All due respect, I don't get it

3 views
Skip to first unread message

Peter Laird

unread,
Jun 20, 2008, 12:23:55 AM6/20/08
to Clipperz
Would appreciate someone explaining this.

I don't get the big appeal. Clipperz seems to be an unworkable
solution for:

1. Apps that do need to know me as a human, e.g. my bank. I am
associated with a real customer account, so I can't be anonymous to
them.

2. Sites where I buy stuff. It would be hard for them to ship
something to me if they couldn't associate my personal info (name,
CCard, address) with my order. That means they need to store my data.

3. Apps that on which I want to build a social network, ala LinkedIn,
Facebook, delicious, etc. My username/data identifies who I am so my
friends can find me. LinkedIn wouldn't be too useful if everyone had
profiles like user123, user423, user994.

4. Apps that provide community driven ratings. These apps are moving
to be less anonymous, like AMZN now can associate the user's profile
to comments. You might think this sucks but in the world of rampant
comment SPAM I think it helps.

5. Sites where financial transactions between users are taking place,
like eBay. I would feel more comfortable knowing something about the
user on the other end of the transaction.

It seems that Clipperz is not suitable for sites that are engaged in
social computing or any kind of finance. For the rest, like news sites
that want a login, you can already just provide a stupid username for
yourself "bozotheclown123". So net effect - in the places where you
want it to work it can't, and for where it will work there is already
an easy solution.

As for SSO, OpenID seems to already attacking that problem.

There seems to be a lot of people interested in this solution, so
clearly I am missing something.

Thanks,
Peter

Marco Barulli

unread,
Jun 20, 2008, 11:00:33 AM6/20/08
to peter...@gmail.com, Clipperz
Dear Peter,
first of all thanks for sharing your thoughts.

Clipperz is basically a password manager that also implements a "pragmatic" single sign-on.
This means that our users can keep using their set of credentials, but without the hassles derived from remembering all of them.

1. Apps that do need to know me as a human, e.g. my bank. I am
associated with a real customer account, so I can't be anonymous to
them.

You are anonymous to the Clipperz application. Clipperz knows nothing about its users, not even their usernames!
But if you use the "direct login" feature to login to your bank with one click, then you are providing your bank the same credentials that you would enter manually.
It's hugely convenient and, again, it does not leak any information to Clipperz. Not even your login patterns.

2. Sites where I buy stuff. It would be hard for them to ship
something to me if they couldn't associate my personal info (name,
CCard, address) with my order. That means they need to store my data.

Again, with Clipperz you only get the security to keep your credentials for accessing web merchants in a safe place, and the convenience to login to their sites with one click. Clipperz is not involved in sending information to the merchant, it just logs you in.

3. Apps that on which I want to build a social network, ala LinkedIn,
Facebook, delicious, etc. My username/data identifies who I am so my
friends can find me. LinkedIn wouldn't be too useful if everyone had
profiles like user123, user423, user994.
 
4. Apps that provide community driven ratings. These apps are moving
to be less anonymous, like AMZN now can associate the user's profile
to comments. You might think this sucks but in the world of rampant
comment SPAM I think it helps.
 
5. Sites where financial transactions between users are taking place,
like eBay. I would feel more comfortable knowing something about the
user on the other end of the transaction.
 
It seems that Clipperz is not suitable for sites that are engaged in
social computing or any kind of finance. For the rest, like news sites
that want a login, you can already just provide a stupid username for
yourself "bozotheclown123". So net effect - in the places where you
want it to work it can't, and for where it will work there is already
an easy solution.

Same considerations as above. Clipperz makes you forget all your passwords because you are not typing them any longer.
Therefore you can afford to use different passwords at each website. And this is good for your online security.
But Clipperz is not involved in what happens after you are logged in.

There seems to be a lot of people interested in this solution, so
clearly I am missing something.

I would say that there is probably something wrong in our way to communicate what Clipperz is and what it can do for you.

May I ask you to take a look at the following blog posts?
http://www.clipperz.com/users/marco/blog/2007/08/24/anatomy_zero_knowledge_web_application
http://www.clipperz.com/users/marco/blog/2008/05/30/freedom_and_privacy_cloud_call_action

I would be honored to know your opinion about the "zero-knowledge web apps" concept.

Many thanks,
Marco

--
Marco Barulli
www.clipperz.com

Giulio Cesare Solaroli

unread,
Jun 20, 2008, 12:37:34 PM6/20/08
to peter...@gmail.com, Clipperz
Hello Peter,

I think that your main concerns are about the "zero-knowledge web
architecture", more than the Clipperz application itself.

For some of the examples you have listed, our proposed architecture is
probably not very suitable.

But the problem we are raising, is that everybody is taking the
current architecture (the server knows everything about everybody) as
a matter of fact, and not a design decision you can choose to subvert.

Many times, the choice to keep all the data in their plain format on
the server is just the easiest way to go, not necessarily the "best"
(whatever this could mean in any given situation).

A very simple example we have been reasoning about lately, is the
online poker applications; the current implementations keep the full
state of any macht on the server, and this as already caused a few
frauds.
We are trying to point out that it would be possible to implement an
online poker application that could keep things going as usual,
without any privileged insight on what is going on. It would still be
able to know who won and who lost, but not much more.

Again, consider "zero-knowledge web architecture" as a new conceptual
framework to think about how problems can be solved online available
to designer; it may not be always the best fit, but it is definitely
something that could be quite helpful in many occasions.

Hope this answer some of your concerns.

Best regards,

Giulio Cesare

Reply all
Reply to author
Forward
0 new messages