Re: [foaf-dev] Credentials Community Group
Tim Holborn <[email protected]> Thu, 31 Jul 2014 16:24:00 +1000
| Newsgroups | gmane.comp.web.rdfweb |
|---|---|
| Message-ID | <[email protected]> |
--===============4454027238677641716== Content-Type: multipart/alternative; boundary="Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5" --Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=windows-1252 Hi Manu, I=92m really pleased to see the initiative set-up to form a community = that=92s seemingly designed to focus on identity issues specifically, = rather than the use of identity in trade use-cases. Potentially a great = outcome. I=92m therefore hoping the notes below can be assessed, = considered and perhaps put into more cognoscente set of considerations = overall.. I haven=92t seen any references supporting loosely coupled identifiers = (i.e. private associations between the proposed identity credential = tools - and psudo-anonymity / loosely coupled identifiers). I refer back to = http://www.verisigninc.com/en_US/innovation/verisign-labs/speakers-series/= evolution-of-internet/index.xhtml (particularly @23minutes - but the = whole thing is good) This in-turn relates to issues such as =91choice of law=92, when = signing-up to site services and an array of other more sophisticated = problems / considerations, that perhaps people generally could better = understand as a constituent of entering into any-such agreements.=20 I also note that WebID and FOAF is not listed in the proposal, nor are = what i=92d term =91data-rights declarations=92 listed in the scope of = work. In terms of =92safety=92 (per the video above) or security, i = think the ability to include other identity related =91linked-data=92 = issues - such as methods for credential holders to make declaration = about the use-expectations for information/data provided to 3rd parties; = and, the ability to not require individuals to unnecessarily disclose = identity information. Inclusively providing means to beneficially = support protection of individuals, whilst still establishing new = identity related tools (which in-turn bring new safety issues for = web-users). In effect, a more holistic approach may benefit the = requirements (and/or intent) pursuant to other safety issues inclusive = to identity and authentication, whether explicit or implicit; and, as = described in precedent requirements such as KYC / AML.=20 Without the use of identity for authentication - the identity credential = itself becomes useless. =20 =92not everyone needs to know or see everything=92.=20 It seems that the authentication principles (inc. systems) also form = important elements of the identity credentials lifecycle. I=92ve been = constructing concept of =91data rights=92, which has yielded some = interest already - and i=92m yet to find a technical home for it, though = i believe could fit in well to a W3 CG that=92s appropriately broad in = its considerations of personal identity requirements. =20 Therein; some of the =91data rights' ontological concepts i=92ve = considered include, Data:Reuse Data:Accessibility Data:Security Data:Privacy Data:Sovereignty=20 Data:Storage I note that in my research i=92ve found that organisations may suffer = from the costs incurred if / when privacy (or other) legislation is = passed by a state, incurring new obligations that in-turn need to be = enacted through DB related SYSADMIN tasks. therein, the capacity for = individuals to be presented with choices (perhaps also incentives for = different types of choices - i.e. join the loyalty program get 10% = discount, free-updates, etc.) assists all parties involved in the = transaction. I think in other instances, it=92s a bit like seeing = advertising your actually interested in - or ensuring the direct mail is = being received by people, not dumped into the virtual dumpster - which = is a waste of energy, if not to consider other issues therein. Finally - these standards most affect individuals, who are not = ordinarily paid-up members of W3C. The membership of W3C in-turn have = fiduciary requirements around what they need, in-order to comply with = law. Due to the truly amazing behaviours, works and passion - arguably = for furthering humanity (can=92t think of a way to summarise it - i=92ve = started considering the concepts around how we all share WWW = citizenship..) the platform exists, as may not have been the case should = some of the initial decisions have been different.. The motivations = were designed to help organisations, by empowering people to communicate = more effectively. =20 I find "Network Theory Seminar with Tim Berners-Lee=94 presentation = https://twitter.com/WebCivics/status/492707794760392704 (the = https://twitter.com/WebCivics/ will be resourcing an array of links = around this territory of consideration / =91web science=92) quite = grounding; and in-turn, we are certainly at a stage where identity, the = digital treatment of persons is a massive issue, on so very many levels. = This area is a can of worms. So my $0.02c (or currently about = 0.03488uBTC) would be that credentials is an element of identity and = personal permissions standards - or - regardless of the name - perhaps = your scope is a little too narrow, as to best serve the needs of its = intended beneficiaries. - Authentication is required to create =91barriers=92 around someone who = is not you, =91authenticating=92 as you - on computing systems. - Permissions are required so that we=92re not entrapping people into = things they=92re otherwise not required to do. - Personal - is different from any act you make, in association to = others whether acting as an agent or a member of the community. Identity is more broadly nebulous, a concept of study in many social = sciences / liberal arts - manifestly, something that is not digital or = binary. YET, we have credentials and identifiers, or 'footprints'=85 = We are legally recognised entities - or at least, we should be. =20 inclusive concepts of course: include, the rights, privileges and = responsibilities of citizenship and social participation; yet, then it = starts to become more complicated. In this world, without economic = recognition - people can barely subsist.=20 Access to justice for incorporated entities, vs. access to justice for = the majority of WWW citizens is not reasonably equal. large companies = and individuals have issues sharing intellectual property, without a = ledger - who knows who did what first; generally, the individual does = not have a legal department, yet equally perhaps they=92ve got some = strategy that could waste alot of time and shareholder money - or = perhaps, someone had a KPI that they found difficult to meet without = =91cutting corners=92. =20 when dealing with identity - at this level no less - I think it=92s = imperative that we ensure the scope is defined in a manner that = holistically ensures =91duty of care=92, as we are able to discharge as = professional - community members - on a best-efforts basis, to make an = attempt that our work is defined in such a way that it seeks not = diminish the responsibility or opportunity of any party, to act in = good-faith and to maintain our responsibilities as citizens throughout = our affairs, including those in which we act as an authorised = representative and/or agent - for an incorporated entity.=20 =20 love it or hate it - most things that affect us has an economic = price-tag, whether that rational has been realised, is yet to become = realised or has become subject to barriers and may be unaccessible.=20 FUNCTIONAL I note an array of community initiatives. https://webwewant.org/ http://webfoundation.org/ http://www.purpose.com/ (noting that many others exist=85) I=92m also working on this concept called =91web civics=92 which aims to = create events that link =91locals=92 with =91international experts=92, = help finish product produced by scientists such as those on these lists, = etc.=20 I=92ve found that people are engaging me about these sorts of issues and = that the most interesting conversations are with people who are = consummate professionals, in different (and sometimes related or = complimentary) fields. I feel it=92s important to develop these = conversations, build social bridges. Yet when it gets down to functional - the concepts need to be converted = into standards, and i believe supporting W3C Community group works - is = the best possible method to get that work done. Perhaps, this is = misguided - not sure. ATM i can see an array of different groups = looking at identity related issues. =46rom the persistent messages = about different crypto standards, to ontological debates, messaging = standards (i.e.: serialisation methods - turtle vs. json-ld), etc. underlying some of these issues is most likely a host of patent / IPR = issues, etc. If,=20 W3 participants specialised in this field - no matter where in the = ideological spectrum they=92re focused upon - can accumulatively = collaborate / cooperate - towards a standard that can support an array = of different use-cases (focused on the use of Linked-Data / RDF / = including decentralised web tech.) then, i believe the potential for = standards work could have enormously beneficial implications. However - I equally understand that this may in-turn bring about a = resourcing issue. To which, a largely philosophical strategy might need = to be deployed in considering how these needs be met. =20 =20 On 31 Jul 2014, at 2:03 pm, Manu Sporny <msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]> = wrote: > For those of you that may have missed it in the minutes, we believe we > now have enough momentum to launch a Credentials Community Group at = W3C > to take over the identity/credentials use cases and technology that = this > group has been working on for a few years now. >=20 > There has been concern voiced that this group would be side-tracked by > much of the identity/credentials work. We now believe that we've found > some other organizations in the payments, education, and government ID > spaces that would like to lead the work (ensuring that the identity = use > cases related to payment continue to be supported). The proposed = charter > for that group is here: >=20 > = https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr522nBWCjLJMQ_vGbbtsA5= -pAsg/edit >=20 > Please provide input on the charter. It's heavily modeled on the = charter > for this group (so if you like the way this group is run, you should > like the way that group is run). >=20 > The discussion around the formation of the group starts here: >=20 > https://web-payments.org/minutes/2014-07-30/#2 >=20 > -- manu >=20 > --=20 > Manu Sporny (skype: msporny, twitter: manusporny, G+: +Manu Sporny) > Founder/CEO - Digital Bazaar, Inc. > blog: The Marathonic Dawn of Web Payments > http://manu.sporny.org/2014/dawn-of-web-payments/ >=20 --Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=windows-1252 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html = charset=3Dwindows-1252"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">Hi = Manu,<div><br></div><div>I=92m really pleased to see the initiative = set-up to form a community that=92s seemingly designed to focus on = identity issues specifically, rather than the use of identity in trade = use-cases. Potentially a great outcome. I=92m therefore = hoping the notes below can be assessed, considered and perhaps put into = more cognoscente set of considerations = overall..</div><div><br></div><div>I haven=92t seen any references = supporting loosely coupled identifiers (i.e. private associations = between the proposed identity credential tools - and psudo-anonymity / = loosely coupled identifiers).</div><div><br></div><div>I refer back = to <a = href=3D"http://www.verisigninc.com/en_US/innovation/verisign-labs/speakers= -series/evolution-of-internet/index.xhtml">http://www.verisigninc.com/en_U= S/innovation/verisign-labs/speakers-series/evolution-of-internet/index.xht= ml</a> (particularly @23minutes - but the whole thing is = good)</div><div><br></div><div>This in-turn relates to issues such as = =91choice of law=92, when signing-up to site services and an array of = other more sophisticated problems / considerations, that perhaps people = generally could better understand as a constituent of entering into = any-such agreements. </div><div><br></div><div>I also note that = WebID and FOAF is not listed in the proposal, nor are what i=92d term = =91data-rights declarations=92 listed in the scope of work. In = terms of =92safety=92 (per the video above) or security, i think the = ability to include other identity related =91linked-data=92 issues - = such as methods for credential holders to make declaration about the = use-expectations for information/data provided to 3rd parties; and, the = ability to not require individuals to unnecessarily disclose identity = information. Inclusively providing means to beneficially support = protection of individuals, whilst still establishing new identity = related tools (which in-turn bring new safety issues for web-users). = In effect, a more holistic approach may benefit the requirements = (and/or intent) pursuant to other safety issues inclusive to identity = and authentication, whether explicit or implicit; and, as described in = precedent requirements such as KYC / = AML. </div><div><br></div><div><div>Without the use of identity for = authentication - the identity credential itself becomes useless. = </div></div><div><br></div><div>=92not everyone needs to = know or see everything=92. </div><div><br></div><div>It seems that = the authentication principles (inc. systems) also form important = elements of the identity credentials lifecycle. I=92ve been constructing = concept of =91data rights=92, which has yielded some interest already - = and i=92m yet to find a technical home for it, though i believe could = fit in well to a W3 CG that=92s appropriately broad in its = considerations of personal identity requirements. = </div><div><br></div><div>Therein; some of the =91data rights' = ontological concepts i=92ve considered = include,</div><div><br></div><div><div>Data:Reuse</div><div>Data:Accessibi= lity</div><div>Data:Security</div><div>Data:Privacy</div><div>Data:Soverei= gnty </div><div>Data:Storage</div></div><div><br></div><div>I note = that in my research i=92ve found that organisations may suffer from the = costs incurred if / when privacy (or other) legislation is passed by a = state, incurring new obligations that in-turn need to be enacted through = DB related SYSADMIN tasks. therein, the capacity for individuals to be = presented with choices (perhaps also incentives for different types of = choices - i.e. join the loyalty program get 10% discount, free-updates, = etc.) assists all parties involved in the transaction. I think in = other instances, it=92s a bit like seeing advertising your actually = interested in - or ensuring the direct mail is being received by people, = not dumped into the virtual dumpster - which is a waste of energy, if = not to consider other issues therein.</div><div><br></div><div>Finally - = these standards most affect individuals, who are not ordinarily paid-up = members of W3C. The membership of W3C in-turn have fiduciary = requirements around what they need, in-order to comply with law. = Due to the truly amazing behaviours, works and passion - arguably = for furthering humanity (can=92t think of a way to summarise it - i=92ve = started considering the concepts around how we all share WWW = citizenship..) the platform exists, as may not have been the case should = some of the initial decisions have been different.. The = motivations were designed to help organisations, by empowering people to = communicate more effectively. </div><div><br></div><div>I find = "Network Theory Seminar with Tim Berners-Lee=94 presentation <a = href=3D"https://twitter.com/WebCivics/status/492707794760392704">https://t= witter.com/WebCivics/status/492707794760392704</a> (the <a = href=3D"https://twitter.com/WebCivics/">https://twitter.com/WebCivics/</a>= will be resourcing an array of links around this territory of = consideration / =91web science=92) quite grounding; and in-turn, we are = certainly at a stage where identity, the digital treatment of persons is = a massive issue, on so very many levels. This area is a can of = worms. So my $0.02c (or currently about 0.03488uBTC) would be that = credentials is an element of identity and personal permissions standards = - or - regardless of the name - perhaps your scope is a little too = narrow, as to best serve the needs of its intended = beneficiaries.</div><div><br></div><div>- Authentication is required to = create =91barriers=92 around someone who is not you, =91authenticating=92 = as you - on computing systems.</div><div>- Permissions are required so = that we=92re not entrapping people into things they=92re otherwise not = required to do.</div><div>- Personal - is different from any act you = make, in association to others whether acting as an agent or a member of = the community.</div><div><br></div><div>Identity is more broadly = nebulous, a concept of study in many social sciences / liberal arts - = manifestly, something that is not digital or binary. YET, we have = credentials and identifiers, or 'footprints'=85 We are legally = recognised entities - or at least, we should be. = </div><div><br></div><div>inclusive concepts of course: include, = the rights, privileges and responsibilities of citizenship and social = participation; yet, then it starts to become more complicated. In = this world, without economic recognition - people can barely = subsist. </div><div><br></div><div>Access to justice for = incorporated entities, vs. access to justice for the majority of WWW = citizens is not reasonably equal. large companies and individuals have = issues sharing intellectual property, without a ledger - who knows who = did what first; generally, the individual does not have a legal = department, yet equally perhaps they=92ve got some strategy that could = waste alot of time and shareholder money - or perhaps, someone had a KPI = that they found difficult to meet without =91cutting corners=92. = </div><div><br></div><div>when dealing with identity - at this = level no less - I think it=92s imperative that we ensure the scope is = defined in a manner that holistically ensures =91duty of care=92, as we = are able to discharge as professional - community members - on a = best-efforts basis, to make an attempt that our work is defined in such = a way that it seeks not diminish the responsibility or opportunity of = any party, to act in good-faith and to maintain our responsibilities as = citizens throughout our affairs, including those in which we act as an = authorised representative and/or agent - for an incorporated = entity. </div><div> </div><div>love it or hate it - most = things that affect us has an economic price-tag, whether that rational = has been realised, is yet to become realised or has become subject to = barriers and may be = unaccessible. </div><div><br></div><div>FUNCTIONAL</div><div><br></di= v><div>I note an array of community = initiatives.</div><div><br></div><div><a = href=3D"https://webwewant.org/">https://webwewant.org/</a></div><div><a = href=3D"http://webfoundation.org/">http://webfoundation.org/</a></div><div= ><a = href=3D"http://www.purpose.com/">http://www.purpose.com/</a></div><div><br= ></div><div>(noting that many others = exist=85)</div><div><br></div><div>I=92m also working on this concept = called =91web civics=92 which aims to create events that link =91locals=92= with =91international experts=92, help finish product produced by = scientists such as those on these lists, = etc. </div><div><br></div><div>I=92ve found that people are = engaging me about these sorts of issues and that the most interesting = conversations are with people who are consummate professionals, in = different (and sometimes related or complimentary) fields. I feel = it=92s important to develop these conversations, build social = bridges.</div><div><br></div><div>Yet when it gets down to functional - = the concepts need to be converted into standards, and i believe = supporting W3C Community group works - is the best possible method to = get that work done. Perhaps, this is misguided - not sure. = ATM i can see an array of different groups looking at identity = related issues. =46rom the persistent messages about different = crypto standards, to ontological debates, messaging standards (i.e.: = serialisation methods - turtle vs. json-ld), = etc.</div><div><br></div><div>underlying some of these issues is most = likely a host of patent / IPR issues, = etc.</div><div><br></div><div>If, </div><div><br></div><div>W3 = participants specialised in this field - no matter where in the = ideological spectrum they=92re focused upon - can accumulatively = collaborate / cooperate - towards a standard that can support an array = of different use-cases (focused on the use of Linked-Data / RDF / = including decentralised web tech.) then, i believe the potential for = standards work could have enormously beneficial = implications.</div><div><br></div><div>However - I equally = understand that this may in-turn bring about a resourcing issue. = To which, a largely philosophical strategy might need to be = deployed in considering how these needs be met. = </div><div><br></div><div><br></div><div><br></div><div> <br><d= iv><div>On 31 Jul 2014, at 2:03 pm, Manu Sporny <<a = href=3D"mailto:msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]">msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]</a>>= ; wrote:</div><br class=3D"Apple-interchange-newline"><blockquote = type=3D"cite">For those of you that may have missed it in the minutes, = we believe we<br>now have enough momentum to launch a Credentials = Community Group at W3C<br>to take over the identity/credentials use = cases and technology that this<br>group has been working on for a few = years now.<br><br>There has been concern voiced that this group would be = side-tracked by<br>much of the identity/credentials work. We now believe = that we've found<br>some other organizations in the payments, education, = and government ID<br>spaces that would like to lead the work (ensuring = that the identity use<br>cases related to payment continue to be = supported). The proposed charter<br>for that group is here:<br><br><a = href=3D"https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr522nBWCjLJMQ_= vGbbtsA5-pAsg/edit">https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr5= 22nBWCjLJMQ_vGbbtsA5-pAsg/edit</a><br><br>Please provide input on the = charter. It's heavily modeled on the charter<br>for this group (so if = you like the way this group is run, you should<br>like the way that = group is run).<br><br>The discussion around the formation of the group = starts = here:<br><br>https://web-payments.org/minutes/2014-07-30/#2<br><br>-- = manu<br><br>-- <br>Manu Sporny (skype: msporny, twitter: manusporny, G+: = +Manu Sporny)<br>Founder/CEO - Digital Bazaar, Inc.<br>blog: The = Marathonic Dawn of Web = Payments<br>http://manu.sporny.org/2014/dawn-of-web-payments/<br><br></blo= ckquote></div><br></div></body></html>= --Apple-Mail=_71F9A8A4-ACFE-4DA3-B644-1DEA54ABB5D5-- --===============4454027238677641716== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ foaf-dev mailing list foaf-dev-RyYwo1q5J+qsOXdr9/[email protected] http://lists.foaf-project.org/mailman/listinfo/foaf-dev --===============4454027238677641716==--