<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Digital Trust</title>
	<atom:link href="http://openidtrustbearer.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://openidtrustbearer.wordpress.com</link>
	<description>A Convenient and Secure Connection to the Web</description>
	<lastBuildDate>Thu, 22 Sep 2011 10:32:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='openidtrustbearer.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/879a9c10d8e91e955c67a043cb6537cd?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Digital Trust</title>
		<link>http://openidtrustbearer.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://openidtrustbearer.wordpress.com/osd.xml" title="Digital Trust" />
	<atom:link rel='hub' href='http://openidtrustbearer.wordpress.com/?pushpress=hub'/>
		<item>
		<title>For Archival Purposes</title>
		<link>http://openidtrustbearer.wordpress.com/2010/11/01/for-archival-purposes/</link>
		<comments>http://openidtrustbearer.wordpress.com/2010/11/01/for-archival-purposes/#comments</comments>
		<pubDate>Mon, 01 Nov 2010 18:38:13 +0000</pubDate>
		<dc:creator>Brian Kelly</dc:creator>
				<category><![CDATA[trustbearer]]></category>

		<guid isPermaLink="false">http://openidtrustbearer.wordpress.com/?p=385</guid>
		<description><![CDATA[You probably could&#8217;ve guessed that this blog has been retired since VeriSign acquired TrustBearer in April of this year.  We&#8217;ve also retired the trustbearer.com domain, but we still get a fair amount of traffic here, so I&#8217;m moving this blog &#8230; <a href="http://openidtrustbearer.wordpress.com/2010/11/01/for-archival-purposes/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=385&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You probably could&#8217;ve guessed that this blog has been retired since <a href="http://www.verisign.com/authentication/pki-infrastructure-solutions/managed-pki/trust-bearer-acquisition/index.html">VeriSign acquired TrustBearer</a> in April of this year.  We&#8217;ve also retired the trustbearer.com domain, but we still get a fair amount of traffic here, so I&#8217;m moving this blog back to it&#8217;s original WordPress URL, <a href="http://openidtrustbearer.wordpress.com/">openidtrustbearer.wordpress.com</a>.</p>
<p>Yes, this will break some inbound links, but at least the content will still be searchable. Thanks to everyone who has read and contributed over the years.</p>
<br />Filed under: <a href='http://openidtrustbearer.wordpress.com/category/trustbearer/'>trustbearer</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/385/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=385&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2010/11/01/for-archival-purposes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f410ddf1ca68d8030fcdb0ed53af2dfd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Brian Kelly</media:title>
		</media:content>
	</item>
		<item>
		<title>The Challenges and Pleasures of Working for a Growing Software Company</title>
		<link>http://openidtrustbearer.wordpress.com/2010/03/10/the-challenges-and-pleasures-of-working-for-a-growing-software-company/</link>
		<comments>http://openidtrustbearer.wordpress.com/2010/03/10/the-challenges-and-pleasures-of-working-for-a-growing-software-company/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 14:59:05 +0000</pubDate>
		<dc:creator>rsteger</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[early stage software company]]></category>
		<category><![CDATA[security start-up]]></category>
		<category><![CDATA[working for a start-up]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=346</guid>
		<description><![CDATA[My name is Rachel Steger, Office Manager for TrustBearer.  As a newcomer to the world of start-ups and software development last summer, my first six months with TrustBearer have been hugely enlightening.  With a background only in medium to large-sized &#8230; <a href="http://openidtrustbearer.wordpress.com/2010/03/10/the-challenges-and-pleasures-of-working-for-a-growing-software-company/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=346&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>My name is Rachel Steger, Office Manager for TrustBearer.  As a newcomer to the world of start-ups and software development last summer, my first six months with TrustBearer have been hugely enlightening.  With a background only in medium to large-sized corporations, I have found that I had a few misconceptions about what my professional life would look like once employed by an early-stage start-up company.  I never realized how non-existent bureaucracy could be within a hugely successful company, or how much of a relief it would be to not have to wear a suit and heels for my first day in the office.</p>
<p>TrustBearer life is about as casual as it gets – which is pretty typical for a small software company, from what I understand.  We all appreciate the flexibility of tracking our own hours and coming to work in shorts in the summer, if we want to.  Work hours are often long, but we all have a good time while we’re here.</p>
<p>The casual environment should not be confused for a slow-paced work day, however, or a lack of professionalism.   Work pours in and we pour it back out.  Projects show up with short deadlines, customers on other continents need immediate attention and assistance, and our office in D.C. keeps us hopping with an ever-growing list of government sales.</p>
<p>As Office Manager, I’ve been tasked with adding structure to this small company as it quickly outgrows its start-up status – as well as just about anything else that needs done (OK, so we’re not quite out of the start-up phase yet).  I would have to say that one of the joys of my job is that there are very few of us who have to come to consensus on how this should be done, which simplifies the process immensely.  The challenge has been to figure out how to grow without killing the great environment that has been built here over the past five years — how to add policies and procedures without completely annihilating the freedoms that we all appreciate on a daily basis.</p>
<p>When I joined the company last year, I didn’t quite anticipate the types of clients that a company of a dozen people would be working with on a daily basis – large enterprise customers and government clients such as SSA, FAA, Air Force, and others, to name a few.  As the smallest company in the smart card/middleware market, it has been exciting to see us build important relationships with large-scale companies, and to understand that even a small company in Fort Wayne, Indiana can make a world-wide impact in the security industry.</p>
<p>2009 was a great year for TrustBearer!  For the first time we have formal, dedicated 24-7 customer support; we helped rollout a <a href="http://opentheredbox.com/healthID.php">healthcare product</a> and obtained an exclusive <a href="http://www.trustbearer.com/news/aha-endorsement.php">American Hospital Association (AHA) endorsement</a>; we expanded to a second location in downtown Washington, D.C.; we made an appearance on the GSA schedule; and we forged exciting partnerships with companies from all over the world.  It will be interesting to see what 2010 looks like.</p>
<p>Stay tuned…..</p>
<br />Filed under: <a href='http://openidtrustbearer.wordpress.com/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://openidtrustbearer.wordpress.com/tag/early-stage-software-company/'>early stage software company</a>, <a href='http://openidtrustbearer.wordpress.com/tag/security-start-up/'>security start-up</a>, <a href='http://openidtrustbearer.wordpress.com/tag/working-for-a-start-up/'>working for a start-up</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/346/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=346&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2010/03/10/the-challenges-and-pleasures-of-working-for-a-growing-software-company/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9b8b8ca42183fd6baa3880913e8264e7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rsteger</media:title>
		</media:content>
	</item>
		<item>
		<title>RSA 2010</title>
		<link>http://openidtrustbearer.wordpress.com/2010/02/26/rsa-2010/</link>
		<comments>http://openidtrustbearer.wordpress.com/2010/02/26/rsa-2010/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 23:04:08 +0000</pubDate>
		<dc:creator>stevepepple</dc:creator>
				<category><![CDATA[demo]]></category>
		<category><![CDATA[enterpise openid]]></category>
		<category><![CDATA[Managed PKI]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[saml]]></category>
		<category><![CDATA[secruity conference]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=367</guid>
		<description><![CDATA[If you are going to be at the RSA Conference this year, we look forward to talking with you. The RSA Security Expo Monday March 1st &#8211; Thursday March 4th VeriSign Booth #1717 (see map below) San Francisco, CA Moscone &#8230; <a href="http://openidtrustbearer.wordpress.com/2010/02/26/rsa-2010/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=367&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img title="RSA Conference" src="http://farm3.static.flickr.com/2471/3616554879_3984632381.jpg" alt="" width="500" height="332" /></p>
<p>If you are going to be at the RSA Conference this year, we look forward to talking with you.</p>
<p><strong>The RSA Security Expo</strong><br />
Monday March 1st &#8211; Thursday March 4th</p>
<p><strong>VeriSign Booth #1717</strong><br />
(see map below)</p>
<p>San Francisco, CA<br />
Moscone Center</p>
<hr />This year, we&#8217;ve worked with VeriSign to integrate TrustBearer&#8217;s technology with VeriSign&#8217;s Managed PKI (MPKI) product, and we&#8217;ll be showing demos of this joint solution at the VeriSign booth.</p>
<p>We&#8217;ll also be showing our updated OpenID and SAML identity provider, which now allows users to register their computer with VeriSign MPKI. Similarly, users with PIV and CAC smart cards, and many other security devices, can use their credential for multi-factor authentication to web applications like Google Apps, Salesforce, and Basecamp.</p>
<p>If you would like to schedule a meeting with us during the conference, send us an email: <a href="mailto:sales@trustbearer.com">sales@trustbearer.com</a>.</p>
<p>To learn what we are up to during the conference, follow us on Twitter: <a href="http://twitter.com/trustbearer">@trustbearer.</a></p>
<p><a href="http://openidtrustbearer.files.wordpress.com/2010/02/verisign-booth1.jpg"><img class="size-full wp-image-369 alignleft" title="verisign-booth" src="http://openidtrustbearer.files.wordpress.com/2010/02/verisign-booth1.jpg?w=500" alt=""   /></a></p>
<br />Filed under: <a href='http://openidtrustbearer.wordpress.com/category/demo/'>demo</a>, <a href='http://openidtrustbearer.wordpress.com/category/enterpise-openid/'>enterpise openid</a> Tagged: <a href='http://openidtrustbearer.wordpress.com/tag/managed-pki/'>Managed PKI</a>, <a href='http://openidtrustbearer.wordpress.com/tag/openid/'>openid</a>, <a href='http://openidtrustbearer.wordpress.com/tag/rsa/'>RSA</a>, <a href='http://openidtrustbearer.wordpress.com/tag/saml/'>saml</a>, <a href='http://openidtrustbearer.wordpress.com/tag/secruity-conference/'>secruity conference</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/367/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=367&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2010/02/26/rsa-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3b7ca1b72060225b355161d93698cbe3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevepepple</media:title>
		</media:content>

		<media:content url="http://farm3.static.flickr.com/2471/3616554879_3984632381.jpg" medium="image">
			<media:title type="html">RSA Conference</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2010/02/verisign-booth1.jpg" medium="image">
			<media:title type="html">verisign-booth</media:title>
		</media:content>
	</item>
		<item>
		<title>Showcase with EXTENSION at HIMSS 2010</title>
		<link>http://openidtrustbearer.wordpress.com/2010/02/25/showcase-with-extension-at-himss-2010/</link>
		<comments>http://openidtrustbearer.wordpress.com/2010/02/25/showcase-with-extension-at-himss-2010/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 16:24:36 +0000</pubDate>
		<dc:creator>stevepepple</dc:creator>
				<category><![CDATA[healthcare]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[EXTENSION]]></category>
		<category><![CDATA[HealthID]]></category>
		<category><![CDATA[HIMSS 2010]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=371</guid>
		<description><![CDATA[We&#8217;ll be at HIMSS 2010 next week with EXTENSION Inc., showing the EXTENSION HealthID product: HIMSS 2010 Monday March 1st &#8211; Thursday March 4th Booth #5955 Atlanta, Georgia World Congress Centre Show Hours Are: Monday, March 1, 12:30 pm &#8211; &#8230; <a href="http://openidtrustbearer.wordpress.com/2010/02/25/showcase-with-extension-at-himss-2010/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=371&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://openidtrustbearer.files.wordpress.com/2010/02/himss.jpg"><img class="size-full wp-image-372 alignnone" title="himss" src="http://openidtrustbearer.files.wordpress.com/2010/02/himss.jpg?w=500" alt=""   /></a></p>
<p>We&#8217;ll be at HIMSS 2010 next week with EXTENSION Inc., showing the <a href="http://opentheredbox.com/healthID_faq.php">EXTENSION HealthID product</a>:</p>
<p><strong>HIMSS 2010</strong><br />
Monday March 1st &#8211; Thursday March 4th</p>
<p><strong>Booth #5955<br />
</strong>Atlanta, Georgia World Congress Centre</p>
<p>Show Hours Are:</p>
<ul>
<li>Monday, March 1, 12:30 pm &#8211; 5:30 pm</li>
<li>Tuesday, March 2, 10:00 am &#8211; 1:00 pm and 2:30 pm &#8211; 5:30 pm</li>
<li>Wednesday, March 3, 10:00 am &#8211; 1:00 pm and 2:30 pm &#8211; 5:30 pm</li>
</ul>
<p>If you are at HIMSS this year, we&#8217;ll look forward to talking with you.</p>
<br />Filed under: <a href='http://openidtrustbearer.wordpress.com/category/healthcare/'>healthcare</a> Tagged: <a href='http://openidtrustbearer.wordpress.com/tag/conference/'>conference</a>, <a href='http://openidtrustbearer.wordpress.com/tag/extension/'>EXTENSION</a>, <a href='http://openidtrustbearer.wordpress.com/tag/healthcare/'>healthcare</a>, <a href='http://openidtrustbearer.wordpress.com/tag/healthid/'>HealthID</a>, <a href='http://openidtrustbearer.wordpress.com/tag/himss-2010/'>HIMSS 2010</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/371/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=371&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2010/02/25/showcase-with-extension-at-himss-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3b7ca1b72060225b355161d93698cbe3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevepepple</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2010/02/himss.jpg" medium="image">
			<media:title type="html">himss</media:title>
		</media:content>
	</item>
		<item>
		<title>The Use and Abuse of Identifiers</title>
		<link>http://openidtrustbearer.wordpress.com/2010/02/17/the-use-and-abuse-of-identifiers/</link>
		<comments>http://openidtrustbearer.wordpress.com/2010/02/17/the-use-and-abuse-of-identifiers/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 18:45:40 +0000</pubDate>
		<dc:creator>stevepepple</dc:creator>
				<category><![CDATA[identity]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[identifiers]]></category>
		<category><![CDATA[identity attributes]]></category>
		<category><![CDATA[security you can use]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=354</guid>
		<description><![CDATA[In my line of work at TrustBearer, we work with a number of different identifiers, be they OpenID URIs, usernames, or email addresses. In this way, I probably don&#8217;t have an realistic appreciation for how most people using such identifiers &#8230; <a href="http://openidtrustbearer.wordpress.com/2010/02/17/the-use-and-abuse-of-identifiers/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=354&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://openidtrustbearer.files.wordpress.com/2010/02/who-where-what1.jpg"><img title="who-where-what" src="http://openidtrustbearer.files.wordpress.com/2010/02/who-where-what1.jpg?w=450&#038;h=60" alt="" width="450" height="60" /></a></p>
<p>In my line of work at TrustBearer, we work with a number of different identifiers, be they OpenID URIs, usernames, or email addresses. In this way, I probably don&#8217;t have an realistic appreciation for how most people using such identifiers think and feel about their email addresses,  usernames, or twitter handles. And for this reason, I&#8217;ve found the research of doctoral student Ben Gross (<a href="http://twitter.com/bengross">@bengross</a>) quite interesting and valuable.</p>
<p>In short, Gross has found that people have rather personal feelings about the identifiers that they are assigned and used, and they have a hard time using these identifiers how they would like, or how their employer expects them to.</p>
<p>Much of this research was discussed in a recent <a href="http://itc.conversationsnetwork.org/shows/detail4305.html">presentation at BayChi San Francisco</a> (a chapter of the ACM Special Interest Group on Computer-Human Interaction).</p>
<p>Gross&#8217;s research involved talking with people in two types of companies, financial and creative, about the identifiers they use at work and in their personal life. His findings help explain why people often accidentally (and purposely) misuse identity systems:</p>
<ul>
<li>Most people are managing a few email addresses, dozens of usernames and passwords, and several other identifiers, and they make very complex social decisions about how and why they use these identifiers.</li>
<li>The people Gross talked with wanted their identifiers to be their own name—even John Smith— or something meaningful and easy-to-remember.</li>
<li>People want to use personal and other identifiers at work; if they have trouble with identity and communications  systems at work, they use personal ones, e.g. their Hotmail.</li>
<li>Everyday use of identifiers can involve technical concepts, which are foreign to most users.</li>
<li>Some people Gross talked with started using an identifier in a certain way, but they don&#8217;t remember the initial reason or preference for this.</li>
<li>People usually don&#8217;t understand and often dislike and avoid identity system policies and rules.</li>
</ul>
<p>Gross also has looked into what people know and don&#8217;t know about their privacy related to identifiers. Like something you are or something you have, the things that you are assigned, such as a IP address, a location, or a web cookie, act as identifiers. And it is these identifiers that are most often used on the web for tracking people&#8217;s behavior and information (See <a href="http://www.identityblog.com/?p=1089">Kim Cameron&#8217;s recent post about browser fingerprints</a>). In this case, Gross looks forward to better applications and tools that allow average web users to control their privacy and for more transparent policies with regard to what information companies or other entities store and track.</p>
<p>Gross&#8217; <a href="http://bengross.com/dissertation/">dissertation</a> and published writings are available on his <a href="http://bengross.com">website</a>. He has written about <a href="http://www.messagingnews.com/story/promise-and-problems-openid">OpenID</a> and <a href="http://www.messagingnews.com/story/oauth-giving-access-castle-without-losing-control">OAuth</a> on <a href="http://www.messagingnews.com/onmessage">his blog at The Messaging News</a>.</p>
<br />Filed under: <a href='http://openidtrustbearer.wordpress.com/category/identity/'>identity</a>, <a href='http://openidtrustbearer.wordpress.com/category/openid/'>openid</a> Tagged: <a href='http://openidtrustbearer.wordpress.com/tag/email/'>email</a>, <a href='http://openidtrustbearer.wordpress.com/tag/identifiers/'>identifiers</a>, <a href='http://openidtrustbearer.wordpress.com/tag/identity/'>identity</a>, <a href='http://openidtrustbearer.wordpress.com/tag/identity-attributes/'>identity attributes</a>, <a href='http://openidtrustbearer.wordpress.com/tag/security-you-can-use/'>security you can use</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/354/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=354&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2010/02/17/the-use-and-abuse-of-identifiers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3b7ca1b72060225b355161d93698cbe3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevepepple</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2010/02/who-where-what1.jpg" medium="image">
			<media:title type="html">who-where-what</media:title>
		</media:content>
	</item>
		<item>
		<title>Software Testing at TrustBearer</title>
		<link>http://openidtrustbearer.wordpress.com/2009/12/29/software-testing-at-trustbearer/</link>
		<comments>http://openidtrustbearer.wordpress.com/2009/12/29/software-testing-at-trustbearer/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 22:03:35 +0000</pubDate>
		<dc:creator>cpenn</dc:creator>
				<category><![CDATA[product]]></category>
		<category><![CDATA[quality assurance]]></category>
		<category><![CDATA[security testing]]></category>
		<category><![CDATA[software quality]]></category>
		<category><![CDATA[software testing]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=323</guid>
		<description><![CDATA[Hello, I&#8217;m Charles and I&#8217;m the new Quality Engineer at TrustBearer.  TrustBearer brought me on keep the company on track to meet its quality goals. Some of these goals were already being implemented when I got here: unit tests, code &#8230; <a href="http://openidtrustbearer.wordpress.com/2009/12/29/software-testing-at-trustbearer/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=323&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hello, I&#8217;m Charles and I&#8217;m the new Quality Engineer at TrustBearer.  TrustBearer brought me on keep the company on track to meet its quality goals. Some of these goals were already being implemented when I got here: unit tests, code reviews, good defect tracking, code documentation. For my part, I tend to focus on system level testing, including functional and non-functional testing (security, performance, etc.), as well as developing a more solid and repeatable testing process. With this in mind, I&#8217;ll going to discuss the testing and quality assurance work we do at TrustBearer to ensure that our products work well and are secure. I&#8217;ll also focus on some of my personal philosophy with regards to testing.</p>
<p>My philosophy boils down to the idea that no program can be fully tested, and that a tester, or testing team, should focus on the ROI for their time. A lot of this philosophy has been developed from discussions with and readings from other professionals in the field such as <a title="Cem Kaner" href="http://www.satisfice.com/kaner/">Cem Kaner</a>, <a title="James Bach" href="http://www.satisfice.com/blog/">James Bach</a>, and <a title="Michael Kelly" href="http://www.michaeldkelly.com/">Michael Kelly</a>, including the idea of <a title="Context-Driven Testing" href="http://www.context-driven-testing.com/">Context-Driven Testing</a>. Some of my ideas also come from one or both of the organizations I belong to, the Association for Software Testing (<a title="AST" href="http://www.associationforsoftwaretesting.org/drupal/">AST</a>) and the Indianapolis Workshops on Software Testing (<a title="IWST" href="http://www.iwst2009.com">IWST</a>).</p>
<p>Now, how does this philosophy apply to TrustBearer products? Well, if we look at our website at the<a title="TrustBearer Desktop page" href="http://www.trustbearer.com/desktop/"> TrustBearer Desktop page</a>, we list our compatibility for various smart cards, OSes, and mention other technologies we are compatible with. Just looking at the page tells me that there is a good number of combinations of OSes, browsers, smart cards, and mail programs that need to be tested, and that ignores any external factors (other USB devices that are used by the customer causing problems with our system, for an example).</p>
<p>So if it&#8217;s impractical to test everything all of the time, what is tested? There is no one correct answer, however, a good tactic to take focuses on defining the problem space. For me, this involves finding the typical configurations first. When I say a typical configuration for TrustBearer products, I mean this in regards to what our software interacts with. We can never fully replicate what our customers will have in terms of hardware and software, but we can have a reasonable approximation. For instance, if most of our customers are using PIV cards with Windows 7 as their OS, Firefox 3.5.6 as their web browser, and Outlook 2007 as their mail program, then my tests are run primarily using that as a base configuration.</p>
<p>Another good way to focus what is tested is to look at what features are used the most, and in what ways. For a good example of this, our software products facilitate the use of hardware and software tokens for things like windows logon, email signing and encryption, signing Word and PDF documents, as well as interacting with various websites. While we test all of these features, initial testing would focus on what our customers typically used our software for most.</p>
<p>Another generally good method of testing is focusing on high-risk areas. For some applications, this might be the billing system, or the login system, neither of which you want to find any serious defects in). For TrustBearer, this focus tends to fall on security testing. For instance, sometimes we develop web pages for customers that work with our TrustBearer Live Plugin, and we run tests simulating SQL Injection, phishing, and man-in-the-middle attacks to make sure that our customer&#8217;s data can&#8217;t be exposed to anyone untrustworthy.</p>
<p>Using these techniques as a base, we go on to test more and more features and platform combinations. The goal being that we have confidence that any bugs we have not found are minor, obscure, and will not cause problems for our customers. As with everything else in software, this is never a finished process, but with a good philosophy and a dedicated team, quality improves with every revision.</p>
<p>While that isn&#8217;t all there is to testing, I hope that the above gives you a little glimpse into the process, and hopefully I&#8217;ll be able to share more of the process of testing, tools we use, and how we determine when we&#8217;re &#8216;finished&#8217;.</p>
<p>- Charles</p>
<br />Posted in product Tagged: quality assurance, security testing, software quality, software testing <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/323/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=323&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2009/12/29/software-testing-at-trustbearer/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/12246e004458df53812cbc30fc101cfc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cpenn</media:title>
		</media:content>
	</item>
		<item>
		<title>First Impressions of ISO/IEC 24727</title>
		<link>http://openidtrustbearer.wordpress.com/2009/12/11/first-impressions-of-isoiec-24727/</link>
		<comments>http://openidtrustbearer.wordpress.com/2009/12/11/first-impressions-of-isoiec-24727/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 17:56:05 +0000</pubDate>
		<dc:creator>Brian Kelly</dc:creator>
				<category><![CDATA[standards]]></category>
		<category><![CDATA[24727]]></category>
		<category><![CDATA[gics]]></category>
		<category><![CDATA[iec]]></category>
		<category><![CDATA[iso]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[smart card]]></category>
		<category><![CDATA[standard]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=284</guid>
		<description><![CDATA[** 6 Jan 2010 Update:  The official presentations are now available from NIST. Today, googling for ISO/IEC 24727 returns ~5000 results.  The first four are links to purchase the standard specifications from either the ISO or IEC webstore.  The fifth, &#8230; <a href="http://openidtrustbearer.wordpress.com/2009/12/11/first-impressions-of-isoiec-24727/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=284&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://openidtrustbearer.files.wordpress.com/2009/12/googling-iso-iec-24727.png"><img class="alignright size-medium wp-image-286" title="Googling ISO/IEC 24727" src="http://openidtrustbearer.files.wordpress.com/2009/12/googling-iso-iec-24727.png?w=206&#038;h=300" alt="Results of the Google search for ISO/IEC 24727" width="206" height="300" /></a><span style="color:#ff0000;"><em>** 6 Jan 2010 Update:  The </em></span><a href="http://csrc.nist.gov/news_events/ISO_IEC-24727-Tutorial/presentations.html"><span style="color:#ff0000;"><em>official presentations are now available</em></span></a><span style="color:#ff0000;"><em> from NIST.<br />
</em></span></p>
<p>Today, googling for <em><a href="http://www.google.com/search?q=ISO/IEC+24727">ISO/IEC 24727</a></em> returns ~5000 results.  The first four are links to purchase the standard specifications from either the <a href="http://www.iso.org/iso/catalogue_detail.htm?csnumber=38837">ISO</a> or <a href="http://webstore.iec.ch/Webstore/webstore.nsf/Artnum_PK/41914">IEC</a> webstore.  The fifth, <em><a href="http://www.springerlink.com/content/nh22vht81g452547/">ISO/IEC 24727 &#8211; A Future Standard for Smart Card Middleware</a></em>, looked like a simple description of the standard, maybe distilled for a broader audience&#8230;  But, it&#8217;s actually a paper about the standard <em>on sale for $25!</em> Perhaps this lack of free information was part of the reason <a title="National Institute of Standards and Technology">NIST</a> decided to hold a workshop all about the standard this past week.</p>
<p>I attended <a href="http://csrc.nist.gov/news_events/ISO_IEC-24727-Tutorial/">NIST&#8217;s Tutorial Workshop on ISO/IEC 24727</a> (Identification Cards – Integrated Circuit Card Programming Interfaces).  It lasted a few days and it covered a ton of information about this 6-part standard.  The workshop speakers included several editors of the standard, including Tim Jurgensen, Mike Neumann and Alex Gagel, as well as representatives from NIST who have also been working with 24727 in various capacities: Terry Schwarzhoff, Bill MacGregor, and Sal Francomacaro.  Ketan Mehta &amp; Hung Dang from Booz Allen Hamilton and Alexander Winnen from Giesecke &amp; Devrient gave technical demonstrations of the standard in-action.  Alex Gagel also detailed the first substantial use of the standard for the Queensland, AUS Driver license.</p>
<p>Outside of NIST, it seems that there has been little involvement from United States companies in developing 24727.  Perhaps that is part of the reason why there is not a ton of information available online.  This post explores 24727 from a U.S. smart card standards perspective.  If you&#8217;re familiar with CAC and PIV, but are just hearing about 24727, I hope this helps.</p>
<h3>Some Background – HSPD-12 &amp; PIV</h3>
<p><a href="http://openidtrustbearer.files.wordpress.com/2009/12/generic-piv.png"><img class="alignleft size-medium wp-image-302" title="PIV Smart Card" src="http://openidtrustbearer.files.wordpress.com/2009/12/generic-piv.png?w=196&#038;h=300" alt="" width="196" height="300" /></a>ISO/IEC 24272 is a bold attempt to make identity credentials (such as smart cards) and the applications that consume those credentials much more interoperable than they are today.  <em>Wait, isn&#8217;t that what <a title="U.S. Government's Personal Identity Verification standard" href="http://csrc.nist.gov/groups/SNS/piv/index.html">PIV</a> was supposed to do?</em> Sort of, but 24727 goes much further in its interoperability goals.  On the technical interoperability side, PIV defined a smart card edge (API), data model (to store the cardholder&#8217;s name, ID#, photograph, etc.), and required cryptographic capabilities.  <a title="Federal Information Processing Standards Publication 201:  Personal Identity Verification (PIV) of Federal Employees and Contractors" href="http://csrc.nist.gov/publications/PubsFIPS.html#FIPS-201--1">FIPS 201</a> (Titled <em>Personal Identity Verification of Federal Employees and Contractors</em> or &#8221;PIV&#8221; for short) tackled much more than just the technical specifications of the smart card.  It also defined the physical card look and feel of the card, standardized the identity vetting procedures, and provided use cases for physical and logical access.</p>
<p>The goals of 24727 are slightly different than the U.S. Government&#8217;s goals with PIV.  FIPS 201 / PIV was created in response to <a href="http://csrc.nist.gov/drivers/documents/Presidential-Directive-Hspd-12.html">HSPD-12</a> – a request from former President G.W. Bush to create an identity standard for all federal employees and contractors.  NIST answered the call and developed the FIPS 201 specification in 6 months – a very short amount of time for a standard encompassing many identity concepts.  PIV defined a single smart card standard that enabled many different hardware and software manufacturers to <a title="FIPS 201 Evaluation Program Approved Products List" href="http://fips201ep.cio.gov/apl.php">create compatible products</a>.  This has had an enormously positive impact for the adoption of identity smart cards and related products in the U.S. Government.  PIV was also a <em>huge</em> boost TrustBearer&#8217;s industry.  Now, <a href="http://www.smartcardalliance.org/articles/2008/10/28/hspd-12-piv-cards-moving-into-states-and-enterprises-for-network-security-and-emergency-responder-credentialing-programs">state &amp; local governments</a> and <a href="http://www.smartcardalliance.org/pages/newsletter-200903-feature?issue=200903">private companies</a> are starting to take advantage of this federal government investment.  <em>See the </em><a href="http://www.idmanagement.gov/documents/PIV_IO_NonFed_Issuers_May2009.pdf"><em>CIO Council&#8217;s PIV-Interoperable document</em></a><em>.</em></p>
<p>The scope of the PIV specification was deliberately limited to address the requests in HSPD-12.  PIV defined a smart card application for usage, but not for card personalization.  PIV also defined a very specific card data model intended to store information that would be helpful to identify federal employees and contractors.  Organizations outside the federal government are now trying to adopt PIV, but are finding that these deliberate limitations make PIV a less flexible identity standard.  <em>Consider healthcare: PIV does not define nor provide a way to extend the data model to record clinical information like allergies or medications on the card</em>.</p>
<h3>A More Flexible Identity Credential Standard</h3>
<p>As Mike Neumann mentions in <a title="ISO/IEC 24727 and INCITS #2094: Bringing it Together (Mike Neumann, Agile Set presentation) – It's excellent!" href="http://www.slideshare.net/agileset/neumann-24727-b1012-update-20091029-am-r3">his presentation</a> from earlier this year,</p>
<blockquote><p>ISO/IEC 24727 is a framework for interoperable IAS [Identification, Authentication, Signature] systems.</p></blockquote>
<p>It provides abstraction at every level of an IAS system, including the card data model &amp; associated security model, card administration, communication protocols, and authentication protocols.  Even the testing section was developed to be completely extensible.  When these concepts and this image were first presented, I was a bit overwhelmed.</p>
<p><a href="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-architecture-1.png"><img class="aligncenter size-full wp-image-300" title="ISO/IEC 24727: Architecture" src="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-architecture-1.png?w=500&#038;h=306" alt="" width="500" height="306" /></a></p>
<p>This was such a leap beyond what PIV and CAC tried to accomplish that I really needed those few days to digest the breadth of the 24727 standard.  I like to think about it this way – 24727 gives</p>
<ul>
<li>Card operating system / applet providers, and</li>
<li>Card Management System (CMS) providers</li>
</ul>
<p>a standard way to describe the card/applet&#8217;s</p>
<ul>
<li>technical capabilities (e.g. crypto)</li>
<li>data model</li>
<li>data security model</li>
<li>administrative capabilities (for personalization / lifecycle management)</li>
<li>communication protocol capabilities (e.g. APDU, TLS)</li>
</ul>
<p>for use by</p>
<ul>
<li>Card middleware providers (e.g. TrustBearer), and ultimately</li>
<li>Client applications (e.g. Windows, Custom smart card viewer, Web services)</li>
</ul>
<p>Before this standard, there were always some functionality limitations in layers between these components.  By functionality limitations I mean that layer <em>x</em> (e.g. application) could not access (or didn&#8217;t know how to access) a feature in layer <em>y</em> (e.g. specific data container on card).  To pick on one at a relatively high level, consider PKCS#11, commonly used in non-Microsoft browsers and Email clients.  PKCS#11 allows client applications to use digital certificates and keys stored in a variety of locations – usually in software or hardware (smart cards).  Smart card middleware vendors provide PKCS#11 modules to communicate with the smart cards that they support.  PKCS#11 allows for a single PIN or passphrase to be entered, typically to gain access to use a private key located on a smart card.  But what if different PINs are used for different keys or different operations on those keys (e.g. signing v. authentication)?  PKCS#11 doesn&#8217;t support it.</p>
<p>To borrow another description from Mike&#8217;s presentation, he describes two approaches to previous standards / specs:</p>
<blockquote><p>&#8220;client-down&#8221;, e.g.</p>
<ul>
<li>PKCS#11 – general, but uncoordinated across API</li>
<li>CSP – Single function of a single application view</li>
</ul>
</blockquote>
<blockquote><p>&#8220;card-up&#8221;, e.g.</p>
<ul>
<li>All of ISO/IEC 7816 series</li>
<li>(Nearly?) all middleware based on ISO/IEC 7816</li>
</ul>
</blockquote>
<blockquote><p>ISO/IEC 24727 is the first series of standards to be designed with both in mind.</p></blockquote>
<p>This is a helpful way to start to get a feeling for the scope of 24727.</p>
<h3>6 Parts</h3>
<p>24727 is divided into six parts <em>(and ISO &amp; IEC will be happy to take your money to download each one)</em>.</p>
<ul>
<li><strong>Part 1: Architecture</strong> – The diagram you saw above, plus some more detail;  The shortest of all parts</li>
<li><strong>Part 2: Generic Card Interface (GCI)</strong> – Provides a well-defined syntax to describe any card&#8217;s data model, security model (Access Control Lists), and capabilities;  Allows middleware to talk to a card without knowing the specific card edge commands</li>
<li><strong>Part 3: Application Programming Interface (API)</strong> – Provides a well-defined syntax for client applications to communicate with the GCI;  Apps can discover data on cards they&#8217;ve never seen previously</li>
<li><strong>Part 4: API Administration</strong> – Used for secure communication to the card and lifecycle management;  This was added as  a new work item while developing the spec;  It addresses end-to-end security, connectivity, secure messaging, stack configuration &amp; use, and interface devices (IFD)</li>
<li><strong>Part 5: Testing</strong> – Baked in from the beginning, there&#8217;s a model and test script to help prove compliance with the parts that your product claims to implement</li>
<li><strong>Part 6: Register Authentication Protocols (AP)</strong> – A maintained list of commonly used authentication protocols, such as internal authenticate and external authenticate;  Industries will need their own domain-specific APs, and this allows them to register specific APs to share with others. (See <a title="IDTP's presentation on PIV for PACS or MR-PIV, Mutual Registration in PIV" href="http://www.idmanagement.gov/iab/presentations/MR-PIV.pdf">PIV for PACS or MR-PIV</a> and <a title="Protocol for Lightweight Authentication of Identity" href="https://www.govdex.gov.au/confluence/pages/viewpageattachments.action?pageId=61931545&amp;highlight=CentrelinkPLAID_Version8+Dec09.pdf#Home-attachment-CentrelinkPLAID_Version8+Dec09.pdf">PLAID</a> for examples of a newly proposed APs that could be brought into this part of 24727 someday)</li>
</ul>
<p><a href="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-part-3-basic-entity-relationships.png"><img class="aligncenter size-medium wp-image-304" title="ISO-IEC 24727 part 3 - basic entity relationships" src="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-part-3-basic-entity-relationships.png?w=300&#038;h=158" alt="" width="300" height="158" /></a></p>
<p><a href="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-generic-ias-card-application.png"><img class="aligncenter size-medium wp-image-305" title="ISO-IEC 24727 generic IAS card-application" src="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-generic-ias-card-application.png?w=300&#038;h=146" alt="" width="300" height="146" /></a></p>
<p>I am just scratching the surface here.  Each of these parts could be another post on its own.  There are some really interesting concepts introduced in the details.  Such as the Part 2 translation scripts – this is where the conversion from a card protocol, like APDUs and the Part 3 API is made.  In some cases, a card could actually store ISO 20060 bytecode that describes its data model and supported functions.  Middleware could then download and run this bytecode to make these translations in real-time.  This is, of course, for new cards that adopt the standard at the card level.</p>
<h3>Transition from Existing Applications and Cards</h3>
<p><a href="http://www.flickr.com/photos/trustbearer/4164577862/"><img class="alignright" title="Windows &amp; Linux PIV 24727 demo" src="http://farm5.static.flickr.com/4002/4164577862_86b4eb0c6e_m_d.jpg" alt="" width="240" height="180" /></a>While it would be great if every opportunity out there was a greenfield, like the Queensland Driver&#8217;s License project, there are many well-established identity programs with cards already in use, such as CAC and PIV.  24727 can be adopted at various parts.  NIST gave a demo at the workshop of a 24727 Reference Implementation for PIV smart cards.  Ketan Mehta and Hung Dang implemented parts 2 and 3 and hooked this up to a Cryptographic Service Provider (CSP) on Windows to demonstrate smart card logon.  They also connected a PKCS#11 module on both Windows and Linux to their 24727 ref imp to demonstrate email signing on both operating systems and smart card logon using PAM on Linux.  All of this was accomplished without modifying the actual PIV card at all.</p>
<p>During the wrap-up on the last day, Bill MacGregor said this ability to work with existing, deployed tokens was one of his two top benefits of 24727.  The other was the identity abstraction layer in part 3, which provides a tool to think about digital identities and tokens that we have not had in the past.  There are no promises that the next revision of FIPS 201 / PIV will utilize 24727, but I believe it is being considered as a possibility to extend the current PIV standard while remaining backwards compatible with existing PIV &amp; CAC cards.</p>
<h3>Generic Identity Command Set (GICS)</h3>
<p>We had a Q&amp;A session on the last day of the workshop, and I asked about GICS, which is yet another smart card technical specification that primarily came from industry (INCITS B10.12).  <a href="http://www.sourcemediaconferences.com/CTST09/PDF09/D/Thursday/GOYETnew.pdf">This presentation from Oberthur at CTST</a> this year gives a helpful background and details about the in-progress spec.  The motivations behind developing GICS are interesting.  The presentation starts out by listing all the government endorsed standards released over the years: GSC-IS 2.0, 2.1, PIV&#8217;s SP 800-73, 800-73-1, then 24727.  Then it follows with the statement that this costs industry a lot of money to make products that comply with these changing standards, but there&#8217;s not much ROI from deploying these changes in the market.</p>
<blockquote><p><strong>Summer 2006</strong>: Using experiences from the development of PIV products, a group of smart card technical experts from the industry decided to work together to define a stable generic card command set that would piggyback on the PIV End Point card edge developed by NIST, but extend its reach outside of the Government area, to extend the market.</p></blockquote>
<p>GICS is a proposal from the smart card industry to preserve the existing investments of PIV, TWIC, etc. and address the needs for greater interoperability for new card applications other than PIV (or maybe those that have derived from PIV).  GICS introduces a standard card command set, <em>not</em> a new card application command set.</p>
<p>You can see the full list of expected benefits in the presentation, but essentially GICS is trying to standardize an extensible smart card command set for identity cards so that when a card or applet vendor makes an investment to develop products that comply with this command set, the market for these products is much larger than it would be for a specific command set (e.g. PIV).  Certification (like FIPS 140) could be performed on a single GICS card / applet one time rather than an a card/applet for each different identity specification.</p>
<p>The technical characteristics in GICS cover a wide range of capabilities found in modern smart cards: Data objects, parser, templates, tag lists, and even On-Card fingerprint verification.  It also includes a set of common Authentication Protocols and allows that list to be extended.</p>
<p><em>Sounds a lot like 24727, right?</em></p>
<p>While it does have some similar goals in extensibility and interoperability, GICS does not go nearly as far as 24727.  It sticks to smart cards and APDUs.  It builds atop PIV to allow for PIV Interoperable and PIV compatible specs to be invented and implemented without requiring yet another applet that needs to be certified.  It stays within the smart card middleware world that we know today.  At the conference Mike Neumann said that 24727 and GICS work together.  From <a href="http://www.slideshare.net/agileset/neumann-24727-b1012-update-20091029-am-r3">his presentation</a> that I referenced earlier, &#8220;ISO/IEC 24727 defines the system interfaces; GICS defines the card commands.&#8221;</p>
<h3>Opinion</h3>
<p>My goal in attending the workshop last week was to learn about ISO/IEC 24727 and understand how it affects TrustBearer&#8217;s business.  Among other things, we provide middleware software that allows all kinds of applications and devices take advantage of high assurance identity credentials like smart cards.  Technical identity standards like PIV and ISO 24727 often indicate that there will be a market for the types of products that we build.</p>
<p>24727 is the first attempt I&#8217;ve seen at taking a brand-new look at how identity credentials and systems could be made much more interoperable.  This is an <em>extremely </em>extensible specification.  Data and security models can be discovered.  The communication protocols can evolve – imagine not needing to know what an APDU even<em> </em><em>is!</em> From a technical perspective, these concepts and the proposed architecture are very impressive.  But the level of abstractions introduced in this specification couldn&#8217;t help but remind me of Spolsky&#8217;s posts on <a href="http://www.joelonsoftware.com/articles/fog0000000018.html">architecture</a> <a href="http://www.joelonsoftware.com/items/2008/05/01.html">astronauts</a>.</p>
<p>Does 24727 have too much abstraction?  Is there really a market demand for the concepts introduced in this standard?  That is the top question in my mind.  It was helpful to hear from Alex Gagel, one of the lead architects on the Australian Queensland Smart Driver&#8217;s License project.  That smart card project is clearly the largest and most thorough implementation of 24727 to date.  Alex and his team are such early adopters of the standard that they are the editors for parts 5 (Testing) and 6 (AP Register) of the standard.  <a href="http://www.apsca.org/event/meeting114/ISO_IEC_FAQ.html">This FAQ states</a> that the European Union Citizens Card, German Smart ID Card and German Electronic Health Card will also be adopting 24727, but to what degree I am not sure.</p>
<p>Is GICS a more practical step in the right direction?  I can say that from a middleware and card application provider perspective, GICS has a more well-defined scope and short-term value proposition for the U.S. ID credential market.  GICS has the luxury of building on top of an existing standard (PIV) and it&#8217;s scope us much more narrow than 24727.  Is GICS itself sufficient for the next 5 years?</p>
<p>&lt;ISO/IEC $$$ rant&gt; I do not have all the information on why ISO and IEC charge money to download their specifications, but coming from the technology / Web 2.0 industry, where companies are dying to give away their API documentation in order to drive adoption&#8230; I don&#8217;t get it.  How does charging anywhere from $95 USD to $245 USD for <em>each part </em>of the 24727 specification encourage the world to adopt this <em>interoperability</em> specification?  It just doesn&#8217;t make any sense to me. &lt;/rant&gt;</p>
<p><strong>**COUPON: </strong>On that topic, we were informed at the workshop that ANSI has an agreement with ISO/IEC to sell each part of the 24727 spec for $30 USD.  <a href="http://webstore.ansi.org/FindStandards.aspx?SearchString=24727&amp;SearchOption=0&amp;PageNum=0&amp;SearchTermsArray=null%7c24727%7cnull">Access the ANSI eStandards Store and search for 24727</a> to see each part – the discounted ones are at the bottom.</p>
<p>TrustBearer will be keeping an eye on the adoption of 24727.  Until we see a significant demand coming from our existing customers and focus markets, we will probably not begin to adopt these concepts in our software.  That said, I would like to hear the opinions of others who stumbled across this article.  Is 24727 affecting development of your products today?  And for those in charge of identity programs, will 24727 be a cornerstone of your next ID credential?  Please <a href="mailto:brian.kelly@trustbearer.com">email me</a> or leave a comment.</p>
<h3>Presentation References</h3>
<p>NIST said that all the presentations from the workshop should be eventually published online.  For now, I&#8217;ll embed the two that I found very helpful when writing this article.</p>
<p><strong>Mike Neumann&#8217;s 24727 &amp; GICS Presentation</strong></p>
<iframe src='http://www.slideshare.net/slideshow/embed_code/2372761' width='500' height='410'></iframe>
<p><strong>Oberthur&#8217;s GICS Presentation</strong></p>
<iframe src='http://www.slideshare.net/slideshow/embed_code/2699569' width='500' height='410'></iframe>
<br />Posted in standards Tagged: 24727, gics, iec, iso, NIST, smart card, standard <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/284/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=284&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2009/12/11/first-impressions-of-isoiec-24727/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f410ddf1ca68d8030fcdb0ed53af2dfd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Brian Kelly</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/12/googling-iso-iec-24727.png?w=206" medium="image">
			<media:title type="html">Googling ISO/IEC 24727</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/12/generic-piv.png?w=196" medium="image">
			<media:title type="html">PIV Smart Card</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-architecture-1.png" medium="image">
			<media:title type="html">ISO/IEC 24727: Architecture</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-part-3-basic-entity-relationships.png?w=300" medium="image">
			<media:title type="html">ISO-IEC 24727 part 3 - basic entity relationships</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/12/iso-iec-24727-generic-ias-card-application.png?w=300" medium="image">
			<media:title type="html">ISO-IEC 24727 generic IAS card-application</media:title>
		</media:content>

		<media:content url="http://farm5.static.flickr.com/4002/4164577862_86b4eb0c6e_m_d.jpg" medium="image">
			<media:title type="html">Windows &#38; Linux PIV 24727 demo</media:title>
		</media:content>
	</item>
		<item>
		<title>Internationalization in TrustBearer Products</title>
		<link>http://openidtrustbearer.wordpress.com/2009/12/02/internationalisation-in-trustbearer-products/</link>
		<comments>http://openidtrustbearer.wordpress.com/2009/12/02/internationalisation-in-trustbearer-products/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 02:11:18 +0000</pubDate>
		<dc:creator>Taylor Venable</dc:creator>
				<category><![CDATA[new feature!]]></category>
		<category><![CDATA[product]]></category>
		<category><![CDATA[globalization]]></category>
		<category><![CDATA[international software]]></category>
		<category><![CDATA[internationalization]]></category>
		<category><![CDATA[multi-language software]]></category>
		<category><![CDATA[TeX]]></category>
		<category><![CDATA[translation]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=241</guid>
		<description><![CDATA[Introduction Here at TrustBearer, we&#8217;re working on reworking the underlying pieces of our software to provide services which are required for full treatment of internationalization issues from cultural sensitivity to language translation.  Fitting such an infrastructure onto a vast existing &#8230; <a href="http://openidtrustbearer.wordpress.com/2009/12/02/internationalisation-in-trustbearer-products/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=241&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://openidtrustbearer.files.wordpress.com/2009/12/red-flags.jpg"><img class="alignnone size-full wp-image-277" title="red-flags" src="http://openidtrustbearer.files.wordpress.com/2009/12/red-flags.jpg?w=500&#038;h=59" alt="" width="500" height="59" /></a></p>
<h3>Introduction</h3>
<p>Here at TrustBearer, we&#8217;re working on reworking the underlying pieces of our software to provide services which are required for full treatment of internationalization issues from cultural sensitivity to language translation.  Fitting such an infrastructure onto a vast existing system of hardcoded, interlinked modules which span multiple (programming) languages and techniques on several platforms is a challenge, but we have come a long way to eventually realizing the goal of true international support.</p>
<h3>Issues of Internationalization</h3>
<p>The most obvious issue of internationalization is the language in which the user interface is presented; if your audience only speaks French, or perhaps just as importantly <em>prefers</em> to speak French, then you need to offer a user interface in French.  Secondary issues can carry much more subconscious weight, however: as individual cultures have risen and separated from one-another across the planet, even in the age of international commerce and communication that the Internet conveys, specific communities still carry important symbols, ideas, and values which are intrinsically and uniquely their own.</p>
<p>The meaning of colors varies from one society to another, as does the importance of iconography.  For example, the dagger (†) bears similarity to the Christian cross (which it should, since that was part of the original meaning conveyed in its use) and should be used carefully, even in purely typographical meaning, to avoid unintentional religious connotations. This sort of care is often given nary a second thought by those responsible for internationalization strategy, and it&#8217;s important to address it just as evenly as one addresses language.  On the subject of translation, there are many things which carry over along with the baggage of verbal communication: formality, dialect, the hints and subtleties that individual words carry both inside and outside of specific contexts, all of these come into play with deciding on a technique for providing the infrastructure with which to provide international support for a software system.</p>
<p><a href="http://openidtrustbearer.files.wordpress.com/2009/12/blue-flags.jpg"><img class="alignnone size-full wp-image-276" title="blue-flags" src="http://openidtrustbearer.files.wordpress.com/2009/12/blue-flags.jpg?w=500&#038;h=58" alt="" width="500" height="58" /></a></p>
<h3>Implementations</h3>
<p>There are four fundamental systems in TrustBearer&#8217;s overall product ecosystem: the web plugin with dynamic device support, the browser, static web content, and the server.  We have chosen to implement three components which satisfy the translation needs of all four pieces.</p>
<h4>Plugin, Device Support, and JavaScript</h4>
<p>We implement dynamic translation features in the plugin as a module, which is loaded at run-time just like device support is.  In this way we offer the ability to switch languages in real-time.  It also gives us the luxury to download translations from a server where they can be modified on the fly without the need for any kind of recompilation or redistribution.  Because our plugin and the methods of its modules, which have been marked with the appropriate access level, are accessible from JavaScript running in the browser, we can extend such dynamic translation support to the browser as well.</p>
<p>Translations are conducted using a very simple macro language inspired syntactically by TeX.  It allows placement of separately translated arguments in arbitrary order (to facilitate support of languages such as German which have different or flexible word order structures) and automatic construction of quotation marks (to handle nested quotations build from separate translations substituted as in the previous remark).  Because of the nature of the system, new extensions can be added but this will not complicate the writing of a translation module: the goal is to allow our customers to be able to modify these to substitute their own language if they see fit.</p>
<h4>Static Web Content</h4>
<p>The exact same translation module drives a compile-time tool to create static versions of web pages, style sheets, and so forth which support individual cultures.  This step occurs automatically using pkgBuilder, the tool used throughout TrustBearer for building all systems we produce.  The result is a collection of HTML files, one for each culture which is supported.  Customers are then free to select from the available languages to deploy, and to use their webserver&#8217;s rewriting capabilities to send e.g. their Norwegian users to <tt>index.no.html</tt> rather than <tt>index.en.html</tt>.  This provides a balance between computation time required and flexibility offered; while TrustBearer&#8217;s clients no longer have the capability to retranslate pages without any extra work, their servers will not be constantly working to provide the latest translated version when such is very unlikely to change with any notable frequency.</p>
<h4>Daemon</h4>
<p>The core TrustBearer server, which we simply call &#8220;the daemon,&#8221; rarely provides information directly to the user.  Rather, it contains a lookup system to check incoming error attributes against a database and return a corresponding message which is meaningful to the humans who will diagnose or work around problems.  For quite some time, the daemon has used the client&#8217;s language (as provided by their browser) as a means of looking up these human-readable messages.  Little to no extension of this system is necessary to continue to provide error and status messages to users in the languages in which they are accustomed to communicating.</p>
<h3>The Road Ahead</h3>
<p>While the architecture of the internationalization system is fairly set, the work on retrofitting this into the existing system is just beginning.  Over the next few months, we will be externalizing strings and incorporating the new methods of translating messages dynamically.  TrustBearer&#8217;s head engineer, Eirik Herskedal, is from Norway and will be providing a pilot translation into his native tongue for us to begin testing with.  The testing and quality assurance process will take the longest, but features in the translation system (for example, XXX&#8217;ing out strings for which no translation exists) will make this process smoother.  After several months, we expect these features to enter beta use by our most prestigious customers. Then, with the consideration of customer feedback,  these features will be added to all of our future deployments.</p>
<p>Software systems that  work with the cultural complexities and sensitivities of their users, rather than against them, are woefully under supplied.  At TrustBearer, we value the differences in our users, and wish to better cater to the multi-faceted nature of their individual societies.  By starting this long work to implement internationalization features in TrustBearer products, we begin down the road of providing our system in a way that works best for <em>you</em>, whoever and wherever you may be.</p>
<br />Posted in new feature!, product Tagged: globalization, international software, internationalization, multi-language software, TeX, translation <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/241/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=241&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2009/12/02/internationalisation-in-trustbearer-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/77487f56af0d1e77c9730b7b6b64762b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">taylorvenable</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/12/red-flags.jpg" medium="image">
			<media:title type="html">red-flags</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/12/blue-flags.jpg" medium="image">
			<media:title type="html">blue-flags</media:title>
		</media:content>
	</item>
		<item>
		<title>Bureaucrats with Badges</title>
		<link>http://openidtrustbearer.wordpress.com/2009/11/24/bureaucrats-with-badges/</link>
		<comments>http://openidtrustbearer.wordpress.com/2009/11/24/bureaucrats-with-badges/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 15:09:28 +0000</pubDate>
		<dc:creator>stevepepple</dc:creator>
				<category><![CDATA[government]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[public key infrastructure]]></category>
		<category><![CDATA[smartcard]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[badges]]></category>
		<category><![CDATA[CAC]]></category>
		<category><![CDATA[common access card]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[hspd-12]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[military]]></category>
		<category><![CDATA[military identification]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=252</guid>
		<description><![CDATA[There was a peculiar piece in the American Spectator online last week, a &#8220;Special Report&#8221; by Mark Hyman. The author lists a number of unfortunate circumstances by which harmless passengers, many times military personnel, have been delayed or hassled by &#8230; <a href="http://openidtrustbearer.wordpress.com/2009/11/24/bureaucrats-with-badges/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=252&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://openidtrustbearer.files.wordpress.com/2009/11/authorized-personnel1.jpg"><img class="alignnone size-full wp-image-263" title="authorized-personnel" src="http://openidtrustbearer.files.wordpress.com/2009/11/authorized-personnel1.jpg?w=500" alt=""   /></a></p>
<p>There was a peculiar piece in the American Spectator online last week, <a href="http://spectator.org/archives/2009/11/20/bureaucrats-with-badges">a &#8220;Special Report&#8221; by Mark Hyman</a>. The author lists a number of unfortunate circumstances by which harmless passengers, many times military personnel, have been delayed or hassled by TSA and airport security protocols. He blames these anecdotal mishaps on &#8220;government bureaucrats armed with &#8216;rules, policies and procedures&#8217; and employing no commonsense.&#8221;</p>
<p>He goes on to question a number of security and procedural policies in government and military institutions, which he thinks are unnecessary and demeaning to the personnel at these institutions. As a primary example, Hyman makes the case that the rules for issuing and renewing CACs (Common Access Cards) are unneeded and absurd.</p>
<p>He is miffed because he did not renew his CAC before it expired and he had to go though a bureaucratic process to straighten this out:</p>
<blockquote><p>&#8220;My CAC had expired days earlier so I contacted an issuing office to get a replacement. A clerk in the ID card office informed me that all appointments had to be made online using the intranet. Yet, my expired CAC prevented me from using the intranet system. In spite of my predicament the clerk told me, &#8220;Our policy requires all appointments to be scheduled online. If you are unable to use the intranet, then there is nothing more I can do.&#8221; It sounded like the beginning of an Abbott and Costello routine.&#8221;</p></blockquote>
<blockquote><p>&#8220;Rather than fight this particular battle, I decided to renew my CAC at another issuing office. While there, I was asked to produce a picture ID. I showed my state driver&#8217;s license. I was then asked for a second form of ID and was told the CAC was not acceptable since it expired five days earlier. A week earlier it would have been valid, but on this day it was deemed worthless. So I showed the clerk my company-issued ID card that looked as though it was made on an office computer and laminated at the local Kinko&#8217;s. As a matter of fact, that was exactly how that ID was manufactured. But it was good enough. The clerk accepted the flimsy company ID over the just-expired military CAC.&#8221;</p></blockquote>
<p>Hyman concludes,</p>
<blockquote><p>&#8220;What makes this episode even sadder is that the military CAC is generally not accepted as a valid form of identification for use by visitors to the Pentagon. Visitors must also have a Pentagon-issued ID or another form of identification such as a state driver&#8217;s license. The reason, according to a security officer, is that at least one machine that manufactures CACs and several hundred blank CACs are missing and presumed to have been stolen. Security officials do not know which CAC is valid and which is a forgery.&#8221;</p></blockquote>
<p>The latter claim is nonsensical and shows that the security officials Hyman chats with are miss informing him about how his CAC works. This too, expresses a common misconception— that possession of the card is the only thing that verifies identity.</p>
<p>To his point about the pains of standing in line to renew something only to find that you don&#8217;t have the right materials: I can empathize with this, but I cannot gather what rules Hyman thinks are silly, and which are reasonable. Is he arguing that he shouldn&#8217;t have to have a CAC, or that he should be able to use his expired CAC, by itself, for renewal? And what does this have to do with policy created by top-level military and government officials?</p>
<p>What is clear from reading the piece is that he doesn&#8217;t like the rules much because he doesn&#8217;t understand why they are in place. He wanted an exception so he could use his expired CAC. Similarly, in another of his examples, he complains that his wife couldn&#8217;t renew her own CAC using an expired passport.</p>
<p>There are two fundamental questions that would help Hyman better appreciate these rules: Why are identification badges, such as CAC cards, used? And, how is the true identity of a badge-holder verified? In other words, what is a CAC good for anyways?</p>
<p>The military provides several <a href="http://cac.mil/Getting.html">resources for answering these questions</a>. In fact, had Hyman consulted these, or <a href="http://blunoz.blogspot.com/2009/08/pentagon-gouge-cac-cards.html">unofficial resources</a>, anytime before his CAC expired he would have had less of a hassle renewing it.</p>
<p>Identity, and the privileges we associate with it, is an abstract thing that is difficult to verify. The best way for a large institutions to verify a person&#8217;s identity is to gather the various artifacts of identity, such as a state driver&#8217;s license, for this person and grade the validity of these items and the authority of the institution who gave the item.  The bureaucratic pronouncements on this process (i.e. <a href="http://www.dhs.gov/xabout/laws/gc_1217616624097.shtm#1">presidential directives</a> and <a href="http://www.cac.mil/assets/pdfs/DTM%2012-1-2008-08872-08.pdf">policies</a>) say that the best way to verify the identity and authorization of millions of people is to create a system of rules that make the procedures repeatable, reliable, and safe. (One such rule may reason that an expired identity artifact should not be considered valid, even if it was valid yesterday.)</p>
<p>Now, the process of using a CAC card is not as simple as it could be. Systems that use badges for the identification of people and the verification of people&#8217;s permissions and authority are complex and imperfect, but this is not a problem of bureaucracy. It&#8217;s more a matter of improving these systems for most users and reminding users, like Hyman, why they were given a badge to begin with.</p>
<br />Posted in government, healthcare, public key infrastructure, smartcard Tagged: authentication, badges, CAC, common access card, dod, hspd-12, identity, military, military identification <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/252/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=252&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2009/11/24/bureaucrats-with-badges/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3b7ca1b72060225b355161d93698cbe3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevepepple</media:title>
		</media:content>

		<media:content url="http://openidtrustbearer.files.wordpress.com/2009/11/authorized-personnel1.jpg" medium="image">
			<media:title type="html">authorized-personnel</media:title>
		</media:content>
	</item>
		<item>
		<title>Interview with Eugene Spafford</title>
		<link>http://openidtrustbearer.wordpress.com/2009/11/12/interview-with-eugene-spafford/</link>
		<comments>http://openidtrustbearer.wordpress.com/2009/11/12/interview-with-eugene-spafford/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 15:44:15 +0000</pubDate>
		<dc:creator>stevepepple</dc:creator>
				<category><![CDATA[government]]></category>
		<category><![CDATA[CERIAS]]></category>
		<category><![CDATA[gene spafford]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[internet secruity]]></category>
		<category><![CDATA[security education]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://blog.trustbearer.com/?p=239</guid>
		<description><![CDATA[TrustBearer is located in Indiana and—as it might be expected— several members of the company, including the company&#8217;s founder, are graduates of Purdue University, in Lafayette, IN. A couple of TrustBearer&#8217;s Purdue alums studied at the Center for Education and &#8230; <a href="http://openidtrustbearer.wordpress.com/2009/11/12/interview-with-eugene-spafford/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=239&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>TrustBearer is located in Indiana and—as it might be expected— several members of the company, including the company&#8217;s founder, are graduates of Purdue University, in Lafayette, IN. A couple of TrustBearer&#8217;s Purdue alums studied at the <a href="http://www.cerias.purdue.edu/"><em>Center for Education and Research in Information Assurance and Security</em></a> (CERIAS), under the direction of Gene Spafford.</p>
<p>Gene Spafford is a well-known programmer, researcher, and educator in the field of computer and information security. He is perhaps <a href="http://itknowledgeexchange.techtarget.com/security-bytes/how-the-morris-worm-foretold-the-future-of-computer-security/">best known</a> for his analysis of the first internet-distributed worm in 1988, the Morris worm. He also has a knack for punch <a title="List of Spafford's Security Analogies" href="http://homes.cerias.purdue.edu/~tripunit/spaf-analogies.html">security metaphors</a>.</p>
<p>Spafford was recently <a href="http://www.govinfosecurity.com/articles.php?art_id=1789&amp;opg=1">interviewed by Tom Field of the Information Security Media Group</a>. It&#8217;s a thoughtful, thorough interview, which is well worth sharing. The subject of the interview concerns information assurance education. Spafford was asked about the current state of information assurance:</p>
<blockquote><p><strong>SPAFFORD:</strong> Well, it is still rather chaotic. There are a range of issues and priorities within the field where education can be directed; some of the education is directed towards people who are practitioners, who are going to be on the front lines running systems. Some are oriented towards management-type positions that are setting policies and ensuring compliance. And there still is a community focused on the research aspects, more how to solve problems that are just emerging.</p></blockquote>
<blockquote><p>We don&#8217;t really have a common curriculum that runs across these, although there are a couple efforts that are underway to try define parts of it, and it is isn&#8217;t really certain what the best practices are, what the background expertise should be for these positions. So it is still an area that is evolving quite rapidly.</p></blockquote>
<p>In the interview, Spafford also talks about how information assurance and security have changed over the past couple of decades:</p>
<blockquote><p>When I really saw the start of this field in the late 80&#8242;s and early 90&#8242;s, most of the people who were involved had a deep understanding of issues of machine architecture, encoding, network protocols, and really understood the systems at a low-level. What we see now for many educational institutions is they are focusing on high-level applications, web security, JAVA, running prepackaged firewalls and IDS systems, and many of the people going to that educational path are not exposed to those low-level details, even though some of the attackers are exploiting those low-level details. So we have seen a split off of that kind of expertise in two areas, both the research arena and also some in the forensics arena.</p>
<p>But of course the field has also grown; the level of threat has changed significantly. If we go from the late 80&#8242;s/early 90&#8242;s, there wasn&#8217;t any commercial use of the Internet, and it didn&#8217;t have the global reach it does now. So the issues of social engineering, fraud, phishing, many of the other kinds of false information presentation and mailed-around exploits didn&#8217;t exist back then. So we have seen a huge evolution in the threat picture, in the target set, and in the overall understanding of what security in computing is all about.</p></blockquote>
<p><strong>Related Links</strong></p>
<p><a href="http://www.c-spanvideo.org/program/284210-7">Spafford Interview on C-SPAN</a> An expansive (30 min) general interest interview with Spafford on the state of internet security and identity protection.</p>
<p><a href="http://www.nytimes.com/2009/02/15/weekinreview/15markoff.html?_r=2&amp;pagewanted=all">Do We Need a New Internet?</a> New York Times piece on the future of internet security, including a discussion of Spafford&#8217;s work.</p>
<br />Posted in government Tagged: CERIAS, gene spafford, information assurance, internet secruity, security education, worms <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/openidtrustbearer.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/openidtrustbearer.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/openidtrustbearer.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/openidtrustbearer.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/openidtrustbearer.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/openidtrustbearer.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/openidtrustbearer.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/openidtrustbearer.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/openidtrustbearer.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/openidtrustbearer.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/openidtrustbearer.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/openidtrustbearer.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/openidtrustbearer.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/openidtrustbearer.wordpress.com/239/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=openidtrustbearer.wordpress.com&amp;blog=2855421&amp;post=239&amp;subd=openidtrustbearer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://openidtrustbearer.wordpress.com/2009/11/12/interview-with-eugene-spafford/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3b7ca1b72060225b355161d93698cbe3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevepepple</media:title>
		</media:content>
	</item>
	</channel>
</rss>
