User-Centric Digital Identity

From P2P Foundation

Jump to: navigation, search


Proposals

Johannes Ernst:

"Around 2005/2006, there were about four major lines of thought on user-centric identity with a few variations. We can quibble about the exact numbers and times, but in broad strokes — which is what this post is all about — that seems about right.


(http://netmesh.info/jernst/big_picture/the-death-of-user-centric-identity-for-now)

Status

Johannes Ernst:

" here we are in 2011, and it is time to acknowledge that none of these original visions have worked out. Cardspace has been canceled. The rest of the proposals was, sort of, merged into what became OpenID. When we did this merger, we were all hoping that OpenID would end up being the sum of all (good) parts. Unfortunately, it became the opposite: an oddity not true to any of the visions, and far, very far, from being an aggregate of the best. Worse, its evolution has disintegrated into multiple incompatible architectures all of which have plenty of trees, but no forest. None of the original visionaries are actively involved in it any more, and it shows.

Here’s an example: current OpenID implementation practice is to use non-correlatable identifiers as the URLs that I envisioned for LID, in order to get CardSpace-like privacy features. But then, the first piece of information that is typically pushed to sites, Sxip-style, is the user’s e-mail address — a perfectly correlatable identifier if there ever was one. The identity push features in OpenID 2, from their roots in Sxip, are unused beyond a few like name and e-mail address; instead, any meaningful data exchange is performed using OAuth, an (incompatible) branch-off which is much closer in architecture to XDI and LID than to either Sxip or Cardspace, without any of the sophisticated query and privacy features envisioned in either, and without any aspirations whatsoever to be user-centric.

And because we totally, disastrously, failed in keeping the cats herded that like nothing better than to come up with a 5%-better version of some aspect of some obscure protocol oblivious to recognize that this splits the market and makes either version un-implementable, you can now chose between some power set of incompatible ways of implementing all of it, none of which ever has an even remote chance of really working on a mass scale.

The result: the top Quora answer on OpenID has 457 positive votes on “OpenID was doomed the day it launched”. Answer #6, with 25 votes, is the first positive response, and rather defensive at that. While the OpenID Foundation prods on, I have to say — and mind you, I was one of its co-founders — I have not the slightest clue what it is trying to do at this point in 2011. The most recent board meeting minutes sound very much like a typical management meeting would have been at Nokia if they hadn’t had the wits to bring in a new “The Platform is Burning” CEO.

The clear winner: Facebook. To their credit, they first hired the right people out of the identity world. Then, they thought hard how to turn user-centric identity into a product that mere mortals can understand — and that increases the Facebook stock price. That it has, literally by billions. Users’ lives have become better on the net as a result, but make no mistake: the primary beneficiary has been Facebook and its shareholders. There is nothing user-centric in Facebook’s implementation of identity. At least nothing that any of the above visionaries would recognize as part of their vision. Facebook-centric is the best way of calling it.

(To be clear, I have no problem with what Facebook did on this subject. In a competitive market, they should be held in check by competitive forces. Sadly, its competitors’ forces seem to have been exhausted by being asleep at the wheel to an extent I have a hard time grasping.)

So, for now user-centric identity is dead in the sense that it has been losing market share and mind share at a furious rate, with no white knight in sight. It was fun while the ride lasted. It will come back up for sure, with new visions by (likely) new visionaries. Decentralization, user-centricity, like democracy, does not ever die, it just disappears from sight for a while." (http://netmesh.info/jernst/big_picture/the-death-of-user-centric-identity-for-now)


More Information

  1. Interview with Kaliya Hamlin, 2007
  2. Overview page at Identity
  3. User-Centric Digital Identity Movement
Personal tools
Namespaces
Variants
Actions
p2pfoundation
Navigation
Toolbox

Share this content
Bookmark and Share