<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Technology Stir Fry</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/" />
    <link rel="self" type="application/atom+xml" href="http://www.iay.org.uk/blog/atom.xml" />
   <id>tag:www.iay.org.uk,2010:/blog//1</id>
    <link rel="service.post" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1" title="Technology Stir Fry" />
    <updated>2010-01-18T13:00:01Z</updated>
    <subtitle><![CDATA["A nearly impenetrable thicket of geekitude&hellip;"]]></subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 3.33</generator>
 
<entry>
    <title>E-mail Certificates</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2010/01/email_certifica.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=200" title="E-mail Certificates" />
    <id>tag:www.iay.org.uk,2010:/blog//1.200</id>
    
    <published>2010-01-18T12:21:18Z</published>
    <updated>2010-01-18T13:00:01Z</updated>
    
    <summary><![CDATA[The Thawte Web of Trust, for which I was a fairly junior notary, was shut down recently. This included revoking all existing certificates back in November, at least according to Thawte's FAQ on the closure. Amusingly &mdash; but perhaps not...]]></summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>The Thawte <a href="http://www.thawte.com/resources/personal-email-certificates/index.html" title="Thawte Web of Trust">Web of Trust</a>, for which I was a fairly junior <a href="http://www.iay.org.uk/blog/2007/12/thawte_wot_nota.html" title="Technology Stir Fry: Thawte WoT Notary">notary</a>, was shut down recently.  This included revoking all existing certificates back in November, at least according to Thawte's <a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&id=SO12658" title="Frequently Asked Questions for the EOL of WOT / Class One">FAQ</a> on the closure.  Amusingly &mdash; but perhaps not surprisingly to anyone familiar with the area &mdash; I've had to date precisely <em>no</em> queries relating to my continued use of the supposedly revoked personal e-mail certificate.</p>

<p>The only other S/MIME certificate authority I'm aware of that does Web of Trust type identity validation is <a href="http://www.cacert.org/">CAcert</a>; unfortunately their root certificate isn't trusted by most browsers and e-mail clients and until that happens (if it ever does) I can't recommend them as a replacement.  Similarly, the lack of built-in PGP/GPG support in current mail clients rules that system out for most people.</p>

<p>If you had a Thawte S/MIME e-mail certificate, you may have been able to trade it in for a 1-year <a href="http://www.verisign.com/authentication/individual-authentication/digital-id/index.html" title="VeriSign: Digital IDs for Secure Email">equivalent from VeriSign</a> free of charge.  Unfortunately, after the first year it looks like VeriSign charge $19.95 per annum even for a "persona not validated" certificate, which doesn't sound to me like a lot of bang for your buck.</p>

<p>One alternative for the cost-conscious is Comodo's <a href="http://www.instantssl.com/ssl-certificate-products/free-email-certificate.html" title="Instant SSL by Comodo: Free Secure Email Certificate">Free Secure Email Certificate</a> product.  Again, this is "persona not validated" but should be sufficient for most uses and you can't beat the price.</p>]]>
        
    </content>
</entry>
<entry>
    <title>FAM09: Metadata Aggregation</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/11/fam09_metadata.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=198" title="FAM09: Metadata Aggregation" />
    <id>tag:www.iay.org.uk,2009:/blog//1.198</id>
    
    <published>2009-11-24T08:14:42Z</published>
    <updated>2009-11-24T11:21:10Z</updated>
    
    <summary>Metadata aggregation as a route to cross-federation inter-operation continues to be my main focus for the year, and yesterday I delivered a presentation on the subject at JISC&apos;s Federating the next generation event. I think the talk went reasonably well;...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>Metadata aggregation as a route to cross-federation inter-operation continues to be my main focus for the year, and yesterday I <a href="http://www.jisc.ac.uk/whatwedo/themes/accessmanagement/federation/events/federatingthenextgeneration/MetadataAggregation" title="FAM09: Metadata Aggregation">delivered a presentation</a> on the subject at JISC's <a href="http://www.jisc.ac.uk/whatwedo/themes/accessmanagement/federation/events/federatingthenextgeneration.aspx" title="FAM09: Federating the next generation">Federating the next generation</a> event.</p>

<p>I think the talk went reasonably well; a couple of people remarked that they liked having the key concepts separated out and clarified.  People even chuckled in the right places a couple of times.</p>

<p>Checking Twitter for the <a href="http://twitter.com/#search?q=%23fam09" title="Twitter: #FAM09">#FAM09</a> tag I find that the main thing a couple of people took away from the talk was a <a href="http://twitter.com/fooflington/statuses/5979053141">snarky remark</a> I made about <a href="http://www.w3.org/TR/xslt" title="W3C: XSL Transformations (XSLT)">XSLT</a>.  Curiously, I find that I'm fine with that.</p>

<p>As usual, here's a PDF version of my slides from the presentation:</p>

<blockquote><a href="http://www.iay.org.uk/blog/2009/11/20091123-Metadata-Aggregation.pdf" title="20091123-Metadata-Aggregation.pdf">20091123-Metadata-Aggregation.pdf</a></blockquote>

<p>There are a fair number of animated diagrams in this talk, and not as many words as usual.  That might mean that some parts are hard to follow without hearing me talk.  I'm going to try and get hold of the audio recording made at the time and will upload a slide-synchronised version of the talk later if possible.</p>]]>
        
    </content>
</entry>
<entry>
    <title>No Hats</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/11/no_hats.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=197" title="No Hats" />
    <id>tag:www.iay.org.uk,2009:/blog//1.197</id>
    
    <published>2009-11-01T14:01:38Z</published>
    <updated>2010-03-03T14:26:20Z</updated>
    
    <summary> Seen on a recent trip to San Antonio, Texas, which is probably the last place you&apos;d expect to see any attempt to constrain the use of any kind of headwear. Obviously they don&apos;t mean you can&apos;t wear your own...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Photography" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p><a href="http://www.flickr.com/photos/28778115@N00/4063497413" title="View 'Please do not take photos with hats on' on Flickr.com"><img src="http://farm3.static.flickr.com/2438/4063497413_5ef329dd3e_m.jpg" alt="Please do not take photos with hats on" border="0" width="240" height="207" align="right" /></a></p>

<p>Seen on a recent trip to San Antonio, Texas, which is probably the last place you'd expect to see any attempt to constrain the use of any kind of headwear.</p>

<p>Obviously they don't mean you can't wear your own hat while taking photos; what they want to prevent is people wearing the display hats for the purposes of having their photographs taken.  Or at least I think so; there were no hats in the vicinity of this particular notice.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Imperfect</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/11/imperfect.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=196" title="Imperfect" />
    <id>tag:www.iay.org.uk,2009:/blog//1.196</id>
    
    <published>2009-11-01T13:16:03Z</published>
    <updated>2010-01-30T12:14:42Z</updated>
    
    <summary>Many of us, particularly if we have been programmers, have got into the habit of regarding computers as flawless execution engines. People with more of an electronics background tend to be a bit more sceptical, I think. I&apos;ve been trying...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Hardware" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>Many of us, particularly if we have been programmers, have got into the habit of regarding computers as flawless execution engines.  People with more of an electronics background tend to be a bit more sceptical, I think.</p>

<p>I've been trying to figure out why I couldn't burn a Fedora 11 DVD to upgrade one of my oldest machines for several months now.  I had checked the SHA-256 hash of the download then copied the file from the server where I run BitTorrent across to a desktop machine's external hard drive.  The burned disk verified against the image on the machine that created it but the installation self-test always failed, claiming the disk was corrupt.  I tried burning from the same image on another machine; I tried burning at different speeds; I tried different blank DVDs.  No change.</p>

<p>Finally, today, I thought to try verifying the hash on the copied image rather than the original one.  It was different.  Comparing the original download with the copy, I discovered two locations in the copy where byte 0x12 of a block had dropped the 0x08 bit.</p>

<p>It's probably not a coincidence that the machine on which I made the corrupted copy has recently come back from a couple of extended "warranty repair" holidays during which first the main system logic board and then (at my strong and repeated insistence) the actual DRAM were replaced.  The machine had been having some intermittent problems involving applications shutting down unexpectedly; these looked like memory issues to me but the manufacturer's diagnostics had always given it a clean bill of health.  As an old-school computer guy, of course, I know that the manufacturer's diagnostics <em>never</em> detect real memory issues.</p>

<p>The moral of the story?  I'm not sure there is one: "faulty hardware sometimes gives the wrong answer" seems rather an obvious thing to say.  On the other hand, if you are aware of the concept of <a href="http://en.wikipedia.org/wiki/Metastability_in_electronics" title="Wikipedia: Metastability in electronics">metastability in electronics</a>, you know that there's no such thing as perfect hardware as long as the logic needs to talk to the outside world.  So we can reduce the frequency of odd weirdness to the point where we never expect to encounter it, but we can never make it go away altogether.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Concepts and Methods V1.10</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/05/concepts_and_me.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=195" title="Concepts and Methods V1.10" />
    <id>tag:www.iay.org.uk,2009:/blog//1.195</id>
    
    <published>2009-05-22T10:38:47Z</published>
    <updated>2009-05-22T10:41:45Z</updated>
    
    <summary><![CDATA[I've talked about a metadata exchange approach to inter-federation working here before. Since my last update, I think we've seen some level of acceptance in both the technical and policy communities that this is &mdash; at least in principle &mdash;...]]></summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>I've talked about a metadata exchange approach to inter-federation working here before.  Since <a href="http://www.iay.org.uk/blog/2008/10/metadata_interc.html" title="Technology Stir Fry: Metadata Interchange V3">my last update</a>, I think we've seen some level of acceptance in both the technical and policy communities that this is &mdash; at least in principle &mdash; a valid approach, and there is work going on in a variety of places on that basis.</p>

<p>One thing that has become apparent as that work has developed is that we need to look at some of our basic assumptions with a fresh eye: complex problems can be often be simplified by looking at them from a different direction.  To that end, <a href="http://expatchad.info/" title="expatchad.info">Chad La Joie</a> (of <a href="http://www.switch.ch/" title="SWITCH: Serving Swiss Universities">SWITCH</a> and <a href="http://shibboleth.internet2.edu/" title="Internet2: Shibboleth project">Shibboleth</a>) and I have put together <em>Interfederation and Metadata Exchange: Concepts and Methods,</em> the current version of which you can download here:</p>

<blockquote><a href="http://www.iay.org.uk/blog/2009/05/concepts-v1.10.pdf" title="Interfederation and Metadata Exchange: Concepts and Methods">concepts-v1.10.pdf</a></blockquote>

<p>The main aim of <em>Concepts</em> is to provide a framework in which it is possible to think clearly about identity federations in a multi-federation world.  This involves first separating concerns and then recombining them in new ways, leading to what we think is probably best thought of as a global <em>metadata layer.</em> There is also coverage of some of the technical implications of such an approach, but we've tried to keep that part as light-weight as possible here.</p>

<p>During the recent <a href="http://events.internet2.edu/2009/spring-mm/" title="Spring 2009 Internet2 Member Meeting">Internet2 Member Meeting</a> in Arlington, this document was also reviewed by Scott Cantor, Steven Carmody, Josh Howlett, Leif Johansson, Thomas Lenggenhager and Valter Nordh.  We are grateful to our colleagues for their many constructive comments, which we have have tried to incorporate faithfully in the current version.  I will leave it to those individuals to state whether, and to what degree, they endorse our conclusions.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Details, Details</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/05/details_details.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=194" title="Details, Details" />
    <id>tag:www.iay.org.uk,2009:/blog//1.194</id>
    
    <published>2009-05-14T15:27:21Z</published>
    <updated>2010-02-18T08:56:27Z</updated>
    
    <summary>I&apos;ve been using Apple&apos;s Mighty Mouse on my desktop machines for a couple of years now. I quite like them, although the mouse&apos;s inability to represent both mouse buttons being held down at the same time makes it necessary to...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Hardware" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>I've been using Apple's <a href="http://www.apple.com/mightymouse/" title="Mighty Mouse">Mighty Mouse</a> on my desktop machines for a couple of years now.  I quite like them, although the mouse's inability to represent both mouse buttons being held down at the same time makes it necessary to keep a conventional mouse around for things like gaming.</p>

<p>This is a nice mouse to use, though.  For example, it makes a nice solid mechanical click when you use the left or right buttons (even though there is really only one mechanical button &mdash; the whole mouse &mdash; touch sensors inside give you two "logical" buttons).</p>

<p>There's even a tiny clicking sound when you squeeze the side buttons or roll the little trackball around.  You can hardly hear these sounds in a normal office, but they make all the difference to the "feel" of the device.  And, until today, I would have meant that literally: I'd have sworn that I could feel the little clicks through my fingertips.</p>

<p>Today, quite by accident, I discovered that the mouse <i>does not make these tinier sounds if it isn't plugged in&hellip;</i> or, in the case of the wireless version, if you take the battery out.</p>

<p>Yes, there's a <a href="http://arstechnica.com/old/content/2005/08/dissect.ars" title="Ars Technica: Dissecting Mighty Mouse">tiny speaker</a> inside, whose only purpose is to make sounds that are almost &mdash; but not quite &mdash; too quiet to hear.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Lessons</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/04/lessons.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=193" title="Lessons" />
    <id>tag:www.iay.org.uk,2009:/blog//1.193</id>
    
    <published>2009-04-29T14:43:56Z</published>
    <updated>2010-02-18T22:20:24Z</updated>
    
    <summary>I&apos;m in Arlington, Virginia this week for the Internet2 Member Meeting. As usual, lots of good hallway conversations and meetings. I had to work my passage this time by contributing a presentation to a joint session on Building on Success:...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>I'm in Arlington, Virginia this week for the <a href="http://events.internet2.edu/2009/spring-mm/" title="Spring 2009 Internet2 Member Meeting">Internet2 Member Meeting</a>.  As usual, lots of good hallway conversations and meetings.  I had to work my passage this time by contributing a presentation to a joint session on <a href="http://events.internet2.edu/2009/spring-mm/agenda.cfm?go=session&id=10000483&event=909" title="Building on Success: from Identity Federation to Interfederation">Building on Success: from Identity Federation to Interfederation</a>.</p>

<p>As well as the traditional statistics about how large the <a href="http://www.ukfederation.org.uk/" title="UK Access Management Federation for Education and Research">UK federation</a> has become, I talked a bit about some of the things I think contributed to its success.  This was more in terms of broad concepts than details, the idea being to give people thinking of setting up new federations a guide to some of the tradeoffs involved.</p>

<p>As usual, here's a PDF version of my slides from the presentation:</p>

<blockquote><a href="http://www.iay.org.uk/blog/2009/04/20090428-Lessons-iay.pdf" title="20090428-Lessons-iay.pdf">20090428-Lessons-iay.pdf</a></blockquote>]]>
        
    </content>
</entry>
<entry>
    <title>FAM Futures</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/04/fam_futures.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=192" title="FAM Futures" />
    <id>tag:www.iay.org.uk,2009:/blog//1.192</id>
    
    <published>2009-04-12T13:08:18Z</published>
    <updated>2010-02-19T08:06:51Z</updated>
    
    <summary>Earlier this month, I led a couple of breakout sessions at the UK Serials Group&apos;s conference in Torquay. I knew that I&apos;d have a wide range of people in the room in each session, so I put together a slide...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>Earlier this month, I led a couple of breakout sessions at the <a href="http://www.uksg.org/" title="UK Serials Group">UK Serials Group</a>'s <a href="http://www.uksg.org/event/conference09" title="32nd UKSG Annual Conference and Exhibition: Torquay">conference in Torquay</a>.</p>

<p>I knew that I'd have a wide range of people in the room in each session, so I put together a slide deck that would have something for everyone and talked about different subjects to different levels on each of the two days.</p>

<p>Some of the slides won't make much sense without explanation, but others do stand alone, I think.  If you're interested, here's a PDF version of the slides stripped of the animations:</p>

<blockquote><a href="http://www.iay.org.uk/blog/2009/04/20090331-Futures-noanim.pdf" title="Federated Access Management Futures: 1.7MB PDF">20090331-Futures-noanim.pdf</a></blockquote>
]]>
        
    </content>
</entry>
<entry>
    <title>Bedside Chocolate</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2009/02/bedside_chocola.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=191" title="Bedside Chocolate" />
    <id>tag:www.iay.org.uk,2009:/blog//1.191</id>
    
    <published>2009-02-18T18:09:16Z</published>
    <updated>2010-03-08T11:36:56Z</updated>
    
    <summary><![CDATA[ This is another "snapshots from my travels" picture, from a recent trip to Z&uuml;rich, Switzerland. In many countries, it's common to find an inedible boiled mint on your hotel pillow. In Switzerland, hoteliers apparently have tastebuds that work....]]></summary>
    <author>
        <name></name>
        
    </author>
            <category term="Photography" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p><a href="http://www.flickr.com/photos/28778115@N00/3290226395" title="View 'Bedside Chocolate' on Flickr.com"><img src="http://farm4.static.flickr.com/3304/3290226395_75a37914c7_m.jpg" alt="Bedside Chocolate" border="0" width="240" height="182" align="right" /></a></p>

<p>This is another "snapshots from my travels" picture, from a recent trip to Z&uuml;rich, Switzerland.</p>

<p>In many countries, it's common to find an inedible boiled mint on your hotel pillow.  In Switzerland, hoteliers apparently have tastebuds that work.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Avoiding the Martians</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2008/10/avoiding_the_ma.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=190" title="Avoiding the Martians" />
    <id>tag:www.iay.org.uk,2008:/blog//1.190</id>
    
    <published>2008-10-15T17:33:48Z</published>
    <updated>2008-10-15T17:33:59Z</updated>
    
    <summary>Alastair at UHI comments on my most recent Metadata Interchange document revision. His post highlights a couple of places where I can see I need to clarify what I&apos;m proposing in a future revision. I recently purchased a copy of...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p><a href="http://codebrane.com/blog/?p=479" title="'Metadata Interchange : avoiding the Martians' at Alistair's cakeBlog">Alastair at UHI comments</a> on my most recent <a href="http://www.iay.org.uk/blog/2008/10/metadata_interc.html" title="Metadata Interchange V3 at Technology Stir Fry">Metadata Interchange</a> document revision.  His post highlights a couple of places where I can see I need to clarify what I'm proposing in a future revision.  I recently purchased a copy of the <a href="http://www.omnigroup.com/applications/omnigraffle/" title="The Omni Group - OmniGraffle">OmniGraffle</a> diagramming tool, and Alistair's post is a good example of why&hellip; sometimes a simple diagram really can be clearer than large amounts of plain text.  Misunderstandings aside, I think we agree on most things.</p>

<p>One area where I've felt for some time we all need to express things more clearly is with regard to that thing we call "trust".  I usually break this down first into "technical" trust (which allows you to know you're talking to the entity you think you are) and "behavioural" trust (which gives you expectations about the behaviour of a known entity).  This isn't the whole story by all means, but does allow us to see that trust isn't a singular property; it's more like a stack or chain of elements that we can build up into something we can actually use.</p>

<p>Any federation can choose to act as a trust broker at many levels; for example, one federation may have strictly enforceable rules controlling member behaviour while another may leave behavioural trust to bilateral arrangements between members (such as the commercial contracts that are usually present in content licensing situations).  The UK federation is towards the latter end of the scale: as all federations do, it acts as a broker of technical trust, but mere presence of an entity within the UK federation's metadata has never carried any behavioural guarantees.</p>

<p>What this means is that if you're used to operating in something like the UK federation, your stance is already to treat <em>everyone</em> as a potential <a href="http://www.imdb.com/title/tt0116996/" title="Mars Attacks! (1996) at IMDb">ray-gun-toting Martian</a> unless you have some specific reason to view them otherwise.  Adding more Martians from other federations therefore doesn't change anything; the important thing that an inter-federation agreement adds is the assurance that the originating federation has registration procedures strong enough to prevent a Martian from masquerading as someone you have a real relationship with, and conversely provides technical trust strong enough to support you in picking the entities you do want to do business with out of the sea of entities you don't care about.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Metadata Interchange V3</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2008/10/metadata_interc.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=189" title="Metadata Interchange V3" />
    <id>tag:www.iay.org.uk,2008:/blog//1.189</id>
    
    <published>2008-10-12T21:55:26Z</published>
    <updated>2010-02-18T08:58:04Z</updated>
    
    <summary>Many thanks to everyone who commented on the previous edition of Some Notes on Metadata Interchange. I&apos;m in New Orleans for the Internet2 Fall Member Meeting this week, and as I expect to be discussing this area with a number...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>Many thanks to everyone who commented on the <a href="http://www.iay.org.uk/blog/2008/09/snomi_v2.html" title="Some Notes on Metadata Interchange, V2">previous edition</a> of <em>Some Notes on Metadata Interchange</em>.  I'm in New Orleans for the <a href="http://events.internet2.edu/2008/fall-mm/" title="Internet2 Fall Member Meeting 2008">Internet2 Fall Member Meeting</a> this week, and as I expect to be discussing this area with a number of the other people attending I think this seems like a good time to publish a revision.  This edition goes into more detail in some areas, as well as improving sections which needed clarification.</p>
<ul><li><a href="http://www.iay.org.uk/blog/2008/10/snomi-v3.pdf" title="snomi-v3.pdf">snomi-v3.pdf</a> is a clean copy of the document for new readers</li><li><a href="http://www.iay.org.uk/blog/2008/10/snomi-v3-diff.pdf" title="snomi-v3-diff.pdf">snomi-v3-diff.pdf</a> includes change indications for people who have read the previous edition</li></ul>
<p>I continue to welcome comments and discussion.  The next edition might be a couple of weeks away, but will likely go into more detail on what I think an aggregation appliance might need to include.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Vendor Lock-in</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2008/10/vendor_lockin.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=188" title="Vendor Lock-in" />
    <id>tag:www.iay.org.uk,2008:/blog//1.188</id>
    
    <published>2008-10-10T17:32:06Z</published>
    <updated>2010-02-16T15:11:05Z</updated>
    
    <summary>I own two Uninterruptable Power Supply units. Each has a button on the front with which you can perform a self-test; I do this once a month to make sure that they are &quot;still good&quot;. On unit A, you tap...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Hardware" />
            <category term="Humour" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>I own two Uninterruptable Power Supply units.  Each has a button on the front with which you can perform a self-test; I do this once a month to make sure that they are "still good".</p>

<p>On unit A, you tap the button and it does a self-test.  If you press and hold the button then the unit turns off, taking the attached hardware with it.</p>

<p>Unit B (from a different vendor) requires you to hold the button in to perform the self-test.  Tapping the button&hellip; no, why don't <em>you</em> guess what that does?</p>

<p>Sneakiest attempt at vendor lock-in I think I've ever come across.</p>]]>
        
    </content>
</entry>
<entry>
    <title>Metadata Interchange Notes</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2008/09/snomi_v2.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=187" title="Metadata Interchange Notes" />
    <id>tag:www.iay.org.uk,2008:/blog//1.187</id>
    
    <published>2008-09-16T18:41:10Z</published>
    <updated>2010-02-02T11:27:36Z</updated>
    
    <summary>I&apos;ve been working with SAML-based identity federations for a bit over four years now. For most of that time, it&apos;s been obvious that after basic federations like the UK federation and InCommon were up and running in production, the next...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Identity" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p>I've been working with SAML-based identity federations for a bit over four years now.  For most of that time, it's been obvious that after basic federations like the <a href="http://ukfederation.org.uk/" title="UK Access Management Federation for Education and Research">UK federation</a> and <a href="http://www.incommonfederation.org/" title="InCommon Federation">InCommon</a> were up and running in production, the next big question would be how to break out of the "federation of my close friends" model.  I've spent the last couple of years bending ears at conferences with my own particular views about how this might be done.</p>

<p>Impromptu in-person rants of that kind are very useful for finding out whether ideas have any appeal to other people at all, but I've felt for a while that something more coherent might be useful.  I've therefore put together <em>Some Notes on Metadata Interchange</em> as a personal position paper on this area.</p>

<ul>
<li><p>
<a href="http://www.iay.org.uk/blog/2008/09/snomi-v2.pdf" title="snomi-v2.pdf">snomi-v2.pdf</a> is the current version of the document;
</p></li>
<li><p>
<a href="http://www.iay.org.uk/blog/2008/09/snomi-v2-diff.pdf" title="snomi-v2-diff.pdf">snomi-v2-diff.pdf</a> is the same document with change bars from the previous version.  This means you can deduce what V1 looked like if that's of interest.
</p></li>
</ul>

<p>I very much welcome comments and discussion on this document.  If you'd like to, you can leave a comment here (if you don't have a <a href="http://www.sixapart.com/typekey/" title="TypeKey authentication system">TypeKey</a> account, there will be a delay before it's published) or post on your own blog or just <a href="http://www.iay.org.uk/ian-a-young.html" title="contact information">send me e-mail</a>.</p>

<p>Some disclaimers:  This document does not represent the official position of any organisation or group, nor is it an attempt to describe any consensus view; it's purely a personal summary.  It's not a collaborative document, except in the sense that if you change my mind I'll change the text.</p>

<p>I expect this document to change fairly often over the next few months; hopefully, some consensus-building (and even specification-building) efforts can be budded off from it when that seems appropriate; they will probably be hosted elsewhere.</p>]]>
        
    </content>
</entry>
<entry>
    <title>More Pixies Inside</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2008/09/more_pixies_ins.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=186" title="More Pixies Inside" />
    <id>tag:www.iay.org.uk,2008:/blog//1.186</id>
    
    <published>2008-09-16T17:46:29Z</published>
    <updated>2008-09-16T17:46:44Z</updated>
    
    <summary> There used to be a joke in photographic circles that most people had rolls of film printed with &quot;Christmas at each end and a beach in the middle&quot;. This blog hasn&apos;t been idle quite that long, but I&apos;ve just...</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Miscellanea" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<p><a href="http://www.flickr.com/photos/28778115@N00/2862401355" title="View 'More Pixies Inside' on Flickr.com"><img src="http://farm4.static.flickr.com/3194/2862401355_a2590f7143_m.jpg" alt="More Pixies Inside" border="0" width="240" height="176" align="right" /></a></p>

<p>There used to be a joke in photographic circles that most people had rolls of film printed with "Christmas at each end and a beach in the middle".  This blog hasn't been idle quite that long, but I've just got back from a very nice vacation in Bruges inspired by the visit I made for the conference mentioned in the last two entries.</p>

<p>Mmmmmm, chocolate&hellip; and, apparently, pixies.  Who knew?</p>]]>
        
    </content>
</entry>
<entry>
    <title>Dueling Fingers</title>
    <link rel="alternate" type="text/html" href="http://www.iay.org.uk/blog/2008/05/dueling_fingers.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.iay.org.uk/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=185" title="Dueling Fingers" />
    <id>tag:www.iay.org.uk,2008:/blog//1.185</id>
    
    <published>2008-05-22T11:06:11Z</published>
    <updated>2008-09-16T17:19:03Z</updated>
    
    <summary> Dueling Fingers Originally uploaded by nklingenstein The wireless networking may have been problematic, but the human networking was excellent. Spirited argument between friends (see picture) is always great fun....</summary>
    <author>
        <name></name>
        
    </author>
            <category term="Miscellanea" />
    
    <content type="html" xml:lang="en" xml:base="http://www.iay.org.uk/blog/">
        <![CDATA[<div style="float: right; margin-left: 10px; margin-bottom: 10px;">
<a href="http://www.flickr.com/photos/nklingenstein/2509112762/" title="photo sharing"><img src="http://farm4.static.flickr.com/3245/2509112762_c8a8a5daf2_m.jpg" alt="" style="border: solid 2px #000000;" /></a>
<br />
<span style="font-size: 0.9em; margin-top: 0px;">
<a href="http://www.flickr.com/photos/nklingenstein/2509112762/">Dueling Fingers</a>
<br />
Originally uploaded by <a href="http://www.flickr.com/people/nklingenstein/">nklingenstein</a>
</span>
</div>
The wireless networking may have been problematic, but the human networking was excellent.  Spirited argument between friends (see picture) is always great fun.
<br clear="all" />]]>
        
    </content>
</entry>

</feed> 

