<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; MySpace</title>
	<atom:link href="http://blog.talkingidentity.com/tag/myspace/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>We need a strong Internet Identity Framework, NOW!</title>
		<link>http://blog.talkingidentity.com/2007/11/we_need_a_strong_internet_iden.html</link>
		<comments>http://blog.talkingidentity.com/2007/11/we_need_a_strong_internet_iden.html#comments</comments>
		<pubDate>Wed, 28 Nov 2007 23:43:18 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Personal Identity Management]]></category>
		<category><![CDATA[User-Centric Identity]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Identity Governance Framework]]></category>
		<category><![CDATA[Identity in Social Networking]]></category>
		<category><![CDATA[IGF]]></category>
		<category><![CDATA[Megan Meier]]></category>
		<category><![CDATA[MySpace]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=89</guid>
		<description><![CDATA[This is a little bit of a rant, but read this article in the New York Times and you may understand why. It is difficult to get past the feelings of disbelief, outrage and anger that the tragic story of Megan Meier will stir inside you. But if you somehow manage to move past it [...]]]></description>
			<content:encoded><![CDATA[<p>This is a little bit of a rant, but read <a href="http://www.nytimes.com/2007/11/28/us/28hoax.html?_r=1&amp;ref=us&amp;oref=slogin">this article</a> in the New York Times and you may understand why. It is difficult to get past the feelings of disbelief, outrage and anger that the tragic story of <span style="font-weight: bold;">Megan Meier</span> will stir inside you. But if you somehow manage to move past it and think about the implications, it becomes clear that there are some pretty important things that we (the identity community) need to work out, and fast.</p>
<p>Most of today&#8217;s social web applications (like MySpace and Facebook) are <span style="font-style: italic;">persona-based, not identity-based</span>. What I mean is that these applications don&#8217;t really care about who you are, they only care about letting you be what you want to be within their context. So, it is not surprising that a 47 year old woman was able to pose so devastatingly as a 16 year old boy, because in essence that is what MySpace was built to be &#8211; a way to express a persona of your choosing.</p>
<p>Why don&#8217;t these applications, that know the kind of impact they can have (we all understand the threat predators pose online) on a persons life, care about who you really are? Because, bluntly put, <span style="font-weight: bold;">they can&#8217;t</span>. It is not possible for them to do that in a scalable, cost-effective manner. The lack of a solid identity framework for the internet prevents these applications from being truly identity-based. We have seen a push towards heavy-handed <span style="font-weight: bold;">identity verification</span> mechanisms (see <a href="http://blogs.oracle.com/talkingidentity/2007/05/15">my earlier post</a> about identity verification in Second Life), but those solutions are so costly (time, infrastructure, cost) as to be impractical for most web applications. This kind of model will effectively curtail the free-wheeling collaborative spirit prevalent in the current generation of internet apps, and throttle innovation. If you had to stand in a line somewhere for 4 hours, and had to show your passport to someone, just so you could sign up for a Twitter account, would you?</p>
<p>A one-size-fits-all approach is not the answer. The correct solutions in life only come from taking a balanced approach to the problem. Nothing is more annoying to me when adding a Facebook app than being<br />
required to check the box agreeing to share my information with the<br />
app, even though I know that it doesn&#8217;t need <span style="font-style: italic;">any</span> of it, and most likely isn&#8217;t using it at all. Consequently, I avoid adding those apps unless I <span style="font-style: italic;">really</span> want to.</p>
<p>This is where pieces like Bob Blakely&#8217;s <span style="font-weight: bold;">Identity Oracle</span>, the <span style="font-weight: bold;">Identity Services </span>model, Burton&#8217;s <span style="font-weight: bold;">Limited Liability Persona</span>, the <span style="font-weight: bold;">IGF</span> and <span style="font-weight: bold;">user-centric methodologies</span> have to all  fit together. We do need strong identity verification mechanisms, but we shouldn&#8217;t need to go through that for every single site we want to use. Indirection is the solution to many a problem, and the right identity framework for the internet is the necessary thing to have this identity verification feed into a platform level identity that multiple applications can build on.</p>
<p>This is also needed as a necessary step to support <span style="font-weight: bold;">pseudonymity</span> online. The goal of an identity framework is not to prevent people from creating online personae that are<br />
divorced from reality. It is to give applications the ability to create<br />
suitable boundaries within which such a persona can be created. Using this,<br />
an application like MySpace, where the identity consequences can be so<br />
devastating, can choose to, for example, prevent people whose identity<br />
is in the 30+ age group from creating a persona that is in the 10-20<br />
age group.</p>
<p>Like so many things in modern life, we have gotten immune to all the horror stories of online predators. Until a story like this comes along to remind us that these are important things that we are working on, and we need to get it right.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/facebook" rel="tag">Facebook</a>, <a href="http://blog.talkingidentity.com/tag/identity-governance-framework" rel="tag">Identity Governance Framework</a>, <a href="http://blog.talkingidentity.com/tag/identity-in-social-networking" rel="tag">Identity in Social Networking</a>, <a href="http://blog.talkingidentity.com/tag/igf" rel="tag">IGF</a>, <a href="http://blog.talkingidentity.com/tag/megan-meier" rel="tag">Megan Meier</a>, <a href="http://blog.talkingidentity.com/tag/myspace" rel="tag">MySpace</a>, <a href="http://blog.talkingidentity.com/tag/personal-identity-management" rel="tag">Personal Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/user-centric-identity" rel="tag">User-Centric Identity</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2007/11/we_need_a_strong_internet_iden.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

