Once past the convenience of remembering just a single set of
credentials, users and operators began to realize that the web
farm of one single operator was in the position of keeping track
of all their movements and didn??™t like the idea. When the technical
reasons for outsourcing authentication disappeared, or
were greatly reduced, there was no justi?¬?cation for that situation.
If you add that some websites tried to make it as unobvious
as possible that they were in fact relying on Passport, you can
see how users didn??™t feel much in control.
In fact, ???Justi?¬?able Parties??? is another ?¬‚avor of the ???User Control
and Consent??? law. Every time the user discloses his identity information,
he needs to be able to assess not only to whom he is
sending data, but also understand its role in the current transaction
and the implications of its involvement. Let??™s get back to the
wine seller example we introduced in the previous section. The
merchant needs to know whether you are of age before serving
you alcohol, and he may not take your word for it. In the of?¬‚ine
world, the natural solution entails extracting your governmentissued
ID document and exhibiting it.
Pages:
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182