Bigger, Better Business With OAuth
Upcoming SlideShare
Loading in...5

Bigger, Better Business With OAuth



OAuth is more than an authentication protocol. A decade from now, OAuth will be viewed as the great enabler of new business models and wealth creation in the app economy. ...

OAuth is more than an authentication protocol. A decade from now, OAuth will be viewed as the great enabler of new business models and wealth creation in the app economy.
In this session we'll investigate why many business development ideas don't make it past the whiteboard and how OAuth changes that. We'll tickle our imaginations and explore what is possible in a world where crossing trust boundaries is done with lower risk, more control and higher security.
We Will Discuss »
- Blockers to Business Innovation
- How OAuth Changes the Rules
- Re-Imagining the Future of Business Development



Total Views
Views on SlideShare
Embed Views



16 Embeds 13,207 12844 159 105 39 19 7 6 6 6 5 4 3 1 1
http://mktg-new.local 1 1


Upload Details

Uploaded via as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
  • <br /><iframe width="350" height="288" src="" frameborder="0" allowfullscreen></iframe>
    Are you sure you want to
    Your message goes here
Post Comment
Edit your comment
  • Creative Commons Attribution-Share Alike 3.0 United States License
  • Invisible Engines
  • For most people, their car is their first or second most valuable possession, valued in tens of thousands of dollars. They are convenient places to leave our other valuables like computers and clothing. Yet we are sometimes required to give them to young, low-paid workers  whom we’ve never met before.
  • can we trust them?
  • In this situation we can give them a valet key – an authorization token with limited rights that can operate the vehicle but not grant access to the trunk, glovebox - or the rest of our keychain.

Bigger, Better Business With OAuth Bigger, Better Business With OAuth Presentation Transcript

  • Bigger, Better Business withOAuth11.11.17 @ 11:05 PSTVOIP or Dial-in (see chat) Ramji @sramjiBrian Mulloy @landlessness
  • Your hosts
  • @landlessness @sramji
  • 4
  • 5
  • Every market in history has had intermediaries
  • Business Intermediaries Customers
  • These intermediaries connect buyers andsellers by knowing what both want andcreating convenient ways to transact
  • Apps are the new intermediaries.
  • Business Apps Customers
  • They occupy many niches already andcontinue to multiply
  • App Store Growth 2008-2011 600 12 500 10 Apps AvailableThousands Total App Downloads 400 8 Billions 300 6 200 4 100 2 0 0 Data from Wikipedia
  • As do devices.
  • Mary MeekerKleiner Perkins
  • Companies cannot build for all these niches aseach one requires distinct expertise in designand development, and there are too manyniches.
  • As Marc Andreessen observed recently
  • “ In short, software is eating the world. We are in the middle of a dramatic and broad technological and economic shift in which software companies are poised to take over large swathes of the economy. Marc Andreessen
  • Evans, Hagiu, and Schmalenseeexplored this deeply in 2006
  • And Annabelle Gawerhas formalized the solution
  • The platform business model.
  • As we’ve learned from digital natives like
  • open platforms grow the fastest.
  • Visualization by Apigee
  • In the API era of competition, speed is crucialbecause critical mass leads rapidly to marketdominance.
  • [Ecosystem Competition] Kishore S. Swaminathan, Chief Scientist, Accenture
  • Open platforms mean thatapps can be built by developers quicklywithout formal commitment tojoint research,joint development, andjoint marketing.
  • Open platforms decouple partners from theplatform provider’s business cycles.
  • This reduces the cost of innovation,enabling many more experiments to be mademore quickly,increasing the chance of a major improvementto the platform business, its customers, and itsintermediaries.
  • This is low-friction innovation.
  • This takes us to the stakes required for adigital business in the API era.
  • For an intermediary to connect a buyer andseller, there must be trust.
  • The intermediary must be trustworthy,and the transaction must be trustworthy.
  • In modern businesses, buyers (users)have accounts with sellers (providers)which are filled with dataas well as transaction privileges.
  • For the system to function well, buyers must be able to fire their intermediarywithout breaking their relationship with the seller.
  • With apps as the intermediary, new dynamicsexist on top of the historical foundation.
  • Apps are new.They are often short-lived.Their business model depends on building ahigh volume of users.They must have some way to attain their firsttransaction and be proven or else improved.
  • And this way must align with theloose coupling philosophy at the heartof an open platformotherwise we’ve just secured our way backinto old-fashioned closed businessesand killed our platform opportunity.
  • “ 20th Century IT was about raising barriers to entry for competitors. 21st Century IT is about lowering barriers to participation. James Governor Redmonk
  • So how do you build a trustworthy systemin an open world?
  • It takes an open security architecture.
  • It’s a free and open protocol built on licenses from the Open Web Foundationand it’s the right choice for securing open platforms.
  • The Valet Key Metaphor
  • Eran Hammer-Lahav comparesthe OAuth model to a valet key.This is an apt metaphor.
  • A Valet Key for Open Platforms
  • The heart of OAuthis an authorization token with limited rightswhich the user can revoke at any timeshould they become suspicious or dissatisfiedwith the app they’re usingto access your business.
  • When the token is first grantedthe business shows the user what rights theapp is asking for
  • and this negotiation is invisible to the app.
  • A perfect design for bootstrapping trust.
  • Just Enough Permission
  • An app should have just enough permissionto do the things the user wants it to.
  • OAuth allows for granular access to the user’saccount.The current alternative is all or noneGive the app your username and password –which gives the app access to everythingabout you.
  • In OAuth, permissions can be gracefullyupgraded as well.If the user tries to do something in an app andthey haven’t authorized the correspondingpermission, the business can give the usersthe option to add that permission, using thebootstrapping sequence used to grant thetoken in the first place.
  • Just Enough Responsibility
  • App developers are not security experts.
  • A developer’s job is to make software thatdoes what it is supposed to do.A security expert’s job is to make suresoftware never does what it is not supposedto do.
  • App developers DO NOT WANT theresponsibility of holding a user’s secretinformation.Usernames and passwords,Credit card and banking information,Lifetime history of everyone you’ve emailedThese are heavy secretsand require heavy security.
  • The right place for these is within your ownbusiness, secured by your own experts andyour own infrastructure investments.
  • Decoupling partners from these challengeskeeps security consistentwith the open platform potential forlow-friction innovation.
  • The most popular intermediariesare connecting buyers with severalcomplementary sellers at the same time
  • That increases their value to the buyerbut also multiplies the difficulty andrisk of security
  • If one app holds secrets for many businessesthat app becomes the highest-risk part of thesystem.
  • As more businesses follow the platformimperative and add APIs
  • there is an imperative for the healthy growthof the market through the new intermediaries.
  • The imperative is to make it easy fordevelopers to build great appsthat can delight usersand grow businesses.
  • The imperative is for businessesto standardize on OAuth.
  • “We have our own version of OAuth”
  • “We invented something that’s kind of like OAuth”
  • The imperative is to make it easy fordevelopers to build great appsthat can delight usersand grow businesses.
  • The imperative is for businessesto standardize on OAuth.
  • No developers were harmed in the production of thispresentation.
  • 3 B.O. 89
  • App 90
  • U CANT HAS PLZ? MAH PASWORDZ! App AppDeveloper User 91
  • App App LimitedDeveloper User 92
  • 93
  • 94
  • 95
  • PLZ? NO MOAR 4 U! App APIDeveloper Team 96
  • App App App World of API Internal App APIUser Store Developer APIs Team Systems 97
  • Big Company Big Big BigCustomer Partner Company App App API User Developer Team 98
  • 4 A.O. 99
  • Big Company API Team Big BigCustomer Partner App App User Developer 100
  • ba 101
  • bsecurity a capability 102
  • Questions? 103
  • THANK YOUQuestions and ideas