<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:,2009:/1/tag:www.readwriteweb.com,2008://1.13187-</id>
  <updated>2009-11-23T01:10:38Z</updated>
  <title>Comments for Security and Privacy on Social Networks and the Semantic Web</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2008://1.13187</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=13187" title="Security and Privacy on Social Networks and the Semantic Web" />
    <published>2008-12-31T04:10:29Z</published>
    <updated>2008-12-31T04:11:06Z</updated>
    <title>Security and Privacy on Social Networks and the Semantic Web</title>
    <summary>While the MD5 hack that puts e-commerce sites at risk by faking security certificates received most of the attention at the 25C3 conference in Berlin today, another interesting talk about using XMPP to ensure privacy and security on social networks by Jan Torben Heuer caught our eyes as well. Heuer demoed a social bookmarking service...</summary>
    <author>
      <name>Frederic Lardinois</name>
      
    </author>
    
    <category term="NYT" />
    
    <category term="News" />
    
    <category term="Semantic Web" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="diki_logo.png" src="http://www.readwriteweb.com/images/diki_logo.png"  />While the <a href="http://events.ccc.de/congress/2008/Fahrplan/events/3023.en.html">MD5 hack</a> that puts e-commerce sites at risk by faking security certificates received most of the <a href="http://www.techmeme.com/081230/p22#a081230p22">attention</a> at the <a href="http://events.ccc.de/congress/2008/">25C3 conference</a> in Berlin today, another <a href="http://events.ccc.de/congress/2008/Fahrplan/events/2873.en.html">interesting talk</a> about using <a href="http://xmpp.org/about/">XMPP</a> to ensure privacy and security on social networks by <a href="http://www.jtheuer.de/">Jan Torben Heuer</a> caught our eyes as well. Heuer demoed a social bookmarking service named <a href="http://www.pace-project.org/live-demo">Diki</a>, which implements some of his ideas, though in the long run, the developers are planning to take this prototype and develop a full-blown social network with a focus on privacy and encryption around this.</p>]]>
      <![CDATA[<p>Heuer argues that ensuring privacy on social networks is almost impossible, due to the centralized architecture of these networks, where all your information is controlled by one corporate entity, and where the user has to simply trust the service provider without having any control over what this provider does with the information.</p>

<p>As an alternative, Heuer proposes to use a decentralized network based on XMPP, where data is only exchanged between friends and transmissions are encrypted. One might argue that XMPP still relies on servers, though it is surely a more decentralized system than the monolithic reliance on one service provider. </p>

<p><img alt="diki_screenshot_linux.png" align="right" src="http://www.readwriteweb.com/images/diki_screenshot_linux.png"  />The talk mostly focused on the technical and privacy aspects of sharing semantic data like Friend-of-a-Friend (FOAF) information through an XMPP network, but it also introduced the <a href="http://www.pace-project.org/">Diki</a> bookmarking and tagging application, which you can download and start from <a href="http://www.pace-project.org/live-demo">here</a>.</p>

<h2>Diki</h2>

<p>Diki is the first implementation of these ideas and is available as a Java application that allows you to create a new account, import your delicious bookmarks, rate your friends' bookmarks, and which automatically encrypts your communication by using the <a href="http://en.wikipedia.org/wiki/OpenPGP#OpenPGP">OpenPGP</a> standard. It's clearly still a prototype, but it raises a lot of interesting questions.</p>

<p>If you want to delve deeper into this topic, you can download the presentation <a href="http://events.ccc.de/congress/2008/Fahrplan/attachments/1236_heuer_presentation_25c3.pdf">here</a> (PDF), or read the actual <a href="http://events.ccc.de/congress/2008/Fahrplan/attachments/1199_heuer_25c3_privacy_semantic_web_xmpp.pdf">paper</a> (PDF). If you have some bandwidth to spare, you can also download this presentation and all others from this week's Chaos Computer Congress from <a href="http://events.ccc.de/congress/2008/wiki/Conference_Recordings">here</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.13187-comment:121272</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.13187" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php#c121272" />
    <title>Comment from Anita CM on 2008-12-30</title>
    <author>
        <name>Anita CM</name>
        <uri>http://www.vantrix.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.vantrix.net">
        <![CDATA[<p>Expecting Privacy and Security on internet literally amounts to daydreaming. These two things last as far as your nosetip.Your privacy and security lasts till the time you are not found by others or others decide not to look for you on net...</p>]]>
    </content>
    <published>2008-12-31T06:16:10Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.13187-comment:121273</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.13187" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php#c121273" />
    <title>Comment from Meitar Moscovitz on 2008-12-30</title>
    <author>
        <name>Meitar Moscovitz</name>
        <uri>http://maymay.net/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://maymay.net/">
        <![CDATA[<p>It does seem like XMPP is becoming more like SMTP when used in this way, doesn't way? I like the notion of a privacy-centric social network, but one wonders how to balance the benefits of transparency with such a potentially security-paranoid model. It's a trade off to be sure, and one I think people should be able to make for themselves. Still…one wonders.</p>]]>
    </content>
    <published>2008-12-31T06:45:01Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.13187-comment:121287</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.13187" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php#c121287" />
    <title>Comment from Todd on 2008-12-31</title>
    <author>
        <name>Todd</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>"...Heuer proposes to use a decentralized network based on XMPP, where data is only exchanged between friends and transmissions are encrypted. One might argue that XMPP still relies on servers, though it is surely a more decentralized system than the monolithic reliance on one service provider."</p>

<p>Oh YES! Excellent.</p>

<p>Its important to note why I am a big fan of this - it helps us take our time and attention back from those that profit from it (!!!).</p>

<p>PR and Marketing people have discovered the value of "buzz" and are making a fortune with it - and giving us users nothing in return. </p>

<p>This GMPP model would put control of "buzz" in our hands that we could then sell access to the Marketers.</p>]]>
    </content>
    <published>2008-12-31T12:01:43Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.13187-comment:121486</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.13187" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/ensuring_security_and_privacy_through_xmpp.php#c121486" />
    <title>Comment from social networking web design on 2009-01-02</title>
    <author>
        <name>social networking web design</name>
        <uri>http://www.megastarmedia.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.megastarmedia.com">
        <![CDATA[<p>interesting article, would like to see results posted here as well.</p>]]>
    </content>
    <published>2009-01-02T19:21:07Z</published>
  </entry>

</feed>