Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Five Easy Pieces of Online Identity (evhead.com)
38 points by hornokplease on April 8, 2011 | hide | past | favorite | 15 comments


His first three concepts already have names: authentication/authorization (he's conflated here), non-repudiability, and availability. The last two topics seem like applications and not properties of identity.

I think you could solve all of "2" - "5" given a workable solution for "1" --- that is to say, if everyone could agree on an Internetwide scalable authentication system, the other benefits of identity could be built organically around that kernel. But scalable authentication is a galactically complicated political problem involving virtually every single one of the largest technology companies in the world.


At the end of the post he did write "From a technical perspective, authentication defines who someone is and authorization defines what they have permission to do. However, I didn't find that terminology useful for my purposes here."


Was that there an hour ago? I'm surprised I missed it.


It was not there an hour ago - I would like to think that I was the impetus, as I saw it right when he posted and immediately replied: https://twitter.com/#!/andrewpbrett/status/56503853184598016


I have no idea but on at least one occasion someone changed what their article said after I remarked on it on HN. HN is pretty well known. I wouldn't be surprised if they updated it because of your remark, as appears to have happened once in a different article/blog because of a remark I made (thus making me look "dumb" at the time).


Actually, identity is who you are, and authentication is proving it.


Even with his clarification, I think the distinction does matter between authentication and authorization, because "who I am?" will result in different answers to "do I have permission?" depending on the context. Location, time, etc. all play a role: I can drink in the bar at 10pm, but maybe not at 2:01am after they close, and probably not in church.


OpenID and OAuth come to mind


OpenID kind of illustrates my point.

OAuth, on the other hand, isn't scalable Internet-wide authentication so much as a tool for doing delegated authentication.


I'd add a sixth component, something like "Which role do you want to play?" jerf-the-HN-participant partially exists to lead a life sharded from jerf-the-family-member or jerf-the-employee. The oil-and-water metaphor for those roles I have is particularly apt, in that it doesn't particularly take effort for me to keep them separate because they actively avoid mixing naturally on their own, but I can't use(/refuse to use) a system like Facebook that insists on mixing them anyhow. The ability of the Internet to facilitate this is an important aspect it has and I don't want to see us give it up.


"Every Internet service that has a concept of users has to deal with identity."

We have users and customers and we don't care who they are. Customers we care if their money is good.

The idea of validated internet identity for things outside of banking/finance and voting is a complete sham.

These companies screaming for identity know perfectly well they are lying to their customers. What they are really interested in is monitoring people and selling information about their habits to marketers.


If anyone is interested in this stuff, there is a classic presentation on this subject Dick Hardt did back in 2005 that really digs into a lot of these different aspects of identity (albeit from an Open Source perspective): http://www.identity20.com/media/OSCON2005/

It also happens to use the brilliant Lessig Style of presentation, which is always fun to watch.


The first thing I think of in reference to online "reputation" is forums.

Daniweb's a pretty good example - post count, up-vote count, solved threads and reputation points which determine a user's power to affect other people's reputations.


CRAPR?


Why does he write that in BOLD at the end?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: