Slashdot Mirror


Private Personal Agents vs. Microsoft's Passport

stefaanh asks: "With the recent MS Passport concerns, I remembered an 'IEEE Expert' 'JANUARY-FEBRUARY 1997 article called 'Managing your privacy in an on-line world' written by Michael McCandless. It talks about why you would hand out private information (on the Net), and proposes a personal agent that manages your info, in a way that you control, what, who and when to give out a selection of your sensitive data. Who benefits: you, and the companies that don't pay for outdated or inaccurate data anymore, but [pay you] for accessing correct data. Since I consider Passports 'security' not as serious as the potential of consumer tracking, what sits in the way for this personal agent to challenge the threat of Passport's centralized approach? Isn't the time right for such an implementation?"

138 comments

  1. Privacy? by Anonymous Coward · · Score: 1, Interesting
    What privacy?

    Didn't you watch Ashcroft's announcement how fighting the terrorism means that you have you sacrifice your privacy to the FBI? If you haven't done anything, you've got nothing to fear, right?

    1. Re:Privacy? by Anonymous Coward · · Score: 0

      I wonder if those of us who send all but the most trivial of our emails using pgp and only use ssh are more suspect than those who don't.

    2. Re:Privacy? by Anonymous Coward · · Score: 0
      Suspect?

      I bet that using strong encryption will be declared illegal this year.

      For your own good, of course. Who cares if the terrorists manage their cells like hundreds of years ago: dead-drops and personal meetings. Banning encryption and draconian phone tapping laws won't help!

  2. Privacy rights are still an issue. by www.sorehands.com · · Score: 3, Interesting
    How secure is this data? I don't mean in the sense of encryption or hacking, but being subject to subpeona.

    The police will be able to come to your door and demand your electronic wallet. Or in an auto accident, the opposing party can demand it in discovery. Think of the black boxe in your totalled vehicle, now in the possession the insurance company. What if it contained GPS data?

    1. Re:Privacy rights are still an issue. by gweihir · · Score: 2, Interesting

      Or in an auto accident, the opposing party can demand it in discovery.

      Please keep in mind, that Passport is a global thing, while the problem above is a problem of US law. No such possibilities exit in most of Europe. The opposing party has no means to demand private information from you or other parties.

      Not the whole world has the virtually nonextistent privacy laws the US has. In fact a lot of the data trading with private data going on in the US would be criminal in, e.g., Germany.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted and ignored otherwise.
    2. Re:Privacy rights are still an issue. by scenic · · Score: 2
      The police will be able to come to your door and demand your electronic wallet. Or in an auto accident, the opposing party can demand it in discovery. Think of the black boxe in your totalled vehicle, now in the possession the insurance company. What if it contained GPS data?

      Those aren't privacy rights that you've mentioned above. There is not an obligation for someone to be able to lie to a court order or subpeona. And as a private citizen, you don't have that right. The important thing is that you have control over your data.... when you're faced with a subpeona, you don't really have control over your data, except that you can fight the subpeona.

      Your concern seems to be that you should be able to turn off data collection. You should disable the data collection when you don't want a record kept (a.k.a. use cash, or disposable PayPal account, etc.). But having a user-side agent isn't a bad thing.

      Sujal

      --

      politics, food, music, life: FatMixx

    3. Re:Privacy rights are still an issue. by nate1138 · · Score: 1

      Umm, how is this any different from the centralized approach?? At least with a decentralized agent supplying this data to those that you authorize it to you are in control of who gets it, not some faceless corp. Remeber when all of the dot-coms that promised not to reveal personal information started dying?? "Private" Customer information was often the first thing they sold. In addition, at least now people will have to ask YOU for the information instead of sending the subpoena to Microsoft......

      --
      Where's my lobbyist? Right here.
    4. Re:Privacy rights are still an issue. by bendude · · Score: 2, Insightful

      "Hello... Foriegn Leader? Hi, this is GWB calling. I was wondering if you would like to impliment all of our suggested internet security measures as detailed in the email my boys sent you last week? Oh, you were unsure about which bit? Look, let me take this opportunity to assure you that if you find anything whatsoever in these suggestions to be iffy, then we will have no hesitation in turning your county into a glowing, smoking crater. What's that? 110 percent. That's great (thumbs up to advisors sitting quietly across desk)- knew we could count on you. Bye"

      --


      Get the Hell off my planet, you slimy mobster Bush!
    5. Re:Privacy rights are still an issue. by clare-ents · · Score: 2

      This is exactly the attitude that fosters hatred of the USA.

      Running around telling the rest of the world what to do because you are so big and invulnerable doesn't work.

      I was hoping the US might figure this out sometime soon but given Bush's recent pissed off bully style behaviour it appears not.

      --
      Only two things are infinite, the universe and human stupidity, and I'm not sure about the former. (Einstein)
    6. Re:Privacy rights are still an issue. by Anonymous Coward · · Score: 0

      What if it contained GPS data?
      What if it did? Its hardly private, riding around in your car, is it?

    7. Re:Privacy rights are still an issue. by bendude · · Score: 1

      I have a lot of respect and admiration for the people of America. I am feeling this event just as much as anyone else not directly involved. (Most of the US and most of the rest of the world)
      I do not think it is anything like the time to go into my theories on "the need for states at all".

      We shouldn't think of this as a "US" thing or a "westerners"||"Christians"||etc thing. This is a humanity thing. Each and every person was toched by that event and though it's getting a tired point, the world will never be the same again.

      My suggestion: Crises talks held at UN (or somewhere better). Nations are told "people are dying. It will stop now. Stop your sniveling, stop your bickering, smarten yourselves up and fix this mess, Now!". Cease fire must be declared everywhere. Once we've come up with an initial direction to head out from, we must then examine this event along with all others for a proper perspective on the events that lead to our near downfall.

      --


      Get the Hell off my planet, you slimy mobster Bush!
    8. Re:Privacy rights are still an issue. by budalite · · Score: 1

      And what if you are a legitmate suspect, and really guilty? If you have nothing to hide, you have nothing to hide.

  3. Mozilla has this feature by epsalon · · Score: 3, Interesting

    It keeps your personal data (optionally encrypted) and fills in forms for you. You can then select what data you want actually sent.
    Is this what the asker referred to?

  4. Look guys... by Anonymous Coward · · Score: 1, Interesting

    I don't like tracking, and I can remember multiple, non-obvious passwords. A lot of other people can't, and most of us don't have any serious data to protect. Passport isn't perfect, but nothing is. It simplifies life for a lot of people, they like it, they WANT to use it, so why not just leave them alone?

    Better yet, write another open source replacement that copies the commercial versions features, only make it WORK and don't do it in JAVA for Chrissake....

    'Gassport' perhaps?

  5. Only one sentence by Anonymous Coward · · Score: 1, Insightful

    The software that manages your personal information should run on your personal computer.

    1. Re:Only one sentence by Anonymous Coward · · Score: 0

      With backups at the FBI, CIA, NSA,...

    2. Re:Only one sentence by Anonymous Coward · · Score: 0

      That's an interesting variation of Linus' backup method: "Real men don't do backups - they post their code to the Internet, and let others mirror it."

  6. The ultimate personal agent by Invisible+Agent · · Score: 5, Funny

    a personal agent that manages your info, in a way that you control, what, who and when to give out a selection of your sensitive data.

    Boy, I think I already have one of these. It's called my brain, and when a web site asks me for personal information, I consult with my brain to see if I want to give it to them. Then, I use another technology called my 'keyboard', and type in the relevant data. It takes about 30 seconds usually, and it has none of the potential vulnerabilities that come from entrusting my data to some 3rd party.

    Are people really this lazy, or am I missing something?

    --

    Invisible Agent
    This post is a mirror; when a monkey stares in, no hacker gazes out.
    1. Re:The ultimate personal agent by Cynikal · · Score: 3, Insightful

      Yes but don't forget that our era is based on laziness. Anything that makes our lives just that tiny little bit easier is essential to some people. How many people will spend 30 minutes looking for the remote when they could just walk up and change the channel?

      Then theres people like my father who *can't* remember half their information. Sometimes i have to call him to get his new email address cause he forgot his password and had to register a new account.. now if only he could get a fingerprint authenticy device to log him into one server that could feed whatever else to whatever site he needed...

      I don't know, Its a good idea for some, and a bad idea to others. It depends on what you like. just respect other peoples' choices to decide what THEY like...

    2. Re:The ultimate personal agent by Yo_mama · · Score: 3, Interesting

      I think you're missing something.

      "They" are trying to come up with a system so you don't HAVE to type that data in over and over (good for those of us with RSI). The corporate world throws in the added benifit for themselves of keeping the data that allows them to profile and target consumers. What we need is a system that benefits us. I don't mind helping a company out but I want to choose when to do it.

      You can argue that if you don't like it you don't have to do it, but what if it becomes a wide spread system? What if for some assinine system the US government started using MS passport to log into the IRS page and you HAD to file electronically? You start getting boxed into a corner. It's important that we have some say over the information profiles on us.

      --
      Never understimate the power of human stupidity -Lazarus Long
    3. Re:The ultimate personal agent by jheinen · · Score: 4, Insightful

      It doesn't matter if people are lazy or not. Your brain and keyboard don't mean squat when you want to order a book from Amazon and it says "Passport required." When all commercial sites require this, you are left with no choice but to sign up and have your data managed by M$. Either that, or forgo purchasing online and start buying all your stuff from brick & mortar shops with cash.

      -Jeff

      --
      -Vercingetorix
      "Necessitas non habet legem." -St. Augustine
    4. Re:The ultimate personal agent by gweihir · · Score: 1

      Boy, I think I already have one of these. It's called my brain, and when a web site asks me for personal information, I consult with my brain to see if I want to give it to them. Then, I use another technology called my 'keyboard', and type in the relevant data. It takes about 30 seconds usually, and it has none of the potential vulnerabilities that come from entrusting my data to some 3rd party.

      And it has the nice advantage that access control is already built in. I mean, if you trust something like Passport, you have to _really_ secure your access to it.

      Regular sweeps for bugged keyboards. No passwords while somebody looks over your shoulder. No writing down of passwords. ... Sounds actually more complicated to me than just typing in private date when you want to give it.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted and ignored otherwise.
    5. Re:The ultimate personal agent by Anonymous Coward · · Score: 0

      I use another technology called my 'keyboard', and type in the relevant data. It takes about 30 seconds [...] Are people really this lazy, or am I missing something?

      With a passport, not only don't you have to type in your personal info, you don't even need to know your address, zipcode, phone number and birthdate.

    6. Re:The ultimate personal agent by mnordstr · · Score: 0

      Are people really this lazy, or am I missing something?

      To make a long answer short; Yes, people are really that lazy.

    7. Re:The ultimate personal agent by natet · · Score: 0, Troll
      Yes, I think you missed something...

      Who benefits: you, and the companies that don't pay for outdated or inaccurate data anymore, but [pay you] for accessing correct data.

      I sure would love it of some of the spammers that get my address from who knows where would pay me to recieve their email...
      --
      IANAL... But I play one on /.
    8. Re:The ultimate personal agent by singularity · · Score: 1

      I am surprised no one pointed out the other problem with this way of doing things: You have no control over that data once it leaves your keyboard.

      Yes, you can spend time reading their privacy policy (more than the 30 seconds you allotted), but then you have to worry about the data being sold (and the privacy policy changing post de facto).

      --
      - (c) 2018 Hank Zimmerman
    9. Re:The ultimate personal agent by spencerogden · · Score: 3, Insightful

      Wouldn't a program on your computer, which stores your info encrypted, and then sends it out when it gets a finger print work? And would also mean you don't have to store your info on a third party?

    10. Re:The ultimate personal agent by 1010011010 · · Score: 2

      Door number two, "local vendor," thank you very much.

      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
    11. Re:The ultimate personal agent by vanyel · · Score: 1

      This is what "competition" is all about. Vote with your dollar. If amazon starts requiring a passport login, they'll lose my business and I'll tell them why. There are plenty of others that don't require it and aren't likely to (Powell's for one, at least for books).

    12. Re:The ultimate personal agent by morcheeba · · Score: 1

      Forget the commerical pages... maybe all pages. Try going to starbucks and you can't read any page there (even the privacy policy! ) without passport cookies. All I wanted to do was to check on there 802.11b implementation progress - not even buy something over the web.

    13. Re:The ultimate personal agent by aozilla · · Score: 2

      Boy, I think I already have one of these. It's called my brain, and when a web site asks me for personal information, I consult with my brain to see if I want to give it to them.


      Yeah, but then I have to remember which false information I gave for which site. It would be much nicer if my computer could remember that I told ebay.com that my name was Bill Gates and I was born February 10, 1970, but when I signed up for hotmail.com I used the name Joe Schmoe and the birthdate May 16, 1975.

      --
      ok then your [sic] infringing on my copyright! Could you as [sic] me next time before STEALING my comments for your own?
    14. Re:The ultimate personal agent by aka-ed · · Score: 2, Insightful

      The words that come to mind are "slippery slope." I am a lifelong non-driver. When I was a young adult, I was able to live my life unencumbered by *any* form of ID, and became quite accustomed to doing so. Nowadays I must carry my passport (the govt-issued one, not MS's).

      Once 80% of the population have Passport, how many voters would object to a government requirement that you have Passport (or its equivalent) to do your taxes? Or to do any monetary exchange?

      Vote with your dollars on that? I don't think so.

      --
      I survived the Dick Cheney Presidency 7 to 9 AM 7-21-07
    15. Re:The ultimate personal agent by bhudda · · Score: 1

      Then they just loose business, right?
      No way in hell I am going to fill out a form to read their public info.

      Besides, instead of Starbucks, get thee a coffe pot and make your own.

      Bhudda

    16. Re:The ultimate personal agent by aka-ed · · Score: 1
      Point well taken except you mistyped the html.

      Starbucks is here. Note the "Passport" login at the top right of the page.

      --
      I survived the Dick Cheney Presidency 7 to 9 AM 7-21-07
    17. Re:The ultimate personal agent by Anonymous Coward · · Score: 0

      whoops... thanks!

    18. Re:The ultimate personal agent by Cynikal · · Score: 1

      And if his hard drive crashes, he's essentially lost everything.. Theres two schools of thought on that, some believe its safer to keep your info at home, and others think an offsite storage is more prudent. I personally aggree with you on this subject, but i was just pointing out why people use these services, not saying that i think it's a great thing..

    19. Re:The ultimate personal agent by alexburke · · Score: 2

      Your brain and keyboard don't mean squat when you want to order a book from Amazon and it says "Passport required." When all commercial sites require this, you are left with no choice but to sign up and have your data managed by M$. Either that, or forgo purchasing online and start buying all your stuff from brick & mortar shops with cash.

      The moment Amazon does this, the moment they lose my business. I can go down to Chapters, sit in a comfortable chair (with a Starbucks only a few steps away, no less), and read ALL DAY, without ever being asked to buy anything. When I find something I like, I buy it at my own leisurely pace.

      It's civil, and it doesn't require my data being held by third parties [for my own protection/because I'm a fucking moron like all the other consumers].

    20. Re:The ultimate personal agent by binner1 · · Score: 1

      I agree! When it comes to having no choice left (all online shops enforce passport), I'm heading down to Chapters.

      I will not be forced to use bad technology simply because the rest of the World thinks MS knows how to look after their data.

      -Ben

    21. Re:The ultimate personal agent by bolthole · · Score: 2, Interesting
      Then they just loose business, right? No way in hell I am going to fill out a form to read their public info.

      Right. But it does no good for you to just not shop there. It is important for you to email their site designers and TELL THEM "you have lost my business because you have given me no alternative to shop without MS-passport".

      http://www.starbucks.com/customer/contact_forms.as p?nav=3i

      Be fore-warned: Unfortunately, the idiots require javascript to submit this form, on top of everything else.

      But I think it would definately get their attention if 20 different people contacted them with this.

      NOTE: do NOT convert the above URL to a link. It will look better if they cant see the complaints all came from one place like slashdot.

    22. Re:The ultimate personal agent by kr4jb · · Score: 1

      When all commercial sites require this, you are left with no choice but to sign up and have your data managed by M$.

      Simply place your order on the the phone. And mention that you refuse to use Passport. They will get the message.

      --
      // Alan Porter
    23. Re:The ultimate personal agent by raymondlowe · · Score: 1
      Yeah, but then I have to remember which false information I gave for which site. It would be much nicer if my computer could remember that I told ebay.com that my name was Bill Gates and I was born February 10, 1970, but when I signed up for hotmail.com I used the name Joe Schmoe and the birthdate May 16, 1975.

      This is true, the other day we worked out that the three people in our house have about 10 email addresses total -- all in production, not counting dead ones -- and that includes my 4yr old son (ok he only has one).

      R.

    24. Re:The ultimate personal agent by SeekChaos · · Score: 1
      With about 30 different accounts (including /.), currently adding two or three every month, the amount of accounts is hard to keep track of. Sometimes my prefered username already exists at a site. I use the same passwords over and over again, but sometimes a minimum length is required, or it has to contain at least one number or so. I have to write some of 'em down in order to remember. I can see the advantage of a 'personal agent'.

      Try working of two or three computers and answer some of the alternatives mentioned in the discussion:
      • store file on hard drive: no option;
      • store information in cookies: no option;
      • store information at Microsoft: not prefered!;
      It would be convenient - though lazy - to have such a personal agent. Security and privacy are the real issues here, not laziness and preference. How do you keep companies from reselling your information? How do you keep them from sending you unsollicited mail? Especially interesting question: would such a personal agent be safe enough to store my credit card data??
      --
      /M
    25. Re:The ultimate personal agent by Steeltoe · · Score: 1

      Agreed! Besides, there's a really good English bookstore where I live. If online dealers don't want my credit card number, they can start packing.

      - Steeltoe

    26. Re:The ultimate personal agent by Steeltoe · · Score: 1

      Leave the country. With all the patriotism you can muster. Vote with your homes!

      Yeah, I'm joking ;-)

      - Steeltoe

  7. ugh by teknopurge · · Score: 1

    yeah, let's call it "Passport" and bundle it with XP so that we can manage our information from our desks and have it centralized at the same time. sure it will be suceptible to attack, but it would be convienent; oh wait, it alread is.

    1. Re:ugh by Lonath · · Score: 2, Funny

      Fortunately, I am working on a free replacement to Passport. It's called GMOTB (GNU Mark of the Beast). All versions will be version 6.66. The software is free (as in beer) and free (as in speech), except you will have to give us an irrevocable perpetual non-exclusive license to your soul. We will not have to safeguard your soul or keep it private, and we can cross-sell souls with some of the other companies with businesses in this same IP space (such as the Christians and Muslims). Even though they don't like us very much. We are protecting our IP space from thieves like open source advocates by enforcing our patents in several key areas including "A Method and Apparatus for Parallel Achievement of Salvation", and "An Apparatus for Storing Large Numbers of 1's and 0's and Changing them Periodically to New Arrangements Based on their Current Arrangements to Create Mathematical Models of Real-World Phenomena". Needless to say, although Bill Gates has been one of our strategic partners for a long time, we feel it is important enough to win in this market segment that we have struck out on our own to give consumers true choice.

  8. Goodbye old conventions by estoll · · Score: 1

    Before you know it, when you go to a store to make a purchase, instead of being asked for your address and phone number, they will ask for your IP address.

    --
    http://www.askthevoid.com
    1. Re:Goodbye old conventions by gweihir · · Score: 1

      No, not enoug of these around. At least until we go to IPv6.
      Then you will be able to give a new one every time they ask ;-)=)

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted and ignored otherwise.
    2. Re:Goodbye old conventions by Anonymous Coward · · Score: 0

      In the interests of anti-terrorism, all who wish to make a purchase must display their IPv6 address that has been imprinted on their wrist or forehead.

  9. Maybe I'm missing something? by mjh · · Score: 3, Interesting

    Even if we have dedicated networks to homes, and even if those networks are deployed to everyone's home like telephones, and even if we create this cryptographically secure database, how do we prevent someone from getting information out of it, and then reselling that information to someone else?

    I think that this guy has an interesting idea, but I don't think that it's necessarily a solution for the privacy problem. I do very much like the idea of flipping a switch on my home PC to invite people to advertise to me for services that I need at the current time (e.g. my washer just broke and I need a new one). But how do I then prevent the phone number, contact information, interests, etc that I just gave out to Sears (et al) from getting stored in their own database and being resold to someone else?

    Did I miss something in the article that addressed this?

    --
    Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    1. Re:Maybe I'm missing something? by listen · · Score: 1

      In the UK, we have something called the Data Protection Act. It basically says "Don't give out your customers data unless they ask you to."

      I believe similar laws exist in the rest of the EU.

      Now the downside: A lot of contracts specify that you are waiving your data protection rights (eg credit cards, so they can run a little "bad credit" clearing extortion racket on the side). This is dodgy, and a lot of consumer rights groups are pissed off about it. Hopefully it will be changed.

      Other contracts have tiny boxes saying eg "tick here if you don't want to not invalidate your data protection rights" or something equally bewildering, so a lot of people have no idea what the box means, and end up giving permission for their data to be sold.

      Anyway, a law like this could work.

      But if you want a technical solution for your particular problem, there are a couple:

      1) The advertising requester could create a proxy with a one time address that would then be deleted when you no longer want that bunch of adverts. They don't need info about you and they don't need to correlate it. They just need info about your requirements.

      2) (My favourite) everyone just publishes information about their services on thier website in a machine understandable form ( eg similar to the BizTalk XML schemas without the broken licence) and multiple search engines indexes them. Then you put in your query, and get the list of services that fit your requirements. And contact them in whatever way you see fit.

      Anyway, enough rambling..

    2. Re:Maybe I'm missing something? by Kaki+Nix+Sain · · Score: 1
      But how do I then prevent the phone number, contact information, interests, etc that I just gave out to Sears (et al) from getting stored in their own database and being resold to someone else?
      You can't, that is why you only give them some temporary contact info. I'm thinking of something like a sneakemail address, iwantawasher9382@myhomenetwork.whatever. When you buy the washer you want, you kill the address. Then you no longer have to care if they sell it to whoever is stupid enough to pay for a dead address.

      --

      (C) Kaki Sain, 2011. By reading this, you have illegally copied my property to your brain.

    3. Re:Maybe I'm missing something? by natet · · Score: 1
      I think you did miss something...

      Who benefits: you, and the companies that don't pay for outdated or inaccurate data anymore, but [pay you] for accessing correct data.

      I for one would like for spammers to pay me for all the mail they send me, instead of whomever they are paying now...
      --
      IANAL... But I play one on /.
    4. Re:Maybe I'm missing something? by bolthole · · Score: 1
      n the UK, we have something called the Data Protection Act. It basically says "Don't give out your customers data unless they ask you to."

      Yeah, but not in the US.

      Funny thing about being in the "land of the free".
      a lot of times, the "freedom" applies more to businesses than to people.

  10. ESR on the WTC Attack by szcx · · Score: 1, Offtopic
    Boneheaded, opportunistic comment of the day. Last week Jerry Falwell blamed the WTC attack on the ACLU, feminists, and gays. Here's what ESR has to say about it;

    Raymond, the libertarian open-source guru, known for his love of firearms, suggested that if the passengers of the hijacked jets had had guns the four-plane tragedy might have been prevented: "We have learned today that trying to keep civilian weapons out of airplanes and other areas vulnerable to terrorist attack is not the answer either -- indeed, it is arguable that the lawmakers who disarmed all the non-terrorists on those four airplanes, leaving them no chance to stop the hijackers, bear part of the moral responsibility for this catastrophe."
    The story about this took less than five minutes to be rejected by the editors. Apparently when your stock is circling the drain, a member of the Board of Directors saying something like that isn't something you necessarily want publicised.

    Think air rage is bad now? Try arming those drunk businessmen and see what happens.

    1. Re:ESR on the WTC Attack by HendriX · · Score: 1

      I had been asking myself why this wasn't discussed here and if nobody submitted such story.

      I think that this is MUCH more important for Open Source than many other things that are discussed

      Regards

  11. Identity Manager by dannu · · Score: 1
    I know of some people thinking about implementing identity managers (mostly in germany). They center around the idea of "user-side" managment (as opposed to - you know it - passport).

    Myself i have the vision of a central Identity managing agent which basically

    let's you define identities in one central place (name/pgp-keys/ssh-keys etc.)

    provides interfaces (corba/c) to other programs (e.g. email-clients) to use the current identity settings

    acts as an ssh-agent

    acts as an pgp-agent (much the same way as the ssh-agent does)

    generally manages Identity-Information in profiles (like business-profile1, privat1,privat2, anonymous)

    spawns and configures proxies intercepting network communication (mostly smtp/http-proxy), filtering/altering cookies and other identification elements

    aids in encrypting personal stuff

    could run on embedded (more controalable) environments/chipcards

    I guess the agent itself should be very lean. The gui to configure/login is separated. And the programs using the ident-information (email/browsing/logins/Formular filling) should be separate too. And this has to be a free project not owned or controled by any company, i guess.

  12. My thoughts on the above article... by Igloo+Boy · · Score: 0, Offtopic

    Brrrr... Is it ever cold outside. I think I'll just stay home. I love hanging out beside my wood stove, it keeps me warm. It, however, doesn't ever get warm enough to melt my igloo.

  13. Personal Agents? by j-beda · · Score: 2, Interesting
    While it might be good to have complete control over your data and agents by way of not having Microsoft or anyone else store the sensitive information, it does make it a little less convenient to have to do the maintenance yourself.

    Having to carry all that information with you (maybe in a PDA or something?) if you want access to it is an additional burden.

    Perhaps having an open standard for exchange of this type of information such as done by http://xns.org/, would allow multiple competing agencies to act as costodians. Give people choice and perhaps some of the control and privacy (and cost) issues would be less pressing than if all data was held by a single player such as Microsoft.

    The article by Michael McCandless (stupid PDF file!) addresses some of the issues that XNS tries to address - albeit with the idea of the personal information residing on your network connected home computer rather than on an XNS-server run by some company that you decide to trust.

    Now if XNS would get around to releasing their open source code examples and the detail technical specifications perhaps there could be more motion to widespread adoption. They claim plans to do so "real soon now".

    With that said, XNS's ecard address book features are pretty nifty even at this early development stage.

    1. Re:Personal Agents? by MikeBabcock · · Score: 2

      Why not simply offer remote storage facilities that allow the storage of arbitrary encrypted data? Personal agents can then fetch that data using a username and password through, for example, LDAP. That data is decrypted on the user's computer (or cell, pda, etc.).

      This can be a subscription service and storage prices and access speed would be the points of value for consumers. It also requires nothing from the subscriber except a way for them to pay (pre-paying even?) and a username+password combo.

      No stats tracking by remote sites.

      --
      - Michael T. Babcock (Yes, I blog)
    2. Re:Personal Agents? by j-beda · · Score: 1
      Why not simply offer remote storage facilities that allow the storage of arbitrary encrypted data? Personal agents can then fetch that data using a username and password through, for example, LDAP. That data is decrypted on the user's computer (or cell, pda, etc.).

      Well, many of the uses for this type of data require the exchange of the data with others, rather than simply the storage of the data for your own use. It may be nice to have personel access to your medical records in case you ever want to remember exactly which toe you broke in the third grade. It would probably be even more useful if you could allow select individuals such as your current doctor to have the ability to access the information, and only that information, you would grant them access to.

      I want the child-car-seat manufacturer to be always able to send me recall notices and thus I need them to be able to find my mailing address, even when I move. XNS protocols promise this ability while preventing the child-car-seat manufacturer using that information for junk mail, if that is how I set up the privacy contract.

      These types of data exhanges, regardless where the data is stored and who controls the access to it, will require some sort of data-exchange protocol. XNSorg seems to be working towards that protocol development in an open standards way which gives me more confidence than many of the other initiatives I have seen.

    3. Re:Personal Agents? by MikeBabcock · · Score: 2

      I don't think you understood my point.

      I was suggesting configuring personal agents on one's own devices to access encrypted data at these remote sites to then send themselves to the websites / services requiring that information.

      Instead of having "ME visit ECOMM site, ECOMM site pass me to PASSPORT, PASSPORT log me into ECOMM site", it would be "ME visit ECOMM site, MY AGENT fetch data from STORAGE SITE, MY AGENT send data to ECOMM site."

      --
      - Michael T. Babcock (Yes, I blog)
    4. Re:Personal Agents? by Taufiq · · Score: 1

      Novell's DigitalMe is something like this. You decide which bits of information other DigitalMe accounts have access to. It has an interface which will log you into all your web site accounts. The only problem is allowing a corporate entity control over the database. Thanks to Novell's distributed Directory Service, it is theoretically possible for a user to choose a trusted entity to host the information.

    5. Re:Personal Agents? by j-beda · · Score: 1
      You are correct, I did misunderstand.

      This is added functionality to just having a data repository, but it does not provide the same level of functionality that XNS could provide - not that MikeBabcock implied that it did of course.

      I do like the idea of privacy contracts that some of XNS's features are built upon.

    6. Re:Personal Agents? by MikeBabcock · · Score: 2

      There is almost no need for a privacy contract when using strong crypto and deciding which data to pass along yourself.

      --
      - Michael T. Babcock (Yes, I blog)
    7. Re:Personal Agents? by j-beda · · Score: 1
      But once you pass the data along, without some agreement you have little control over what is done with the data.

    8. Re:Personal Agents? by MikeBabcock · · Score: 2

      That is no different in my way than xns or passport; that data, once received by the remote site, is in their hands. You need a service contract _with them_, not with xns or passport unless you trust those entities to enforce the rules.

      My suggestion was just to make that data available to the personal agent.

      --
      - Michael T. Babcock (Yes, I blog)
    9. Re:Personal Agents? by j-beda · · Score: 1
      OK, but XNS provides a standardized method of exchanging a service contract between you and the other party. XNS is only the protocol being managed by XNSorg.

      It isn't clear to me what stance XNSorg would adopt in any dispute between parties who used XNS to exchange data, but it is clearly in the interest of XNSorg to work towards widespread compliance with the privacy agreements. While the privacy contracts would allow for court cases, most disputes would probably be settled with political pressure - play nice or you don't get to use XNS technology and have XNS using customers.

  14. XNS.org - private agent already here by Tumbleweed · · Score: 2

    I used to work for Intermind, which morphed into 'OneName', which was the commercial counterpart to xns.org. The open source community just hasn't picked up the XNS ball for some reason. *shrug*

    1. Re:XNS.org - private agent already here by ek_adam · · Score: 1

      XNS has most of the features that people here have been mentioning, but they still haven't released the source for it. They're still saying they plan to, but they're about a year behind schedule in doing so.

    2. Re:XNS.org - private agent already here by acaben · · Score: 2
      The open source community just hasn't picked up the XNS ball for some reason.

      There's a really good reason: XNS is vaporware.

      There is no source to be seen. There are still no technical specs to be seen. There are no answers on the mailing list, other than stalling tactics and vague "soons" that have been uttered by those "in the know" since day one.

      The reason the community doesn't pay any attentiong to XNS is because they haven't given anything to pay attention to.

      It's really time for them to put up or shut up.

  15. Re:Mozilla has this feature - sortof by Camel+Pilot · · Score: 2, Interesting

    From what I understand this only works for previously filled out forms.

    What is really needed is someone to release a standard for form field naming (i.e. name_first) then when confronted with a form you can select to fill all recognized form fields from an encrypted password protected database kept on your computer. Then it would nice if you could transfer this this database, encrypted and password protected, to sync up your other computers. This would make MS .net authentication less attractive.

  16. Monty Python on advocacy by Anonymous Coward · · Score: 0


    Rabid Linux Geek: 'Evening, squire!
    Squire: (stiffly) Good evening.
    Rabid Linux Geek: Is, uh,...Is your wife a goer, eh? Know whatahmean, know whatahmean, nudge nudge, know whatahmean, say no more?
    Squire: I, uh, I beg your pardon?
    Rabid Linux Geek: Your, uh, your wife, does she go, eh, does she go, eh?
    Squire: (flustered) Well, she sometimes "goes", yes.
    Rabid Linux Geek: Aaaaaaaah bet she does, I bet she does, say no more, say no more, knowwhatahmean, nudge nudge?
    Squire: (confused) I'm afraid I don't quite follow you.
    Rabid Linux Geek: Follow me. Follow me. That's good, that's good! A nod's as good as a wink to a blind bat!
    Squire: Are you, uh,...are you selling something?
    Rabid Linux Geek: SELLING! Very good, very good! Ay? Ay? Ay? (pause) Oooh! Ya wicked Ay! Wicked Ay! Oooh hooh! Say No MORE!
    Squire: Well, I, uh....
    Rabid Linux Geek: Is, your uh, is your wife a sport, ay?
    Squire: Um, she likes sport, yes!
    Rabid Linux Geek: I bet she does, I bet she does!
    Squire: As a matter of fact she's very fond of cricket.
    Rabid Linux Geek: 'Oo isn't? Likes games, eh? Knew she would. Likes games, eh? She's been around a bit, been around?
    Squire: She has traveled, yes. She's from Scarsdale. (pause)
    Rabid Linux Geek: SAY NO MORE!!
    Rabid Linux Geek: Scarsdale, saynomore, saynomore, saynomore, squire!
    Squire: I wasn't going to!
    Rabid Linux Geek: Oh! Well, never mind. Dib dib? Is your uh, is your wife interested in....photography, ay? "Photographs, ay", he asked him knowlingly?
    Squire: Photography?
    Rabid Linux Geek: Snap snap, grin grin, wink wink, nudge nudge, say no more?
    Squire: Holiday snaps, eh?
    Rabid Linux Geek: They could be, they could be taken on holiday. Candid, you know, CANDID photography?
    Squire: No, no I'm afraid we don't have a camera.
    Rabid Linux Geek: Oh. (leeringly) Still, mooooooh, ay? Mwoohohohohoo, ay? Hohohohohoho, ay?
    Squire: Look... are you insinuating something?
    Rabid Linux Geek: Oh, no, no, no...yes.
    Squire: Well?
    Rabid Linux Geek: Well, you're a man of the world, squire.
    Squire: Yes...
    Rabid Linux Geek: I mean, you've been around a bit, you know, like, you've, uh.... You've "done it"....
    Squire: What do you mean?
    Rabid Linux Geek: Well, I mean like,....you've SLEPT, with a lady....
    Squire: Yes....
    Rabid Linux Geek: Do they run Linux?

  17. There's an interesting idea. by Telek · · Score: 2

    Make it a law: in order to email me or send me junkmail or otherwise harass me with advertising, you must pay me to get my updated contact information. (It'd be like $0.001 per but you know, when someone sends out 1,000,000 emails that's $10000 extra. At the rate of emails that I get, about 30 spams a day prefilter, that'd add up after a while).

    Even if it was like $0.0001 the advertiser could benefit because they would have up-to-date advertising information.

    And if I could indicate what I like and don't like, then they can also target better.

    So $0.0001 if you just want my updated email address, or $0.001 if you want to know what I don't like, or $0.005 if you want to know what I like.

    Pay per use advertising. Nice!

    Scary thing is that it could benefit the advertisers too. =)

    --

    If God gave us curiosity
  18. Rich people already have "personal agents" by JoeShmoe · · Score: 4, Interesting

    They are called financial managers. They get all the bills, they keep tabs on all expenses, they handle all dealings with the financial world. All the rich person does is spend it and read reports on the interest they've earned.

    So why shouldn't the rest of us have the same thing? I hate having to update dozens of records across the country every time i change an address or lose a credit card. Switching banks caused a huge uproar in my automatic online banking.

    It's like e-mail. I would have to be a complete idiot to use my ISP-given e-mail box. As soon as a switch providers, its worthless since no ISP wants to offer a nice handy eForwarding option (even for a small fee). They want to punish you for leaving. Not even that, sometimes ISPs decide on their own to change their addresses (like what Netscape did when it bought some free webmail thing, or like MediaOne did when they became part of @Home).

    So what do I do? I get my own domain and give that out. When my ISP changes, I don't care. Update the record in a single place and I'm done.

    Extra layers of abstraction, like this, are desperately needed in the financial sector. I would love to see some AI that could handle the same functions as a financial manager without me having to make enough interest off of my measly savings account to be able to pay his salary.

    - JoeShmoe

    --
    -- I wonder which will go down in history as the bigger failure: the War on Drugs or the War on Filesharing
    1. Re:Rich people already have "personal agents" by ultigirl · · Score: 1


      Passport is exactly like an ISP - think of it as a CSP - a credential service provider. Every issue you hate about ISPs applies. You just haven't figured it out yet cause M$ is almost the only CSP around, and most people figure that since passport is free, it doesn't matter anyways.

      So what happens when M$ decides in 5 years to suddenly charge you $50 a year for passport service? At least you can CHOOSE to switch ISP's! And even if you have a choice in the future to switch to a different CSP - whaddaya know, you still have to enter all your information all over again.

      I hate to break it to you, but passport probably won't make your life that much easier.

      Ultigirl

    2. Re:Rich people already have "personal agents" by JoeShmoe · · Score: 2

      I'm not suggesting we all use Passport, in fact I think it should be avoided for the exact reasons you list.

      The article I thought was talking about agents that we would each be running ourselves, just like any other service (web, mail, ftp). That agent that we run and maintain interacts on our behalf each time some organization needs financial information.

      There would probably have to be some central database, just like there are root servers for resolving web addresses. But there is no reason these databases can't all compete with each other just like registrars are supposed to be doing.

      Point is it should definitely be something that we control or maintain, although low tech users may with to enroll with a CSP provider rather than maintain the service themselves.

      - JoeShmoe

      --
      -- I wonder which will go down in history as the bigger failure: the War on Drugs or the War on Filesharing
  19. ZeroKnowledge? by Coryoth · · Score: 1
    How about Freedom from ZeroKnowledge up in Canada? It's been a while since I looked at it properly, but it always looked like it was building into exactly what you're talking about.

    Jedidiah

  20. Buckets of salt, but... by tshak · · Score: 2

    A recent MSDN article quotes, "Microsoft will not mine, target, sell, or publish any data contained within the Hailstorm data store without explicit user concent."

    Is there any way to have a "EULA" type thing from the USER instead of the company? Could we take legal action in the same way they can if we violate thier EULA?

    --

    There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    1. Re:Buckets of salt, but... by Planesdragon · · Score: 2

      Is there any way to have a "EULA" type thing from the USER instead of the company? Could we take legal action in the same way they can if we violate thier EULA?

      IANAL, but...

      An EULA is a contract, worded by the company and agreed to you by you. If they state in the EULA to not do something, and they do, you can file suit and win--and any ambiguous wording in the EULA will be decided against them.
      Plus, if you've got the cash you can take them to court and challenge the validity of the EULA yourself. Such legal activities aren't reccommended to anyone without oodles of money--enough money to hire real lawyers, and not IANAL'd Slashdot posters!

    2. Re:Buckets of salt, but... by j-beda · · Score: 1
      This does seem to be the intent of the XNS system's privacy contracts. The users of the data have to agree on how the data is used by legally binding contracts before they can have access to the data itself.

      From the FAQ:
      This contract specifies the privacy and security terms governing the data to be exchanged, including the specific privacy permissions and synchronization permissions granted by the data owner.

    3. Re:Buckets of salt, but... by Anonymous Coward · · Score: 0

      Good luck catching them if they do. If you suddenly get 3x as much spam and junkmail as you used to, what's to say it's MS and not Amazon or anyone else you bought from?

    4. Re:Buckets of salt, but... by Malcontent · · Score: 2

      Read further. It sates that the terms can change any time without notice to you. All they have to do is to decide to sell and voila it's all good.

      --

      War is necrophilia.

  21. There are several options today. by Tephyrnex · · Score: 1

    I believe that there are several options available to do some similar things today. Zero Knowledge's Freedom Firewall provides an encrypted personal info tool with it's free firewall and cookie manager. You don't even need to sign up for their anonymous web browsing service to get it.

    1. Re:There are several options today. by jma42 · · Score: 1

      The trouble with ZeroKnowledge and other such anonymizers is that they will all be illegal under the Cybercrime Treaty. My guess is that the Twin Tower attack has made the treaty a done deal.

      --
      OKsofar
  22. Re:Privacy? the real threat by kurt555gs · · Score: 2, Interesting

    This truely scares me. No words can describe the terrible events of Sept. 11 and there are things that can be and should be doen to improve security like having well paid, well trained FAA people at security checkpoints, and although im loath to say this face recognition software at those bording gates as well.

    However, for the Atty General to want to trash the Bill of Rights which is was supposededly sworn to uphold is a far greater threat than any terrorist act.

    Think of all the people that fought in previous wars and gave their lives to protect us from random police searches.

    This is one of the most fundimental freedoms we have.

    Am iI the only one to see Mr Ashcrofts actions as spitting on all the veterens of every war since 1776?

    I hope those who cherish freedom can help in this, I for one am going to donate to the EFF.

    If we let the FBI (et al) randomly scoure our comunications, then the terrorists have won, and iI am not ready for this.

    I do not want to live in a 'banana republic' however if we allow this invasion of our privacy, the next White House news conference may very well look like THIS

    --
    * Carthago Delenda Est *
  23. the only solution: manage your privacy proactively by Anonymous Coward · · Score: 2, Insightful

    I've found that the *only* way to effectivly manage your personal information is to fabricate it when the request for it viloates your personal boundaries.

    Everybody treats identify theft as a bad thing; however, I believe that as long as you are ethical in your use of another person's or fabricated identity (ie you aren't using their idenity to commit some sort of tanageable fraud that results in loss to another person or company for the direct purpose of evading prosecurtion), there's absoluetly *nothing* wrong with it.

    Case in point: ebay has *never* had any of my personal information. They might have enough to eventually track me down to a phone number, but then who's to say if actually that means anything. In retrospect (when the .com boom going got a little tough), I'm very glad I made this decision. This does go to show you just how careful you have to be when making this call.

    My windows boxes? All registered to "_" who works for a company called "_@-.com". My word documents? All check with strings and binary edited to remove unwanted tracking information. I'd suggest everyone out there do the same and show microsoft just how irrelivant their user ID is (something that I hope they're not using for passport).

    Some suggested reading:

    Who Are you?
    Inetrrupted Identity
    From Victim to Victor

    The degree to which an alternate identity is used is, of course, up to the users. And obviously, there's some funadmental line in the sand that each of us draw. Mine is my employer. Basically, I believe that it is funadmentally wrong to use an alternate identity for employment. That usually goes a long way towards abreviating any run-ins I might have with the Feds. regarding victimless forms of "fraud" as interperted by the letter of the law. If you're cleaver, other ways to sign documents and fill out government forms that will keep you clear of these issues, but, for me, it's not worth the hassel.

    One of my biggest pet peeves is recruiters and placment sites/agencies that take liberties with my resume, references or other personal information. Recruiters are such information whores (part of their job) and job web sites are even more poorly secured that most ecommerce sites... once the information goes into the hands of recruitment, it's basically public domain. What *really* pisses me off are the government job-kit sites that require your SSN (and threatens the force of fenderal fraud law if you don't supply the correct one). If you've shopped around for a government job, one thing you'll notice is that government bureaucrats required the use of these sites and have you fill out all manner of paperwork and forms in order to reduce their work load. Often, they'll require your SSN to be actually listed *on* your resume (god help you if you mix that up with the regular recruitment agencies).

    Consequently, I use web bugs to track the distribution of documents I write. In particular, my resume:

    http://www.datadoctors.com/webbugs/

    Adding a web bug to your resume is so incrediably easy I don't understand why more people don't do it:

    Microsoft Word
    Main menu
    Insert
    Picture
    From file
    URL in the filename box
    Pulldown: link to file.

    Of course you have to have a transparent 1 pixel gif/jpg out on a web server to which you have access to the log, but hey doesn't every self-respecting geek have one of those?

    I only which this microsoft word feature had the ability to send more information back and perhaps execute some server side code; it would be really nice if you could gain access to word environment variables via the url specification, like this:

    http://www.resume-tracker.com/cgi-bin/trackit?user s-resume?

    Which would serve up a 1 pixel transparent gif/jpg while recording the reader's e-mail address in my log file.

    Or, how about a word macro that automatically inserts a web bug with the date as a filename in each document you write (of course, you'd have to load up your webserver with a bunch of 1 pixel gifs or the macro would have to dynamically publish the new file name out to the server).

    I've also been thinking about extending this technique to web-based or HTML e-mail using javascript/activex, but I don't write a lot of HTML mail (it's fundamentally evil in my opinion).

    Also Adding embedded javascript/active-X into the text input at various job sites meets with varying amounts of success.

    Of course, sending a word or html document that would load the core information (payload?) from a central location using strong encryption would be best

    Upon sending out a few resumes, I've noticed serveral things. First, I can identify those who are well networked. Second, I can track resume age/versions fairly accurately. And finally, I can easily discover which job search sites are the best with respect to the privacy vs. dispersion trade-off.

    A resume isn't a fully fleged meme, but it's close and, as a consequence, I would like to have a little control/information about how it propagates.

    Is that too much to ask?

  24. Nah... that'll only work with IPv6 by Bake · · Score: 1

    Since there are a lot of people behind NAT'd IP's the store clerks will probably hear a lot of ..
    "Yeah, it's 10.0.0.1" or "192.168.0.45" etc.

  25. Mhhh by platypus · · Score: 2

    Looking at online stores I think it's a fair deal that they collect the information _they_need_ to do their business in a database - but only that bits they need and with a grant that they use this information only for their business.

    So the problem remains with logging in to their site and people today seemingly unable to remember username&password. So what we need is a standardized login interface (xml-rpc, soap whatever) and a facility in the browser to talk to it.
    The browser would hold a database with URIs (https of course) and login/pw. To add security, this database could be encrypted globally with a user password and per-site with a key the site transmits (or just with the URI said information gets POSTed to).

  26. Once again. Too little, too late. by youreanidiot · · Score: 1

    The problem the open source community I think is in it's lack of innovation. Rather than just trying to do "that", only make it open source is a bad approach to ever making any real change, or ever getting people to use your software. The idea should be to do "that", first. When it matters. Just something to think about.

  27. Missing the point. by Carnage4Life · · Score: 3, Insightful

    Are people really this lazy, or am I missing something?

    Passport isn't about saving keystrokes, it's about control, specifically who has access to your personal data and for how long.

    As slashdot has reported in the past, Failed Dotcoms Like Selling Private Customer Data, and a most recent example of this is Egghead.com selling its customer list to Fry's Electronics Twice already I personally have knowingly been bitten by this (CDNow and Egghead) and I have no idea what websites I may have bought a book or CD from in the past that may have failed with my personal info in their databases or haven been sold to a competitor. With a system like Passport, I specify what which websites have information about me, what information they get to see and exactly how long keep this information.

    This is just one of dozens of possible Passport usage scenarios.

    1. Re:Missing the point. by CentrX · · Score: 1

      How does that work? The sites you allow information can just copy your personal information ("keep it locally for convenience") and they have it forever.

      --

      "The price of freedom is eternal vigilance." - Thomas Jefferson
  28. They stole this one too... by Anonymous Coward · · Score: 0

    Digitalme from Novell already did it before passport came along. Gives you the option of giving out any one of your many identities and controlling what info they get. Combined with a personal directory this could be used to "sell" your identity info to any company you trust.

    Geez...one day they may come up with something unique.

  29. Consumer tracking? by sheldon · · Score: 3, Interesting

    I don't want to dismiss the fear, because I think it is important.

    But why attack Passport? How is Passport any more centralized than Visa or Mastercard?

    You don't think credit card companies track your purchases? You don't get a statement at the end of the month? In the case of American Express they send you a statement at the end of the year that even classifies your purchases, so much at restaurants, so much for travel, etc...

    These reactions seem to be more anti-Microsoft kneejerk reactions than any serious discussion of the problems and solutions. I don't see much value in that tactic.

    1. Re:Consumer tracking? by Anonymous Coward · · Score: 0
      Short and simple: Microsoft is evil and untrustworthy.

      Unlike Visa or Mastercard.

    2. Re:Consumer tracking? by stefaanh · · Score: 1

      It is not because Visa or Mastercard are already doing this, that there is no problem. And yes, it's obvious you see it as an anti-Microsoft action.

      It is more Michael's article that brought me to the subject, years ago. Passport just reminded me of that article. And I am still convinced that technically it should be possible to postpone revealing your identity online until the moment you actually buy a product or service. Everything what happens before that should stay anonymous.

      -- Speaking of Passport: I was particularly upset when I got my "Passport" for "free", even after explicitly declining the proposition during a MSN Messenger update. MS imposed a Hotmail account with its MSN Messenger subscribtion. The Hotmail account splitted to create that free Passport account. With Passport is sure goes in the wrong direction with far more implications involved than VISA's or MC's tracking of buying habits. Passport is far more pro-active. And many Passport users seem to never have had the chance to think, let alone say no.

      And could someone convince me that Passport enabled sites actually never see [part of] your identity without your consent?

      --
      --------
      * Sigh *
    3. Re:Consumer tracking? by mwa · · Score: 1
      With a credit card, I hold my tastes, wants and desires; all information relevant to the process of negotiation; back until I am ready to buy. This lets me look around for what I want. With Passport, the minute I click in, I'm attacked with what the vendor thinks I want which is almost always wrong. (Like quorum.org's "relevancy" thingie is always wrong for me.)


      Plus there's a good chance they've got an idea about how much I might be willing to spend. Ever shop on-line for an airline ticket? I shopped for prices, decided what I wanted and went back to it to find the price went up. Huh? It was less than 5 minutes ago! Found a cookie from the airline, deleted it, and the price dropped back down. With a CC, the price is set before they know who I am, where I've been, or how I'm going to pay. All their tracking buys them is what kind of "special deals" to mail me so I can throw them away for them.

    4. Re:Consumer tracking? by Malcontent · · Score: 2

      It has to do with trust. Microsoft has a history of unethical and sleazy behavior. While Visa and mastercard also have had bouts with sleazy behavior it certainly has not been the same pathological degree.

      I for one would much rather trust Visa then MS about anything. If Bill gates offered to babysit my kids I'd refuse.

      --

      War is necrophilia.

    5. Re:Consumer tracking? by simong · · Score: 1

      I would contend that you don't have a choice if you choose to use MSN Messenger. It is, after all, a Microsoft product, as is Hotmail. I have no problem in Microsoft giving me a Passport account for using Microsoft services (such as I do). I would be more concerned if I had to use that account to, say, buy anything from Tesco or something.

    6. Re:Consumer tracking? by sheldon · · Score: 2

      Yes, but that's because you are ignorant.

      USBank, Mellon Bank... Heard of them?

      Heard of GLB law?

  30. Gator by CarterUSM · · Score: 1

    Maybe I'm missing the point, but hasn't Gator been doing this for years? I'm not sure about it's backend and whether it encrypts your data or not, but it keeps your information on your computer and fills in forms semi-automagically. Despite it's reputation as spyware I know a lot of people who use it to simplify their online lives.

    --
    perl -le 's;;uoli;;$a=length;y;g-w;e-u;;$a--;s;j;$a;;print'
  31. Re:Privacy? the real threat by jacoplane · · Score: 1

    We must absolutely protect our privacy, as it will come increasingly under attack. The war on terrorism will (in my opinion) never be won, and every time there is an attack, privacy will slip away more and more.

    Ohh, and why the heck aren't there security guards on aeroplanes?

  32. The problem with agents.... by deranged+unix+nut · · Score: 2, Interesting

    ...is that they run on hostile computer systems.

    How can you make code that securely holds data, can unlock that data, can not be altered, and runs on systems that you do not control?

    Sooo, which is worse, MS holding data about you on the terms that they won't do anything with it without your permission, or a piece of code running on hostile systems in every corporation that holds more data about you?

    1. Re:The problem with agents.... by OttoM · · Score: 1

      An agent can very well use remote messaging to communicate. That way, you have the advantage of an agent managing your profile and exercising your policy, without the risks of travelling to a unknown host. Of course, host authentication can solve this problem, allowing save travelling.

      My employer Tryllian makes an agent platform that solves a lot of these issues.

  33. "Nothing's Perfect" by Tony · · Score: 1

    Nothing's perfect, but some things are more perfect than others. Passport is not perfect in many ways-- security, the group that controls it, single-point-of-failure concerns, scaling concerns, etc.

    *I* want to manage my own personal data; it should be up to *me* to handle it. There is no reason a public-key system shouldn't work in a peer fashion for single-login authentication. Security would still be a problem, but a security breach means only one person has to deal with it. An *individual* should be responsible for maintaining their own identity, just as they are responsible for maintaining their own wallet or house.

    Just my views on this, but I think a combination would work well-- by default, a person can manage their own data, but proxy sites can be set up to manage it for them, like passport does currently.

    --
    Microsoft is to software what Budweiser is to beer.
    1. Re:"Nothing's Perfect" by Anonymous Coward · · Score: 0

      Nobody is trying to take away your ability to provide your own authentication and security, but these anti-MS zealots are trying to take away others' ability to use Passport.

      I don't even use it, but the constant MS bashing here is just silly sometimes....

  34. Something in between... by no_opinion · · Score: 1

    Another alternative is network based peered agent services that are operated by third parties on the behalf of consumers. This would be similar to having someone run your personal agent for you, or being able to choose between a bunch of different passport service operators. This eliminates the operations burden on end users who are then able to use the trusted third party of their choice to host their information. Access to the information would still be governed based on rules defined by the end user.

    -n

  35. Evilness by Tony · · Score: 1

    Short and simple: Microsoft is evil and untrustworthy.

    Unlike Visa or Mastercard.


    Oh, both Visa and Mastercard are evil-- but they already own the financial world. This is just Microsoft's attempt to take over the financial world.

    They need a source of recurring cash flow, which Visa and MC already have.

    --
    Microsoft is to software what Budweiser is to beer.
  36. Bullets and Airplanes BAD by Anonymous Coward · · Score: 0

    This seems like a good idea until you think of what would happen. I believe (correct me if I am wrong) that most handgun and nearly all rifle rounds would puncture holes in the cabin if they missed or went clean through their target. That means depressurization and death for all occupants. While I all for arming the public, this might be one of those few places projectile weapons should not be allowed. If everyone were carrying knives, however, that would be a good defense.

  37. I need to stop coding right now... by __aahlyu4518 · · Score: 1

    I need to get some sleep...

    I read something about a Microsoft agents' personal privates...

    Now my stomach is really upset... :-b

  38. Interesting approach by sfe_software · · Score: 4, Insightful

    I personally hate Passport. However, if a centralized system were done *correctly*, there are a couple of advantages.

    You can use it from any PC. A "wallet" system is just too complicated for most users (it can be transported, but most users won't bother). Plus, if I'm not mistaken, Passport would work from any browser. Wallet systems (which I believe IE and Mozilla both have an implementation) work only on that browser, and on that PC unless you export.

    On top of that, the Passport system is more automatic; get a Hotmail account and you have a Passport account. Use one of the participating online retailers and you have a passport account.

    OTOH, if a "wallet" system were implemented that was cross-browser (if not cross-platform), and more easily transportable, maybe it would catch on. I would trust my data on my own machine long before I'd trust it on a bunch of NT boxes up in Redmond (or wherever)...

    In either case, personally I prefer to judge everything on a site-by-site basis. I often use a different email address for each site, partly so I can track originators of SPAM lists and such... so neither method would work for me.

    Also keep in mind that, if you use a "wallet" system and use the same information at each site, this information could just as easily be shared between sites, and compared/compiled to track your usage, though admittedly it would be more difficult/less likely than a centralized system.

    --
    NGWave - Fast Sound Editor for Windows
    1. Re:Interesting approach by pointym5 · · Score: 1
      Passport would work from any browser


      For now, maybe (and I do mean maybe), but can you honestly believe that Microsoft isn't working on a suite of Passport-related ActiveX plugins (or .Net or whatever) that work on any browser so long as it's an IE version running on a Windows platform? Or an IE release that has native support for HTML extensions needed to effectively use Passport?

    2. Re:Interesting approach by John+Zero · · Score: 1

      "Plus, if I'm not mistaken, Passport would work from any browser."

      Try using Mozilla 0.9.4/Linux for registering at passport.com!

      When you click on "register", it will say "Unsupported browser, need at least IE 4.0+ or Netscape Navigator 4.08+" and won't let you register.

      (translated from Hungarian, although I'd rather see this message in English, it would be easier to copy that here)

    3. Re:Interesting approach by sfe_software · · Score: 2

      I'll admit that I don't know much about how Passport works, but I was under the impression that it was a simple cookie-based system, coupled with a redirection through the Passport site for authentication. I thought they really did intend it to be cross-platform, if only due to "internet appliances" and public kiosks that may not be IE...

      I think Microsoft will (or has) probably weigh the benefits of making it IE specific versus the benefits of making it cross-platform. In this case, even MS sees that people will be more apt to use it if they know they can get there using their iPaq or whatever.

      --
      NGWave - Fast Sound Editor for Windows
    4. Re:Interesting approach by sfe_software · · Score: 2

      Oddly enough, Mozilly 0.9.4 is my main browser; I don't have access to an IE machine, and I don't keep the older Netscape around any more.

      Maybe, just to get some better insight on all of this, I'll try to register using either Mozilla or Konqueror (with which I can fake the User-Agent if necessary) out of curiosity. Maybe I was wrong on that (I explained my thinking in a different reply above)...

      --
      NGWave - Fast Sound Editor for Windows
    5. Re:Interesting approach by simong · · Score: 1

      But Passport is a Microsoft product and IE is a Microsoft product. iPaqs are PocketPCs, which as everyone knows, run WindowsCE, which is a Microsoft product. It's not in Microsoft's interest to make Passport cross-platform.

    6. Re:Interesting approach by sfe_software · · Score: 2

      iPaqs are PocketPCs, which as everyone knows, run WindowsCE...

      Oops - I got the name mixed up. What was the Linux-powered net appliance thing Compaq had a while back? I remember seeing one at CompUSA about a year ago or so... anyway, my point was that there are (and will be more) non-MS appliances for accessing the internet.

      --
      NGWave - Fast Sound Editor for Windows
  39. Have your agent hold your Passport by Broadcatch · · Score: 2, Interesting

    At OpenPrivacy, we are building a framework to separate who you are from what you do, so that you can contract with an agent (via a pseudonymous nym, so even the agent doesn't know who you are) to act as your "book recommender." This agent could be loaded with not only the books you're bought from Amazon, but also relevant magazine subscription, web sites, and, of course, books bought from other sources online or in meatspace. This agent would present this info to Amazon - perhaps via a Passport - as representing person X (or a demographic segment of size Y with Z tastes). After Amazon makes its recommendations and this information is returned to the user via an onion-routed delivery path, the user could go to Amazon and buy what they want. Or somewhere else, if Amazon won't play unless you have a Passport, which I doubt will happen.

    --

    The antidote for misuse of freedom of speech is more freedom of speech.
    -- Molly Ivins

  40. Re:Bullets and Airplanes GOOD by Anonymous Coward · · Score: 0

    Decompression doesn't result in the deaths of all occupance and it is preferable to running into the ground, hitting the ground, or exploding mid flight. Certainly there should be arms on planes. We have seen the results of them flying without arms. The real question is whether you trust the common citizen or you believe that some elite should protect them. Personally, I believe in the common citizen.

  41. Here's a solution by IronClad · · Score: 1
    Disclaimer: I work for this company.


    Great question! We've been working on this solution for a year, and plan to go alpha this month. Basically, it's a privacy firewall and service platform that allows an ISP or other provider (whom you already trust and typically already knows all about you) to customize the content or services you get without your personal info flying all over the net. A sandbox approach even allows content providers to provide customization and policies for it.


    http://www.netdestinysystems.com

  42. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  43. Legal Issues by David99 · · Score: 1
    Some of the stuff that goes on in the US is illegal in many other countries. Collection of data without a persons knowledge, use of collected data for purposes other than the specified use, matching of different personal database - these are all illegal.



    Unless the US shapes up it's privacy practices, a lot of US outfits will find themselves involved in foreign lawsuits.

    --
    -- Welcome to nowhere fast / nothing here ever lasts.
  44. My website doesn't accept passport... by bergeron76 · · Score: 1

    Our company has a notice up that specifically rejects passport users and directs them to a link that demonstrates the security flaws in it. The link is below on the info page for those intersted.

    --
    Don't think that a small group of dedicated individuals can't change the world. It's the only thing that ever has.
  45. Re:Mozilla has this feature - sortof by bLanark · · Score: 1
    What is really needed is someone to release a standard for form field naming (i.e. name_first) then when confronted with a form you can select to fill all recognized form fields from an encrypted password protected database kept on your computer.

    What's the point in encrypting your name? Or address? The only useful stuff to keep encrypted would be passwords to web sites. Possibly credit card numbers, if you're paranoid. Remember that to be really secure you'd have to protect this stash with a long and secure passphrase. If you worked in an office, you should not cache this passphrase, so you type it in each time. Is it really worthwhile?

    Having a standard name for the fields and auto-fill is a good idea, but it will never happen in reality. Can you really see all an Italian web sites having visitor-book scripts with labels in english? A web site may start out as local but end up as global. I'm sure many do.

    Opera has auto-completion of name, address, etc which I have found to be useful. I never put my email address in any app such as a newsreader or a browser, btw.

    bLanark
    Standards are great! There are so many to choose from!

    --
    Note to ACs: I won't mod you up, even if you are being funny or insightful. So take a chance! It's not real life!
  46. Passport takes the money and runs by OttoM · · Score: 2, Insightful
    A centralized storage "solution" for sensitive information cannot work. Compare it to a bank: while in general we can trust banks, it still happens that bank employees take the money and run.

    A personal agent can store your profile data, and have an active implementation of your policy, possibly performing interaction with the owner.

    The advantages are clear:

    • everybody can create their own agents to represent them, putting the responsability where it belongs,
    • no update problems,
    • no single party that everyone must trust.
    • No centralized storage of sensitive information.
    • Depending on the type of application the agent can move to the host or do its work remotely using messaging.

    <SHAMELESS PLUG>
    My employer Tryllian sells a platform that from the start was designed to deal with these issues.
    </SHAMELESS PLUG>

  47. To make a long answer short; Yes, people are really that lazy.

    I need a detailed answer, what's up with this lazy-ass 12-word answer? 8^

    Six of that, half dozen of the other.
  48. Re:Bullets and Airplanes GOOD by larien · · Score: 1

    Personally, I don't trust the common citizen as far as I could throw an aeroplane. These are the same people that voted Dubya in, after all.

  49. A simple open solution? by magi · · Score: 2

    I guess it would be rather easy to define an open and distributed authentication protocol that uses open encryption algorithms and protocols. Just use PGP/GPG or even SSH as the basis for the protocol.

    I guess there might already be such software?

    You could hold your "PassPouch" on a single client machine, but you could add a possibility to give a "PassPouch" to a centralized server. Then use a trivial negotiation. I guess it wouldn't take too many days (hours?) to implement a simple prototype.

    Or use public key crypto the way PGP or SSH does, and simply give a public key to the sites that need authentication, and implement a trivial negotiation.

    I guess the biggest problem is finding trusted servers for storing the pass pouches. The servers can also be hacked easily, in which case someone could steal your passpouch (which is useless without a password though) and then sniff your password. I think there might be some cryptographic solutions for this. In some earlier Slashdot article someone mentioned that computing in a hostile environment might be possible with some cryptographic solution. It might then be possible to run the authentication code in a secure virtual computer.

    You could also have a number of different pouches for different tasks, if you want to have more security.

    IANACE.

  50. Passport - Seizing the straits by Anonymous Coward · · Score: 0

    Edward Jung, former Microsoft bigwig, gave the keynote address at the Global Grid Forum in July. He explained quite enthusiastically that the key to success was to identify "hourglass configurations" [he never said "bottlenecks"], and that Passport [authentication services] was the key to Microsoft's strategy; as one operating system for the desktop drove the economics of the past two decades, so one global authentication service will drive the economics of pervasive computing.

    The challenge presented is very clear. There's no reason that there should be only one authentication service, without others working together. But if you want to read his slides, you will need to use IE.

  51. So what does your company accept ? by Anonymous Coward · · Score: 0

    Other than a rant against Passport there is no info on what types of payments your company accepts.

    Can I write you a personal check ? A merchant that accepts that for payment may not find out for up to a week whether the check is good due to the antiquated clearing system our banks use.

    My Visa card with the chip gets docked in the smart card reader on my pc. I enter my PIN number and this opened a 30 second window for a secure transaction at Amazon. At least the merchant can match the account opened, originating location of pc, and PIN entered for the card to authenticate the transaction.

  52. Slashdot Crowd == RIAA by Space+Cow · · Score: 1

    Ok, not quite but the similarities are there.

    The Slashdot crowd wants to PROTECT valuable personal information that they LOSE almost all control over once they SELL (usually for extra services) them to a commercial entity .

    The RIAA wants to PROTECT valuable songs that they LOSE almost all control over once they SELL them Joe Blow.

    Both are looking at technology to solve a problem that is (as the movie and music industries have demonstrated) better solved through force of law.

  53. Re:Mozilla has this feature - sortof by Anonymous Coward · · Score: 0

    O.k. so I maybe ingnorant but isn't html english based?

  54. Privacy? by Anonymous Coward · · Score: 0

    Trade Security for freedom? Wasn't it Ben Franklin who said you will end up with neither?

    Do you really want a big brother world? The drug siezure laws seem like a really great idea until your kid throws a rock trhough a window in school and the government siezes your house without due process. Once you open the door and let them in, you can't get them out.

    Germany in the 30's had some reforms that seemed OK at the time, but one thing let to another and another and somehow the atrocities were normal at the time.

    For years airport security has been interested in stopping guns and busting a young person with a joint in a knapsack. Profiling terrorists? Then the CIA and the FBI and the ATF (and all of the other alpahbet agenties) might have to talk to each other! What if they were accountable? If someone is determined to do something, and they have time and money, they probably can. How many guns were used on the hijackings? They probably cut up a stewardess or 2 to get access to the flight crew, and then it was all over. Remember the word terror is in the word terrorist. Afraid to fly, the drive. Only 250 people were likked this year on airline flights, but 30,000 have been killed in cars, so whats safer?

    Terrorists (and opressive governments) rely on clueless sheep, so hunker down and hope some one else will do something. That's what THEY are ounting on.