Technology lessons

[Dave Birch] It must make me sound like some sort of snob, but I genuinely feel that one of the problems with the discussion of identity, privacy and related issues in the public sphere is that, ultimately, the policymakers, regulators and politicians just do not understand either technology as part of the problem or technology as part of the solution. Ian Brown’s review of the Thomas/Walport report about data sharing touches on this:

While it makes a brief mention of credentials (r. 5), the report is extremely backward-looking on technology,

[From Blogzilla: Thomas/Walport data sharing review published]

The problem, I think, is more insidious than it seems at first. It isn’t just that the people writing the report don’t understand the technology, it’s that they don’t even appear to think that the technology is important. As I noted at the time of the review…

Pete Bramhall from HP sagely noted that the consultation document began with the statement that it assumed a familiarity with the Data Protection Act and other relevant legislation. How come, he pointed out, it did not assume a familiarity with rudimentary information technology, basic data security, elementary cryptography or, indeed, anything else that might help to develop a privacy-enhancing infrastructure for the modern world. Quite.

[From Digital Identity Forum: Another thing invented by lawyers]

How are we going to get a genuine breakthrough in identity management when the gap between the “two cultures” appears to be widening. No, not those two cultures but the cultures of information and communications technology one the one hand and lawyers (particularly the ones that end up in the government).

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

2.5FA

[Dave Birch] 2FA is clearly important. But what kind of 2FA? At the moment, the "something you know" plus "something you have" version is in vogue, and a great many organisations have been rolling out tokens of one form or another. In the U.K., Barclays (to name but one) have already rolled-out 2FA to the mass market:

 

Gemalto announced it has passed the 1 million mark for Barclays customers using PINsentry, its cryptographic smart card reader. The bank started deploying its authentication program in July 2007 and since then not one PINsentry online customer has suffered fraud.

[From 1 million Barclays customer using smart card reader : SecureID News]

As I’ve said before, I’m a happy PINsentry customer, even though I know it doesn’t provide total security. But it’s a bit limited. I can’t use it to log in to anything else: I’d much rather that Barclays offered a 2FA OpenID login using the PINsentry and then I could use my Barclays OpenID to log in not only to the bank but to any other sites that needed that kind of security (eg, the government). Simon Willison’s excellent OpenID blogged alerted me to the fact that other people are already thinking in that direction.

 

Microsoft are accepting OpenID for their new HealthVault site, but with a catch: you can only use OpenIDs from two providers: Trustbearer (who offer two-factor authentication using a hardware token) and Verisign.

[From Simon Willison’s Weblog]

So OpenID/2FA is not only feasible, it’s a good idea. But we don’t want to end up with a 2FA necklace — with the tokens from half-a-dozen banks plus eBay plus our corporate networks plus plus plus — that we have to carry with us at all times and this could happen if banks and other service providers don’t accept each other’s OpenIDs in a rich enough way.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

User inexperience

[Dave Birch] So I’m a big e-money fan, and I really don’t want to bother with cash, and I want to pay everywhere using cards, phones, psychic power, whatever. Yet my cash replacement experiences are so poor I’m being to lose heart. I tried to pay for my coffee (and a colleague’s Snapple — note the journalistic accuracy) using my contactless Visa card. The UOB terminal said that it read the card, then a red light flashed momentarily and I got the message “transaction failed”. Why? I didn’t know, and nor did the shop assistant. Wrong card? Wrong card scheme? Gone over my limit? Offline No CVM counter reached zero… now I’m thinking “shall I waste money on an international mobile call to Barclays, shall I waste money on a call to UOB, shall I have to pay another ATM fee” as well as “how many times have I used this card without the PIN, is it 9 or 10 you’re allowed before you’re declined… but hold on, shouldn’t the terminal say if there’s a routine security check… no, what’s the phrase on the terminals in our office…”

Wait a minute: Normal people don’t start thinking about Cumulative Offline Value and other EMV risk management parameters, they just think “what a bad system, I won’t bother to use it again”. If we want to replace cash, guys, we’re going to have to do better than this. I’m hope that London taxi drivers have been given a full briefing on extended risk management in EMV Level 2 transactions over a wireless interface…

RBS will pilot contactless card acceptance in association with MasterCard in 25 London-based taxis owned by Xeta. If demand meets expectations, rollout of contactless card readers will be extended to Xeta’s entire taxi fleet.

[From ePaynews.com - the payment news and resource Center]

As was discussed back at the Digital Money Forum, after an excellent presentation by Ronnie O’Toole from National Irish Bank, a significant step toward cash replacement would be for taxi regulators to insist that cabs take contactless. This was part of the bank’s submission to the Irish Department of Finance:

The taxi regulator should make it compulsory for all taxis and hackneys to accept payment by debit or credit cards by the 1st of November 2008.

[From Digital Money Forum: I don't care too much for money...]

I think I’m going to write to Boris about this.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Out of band, out of mind

[Dave Birch] Using SMS to provide an out-of-band 2FA scheme for access to online services sounds like a reasonable idea. But it depends on customers to do the right thing, and this is generally a bad idea in security terms. One study of a scheme that required customers to copy a pass code from their phone to a web page (to confirm online transactions) found that customers did not notice when the message included incorrect details. My guess is that this is a general result: once you train customers to perform some simple action in order to obtain security, they won’t do any of the other cross-checks and because they think (for no reason) that SMS is somehow secure, then SMS-based approaches may be even more exposed. This is a shame, because it may hinder the development of mobile services, such a banking. People are increasingly comfortable with using their mobiles for banking, we all know that. According to TowerGroup, 90% of those who tried mobile banking at Bank of America have remained active with 99% checking balances, 87% looking at transaction history, 10% making funds transfers, and 5% paying a bill. But if they begin to read in the newspapers about mobile security being subverted, those numbers will fall.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Nymity vs. anonymity

[Dave Birch] In The Future of Money by Benjamin Cohen, the author says that one of factors that may make it difficult for e-money to substitute for physical notes and coins (“p-money”) is that e-money cannot reproduce the anonymity of p-money. I said that I would come back to this subject when I ad some time to think about. Having done so, it led me to reflect on my experiences in the early days of e-cash, the age of Mondex, VisaCash, DigiCash, CyberCoin and all the others. I had certainly had that opinion in the early days: When I first began working around these schemes, I assumed that anonymity was a key requirement for cash replacement. For one thing, that’s what customers said in market research, which was music to Mondex’s ears. (Note that consumers also said that they wanted the ability to “lock” Mondex cards with a PIN, a feature that I never once saw used in the live service.) But after some time, I began to realise that I was misunderstanding the customers’ desire for anonymity. For the most part, it wasn’t a real requirement at all, but a kind of comfort factor introduced into the portfolio of cash-like features. To use the post-modern visualisation of Umberto Eco, we shouldn’t have been designing virtual cash, but hypercash: Not an electronic version of cash as it is, but an electronic version of cash as it should be. I’m not advocating the construction of fantasy money that disconnects from the real world (Eco warns of the dangers of feeling “homesick for Disneyland” in “Travels in Hyperreality”, whioh was one of those books you enjoy reading, but at the end realise that you haven’t understood it) but more of an inclusive approach. We should be able to at least categorise the requirements of the various stakeholders (I don’t propose to do that here) to get a better idea of what digital money ought to be aiming for, rather than raise the bar no higher than than an electronic simulation of the plastic simulation of the paper simulation of money that we have now.

(This, incidentally, is going to be my rallying cry: No more e-money, it’s time for h-money! More on this later.)

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Fingers in the dyke

[Dave Birch] Over on the Digital Money Blog, we’ve been talking about the well-known MiFare security issue. We’re interested in it over there because MiFare is used for things such as Oyster cards and there’s an overlap between contactless cash replacement and contactless transit systems. From this frame of reference, the security issue is interesting and it needs to be factored in to system procurement, card updates and that kind of thing. No-one is going to implement an electronic purse system using MiFare Classic, so the sky isn’t falling in. So, the guys are saying, well, next time we buy some cards we’ll buy MiFare Plus instead, but other than that, what’s the worry. But now it turns out that the problem may be far more troublesome than at first realised, because it turns out that the same technology (designed for mass transit) is being used by the Dutch government to secure access to important facilities:

…the Dutch Interior Ministry‘s spokesman said this is “a national security issue,” since several government agencies there use the same technology to restrict access to their facilities.

It looks as if the researchers behind the MiFare crack have done Dutch citizens a big favour by alerting them to the inappropriate use of technology — MiFare Classic was designed for mass transit, not for identity cards and access control for sensitive facilities — before some bad guys do.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Lighthearted? You can judge!

[Dave Birch] Digital Money denizens will undoubtedly have been following the evolving MiFare security story (basically, researchers discovered the secret algorithm used in MiFare Classic products — in quite a clever way, it has to be said) with great interest. The details are not relevant to this post, but you’ll recall that the essence of the story is that some researchers reverse-engineered a MiFare chip to discover the hiterto secret algorithm used to protect chip contents and discovered a weakness that enabled them to obtain keys. NXP were not terribly happy about this, as you might imagine. This problem is potentially serious, because millions of MiFare chips are used for applications ranging from public transport tickets to corporate access control. There is no arguing with their findings, and the inevitable consequence is that the MiFare Classic implementations will need to be replaced with the new MiFare Plus chips when they reach commercial shipment volumes next year sometime. MiFare Plus differs from MiFare Classic in that it uses standard AES encryption: The algorithm is public, and the security of the system relies on keeping the keys secret, which is the preferred way of handling transaction security nowdays. Anyway, last week we heard that

Chipmaker NXP, formerly Philips Semiconductors, is taking Dutch Radboud University to court on Thursday to prevent researchers publishing their controversial report on the Mifare Classic chip.

[From NXP sues to silence Oyster researchers | The Register]

We don’t yet know what the outcome of this was, and I have no idea of the legal rights and wrongs, but I did notice this response this morning:

Dutch semiconductor manufacturer NXP is making a mistake suing Radboud University Nijmegen in the Netherlands, says Karsten Nohl, a University of Virginia graduate student who worked with others to break the MIFARE cryptographic algorithm.

[From Nohl: NXP making ‘terrible decision’ : Contactless News]

I’m very interested in Karsten’s opinions, especially because we’re going to be having a little chat in Vienna at the end of September at Mobile Banking Security. As the brochure says,

In this interview style session, chairman David Birch, Consult Hyperion, will lead a more light-hearted and informal discussion with Karsten Nohl, University of Virginia, about his research team’s experiences of cracking the security of the MiFare chip.

I’m not sure either NXP or Karsten will be especially light-hearted if they are still in court, but I’ll do my best to help.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

BarCampBank “near money”

[Dave Birch] James Gardner is absolutely correct that the lack of a set agenda is the power of the BarCamp format. I wasn’t really intending to talk about alternative, complementary or community currencies when I went along last week — I was really thinking more about mobile, to be honest — but when I saw a sticker on the wall, I couldn’t resist and I got to take part in an excellent round (well, oval) table discussion about “near money” (ie, things that aren’t really money but can be used as money). The reason that I’m interested in this is because I’m working on some big picture stuff about the long-term impact of technological change on money, and it seems that one of the key trends that needs to be considered in the analysis is the tendency of the technological change to convert stores of value into means of exchange, thus “monetising” assets. The extent of the shifts are very significant in the history of the financial sector: Consider that before the introduction of the cash management account (CMA), something like two-thirds of Americans’ savings were in demand deposit accounts, whereas afterwards something like two-thirds were not. Following Nick Szabo’s thinking about commodity derivatives, I was musing whether technology push or business pull would dominate an evolutionary period. On the one hand, the technology means that we can trade new instruments, but on the other hand someone needs to invent the new instruments to trade.

But suppose the next evolutionary period is different, in that the technology has decentralised invention to the point where rapid experimentation can take place “at the edge” as the OpenTech crowd would say, not business pull as in the past but business experiment on a large scale. Well, it may be that the next near-money to shift from store of value to medium exchange might already be being traded in some small community somewhere, just waiting for the dynamics of networks to take their course. So what is it? Linden Dollars or Pieces of Telefonica Eight, Microsoft Moolah or Google Groats? To cross the chasm into the mainstream, the near-money would need to be something that it is easy for people to understand and easy for them to visualise holding and using: My candidate is access to telecommunications services (mobile minutes or broadband megabytes or similar). What’s yours?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

John Letizia, BBA

[Dave Birch] John Letizia is the Director of Government Affairs and Special Assistant to the Chief Executive at the British Bankers Association (BBA). He joined the BBA in July 2005. He is responsible for building strong relations with key people at all levels across UK Government, Parliament and other key stakeholders, and to build and maintain a pro-active representation programme. Prior to joining the BBA, John was Political and Regional Affairs Adviser at a leading manufacturing employers’ organisation. John has also worked for a number of consultancies and has been an Adviser to a Government Minister. In this podcast, John reflects on the BBA’s views of the proposed UK national identity card. Since banks are seen as being key users of such a scheme, these views are important.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Contactless trajectory

[Dave Birch] It looks as if the roll-out of contactless payment cards is not going as well as the industry had hoped. Our good friends at CPP commissioned a survey and found out that

two thirds (77 percent) of respondents are worried about card fraud, as no PIN is required for contactless purchases below £10. Other concerns include a fear of increased crime levels (48 percent) and of criminals hacking into personal details (34 percent).

[From ePaynews.com - the payment news and resource Center]

So people are scared of using contactless cards because of fraud, retailers are surcharging to cut down use and terminals are not good enough. What with one thing and another, it’s a surprise to discover that there are any contactless retail transactions in London at all. Is it therefore reasonable for James van Dyke to say that

I’m coming around on contactless.

[From Javelin Strategy and Research » Coming Around on Contactless]

I’m genuinely wondering. But is this the usual post-hype dip or has contactless just taken too long to move into the marketplace? I’ve heard more and more people — on the issuing side — talk about skipping over contactless cards completely and just moving directly to phones of one form or another, either NFC phones or phones with NFC stickers on them. The argument is, essentially, that it’s hard to deliver enough added-value to compete with the cash just using a card whereas a phone can be a platform for more services for the both the payments and retail sectors.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.