Category: Legal (page 1 of 2)

VRM+CRM at IIW

Four years and a few months ago, CRM Magazine devoted much of its May issue to VRM.not_iball1 That’s the cover there on the right. It was way ahead of its time. Same goes for ProjectVRM, which started four years earlier.

Now things are starting to shift.

I’ve heard encouraging reports from friends who went to Oracle OpenWorld last month and are headed to Salesforce‘s Dreamforce  next week. They tell me it is now becoming apparent to CRM that it needs a hand to shake on the customer side that’s not a captive one. Specifically —

  • That customers need scale across the many companies they deal with, just as companies need scale across the many customers they deal with. So, for example…
  • A customer should to be able to change his or her address (plus other form fields) for every company they deal with in one move, rather than one at a time within each company’s separate CRM system.
  • A customer should be able to intentcast as a qualified lead, safely and (at least at first) anonymously, outside of any one company’s captive marketplace.
  • An individual’s sovereign identity matters more to them — and to the marketplace — than any administrative identities conferred by companies or governments.
  • The negative externalities of unwelcome surveillance tend to outweigh whatever positive internalities the practice provides.
  • Co-creating the customer experience is better than having one side in charge of the whole thing — especially when the customer has few ways to bring consistency to her experience with many different companies.
  • Customers should have clouds of their own (aka personal clouds, stores, vaults, PIMS), and not just those of silo’d services.
  • Customers need ways to express their own policies, preferences, terms and conditions, and not be forced all the time to accept those provided by sellers — and that mutually agreeable terms will be far better than the one-sided (and in many cases unenforceable) ones nobody reads because there’s no point to it.
  • There is far more leverage on customer retention in the “own cycle” than in the “buy cycle” of the customer experience.

Speaking of which, here’s how that cycle looks, thanks to Esteban Kolsky, who drew the original: oracle-twist

There are now many dozens of developers in or near the VRM space that can be helpful for CRM as well.

Given all the action that’s going on, it would be way cool if we can get players on both sides together in one room to talk and whiteboard our way onto common ground and build new and better stuff there.

So we’re in luck, because that’s what we have with VRM Day and IIW, both at the Computer History Museum in downtown Silicon Valley (101 and Shoreline Road in Mountain View), on the last week of this month.

  • VRM Day is Monday, October 27.
  • IIW (Internet Identity Workshop) is Tuesday to Thursday, October 28-30.

The two go together. VRM Day is located and timed to lead in to IIW. The topics are ones we’ll want to be working on for the next three days — and beyond.

IIW is an unconference. There are no speakers or panels. All the topics are vetted by participants, who lead discussions and push topics forward in breakout rooms. It’s designed that way so stuff gets done and not only talked about.

While the original focus was (and remains) identity, the workshop is open to anything. High on the list of topics that get worked on, every time, are VRM ones like those listed above.

VRM Day and IIW will provide an ideal week for anybody who wants CRM to truly engage customers to get together and help make that happen.

VRM developers need to know more about how to connect with and help CRM systems and related ones, such as sCRM (social CRM), Customer Experience Management and call centers.

CRM developers need to know more about how to connect with and help VRM developers.

And, since everybody with a wallet is also a customer, that character will be well-represented too.

So I encourage everybody involved in CRM or VRM to come to VRM Day and IIW — with a special shout-out to Oracle, SAP, Microsoft Dynamics, IBM, Salesforce and SugarCRM. We need you there. And so do you. :-)

It’s time to make good on the promise we’ve seen coming for way too long.

State of the VRooM, 2014

As of today, ProjectVRM is eight years old.

So now seems like a good time for a comprehensive (or at least long) report on what we’ve been doing all this time, how we’ve been doing it, and what we’ve been learning along the way.

ProjectVRM has always been both a group effort and provisional in its outlook and methods. So look at everything below as a draft requiring improvement, and send me edits, either by email (dsearls at cyber dot law dot harvard dot edu) or by commenting below.

Summary

After eight years of encouraging development of tools and services that make individuals both independent and better able to engage, ProjectVRM (VRM stands for vendor relationship management) is experiencing success in many places; most coherently in France, the UK and Oceania (Australia and New Zealand). There are now dozens of VRM developers (though many descriptors besides VRM are used), and investor interest is shifting from the “push” to the “pull” side of the marketplace. Government encouragement of VRM is strongest in the UK and Australia.  ProjectVRM and its community are focused currently on “first person” technologies, privacy, trust, identity (including anonymity), relationship (including experience co-creation), substituability of services and the Internet of Things. Verticals are personal information management, relationship (VRM+CRM), identity, on-demand services, payments, messaging (e.g. secure email), health, automotive and real estate.  There are many possibilities for research, possibly starting with the effects on business of individuals being in full control of their sides of agreements with companies.

Here are shortcuts to each section:

  1. History
  2. Development
  3. Community
  4. Influence
  5. Issues
  6. Verticals
  7. Investment
  8. Research
  9. Questions

1. History

ProjectVRM is one of many research projects at the Berkman Center for Internet and Society at Harvard University. It started when I began a four-year fellowship at Berkman in September, 2006. In those days Berkman fellows were encouraged to work on a project. I had lots of guidance from Berkman staff and other veterans; but what best focused my purpose was something Terry Fisher said at one of the orientation talks. He said Berkman did its best to be neutral about the subjects it studies, but also that “we do look for effects.”

The effect-generating work for which I was best known at the time was The Cluetrain Manifesto, which I co-authored seven years earlier with Chris Locke, David Weinberger and Rick Levine. By most measures Cluetrain was a huge success. The original website launched a meme that won’t quit, and the book that followed was a bestseller.(It still sells well today). But I felt that its alpha clue, written by Chris Locke, still wasn’t true. It said,

we are not seats or eyeballs or end users or consumers.
we are human beings and our reach exceeds your grasp. deal with it.

There is a theory in there that says the Internet gives human beings (the first person we) the reach they need to exceed the grasp of marketers (the second person your).

So either the theory wasn’t true, or the Internet was a necessary but insufficient condition for the theory to prove out. I went with the latter and decided to to work on the missing stuff.

That stuff couldn’t come from marketers, because they were on the second person side. In legal terms, they were the second party, not the first. This is why their embrace  of  Cluetrain’s “markets are conversations” couldn’t do the job. Demand needed help that Supply couldn’t provide. What we needed, as individuals, were first party solutions — ones that worked for us.

The more I thought about the absence of first party solutions, the more I realized that this was a huge hole in the marketplace: one that was hard to see from the client-server perspective, always drawn like this:

468px-Client-server-model.svg

While handy and normative, client-server is also retro. Here’s a graphic from Virtual Teams: People Working Across Boundaries with Technology (Jessical Lipnack and Jeffrey Stamps, 2000,  p. 47) that puts it in perspective:

lipnack

Client-server is hierarchical, bureaucratic industrial and agricultural (see the image below). But it’s also most of what we experience on the Web, and also where the entirety of the supply side sits. So, even if Cluetrain is right when it says (in Thesis #7) “hyperlinks subvert hierarchy,” subversion goes slow when the people running the servers are in near-absolute control and hardly care at all about links. In less abstract terms, what we have on the Web is this:

calf-cow

As clients we go to servers for the milk of text, graphics, sound and videos. We get all those, plus cookies (and other tracking methods) to remember who we are and where we were the last time we showed up. And, since we’re just clients, and servers do all the heavy lifting  (and with technology what can be done will be done) the commercial Web’s ranch has turned into what Bruce Schneier calls Our Internet surveillance state.

By 2006 it was already clear to me that we could make the whole marketplace a lot bigger if individuals were fully capable human beings and not just calves — if we equipped Demand to drive Supply at least as well as Supply drives Demand.

To help people imagine what will happen when Demand reaches full power, I wrote a Linux Journal column a few months earlier, titled “The Intention Economy.” Here’s the gist of it:

The Intention Economy grows around buyers, not sellers. It leverages the simple fact that buyers are the first source of money, and that they come ready-made. You don’t need advertising to make them.

The Intention Economy is about markets, not marketing. You don’t need marketing to make Intention Markets.

The Intention Economy is built around truly open markets, not a collection of silos. In The Intention Economy, customers don’t have to fly from silo to silo, like a bees from flower to flower, collecting deal info (and unavoidable hype) like so much pollen. In The Intention Economy, the buyer notifies the market of the intent to buy, and sellers compete for the buyer’s purchase. Simple as that.

The Intention Economy is built around more than transactions. Conversations matter. So do relationships. So do reputation, authority and respect. Those virtues, however, are earned by sellers (as well as buyers) and not just “branded” by sellers on the minds of buyers like the symbols of ranchers burned on the hides of cattle.

The Intention Economy is about buyers finding sellers, not sellers finding (or “capturing”) buyers.

In The Intention Economy, a car rental customer should be able to say to the car rental market, “I’ll be skiing in Park City from March 20-25. I want to rent a 4-wheel drive SUV. I belong to Avis Wizard, Budget FastBreak and Hertz 1 Club. I don’t want to pay up front for gas or get any insurance. What can any of you companies do for me?” — and have the sellers compete for the buyer’s business.

This car rental use case is one I’ve used to illustrate what would be made possible by “user-centric” or “independent” identity, which was also the subject of the cover story in last October’s Linux Journal, plus this piece a year earlier, and various keynotes I’ve given at Digital Identity World, going back to 2002. It is also the use case against which the new open source Higgins project was framed.

Even though I’ve been thinking out loud about Independent Identity for years, I didn’t have a one-word adjective for the kind of market economy it would yield, or where it would thrive. Now, thanks to all the unclear talk at eTech about attention, intentional is that adjective, because intent is the noun that matters most in any economy that gives full respect to what only customers can do, which is buy.

Like so many other things that I write about (including everything I’ve written about identity), The Intention Economy is a provisional idea. It’s an observation that might have no traction at all. Or, it might be a snowball: an core idea with enough heft to roll, and with enough adhesion to grow, so others add their own thoughts and ideas to it.

So that’s the purpose I chose for my new Berkman project: to get a snowball of development rolling toward the Intention Economy.

The project has been lightweight from the start, consisting of myself* and other volunteers. Our instruments are this blog, a wiki, a mailing list and events. In gatherings of project volunteers at Berkman and elsewhere, we narrowed our focus to encouraging development of tools for independence and engagement. That is, tools that would make individuals both independent of other entities (especially companies) and better able to engage with them. These shaped the principles, goals and tools listed on our wiki.

The term VRM came about accidentally. I was talking about my still-nameless project on a Gillmor Gang podcast in October 2006. Another guest on the show, Mike Vizard, started using the term VRM, for Vendor Relationship Management — or the customer-side counterpart of CRM, for Customer Relationship Management, which was then about a $6.2 billion B2B software and services industry.  (It’s now past $20 billion.) The Gillmor Gang is a popular show, and the term stuck. It wasn’t perfect (we wanted a broader focus than “vendors,” which is also a B2B term, rather than C2B). But the market made a decision and we ran with it. Since then VRM has gained a broader meaning anyway. Every thing (hardware, software, policies, legal moves) that enables an individual to interact with full agency in any relationship is a  VRM thing. “RM” turns out to  be handy for sub-categories as well, such as GRM (government relationship management) and HRM (health relationship management).

ProjectVRM has always been unusual for Berkman in two ways. One is that it has been focused on business — the commercial side of the “society” in Berkman’s name. The other is that it put the development horse ahead of the research cart. So, while we always wanted to do research (and did some along the way, such as with ListenLog), we felt it was important to create research-worthy effects first.

My first mistake was thinking we would have those effects within a year. My second mistake was thinking we would have them within four years — the length of my fellowship. It has taken twice that long, and still requires one more piece. More about that below, in the Research and Opportunities sections.

In its early years, when it was pure pioneering, ProjectVRM had a lot of volunteer organizational help. There were weekly conference calls and meetings, and events held in Cambridge, London, San Francisco and elsewhere. But the main gatherings from the start were at the Internet Identity Workshop (IIW), an unconference I co-organize at the Computer History Museum in Mountain View. (Our next VRM Day is 27 October. Register here.)

IIW also started with Berkman help. It was first convened as a group I pulled together for a December 31, 2004 Gillmor Gang podcast on identity. Steve Gillmor called the nine participants in the show “The Identity Gang.” The conversation continued by phone and email, with growing energy. So we convened again, this time in person with a larger group, in February 2005 at Esther Dyson’s PC Forum in Scottsdale, Arizona. It was there that John Clippinger asked if we would like “a clubhouse” at Berkman. I said yes, and John had Paul Trevithick create a Berkman site for the gang. As interest collected around the site and its list, three members — Phil Windley (then CIO of Utah), Kaliya Hamlin (aka “IdentityWoman“) and I morphed the gang meetings into IIW, which met for the first time in Fall of 2005. Our 19th is coming up on 28-30 October. (Register here.)  It tends to have 180-250 participants from all over the world. While identity remains the central theme, as an unconference its topics can be whatever participants choose. VRM is always a main focus, however. And we always have a “VRM Day” at the Museum the day before IIW. The next is on 27 October. It’s free.

The Identity Gang  also grew out of other efforts by a number of individuals and groups:

I’ll leave it at those for now. Others can add to it and help me connect the dots later. What matters is that ProjectVRM has both roots and branches that intertwine with the digital identity movement. I unpack more in the Community section below. Meanwhile it is essential to note that Kim Cameron’s Seven Laws of Identity had a large guiding influence on ProjectVRM. This is partly because they were all good laws, but mostly because they came from the individual’s side:

  1. User control and consent
  2. Minimal disclosure for a constrained use
  3. Justifiable parties (“disclosure of identifying information is limited to parties having a necessary and justifiable place in a given identity relationship”)
  4. Directed identity (“facilitating discovery while preventing unnecessary release of correlation handles”)
  5. Pluralism of operators and technologies
  6. Human integration
  7. Consistent experience across contexts

As you see, all of those should apply just as well to VRM tools and services.

We have had two interns in our history, both hugely helpful. The first was Doug Kochelek, an HLS law student with a BS and a EE from Rice. He came on board at the very beginning, in September 2006. He’s the guy who worked with Berkman’s Geek Cave to create the wiki, the blog and the list. He also shook down many technical problems along the way. The second was Alan Gregory, a 2009 summer intern and a law student at the University of Florida. Alan helped with research on the chilling effects of copyright expansion on Web streaming, which was a focus of a research project we did with PRX called ListenLog — a self-tracking feature installed in PRX’s Public Media Player iPhone app. (Here’s a presentation Alan and I did at a Fellows Hour.) ListenLog was the brainchild of Keith Hopper, then of NPR, and was years ahead of its time. Work on those projects was funded by a grant from the Surdna Foundation.

To keep its weight light and its work focused on development and relevant issues, ProjectVRM does not have its own presence on Twitter or Facebook. Its social media activity is instead comprised of postings by individual participants in the project, and the memes they drive. #VRM, for example, gets tweeted plenty, and has come to serve as shorthand for individual empowerment.

In 2007 we did a good job of publicizing what VRM and ProjectVRM were about, and got a lot of buzz. It was  premature, and our first big lesson: it’s not good to publicize anything for which the code isn’t ready. In the absence of code, it’s easy for commentators (such as here) to assume that what we’re trying to do can’t be done.

So we got more heads-down after that, and avoided publicity for its own sake.

not_iball1Still, the idea of VRM is attractive, especially to folks at the leading edge of CRM. This is what caused nearly an entire issue of CRM magazine to be devoted to VRM ,in May 2010. It too was ahead of its time, but it helped. So did two books that came out the same year: John Hagel’s The Power of Pull, and David Siegel’s Pull: The Power of the Semantic Web to Transform Your Business. John also helped in June 2012 with The Rise of Vendor Relationship Management.

That essay was a review of  The Intention Economy: When Customers Take Charge, which arrived in May from Harvard Business Review Press. The book reported on VRM development progress and detailed the projected shifts in market power that I first called for in my 2006 column with the same title.

While  The Cluetrain Manifesto has been a bigger seller, The Intention Economy Intention-economy-cover has had plenty of effects. Currently, for example, it is informing the work of Mozilla’s commercial arm, headed by Darren Herman, who this year hired @SeanBohan from the VRM talent pool. (Here’s a talk I gave at Mozilla in New York last month.) On the publicity side, the book was compressed to a Wall Street Journal full-page Review section cover essay titled “The Customer as a God.”

So far ProjectVRM has one spin-off: Customer Commons, a California-based nonprofit. Its mission is “restore the balance of power, respect and trust between individuals and organizations that serve them.” CuCo is a membership organization with the immodest ambition of attracting “the 100%.” In other words, all customers. And it is modeled to some degree on Creative Commons CustomerCommonsLogo4(a successful early Berkman spin-off), by serving as the neutral place where machine- and person-readable versions of personal terms, conditions, policies and preferences of the individual can be maintained. Among those terms will be those restricting or preventing unwanted tracking, and among those policies will be those establishing the boundaries we call privacy. Customer Commons is a client of the Cyberlaw Clinic, which is helping develop both. But much more can be done. We’ll visit that in the Opportunities section below.

2. Development

The list of VRM developers is now up to many dozens. While most don’t use the term “VRM” in marketing their offerings (nor do we push it), the term is gathering steam. For example, while updating the developers list a few minutes ago, I found two new companies that use VRM in the description of their offerings: InformationAnswers (“Where CRM meets VRM.”) and PeerCraft (“The main purpose for PeerCraft is to support Vendor Relation Management.”)

Some developers on our list are now familiar brands, though none started that way, and most did not exist when ProjectVRM began. Some of the successes (e.g. Uber and Lyft) have not been directly engaged with ProjectVRM, but are listed because they are what we call “VRooMy.” Other successes (e.g. Personal.com, Reputation.com and GetSatisfaction) have been engaged, one way or another. One that got a lot of notice lately is Thumbtack, for picking up a $100 million investment from Google. That’s atop the $30 million they got earlier this year.

In fact many VRM developers are now having an easier time getting money, thanks to a trend on which ProjectVRM has had influence: a shift of market interest away from “push” (e.g. advertising) and toward “pull” (e.g. VRM). (More about investment below.)

Several years ago, a bunch of VRM developers (and I) worked on developing SWIFT’s Digital Asset Grid. (SWIFT is the main international system for moving money around, and is headquartered in Belgium.) The code is open source, as is other VRooMy work in the financial sector. (Such as the stuff being done by the Romanian company I wrote about here.) OIX also maintains a set of “trust frameworks,” one of which is at the heart of the Respect Network, which I’ll unpack below.

While there is a lot of development in the U.S., and there are VRM startups scattered around the world, the three main hotbeds of activity are the UK, France and Oceania (Australia and New Zealand). Each is a community of its own, cohering in different ways. It’s helpful to visit each, because they represent unique contexts and resources for moving forward.

The UK

In the UK, government is central, through a role one official there calls “being a giant consumer of personal data from citizens.” It gets that data either from individuals directly or from companies that provide individuals with what are called variously called personal clouds, data stores, lockers and vaults. While all these companies perform as intermediaries, they work primarily for the individual. To differentiate this new class of company from traditional third parties, ProjectVRM calls them “fourth parties”. (That term is alien to lawyers, but is catching on anyway. For example, there is a new VRM company in Australia with the name “4th Party.”)

Leading the UK government in a VRooMy direction from the inside is in the Efficiency and Reform Group of the Government Digital Service (GDS) in the Cabinet Office.  In this presentation by Chris Ferguson, Deputy Director of the GDS we see the government pulling in big companies (e.g. Google, Equifax, Lexis-Nexis, Experian, Paypal, Royal Mail, BT, Amazon, O2, Symantec) to legitimize and engage fourth parties serving individuals (e.g. Mydex, Paoga and Allfiled).

Two outside groups working with the UK government are Ctrl-Shift and OIX (Open Identity Exchange). Ctrl-Shift is a research consultancy that has been engaged with ProjectVRM from the beginning. OIX is a Washington-based international .org focused on ‘building trust in online transactions.’

France

VRM is a familiar and well-understood concept in France. There are meetups (such as this one) and many VRooMy startups, such as Privowny (led by French folk and HQ’d in Palo Alto), CozyCloud, and OneCub. A big organizational driver of VRM in France is Fing.org, a think tank that brings together large companies (e.g. Carrefour, Societe General, Orange and LaPoste) with small companies such as the ones I just mentioned. They do this around research projects. For example, ProjectVRM informed Fing’s Mesinfos research project (described here).

Oceania

If we were to produce a heat map of VRM activity, perhaps the brightest area would be Australia and New Zealand. I’ve been down that way three times since June of last year, to help developers and participate in meetings and events. As with the UK, government in Australia is very supportive of VRM development, and with empowering individuals generally. (We met with three agencies on one of the trips: one with the federal government in Canberra and two with the New South Wales government in Sydney. One of them called citizens “customers” of government services, because “they pay for them.”) Startups there include Flamingo, Meeco, Welcomer, Geddup,4th Party, Fifth Quadrant, Onexus and the New Zealand based MyWave.

Recent changes in Australian privacy policy also attract and support VRM development. Australian companies (and government agencies) collecting personal data from people on the Web (or anywhere) are now required to make that data available to those people to use as they please. (Or so I understand it.) This gives Canberra-based Welcomer, for example, a reason to exist. Welcomer makes “private data dashboards” that “show collected summaries of the personal data held by organisations and by individuals including the person themselves. The dashboard gives a summary of personal data with the ability to link through to the source data (where required).”

This summer, the first commercial community to grow out of ProjectVRM work, the Respect Network (which Privacy By Design (PbD) calls the “World’s First Global Private Cloud Network”) held a world tour to launch the community and stimulate funding for members’ common goals, standards and code development. I was on the tour (London, San Francisco, Sydney, Tel Aviv), and wrote a report on the ProjectVRM blog. (Naturally, I shot pictures. Those are here. I also spoke at each venue. One of my Sydney talks is here.)

3. Community

To understand where ProjectVRM fits in the world, and how it works, I like the Competing Values Framework by Kim S. Cameron (no relation to the one above), Robert E. Quinn, Jeff DeGraff and Anjan Thakor:

Screen Shot 2014-09-01 at 5.48.45 PM

While there are many VRM developers operating in the lower half of that graphic, what ProjectVRM does is in the upper half of that diagram.  We have a collaborative clan of flexible and creative individuals in an adhocracy, working together on long-term transformational change.

Pretty much everything that gets criticized about our efforts falls in the lower half. That’s because we have no hierarchy and don’t work to control what anybody does. And progress on the whole  has been slow. (Though there are exceptions, such as Uber, Lyft and Thumbtack.)

That graphic is just one of many helpful ones in David Ronfeldt‘s Organizational forms compared, which he’s been updating since first publishing it in May 2009. One reason it is helpful is that the hierarchical short-term stuff is obvious and easily understood, while collaborative long term stuff is much harder to grok. It’s like the difference between weather and geology. Which makes me think that graphic should be flipped vertically: slow stuff on the bottom, fast stuff at the top. That’s what the Long Now foundation does with this graphic, which I’ve always loved:

layers of time

The change we want most is down in the culture, governance and infrastructure layers, even though our focus is on commerce. This also explains why we run into trouble when we play with fashion. The last thing we want is for VRM to be cool. (This is also a lesson I learned and re-learned over two decades of watching Linux, free software and open source for Linux Journal.)

The following graphics are all from David Ronfeldt’s scholastic gatherings. Each in its own way helps explain how our community works — and how it doesn’t. First, from one of Bob Jessop‘s many papers on governance and metagovernance (this one from 2003):

jessop figure

That’s our column on the right.

Then there is this, from Federico Iannacci and Eve Mitleton–Kelly’s Beyond markets and firms: the emergence of Open Source networks (First Monday, May, 2005):

iannacci

That’s us in the middle. We’re a stable and decentralized heterarchy that coordinates by mutual adjustment.

Then there is this from Karen Stephenson‘s Neither Hierarchy nor Network: An Argument for Heterarchy (in Ross Dawson’s Trends in the Living Networks, April, 2009):

stephenson

Again that’s us on the right.

Something I like about those last two is the respect they give to heterarchy, which has been a focus for many years of Adriana Lukas, another VRM stalwart who has been with the project since before the beginning. Here’s her TED talk on the subject.

Finally, there is this graphic, from  Clay Spinuzzi‘s Toward a Typology of Activities (2013):

Spinuzzi

In Spinuzzi’s Losing by Expanding: Corralling the Runaway Object, an object is identified as “a material or problem that is cyclically transformed by collective activity.” With our tacit, inductive and flexible approach, this also characterizes the way our community works.

One can see all this at work on the ProjectVRM mailing list, an active collection of 615 subscribers. We also meet in person twice a year at IIW, starting one day in advance of the event, with “VRM Day.” This adds up to a total of at least eight days per year of in-person collaboration time.

Most of the rest of the VRM community meets locally, or through the organizing work of organizations such as Respect Network (U.S. based, but spanning the world) and Fifth Quadrant (Sydney based, and focused on Australia and New Zealand).

There are many other organizations with which ProjectVRM is well aligned. Among them are:

If things go the way I expect, Mozilla will also emerge as a center of VRM interest and development as well. (For example, I expect VRM to be a topic in October at MozFestival in the U.K.

4. Influence

Nearly all VRM influence derives from the work of its volunteers and its developers. “Markets are conversations,” Cluetrain said, and we drive a lot of those. But they rarely get driven exactly the way I, or we, would like. Conversations are like that. EIC awardSo are heterarchical networks. Everybody wants to come at issues from their own angle, and often with their own vocabulary. We see that especially with analysts and think tanks. None of them like the term VRM. (In fact lots of developers avoid it as well. I don’t blame them, but we’re stuck with it.) Ctrl-Shift, for example, calls fourth parties PIMS, for Personal Information Management Services. Kuppinger-Cole, which gave ProjectVRM an award in 2008 (that’s the trophy on the right), insists on the term “Life Management Platforms.” (I pushed it for awhile. Didn’t take.) Here in the U.S., Forrester Research calls the same category PIDM for Personal Identity and Data Management. We don’t care, because we look for effects.

As for the influence of others on ProjectVRM, there are too many to list.

5. Issues

Privacy is the biggest one right now. (A Google search brings up more than five billion results). We’ve done a lot to drive interest in the topic, and have brought thought leadership to the topic as well. (Here is one example.) On behalf of ProjectVRM, I’ve participated in many privacy-focused events, such as the Data Privacy Hackathon earlier this year, and at GovLab gatherings such as the one reported on here. I’m also in Helen Nissenbaum‘s Privacy Research Group at the NYU Law School, where I presented ProjectVRM developers’ privacy work on February 26 of this year.

Tied in with privacy online, or lack of it, is users’ need to submit to onerous terms of service and meaningless privacy policies. Those terms, also called contracts of adhesion, have been normative ever since industry won the industrial revolution, but have become especially egregious in the online world. Today there is a crying need both for better terms on the sites’ and services’ side, and for terms individuals can asset on their side. From the beginning ProjectVRM has been focused mostly on the latter.

Trust is another huge issue, also tied with privacy. ProjectVRM has both encouraged and influenced the growth of “trust frameworks” such as the Respect Trust Framework and others (there are five) at OIX, as well as Open Mustard Seed and OpenPDS under IDcubed at the MIT Media Lab.

VRM+CRM has been a focus from the start, but the timing has not been right until now. At the beginning, we expected CRM companies to welcome VRM. Press and analysts in the CRM space were encouraging from the start (CRM Magazine devoted an entire issue to it in 2010), but the big CRM companies showed little interest, until this year.

Sitting astride or beside VRM and CRM is a category variously called CX (for Customer Experience), CRX (for Customer Relationship Experience), EM (for Experience Management) CEM or CXM (for Customer Experience Management) and other two and three-letter initialisms. Another happening in the midst of all these is “co-creation” of customer experience. The purpose here is to bring customers and companies together to co-create experience in a lab-like setting where research can be done. This is what Flamingo does in Australia. In a similar way, MyWave in New Zealand (with developers in Australia) “puts the customer in charge of their data and the experience” for a “direct ‘segment of one’ relationship with businesses.”

With the Internet of Things (IoT) heating up as a topic, there is also an increased focus, on the “own cycle,” rather than the “buy cycle” of the customer experience. I explain the difference here, using this graphic from Esteban Kolsky:

oracle-twist

In our lives the own cycle is in fact the largest, because we own things — lots of them — all the time and are buying things only some of the time. In fact, most of the time we aren’t buying anything, or even close to looking. This is a festering problem with the advertising-driven commercial Web, which assumes that we are constantly in the market for whatever it is they push at us. In addition to not buying stuff all the time, we are employing more and more ways of turning advertising off (ad blockers are the top browser extensions). For advertising and ad-supported companies, including millions of ad-supported publishers on the Web, this is a mounting crisis. According to an August 2013 PageFair report, “up to 30% of web visitors are blocking ads, and that the number of adblocking users is growing at an astonishing 43% per year.” In The Intention Economy, I called online advertising a “bubble” and I stand by the claim. It’s just a matter of time.

As the stuff we own gets smart, and as more of it finds its way onto the Net service becomes far more important to companies than sales. And VRM developers are laying important groundwork in service. I wrote about this in Linux Journal last year, drawing special attention to the pioneering work led by Phil Windley, who has been a VRM stalwart since before the beginning. In fact it’s Phil’s work that makes clear that things themselves don’t need to be smart to exist on the Internet. All they need is clouds that are smart, which Phil calls picos for persistent computing objects. In this HBR post I explain how the shared clouds of products can be platforms for relationship between company and customers , with learnings flowing in both directions.

6. Verticals

Relationship

This was the first for VRM, and it’s still a primary interest. We need tools on the individual’s side for managing many relationships. There still is not a good “relationship dashboard,” though there are a number of efforts in this direction. But as soon as we have code on the VRM side that matches up with code on the CRM side (including, for example, call centers, which are also interested in VRM), we’ll rock.

Payments

Even though ProjectVRM’s mission is centered around relationship and conversation, transaction is a big part of it too — just not the only part, as business often assumes. Our first efforts, starting in 2006, were around making it as easy as possible for individuals to donate money in one standard way to many different public radio stations.

We have been involved in many meetings and discussions around payments and secure data transactions, and some projects as well. We worked with SWIFT on the Digital Asset Grid, and have been in conversations with banks (e.g. Chase) and VISA Europe for a long time as well. With the rise of alternative currencies (e.g. Bitcoin), distributed accounting (e.g. Blockchain), digital wallets and other new means for transacting and accounting, there are many ways for VRM developments to play.

Email

In what is being called “post-Snowden time,” many new secure and encrypted email approaches have evolved. While some are listed on the ProjectVRM developers list, we haven’t been very involved with them — at least not yet. But we are involved with developers working on privacy-protecting tools that can either be embedded in existing email systems or offer alternative communications “tunnels.”

Personal information Management

There are two breeds of development here.

One is fourth party services and code bases for managing and sharing personal data selectively online. There are now many of these. Some support self-hosting as well. (ProjectVRM has always been supportive of free software, open source, and the “first person technology” and “indie” movements.) One organization, the Respect Network, was created to provide a framework for substitutability of services and apps.

The other is code the individual uses to manage his or her own life, and connections out to the world. This is where calendar, email, IM, to-do lists, password managers and other convenience-producing apps for the connected world come together. There is no leader here, though there are many players, including Apple, Microsoft and Google.  So far, this area has only seen centralized and siloed players, with inherent security and data mining disadvantages. But recently, commercial and open source conversations about a decentralized approach to this opportunity have been taking place.

A test case for VRM that applies to both kinds of solutions is this: being able to change my address, my last name or my phone number for many services in one move. This is exactly what the UK government is calling for from citizens’ personal information management systems (what Ctrl-Shift calls PIMS). A citizen should be able to change her address for the Royal Mail, the Passport Office and the National Health Service, all at once. Bonus links: Making things open, making things better, by Mike Bracken in the Gov.UK Government Digital Service blog, where Mike’s prior post, Reading the Digital Revolution featured this illustration by our old friend Paul Downey:

cluetrain-620x295

Apple’s HealthKit and HomeKit, which go live with the release of iOS 8on 9 September, also have some VRM developers excited, because it will make this kind of integration at the individual end easy to do in two verticals: Health and Home Automation.

Health

Early on with ProjectVRM, I avoided health as an issue, because I wanted to see real progress in my lifetime — and I felt that the situation in the U.S. was fubar. But other VRM folk did not agree, and have pushed VRM forward very aggressively in the health field. Dr. Adrian Gropper and Dr. Deborah Peel of Patient Privacy Rights have done a remarkable job of carrying the VRM flag up a very steep and slippery hill. Berkman veteran John Wilbanks is another active ProjectVRM volunteer whose work in health is broad, deep, influential and at the leading edge of the pioneering space where personal agency engages the wild and broken world of the U.S. health care system. Brian Behlendorf, the primary developer of the Apache Web server (which hosts the largest share of the world’s Web sites and services) and the CONNECT open source code base for health service collaboration, is also an active participant in ProjectVRM.

A number of VRM developers are working with, or paying close attention to, Apple’s HealthKit. In the words of one of those developers, “It’s very VRooMy.” HealthKit developments go live when Apple rolls out iOS 8 on 9 September.

Automotive

While a number of car makers are eager to spy on drivers, Volkswagen has put a stake in the ground. In March, Volkswagen CEO Martin Winkerhorn gave a keynote at the Cebit show that drew this headline: “Das Auto darf nicht zur Datenkrake warden.” My rusty Deutsch tells me he’s saying the car shouldn’t be a data octopus.

Toward that end, Phil Windley’s Kickstarter-based  Fuse will give drivers and car owners all the data churned out of their cars’ ODB-II port, which was created originally for diagnostics at car dealers and service stations. With an open API around that data, developers can create apps to alert you to schedule maintenance, monitor your teen’s driving and much more.

Real Estate

The only products that cost us more than cars are homes. Here too we have a VRM advocate in Cambridge-based Bill Wendell of Real Estate Café. He has always been way ahead of his time, but it’s clear his time is coming. (Here’s Bill leading a session on VRM in Real Estate at IIW 18 in May.)

7. Investment

There is an upswing of investment in start-ups on the “pull” — the individual’s — side of the marketplace. Many wealthy individuals, some quite new to tech investing, perceive an opportunity in “pull” side tools, so interest is building, especially in angel funding. There are currently at least three initiatives coming together to invest in VRM or intention based start-ups in Silicon Valley and Europe. This is one of the outcomes of the last IIW (in May of this year), where investment emerged as a big theme, with a number of VC’s for the first time participating in IIW sessions. I’m involved in planning a VRM specific fund, which is still in its preliminary stages. If it moves forward (which I believe it will), it should come into shape by next year.

In some cases government is also involved. In the UK, for example, the SEIS (Seed Enterprise Investment Scheme) program offers huge tax incentives to angel investors.

8. Research

There are many questions we can probe with research, but only one I want to work on in the near term: What happens when individuals come to websites with their own agreeable terms?creativecommons-licenses

Such as, “I’m cool with you tracking me on your site, but don’t follow me when I leave.” And, on the site’s side,  “We’re cool with that.” In proper legalese, of course — but expressed on both sides in code and symbols that work like Creative Commons’ licenses (there on the right).

The Cyberlaw Clinic is already involved, though its work with Customer Commons on a broader set of terms than the one I just mentioned, and Berkman’s own  Privacy Tools for Sharing Research Data could assist with and follow the process, both through the term-creation process and as the terms get implemented in code and materialize on the Web.

We would be dealing with cooperative efforts that require this already. One is Respect Network’s Respect Connect “Login with Respect” button.  As I explain here, the terms of OIX’s Respect Trust frame require the setting of, and respect for, the boundaries of individuals. This can be done, even within the calf-cow framework of client-server.

Respect Connect  is based onXDI, which the Respect Trust Framework also specifies. XDI is a protocol that employs “link respect-connect-buttoncontracts.” Drummond Reed, the father of XDI (and CEO of the Respect Network) describes link contracts as “machine-readable XDI descriptions of the permissions an individual is giving to another party for access to and usage of the owner’s personal data.” Very handy. And binding. In code.

Mozilla has also made efforts in this same direction, most recently with  Persona (there on the right). signinWe can help them out with this work, and I am sure other and other browser makers will also want to get on board — which they should, and with Berkman’s convening power probably will.

At the end of the project we will have both standard terms for posting at Customer Commons and reference implementations hosted by Berkman, or shared by Berkman over Github or some other data repository.

And we would bring to the table many dozens of developers already eager to see increased agency and term-proffering power on the individual’s side. I can easily see privacy dashboards, on both the client and the server sides of websites.

(Thinking out loud here…) We could host focused discussions and invite participants (including law folk — especially students, from anywhere) to vet terms the way the IETF vets Internet standards: with RFCs, or Requests for Comments. Some open source code for this already exists with Adblock Plus’s white list for non-surveillance-based advertisers. I would hope they’d be eager to participate as well. We (ProjectVRM, the Berkman Center or Customer Commons) could publish lists of conformant requirements for website and Web service providers, and lists (or databases) of conformant ones.

This work would also separate respectful actors on the supply side of the marketplace from ones that want to stick with the surveillance model.

While there are lots of things we could do, this is the one I know will have the most leverage in the shortest time, and would be great fun as well.

It is also highly cross-disciplinary, with many lines of cooperation and collaboration within the university and out to the rest of the world. Right at Berkman we have the  Privacy Tools for Sharing Research Data project and its many connections to other centers at Harvard. Its mission — “to help enable the collection, analysis, and sharing of personal data for research in social science and other fields while providing privacy for individual subjects” — is up many VRM development alleys, especially around health care.

9. Questions

What if we fail?

What if it turns out that free customers are not more valuable than captive ones for most businesses? That’s been the default belief of big business ever since it was born.

What if the free market on the Net turns out to be “Your choice of captor?” Client-server lends itself to that, although we can work around its inequities with moves like the one proposed in the Research section above.

What if the only VRM implementations that succeed in the marketplace are silo’d and non-substitutable ones? To some degree, that’s what we have with Uber and Lyft. While they are substitutable (as two apps on one phone), we don’t yet have a way to intentcast to multiple ride sharing providers at once, or to keep data that applies to both. Maybe we will in the long run, but so far we don’t.

Apple may be VRooMy with HealthKit and HomeKit, but both still operate within Apples silo. You won’t be able to use them on Android (far as I know, anyway).

And what if the Internet of Things turns out to be a world of silos as well? This too is the default, so far. Phil Windley mocks the Apple of Things and the Google of Things by calling both The Compuserve of Things — and making the case for substitutablility as well.

And what if customers just don’t care? This too is the default: the body at rest that tends to stay at rest. For VRM to fully happen, the whole body needs to be in motion — to move from one Newtonian state to another. It’s doing that in places, but not across the board.

Finally, what if we succeed? VRM is about making a paradigm shift happen. So was  Cluetrain before it. On the plus side, the Net itself lays the infrastructural groundwork for that shift. But the rest is up to us.

Whether we  fail or succeed (or both), there will be plenty to study. And that’s been the idea from the start too.

_________________

* Disclosures: I was paid modest sums as a fellow early on, but otherwise have received no compensation from the Berkman Center. I make my living as a speaker, writer and consultant. I have consulted a number of companies listed on the ProjectVRM development work page, and am on the boards of two start-ups: Qredo in the U.K. and Flamingo in Australia. In my work for them my main goal is to see VRM succeed, and I don’t play favorites in competition between VRM companies.

#VRM and the OpenNotice Legal Hackathon

The OpenNotice Legal Hackathon is happening now: 12 July 2014. Go to that link and click on various links there to see the live video, participate via IRC and other fun stuff.

It’s multinational. Our hosts are in Berlin. I’m in Tel Aviv (having just arrived from Sydney by way of Istanbul). Others are elsewhere in the world.

It’s moving up on 5pm, local time here, and 10am in New York.

I’m prepping for talking #VRM at this link here and  this link here.

Here are some core questions we’ll be visiting.

I’ll add more links later. This is enough to get us started.

Reporting on the Data Privacy Hackathon

Data Privacy HackathonIn case you missed the Data Privacy Hackathon, held this past weekend in London, New York and San Francisco, there should be a good mother lode of posts, tweets and videos up now, or soon.

Here is a small starter-pile of links from the New York one:

  • The hackathon page.
  • #privacyhack on Twitter
  • Videos of the event, courtesy of the New York Chapter of the Internet Society.  VRM and I come in at ~ 27 minutes into the first video. Finalist hacks are presented in this video here. One of the entries, Re-entry, led by Lina Kaisey, Harvard Law School ’14, starts at about 56 minutes into the last video link, and is to some degree based on my challenge in the first video link. It came in second. The winner was Ghostdrop, the presentation for which follows Lina’s, and which allows private communications between individuals. (Re-entry does that too, for prisoners re-entering the free world, and communicating with The System).

More at LegalHackathon.net.

LG jumps on advertising bandwagon, runs over its own customers

Used to be a TV was a TV: a screen for viewing television channels and programs, delivered from stations and networks through a home antenna or a cable set top box. But in fact TVs have been computers for a long time. And, as computers, they can do a lot more than what you want, or expect.

Combine that fact with the current supply-side mania for advertising aimed by surveillance, and you get weirdness such as Doctor Beet‘s LG Smart TVs logging USB filenames and viewing info to LG servers. According to Doctor Beet, viewer activity is actually reported to a dead URL (which may not be, say some of the comments). The opt-out is also buried an off-screen scroll. And LG tells Doctor Beet to live with it, because he “accepted” unseen opt-out terms and conditions.

But wait: there’s more.

If you want to really hate LG — a company you barely cared about until now, watch this. It’s a promotional video for “LG Smart AD,” which “provides the smartest way to reach your targeted audiences across the borders and connected devices with excitement powered by LG’s world best 3D and HD home entertainment technology” and “enables publishers to maximize revenues through worldwide ad networks, intelligent platform to boost CPM and the remarkable ecosystem.” The screen shot above shows (I’m not kidding) a family being terrorized by their “immersive” advertising “experience.”

This promotional jive, plus the company’s utterly uncaring response to a customer inquiry, shows what happens when a company’s customers and consumers become separate populations — and the latter is sold to the former. This split has afflicted the commercial broadcast industry from the start, and it afflicts the online advertising industry today. It’s why the most popular browser add-ons and extensions are ones that thwart advertising and tracking. And it’s why the online advertising industry continues to turn deaf ears and blind eyes toward the obvious: that people hate it.

Clearly LG is getting on the surveillance-based advertising-at-all-costs bandwagon here. The sad and dumb thing about it is that they’re actually selling customers they already have (TV buyers) to ones they don’t (advertisers). Their whole strategy is so ham-fisted that I doubt they’ll get the message, even if bad PR like this goes mainstream.

The one good effect we might expect is for competing companies to sell surveillance-free viewing as a feature.

Bonus link.

Prepping for #VRM Day and #IIW

The 16th IIW (Internet Identity Workshop) is coming up, Tuesday to Thursday, 7-9 May, will be tat the Computer History Museum in Mountain View, CA. As usual, VRM will be a main topic, with lots of developers and other interested folk participating. Also as usual, we will have a VRM planning day on the Monday preceding: 6 May, also at the CHM. So that’s four straight days during which we’ll get to present, whiteboard, discuss and move forward the many projects we’re working on. From the top of my head at the moment:

  • Personal Clouds, including —
    • The Internet of Me and My Things
    • QS (Quantified Self) and Self-Hacking
  • Fully personal wallets, rather than branded ones that work only with payment silos and their partners
  • Intentcasting — where customers advertise their purchase intentions in a secure, private and trusted way, outside of any vendor’s silo
  • Browser add-ons, extensions, related developments
  • Licensing issues
  • Sovereign and administrative identity approaches, including Persona, formerly BrowserID, from Mozilla
  • Legal issues, such as creating terms and policies that individuals assert
  • Tracking and ad blocking, and harmonizing methods and experiences
  • Health Care VRM
  • Devices, such as the freedom box
  • VRM inSovereign vs./+ Administrative identities
    • Real estate
    • Banking (including credit cards, payments, transactions)
    • Retail
  • Personal data pain points, e.g. filling out forms
  • Trust networks
  • Harnessing adtech science and methods for customers, rather than only for vendors

The morning will be devoted to VRM issues, while the afternoon will concentrate on personal clouds.

We still have eight tickets left here. There is no charge to attend.

In the next few days here on the blog we’ll be going over some of the topics above. Input welcome.

 

VRM development work

I’ll be having a brown bag lunch today with a group of developers, talking about VRM and personal clouds, among other stuff that’s sure to come up. To make that easier, I’ve copied and pasted the current list from the VRM developers page of the ProjectVRM wiki. If you’d like to improve it in any way, please do — either on the wiki itself, or by letting us know what to change.

While there are entire categories that fit in the larger VRM circle — quantified self (QS) and personal health records (PHRs) are two that often come up — we’ve tried to confine this list to projects and companies that directly address the goals (as well as the principles) listed on the main page of the wiki.


Here is a partial list of VRM development efforts. (See About VRM). Some are organizations, some are commercial entities, some are standing open source code development efforts.

SOFTWARE and SERVICES
Intentcasting
AskForIt † – individual demand aggregation and advocacy
Body Shop Bids † – intentcasting for auto body work bids based on uploaded photos
Have to Have † – “A single destination to store and share everything you want online”
Intently † – Intentcasting “shouts” for services, in the U.K.
Innotribe Funding the Digital Asset Grid prototype, for secure and accountable Intentcasting infrastructure
OffersByMe † – intentcasting for local offers
Prizzm †- social CRM platform rewarding customers for telling businesses what they want, what they like, and what they have problems with
RedBeacon † – intentcasting locally for home services
Thumbtack † – service for finding trustworthy local service providers
Trovi intentcasting; matching searchers and vendors in Portland, OR and Chandler, AZ†
Übokia intentcasting†
Zaarly † intentcasting to community – local so far in SF and NYC
Browser Extensions
Abine † DNT+, deleteme, PrivacyWatch: privacy-protecting browser extentions
Collusion Firefox add-on for viewing third parties tracking your movements
Disconnect.me † browser extentions to stop unwanted tracking, control data sharing
Ghostery † browser extension for tracking the trackers
PrivacyScore † browser extensions and services to users and site builders for keeping track of trackers
Databases
InfoGrid - graph database for personal networking applications
ProjectDanube - open source software for identity and personal data services
Messaging Services and Brokers
Gliph †- private, secure identity management and messaging for smartphones
Insidr † – customer service Q&A site connecting to people who have worked in big companies and are willing to help when the company can’t or won’t
PingUp (was Getabl) †- chat utility for customers to engage with merchants the instant customers are looking for something
TrustFabric † – service for managing relationships with sellers
Personal Data and Relationship Management
Azigo.com † – personal data, personal agent
ComplainApp † – An iOS/Android app to “submit complaints to businesses instantly – and find people with similar complaints”
Connect.Me † – peer-to-peer reputation, personal agent
Geddup.com † – personal data and relationship management
Higgins - open source, personal data
The Locker Project - open source, personal data
Mydex †- personal data stores and other services
OneCub †- Le compte unique pour vos inscriptions en ligne (single account for online registration)
Paoga † – personal data, personal agent
Personal.com † – personal data storage, personal agent
Personal Clouds - personal cloud wiki
Privowny † – privacy company for protecting personal identities and for tracking use and abuse of those identities, building relationships
QIY † – independent infrastructure for managing personal data and relationships
Singly † – personal data storage and platform for development, with an API
Transaction Management
Dashlane † – simplified login and checkout
Trust-Based or -Providing Systems and Services
id3 - trust frameworks
Respect Network † – VRM personal cloud network based on OAuth, XDI, KRL, unhosted, and other open standards, open source, and open data initiatives. Respect Network is the parent of Connect.Me.
Trust.cc Personal social graph based fraud prevention, affiliated with Social Islands
SERVICE PROVIDERS OR PROJECTS BUILT ON VRM PRINCIPLES
First Retail Inc. † commodity infrastructure for bi-directional marketplaces to enable the Personal RFP
dotui.com † intelligent media solutions for retail and hospitality customers
Edentiti Customer driven verification of idenity
Real Estate Cafe † money-saving services for DIY homebuyers & FSBOs
Hover.com Customer-driven domain management†
Hypothes.is - open source, peer review
MyInfo.cl (Transitioning from VRM.cl) †
Neustar “Cooperation through trusted connections” †
NewGov.us - GRM
[1] † – Service for controlling one’s reputation online
Spotflux † malware, tracking, unwanted ad filtration through an encrypted tunnel
SwitchBook † – personal search
Tangled Web † – mobile, P2P & PDS
The Banyan Project- community news co-ops owned by reader/members
TiddlyWiki - a reusable non-linear personal Web notebook
Ting † – customer-driven mobile virtual network operator (MVNO – a cell phone company)
Tucows †
VirtualZero - Open food platform, supply chain transparency
INFRASTRUCTURE
Concepts
EmanciPay - dev project for customer-driven payment choices
GRM: Government Relationship Management - subcategory of VRM
ListenLog - personal data logging
Personal RFP - crowdsourcing, standards
R-button - UI elements for relationship members
Hardware
Freedom Box - personal server on free software and hardware
Precipitat, WebBox - new architecture for decentralizing the Web, little server
Standards, Frameworks, Code bases and Protocols
Datownia † – builds APIs from Excel spreadsheets held in Dropbox
Evented APIs - new standard for live web interactivity
KRL (Kinetic Rules Language) - personal event networks, personal rulesets, programming Live Web interactions
Kynetx † – personal event networks, personal rulesets
https://github.com/CSEMike/OneSwarm Oneswarm] – privacy protecting peer-to-peer data sharing
http://www.mozilla.org/en-US/persona/ Mozila Persona] – a privacy-protecting one-click email-based way to do single sign on at websites
TAS3.eu — Trusted Architecture for Securely Shared Services - R&D toward a trusted architecture and set of adaptive security services for individuals
Telehash - standards, personal data protocols
Tent - open decentralized protocol for personal autonomy and social networking
The Mine! Project - personal data, personal agent
UMA - standards
webfinger - personal Web discovery, finger over HTTP
XDI - OASIS semantic data interchange standard
PEOPLE
Analysts and Consultants
Ctrl-SHIFT † – analysts
Synergetics † – VRM for job markets
VRM Labs - Research
HealthURL - Medical
Consortia, Workgroups
Fing.org - VRM fostering organization
Information Sharing Workgroup at Kantara - legal agreements, trust frameworks
Pegasus - eID smart cards
Personal Data Ecosystem Consortium (PDEC) – industry collaborative
Meetups, Conferences, and Events
IIW: Internet Identity Workshop - yearly unconference in Mountain View
VRM Hub - meeting in LondonNOTES:
† Indicates companies. Others are organizations, development projects or both. Some development projects are affiliated with companies. (e.g. Telehash and The Locker Project with Singly, and KRL with Kynetx.)
A – creating standard
B – Using other standards
1 – EventedAPI

Let’s turn Do Not Track into a dialog

Do Not Track (DNT), by resembling Do Not Call in name, sounds like a form of prophylaxis.  It isn’t. Instead it’s a request by an individual with a browser not to be tracked by a website or its third parties. As a request, DNT also presents an interesting opportunity for dialogue between user and site, shopper and retailer, or anybody and anything. I laid out one possibility recently in my Inkwell conversation at The Well. Here’s a link to the page, and here’s the text of the post:

The future I expect is one in which buyers have many more tools than they have now, that the tools will be theirs, and that these will enable buyers to work with many different sellers in the same way.

One primitive tool now coming together is “Do Not Track” (or DNT): http://en.wikipedia.org/wiki/Do_Not_Track It’s an HTTP header in a user’s browser that signals intention to a website. Browser add-ons or extensions for blocking tracking, and blocking ads, are also tools, but neither constitute a social protocol, because they are user-side only. The website in most cases doesn’t know ad or tracking blocking being used, or why. On the other hand, DNT is a social gesture. It also isn’t hostile. It just expresses a reasonable intention (defaulted to “on” in the physical world) not to be followed around.

But DNT opens the door to much more. Think of it as the opening to dialog:

User: Don’t track me.
Site: Okay, what would you like us to do?
User: Share the data I shed here back to me in a standard form, specified here (names a source).
Site: Okay. Anything else?
User: Here are my other preferences and policies, and means for matching them up with yours to see where we can agree.
Site: Good. Here are ours.
User: Good. Here is where they match up and we can move forward.
Site: Here are the interfaces to our CRM (Customer Relationship Management) system, so your VRM (Vendor Relationship Management) system can interact with it.
User: Good. From now on my browser will tell me we have a working relationship when I’m at your site, and I can look at what’s happening on both sides of it.

None of this can be contemplated in relationships defined entirely by the sellers, all of which are silo’d and different from each other, which is what we’ve had on the commercial Web since 1995. But it can be contemplated in the brick & mortar world, which we’ve had since Ur. What we’re proposing with VRM is nothing more than bringing conversation-based relationships that are well understood in the brick-and-mortar world into the commercial Web world, and weaving better marketplaces in the process.

A bit more about how the above might work:
http://blogs.law.harvard.edu/vrm/2012/02/23/how-about-using-the-no-track-button-we-already-have/

And a bit more about what’s wrong with the commercial Web (so far, and it’s not hard to fix) here:
http://blogs.law.harvard.edu/vrm/2012/02/21/stop-making-cows-stop-being-calves /

So, to move forward, consider this post a shout-out to VRM developers, to the Tracking Protection Working Group at the W3C, to browser developers, to colleagues at Berkman (where Chris Soghoian was a fellow, about at the time he helped think up DNT) — and to everybody with the will and the ways to move forward on this thing.

And hey: it’s also our good luck that the next IIW is coming up at the Computer History Museum in Mountain View, from October 23rd to 25th. IIW is the perfect place to meet and start hashing out DNT-D (I just made that up: DNT-Dialog) directions. IIW is an unconference: no keynotes, panelists or vendor booths. Participants vet and choose their own topics and break out into meeting rooms and tables. It’s an ideal venue for getting stuff done, which always happens, and why this is the 15th of them.

Meanwhile, let’s get in touch with each other and start making it happen.

Can we each be our own Amazon?

The most far-out chapter in  is one set in a future when free customers are known to be more valuable than captive ones. It’s called “The Promised Market,” and describes the imagined activities of a family traveling to a wedding in San Diego. Among the graces their lives enjoy are these (in the order the chapter presents them):

  1. Customer freedom and intentions are not restrained by one-sided “agreements” provided only by sellers and service providers.
  2. — service organizations working as agents for the customer — are a major breed among user driven services.
  3. The competencies of nearly all companies are exposed through interactive that customers and others can engage in real time. These will be fundamental to what calls .
  4. s (now also called intentcasts), will be common and widespread means for demand finding and driving supply in the marketplace.
  5. Augmented reality views of the marketplace will be normative, as will mobile payments through virtual wallets on mobile devices.
  6. Loyalty will be defined by customers as well as sellers, in ways that do far more for both than today’s one-sided and coercive loyalty programs.
  7. Relationships between customers and vendors will be genuine, two-way, and defined cooperatively by both sides, which will each possess the technical means to carry appropriate relationship burdens. In other words, VRM and CRM will work together, at many touch-points.
  8. Customers will be able to proffer prices on their own, independently of intermediaries (though those, as fourth parties, can be involved). Something like EmanciPay will facilitate the process.
  9. Supply chains will become “empathic” as well as mechanical. That is, supply chains will be sensitive to the demand chain: signals of demand, in the context of genuine relationships, from customers and fourth parties.
  10. The advertising bubble of today has burst, because the economic benefits of knowing actual customer intention — and relating to customers as independent and powerful economic actors, worthy of genuine relationships rather than coercive — bob will have became obvious and operative. Advertising will continue to do what it does best, but not more.
  11. Search has evolved to become far more user-driven and interactive, involving agents other than search engines.
  12. ‘s will be taken for granted. There will still be businesses that provide connections, but nobody will be trapped into any one provider’s “plan” that excludes connection through other providers. This will open vast new opportunities for economic activity in the marketplace.

In , Sheila Bounford provides the first in-depth volley on that chapter, focusing on #4: personal RFPs. I’ll try to condense her case:

I’ve written recently of a certain frustration with the seemingly endless futurology discussions going on in the publishing world, and it’s probably for this reason that I had to fight my way through the hypothesis in this chapter. However on subsequent reflection I’ve found that thinking about the way in which Amazon currently behaves as a customer through its Advantage programme sheds light on Searls’ suggestions and projections…

What Searls describes as the future for individual consumers is in fact very close to the empowered relationship that Amazon currently enjoys with its many suppliers via Amazon Advantage…  Amazon is the customer – and a highly empowered one at that.

Any supplier trading with Amazon via Advantage (and that includes most UK publishing houses and a significant portion of American publishers) has to meet all of the criteria specified by Amazon in order to be accepted into Advantage and must communicate online through formats and channels entirely prescribed and controlled by Amazon…

Alone, an individual customer is never going to be able to exert the same kind of leverage over vendors in the market place as a giant like Amazon. However individual customers online are greater than the sum of their parts: making up a crucial market for retailers and service providers. Online, customers have a much louder voice, and a much greater ability to collect, organise and mobilise than offline. Searls posits that as online customers become more attuned to their lack of privacy and control – in particular of data that they consider personal – in current normative contracts of adhesion, they will require and elect to participate in VRM programmes that empower them as individual customers and not leave them as faceless, impotent consumers.

So? So Amazon provides us with a neat example of what it might look like if we, as individuals, could control our suppliers and set our terms of engagement. That’s going to be a very different online world to the one we trade in now.  Although I confess to frustration with the hot air generated by publishing futurology, it seems to me that the potential for the emergence VRM and online customer empowerment is one aspect of the future we’d all do well to work towards and plan for.

From the start of ProjectVRM, Iain Henderson (now of The Customer’s Voice) has been pointing to B2B as the future model for B2C. Not only are B2B relationships rich, complex and rewarding in ways that B2C are not today (with their simplifications through customer captivity and disempowerment), he says, but they also provide helpful modeling for B2C as customers obtain more freedom and empowerment, outside the systems built to capture and milk them.

Amazon Advantage indeed does provide an helpful example of where we should be headed as VRM-enabled customers. Since writing the book (which, except for a few late tweaks, was finished last December) I have become more aware than ever of Amazon’s near-monopoly power in the book marketplace, and possibly in other categories as well. I have heard many retailers complain about “scan and scram” customers who treat brick-and-mortar stores as showrooms for Amazon. But perhaps the modeling isn’t bad in the sense that we ought to have monopoly power over our selves. Today the norm in B2C is to disregard that need by customers. In the future I expect that need to be respected, simply because it produces more for everybody in the marketplace.

It is highly astute of Sheila to look toward Amazon as a model for individual customers. I love it when others think of stuff I haven’t, and add to shared understanding — especially of a subject as protean as this one. So I look forward to the follow-up posts this week on her blog.

Coming to terms

We lie every time we “accept” terms that we haven’t read — a pro forma  behavior that is all but required by the calf-cow model of the Web that’s prevailed since 1995. We need to change that. And so we are.

StandardLabel.org is working on “A clear, consistent way for websites to say what they do with the data they share, before we share it.” While its recent Kickstarter campaign came up a bit short, the work continues. Here is one (prototypical) way that label might look:

(The actual image I wanted there was this one, but heard it wasn’t showing up in all browsers, so I went with the one above.)

The StandardLabel folks also have a survey, which I recommend taking.

CommonTerms intends “to solve the problem of non-accessible online legal texts in a way similar to how Creative Commons made different copyright licenses accessible,” adding, “We thought that by analyzing existing agreements, we could identify the most common terms, and then create icons to symbolize them.” Background:

The CommonTerms project is coordinated by Metamatrix AB andsponsored by Internetfonden.se

The project is a result of a session on “sustainable web development” by Pär Lannerö and Thomas Bjelkeman at the Sweden Social Web Camp, in August 2010.

Their prototype, focused on icons, stars Pär and looks like this:

Par and  Lars-Erik Jakobsson (icon), Gregg BernsteinCarl TörnquistHanna ArkestålMax WalterMattias AspelundAnders Carlman have since added BiggestLie.com, source of the image at the top of this post, plus this one here, which I just earned:

The idea is to start getting real about what we’re all doing and not doing.

What we’re doing is lying: i.e. agreeing not only to what we don’t read, but to the rotted status quo of which one-sided non-agreements are a part. What we’ve not been doing for most of the last 17 years is solving the problem.

But, thanks to the work above (plus whatever I’ve missed), we are doing some things. So are PDEC.cc and companies like Personal. Other work is happening with personal clouds. (PDEC is on that case too.) Aza Raskin‘s Privacy Icons are an effort in this same direction. (CommonTerms has a longer list.)

Still, looks to me like most of the work being done so far is on the cow side of the calf-cow relationship. On our side, we need to stop being calves, for real. That is, we need to have full agency in the original sense of the word: power to cause intended effects on our own.

For that we will need machine- and user-readable ways to express own terms, preferences and policies, so they can be read by sites (the cows) and matched up. That’s the idea behind EmanciTerm, described in How about using the ‘No Track’ button we already have? and in The Intention Economy. There I explain,

With full agency, however, an individual can say, in the first person voice, “I own my data, I control who gets access to it, and I specify what I wish to happen under what conditions.” In the latter category, those wishes might include:

  • Don’t track my activities outside of this site.
  • Don’t put cookies in my browser for anything other than helping us remember each other and where we were.
  • Make data collected about me available in a standard, open format.
  • Please meet my fourth-party agent, Personal.com (or whomever).

These are EmanciTerms, and there will be corresponding ones on the vendor’s side. Once they are made simple and straightforward enough, they should become normative to the point where they serve as de facto stan- dards, in practice.

Since the terms should be agreeable and can be expressed in text that code can parse, the process of arriving at agreements can be automated.

For example, when using a public wi-fi access point, a person’s EmanciTerms might say, “I will not knowingly hog this shared resource, for example, by watching high-def video on it,” or “I will not engage in illegal activities here.” If the provider of the access point has a VRM-ready service that is willing to deal with the user on his or her own EmanciTerms as well as those of the provider, it should be possible to automate the formalities and let the user bypass the usual “read and accept our agreement” ritual.

Not everything we express in the proposed ceremony here has to be one side of a binding agreement. If we express these terms as preferences or policies they can still be heard, even if they’re not agreed to. Being heard is one idea behind BiggestLie. But the cows can’t fix this on their own. We need to work both sides.

The only problem with all this is that our work is scattered. Let’s get it together.

Older posts

© 2014 ProjectVRM

Theme by Anders NorenUp ↑