Re: [arch-d] Proposed IAB program on Wholistic Human-Oriented Discussions on Identity Systems (WHODIS)

Martin Thomson <mt@lowentropy.net> Wed, 21 June 2023 23:40 UTC

Return-Path: <mt@lowentropy.net>
X-Original-To: architecture-discuss@ietfa.amsl.com
Delivered-To: architecture-discuss@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BEEFCC14CE2E for <architecture-discuss@ietfa.amsl.com>; Wed, 21 Jun 2023 16:40:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level:
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b="BtlwO5ug"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="D7tkDyFQ"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 54VwQYz7ydTA for <architecture-discuss@ietfa.amsl.com>; Wed, 21 Jun 2023 16:40:40 -0700 (PDT)
Received: from out3-smtp.messagingengine.com (out3-smtp.messagingengine.com [66.111.4.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D143C14CE2B for <architecture-discuss@ietf.org>; Wed, 21 Jun 2023 16:40:40 -0700 (PDT)
Received: from compute6.internal (compute6.nyi.internal [10.202.2.47]) by mailout.nyi.internal (Postfix) with ESMTP id BE5665C00CA; Wed, 21 Jun 2023 19:40:39 -0400 (EDT)
Received: from imap41 ([10.202.2.91]) by compute6.internal (MEProxy); Wed, 21 Jun 2023 19:40:39 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm3; t= 1687390839; x=1687477239; bh=rfJvaZAXS5aNs0tc+zJEo4x8WnGn1rPIeDY Rw2dccYo=; b=BtlwO5ugJ8x+WuBp3onL/t/GNCvRSavSBbX+IzB4C64BlFozphQ d7iGL+V6/qlUa9U043Ze4A70PQNyDwwqEgPG9AUYdJ94fMqaGuvgYviTZs8BYxV0 0RUNzLErD1gQABV3vbbU8E/MI0TuxSjIunfZIjpMfxAZr3kYGXdBojqrhoh2xP35 3iMHr2Ur4V4YQR07U9E5D4QPizKBxsCeGA/y4vgkxKPKUqCOoH7tw34FY2yjXnPp Rw5T1cLy1LAB6tC4Jx9BU/7Pgy/Lo3dL+5+NGJdGKMGqzzAucjYMovmX1K2A4p4x +EoGdR9Qm9mqJqgctR1++lqaNEE4cDHZsfg==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:sender:subject:subject:to:to:x-me-proxy:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1687390839; x= 1687477239; bh=rfJvaZAXS5aNs0tc+zJEo4x8WnGn1rPIeDYRw2dccYo=; b=D 7tkDyFQ1xL8uvFsAZehrBr5pEaqAcno19XlbspzFTjYP6JbTGohKtucHHgtjvrgA gkDBkbQPATYKng2tfj4eY28K1gyJcpljJ+R7pz8sHNSnX2P4FkWIGrnKc/30H6za cW+oQXR7LU2CUw7FWibYPXa32MvjEH3N6I3K3qQrslXV80N7LLzIuRJfebD413LK +ag8y1B0dQQU4IAlBcXYoJUraJo2r0Os+FmacnOjDzYBG3CNODCNKpiIA7k7rCWe F2PKQ8YSKgSBYF1eSeWO2v5lZ5axzq3bzu/yP+F1rkBnpsBeaoVPQXC2FO59q6fC qCiAV4ufpe6pWGf17Fc+g==
X-ME-Sender: <xms:d4qTZLVRLOvFWi7_EET1r3BB5eRO0F8pIyDB3cNZVuoxisby6efoyQ> <xme:d4qTZDmEGYTz0ID5MbXOJJ80C5t-1xG5wFR-kMEncDkPfPUELwcgEEi95qRtVAYsx _mw2QK6IjzwjMBFTtM>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrgeegtddgvddtucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepofgfggfkjghffffhvffutgfgsehtqhertderreejnecuhfhrohhmpedfofgr rhhtihhnucfvhhhomhhsohhnfdcuoehmtheslhhofigvnhhtrhhophihrdhnvghtqeenuc ggtffrrghtthgvrhhnpeefieeuveelhefhfedujeevteffjeegudegtdfffffgtdfhhfeu teelfeekueehtdenucffohhmrghinhepuhhlrdgtohhmpdhgihhthhhusgdrtghomhdprh gvrggumhgvrdhmugdpihgvthhfrdhorhhgnecuvehluhhsthgvrhfuihiivgeptdenucfr rghrrghmpehmrghilhhfrhhomhepmhhtsehlohifvghnthhrohhphidrnhgvth
X-ME-Proxy: <xmx:d4qTZHbalHWuFv0GwkUGGhmJRNakyima_pbbgw1fRRwUaZ230JQy1A> <xmx:d4qTZGV0UsrpDPD9tgTUB7z8GAgtBBrxaNavIOA3UlvMmokcSvDV-A> <xmx:d4qTZFkRDlk0cmVT11zxMetktd3dOEWW9PWz6wXwoTSDlTVfBdWRqw> <xmx:d4qTZEuQOqHCaoP12Q7ojWdHGtUQLVnKHW8DfXDB6qWpqId2zNzxRA>
Feedback-ID: ic129442d:Fastmail
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 3963B234007B; Wed, 21 Jun 2023 19:40:39 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.9.0-alpha0-499-gf27bbf33e2-fm-20230619.001-gf27bbf33
Mime-Version: 1.0
Message-Id: <0439cbdf-fe23-4ffd-8b43-3d1494d7eb73@betaapp.fastmail.com>
In-Reply-To: <d65583b8-7706-ddbd-1430-ba353e05bfee@lear.ch>
References: <17514E09-F39D-425C-970C-BC14C70F15B9@heapingbits.net> <d65583b8-7706-ddbd-1430-ba353e05bfee@lear.ch>
Date: Thu, 22 Jun 2023 09:40:17 +1000
From: Martin Thomson <mt@lowentropy.net>
To: Eliot Lear <lear@lear.ch>, Christopher Wood <caw@heapingbits.net>, architecture-discuss@ietf.org
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/architecture-discuss/YC-JWtCwZiJXJf_x-6v_HjjrvZY>
Subject: Re: [arch-d] Proposed IAB program on Wholistic Human-Oriented Discussions on Identity Systems (WHODIS)
X-BeenThere: architecture-discuss@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: open discussion forum for long/wide-range architectural issues <architecture-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/architecture-discuss>, <mailto:architecture-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/architecture-discuss/>
List-Post: <mailto:architecture-discuss@ietf.org>
List-Help: <mailto:architecture-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/architecture-discuss>, <mailto:architecture-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Jun 2023 23:40:44 -0000

I think that I disagree with Eliot with respect to the device thing.

>From my perspective, devices are relevant only to the extent that they are agents of or proxies for people.

There are contexts in which this is not the case, but the considerations are very different in those cases.

You should include reference to how government-provided identity systems integrate with technology (e.g., Aadhar).  Mobile drivers licenses are an emerging trend that needs care and consideration, see https://www.ul.com/resources/new-isoiec-standard-electronic-credentials

Colleagues at Mozilla have done a lot of work in this space; we might be interested in participation.

(I also disagree with Eliot; the name is not just fine, but a good choice.  A great pairing for OHAI, which is a useful tool in this space, as it happens.)

On Thu, Jun 22, 2023, at 03:06, Eliot Lear wrote:
> I think it sounds interesting, and I'm interested!  Obviously this is a 
> very active area, and has been for a long time, so your proposed 
> approach sounds pretty good.  It's good that IAB is giving it some focus.
>
> One nit:
>
> I do think you are just a bit too cutsy with the name, since you 
> specifically call out device identity, as you should.  I would suggest 
> that the name itself might mislead people to think you're only talking 
> about user identity. Perhaps Big Fat Discussions on Identity Systems 
> (BiFDIS)?  ;-)
>
> A meta-comment:
>
> I like the idea of reviewing identity systems, but often times those 
> systems are tied necessarily to specific functions, as OAUTH 
> demonstrates.  I would suggest that the program not be too rigid about 
> its charter in this regard.  Some underlying functionality may help 
> elaborate the need for different sorts of systems.
>
> Eliot
>
> On 21.06.23 08:01, Christopher Wood wrote:
>> Hi folks,
>>
>> The IAB proposes to create a new program that focuses on standardized identity systems used in practice. At a high level, there are three primary goals:
>>
>> 1. Survey the identity standardization landscape (inside and outside of the IETF);
>> 2. Distill practical use cases for identity systems; and
>> 3. Identify gaps and opportunities for technical work that can help address important use cases.
>>
>> A more complete description of the proposed program can be found at [1]. For those interested, we intend to allocate some time during the IAB Open meeting at IETF 117 to discuss this topic.
>>
>> Please let us know what you think!
>>
>> Best,
>> Chris, for the IAB
>>
>> [1] https://github.com/intarchboard/proposed-program-whodis/blob/main/README.md
>> _______________________________________________
>> Architecture-discuss mailing list
>> Architecture-discuss@ietf.org
>> https://www.ietf.org/mailman/listinfo/architecture-discuss
>>
>
> _______________________________________________
> Architecture-discuss mailing list
> Architecture-discuss@ietf.org
> https://www.ietf.org/mailman/listinfo/architecture-discuss