Archived post — originally published 2013-06-28.
Historical context: Project capabilities and the SMS example describe the 2013 event, not current authentication guidance. Five original Flickr illustrations are unavailable.
This past weekend I attended IndieWebCamp 2013, a small, two day barcamp style conference in Portland, OR. I have never been to anything like this before, but needless to say, given all of the amazing ideas and fantastic projects people came and left with, I had a fantastic time and left inspired.
Projects that blew my mind
Every project at IWC2013 was interesting and important in its own way. They are the product of everyone scratching their own itch, doing things their own way, finding common ground with others and ultimately avoiding monoculture. That being said, the following projects really blew my mind.
IndieAuth: Passwordless Authentication and Persona
Image unavailable. Original image URL
IndiAuth added two additional authentication methods over the weekend, SMS and Persona. Austin King and Francois Marier, both Mozilla Developers, as well as as Aaron Parecki worked their magic and made this happen.
-
IndiAuth now supports Persona when provided an email address.
Mozilla Persona has many benefits over the siloed implementations of openIDOAuth. You can now add a rel="me" to an email address on your web page and authenticate using Persona in IndieAuth. Apparently this could also work the other way, where IndieAuth serves as an authentication provider for Persona. There was also discussion about ways to use Persona with IndieAuth without having to have an email address posted publicly. These last two items have not been implemented yet. More can be read on Francois’s blog
-
SMS Authentication killed the password
Aaron also managed implemented SMS authentication. If you add
<a rel="me" href="sms:+15035555555">(503) 555-5555</a>
to your identifying website, IndieAuth allows you to authenticate with your domain and the associated phone number alone. No passwords.
This is a big idea.
Lots of influential tech companies talk about killing passwords. IndieWebCamp has a working model for this today. If only we could associate phone numbers with email addresses, maybe we could speed up adoption…
Webfist
What happens when two incredibly skilled Google engineers sit down for a day and hack on the solution to corporations who are too stubborn and/or slow to adopt open web technologies?
-
The answer to that is Webfist.
Developed by Brett Slatkin and Brad Fitzpatrick, Webfist is the the answer to the slow rate at which Webfinger is being implemented by basically everyone.
-
Here are the details I remember from the weekend.
Webfinger lets you associate arbitrary pieces of information to an email address so that services can discover that information simply by knowing your email address. This is done by relying on the email host to implement Webfinger. Examples of information you might want associated with your email address.
- A (link to a) profile photo
- Public encryption key
- Website URL
- Phone number
- Bitcoin Address
- Preferred authentication method(s)
The only problem is that the major email providers have not yet implemented Webfinger, even though the engineers behind the scene are clamoring for it, and may or may not have already even dark launched it.
Webfist is the software used to run a distributed fallback network that allows webfinger attributes to be associated with any email address, even if the email provider has not yet implemented Webfinger support. The way it actually works is kind of complicated, but it uses some kind of fancy cryptographic header information that the major players have implemented to help fight spam. This cryptographic header information also happens to be a convenient way to allow an email address to associate Webfinger data with itself securely.
-
How can I start using it today?
After speaking with Brad, it sounds like it wont be necessary for many individuals to run a Webfist server, although its completely possible for anyone to run a node in the distributed network. It sounds like the developers have a number of connections that can provide the necessary infrastructure to get the network off the ground.
I still have not found dead simple example showing exactly how to get data into the Webfist network.
-
What about the whole own your domain thing?
There was some controversy surrounding Webfinger during the discussion session on Webfist. On the one hand, this powerful discoverability tool could potentially pull wind away from people seeing the need to represent themselves on a domain name (IE, why would I need a domain name if I can assert my identity using my email address). The other perspective is that it could act as a transitional bridge away from silos serving as identity authorities for those without a domain name.
Oh, and I can’t confirm or deny if webfist.me was purchased over the weekend.
IndieWeb Implementations
Image unavailable. Original image URL
Shortly before IWC2013, an interesting thing happened at eschnou.com. Using standard HTML, Microformats, and Pingbacks/Webmentions, a distributed commenting system emerged.
- No central servers
- No company controlled APIs
- No single software stack
Anyone with some common HTML classes and dom structures with the ability to send dead simple HTTP requests can participate. Post the reply on your own website noting your reply context, then notify the site about your activity using a webmention or pingback. Here are some examples:
- eschnou.com
- aaronparecki.com
- waterpigs.co.uk
- sandeep.io (featuring the original Indie “Likes”!)
- werd.io
- willnorris.com
Some implementations display like a traditional comment system, others follow the twitter UX for handling replies. Some people are even experimenting with threads. The key to success here is that everyone is selfdogfooding.
Image unavailable. Original image URL
After Sunday, it became apparent that everyone still had momentum from the weekend. Ben Werdmuller and I decided that rounding up anyone still in Portland was a good idea.
A few hours (or just an hour?), Ben managed to implement an event post and a working RSVP model! After realizing the original announcement details needed to be updated after posting, tantek helped draft comment updates+deletes (CRUD), which Ben implemented a day later.
-
The indieweb delete protocol is aptly named the Pilgrim Protocol
Hats off to Ben and the Idno project, as well as everyone else involved, for the impressive speed at implementing these important concepts. Aaron already has his RSVP implementation working!
This stuff is developing fast! Just the other evening Aaron also implemented IndieWeb IRC replies!
Things that looked rad but I did not fully understand
The following projects look super interesting but I am still confused about exactly what they are or how they work.
Camlistore
Image unavailable. Original image URL
Brad gave a talk on Camlistore. It appears to be way to store data in some kind of blob tree which offers a lot of flexibility on how it can be accessed and stored. It also sounds like it could enable distributed file sharing in really interesting ways. It also has versioning built in by design. Apparently you will eventually be able to rent out space to others for Bitcoins.
I myself, am sitting on a pile of data at home, unsatisfied with how its stored and accessed. This sounds like it has a huge potential for providing some satisfaction to my data problem.
Update: A video has surfaced of basically what we saw during the conference! Check it out.
Smallest-Federated-Wiki
Image unavailable. Original image URL
I missed the discussion on this project, and I wish I hadn’t. The Smallest-Federated-Wiki is a wiki that allows anyone to fork pages from someone else’s wiki to their own instance the wiki, and allows others to pull those changes in… Or display content from another wiki? I think. The implementation looks really slick and has a lot of interesting client side stuff going on. Check out some of the demo videos. I might jump on this and set up my own instance eventually.
IFTTT Everything
Paul Fenwick led an interesting discussion and gave some demos about implementing APIs, data collection and automated actions where there previously was nothing.
Having little experience or skills relevant to this topic, I found myself kind of lost, but the automation and interfacing with data sources was impressive. There are some interesting links from that sessions etherpad.
Other Ideas that resonated with me
Ideas for next year
-
IRC Brainstorm
IRC plays an integral role in developing these projects, as it serves as the primary channel of real-time communication for those involved. It is my wager that the recent IndieWeb commenting system would not have arisen without this channel. It can be tough for new users of IRC to participate this way because the software is hard to use, or complicated to set up in many cases. I would like to see discussions about how people use IRC in relation to the IndieWeb, as well as look for new uses for this communication tool.
We could also just demo everyones exotic IRC setups, and help newcomers get started.
-
Static Sites
Static websites are fairly easy create, and dead simple to host. I would like to discuss how people can participate on the Indieweb with only static HTML and client side JS. I am primarily curious how others over come some of the challenges of doing everything at compile time. I would also be happy sharing what I have learned from my own experiments.
How I can contribute going forward
-
Increase my IndieMark score by implementing all post types
-
Display Webmentions/Pingbacks I have received on Pingback.me
-
Automate webmentions and pingbacks
-
Look into Unhosted posting methods
It was an honor, IWC2013!