<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><!-- generator="wordpress/2.2" --><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">

<channel>
	<title>Identity, Security &amp; Me</title>
	<link>http://blog.pdtoal.com</link>
	<description>My thoughts on just about anything</description>
	<pubDate>Sun, 26 Oct 2008 22:50:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/IdentitySecurityMe" type="application/rss+xml" /><item>
		<title>Is the Olympics necessary?</title>
		<link>http://blog.pdtoal.com/2008/10/26/is-the-olympics-necessary/</link>
		<comments>http://blog.pdtoal.com/2008/10/26/is-the-olympics-necessary/#comments</comments>
		<pubDate>Sun, 26 Oct 2008 22:50:19 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Politics]]></category>

		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/10/26/is-the-olympics-necessary/</guid>
		<description><![CDATA[In the current global economic crisis, it is really prudent to spend £9.2bn on the 2012 London Olympics. I&#8217;m sure the money could be put to better use&#8230;..
                            [...]]]></description>
			<content:encoded><![CDATA[<p>In the current global economic crisis, it is really prudent to spend £9.2bn on the 2012 London Olympics. I&#8217;m sure the money could be put to better use&#8230;..</p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/10/26/is-the-olympics-necessary/feed/</wfw:commentRss>
		</item>
		<item>
		<title>My First YouTube Post</title>
		<link>http://blog.pdtoal.com/2008/10/13/my-first-youtube-post/</link>
		<comments>http://blog.pdtoal.com/2008/10/13/my-first-youtube-post/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 22:08:03 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/10/13/my-first-youtube-post/</guid>
		<description><![CDATA[I&#8217;ve decided to start posting videos to YouTube. Therefore, if you want a laugh at my poor attempt at Beethoven, please see here.
                                 [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve decided to start posting videos to YouTube. Therefore, if you want a laugh at my poor attempt at Beethoven, please see <a href="http://www.youtube.com/watch?v=fl-nKuW0n5g">here</a>.</p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/10/13/my-first-youtube-post/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is ALL water a wishing well?</title>
		<link>http://blog.pdtoal.com/2008/08/30/is-all-water-a-wishing-well/</link>
		<comments>http://blog.pdtoal.com/2008/08/30/is-all-water-a-wishing-well/#comments</comments>
		<pubDate>Sat, 30 Aug 2008 22:22:47 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Funny]]></category>

		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/08/30/is-all-water-a-wishing-well/</guid>
		<description><![CDATA[I have this theory which seems to bear out no matter where I travel to in the UK&#8230;..
When I was a child I used to throw pennies into wishing wells and make a wish. As I grew up I noticed the security protecting the coins getting stronger (however, I digress).
What I have noticed now for [...]]]></description>
			<content:encoded><![CDATA[<p>I have this theory which seems to bear out no matter where I travel to in the UK&#8230;..</p>
<p>When I was a child I used to throw pennies into wishing wells and make a wish. As I grew up I noticed the security protecting the coins getting stronger (however, I digress).</p>
<p>What I have noticed now for a number of years is that any expanse of water contained in a public place becomes a public wishing well. You may notice that all of these places have coins thrown into them. These include water features in shopping centres as well as water fountains outside.</p>
<p>What happened to the good old wishing well and why do people find an urge to thrown money anywhere where there is water?</p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/08/30/is-all-water-a-wishing-well/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Date of Birth on Facebook</title>
		<link>http://blog.pdtoal.com/2008/08/30/date-of-birth-on-facebook/</link>
		<comments>http://blog.pdtoal.com/2008/08/30/date-of-birth-on-facebook/#comments</comments>
		<pubDate>Sat, 30 Aug 2008 22:18:52 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/08/30/date-of-birth-on-facebook/</guid>
		<description><![CDATA[It still amazes me that so many of my friends are displaying their date of birth on their public facebook profile. 
Don&#8217;t they realise how useful this is to potential Identity thief?
                        [...]]]></description>
			<content:encoded><![CDATA[<p>It still amazes me that so many of my friends are displaying their date of birth on their public facebook profile. </p>
<p>Don&#8217;t they realise how useful this is to potential Identity thief?</p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/08/30/date-of-birth-on-facebook/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Identity Fraud has finally happened to me</title>
		<link>http://blog.pdtoal.com/2008/08/30/identity-fraud-has-finally-happened-to-me/</link>
		<comments>http://blog.pdtoal.com/2008/08/30/identity-fraud-has-finally-happened-to-me/#comments</comments>
		<pubDate>Sat, 30 Aug 2008 22:17:35 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/08/30/identity-fraud-has-finally-happened-to-me/</guid>
		<description><![CDATA[Well its finally happened to me. 
After been very careful with my credit card details over the years, last week I finally fell victim to Identity Fraud. Yes, whilst checking my credit card transactions online, I noticed a airline ticket that I certainly didn&#8217;t buy. A call to my credit card company revealed two further [...]]]></description>
			<content:encoded><![CDATA[<p>Well its finally happened to me. </p>
<p>After been very careful with my credit card details over the years, last week I finally fell victim to Identity Fraud. Yes, whilst checking my credit card transactions online, I noticed a airline ticket that I certainly didn&#8217;t buy. A call to my credit card company revealed two further airline transactions that had not yet been posted onto my statement.</p>
<p>Within one day, 3 separate airline tickets had been bought on my card. Fortunately, the bank had noticed something suspicious and put a stop on my card. Of course, i&#8217;m fully covered by my credit card company. However, I can&#8217;t help thinking now whether my stolen details were a result of something careless I have done or whether it was a problem over which I had no control (i.e. insider fraud). Still, irrespective of which it is, I will be ever more vigilant when my replacement card arrives.</p>
<p></p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/08/30/identity-fraud-has-finally-happened-to-me/feed/</wfw:commentRss>
		</item>
		<item>
		<title>iPod Graveyard</title>
		<link>http://blog.pdtoal.com/2008/06/23/ipod-graveyard/</link>
		<comments>http://blog.pdtoal.com/2008/06/23/ipod-graveyard/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 21:00:53 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/06/23/ipod-graveyard/</guid>
		<description><![CDATA[Where have all the original iPods gone?
I have an 4GB iPod Mini. Its not that old and it serves my purpose. However, I seem to be the only person on the planet that has a pre-video iPod. What has happened to all of the people who bought older iPods. Do they just throw them away [...]]]></description>
			<content:encoded><![CDATA[<p>Where have all the original iPods gone?</p>
<p>I have an 4GB iPod Mini. Its not that old and it serves my purpose. However, I seem to be the only person on the planet that has a pre-video iPod. What has happened to all of the people who bought older iPods. Do they just throw them away and buy new ones or is there some sort of iPod graveyard that they send them to?</p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/06/23/ipod-graveyard/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Strange Acquisitions</title>
		<link>http://blog.pdtoal.com/2008/04/11/strange-acquisitions/</link>
		<comments>http://blog.pdtoal.com/2008/04/11/strange-acquisitions/#comments</comments>
		<pubDate>Fri, 11 Apr 2008 10:40:24 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/04/11/strange-acquisitions/</guid>
		<description><![CDATA[There are some acquisitions within the Identity space that come as no surprise. For example, when Sun acquired Vaau as a knee-jerk reaction to Oracle&#8217;s acquisition of BridgeStream (sorry, I had to get that jibe in), it came as no surprise. Equally, as the other independent role management vendors get bought up, that will be [...]]]></description>
			<content:encoded><![CDATA[<p>There are some acquisitions within the Identity space that come as no surprise. For example, when Sun acquired Vaau as a knee-jerk reaction to Oracle&#8217;s acquisition of BridgeStream (sorry, I had to get that jibe in), it came as no surprise. Equally, as the other independent role management vendors get bought up, that will be expected also. The only slight surprises may come from who buys who.</p>
<p>However, every now and again a complete left field acquisition shocks the industry. This occurred at RSA with Hitachi announcing it had bought a major share in M-Tech. Everyone seems to be talking about it. <a href="http://feeds.feedburner.com/%7Er/bgidps/indexrdf/%7E3/267349545/hitachi-who-kne.html">Burton</a>, <a href="http://feeds.feedburner.com/%7Er/csoblogs/blog/25/feed/%7E3/266294848/the_acquisitions_continue">Digital ID World</a>, <a href="http://vquill.com/2008/04/another-one-bites-dust.html">Dave Kearns</a>, <a href="http://www.schneier.com/blog/archives/2007/08/another_biometr.html">Bruce Schneier</a> etc.</p>
<p>What next, Amstrad buying Courion? <img src='http://blog.pdtoal.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/04/11/strange-acquisitions/feed/</wfw:commentRss>
		</item>
		<item>
		<title>iPlayer on Wii</title>
		<link>http://blog.pdtoal.com/2008/04/10/iplayer-on-wii/</link>
		<comments>http://blog.pdtoal.com/2008/04/10/iplayer-on-wii/#comments</comments>
		<pubDate>Thu, 10 Apr 2008 10:24:24 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/04/10/iplayer-on-wii/</guid>
		<description><![CDATA[Yesterday, the BBC announced the their iPlayer can now be run on the Wii through the use of the Internet Channel and that they even hope to provide a separate channel to remove the dependancy on the Opera browser.
I had to try it. How cool!!
           [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, the BBC <a href="http://www.bbc.co.uk/blogs/bbcinternet/2008/04/bbc_iplayer_on_wii.html">announced </a>the their iPlayer can now be run on the Wii through the use of the Internet Channel and that they even hope to provide a separate channel to remove the dependancy on the Opera browser.</p>
<p>I had to try it. How cool!!</p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/04/10/iplayer-on-wii/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Social Networks galore!!</title>
		<link>http://blog.pdtoal.com/2008/04/05/social-networks-galore/</link>
		<comments>http://blog.pdtoal.com/2008/04/05/social-networks-galore/#comments</comments>
		<pubDate>Sat, 05 Apr 2008 22:41:02 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/04/05/social-networks-galore/</guid>
		<description><![CDATA[I&#8217;m sure like me you are constantly getting invitations to the myriad of different social networking/web 2.0 sites out there. Personally, I have accounts on:
FacebookLinkedInMySpaceNaymzPlaxoDel.icio.usClaimIDTechnoratiand i&#8217;m sure there are others&#8230;&#8230;
I don&#8217;t have the time to keep all of these up to date, never mind joining any more.
Looking specifically at the number of social networks out [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m sure like me you are constantly getting invitations to the myriad of different social networking/web 2.0 sites out there. Personally, I have accounts on:</p>
<p>Facebook<br />LinkedIn<br />MySpace<br />Naymz<br />Plaxo<br />Del.icio.us<br />ClaimID<br />Technorati<br />and i&#8217;m sure there are others&#8230;&#8230;</p>
<p>I don&#8217;t have the time to keep all of these up to date, never mind joining any more.</p>
<p>Looking specifically at the number of social networks out there, surely there has to be a point when these must start to consolidate their functionality. I can see it has already starting happening to a certain extent. </p>
<p>LinkedIn is designed for business relationships. Plaxo extends that so you can categorise people as either business or friends. Similarly, LinkedIn allows you to write an endorsement for someone, whereas, Naymz whole philosophy is based on reputation and references.</p>
<p>I don&#8217;t see how all of these sites can be sustainable as we move further into 2008.</p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/04/05/social-networks-galore/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OpenID in the Enterprise</title>
		<link>http://blog.pdtoal.com/2008/04/05/openid-in-the-enterprise/</link>
		<comments>http://blog.pdtoal.com/2008/04/05/openid-in-the-enterprise/#comments</comments>
		<pubDate>Sat, 05 Apr 2008 22:30:32 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://blog.pdtoal.com/2008/04/05/openid-in-the-enterprise/</guid>
		<description><![CDATA[As always, I am constantly talking to new people about Identity Management in the Enterprise. We always talk about the usual topics; provisioning, authentication, authorisation, audit etc. More and more recently I have been asked by people what my thoughts are on OpenID. Previously, these types of discussions were limited to the hardcore ID people [...]]]></description>
			<content:encoded><![CDATA[<p>As always, I am constantly talking to new people about Identity Management in the Enterprise. We always talk about the usual topics; provisioning, authentication, authorisation, audit etc. More and more recently I have been asked by people what my thoughts are on OpenID. Previously, these types of discussions were limited to the hardcore ID people such as the <a href="http://wiki.idcommons.net/index.php/Identity_Gang">Identity Gang</a>. But now, I seem to be getting asked the question more and more by people within the Enterprise. A number of times it has been people who don&#8217;t really understand what OpenID is, other than its one of the &#8216;new terms&#8217;. Others are more informed.</p>
<p>So what do I think of OpenID and its application in the Enterprise&#8230;&#8230;</p>
<p>I think OpenID so far has done a lot for pushing forward Identity 2.0 and has seen a reasonable adoption within the &#8217;social internet&#8217; (blogs, wikis etc). There is definately a good use case for its application there. However, organisations have not yet really started to adopt this technology. There have been a couple, including <a href="http://www.sun.com/aboutsun/pr/2007-05/sunflash.20070507.4.xml">Sun </a>who announced an internal OpenID server for employees last year. However, in the main its uptake has been extremely limited.</p>
<p>I have no doubt that eventually OpenID will start to find a place within the Enterprise. However, at the moment, I really can&#8217;t see its application within the arena. The problem that I see Enterprises facing when looking at OpenID is the lack of trust in the Identity provider. Anyone can set up an OpenID server (indeed this blog is one) and use it to sign-on to OpenID enabled sites. However, where is the trust that I am indeed Paul Toal when I hit the target site. For enterprise, cross domain single sign-on, federation based on SAML (and the other standards) provides that pre-defined trust agreement. Clearly, what it lacks (and OpenID goes towards addressing) is the user consent. </p>
<p>As long as the trust issue is outstanding I don&#8217;t see why Enterprises would adopt OpenID for any transactions of any value (financial or otherwise). There is a big difference from posting a comment on a blog that I have signed onto with my OpenID Identity, to performing a business transaction with an Enterprise partner using my self-asserted OpenID. </p>
<p>The answer to this might be to ensure Enterprises host the OpenID server so that their partners can be assured of trust. However, isn&#8217;t that what standard federation today gives us. Do we actually want our employees deciding whether, as an employee their Identity information can or can&#8217;t be shared with other business partners? </p>
<p>Maybe I am missing the point (feel free to correct me), but at the moment, I just don&#8217;t see where OpenID fits within the Enterprise.</p>
<p>Technorati Tags: <a class="performancingtags" href="http://technorati.com/tag/OpenID" rel="tag">OpenID</a>, <a class="performancingtags" href="http://technorati.com/tag/federation" rel="tag">federation</a>, <a class="performancingtags" href="http://technorati.com/tag/enterprise" rel="tag">enterprise</a>, <a class="performancingtags" href="http://technorati.com/tag/trust" rel="tag">trust</a></p>
                                        <p><hr /><br><center>&copy; <href="http://www.pdtoal.com">Paul Toal</a> - The views and comments on this site are my own views only and not the views of my current or any previous employers. </center></p>                              ]]></content:encoded>
			<wfw:commentRss>http://blog.pdtoal.com/2008/04/05/openid-in-the-enterprise/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
