<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My Christmas Wish List: Personal Identity-Persona Service</title>
	<atom:link href="http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Thu, 15 Jul 2010 18:27:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Nick Taylor &#8211; Watching my PII</title>
		<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/comment-page-1/#comment-1042</link>
		<dc:creator>Nick Taylor &#8211; Watching my PII</dc:creator>
		<pubDate>Wed, 06 Jan 2010 22:26:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/#comment-1042</guid>
		<description>[...] it all in a secure manner, I&#8217;d like a service along the lines of that described by Mark Dixon here to manage it all; though as I commented on his post, I&#8217;d like something a bit more [...]</description>
		<content:encoded><![CDATA[<p>[...] it all in a secure manner, I&#8217;d like a service along the lines of that described by Mark Dixon here to manage it all; though as I commented on his post, I&#8217;d like something a bit more [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Dixon</title>
		<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/comment-page-1/#comment-542</link>
		<dc:creator>Mark Dixon</dc:creator>
		<pubDate>Thu, 24 Dec 2009 13:07:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/#comment-542</guid>
		<description>&lt;p&gt;Hi Nick:&lt;/p&gt;
&lt;p&gt;Your idea of extending the audit process is a great thought.&lt;/p&gt;
&lt;p&gt;I do share your fear that a viable business model that addresses both the complex functionality some of us techies want while addressing the much less complex needs of the majority may be hard to come by.&lt;/p&gt;
&lt;p&gt;Happy Holidays!&lt;/p&gt;
&lt;p&gt;Mark&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi Nick:</p>
<p>Your idea of extending the audit process is a great thought.</p>
<p>I do share your fear that a viable business model that addresses both the complex functionality some of us techies want while addressing the much less complex needs of the majority may be hard to come by.</p>
<p>Happy Holidays!</p>
<p>Mark</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick Taylor</title>
		<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/comment-page-1/#comment-541</link>
		<dc:creator>Nick Taylor</dc:creator>
		<pubDate>Thu, 24 Dec 2009 11:32:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/#comment-541</guid>
		<description>&lt;p&gt;Hi Mark,&lt;/p&gt;
&lt;p&gt;I like the idea of the PIPS as you&#039;ve described it, but as somewhat of a data nerd, there&#039;s a further piece of functionality I&#039;d like to see.&lt;/p&gt;
&lt;p&gt;It&#039;s an extension of your audit point, where you&#039;re focused inwards on use of the PIPS itself - instead I&#039;d like to see which SPs have my data, and whether they took a one-off copy from the PIPS IdP or if they have ongoing access. &lt;/p&gt;
&lt;p&gt;Additionally, Ideally some kind of contract between the PIPS and the various SPs using my identity data that allows me - within the PIPS - to define how they can use my data.&lt;/p&gt;
&lt;p&gt;Alas I fear the trouble with this utopian service is that typical consumers just don&#039;t care enough to make it a viable business proposition. &lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi Mark,</p>
<p>I like the idea of the PIPS as you&#8217;ve described it, but as somewhat of a data nerd, there&#8217;s a further piece of functionality I&#8217;d like to see.</p>
<p>It&#8217;s an extension of your audit point, where you&#8217;re focused inwards on use of the PIPS itself &#8211; instead I&#8217;d like to see which SPs have my data, and whether they took a one-off copy from the PIPS IdP or if they have ongoing access. </p>
<p>Additionally, Ideally some kind of contract between the PIPS and the various SPs using my identity data that allows me &#8211; within the PIPS &#8211; to define how they can use my data.</p>
<p>Alas I fear the trouble with this utopian service is that typical consumers just don&#8217;t care enough to make it a viable business proposition. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Dixon</title>
		<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/comment-page-1/#comment-540</link>
		<dc:creator>Mark Dixon</dc:creator>
		<pubDate>Wed, 23 Dec 2009 18:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/#comment-540</guid>
		<description>&lt;p&gt;Bob:&lt;/p&gt;
&lt;p&gt;Yes, it appears that your Kantara Group is focused directly on the issues that I bring up in my post. And I agree that the business issues, such as how IdP&#039;s make money and how RP&#039;s can be properly incented to work with the IdP&#039;s are the biggest factors delaying implementation of such a system.&lt;/p&gt;
&lt;p&gt;I look forward to seeing monitoring your work with Kanatara and reading the white papers you are producing.  I&#039;d be happy to discuss my ideas and views in more detail if you would like.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Mark&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Bob:</p>
<p>Yes, it appears that your Kantara Group is focused directly on the issues that I bring up in my post. And I agree that the business issues, such as how IdP&#8217;s make money and how RP&#8217;s can be properly incented to work with the IdP&#8217;s are the biggest factors delaying implementation of such a system.</p>
<p>I look forward to seeing monitoring your work with Kanatara and reading the white papers you are producing.  I&#8217;d be happy to discuss my ideas and views in more detail if you would like.</p>
<p>Thanks,</p>
<p>Mark</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Pinheiro</title>
		<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/comment-page-1/#comment-539</link>
		<dc:creator>Bob Pinheiro</dc:creator>
		<pubDate>Wed, 23 Dec 2009 17:20:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/#comment-539</guid>
		<description>&lt;p&gt;Mark, take a look at the work of the Kantara Initiative&#039;s Consumer Identity Work Group, of which I&#039;m Chair.  I think your desires for a PIPS service are consistent with the goals of the WG.&lt;/p&gt;
&lt;p&gt;The idea of a bank (or anyone else) acting as your identity provider presents at least two problems.  The first is liability.  What if a mistake is made, and an imposter is able to claim your identity?  Is the bank liable in any way?  Which gets to the second problem:  What is the business model for the bank to act as your IdP?  Can they make any money by doing it?  Why should they accept any liability if something goes wrong?  I think banks would need to really push something like this, and educate the public about why this would be beneficial, to get sufficient uptake.&lt;/p&gt;
&lt;p&gt;Then there are the Service Providers / Relying Parties who will rely on an identity assertion from your bank.  Are there sufficient incentives in place to motivate these SPs/RPs to care enough about who they are dealing with in high value transactions?  Many SPs/RPs don&#039;t want to scare off customers by requiring stronger forms of authentication, but someone eventually has to pay when fraud occurs.  And payment may not always be monetary; there may be &quot;payment&quot; in terms of a damaged reputation.  &lt;/p&gt;
&lt;p&gt;I&#039;m hoping the US government&#039;s Open Identity Initiative, which is starting out with low assurance applications in which a person&#039;s true identity doesn&#039;t matter, will eventually spur progress towards greater deployments of high assurance consumer identity services.  &lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Mark, take a look at the work of the Kantara Initiative&#8217;s Consumer Identity Work Group, of which I&#8217;m Chair.  I think your desires for a PIPS service are consistent with the goals of the WG.</p>
<p>The idea of a bank (or anyone else) acting as your identity provider presents at least two problems.  The first is liability.  What if a mistake is made, and an imposter is able to claim your identity?  Is the bank liable in any way?  Which gets to the second problem:  What is the business model for the bank to act as your IdP?  Can they make any money by doing it?  Why should they accept any liability if something goes wrong?  I think banks would need to really push something like this, and educate the public about why this would be beneficial, to get sufficient uptake.</p>
<p>Then there are the Service Providers / Relying Parties who will rely on an identity assertion from your bank.  Are there sufficient incentives in place to motivate these SPs/RPs to care enough about who they are dealing with in high value transactions?  Many SPs/RPs don&#8217;t want to scare off customers by requiring stronger forms of authentication, but someone eventually has to pay when fraud occurs.  And payment may not always be monetary; there may be &quot;payment&quot; in terms of a damaged reputation.  </p>
<p>I&#8217;m hoping the US government&#8217;s Open Identity Initiative, which is starting out with low assurance applications in which a person&#8217;s true identity doesn&#8217;t matter, will eventually spur progress towards greater deployments of high assurance consumer identity services.  </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Dixon</title>
		<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/comment-page-1/#comment-538</link>
		<dc:creator>Mark Dixon</dc:creator>
		<pubDate>Wed, 23 Dec 2009 15:26:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/#comment-538</guid>
		<description>&lt;p&gt;Mark:&lt;/p&gt;
&lt;p&gt;Thanks for your feedback.  I&#039;m working on a piece for healthcare.  I&#039;d like to get your feedback when it&#039;s done.&lt;/p&gt;
&lt;p&gt;I agree that too many choices can complicate things.  A good system needs to be flexible enough to accommodate the &quot;power user&quot; but simple enough for non-techies to master easily.&lt;/p&gt;
&lt;p&gt;Mark&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Mark:</p>
<p>Thanks for your feedback.  I&#8217;m working on a piece for healthcare.  I&#8217;d like to get your feedback when it&#8217;s done.</p>
<p>I agree that too many choices can complicate things.  A good system needs to be flexible enough to accommodate the &quot;power user&quot; but simple enough for non-techies to master easily.</p>
<p>Mark</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Montgomery</title>
		<link>http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/comment-page-1/#comment-537</link>
		<dc:creator>Mark Montgomery</dc:creator>
		<pubDate>Wed, 23 Dec 2009 11:51:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.discoveringidentity.com/2009/12/23/my-christmas-wish-list-personal-identity-persona-service/#comment-537</guid>
		<description>&lt;p&gt;I like it Mark generally. I have often thought that the banking model should be used for personal healthcare, but the problem of course is that unlike banking where our money is consolidated, healthcare records are fragmented, in multiple formats even when digitized....&lt;/p&gt;
&lt;p&gt;I particularly like the focus on ease of use, but think you have too many choices still for ave user. After all we only have one true identity, and it should be ours to control -- no exceptions, whether banking, healthcare, or anything else.&lt;/p&gt;
&lt;p&gt;I prefer encrypted finger print combined with password protection. .02- MM&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I like it Mark generally. I have often thought that the banking model should be used for personal healthcare, but the problem of course is that unlike banking where our money is consolidated, healthcare records are fragmented, in multiple formats even when digitized&#8230;.</p>
<p>I particularly like the focus on ease of use, but think you have too many choices still for ave user. After all we only have one true identity, and it should be ours to control &#8212; no exceptions, whether banking, healthcare, or anything else.</p>
<p>I prefer encrypted finger print combined with password protection. .02- MM</p>
]]></content:encoded>
	</item>
</channel>
</rss>
