<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Twitter</title>
	<atom:link href="http://blog.talkingidentity.com/tag/twitter/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The Difference between Twitter as Utility and Twitter as IdP</title>
		<link>http://blog.talkingidentity.com/2011/06/the-difference-between-twitter-as-utility-and-twitter-as-idp.html</link>
		<comments>http://blog.talkingidentity.com/2011/06/the-difference-between-twitter-as-utility-and-twitter-as-idp.html#comments</comments>
		<pubDate>Thu, 09 Jun 2011 15:14:39 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Identity in Social Networking]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS 5]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1219</guid>
		<description><![CDATA[The buzz, and confusion, around the Twitter-iOS integration is incredible, especially among the identirati. It&#8217;s created some very interesting twitter discussions, and some huge claims about what this means for Twitter, Apple and the social landscape in general. I&#8217;ve now seen a number of articles that equated the WWDC announcement as confirming that &#8220;Twitter is [...]]]></description>
			<content:encoded><![CDATA[<p>The buzz, and confusion, around the <strong>Twitter-iOS integration</strong> is incredible, especially among the identirati. It&#8217;s created some very interesting twitter discussions, and some huge claims about what this means for Twitter, Apple and the social landscape in general. I&#8217;ve now seen a number of articles that equated the WWDC announcement as confirming that &#8220;<a href="http://bit.ly/iqzQwo" target="_blank">Twitter is now the Identity Provider for Apple</a>&#8220;. Since so much of what we&#8217;re hearing seems to be speculation, I&#8217;m going to wait for today&#8217;s debriefing on the integration to provide details before I comment on the implications of the integration (<a href="http://bit.ly/jSZ3jo" target="_blank">Phil Hunt</a> will be my Bob Woodward on this, doing all the investigative reporting from the event). But I do want to explain the difference I see between Twitter as Utility and Twitter and IdP.</p>
<p><strong><img class="alignright size-full wp-image-1221" title="Utility-Pipe" src="http://blog.talkingidentity.com/wp-content/uploads/2011/06/Utility-Pipe.jpg" alt="Utility-Pipe" width="200" height="194" />TWITTER AS UTILITY </strong>is very similar to how &#8220;Email Photo&#8221; works when you&#8217;re in the <em>Photos </em>app. When you click on the button, the <em>Photos </em>app knows how to call the iOS API to send the picture to the <em>Mail </em>app. From that point on, it is the <em>Mail</em> app that deals with how to send it out as an email, including knowing which account on which email provider (out of many even) to use. The <em>Photos </em>app neither knows nor cares about this. In the <em>Flickr </em>app, an app backed by an online service, when I click on &#8220;Email Photo&#8221;, the app simply pulls down the URL for the photo and sends that (via the iOS API) to the <em>Mail </em>app. My Flickr service saw nothing about which email provider was used. This is how the &#8220;Tweet Photo&#8221; button could end up working (except that it doesn&#8217;t launch an app but rather an in-built interface to writing up the tweet). Through and after all this, <span style="text-decoration: underline;">no</span> relationship exists between my Flickr account and my Twitter account. Implication = there is nothing to revoke either.</p>
<p><strong><img class="alignright size-full wp-image-1222" title="Bank" src="http://blog.talkingidentity.com/wp-content/uploads/2011/06/Bank.jpg" alt="Bank" width="200" height="175" />TWITTER AS IdP </strong>is much more involved in not only the app, but in the online service the app represents. The first time I download and launch an app like the <em>LivingSocial</em> app, it will want to associate that app with an account in the LivingSocial service. In a scenario where I&#8217;ve never LivingSocial before, it will want me to register for an account. In the current pre iOS 5 world, this involves the app showing me 3 options &#8211; &#8220;Register for Account&#8221;, &#8220;Sign In with Twitter&#8221;, &#8220;Sign In with Facebook&#8221;. Clicking on &#8220;Sign In with Twitter&#8221; would send me through the OAuth dance. If Twitter truly were an IdP in iOS, then this experience would change radically. (Hypothetically) I would instead get the option to &#8220;Sign Up with You Twitter Identity&#8221; or &#8220;Other Options&#8221;, and clicking on the first would just get me in, without having to go through the OAuth dance. In fact, if there were an iOS setting that allowed me to set my preference to  always register for services with Twitter (provided the service supports that), then I may never even see the sign up screen. And the backend service now relies on Twitter as my IdP, maybe even being authorized (OAuth permissioning) to interact with it even outside of when I use the app (like if I sign up for a deal while interacting with the website on my computer).</p>
<p>The implications of the latter are pretty vast, in terms of what controls iOS would need to provide users over how to authorize, permission and revoke access. This would be no easy undertaking, and like the Facebook privacy settings we all love to hate, could get very messy and complicated to understand and manage.</p>
<p>Your thoughts? And like I said, I look forward to learning more in today&#8217;s event.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/identity-in-social-networking" rel="tag">Identity in Social Networking</a>, <a href="http://blog.talkingidentity.com/tag/ios" rel="tag">iOS</a>, <a href="http://blog.talkingidentity.com/tag/ios-5" rel="tag">iOS 5</a>, <a href="http://blog.talkingidentity.com/tag/oauth" rel="tag">OAuth</a>, <a href="http://blog.talkingidentity.com/tag/twitter" rel="tag">Twitter</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/06/the-difference-between-twitter-as-utility-and-twitter-as-idp.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quick Thoughts on the Twitter-iOS Integration</title>
		<link>http://blog.talkingidentity.com/2011/06/quick-thoughts-on-the-twitter-ios-integration.html</link>
		<comments>http://blog.talkingidentity.com/2011/06/quick-thoughts-on-the-twitter-ios-integration.html#comments</comments>
		<pubDate>Tue, 07 Jun 2011 15:27:48 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS 5]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1217</guid>
		<description><![CDATA[One of the big announcements at yesterdays WWDC conference was the integration of Twitter into iOS 5 (those screenshots are nice!). Twitter fanatics are going gaga about this, talking about how this is a game-changer and even conjecturing on what the apparent Facebook snub means. However, what I want to know is &#8211; what does [...]]]></description>
			<content:encoded><![CDATA[<p>One of the big announcements at yesterdays WWDC conference was the <a href="http://tcrn.ch/lfh4iM" target="_blank">integration of Twitter into iOS 5</a> (those screenshots are nice!). Twitter fanatics are going gaga about this, talking about how <a href="http://tnw.co/la4E2N" target="_blank">this is a game-changer</a> and even conjecturing on what the <a href="http://read.bi/lmxvr2" target="_blank">apparent Facebook snub</a> means. However, what I want to know is &#8211; what does this mean for how <strong>OAuth</strong> is used to integrate with Twitter.</p>
<p>First things first, it isn&#8217;t even clear if the integration between iOS and Twitter is based on OAuth or Twitter&#8217;s own xAuth. One would hope the former given Twitter&#8217;s <a href="http://bit.ly/m5nvZC" target="_blank">stated direction</a>. Ping Identity&#8217;s resident OAuth wizard Paul Madsen tried to imagine what the <a href="http://bit.ly/lnX4U3" target="_blank">OAuth based integration would look like</a>. Looking at it made me wonder if we&#8217;re seeing a radical change in how OAuth could be used on devices.</p>
<p>The problem is this: Apple is (justifiably) proud of the attention they pay to the usability of their products. And the OAuth flow would seem to be a problem here. In the simplest form, authorizing all the apps in iOS (camera, contacts, safari, etc) to have Twitter access would repeatedly send the user through the OAuth flow, a user experience I doubt Apple would agree to. So the question is whether a single request token asked for by iOS could be shared amongst all the apps on iOS. If yes, then how can the user manage permissions regarding what these apps can do individually? And how would they revoke a specific app? This model would make it highly unlikely that the integration would extend to 3rd party apps installed from the app store (because of that lack of separation).</p>
<p>Another possibility is that iOS will include some APIs that <strong>proxy </strong>the Twitter integration. So all communication to Twitter would simply originate from iOS, not from the apps directly. This would eliminate the need for multiple OAuth flows, but the same challenges around permissioning and revocation would remain. On Twitter, the user would just see one app authorized for access &#8211; iOS/iPhone/iPad. One way I can see Apple mitigating this while also opening this feature up to 3rd party apps is by adding their own app specific permission layer in the iOS settings. Which would be a practical way to manage this, and open up a whole slew of questions around OAuth and OAuth proxies on devices.</p>
<p>Of course, all of this is moot if the integration requires me to go into iOS settings and enter my Twitter username and password&#8230;</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/apple" rel="tag">Apple</a>, <a href="http://blog.talkingidentity.com/tag/ios" rel="tag">iOS</a>, <a href="http://blog.talkingidentity.com/tag/ios-5" rel="tag">iOS 5</a>, <a href="http://blog.talkingidentity.com/tag/oauth" rel="tag">OAuth</a>, <a href="http://blog.talkingidentity.com/tag/twitter" rel="tag">Twitter</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/06/quick-thoughts-on-the-twitter-ios-integration.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Connection Denied: Why the Military should play with Social Media</title>
		<link>http://blog.talkingidentity.com/2009/08/connection-denied-why-the-military-should-play-with-social-media.html</link>
		<comments>http://blog.talkingidentity.com/2009/08/connection-denied-why-the-military-should-play-with-social-media.html#comments</comments>
		<pubDate>Mon, 31 Aug 2009 19:54:59 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Data Leakage Protection]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Oracle_IDM]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=624</guid>
		<description><![CDATA[A few weeks ago, while I was at Catalyst, I read an article about the marines banning the use of social media. The policy on social media usage is far from consistent within our armed forces, as revealed in this Stars and Stripes story that shows just how confused and divided the policy makers are: [...]]]></description>
			<content:encoded><![CDATA[<p>A few weeks ago, while I was at Catalyst, I read an <a href="http://www.wired.com/dangerroom/2009/07/military-may-ban-twitter-facebook-as-security-headaches/" target="_blank">article about the marines banning the use of social media</a>. The policy on social media usage is far from consistent within our armed forces, as revealed in <a href="http://www.stripes.com/article.asp?section=104&amp;article=64044" target="_blank">this Stars and Stripes story</a> that shows just how confused and divided the policy makers are:</p>
<blockquote><p>Marines can’t use Twitter or Facebook on duty, but soldiers and sailors can. For airmen, it depends on the base.<br />
As for YouTube, the Air Force has created its own channel &#8211; which can’t be accessed from work computers.</p></blockquote>
<p>A lot of people in favor of social media use (including yours truly) view it as an important communication and PR tool, providing some much needed openness and transparency in a time of record low recruitment and mistrust. It is also viewed as a weapon for the military to take back the narrative regarding the wars in Iraq and Afghanistan from the hype-driven media. The rate at which information can be gleaned from these media makes them effective early-warning systems on all manner of critical events &#8211; from earthquakes to civil war and revolutions. And don&#8217;t forget how incredibly useful it is as a tool for our troops to stay in contact with friends and loved ones. For a much better, insider take on how critical the use of social media is to our national security, read <a href="http://www.federaltimes.com/index.php?S=4245792" target="_blank">this extremely well-written article</a> in the Federal Times.</p>
<p>I shared the story on twitter, along with <a href="http://twitter.com/NishantK/status/2953691440" target="_blank">my opinion</a> that the ban was the wrong approach for the military to be taking. <a href="http://twitter.com/brad_tumy" target="_blank">Brad Tumy</a> <a href="http://twitter.com/brad_tumy/status/2953822426" target="_blank">challenged me to explain</a> why I thought it was the wrong approach, and what I think they should be doing instead. I promised I would address his question in a blog post soon, so here goes.</p>
<p>Lets take a look at some of the main reasons given for banning social media.</p>
<h3>1) Bandwidth Issues</h3>
<p>The amount of bandwidth sucked up by YouTube, Facebook and the like puts a strain on limited DoD resources. But today, network tools that monitor bandwidth usage and throttle the traffic based on conditions are quite common. And using geolocation and device identification to cut off access on machines being used in the field (that use extremely limited satellite-based bandwidth) is technically possible (and as someone I met at Catalyst told me in a different context, is being done every day).</p>
<h3>2) Spread of Malware</h3>
<p>Highly publicized incidents like the Koobface worm spreading via Facebook have led some of the security experts to consider these sites to be tremendously dangerous to the integrity of the DoD networks. But the malware threat from social media is nothing compared to the attacks the DoD has to fend off on a daily basis via sanctioned channels, namely <a href="http://fcw.com/articles/2008/03/06/osd-cio-network-configuration-scanning-softened-cyberattack-blow.aspx" target="_blank">email</a> and so called <a href="http://www.ukfast.co.uk/internet-news/microsoft_admits_msn_hack_in_s_korea.html" target="_blank">&#8220;good&#8221; websites</a>. And the tools to protect against the malware attacks are well understood and widely deployed. Most folks learn pretty quickly to identify and ignore malware messages, no matter what the medium. And cloud-based social media sites will do a much better job of cutting an attack off at the knees than thousands of distributed email systems ever will.</p>
<h3>3) Information Leakage</h3>
<p>In providing their reason for banning social media, the Marine Corps said</p>
<blockquote><p>the very nature of social networking sites creates a larger attack and exploitation window, exposes unnecessary information to adversaries and provides an easy conduit for information leakage.</p></blockquote>
<p>This is probably the most serious cause for concern, and one where IAM and Security technologies can play a crucial role. In many cases, the challenge here is similar to the one faced when dealing with any communication channel, whether it be email or ftp. Many enterprises rely on <strong>Security Information Management</strong> to protect their most sensitive resources &#8211; their data. A well established <strong>Identity Management </strong>infrastructure provides the first layer of protection by ensuring that only authorized individuals have access to sensitive information, and then providing a complete audit trail around the access of that data. This has been shown to have a deterrent effect in information protection, and can assist in tracing back the source of a data leak. <strong>DLP</strong> (Data Leakage Protection) tools provide data security by enabling data identification, classification, usage and wrapping controls around it all. <strong>Firewalls</strong> are getting increasingly sophisticated (take a look at <a href="http://www.paloaltonetworks.com/" target="_blank">Palo Alto Networks</a>, which is getting traction with a <strong>content inspection engine</strong> that can &#8220;<em>accurately identify applications &#8230; and scan content to stop threats and prevent data leakage</em>&#8220;). The fact that Facebook and Twitter have APIs that allow the creation of <strong>custom clients</strong> means that users can be given access in a secure way through apps developed by the military. And there is commercial software out there that does much the same.</p>
<p>Now, the way I see it, the armed forces are facing the exact same dilemma that most enterprises are facing when considering how to tackle the use of social media in the workplace. The only difference is in the amplification of the potential consequences. Exploitation of the attack window that social media use creates could lead an enterprise to lose a lot of money, but in the case of the armed forces it could lead to serious loss of life. That does mean that while the issues are the same, the risks are vastly different. This would necessitate a completely different risk mitigation strategy. But does that mean that the solutions that can help would change too?</p>
<p>A blanket ban such as the one being discussed would lead you to believe that there exists no ability to handle what are essentially security and access control issues in the system, and that simply is not the case. I&#8217;m not saying that it is perfect, but a combination of tools, policies and guidelines can make it possible for social media to be leveraged by the military in ways that serves their (and our) national cause without harming their mission. And that would be to everyone&#8217;s benefit.</p>
<p>If you ever saw the movie &#8220;Breach&#8221; about how Robert Hanssen leaked national secrets by photocopying files and carrying them out in his bag, just think of how much more quickly he might have been caught if he had been sending those files over a social media connection. USB drives and email are far bigger threats (right now) than social media. and by being proactive, the military can turn these tools to their advantage. On the other hand, by not playing in one of the emerging technologies in the market, the US military risks becoming outdated, outmoded and outplayed by our adversaries.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/data-leakage-protection" rel="tag">Data Leakage Protection</a>, <a href="http://blog.talkingidentity.com/tag/dlp" rel="tag">DLP</a>, <a href="http://blog.talkingidentity.com/tag/facebook" rel="tag">Facebook</a>, <a href="http://blog.talkingidentity.com/tag/firewall" rel="tag">Firewall</a>, <a href="http://blog.talkingidentity.com/tag/identity-management" rel="tag">Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/military" rel="tag">Military</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a>, <a href="http://blog.talkingidentity.com/tag/social-media" rel="tag">Social Media</a>, <a href="http://blog.talkingidentity.com/tag/social-networking" rel="tag">Social Networking</a>, <a href="http://blog.talkingidentity.com/tag/twitter" rel="tag">Twitter</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/08/connection-denied-why-the-military-should-play-with-social-media.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Identity Proofing on Twitter &#8211; problems and potential</title>
		<link>http://blog.talkingidentity.com/2009/06/identity-proofing-on-twitter-problems-and-potential.html</link>
		<comments>http://blog.talkingidentity.com/2009/06/identity-proofing-on-twitter-problems-and-potential.html#comments</comments>
		<pubDate>Fri, 12 Jun 2009 20:00:02 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Personal Identity Management]]></category>
		<category><![CDATA[Identity Proofing]]></category>
		<category><![CDATA[Reputation Management]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Twitter Verified Accounts]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=521</guid>
		<description><![CDATA[All the web has been abuzz recently about Twitters launch of Verified Accounts (read Mashable&#8217;s post about it here). The goal of the program is to be able to show a badge on a Twitter account that communicates to readers the authenticity of the twitter stream. The reason for Twitter doing this is to avoid [...]]]></description>
			<content:encoded><![CDATA[<p>All the web has been abuzz recently about Twitters launch of <em>Verified Accounts</em> (read Mashable&#8217;s post about it <a href="http://mashable.com/2009/06/11/twitter-verified-accounts-2/" target="_blank">here</a>). <img src="http://ec.mashable.com/wp-content/uploads/2009/06/verifiedaccount.gif" alt="" align="right" />The goal of the program is to be able to show a badge on a Twitter account that communicates to readers the authenticity of the twitter stream. The reason for Twitter doing this is to avoid issues and lawsuits due to celebrity impersonators. This limited goal is reflected in the proofing mechanism they are relying on &#8211; <em>Manual Verification</em> (the equivalent of the age-old, well understood Know-Your-Customer mechanism of in-person verification).</p>
<p>TechCrunch <a href="http://www.techcrunch.com/2009/06/11/twitter-starts-verifying-accounts-without-verifying-them/" target="_blank">blogged about</a> Michael Arrington&#8217;s twitter account getting verified without appearing to be verified (no one contacted him). This <a href="http://mashable.com/2009/06/06/twitter-verified-accounts/" target="_blank">Mashable post </a>may explain how this happened:</p>
<blockquote><p>&#8230;Twitter will look to see if an official channel of the person in question links to his or her Twitter account from a place like an official website.</p></blockquote>
<p>This is a good model for verifying a channel -  to look at a known <span style="text-decoration: underline;">official</span> channel to see if it (officially) links to the channel being verified. However, it doesn&#8217;t scale beyond the celebrity use case, because the vast majority of users (like me) do not have <em>anything that Twitter will recognize as</em> an official channel. And Twitter will never have the manpower necessary to run an in-person verification program. But is there a clue buried in how Twitter is approaching this to how we could potentially do this at scale?</p>
<p>An emerging discussion in the identity space has been the topic of <strong>reputation as the basis of trust</strong> (which is what verified accounts are ultimately about). In the Twitter model, the reputation of the account is enhanced 100% because of it being cited on a well-known, officially recognized website. I recently <a href="http://www.wired.com/culture/geekipedia/magazine/17-06/mf_impactfactor" target="_blank">read a Wired article</a> about a new system for ranking/rating scientists based on number of citations as opposed to publications. Twitter has multiple (similar) variables that could potentially be used to calculate the reputation of a twitter account &#8211; number of followers, number of retweets, number/nature/participants of conversations (replies).</p>
<p>If these could be used to calculate the reputation of a twitter account, then you could get to the point where you could calculate the trustworthiness of an account. And then the whole &#8220;log in with your twitter account&#8221; feature that for now is only getting used in blog commenting systems could take on a much more significant role in the identity metasystem.<br />
<a href="http://geekandpoke.typepad.com/geekandpoke/2009/06/living-in-web-2010-rule-1.html" target="_blank"><img src="http://geekandpoke.typepad.com/.a/6a00d8341d3df553ef011570d161ab970b-800wi" alt="" /></a></p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/identity-proofing" rel="tag">Identity Proofing</a>, <a href="http://blog.talkingidentity.com/tag/personal-identity-management" rel="tag">Personal Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/reputation-management" rel="tag">Reputation Management</a>, <a href="http://blog.talkingidentity.com/tag/twitter" rel="tag">Twitter</a>, <a href="http://blog.talkingidentity.com/tag/twitter-verified-accounts" rel="tag">Twitter Verified Accounts</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/06/identity-proofing-on-twitter-problems-and-potential.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The new Identity Equation</title>
		<link>http://blog.talkingidentity.com/2009/05/the-new-identity-equation.html</link>
		<comments>http://blog.talkingidentity.com/2009/05/the-new-identity-equation.html#comments</comments>
		<pubDate>Tue, 12 May 2009 02:18:58 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Personal Identity Management]]></category>
		<category><![CDATA[Relationship Management]]></category>
		<category><![CDATA[Reputation Management]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Twitter Search]]></category>
		<category><![CDATA[User-Centric Identity]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=480</guid>
		<description><![CDATA[A few days ago, I tweeted about this CNET article that talks about the plans that Twitter has to expand their search service into what could be one of the most powerful real-time search engines anywhere. The key to this whole thing is the idea of reputation &#8211; that ephemeral quality that will improve the [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago, I <a href="http://twitter.com/NishantK/status/1731934163" target="_blank">tweeted</a> about <a href="http://news.cnet.com/8301-17939_109-10235360-2.html" target="_blank">this CNET article</a> that talks about the plans that Twitter has to expand their search service into what could be one of the most powerful real-time search engines anywhere. The key to this whole thing is the idea of reputation &#8211; that ephemeral quality that will improve the search quality by bubbling to the top results that are more relevant based on how reputed the source is.</p>
<blockquote><p>Twitter Search will also get a &#8220;reputation&#8221; ranking system soon, Jayaram told me. When you do a search on a &#8220;trending&#8221; topic&#8211;a topic that is so big it gets its own link in the Twitter.com sidebar&#8211;Twitter will take into account the reputation of the person who wrote each tweet and rank the search results in part based on that.</p></blockquote>
<p>The article does mention that the engineering team at Twitter is still trying to figure out how to do this. But no more than a day later, Stan Schroeder of Mashable <a href="http://mashable.com/2009/05/08/gfail-twitter/" target="_blank">pointed out</a> one of the key aspects to making reputation work &#8211; it has to be context-sensitive with respect to the identity of the source and their authority on the subject.</p>
<blockquote><p>Thinking about it, it seems that this reputation ranking system is far more complex than a simple combination of factors such as followers and retweets. The system needs to be <strong>contextual</strong>; it needs to recognize which tweeple are important for a certain keyword or phrase. For example, tweets from the White House, Barack Obama and politicians aren’t that useful in the context of a Gmail outage, but they’re crucial during some political event.</p></blockquote>
<p>In other words, the reputation engine (if it is to be done right) can&#8217;t just look at the number of followers, the number of retweets and hashtags. It also can&#8217;t rely purely on the 140 character biography that all the tweeples have posted on their twitter profiles. No, to really do this thing justice, Twitter (or some other company that could step in) would need to navigate the semantic, social and identity web in a way that builds up an accurate picture of a persons authority regarding a particular subject. And it is not just based on what we put out there, but even more so on what others put out there in response.</p>
<p>If this feels like somebody is about to start building a credit score of our online lives, it isn&#8217;t too far off the mark. The implications in the area of personal identity management and privacy could be huge!</p>
<p>This highlights a change we are seeing in the personal identity space. Since there are no secrets any more (as <a href="http://notabob.blogspot.com/" target="_blank">Bob Blakley</a> is wont to remind us every now and then), relationships and reputation are likely to become the primary variables in the identity equation. The question therefore is, what tools do we need to manage and control our online identity in light of this new perspective on identity? Is it simply about having an OpenID and clean living? What tools do the social networks like Facebook and LinkedIn need to incorporate that give us control over not just what we put out there, but what others put out there about us? It&#8217;s a tough nut to crack, and should make for some interesting discussions at IIW next week. Maybe I&#8217;ll throw it up there on the board as a topic.</p>
<p><a href="http://www.geekculture.com/joyoftech/joyarchives/001_300/051.html"><img class="aligncenter" title="Joy Of Tech" src="http://www.geekculture.com/joyoftech/joyimages/001_300/051.gif" alt="" width="513" height="475" /></a></p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/personal-identity-management" rel="tag">Personal Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/relationship-management" rel="tag">Relationship Management</a>, <a href="http://blog.talkingidentity.com/tag/reputation-management" rel="tag">Reputation Management</a>, <a href="http://blog.talkingidentity.com/tag/twitter" rel="tag">Twitter</a>, <a href="http://blog.talkingidentity.com/tag/twitter-search" rel="tag">Twitter Search</a>, <a href="http://blog.talkingidentity.com/tag/user-centric-identity" rel="tag">User-Centric Identity</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/05/the-new-identity-equation.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

