So far it hasn’t been a great year for identity and those in the business of identity.
Chris Zannetos, for example (he’s the CEO of Courion, in case you forgot) came back from the Gartner IAM Summit in London a couple of weeks ago and related this experience:
“I walked into a session led by one of the world’s largest companies, touting its success in IAM. And what did they talk about? Creating a white pages directory with ‘a single IT identity for every user.’ The big example of value … phone numbers. I waited. There must be more I thought. This must have been the very beginning of the effort years ago. This is a customer put forth as a leading light. I waited. That was it. Here at this leading edge conference. A vendor put up a customer as a leading edge customer who had created a white pages directory with phone numbers. Welcome to the early 1990s.”
OUTLOOK: What does 2011 hold for identity management?
Chris concluded:
“In general, IAM projects have not delivered the value expected to customers and there are a lot of discussions going on about ‘the problem with IAM.’ If we in our industry — and I mean market analysts, vendors, and the IT/Security practitioners who are our customers — are not careful we will find the lifeless body of IAM in the woods. And realize that the trouble with IAM is that it is dead.”
But the problems aren’t just on the enterprise front.
Johannes Ernst was one of the founders (or, maybe, “midwives” is a better term) of OpenID which was launched when he, Dick Hardt (of Sxip), Drummond Reed (XRI) and Brad Fitzpatrick (SixApart) made separate presentations at the first Internet Identity Workshop in 2005. They realized that they were all working toward the same goal and OpenID was born. But Johannes (still CEO of NetMesh) recently wrote about “The Death Of User-Centric Identity — for now.” He first outlined the history both of OpenID (and its predecessors) and Infocards (and Microsoft‘s CardSpace). Then got to his main point:
“Well, here we are in 2011, and it is time to acknowledge that none of these original visions have worked out. CardSpace has been canceled. The rest of the proposals were, sort of, merged into what became OpenID. When we did this merger, we were all hoping that OpenID would end up being the sum of all (good) parts. Unfortunately, it became the opposite: an oddity not true to any of the visions, and far, very far, from being an aggregate of the best. Worse, its evolution has disintegrated into multiple incompatible architectures all of which have plenty of trees, but no forest. None of the original visionaries are actively involved in it any more, and it shows.”
Are we really doomed? Are both IAM and user-centric identity not endpoints but dead ends? Come back next issue and we’ll see.




