[Wg-p3] Prep For Privacy Workshop in Washington DC - August 10

Robin Wilton futureidentity at fastmail.fm
Thu Aug 6 07:58:35 PDT 2009


On Thu, 06 Aug 2009 10:48 -0400, "Bob Pinheiro"
<kantara at bobpinheiro.com> wrote:

Brett McDowell wrote:

  I am seeing a few topics emerge from this discussion that I'll
  summarize:



- are all the major protocols properly represented, especially
regarding privacy features?

- should the Open Government initiative(s) require
better-than-passwords for any app collecting PII?

I think the question is, Should the Open Government initiatives
require better-than-password authentication of consumers/citizens
by Identity Providers when fraudulent access to certain eGov
applications could potentially cause "moderate" harm to the
consumer/citizen whose identity was "stolen?"  Are there such
eGov applications?  And if so, who is going to do the work to
help ensure that consumer/citizens have these credentials and
know how to use them, and that use of such credentials won't
cause the citizen's/consumer's privacy to be compromised?

Right - and I think this comes back to that 'framing' question of
whether anyone has produced the 'mapping' of

credentials -> levels of assurance -> services requested

I think you're right that there's a class of applications where
the possible harm is assessed as "moderate" and the appropriate
level of assurance is probably higher than what is currently
envisaged; I also think there are questions about what kind of
authentication (or anonymity/pseudonymity) is appropriate for
what one might term "zero-value" online services, and indeed
whether those justify the collection of any PII whatsoever.

Looking forward to discussion of this. Am going to open up the
conf call line now. Reminder of the dial-in details:

7-Digit Access Code 9247530 (public)
Toll Free Access Phone Number: 1.866.305.1460 (USA and Canada)
Direct Dial Access Phone Number: +1.416.620.1296

US: 1 866 305 1460
Canada: 1 866 305 1460
UK: 08009175847
Netherlands: 08002659007
Belgium: 080079491
Japan: 00531160345
Robin Wilton

Director, Future Identity
Director of Privacy and Public Policy, Liberty Alliance


www.futureidentity.eu
+44 (0)705 005 2931
====================================================================
Structured consulting on digital identity, privacy and public policy
====================================================================
Future Identity is a limited company number 6777002, registered in England & Wales

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://kantarainitiative.org/pipermail/wg-p3_kantarainitiative.org/attachments/20090806/33d8dbca/attachment.html>


More information about the Wg-p3 mailing list