections), or based on their previous work (that I found using other Internet services), or even based on me knowing the person in real life. In no way does the real name of Internet users in my network have anything to do with me trusting them, trust is based on other parameters, reputation and performance being the most important.
A bizarre phenomenon is that many years ago I could open a Gmail account, using any stupid account name that I could imagine. Never ever did Google ask me to prove my identity as a person, and never would they claim that my mail is reliable or trustworthy. Of course they can't, because they don't know me in person and because I never needed a trustworthy email account in the first place, I just wanted a free web based communication facility. And now that they added + to my mail, they claim that all my communication will be more trustworthy if I use a different, real name.
These service providers have a point in a way that they manage to position themselves not only as a service provider, but as an identity provider, one of the major parties in a trust framework. Their users can use these identities towards other service providers, using protocols like OpenID and OAuth. But here they fail to understand that a digital identity, such as a + name, is just one of the identities that I, as a natural person, have. I have plenty more. G+ is not my real identity and you should not trust it, since this identity provider doesn't know me.
But, that's not all true. Google does know me, in the digital world. They know my interests and behavior based on my digital history. They know what I'm looking for and what other identities I have relations with. And this knowledge is valuable in exploiting their core advertising business, this knowledge is their business model. I get to use their services for free and they get to know me in order to let their commercial partners contact me for relevant offers. A fair deal, but trust is in no way a concern. I create my own network and I use the services that I want.
But how can these Googles and Facebooks earn more money? When digital identities are connected to real life consumers, ad campaigns have a higher return, these campaigns can be more relevant. And so ads are more valuable, resulting in higher earnings. That's their new business case, their new hight profit business model: connecting digital identities to real life individuals.The providers claim to help create more trust. By now they should know better. Diginotar proves that trust is not a technical issue, It's a people thing. And requiring real names does not help. In fact it is a new threat to my freedom in choosing the services that I want to use, in connecting to whoever I like and to be on the Internet who and what I like to be. Sometimes anonymity is not bad and sometimes an unreal name is more secure.
Posts tonen met het label laws of identity. Alle posts tonen
Posts tonen met het label laws of identity. Alle posts tonen
woensdag 21 september 2011
maandag 15 december 2008
Behavior centric identity management
What's the problem with people knowing my identity attributes, my personal data? Okay, not all data are public, but why should I hide my identity? What personal data should I protect?
I have been thinking about this privacy thing a lot lately. Partly because we have to protect privacy stuff by law. But we protect all information, you might say that all privacy data are protected implicitly if we live by our security policy, right?
The reasoning behind my thoughts is that there are several initiatives to use authentication services like OpenID. And I hesitate. And you know, the problem is that I want to keep my behavior private. That's it, I don't mind third parties knowing me, or part of me, but what I do, that's my business. What I do may lead to some status change of my identity, and that may be publicly known, but my behavior is mine.
We have been exploring some identity aspects and perhaps that we will be able to classify security requirements based on identity aspects.
We learned about Identity DNA, fixed attributes, like name, sexe, date of birth, even Social Security Number. The data elements will (almost) never change. It is so fixed, that it is even public, so why protect the confidentiality aspect?
Next you might talk about Identity Status, information that will change. Like an address, phone number, relationships (even commercial relations, like "customer of", the data that is to be protected because of privacy laws?). Protecting confidentiality might not be needed for all identities by default, but it may be economic to do so.
And then there must be something like Identity Behavior. This must be the most sensitive part of identity data. This is the knowledge part. That's why voting machines are no go right now. That's why financial and medical information are valuable. I want to protect this information. I don't care about my identity DNA, can't change that, but the acts of my identity are personal. Publishing my identity status is my responsibility (I can move, or not, get a new job or not), it's public within the context of my identity, but what I do whit it is my business.
So much for now, perhaps this is way to academic. But at least I got it off my chest.
I have been thinking about this privacy thing a lot lately. Partly because we have to protect privacy stuff by law. But we protect all information, you might say that all privacy data are protected implicitly if we live by our security policy, right?
The reasoning behind my thoughts is that there are several initiatives to use authentication services like OpenID. And I hesitate. And you know, the problem is that I want to keep my behavior private. That's it, I don't mind third parties knowing me, or part of me, but what I do, that's my business. What I do may lead to some status change of my identity, and that may be publicly known, but my behavior is mine.
We have been exploring some identity aspects and perhaps that we will be able to classify security requirements based on identity aspects.
We learned about Identity DNA, fixed attributes, like name, sexe, date of birth, even Social Security Number. The data elements will (almost) never change. It is so fixed, that it is even public, so why protect the confidentiality aspect?
Next you might talk about Identity Status, information that will change. Like an address, phone number, relationships (even commercial relations, like "customer of", the data that is to be protected because of privacy laws?). Protecting confidentiality might not be needed for all identities by default, but it may be economic to do so.
And then there must be something like Identity Behavior. This must be the most sensitive part of identity data. This is the knowledge part. That's why voting machines are no go right now. That's why financial and medical information are valuable. I want to protect this information. I don't care about my identity DNA, can't change that, but the acts of my identity are personal. Publishing my identity status is my responsibility (I can move, or not, get a new job or not), it's public within the context of my identity, but what I do whit it is my business.
So much for now, perhaps this is way to academic. But at least I got it off my chest.
maandag 11 augustus 2008
Abonneren op:
Posts (Atom)
