Liberty Alliance Releases Specifications
Darren.Moffat writes "Has the time come for Passport to move over ? Technical Specs of the Liberty Alliance Project technology are now available from the website and were officially announced at the Burton Group conference today." We've done stories on the Liberty Alliance and digital identity before.
Stolen identity doesn't exist? Care to tell that to the thousands of people each year that have their credit hijacked. It's amazing the stuff you can do with a SSN.
What makes this better than passport? Is it just that it doesn't have MS in front of it? Is it because it has the word "Liberty" in it? Both have words relaiting to freedom: Pass and Liberty. Both have little to do with freedom. Absoultue Annonominity or Full Disclosure must be present for freedom. If there is a monitoring agency that can restrict what it sees to itself, it is inherently flawed. It must fully disclose everything, to everyone... And that is non trivial... But probably worth pursuing. Untill then, We should not have a self accountable agency like these systems that base decisions on limited, selected for cheapness/support viewpoint information. I propose that everyone give everyone else their MS passport passwords etc... make copies of fingerprints and retnas etc, and distribute them freely (An idea similar to one that Richard Stallman has promoted)
Please use [ informative / summarizing ] SUBJECT LINES
Flame me here
I'm sure the companies are all money hungry, but somehow I don't think any of them would accept any of the others using Liberty Alliance as their own private data source. There's more than one degree of separation going on here.
Brilliant. Why not hang a neon sign out in front saying "Welcome crackers!" Diversity is a strength.
/.!
Say I have various accounts at 40 different firms. Say one is compromised. If I do things right (vary passwords, don't store appealing information like account numbers where it's not absolutely necessary), at least some of the other 39 are safe.
On the other hand, say LA or Passport is cracked. Suddenly, my electronic doppelganger is running up charges at CheapBytes and eBay and, worse yet, ruining my rep on
Why not a use random username/password generator, store the results as a file on your local machine, and encrypt it. I can even see storing that as a good use for one of those "USB-connected flash on a keychain" toys.
It's just like a fascist dictatorship, without the punctual rail service!