Re: [foaf-dev] Credentials Community Group

Tim Holborn <[email protected]> Thu, 31 Jul 2014 16:24:00 +1000
Newsgroups gmane.comp.web.rdfweb
Message-ID <[email protected]>
--===============4454027238677641716==
Content-Type: multipart/alternative; boundary="Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5"


--Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

Hi Manu,

I=92m really pleased to see the initiative set-up to form a community =
that=92s seemingly designed to focus on identity issues specifically, =
rather than the use of identity in trade use-cases.  Potentially a great =
outcome.  I=92m therefore hoping the notes below can be assessed, =
considered and perhaps put into more cognoscente set of considerations =
overall..

I haven=92t seen any references supporting loosely coupled identifiers =
(i.e. private associations between the proposed identity credential =
tools - and psudo-anonymity / loosely coupled identifiers).

I refer back to =
http://www.verisigninc.com/en_US/innovation/verisign-labs/speakers-series/=
evolution-of-internet/index.xhtml  (particularly @23minutes - but the =
whole thing is good)

This in-turn relates to issues such as =91choice of law=92, when =
signing-up to site services and an array of other more sophisticated =
problems / considerations, that perhaps people generally could better =
understand as a constituent of entering into any-such agreements.=20

I also note that WebID and FOAF is not listed in the proposal, nor are =
what i=92d term =91data-rights declarations=92 listed in the scope of =
work.  In terms of =92safety=92 (per the video above) or security, i =
think the ability to include other identity related =91linked-data=92 =
issues - such as methods for credential holders to make declaration =
about the use-expectations for information/data provided to 3rd parties; =
and, the ability to not require individuals to unnecessarily disclose =
identity information. Inclusively providing means to beneficially =
support protection of individuals, whilst still establishing new =
identity related tools (which in-turn bring new safety issues for =
web-users).  In effect, a more holistic approach may benefit the =
requirements (and/or intent) pursuant to other safety issues inclusive =
to identity and authentication, whether explicit or implicit; and, as =
described in precedent requirements such as KYC / AML.=20

Without the use of identity for authentication - the identity credential =
itself becomes useless.  =20

=92not everyone needs to know or see everything=92.=20

It seems that the authentication principles (inc. systems) also form =
important elements of the identity credentials lifecycle. I=92ve been =
constructing concept of =91data rights=92, which has yielded some =
interest already - and i=92m yet to find a technical home for it, though =
i believe could fit in well to a W3 CG that=92s appropriately broad in =
its considerations of personal identity requirements. =20

Therein; some of the =91data rights' ontological concepts i=92ve =
considered include,

Data:Reuse
Data:Accessibility
Data:Security
Data:Privacy
Data:Sovereignty=20
Data:Storage

I note that in my research i=92ve found that organisations may suffer =
from the costs incurred if / when privacy (or other) legislation is =
passed by a state, incurring new obligations that in-turn need to be =
enacted through DB related SYSADMIN tasks. therein, the capacity for =
individuals to be presented with choices (perhaps also incentives for =
different types of choices - i.e. join the loyalty program get 10% =
discount, free-updates, etc.) assists all parties involved in the =
transaction.  I think in other instances, it=92s a bit like seeing =
advertising your actually interested in - or ensuring the direct mail is =
being received by people, not dumped into the virtual dumpster - which =
is a waste of energy, if not to consider other issues therein.

Finally - these standards most affect individuals, who are not =
ordinarily paid-up members of W3C.   The membership of W3C in-turn have =
fiduciary requirements around what they need, in-order to comply with =
law.  Due to the truly amazing behaviours, works and passion - arguably =
for furthering humanity (can=92t think of a way to summarise it - i=92ve =
started considering the concepts around how we all share WWW =
citizenship..) the platform exists, as may not have been the case should =
some of the initial decisions have been different..  The motivations =
were designed to help organisations, by empowering people to communicate =
more effectively. =20

I find "Network Theory Seminar with Tim Berners-Lee=94 presentation =
https://twitter.com/WebCivics/status/492707794760392704  (the =
https://twitter.com/WebCivics/ will be resourcing an array of links =
around this territory of consideration / =91web science=92) quite =
grounding; and in-turn, we are certainly at a stage where identity, the =
digital treatment of persons is a massive issue, on so very many levels. =
 This area is a can of worms.  So my $0.02c (or currently about =
0.03488uBTC) would be that credentials is an element of identity and =
personal permissions standards - or - regardless of the name - perhaps =
your scope is a little too narrow, as to best serve the needs of its =
intended beneficiaries.

- Authentication is required to create =91barriers=92 around someone who =
is not you, =91authenticating=92 as you - on computing systems.
- Permissions are required so that we=92re not entrapping people into =
things they=92re otherwise not required to do.
- Personal - is different from any act you make, in association to =
others whether acting as an agent or a member of the community.

Identity is more broadly nebulous, a concept of study in many social =
sciences / liberal arts - manifestly, something that is not digital or =
binary.  YET, we have credentials and identifiers, or 'footprints'=85  =
We are legally recognised entities - or at least, we should be. =20

inclusive concepts of course: include, the rights, privileges and =
responsibilities of citizenship and social participation; yet, then it =
starts to become more complicated.  In this world, without economic =
recognition - people can barely subsist.=20

Access to justice for incorporated entities, vs. access to justice for =
the majority of WWW citizens is not reasonably equal. large companies =
and individuals have issues sharing intellectual property, without a =
ledger - who knows who did what first; generally, the individual does =
not have a legal department, yet equally perhaps they=92ve got some =
strategy that could waste alot of time and shareholder money - or =
perhaps, someone had a KPI that they found difficult to meet without =
=91cutting corners=92. =20

when dealing with identity - at this level no less - I think it=92s =
imperative that we ensure the scope is defined in a manner that =
holistically ensures =91duty of care=92, as we are able to discharge as =
professional - community members - on a best-efforts basis, to make an =
attempt that our work is defined in such a way that it seeks not =
diminish the responsibility or opportunity of any party, to act in =
good-faith and to maintain our responsibilities as citizens throughout =
our affairs, including those in which we act as an authorised =
representative and/or agent - for an incorporated entity.=20
=20
love it or hate it - most things that affect us has an economic =
price-tag, whether that rational has been realised, is yet to become =
realised or has become subject to barriers and may be unaccessible.=20

FUNCTIONAL

I note an array of community initiatives.

https://webwewant.org/
http://webfoundation.org/
http://www.purpose.com/

(noting that many others exist=85)

I=92m also working on this concept called =91web civics=92 which aims to =
create events that link =91locals=92 with =91international experts=92, =
help finish product produced by scientists such as those on these lists, =
etc.=20

I=92ve found that people are engaging me about these sorts of issues and =
that the most interesting conversations are with people who are =
consummate professionals, in different (and sometimes related or =
complimentary) fields.  I feel it=92s important to develop these =
conversations, build social bridges.

Yet when it gets down to functional - the concepts need to be converted =
into standards, and i believe supporting W3C Community group works - is =
the best possible method to get that work done.  Perhaps, this is =
misguided - not sure.  ATM i can see an array of different groups =
looking at identity related issues.  =46rom the persistent messages =
about different crypto standards, to ontological debates, messaging =
standards (i.e.: serialisation methods - turtle vs. json-ld), etc.

underlying some of these issues is most likely a host of patent / IPR =
issues, etc.

If,=20

W3 participants specialised in this field - no matter where in the =
ideological spectrum they=92re focused upon - can accumulatively =
collaborate / cooperate - towards a standard that can support an array =
of different use-cases (focused on the use of Linked-Data / RDF / =
including decentralised web tech.) then, i believe the potential for =
standards work could have enormously beneficial implications.

However -  I equally understand that this may in-turn bring about a =
resourcing issue.  To which, a largely philosophical strategy might need =
to be deployed in considering how these needs be met. =20



=20
On 31 Jul 2014, at 2:03 pm, Manu Sporny <msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]> =
wrote:

> For those of you that may have missed it in the minutes, we believe we
> now have enough momentum to launch a Credentials Community Group at =
W3C
> to take over the identity/credentials use cases and technology that =
this
> group has been working on for a few years now.
>=20
> There has been concern voiced that this group would be side-tracked by
> much of the identity/credentials work. We now believe that we've found
> some other organizations in the payments, education, and government ID
> spaces that would like to lead the work (ensuring that the identity =
use
> cases related to payment continue to be supported). The proposed =
charter
> for that group is here:
>=20
> =
https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr522nBWCjLJMQ_vGbbtsA5=
-pAsg/edit
>=20
> Please provide input on the charter. It's heavily modeled on the =
charter
> for this group (so if you like the way this group is run, you should
> like the way that group is run).
>=20
> The discussion around the formation of the group starts here:
>=20
> https://web-payments.org/minutes/2014-07-30/#2
>=20
> -- manu
>=20
> --=20
> Manu Sporny (skype: msporny, twitter: manusporny, G+: +Manu Sporny)
> Founder/CEO - Digital Bazaar, Inc.
> blog: The Marathonic Dawn of Web Payments
> http://manu.sporny.org/2014/dawn-of-web-payments/
>=20


--Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=windows-1252

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dwindows-1252"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">Hi =
Manu,<div><br></div><div>I=92m really pleased to see the initiative =
set-up to form a community that=92s seemingly designed to focus on =
identity issues specifically, rather than the use of identity in trade =
use-cases. &nbsp;Potentially a great outcome. &nbsp;I=92m therefore =
hoping the notes below can be assessed, considered and perhaps put into =
more cognoscente set of considerations =
overall..</div><div><br></div><div>I haven=92t seen any references =
supporting loosely coupled identifiers (i.e. private associations =
between the proposed identity credential tools - and psudo-anonymity / =
loosely coupled identifiers).</div><div><br></div><div>I refer back =
to&nbsp;<a =
href=3D"http://www.verisigninc.com/en_US/innovation/verisign-labs/speakers=
-series/evolution-of-internet/index.xhtml">http://www.verisigninc.com/en_U=
S/innovation/verisign-labs/speakers-series/evolution-of-internet/index.xht=
ml</a>&nbsp; (particularly @23minutes - but the whole thing is =
good)</div><div><br></div><div>This in-turn relates to issues such as =
=91choice of law=92, when signing-up to site services and an array of =
other more sophisticated problems / considerations, that perhaps people =
generally could better understand as a constituent of entering into =
any-such agreements.&nbsp;</div><div><br></div><div>I also note that =
WebID and FOAF is not listed in the proposal, nor are what i=92d term =
=91data-rights declarations=92 listed in the scope of work. &nbsp;In =
terms of =92safety=92 (per the video above) or security, i think the =
ability to include other identity related =91linked-data=92 issues - =
such as methods for credential holders to make declaration about the =
use-expectations for information/data provided to 3rd parties; and, the =
ability to not require individuals to unnecessarily disclose identity =
information. Inclusively providing means to beneficially support =
protection of individuals, whilst still establishing new identity =
related tools (which in-turn bring new safety issues for web-users). =
&nbsp;In effect, a more holistic approach may benefit the requirements =
(and/or intent) pursuant to other safety issues inclusive to identity =
and authentication, whether explicit or implicit; and, as described in =
precedent requirements such as KYC / =
AML.&nbsp;</div><div><br></div><div><div>Without the use of identity for =
authentication - the identity credential itself becomes useless. =
&nbsp;&nbsp;</div></div><div><br></div><div>=92not everyone needs to =
know or see everything=92.&nbsp;</div><div><br></div><div>It seems that =
the authentication principles (inc. systems) also form important =
elements of the identity credentials lifecycle. I=92ve been constructing =
concept of =91data rights=92, which has yielded some interest already - =
and i=92m yet to find a technical home for it, though i believe could =
fit in well to a W3 CG that=92s appropriately broad in its =
considerations of personal identity requirements. =
&nbsp;</div><div><br></div><div>Therein; some of the =91data rights' =
ontological concepts i=92ve considered =
include,</div><div><br></div><div><div>Data:Reuse</div><div>Data:Accessibi=
lity</div><div>Data:Security</div><div>Data:Privacy</div><div>Data:Soverei=
gnty&nbsp;</div><div>Data:Storage</div></div><div><br></div><div>I note =
that in my research i=92ve found that organisations may suffer from the =
costs incurred if / when privacy (or other) legislation is passed by a =
state, incurring new obligations that in-turn need to be enacted through =
DB related SYSADMIN tasks. therein, the capacity for individuals to be =
presented with choices (perhaps also incentives for different types of =
choices - i.e. join the loyalty program get 10% discount, free-updates, =
etc.) assists all parties involved in the transaction. &nbsp;I think in =
other instances, it=92s a bit like seeing advertising your actually =
interested in - or ensuring the direct mail is being received by people, =
not dumped into the virtual dumpster - which is a waste of energy, if =
not to consider other issues therein.</div><div><br></div><div>Finally - =
these standards most affect individuals, who are not ordinarily paid-up =
members of W3C. &nbsp; The membership of W3C in-turn have fiduciary =
requirements around what they need, in-order to comply with law. =
&nbsp;Due to the truly amazing behaviours, works and passion - arguably =
for furthering humanity (can=92t think of a way to summarise it - i=92ve =
started considering the concepts around how we all share WWW =
citizenship..) the platform exists, as may not have been the case should =
some of the initial decisions have been different.. &nbsp;The =
motivations were designed to help organisations, by empowering people to =
communicate more effectively. &nbsp;</div><div><br></div><div>I find =
"Network Theory Seminar with Tim Berners-Lee=94 presentation&nbsp;<a =
href=3D"https://twitter.com/WebCivics/status/492707794760392704">https://t=
witter.com/WebCivics/status/492707794760392704</a>&nbsp; (the <a =
href=3D"https://twitter.com/WebCivics/">https://twitter.com/WebCivics/</a>=
 will be resourcing an array of links around this territory of =
consideration / =91web science=92) quite grounding; and in-turn, we are =
certainly at a stage where identity, the digital treatment of persons is =
a massive issue, on so very many levels. &nbsp;This area is a can of =
worms. &nbsp;So my $0.02c (or currently about 0.03488uBTC) would be that =
credentials is an element of identity and personal permissions standards =
- or - regardless of the name - perhaps your scope is a little too =
narrow, as to best serve the needs of its intended =
beneficiaries.</div><div><br></div><div>- Authentication is required to =
create =91barriers=92 around someone who is not you, =91authenticating=92 =
as you - on computing systems.</div><div>- Permissions are required so =
that we=92re not entrapping people into things they=92re otherwise not =
required to do.</div><div>- Personal - is different from any act you =
make, in association to others whether acting as an agent or a member of =
the community.</div><div><br></div><div>Identity is more broadly =
nebulous, a concept of study in many social sciences / liberal arts - =
manifestly, something that is not digital or binary. &nbsp;YET, we have =
credentials and identifiers, or 'footprints'=85 &nbsp;We are legally =
recognised entities - or at least, we should be. =
&nbsp;</div><div><br></div><div>inclusive concepts of course: include, =
the rights, privileges and responsibilities of citizenship and social =
participation; yet, then it starts to become more complicated. &nbsp;In =
this world, without economic recognition - people can barely =
subsist.&nbsp;</div><div><br></div><div>Access to justice for =
incorporated entities, vs. access to justice for the majority of WWW =
citizens is not reasonably equal. large companies and individuals have =
issues sharing intellectual property, without a ledger - who knows who =
did what first; generally, the individual does not have a legal =
department, yet equally perhaps they=92ve got some strategy that could =
waste alot of time and shareholder money - or perhaps, someone had a KPI =
that they found difficult to meet without =91cutting corners=92. =
&nbsp;</div><div><br></div><div>when dealing with identity - at this =
level no less - I think it=92s imperative that we ensure the scope is =
defined in a manner that holistically ensures =91duty of care=92, as we =
are able to discharge as professional - community members - on a =
best-efforts basis, to make an attempt that our work is defined in such =
a way that it seeks not diminish the responsibility or opportunity of =
any party, to act in good-faith and to maintain our responsibilities as =
citizens throughout our affairs, including those in which we act as an =
authorised representative and/or agent - for an incorporated =
entity.&nbsp;</div><div>&nbsp;</div><div>love it or hate it - most =
things that affect us has an economic price-tag, whether that rational =
has been realised, is yet to become realised or has become subject to =
barriers and may be =
unaccessible.&nbsp;</div><div><br></div><div>FUNCTIONAL</div><div><br></di=
v><div>I note an array of community =
initiatives.</div><div><br></div><div><a =
href=3D"https://webwewant.org/">https://webwewant.org/</a></div><div><a =
href=3D"http://webfoundation.org/">http://webfoundation.org/</a></div><div=
><a =
href=3D"http://www.purpose.com/">http://www.purpose.com/</a></div><div><br=
></div><div>(noting that many others =
exist=85)</div><div><br></div><div>I=92m also working on this concept =
called =91web civics=92 which aims to create events that link =91locals=92=
 with =91international experts=92, help finish product produced by =
scientists such as those on these lists, =
etc.&nbsp;</div><div><br></div><div>I=92ve found that people are =
engaging me about these sorts of issues and that the most interesting =
conversations are with people who are consummate professionals, in =
different (and sometimes related or complimentary) fields. &nbsp;I feel =
it=92s important to develop these conversations, build social =
bridges.</div><div><br></div><div>Yet when it gets down to functional - =
the concepts need to be converted into standards, and i believe =
supporting W3C Community group works - is the best possible method to =
get that work done. &nbsp;Perhaps, this is misguided - not sure. =
&nbsp;ATM i can see an array of different groups looking at identity =
related issues. &nbsp;=46rom the persistent messages about different =
crypto standards, to ontological debates, messaging standards (i.e.: =
serialisation methods - turtle vs. json-ld), =
etc.</div><div><br></div><div>underlying some of these issues is most =
likely a host of patent / IPR issues, =
etc.</div><div><br></div><div>If,&nbsp;</div><div><br></div><div>W3 =
participants specialised in this field - no matter where in the =
ideological spectrum they=92re focused upon - can accumulatively =
collaborate / cooperate - towards a standard that can support an array =
of different use-cases (focused on the use of Linked-Data / RDF / =
including decentralised web tech.) then, i believe the potential for =
standards work could have enormously beneficial =
implications.</div><div><br></div><div>However - &nbsp;I equally =
understand that this may in-turn bring about a resourcing issue. =
&nbsp;To which, a largely philosophical strategy might need to be =
deployed in considering how these needs be met. =
&nbsp;</div><div><br></div><div><br></div><div><br></div><div>&nbsp;<br><d=
iv><div>On 31 Jul 2014, at 2:03 pm, Manu Sporny &lt;<a =
href=3D"mailto:msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]">msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]</a>&gt=
; wrote:</div><br class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite">For those of you that may have missed it in the minutes, =
we believe we<br>now have enough momentum to launch a Credentials =
Community Group at W3C<br>to take over the identity/credentials use =
cases and technology that this<br>group has been working on for a few =
years now.<br><br>There has been concern voiced that this group would be =
side-tracked by<br>much of the identity/credentials work. We now believe =
that we've found<br>some other organizations in the payments, education, =
and government ID<br>spaces that would like to lead the work (ensuring =
that the identity use<br>cases related to payment continue to be =
supported). The proposed charter<br>for that group is here:<br><br><a =
href=3D"https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr522nBWCjLJMQ_=
vGbbtsA5-pAsg/edit">https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr5=
22nBWCjLJMQ_vGbbtsA5-pAsg/edit</a><br><br>Please provide input on the =
charter. It's heavily modeled on the charter<br>for this group (so if =
you like the way this group is run, you should<br>like the way that =
group is run).<br><br>The discussion around the formation of the group =
starts =
here:<br><br>https://web-payments.org/minutes/2014-07-30/#2<br><br>-- =
manu<br><br>-- <br>Manu Sporny (skype: msporny, twitter: manusporny, G+: =
+Manu Sporny)<br>Founder/CEO - Digital Bazaar, Inc.<br>blog: The =
Marathonic Dawn of Web =
Payments<br>http://manu.sporny.org/2014/dawn-of-web-payments/<br><br></blo=
ckquote></div><br></div></body></html>=

--Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5--

--===============4454027238677641716==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
foaf-dev mailing list
foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]
http://lists.foaf-project.org/mailman/listinfo/foaf-dev
--===============4454027238677641716==--