Why virtual identities are real to some of us

[Dave Birch] The real world is a horrible place, especially near where I live. No wonder that I prefer to sojourn in cyberspace. Is this because I am a geek, an outlier? No, it’s because I’m normal.

There’s a fairly strong argument that internet is, in fact, much, much better than the entire “real world”. It’s just easier being a human being there — not surprisingly, given that human beings invented it for human beings to be in; unlike the world, which we did not and are, let’s face it, still busking our way through.

[From Goodbye cruel world, I’m moving to the internet | Caitlin Moran - Times Online]

A few years ago, I wrote a couple of pieces that touched on this theme, including an article on “Opening a Branch in Narnia” for Financial World magazine after Alex Krotoski, Richard Bartle and I ran a seminar on virtual worlds for the CSFI. In this I noted that

One could imagine a flight to virtual communities, where mathematics (in the form of cryptography) provides a defence against crime and disorder that the metal barriers of a gated community cannot. If the community decides on a new law—no swearing in public places, let’s say—then they can enforce it instantly and 100% effectively by downloading a software update. If there are members of the community who don’t like it, they can go to another community instead.

[From Opening a Branch in Narnia An edited version of this article appeared in Financial World magazine, July 2006.]

Building on the Lessig-amplified “code is law” meme, I pointed out that whatever (in that case) Tony Blair might want for the country, he couldn’t just change a couple of parameters and reboot. The real world doesn’t work like that.

But the virtual one does.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

We’re on, what, 3.1?

[Dave Birch] if you have a few minutes to spare, you might enjoy this YouTube video of Douglas Rushkoff talking in New York in November 2009. He says that the "operating system for money is obsolete" and gives a rabble-rousing (I mean this in the best possible way) call for monetary revolution to which I am not at all unsympathetic. He says that money is broken and that we need a more local, more distributed future. I won't spoil it for you, nor will I mention that I regard some of the monetary history as a little vague. Douglas' theory that current monetary arrangements date from the renaissance when local currencies were eradicated in favour of the "King's currency" by which the rulers obtained indirect tax revenues through seigniorage might be disputed by monetary historians — King Alfred had a working system of mints up and running in the ninth century, and our very own Guildford had a mint by 975). In fact, when Alfred re-founded London in 886, it was the home of one of about 30 mints in England and by the time of Ethlered II (978-1016) there were more than 70 mints in towns across England, all minting silver pennies, the only English coin of the time. But that's nit-picking. The spirit of Mr. Rushkoff's complaint is surely correct. Just as the transition to an agricultural society saw the invention of coins for circulation instead of bullion and the transition to an industrial age saw the invention of central banking and credit money, so the transition to an information age will surely result in the invention of some new and novel monetary arrangement, whether Edward de Bono's "IBM Dollar" (in David Boyle's splendid "The Money Changers") or anything else.

I've been reading "trendspotter" Marian Salzman again, and she says that hyperlocalisation is a marketing buzzword for 2010 as people organise themselves into communities — I don't think she means only in the geographic sense: my son's guild in World of Warcraft is as real to him as a community as the soccer team he plays in — and I wonder if this is at least a pointer towards the shape of the next monetary system?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

2 + 2 = X

[Dave Birch] I went to an enjoyable dinner (under Chatham House Rule) organised by DEMOS (a think tank that published a paper on privacy called "Putting People First" a couple of years ago) to discuss some issues around identity and privacy, particularly in the context of social networking. A couple of people raised that point that more privacy is, by itself, not necessarily a social benefit or a individual benefit. The "Privacy Taliban" should recognise economic activity as a social good, essentially.

It’s a controversial topic, but important, since hasty legislation could have dire consequences for the survival of newspapers.

[From The Spectator]

Indeed, and I was keen to press the point about helping content industries to reshape rather than preserve their business models a point of which there seemed to be fairly wide agreement. One area where there wasn't, and where my opinions were regarded as odd, was choice. I said that it was obvious to me that giving people choices about how much information they disclosed online (and to whom) was a practical way forward.

It turns out that the people who most benefit from the ability to set their own software preferences are well educated I.T.-saavy professionals with money — the people who suffer are the poorer and less educated users. So making privacy an individual option basically takes privacy away from the poor.

[From multicast » Blog Archive » On Facebook, Only the Rich Have Privacy]

This is surely correct. Now, I accept that the coming generation see privacy in a different way, and may have different norms, but we don't let them have a choice about whether to wear seatbelts or build houses that aren't to code, even though we acknowledge their perspectives.

Digital immigrants tend to think about privacy as the ability to conceal information from others. Digital natives instead share information within certain contexts, and with granular privacy controls on that information.

[From Is Online Privacy a Generational Issue? | GeekDad | Wired.com]

One topic that was raised was that the trawling of social networks by machines can take facts that are by themselves not particularly sensitive and match them together to obtain information that is sensitive. This is a topic discussed here before, and I don't want to rehash it, but it is interesting to delve into the commercial side of this. I think, because I'm optimistic about technology, that it ought to be possible for the "system" to mine data about me and offer me useful and relevant commercial relationships without knowing who I am. And I don't mean just knocking the name off.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Will the Tories abolish cash?

[Dave Birch] Britain's Tory party has said that a future conservative government may replace the "Pay As Your Earn" (PAYE) income tax collection system — whereby employers deduct tax at source and send it to the government — with some intrusive spy system that banks have to implement so that they will deduct the tax from your salary as it is paid into the your account. I'm not commenting on whether this is a good idea or not, but I am interested in it because it can only work if it becomes illegal to pay people in cash.

The Conservatives are working on a pilot for a new automated bank-based system that would remove the responsibility of deducting and paying income tax from employers. The new system could save businesses up to £5.5bn according to the Tories and increase revenues to the Exchequer of £1bn., according to the Tories election hopefuls.

[From Tories plan biggest shake up of income tax system since Second World War - Telegraph]

I couldn't find any details of how this would actually work — I suppose that HMRC would just deduct 50% of all payments into your bank account and then refund you at the end of the year — so I couldn't form an opinion as to whether it is more or less likely to work than the current system.

HMRC spends about £740m a year in IT. The [Capgemini] contract is one of the biggest outsourcing deals, worth £2.6 bn when was first signed in 2004 and now with the new arrangement extended until 2017 reach a life-time value of £8.5bn.

[From HMRC saving costs with IT Shakedown of Outsourced Systems : OrangeGenie]

A much better policy would be to abolish income tax completely, but that's a different point. What if the Tory party really did decide to reduce the use of cash?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

B. Off (old Fawlty Towers reference)

[Dave Birch] I’m against the idea of the Post Office-based “People’s Bank”, although I understand why many people who haven’t really thought about it find it so attractive: there’s an anti-bank backlash, and people are looking for a sort-of-vague communitarian reinvention. After all, there is a serious problem that needs to be solved, and the Post Office might be a way to solve it.

Almost a million of the UK’s poorest people could be lifted out of financial exclusion if a new, simple-to-use bank account is launched by the Post Office. So says Consumer Focus, the statutory body that represents consumers’ interests in post office services.   The Government has already outlined plans [to] offer current accounts; children’s savings accounts; business accounts; mortgages and weekly budgeting accounts.

[From Post Office Bank a remedy for financial exclusion]

What a wasted opportunity. Instead of creating a new kind of financial institution, exploiting the new European regulations introduced under SEPA (such as the PSD, which came into force in the UK in November 2009), we in Britain can’t help but formulate a ground-breaking, innovative approach to build something exactly the same as it would have been a century ago. I know we are a conservative bunch, but really! Are we just going to watch from sidelines and wave politely as the 21st century sails on past us?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Travel advisory

[Dave Birch] When we think about electronic identity, we tend to think in terms of the identity structures that we are familiar with from the physical world, so we talk about passports and borders. But the current system of passports, visas and border controls doesn’t work terribly well — see the discussions ad infinitum about the recent Dubai death squad’s comedy disguises and simple faked passports — so I’m not sure it’s much of a basis for exploration. Why do I say this? Well, because I’ve been to a few presentations about the various systems involved recently and have been trying to understand some of the dynamics to help our customers develop some longer-term strategies around identity.

One of the problems is that there is so much going on. Start with moving on from SIS. The SIS2 (Schengen Information System 2) will store biometrics to prevent visa fraud. After a three year transitional period, SIS2 must check with the new Visa Information System (VIS). VIS will require fingerprints and these will be matched via AFIS (so that if, say, a Moroccan person applies for visas in both French and German consulates then this will be known). The fingerprints are currently kept for five years. The Central VIS will connect via a new secure network (S-TESTA) to the national VIS systems and these national systems are connected in turn to the national consulates overseas. Are you with me so far?

What’s the point? Well, it’s so that when a non-EU person applies for a visa in Schengen country, the details will be passed up to the central system and then they will be checked when the passport is presented at Schengen border control. The purpose of all this is to defeat a common immigration fraud, which is that a bona-fide Chinese businessman (say) gets a visa to come to a Schengen country, and gives it to someone else. That person enters Schengen and then sends the passport and visa back to China by DHL. The next Chinese person enters Schengen, and then posts it back again… Will SIS2 fix this? Surely the problem will shift to the feeder documents. It’s impossible to imagine that an EU consulate somewhere can accurately verify and validate passports from 196 countries, but let’s put that to one side for a moment. There are plenty of people who think that SIS will end up causing more problems than it is solving.

The number of computers with access to the Schengen Information System has doubled to 500,000 thanks to the extension of the EU.

[From Half a million PCs can access Schengen's 'secure' database • The Register]

Since half a million PCs around Europe can access the system, that means that to all intents and purposes everything on the system is public.

Statewatch, a group that monitors civil liberties in Europe, said it was aware of a case in Belgium where personal information extracted from the system by an official was sold to an organised criminal gang.

[From 500,000 EU computers can access private British data | Technology | The Observer]

There’s another system coming online as well, the Euro Border Surveillance System, or Eurosur. This aims to reduce illegal migrants entering EU by sea, particularly aimed at Mediterranean). Good luck on that one. Spain has had some positive results from using satellite tracking (positive in the sense that the immigrants go to Italy instead) but I’m sure Eurosur will help further.

Then there’s the new e-passport. As has been discussed many times before, the current e-passport is a complement to the physical passport: that’s why it’s a chip inside the passport, not a chip instead of a passport. Almost everywhere you go in the world, the chip is not used, but in the future it may be. There’s security, naturally. The e-passports have Basic Access Control (BAC), which we’ve also discussed before. BAC locks the passport so that you have to physically read the passport MRZ in order to read the data from the chip (this is not strictly true, by the way, because the MRZ data isn’t random, but that’s a detail). Extended Access Control (EAC) is the next step: for one thing, it stops people from cloning the chips. But it adds additional functionality as well so, from 28th June 2009, member states have been required to issue EAC e-passports only.

Back to the difference between the chip and the book. If the e-passport is going to store data that isn’t on the passport (eg, your fingerprints) then these must be encrypted so that they can only be read by authorised authorities. An EAC passport will therefore only give up data to readers that it can authorise through the use of asymmetric cryptography (the reader must present a certificate signed by a recognised authority) and the passport can then encrypt and sign its own data. There’s something called Active Authentication as well, so the e-passport contains a key pair: the secret private key and the not secret public key (which appears in Data Group 14, DG14, in the data).

Unfortunately, shifting to EAC adds complexity because there are now two trust chains: the data trust chain (so that the readers can verify the passport data) and the terminal trust chain (so that the passport can verify the reader data). You can imagine that co-ordinating both of these chains across the globe has turned out to be something of a problem: every reader has to have every valid certificate from every country in it. The Brussels Interoperability Group (BIG) is responsible for harmonising the e-passport specification throughout the EU and has also been responsible for the certificate policies, protection profiles, conformance tests and interoperability tests. At ID World, Bob Carter from IPS said that the most difficult job was trying to work out how to exchange certificates between countries and he is, of course, right. One thing that is not yet in place is the protection profile from readers (a lesson from chip and PIN deployment in the UK: there’s no point having secure chips and wholly insecure readers).

It would be nice to be able to set a date when we might move to a wholly e-passport world, but to get there we have to get rid of visa stickers. There’s a name for this too: ESTA (Electronic System for Travel Authorisation). If this could be achieved, then there is no need to have manned border control, since introducing people into the loop could not improve the system in any way. This is a very appealing prospect to governments, but I think there is a real concern here: if a criminal is able to get a legitimate visa certificates, smart card, e-stamp or whatever else and is never questioned by a human security official, then once they are inside the perimeter they can operate with impunity.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.