Posts tonen met het label twitter. Alle posts tonen
Posts tonen met het label twitter. Alle posts tonen

vrijdag 13 mei 2016

That was the EIC16 that was


Each year, the German security consultancy firm KuppingerCole in Munich is organizing a multi-day conference on the theme of identity and access management.
The KC conference was well organized. Nice location for both sessions and the inevitable vendor marketplace. Lovely brochures, event app, fine catering and a lot of famous people. We'll get back to that later. KC is a large company, has many expert analysts and these are actively present. They moderate panels, are chairing different tracks and give presentations.

The conference lasts three days, long days ... the first keynote generally starts at half past eight and the day closing somewhere between 19 and 20. But that's not all, there are also pre- and post-conference workshops. I decided to join a preconf day this year, namely the workshop on the theme blockchain. I cannot give a full overview of the conference, but I will point to a few highlights.

The hype of this moment is Blockchain. The pre-conference workshop lasted a whole day and treated the backgrounds and ideas around Blockchain and also bitcoin. Also on the third day there was extensive attention given to blockchain in one of the four parallel tracks. Briefly: Blockchain is a promising technology (immutable storage of transactions, transparent, fast and cheap), but so far it’s little used (not really an anonymous platform, ‘bitcoin image’ is not very positive). But biggest problem is the issue of trust. Can you trust the blockchain, do you trust the longevity and continuity? But the advice is: go play with it, within a year or three there are business cases and apps to make use of blockchain technology.

Second hype: CIAM, customer Identity & Access Management. And yet, actually not quite a hype, we have already know,  implement and use it. More importantly is the underlying mechanism, namely federation.

More or less the same applies to IoT and Big Data. These developments also look at federated solutions to preserve both the business benefits and guarantees regarding privacy.

Federation was not only reflected in many presentations. There was a separate track in which the OpenID Foundation presented the many developments. Of course there was OpenID Connect (yes, we really should implement this as often and as broad as possible) and OIX (OpenId Exchange, it so looks like the implementation of what I wished for in my old blogs - http://id-use.blogspot.com/2008/06/trust-model-for-identity-providers.html ), but also a number of working groups on the themes of health (the OpenID Heart working group led by Eve Maler of Forgerock) and the Financial Services API WG.

But not everything topic at EIC16 was about IAM technology, unquestionable the most impressive presentation was by Mia Harbitz of the World Bank. She described identity management in a world where a birth certificate is already a challenge. Children with a birth certificate get a vaccination three times as often as children without a birth certificate. She had more shocking numbers of people without a formal identity, without access to life saving services because of it.

Providing an identity to refugees is also a hot topic (especially in Germany, with 800,000 refugees in the past year). This was discussed in a separate track with an interesting panel discussion. It soon turned out that we give refugees an identity because we want to avoid them actually abusing the services paid by us. Not because we want to offer our refugees just enough identity to survive. Sad really ...

An interesting development was an initiative by Ian Glazer (Salesforce). He and Kantara (for example known for User Managed Access – we should make this a default way of customer access control) took the initiative to investigate whether the Identity professionals can unite. The "Keepers of Identity" are increasingly more import, cooperation is essential. More info: https://kantarainitiative.org/digital_identity_professional/

And for those of us who are in despair… there are still use cases for on premise use of Active Directory. Kim Cameron (Microsoft) sees a shift to Azure AD, but an on premise AD will still remain for the coming years.

These were intense days. I finally met with many digital friends. And I advise you to look up the hashtag #eic16 on twitter. Lots of nice tweets, many photos and video’s and links to interesting articles.

And do yourself a pleasure and visit the blog of my good friend Alessandro Festa...


vrijdag 11 januari 2013

Responsible Disclosure


These days in The Netherlands several initiatives pop-up around the issues of ethical hacking and Responsible Disclosure.

What's all the fuss about?
Last year a hacker reported a vulnerability and a data leak in a back-up server of a Dutch hospital. He claimed that he found a lot of confidential information on a server that was readily accessible from the internet. The report was made through a Dutch journalist, +Brenno de Winter.
After publishing the incident we learned that the hospital sued the hacker and for us, the security community, this was unheard of: why sue someone who reports a vulnerability? Who are the amateurs responsible for this leak and do they really think they can get away by suing a security researcher?

In the mean time the minister of Internal Affairs published his guidelines for ethical hacking. And in those guidelines a hacker might be exempt from prosecurtion if he acted conform.

So, we, the Dutch security community, were puzzled. Then rumors came in that the hacker had installed malware on the hospital's server. Sentiment changed, but despite the new guidelines, trust of the hacker community in the authorities, like the DA responsible for cyber crime, vanished. Trust was gone and so was the willingness to co-operate. And right after, some critics of the official guidelines raised their voices and it looked like the guidelines were no longer valid for the people that were addressed in the guidelines.

At this moment this is the status:

And that's not all, there is at least one more initiative, but that's not yet ready for prime time yet.

Anyway a lot of activity in interesting times. Please have a look at Floor's site and feel free to react!

I will try to publish some more about all activity and invite you to join the discussion.



maandag 19 november 2012

I shared an email with you

Twitter introduced an interesting new feature, emailing a tweet that you think might be of interest to someone else. Twitter lets you send an email straight from the Twitter web interface. If you choose so, up pops a browser window that lets you enter the email address of the recipient and enter some text next to the tweet. Press a button and Twitter takes care of sending the tweet.

Why does this bother me?
Some time ago I wrote a blog entry about Behavior centric identity management. I said that my Identity is constructed using several components, one of which is my behavior. You may know my name, or my interests, my relations, my work, whatever, but the more aspects of me you know, the better you know the real me, the closer you come to the real me. In order to be in control of the real me, for me this means seperating these components as much as possible. That's why I use netvibes rss aggregator (that knows about my areas of interest) instead of iGoogle (that will disappear anyway).

My Twitter handle is one of my identity components, just like my email relations. And the tweeps I follow are not randomly chosen, no, they are part of my identity too. But Twitter is just an instrument for me to use and Twitter has got nothing to do with my other identity components.

But now that they started offering an email facility, they have to possibility to combine my separate identity components. They can combine my areas of interest (the tweet that I want to share) and my non-Twitter relations (this function is obviously meant to reach non.tweeps, otherwise a simple RT would do). It's an effective interest aggregator.  The email sent contains lots of information, but most important is that Twitter owns the mail server. And Twitter is the owner of the sent email message.

Twitter could of course offer the email button and start my email client, just as easy, and they would never know to whom I would like to send a tweet. But by implementing the email facility like they did, they are in the middle of my communication channel with a non-Tweep. They know that my Twitter ID is interested in informing a non Twitter identity about a certain subject.

Since Twitter is becoming the on-line memory for our thoughts, I don't think that Twitter will remove all emails and temp files, do you?