Business and identity cards

[Dave Birch] We've decided to run a number of events linking the Digital Identity Forum to sister organisations with shared interests. The first of these will be joint seminar with EEMA at the British Computer Society in London on January 29th next year. This seminar, sponsored by Consult Hyperion, will be looking at the business opportunities that might arise from the introduction of the UK national identity card. You can register for the seminar at the EEMA web site. IPS will be presenting and we're hoping that all of their prime contractors will join an expert panel to share ideas on how British businesses can create new value around the scheme. We'll have an in-depth case study from Belgium to examine the business ecosystem that has grown up around the smart identity card introduced there. Look forward to seeing you there.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Drastic for plastic

[Dave Birch] At the recent Digital Money Summit in London, Tomi Ahonen noted that more people on Earth send text messages that use the Internet and that there are 3.4 billion mobile phones in use worldwide (of which three billion are unique subscribers). To illustrate the critical role of mobile phones in the future of payments, he used the example of South Korea to light up the trajectory of payment cards. There, half of the population already use mobile payments of one form or another

Incidentally, he also mentioned that 43% of the population there have a Cyworld account. I’ve written about Cyworld and it’s Acorn currency before, but this reinforced the view that we should not see virtual worlds such as Cyworld as games. They are not games — from the payments perspective — they are transaction spaces. Cyworld, by the way, is now the world’s second biggest music store after iTunes.

In South Korea, gift cards for the virtual currency used in Cyworld, known as dotori (“acorns”), are sold in more than 10,000 retail outlets as well as online and via mobile phones. Players use the currency to buy avatars and media to decorate their virtual space. Since one dotori costs approximately 10 cents, this market is obviously limited. Indeed, it amounts to only about $200,000. Per day.

[From Dave Birch: | Technology | The Guardian]

Tomi’s main point, though, and a point that has stuck with me since, is that we (ie, payments people) should not be taking existing instruments such as credit cards and simulating them on mobile phones, we should be creating “something that is magic” because great mobile services — whether Shazam, one of my favourites, or the cameraphones that convert English text to Japanese — look like magic to the consumer. Yes! Another manifesto commitment for digital money!

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Gambling on ID security

[Dave Birch] It’s been a landmark week for those of us fascinated by the UK’s national identity card scheme. The first cards have now actually been issued, so even as we speak identity fraud in the UK will be going… up. Why? Well, the government has met its own artificial target for the issuing of cards, but as you may have observed when you try to use one of the other smart cards in your possession (eg, your debit card), the cards are not the system.

Britain’s first ID cards cannot be read by any official body because the government has not issued a single scanner. Ministers promised to roll out hundreds of electronic readers of biometric details. However, a spokesman for the Home Office admitted last week that no employers, police forces, hospitals or colleges have been given the machine – and there are as yet no plans to issue them.

[From No scanners to read ID cards | Politics | The Observer]

So, in other words, as long as you can make something that looks like a plausible ID card, no problem. If you want to make it plausible, you need to go to the IPS web site to find out what physical features might be required to pass manual inspection. This will direct you to a helpful section on the UK Border Agency web site that describes those features in detail. it also explains how to verify a card that is presented to you…

Sponsors are expected to look at the card carefully. It will show the person’s entitlement to work, study or access public funds. The Guidance on identity cards for foreign nationals shows how you can check a card to ensure it is valid. This will help you to become familiar with its design and recognise the card when you are shown one. It also gives information on the card’s security features, to help you make your checks.

Although you are not legally required to check documents, we recommend that you do so for everyone you wish to employ.

[From UK Border Agency | Checking identity cards for foreign nationals]

The accompanying Guidance explains what a valid card should look like, but also includes some additional helpful steps for employers. These include

Physical checks can also be performed on the card. As it is made entirely from polycarbonate, it will have a distinctive sound when flicked, and the holder’s image will always be in grey-scale. The card should not be bent or folded, as this is likely to cause it to break. Contact with water should be avoided to prevent damage to the contact chip.

[From UK Border Agency | Checking identity cards for foreign nationals]

As far as I can see, life just got easier for illegal workers, since all they now have to do is to produce a valid-looking card and they are sorted. If you think that this is a hypothetical problem because no-one in the UK actually accepts these cards as proof of anything, think again.

UK casino operators can accept the Government’s new compulsory identity cards for foreign nationals as proof of ID – provided they meet money laundering regulation requirements, according to the Gambling Commission.

[From Identity Cards Now Welcome At UK Casinos | GamblingCompliance.com]

I’m sure the chance of an illegal immigrant using a forged card to launder money in a casino is so small as to be infestiminal, but nevertheless it does seem slightly odd to not even have plans to issue readers.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

It was great until the users showed up

[Dave Birch] An example that I’ve used before to explore what can go wrong with identity management system is the smart card-based “strong” authentication system that has been delivered as part of the National Health Service (NHS) £20 billion Connecting for Health (CfH) scheme.

The poll of more than 300 GPs found that one in six family doctors said they were aware of NHS staff sharing smartcards in their area, and one in 20 GPs admitted they sharing their own smartcard. Reasons given included the time taken to log-on to systems or to access data at multiple terminals, and losing cards or leaving them at home.

[From E-Health Insider Primary Care :: CfH condemns smartcard sharing]

Now, obviously the $20 billion and-still-rising Connecting for Health scheme is hardly representative of the average project with identity management requirements, but it does illustrate what happens when the management consultant-driven top-down politically-architected grand project meets the real world: in the end, something always gives.

A spokesperson for NHS Conecting for Health said the sharing of smarcards was unacecceptable and a serious discplinary offence.

[From E-Health Insider Primary Care :: CfH condemns smartcard sharing]

Whatever.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Good vs. bad

[Dave Birch] A thought experiment. Suppose you found a flaw in a widely-used payment scheme, such as EMV. Suppose the flaw had come about because of a mistaken interpretation of a specification and would take some time to fix. Would you keep the flaw secret, and hope that the criminals didn’t find it, or would you tell the banks, or would you tell the banks about the flaw and tell them that the flaw will be made public in six months. I’m genuinely curious: what would you do? I’m sure that the first option is the most wrong: not exploring how to break a payment scheme means that the criminals will break it and you won’t know what to do. Consider the recent example of SIM card cloning in India, which the police apparently had difficulty responding to:

The experts said no one has actually done any research on SIM card cloning because the activity is illegal in the country.

If the good guys can’t even participate, the bad guys will always win.

[From Schneier on Security: The Ill Effects of Banning Security Research]

Bruce is, as is generally the case, right. Banning research means that only the bad guys will do the research. Hoping that the bad guys won’t find the flaw is a ridiculous strategy: it’s much better to come clean, bite the bullet and then fix it. What does “fix” mean though?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.