the identity landscape · internet mail uucp bitnet mail x.400 fidonet. cc:mail banyan vines...

25
The Identity Landscape A place where Mad Max would feel right at home

Upload: others

Post on 06-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

The Identity LandscapeA place where Mad Max would feel right at home

Page 2: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Very few things happen at the right time, and the rest do not happen at all: The conscientious historian will correct these defects.

Mark Twain

Page 3: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

… once upon a time

Page 4: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

cc:MailBanyan VINESInternet MailUUCPBITNET MailX.400FidoNet

Page 5: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,
Page 6: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

cc:MailBanyan VINESInternet MailUUCPBITNET MailX.400FidoNet

Page 7: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Interoperability… the complete lack thereof

Page 8: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,
Page 9: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

No message was ever improved by a gateway

Page 10: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Internet Mail (RFC 822)

Page 11: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,
Page 12: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Email today...(...which mostly works btw)

● Works for both sunet.se, cisco.com and google.com

● Straight forward to operated for small domains

● Multiple interoperating implementations

Page 13: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Identity “architecture”

Page 14: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

You call that architecture?● Trust Management

○ X509, SAML Metadata, webfinger+HTTPS, WS-Trust

● Identity Claims and Assertions○ SAMLv1, SAMLv2, OpenID Connect,

OpenID 1, OpenID 2.0, WS-Federation, McGyvered-JOSE, CBOR/COSE, OAUTH, OAUTH-over-JOSE

● … and re-spin for IoT

Page 15: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Is OpenIDC the one?

Page 16: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Who Made OpenIDC?...Google, Facebook, Microsoft….

Page 17: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

… and also this guy!

Page 18: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Decisions are made by the folks who show up

Page 19: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Is OpenIDC The one?

Page 20: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Is OpenIDC The one?It depends...

Page 21: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

OpenIDC works when...

● You have a very small number of IdPs● You do “continuous deployment”

Page 22: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

What is missing?● Scalable trust management that doesn’t tie us to the Web PKI● “Sendmail” now (multiprotocol gateway) and then “Postfix” (simplification)● A trusted solution to the discovery problem (accountchooser?)● A way to make phishing much less attractive (FIDO?)

Page 23: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,
Page 24: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Whats next?● AL2 is becoming cheap

○ Vertical federations have to become either buyers clubs or provide AL3

● Passwords are (finally, maybe) not the only way to authenticate users○ If you’re not already integrating FIDO U2F/2.0 - start working on it

Page 25: The Identity Landscape · Internet Mail UUCP BITNET Mail X.400 FidoNet. cc:Mail Banyan VINES Internet Mail UUCP BITNET Mail X.400 FidoNet. ... WS-Federation, McGyvered-JOSE, CBOR/COSE,

Support your SDO

Decisions are made by the folks who show up.