About

Twenty years of security architecture and a Masters in Theology. The combination is less unusual than it sounds — both are disciplines about who counts as who.

Mike Kiser

Director of Strategy and Standards at SailPoint, writing here about identity: who you are, who gets to say so, and what it costs.

The journal article is the formal version. The essays are where the argument is still moving.

Ethical standards and identity

One strand of current research is the consolidation and practical application of ethics in identity-driven algorithms, with an emphasis on open-source tooling and assets. The complete treatment is in this journal article. I have a Masters degree in Theology, so the intersection of identity and ethics drives a good deal of what I do.

Open work

Spartacus as a Service is an attempt at privacy through obfuscation rather than concealment — named for the closing scene of the Kirk Douglas film, and presented at Black Hat, DEF CON and the Crypto and Privacy Village. Two later projects point a camera at opposite ends of the same question: Ruse alters a photograph so it stays useful to human eyes and useless to facial recognition, while Sigillo signs one at the moment of capture, embedding C2PA Content Credentials so that provenance travels with the file rather than being reconstructed after the fact. Shared-Signals.Dev is the standards-side counterpart — a working transmitter and receiver for the Shared Signals Framework, so the specification can be tried rather than only read. All of it is open source and open to contribution.

At the OpenID Foundation

I co-chair the Shared Signals working group, with Sean O'Dell and Atul Tulshibagwale. It produces the Shared Signals Framework and the CAEP and RISC profiles: the machinery by which one service tells another that something about a person has changed, rather than each of them discovering it late and separately. Shared-Signals.Dev is a working demonstration of it.

I also co-chair the Death and the Digital Estate community group, with Dean H. Saxe and Eve Maler. It works on the use cases behind a person's right to decide what becomes of their data after they die or lose capacity — a question the industry has largely left alone, to the point that there is still no defined way to tell a provider that someone has died.

Writing and speaking

I write and speak often, locally and internationally. The essays are here; the talks and the outside pieces have sections of their own.

Industry background

A long history in technology and security, and a good many hats: security strategist, analyst, architect. Over two decades that has meant designing, directing and advising on large-scale security deployments for a global clientele.

Contact

Prompt replies go to press queries on breaking security, identity or ethics stories; genuine speaking enquiries; and questions about Ruse or Spartacus.

Getting in touch

Thanks for wanting to reach out. I answer all legitimate correspondence, some of it quickly.

EmailBest route

mike@mikekiser.org

The most reliable way to reach me. Replies are relatively prompt.

TwitterNotices

@_MikeKiser

Where new writing and talks get announced. DMs are usually open, but email is steadier.

LinkedInCareer

Mike Kiser

A brief overview of the past few decades.

GitHubCode

derrumbe

Spartacus, Ruse, and whatever else is currently half-finished.