<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The DataPortability Project &#187; privacy</title>
	<atom:link href="http://blog.dataportability.org/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.dataportability.org</link>
	<description> Connect. Control. Share. Remix.</description>
	<lastBuildDate>Tue, 05 Jul 2011 15:44:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Data Portability Applauds US CIO, Mourns Departure</title>
		<link>http://blog.dataportability.org/2011/06/16/data-portability-applauds-us-cio-mourns-departure/</link>
		<comments>http://blog.dataportability.org/2011/06/16/data-portability-applauds-us-cio-mourns-departure/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 02:17:02 +0000</pubDate>
		<dc:creator>Steve Repetti</dc:creator>
				<category><![CDATA[Official comment]]></category>
		<category><![CDATA[perspective]]></category>
		<category><![CDATA[Accessibility]]></category>
		<category><![CDATA[data portability]]></category>
		<category><![CDATA[dataportability]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[US CIO]]></category>
		<category><![CDATA[Vivek Kundra]]></category>

		<guid isPermaLink="false">http://dataportability.org/?p=665</guid>
		<description><![CDATA[<p>Today, friends of Data Portability lost an ally in their cause when the Federal CIO, Vivek Kundra, announced he will be leaving his post in August. Mr. Kundra was the first-ever Chief Information Officer of the United States. During his tenure, Mr. Kundra championed the use of open standards, cloud computing, accessibility, and data <span style="color:#777"> . . . &#8594; Read More: <a href="http://blog.dataportability.org/2011/06/16/data-portability-applauds-us-cio-mourns-departure/">Data Portability Applauds US CIO, Mourns Departure</a></span>]]></description>
			<content:encoded><![CDATA[<p>Today, friends of Data Portability lost an ally in their cause when the Federal CIO, Vivek Kundra, announced he will be leaving his post in August. Mr. Kundra was the first-ever Chief Information Officer of the United States. During his tenure, Mr. Kundra championed the use of open standards, cloud computing, accessibility, and data portability through a variety of initiatives but lately saw his budgets slashed almost to the point of ineffectiveness. The irony of this is that his cost-saving initiatives netted the Government billions in savings, yet he was unable to save his own projects.</p>
<p>We are at a time when information is instantaneous and permeates every aspect of our lives. Data portability, privacy, and accessibility are the heart of the matter and leadership in this area is game changing on a global scale. If we screw this up we become second fiddle to those that do get it. Mr. Kundra was on the right path, and we at the Data Portability organization applaud his efforts as he re-enters the private sector. We wish him well at his new post at Harvard and hope his voice and passion never lose their strength.</p>
<p>Through this all, our Federal Government and politicians would do well to reassess the importance of the initiatives brought forth by real-world need and championed by Mr. Kundra, for failure to do so will be the real loss felt by the people and businesses of this country.</p>
<p>&#8211;Steve Repetti, Chairman, DataPortability.org</p>
<div class="shr-publisher-665"></div>]]></content:encoded>
			<wfw:commentRss>http://blog.dataportability.org/2011/06/16/data-portability-applauds-us-cio-mourns-departure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>#portability4trust: How we will bring data portability to trust frameworks this quarter.</title>
		<link>http://blog.dataportability.org/2011/04/25/portability4trust-how-we-will-bring-data-portability-to-trust-frameworks-this-quarter/</link>
		<comments>http://blog.dataportability.org/2011/04/25/portability4trust-how-we-will-bring-data-portability-to-trust-frameworks-this-quarter/#comments</comments>
		<pubDate>Mon, 25 Apr 2011 18:08:59 +0000</pubDate>
		<dc:creator>Phil Wolff</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Open Standards]]></category>
		<category><![CDATA[Portability Policy]]></category>
		<category><![CDATA[dataportability]]></category>
		<category><![CDATA[pii]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[portability]]></category>
		<category><![CDATA[portability4trust]]></category>
		<category><![CDATA[PortabilityPolicy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trust]]></category>
		<category><![CDATA[trust frameworks]]></category>
		<category><![CDATA[wef]]></category>

		<guid isPermaLink="false">http://dataportability.org/?p=640</guid>
		<description><![CDATA[<p>Dial or Skype details for this Wednesday&#8217;s Conference Call to start before IIW.</p> <p>Here’s how you can bring the ideas in our data portability policy to hundreds of millions of people. I’ll need your help in May and June to start. In short: build portability principles into boilerplate identity contracts.</p> <p>What’s a trust framework? <span style="color:#777"> . . . &#8594; Read More: <a href="http://blog.dataportability.org/2011/04/25/portability4trust-how-we-will-bring-data-portability-to-trust-frameworks-this-quarter/">#portability4trust: How we will bring data portability to trust frameworks this quarter.</a></span>]]></description>
			<content:encoded><![CDATA[<blockquote style="border-bottom-color: #cc9; padding-bottom: 0.5em; border-top-color: #ffc; margin: 0px 0px 1em 1em; padding-left: 1em; width: 30%; padding-right: 1em; background: #ff9; float: right; border-right-color: #cc9; border-left-color: #cc9; padding-top: 0.5em"><p><a title="details on this page" href="#20110427confcall">Dial or Skype details for this <strong>Wednesday&#8217;s Conference Call</strong></a><strong> to start before IIW.</strong></p>
</blockquote>
<p><strong>Here’s how you can bring the ideas in our </strong><a title="PortabilityPolicy.org" href="http://PortabilityPolicy.org"><strong>data portability policy</strong></a><strong> to hundreds of millions of people. </strong>I’ll need your help in May and June to start. In short: build portability principles into boilerplate identity contracts.</p>
<p><strong>What’s a trust framework? </strong></p>
<p>Trust frameworks are the many contracts that say how all the parties who move your personal data should behave.</p>
<p>For example, there are contracts between you and organizations that hold and use your data. These can be a Facebook, a bank, a hospital, a phone company, a government agency, a school or a library. These organizations help you use your identity with them, like your Facebook ID, to prove who you are to third-parties.</p>
<p>Trust frameworks describe the contracts between you and each identity provider, between the identity provider and the relying parties who receive and change your data. Trust frameworks improve clarity and accountability and lower the cost and effort of sharing data well and safely.</p>
<p align="center"><img src="http://farm6.static.flickr.com/5264/5654030869_955cf9ac6e.jpg" /></p>
<p>These are the legal and policy counterparts to the technical protocols like OAuth used to sign you in among web sites and to move your data. There are a few trust frameworks live and more on the way. The contracts promise things like keeping your data safe or asking for permission before selling your data.</p>
<p>I believe they should include data portability practices among the promises made to users.</p>
<p><strong>Why now? </strong></p>
<p><a title="National Strategy for Trusted Identities in Cyberspace" href="http://www.nist.gov/nstic/">NSTIC</a> is an international program to encourage everyone to build and use trust frameworks. NSTIC is short for the National Strategy for Trusted Identity in Cyberspace. Here is the <a href="http://www.nstic.us/strategy.html">full text of the NSTIC strategy document</a>. Last week the White House moved the NSTIC project office to the US Department of Commerce’s NIST, the <a href="http://www.nist.gov/">National Institute of Standards and Technology</a>. Corporate, startup and NGO interest are high. </p>
<p>The <a href="http://www.weforum.org/">World Economic Forum</a> launched a three year “<a href="http://www.weforum.org/issues/rethinking-personal-data">Rethinking Personal Data</a>” project, including data portability. Their first report, <a href="http://www.weforum.org/reports/personal-data-emergence-new-asset-class?ol=1">Personal Data: The Emergence of a New Asset Class</a>, shows their directions.</p>
<p>The <a href="http://personaldataecosystem.org/">Personal Data Ecosystem Consortium</a> is picking up members, traction, and launching three programs over the next few weeks. </p>
<p><strong>What can we do as the DataPortability Project?</strong></p>
<p>We can give organizations building trust frameworks the raw material they need to define data portability in practice and in enforceable contracts. They are writing standard language for millions of contracts right now.</p>
<p><strong>Data Portability Trust Framework Documents</strong></p>
<p>Teams building trust frameworks with data portability need our Project to draft, validate, refine, and publish these seven documents. </p>
<ul>
<li><strong>A portability principles manifesto.</strong> Listing the principles of data portability and why they matter. </li>
<li><strong>A portability policy pledge.</strong> A short, direct promise to support the data portability principles. </li>
<li><strong>A portability policy template.</strong> Like the questions found at <a href="http://PortabilityPolicy.org">PortabilityPolicy.org</a>, a structured way to assure all data portability principles are addressed and disclosed, whether they are supported or not. </li>
<li><strong>A portability policy minimum disclosure.</strong> Describe the least amount of disclosure required by a trust framework. </li>
<li><strong>A portability policy minimum practice.</strong> Describe required data portability practices. This is prescriptive. </li>
<li><strong>A portability policy recommended practice.</strong> Describe portability practices above and beyond the required. With time and support of the trust framework’s organization, recommended practices may become required. </li>
<li><strong>A portability glossary.</strong> Defining our terms.&#160;&#160; </li>
</ul>
<p>Some of these documents should and can be in simple, plain language. For example the manifesto should explain data portability persuasively.</p>
<p>Others should be sufficiently specific that a third-party could verify portability claims in practice. So if you say you delete all a user’s data on request, the minimum practice lists how that would be proved.</p>
<p>We’ll version these documents and bring them through stages of maturity, from proposed to draft to final, or a similar approach. This way everyone knows exactly what they sign up for.</p>
<p><strong>The next 30 days.</strong></p>
<p>Now through June. Project volunteers will write and edit the documents.</p>
<p> <a name="20110427confcall"></a>
<p>27 April. I’ll host a <strong>Portability for Trust Frameworks</strong> conference call Wednesday to get things started. </p>
<ul>
<li>11:00 AM Pacific, 2:00 PM Eastern, 7:00 PM London, 20:00 Berlin, <a href="http://www.timeanddate.com/worldclock/fixedtime.html?msg=Portability+for+Trust+Frameworks+Call&amp;iso=20110427T11&amp;p1=224&amp;sort=2">other local times</a>. </li>
<li>In the USA: <a title="Call this number with Skype." href="skype:+12017939022?call">+1-201-793-9022</a>, access code 1719146#. </li>
<li>Toll free via Skype:<a href="skype:+9900827041719146?call">+9900827041719146</a>. </li>
<li>Skype IM backchannel: <a href="http://tinyurl.com/dpptrust">http://tinyurl.com/dpptrust</a>.</li>
<li>We will have weekly conference calls where they don’t conflict with other events.</li>
</ul>
<p>3-5 May. <a href="http://www.internetidentityworkshop.com/">The Internet Identity Workshop</a> (IIW12). We will have data portability working sessions to scope, write, edit, and test the documents. See you there.</p>
<p>10-13 May. <a href="http://www.id-conf.com/">European Identity Conference</a>. Munich. Not yet scheduled, but we’re hoping for a birds-of-a-feather session to discuss this work and recruit EU contributors. More than five hours of this EIC are on trust frameworks.</p>
<p>11-13 May. <a href="http://www.newdigitaleconomics.com/EMEA_May2011/index.php">Telco 2 and Personal Data 5</a>. London. I hope some of the Personal Data unconference attendees will schedule a working session on day three.</p>
<p>19-21 May. <a href="http://pii2011.com/">Privacy, Identity, Innovation 2011</a> conference (PII), with <a href="http://privacycamp.wordpress.com/2011/04/07/partnership-with-the-privacy-identity-and-innovation-conference/">PrivacyCamp</a> on Saturday. We’ll have working sessions during PrivacyCamp. Silicon Valley.</p>
<p><strong>What you should do now. </strong></p>
<ol>
<li>Put time on your calendar for our events and conference calls. (5 minutes) </li>
<li>Join our low volume Google group (2 minutes).<br />
<table style="padding-bottom: 5px; border-right-width: 0px; background-color: #fff; padding-left: 5px; padding-right: 5px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 5px" border="0" cellspacing="0">
<tbody>
<tr style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px">
<td style="border-right-width: 0px; padding-left: 5px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px"><b>Subscribe to &quot;Data Portability Trust Framework&quot;</b> </td>
</tr>
<form style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" action="http://groups.google.com/group/data-portability-trust/boxsubscribe">
<tr style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px">
<td style="border-right-width: 0px; padding-left: 5px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px">Email:<br />
<input name="email" />
<input name="sub" type="submit" /> </td>
</tr></form>
<tr>
<td align="right"><a href="http://groups.google.com/group/data-portability-trust">Visit this group</a> </td>
</tr>
</tbody>
</table>
</li>
<li>Re-read the <a href="http://portabilitypolicy.org/questions.html">10 Questions</a> on <a href="http://PortabilityPolicy.org">PortabilityPolicy.org</a> so you are familiar with the baseline documents. (10 minutes) </li>
<li>Invite fellow authors to work on this. </li>
<li><a href="http://whatthetrend.com/trend/portability4trust">#Portability4Trust</a> is our hashtag. Spread the word that we need help, please. </li>
<li>Cash. Some of this work will involve travel and professional services. <a href="http://dataportability.org">The DataPortability Project</a> is a 501(c)3 California charitable corporation. Underwrite our work with donations and in-kind legal services. </li>
</ol>
<p>As always, I’m available to talk in private. +1-510-316-9773, <a href="skype:evanwolf?chat">skype:evanwolf</a>, @evanwolf. – Phil Wolff.</p>
<p>A draft of slides for IIW below… </p>
<div style="width: 595px" id="__ss_7729245"><strong style="margin: 12px 0px 4px; display: block"><a title="#Portability4Trust - Personal Data Portability for Trust Frameworks" href="http://www.slideshare.net/evanwolf/portability4-trust">#Portability4Trust &#8211; Personal Data Portability for Trust Frameworks</a></strong> <iframe height="497" marginheight="0" src="http://www.slideshare.net/slideshow/embed_code/7729245" frameborder="0" width="595" marginwidth="0" scrolling="no"></iframe></div>
<div class="shr-publisher-640"></div>]]></content:encoded>
			<wfw:commentRss>http://blog.dataportability.org/2011/04/25/portability4trust-how-we-will-bring-data-portability-to-trust-frameworks-this-quarter/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Data portability in the Credit Card industry</title>
		<link>http://blog.dataportability.org/2010/05/28/ccportabilitygroup/</link>
		<comments>http://blog.dataportability.org/2010/05/28/ccportabilitygroup/#comments</comments>
		<pubDate>Fri, 28 May 2010 18:31:09 +0000</pubDate>
		<dc:creator>Elias Bizannes</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[credit]]></category>
		<category><![CDATA[creditcard]]></category>
		<category><![CDATA[data portability]]></category>
		<category><![CDATA[dataportability]]></category>
		<category><![CDATA[dpp]]></category>
		<category><![CDATA[finance]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[payment]]></category>
		<category><![CDATA[PayPal]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[visa]]></category>

		<guid isPermaLink="false">http://blog.dataportability.org/?p=513</guid>
		<description><![CDATA[Credit card data portability <span style="color:#777"> . . . &#8594; Read More: <a href="http://blog.dataportability.org/2010/05/28/ccportabilitygroup/">Data portability in the Credit Card industry</a></span>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin: 0px 1em 1em 0px;" title="Credit Card Data Portability Badge" src="http://credit-card-data-portability.s3.amazonaws.com/badge.png" alt="Credit Card Data Portability Badge" width="172" height="81" />Our Steering Group accepted <a href="http://PortabilityStandard.org">PortabilityStandard.org</a> as an official action group of the  <a href="http://dataportability.org">DataPortability Project</a>, with <a href="http://www.braintreepaymentsolutions.com/">Bryan Johnson</a> of <a href="http://www.braintreepaymentsolutions.com/">Braintree Payment Solutions</a> as chairperson.</p>
<p>In the words of the new group:</p>
<blockquote><p>The Credit Card Data Portability Standard is supported by an opt-in  				community of electronic payment processing providers (<a onclick="Effect.ScrollTo('definitions', { offset: -42}); new Effect.Highlight('serviceProviders', { startcolor: '#fffa29', endcolor: '#eaeaea', duration: 3.5}); return false;" href="http://www.portabilitystandard.org/#">service providers</a>) that agree to provide credit card data and associated transaction information (<a onclick="Effect.ScrollTo('definitions', { offset: -42}); new Effect.Highlight('sensitiveData', { startcolor: '#fffa29', endcolor: '#eaeaea', duration: 3.5}); return false;" href="http://www.portabilitystandard.org/#">sensitive data</a>) to an existing merchant upon request in a PCI Compliant manner.</p></blockquote>
<p><strong>Why are we supporting it</strong></p>
<p>There is a perception that the DataPortability Project is addressing only social networking issues, but we try to focus our efforts in other verticals <a href=" http://wiki.dataportability.org/x/C4A8">like medical</a> and now financial. To give an example of why this is important:</p>
<ul>
<li>Let&#8217;s say you have an account with Netflix. You&#8217;ve provided your credit card to purchase movies through Netflix.</li>
<li>Netflix uses a payment provider like PayPal, who does the actual credit card processing.</li>
<li>One day Netflix decides it doesn&#8217;t like PayPal&#8217;s policies and new fees. They start shopping for a new payment provider</li>
<li>Because credit card data portability is not in effect, Netflix has to re-ask its consumers for their credit cards. This is because PayPal &#8211; not Netflix &#8211; is the company that stores and controls your credit card data.</li>
</ul>
<p>It&#8217;s crazy because Netflix is the company a consumer creates the relationship with, and yet PayPal controls this important information about them.</p>
<p>This is why we welcome the credit card working group. This is an issue hidden from consumers, and will only affect how <a href="http://en.wikipedia.org/wiki/Business-to-business">B2B</a> operates &#8211; but in the long run, it&#8217;s making the market more efficient as we march towards a world of true <a href="http://wiki.dataportability.org/x/SoA0">data portability</a>.</p>
<p>We look forward to working with the group to develop the approach and <a href="http://www.braintreepaymentsolutions.com/blog/data-portability">increase exposure of this important issue</a>.</p>
<p><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/1lXaGCmp7mY&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/1lXaGCmp7mY&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object> </p>
<div class="shr-publisher-513"></div>]]></content:encoded>
			<wfw:commentRss>http://blog.dataportability.org/2010/05/28/ccportabilitygroup/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Redefining and Standardizing &#8216;Ownership&#8217;</title>
		<link>http://blog.dataportability.org/2009/02/16/redefining-and-standardizing-ownership/</link>
		<comments>http://blog.dataportability.org/2009/02/16/redefining-and-standardizing-ownership/#comments</comments>
		<pubDate>Tue, 17 Feb 2009 01:32:42 +0000</pubDate>
		<dc:creator>Daniela Barbosa</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[control]]></category>
		<category><![CDATA[data portability]]></category>
		<category><![CDATA[dataportability]]></category>
		<category><![CDATA[dpp]]></category>
		<category><![CDATA[eula]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[ownership]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[taskforce]]></category>
		<category><![CDATA[tos]]></category>

		<guid isPermaLink="false">http://blog.dataportability.org/?p=190</guid>
		<description><![CDATA[<p>Facebook, by virtue of its sheer size and scope, is often the first to run into issues that the rest of the social web will need to address sooner rather than later. To its credit, Facebook seems to be trying to address these issues in a way that protects their short and long term <span style="color:#777"> . . . &#8594; Read More: <a href="http://blog.dataportability.org/2009/02/16/redefining-and-standardizing-ownership/">Redefining and Standardizing &#8216;Ownership&#8217;</a></span>]]></description>
			<content:encoded><![CDATA[<p>Facebook, by virtue of its sheer size and scope, is often the first to run into issues that the rest of the social web will need to address sooner rather than later. To its credit, Facebook seems to be trying to address these issues in a way that protects their short and long term business while balancing the needs of the community.</p>
<p>By observing these actions the DataPortability project, and the wider community, can learn lessons on what works and what doesn&#8217;t so we can all adopt clear community endorsed best practices.</p>
<p>The latest Facebook step (misstep?) occurred last week when they made some changes to their Terms of Service and one of the items of contention by many is the following statement:</p>
<blockquote><p><em>&#8220;You may remove your User Content from the Site at any time. If you choose to remove your User Content, the license granted above will automatically expire, however you acknowledge that the Company may retain archived copies of your User Content. &#8220;</em></p></blockquote>
<p>&#8220;So Who Owns Your Data&#8221; is always a question that myself and other members of the DataPortability Project (DPP) have grappled with for some time. No doubt &#8216;ownership&#8217; of data is top of mind to people who are interested in data portability.</p>
<p>We have said in the past that Ownership without Control is worthless. Scope of Control, however, seems to stem from ownership. That is, you should only be able to control what you own. So the fundamental question of Ownership is still important.</p>
<p>&#8216;Ownership&#8217;, however, is tricky when you are talking about bits and bytes that are getting shared, indexed, replicated and mixed together by multiple services and participants.</p>
<p>Perhaps Ownership is not the right metaphor at all? Late last year, fellow DPP co-founder Elias took the time to address some thoughts on &#8216;ownership&#8217; of data with a post titled &#8220;<a href="http://liako.biz/2008/11/you-dont-nor-need-to-own-your-data/">You don’t nor need to own your data</a>&#8221; that I would recommend reading. In it, Elias discusses traditional concepts of ownership and goes on to suggest that perhaps we need a new term to describe our relationship to social data.</p>
<p>Here is a large section from <a href="http://liako.biz/2008/11/you-dont-nor-need-to-own-your-data/">his post</a>:</p>
<blockquote><p>First of all, let’s define property ownership: “the ability to deny use of an asset by another entity”. The reason you can claim status to owning your house, is because you can deny someone else access to your property. Most of us have a fence to separate our property from the public space; others like the hillbillies sit in their rocking chair with a shot gun ready to fire. Either way, it’s well understood if someone else owns something, and if you trespass, the dogs will chase after you.</p>
<p><a href="http://flickr.com/photos/xplosive/133377798/"><img src="http://farm4.static.flickr.com/3222/3033746793_847965c6a1.jpg" alt="133377798_8c85d1f1a6_o" width="500" height="331" align="center" /></a></p>
<p>The characteristics of ownership can be described as follows:</p>
<ol>
<li>You have legal title recognising in your legal jurisdiction that you own it.</li>
<li> You have the ability to enforce your right of ownership in your legal jurisdiction</li>
<li> You can get benefits from the property.</li>
</ol>
<p>The third point is key. When people cry out loud “I own my data”, that’s essentially the reason (when you take out the Neanderthal emotionally-driven reasoning out of the equation). Where we get a little lost though, is when we define those benefits. It could be said, that you want to be able to control your data so that you can use it somewhere else, and so you can make sure someone else doesn’t use it in a way that causes you harm.</p>
<p>Whilst that might sound like ownership to you, that’s where the house of cards collapses. The reason being, unless you can prove the ability to deny use by another entity, you do not have ownership. It’s a trap, because data is not like a physical good which cannot be easily copied. It’s like a butterfly locked in a safe: the moment you open that safe up, you can say good bye. If data can only satisfy the ownership definition when you hide it from the world, that means when it’s public to the world, you no longer own it. And that sucks, because data by nature is used for public consumption. But what if you could get the same benefits of ownership &#8211; or rather, receive benefits of usage and regulate usage &#8211; without actually ‘owning’ it?</p>
<p><strong>Property and data &#8211; same same, but different</strong><br />
Both property and data are assets. They create value for those who use them. But that’s where the similarity’s end.</p>
<p>Property gains value through scarcity. The more unique, the more valuable. Data on the other hand, gains value through reuse. The more derivative works off it, means the more information generated (as information is <a href="http://liako.biz/2008/03/can-you-answer-my-question/">simply data connected with other data</a>). The more information, the more knowledge, the more value created &#8211; working its way along the <a href="http://liako.biz/2008/05/the-value-chain-for-information/">information value chain</a>. If data is isolated, and not reused, it has little value. For example, if a company has a piece of data but is not allowed to ever use it &#8211; there is no value to it.</p>
<p>Data gains value through use, and additional value through reuse and derivative creations. If no one reads this blog, it’s a waste of space; if thousands of people read it, its value increases &#8211; as these ideas are decimated. To give one perspective on this, when people create their own posts reusing the data I’ve created, I generate value through them linking back to me. No linking, no value realised. Of course, I get a lot more value out of it beyond page rank juice, but hopefully you realise if you “steal” my content (with at least some acknowledgement to me the person), then you are actually doing me a favour.</p>
<p><strong>Ignore the above!</strong><br />
Talking about all this ownership stuff doesn’t actually matter; it’s not ownership that we want. Let’s take a step back, and look at this from a broader, philosophical view.</p>
<p>Property ownership is based on the concept that you get value from holding something for an extended period of time. But in an age of rapid change, do you still get value from that? Let’s say, we lose the Holy War for people being able to ‘own’ their data. Facebook &#8211; you win &#8211; you now ‘own’ me. This is because it owns the data about me &#8211; my identity, it would appear, is under the control of Facebook &#8211; it now owns, that “I am in a relationship”. However, the Holy War might have been lost but I don’t care. Because Facebook owns crap &#8211; as six months ago, I was in a relationship. Now I’m single and haven’t updated my status. The value for Facebook, is not in owning me in a period of time: it’s in having access to me all the time &#8211; because one way they translate that data into value is advertising, and targeting ads is pointless if you have the wrong information to base your targetting on. Probably the only data that can be static in my profile, is birth-date and gender &#8211; but with some tampering and cosmetics, even those can be altered now!</p></blockquote>
<p>With their change of terms, Facebook is essentially saying that they will &#8216;forever own&#8217; a copy of your data as part of their archives to do with what they wish. I will go so far as to sympathize personally with the team there and give them an approving nod for some of <a href="http://blog.facebook.com/blog.php?post=54434097130">Zuckerberg&#8217;s comments</a> especially acknowledging that they are indeed trying to address some serious questions around how we live our digital lives. It&#8217;s not easy and they certainly don&#8217;t have to go it alone.</p>
<p>I would invite them, and anyone else interested in the topic, to join one of our most recent TaskForces &#8211; the <a href="http://wiki.dataportability.org/pages/viewpage.action?pageId=4490392">EULA &amp; ToS Taskforce</a>.</p>
<p>Following the example of  <a href="http://creativecommons.org/">Creative Commons</a>, the goal of our task force is to identify and name key concepts that help users and service providers understand what each other expects . The intended output will be a set of documents that can be referenced or included in EULA and TOS agreements and simple descriptions for users to understand what it means when they upload and share data with services providers.</p>
<p>As part of this taskforce, we seek to provide a <em><strong>standard </strong></em>way of describing the relationship between the user and site that is easy to understand and provides both sides with the control that they need.</p>
<p>If you are interested in the subject &#8211; now is the time to join us and help define some basic principles that services providers should support by joining and supporting the work that the <a href="http://wiki.dataportability.org/pages/viewpage.action?pageId=4490392">EULA &amp; ToS Taskforce </a>is conducting.</p>
<p>And another kudos to Facebook for starting a <a href="http://www.facebook.com/group.php?gid=77069107432#/topic.php?uid=77069107432&amp;topic=7673">discussion topic</a> immediately on the &#8220;<a href="http://www.facebook.com/group.php?gid=77069107432#/group.php?gid=77069107432">People Against the new Terms of Service (TOS)&#8221;</a> Facebook Group. Some real use cases and concerns are being captured in that discussion that will help us all as we work towards our common goal.</p>
<p>Some additional posts on the subject of Facebooks New Terms of Service:</p>
<ul>
<li>Where the buzz started on the Consumerist Blog (a consumer advocacy blog) <a href="http://consumerist.com/5150175/facebooks-new-terms-of-service-we-can-do-anything-we-want-with-your-content-forever">Facebook&#8217;s New Terms Of Service: &#8220;We Can Do Anything We Want With Your Content. Forever</a>.&#8221;</li>
<li>Caroline McCarthy CNET: <a href="http://news.cnet.com/8301-13577_3-10165190-36.html">Facebook: Relax, we won&#8217;t sell your photos</a></li>
<li>An interesting overview of the various terms of service out there by Amanda French : <a href="http://amandafrench.net/2009/02/16/facebook-terms-of-service-compared/">Facebook terms of service compared with MySpace, Flickr, Picasa, YouTube, LinkedIn, and Twitter</a></li>
<li>web.tech.law <a href="http://webtechlaw.com/what-facebooks-revised-terms-use-mean-your-content">What Facebook&#8217;s revised terms of use mean for your content</a></li>
<li>There are plenty of other posts and suspect more to come so here is a link to posts via <a href="http://www.techmeme.com/090216/p91#a090216p91">Techmeme</a></li>
<li><a href="http://amandafrench.net/2009/02/16/facebook-terms-of-service-compared/">Comparing the Terms and Conditions </a>of Facebook, Myspace, Flickr, Picasa, YouTube, LinkedIn and Twitter.</li>
</ul>
<div class="shr-publisher-190"></div>]]></content:encoded>
			<wfw:commentRss>http://blog.dataportability.org/2009/02/16/redefining-and-standardizing-ownership/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Graceful Exit: The Power to Fight Eviction</title>
		<link>http://blog.dataportability.org/2009/01/16/the-power-to-fight-eviction/</link>
		<comments>http://blog.dataportability.org/2009/01/16/the-power-to-fight-eviction/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 21:20:01 +0000</pubDate>
		<dc:creator>Phil Wolff</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Portability Policy]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[data portability]]></category>
		<category><![CDATA[dataportability]]></category>
		<category><![CDATA[dpp]]></category>
		<category><![CDATA[equity]]></category>
		<category><![CDATA[evict]]></category>
		<category><![CDATA[evicted]]></category>
		<category><![CDATA[eviction]]></category>
		<category><![CDATA[evictions]]></category>
		<category><![CDATA[fairness]]></category>
		<category><![CDATA[gracefulexit]]></category>
		<category><![CDATA[power]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[rights]]></category>

		<guid isPermaLink="false">http://blog.dataportability.org/?p=146</guid>
		<description><![CDATA[Online Eviction <p>Jason Scott&#8217;s Protection From Online Eviction? and his follow up post make the argument that services like AOL, MySpace, flickr, or Skype should be treated like landlords.</p> <p>The power landlords have over tenants is overwhelming, unless restricted by law. The argument: if they want to shut down a service, essentially evicting users, <span style="color:#777"> . . . &#8594; Read More: <a href="http://blog.dataportability.org/2009/01/16/the-power-to-fight-eviction/">Graceful Exit: The Power to Fight Eviction</a></span>]]></description>
			<content:encoded><![CDATA[<h4><strong>Online Eviction</strong></h4>
<p>Jason Scott&#8217;s <a href="http://tech.slashdot.org/article.pl?sid=09/01/03/203255">Protection From Online Eviction?</a> and <a href="http://ascii.textfiles.com/archives/1649">his follow up post</a> make the argument that services like AOL, MySpace, flickr, or Skype should be treated like landlords.</p>
<p>The power landlords have over tenants is overwhelming, unless restricted by law. The argument: if they want to shut down a service, essentially evicting users, they should be required to give notice and keep things running for a year.</p>
<p>This would allow people to safely migrate their digital objects like photos and videos and blog posts, renew relationships with people in their contacts and agree on where to move, file change of address notices for their businesses, and otherwise minimize the logistical, economic, political, emotional, and familial havoc forcible ejection can create.</p>
<h4><strong>Death and Taxes</strong></h4>
<p>Should Terms of Service (TOS) defend a user from data loss? from identity nullification? from contact list deletion? from history erasure?</p>
<p><a href="http://skypejournal.com/2008/08/letter-to-editor-reconsider-skypecasts.html">The closure of the Skypecasts service</a> is the example from <a href="http://Skype.com">Skype</a> history that comes to mind. Skype could have given more notice, preserved the site for archival purposes, turned off commenting and new sessions, allowed people to extract contact lists.</p>
<p>Might Skype have designed Skypecasts services with &#8220;graceful exit&#8221; in mind?</p>
<p>Everything dies. Plants, animals, families, civilizations. Even businesses and web sites.</p>
<p>It&#8217;s wise to acknowledge mortality and plan for service end-of-life. And it&#8217;s prudent to build societal safeguards outside of company-issued boilerplate.</p>
<p>From a company&#8217;s view, it&#8217;s like setting aside resources for taxes you know you must pay later. Or contingency funds in a project budget.</p>
<p>Maybe this is green service design. Designing web products for recycling and reuse.</p>
<p>It was time for Skypecasts 1.0 to die. What was the right way for Skype to retire the service? How could they have preserved user equity in data and the social capital created through use of the Skypecasts services?</p>
<h4><strong>What is the moral thing to do?</strong></h4>
<p>The question is broader than the one product.</p>
<p>It goes to the tension between consumer rights, enterprise service rights, and the health of our society. For example, if a province decides to demolish your building, you have many rights under law to contest that decision. In the US, many cities have laws about protecting historic landmark buildings.</p>
<p>In my case, as a user of Google mail, I have no power over Google. If they decide to cancel my account, delete my email or spam all my contacts, that&#8217;s within their power. They don&#8217;t need to give notice, or offer me a chance to back everything up. Nobody outside Google will hear my appeal or listen to my concerns.</p>
<p>Societies, civilization and economies have an interest in protecting and preserving the intellectual work of individuals. Even family photos, business blogs, and the most idiotic of forums have value. Value to their creators, value as history, value even as part of the creative commons.</p>
<h4><strong>Action.</strong></h4>
<p>So what can be done to redress this imbalance of power? I&#8217;ll suggest six things, by no means a complete or even feasible list.</p>
<p><strong>First, intervene.</strong> <a href="http://www.archiveteam.org/">ArchiveTeam.org</a> is a rapid response team. They will respond to a pending shutdown by backing up as much as they can. They are a volunteer team but just starting. I can easily imagine this being a not-for-profit or a government agency.</p>
<p><strong>Second, prevent.</strong> Promote exit strategies in project and product design. This is an education program for product managers. Knowledge about the issues, checklists for planning and conducting a graceful exit, forums for getting help, directories of certified Graceful Exit professionals.</p>
<p><strong>Third, commit.</strong> Write model language for EULAs and TOSs. After a company implements preventive measures, give them the language for making promises legally. Plain language, lawyer approved. Even a badge to show at registration to give that safe, comfortable feeling.</p>
<p><strong>Fourth, insure.</strong> Create a mutual insurance fund. Put money into a pool to pay for recovery and distribution of digital assets if you should shut down a service. Coverage is proportional to the number of clients and the size of their assets. Risk factors include the health and activity of your business, how well you&#8217;ve engineered preventive measures (discounts for readiness). Money may be paid to outfits like ArchiveTeam.org. Insurance spreads risk, but proper tweaking of rates can incent better behavior; fire insurance led to fire codes (prevention) and fire departments (remediation).</p>
<p><strong>Fifth, advocate.</strong> The cause needs a forceful voice for consumers. When companies, large or small, threaten to willfully destroy their customer&#8217;s digital works, they should be educated, persuaded, and publically shamed as needed. I&#8217;m thinking some cross between Electronic Frontier Foundation and Consumers Union.</p>
<p><strong>Sixth, enforce.</strong> Teeth, if you will. I want laws that enshrine cherished principles and adapt to changing times and fluid technologies. Injunctive relief is a powerful incentive to do the right thing. Class actions in the public interest might convince the reluctant to do the right thing.</p>
<p>P.S. <a href="http://scripting.com">Dave Winer</a> was the first person to bring this to my attention as an issue, eight or nine years&#8217; ago. His response was to create a specification to hold your structured data from his <a href="http://manila.userland.com/">manila blogging services</a> and features that let you <a href="http://frontier.userland.com/usersGuide#downloadingACopyOfYourManilaSite">backup your blog in one step</a>.  Thanks, Dave.</p>
<p>P.P.S. While I&#8217;m on DPP.org&#8217;s steering group, these are my words and may, or may not, be the official view of <a href="http://blog.dataportability.org/">The DataPortability Project</a>.</p>
<div id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:2936042c-8277-4957-b3a5-f3faf2e19b2a" class="wlWriterEditableSmartContent" style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px">
<p style="font-size:smaller; background:#f0f0f0; padding:.5em;">tags: <a rel="tag" href="http://technorati.com/tags/skype">skype</a>, <a rel="tag" href="http://technorati.com/tags/skypecasts">skypecasts</a>, <a rel="tag" href="http://technorati.com/tags/archiveteam">archiveteam</a>, <a rel="tag" href="http://technorati.com/tags/rights">rights</a>, <a rel="tag" href="http://technorati.com/tags/liberties">liberties</a>, <a rel="tag" href="http://technorati.com/tags/power">power</a>, <a rel="tag" href="http://technorati.com/tags/activism">activism</a>, <a rel="tag" href="http://technorati.com/tags/law">law</a>, <a rel="tag" href="http://technorati.com/tags/regulation">regulation</a>, <a rel="tag" href="http://technorati.com/tags/backup">backup</a>, <a rel="tag" href="http://technorati.com/tags/aol">aol</a>, <a rel="tag" href="http://technorati.com/tags/google">google</a></p>
<p style="font-size:smaller"><em>Talk with Phil Wolff on <a rel="me" href="http://www.twitter.com/evanwolf">Twitter</a> or <a rel="me" href="http://friendfeed.com/evanwolf">FriendFeed</a> or on <a title="add Phil Wolff as a Skype friend" rel="me" href="skype:evanwolf?userinfo">Skype</a>.<br />
Follow <a href="http://twitter.com/skypejournal">Skype Journal on twitter</a></em></p>
</div>
<div class="shr-publisher-146"></div>]]></content:encoded>
			<wfw:commentRss>http://blog.dataportability.org/2009/01/16/the-power-to-fight-eviction/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Time To Criminalize The Password Anti-pattern</title>
		<link>http://blog.dataportability.org/2009/01/04/time-to-criminalize-the-password-anti-pattern/</link>
		<comments>http://blog.dataportability.org/2009/01/04/time-to-criminalize-the-password-anti-pattern/#comments</comments>
		<pubDate>Sun, 04 Jan 2009 21:00:29 +0000</pubDate>
		<dc:creator>Elias Bizannes</dc:creator>
				<category><![CDATA[Open Standards]]></category>
		<category><![CDATA[anti-patterns]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[data portability]]></category>
		<category><![CDATA[dataportability]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[dpp]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[openID]]></category>
		<category><![CDATA[password anti-pattern]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.dataportability.org/?p=61</guid>
		<description><![CDATA[<p>Update: Twitter made another commitment today to adopting OAuth which is great! However they acknowledge that it won&#8217;t solve all problems (like we argue) &#8211; nevertheless these are positive steps to us eradicating the password anti-pattern</p> <p></p> <p>In case you&#8217;ve never heard of it, Twitter is a micro-blogging service that is doing to communications <span style="color:#777"> . . . &#8594; Read More: <a href="http://blog.dataportability.org/2009/01/04/time-to-criminalize-the-password-anti-pattern/">Time To Criminalize The Password Anti-pattern</a></span>]]></description>
			<content:encoded><![CDATA[<p><em><strong>Update: Twitter made <a href="http://blog.twitter.com/2009/01/monday-morning-madness.html">another commitment today</a> to adopting OAuth which is great! However they acknowledge that</strong><strong> it won&#8217;t solve all problems (like we argue)</strong></em><strong><em> &#8211; nevertheless these are positive steps to us eradicating the password anti-pattern</em></strong></p>
<p><img class="alignleft size-full wp-image-75" title="twitter_logo" src="http://blog.dataportability.org/wp-content/uploads/2009/01/twitter_logo.png" alt="twitter_logo" width="205" height="48" /></p>
<p>In case you&#8217;ve never heard of it, <a href="http://twitter.com">Twitter</a> is a micro-blogging service that is doing to communications what search did to information. It has exploded in popularity, and whether they find a revenue model or not &#8211; their impact is permanent and is leading the way for a new era of communications. I am one of their biggest fans and want to help them succeed. But I feel with their growth, propelled by loyal users like myself, we ought to let them know there are things that concern us.</p>
<p>The biggest issue is that whilst they enable data portability, they are doing it in an insecure way. As Chris Messina said, lets make <a href="http://factoryjoe.com/blog/2009/01/02/twitter-and-the-password-anti-pattern/">2009 the year</a> we see the end to the <a href="http://microformats.org/wiki/social-network-anti-patterns">password anti-pattern</a>. In this post, I will explain what that anti-pattern is and a way we can fix it. The biggest reason why Twitter is continuiing with this anti-pattern (from my eyes), is because it&#8217;s a usability issue. But as you will see me prove below through screenshots, it isn&#8217;t. Just think of having a PIN code on your bank card: that&#8217;s a usability issue as well, but y&#8217;know, one of those good usability issues.</p>
<p><strong>Twitter and Security: all we&#8217;ve heard in 2009 so far</strong><br />
Twitter is used to constant free PR, but this year two separate events occurred that could have been non-events (if they do what we ask).</p>
<p>The first was a <a href="http://twply.com/">third-party that provided a feature</a> people wanted. As Twitter has an <a href="http://en.wikipedia.org/wiki/API">Application Programming Interface (API)</a>, third-party&#8217;s can create <a href="http://en.wikipedia.org/wiki/Mashup_(web_application_hybrid)">mashups</a> and therefore provide this functionality to Twitter users. However because Twitter does not support delegated authentication, you need to enter your username and password. There are hundreds of third-party applications like this, and most are safe (we hope), but this particular site within <a href="http://www.centernetworks.com/twply-twitter-replies-auction">24 hours had put itself up for sale</a>! And <a href="http://www.techcrunch.com/2009/01/01/the-problem-with-twply-is-you-cant-turn-it-off/">people couldn&#8217;t turn off the service</a> &#8211; they had to change their password to do so.</p>
<p>The second incident to occur this last week, was an attempted <a href="http://blog.twitter.com/2009/01/gone-phishing.html">phishing</a>. Apparently, some users were being <a href="http://chris.pirillo.com/2009/01/03/phishing-scam-spreading-on-twitter/">sent private messages telling them to visit a certain site </a>which compromised their security. It&#8217;s ironic that Twitter tells you to not &#8220;<a href="http://status.twitter.com/post/68196572/dont-share-your-secret-info">share your private info</a>&#8221; but for you to get value out of their API for mash-ups and third-party tools, that&#8217;s exactly what you need to do &#8211; and it makes situations like this slightly more risky.</p>
<p>Fortunately, there are things that can be done to minimize the risk of your accounts getting hacked, and for you to never have to give up information about you that will compromise your security.</p>
<p><strong>Delegated authorization</strong><br />
There is a solution to this situation. It&#8217;s free to support it, simple to use, and in fact &#8211; Twitter&#8217;s team <a href="http://oauth.net/about">inspired its creation the other year</a>. It&#8217;s through the use of an Open Standard called <a href="http://oauth.net/">OAuth</a>. There is plenty of material you can read on the web about this and a good start is <a href="http://www.hueniverse.com/hueniverse/2007/09/explaining-oaut.html">Eran Hammer-Lahav&#8217;s explanation of oAuth</a> followed by his <a href="http://www.hueniverse.com/hueniverse/2007/10/beginners-guide.html">three-part series for beginners</a> if you want to dig a little deeper.</p>
<p>The basic concept is that it allows you to delegate authorization for use of an API. Huh?</p>
<p>I&#8217;ll illustrate this with an example. Let&#8217;s say you come across a Cool Product that allows you to do something unique with your Twitter account (say, being able to stream your Tweets through your e-mail client rather you having to visit the Twitter website). As this Cool Product has no formal links to Twitter, for you to use it, it needs to pretend to be you. Therefore, it asks for your user name and password. It knocks on Twitter&#8217;s API door, pretending to be you, and the Cool Product then gets access to your account to do the stuff you want to do with this third-party application. The problem with this approach, however, is that they can knock on Twitter&#8217;s door anytime pretending to be you &#8211; even when you don&#8217;t want them to.</p>
<p>With OAuth, it would be very different. Instead of you needing to provide your username and password, this Cool Product will say &#8220;Hey dude, I need to get some permissions &#8211; click this link to give it to me&#8221;. Then a request will be sent to Twitter&#8217;s API and Twitter will send you to a screen saying &#8220;hey dude, these third party dudes want access to your account &#8211; you cool with that?&#8221;. Then, with a simple click of the button, you can approve or deny access. Once approved, the Cool Product can then function &#8211; and you didn&#8217;t have to give up any private information like your password.</p>
<p>Here are some screen shots between another innovative start-up called FriendFeed and Google (who supports OAuth).</p>
<p>In this scenario, I want to add some more friends on my FriendFeed account. So I click on the option to invite them</p>
<p><img class="aligncenter size-full wp-image-62" title="friendfeed-import-address-book" src="http://blog.dataportability.org/wp-content/uploads/2009/01/friendfeed-import-address-book.jpg" alt="friendfeed-import-address-book" width="571" height="218" /></p>
<p>When I click on &#8220;import from Gmail&#8221;, instead of having to type in my username and password to access my contacts, I simply get redirected to a screen. And because I&#8217;m permanently logged into my Gmail account, I don&#8217;t need to do anything else other than read and click &#8220;grant access&#8221; (otherwise, I would need to enter my Google credentials).</p>
<p><img class="aligncenter size-full wp-image-63" title="google-authentication" src="http://blog.dataportability.org/wp-content/uploads/2009/01/google-authentication.jpg" alt="google-authentication" width="501" height="251" />.</p>
<p>Easy! Compare this to Facebook, another company that needs to think more proactively about its users security. If I want to add friends to my Facebook account, instead of redirecting me to the Google servers where I can grant access, it asks for my password.</p>
<p><img class="aligncenter size-full wp-image-64" title="facebook-find-your-friends-on-facebook" src="http://blog.dataportability.org/wp-content/uploads/2009/01/facebook-find-your-friends-on-facebook.jpg" alt="facebook-find-your-friends-on-facebook" width="500" height="246" /></p>
<p><strong>Next steps</strong><br />
As people on the web using web services, we&#8217;ve been forced to give up confidential information to get the value out of a service. We&#8217;ve forced ourselves to be okay with it with the sites we trust, but there are plenty of brands out there we don&#8217;t know to trust. But the thing is, this isn&#8217;t something we need to trust anyone with. With our health records and financial records accessible online, this isn&#8217;t just a matter of reputation risk but one of genuine identity risk.</p>
<p>There is a solution to this problem, and now that you recognize it, demand web services to give you data portability in a secure way. Let&#8217;s make 2009 the year that we kill the <a href="http://microformats.org/wiki/social-network-anti-patterns">password anti-pattern</a>. While easier said than done, it&#8217;s a fix that will curb some of the security issues: we hope Twitter hurries up in changing their API to require OAuth.</p>
<p>Twitter &#8211; we know you&#8217;ve been meaning to do it, but hopefully you <a href="http://www.flickr.com/photos/factoryjoe/2986697776/">really mean it</a> this time. Because quite frankly, we as users are fueling your growth and the promotion of your API without some sort of safe-guards like this, is irresponsible (especially <a href="http://threatchaos.com/2009/01/twitter-phishing/">as these attacks prove</a> you are going all the more mainstream. I don&#8217;t want to tell you how to run your business &#8211; it <a href="http://lets.coozi.com.au/content/token-based_authentication_for_api_access.html">doesn&#8217;t have to be OAuth</a> &#8211; but for crying out loud, give us some security for our digital identity.</p>
<p><strong>One final Big But</strong><br />
Twitter has strong arguments to not jump onto OAuth, some of which they&#8217;ve said publicly and some that I think might be issues. They certainly have a competent team, and <a href="http://twitter.com/al3x/status/1096088767">whilst they know the benefits</a>, they also understand the fact that <em><strong>jumping onto OAuth or any type of delegated authorization will not fix all problems.</strong> </em>However it&#8217;s a start. Here are some issues:</p>
<ol>
<li><em>OAuth is only good for services over web browsers.</em> It is a real pain (or virtually impossible without some hacks) to use it for the client side (ie, on the desktop) and mobile sites &#8211; both of which Twitter has a lot of users that use it this way. The response to that is that some security is better than none &#8211; it&#8217;s not a big deal that users will have to authorize applications via the browser (and Twitter can just point a hairy finger at the standards community so they can fix it). At least give users the option to determine how secure they want to be.</li>
<li><em>Twitter will need to support multiple authentication systems due to the limitations of oAuth</em>. This is a real issue, but not an impossible one to manage, and the community is certainly willing to help out. My main point is that this is actually a security issue that matters, and because the cost is borne by the users and not the company, it&#8217;s not given equal recognition.</li>
<li><em>The user experience will suffer for users. </em>Well the reason users will &#8220;suffer&#8221; is because now, instead of just entering their password, they will now have to click a few buttons on different screens. As the screenshots show above, the user experience is not affected that much and I think while a valid point, it&#8217;s more a &#8220;different&#8221; user experience</li>
<li><em>The user experience will suffer for developers. </em>Yes it will, because instead of the lazy option to just ask users to hand over their password, they actually have to write some code to get the appropriate permissions happening. But this is a core reason why the DataPortability Project supports widely-supported Open Standards, as it minimizes the costs to business: once a developer learns it once, they know it for all future application development.  And like I said above: a bank not puting a code on your bank card, is more painful for your bank, but better that pain than the option without which poses risks for users.</li>
<li><em>It will not prevent phishing</em>.  <a href="http://log.lachstock.com.au/past/2008/4/1/phishing-fools/">Lachlan Hardy gives a useful explanation on why</a> (notice all Australians give the best explanations <img src='http://blog.dataportability.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ), as theoretically, people will be more prone to phishing attacks because of the ease. This is a valid point, as people potentially will just blindly click away to their doom, but let&#8217;s also remember there will also be a lot more control. A site can monitor suspect services to alert users, there is a full digital paper trail, and a user can revoke their authorization at any time. Certainly a bit of control is better than none, and by reducing the weak spots in the chain, more targeted efforts can be made to ensure users&#8217; security is no compromised.</li>
</ol>
<p><em><strong><br />
</strong></em><strong></strong> </p>
<div class="shr-publisher-61"></div>]]></content:encoded>
			<wfw:commentRss>http://blog.dataportability.org/2009/01/04/time-to-criminalize-the-password-anti-pattern/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

