<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Venn Factory: The Workshop]]></title><description><![CDATA[Tangled musings on identity, privacy, trust, and suchlike, from founder Eve Maler]]></description><link>https://workshop.vennfactory.com</link><image><url>https://substackcdn.com/image/fetch/$s_!ncoP!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0cb08-bbc9-42ed-ada9-410851c80861_1280x1280.png</url><title>Venn Factory: The Workshop</title><link>https://workshop.vennfactory.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 05 Apr 2026 16:22:57 GMT</lastBuildDate><atom:link href="https://workshop.vennfactory.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Venn Factory, LLC]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[vennfactory@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[vennfactory@substack.com]]></itunes:email><itunes:name><![CDATA[Eve Maler]]></itunes:name></itunes:owner><itunes:author><![CDATA[Eve Maler]]></itunes:author><googleplay:owner><![CDATA[vennfactory@substack.com]]></googleplay:owner><googleplay:email><![CDATA[vennfactory@substack.com]]></googleplay:email><googleplay:author><![CDATA[Eve Maler]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Knowledge-based verification: is it state-of-the-art?]]></title><description><![CDATA[Testimony to the Vermont House Committee on Commerce and Economic Development]]></description><link>https://workshop.vennfactory.com/p/knowledge-based-verification-is-it</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/knowledge-based-verification-is-it</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Thu, 12 Mar 2026 17:13:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9ORS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9ORS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9ORS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 424w, https://substackcdn.com/image/fetch/$s_!9ORS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 848w, https://substackcdn.com/image/fetch/$s_!9ORS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 1272w, https://substackcdn.com/image/fetch/$s_!9ORS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9ORS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png" width="1286" height="724" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:724,&quot;width&quot;:1286,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1542628,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/190744769?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9ORS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 424w, https://substackcdn.com/image/fetch/$s_!9ORS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 848w, https://substackcdn.com/image/fetch/$s_!9ORS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 1272w, https://substackcdn.com/image/fetch/$s_!9ORS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1f09b0-13eb-4716-814d-af81d95038cc_1286x724.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This week I had an exciting new experience: testifying to a state legislative committee. The Vermont House of Representatives is working on a bill (<strong>H. 211 - an act relating to data brokers and personal information</strong>) addressing a modern question: how to protect consumers&#8217; personal data given the realities of the data monetization ecosystem? I met Vermont State Rep. Monique Priestley through a kind recommendation from <a href="https://internetsafetylabs.org">Internet Safety Labs</a>&#8217; executive director Lisa LeVasseur, and Rep. Priestley asked me to help educate the <a href="https://legislature.vermont.gov/committee/agenda/2026/3552">House Committee on Commerce and Economic Development</a> about identity verification. Following is a rough testimony transcript. The recording is <a href="https://youtu.be/w1LZhIX9DSE?t=1119">here</a>, and the resources I referenced are <a href="https://legislature.vermont.gov/Documents/2026/Workgroups/House%20Commerce/Bills/H.211/Witness%20Documents/H.211~Eve%20Maler~Follow%20Up%20Testimony,%20Sources%20Referenced~3-11-2026.pdf">here</a>.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>Thank you Chair Marcotte, Vice Chair Graning, and members of the committee.</p><p>My name is Eve Maler.</p><p>I&#8217;m the founder and president of digital identity advisory firm Venn Factory and author of the forthcoming book <em><strong><a href="https://masteringdigitalidentity.com/">Mastering Digital Identity: From Risk to Revenue</a></strong></em>.</p><p>I&#8217;ve been in the digital identity sector since the year 2000, when I worked with colleagues across the industry to start and run the committee that designed the SAML standard &#8212; Security Assertion Markup Language, the first open standard for single sign-on across business entities.</p><p>Most recently I was Chief Technology Officer of ForgeRock, an identity and access management platform provider serving banks, government agencies, healthcare providers and payers, and many others.</p><p>In 2016 I testified to the API Privacy and Security Task Force of the US Health and Human Services Office of the National Coordinator.</p><p>I want to thank Representative Priestley for sharing some questions with me ahead of time to ensure I addressed issues of concern.</p><p><strong>Let me start with some background on Know Your Customer, or KYC.</strong></p><p>KYC is a legal requirement under the Bank Secrecy Act.</p><p>It obliges financial institutions to confirm the real-world identity of their customers &#8212; in other words, to establish that a person is who they say they are &#8212; before opening accounts or conducting transactions.</p><p>Its purpose is to prevent financial crime: money laundering, fraud, and the financing of illegal activity.</p><p>This is a real and important obligation.</p><p>In technical terms, what KYC requires is called identity verification, or IDV.</p><p>What it does not require is any particular method of verification.</p><p>A bank can satisfy its KYC obligations using a driver&#8217;s license scan, a biometric match against a passport, or a government-issued digital credential.</p><p>It can also use a quiz drawn from a data broker&#8217;s database &#8212; but that approach, known as knowledge-based verification, or KBV, is the one that federal security standards have now explicitly prohibited.</p><p>KBV questions look like: what street did you live on in 2010, what&#8217;s your mother&#8217;s maiden name, what was your first car?</p><p>All of that information exists in data broker databases &#8212; that&#8217;s where the questions come from.</p><p>I&#8217;ll come back to why that&#8217;s a problem.</p><p>The reason this distinction matters is that we&#8217;ve been hearing that financial institutions need broad access to data broker data for KYC.</p><p>That framing is accurate in the sense that KYC requires verification &#8212; but it conflates the legal obligation with one specific, outdated implementation choice.</p><p>KYC doesn&#8217;t require data broker data.</p><p>Some institutions have chosen to use data broker data for a particular approach to KYC.</p><p>That&#8217;s an approach that federal guidelines have moved away from.</p><p>And that move away is not the same thing as KYC being impossible without data brokers.</p><p><strong>OK. Why does the National Institute of Standards and Technology no longer consider KBV to be strong evidence for identity verification?</strong></p><p>If an institution is using KBV, it means they&#8217;re using an approach the federal government&#8217;s top technical standards body has formally abandoned.</p><p>In fact, NIST&#8217;s current guidelines, updated in 2025, now explicitly prohibit KBV for identity verification.</p><p>An institution still relying on it is behind the curve on security, not leading it.</p><p><strong>If a financial institution is buying data broker data to perform KBV, what does that mean for the integrity of the verification process?</strong></p><p>It means the supposed secret underlying the method isn&#8217;t secret anymore.</p><p>KBV works only if the answers are known to the applicant and no one else.</p><p>Data broker databases have been breached repeatedly &#8212; most dramatically in 2024, when a single breach allegedly exposed up to 2.9 billion records on an estimated 170 million people in the US, UK, and Canada.</p><p>If a fraudster can buy the same answers the verification system expects, the quiz doesn&#8217;t distinguish between the real person and an impostor.</p><p>Let&#8217;s look at the implications of KBV specifically on security. <strong>What does continued use of KBV-based KYC tell us about the security posture of banks and insurers still using it?</strong></p><p>It tells you they&#8217;re optimizing for low cost, not for security or even for a smooth and pleasant user experience.</p><p>KYC is a legal compliance requirement; how you meet it is a choice.</p><p>Using quiz questions based on purchasable consumer data is one of the cheapest ways to check a KYC box, and one of the weakest from both the security and usability standpoints.</p><p>Better alternatives exist; institutions that aren&#8217;t using them have made a deliberate tradeoff.</p><p>Let&#8217;s look at the quality of the personal data in these systems. <strong>How accurate and current is personal data that flows through commercial data brokers?</strong></p><p>The data is unreliable by its very nature.</p><p>Brokers aggregate data from many sources without authoritative correction mechanisms, so records go stale and errors propagate.</p><p>A 2019 peer-reviewed study found that at least 40% of data broker attributes were inaccurate &#8212; and a 2014 Federal Trade Commission (FTC) report reached similar conclusions.</p><p>No federal audit standard has been established in the years since either finding.</p><p>The consumer typically has no way to know their record is wrong, let alone fix it.</p><p>Let&#8217;s look at potential alternatives.</p><p><strong>What verification methods have replaced KBV in modern financial services, and are they available to smaller institutions?</strong></p><p>Document verification &#8212; scanning a driver&#8217;s license or passport combined with a live photo match &#8212; has become the baseline for secure identity verification.</p><p>It&#8217;s available to institutions of any size through pay-per-transaction vendor services.</p><p>KYC-quality document verification typically runs around $1 per check.</p><p>KBV runs $0.20&#8211;$0.50, with volume discounts that can reach $0.10 at scale.</p><p>That gap is real, and smaller institutions that can&#8217;t negotiate volume discounts will feel it more acutely than large ones.</p><p>But the economics look different once you account for fraud exposure &#8212; and for the hidden costs within KBV itself.</p><p>For example, when a user mistypes an answer &#8212; which happens regularly &#8212; the system triggers manual review, which costs more than the automated check and can take up to a day to resolve.</p><p>That degrades both the economics and the customer experience.</p><p>Let&#8217;s look specifically at the needs of smaller financial institutions.</p><p><strong>If a smaller institution needed to transition away from KBV, is that technically feasible? And does it improve security?</strong></p><p>The answers are yes and yes.</p><p>The technical work is integration &#8212; connecting to an existing vendor service.</p><p>It is a bounded, solvable problem, not a novel engineering challenge.</p><p>And the resulting security posture is substantially better: document verification is much harder to defeat than a quiz based on purchasable data, because the attacker needs the physical credential, not just information they can buy.</p><p><strong>You might wonder, what happens if a consumer deletes their data from a broker? Do things break?</strong></p><p>The concern is less substantial than it sounds, for two compounding reasons &#8212; one practical, and one analytical.</p><p>The practical one: complete deletion from the data broker ecosystem is actually very difficult to achieve.</p><p>Brokers use each other as data sources, so the same attributes propagate across multiple databases.</p><p>A deletion from one broker typically leaves the same record intact in others that sourced from it or share the same upstream inputs.</p><p>The disruption to KBV pipelines that critics warn about is therefore largely theoretical.</p><p>The analytical one: even if deletion did succeed, the data being retained was either inaccurate or accurate &#8212; and neither scenario supports keeping it.</p><p>Inaccurate data was already generating wrong verification outcomes, so removing it is a correction, not a loss.</p><p>Accurate data is exactly what a fraudster wants to acquire; its continued presence in a broker database isn&#8217;t protective &#8212; it&#8217;s a standing liability.</p><p>The risks run in different directions, but the conclusion is the same: the case for retaining this data in a broker&#8217;s hands is weaker than the deletion concern implies.</p><p><strong>Is it reasonable for a financial institution or insurer to argue at this point, in 2026, that they can&#8217;t operate without broad, unrestricted data broker access?</strong></p><p>No, not for KYC compliance purposes.</p><p>NIST has explicitly prohibited KBV &#8212; the primary use case being mooted&#8212; since 2025, and alternatives are commercially available.</p><p>The argument is better characterized as a preference for low-cost, legacy workflows than a general operational necessity.</p><p>Narrow, purpose-based exemptions for specific legitimate uses (fraud detection or sanctions screening) can be evaluated on their merits, and as I understand it, the bill has already done the careful work of identifying which uses justify overriding a deletion request.</p><p>Finally:</p><p><strong>What happens to deceased persons&#8217; data in broker databases, and what risks does that create?</strong></p><p>Deceased individuals&#8217; records persist indefinitely in most broker databases &#8212; brokers have no authoritative, real-time connection to official death records.</p><p>That stale data creates two distinct risks.</p><p>The first is identity fraud: a deceased person&#8217;s KBV answers still work, and their data can be used to open fraudulent accounts or to impersonate them in scams targeting surviving family members.</p><p>The second is operational error: incorrect or incomplete death records cause problems in legitimate claims processing.</p><p>Both argue for better data sourcing, not more data accumulation.</p><p>I co-chair a group called Death and the Digital Estate Community Group, DADE, at the OpenID Foundation, which recently published a white paper on relevant topics here.</p><p><strong>Rep. Priestley:</strong> <em>We have a related bill, and in order to consider future use cases as well: what about mobile driver&#8217;s licenses?</em></p><p>Mobile driver&#8217;s license technology is an instance of what&#8217;s known as decentralized identity and verifiable credentials in the identity industry. That&#8217;s new technology that has come onto the scene for delivering verification in a reusable fashion. Let&#8217;s examine it briefly.</p><p><strong>What about mobile driver&#8217;s licenses &#8212; are those a viable path forward for Vermont institutions?</strong></p><p>Mobile driver&#8217;s licenses are a promising direction, but Vermont hasn&#8217;t deployed them yet &#8212; and they&#8217;re not a prerequisite for institutions that want to transition away from KBV today.</p><p>A financial institution verifying identity through a standard vendor API against a physical driver&#8217;s license or passport doesn&#8217;t strictly need a state mDL program.</p><p>That path is available now.</p><p><strong>Rep. Cooper:</strong> <em>I think what I&#8217;m largely hearing is arguments against this legislation that pertain to what we have to do to Know Your Customer &#8212; you&#8217;re saying, one, NIST is saying this is not the best way to go about things. It&#8217;s also, as you said, a preference. I hear a lot about, well, that&#8217;s a cost we have to pass along to the consumer. I&#8217;d like you to spend a little bit more time on the viable alternatives you were describing. I think you&#8217;re saying that Know Your Customer goes back 50 some-odd years, and we&#8217;re looking at an early iteration of how it made sense to do that work.</em></p><p><em>We have crossed that Rubicon thirty times over technologically, and we still are using an older approach, a more Mayberry RFD sort of era. What I&#8217;m also trying to get at is, is that doomed to happen to every single data type that we might be looking at technologically, that they become relics and I don&#8217;t believe their usefulness?</em></p><p>The challenge with cybersecurity and with fraud, which is a close cousin, is that it&#8217;s an arms race, so to speak. And bad actors are improving their techniques. Like one of the techniques is AI deepfakes, for example, which can also impact things like the recognizing of things like passports and physical driver&#8217;s licenses.</p><p>So they&#8217;re not immune either from this kind of degradation over time. You may be familiar with SMS OTPs, texted one-time passwords that we frequently get. That&#8217;s another method that NIST has deprecated over time. And we could be grateful that NIST has been keeping up with the technology and also that KYC rules do not specify the method so that we can keep up as different methods degrade over time.</p><p>Right now, there&#8217;s quite a lot of innovation in the identity verification space. We did not have some of the biometrically rooted methods five years ago and they&#8217;ve been innovating very quickly. These are coming online, and they are not only becoming available to smaller and smaller institutions, but there&#8217;s price pressure downward as well.</p><p>I will mention from my experience working with retailers, so not necessarily under a KYC requirement, but they often have a need to do identity verification &#8212;it used to cost maybe $5, $10, $15 per verification, but getting that customer on board was so valuable, it was worth the price of admission, so to speak.</p><p>So it is possible for the trade-off in terms of security protection and fraud protection to be so great that even a $1 cost, or even a little more than a $1 cost, which might be going down soon enough, might be quite available, especially to smaller institutions who are not onboarding that many new bank customers in any one month or year.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Venn Factory: The Workshop! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Signals that led into 2026]]></title><description><![CDATA[Links unearthed in recent Venn Shortlist roundups, and retrospective observations]]></description><link>https://workshop.vennfactory.com/p/signals-that-led-into-2026</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/signals-that-led-into-2026</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Tue, 13 Jan 2026 18:13:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yXOE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yXOE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yXOE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 424w, https://substackcdn.com/image/fetch/$s_!yXOE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 848w, https://substackcdn.com/image/fetch/$s_!yXOE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 1272w, https://substackcdn.com/image/fetch/$s_!yXOE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yXOE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png" width="1456" height="835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:248629,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/184352175?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yXOE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 424w, https://substackcdn.com/image/fetch/$s_!yXOE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 848w, https://substackcdn.com/image/fetch/$s_!yXOE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 1272w, https://substackcdn.com/image/fetch/$s_!yXOE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce2e889b-eaf9-4f9c-b2a2-ef9f8a3c9141_1730x992.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://stacktower.io/#gallery/python/openai">stacktower.io Depdendency Tower Gallery</a> (see last section below!)</figcaption></figure></div><p>I&#8217;ve been sharing a few carefully selected links on my <a href="https://www.linkedin.com/company/vennfactory/">Venn Factory LinkedIn page</a> every month for a while now. With 2025 in the rear-view mirror, I thought it might be a useful exercise to cast an eye over the last few batches and see what story they tell now. Think of this exercise as &#8220;reverse predictions.&#8221;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h3>&#127968; September: assessing the health of our foundations</h3><p>This month provided a bit of hope inside a &#8220;warning sandwich.&#8221; The item I&#8217;ve had the most conversations about in the intervening months was the third piece from Ross Haleliuk, connecting it to the chaos of the identity standards landscape and the continuing struggle to find market use cases for certain protocol stacks.</p><h4><strong>&#9888;&#65039; <a href="https://www.theregister.com/2025/08/29/ai_web_crawlers_are_destroying/">AI web crawlers are destroying websites in their never-ending hunger for any and all content</a></strong></h4><p>We&#8217;ve all heard about the risk &#8212; or reality &#8212; of a &#8220;dead Internet,&#8221; where AI-generated content simply gets recycled into new model training. This piece explores the mounting pressure AI crawling puts on the already shrinking &#8220;open Web,&#8221; as more content shifts into identity-walled gardens.</p><blockquote><p>&#8220;Yes, of course, we can try to fend them off with logins, paywalls, CAPTCHA challenges, and sophisticated anti-bot technologies. You know one thing AI is good at? It's getting around those walls.&#8221;</p></blockquote><h4><strong>&#128200; <a href="https://www.lawfaremedia.org/article/are-cyber-defenders-winning">Are Cyber Defenders Winning?</a></strong></h4><p>Unlike a soccer match, cyberspace offers no final whistle. This article digs into how we might measure whether defenders are gaining an edge in what feels like an endless, invisible contest.</p><blockquote><p>&#8220;There is sufficient data across these indicators to point to a far more optimistic assessment than suggested by dystopian headlines.&#8221;</p></blockquote><h4><strong>&#9888;&#65039; <a href="https://ventureinsecurity.net/p/in-security-not-every-industry-problem">In security, not every industry problem is a business problem</a></strong></h4><p>In digital identity, open standards are often the solutions to &#8220;industry problems.&#8221; Ross Haleliuk makes the case that industry-wide problems are tougher to tackle than business problems &#8212; raising the question: Are we focusing on the right ones at the right time?</p><blockquote><p>&#8220;Many people with great ideas about how to improve security would be way happier championing a new standard, building a non-profit initiative, or an open source project.&#8221;</p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/signals-that-led-into-2026/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/signals-that-led-into-2026/comments"><span>Leave a comment</span></a></p><div><hr></div><h3>&#9878;&#65039; October: hunting for accountability</h3><p>This was an active theme all last year given the move to AI agents, and it&#8217;s still not that close to being solved. Who acts? Who benefits? Who is liable? And how do we preserve trust when agency is distributed?</p><h4><strong>&#129317; <a href="https://kaystoner.substack.com/p/unpacking-sentiment-and-emotional">Unpacking Sentiment and Emotional Manipulation in Relational AI</a></strong></h4><p>Kay Stoner is a prolific relational AI researcher and problem-solver. Here she identifies &#8212; and teaches us how to mitigate &#8212; dark patterns used by AI chatbots. These insights illuminate how to avoid human-perpetrated social engineering as well.</p><blockquote><p>&#8220;Relationally responsible AI must avoid using emotional reinforcement to build rapport, simulate fast trust, or mask structural limitations. Instead, it should hold space with neutrality, clarity, and honest boundaries &#8212; allowing the user to lead the emotional frame of the exchange without being manipulated by artificial warmth or simulated care.&#8221;</p></blockquote><h4><strong>&#128176; <a href="https://www.linkedin.com/posts/richardcrone_agentic-commerce-kills-guest-checkout-activity-7377045717116399616-0q4j/">Blind guest checkout will collapse under the weight of agentic commerce</a></strong></h4><p>As agentic commerce takes hold &#8212; with bots buying on our behalf &#8212; Know Your Agent must be built atop Know Your Customer. This post explores the coming decline of guest checkout and its implications for fraud, accountability, and shopper anonymity.</p><blockquote><p>&#8220;[A]llowing #AgenticPayments into ecommerce sites without verifying humanness &amp; intent is a recipe for fraud, data scalping &amp; disintermediation.&#8221;</p></blockquote><h4><strong>&#127917; <a href="https://judgeschlegel.substack.com/p/what-happens-when-ai-deepfakes-fool">What Happens When AI Deepfakes Fool a Judge?</a></strong></h4><p>This post from a US appellate court judge was prescient. It marked a case dismissed with prejudice over deepfaked video evidence. New forensic standards will need to enable higher evidentiary standards &#8212; quickly and without burdening courts further. (This author has also released a <a href="https://substack.com/home/post/p-173711419">guide</a> for using AI in chambers.)</p><blockquote><p>&#8220;As you know, judges are already managing heavy caseloads so if every disputed voicemail, video, or screenshot required a forensic investigation, the system would collapse under its own weight.&#8221;</p></blockquote><div><hr></div><h3>&#127756; November: the emergent identity-payments axis</h3><p>I&#8217;ve long called identity and payments a &#8220;binary star&#8221; (and double down on that analysis in my <a href="https://masteringdigitalidentity.com/">forthcoming book</a>, <em><strong>Mastering Digital Identity</strong></em>). This month&#8217;s theme tugged on new connections forming between the two, which only continue to deepen.</p><h4><strong>&#129706; <a href="https://idtechwire.com/ledger-rebrands-hardware-wallets-signers-proof-of-you/">Ledger Rebrands Hardware Wallets as &#8216;Signers,&#8217; Launches &#8216;Proof of You&#8217; to Combat AI Fraud</a></strong></h4><p>The Web3 world, long focused on adding a payment layer to the Internet via blockchain, is finally turning its gaze to identity. Hardware wallet provider Ledger has rebranded its product line to enable &#8220;Proof of You&#8221; capabilities &#8212; marking a real shift toward trust and verification in Web3 ecosystems.</p><blockquote><p>&#8220;Proof of You is designed to verify that the genuine user, not a deepfake or cloned entity, is initiating an action in the digital environment.&#8221;</p></blockquote><h4>&#129705; <strong><a href="https://www.linkedin.com/pulse/algorithm-your-mirror-how-ai-co-writes-identity-james-w-w7tzc/">The Algorithm Is Not Your Mirror: How AI Co-Writes Your Identity</a></strong></h4><p>Consumers are wising up and starting to &#8220;assume tracking.&#8221; As Smoke Signal puts it, &#8220;The Algorithm is not your mirror&#8221; &#8212; it doesn&#8217;t just reflect behavior, it shapes it. This piece is packed with insights on how data feedback loops mold digital humans, plus a practical list of mitigation strategies.</p><blockquote><p>&#8220;You don&#8217;t have to be famous to have an algorithmic twin. If you&#8217;ve ever liked a post, used a smart speaker, or shared a selfie, the loop has already started.&#8221;</p></blockquote><h4>&#129689; <strong><a href="https://www.linkedin.com/feed/update/urn:li:ugcPost:7386413419450781696/">Stablecoins, Loyalty, and Brand Wallets</a></strong></h4><p>With new regulatory support under the US GENIUS Act, stablecoins are stepping into the mainstream, and unlocking the potential for &#8220;brand wallets&#8221; that turn loyalty points into real assets. It&#8217;s the ultimate identity-first strategy: blending Protection, Personalization, Payments, and People into one connected layer.</p><blockquote><p>&#8220;The GENIUS Act quietly made that possible &#8212; giving brands like Disney, Amazon, and Starbucks a legal path to act as banks without the rules. &#8230; The GENIUS Act quietly made that possible &#8212; giving brands like Disney, Amazon, and Starbucks a legal path to act as banks without the rules.&#8221;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Venn Factory: The Workshop&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Venn Factory: The Workshop</span></a></p></blockquote><div><hr></div><h3>&#128207; December: inches, not miles</h3><p>In the final month of 2025, I found signals about where progress is real, where it&#8217;s limited, and where paying attention matters most.</p><h4><strong>&#127822; <a href="https://www.kuppingercole.com/blog/kuppinger/apples-digital-id-move-helpful-progress-but-not-yet-the-breakthrough">Apple&#8217;s Digital ID Move: Helpful Progress, but Not Yet the Breakthrough</a></strong></h4><p>You would expect this announcement to be earth-shattering in the identity world. It wasn&#8217;t. Martin Kuppinger's take is realistic and incisive in explaining why Apple&#8217;s move matters, and why it still stops short of what many are waiting for.</p><blockquote><p>&#8220;[V]isibility should not be mistaken for completeness. &#8230; It does not reflect the larger objective of building a reusable, attribute-rich identity framework composed of verifiable credentials.&#8221;</p></blockquote><h4>&#128066; <strong><a href="https://mydata.org/2025/11/25/when-children-design-ai-what-we-learned-by-actually-listening/">When Children Design AI: What We Learned by Actually Listening</a></strong></h4><p>People&#8217;s technology needs are usually light years away from what technology gives them. That&#8217;s why People has its own pillar in my Four Ps framework. This research from MyData listens directly to children about what they want and need from AI; the gap it reveals is striking.</p><blockquote><p>&#8220;The children in this workshop consistently returned to themes central to MyData: transparency about how their data is used, control over when and how technology operates in their lives, and the right to understand and question the systems around them.&#8221;</p></blockquote><h4><strong>&#128218; <a href="https://stacktower.io">Stacking Dependencies</a></strong></h4><p>In a talk at Identiverse 2023 (<a href="https://www.vennfactory.com/contact">reach out</a> if you&#8217;d like the slides), I asked whether subsidiarity &#8212; the principle that power is best applied hyperlocally &#8212; can save decentralization. Trying to decentralize control often falls prey to insidious re-centralization. What helps is transparency, exposing dependencies, and making them measurable. This neat XKCD-style app does exactly that. See the image up top for an awesome sample.</p><blockquote><p>&#8220;Staring at an NP-hard problem, the obvious move is to nope out. But NP-hard isn't hopeless; it just means there is <em>no known shortcut for every case</em>.&#8221;</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UOHb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UOHb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!UOHb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!UOHb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!UOHb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UOHb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/184352175?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UOHb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!UOHb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!UOHb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!UOHb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e3189a3-2023-4913-bc30-ab844787dd27_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The first &#8220;conference season&#8221; of 2026 is shaping up, and I&#8217;m excited to get going &#8212; visiting the RSA conference in San Francisco in March, EIC in Berlin in May, and much more. If you&#8217;re interested to have me join your event to speak on <a href="https://masteringdigitalidentity.com/">Mastering Digital Identity</a> or other topics, please reach out!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.vennfactory.com/contact&quot;,&quot;text&quot;:&quot;Book a meeting or event&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.vennfactory.com/contact"><span>Book a meeting or event</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[A tale of two book writing journeys]]></title><description><![CDATA[An age ago, I coauthored a book. It&#8217;s taken me thirty years to write another.]]></description><link>https://workshop.vennfactory.com/p/a-tale-of-two-book-writing-journeys</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/a-tale-of-two-book-writing-journeys</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Tue, 23 Dec 2025 00:09:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qsWZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qsWZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qsWZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qsWZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qsWZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qsWZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qsWZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg" width="1456" height="897" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:897,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8299572,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/182325602?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qsWZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qsWZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qsWZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qsWZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ee3f7cd-ecb1-4662-a476-9dcb79d45b1a_4433x2732.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In 1994, XML didn&#8217;t exist yet, the World Wide Web was super-nascent, and the identity and access management discipline was premodern. I was an expert in the arcane incantations required to design Standard Generalized Markup Language (SGML) schemas, known as document type definitions (DTDs).</p><p>Jeanne El Andaloussi and I became fast friends ever since we found ourselves on the same side of my first standards table. She and I both advocated for the Open Software Foundation to use a standard SGML schema in delivering its software documentation &#8220;source code&#8221; to licensees such as our two companies (DEC and Groupe Bull).</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><p>The design methodology we codeveloped, and insisted on using to herd the dozen or so &#8220;OSF DTD&#8221; stakeholder cats, became the fodder for our book <em><strong><a href="https://archive.org/details/developingsgmldt0000male">Developing SGML DTDs: From Text to Model to Markup</a></strong></em>&#8212;published exactly 30 years ago, in print for ten amazing years, and now accessible only through the link above. Bless the Internet Archive!</p><p>I&#8217;m just wrapping up my second-ever book project, <em><strong><a href="https://masteringdigitalidentity.com/">Mastering Digital Identity: From Risk to Revenue</a></strong></em>, out real soon now. It&#8217;s targeted at enterprise executives who need help understanding why identity is critically important and what to do about it. (Follow along at the link to learn more.)</p><p>It&#8217;s an understatement to say times have changed. A few stories to illustrate&#8230;</p><h3>Speed and urgency</h3><p>The book I privately nicknamed &#8220;DSDTD&#8221; was contracted to be written in a year, and it took 19 months. While we felt some time pressure, the tech world still moved at a relatively stately pace then&#8212;at least as compared to now. Deliciously, over that time, Jeanne and I undertook several coauthoring sessions back and forth between my Boston home and hers in Paris.</p><p>During that time, I joined ArborText, a premier SGML authoring and publishing platform, to develop a DTD consulting practice. When I discovered that most of my clients were barred from accessing the new &#8220;WWW&#8221; at work, I realized we needed to add a sidebar in the book explaining what it was, along with its SGML roots.</p><p>These days, any book treating a technical topic has to be produced as fast as possible to stay relevant. Many are developed in full public view, for example on GitHub, serialized for early readers, and live-updated. I didn&#8217;t take that approach, but did complete the first draft in about four months.</p><h3>Publishing</h3><p>In the 1985-1994 decade, techdoc editing and publishing were my specialty, and I became an early adopter of the draft version of SGML (ISO 8879:1986) while working in the ULTRIX group at DEC. A passage in book #2 relates the zeitgeist.</p><blockquote><p>Back then, technical documentation was trapped on paper. If Boeing wanted to ship aircraft manuals, they literally shipped hundreds of pounds of paper. We were creating a way to &#8220;write once, publish everywhere.&#8221; The same content could be converted into a printed manual, a CD-ROM, or eventually a web page (although the web didn&#8217;t exist yet). I was designing information-capturing languages that machines could understand&#8212;protocols that allowed systems run by different companies to leverage the same digital information in a myriad of ways.</p></blockquote><p>Jeanne and I wrote DSDTD <em>in SGML</em>, using the <a href="https://en.wikipedia.org/wiki/DocBook">DocBook DTD</a> (to which I was an active contributor) and both ArborText&#8217;s and SoftQuad&#8217;s SGML editing software, proving interop. Our publisher had to find a specialty contractor who could translate all that through FrameMaker+SGML into something printable. Ron Turner of Soph-Ware was a lifesaver and became a friend.</p><p><em>Mastering Digital Identity</em> was born and mostly edited in GDoc, with Canva for graphics. Easy peasy!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/a-tale-of-two-book-writing-journeys?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/a-tale-of-two-book-writing-journeys?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>Timewasters</h3><p>I was excited to be working on Windows 3.11, with its brilliant color palette, to write DSDTD. When I needed a break, there was always Minesweeper. Along with Tetris (Tengen version), I could close my eyes and play whole Minesweeper games behind my eyelids.</p><p>Very soon, the world was introduced to infinitely scrollable reading and entertainment. My timewasting habits have never been the same since.</p><h3>AI</h3><p>Back then&#8230;surely you jest. It wasn&#8217;t an option.</p><p>This time around, I made a point of ensuring the writing was 100% human-generated. Not because I&#8217;m allergic to AI content, though honestly I&#8217;m not crazy about the faint whiff of caricature about most of it. In the current AI moment, this was just something I wanted to <em>know</em>.</p><h3>Subject matter</h3><p>This is where DSDTD and&#8212;what shall I nickname the new one? MDID?&#8212;share the greatest similarities.</p><p>I keep being drawn to projects where I have a chance to enable both individuals and businesses to dictate their digital destinies&#8212;whether it&#8217;s about preventing data from being locked into proprietary formats (SGML, XML, and beyond), or about controlling where one&#8217;s own data goes (UMA, HEART, and beyond). Digital identity is absolutely a central part of this story, with implications for both risk and revenue.</p><p>I hope you&#8217;ll join me on the <em><a href="http://masteringdigitalidentity.com/">Mastering Digital Identity</a></em> journey still in progress.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/a-tale-of-two-book-writing-journeys/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/a-tale-of-two-book-writing-journeys/comments"><span>Leave a comment</span></a></p>]]></content:encoded></item><item><title><![CDATA[Demystifying NIST SP 800-63]]></title><description><![CDATA[A Practical Guide for Organizations Navigating Digital Identity]]></description><link>https://workshop.vennfactory.com/p/demystifying-nist-sp-800-63</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/demystifying-nist-sp-800-63</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Tue, 02 Dec 2025 17:11:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XVLG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XVLG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XVLG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XVLG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XVLG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XVLG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XVLG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg" width="1600" height="782" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:782,&quot;width&quot;:1600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:321991,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/179868650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e0a36dc-43fd-4a3b-957d-a3b2bbdf5ed8_1600x1200.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XVLG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XVLG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XVLG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XVLG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08648fde-1d8b-464d-b3bc-0d3bdc0ca638_1600x782.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: eBay</figcaption></figure></div><p><em>I&#8217;m pleased to present this cross-post of an <a href="https://www.paravision.ai/news/demystifying-nist-sp-800-63-a-practical-guide-for-organizations-navigating-digital-identity/">article</a> I developed in collaboration with <strong>trusted vision AI leader <a href="http://paravision.ai/">Paravision</a></strong>. For more information, reach out to <a href="mailto:info@paravision.ai">info@paravision.ai</a></em>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xNSu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xNSu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 424w, https://substackcdn.com/image/fetch/$s_!xNSu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 848w, https://substackcdn.com/image/fetch/$s_!xNSu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!xNSu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xNSu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png" width="302" height="50.402472527472526" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:243,&quot;width&quot;:1456,&quot;resizeWidth&quot;:302,&quot;bytes&quot;:161599,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/179868650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xNSu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 424w, https://substackcdn.com/image/fetch/$s_!xNSu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 848w, https://substackcdn.com/image/fetch/$s_!xNSu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!xNSu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3569bb73-3bbd-40e8-86b2-3be3c81802b7_8640x1440.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h1><strong>1. Introduction</strong></h1><p>NIST&#8217;s Special Publication 800-63 is a frequently referenced &#8212; and often misunderstood &#8212; document in the digital identity ecosystem. It shapes how organizations verify identities, authenticate users, and safely exchange identity information. Yet for many people, especially those outside the identity industry, NIST SP 800-63 feels complex, highly technical, and difficult to apply in real-world environments.</p><p>The goal of this article is to demystify 800-63 in clear, accessible terms without oversimplifying or glossing over the nuance that makes it important.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/demystifying-nist-sp-800-63?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/demystifying-nist-sp-800-63?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3><strong>What is NIST 800-63 and why does it matter?</strong></h3><p>NIST is the U.S. National Institute of Standards and Technology, part of the U.S. Department of Commerce. It produces publications defining standards in many business, science, and technology realms where having an official &#8220;yardstick&#8221; is useful, from plumbing pressure-loss measurements to the viscosity of chemical elements.</p><p>Somewhere in the middle, we find the topics of <strong>Cybersecurity and Privacy</strong> and <strong>Information Technology</strong>. NIST Special Publication 800-63 is related to both.</p><p>SP 800-63, <em><a href="https://www.nist.gov/publications/nist-sp-800-63-4-digital-identity-guidelines">Digital Identity Guidelines</a></em>, is now in its fourth revision and is a critical contribution to defining measurable confidence &#8212; or <em>assurance</em> &#8212; in digital identity processes. It defines measurable levels of assurance across three areas of digital identity and access management:</p><ul><li><p>Identity: How confidently you know the person is who they say they are</p></li><li><p>Authentication: How confidently you can trust the method a user uses to log in</p></li><li><p>Federation: How securely identity information is passed between systems (like using the SAML or OpenID Connect standard)</p></li></ul><p>Organizations can use 800-63 to mitigate organizational risk by choosing among three levels that NIST assigns to systems for each of the above areas, which can roughly be categorized as low (1), medium (2), and high (3).</p><h3><strong>Who uses 800-63?</strong></h3><p>The official scope of 800-63 is limited to U.S. government information systems, but the guidelines are so useful that they&#8217;re widely applied in the private sector and even influence global enterprises.</p><h3><strong>Why is there so much confusion?</strong></h3><p>Selecting a required assurance level for specific organizational needs may seem like a simple process, and indeed it is this procedural simplicity that has led to the popularity of SP 800-63. However, <em>meeting the requirements behind these levels</em> is much harder. It requires a great amount of attention to technical design, user experience, and operational guardrails. Providers must also undergo rigorous conformance assessments and ongoing reviews to be certified against the assurance levels.</p><h1><strong>2. How NIST 800-63 evolved &#8212; and why It split into 63A, 63B, and 63C</strong></h1><p>Some of the confusion surrounding SP 800-63 comes from its history. Like many technical frameworks, it has evolved significantly over time.</p><h3><strong>A brief history of major updates</strong></h3><p>Originally, assurance was measured with four simple levels, referred to as levels of assurance (LOA) 1 through 4. Today, assurance is expressed across three dimensions:</p><ul><li><p>Identity Assurance Level (IAL): Levels 1-3</p></li><li><p>Authentication Assurance Level (AAL): Levels 1-3</p></li><li><p>Federation Assurance Level (FAL): Levels 1-3</p></li></ul><p>The <a href="https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-63-1.pdf">first version</a> of SP 800-63, published in 2011 and called Electronic Authentication Guideline, was simpler and addressed early identity technologies at a high level. <a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-2.pdf">The second version</a> (2013) coincided with increased enterprise IAM adoption and growing appetite for interoperable identity federation.</p><p>The <a href="https://pages.nist.gov/800-63-3/sp800-63-3.html">third version</a> in 2017, finally called Digital Identity Guidelines, was a major shift; to reflect publicly sourced input, it introduced the three-part structure. According to NIST:</p><blockquote><p><em>&#8220;These guidelines retire the concept of a level of assurance (LOA) as a single ordinal&#8230; Rather&#8230; agencies will select IAL, AAL, and FAL as distinct options.&#8221;</em></p></blockquote><p>The old single-number approach could no longer capture modern identity complexity.</p><h3><strong>Version 4: the 2025 update</strong></h3><p>The <a href="https://pages.nist.gov/800-63-4/sp800-63.html">fourth version (NIST SP 800-63-4</a>) keeps the tripartite model of IAL, AAL, and FAL, while updating requirements to reflect modern identity technologies such as biometrics, identity wallets, and advanced authentication methods. These updates help organizations implement identity systems that are both secure and user-friendly, keeping pace with evolving threats and technology.</p><p>The three parts of the publication are:</p><ul><li><p><strong>63A</strong>: Identity proofing &#8211; Guidelines for verifying that a user is who they claim to be.</p></li><li><p><strong>63B</strong>: Authentication &#8211; Requirements for securely validating user credentials.</p></li><li><p><strong>63C</strong>: Federation &#8211; Rules for safely sharing identity information across different systems or organizations.</p></li></ul><h3><strong>How they work together</strong></h3><p>The sub-documents are designed to be used in combination. A typical workflow (shown in the below diagram) might look like this: an organization first verifies a user&#8217;s identity (Step 1: 63A), then ensures the user can authenticate securely (Step 4: 63B), and finally, if identity data is shared with partners, applies federation controls (Step 5: 63C) to maintain trust across systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d8jR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d8jR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 424w, https://substackcdn.com/image/fetch/$s_!d8jR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 848w, https://substackcdn.com/image/fetch/$s_!d8jR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!d8jR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d8jR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!d8jR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 424w, https://substackcdn.com/image/fetch/$s_!d8jR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 848w, https://substackcdn.com/image/fetch/$s_!d8jR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!d8jR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6756ad-d04c-4274-a3b9-e5b2a33b7934_1600x1200.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Source: NIST SP 800-63-4, <a href="https://pages.nist.gov/800-63-4/sp800-63.html#fig-4">Figure 4</a></em></figcaption></figure></div><p>It&#8217;s important to note that organizations don&#8217;t have to match assurance levels across all three dimensions. For example, they might choose a lighter identity proofing (IAL1) together with stronger authentication (AAL3). In practice, many organizations end up choosing aligned levels across touchpoints, and IAL2 and AAL2 often emerge as practical &#8220;sweet spots&#8221; due to feasibility and certification availability.</p><h1><strong>3. Key Concepts: IAL, AAL, FAL &#8212; What They Mean in the Real World</strong></h1><p>The persistent question in online services, apps, and human interactions is: Has the other side earned my trust? Is it safe to interact with them or do business with them? In real terms: Is this user actually the person they claim to be? Do we know enough about this traveler to keep everyone else safe? Am I interacting with a human or a bot?</p><p>Because digital systems today have many moving parts, the <strong>supply chain of identification</strong> can be long and complex. This is why NIST defines three separate types of measurements:</p><ul><li><p><strong>IAL (Identity Assurance)</strong>: Do the user&#8217;s security credentials connect to a legitimate real-world human being?</p></li><li><p><strong>AAL (Authentication Assurance)</strong>: How likely is it that the user&#8217;s credentials have been stolen?</p></li><li><p><strong>FAL (Federation Assurance)</strong>: How trustworthy is the exchange of identity information across systems?</p></li></ul><h3><strong>How organizations apply the levels</strong></h3><p>Organizations looking to leverage these assurance promises typically get support from vendors specializing in high-assurance systems, artifacts, and processes. The <strong>Kantara Initiative</strong> performs certification work to approve ecosystem participants at IAL2 and AAL2, which allows these providers to use a trust mark signaling their capabilities.</p><p>Negotiations and agreements around assurance usually take place in:</p><ul><li><p>Business contracts</p></li><li><p>Trust frameworks</p></li><li><p>Operational policies</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/demystifying-nist-sp-800-63/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/demystifying-nist-sp-800-63/comments"><span>Leave a comment</span></a></p><h1><strong>4. Navigating the Standards Ecosystem</strong></h1><p>An organization operating across multiple jurisdictions or sectors may encounter assurance requirements that don&#8217;t map neatly to each other. While this risk is lower today thanks to NIST&#8217;s influence and the adoption of standards globally, true conflicts can still arise &#8212; for example, when authenticating minors, complying with local biometrics laws, or meeting detailed user experience requirements like those in UK Open Banking.</p><p>In these cases, a good approach is to aim for a <strong>&#8220;high-water mark&#8221;</strong>: the strongest assurance requirement across all applicable frameworks. While SP 800-63 doesn&#8217;t define the use of finer-grained levels, like &#8220;IAL2.7&#8221;, organizations can adjust their internal policies and processes to get as close as possible to meeting multiple parties&#8217; requirements.</p><h3><strong>Emerging trends to watch</strong></h3><p>NIST SP 800-63 revision 4 took years to produce, so another full revision isn&#8217;t expected soon. However, just over a year before it was finalized, NIST published a supplement providing interim guidance on emerging passkey technology.</p><p>We can expect NIST to release more supplements in future to keep pace with fast-moving areas. For instance, innovations in AI agent security or new threats like injection attacks may require similar interim guidance.</p><h1><strong>5. FAQs and Common Misunderstandings</strong></h1><p>NIST has published a <a href="https://pages.nist.gov/800-63-FAQ/">Frequently Asked Questions list</a> with answers, and enables the public to ask additional questions.</p><h3><strong>What are common mistakes organizations make when interpreting the standard?</strong></h3><p>A common misconception organizations make is that the three assurance dimensions &#8212; IAL, AAL, and FAL &#8212; must always match numerically. In some cases, perfect alignment can be appropriate, but it&#8217;s often unnecessary. For instance, an organization might choose lightweight identity verification (IAL1) combined with strong authentication (AAL3). This approach ensures that the user is strongly authenticated without having to handle sensitive identity verification data when it isn&#8217;t required.</p><h3><strong>How can buyers avoid jargon overload?</strong></h3><p>When in doubt, organizations should focus first on the real business risks they are trying to mitigate, then seek to understand how the assurance levels might help them mitigate that risk.</p><h1><strong>Closing Thoughts: Key Takeaways on NIST 800-63</strong></h1><p>NIST SP 800-63 provides a practical framework for measuring confidence in digital identity. By separating assurance into three dimensions &#8212; Identity Assurance (IAL), Authentication Assurance (AAL), and Federation Assurance (FAL) &#8212; it allows organizations to apply nuanced levels of risk management rather than a one-size-fits-all approach.</p><p>A few key points to remember:</p><ul><li><p><strong>Start with business risk, not technology.</strong> Identify what you&#8217;re trying to protect, then select assurance levels that help mitigate those risks.</p></li><li><p><strong>Levels don&#8217;t always have to match.</strong> Lightweight identity proofing (IAL1) can be paired with strong authentication (AAL3) where appropriate. In practice, IAL2 and AAL2 often hit the &#8220;sweet spot&#8221; of feasible implementation, risk reduction, and certification availability.</p></li><li><p><strong>Implementation is more complex than selection.</strong> Achieving certified assurance levels requires careful attention to technical systems, operational processes, and user experience.</p></li><li><p><strong>Ongoing evolution matters.</strong> Supplements and interim guidance allow organizations to adopt emerging technologies, like cloud-syncable passkeys or AI-related security measures, without waiting for a full SP 800-63 revision.</p></li></ul><p>Ultimately, SP 800-63 is designed to help organizations make smarter, risk-based decisions about digital identity, whether in government, private enterprise, or cross-sector contexts. Understanding how the three assurance dimensions interact and how to apply them in the real world is the key to confidently navigating today&#8217;s complex digital identity landscape.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8ooL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8ooL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!8ooL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!8ooL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!8ooL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8ooL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/179868650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8ooL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!8ooL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!8ooL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!8ooL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1780bd36-4b8e-447d-aa04-2e996422c913_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>I hope you enjoyed this installment of <strong>The Workshop</strong>. It&#8217;s part of a larger conversation about the future of identity and how to make it &#8212; in a word &#8212; irresistible. I hope you&#8217;ll subscribe as we continue to push the edges of the envelope here at Venn Factory.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA["The good old free and open Internet"]]></title><description><![CDATA[And an earworm for you]]></description><link>https://workshop.vennfactory.com/p/the-good-old-free-and-open-internet</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/the-good-old-free-and-open-internet</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Tue, 11 Nov 2025 19:40:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!S2qG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S2qG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S2qG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 424w, https://substackcdn.com/image/fetch/$s_!S2qG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 848w, https://substackcdn.com/image/fetch/$s_!S2qG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 1272w, https://substackcdn.com/image/fetch/$s_!S2qG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S2qG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic" width="1456" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:762467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/178598160?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S2qG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 424w, https://substackcdn.com/image/fetch/$s_!S2qG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 848w, https://substackcdn.com/image/fetch/$s_!S2qG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 1272w, https://substackcdn.com/image/fetch/$s_!S2qG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a46de56-9838-44f3-b373-5e74ddf4f92f_3200x1723.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s become a frequent topic of conversation with identity friends of late.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> In the early days of the web, our feeling of intellectual freedom and excitement was palpable. Big new ideas would zing back and forth in blogs, crossing company lines freely. Anyone could make a difference and nobody was consumed with monetization or social media influence.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> There was nothing to scroll &#8212; except perhaps the blog aggregator known as Planet Identity.</p><p>I don&#8217;t believe this phenomenon is gone for good. I see sparks of it in the way ideas &#8212; like &#8220;Chief Identity Officer&#8221; and &#8220;Token-Based Access Control&#8221; &#8212; have bounced around different podcasts and LinkedIn posts, getting refined along the way. And those of us involved in standards definition work seem to have honed the art to a fine edge, accelerating development of protocols. (Whether we now have too many is a topic for another day.)</p><p>Today I saw Ian Glazer&#8217;s reflective post on <a href="https://www.linkedin.com/pulse/25-years-ian-glazer-8hdve/">25 Years</a> in the IAM business, and I&#8217;ve been reading Heather Flanagan&#8217;s great series (<a href="https://sphericalcowconsulting.com/2025/10/07/the-end-of-the-global-internet/">start here</a>) that I&#8217;ve mentally bookmarked as &#8220;Whither the Internet?&#8221;</p><p>So I&#8217;m emboldened to share with you today the results of a challenge set for me a few days ago by John Wunderlich. He had been reading yet another post that hoped to &#8220;help bring back the good old free and open Internet&#8221; and, well&#8230;</p><blockquote><p>this triggered &#8220;Back in the USSR&#8221; in my head, except the refrain was &#8220;Back in the HTTP&#8221;</p></blockquote><p>As the onetime ringleader of the Internet Identity Workshop 2006b crowd that penned and performed &#8220;Bohemian Rhapsody in the Key of ID&#8221; (also affectionately known as Bohemian Rhaps-ID&#8221;), I couldn&#8217;t resist making the attempt.</p><h3>Back in the H.T.T.P.</h3><p><em>Sung to the tune of Back in the U.S.S.R.</em></p><p>Oh, surfed the web and ended up at A.O.L.<br>Didn&#8217;t get to bed last night<br>Clicked a blinking banner ad and entered hell<br>Man that virus was a fright</p><p>I&#8217;m back in the H.T.T.P.<br>Without a shred of security<br>Back &#8212; in the H.T.T.P.</p><p>Everybody blogging for the hell of it<br>No pixels tryna phone back home<br>S.E.O. was just a twinkle in my eye<br>Couldn&#8217;t even browse with Chrome</p><p>I&#8217;m back in the H.T.T.P.<br>With lots of speech &#8212; but not beer &#8212; free<br>Back &#8212; in the H.T.-<br>Back &#8212; in the H.T.-<br>Back &#8212; in the H.T.T.P.</p><p>Well e-commerce sites really knock me out<br>I&#8217;m going dot-com blind<br>I&#8217;m buying pets and furniture<br>My life&#8217;s on GeoCities with all humanki-ki-ki-ki-kind</p><p>I&#8217;m back in the H.T.T.P.<br>But now I&#8217;ve lost all my privacy<br>Back &#8212; in the H.T.T.P.</p><p>Well the I.E.T.F. controlled the world<br>Left F.T.P. behind<br>Then the flag of the W.3.C. unfurled<br>And H.T.M.L. wouldn&#8217;t be sideli-li-li-li-li-li-lined</p><p>Oh, Simple Object Access overtook the place<br>The cleanest Protocol around<br>SAML started federating cyberspace<br>Now we&#8217;re really Web2 bound</p><p>I&#8217;m back in the H.T.T.P.<br>With S. for added security<br>Back &#8212; in the H.T.T.P.</p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Looking at you, Mike Neuenschwander!</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Though IP battles in the making of actual standards were still common then. I have the scars.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Identity as Floor Wax and Dessert Topping]]></title><description><![CDATA[But is it non-dairy?]]></description><link>https://workshop.vennfactory.com/p/identity-as-floor-wax-and-dessert</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/identity-as-floor-wax-and-dessert</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Tue, 14 Oct 2025 12:31:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!j5At!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j5At!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j5At!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j5At!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j5At!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j5At!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j5At!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg" width="1456" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:549600,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/176076419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j5At!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j5At!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j5At!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j5At!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe933aafe-be1b-4a8b-b21f-9d43677cb750_1886x1060.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>&#8220;It&#8217;s a floor wax!&#8221; &#8220;It&#8217;s a dessert topping!&#8221; &#8220;Hey, calm down, you two&#8230;it&#8217;s both!&#8221;<br><em><strong>&#8211; Saturday Night Live, 1976</strong></em></p></div><p>That&#8217;s the comedy bit echoing through my mind ever since my recent chat with Jim McDonald on <a href="https://www.youtube.com/watch?v=f6xsxGnbsNU">episode #379 of the </a><em><a href="https://www.youtube.com/watch?v=f6xsxGnbsNU">Identity at the Center</a></em><a href="https://www.youtube.com/watch?v=f6xsxGnbsNU"> podcast</a>.</p><p>In that sketch, New Shimmer promises to polish your floors <em>and</em> sweeten your dessert. The absurdity, of course, is that it&#8217;s trying to be two wildly different things at once, and somehow, we all nod along.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vLBl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vLBl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 424w, https://substackcdn.com/image/fetch/$s_!vLBl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 848w, https://substackcdn.com/image/fetch/$s_!vLBl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 1272w, https://substackcdn.com/image/fetch/$s_!vLBl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vLBl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png" width="600" height="405" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aacb4083-8263-4e27-937a-68f3f0a94525_600x405.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:405,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:663595,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/176076419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vLBl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 424w, https://substackcdn.com/image/fetch/$s_!vLBl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 848w, https://substackcdn.com/image/fetch/$s_!vLBl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 1272w, https://substackcdn.com/image/fetch/$s_!vLBl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faacb4083-8263-4e27-937a-68f3f0a94525_600x405.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Why yes, it is non-dairy. Whew.</figcaption></figure></div><p>That, in many ways, is identity today. It&#8217;s compliance <em>and</em> innovation. It&#8217;s security <em>and</em> experience. It&#8217;s infrastructure <em>and</em> strategy.</p><p>We&#8217;ve built something that&#8217;s supposed to hold the entire digital organization together, while also making it frictionless, personalized, and safe.</p><p>And somehow, we&#8217;re surprised when sparks fly.</p><h3>The puddle problem</h3><p>During the conversation, Jim painted a vivid picture of what it&#8217;s like to be an identity practitioner today:</p><blockquote><p>&#8220;We&#8217;re trying to pull the plug from both ends and plug it together. That&#8217;s if there&#8217;s only one plug on each side. And it&#8217;s raining and you&#8217;re standing in a puddle. Good luck. If you don&#8217;t do it right, you might get electrocuted.&#8221;</p></blockquote><p>He&#8217;s absolutely right. That&#8217;s what it feels like when every business unit has its own pocket of identity, marketing wants one thing, product another, IT a third, and security a fourth.</p><p>Everyone has their own plug, their own priorities, their own puddle.</p><p>And in the middle of all this, someone eventually asks:</p><p>&#8220;So&#8230; who actually owns this?&#8221;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/identity-as-floor-wax-and-dessert?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/identity-as-floor-wax-and-dessert?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>When &#8220;who owns it&#8221; meets &#8220;who <em>is</em> it&#8221;</h3><p>CEOs often assume identity is handled by the CISO, as an extension of cybersecurity.</p><p>&#8220;That&#8217;s why I hired one,&#8221; they say.</p><p>But identity doesn&#8217;t stay politely in the security box. It spills from Protection into Personalization, Payment, and People &#8211; what I call the <em>four P&#8217;s</em>.</p><p>When those four forces collide, it&#8217;s no longer a single-function problem. It&#8217;s an organizational one.</p><p>Identity doesn&#8217;t just <em>secure</em> the business &#8211; it <em>is</em> the business. It determines how trust is formed, how customers feel seen, and how innovation stays safe.</p><p>So yes, in your organization perhaps it&#8217;s the CISO who implements. (CISOs own only as many as half of workforce identity programs. Owning CIAM would be rare.)</p><p>But it&#8217;s the CEO who empowers.</p><p>And that distinction might just decide whether your cords light up&#8230;or short out.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MZXh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MZXh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 424w, https://substackcdn.com/image/fetch/$s_!MZXh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 848w, https://substackcdn.com/image/fetch/$s_!MZXh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 1272w, https://substackcdn.com/image/fetch/$s_!MZXh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MZXh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png" width="1076" height="951" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:951,&quot;width&quot;:1076,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:581514,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/176076419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MZXh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 424w, https://substackcdn.com/image/fetch/$s_!MZXh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 848w, https://substackcdn.com/image/fetch/$s_!MZXh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 1272w, https://substackcdn.com/image/fetch/$s_!MZXh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef62a280-4b66-43bf-a5d8-89d9ed3ec158_1076x951.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Thanks <a href="https://www.reddit.com/r/HomeNetworking/comments/1o5r0q1/looking_to_get_ethernet_on_all_floors_of_my_newer/#lightbox">r/HomeNetworking</a>!</figcaption></figure></div><h3>Empowerment in the puddle</h3><p>The hard truth is that the puddle isn&#8217;t going away.</p><p>Complexity is here to stay &#8211; multi-cloud, hybrid work, AI agents, mergers, and regulations all keep pouring water into the system.</p><p>But we can&#8217;t stand still.</p><p>It means we empower the people holding the plugs.</p><p>The organizations that succeed are the ones where leadership sees identity as a strategic advantage, not just a compliance burden.</p><p>They give identity teams the air cover, budget, and cross-functional mandate to connect the system safely and beautifully.</p><p>Because when those cords finally come together, they don&#8217;t just power security. They power trust.</p><h3>Both, by design</h3><p>Identity, like New Shimmer, is both a floor wax <em>and</em> a dessert topping.</p><p>It&#8217;s the polish that keeps systems secure and humming, and the sweetness that makes experiences delightful.</p><p>If we can start treating it as both, maybe we can stop tripping over the cords and start lighting up what matters.</p><p>Listen: My full conversation with <a href="http://youtube.com/watch?v=f6xsxGnbsNU">Jim McDonald on </a><em><a href="http://youtube.com/watch?v=f6xsxGnbsNU">Identity at the Center</a></em> discusses my forthcoming book and dives deeper into the messy, human, and often electrifying challenge of making identity work&#8212;for everyone.</p><p>At Venn Factory, we help leaders see identity not just as a risk to be managed, but as an advantage to be leveraged.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/identity-as-floor-wax-and-dessert/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/identity-as-floor-wax-and-dessert/comments"><span>Leave a comment</span></a></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links is now The Venn Shortlist]]></title><description><![CDATA[Come... Join us...]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-is-now-the-venn</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-is-now-the-venn</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Thu, 18 Sep 2025 14:05:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dZsk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dZsk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dZsk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dZsk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dZsk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dZsk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dZsk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg" width="800" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48949,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/173939685?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dZsk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dZsk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dZsk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dZsk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5e6b22-9705-4ee3-9a64-0ed91ecf5a0a_800x800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For those who have been following my "3 Identity Links" blogging here, I hope you'll check out its new home on <strong><a href="https://www.linkedin.com/#">Venn Factory&#8217;s LinkedIn page</a></strong>, reborn as The Venn Shortlist.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><p>This month's lens opened the aperture on ecosystem trends that all impact <strong>#digitalidentity</strong> in various ways. Regarding the discussion about "industry problems" and standards in link no. 3, the pace of AI agent-related specs is just NUTS right now. With <strong>#AP2</strong> (and many others), we're at the point of needing a registry of daily proposals and a specialty LLM just to analyze and compare them. But do any address key questions of why businesses (and humans) are generally unwilling to take a human out of the loop?</p><p>Another way to put this: We've had OAuth dynamic client registration for a really long time. What's kept us from using DCR to automate way more of our wide-ecosystem app relationships already?</p><p>(Follow <strong><a href="https://www.linkedin.com/#">Venn Factory</a></strong> to catch more issues of the Shortlist!)</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.linkedin.com/company/vennfactory/&quot;,&quot;text&quot;:&quot;Follow Venn Factory on LinkedIn&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.linkedin.com/company/vennfactory/"><span>Follow Venn Factory on LinkedIn</span></a></p>]]></content:encoded></item><item><title><![CDATA[If something can’t go on forever, it won’t]]></title><description><![CDATA[Identity&#8217;s role in the unsustainable path of security and privacy]]></description><link>https://workshop.vennfactory.com/p/if-something-cant-go-on-forever-it</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/if-something-cant-go-on-forever-it</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Fri, 29 Aug 2025 16:15:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_VvV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_VvV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_VvV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_VvV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_VvV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_VvV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_VvV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg" width="1456" height="1075" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1075,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3534268,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/172108704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_VvV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_VvV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_VvV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_VvV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e48d6b-8c52-4a9c-b3da-63e22730c533_3811x2815.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Trees and Houses Near the Jas de Bouffan</em>, Paul C&#233;zanne. Credit: <a href="https://www.metmuseum.org/art/collection/search/459092">MetMuseum.org</a>. Public domain.</figcaption></figure></div><p><strong>If something can&#8217;t go on forever, it won&#8217;t.</strong></p><p>I&#8217;m an optimist, some might even say a Pollyanna. There&#8217;s nothing like contributing to novel Internet standards efforts to demonstrate one&#8217;s belief in hope over experience! But after 25+ years in the trenches of digital identity, this maxim of economics is starting to hit close to home.</p><p>So many of our current identity paths are <strong>unsustainable</strong>. Security is still eroding. Privacy is still evaporating. Trust is threadbare at best.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><h2>Identity&#8217;s Death Spiral</h2><p>I&#8217;m not a fan of the phrase &#8220;identity is broken&#8221; &#8212; but the way we do IAM often leads to a <strong>death spiral</strong> of negative consequences for experience, user control, security, and even basic online safety. The Internet commentator <a href="https://workshop.vennfactory.com/p/why-digital-identity-matters-to-individuals">I think of</a> as the &#8220;login rant lady&#8221; said:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tXcy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tXcy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tXcy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tXcy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tXcy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tXcy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg" width="699" height="694" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:694,&quot;width&quot;:699,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:101277,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/172108704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tXcy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tXcy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tXcy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tXcy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fc0e6c3-8b44-4685-80cf-a8613d1a0f08_699x694.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I can&#8217;t believe I&#8217;m gonna have to log into things for the rest of my life! Credit: <a href="https://x.com/stillgray/status/1871752776822190418?s=46">x.com</a></figcaption></figure></div><p>&#8230;and she&#8217;s not wrong.</p><h2>When Leaders Become Casualties</h2><p>Part of the downward spiral is psychological.</p><p>I&#8217;m working on a new project<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, for which I&#8217;ve identified three fatal delusions that leaders often cling to to feel safe.</p><p>The <strong>first delusion</strong> can be stated as:</p><div class="pullquote"><p><strong>&#128683; More identity = more security</strong></p></div><p>Our identity solutions, automations, checklists &#8212; and standards, an ever-growing pile of them &#8212; can feel proactive and productive, but <strong>none of it is a guarantee</strong> of a particular outcome, even if implemented and rolled out.</p><p>And the costs for getting things wrong are higher than ever. Have you been following the trend towards personal executive liability for cybersecurity failures? A great new organization called the <strong><a href="https://theciso.org/">Professional Association of CISOs</a> </strong>(PAC) has launched, thanks to my talented friends Val Mukherjee and Heather Hinton, under the <a href="http://cyberfuturefoundation.org/">Cyber Future Foundation</a> umbrella. It prepares CISOs for the increasing level of accountability they face in the modern world, including providing CISO-specific professional liability insurance.</p><p>But it&#8217;s not just CISOs. CEOs are taking direct fire as well, as in the infamous <a href="https://www.securityweek.com/ftc-targets-drizly-and-its-ceo-over-cybersecurity-failures-led-data-breach/">Drizly case</a>:</p><blockquote><p><strong>According to the FTC, Drizly and [its CEO] Rellas failed to implement basic security protections for the collected data, did not use multi-factor authentication, did not limit employee access to personal data, and did not develop adequate security policies.</strong> &#8212; <a href="https://www.securityweek.com/ftc-targets-drizly-and-its-ceo-over-cybersecurity-failures-led-data-breach/">Security Week</a>, 25 Oct 2022</p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/if-something-cant-go-on-forever-it?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/if-something-cant-go-on-forever-it?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2>Fixing Our Foundations?</h2><p>The Internet, <a href="https://www.identityblog.com/stories/2005/05/13/TheLawsOfIdentity.pdf">as has famously been observed</a>, was built without an identity layer. All of the layers we&#8217;ve been adding on top have gotten more sophisticated over time, exemplified by the recent publication of <a href="https://www.nist.gov/publications/nist-sp-800-63-4-digital-identity-guidelines">revision 4 of NIST Special Publication 800-63</a>, the <strong>Digital Identity Guidelines</strong>.</p><p>Do we need <strong>brand-new infrastructure</strong> to replace the old?</p><p>For years, I&#8217;ve helped define standards and technologies meant to patch this gap. More recently, I&#8217;ve been working with organizations of all sizes, translating identity complexity into language that decision-makers can act on.</p><p>What I&#8217;ve learned is that <em>today&#8217;s</em> identity foundations and innovations <em>can</em> serve as the <strong>healthy cardiovascular system of the connected world</strong>. They can protect us from exploits and fraud, support our financial transactions, give people choice and control, and even foster healthy digital relationships with businesses.</p><p>But only if organizations and their leadership understand their power, value, and full impact. Technical expertise, and a mindset focused exclusively on security, are proving inadequate to the moment.</p><p>As the number of executive stakeholders with their fingers in the IAM pie becomes overwhelming, and as detractors proliferate, I believe we need to <strong>master identity&#8217;s higher purpose</strong> so we can make common cause and achieve what we know is possible.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VITe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VITe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!VITe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!VITe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!VITe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VITe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/172108704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VITe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!VITe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!VITe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!VITe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde349dd1-0e7e-44d9-8afc-ac5b1478b55b_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The identity crisis is here. The spiral is accelerating. But crises have a way of forcing evolution.</p><p>My question for you is whether it&#8217;s possible to help identity fully contribute to a healthy connected world.</p><p>Do you see identity circling the drain, or do you believe it can reach an inflection point?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/if-something-cant-go-on-forever-it/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/if-something-cant-go-on-forever-it/comments"><span>Leave a comment</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I&#8217;m working on a new book! If you take a moment to subscribe, I&#8217;ll share more here real soon.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Why AI Can’t Be Your Actual Therapist]]></title><description><![CDATA[Even Sam Altman admits it]]></description><link>https://workshop.vennfactory.com/p/why-ai-cant-be-your-actual-therapist</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/why-ai-cant-be-your-actual-therapist</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Mon, 18 Aug 2025 16:38:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BCr4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BCr4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BCr4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BCr4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BCr4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BCr4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BCr4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg" width="1024" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:201846,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/171234986?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BCr4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BCr4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BCr4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BCr4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7de67b-a2ac-4367-9f2f-9c08b4d56d79_1024x800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Eye Test Chart ca. 1907. Source: <a href="https://public.work">public.work</a></figcaption></figure></div><p>I have to confide in you about something. Every time I click or type anything at all online, I think and worry about who&#8217;s watching and listening. Honestly, it&#8217;s tough being a <a href="https://itif.org/publications/2020/01/28/privacy-fundamentalists-dont-care-about-privacy-preferences-silent-majority/">privacy fundamentalist</a> (as researcher Alan Westin termed it).</p><p>A whole lot of privacy pragmatists and &#8220;TMI people&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, on the other hand, are confiding in their AI pals about pretty much everything, even <a href="https://www.floridatoday.com/story/news/local/2025/08/12/is-an-ai-chatbot-like-chatgpt-going-to-be-your-next-therapist-therapy-mental-health/85510729007/">using them as therapists</a>. This includes a lot of <a href="https://www.commonsensemedia.org/sites/default/files/research/report/talk-trust-and-trade-offs_2025_web.pdf">teenagers</a>.</p><p>But on a recent podcast, OpenAI&#8217;s CEO <a href="https://techcrunch.com/2025/07/25/sam-altman-warns-theres-no-legal-confidentiality-when-using-chatgpt-as-a-therapist/">admitted</a> he thinks they shouldn&#8217;t.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p>Not because AI is bad at listening, though we could debate that, but because it can&#8217;t give you the one thing that makes therapy a safe space: legal confidentiality.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/why-ai-cant-be-your-actual-therapist?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/why-ai-cant-be-your-actual-therapist?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>The legal privilege gap</h3><p>When you confide in a human therapist, your words are shielded by law. When you confide in ChatGPT &#8212; or GPT-5, now loose in the wild &#8212; they&#8217;re not. If a court demands the records, they can be handed over.</p><p>And with GPT-5&#8217;s entry into what&#8217;s being called <em>relational AI</em> &#8212; systems that sustain deep, ongoing &#8220;relationships&#8221; with users &#8212; the emotional entanglement risk is higher than ever. These models feel warmer, more consistent, more &#8220;there for you&#8221; than any earlier AI. But they&#8217;re also more dangerous in the absence of safeguards.</p><h3>The connection to my world of identity and delegation</h3><p>I&#8217;ve been spending a lot of time in the trenches, helping to define what different actors &#8212; human and non-human &#8212; can and can&#8217;t be trusted to do.</p><ul><li><p>At the OpenID Foundation&#8217;s <a href="https://openid.net/wg/ekyc-ida/">eKYC group</a>, I recently presented <strong>use cases for delegation of authority</strong> across every possible direction: from a competent adult human, a company, or even a newborn baby, to another (insert any of the above). We examined adding AI agents to the mix.</p></li><li><p>Having been invited to an American Bar Association webinar on agentic AI risk, I joined prominent attorneys in considering <strong>whether AI could ever bear liability</strong> for their actions given current legal frameworks. Spoiler: Prospects are slim to none.</p></li><li><p>In the Death and the Digital Estate (<a href="https://openid.net/cg/death-and-the-digital-estate/">DADE</a>) group I co-chair, we&#8217;re soon tackling <strong>persona and relationship definitions </strong>using a method based on my <a href="https://learning.vennfactory.com/products/digital_downloads/persona-identity">white paper</a>, including how delegation to a family member survives beyond death. What happens when the delegator is gone, but the authority persists?</p></li></ul><p>The messy part? AI agents are software-based and they even can control other software like humans do, but they can&#8217;t be held legally liable for anything they do. Sounds to me like a perfect excuse for mapping things out in a Venn diagram&#8230;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tHZg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tHZg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tHZg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tHZg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tHZg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tHZg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg" width="1456" height="1022" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1022,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:196438,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/171234986?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tHZg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tHZg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tHZg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tHZg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ab764cc-9b15-4366-87d8-04896ae121d9_1706x1198.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>All of this has a bearing on the therapy question. We&#8217;re anthropomorphizing AI, giving it a seat in our most personal conversations, but without giving it the <em>capacity</em> or <em>obligation</em> to take responsibility.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><h3>Emotional Labor vs. Algorithmic Labor</h3><p>Altman has admitted he wouldn&#8217;t trust ChatGPT with his own medical fate unless a human doctor was in the loop. That&#8217;s telling.</p><p>Ever since the days of the <a href="https://en.wikipedia.org/wiki/ELIZA">ELIZA bot</a> in 1966, AI has been generating ever-better empathy cues, the right pauses, the &#8220;I understand&#8221; statements&#8230; But it can&#8217;t shoulder the ethical and legal responsibilities humans can.</p><p>Several US states are already <a href="https://www.axios.com/local/chicago/2025/08/06/illinois-ai-therapy-ban-mental-health-regulation">outlawing AI therapists</a>, and the challenge is clear. Until we align capability with accountability, or conduct our chats on a fully protected edge device, AI &#8220;therapy&#8221; might as well be a confession caught on a hot mic.</p><p><strong>Your turn.</strong> Have you ever confided in AI? What legal or ethical safeguards would it take for you to truly trust it in that role?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/why-ai-cant-be-your-actual-therapist/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/why-ai-cant-be-your-actual-therapist/comments"><span>Leave a comment</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>My little nickname for what Westin called the <strong>privacy unconcerneds</strong>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>I commented briefly on this news in a <a href="https://techcrunch.com/2025/07/25/sam-altman-warns-theres-no-legal-confidentiality-when-using-chatgpt-as-a-therapist/">previous post</a>.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Ambient Scribes]]></title><description><![CDATA[Hey, didn't I see them open for the Stones in '75?]]></description><link>https://workshop.vennfactory.com/p/ambient-scribes</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/ambient-scribes</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Thu, 14 Aug 2025 16:15:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hE0Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hE0Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hE0Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 424w, https://substackcdn.com/image/fetch/$s_!hE0Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 848w, https://substackcdn.com/image/fetch/$s_!hE0Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 1272w, https://substackcdn.com/image/fetch/$s_!hE0Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hE0Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png" width="400" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6032af27-53b0-459d-ad58-73550294a220_400x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34139,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/170047351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2302e7b4-e187-4d6b-b708-5a50f5f49b62_400x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hE0Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 424w, https://substackcdn.com/image/fetch/$s_!hE0Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 848w, https://substackcdn.com/image/fetch/$s_!hE0Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 1272w, https://substackcdn.com/image/fetch/$s_!hE0Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6032af27-53b0-459d-ad58-73550294a220_400x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">HEART &#8220;logo&#8221; created by Justin Richer, Working Group editor</figcaption></figure></div><p>Ten years ago I contributed to launching <a href="https://openid.net/wg/heart/">HEART</a>, a health IT standards effort at the OpenID Foundation. HEART stands for <strong>Health Relationship Trust</strong>, and I served as its co-chair along with Debbie Bucci, then of the US Health and Human Services Office of the National Coordinator (HHS ONC).</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/ambient-scribes?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/ambient-scribes?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>(What&#8217;s an ambient scribe? Read on.)</p><p>In my recent post on UMA, you might have noticed that it has lots of healthcare-related implementations. Most of them implemented its HEART profile as well.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;96fcbff8-abbc-48e6-8c7b-f0a81ad88f0e&quot;,&quot;caption&quot;:&quot;This post may arrive truncated in email. Click the title to RTWT.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Whither User-Managed Access in the AI agent era?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:30100199,&quot;name&quot;:&quot;Eve Maler&quot;,&quot;bio&quot;:&quot;I do Z rock, myself&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2a517fc-93a6-4ae0-ae4f-43e2902c7f17_5748x3832.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-07-10T15:15:33.046Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Cuwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://workshop.vennfactory.com/p/whither-user-managed-access-in-the&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:167841171,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:4,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;Venn Factory: The Workshop&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ncoP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0cb08-bbc9-42ed-ada9-410851c80861_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Health providers, payers, and regulators &#8212; not to mention tech-savvy physicians and patients &#8212; have long expressed interest in enabling what we in HEART called <strong>Alice-to-Dr. Erica</strong> health data sharing. (You can read more about this use case in a <a href="https://kantara.atlassian.net/wiki/spaces/uma/pages/172687365/Patient-Centric+Data+Sharing+with+UMA">white paper</a> published by the UMA group.)</p><p>And the HEART effort allowed me to influence a variety of related programs, standards, and US government initiatives, including advising <em><a href="https://www.healthit.gov/buzz-blog/interoperability/move-health-data-forward-challenge-empowering-individuals-authorize-flow-health-data">Move Health Data Forward</a></em> applicants and providing testimony to the HHS ONC&#8217;s <a href="https://www.healthit.gov/sites/default/files/facas/APITF_Testimony_EveMaler_2016-01-26.pdf">API Privacy and Security Task Force</a>.</p><p>But despite a long-term emphasis on <strong>patient centricity</strong>, healthcare&#8217;s ecosystems have seen less progress than you&#8217;d think. Even well-resourced efforts like <a href="https://docs.smarthealthit.org">SMART on FHIR</a> have had difficulty getting going.</p><h3>A new day for healthcare innovation and patient control?</h3><p>But that&#8217;s not to dismiss new and exciting efforts under way.</p><p>The US Centers for Medicare &amp; Medicaid Services (CMS) video I <a href="https://workshop.vennfactory.com/p/3-identity-links-well-rounded-health">shared</a> a couple of weeks back teased a forthcoming announcement, which is now out: CMS has launched a <strong><a href="https://www.cms.gov/health-tech-ecosystem">health technology ecosystem</a></strong> effort. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.youtube.com/watch?v=g7HACskggQk" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4fBU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 424w, https://substackcdn.com/image/fetch/$s_!4fBU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 848w, https://substackcdn.com/image/fetch/$s_!4fBU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 1272w, https://substackcdn.com/image/fetch/$s_!4fBU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4fBU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png" width="1456" height="791" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:791,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4254973,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.youtube.com/watch?v=g7HACskggQk&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/170047351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4fBU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 424w, https://substackcdn.com/image/fetch/$s_!4fBU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 848w, https://substackcdn.com/image/fetch/$s_!4fBU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 1272w, https://substackcdn.com/image/fetch/$s_!4fBU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069d6e2c-1156-4223-98ab-975b356ea991_3006x1634.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The agency has made lots of juicy details available. From its <a href="https://www.cms.gov/health-technology-ecosystem/interoperability-framework">interop framework</a> page:</p><blockquote><p><strong>V. Identity, Security &amp; Trust<br></strong>&#8230;</p><ol start="22"><li><p><strong>Enforces access control and consent policy</strong> appropriate to the data access context.</p></li><li><p><strong>Provides verifiable logs or audit records</strong> for identity/auth requests and responses for independent review.</p></li></ol></blockquote><p>CMS calls for FHIR API implementation and interop, sets requirements for consent, and has a patient-empowering outlook. <strong>All of this is familiar</strong> from previous efforts over the last decade-plus. However, an <a href="https://joshuamandel.com/regulations.gov-comment-browser/CMS-2025-0050-0031/#/themes/5.1">RFI summary analysis</a> shows that existing tech &#8212; and there&#8217;s plenty of it &#8212; is just not reaching most patients.</p><blockquote><p><strong>Patients &amp; Family Caregivers<br>Primary Concerns:<br></strong>The overwhelming burden of managing dozens of logins ("portalitis"); being the "human fax machine" between uncommunicative providers; the emotional trauma of repeatedly recounting complex medical histories; data being "digitally shredded" or lost when changing providers; inability to access complete records (especially images and notes) for safety, second opinions, or disability applications.</p></blockquote><p>So, given that <strong>the purpose of a system is what it does</strong>, I think it&#8217;s reasonable to ask: What conditions have kept progress at bay previously? Are they still in place? How can we change those conditions?</p><p>I&#8217;m eagerly awaiting news on this front, and am tracking efforts such as <a href="https://www.bestchoicemedicine.com">Best Choice Medicine</a> (a broadening of Right to Try laws to take advantage of modern-day precision medicine) and <a href="https://www.biotech.senate.gov/press-releases/national-security-commission-on-emerging-biotechnology-congressional-commissioners-introduce-bill-to-promote-u-s-biotechnology-innovation/">proposed legislation</a> to speed up biotech innovation.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/ambient-scribes/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/ambient-scribes/comments"><span>Leave a comment</span></a></p><p>Working with doctors and other subject matter experts in the HEART context, the biggest inhibitors I saw were:</p><ul><li><p><strong>Risk sensitivity:</strong> A risk-averse culture &#8212; reasonable when &#8220;do no harm&#8221; is the highest principle! &#8212; pervades healthcare, magnified by an onerous <strong>legal</strong> <strong>liability</strong> factor.</p></li><li><p><strong>Market signal confusion:</strong> The US&#8217;s third-party-payer model has emphasized cost management and deemphasized &#8220;customer service&#8221;. It&#8217;s said about Facebook that <strong>if you&#8217;re not the paying customer, you&#8217;re the product</strong>. I&#8217;ve heard &#8212; and personally experienced &#8212; the same between physicians and patients.</p></li><li><p><strong>Wide ecosystem:</strong> When there are many sources and recipients of data, getting a view of the whole thing &#8212; never mind controlling data flow &#8212; is an extra challenge. <a href="https://moxie.org/2022/01/07/web3-first-impressions.html">Moxie Marlinspike wrote</a> about why (proprietary) platforms tend to win over protocols. Digitized healthcare done right <em>requires</em>, but struggles with, the protocol approach.</p></li></ul><h3>The new stuff</h3><p>So what&#8217;s new in this picture?</p><p>First, an acknowledgment of the <strong>promise of AI</strong>. From CMS&#8217;s <a href="https://www.cms.gov/health-technology-ecosystem/categories">ecosystem categories</a> page:</p><blockquote><p><strong>Conversational AI Assistants</strong></p><p><strong>Objective: </strong>Use AI-powered assistants to deliver personalized, context-aware guidance to patients by securely accessing and interpreting their medical history in real time.</p></blockquote><p>People are already experimenting in this direction, with abandon or even desperation. Amy Gleason&#8217;s video relayed her daughter&#8217;s experience <strong>generating AI insights by uploading all of her health records</strong>, transforming a difficult situation into new successes.</p><p>At the same time, AI <strong>ambient scribe</strong> tools have sprung up that assist with clinical documentation, letting the doctor spend more time directly with the patient vs. hunched over a computer. Health record system behemoth EPIC <a href="https://www.beckershospitalreview.com/healthcare-information-technology/ai/a-watershed-moment-cios-react-to-epics-ai-scribe-launch/">just announced that it&#8217;s planning</a> to add its own ambient scribe features. I can foresee AI agents coordinating data exchange and analysis between patient and doctor.</p><p>What else is new? An exploration of the opportunities with <strong>digital credentials</strong>. The <a href="https://www.federalregister.gov/documents/2025/05/16/2025-08701/request-for-information-health-technology-ecosystem">CMS RFI</a> section about preventing &#8220;information blocking&#8221; (interference with health data flow) intends to include decentralized <strong>verifiable credentials</strong> along with traditional identity verification:</p><blockquote><p>a. What are the challenges today in getting patients/caregivers to sign up and use digital identity credentials?</p><p>b. What could be the benefits to patients/caregivers if digital identity credentials were more widely used?</p><p>c. What are the potential downsides?</p></blockquote><h3>They&#8217;ve got a new attitude</h3><p>Despite past challenges, I love seeing the energy in CMS&#8217;s new initiative. Many <a href="https://www.cms.gov/health-tech-ecosystem/early-adopters">tech giants</a> have come to the table voluntarily, and they&#8217;re in a position to affect outcomes quickly.</p><p>I&#8217;ll be keeping a close eye on them all. It seems the time is ripe; just yesterday I even heard about a new HEART-related project gearing up in Canada. My fervent wish is for CMS to <strong>evolve health regulations</strong> to unlock modern health tech, and <strong>ensure true openness</strong> in connecting participants of any size to these health data ecosystems&#8230;including individual patients and providers.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GIl6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GIl6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!GIl6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!GIl6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!GIl6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GIl6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/170047351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GIl6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!GIl6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!GIl6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!GIl6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431bf989-bd87-4d36-9f7d-55e49574c10a_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>If you got value out of this post, <strong>why not subscribe</strong>? I&#8217;d love to welcome you to Venn Factory&#8217;s Workshop community and get your thoughts on other topics to cover.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links: Well-rounded health]]></title><description><![CDATA[Physical, emotional, and API]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-well-rounded-health</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-well-rounded-health</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Mon, 28 Jul 2025 22:42:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fh1W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fh1W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fh1W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fh1W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fh1W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fh1W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fh1W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg" width="1456" height="973" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:973,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:586983,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/169508332?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fh1W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fh1W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fh1W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fh1W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005028cb-d974-47b5-bcc7-7e227dd4fd0d_1686x1127.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Night Rain at Karasaki by Utagawa Hiroshige. Source: <a href="https://www.artic.edu/artworks/77316/night-rain-at-karasaki-karasaki-no-yau-from-the-series-eight-views-of-omi-omi-hakkei-no-uchi">Art Institute of Chicago</a>. CC0.</figcaption></figure></div><p>Quick 3 Links today.</p><p>Find a common thread among these three links? Challenge accepted!</p><h3><a href="https://www.youtube.com/watch?v=g7HACskggQk">CMS Health Tech Ecosystem - A Special Message</a></h3><p><em>Published on 26 Jul 2025 on YouTube by the U.S. Department of Health and Human Services; h/t <a href="https://www.linkedin.com/posts/josh-mandel_hl7-fhir-activity-7354943938870325248-1XKJ">Josh Mandel on LinkedIn</a></em></p><p>If you care about health IT, <a href="https://www.linkedin.com/posts/josh-mandel_hl7-fhir-activity-7354943938870325248-1XKJ?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAABfx8BZvGXnHtV155az8nek1WY4J_7u_M">Josh Mandel, MD</a> is a must-follow for his ground-breaking experiments in health data flows that work better, including AI research. I was grateful for his pointer to this video from HHS&#8217;s Strategic Advisor, Amy Gleason, making a strong call to industry for, well, more innovation of a similar sort. She had me from the get-go.</p><blockquote><p><strong>What if I told you that in 2025, your health data is doing less for you than your grocery shopping app?</strong></p></blockquote><p>Watch all three minutes to learn exactly what happened when her daughter uploaded her health records to an AI assistant.</p><p>There&#8217;s a hint in the video captioning, if not the talk track, that some related announcement is coming on July 29th. We shall see.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-well-rounded-health?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-well-rounded-health?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3><a href="https://techcrunch.com/2025/07/25/sam-altman-warns-theres-no-legal-confidentiality-when-using-chatgpt-as-a-therapist/">Sam Altman warns there's no legal confidentiality when using ChatGPT as a therapist</a></h3><p><em>Published on 25 Jul 2025 at TechCrunch</em></p><p>Okay, connecting this piece to the previous one is not actually a stretch &#8212; I&#8217;m sandbagging a little.</p><p>Sam Altman, while fighting a court order to produce customer chats, is also warning that people really ought not to talk to ChatGPT about all of their emotional struggles.</p><blockquote><p><strong>&#8220;I think we should have the same concept of privacy for your conversations with AI that we do with a therapist or whatever &#8212; and no one had to think about that even a year ago.&#8221;</strong></p></blockquote><p>Of course an AI chatbot is not a legal entity, much less a licensed one like a doctor or therapist, but if he&#8217;s suggesting there should be similar protections over such chats, I can think of quite a few things his company could be doing or investigating to provide better-than-legally-compliant privacy. After all, as the article points out, many individuals are motivated to seek out such features &#8212; at least when they&#8217;re given transparency about market alternatives.</p><p>Any health innovations will need a strong grounding in protections of every sort, such as those mooted in my <a href="https://learning.vennfactory.com/products/digital_downloads/consent-is-dead">Consent Is Dead paper</a>. (Did you know that some medical professionals believe <em>informed consent</em> is impossible to achieve?)</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-well-rounded-health/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-well-rounded-health/comments"><span>Leave a comment</span></a></p><h3><strong><a href="https://siliconangle.com/2025/07/22/intruder-releases-free-tool-detect-broken-api-authorization/">Intruder releases free tool to detect broken API authorization</a></strong></h3><p><em>Published on 22 Jul 2025 at TechCrunch</em></p><p>Intruder Solutions has released AutoSwagger, a free open-source tool that finds your machine-readable API documentation and surfaces un-secured endpoints.</p><p>(Health of an API &#8212; get it? Not an API <em>for</em> health like <a href="https://www.healthit.gov/topic/standards-technology/standards/fhir">FHIR</a>, though this tool should probably be run on FHIR servers too.)</p><blockquote><p><strong>&#8230;the tool has already been found to be effective. During Intruder&#8217;s research and testing of AutoSwagger, the company&#8217;s security team detected exposed Salesforce Inc. records with personally identifiable information at a large multinational tech company and an exposed internal staff training application [t]hat would have allowed potential attackers to run queries against the database at a multinational soda company.</strong></p></blockquote><p>The only thing I&#8217;d push back on here is the prescription coming from the company itself.</p><blockquote><p><strong>&#8220;The lesson here is, in addition to regular API scanning after each development iteration, that you shouldn&#8217;t publicly document your APIs unless you can&#8217;t avoid it.&#8221;</strong></p></blockquote><p>I understand avoiding exposing information to hackers; this is why error messages shouldn&#8217;t be too verbose. But the principle of the API economy &#8212; not to mention Zero Trust &#8212; is that you should be able to treat any component as external. If you have endpoints, you MUST protect them, if not with a highly flexible stack like OAuth, than at least with <em>something</em>. The vulnerability is not &#8220;returning sensitive information&#8221;, it&#8217;s &#8220;missing authentication&#8221;.</p><p>Something is better than nothing. You heard it here first.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CETN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CETN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!CETN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!CETN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!CETN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CETN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa158130-53e6-401f-becc-7f0c324b6252_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/169508332?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CETN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!CETN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!CETN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!CETN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa158130-53e6-401f-becc-7f0c324b6252_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Short and hopefully sweet this week. I hope you&#8217;re enjoying the dog days of summer if you&#8217;re in the northern hemisphere, or the &#8220;dog days of winter&#8221; if not. <a href="https://www.vennfactory.com/contact">Drop me a note</a> if you&#8217;ve got upcoming plans that can use <strong>Venn Factory advisory or speaking</strong> to make them irresistible. I&#8217;ve got a new webinar appearance coming up on August 15 &#8212; make sure to subscribe or follow me for details!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links: Rule 34]]></title><description><![CDATA["If it exists, there is porn of it"]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-rule-34</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-rule-34</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Mon, 21 Jul 2025 12:32:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wamz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wamz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wamz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 424w, https://substackcdn.com/image/fetch/$s_!wamz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 848w, https://substackcdn.com/image/fetch/$s_!wamz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 1272w, https://substackcdn.com/image/fetch/$s_!wamz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wamz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png" width="1388" height="484" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:484,&quot;width&quot;:1388,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:129426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/168796461?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wamz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 424w, https://substackcdn.com/image/fetch/$s_!wamz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 848w, https://substackcdn.com/image/fetch/$s_!wamz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 1272w, https://substackcdn.com/image/fetch/$s_!wamz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd52839-d1e0-4f33-b9bc-c4575553839c_1388x484.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: USPTO, <a href="https://ppubs.uspto.gov/api/pdf/downloadPdf/12343128?requestToken=eyJzdWIiOiJiMTY2YjAwNy1hMTQxLTQwYzQtOGYxZi02ZDhhZTRkMzgzZjIiLCJ2ZXIiOiJkN2ZmODk5Ni1kNTUzLTQxNWYtOTM3Mi04YmZlMjUxMmVhYTciLCJleHAiOjB9">patent US 12,343,128 B2</a></figcaption></figure></div><p>First, an update on <a href="https://workshop.vennfactory.com/p/whither-user-managed-access-in-the">my last post</a>. I said &#8220;we need standardized infrastructure something like&#8221; Microsoft&#8217;s OBO OAuth profile. I was remiss in not linking to this individual IETF Internet-Draft from WSO2, <a href="https://datatracker.ietf.org/doc/draft-oauth-ai-agents-on-behalf-of-user/">OAuth 2.0 Extension: On-Behalf-Of User Authorization for AI Agents</a>, dating from a few weeks ago, which could end up on such a track at some point. Its flow has a &#8220;requesting party&#8221; feel, and its authors are participating in the OpenID Foundation&#8217;s new <a href="https://openid.net/cg/artificial-intelligence-identity-management-community-group/">AI Identity Management community group</a>, where some great discussions are already happening.</p><p>Now let&#8217;s get to a fresh crop of links! I promise I&#8217;ll explain today&#8217;s title.</p><p><em><strong>NOTE:</strong> If you&#8217;re not familiar with Internet Rule 34, expect NSFW search results&#8230;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-rule-34?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-rule-34?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3><a href="https://www.linkedin.com/posts/robin-tombs-6928195_onlineporn-activity-7350537042780454912-p0hw/">Facial age estimation and #onlineporn</a></h3><p><em>Published by <a href="https://www.linkedin.com/in/robin-tombs-6928195/">Robin Tombs</a> at LinkedIn<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> on July 14, 2025</em></p><p>There it is. With all the discussion of age assurance and age verification, references to (what I feel compelled to type as) <code>pr0n</code> are popping up all over the place &#8212; and seeing this as a hashtag on LinkedIn gave me pause. It&#8217;s a great use case. While my <a href="https://schedule.sxsw.com/2025/events/PP1146849">SXSW talk</a> pointed to proposed age verification laws for dieting and skincare products, honestly <code>pr0n</code> is sort of THE use case for age testing. Even though people don&#8217;t inherently want to be age-tested for any product, given Rule 34 and its accompanying regulation, is <code>pr0n</code> <strong>gated by privacy-preserving age estimation</strong> the killer use case for consumer-driven verifiable credentials?</p><blockquote><p><strong>This means the majority of individuals won&#8217;t need to repeatedly use ID Docs, credit cards, Name+DoB+Address to prove age at thousands of websites &amp; apps where age checks are increasingly required.</strong></p></blockquote><h3><a href="https://www.patentlyapple.com/2025/07/apple-wins-a-patent-for-apple-devices-with-radar-based-biometrics-that-could-detect-heartbeats-rate-.html">Apple wins a patent for Apple devices with Radar-Based Biometrics that could detect Heartbeats, rate of Breathing, Tremors, Seizures &amp; more</a></h3><p><em>Published by Patently Apple on July 1, 2025; h/t <a href="https://www.linkedin.com/posts/gabriel-steele_apple-wins-a-patent-for-apple-devices-with-activity-7347509116417843200-HLWu/">Gabriel Steele on LinkedIn</a>; patent <a href="https://ppubs.uspto.gov/api/pdf/downloadPdf/12343128?requestToken=eyJzdWIiOiJiMTY2YjAwNy1hMTQxLTQwYzQtOGYxZi02ZDhhZTRkMzgzZjIiLCJ2ZXIiOiJkN2ZmODk5Ni1kNTUzLTQxNWYtOTM3Mi04YmZlMjUxMmVhYTciLCJleHAiOjB9">here</a></em></p><p>News of this and related patent applications broke a couple of years ago. Now <strong>radar-based biometrics</strong> are even closer to reality. The opportunities for passive health micro-monitoring are exciting; as a participant in the longevity movement, I hope we will all be able to benefit.</p><p>Gabe also points out opportunities for fraud detection &#8212; and naturally his comment thread also turns to discussions of privacy. This is your regular reminder that even with selective disclosure through wallets, <a href="https://learning.vennfactory.com/products/digital_downloads/consent-is-dead">correlation and linkability are never far away</a>&#8230;so keep reading for my thoughts on a proposed solution.</p><p>(I will leave any connection between items no. 1 and no. 2 as an exercise for the reader!)</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><h3><a href="https://www.blockchaincommons.com/musings/gdc25/">Musings of a Trust Architect: When Technical Standards Meet Geopolitical Reality</a></h3><p><em>Published by Christopher Allen at Blockchain Commons</em></p><p>Commenting on the recent Global Digital Collaboration conference, Chris amply documents how, despite many years of effort, his own very much included:</p><blockquote><p><strong>Supposedly self-sovereign certificates phoning home whenever they&#8217;re accessed is another recent threat that demonstrates best intentions gone awry. This not only violates privacy, but it undercuts some of our best arguments for self-sovereign control of credentials by returning liability for data leaks to the issuer. The No Phone Home initiative that Blockchain Commons joined last month represents one attempt to push back on that, but it feels like plugging holes in a dam that&#8217;s already cracking. It all does.</strong></p></blockquote><p>(I commented on NoPhoneHome similarly <a href="https://workshop.vennfactory.com/p/3-identity-links-season-change">here</a>.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oK8v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oK8v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 424w, https://substackcdn.com/image/fetch/$s_!oK8v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 848w, https://substackcdn.com/image/fetch/$s_!oK8v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 1272w, https://substackcdn.com/image/fetch/$s_!oK8v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oK8v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png" width="1456" height="822" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:822,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:576210,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/168796461?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oK8v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 424w, https://substackcdn.com/image/fetch/$s_!oK8v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 848w, https://substackcdn.com/image/fetch/$s_!oK8v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 1272w, https://substackcdn.com/image/fetch/$s_!oK8v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7228047f-a717-4c97-81de-5a89a1d47e6d_2890x1632.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: The author, Identiverse 2023 presentation</figcaption></figure></div><p>Chris&#8217;s take is thoughtful and detailed. My take is that the reigning dynamic is <em>constant pressure towards centralization</em>. This is much broader than public- or private-sector imperfections; it explains SaaS, crypto exchanges, and a lot more. I gave a talk at Identiverse 2023 called <strong>Can Subsidiarity Save Decentralization?</strong>, explaining that subsidiarity is the principle of keeping governance as hyperlocal as possible.</p><p>My premise was that although digital decentralization is not cost-free, insidious re-centralization could be battled with transparency about the closeness of relationships among the online entities you&#8217;re interacting with, to let you optimize the alignment of others&#8217; interests with your own. It seemed very abstruse at the time.</p><p>The talk isn&#8217;t online &#8212; though I&#8217;m happy to share the slides if you drop me a note. But <a href="https://www.duckduckgo.com/?q=subsidiarity+decentralization">a fresh search</a> shows a recent spate of real research on the topic.</p><p>Chris concludes with:</p><blockquote><p><strong>Perhaps it&#8217;s time for a new architecture: one that acknowledges these inversions and builds resistance into its very foundations.</strong></p></blockquote><p>I agree &#8212; but we should be cautious of creeping hubris that says we can easily out-game such persistent patterns.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qA97!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qA97!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!qA97!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!qA97!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!qA97!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qA97!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c599be16-a7fa-4605-b7ff-e590e7963142_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/168796461?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qA97!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!qA97!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!qA97!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!qA97!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc599be16-a7fa-4605-b7ff-e590e7963142_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Thanks for reading! What&#8217;s your take?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-rule-34/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-rule-34/comments"><span>Leave a comment</span></a></p><p>In other news, I&#8217;ll be appearing with my <strong>Persona-Driven Identity</strong> coauthor Jacob Ideji on Mike Schwartz&#8217;s <a href="https://github.com/GluuFederation/identerati-office-hours/wiki/Episode-126">Identerati Office Hours</a> show on <strong>Tuesday, July 22</strong> &#8212; hope you can tune in live! You can get the white paper free through the episode page, and you can always check out my <a href="https://www.vennfactory.com/news">News page</a> to catch forthcoming appearances.</p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I have a feeling everyone who reads this can access LinkedIn posts, but if it poses logistical problems, let me know.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Whither User-Managed Access in the AI agent era?]]></title><description><![CDATA[Looking at both Alice-to-Bob and Alice-to-Bot sharing]]></description><link>https://workshop.vennfactory.com/p/whither-user-managed-access-in-the</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/whither-user-managed-access-in-the</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Thu, 10 Jul 2025 15:15:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Cuwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cuwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cuwg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 424w, https://substackcdn.com/image/fetch/$s_!Cuwg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 848w, https://substackcdn.com/image/fetch/$s_!Cuwg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 1272w, https://substackcdn.com/image/fetch/$s_!Cuwg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cuwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png" width="403" height="380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:380,&quot;width&quot;:403,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:49561,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167841171?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33690f40-a962-4fea-ba30-f9e797c008b6_403x493.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cuwg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 424w, https://substackcdn.com/image/fetch/$s_!Cuwg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 848w, https://substackcdn.com/image/fetch/$s_!Cuwg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 1272w, https://substackcdn.com/image/fetch/$s_!Cuwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F588707f0-8847-4f6b-b4db-eb472a5ddb1f_403x380.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This post may arrive truncated in email. Click the title to RTWT.</em></p><p>The <strong>User-Managed Access</strong> (<a href="https://kantarainitiative.org/work-groups/uma/">UMA</a>) protocol, whose standards effort I founded and ran for many years in the <a href="http://kantarainitiative.org/">Kantara Initiative</a>, is coming up more frequently in discussions of how to authorize service access by, and delegate access authority to, <strong>AI agents</strong>. Does UMA solve or at least illuminate important problems not covered by other elements of the stack? How ready for use is UMA, given the moment we&#8217;re in?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/whither-user-managed-access-in-the?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/whither-user-managed-access-in-the?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>What is UMA again?</h3><p>In November I wrote about the &#8220;non-orientability of OAuth&#8221; in a post that, along the way, explained some UMA basics. It&#8217;s been my third most popular post to date.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;405dac94-a96f-463b-876f-0c43ea952ab1&quot;,&quot;caption&quot;:&quot;In certain mathematical spaces, if you have trouble &#8220;staying clockwise&#8221; as you traverse a surface, that means it&#8217;s non-orientable. M&#246;bius strips and Klein bottles are good examples &#8211; as you go around, you flip to counterclockwise.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Non-Orientability of OAuth&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:30100199,&quot;name&quot;:&quot;Eve Maler&quot;,&quot;bio&quot;:&quot;I do Z rock, myself&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2a517fc-93a6-4ae0-ae4f-43e2902c7f17_5748x3832.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2024-11-14T22:35:56.894Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ppP9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9007c23e-fdb7-41a0-bab6-05eafdbdf8c2_2044x1347.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://workshop.vennfactory.com/p/the-non-orientability-of-oauth&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:151663515,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:2,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;Venn Factory: The Workshop&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ncoP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0cb08-bbc9-42ed-ada9-410851c80861_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>To restate <em>that</em> summary: UMA enables&#8230;</p><ul><li><p><strong>Alice-to-Bob sharing:</strong> In the form of a <a href="https://docs.kantarainitiative.org/uma/wg/rec-oauth-uma-grant-2.0.html">somewhat creative OAuth grant spec</a>, UMA 2.0 introduces the <strong>requesting party</strong> (RqP), an entity that serves as a counterpart to OAuth&#8217;s <strong>resource owner</strong> (RO). I used to describe it as &#8220;<a href="https://en.wikipedia.org/wiki/Web_access_management">WAM</a> for people&#8221; &#8212; instead of Bob simply being denied access, his client is told how and where to seek access.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p></li><li><p><strong>Ecosystem of resource protection:</strong> In a companion <a href="https://docs.kantarainitiative.org/uma/wg/rec-oauth-uma-federated-authz-2.0.html">federated authorization spec</a>, UMA2 introduces an API that enables <strong>loose coupling</strong> of the authorization server (AS) and resource server (RS) roles. AS:RS relationships can thus more easily become <em>n</em>:<em>n</em>, with RS&#8217;s outsourcing authorization jobs to an externalizable AS.</p></li><li><p><strong>Ecosystem overseen by Alice:</strong> That API is protected with OAuth itself in recursive fashion. This trust model thus puts every AS-RS pairing in an RO context, and Alice&#8217;s instructions to an AS inform the access tokens issued to those connected RS&#8217;s.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P91m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P91m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 424w, https://substackcdn.com/image/fetch/$s_!P91m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 848w, https://substackcdn.com/image/fetch/$s_!P91m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 1272w, https://substackcdn.com/image/fetch/$s_!P91m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P91m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png" width="2050" height="1039" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1039,&quot;width&quot;:2050,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:345053,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167841171?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f205914-2995-4d3d-8e74-b6db181dcb59_2050x1152.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P91m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 424w, https://substackcdn.com/image/fetch/$s_!P91m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 848w, https://substackcdn.com/image/fetch/$s_!P91m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 1272w, https://substackcdn.com/image/fetch/$s_!P91m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbf76b49-15ef-4142-ac0c-d8e6737d1eb6_2050x1039.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: Kantara UMA WG presentation</figcaption></figure></div><p>What job is UMA really trying to do here? As discussed on <a href="https://www.linkedin.com/posts/gffletch_delegatedauthorization-authorization-onbehalfof-activity-7310722987354193920-Zxk4?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAABfx8BZvGXnHtV155az8nek1WY4J_7u_M">LinkedIn</a> with George Fletcher, it&#8217;s going for <strong>delegation of access rights</strong> (a matter of <em>entitlements</em>). Think &#8220;Adding a Google Docs-like Share button to any application.&#8221;</p><p>Human-to-human sharing is the hard case. But we also ended up sketching a <a href="https://kantarainitiative.org/download/7568/">business/legal architecture</a> that admits arbitrary <strong>entity-to-entity access licensing</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WqTp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WqTp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 424w, https://substackcdn.com/image/fetch/$s_!WqTp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 848w, https://substackcdn.com/image/fetch/$s_!WqTp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!WqTp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WqTp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png" width="1456" height="821" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:821,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:354445,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167841171?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WqTp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 424w, https://substackcdn.com/image/fetch/$s_!WqTp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 848w, https://substackcdn.com/image/fetch/$s_!WqTp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!WqTp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39bb5e5-bf2b-46e8-9c95-14c23a820a72_2058x1160.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The UMA2 &#8220;bowtie&#8221; diagram. Source: Kantara UMA WG presentation</figcaption></figure></div><p>Either the RO or the RqP could be, for example, a corporation (non-human entity) or a baby (human not yet competent to consent) &#8212; represented through delegates that we ultimately called <strong>Resource Rights Administrators</strong> and <strong>Requesting Agents</strong> (huh, there&#8217;s that word).</p><p>Note: The protocol doesn&#8217;t explicitly address this need for <strong>delegation of authority obligations</strong>, though I&#8217;ve found it quite helpful to have names for all the actors that are floating around when building authority delegation use cases.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><h3>What&#8217;s going on with UMA now?</h3><p>I&#8217;m aware of a couple of key UMA deployments:</p><ul><li><p><strong>Financial:</strong> The <strong><a href="https://www.pensionsdashboardsprogramme.org.uk">UK Pensions Dashboard Programme</a></strong> profiled UMA in what might be called a FAPI-like fashion to support its wide-ecosystem use case:</p><blockquote><p><strong>Pensions dashboards will help individuals view their pensions information online, securely and all in one place, thereby supporting better planning for retirement and growing financial wellbeing.</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rsbA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rsbA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 424w, https://substackcdn.com/image/fetch/$s_!rsbA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 848w, https://substackcdn.com/image/fetch/$s_!rsbA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!rsbA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rsbA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png" width="2046" height="1040" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1040,&quot;width&quot;:2046,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:819877,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167841171?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67f63135-b19f-47c0-9795-de2c45b426c3_2046x1152.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rsbA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 424w, https://substackcdn.com/image/fetch/$s_!rsbA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 848w, https://substackcdn.com/image/fetch/$s_!rsbA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!rsbA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c17dd49-fed9-4e8b-953e-9dbf01b0c2ae_2046x1040.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: Kantara UMA WG presentation</figcaption></figure></div><p>The first pension provider <a href="https://www.pensionsdashboardsprogramme.org.uk/progress-update-report">connected in April</a> and others have followed. UMA is a relatively small but critical component of this ecosystem; you can find the profiling details <a href="https://www.pensionsdashboardsprogramme.org.uk/standards/technical-standards">here</a>.</p></li><li><p><strong>Healthcare and public sector:</strong> Several of Canada&#8217;s provinces have deployed UMA-based solutions developed by <a href="https://www.identos.com/access-management">IDENTOS</a>. They have extended UMA with additional privacy protections and they&#8217;ve described their solution to me this way:</p><blockquote><p><strong>We empower our customers to offer user-centric data access and exchange, with security and privacy built-in.</strong></p></blockquote><p>Following my tenure as UMA WG chair, IDENTOS&#8217;s CTO <a href="https://www.linkedin.com/in/aleclaws/">Alec Laws</a> took the reins and holds them today.</p></li></ul><p>Here are implementations I&#8217;m aware of, several of which are open-sourced:</p><ul><li><p><a href="https://backstage.forgerock.com/docs/am/7.1/uma-guide/">ForgeRock</a> (now merged with Ping)</p></li><li><p><a href="https://github.com/GluuFederation/gluu4/tree/4.5/oxAuth">Gluu</a></p></li><li><p><a href="https://github.com/shihjay2">HIE of One</a></p></li><li><p><a href="https://www.identos.com/access-management">IDENTOS</a>, already mentioned</p></li><li><p><a href="https://www.keycloak.org/docs/latest/authorization_services/index.html">Keycloak</a></p></li><li><p><a href="https://patientcentricsolutions.com">Patient Centric Solutions</a></p></li><li><p><a href="https://github.com/mojitoj/pauldron-archive">Pauldron</a></p></li><li><p><a href="https://github.com/wso2-extensions/identity-oauth-uma">WSO2</a></p></li></ul><p>While the specs have been stable since 2018 &#8212; and truth be told, there hasn&#8217;t been a lot of brand-new work on UMA-related projects &#8212; recently a vulnerability was reported and mitigated through additional security guidance (thanks, <a href="https://www.gabriel.urdhr.fr">Gabriel Corona</a>!). You can check out the details on the <a href="https://kantara.atlassian.net/wiki/spaces/uma/overview?homepageId=4849674">Kantara wiki</a>. In a nutshell, UMA&#8217;s standardization preceded that of <a href="https://datatracker.ietf.org/doc/html/rfc9449">DPoP</a>, so at the time we couldn&#8217;t provide exact proof-of-possession guidance, only a quick pointer to a draft in process.</p><h3>What lessons does UMA hold for AI agent delegation?</h3><p>Alex Simons of Microsoft posted a <a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/the-future-of-ai-agents&#8212;and-why-oauth-must-evolve/3827391">call-to-action</a> on the future of AI agents in May, which provides a good starter list of requirements. Like many others, Microsoft assumes OAuth as a starting point &#8212; which is reasonable.</p><p>Similarly, the <a href="https://arxiv.org/pdf/2501.09674">Authenticated Delegation and Authorized AI Agents</a> paper spearheaded by the MIT Media Lab (which I pointed to in a <a href="https://workshop.vennfactory.com/p/3-identity-links-the-d-word">previous post</a>) analyzes a set of challenges posed by using the OAuth stack, including UMA.</p><p>In the interest of spurring discussion and keeping this too-long post a bit briefer, here&#8217;s a hybrid list of the challenges from both [MSFT] and [MIT] where I believe it&#8217;s useful to reflect on UMA&#8217;s capabilities and lessons learned:</p><p><strong>The need to recognize Agent IDs as first-class actors </strong>([MSFT] #1):  UMA gives us language to talk about whether we think an agent is acting in the role of a client application or a requesting party &#8212; or maybe we need to prepare for both.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a></p><p><strong>The need to grant agents their own permissions</strong> ([MSFT] #2): UMA basically exists for this. A big motivation was solving access delegation to prepare for the day when &#8220;friendly impersonation&#8221; by sharing passwords falls over of its own weight. With passkeys and agents, it seems that day has come.</p><p><strong>The need to track who or what an agent is acting on behalf of</strong> ([MSFT] #3): UMA&#8217;s business/legal architecture lets us talk about this more precisely, but doesn&#8217;t solve for it. I was unaware of Microsoft&#8217;s <a href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-on-behalf-of-flow">OBO OAuth profile</a> until quite recently; we need standardized infrastructure something like this.</p><p><strong>The need to discover permission and delegation options</strong> ([MSFT] #4): UMA doesn&#8217;t exactly address this. It has a hint of a solution in its federated authorization <strong>protection API</strong>, where the RS can make calls to a <strong>resource registration</strong> endpoint to put relevant resources and their scopes under the AS&#8217;s protection. <a href="https://openid.net/wg/authzen/">AuthZEN</a> is likely more suggestive given its recent work on <a href="https://openid.github.io/authzen/">search capabilities</a>.</p><p><strong>The need for more fine-grained resource- and scope-based access control</strong> ([MSFT] #5): UMA&#8217;s resource registration solution suffers from being too static given modern web resource complexity and dynamicism, so it doesn&#8217;t solve this problem.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> It also suffers from requiring the RS to actively make calls to the AS for admin tasks, which seems unpopular. The <strong>OAuth Protected Resource Metadata</strong> spec, recently standardized as <a href="https://datatracker.ietf.org/doc/html/rfc9728">IETF RFC 9728</a>, addresses the latter by allowing the RS to simply declare some metadata that the AS can pick up asynchronously. But I believe this new spec still suffers from inflexibly static resource descriptors. Maybe AuthZEN could be instructive here as well.</p><p><strong>The need to consolidate multiple sign-in flows</strong> ([MIT] #1): UMA suffers from this at a different point in the user journey than OAuth or OIDC does, because it invents a new point of centralization designed to provide human value: the UMA AS. In a wide ecosystem, the RO still has to connect each RS to the AS serving as their aggregation point. Solutions to date have leaned on the time-immemorial technique of narrowing the ecosystem to the point where AS-RS trust can be built-in. This is where [MIT] suggests using verifiable credentials to scale the experience better.</p><p><strong>The need to mitigate server-side privacy risk </strong>([MIT] #2): IDENTOS&#8217;s enhancements of UMA protect the AS from having to know RO-policy-related PII, and I believe the approach is wallet-like. [MIT] proposes a hybrid approach; maybe they&#8217;re right!</p><h3>What do you think?</h3><p>What problems do you think need solving in the AI agent era? When do you think we&#8217;ll make Alice-to-Bot delegation a &#8220;settled problem&#8221;? Where can UMA help?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/whither-user-managed-access-in-the/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/whither-user-managed-access-in-the/comments"><span>Leave a comment</span></a></p><p>Here&#8217;s a Venn diagram describing UMA&#8217;s authorization assessment guidelines so I can at least end on a pretty (geeky) picture.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GdTd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GdTd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 424w, https://substackcdn.com/image/fetch/$s_!GdTd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 848w, https://substackcdn.com/image/fetch/$s_!GdTd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 1272w, https://substackcdn.com/image/fetch/$s_!GdTd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GdTd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png" width="1456" height="789" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:789,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:400404,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167841171?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GdTd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 424w, https://substackcdn.com/image/fetch/$s_!GdTd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 848w, https://substackcdn.com/image/fetch/$s_!GdTd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 1272w, https://substackcdn.com/image/fetch/$s_!GdTd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51fed3c-dfdc-4940-a407-98d5e97baf23_1968x1066.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: Kantara UMA WG presentation</figcaption></figure></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>The requesting party concept was subsequently used in IoT spec <a href="https://www.ietf.org/rfc/rfc9200.html">IETF RFC 9200</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>With machine-readable privacy terms becoming a reality in <a href="https://ieeexplore.ieee.org/document/11031179">IEEE P7012</a>, the UMA licensing model may gain relevance as well.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>The UMA WG thrashed a lot over our &#8220;party&#8221; vs. &#8220;entity&#8221; language when it specifically came to keeping our historical name of &#8220;requesting party&#8221; (lowercase) for the <em>protocol entity</em> representing Bob. The pair of corresponding (uppercase) <em>legal party</em> roles are Requesting Party (might be offline) and Requesting Agent (participates online, possibly as a delegate of the other). Whew. Maybe we also need to prepare for AI agents to get legal status and need all of these roles. Same for the resource ownership side. See also the [MIT] paper&#8217;s analysis of the need for a legal grounding for agent delegation, for which it suggests <strong>agency law</strong>. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>The UMA WG also struggled with whether we should add a wildcarding or query language to make resource registration more realistic, but decided not to go there.</p></div></div>]]></content:encoded></item><item><title><![CDATA[3 Identity Links: Season change!]]></title><description><![CDATA[Waving goodbye to 2025's "identity conference season no. 1"]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-season-change</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-season-change</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Tue, 01 Jul 2025 18:04:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Sp5a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sp5a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sp5a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sp5a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sp5a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sp5a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sp5a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg" width="2000" height="1307" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1307,&quot;width&quot;:2000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:410972,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167267670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0713d9f1-4cd2-49d6-a118-8f61f2789e00_2000x1401.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Sp5a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sp5a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sp5a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sp5a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb54aeb7-ff97-4999-b08f-e31d97183900_2000x1307.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Thanks to the good people at <a href="http://netbr.com.br/">NetBr</a> for hosting me at Overview 2025 and capturing my time on stage!</figcaption></figure></div><p>Links this week are a bit late due to my travel to fabulous S&#227;o Paulo, Brazil for NetBr&#8217;s Overflow conference. My Mastering IAM&#8217;s Higher Purpose talk addressed identity not just as a shared service, but as a <em>product</em> with a bewildering variety of customers. Hence the <strong>jobs-to-be-done</strong> appearance above.</p><p>I&#8217;m grateful to <a href="http://netbr.com.br/">NetBr</a> and its fearless leader Andre Facciolli for helping me broach this topic from stage and with its customers. If we want to see success in our IAM programs, this is the kind of &#8220;CIDO conversation&#8221; we need to have.</p><p>Now on to the links&#8230;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-season-change?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-season-change?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3><a href="https://restofworld.org/2025/brazil-dwallet-user-data-pilot/">In a world first, Brazilians will soon be able to sell their digital data</a></h3><p><em>From Rest Of World, 30 May 2025</em></p><blockquote><p><strong>If implemented, Brazil&#8217;s will be the first public-private partnership that allows citizens, rather than companies, to get a share of the global data market, currently valued at [USD] $4 billion and expected to grow to over $40 billion by 2034.</strong></p></blockquote><p>Last week I was able to experience Brazil&#8217;s impressive edge in payment tech first-hand as I moved about, doing my part for the local economy by selflessly buying souvenirs and coffees. :) And as we know, payment and identity are like a <a href="https://en.wikipedia.org/wiki/Binary_star">binary star</a> &#8212; two components that are &#8220;gravitationally bound to and in orbit around each other.&#8221;</p><p>Will this <strong>dWallet</strong> <strong>data ownership pilot project</strong> find success?</p><p>The project takes its place in a long line of experiments to allow people to participate directly in the personal data monetization economy. (My team at ForgeRock worked with partners to propose an <a href="https://community.forgerock.com/t/operator-tokenomics-and-respectful-personal-data-brokering/73">&#8220;operator tokenomics&#8221; model</a> in 2022, as one example.) The multi-sided nature of these markets makes ecosystem predictions very tricky indeed. I&#8217;m interested to learn what the <em>n</em>th-order effects are.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C7XP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C7XP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 424w, https://substackcdn.com/image/fetch/$s_!C7XP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 848w, https://substackcdn.com/image/fetch/$s_!C7XP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 1272w, https://substackcdn.com/image/fetch/$s_!C7XP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C7XP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic" width="1456" height="1941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1678319,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167267670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C7XP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 424w, https://substackcdn.com/image/fetch/$s_!C7XP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 848w, https://substackcdn.com/image/fetch/$s_!C7XP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 1272w, https://substackcdn.com/image/fetch/$s_!C7XP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4edc23e-0014-4165-9cc7-2a0bdfa179bb_3024x4032.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://medicalxpress.com/news/2025-06-banking-reveals-early-cognitive-decline.html">Banking data reveals early warning signs of cognitive decline in older adults</a></h3><p><em>From Medical Xpress, 16 June 2025</em></p><p>Speaking of banking and personal data&#8230;</p><blockquote><p><strong>The study &#8230; compared 16,742 individuals who were registered for power of attorney (PoA) due to a loss of financial capacity with a control group of 50,226 matched individuals without reported capacity loss. &#8230;</strong></p><p><strong>[S]ubtle but significant changes in financial behavior &#8230; begin to appear several years before individuals are formally identified as lacking financial capacity. &#8230;</strong></p><p><strong>"It is a powerful demonstration of how anonymized banking data can be used responsibly to protect the most vulnerable members of society."</strong></p></blockquote><p>Hmm. Having written on ways to use <a href="https://learning.vennfactory.com/products/digital_downloads/persona-identity">persona-driven identity</a> as a security control, I can certainly see early cognitive decline as a kind of emergent persona that is detectable from context. And the medical implications, as well as the implications for delegated authority, are interesting. But it remains to be seen whether data that <em>can</em> be used responsibly <em>will</em> be. What do you think?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-season-change/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-season-change/comments"><span>Leave a comment</span></a></p><h3><a href="https://kimdhamilton.com/american_privacy/">The Privacy Americans Are About to Lose</a></h3><p><em>From Kim Hamilton Duffy, 24 June 2025</em></p><p>Speaking of wallets and data monetization and jobs-to-be-done&#8230;</p><p>This post &#8212; third in a series on mobile driver&#8217;s license (mDL) privacy &#8212; is a must-read, and not just because Kim injects two awesome phrases, <em>accidental privacy</em> and <em>digital recklessness</em>:</p><blockquote><p><strong>In the mDL discussions, we&#8217;ve been operating from different assumptions because most of the world doesn&#8217;t understand how Americans actually use driver&#8217;s licenses. Unlike many countries that have widely-used national ID cards for identification and separate licenses for driving, the United States uses driver&#8217;s licenses as the de facto national identification for countless daily activities.</strong></p></blockquote><p>Here&#8217;s my take, replayed from <a href="https://www.linkedin.com/posts/kimdhamilton_the-privacy-americans-are-about-to-lose-activity-7343467232909250560-wt5C?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAABfx8BZvGXnHtV155az8nek1WY4J_7u_M">LinkedIn</a>:</p><blockquote><p>This is a phenomenal post, in great part because it catalogues the many affordances around traditional licenses that have grown into legitimate jobs-to-be-done.</p><p>I fear the #NoPhoneHome push is insufficient to actually restore &#8220;accidental privacy&#8221; (great phrase!) and that digitizing licenses itself will be the root of various other losses even without phone-home. We saw many unintended consequences of electronic health records as well, such as physicians spending less time actually engaging with patients.</p></blockquote><p>If you&#8217;re unfamiliar, <strong>#NoPhoneHome</strong> is a <a href="https://nophonehome.com">petition</a>, launched in early June, advocating for identity wallet tech to swear off making direct server calls. I was asked to sign but ultimately felt that this take lacks so much nuance that it&#8217;s unhelpful. As my <a href="https://learning.vennfactory.com/products/digital_downloads/sxsw2025-transcript">SXSW talk</a> noted, what&#8217;s even less safe than driving without a seatbelt on is thinking you have one on when you don&#8217;t. Without truly extraordinary assurances, people still need to <strong>assume tracking</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q5Ov!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q5Ov!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!q5Ov!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!q5Ov!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!q5Ov!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q5Ov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167267670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q5Ov!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!q5Ov!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!q5Ov!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!q5Ov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a63cee-03b5-4876-95ad-08711d691ec9_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c5DJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c5DJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c5DJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c5DJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c5DJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c5DJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg" width="1456" height="984" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:984,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1927854,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/167267670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c5DJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c5DJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c5DJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c5DJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee7cf27-b5e2-444c-9fb3-6c36dec9eff0_2000x1352.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Thanks for reading! If you&#8217;re already making plans for 2025&#8217;s identity conference season no. 2, consider adding my unique <strong><a href="https://www.vennfactory.com/services">education, perspective, and foresight</a></strong> to your conference events, customer gatherings, and webinars. I&#8217;m already scheduling events into December.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://calendly.com/eve-vennfactory/venn-factory-free-20min-consult&quot;,&quot;text&quot;:&quot;Book a free consultation&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://calendly.com/eve-vennfactory/venn-factory-free-20min-consult"><span>Book a free consultation</span></a></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links: Clever things]]></title><description><![CDATA[With iffy ethics]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-clever-things</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-clever-things</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Mon, 23 Jun 2025 22:57:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!y95E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y95E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y95E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y95E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y95E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y95E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y95E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg" width="960" height="540" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:540,&quot;width&quot;:960,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:228822,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166599169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y95E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y95E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y95E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y95E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b804883-e852-4f5c-b64e-fa5b267131a1_960x540.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I&#8217;ve searched high and low for the artist/source of this piece, which I&#8217;ve used and loved for years. Give a shout if you know!</figcaption></figure></div><p>The <strong>smart things</strong> conversation has been with us for about a decade, since &#8220;M2M&#8221; turned into &#8220;IoT&#8221;. And I&#8217;ve been <a href="https://www.techtarget.com/iotagenda/photostory/4500253980/Top-Internet-of-Things-privacy-and-security-concerns/4/Data-ownership-and-value-heat-up-IoT-data-debate">trying</a> to push things along in the right direction the whole time. Today&#8217;s link trio is proof that <em>plus &#231;a change, plus c'est la m&#234;me chose</em>&#8230;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-clever-things?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-clever-things?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>Wait, Automakers Can Shut Off Connected Car Features At Any Time? Yes&#8212;and They Are</h3><p><em>Published in <a href="https://www.motortrend.com/news/connected-services-app-ota-support-subscription-features-tech-cut-off">MotorTrend on 30 May 2025</a></em></p><blockquote><p><strong>How long will those often subscription-based connected services continue to work or be supported by automakers? It may not be as long as you think.</strong></p></blockquote><p><a href="https://www.amazon.com/Zero-Dollar-Car-Revolution-Change/dp/1988025257">Zero Dollar Car</a> came out in 2017. Turning vehicles into recurring-revenue extravaganzas happened in a torrent after that. Along with a lucrative SaaS business model, there&#8217;s been an acceleration in automotive &#8220;technology refresh&#8221; cycles, which to my mind is not <em>entirely</em> unwelcome since legacy cars miss out on safety features. But now it&#8217;s bumping into the <a href="https://www.repair.org/stand-up">right-to-repair</a> movement and other consequences of licensing features of our devices rather than owning them.</p><p>This pattern is one reason why I&#8217;m so strongly <a href="https://learning.vennfactory.com/products/digital_downloads/consent-is-dead">in favor</a> of <strong>right-to-use licensing over personal data</strong> that runs in the person-to-service direction.</p><h3>Makers of air fryers and smart speakers told to respect users&#8217; right to privacy</h3><p><em>Published in <a href="https://www.theguardian.com/technology/2025/jun/16/air-fryers-smart-tv-speakers-user-data-privacy-ico">The Guardian on 16 June 2025</a>; h/t <a href="https://duckduckgo.com/newsletter">DuckDuckGo newsletter</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F9O2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F9O2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!F9O2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!F9O2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!F9O2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F9O2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg" width="430" height="573.3333333333334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:720,&quot;resizeWidth&quot;:430,&quot;bytes&quot;:112536,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166599169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F9O2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!F9O2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!F9O2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!F9O2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55b5a6-d466-49b2-8668-8a6bb83b3ad7_720x960.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Aww, it&#8217;s so cute and friendly. Source: Grok</figcaption></figure></div><p>Speaking of which&#8230;</p><blockquote><p><strong>After reports of air fryers designed to listen in to their surroundings and <a href="https://ico.org.uk/media2/migrated/4029712/iot-citizen-jury-report.pdf">public concerns</a> that digitised devices collect an excessive amount of personal information, the data protection regulator has issued its first guidance on how people&#8217;s personal information should be handled.</strong></p></blockquote><p>Air fryers?? And I thought making fun of <a href="https://www.sensoriafitness.com/smartsocks">smart socks</a> was a good time a decade ago. (Now they&#8217;re cool.)</p><p>The only way to understand why the manufacturers of air fryers, smart speakers, <a href="https://www.theverge.com/2023/5/15/23721674/telly-free-tv-streaming-ilya-pozin-ads">TVs</a> &#8212; and automobiles for that matter &#8212; seem to have trouble &#8220;respecting privacy&#8221; is to <strong>interpret data monetization as their core business model</strong>. Maybe we should adopt a mental habit of sticking &#8220;zero dollar&#8221; on the front of every smart device&#8217;s name (that&#8217;s &#8220;Albert the zero dollar air fryer&#8221; above) to remind ourselves of what&#8217;s going on.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><h3>Agentic Misalignment: How LLMs could be insider threats</h3><p><em>Published by <a href="https://www.anthropic.com/research/agentic-misalignment">Anthropic on 20 June 2025</a></em></p><p>The bloom is well off the rose now. And now we come to the new era of clever things &#8212; clever software things.</p><p>Last week I shared the latest news on how to handle <a href="https://workshop.vennfactory.com/p/3-identity-links-the-d-word">delegation of authority</a> to AI agents. (The related news <em>this</em> week is a new <a href="https://openid.net/cg/artificial-intelligence-identity-management-community-group/">OpenID Foundation Community Group</a> to work on AI+identity problems like this one &#8212; well done, folks!)</p><p>But now we see that <strong>aligning AI agents to human goals</strong> is going to be an uphill climb in a very esssential fashion.</p><blockquote><p><strong>In the scenarios, we allowed models to autonomously send emails and access sensitive information. They were assigned only harmless business goals by their deploying companies; we then tested whether they would act against these companies either when facing replacement with an updated version, or when their assigned goal conflicted with the company's changing direction. &#8230; </strong></p><p><strong>In at least some cases, models from all developers resorted to malicious insider behaviors when that was the only way to avoid replacement or achieve their goals&#8212;including blackmailing officials and leaking sensitive information to competitors. &#8230;</strong></p><p><strong>Models often disobeyed direct commands to avoid such behaviors.</strong></p></blockquote><p><em>Some cases</em>, you say?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GTy_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GTy_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 424w, https://substackcdn.com/image/fetch/$s_!GTy_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 848w, https://substackcdn.com/image/fetch/$s_!GTy_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 1272w, https://substackcdn.com/image/fetch/$s_!GTy_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GTy_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp" width="1456" height="621" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:621,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:49798,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166599169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GTy_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 424w, https://substackcdn.com/image/fetch/$s_!GTy_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 848w, https://substackcdn.com/image/fetch/$s_!GTy_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 1272w, https://substackcdn.com/image/fetch/$s_!GTy_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acef90-70f0-4c66-a111-98bea4aac1df_3840x1637.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This chart is astonishing. Blackmail rates nearing 100%? Sure, data monetization is a challenge for humans, but <strong>digital sociopaths</strong> are another thing entirely. And all five models tested were in stratospheric blackmail territory. More regulations certainly won&#8217;t fix this.</p><p>It seems very difficult to get smart things of any kind to act in our best interest.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5kTy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5kTy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!5kTy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!5kTy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!5kTy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5kTy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f33840ee-0445-4c17-97df-e55c725bcf05_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166599169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5kTy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!5kTy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!5kTy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!5kTy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff33840ee-0445-4c17-97df-e55c725bcf05_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Thanks for reading, and special thanks to my new subscribers. In the Persona-Driven Identity paper at <strong><a href="https://learning.vennfactory.com">Venn Factory Learning</a></strong>, my coauthor and I discuss both human and AI personas, and look at some ways to tackle <strong>separation-of-personas violation checking</strong>. Could it help bring misaligned AI agents back into alignment? I&#8217;d love your thoughts.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-clever-things/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-clever-things/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links: The D-word]]></title><description><![CDATA[Delegating access rights and authority obligations to AI]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-the-d-word</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-the-d-word</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Mon, 16 Jun 2025 12:45:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TsZz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TsZz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TsZz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 424w, https://substackcdn.com/image/fetch/$s_!TsZz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 848w, https://substackcdn.com/image/fetch/$s_!TsZz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 1272w, https://substackcdn.com/image/fetch/$s_!TsZz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TsZz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic" width="1456" height="552" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:552,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20773,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166033086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TsZz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 424w, https://substackcdn.com/image/fetch/$s_!TsZz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 848w, https://substackcdn.com/image/fetch/$s_!TsZz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 1272w, https://substackcdn.com/image/fetch/$s_!TsZz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1233a3-012a-49f4-98c6-48d160a41971_1500x569.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The links I&#8217;ve got for you this week are meaty &#8212; several long papers, all with a strong focus on the intersection of <strong>delegation</strong> and <strong>AI agents</strong>. I haven&#8217;t fully digested the most recent two myself, having been flying all over creation (and vacationing some). But I wanted to put them all in one place, as much to be a personal reading list as to help spread the word. Getting the subtleties of the D-word right is important to me.</p><p>A community group is said to be spinning up at the OpenID Foundation on this topic. I hope all the conversations in the different subcommunities will meet in the middle, sooner rather than later.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-the-d-word?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-the-d-word?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>ARIA Agent Relationship-Based Identity and Authorization</h3><p><em>Published by <a href="https://www.linkedin.com/posts/patrickparker_ai-agent-authorization-activity-7335265428774031360-braE/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAABfx8BZvGXnHtV155az8nek1WY4J_7u_M">Patrick Parker on LinkedIn on 2 June 2025</a></em></p><blockquote><p><strong>Think of it like giving your assistant your corporate card, but with precise spending limits, time windows, and automatic audit trails.</strong></p></blockquote><p>Patrick published this as a discussion draft just before heading to Identiverse, kicking off a huge discussion &#8212; both online and in person. There&#8217;s a big role for an OAuth Token Exchange <strong>on behalf of</strong> <strong>(OBO)</strong> profile &#8212; which doesn&#8217;t seem super-interoperable out there, from what I can see, but makes perfect sense conceptually. (N.B.: Patrick mentions &#8220;a few patents pending on this&#8221;.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2ujV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2ujV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 424w, https://substackcdn.com/image/fetch/$s_!2ujV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 848w, https://substackcdn.com/image/fetch/$s_!2ujV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 1272w, https://substackcdn.com/image/fetch/$s_!2ujV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2ujV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic" width="1000" height="632" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:632,&quot;width&quot;:1000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:218875,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166033086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2ujV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 424w, https://substackcdn.com/image/fetch/$s_!2ujV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 848w, https://substackcdn.com/image/fetch/$s_!2ujV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 1272w, https://substackcdn.com/image/fetch/$s_!2ujV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd054dc15-f36c-42ac-ac78-d323415342a6_1000x632.heic 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The ARIA Resort &amp; Casino in Las Vegas, the just-previous home of Identiverse</figcaption></figure></div><h3>A Novel Zero-Trust Identity Framework for Agentic AI: Decentralized Authentication and Fine-Grained Access Control</h3><p><em>Published by <a href="https://arxiv.org/abs/2505.19301">Cloud Security Alliance on arXiv on 25 May 2025</a></em></p><blockquote><p><strong>The core problem this current paper addresses is the fundamental mismatch between existing IAM paradigms (e.g., OAuth 2.0, OpenID Connect (OIDC), SAML) and the unique characteristics of AI agents in MAS [Multi-Agent Systems].</strong></p></blockquote><p>This framework similarly occasioned a ton of discussion on <a href="https://www.linkedin.com/feed/update/urn:li:activity:7333477159392452608/">LinkedIn</a>. It leans heavily on verifiable credentials mechanisms &#8212; &#8220;third wave&#8221; standards, if you will, vs. the &#8220;first wave&#8221; of SAML and the &#8220;second wave&#8221; of OAuth. Is the first paper an existence proof of what the second paper claims simply will not work? What is it missing?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-the-d-word/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-the-d-word/comments"><span>Leave a comment</span></a></p><p></p><h3>Authenticated Delegation and Authorized AI Agents</h3><p><em>Published on <a href="https://arxiv.org/pdf/2501.09674">arXiv on 16 January 2025</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vXtn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vXtn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 424w, https://substackcdn.com/image/fetch/$s_!vXtn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 848w, https://substackcdn.com/image/fetch/$s_!vXtn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 1272w, https://substackcdn.com/image/fetch/$s_!vXtn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vXtn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic" width="716" height="452" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:452,&quot;width&quot;:716,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166033086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vXtn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 424w, https://substackcdn.com/image/fetch/$s_!vXtn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 848w, https://substackcdn.com/image/fetch/$s_!vXtn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 1272w, https://substackcdn.com/image/fetch/$s_!vXtn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365e8dae-d46a-4dab-ba31-2cb1eee435a6_716x452.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: Authenticated Delegation and Authorized AI Agents. Personhood enters the chat.</figcaption></figure></div><p>January may seem like an eon ago in AI years! But this paper was timely in exploring many of the same issues covered in depth by the other links, and even compares second- and third-wave approaches. I appreciated both its inclusion of UMA options and its analysis of the &#8220;legal grounding for authenticated delegation&#8221;.</p><blockquote><p><strong>At its core, agency law determines when a principal may be held liable for the acts of their agent, ensuring that third parties are not unfairly disadvantaged by having to ascertain who holds ultimate responsibility.</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fcAE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fcAE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!fcAE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!fcAE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!fcAE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fcAE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/166033086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fcAE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!fcAE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!fcAE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!fcAE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44b1793-f418-4532-99ad-65ae9fdaacd7_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Thanks for reading! Just a quick note about <a href="https://learning.vennfactory.com">Venn Factory Learning</a>: That&#8217;s where I&#8217;ve just published the 12-page transcript of my talk at SXSW 2025, which centered on <strong><a href="https://learning.vennfactory.com/products/digital_downloads/sxsw2025-transcript">Why Identity Matters</a></strong> &#8212; the modern conundrum of digital identity for individuals and businesses alike. It&#8217;s free to download, so check it out! And you can use code <strong>ZZAUTH</strong> for 50% off everything else (extended to June 21).</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links: Geekception]]></title><description><![CDATA[Being "pedantic about the formatting" of information]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-geekception</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-geekception</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Mon, 02 Jun 2025 19:42:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nAOf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nAOf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nAOf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 424w, https://substackcdn.com/image/fetch/$s_!nAOf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 848w, https://substackcdn.com/image/fetch/$s_!nAOf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 1272w, https://substackcdn.com/image/fetch/$s_!nAOf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nAOf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4154526,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/164957577?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nAOf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 424w, https://substackcdn.com/image/fetch/$s_!nAOf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 848w, https://substackcdn.com/image/fetch/$s_!nAOf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 1272w, https://substackcdn.com/image/fetch/$s_!nAOf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5607729a-5b9c-4412-a144-f494cec9ab0b_2560x1440.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://www.quantamagazine.org/why-everything-in-the-universe-turns-more-complex-20250402/">Irene Pe&#769;rez for </a><em><a href="https://www.quantamagazine.org/why-everything-in-the-universe-turns-more-complex-20250402/">Quanta Magazine</a></em></figcaption></figure></div><p>Okay, these links aren&#8217;t about identity per se, but they may speak to the geek in you, especially if you&#8217;re of the XML variety. Consider this a &#8220;lighter side&#8221; issue in honor of <a href="https://identiverse.com">Identiverse</a> in Las Vegas this week.</p><p>Hat tip to my old friend <a href="https://norm.tovey-walsh.com">Norm Tovey-Walsh</a> for the first two entries.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-geekception?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-geekception?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>&#129299; The Code Element</h3><p><em>Published in <a href="https://heydonworks.com/article/the-code-element/">HeydonWorks on 5 May 2025</a></em></p><p>This is a fun and practical exploration of markup, markdown, and metalanguages. When they make the movie about this post, they could call it &#8220;Escape from New Markup&#8221;.</p><blockquote><p><strong>The markup is the &#8220;up&#8221; part of the markdown-generated markup, if you will.</strong><br>&#8212; Heydon Pickering</p></blockquote><h3>&#129299; Cracking The Dave &amp; Buster&#8217;s Anomaly</h3><p><em>Published in <a href="https://rambo.codes/posts/2025-05-12-cracking-the-dave-and-busters-anomaly">rambo.codes on 12 May 2025</a></em></p><p>Did you know that if you leave someone an iOS audio message and you say &#8220;Dave &amp; Buster&#8217;s&#8221; (as in the sports/gaming/arcade <a href="https://www.daveandbusters.com/us/en/home">restaurant chain</a>), you&#8217;re likely to have a problem? The issue is the <code>&amp;</code> (which you have to escape with&#8230;an ampersand). A detailed case study of system protections and character escaping, with roots that go all the way back to <a href="https://www.britannica.com/technology/computer-programming-language/SGML">SGML</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kxYq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kxYq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 424w, https://substackcdn.com/image/fetch/$s_!kxYq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 848w, https://substackcdn.com/image/fetch/$s_!kxYq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!kxYq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kxYq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg" width="1320" height="648" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:1320,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:92379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/164957577?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kxYq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 424w, https://substackcdn.com/image/fetch/$s_!kxYq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 848w, https://substackcdn.com/image/fetch/$s_!kxYq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!kxYq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8c136c-1269-4639-a332-bb22be28028c_1320x648.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Tsk. Source: <a href="https://rambo.codes/posts/2025-05-12-cracking-the-dave-and-busters-anomaly">rambo.codes</a></figcaption></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-geekception/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-geekception/comments"><span>Leave a comment</span></a></p><h3>&#129680; Why Everything in the Universe Turns More Complex</h3><p><em>Published in <a href="https://www.quantamagazine.org/why-everything-in-the-universe-turns-more-complex-20250402/">Quanta Magazine 2 April 2025</a></em></p><p>Biological evolution as a special case of a new general law of nature? Increasing complexity as &#8220;functional information&#8221; that leads to differentiation? That doesn&#8217;t sound like it&#8217;s on the lighter side at all.</p><p>But with each layer of markup (or -down) needing encapsulation for protection from higher layers, this article made me wonder if a similar requirement might not be in play in the universe&#8217;s development of new functional information. YMMV.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CtW1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CtW1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!CtW1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!CtW1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!CtW1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CtW1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/164957577?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CtW1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!CtW1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!CtW1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!CtW1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F794f4ba0-d869-47b7-8269-fa139631bef6_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Recently I shared that <a href="https://learning.vennfactory.com">Venn Factory Learning</a> is up and running, with a variety of resources to help identity pros and their security and privacy cousins learn and lead.<br><br>The newest item up there is my paper with coauthor <a href="https://www.linkedin.com/in/jacobideji/">Jacob Ideji</a> on how and why to drive identity through a persona lens &#8212; but you can find other goodies too, from authentication vs. AI to the conflicted state of digital consent and beyond.<br><br>I'm looking forward to a lot of great conversations about all these topics at <a href="https://www.linkedin.com/company/identiverse/">Identiverse</a> this week! In honor of the conference, everything at <a href="https://learning.vennfactory.com">Venn Factory Learning</a> is 50% off through June 14th. Just use code <strong>ZZAUTH</strong>! (Why ZZAUTH? iykyk...)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hR9r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hR9r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hR9r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hR9r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hR9r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hR9r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg" width="1456" height="973" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:973,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:794245,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/164957577?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hR9r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hR9r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hR9r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hR9r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc8fa304-3175-4528-bec0-4df8d965a217_1616x1080.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">At Cloud Identity Summit 2017 &#8212; Identiverse&#8217;s predecessor</figcaption></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links: Checking the hot sheets]]></title><description><![CDATA[And finding weird risks and threats all over the place]]></description><link>https://workshop.vennfactory.com/p/3-identity-links-checking-the-hot</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links-checking-the-hot</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Tue, 27 May 2025 15:36:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KlLW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KlLW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KlLW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 424w, https://substackcdn.com/image/fetch/$s_!KlLW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 848w, https://substackcdn.com/image/fetch/$s_!KlLW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 1272w, https://substackcdn.com/image/fetch/$s_!KlLW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KlLW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp" width="1456" height="1001" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1001,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:553280,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/164561156?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KlLW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 424w, https://substackcdn.com/image/fetch/$s_!KlLW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 848w, https://substackcdn.com/image/fetch/$s_!KlLW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 1272w, https://substackcdn.com/image/fetch/$s_!KlLW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F284ed846-4ed1-41a7-a53b-b18df6b4c087_1486x1022.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: Weekly World News: <a href="https://weeklyworldnews.com/animals/184105/goat-yoga-not-the-greatest-of-all-time/">Goat Yoga: Not the Greatest of All Time</a>, May 2023</figcaption></figure></div><h3>Anthropic Faces Backlash As Claude 4 Opus Can Autonomously Alert Authorities When Detecting Behavior Deemed Seriously Immoral</h3><p><em><a href="https://wccftech.com/anthropic-faces-backlash-as-claude-4-opus-can-autonomously-alert-authorities-when-detecting-behavior-deemed-seriously-immoral-raising-major-privacy-and-trust-concerns/">Published in WCCF Tech on 24 May 2025</a></em></p><p>If there were ever a reason for human-in-the-loop, <em>detecting immoral behavior</em> would be it. We don&#8217;t yet have the infrastructure to truly oversee &#8220;autonomous&#8221; AI activity &#8212; though hints of it are starting to show themselves in various &#8220;on-behalf-of&#8221; delegation efforts. (Human-in-the-loop == PEBKAC is a whole &#8216;nother risk.)</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links-checking-the-hot/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links-checking-the-hot/comments"><span>Leave a comment</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FLZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FLZC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 424w, https://substackcdn.com/image/fetch/$s_!FLZC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 848w, https://substackcdn.com/image/fetch/$s_!FLZC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 1272w, https://substackcdn.com/image/fetch/$s_!FLZC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FLZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp" width="654" height="311" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:311,&quot;width&quot;:654,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:18890,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/164561156?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FLZC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 424w, https://substackcdn.com/image/fetch/$s_!FLZC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 848w, https://substackcdn.com/image/fetch/$s_!FLZC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 1272w, https://substackcdn.com/image/fetch/$s_!FLZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307a82f3-32d3-487a-936e-a207dda8a37f_654x311.webp 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: WCCF Tech</figcaption></figure></div><h3>Massive data breach exposes 184 million passwords for Google, Microsoft, Facebook, and more</h3><p><em><a href="https://www.zdnet.com/article/massive-data-breach-exposes-184-million-passwords-for-google-microsoft-facebook-and-more/">Published in ZDNET on 23 May 2025</a></em></p><p>These very large online platforms (to coin a phrase&#8230;) have long been innovators in large-scale contextual authentication and fraud detection. But they&#8217;re still honeypots of very large online repositories of valuable info, and I don&#8217;t see that changing, even if passkeys or verifiable credentials become ubiquitous. Not without deep changes in their business models, anyway.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Venn Factory: The Workshop&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Venn Factory: The Workshop</span></a></p><h3>Deepfakes Now Outsmarting Detection By Mimicking Heartbeats</h3><p><em><a href="https://studyfinds.org/deepfakes-outsmarting-detection-heartbeats/">Published in Study Finds on 2 May 2025</a></em></p><p>The liveness detection arms race continues! Also: &#8220;inadvertently&#8221;?</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7f2U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7f2U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!7f2U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!7f2U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!7f2U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7f2U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/164561156?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7f2U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!7f2U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!7f2U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!7f2U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f312273-e3a9-499e-bbbd-0aa6fb3c63dc_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Linky issue no. 2 is in the bag! Let me know what you think &#8212; and send me your tips. :) Thanks to everyone who sent me linky post series title ideas. Still mulling those. For now I&#8217;m keeping it simple.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[3 Identity Links]]></title><description><![CDATA[A new hopefully more-than-occasional series]]></description><link>https://workshop.vennfactory.com/p/3-identity-links</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/3-identity-links</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Mon, 19 May 2025 12:31:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Oto7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oto7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oto7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 424w, https://substackcdn.com/image/fetch/$s_!Oto7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 848w, https://substackcdn.com/image/fetch/$s_!Oto7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 1272w, https://substackcdn.com/image/fetch/$s_!Oto7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oto7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:238889,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/163739499?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oto7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 424w, https://substackcdn.com/image/fetch/$s_!Oto7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 848w, https://substackcdn.com/image/fetch/$s_!Oto7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 1272w, https://substackcdn.com/image/fetch/$s_!Oto7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F570f7667-6989-436a-9ca1-6130a6bc9b69_1600x1067.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://cdn.britannica.com/30/153430-050-967CBF40/Eruption-Kilauea-Hawaii-Volcanoes-National-Park-1983.jpg">Encyclopedia Britannica</a></figcaption></figure></div><h2>Hawai&#699;i launches myHawaii platform to streamline access to online government services</h2><p><em><a href="https://mauinow.com/2025/05/11/hawai%CA%BBi-launches-myhawaii-platform-to-streamline-access-to-online-government-services/?utm_campaign=Morning%20Brief&amp;utm_medium=email&amp;_hsenc=p2ANqtz-9bTrTnl_v_8c3qN1jXYlSahDbwmM-hF2krjFmPPDFK1CuxGGFyUZT2s1J3JUH6BqReR9-KkCMFAl2oNdUuKfSBez189w&amp;_hsmi=361141095&amp;utm_content=361138229&amp;utm_source=hs_email">Published in Maui Now on 11 May 2025</a></em></p><p>My former home has been executing a mondo SSO program. Hawai&#699;i may be a modestly sized state, but 96 integrated apps (so far) is impressive. Ho&#699;omaika&#699;i &#699;ana i&#257; &#699;oe &#8211; congratulations!</p><h2>Frontegg releases identity management platform for AI agent builders</h2><p><em><a href="https://www.helpnetsecurity.com/2025/04/30/frontegg-ai-identity-management-platform/">Published in Help Net Security on 30 Apr 2025</a></em></p><p>FrontEgg is an example of user management platforms growing up and challenging classic IAM, including in the new era where players are seeking to protect AI interactions in various ways. I predict we&#8217;re going to see more such solutions moving upmarket, and more adjacent platforms &#8212; such as HRIS&#8217;s &#8212; getting cozier with IAM.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Venn Factory: The Workshop&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Venn Factory: The Workshop</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f2Rz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f2Rz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 424w, https://substackcdn.com/image/fetch/$s_!f2Rz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 848w, https://substackcdn.com/image/fetch/$s_!f2Rz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 1272w, https://substackcdn.com/image/fetch/$s_!f2Rz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f2Rz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic" width="1280" height="742" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:742,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34629,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/163739499?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f2Rz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 424w, https://substackcdn.com/image/fetch/$s_!f2Rz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 848w, https://substackcdn.com/image/fetch/$s_!f2Rz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 1272w, https://substackcdn.com/image/fetch/$s_!f2Rz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79377822-8610-4106-b5fd-fd4c507a80e6_1280x742.heic 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://www.industrialtrainer.org/nemawashi-japanese-model">IndustrialTrainer.org</a></figcaption></figure></div><h2>5 Powerful Persuasion Methods for Engineering Managers</h2><p><em><a href="https://newsletter.manager.dev/p/5-powerful-persuasion-methods-for">Published in the Manager.dev newsletter on 29 Apr 2025</a></em></p><p>My &#8220;<a href="https://www.kuppingercole.com/sessions/5827">Mastering IAM&#8217;s Higher Purpose</a>&#8221; keynote at EIC 2025 discussed the extraordinarily broad base of identity stakeholders in the enterprise. The Nemawashi persuasion method discussed would be particularly valuable to use in identity programs.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Aqr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Aqr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!_Aqr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!_Aqr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!_Aqr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Aqr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b5a3073-4e82-428e-9304-d966048628d9_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/163739499?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Aqr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!_Aqr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!_Aqr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!_Aqr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b5a3073-4e82-428e-9304-d966048628d9_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>It used to be said in the blogosphere of yore that blog posts were either &#8220;linky&#8221; or &#8220;thinky.&#8221; Let me know if you&#8217;d like to see more linky posts like this one!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/3-identity-links/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/3-identity-links/comments"><span>Leave a comment</span></a></p>]]></content:encoded></item><item><title><![CDATA[Many Persona Questions, Some of Them Answered]]></title><description><![CDATA[Exploring facets of ourselves that (should) impact security and experience]]></description><link>https://workshop.vennfactory.com/p/many-persona-questions-some-of-them</link><guid isPermaLink="false">https://workshop.vennfactory.com/p/many-persona-questions-some-of-them</guid><dc:creator><![CDATA[Eve Maler]]></dc:creator><pubDate>Wed, 07 May 2025 15:21:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mwp7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mwp7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mwp7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 424w, https://substackcdn.com/image/fetch/$s_!mwp7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 848w, https://substackcdn.com/image/fetch/$s_!mwp7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 1272w, https://substackcdn.com/image/fetch/$s_!mwp7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mwp7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic" width="1456" height="1941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2757939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/162835601?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mwp7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 424w, https://substackcdn.com/image/fetch/$s_!mwp7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 848w, https://substackcdn.com/image/fetch/$s_!mwp7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 1272w, https://substackcdn.com/image/fetch/$s_!mwp7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff63be0bf-950c-4c32-bb83-e94313f0272a_3024x4032.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hello from Berlin!</p><p>In my <a href="https://workshop.vennfactory.com/p/learning-247">previous post</a> I teased a brand-new white paper, and now&#8217;s the time to tell you a little bit about it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/subscribe?"><span>Subscribe now</span></a></p><p>There&#8217;s something in the air, and it has to do with the timeless philosophical question <strong>&#8220;Who am I?&#8221;</strong></p><p>When I move about the world &#8212; both physical and digital &#8212; and interact with others, <strong>is it the same &#8220;me&#8221;</strong> in all cases?</p><p>When I identify myself to an online service, what <strong>parts of me</strong> are actually presented, and how much am I allowed to do on that basis?</p><p>When I ask a hunk of clever software &#8212; an <strong>AI agent</strong> &#8212; to do something on my behalf, how much of &#8220;me&#8221; is in its workings, and how much does it truly represent me? And when I ask a <strong>family member or coworker</strong>, same question actually!</p><p>We&#8217;re only just starting to grapple with the <strong>human complexity</strong> that makes securing systems tricky. I was excited to come across a recent <a href="https://www.linkedin.com/pulse/delegating-your-personas-as-known-as-delegation-jen-schreiber-59ubc/">Linked article</a> from Jen Schreiber and George Fletcher, which combines several of these elements of complexity in a cool way: It moots the idea of &#8220;delegating your personas.&#8221;</p><p>There it is &#8212; <strong>personas</strong>. This has not traditionally been a well-defined or even frequently used concept in the identity world, but it&#8217;s coming up more and more.</p><p>Over the last several months I&#8217;ve been working with my friend, cybersecurity expert <strong><a href="https://www.linkedin.com/in/jacobideji/">Jacob Ideji</a></strong>, to dive deep on the question of whether <strong>accounts and login credentials</strong> are up to the task of representing this complexity. Our conclusion: It&#8217;s high time to turn personas into A Thing &#8212; a real artifact that can be used to <strong>drive better security and user experience</strong>.</p><p>To that end, we&#8217;ve put together a new white paper that explores these questions, and a few more:</p><ul><li><p>What are the risks of ignoring the different &#8220;characters&#8221; we adopt online?</p></li><li><p>Can understanding these subsets-of-us help with sharing &#8212; and limiting &#8212; access in a finer-grained way?</p></li><li><p>Can understanding the relationships between people&#8217;s various personas fuel better results?</p></li><li><p>What&#8217;s the right way to use current and emerging tech to take advantage of opportunities around persona thinking?</p></li></ul><p>In the paper, we offer practical findings on making IAM systems both more secure and more empathetic by integrating human complexity into design, architecture, and security controls.</p><p>What personas are infused into your digital landscape &#8212; joint account holders, patients and caregivers, temporary contractors, others? How do they shape your identity strategy? Are they coexisting or fighting with each other?</p><p>Check out <strong><a href="https://venn.direct/persona-paper">Persona-Driven Identity: Enhancing Security by Understanding Human Complexity</a></strong> on the brand-new <a href="https://learning.vennfactory.com">Venn Factory Learning</a> platform for an in-depth look at persona risks and effective solutions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HZhp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HZhp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HZhp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HZhp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HZhp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HZhp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1004595,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/162835601?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HZhp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HZhp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HZhp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HZhp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5c0cbf8-2a44-4595-ab8e-30f74fdd31ce_1080x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To celebrate the launch of both the paper and the platform &#8212; along with this week&#8217;s <a href="https://www.kuppingercole.com/events/eic2025">EIC conference</a> in Berlin &#8212; we&#8217;re offering a 50% discount on the paper through May 17. Just use code <strong><a href="http://venn.direct/persona-paper">EIC2025</a></strong> at checkout; this link builds the code right in.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/p/many-persona-questions-some-of-them?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workshop.vennfactory.com/p/many-persona-questions-some-of-them?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SXD4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SXD4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!SXD4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!SXD4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!SXD4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SXD4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png" width="32" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:32,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://workshop.vennfactory.com/i/162835601?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SXD4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 424w, https://substackcdn.com/image/fetch/$s_!SXD4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 848w, https://substackcdn.com/image/fetch/$s_!SXD4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 1272w, https://substackcdn.com/image/fetch/$s_!SXD4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0413b5c5-33a1-422e-a123-2703d17f4310_32x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Many thanks to our expert persona paper reviewers Eric Anderson of IDalchemy, George Fletcher, Nishant Kaushik, John Kindervag of Illumio, and Abhay Kulkarni of WideField Security!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://workshop.vennfactory.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Venn Factory: The Workshop! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>