Re: [foaf-dev] Credentials Community Group

Peter Williams <[email protected]> Fri, 1 Aug 2014 11:21:27 +0000
Newsgroups gmane.comp.web.rdfweb
Message-ID <222fc5ab2d294ff1a995f01cd7af916b@BN1PR07MB101.namprd07.prod.outlook.com>
--===============1354209655511998733==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_222fc5ab2d294ff1a995f01cd7af916bBN1PR07MB101namprd07pro_"

--_000_222fc5ab2d294ff1a995f01cd7af916bBN1PR07MB101namprd07pro_
Content-Type: text/plain; charset="windows-1256"
Content-Transfer-Encoding: quoted-printable

Have they emerged, or are they just manufactured in lawyerly tradition?

Cannot wait to hear how a w3c culture addresses the morass. If its more of =
the same, then we add another label to the pile.

I like foaf's philosophical approach - allowing lawyerly interpretation of =
a concept, while denying the per eminence of any one interpretation. I like=
 foaf insisting that no identity dogma has relevance to foaf itself - in th=
e sense that foaf exists to verily resist any and all dogma, including what=
ever w3c politics comes up with. Foaf and its spinoffs like webid exist to =
have the continuing conversation and see what logic itself can produce.

Sent from my Windows Phone
________________________________
From: Tim Holborn<mailto:[email protected]>
Sent: =FD7/=FD31/=FD2014 10:44 PM
To: Peter Williams<mailto:[email protected]>
Cc: Manu Sporny<mailto:msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]>; foaf dev<mailto:foaf-dev=
@lists.foaf-project.org>; [email protected]<mailto:[email protected]>; =
Web Payments CG<mailto:[email protected]>; [email protected]<mailto=
:[email protected]>
Subject: Re: [foaf-dev] Credentials Community Group

IMHO - It=92s with misfortune that the identity problems emerge, to form a =
situation that certainly deserves a response.   Yet, fragmenting the identi=
ty elements seems to meet failure.  I think it is such a volatile issue, th=
at as yet - a considered response has not been endeavoured effectively - wh=
ich results in the continuing need to look at it.

Bank and banking - require different capabilities.  I think this may be bes=
t deemed a format that is available to citizens should they seek to act in =
a manner that is lawful or in compliance with their law (of the state / pla=
ce of citizenship? without taking into consideration factors relating to =
=91choice of law=92 and people of other nations signing agreements with int=
ernationally governed entities).

FOAF works for Persona - incredibly well, imo.  I appreciate the technical =
purpose of using the term =91agent=92, yet i also appreciate the legal defi=
nition, and the appropriation of the term more broadly throughout society.

ATM: it=92s legitimate to understand that your Internet Provider can obtain=
 an IP Request from a Website to effectively =91ping=92 the site.  When pur=
chasing an Apple Product - it=92s linked to an online account, with a credi=
t card - which effectively furnishes a similar function.

Yet, a start-up web-business selling say - computer games on the web - migh=
t end-up having their business threatened by =91charge-backs=92, which in-t=
urn stimulates some ideas around how to set-up AML (anti-money laundering) =
/ KYC (know your customer) capabilities, because they=92re sick of sending =
games to scammers.

Yet - this is certainly more complex, and i=92m rather sure - an appropriat=
e solution is not defined yet.  What=92s worse, is that without a solution =
we=92ve ended-up (perhaps) with more problems, as =91tracking=92 and other =
related =91functions=92 of what i think they call =91big data=92, continual=
ly undermine privacy - without actually providing any benefit to natural pe=
rsons.

So - whilst I apologise for the cross-posting - across these groups, we=92v=
e got alot of people thinking about different parts or constituents of iden=
tity and identity related services (including pseudo-anonymity) and it seem=
s reasonable to at least facilitate an opportunity - to seek to get people =
working together on this very important area of dev.

On 1 Aug 2014, at 5:03 am, Peter Williams <[email protected]<mailto:p=
[email protected]>> wrote:

seems VERY un-foaf

The memo sounds like all the same issues that folks used to talk about in t=
he pre-internet EDI world,  which became the billion dollar PKI boondoggle =
of the 2001 era web, and now seems to have re-surfaced in new blob formats =
in the openid connect world - where all the same ideas are being hashed for=
 the 100th time in the last 30 years.

The very think Ive liked about foaf community it that is distinguished itse=
lf from =93ALL THAT=94. it was speciifcally about the web citizen wanting t=
o surf (and who is not some governed entity, some government id, some contr=
acted service client, someone with this our or outrage about some issue, =
=85).


I=92ve certainly been outraged by a few issues.  doesn=92t mean i=92m seeki=
ng to deprive anyone of liberty, human rights, democratic participation, et=
c.   The unfortunate issue, is that some realities in life are taboo - evil=
 happens when good people, still watching, do nothing.  The capacities for =
=91web-citizens=92 - well=85  it=92s a rather serious issue.  we need diffe=
rent perspectives, from different ends of the spectrum, to come-up with thi=
ngs that may not simply require technical solutions in software code, but p=
erhaps also - empowering systems of government to examine issues, and come-=
up with solutions that can help reinforce factors automated via software co=
de.  The ability for someone to give each instance their personal attention=
 - their personal approval - is becoming less, and less relevant.  The mean=
s to deconstruct problems that emerge via automated systems, are equally be=
coming more and more difficult.  Regardless, we have shared values and they=
=92ve been enshrined in documents - such as UN Human Rights conventions - s=
o it=92s not like we=92re starting from a blank canvas.  Regardless, the id=
ea that someone owns IPR around how your identity is recognised by law?  id=
entity issue, recognition of people issues have some very terrible potentia=
l outcomes.  I think we=92re looking to build =91things=92 that help people=
 grow to their fullest potential, in contributing to man-kind, in their way=
 - doesn=92t matter if they=92re out giving soup to local homeless people, =
or standing on some stage speaking of rights, dignity and opportunity.  It =
starts to get ideological from therein.

If systems are deployed that bind a persons identity via HTTP - then if it=
=92s not made with the capacity to support pseudo-anonymity, i don=92t thin=
k it matters which ontology you prefer.  Fundamentally - their is a differe=
nce between systems built for relational database methods; and, those devel=
oped for graph database methods.  I like many parts of the world; but my pa=
ssport and birth-certificate says i=92m Australian.  I=92d like to send an =
secured message that is date-stamped, in a manner that makes it as useful a=
s a patent document.  I=92m sure other =91inventors=92 who don=92t have the=
 ~500k to secure patent protection for different forms of work would also l=
ike some other means for recognition.  I=92d also like to ensure that if an=
 external influencer, not trackable by a system - unreasonably damages a pe=
rsons identifiers on the system - means are defined in-order to reasonably =
figure things out.  Equally, those who have mental-health care issues - per=
haps a bad period of time, that shouldn=92t damage their capacity to be emp=
loyed.  Or means to protect vulnerable people who are threatened or harmed =
by acts that are illegal and materially damaging to others, but formerly pe=
rhaps - without the interest - the technology never applied to help such pe=
ople, almost like an ideological decision.

It=92s a complicated area.  i see the need for the credentials capability, =
but it needs to be well thought out, and i figured sending this note might =
be a positive step rather than an ignorant or thoughtless reception, to wha=
t i believe is a very complex area with a gap-analysis that doesn=92t come-=
up with a very positive review.

TimH.

Sent from Surface Pro

From: Tim Holborn<mailto:[email protected]>
Sent: =FDWednesday=FD, =FDJuly=FD =FD30=FD, =FD2014 =FD11=FD:=FD28=FD =FDPM
To: Manu Sporny<mailto:msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]>
Cc: foaf dev<mailto:foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]>, [email protected]<m=
ailto:[email protected]>, Web Payments CG<mailto:[email protected]=
g>, [email protected]<mailto:[email protected]>

Hi Manu,

I=92m really pleased to see the initiative set-up to form a community that=
=92s seemingly designed to focus on identity issues specifically, rather th=
an the use of identity in trade use-cases.  Potentially a great outcome.  I=
=92m therefore hoping the notes below can be assessed, considered and perha=
ps put into more cognoscente set of considerations overall..

I haven=92t seen any references supporting loosely coupled identifiers (i.e=
. private associations between the proposed identity credential tools - and=
 psudo-anonymity / loosely coupled identifiers).

I refer back to http://www.verisigninc.com/en_US/innovation/verisign-labs/s=
peakers-series/evolution-of-internet/index.xhtml  (particularly @23minutes =
- but the whole thing is good)

This in-turn relates to issues such as =91choice of law=92, when signing-up=
 to site services and an array of other more sophisticated problems / consi=
derations, that perhaps people generally could better understand as a const=
ituent of entering into any-such agreements.

I also note that WebID and FOAF is not listed in the proposal, nor are what=
 i=92d term =91data-rights declarations=92 listed in the scope of work.  In=
 terms of =92safety=92 (per the video above) or security, i think the abili=
ty to include other identity related =91linked-data=92 issues - such as met=
hods for credential holders to make declaration about the use-expectations =
for information/data provided to 3rd parties; and, the ability to not requi=
re individuals to unnecessarily disclose identity information. Inclusively =
providing means to beneficially support protection of individuals, whilst s=
till establishing new identity related tools (which in-turn bring new safet=
y issues for web-users).  In effect, a more holistic approach may benefit t=
he requirements (and/or intent) pursuant to other safety issues inclusive t=
o identity and authentication, whether explicit or implicit; and, as descri=
bed in precedent requirements such as KYC / AML.

Without the use of identity for authentication - the identity credential it=
self becomes useless.

=92not everyone needs to know or see everything=92.

It seems that the authentication principles (inc. systems) also form import=
ant elements of the identity credentials lifecycle. I=92ve been constructin=
g concept of =91data rights=92, which has yielded some interest already - a=
nd i=92m yet to find a technical home for it, though i believe could fit in=
 well to a W3 CG that=92s appropriately broad in its considerations of pers=
onal identity requirements.

Therein; some of the =91data rights' ontological concepts i=92ve considered=
 include,

Data:Reuse
Data:Accessibility
Data:Security
Data:Privacy
Data:Sovereignty
Data:Storage

I note that in my research i=92ve found that organisations may suffer from =
the costs incurred if / when privacy (or other) legislation is passed by a =
state, incurring new obligations that in-turn need to be enacted through DB=
 related SYSADMIN tasks. therein, the capacity for individuals to be presen=
ted with choices (perhaps also incentives for different types of choices - =
i.e. join the loyalty program get 10% discount, free-updates, etc.) assists=
 all parties involved in the transaction.  I think in other instances, it=
=92s a bit like seeing advertising your actually interested in - or ensurin=
g the direct mail is being received by people, not dumped into the virtual =
dumpster - which is a waste of energy, if not to consider other issues ther=
ein.

Finally - these standards most affect individuals, who are not ordinarily p=
aid-up members of W3C.   The membership of W3C in-turn have fiduciary requi=
rements around what they need, in-order to comply with law.  Due to the tru=
ly amazing behaviours, works and passion - arguably for furthering humanity=
 (can=92t think of a way to summarise it - i=92ve started considering the c=
oncepts around how we all share WWW citizenship..) the platform exists, as =
may not have been the case should some of the initial decisions have been d=
ifferent..  The motivations were designed to help organisations, by empower=
ing people to communicate more effectively.

I find "Network Theory Seminar with Tim Berners-Lee=94 presentation https:/=
/twitter.com/WebCivics/status/492707794760392704  (the https://twitter.com/=
WebCivics/ will be resourcing an array of links around this territory of co=
nsideration / =91web science=92) quite grounding; and in-turn, we are certa=
inly at a stage where identity, the digital treatment of persons is a massi=
ve issue, on so very many levels.  This area is a can of worms.  So my $0.0=
2c (or currently about 0.03488uBTC) would be that credentials is an element=
 of identity and personal permissions standards - or - regardless of the na=
me - perhaps your scope is a little too narrow, as to best serve the needs =
of its intended beneficiaries.

- Authentication is required to create =91barriers=92 around someone who is=
 not you, =91authenticating=92 as you - on computing systems.
- Permissions are required so that we=92re not entrapping people into thing=
s they=92re otherwise not required to do.
- Personal - is different from any act you make, in association to others w=
hether acting as an agent or a member of the community.

Identity is more broadly nebulous, a concept of study in many social scienc=
es / liberal arts - manifestly, something that is not digital or binary.  Y=
ET, we have credentials and identifiers, or 'footprints'=85  We are legally=
 recognised entities - or at least, we should be.

inclusive concepts of course: include, the rights, privileges and responsib=
ilities of citizenship and social participation; yet, then it starts to bec=
ome more complicated.  In this world, without economic recognition - people=
 can barely subsist.

Access to justice for incorporated entities, vs. access to justice for the =
majority of WWW citizens is not reasonably equal. large companies and indiv=
iduals have issues sharing intellectual property, without a ledger - who kn=
ows who did what first; generally, the individual does not have a legal dep=
artment, yet equally perhaps they=92ve got some strategy that could waste a=
lot of time and shareholder money - or perhaps, someone had a KPI that they=
 found difficult to meet without =91cutting corners=92.

when dealing with identity - at this level no less - I think it=92s imperat=
ive that we ensure the scope is defined in a manner that holistically ensur=
es =91duty of care=92, as we are able to discharge as professional - commun=
ity members - on a best-efforts basis, to make an attempt that our work is =
defined in such a way that it seeks not diminish the responsibility or oppo=
rtunity of any party, to act in good-faith and to maintain our responsibili=
ties as citizens throughout our affairs, including those in which we act as=
 an authorised representative and/or agent - for an incorporated entity.

love it or hate it - most things that affect us has an economic price-tag, =
whether that rational has been realised, is yet to become realised or has b=
ecome subject to barriers and may be unaccessible.

FUNCTIONAL

I note an array of community initiatives.

https://webwewant.org/
http://webfoundation.org/
http://www.purpose.com/

(noting that many others exist=85)

I=92m also working on this concept called =91web civics=92 which aims to cr=
eate events that link =91locals=92 with =91international experts=92, help f=
inish product produced by scientists such as those on these lists, etc.

I=92ve found that people are engaging me about these sorts of issues and th=
at the most interesting conversations are with people who are consummate pr=
ofessionals, in different (and sometimes related or complimentary) fields. =
 I feel it=92s important to develop these conversations, build social bridg=
es.

Yet when it gets down to functional - the concepts need to be converted int=
o standards, and i believe supporting W3C Community group works - is the be=
st possible method to get that work done.  Perhaps, this is misguided - not=
 sure.  ATM i can see an array of different groups looking at identity rela=
ted issues.  From the persistent messages about different crypto standards,=
 to ontological debates, messaging standards (i.e.: serialisation methods -=
 turtle vs. json-ld), etc.

underlying some of these issues is most likely a host of patent / IPR issue=
s, etc.

If,

W3 participants specialised in this field - no matter where in the ideologi=
cal spectrum they=92re focused upon - can accumulatively collaborate / coop=
erate - towards a standard that can support an array of different use-cases=
 (focused on the use of Linked-Data / RDF / including decentralised web tec=
h.) then, i believe the potential for standards work could have enormously =
beneficial implications.

However -  I equally understand that this may in-turn bring about a resourc=
ing issue.  To which, a largely philosophical strategy might need to be dep=
loyed in considering how these needs be met.




On 31 Jul 2014, at 2:03 pm, Manu Sporny <msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]<mailto:m=
sporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]>> wrote:

For those of you that may have missed it in the minutes, we believe we
now have enough momentum to launch a Credentials Community Group at W3C
to take over the identity/credentials use cases and technology that this
group has been working on for a few years now.

There has been concern voiced that this group would be side-tracked by
much of the identity/credentials work. We now believe that we've found
some other organizations in the payments, education, and government ID
spaces that would like to lead the work (ensuring that the identity use
cases related to payment continue to be supported). The proposed charter
for that group is here:

https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr522nBWCjLJMQ_vGbbtsA5-=
pAsg/edit

Please provide input on the charter. It's heavily modeled on the charter
for this group (so if you like the way this group is run, you should
like the way that group is run).

The discussion around the formation of the group starts here:

https://web-payments.org/minutes/2014-07-30/#2

-- manu

--
Manu Sporny (skype: msporny, twitter: manusporny, G+: +Manu Sporny)
Founder/CEO - Digital Bazaar, Inc.
blog: The Marathonic Dawn of Web Payments
http://manu.sporny.org/2014/dawn-of-web-payments/


--_000_222fc5ab2d294ff1a995f01cd7af916bBN1PR07MB101namprd07pro_
Content-Type: text/html; charset="windows-1256"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dwindows-1=
256">
<meta content=3D"text/html; charset=3Dwindows-1256">
</head>
<body style=3D"word-wrap:break-word">
<div>
<div style=3D"font-size:11pt; font-family:Calibri,sans-serif">Have they eme=
rged, or are they just manufactured in lawyerly tradition?<br>
<br>
Cannot wait to hear how a w3c culture addresses the morass. If its more of =
the same, then we add another label to the pile.<br>
<br>
I like foaf's philosophical approach - allowing lawyerly interpretation of =
a concept, while denying the per eminence of any one interpretation. I like=
 foaf insisting that no identity dogma has relevance to foaf itself - in th=
e sense that foaf exists to verily
 resist any and all dogma, including whatever w3c politics comes up with. F=
oaf and its spinoffs like webid exist to have the continuing conversation a=
nd see what logic itself can produce.<br>
<br>
Sent from my Windows Phone</div>
</div>
<div dir=3D"ltr">
<hr>
<span style=3D"font-size:11pt; font-family:Calibri,sans-serif; font-weight:=
bold">From:
</span><span style=3D"font-size:11pt; font-family:Calibri,sans-serif"><a hr=
ef=3D"mailto:[email protected]">Tim Holborn</a></span><br>
<span style=3D"font-size:11pt; font-family:Calibri,sans-serif; font-weight:=
bold">Sent:
</span><span style=3D"font-size:11pt; font-family:Calibri,sans-serif">=FD7/=
=FD31/=FD2014 10:44 PM</span><br>
<span style=3D"font-size:11pt; font-family:Calibri,sans-serif; font-weight:=
bold">To:
</span><span style=3D"font-size:11pt; font-family:Calibri,sans-serif"><a hr=
ef=3D"mailto:[email protected]">Peter Williams</a></span><br>
<span style=3D"font-size:11pt; font-family:Calibri,sans-serif; font-weight:=
bold">Cc:
</span><span style=3D"font-size:11pt; font-family:Calibri,sans-serif"><a hr=
ef=3D"mailto:msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]">Manu Sporny</a>;
<a href=3D"mailto:foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]">foaf dev</a>; <a href=3D=
"mailto:[email protected]">
[email protected]</a>; <a href=3D"mailto:[email protected]">Web P=
ayments CG</a>;
<a href=3D"mailto:[email protected]">[email protected]</a></span><br>
<span style=3D"font-size:11pt; font-family:Calibri,sans-serif; font-weight:=
bold">Subject:
</span><span style=3D"font-size:11pt; font-family:Calibri,sans-serif">Re: [=
foaf-dev] Credentials Community Group</span><br>
<br>
</div>
<div>IMHO - It=92s with misfortune that the identity problems emerge, to fo=
rm a situation that certainly deserves a response. &nbsp; Yet, fragmenting =
the identity elements seems to meet failure. &nbsp;I think it is such a vol=
atile issue, that as yet - a considered response
 has not been endeavoured effectively - which results in the continuing nee=
d to look at it.
<div><br>
</div>
<div>Bank and banking - require different capabilities. &nbsp;I think this =
may be best deemed a format that is available to citizens should they seek =
to act in a manner that is lawful or in compliance with their law (of the s=
tate / place of citizenship? without
 taking into consideration factors relating to =91choice of law=92 and peop=
le of other nations signing agreements with internationally governed entiti=
es).</div>
<div><br>
</div>
<div>FOAF works for Persona - incredibly well, imo. &nbsp;I appreciate the =
technical purpose of using the term =91agent=92, yet i also appreciate the =
legal definition, and the appropriation of the term more broadly throughout=
 society.</div>
<div><br>
</div>
<div>ATM: it=92s legitimate to understand that your Internet Provider can o=
btain an IP Request from a Website to effectively =91ping=92 the site. &nbs=
p;When purchasing an Apple Product - it=92s linked to an online account, wi=
th a credit card - which effectively furnishes
 a similar function.&nbsp;</div>
<div><br>
</div>
<div>Yet, a start-up web-business selling say - computer games on the web -=
 might end-up having their business threatened by =91charge-backs=92, which=
 in-turn stimulates some ideas around how to set-up AML (anti-money launder=
ing) / KYC (know your customer) capabilities,
 because they=92re sick of sending games to scammers.&nbsp;</div>
<div><br>
</div>
<div>Yet - this is certainly more complex, and i=92m rather sure - an appro=
priate solution is not defined yet. &nbsp;What=92s worse, is that without a=
 solution we=92ve ended-up (perhaps) with more problems, as =91tracking=92 =
and other related =91functions=92 of what i think they
 call =91big data=92, continually undermine privacy - without actually prov=
iding any benefit to natural persons.</div>
<div><br>
</div>
<div>So - whilst I apologise for the cross-posting - across these groups, w=
e=92ve got alot of people thinking about different parts or constituents of=
 identity and identity related services (including pseudo-anonymity) and it=
 seems reasonable to at least facilitate
 an opportunity - to seek to get people working together on this very impor=
tant area of dev.</div>
<div><br>
<div>
<div>On 1 Aug 2014, at 5:03 am, Peter Williams &lt;<a href=3D"mailto:pwilli=
[email protected]">[email protected]</a>&gt; wrote:</div>
<br class=3D"Apple-interchange-newline">
<blockquote type=3D"cite">
<div dir=3D"ltr" style=3D"font-family:Helvetica; font-size:12px; font-style=
:normal; font-variant:normal; font-weight:normal; letter-spacing:normal; li=
ne-height:normal; orphans:auto; text-align:start; text-indent:0px; text-tra=
nsform:none; white-space:normal; widows:auto; word-spacing:0px">
<div dir=3D"ltr" style=3D"font-family:Calibri,'Segoe UI',Meiryo,'Microsoft =
YaHei UI','Microsoft JhengHei UI','Malgun Gothic',sans-serif; font-size:12p=
t">
<div>seems VERY un-foaf</div>
<div><br>
</div>
<div>The memo sounds like all the same issues that folks used to talk about=
 in the pre-internet EDI world,&nbsp; which became the billion dollar PKI b=
oondoggle of the 2001 era web, and now seems to have re-surfaced in new blo=
b formats in the openid connect world
 - where all the same ideas are being hashed for the 100th time in the last=
 30 years.</div>
<div><br>
</div>
<div>The very think Ive liked about foaf community it that is distinguished=
 itself from&nbsp;=93ALL THAT=94. it was speciifcally about the web citizen=
 wanting to surf (and who is not some governed entity, some government id, =
some contracted service client, someone with
 this our or outrage about some issue, =85).<br>
</div>
<div>
<div><br>
</div>
</div>
</div>
</div>
</blockquote>
<div><br>
</div>
I=92ve certainly been outraged by a few issues. &nbsp;doesn=92t mean i=92m =
seeking to deprive anyone of liberty, human rights, democratic participatio=
n, etc. &nbsp; The unfortunate issue, is that some realities in life are ta=
boo - evil happens when good people, still watching,
 do nothing. &nbsp;The capacities for =91web-citizens=92 - well=85 &nbsp;it=
=92s a rather serious issue. &nbsp;we need different perspectives, from dif=
ferent ends of the spectrum, to come-up with things that may not simply req=
uire technical solutions in software code, but perhaps
 also - empowering systems of government to examine issues, and come-up wit=
h solutions that can help reinforce factors automated via software code. &n=
bsp;The ability for someone to give each instance their personal attention =
- their personal approval - is becoming
 less, and less relevant. &nbsp;The means to deconstruct problems that emer=
ge via automated systems, are equally becoming more and more difficult. &nb=
sp;Regardless, we have shared values and they=92ve been enshrined in docume=
nts - such as UN Human Rights conventions -
 so it=92s not like we=92re starting from a blank canvas. &nbsp;Regardless,=
 the idea that someone owns IPR around how your identity is recognised by l=
aw? &nbsp;identity issue, recognition of people issues have some very terri=
ble potential outcomes. &nbsp;I think we=92re looking
 to build =91things=92 that help people grow to their fullest potential, in=
 contributing to man-kind, in their way - doesn=92t matter if they=92re out=
 giving soup to local homeless people, or standing on some stage speaking o=
f rights, dignity and opportunity. &nbsp;It starts
 to get ideological from therein. &nbsp;</div>
<div><br>
</div>
<div>If systems are deployed that bind a persons identity via HTTP - then i=
f it=92s not made with the capacity to support pseudo-anonymity, i don=92t =
think it matters which ontology you prefer. &nbsp;Fundamentally - their is =
a difference between systems built for relational
 database methods; and, those developed for graph database methods. &nbsp;I=
 like many parts of the world; but my passport and birth-certificate says i=
=92m Australian. &nbsp;I=92d like to send an secured message that is date-s=
tamped, in a manner that makes it as useful as
 a patent document. &nbsp;I=92m sure other =91inventors=92 who don=92t have=
 the ~500k to secure patent protection for different forms of work would al=
so like some other means for recognition. &nbsp;I=92d also like to ensure t=
hat if an external influencer, not trackable by a system
 - unreasonably damages a persons identifiers on the system - means are def=
ined in-order to reasonably figure things out. &nbsp;Equally, those who hav=
e mental-health care issues - perhaps a bad period of time, that shouldn=92=
t damage their capacity to be employed.
 &nbsp;Or means to protect vulnerable people who are threatened or harmed b=
y acts that are illegal and materially damaging to others, but formerly per=
haps - without the interest - the technology never applied to help such peo=
ple, almost like an ideological decision.</div>
<div><br>
</div>
<div>It=92s a complicated area. &nbsp;i see the need for the credentials ca=
pability, but it needs to be well thought out, and i figured sending this n=
ote might be a positive step rather than an ignorant or thoughtless recepti=
on, to what i believe is a very complex
 area with a gap-analysis that doesn=92t come-up with a very positive revie=
w.</div>
<div><br>
</div>
<div>TimH.&nbsp;</div>
<div><br>
</div>
<div>
<blockquote type=3D"cite">
<div dir=3D"ltr" style=3D"font-family:Helvetica; font-size:12px; font-style=
:normal; font-variant:normal; font-weight:normal; letter-spacing:normal; li=
ne-height:normal; orphans:auto; text-align:start; text-indent:0px; text-tra=
nsform:none; white-space:normal; widows:auto; word-spacing:0px">
<div dir=3D"ltr" style=3D"font-family:Calibri,'Segoe UI',Meiryo,'Microsoft =
YaHei UI','Microsoft JhengHei UI','Malgun Gothic',sans-serif; font-size:12p=
t">
<div>
<div>Sent from Surface Pro</div>
<div><br>
</div>
</div>
<div style=3D"padding-top:5px; border-top-color:rgb(229,229,229); border-to=
p-width:1px; border-top-style:solid">
<font face=3D" 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Micr=
osoft JhengHei UI', 'Malgun Gothic', 'sans-serif'" style=3D"line-height:15p=
t; letter-spacing:0.02em; font-family:Calibri,'Segoe UI',Meiryo,'Microsoft =
YaHei UI','Microsoft JhengHei UI','Malgun Gothic',sans-serif; font-size:12p=
t"><b>From:</b>&nbsp;<a href=3D"mailto:[email protected]" target=3D=
"_parent">Tim
 Holborn</a><br>
<b>Sent:</b>&nbsp;=FDWednesday=FD, =FDJuly=FD =FD30=FD, =FD2014 =FD11=FD:=
=FD28=FD =FDPM<br>
<b>To:</b>&nbsp;<a href=3D"mailto:msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]" target=3D"_par=
ent">Manu Sporny</a><br>
<b>Cc:</b>&nbsp;<a href=3D"mailto:foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]" target=
=3D"_parent">foaf dev</a>,<span class=3D"Apple-converted-space">&nbsp;</spa=
n><a href=3D"mailto:[email protected]" target=3D"_parent">public-webid@w3=
.org</a>,<span class=3D"Apple-converted-space">&nbsp;</span><a href=3D"mail=
to:[email protected]" target=3D"_parent">Web
 Payments CG</a>,<span class=3D"Apple-converted-space">&nbsp;</span><a href=
=3D"mailto:[email protected]" target=3D"_parent">[email protected]</a></fon=
t></div>
<div><br>
</div>
<div dir=3D"">Hi Manu,
<div><br>
</div>
<div>I=92m really pleased to see the initiative set-up to form a community =
that=92s seemingly designed to focus on identity issues specifically, rathe=
r than the use of identity in trade use-cases. &nbsp;Potentially a great ou=
tcome. &nbsp;I=92m therefore hoping the notes below
 can be assessed, considered and perhaps put into more cognoscente set of c=
onsiderations overall..</div>
<div><br>
</div>
<div>I haven=92t seen any references supporting loosely coupled identifiers=
 (i.e. private associations between the proposed identity credential tools =
- and psudo-anonymity / loosely coupled identifiers).</div>
<div><br>
</div>
<div>I refer back to&nbsp;<a href=3D"http://www.verisigninc.com/en_US/innov=
ation/verisign-labs/speakers-series/evolution-of-internet/index.xhtml" targ=
et=3D"_parent">http://www.verisigninc.com/en_US/innovation/verisign-labs/sp=
eakers-series/evolution-of-internet/index.xhtml</a>&nbsp;
 (particularly @23minutes - but the whole thing is good)</div>
<div><br>
</div>
<div>This in-turn relates to issues such as =91choice of law=92, when signi=
ng-up to site services and an array of other more sophisticated problems / =
considerations, that perhaps people generally could better understand as a =
constituent of entering into any-such
 agreements.&nbsp;</div>
<div><br>
</div>
<div>I also note that WebID and FOAF is not listed in the proposal, nor are=
 what i=92d term =91data-rights declarations=92 listed in the scope of work=
. &nbsp;In terms of =92safety=92 (per the video above) or security, i think=
 the ability to include other identity related
 =91linked-data=92 issues - such as methods for credential holders to make =
declaration about the use-expectations for information/data provided to 3rd=
 parties; and, the ability to not require individuals to unnecessarily disc=
lose identity information. Inclusively
 providing means to beneficially support protection of individuals, whilst =
still establishing new identity related tools (which in-turn bring new safe=
ty issues for web-users). &nbsp;In effect, a more holistic approach may ben=
efit the requirements (and/or intent)
 pursuant to other safety issues inclusive to identity and authentication, =
whether explicit or implicit; and, as described in precedent requirements s=
uch as KYC / AML.&nbsp;</div>
<div><br>
</div>
<div>Without the use of identity for authentication - the identity credenti=
al itself becomes useless. &nbsp;&nbsp;</div>
<div><br>
</div>
<div>=92not everyone needs to know or see everything=92.&nbsp;</div>
<div><br>
</div>
<div>It seems that the authentication principles (inc. systems) also form i=
mportant elements of the identity credentials lifecycle. I=92ve been constr=
ucting concept of =91data rights=92, which has yielded some interest alread=
y - and i=92m yet to find a technical home
 for it, though i believe could fit in well to a W3 CG that=92s appropriate=
ly broad in its considerations of personal identity requirements. &nbsp;</d=
iv>
<div><br>
</div>
<div>Therein; some of the =91data rights' ontological concepts i=92ve consi=
dered include,</div>
<div><br>
</div>
<div>
<div>Data:Reuse</div>
<div>Data:Accessibility</div>
<div>Data:Security</div>
<div>Data:Privacy</div>
<div>Data:Sovereignty&nbsp;</div>
<div>Data:Storage</div>
</div>
<div><br>
</div>
<div>I note that in my research i=92ve found that organisations may suffer =
from the costs incurred if / when privacy (or other) legislation is passed =
by a state, incurring new obligations that in-turn need to be enacted throu=
gh DB related SYSADMIN tasks. therein,
 the capacity for individuals to be presented with choices (perhaps also in=
centives for different types of choices - i.e. join the loyalty program get=
 10% discount, free-updates, etc.) assists all parties involved in the tran=
saction. &nbsp;I think in other instances,
 it=92s a bit like seeing advertising your actually interested in - or ensu=
ring the direct mail is being received by people, not dumped into the virtu=
al dumpster - which is a waste of energy, if not to consider other issues t=
herein.</div>
<div><br>
</div>
<div>Finally - these standards most affect individuals, who are not ordinar=
ily paid-up members of W3C. &nbsp; The membership of W3C in-turn have fiduc=
iary requirements around what they need, in-order to comply with law. &nbsp=
;Due to the truly amazing behaviours, works
 and passion - arguably for furthering humanity (can=92t think of a way to =
summarise it - i=92ve started considering the concepts around how we all sh=
are WWW citizenship..) the platform exists, as may not have been the case s=
hould some of the initial decisions
 have been different.. &nbsp;The motivations were designed to help organisa=
tions, by empowering people to communicate more effectively. &nbsp;</div>
<div><br>
</div>
<div>I find &quot;Network Theory Seminar with Tim Berners-Lee=94 presentati=
on&nbsp;<a href=3D"https://twitter.com/WebCivics/status/492707794760392704"=
 target=3D"_parent">https://twitter.com/WebCivics/status/492707794760392704=
</a>&nbsp; (the<span class=3D"Apple-converted-space">&nbsp;</span><a href=
=3D"https://twitter.com/WebCivics/" target=3D"_parent">https://twitter.com/=
WebCivics/</a><span class=3D"Apple-converted-space">&nbsp;</span>will
 be resourcing an array of links around this territory of consideration / =
=91web science=92) quite grounding; and in-turn, we are certainly at a stag=
e where identity, the digital treatment of persons is a massive issue, on s=
o very many levels. &nbsp;This area is a can
 of worms. &nbsp;So my $0.02c (or currently about 0.03488uBTC) would be tha=
t credentials is an element of identity and personal permissions standards =
- or - regardless of the name - perhaps your scope is a little too narrow, =
as to best serve the needs of its intended
 beneficiaries.</div>
<div><br>
</div>
<div>- Authentication is required to create =91barriers=92 around someone w=
ho is not you, =91authenticating=92 as you - on computing systems.</div>
<div>- Permissions are required so that we=92re not entrapping people into =
things they=92re otherwise not required to do.</div>
<div>- Personal - is different from any act you make, in association to oth=
ers whether acting as an agent or a member of the community.</div>
<div><br>
</div>
<div>Identity is more broadly nebulous, a concept of study in many social s=
ciences / liberal arts - manifestly, something that is not digital or binar=
y. &nbsp;YET, we have credentials and identifiers, or 'footprints'=85 &nbsp=
;We are legally recognised entities - or at
 least, we should be. &nbsp;</div>
<div><br>
</div>
<div>inclusive concepts of course: include, the rights, privileges and resp=
onsibilities of citizenship and social participation; yet, then it starts t=
o become more complicated. &nbsp;In this world, without economic recognitio=
n - people can barely subsist.&nbsp;</div>
<div><br>
</div>
<div>Access to justice for incorporated entities, vs. access to justice for=
 the majority of WWW citizens is not reasonably equal. large companies and =
individuals have issues sharing intellectual property, without a ledger - w=
ho knows who did what first; generally,
 the individual does not have a legal department, yet equally perhaps they=
=92ve got some strategy that could waste alot of time and shareholder money=
 - or perhaps, someone had a KPI that they found difficult to meet without =
=91cutting corners=92. &nbsp;</div>
<div><br>
</div>
<div>when dealing with identity - at this level no less - I think it=92s im=
perative that we ensure the scope is defined in a manner that holistically =
ensures =91duty of care=92, as we are able to discharge as professional - c=
ommunity members - on a best-efforts basis,
 to make an attempt that our work is defined in such a way that it seeks no=
t diminish the responsibility or opportunity of any party, to act in good-f=
aith and to maintain our responsibilities as citizens throughout our affair=
s, including those in which we act
 as an authorised representative and/or agent - for an incorporated entity.=
&nbsp;</div>
<div>&nbsp;</div>
<div>love it or hate it - most things that affect us has an economic price-=
tag, whether that rational has been realised, is yet to become realised or =
has become subject to barriers and may be unaccessible.&nbsp;</div>
<div><br>
</div>
<div>FUNCTIONAL</div>
<div><br>
</div>
<div>I note an array of community initiatives.</div>
<div><br>
</div>
<div><a href=3D"https://webwewant.org/" target=3D"_parent">https://webwewan=
t.org/</a></div>
<div><a href=3D"http://webfoundation.org/" target=3D"_parent">http://webfou=
ndation.org/</a></div>
<div><a href=3D"http://www.purpose.com/" target=3D"_parent">http://www.purp=
ose.com/</a></div>
<div><br>
</div>
<div>(noting that many others exist=85)</div>
<div><br>
</div>
<div>I=92m also working on this concept called =91web civics=92 which aims =
to create events that link =91locals=92 with =91international experts=92, h=
elp finish product produced by scientists such as those on these lists, etc=
.&nbsp;</div>
<div><br>
</div>
<div>I=92ve found that people are engaging me about these sorts of issues a=
nd that the most interesting conversations are with people who are consumma=
te professionals, in different (and sometimes related or complimentary) fie=
lds. &nbsp;I feel it=92s important to develop
 these conversations, build social bridges.</div>
<div><br>
</div>
<div>Yet when it gets down to functional - the concepts need to be converte=
d into standards, and i believe supporting W3C Community group works - is t=
he best possible method to get that work done. &nbsp;Perhaps, this is misgu=
ided - not sure. &nbsp;ATM i can see an array
 of different groups looking at identity related issues. &nbsp;From the per=
sistent messages about different crypto standards, to ontological debates, =
messaging standards (i.e.: serialisation methods - turtle vs. json-ld), etc=
.</div>
<div><br>
</div>
<div>underlying some of these issues is most likely a host of patent / IPR =
issues, etc.</div>
<div><br>
</div>
<div>If,&nbsp;</div>
<div><br>
</div>
<div>W3 participants specialised in this field - no matter where in the ide=
ological spectrum they=92re focused upon - can accumulatively collaborate /=
 cooperate - towards a standard that can support an array of different use-=
cases (focused on the use of Linked-Data
 / RDF / including decentralised web tech.) then, i believe the potential f=
or standards work could have enormously beneficial implications.</div>
<div><br>
</div>
<div>However - &nbsp;I equally understand that this may in-turn bring about=
 a resourcing issue. &nbsp;To which, a largely philosophical strategy might=
 need to be deployed in considering how these needs be met. &nbsp;</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>&nbsp;<br>
<div>
<div>On 31 Jul 2014, at 2:03 pm, Manu Sporny &lt;<a href=3D"mailto:msporny@=
digitalbazaar.com" target=3D"_parent">msporny-FpEJLV8oj+AqgwVRcPComAC/[email protected]</a>&gt; wro=
te:</div>
<br class=3D"Apple-interchange-newline">
<blockquote style=3D"margin-top:0px; margin-bottom:0px">For those of you th=
at may have missed it in the minutes, we believe we<br>
now have enough momentum to launch a Credentials Community Group at W3C<br>
to take over the identity/credentials use cases and technology that this<br=
>
group has been working on for a few years now.<br>
<br>
There has been concern voiced that this group would be side-tracked by<br>
much of the identity/credentials work. We now believe that we've found<br>
some other organizations in the payments, education, and government ID<br>
spaces that would like to lead the work (ensuring that the identity use<br>
cases related to payment continue to be supported). The proposed charter<br=
>
for that group is here:<br>
<br>
<a href=3D"https://docs.google.com/document/d/1dPzWbPF0jlox8UHnr522nBWCjLJM=
Q_vGbbtsA5-pAsg/edit" target=3D"_parent">https://docs.google.com/document/d=
/1dPzWbPF0jlox8UHnr522nBWCjLJMQ_vGbbtsA5-pAsg/edit</a><br>
<br>
Please provide input on the charter. It's heavily modeled on the charter<br=
>
for this group (so if you like the way this group is run, you should<br>
like the way that group is run).<br>
<br>
The discussion around the formation of the group starts here:<br>
<br>
<a href=3D"https://web-payments.org/minutes/2014-07-30/#2">https://web-paym=
ents.org/minutes/2014-07-30/#2</a><br>
<br>
-- manu<br>
<br>
--<span class=3D"Apple-converted-space">&nbsp;</span><br>
Manu Sporny (skype: msporny, twitter: manusporny, G&#43;: &#43;Manu Sporny)=
<br>
Founder/CEO - Digital Bazaar, Inc.<br>
blog: The Marathonic Dawn of Web Payments<br>
<a href=3D"http://manu.sporny.org/2014/dawn-of-web-payments/">http://manu.s=
porny.org/2014/dawn-of-web-payments/</a></blockquote>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</div>
</body>
</html>

--_000_222fc5ab2d294ff1a995f01cd7af916bBN1PR07MB101namprd07pro_--

--===============1354209655511998733==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
foaf-dev mailing list
foaf-dev-RyYwo1q5J+qsOXdr9/[email protected]
http://lists.foaf-project.org/mailman/listinfo/foaf-dev
--===============1354209655511998733==--