DIM 2007
ACM CCS2007
Workshop on
Digital Identity Management
Discucssion Minutes
November 2, 2007, George Mason University, Fairfax, VA, USA
“Usability Issues for Identity Management”
16:00-17:00 Discussion: What are Usability Issues for
Identity Management?
Session Chair: Atsuhiro Goto (NTT)
- Security protocols not intuitively understood by users
- It is difficult for users to understand technical terms, e.g. SAML.
- Reuse of network authentication for “seamless” service usage
- Identities in the real world can be kept / delegated / trusted / linked.
Online identities need to mirror this.
- Dubious behaviors can be detected easily in the real world, but not in cyber space.
- Delegation example: Ask a secretary to do something.
- How to leverage existing devices such as mobile phones.
- Humans lack the ability to discern between that which is to be trusted
and that which is worthy of suspicious; from the Trojan war to modern phishing
attacks, humans have shown a tendency to misevaluate trustworthy.
- Users to machines is not 1-to-1
- One to many, many to one, many to many
- CardSpace is powerful. But how to use it in mobile phone?
- As a company that stores identities, how do you protect the
identities from being lost/ made public/ tampered with.
- There are some regulations, e.g. SOX.
- Trust mark, privacy mark on Web sites.
- Legal / liability issues around identity/ delegation / reputation provider
- Too much depend on the computer security but not visible? need to make what
is uptake aware/visible
- Delivery path? how research ideas can be used in practice.
Via standardization? Open source? Any other alternatives?
- 10 years from now
- Identity information, reputation information -> bocome more important
- Loosely coupled identities that can be used in different applications/services/systems
- Many smart cards merged into one
- Users have stronger control over identities, expressing intention rather than giving attention
- Everyone recognizes the importance of identitiy.