Showing posts with label trust. Show all posts
Showing posts with label trust. Show all posts

Sunday, July 08, 2007

Derived trust

Eric Norman, commenting on my chastization of Chase asks me:

Do you have any idea about what your mother would have an easy time of? That is, your mother would be able to say, "Yes, this is my bank", or "Wait a minute; something is wrong here" and get the right answer every time.

Would the green address bar be enough for your mother?

I started to answer in a comment myself, then thought that this topic was important enough to require its own discussion topic.

The answer to the "green address bar" being enough, of course, is: No. Color, pretty locks, etc. would not be enough for my mother nor, I suspect, many other mothers, fathers, brothers, sisters, etc.

What my mother needs is a means of deriving the trust of a site from other people that she knows and trusts and to have any site that isn't on that list to either be totally blocked or to set off all kinds of bells and whistles so that it's impossible for her to not realize she's walked out of the nice safe world into the dark inner city of the internet.

My mother would trust sites that I, or probably most of my siblings, had said were OK (which is essentially how she does things today, but with a phone call and without protection within the platform that she really is looking at the actual site one of us said was OK).

This would require some client enhancements in browsers and possibly in mailers, some reputation based host that she could point her client towards to say "include Conor's list in my set of sites," a means to get real-time approval, support for multiple such lists (so she could include my sister's list, or my brother's list) etc. etc. I think she would set it to block any non-OKed sites. Others would probably want to be able to add their own sites as well.

As I think about this, much of it feels like the kind of infrastructure AOL has in place for their parental controls (where the parent can control what their youngster has access to), though this would be the reverse direction and rather than a control, it would be advisory (because my mother could change the settings on her browser and do whatever she wants on her computer).

Tags : / / / / /

Thursday, December 21, 2006

Trust and OpenID #2

Avery Glasser writes of OpenID And Promiscuity:

As OpenID grows beyond wikis and blogs and becomes an identity system used for handling more secure or transactional data, the need to be able to trust specific Identity Providers becomes key. Methods such as the MediaWiki plugin may break part of the original vision of the standard, but it does provide the gateway towards OpenID’s future.

This just follows the train of thought I laid out in "Trust and OpenID" -- valuable transactions require security and trust across all parties.

When OpenID starts to solve those problems it can go through all the blood, sweat and tears that the folks at the Liberty Alliance and the OASIS SSTC did in coming up with a protocol that identified and closed many of the security vulnerabilities in such a system. Or they can adopt work that has been heavily reviewed and implemented which meets all of the needs that I have seen expressed and then some.

As I've stated earlier, even if there are some additions or profiles that are needed, I'm sure that the folks involved in SAML (where Liberty has converged their ID-FF work into) would be more than willing to explore meeting those needs.

The bottom line is that security is hard. There's no reason to go through that exercise yet again (unless you like pain).

Tags : / / / / / /