Re: [arch-d] Proposed IAB program on Wholistic Human-Oriented Discussions on Identity Systems (WHODIS)

Eliot Lear <lear@lear.ch> Wed, 21 June 2023 17:06 UTC

Return-Path: <lear@lear.ch>
X-Original-To: architecture-discuss@ietfa.amsl.com
Delivered-To: architecture-discuss@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 86BF7C1595FE for <architecture-discuss@ietfa.amsl.com>; Wed, 21 Jun 2023 10:06:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SPF_HELO_PERMERROR=0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=lear.ch
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F8wnFI2N8Hzj for <architecture-discuss@ietfa.amsl.com>; Wed, 21 Jun 2023 10:06:34 -0700 (PDT)
Received: from upstairs.ofcourseimright.com (upstairs.ofcourseimright.com [IPv6:2a00:bd80:aa::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AB135C15108D for <architecture-discuss@ietf.org>; Wed, 21 Jun 2023 10:06:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=lear.ch; s=upstairs; t=1687367185; bh=c3+Hg3jEsTvbdgDdUBjK8LkayxPDWyyn6H3Pl8nejSg=; h=Date:To:References:From:Subject:In-Reply-To:From; b=me0bsDIkWk7AY6Cwb+kr6zSAZ3Mm/mU2lLoDrqhz8czms9ZC7jiA57gsed76PDB6e anEuuwBnsYAn6XFuznVNTz4UUlbfUZ1uHO41Xa4ZfMRwU7CEiaRotlP5YccvqNs9+p Ea+rftEy+/t/9cBn747DHEosyfsSTxmBdL2EZPZQ=
Received: from [IPV6:2001:420:c0c0:1011::b] ([IPv6:2001:420:c0c0:1011:0:0:0:b]) (authenticated bits=0) by upstairs.ofcourseimright.com (8.15.2/8.15.2/Debian-22ubuntu3) with ESMTPSA id 35LH6OOK560534 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NO); Wed, 21 Jun 2023 19:06:25 +0200
Message-ID: <d65583b8-7706-ddbd-1430-ba353e05bfee@lear.ch>
Date: Wed, 21 Jun 2023 19:06:22 +0200
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Thunderbird/102.11.0
Content-Language: en-US
To: Christopher Wood <caw@heapingbits.net>, architecture-discuss@ietf.org
References: <17514E09-F39D-425C-970C-BC14C70F15B9@heapingbits.net>
From: Eliot Lear <lear@lear.ch>
In-Reply-To: <17514E09-F39D-425C-970C-BC14C70F15B9@heapingbits.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/architecture-discuss/O1r_BaGby-ls-d19DLHNV36ex_o>
Subject: Re: [arch-d] Proposed IAB program on Wholistic Human-Oriented Discussions on Identity Systems (WHODIS)
X-BeenThere: architecture-discuss@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: open discussion forum for long/wide-range architectural issues <architecture-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/architecture-discuss>, <mailto:architecture-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/architecture-discuss/>
List-Post: <mailto:architecture-discuss@ietf.org>
List-Help: <mailto:architecture-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/architecture-discuss>, <mailto:architecture-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Jun 2023 17:06:39 -0000

I think it sounds interesting, and I'm interested!  Obviously this is a 
very active area, and has been for a long time, so your proposed 
approach sounds pretty good.  It's good that IAB is giving it some focus.

One nit:

I do think you are just a bit too cutsy with the name, since you 
specifically call out device identity, as you should.  I would suggest 
that the name itself might mislead people to think you're only talking 
about user identity. Perhaps Big Fat Discussions on Identity Systems 
(BiFDIS)?  ;-)

A meta-comment:

I like the idea of reviewing identity systems, but often times those 
systems are tied necessarily to specific functions, as OAUTH 
demonstrates.  I would suggest that the program not be too rigid about 
its charter in this regard.  Some underlying functionality may help 
elaborate the need for different sorts of systems.

Eliot

On 21.06.23 08:01, Christopher Wood wrote:
> Hi folks,
>
> The IAB proposes to create a new program that focuses on standardized identity systems used in practice. At a high level, there are three primary goals:
>
> 1. Survey the identity standardization landscape (inside and outside of the IETF);
> 2. Distill practical use cases for identity systems; and
> 3. Identify gaps and opportunities for technical work that can help address important use cases.
>
> A more complete description of the proposed program can be found at [1]. For those interested, we intend to allocate some time during the IAB Open meeting at IETF 117 to discuss this topic.
>
> Please let us know what you think!
>
> Best,
> Chris, for the IAB
>
> [1] https://github.com/intarchboard/proposed-program-whodis/blob/main/README.md
> _______________________________________________
> Architecture-discuss mailing list
> Architecture-discuss@ietf.org
> https://www.ietf.org/mailman/listinfo/architecture-discuss
>