Archive for December, 2006

Liberty Alliance [ID-WSF]v2.0 Workshop

Friday, December 22nd, 2006

The Liberty Alliance will be holding a workshop in Redwood Shores, CA on 22-Jan-2006. Perhaps the event catch-phrase “Liberty 2.0″ can be perceived as jumping on the arguably overwrought “2.0″ meme coursing through the web these days, but we did in fact recently complete the ID-WSF v2.0 specification set, which I’d noted in these pages […]

A Cost Analysis of Windows Vista Content Protection

Thursday, December 21st, 2006

Peter Gutmann has just published a fairly detailed examination of Windows Vista Content Protection. It is highly recommended reading in that it has non-trivial implications for essentially all personal computer users of any stripe…

A Cost Analysis of Windows Vista Content Protection
http://www.cs.auckland.ac.nz/~pgut001/pubs/vista_cost.txt

Note that this analysis dovetails with Bruce Schneier’s overall “DRM is futile” piece from 2001…

The […]

XMLdsig implementations for scripting languages

Wednesday, December 20th, 2006

Various folks in what is becoming known as the “scripter” community, i.e. people who code in Perl/PHP/Python/Ruby scripting languages, have complained that SAML is “too hard” to implement, for essentially two reasons..

Having to parse XML.
Having to use XMLdsig — XML Digital Signature specification.

The first excuse is becoming more and more moot as tools and techniques […]

Of various bits of networked computing identity history

Wednesday, December 20th, 2006

Someone had posted on the private-club IDworkshop@ list…
>
> If you were to look back on the entire evolution of digital identity
> systems to date, what would you highlight as some of the key milestone
> events?
And my small contribution to the resulting stream-of-consciousness thread was (essentially, i’ve edited it some)…
In terms of […]

Geek Alert: Start-up generates random numbers from space

Thursday, December 14th, 2006

Ok, so if yer hip to cryptography at least some, then you know that to do truly strong crypto, one needs a source of very random numbers. This is not all that easy, it turns out. If you’re unaware of this little subtle-but-way-important detail, check out Ross Anderson’s book Security Engineering and Bruce Schneier’s Applied […]

SAML: deployments of, and references to — from OASIS Adoption Forum 2006

Wednesday, December 13th, 2006

The procedings of the 2006 OASIS Adoption Forum (28,29-Nov-2006, London) are here..

OASIS Adoption Forum
http://www.oasis-open.org/events/adoptionforum2006/proceedings.php

SAML figures prominently in many of the talks. Below, I’ve sorted the talks by whether they are discussing actual SAML implementations and/or deployments, planning to use SAML, or the talk references SAML in context.
The presos, unto themselves, illustrate […]

So yer not sure why I brought a Gong?

Monday, December 11th, 2006

Eve Maler wrote, in her post about the Un-Talent Show at IIW2006b last Tue evening 5-Dec-2006…
UPDATE: … about the gong. I’m not sure exactly what possessed JeffH to bring it with him, but he’s local and he’s a drummer, so QED, I guess! Kaliya used it throughout the IIW event to signal session transitions and […]