Showing posts with label Identity. Show all posts
Showing posts with label Identity. Show all posts

Tuesday, March 31, 2009

SocialWeb at Web 2.0 Expo

What has been happening with Data Portability on the Social Web. ie. OpenID, OAuth, etc.

The workshop is being run by @chrismessina, @daveman692 and @jsmarr

I will twitter comments from this session using the tag #w2e_sw

If you want to build new and innovative services you don't want to frustrate your users by asking for a bunch of account related data. If the data is out there go and get it. Don't Re-Key!

You need standards to enable mashups. Alternatively, you need consistent formats.

If standards exist - use them!

http://www.oxyweb.co.uk/blog produced a world map of popular social networks. This struck me as a great parallel to the HealthCare world with incompatible/competing health care players.

Functional sites, like Friendfeed, Twitter, last.fm and Dopplr represent specialist services. They have the opportunity to create combined value but they need a social graph to create this.

Facebook solved this for many, as long as developers were prepared to live inside facebook.

Activity streams are an emerging standard. No logo yet.

XMPP is not that popular yet, although it is one of the pipes that Twitter implemented and search.twitter.com leveraged.

Partuza is an Open Social - social Network site that uses Apache Shindig.

Pinax is a platform for rapidly developing websites using social tools such as IM, chat,

The emerging theme is "Connect"

Facebook Connect, OpenSocial Connect.

New building blocks:

  • Who you are
  • Who you know
  • What's going on

These are aspects of the social ecosystem. These create the virtual circle of sharing/knowing.

The anatomy of "Connect":

  • Profile (id, accounts profiles)
  • Relationships (friends, followers)
  • Content
  • Activity
  • Goal (search and discovery)

Most sites are building on the Open Stack:

  • MySpace
  • Yahoo
  • Google
  • Plaxo
  • Microsoft

Supporting:

  • OpenID
  • XRDS-Simple
  • OAuth
  • PortableContacts
  • OpenSocial

Facebook is different but is matching these standards.

Why do this?:

- Why do people have to:

  • Create a new account on every service
  • Re-create their profile
  • Give away their password to every site that asks
  • Re-discover their friends
  • re-friend their friends
  • Learn new ways to share and communicate

Why do developers have to?:

  • Deal with forgotten passwords
  • create another profile form
  • Support every new service API that emerges
  • Force members to invite everyone they know
  • Implement and unsafe method to import contacts
  • Create widgets for incompatible social networks
  • Manually interpret feeds for activity streams

Industry trends:

  • User control of data
  • User centric web services
  • Locatin based services
  • Real time content delivery ubiquitous connectivity
  • Interoperable app platforms
  • content aggregation and syndication
  • increasing quantities of data to work with
  • democratization of digital media creation tools

How do customers benefit:

MySpace has built login with OpenID and OAuth to compete with Facebook Connect.

OpenID popup extension is being developed to simplify the user interface, ala facebook connect.

The emerging issue is that once an item has been made "public" on a social network it can't be withdrawn. If you withdraw an item it may still exist in other places that were connected to the original publishing location.

Demos:

Now for the technical stuff:

OpenID Demo:

Mapquest (owned by AOL). You can sign in to mapquest with OpenID.

In 2009 there are over 30,000 sites that let you login with OpenID (Relying sites). Growth from 20,000 in August 2008 and 10,000 in Jan 2008. (source: http://blog.janrain.com)

Implementing OpenID as a relying party (ie. accept OpenID)

Internally you need to map one or more openIDs to an internal account.

The OpenID User experience

Directed Identity is emerging as one solution to avoid need for users to know URLs.

At least there aren't too many major providers so the button option is still feasible.

Once people have become known to a site it is possible to tailor re-sign in based upon where a user has come from. eg. If they arrive from Gmail then assume a gmail account.

Personal Discovery standard is emerging, driven by EU demands.

The browser knows who you are so this may be a way to simplify login. This moves away from web sites trying to guess which accounts you use.

The Popup extension is emerging as a technique. The challenge is to avoid spoofing. People don't look at the URL bar.

Remember - you can use email address as an indicator of which OpenId providers to support.

Different sites have different account preferences. This leads to sites supporting multiple standards. eg. OpenID + facebook. At least supporting OpenId means you automatically support Yahoo, AOL, Google, MySpace and other popular sites.

Microformats are also important.

Microformats enable webpages to be an API.

Semantic information can be embedded in a page. Some of the oldest standards are hCard (vCard in HTML)

Use CSS classes to markup and style the data. Very simple way to markup information in existing web pages.

This is ideal for database driven sites because you can edit one output web page and apply a microformat to every database record that is displayed through that web page.

Twitter supports hCard and includes the rel=me setting. If you want your blog to be the top search result on your name in Google then add this value to your blog. Simply add rel="me" to a relevant link on your blog.

Discovery

The more you publish the more you need a way to identify what you are publishing as yours. Our desktop is moving out in to the cloud.

Identity enables discovery. XRDS-Simple "the name is more complex than the concept"

XRDS - defines services.

eg. OpenID, PortableContacts

eg. OpenID points to one service. PortableContacts points to Plaxo.

WordPress OpenID plugin supports creating XRDS file.

XRDS-Simple can be used for a personal discovery or for sites to publish their service endpoints

LRDD - Link-based Resource Descriptor Discovery (emerging work)

Authorization

Authorization is important so you don't have to make data public to make it portable.

Will OAuth work in a mobile mode? Yes!

iPhone example is FlightTrack Pro works with Tripit. The iPhone app uses OAuth and Safari to authorize the app on Tripit.com.

OAuth is a protocol for developing password-less APIs.

Plaxo was recently bought by Comcast. Comcast saw a 92% success rate with login using OpenID in collaboration with Google.

The Plaxo-Google connection uses a hybrid. They do the OpenID dance and also handle the OAuth token acquisition at the same time. They also collect and notify user on the basic information that will be used. eg. name and email address.

The Comcast-Google test worked so well that the business folks at Comcast wouldn't let them turn the experiment off!

OAuth can be used asynchronously to allow one user to give permission to someone else to gain access to their information. eg. Dave allows Chris to see his phone number in his contact record.

Relationships and Contacts

Rather than have to support writing to address book APIs for each major service they instead implement a standard protocol. That is PortableContacts. This builds on OAuth and vCard standards.

GMail now supports Portable Contacts. ie. No Google specific code is required to use information from the Google Addressbook.

OpenSocial REST People Protocol is now PortableContact compatible.

vCardDav compatibility is coming with IETF.

Linking Accounts

The XFN Microformat is being used to link accounts and services.

Add a Rel=Me link to connect pages on services..

You can also use Rel=Contact to identify friends.

Google's Social Graph API does this in a simple form. A demo is available.

Activity Streams

Activity Streams are in the realm of "LifeStreaming"

Friendfeed support approximately 59 services. Each was hand coded by Friendfeed.

Activity Streams is about creating a protocol that can be leveraged across sites.

Social Discovery. eg. Plaxo Pulse, LinkedIn network updates, Facebook status updates.

Messaging: Twitter, Yammer, Eventbox (desktop app)

Brand/Personal Monitoring: GetSatisfaction's Overheard searching Twitter.

Primitives: Active, Verb, Object

Actor, Verb Object (context)

Build on Standards

Use ATOM for lists. (aka feeds)

Activity Stream is using a derivation of ATOM to share streams.

Activity Streams is targeted to go in to OpenSocial.

Check out http://activitystrea.ms for the latest info.

Gadgets and OpenSocial

Allow applications to be added tomultiple sites. Write a gadget once and allow in to run on multiple sites. Over 700M users acorss multiple sites support OpenSocial from Myspace to Plaxo to Ning oor Orkut etc.

Shindig is an Apache incubator project for gadgets in OpenSocial.

You can also build OpenSocial apps in the Google AppEngine.

This standard simplifies Engineering integratin and allows developers to focus on PRODUCT integration - ie. How to fit in to the target environment. eg. Ning is different from MySpace.

Next Steps - Homework:

1. Markup existing Data

2. Stop leaking passwords

3. Support OpenID and OAuth

These tools are mature enough to enable simple integration across sites and business partners.

Check out theSocialWeb.tv for the latest news in the space.

Wednesday, October 29, 2008

OpenId closing in on the big One Billion

This week has been a busy week for OpenID. At the Microsoft Professional Developers Conference Microsoft announced that Live ID will be OpenID compliant. I am estimating that this will add about 380 million accounts to the approximately 500 million existing OpenID capable accounts courtesy of Yahoo, AOL, France Telecom and others. Google has been providing limited OpenID support but this week also announced their adoption of OpenID 2.0 support. Interestingly they are also moving to support OAuth. That is a big move.

It could be that the Google announcement is a knee jerk reaction to Microsoft's news. It seems that they are still developing some pieces of the service offering. What is interesting is that Google seems to have take a slightly different approach and some are claiming that they are breaking the OpenID standard. What they are doing is using the gmail email address as the key. This requires sites adopting OpenID to make changes. This is where the shouting is taking place. For an interesting assessment of the implications check out the Neosmart blog. They claim that Google is forking OpenID. Try to take this in your stride. Take a breath and scroll down to the comment left by David Recordon, one of the leading players in the world of OpenID. I have copied David's comments are here:

"Google is taking advantage of a feature in OpenID 2.0 known as "Directed Identity". This allows an OpenID 2.0 Relying Party to start the OpenID protocol flow using a known URL (Yahoo!'s ishttp://openid.yahoo.com/) to allow for "one click" style login dialogues. By performing discovery on this URL, using the XRDS XML format, the OpenID Provider advertises the OpenID Endpoint URL for the Relying Party to make a request against. Google is doing this correctly with the URL to perform discovery against being https://www.google.com/accounts/o8/id.

The piece that Google is currently doing differently is requiring pre-registration of each OpenID Relying Party before users can login to a given site. This does break the common deployment of OpenID on the web today, but Eric Sachs of Google has said on the OpenID mailing list (http://tinyurl.com/562mec) that this is temporary as they work to stabilize their OpenID Provider: "We just need to do the standard scaling, stability, translation quality, etc. evaluation to make sure there are no major problems. If we are lucky, that won't take much time. However it is more then likely that we will need to tweak things in our user interface to make it easier to understand, and unfortunately translating any such tweaks into 40+ languages takes awhile."

As for using email addresses as OpenIDs, this is something the OpenID community is talking about quite a bit right now; Google included."

I think it is clear, As Microsoft noted, OpenID is recognized as a maturing De Facto standard for authentication. The major Internet players are all supporting OpenID. Now it is time for enterprises to recognize the advantage of adopting a global De Facto Authentication standard. This was part of our discussion at Health 2.0 and HealthCampSf last week.

I have been pushing the idea of using OpenID and OAuth, and other elements embraced by the DataPortability initiative, across the Health Care industry. It is now time for the industry to take that leap of faith and make it happen.

Sunday, October 26, 2008

HealthCampSf - more fascinating discussion and planning

A big thanks needs to go out to Manatt Health Solutions for providing the venue for HealthCampSf at the Manatt, Phelps and Phillips offices in the Embarcadero Center, San Francisco. The only downside to this venue is the distraction that the view from their 30th floor offices brings. The views over the bay are totally stunning! Check out my blog from the Health 2.0 Accelerator meeting that was held there earlier this week.

Happening the day after the high octane Heath 2.0 Conference, where even Dr. Ruth made an appearance, The event saw the effects of the party hangover.

Dr. Ruth with Matt and Indu at Health 2.0

HealthCamp took place both physically and virtually with people dialing in from across the country.

THe discussions ranged over a number of subjects.

  • How to evolve the Health 2.0 Accelerator and the Health 2.0 Conference
  • How to promote interoperability initiatives with the Health 2.0 Accelerator

During HealthCampSf the CEO and VP of Business Development from JanRain courtesy of an invitatin from Mike Kirkwood of Polka.com, joined in the sessions and presented the latest developments around OpenId. JanRain's OpenId tools have recently been adopted by Microsoft for use with HealthVault. JanRain have released a Software as a Service offering for OpenId and OAuth, RPX Plus and RPX Pro.

The objective of these products is to bring implementation of OpenId and OAuth down to a less than one day integration exercise.

This is great news. OpenId has over 500 million OpenID capable accounts globally and anything that simplifies the signup process, without sacrificing security is a positive move.

Some of the discussion that spun out of this OpenId and OAuth overview touched on creating an Health Information Interoperability Demonstrator. It was suggested that this could be run in conjunction with the Health 2.0 Conference.

The concept is to plan to bring together developers in the Health 2.0 space and over the course of one or two days to work together to create new health-centric mashups as demonstrators.

One of the things that came through in the Health 2.0 Conference is that the industry has moved on beyond simple health content aggregation and is now focusing on getting real work done and transactions processed. This is great progress, but it just served to drive home the realization that there is much more to be done and the real evolution is when these different applications, platforms and services can be connected together to create new services that can extend the reach and value of these Health 2.0 applications.

For example, how might PharmaSURVEYOR's drug interaction software be integrated with Intelecare's Medical Adherence platform to improve drug safety for patients.

The discussion with JanRain was invaluable. It demonstrated that OpenId and OAuth continue to evolve and provides practical single sign-on capabilities and secure information sharing mechanisms.

After the discussion I was even more convinced that the Health 2.0 Accelerator should leverage the work being done by DataPortability.org. Part of the role of the Health 2.0 Accelerator could be to act as a Health Industry Special Interest Group to promote Health Information interoperability.

Health Care is poised to go through massive transformation. It will increasingly become a consumer-driven industry. As that happens it is entirely logical that the industry should build upon and leverage the developments that are continuing at breakneck pace in the Social Networking world. Emerging standards such as Portable Contacts will grow to become underlying standards in healthcare. We do not need to re-invent the wheel.

Another area to leverage will be Microformats. These machine interpretable but human readable formats keep evolving. The Health 2.0 software sector needs to look at developing Health related formats to complement xisting formats such as Address cards (hCard), Calendars (hCalendar) and ratings (hReview).

Check out the wetpaint wiki site To find out more about HealthCamp. To find out about future events check out the BarCamp.org front page or the HealthCamp specific page.

Thursday, October 23, 2008

Health 2.0 and the Privacy Conundrum

After my stint as a bouncer - yes it is a bizarre adventure....

Now I get to sit down and listen to the discussion on privacy being led by Carol Diamond of the Markle Foundation.

Advice from Philip Marshall of WebMD Health: "Do right by your users. Do right by your sponsors."

Kepa Zubeldia, EVP - Interoperability Technologies at Ingenix. "After the fear of the HIPAA police subsided people began to publish their companion guides to HIPAA that explained their approach to HIPAA. Ingenix has collected over 1200 versions of HIPAA as a result of this."

"HIPAA is a process and not an event. A process that changes and we have to adapt to it."

We have to learn that we can do things as an industry without government compulsion. We have to learn to work together. The pieces have to work together. We have to have an inclusive framework.

HIPAA doesn't work on its own. What is really needed is enforcement to combat inappropriate use of HIPAA information.

Deven McGraw, Director - Health Privacy Project, Center for Democracy and Technology. "When you don't have consistent practices for information management you can easily lose trust."

Consumers are equipped to understand privacy practices. They are just not going to read the legal terms.

Thursday, August 14, 2008

HealthCamp goes international

Earlier this year, at the Web 2.0 Expo in San Francisco, Health 2.0 made the agenda for the Web2Open un-conference track and the Birds of a Feather sessions. This generated a tremendous amount of interest. As I flew back from the event I wanted to make sure the enthusiasm didn't vanish. That lead to creating HealthCampMd then HealthCampDc and HealthCampNy. The enthusiasm seems to be catching. One of the attendees of HealthCampMd is now in the UK and is kicking off HealthCamp UK.

About 20 people participated in a Health 2.0 discussion at the recent BarCampRDU in Raleigh, NC. One of the consistent themes that comes across at these events is the bad experience people have when a serious medical event occurs. That experience manifests itself with a feeling of isolation.

One of the challenges of BarCamp is that conversations just get started and the next session kicks off. It can be a problem getting momentum established. Yes, there is an element of consensus building that needs to take place but it is important that we get a forward momentum and take action. But how do we take action? The problems are so massive and structural they appear as an insurmountable challenge.

This brings me back to a great session I participated in at BarCampRDU where Jim Meyer's "Leap of Faith" talk led me to this idea:

"Being part of a high performing team starts with ourselves"

"...So often in large organizations people feel helpless. They feel that they can't make a difference. Posing the question "What can I do to make a change?" is the first step to achieving exceptional performance.

We must stop worrying about how we can get the world, or our company, to change. Instead focus on the steps that we can personally take. By doing that we have taken the first critical step to becoming exceptional. Success in small ways becomes contagious.

Lead by example."

I need to remember this as future HealthCamps take place. Each article published and presentation made adds to the public consciousness. It all helps to build the wave of change.

I will challenge each attendee to consider what they can do to make the change they want to see happen. You have been warned!

We need to tap in to our social networks and use them for more than just poking and throwing sheep. Let's work out how to use social networks to encourage change. Let's band together and encourage each other.

We are not alone.

I encourage you to promote change in HealthCare. Let's work to make HealthCare more participatory. Let's network so that we know we are not alone.

There is some great technology emerging that can change HealthCare, not just HealthVault or Google Health but some of the open initiatives like Project VRM and the Higgins Open Source Identity Framework.

If you uncover a fascinating technology that is relevant to the HealthCare industry then point it out. Encourage the vendor to get involved with HealthCamp.

Friday, August 01, 2008

VRM and HealthCamp via Health 2.0 at BarCampRDU

I am writing and posting this from the Carolinian traveling down through Virginia to BarCampRDU in Raleigh, North Carolina. Oh, the wonders of modern technology.

In my last blog I weaved together some of the threads from Vendor Relationship Management and Health 2.0. This has been very much on my mind as preparations for HealthCampDc and HealthCampNy continue.

I have volunteered to talk about Health 2.0 and VRM at BarCampRDU. So, as I sat on the train I pulled together a few slides to illustrate the subject. I have uploaded them to Slideshare and am sharing it below.

Monday, July 28, 2008

Health, VRM and Open Source - Coming together at BarCampRDU

This coming weekend is the third BarCampRDU, which is being held at the Red Hat Campus in Raleigh. I am traveling down to the event to join 250 others in discussions revolving around Open Source.

So far the proposed sessions include Data Portability, The Semantic Web, Distributed Agile, Rails/Groovy and other developer focused topics. The growing list is here. I have proposed sessions on Vendor Relationship Management and Social Networking and Open Standards in Health Care - aka Health 2.0 - a prelude to the discussions at HealthCampDc and HealthCampNy at the Web 2.0 Expo Web2Open unconference.

Hopefully Doc Searls won't mind me leveraging some of the great ground laying that he and various colleagues have done in order to spread the word on VRM. I will probably start with the VRM Principles:

Principles

  1. User control
  2. Reduce, Reuse, Recycle (Don't Reinvent the Wheel)
  3. Reciprocity & Everybody Wins
  4. Leverage network effects
  5. Relationships are more than transactions
  6. Solve real-world problems

I should probably also steal some slides from Doc's great intro talk on the VRM Manifesto.

Building on the VRM subject I am hoping to get in to discussions about using the Higgins Identity framework to manage federated group access policies. That could be a fascinating discussion that we just barely scraped the surface of, as we touched on R-Cards at the VRM Workshop.

I see a convergence of VRM with Health Care as the consumer becomes more involved in their own health. As that happens scalability becomes critical and the simplicity of Open Standards such as OpenID and OAuth will come in to play to enable seamless, heterogeneous integration. If I understand the principles behind R-Cards and I-Cards correctly these provide a stepping stone to the Personal Data Store that exists for VRM. The pointer-based nature of R-Cards would allow existing islands of information to be leveraged under the direction of the consumer - the real data owner.

The more I think about all these threads emerging, the more I get excited about our ability to make change happen. This week's BarCampRDU is set to be another stimulating un-conference event which should set the scene for HealthCampDc on September 12th and HealthCampNy immediately the following week.

Stay tuned - or better still - sign up and join in making change happen! You can even buy the T-Shirt!

Tuesday, July 15, 2008

VRM and the Personal Address Manager

This VRM Workshop session covered the concept of the Personal Address Manager.

The scene setting points covered:

  • First Assumption - Privacy
  • Differences from long running relationships
  • - Mutual policy negotiation - pain-free
  • - Default policy bucket
  • - No identifier
  • Easy to produce end of relationship artifacts
  • Win-Win for customers and vendors
  • - Removing barriers to exit is attractive.

A use case was examined: Single Stop Online Shopping

  • With Address
  • With Personal Delivery Service (eg. relationship wth UPS, Fedex etc.)
  • With Vendor Delivery Service (eg. Vendors own delivery service that respects PAM token)
  • With Address from Personal Address Manager

Is the "With Address" scenario a Personal Address Manager (PAM) case? However the PAM might be the place where user relationship policies are stored. "With Address" was eliminated as a policy statement by vendors.

The "with Delivery Service" was selected to analyze.

Roles:

  • Shopper (S:)
  • Merchant (M:)

Assumption:

  • Policy Assurance and Warranty

Scenario:

Step 1.

S: Shop at a compliant store

M: Offer VRM ("use VRM" button on the web page)

Step 2.

S: Click "Use VRM"

M: Endpoint Request

Step 3.

S: VRM Discovery End point - ie. PAM Address pointer

M: Push to provision

Step 4.

S: Provision vendor

S: Give Vendor token (with policy)

M: Policy agreement

M: Use token to get address

M: Use Address

M: Delete

M: Confirmation of End of use

Side notes:

Initiatives are underway to build a policy framework. (SAML and WS-Policy?)

This was a complex discussion to develop the scenario. Edits to refine this discussion can be made on the VRM Workshop Wiki in the Personal Address Manager page.

Monday, July 14, 2008

Project VRM

For the next two days I am attending the Vendor Relationship Management (VRM) Workshop at Harvard University's Berkman Center for Internet and Society. There are about 45 people attending this workshop. The tag for content on Flickr and other sites is #VRM08. I may also broadcast and record some of these sessions using Stickam

The premise of Vendor Relationship Management:

"A free customer is more effective than a captive customer"

How do we turn the current state around. The relationship is at the centre. The relationship between people and organizations.

Some interesting discussions are already starting up. For example: How does VRM get traction in the enterprise? This has already got me thinking about the HealthCare industry as I prepare for the next HealthCamp in DC (HealthCampDc). It strikes me that VRM might find an outlet under the emerging Medical Home concept. To quote the opening line of the Wikipedia entry:

"The basic premise of the medical home concept is continual care that is managed and coordinated by a personal physician with the right tools will lead to betterhealth outcomes."

Identity is a critical component in VRM. Building VRM Relationship Services will be dependent upon new protocols and standards in the applications and network layers.

Some of the emerging components of VRM include:

  • Personal RFP
  • Personal Datastore (this ties in with Data Portability initiatives)
  • Personal Address Manager (this becomes a fascinating SocialGraph application)
  • Personal Healthcare Record
  • Paychoice
  • RelButton

Keith Hopper talked about VRM in Public Broadcasting. Kith talked about Money Left On The Table (MLOTT - a Doc Searls originated term). The RelButton becomes interesting to Public Broadcasters as a mechanism to provide additional avenues to collect donations from viewers and subscribers.

R-Cards are one of the components behind the RelButton. R-Card is a trusted channel between two parties - an umbilical cord so to speak. R-Cards is a component of the Higgins project.

Higgins is an open source identity framework that preserves your privacy having been developed from a user-centric perspective.

The Identity Web Services Framework is a key enabling platform for VRM.


Wednesday, April 18, 2007

User-Centric Identity

John Panzer and Paraveen Alavilli of AOL presented this session on User-Centric Identity. A central tenet of Web 2.0 is that the user is in control Providing users with control over their identity is an essential element to support this notion.

What is identity?

- Identity is necessary for: - Personalization - Authorization and access control - Communication channel

Why we need pervasive online identity

Account management is a barrier to entry to a community. Reversing the massive online identity fragmentation.

What is User-Centric Identity?

Provides user choice. Protects privacy. Easy adoption.Enables collaboration. Internet scalable. The main players - Community: - OpenID - your URL is your identity - CardSpace - from Microsoft - Liberty (SAML) - Open but complex. Single providers: - Yahoo! - BBAuth - Google Account API - AOL OpenAuth

Elements of effective ID

- Simple - Open to multiple programming languages - AOL Authentication API - OpenAuth

Future developments:

- Integrated OpenID Provider - OpenID Authentication Token Exchange Extension - OpenID Consumer/Relying Party The latter piece enables the acceptance of third party OpenIDs