<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Research on Identity Management (by Marco Casassa Mont) - All Comments</title><link>http://www.communities.hp.com/online/blogs/mcm/default.aspx</link><description>Marco Casassa Mont’s “Research on Identity Management” Blog. The focus of this blog is on trends, new technologies/solutions and innovative aspects of Identity Management - in a variety of contexts. I am a researcher at HP Labs: I am very keen to explore and discuss technical and social aspects of Identity Management that are going to affect individuals, enterprises and other organizations in the medium/long terms. What is the next big thing in this space?
</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><item><title>re: Firefox and 50 add-ons for Private and Secure Web Surfing</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/03/firefox-and-50-add-ons-for-private-and-secure-web-surfing.aspx#84165</link><pubDate>Wed, 06 Aug 2008 14:43:54 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84165</guid><dc:creator>marcocasassamont</dc:creator><description>&lt;p&gt;Indeed. This is a good way to get more information about these addons.&lt;/p&gt;
&lt;p&gt;In addition to this, I thought that the audience of this blog might also be interested in &amp;quot;first-hands&amp;quot; views of any of these add-ons (by other readers of this blog) - in particular in understanding if any of them have been really effective in handling some of common (web-based) security and privacy issues. &lt;/p&gt;
&lt;p&gt;All these comments are anyway already going in that direction. Thanks. Marco&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84165" width="1" height="1"&gt;</description></item><item><title>re: Firefox and 50 add-ons for Private and Secure Web Surfing</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/03/firefox-and-50-add-ons-for-private-and-secure-web-surfing.aspx#84163</link><pubDate>Wed, 06 Aug 2008 14:17:39 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84163</guid><dc:creator>Anonymous-HPBLOGCS</dc:creator><description>&lt;p&gt;one additional point i neglected ... if you go to the aforementioned article and click on each listed add-on, you&amp;#39;ll be taken to a Mozilla page describing the add-on ... and each one usually has a set of commentary associated with it. &amp;nbsp;comments tend to be quite insightful.&lt;/p&gt;
&lt;p&gt;best of luck, &amp;nbsp; -b&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84163" width="1" height="1"&gt;</description></item><item><title>re: Firefox and 50 add-ons for Private and Secure Web Surfing</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/03/firefox-and-50-add-ons-for-private-and-secure-web-surfing.aspx#84160</link><pubDate>Wed, 06 Aug 2008 13:38:45 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84160</guid><dc:creator>marcocasassamont</dc:creator><description>&lt;p&gt;Thanks! Good points. Marco&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84160" width="1" height="1"&gt;</description></item><item><title>re: Firefox and 50 add-ons for Private and Secure Web Surfing</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/03/firefox-and-50-add-ons-for-private-and-secure-web-surfing.aspx#84157</link><pubDate>Wed, 06 Aug 2008 12:55:10 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84157</guid><dc:creator>bschafer</dc:creator><description>&lt;p&gt;haven&amp;#39;t read the article, but have used FF for years, and it&amp;#39;s an excellent browser. &amp;nbsp;if you care about security, the 3 most useful (to me, anyway) add-ons are:&lt;/p&gt;
&lt;p&gt; &amp;nbsp; NoScript&lt;/p&gt;
&lt;p&gt; &amp;nbsp; Adblock-Plus&lt;/p&gt;
&lt;p&gt; &amp;nbsp; CookieSafe&lt;/p&gt;
&lt;p&gt;recommend you download and play - you&amp;#39;ll learn more by doing this than any review could possibly provide.&lt;/p&gt;
&lt;p&gt;and for the myriad IE-only web sites at HP, IEview is pretty indispensable as well.&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84157" width="1" height="1"&gt;</description></item><item><title>re: Firefox and 50 add-ons for Private and Secure Web Surfing</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/03/firefox-and-50-add-ons-for-private-and-secure-web-surfing.aspx#84156</link><pubDate>Wed, 06 Aug 2008 12:46:03 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84156</guid><dc:creator>marcocasassamont</dc:creator><description>&lt;p&gt;What is good? &lt;/p&gt;
&lt;p&gt;Did you try any of the listed add-ons for Firefox? Do you have any recommendation to provide to this community on most privacy-effective add-ons?&lt;/p&gt;
&lt;p&gt;Marco&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84156" width="1" height="1"&gt;</description></item><item><title>re: Firefox and 50 add-ons for Private and Secure Web Surfing</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/03/firefox-and-50-add-ons-for-private-and-secure-web-surfing.aspx#84141</link><pubDate>Tue, 05 Aug 2008 15:21:02 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84141</guid><dc:creator>shawn</dc:creator><description>&lt;p&gt;it&amp;#39;s good&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84141" width="1" height="1"&gt;</description></item><item><title>re: Part III: Identity Analytics and Unstructured Data Analysis</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/25/part-iii-identity-analytics-and-unstructured-data-analysis.aspx#84012</link><pubDate>Fri, 25 Jul 2008 16:33:50 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84012</guid><dc:creator>marcocasassamont</dc:creator><description>&lt;p&gt;Hi. Thanks for your input! Marco&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84012" width="1" height="1"&gt;</description></item><item><title>re: Part III: Identity Analytics and Unstructured Data Analysis</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/25/part-iii-identity-analytics-and-unstructured-data-analysis.aspx#84010</link><pubDate>Fri, 25 Jul 2008 14:47:57 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84010</guid><dc:creator>Wainer</dc:creator><description>&lt;p&gt;This is quite interesting, especially in relation to other mechanisms that may help to ensure alignment between producers&amp;#39; intentions and analysts needs across contexts [such as declarations, counter-profiling and procedural frameworks, like the one discussed in one of your recent papers and implemented by Liberty Alliance].&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84010" width="1" height="1"&gt;</description></item><item><title>re: Survey: Only Eight Percent of American are “Very Confident” their Personal Data is Properly Managed</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/17/survey-only-eight-percent-of-american-are-very-confident-their-personal-data-is-properly-managed.aspx#83929</link><pubDate>Sun, 20 Jul 2008 12:19:18 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83929</guid><dc:creator>marcocasassamont</dc:creator><description>&lt;p&gt;Thanks for this link to your comments and thoughts on active directories.&lt;/p&gt;
&lt;p&gt;This is a good reality check about what is currently used in enterprises. The current adoption success of LDAP directories/virtual/meta directories &amp;nbsp;speaks on its own. I guess this is also the result of implicit or explicit assessment of their value, costs, practicality (e.g. integration with authentication processes) vs. involved risks.&lt;/p&gt;
&lt;p&gt;Based on my experience, I know that LDAP directories are currently primarely used (at least in large organisations) to store HR data (e.g. enterprise org charts) and to provide support for authentication. Some PII data is indeed stored in LDAP directories, even if traditional relational databases are still primarely used to store this kind of information. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Independently from this, some of the related threats and risks are still there, in particular in terms of unauthorised access to personal data, privacy violantions, data leakages. Some of the reasons for this is the (current) lack of adequate, privacy-aware access control.&lt;/p&gt;
&lt;p&gt;Part of my past R&amp;amp;D work has been focused to address these issues by means of technical approaches and solutions (e.g. see &lt;a rel="nofollow" target="_new" href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/PrivacyAwareAccessControl/PrivacyAwareAccessControl.htm"&gt;www.hpl.hp.com/.../PrivacyAwareAccessControl.htm&lt;/a&gt;) but we are still far away from having scalable and industrial solutions. &lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83929" width="1" height="1"&gt;</description></item><item><title>re: Survey: Only Eight Percent of American are “Very Confident” their Personal Data is Properly Managed</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/17/survey-only-eight-percent-of-american-are-very-confident-their-personal-data-is-properly-managed.aspx#83921</link><pubDate>Sat, 19 Jul 2008 11:59:14 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83921</guid><dc:creator>James</dc:creator><description>&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://duckdown.blogspot.com/2008/07/active-directory-20.html"&gt;duckdown.blogspot.com/.../active-directory-20.html&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83921" width="1" height="1"&gt;</description></item><item><title>re: Gartner’s Report: Top Seven Cloud-computing Security Risks</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/04/gartner-s-report-top-seven-cloud-computing-security-risks.aspx#83751</link><pubDate>Sat, 12 Jul 2008 17:24:13 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83751</guid><dc:creator>marcocasassamont</dc:creator><description>&lt;p&gt;I can't really understand what this comment is about!&lt;/p&gt;
&lt;p&gt;What is your point? Coudl you please add more details?&lt;/p&gt;
&lt;p&gt;Thanks. Marco&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83751" width="1" height="1"&gt;</description></item><item><title>re: The Future of Identity Management? It is all about Managing Risk …</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/29/the-future-of-identity-management-it-is-all-about-managing-risk.aspx#83750</link><pubDate>Sat, 12 Jul 2008 17:19:25 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83750</guid><dc:creator>marcocasassamont</dc:creator><description>&lt;p&gt;Hi Matt. &lt;/p&gt;
&lt;p&gt;Sorry for the delay to publish your comment. I just noticed it now (no notification from this blog platform ...).&lt;/p&gt;
&lt;p&gt;I can publicly say is that there is currently a trend drven by key decision makers (some of them are actually our customers) from a compliance driven approach to a risk-based approach.&lt;/p&gt;
&lt;p&gt;This is a process that wil ltake long time (5-10 years) so expect no immediate change of directions.&lt;/p&gt;
&lt;p&gt;Anyway, you are asking the right questions. &lt;/p&gt;
&lt;p&gt;Any input about this trend coming from other people operating in this area?&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83750" width="1" height="1"&gt;</description></item><item><title>host-proof hosting</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/04/gartner-s-report-top-seven-cloud-computing-security-risks.aspx#83602</link><pubDate>Fri, 04 Jul 2008 19:14:42 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83602</guid><dc:creator>transcyberia.info</dc:creator><description>&lt;p&gt;Think a minute about the security challenges involved in creating a health-centered social network. Or, more generally, any web application that has to handle sensitive user data. What if the database server becomes compromised? How do you make sure tha&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83602" width="1" height="1"&gt;</description></item><item><title>re: The Future of Identity Management? It is all about Managing Risk …</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/29/the-future-of-identity-management-it-is-all-about-managing-risk.aspx#83512</link><pubDate>Mon, 30 Jun 2008 13:48:14 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83512</guid><dc:creator>Matt Flynn</dc:creator><description>&lt;p&gt;I&amp;#39;ve also been saying this to some degree. As technology people, we want to ensure that our solutions align with core business goals. &amp;nbsp;But, I haven&amp;#39;t seen it resonate with customers in the field. &amp;nbsp;I&amp;#39;d be curious to hear from IdM consultants about what their customers are saying. &amp;nbsp;Is the move to Risk-Based approach actually happening? &amp;nbsp;Or is it something reserved for analysts and bloggers?&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83512" width="1" height="1"&gt;</description></item><item><title>Re: Part II: To Be or Not To Be an Identity </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2007/09/16/HPPost4429.aspx#81003</link><pubDate>Fri, 23 Nov 2007 16:10:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:81003</guid><dc:creator>Marco Casassa Mont</dc:creator><description>Hi. Thanks for your comment.
However, are you sure this comment relates to this post? I would see it more pertinent to my post on "On the Role of “Role Mining” in Enterprises".

Marco&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=81003" width="1" height="1"&gt;</description></item></channel></rss>