<?xml version="1.0" encoding="iso-8859-1"?><!-- generator="wordpress/0.5.0RC-Final" -->
<rss version="0.92">
    <channel>
        <title>=nat: Digital Identity Blog</title>
        <link>http://www.sakimura.org/en/modules/wordpress/index.php</link>
        <description>Thinking around Digital Identity loud. </description>
        <lastBuildDate>Tue, 13 May 2008 07:26:20 GMT</lastBuildDate>
        <docs>http://backend.userland.com/rss092</docs>
        <managingEditor>&#115;&#97;&#107;&#105;m&#117;r&#97;&#64;m&#97;&#114;&#105;&#109;&#98;a&#46;&#111;rg</managingEditor>
        <webMaster>s&#97;&#107;im&#117;&#114;&#97;&#64;&#109;ar&#105;mb&#97;&#46;o&#114;g</webMaster>
        <language>en</language>

        <item>
            <title>Et tu Paperboy.</title>
            <description>	&lt;p&gt;paperboy&amp;#038;co. in Japan started to accept OpenID for its online bookmark service today. &lt;/p&gt;
	&lt;p&gt;Unfortunately, it only accepts OpenID provided by: &lt;/p&gt;
	&lt;p&gt;- OpenID.ne.jp&lt;br /&gt;
- Yahoo! JAPAN&lt;br /&gt;
- livedoor&lt;br /&gt;
- hatena&lt;br /&gt;
- JugemKey&lt;/p&gt;
	&lt;p&gt;Why do those services do white listings? &lt;/p&gt;
	&lt;p&gt;Does it add value? NO. All these are free services, and you can make any number of OpenID with these providers. Then, why bother whitelisting to them? &lt;/p&gt;
	&lt;p&gt;Clearly, whitelisting does not go with the original philosophy of OpenID. &lt;/p&gt;
	&lt;p&gt;I hope that this &amp;#8220;white listing&amp;#8221; boom will find its end soon. &lt;/p&gt;
	&lt;p&gt;But for it, I guess we need some workable reputation framework&amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=38</link>
        </item>
        <item>
            <title>OpenID Dinner @ Basel</title>
            <description>	&lt;p&gt;
&amp;nbsp;&lt;br /&gt;
From Left to Right: &lt;/p&gt;
	&lt;p&gt;=nat, Robert Ott (OpenID Switzerland*), David Reindl (OpenID Switzerland), Martin Paljak (OpenID Estonia), Snorri Giorgetti (OpenID France, OpenID Europe, Chaiman). &lt;/p&gt;
	&lt;p&gt;It was a six course dinner.&lt;br /&gt;
Drink started with Clemont(?) de Alsace, a Swiss white wine, which I do not remember the name, then Mouton Cadet. &lt;/p&gt;
	&lt;p&gt;* Yet to be formed.
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=37</link>
        </item>
        <item>
            <title>OpenID Foudation Japan Announcement Huge Success</title>
            <description>	&lt;p&gt;So, this morning, on the 28th, we have made an annoucement on plan to form the OpenID Foundation, Japan Chapter. &lt;/p&gt;
	&lt;p&gt;45 reporters from 37 magazines and news papers showed up for the press conference and numerous articles were published on it, that it made into the top page of the Google News with a photo. &lt;/p&gt;
	&lt;p&gt;As of now, over 27 articles were written at various places.&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=36</link>
        </item>
        <item>
            <title>Are National ID Cards Going to Snuggle Up With OpenID?</title>
            <description>	&lt;p&gt;The REAL ID Act of 2005 is said by some to pave the way for a United States National ID Card and has come under heavy criticism from a wide range of people in the US. Some recent developments indicate that a National ID card could be tied to the federated authentication standard called OpenID.&lt;/p&gt;
	&lt;p&gt;At the most basic level, this would mean that you could sign in with your National ID card to all the websites where today you can login with a Yahoo! or AIM or other OpenID. Hmmm&amp;#8230;&lt;/p&gt;
	&lt;p&gt;Are National ID Cards Going to Snuggle Up With OpenID?&lt;/p&gt;
	&lt;p&gt;IMHO, the government forcing the use of the Veronym and centralized government operated OpenID is a bad thing. &lt;/p&gt;
	&lt;p&gt;However, if it is &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=35</link>
        </item>
        <item>
            <title>OpenID Compatibility</title>
            <description>	&lt;p&gt;There seem to be some compatibility issues since the rise of OpenID 2.0. For example, something like &lt;/p&gt;
	&lt;p&gt;http://www.readwriteweb.com/cgi-bin/mt/mt-comments.cgi&lt;/p&gt;
	&lt;p&gt;does not support OpenID 2.0 nor XRI so that I cannot login to comment&amp;#8230;&lt;br /&gt;
It does not even support the https://&amp;#8230; url.
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=34</link>
        </item>
        <item>
            <title>[OpenID] Board membership limited?</title>
            <description>	&lt;p&gt;&amp;#8220;[OpenID] Board membership limited?&amp;#8221; is a title in the general@openid.net mailing list. &lt;/p&gt;
	&lt;p&gt;It is posing an interesting question. &lt;/p&gt;
	&lt;p&gt;As it so happens, Bill (the Executive Director of OpenID Foundation, OIDF), states that &amp;#8220;Although the foundation will continue recruiting companies of all sizes to support the OpenID standard, it is not likely to add any more board members.&amp;#8221; &lt;/p&gt;
	&lt;p&gt;It seems the rationale behind it is that community and the corporate power has to be balanced as Dick Hardt states: &lt;/p&gt;
	&lt;p&gt;The community board members want to ensure that the Foundation represents the community, so would like to limit the Corporate board membership, or at least ensure that community board seats balance the corporate board seats &amp;#8211; so adding additional corporate board members &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=33</link>
        </item>
        <item>
            <title>OpenID Foundation Related Links</title>
            <description>	&lt;p&gt;OpenID Foundation&lt;/p&gt;
	&lt;p&gt;IPR&lt;br /&gt;
  - IPR overview&lt;br /&gt;
  - Why the IPR policy and process&lt;br /&gt;
  - IPR Non-Assertion Agreements for Entities and Individuals (covers&lt;br /&gt;
through OpenID 2.0)&lt;br /&gt;
  - IPR Policy and Process (for new spec working groups)&lt;br /&gt;
  - Executed IPR Non-Assertion Agreements (not all from the corporate&lt;br /&gt;
board members have been uploaded yet) - &lt;/p&gt;
	&lt;p&gt;Foundation&lt;br /&gt;
  - Articles of Incorporation with the state of Oregon (http://openid.net/pipermail/board/2007-May/000274.html)&lt;br /&gt;
  - Basic policies and procedures -&lt;br /&gt;
  - Board Meeting Minutes&lt;br /&gt;
  - Membership agreement
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=32</link>
        </item>
        <item>
            <title>OpenID module for Xoops 2 and Xoopscube ver.0.2</title>
            <description>	&lt;p&gt;OpenID RP Module for Xoops JP. ==============================Author: Nat Sakimura (=nat)Date: 2008-02-10Copyright: Nat Sakimura (=nat)License: GPLVersion: 0.2PHP OpenID Library: php-openid-2.0.0DOWNLOAD========&lt;br /&gt;
http://www.sakimura.org/modules/mydownloads/visit.php?cid=1&amp;#038;lid=8&lt;br /&gt;
INSTALL=======1. Unarchive the files under modules/ directory. 2. Define XOOPS_TRUST_PATH somewhere out of the web accessible path &amp;nbsp;&amp;nbsp; in mainfile.php3. Create a foloder &amp;#8220;_php_consumer&amp;#8221; under XOOPS_TRUST_PATH and &amp;nbsp;&amp;nbsp; change the permission so that it will be writable by the web server. 4. Install the module like other modules. &amp;nbsp;&amp;nbsp; (For XoopsCube, install the block as well.)5. Give access permission to guest group for this module. 6. Install block for all the modules. TODOs=====1. Create Admin Panel for easy maintenance of the OpenIDs. 2. Make 5 and 6 above automagic. 3. Clean up the code4. Replace Dummy Admin screens to real ones. 5. &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=31</link>
        </item>
        <item>
            <title>Random thoughs on Reputation</title>
            <description>	&lt;p&gt;Let me make note of my random thougts before I forget. &lt;/p&gt;
	&lt;p&gt;Reputation needs to have an identifier of somebody being scored.&lt;br /&gt;
The same for who is scoring.&lt;br /&gt;
For what criteria, this reputation score was made.&lt;br /&gt;
For the reputation to be aggregatable, it has to have a distribution that we know about the aggregated distribution (such as normal distribution).&lt;br /&gt;
The information about the distribution, including what distribution, mean, and standard diviation must be published together with the score.&lt;br /&gt;
Display score must be intuitive for an average person.&lt;br /&gt;
Date that score was made&lt;br /&gt;
Signature by the score maker&lt;/p&gt;
	&lt;p&gt;So, the reputation score file should contain: &lt;/p&gt;
	&lt;p&gt;itemtypee.g.&lt;/p&gt;
	&lt;p&gt;SubjectID&lt;br /&gt;
XRI/URI&lt;br /&gt;
=nat&lt;/p&gt;
	&lt;p&gt;ReputationServiceID&lt;br /&gt;
XRI/URI&lt;br /&gt;
@myRS&lt;/p&gt;
	&lt;p&gt;Criteria&lt;br /&gt;
Text&lt;br /&gt;
Operation quality of this RP&lt;/p&gt;
	&lt;p&gt;Display Score (Cumulative Percentage)&lt;br /&gt;
float&lt;br /&gt;
74.2&lt;/p&gt;
	&lt;p&gt;Score&lt;br /&gt;
Float&lt;br /&gt;
56.8&lt;/p&gt;
	&lt;p&gt;Distribution&lt;br /&gt;
enum&lt;br /&gt;
normal&lt;/p&gt;
	&lt;p&gt;Mean&lt;br /&gt;
float&lt;br /&gt;
50&lt;/p&gt;
	&lt;p&gt;Standard Deviation&lt;br /&gt;
float&lt;br /&gt;
10&lt;/p&gt;
	&lt;p&gt;Subject Public Key&lt;br /&gt;
String&lt;br /&gt;
2fdlafodnewoldfjkaslf &amp;#8230; &lt;/p&gt;
	&lt;p&gt;Date&lt;br /&gt;
XMLDATE&lt;br /&gt;
2008-02-01T14:34:00Z&lt;/p&gt;
	&lt;p&gt;Signature&lt;br /&gt;
string&lt;br /&gt;
af8afsld92dfjdsla&amp;#8230;blah&amp;#8230;blah&amp;#8230;&lt;/p&gt;
	&lt;p&gt;In the above table, I am proposing to use &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=30</link>
        </item>
        <item>
            <title>On OpenID Association</title>
            <description>	&lt;p&gt;Well, I am not talking about &amp;#8220;association&amp;#8221; in the sense of &amp;#8220;organization&amp;#8221;. It is the first phase of the OpenID protocol that I am talking about. &lt;/p&gt;
	&lt;p&gt;As it so happens, in OpenID 2.0, RP after resolving the OP address, requests OP to establish the association by Diffie-Helman. The association needs to be stored at both OP and RP. Also, because of this phase, check_authentication phase is also required. &lt;/p&gt;
	&lt;p&gt;Perhaps this was necessary in the days of OpenID 1.0, but I feel it to be rather redundant now. &lt;/p&gt;
	&lt;p&gt;If OP and RP publishes their Public Key in their XRDS, we do not need Association nor check_authentication, I think, simplifying the protocol further, and strengethning the security further with Reputation Service that &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=29</link>
        </item>
        <item>
            <title>RedMine OpenID authentication</title>
            <description>	&lt;p&gt;=masaki has completed the integration of RedMine with OpenID.
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=28</link>
        </item>
        <item>
            <title>IIW2007b Day 2</title>
            <description>	&lt;p&gt;Today, I have presented the concept of Trusted Data Exchange and Reputation Service at iiw2007b.&lt;br /&gt;
Am writing an article in iiw wiki, but submit succeeds only sporadically.&lt;br /&gt;
Had a problme with Linksafe login, so to create the article, I am using =sakimura which is being hosted at 2idi, but that is me, =nat. This seems to be the problem that was introduced in conjunction with the introduction of CardSpace as one of the authentication method.&lt;br /&gt;
Conversations:&lt;br /&gt;
with =eekim and =ovdavis: ref linking of inames crossing over the ibroker.&lt;br /&gt;
with Ashish Jain: Necessity of Reputation service for the distributed authentication and data exchange service to be useful, esp. on the RP reputation.&lt;br /&gt;
with Paul Trevithick: Higgins and the contract format.&lt;br /&gt;
with &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=27</link>
        </item>
        <item>
            <title>Trusted and Flexible Data Exchange for OpenID</title>
            <description>	&lt;p&gt;My team has been looking at AX etc. for some time whether it can fulfill the needs of our clients. It looks it is kind of hard to. So, we are defining an additional protocol that hooks to AX. Hopefully, I can present it at iiw2007b.
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=26</link>
        </item>
        <item>
            <title>Libery Alliance Day 2007</title>
            <description>	&lt;p&gt;On the 26th of October, I went to Liberty Alliance Day 2007 in Tokyo. I was invited to the event as a panelar to speak about OpenID at the cocktail reception, but I attended all the other sessions as well as some of the demos. &lt;/p&gt;
	&lt;p&gt;Panel Discussion in Japan oftern ends up just as a series of presentation, but this time, it was a real panel discussion, which was good. &lt;/p&gt;
	&lt;p&gt;At the end of the Panel discussion, Mr. Takahashi asked the panelers &amp;#8220;What is Digital Identity?&amp;#8221;. I was the third person to talk about and by the time it reached me, pretty much was spoken. So, I said &amp;#8220;It is a technology that brings Power to the People. &amp;#8221; refering &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=25</link>
        </item>
        <item>
            <title>Hatena Start Providing OpenID support</title>
            <description>	&lt;p&gt;Hatena, one of the major Japanese blog provider, started the support of the OpenID. &lt;/p&gt;
	&lt;p&gt;See http://www.hatena.ne.jp/info/openid for the further details. &lt;/p&gt;
	&lt;p&gt;As an OP, it provides OpenID in the form of &lt;/p&gt;
	&lt;p&gt;http://www.hatena.ne.jp/hatena_user_name/ &lt;/p&gt;
	&lt;p&gt;As an RP, it only supports the following OpenID providers. &lt;/p&gt;
	&lt;p&gt;livedoor&lt;br /&gt;
LiveJournal&lt;br /&gt;
TypeKey&lt;br /&gt;
Vox&lt;/p&gt;
	&lt;p&gt;As the result, I cannot use their service with my OpenID. This is rather unfortunate. &lt;/p&gt;
	&lt;p&gt;Whether it is OP or RP, unless we ready the reputation service that measures the trustability of the services quickly, the openess of the OpenID gets hart. Need to sort this out.
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=24</link>
        </item>
        <item>
            <title>PAPE or AQE?</title>
            <description>	&lt;p&gt;Over the dinner at a Tofu restaurant in Ginza, Tokyo, David Recordon and I discussed on what would be the appropriate way of achieving an OP that provide registration and authentication quality: whether to use PAPE or AQE. David&amp;#8217;s recommendation seemed to be PAPE.&lt;br /&gt;
Going over the PAPE spec this morning, however, I did not find too much about RA activities. NIST SP800-63 Level 2 and upwards requires identity proofing, but from the PAPE spec, it is not clear if these are required.&lt;br /&gt;
Specifically, for openid.pape.nist_auth_level, the spec states &amp;#8220;[NIST_SP800-63] corresponding to the authentication method and policies employed by the OP when authenticating the End User&amp;#8221;.&lt;br /&gt;
The examples following the above statement also talks only about the authentication and not &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=23</link>
        </item>
        <item>
            <title>OpenID/XRI authentication module for Xoops 2.0.16JP</title>
            <description>	&lt;p&gt;I have developed and deployed the OpenID/XRI authentication module to this site. (http://www.sakimura.org/en/)&lt;br /&gt;
I am pretty sure that there are rough edges, but please have a try and let me know those.&lt;br /&gt;
Unfortunately, current server that I use is not too stable so there might be the times that you need to retry 5 min. or so later but &amp;#8230; (I think this is the effect of Xen. I do not know how to fix it&amp;#8230;)
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=20</link>
        </item>
        <item>
            <title>XRI Resolution 2.0 cycle near completion</title>
            <description>	&lt;p&gt;Most current working draft has been submit to http://www.oasis-open.org/committees/download.php/24096/xri-resolution-v2.0-wd-11-ed-01.doc&lt;br /&gt;
Proposed time schedule to make it Comitte Draft are: &lt;/p&gt;
	&lt;p&gt;May 31 - Editors Draft 02 (ED02) - content complete version&lt;br /&gt;
June 7 - Editors Draft 03 (ED03) - polished version to be submit for comitte approval.&lt;br /&gt;
If you have anything to speak up, this is the time to do so!
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=19</link>
        </item>
        <item>
            <title>Estonia to provide OpenID to all its eID holders</title>
            <description>	&lt;p&gt;This means that over 1,000,000 smart card based OpenIDs will be provided to the Estonian citizen.&lt;br /&gt;
Around 80% of Estonian has something called &amp;#8220;eID&amp;#8221;.&amp;nbsp;&amp;nbsp;They will be provided with unique OpenID with the format open.id.ee/[firstname].[lastname](.number) Example: open.id.ee/martin.paljak&lt;br /&gt;
There will be two types of hardware token:&lt;br /&gt;
(1) Traditional Smart Card.&lt;br /&gt;
(2) GSM sim card.&lt;br /&gt;
The service is provided from open.id.ee and the service will be expanded to other EU eID-s (Belgium, Finland, Spain, Portugal).&lt;br /&gt;
For details, see: https://open.id.ee/about/english
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=18</link>
        </item>
        <item>
            <title>Talk with Drummond</title>
            <description>	&lt;p&gt;Talked with Drummond this morning at iiw2007 . Finally getting to know the problem space that he is tackling. I have always been very vague on what he talks on Subject-predicate etc. and graph model etc.&lt;br /&gt;
Identifier usually is a pointer to an object and nothing more, but what he is trying to do is to build the relationship expression into the identifier itself.&lt;br /&gt;
To illustrate it, he was using &lt;/p&gt;
	&lt;p&gt;has&lt;br /&gt;
has a&lt;br /&gt;
is&amp;nbsp;&lt;br /&gt;
is a&lt;br /&gt;
relationship. The example that he was drawing on was something like this.&lt;br /&gt;
=drummond/$is/=drummond.reed=drummond/$is$a/+person=drummond/$has/+name+first/(someref)=drummond/$has/+name+first//&quot;Drummond&quot;=drummond/$has$a/+car&lt;br /&gt;
Then he went on to the smplification of later two like&lt;br /&gt;
=drumond/+name+first//&quot;Drummond&amp;#8221;&lt;br /&gt;
According to him, $has and $has$a can be shortcut.&lt;br /&gt;
Looks like when &amp;#8220;=&amp;#8221; and &amp;#8220;@&amp;#8221; is the first segment, then &amp;#8220;/&amp;#8221; means &amp;#8220;has&amp;#8221; or &amp;#8220;has &amp;#8230;
&lt;/p&gt;
</description>
            <link>http://www.sakimura.org/en/modules/wordpress/index.php?p=17</link>
        </item>
    </channel>
</rss>