Resources

Handed out after the talk, kept here because a slide URL outlives the slide.

Recovering Authenticity

The standards and organisations behind the talk, and behind the essay it became. Provenance is the part of authenticity that can be built; the rest is argument.

Provenance travels with the file, or it does not travel at all.

Data provenance and content authenticity

Sigillo is my own attempt at the practical end of this: an iOS camera that signs a photograph at the moment of capture, so the credential is embedded before the image is ever seen.

Combating disinformation

  • DISARM Foundation — a shared framework for describing influence operations, so defenders can name the same thing the same way.

On behalf of: delegated authority for AI

Ongoing work, and the part most likely to have moved since you read this.

  • Identity Management for Agentic AI (OpenID Foundation, October 2025) — a survey of where agent authorisation stands and what it still cannot do. Not my paper; the clearest statement of the problem I know.
  • The Unfinished Digital Estate (OpenID Foundation, March 2026) — what becomes of an account after its owner dies. I co-edited this one with Heather Flanagan and Dean H. Saxe.

Where the work happens

I co-chair both. This page gets updated as the standards work moves, at OpenID and at the IETF. Last touched 6 March 2026. If something here has gone stale or a link has rotted, tell me.