<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>i can has identity?</title>
	<atom:link href="http://icanhasidentity.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://icanhasidentity.wordpress.com</link>
	<description>Dave Nesbitt talks about Identity Management, IT, Life and Lolcats</description>
	<lastBuildDate>Thu, 20 Dec 2007 13:03:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='icanhasidentity.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>i can has identity?</title>
		<link>http://icanhasidentity.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://icanhasidentity.wordpress.com/osd.xml" title="i can has identity?" />
	<atom:link rel='hub' href='http://icanhasidentity.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Last post</title>
		<link>http://icanhasidentity.wordpress.com/2007/12/20/last-post/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/12/20/last-post/#comments</comments>
		<pubDate>Thu, 20 Dec 2007 13:01:46 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/12/20/last-post/</guid>
		<description><![CDATA[This will be the last post. I&#8217;ve moved over to http://www.davenesbitt.com now  Ciao!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=30&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This will be the last post. I&#8217;ve moved over to <a href="http://www.davenesbitt.com/">http://www.davenesbitt.com</a> now</p>
<p> Ciao!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/30/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/30/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/30/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=30&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/12/20/last-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
		<item>
		<title>5 Reasons RBAC Projects Go Wrong</title>
		<link>http://icanhasidentity.wordpress.com/2007/12/07/5-reasons-rbac-projects-go-wrong/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/12/07/5-reasons-rbac-projects-go-wrong/#comments</comments>
		<pubDate>Fri, 07 Dec 2007 20:12:02 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[RBAC]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/12/07/5-reasons-rbac-projects-go-wrong/</guid>
		<description><![CDATA[We were discussing the main causes of RBAC projects failing this week at Oxford. The discussion is sure to go on, as there are probably as many reasons for failure as there are roles in most organizations (which is many), but I offer here five of my personal favourites. Before I elaborate though, we should [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=29&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We were discussing the main causes of RBAC projects failing this week at Oxford. The discussion is sure to go on, as there are probably as many reasons for failure as there are roles in most organizations (which is many), but I offer here five of my personal favourites. Before I elaborate though, we should first perhaps clarify what I&#8217;m talking about when I mean &#8220;an RBAC project&#8221; (as others may have different definitions or mental models)</p>
<p>I&#8217;m assuming here we are talking about enabling or facilitating enterprise RBAC and that our architecture comprises some or all of the following:</p>
<ul>
<li>Some applications that have an internal security model that uses roles for managing access to resources (like SAP or other ERP applications)</li>
<li>One or more enterprise directory (Active Directory or LDAP, or both) that stores users in groups that are then used for authorization purposes by applications that don&#8217;t have internal roles</li>
<li>The applications that use the above directories (and there are plenty of them now) for authorization data</li>
<li>An authoritative source of identity data: perhaps (but not exclusively) HR for employees, an enterprise directory, or an IAM application or portal</li>
</ul>
<p>Into this we are looking to deploy a roles management system that will:</p>
<ul>
<li>Define, keep and maintain representations of roles</li>
<li>Automatically decide who gets what roles (and their associated permissions) in some cases, and allow manual administration in others</li>
<li>Have some kind of workflow for approvals and notifications</li>
<li>Provide feedback in the form of audit logs, reports, and (possibly) some kind of dashboard</li>
</ul>
<p>Our aim, in our project, is to deploy this system and almost certainly hook it up to some form of provisioning or identity synchronization service to automatically deploy and manage user accounts and permissions in our enterprise applications and directories. By doing so we aim to reduce the administrative effort associated with managing our application roles and to provide an enterprise-wide view of permissions, thus enhancing security and helping us to comply with regulations such as SOX. We might perhaps also create enterprise roles that comprise many application roles, groups or other permission sets (listen and watch my <a href="http://www.oxfordcomputergroup.com/resourcerequest.aspx?r=M65NOT73674">webinar</a> on pragmatic roles for more about this).</p>
<p>In my experience, the main reasons that roles projects fail are as follows:</p>
<ol>
<li><strong>For the same reasons other IAM projects fail</strong>: lack of executive buy-in, trying to do too much in one go without a clear set of prioritised requirements, and poor project management. See my <a href="http://davenesbitt.com/drupal/files/how_to_avoid_an_iam_trainwreck_1.pdf">trainwreck</a> article for more details on these.</li>
<li><strong>Not allowing enough time and resources for role mining</strong>. You need to allow lots of time to extract all your various application roles from their applications, and you will need support in the form of a business analyst and some technology (either a role-mining app like Eurekify, or do it yourself with ILM and SQL). Armed with these, you then need to probe your key applications and winkle out the roles and permissions buried within.</li>
<li><strong>Not grouping application roles into enterprise roles</strong>. If you don&#8217;t group application roles into the logical wrapper of an enterprise role, you probably will end up in the apocryphal state of having more roles than people. It&#8217;s inevitable that you have lots of application roles, but the aim is to make these manageable by normalizing them into one enterprise role per organizational role (if such a thing exists).</li>
<li><strong>Worrying too much about NIST-compliant RBAC</strong>. Whilst NIST-compliant RBAC remains a worthy goal, I believe that it can sometimes act as an inhibitor for people who should really just crack on and make a start with a few enterprise roles, or just enabling some simple role-based provisioning. If your roles management tool doesn&#8217;t support inheritance or segregation of duty, so be it. Just get on with it anyway.</li>
<li><strong>Getting bogged down trying to define organizational roles</strong>. Again, these are nice to have. If our HR system contained a list of the 300 company-approved roles and every user entry in the system had one (and only one) of these roles, it would be easy to deploy a data-driven provisioning system that could read and act on them. But life is rarely that simple and if you work in a dynamic (dare I say chaotic) organization that changes often and re-engineers itself on a regular basis, you may never get to this stage. As with NIST-compliance, waiting for HR (or those very expensive BPR consultants they have hired) to define every possible role every employee might ever have before starting with some role-based provisioning is a bit like waiting for Godot. And he never comes.</li>
</ol>
<p>Bear in mind here that I&#8217;m a pragmatist rather than a visionary. I don&#8217;t believe in waiting until things are perfect before I act. I like to roll up my sleeves and crack on to try and make things better, even if it&#8217;s just small incremental improvements, it&#8217;s better than nothing. Sometimes this means I discover halfway through that I need to stop, take stock and then reappraise, or even do some rework. But in my opinion that&#8217;s still better than waiting for perfect conditions to appear before starting: they seldom do.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/29/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/29/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/29/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=29&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/12/07/5-reasons-rbac-projects-go-wrong/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
		<item>
		<title>My new site</title>
		<link>http://icanhasidentity.wordpress.com/2007/12/05/my-new-site/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/12/05/my-new-site/#comments</comments>
		<pubDate>Wed, 05 Dec 2007 23:59:32 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/12/05/my-new-site/</guid>
		<description><![CDATA[I registered my own name as a .com domain recently. I was amazed it was still available, but I imagine there aren&#8217;t that many Dave Nesbitts in the world &#8211; or at least none vain enough to register their own .com domain. I was tempted to register some for my kids too, but unfortunately, only [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=28&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I registered my own name as a .com domain recently. I was amazed it was still available, but I imagine there aren&#8217;t that many Dave Nesbitts in the world &#8211; or at least none vain enough to register their own .com domain. I was tempted to register some for my kids too, but unfortunately, only two out of three could have .coms and the other would have to make do with a .co.uk. Talk about modern dilemmas&#8230; Do I register the .coms and the .co.uk or do I get them all .co.uk so that no-one is favoured?</p>
<p>Anyway, I&#8217;ve been moving my content over from here to there slowly and playing around with formats and other content. Take a look &#8211; it&#8217;s <a href="http://www.davenesbitt.com/">www.davenesbitt.com</a></p>
<p>I&#8217;ll probably move over there permanently fairly shortly, so the many thousands of you who are subscribed to my feeds will need to adjust your settings and come on over.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/28/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/28/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/28/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=28&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/12/05/my-new-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
		<item>
		<title>The DIM Report Lives Again</title>
		<link>http://icanhasidentity.wordpress.com/2007/12/04/the-dim-report-lives-again/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/12/04/the-dim-report-lives-again/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 21:11:36 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[Identity Management]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/12/04/the-dim-report-lives-again/</guid>
		<description><![CDATA[Not my temporary Blogspot blog, the original DIM Report is back in all its tawdry glory (real or imagined)! I&#8217;ve recently registered my own name as a domain (www.davenesbitt.com) and whilst I&#8217;m still fiddling about with themes and trying to decide whether to use WordPress or Drupal as my CMS, I thought it might be fun to put the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=27&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Not my temporary <a href="http://dimreport.blogspot.com">Blogspot blog</a>, the original DIM Report is back in all its tawdry glory (real or imagined)!</p>
<p>I&#8217;ve recently registered my own name as a domain (<a href="http://www.davenesbitt.com/">www.davenesbitt.com</a>) and whilst I&#8217;m still fiddling about with themes and trying to decide whether to use WordPress or Drupal as my CMS, I thought it might be fun to put the old <a href="http://www.davenesbitt.com/dimreport/">DIM Report html up there</a>. All the links seem to still work, and the content is quite an eye-opener. It&#8217;s amazing how much has changed in just 3 years, and how much is still the same. Some companies have fallen by the wayside (Critical Path) some have been acquired (Abridean, Waveset, Business Layers, OpenNetwork, RadiantLogic, Netegrity, Oblix, Maxware etc), and some are still going strong on their own, but the basic message has remained the same.</p>
<p>The best way to view it is to click on the &#8220;<a href="http://www.davenesbitt.com/dimreport/dimreport.htm">Report</a>&#8221; link from the top menu, then select a report at random from the left hand menu.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=27&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/12/04/the-dim-report-lives-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
		<item>
		<title>ILM 2 Beta 2</title>
		<link>http://icanhasidentity.wordpress.com/2007/11/29/ilm-2-beta-2/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/11/29/ilm-2-beta-2/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 21:41:26 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[ILM 2]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/11/29/ilm-2-beta-2/</guid>
		<description><![CDATA[I&#8217;m taking part in the Microsoft ILM2 Beta 2 program. Or at least I will be as soon as I get Windows 2008 server installed on a x64 Virtual Machine on my laptop. My laptop processor supports x64 and virtualisation (although it&#8217;s currently running i386 Vista), but unfortunately Microsoft Virtual PC doesn&#8217;t support x64 guests. I&#8217;ve installed [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=24&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m taking part in the Microsoft ILM2 Beta 2 program. Or at least I will be as soon as I get Windows 2008 server installed on a x64 Virtual Machine on my laptop. My laptop processor supports x64 and virtualisation (although it&#8217;s currently running i386 Vista), but unfortunately Microsoft Virtual PC doesn&#8217;t support x64 guests. I&#8217;ve installed VMWare (which is advertised as supporting x64 guests) so now I just need install Server 2008 and we should be away&#8230;</p>
<p>This is a closed Beta, so I won&#8217;t be able to update you on what I find, but you can always take part yourself as the program has only been running for a couple of weeks and should last 6 months. This post on the Microsoft ILM TechNet forums tells you everything you need to know to request participation.</p>
<p><a href="http://forums.microsoft.com/TechNet/ShowPost.aspx?PostID=2400213&amp;SiteID=17">http://forums.microsoft.com/TechNet/ShowPost.aspx?PostID=2400213&amp;SiteID=17</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/24/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/24/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/24/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=24&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/11/29/ilm-2-beta-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Kerberos Cat</title>
		<link>http://icanhasidentity.wordpress.com/2007/11/28/kerberos-cat/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/11/28/kerberos-cat/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 22:23:01 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[Kerberos]]></category>
		<category><![CDATA[lolcats]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/11/28/kerberos-cat/</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=26&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://icanhasidentity.files.wordpress.com/2007/11/kerberoscat.jpg" title="kerberoscat.jpg"><img src="http://icanhasidentity.files.wordpress.com/2007/11/kerberoscat.jpg?w=450" alt="kerberoscat.jpg" /></a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/26/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/26/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=26&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/11/28/kerberos-cat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>

		<media:content url="http://icanhasidentity.files.wordpress.com/2007/11/kerberoscat.jpg" medium="image">
			<media:title type="html">kerberoscat.jpg</media:title>
		</media:content>
	</item>
		<item>
		<title>Final Words (for now) on the Child Benefit Lapse</title>
		<link>http://icanhasidentity.wordpress.com/2007/11/26/final-words-for-now-on-the-child-benefit-lapse/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/11/26/final-words-for-now-on-the-child-benefit-lapse/#comments</comments>
		<pubDate>Mon, 26 Nov 2007 12:42:32 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[UK ID Card]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/11/26/final-words-for-now-on-the-child-benefit-lapse/</guid>
		<description><![CDATA[I read a couple of things over the weekend that seemed to vindicate my main thoughts from last week (well, I would hardly read or report on stuff that contradicted me, would I?). Whilst it&#8217;s never nice to blow your own trumpet, if I don&#8217;t give myself a couple of toots it&#8217;s unlikely anyone else [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=23&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I read a couple of things over the weekend that seemed to vindicate my main thoughts from last week (well, I would hardly read or report on stuff that contradicted me, would I?). Whilst it&#8217;s never nice to blow your own trumpet, if I don&#8217;t give myself a couple of toots it&#8217;s unlikely anyone else will, so what the heck.</p>
<p>Toot! I said that I found it hard to believe that the breach was caused by a junior official deciding on his own initiative to copy the entire database. I thought it was much more likely that the whole thing was down to systematic incompetence. According to The Sunday Times yesterday, &#8220;<a href="http://www.timesonline.co.uk/tol/news/politics/article2937217.ece">the Revenue routinely sent secret data with no security</a>&#8220;. That doesn&#8217;t quite square up with what the good Chancellor of the Exchequer (the government minister in charge of this department, international readers) said in Parliament, but it doesn&#8217;t surprise me at all. In fact, it confirms what I suspected. The main cause of this loss of data was an endemic laissez-faire attitude within Customs and Excise with regard to citizens&#8217; personal data. They didn&#8217;t care enough about it to treat it as valuable. Hopefully they (and other agencies and companies who hoard this stuff) might just have been frightened enough by the reaction to &#8220;datagate&#8221; to change this attitude before it happens again. Which it will.</p>
<p>Toot! Toot! I also said that this affair should convince us all to oppose the National ID Card and database, simply on the grounds that it will not be secure and its contents will inevitably be exposed to ne&#8217;er-do-wells and ID thieves either through negligence or a crooked employee (who now knows the real value of the data). The Government&#8217;s answer to these concerns is &#8220;Biometrics&#8221;. They claim that as the database will contain our encrypted biometric signature, there is no way ID thieves could ever steal our records, as they wouldn&#8217;t be able to use it. Yah, shuah. <a href="http://www.badscience.net/2007/11/make-your-own-id/">Ben Goldacre at Badscience.net</a> does a far better job than I could on systematically dismantling this claim. Sorry, but if you make something valuable enough, someone, somewhere is going to work out how to steal it and how much more valuable is someone&#8217;s biometrically-authenticated identity than a plain old NI number?</p>
<p>Anyway, enough on this for now, more riveting real-world enterprise IAM and not-very-funny lolcats to follow shortly, I promise.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/23/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/23/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=23&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/11/26/final-words-for-now-on-the-child-benefit-lapse/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Sober Reflections on the Child Benefit Agency Debacle</title>
		<link>http://icanhasidentity.wordpress.com/2007/11/22/sober-reflections-on-the-child-benefit-agency-debacle/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/11/22/sober-reflections-on-the-child-benefit-agency-debacle/#comments</comments>
		<pubDate>Thu, 22 Nov 2007 11:40:13 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[UK ID Card]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/11/22/sober-reflections-on-the-child-benefit-agency-debacle/</guid>
		<description><![CDATA[A couple of days have now passed since the Government announced that two CDs containing the entire Child Benefit database went missing in the post, but the furore shows no signs of dying down, quite rightly too. Now I’ve had a chance to listen to the rhetoric on both sides, and the many opinions offered [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=22&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A couple of days have now passed since the Government announced that two CDs containing the entire Child Benefit database went missing in the post, but the furore shows no signs of dying down, quite rightly too. Now I’ve had a chance to listen to the rhetoric on both sides, and the many opinions offered by all sorts of “experts” from every media outlet, I offer the following.</p>
<p><strong>Don&#8217;t Panic, But Do Be Angry</strong><br />
There is no need to panic. To paraphrase Michael Winner, “calm down dear, it’s only your personal data”. The chances of this data actually ending up in the wrong hands are fairly small, and there was no data in the breach that would allow hackers to suddenly log onto our Internet Banking accounts and withdraw huge sums. There is every reason to be angry though as this was a very serious breach. Whilst there was no data that hackers could use directly, there was a mass of data that ID thieves would just love to get their hands on. In particular, details such as our children’s birthdays are often used as secondary verification; I can think of at least one time I used my eldest son’s birthday as a six-figure PIN, along with my wedding day. The sheer weight of this personal data, combined with our National Insurance numbers, could well be sufficient to convince a poorly-trained or naïve customer service rep that the person on the end of the phone claiming to be me actually is me (when it isn’t – it’s a dirty ID thief).</p>
<p><strong>The Truth Will Set You Free<br />
</strong>Hopefully this breach will make us all think a little harder about how we manage our personal identity data. The Government, other organizations, and especially company websites, have trained us to enter our most precious dates and details into online forms in order to receive rewards. We now need to break free from this Pavlovian conditioning and take back control. We need to stop trusting those who ask for our data and ask them some hard questions: why do you need this? How do I know you will look after it properly? Personally, I rarely enter my genuine contact information unless I am utterly convinced there is a need for it. I don’t enter my real date of birth, nor do I enter my mobile or home phone number, even if the little web form has an asterisk next to it telling me it’s mandatory. As an aside, hello to all the web marketers out there – how did you get on with Mickey Mouse, the Ugandan Company Directory who wants to spend $10,000,000 dollars on your software in the next week? What, he turned out to be false? And you handed him over your valuable white paper too? You mean people give you false details when you demand their mobile phone number in return for marketing data? For shame! What is the world coming to? Here’s an idea, how about you all get a grip and stop expecting us to cede our private data to you? I know all you want it for is to sign me up for your newsletter and to give to your telesales monkeys to bombard me with phone calls about your crappy software. I know your game, I don’t trust you and I ain’t gonna give it to you.</p>
<p><strong>Sugar-Coated Iceberg<br />
</strong>We need also to understand that this breach is just the tip of the iceberg. Right now, all across the world, managers and minions who have been mismanaging databases full of identity data are wiping their brows and thinking “thank God it was them, not us”. These people are almost certainly also storing our data insecurely and transporting it inappropriately, they just haven’t been caught out yet. Just look at the <a target="_blank" href="http://www.theregister.co.uk/2007/05/04/txj_nonfeasance/">recent breach at retailer T J Maxx</a>. TJX admitted to losing 45.7m credit and debit card numbers and personal information relating to almost 500,000 people in a recent security breach. How many more will there be? All organizations that capture any personal data need to take a long hard look at their current processes for capturing, storing and providing access to this data. If they don’t need it, they need to get rid of it. If they must keep it, then they must keep it securely. They should encrypt the base data and then put rigorous access control procedures in place, including authentication, authorization, and audit processes. In other words make sure no-one can get access to the data unless they prove who they are (using strong authentication, not just username and passwords), that they have the right to do what they are trying to do and that thorough audit logs are kept</p>
<p><strong>Plain Old Incompetence or More Systemic Failure?<br />
</strong>Getting back to the Child Benefit Agency breach, I find it very hard to believe that this was just simply a junior official deciding on his own initiative, without the knowledge of management, to copy the entire database to CD and pop it in the internal mail. There are some odd things going on here. For a start, why did he copy the entire database? If <a target="_blank" href="http://news.bbc.co.uk/1/hi/uk_politics/7106987.stm">the what the Conservative head of the Public Accounts Committee, Edward Leigh, says is true</a>, and the National Audit Office wanted only limited child benefit records, then surely the most obvious thing to do would be to run a simple query against the database and generate just the data required? You could then take the results file, encrypt it using a file encryption tool, and email it to the recipient with a read receipt attached: simple, cheap and quick. In fact, far simpler and cheaper than copying the whole thing to disk and posting it. Did this just not occur to him? Or, more likely, did someone else in authority suggest it? Apparently this wasn’t the first time the NAO had requested the data – surely he mentioned the fact to his line manager. I can understand the Conservatives and other opposition politicians trying to make political capital out of the mess, but I just don’t buy the argument that this was simply a result of penny-pinching. How can burning a CD be cheaper and easier than my alternative suggestion? The whole thing smacks more of systemic incompetence, lack of training, lack of professionalism and poor supervision. How could the departmental manager not have known what was going on? Surely the request for this extremely sensitive data didn’t go directly to a junior official? If it did, then this says something quite serious about a lack of understanding of the sensitivity of the data and something even more serious about the lines of communication between government departments. If the manager did know what was going on, then he or she needs his or her backside kicked every bit as hard as the clerk who did the awful deed. Had everyone in the department been under no illusions that the database was sacrosanct and that access to it should be protected at all costs, this almost certainly would never have happened.</p>
<p><strong>Morals, Morals, Morals<br />
</strong>The morals of this sorry tale are threefold. For everyone, use this as a reminder to take more care of your personal data. Yes, I know that you have no choice but to hand it over to the Government, and that you should be able to trust them, but learn not to hand it over to anyone else unless you really have to. Question those who would take your identity data from you for no good reason. Question hotel clerks as to why they need your home phone number and don’t give lazy and greedy eCommerce sites your real mobile number unless you think there is a genuine reason for them to have it. For organizations that grab and hoard personal data from customers, stop it. Stop training us to hand over our identity data to people who have no business with it. Retain only that which you really need and then protect it properly. Control access to this data rigorously and keep audit logs. Learn to treat other people’s identity data with respect. We are not commodities. Finally, for the UK Government, realize that what you have done is (once again) reinforce people’s belief that that they cannot trust you and that Government IT departments are fundamentally incompetent. Pay your permanent staff a decent wage and train them properly. Get managers to manage and understand that the buck stops with them. Use external contractors sparingly, but don’t be afraid to call in the experts when you need to. Stop using policies and procedures as crutches, teach individuals instead to be accountable for what they do. Most importantly, drop the ridiculous ID card scheme. It will run vastly over budget and over time. It will cost billions, have little real impact in preventing crime or terrorism, and, most critically, some poorly paid, poorly motivated and poorly managed dweeb will inadvertently (or, if the price is right, deliberately) release the entire contents of the database to the <a target="_blank" href="http://en.wikipedia.org/wiki/Russian_Business_Network">Russian Business Network</a>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/22/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/22/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=22&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/11/22/sober-reflections-on-the-child-benefit-agency-debacle/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
		<item>
		<title>It&#8217;s not funny</title>
		<link>http://icanhasidentity.wordpress.com/2007/11/20/its-not-funny/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/11/20/its-not-funny/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 22:26:20 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[lolcats]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/11/20/its-not-funny/</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=19&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://icanhasidentity.files.wordpress.com/2007/11/revenue1.jpg" title="revenue1.jpg"><img src="http://icanhasidentity.files.wordpress.com/2007/11/revenue1.jpg?w=450" alt="revenue1.jpg" /></a><a href="http://icanhasidentity.files.wordpress.com/2007/11/revenue.jpg" title="revenue.jpg"></a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/19/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/19/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=19&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/11/20/its-not-funny/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>

		<media:content url="http://icanhasidentity.files.wordpress.com/2007/11/revenue1.jpg" medium="image">
			<media:title type="html">revenue1.jpg</media:title>
		</media:content>
	</item>
		<item>
		<title>UK Government Loses My Bank Details</title>
		<link>http://icanhasidentity.wordpress.com/2007/11/20/uk-government-loses-my-bank-details/</link>
		<comments>http://icanhasidentity.wordpress.com/2007/11/20/uk-government-loses-my-bank-details/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 22:13:41 +0000</pubDate>
		<dc:creator>Dave Nesbitt</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://icanhasidentity.wordpress.com/2007/11/20/uk-government-loses-my-bank-details/</guid>
		<description><![CDATA[Along with 25,000,000 others. Read this if you dare. Personally, I find it utterly beyond belief. A complete idiot employed (hopefully not for long) by the UK Revenue and Customs office copied the personal details of all families in the UK with a child under 16, including their bank details, to two CDs, then popped them [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=17&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Along with 25,000,000 others. <a target="_blank" href="http://news.bbc.co.uk/1/hi/uk_politics/7103566.stm">Read this if you dare</a>. Personally, I find it utterly beyond belief. A complete idiot employed (hopefully not for long) by the UK Revenue and Customs office copied the personal details of all families in the UK with a child under 16, including their bank details, to two CDs, then popped them in the internal mail where they subsequently disappeared. I&#8217;m lost for words. And the Government wants to convince us that they can be trusted with a National ID database? Not a chance, not now, not ever. I hearby pledge myself totally to the cause of opposing the ID card and database initiative &#8211; not on any privacy or civil liberties grounds (although I am sure there are plenty of them), just simply because Government IT people cannot be trusted. As sure as eggs is eggs, if they build a National ID database the project will run massively over budget, be delivered late, on old technology, and then some poorly paid, poorly motivated and poorly managed dweeb will accidently send it to their grandma, or put it on a laptop that gets stolen or (far fetched, I know) put it on a CD and pop it in the post.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/icanhasidentity.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/icanhasidentity.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/icanhasidentity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/icanhasidentity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/icanhasidentity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/icanhasidentity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/icanhasidentity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/icanhasidentity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/icanhasidentity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/icanhasidentity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/icanhasidentity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/icanhasidentity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/icanhasidentity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/icanhasidentity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/icanhasidentity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/icanhasidentity.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=icanhasidentity.wordpress.com&amp;blog=2033763&amp;post=17&amp;subd=icanhasidentity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://icanhasidentity.wordpress.com/2007/11/20/uk-government-loses-my-bank-details/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/67bca955f7c72db6d02b60b8722048ed?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Dave Nesbitt</media:title>
		</media:content>
	</item>
	</channel>
</rss>
