Re: [foaf-dev] aggregation vs trusted proxying; FOAF+SSL etc

Melvin Carvalho <[email protected]> Mon, 2 Jul 2012 21:21:24 +0200
Newsgroups gmane.comp.web.rdfweb
Message-ID <CAKaEYhJ932zeg4zzOa3VTL1wm2K17CvEN0UB-zd73-eG4bME1Q@mail.gmail.com>
--===============8759108155023640111==
Content-Type: multipart/alternative; boundary=bcaec501c5c02a66d104c3ddb46f

--bcaec501c5c02a66d104c3ddb46f
Content-Type: text/plain; charset=ISO-8859-1

On 2 July 2012 21:12, Peter Williams <[email protected]> wrote:

> For years, folks have explored crawlers aggregating data sets - for which
> ontologys assist in that process (amongst other benefits). We have seen
> data APIs form the likes of Facebook, for graphs specified as sets of
> connections to other data sets. And, we have seen sites that enable data
> clouds for individuals, leveraging websso connections to aggregate person
> data and then other datums tied to person entities.
>
> Typically, Microsoft waits till things have matured a bit, before
> releasing mainstream support for things. And,
> dataexplorer.sqlazurelabs.com may be the signal that it thinks things are
> more mainstream than once we thought.
>
> Of course, what I note is that its a hybrid approach, not choosing any one
> winner of a technology or standard (being as happy to parse HTML5 semantic
> markup as use a webAPI, or do a SQL query). but what is interesting is that
> the security model for proxying is built in - with the site's rights to go
> pick up backroom data requiring an OAUTH-like delegation from the user (so
> the site can borrow some of the users privileges). What's then interesting
> beyond that is that the mashup then also participates in extending the
> chain of such delegations (with the privilege to use the new mashup... of
> other downstream sources) being projected up to the consumer of the
> aggregate - who must establish read rights to all the component datasets.
> Two users of the same endpoint may get difference results (much like an old
> X.500 server would correlate results-sets from downstream agents
> differently for each consuming user, according to the security policy of
> the component's namespace)
>
> Its been 6+ months since I looked at  foaf or its security modeling
> research. How are things evolving? Things seemed to be heading the right
> way, with foaf agents acting as security guards to data transformation
> processes, allowing chains of foaf agents to cooperate and enforce some
> users policy as a paricualr network of foaf sources would link up.
>
> Did folks ever complete the cycle, and find the ideal "webby" model for
> all the above (probably with the dynamically generated RDFa having embedded
> the javascript client that implemented the (foaf+ssl) security model on the
> client integrating foaf representations of policy? Did the foaf agent go
> this very "ideal" route, or did it like the Microsoft work take more the
> OAUTH route with token-passing between trusted agents?
>

Hi Peter

I think things are still going strong ...

Some of the discussions have moved to building real world apps and social
platforms, for the read write web.  The mailing list, wiki and group
information is here: feel free to join the group.

http://www.w3.org/community/rww/

I've also put together 4 monthly summary posts of the work we've done
recently at:

http://www.w3.org/community/rww/wiki/Monthly_Updates

enjoy!


>
> _______________________________________________
> foaf-dev mailing list
> foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]
> http://lists.foaf-project.org/mailman/listinfo/foaf-dev
>

--bcaec501c5c02a66d104c3ddb46f
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<br><br><div class=3D"gmail_quote">On 2 July 2012 21:12, Peter Williams <sp=
an dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D"_bl=
ank">[email protected]</a>&gt;</span> wrote:<br><blockquote class=3D"=
gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-=
left:1ex">
For years, folks have explored crawlers aggregating data sets - for which o=
ntologys assist in that process (amongst other benefits). We have seen data=
 APIs form the likes of Facebook, for graphs specified as sets of connectio=
ns to other data sets. And, we have seen sites that enable data clouds for =
individuals, leveraging websso connections to aggregate person data and the=
n other datums tied to person entities.<br>

<br>
Typically, Microsoft waits till things have matured a bit, before releasing=
 mainstream support for things. And, <a href=3D"http://dataexplorer.sqlazur=
elabs.com" target=3D"_blank">dataexplorer.sqlazurelabs.com</a> may be the s=
ignal that it thinks things are more mainstream than once we thought.<br>

<br>
Of course, what I note is that its a hybrid approach, not choosing any one =
winner of a technology or standard (being as happy to parse HTML5 semantic =
markup as use a webAPI, or do a SQL query). but what is interesting is that=
 the security model for proxying is built in - with the site&#39;s rights t=
o go pick up backroom data requiring an OAUTH-like delegation from the user=
 (so the site can borrow some of the users privileges). What&#39;s then int=
eresting beyond that is that the mashup then also participates in extending=
 the chain of such delegations (with the privilege to use the new mashup...=
 of other downstream sources) being projected up to the consumer of the agg=
regate - who must establish read rights to all the component datasets. Two =
users of the same endpoint may get difference results (much like an old X.5=
00 server would correlate results-sets from downstream agents differently f=
or each consuming user, according to the security policy of the component&#=
39;s namespace)<br>

<br>
Its been 6+ months since I looked at =A0foaf or its security modeling resea=
rch. How are things evolving? Things seemed to be heading the right way, wi=
th foaf agents acting as security guards to data transformation processes, =
allowing chains of foaf agents to cooperate and enforce some users policy a=
s a paricualr network of foaf sources would link up.<br>

<br>
Did folks ever complete the cycle, and find the ideal &quot;webby&quot; mod=
el for all the above (probably with the dynamically generated RDFa having e=
mbedded the javascript client that implemented the (foaf+ssl) security mode=
l on the client integrating foaf representations of policy? Did the foaf ag=
ent go this very &quot;ideal&quot; route, or did it like the Microsoft work=
 take more the OAUTH route with token-passing between trusted agents?<br>
</blockquote><div><br>Hi Peter<br><br>I think things are still going strong=
 ...<br>
<br>Some of the discussions have moved to building real world apps and soci=
al platforms, for the=20
read write web.=A0 The mailing list, wiki and group information is here: fe=
el free to join the group.<br>
<br>
<a href=3D"http://www.w3.org/community/rww/">http://www.w3.org/community/rw=
w/</a><br><br>
I&#39;ve also put together 4 monthly summary posts of the work we&#39;ve do=
ne recently at:<br>
<br>
<a href=3D"http://www.w3.org/community/rww/wiki/Monthly_Updates">http://www=
.w3.org/community/rww/wiki/Monthly_Updates</a><br>
<br>
enjoy!<br>=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0p=
x 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
_______________________________________________<br>
foaf-dev mailing list<br>
<a href=3D"mailto:foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]">[email protected]=
ect.org</a><br>
<a href=3D"http://lists.foaf-project.org/mailman/listinfo/foaf-dev" target=
=3D"_blank">http://lists.foaf-project.org/mailman/listinfo/foaf-dev</a><br>
</blockquote></div><br>

--bcaec501c5c02a66d104c3ddb46f--

--===============8759108155023640111==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
foaf-dev mailing list
foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]
http://lists.foaf-project.org/mailman/listinfo/foaf-dev
--===============8759108155023640111==--