The nuclear options

Nuclear power is scary, because of the fear of radiation (radiation itself� doesn’t seem to be as bad for you as you might think) escaping and contaminating all around. But is it as scary as banking? There was an absolutely fascinating piece by Tim Harford in the Financial Times last weekend. It was called “What a nuclear reactor can teach us about the economy”, and it draws parallels between the way engineers build safety systems for nuclear reactors (broadly speaking, by applying science and learning from mistakes) and the way that regulators build safety systems for the banking system (broadly speaking, by making things up and not learning from mistakes). The key observation is that the banking system is complex:

It might seem obvious that the way to make a complex system safer is to install some safety measures. Engineers have long known that life is not so simple.

[From� What a nuclear reactor can teach us about the economy]

What Tim is saying is that financial products such as Collateralised Debt Obligations (CDOs) and Credit Default Swaps (CDSs) appeared as safety systems (for spreading risk) and then, just like the coolant filter that got dislodged and jammed the coolant flow thus causing a partial meltdown of the Fermi reactor in Detroit, they blew up the system they were supposed to stabilise.

So what can the financial sector learn from the nuclear reactor sector, given this analogy? Well, using the example of Three Mile Island, Tim explains that one of the key reasons that the reactor came close to meltdown was that the operators couldn’t understand all of the dials, lights, warnings and other signals. As a consequence

since Three Mile Island, much attention has been lavished on the problem of telling the operators what they need to know in a format they can understand.

When the financial system started to melt down, regulators were faced with the same problem: given all of the warning lights flashing, given all of the alarms sounding, what was actually going on?

Andrew Haldane, director for financial stability at the Bank of England… argues that the same technologies now used to check the health of an electricity grid could be applied to a financial net- work map, highlighting critical connections, over-stressed nodes and unexpected interactions.

This analogy is imperfect in a couple of ways, of course, because banks can create money from nothing whereas electricity costs money to create and because electricity substations don’t lie to the national grid in order to get a bigger bonus, but you can see his point.

There’s one aspect of this that Tim didn’t explain though. Engineers don’t forget things, but financiers do. Once engineers have learned, for example, how not to build a bridge, then they stop building bad bridges. But bankers don’t work that way. They would stop building bridges that way for a short time, and then simply go back round and starting building collapsing bridges again a few years later.

What does this have to do with payment systems? I’d like to highlight two points: complexity and decoupling. We need to beware of complexity, to treat it as an enemy (the current� case study of EMV illustrates this perfectly), and we need to decouple so that parts of complex systems can fail without bringing down to whole of the system. It seems to me that this prescription provides a pretty clear manifesto for payments: separate the payments systems from the banking system and have a lots of simple payment systems instead of a small number of complicated ones.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Real-time serendipity

Naturally, given my obsessions, I was struck by a subset of the� Real-Time Club discussions about identities on the web at their evening with� Aleks Krotoski. In particular, I was struck by the discussion about multiple identities on the web, because it connects with some work we (Consult Hyperion) have been doing for the European Commission. One point that was common to a number of the discussions was the extent to which identity is needed for, or integral to, online transactions. Generally speaking, I think many people mistake the need for some knowledge about a counterparty with the need to know who they are, a misunderstanding that actually makes identity fraud worse because it leads to identities being shared more widely than they need be. There was a thread to the discussion about children using the web, as there always is in such discussions, and this led me to conclude that proving that you are over (or under) 18 online might well be the acid test of a useful identity infrastructure: if your kids can’t easily figure out a way to get round it, then it will be good enough for e-government, e-business and the like.

I think the conversation might have explored more about privacy vs. anonymity, because many transactions require the former but not the latter. But then there should be privacy rather than anonymity for a lot of things, and there should be anonymity for some things (even if this means friction in a free society, as demonstrated by the Wikileaks storm). I can see that this debate is going to be difficult to organise in the public space, simply because people don’t think about those topics in a rich enough way: they think common sense is a useful guide which, when it comes to online identity, it isn’t.

On a different subject, a key element of the evening’s discussion was whether the use of social media, and the directions of social media technology, lead to more or less serendipity. (Incidentally, did you know that the word “serendipity” was invented by Horace Walpole in 1754?) Any discussion about social media naturally revolves around Facebook.

Facebook is better understood, not as a country, but as a refugee camp for people who feel today’s lack of identity-forging social experience.

[From� Facebook: the heart in a heartless world | spiked]

I don’t agree, but I can see the perspective. But I don’t see my kids fleeing into Facebook, I see them using Facebook to multiply and enrich their interpersonal interactions. Do they meet new people on Facebook? Yes, they do. Is that true for all kids, of all educational abilities, of all socio-economic classes, I don’t know (and I didn’t find out during the evening, because everyone who was discussing the issue seemed to have children at expensive private schools, so they didn’t seem like a statistically-representative cross-section of the nation).

Personally, I would come down on the side of serendipity. Because of social media I know more people than I did before, but I’ve also physically met more people than I knew before: social media means that I am connected with people who a geographically and socially more dispersed. I suppose you might argue that its left me less connected with the people who live across the street from me, but then I don’t have very much in common with them.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The nuclear options

Nuclear power is scary, because of the fear of radiation (radiation itself doesn’t seem to be as bad for you as you might think) escaping and contaminating all around. But is it as scary as banking? There was an absolutely fascinating piece by Tim Harford in the Financial Times last weekend. It was called “What a nuclear reactor can teach us about the economy“, and it draws parallels between the way engineers build safety systems for nuclear reactors (broadly speaking, by applying science and learning from mistakes) and the way that regulators build safety systems for the banking system (broadly speaking, by making things up and not learning from mistakes). The key observation is that the banking system is complex:

It might seem obvious that the way to make a complex system safer is to install some safety measures. Engineers have long known that life is not so simple.

[From What a nuclear reactor can teach us about the economy]

What Tim is saying is that financial products such as Collateralised Debt Obligations (CDOs) and Credit Default Swaps (CDSs) appeared as safety systems (for spreading risk) and then, just like the coolant filter that got dislodged and jammed the coolant flow thus causing a partial meltdown of the Fermi reactor in Detroit, they blew up the system they were supposed to stabilise.

So what can the financial sector learn from the nuclear reactor sector, given this analogy? Well, using the example of Three Mile Island, Tim explains that one of the key reasons that the reactor came close to meltdown was that the operators couldn’t understand all of the dials, lights, warnings and other signals. As a consequence

since Three Mile Island, much attention has been lavished on the problem of telling the operators what they need to know in a format they can understand.

When the financial system started to melt down, regulators were faced with the same problem: given all of the warning lights flashing, given all of the alarms sounding, what was actually going on?

Andrew Haldane, director for financial stability at the Bank of England… argues that the same technologies now used to check the health of an electricity grid could be applied to a financial net- work map, highlighting critical connections, over-stressed nodes and unexpected interactions.

This analogy is imperfect in a couple of ways, of course, because banks can create money from nothing whereas electricity costs money to create and because electricity substations don’t lie to the national grid in order to get a bigger bonus, but you can see his point.

There’s one aspect of this that Tim didn’t explain though. Engineers don’t forget things, but financiers do. Once engineers have learned, for example, how not to build a bridge, then they stop building bad bridges. But bankers don’t work that way. They would stop building bridges that way for a short time, and then simply go back round and starting building collapsing bridges again a few years later.

What does this have to do with payment systems? I’d like to highlight two points: complexity and decoupling. We need to beware of complexity, to treat it as an enemy (the current case study of EMV illustrates this perfectly), and we need to decouple so that parts of complex systems can fail without bringing down to whole of the system. It seems to me that this prescription provides a pretty clear manifesto for payments: separate the payments systems from the banking system and have a lots of simple payment systems instead of a small number of complicated ones.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Real-time identity

Naturally, given my obsessions, I was struck by a subset of the Real-Time Club discussions about identities on the web at their evening with Aleks Krotoski. In particular, I was struck by the discussion about multiple identities on the web, because it connects with some work we (Consult Hyperion) have been doing for the European Commission. One point that was common to a number of the discussions was the extent to which identity is needed for, or integral to, online transactions. Generally speaking, I think many people mistake the need for some knowledge about a counterparty with the need to know who they are, a misunderstanding that actually makes identity fraud worse because it leads to identities being shared more widely than they need be. There was a thread to the discussion about children using the web, as there always is in such discussions, and this led me to conclude that proving that you are over (or under) 18 online might well be the acid test of a useful identity infrastructure: if your kids can’t easily figure out a way to get round it, then it will be good enough for e-government, e-business and the like.

I think the conversation might have explored more about privacy vs. anonymity, because many transactions require the former but not the latter. But then there should be privacy rather than anonymity for a lot of things, and there should be anonymity for some things (even if this means friction in a free society, as demonstrated by the Wikileaks storm). I can see that this debate is going to be difficult to organise in the public space, simply because people don’t think about those topics in a rich enough way: they think common sense is a useful guide which, when it comes to online identity, it isn’t.

On a different subject, a key element of the evening’s discussion was whether the use of social media, and the directions of social media technology, lead to more or less serendipity. (Incidentally, did you know that the word “serendipity” was invented by Horace Walpole in 1754?) Any discussion about social media naturally revolves around Facebook.

Facebook is better understood, not as a country, but as a refugee camp for people who feel today’s lack of identity-forging social experience.

[From Facebook: the heart in a heartless world | spiked]

I don’t agree, but I can see the perspective. But I don’t see my kids fleeing into Facebook, I see them using Facebook to multiply and enrich their interpersonal interactions. Do they meet new people on Facebook? Yes, they do. Is that true for all kids, of all educational abilities, of all socio-economic classes, I don’t know (and I didn’t find out during the evening, because everyone who was discussing the issue seemed to have children at expensive private schools, so they didn’t seem like a statistically-representative cross-section of the nation).

Personally, I would come down on the side of serendipity. Because of social media I know more people than I did before, but I’ve also physically met more people than I knew before: social media means that I am connected with people who a geographically and socially more dispersed. I suppose you might argue that its left me less connected with the people who live across the street from me, but then I don’t have very much in common with them.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Smart banknote design competition

As one of the legions of fans of the brilliant BBC / British Museum radio series on “A History of the World in 100 Objects”, I was absolutely fascinated by the episode on 14th-century Chinese paper money: follow the link and have a look at the beautiful picture of the Chinese banknote from 1375.

The Chinese writing along the top of this note reads (from right to left): ‘Da Ming tong xing bao chao’ and translates as Great Ming Circulating Treasure Note’

[From� Chinese Ming bank note › The British Museum]

I love that name: Bank of England notes really should be inscribed “Circulating Lack of Treasure Note”. These notes had pictures of the “cash” (copper coins with holes in the middle, threaded on to a string) that they represented: ours should have a picture of… what? What do they represent?

Things have moved on a little since mulberry bark. Some of you may remember Paul Makin’s super presentation about “E-ink and smart banknotes” at the 13th Digital Money Forum in London back in March 2010. The presentation was based on some work that Consult Hyperion had been doing with the� Bill & Melinda Gates Foundation. Less than a year on, it’s fascinating to see how the smart banknote technologies have evolved. Display technology, in particular, is advancing apace.

Quantum dot light emitting diodes (QLEDs) are an advanced technology currently in development that will deliver the ultimate solution for displays and lighting applications… QLEDs are only a couple hundred nanometers thick making them virtually transparent and flexible, and highly suitable for integration onto plastic or metal foil substrates as well as other surfaces[From� QLED Technology]

Displays aren’t the only technology of interest here. I think we can focus down and think of a smart banknote as comprising four main technological components:

  • The note itself, made out of a plastic polymer rather than paper. This makes it durable and waterproof, important if it is to contain electronics. Some countries (eg,� Australia) have already switched from paper to plastic for their banknotes and others (eg,� Canada) are planning to follow. Plastic banknotes last much longer than paper ones, so the additional cost of production doesn’t stop them from being cost-effective.
  • The electronic ink display on the note. Electronic ink, as you’ll recall, only uses power when it is changing, so once the banknote display has been written then it will stay displaying the same thing until it changed.
  • The chip inside the banknote. Why do we need a chip inside the banknote? Well, we want the banknote to be secure: we don’t want it to be counterfeited or altered. And we need the banknote to be able to communicate intelligently with terminals.
  • The antenna connected to the chip. We want our smart banknote to work like an Oyster card, so that you only need to tap it to some form of terminal for it to work.

How would such a note be used? Well, imagine that you have a banknote that says “£10” on it. You to the coffee shop and spend £1.50 on a coffee. You tap the note on the till to pay, and the display now changes to say “£8.50”. When you get to work, your friend reminds you that you owe him £8 from the pub. You give him the note and he gives you a 50p coin in change. Your friend can absolutely trust that the value represented by the note is indeed £8.50 because the tamper-resistant chip and the cryptography it deploys make it impossible to counterfeit.

It’s hard to imagine the implications so a technology combination so radical in everyday use. Take just one aspect: the expense and complexity of engraving plates, adding holograms, printing fine detail and everything else that is needed to make notes hard to counterfeit

Modern banknotes contain up to 50 anti-counterfeiting features, but adding electronic circuits programmed to confirm the note’s authenticity is perhaps the ultimate deterrent, and would also help to simplify banknote tracking.

[From� Banknotes go electric to outwit counterfeiters - tech - 21 December 2010 - New Scientist]

A smart banknote needs none of these, because its security depends on cryptography and the chip tamper-resistance. The state-of-the-art here is already more than adequate for purpose. There are other differences too: since the smart banknote works using contactless communications, there’s no reason for it to be a rectangle. The best smart banknote might be a ball, or a strip or a disc.

What would a banknote look like without security printing, freed from the tyranny of form factor and with a display that changes? That’s an interesting question. Since it’s about technology, it’s easy for people like me to imagine how a smart banknote might work. It’s much harder to imagine what it might look like, and that’s why Consult Hyperion have a launched a competition for artists to design a smart banknote. It’s going to work like this: the competition will run for a month from 21st January 2011 to 21st February 2011. During that time, artists are invited to submit a picture, sketch, diagram, draft, model or any other means of communicating their vision to art (at) chyp.com for consideration. All of the entries will be displayed at the Digital Money Forum website.

The artist� Austin Holdsworth, who presented at the 12th Digital Money Forum in 2009, has been commissioned to review the entries and create a shortlist. The shortlisted candidates will be informed by 25th February 2011 and invited to come along to the Digital Money Forum on Thursday 3rd March to present their concept to our judging panel and you, the delegates. The panel will then select the winning entry and present them with a prize: in this case, an Apple iPad (although naturally the prestige associated with award outweighs the value of this base material prize).

As an aside, the Curator of Modern Money at the British Museum,� Catherine Eagleton, will be speaking at the 14th annual Digital Money Forum in London in March, so if you would like to ask anything about the money objects featured in the radio series, don’t miss the opportunity to come along and meet a genuine expert.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Smart art

As one of the legions of fans of the brilliant BBC / British Museum radio series on “A History of the World in 100 Objects“, I was absolutely fascinated by the episode on 14th-century Chinese paper money: follow the link and have a look at the beautiful picture of the Chinese banknote from 1375.

The Chinese writing along the top of this note reads (from right to left): ‘Da Ming tong xing bao chao’ and translates as Great Ming Circulating Treasure Note’

[From Chinese Ming bank note › The British Museum]

I love that name: Bank of England notes really should be inscribed “Circulating Lack of Treasure Note”. These notes had pictures of the “cash” (copper coins with holes in the middle, threaded on to a string) that they represented: ours should have a picture of… what? What do they represent?

Things have moved on a little since mulberry bark. Some of you may remember Paul Makin’s super presentation about “E-ink and smart banknotes” at the 13th Digital Money Forum in London back in March 2010. The presentation was based on some work that Consult Hyperion had been doing with the Bill & Melinda Gates Foundation. Less than a year on, it’s fascinating to see how the smart banknote technologies have evolved. Display technology, in particular, is advancing apace.

Quantum dot light emitting diodes (QLEDs) are an advanced technology currently in development that will deliver the ultimate solution for displays and lighting applications… QLEDs are only a couple hundred nanometers thick making them virtually transparent and flexible, and highly suitable for integration onto plastic or metal foil substrates as well as other surfaces[From QLED Technology]

Displays aren’t the only technology of interest here. I think we can focus down and think of a smart banknote as comprising four main technological components:

  • The note itself, made out of a plastic polymer rather than paper. This makes it durable and waterproof, important if it is to contain electronics. Some countries (eg, Australia) have already switched from paper to plastic for their banknotes and others (eg, Canada) are planning to follow. Plastic banknotes last much longer than paper ones, so the additional cost of production doesn’t stop them from being cost-effective.
  • The electronic ink display on the note. Electronic ink, as you’ll recall, only uses power when it is changing, so once the banknote display has been written then it will stay displaying the same thing until it changed.
  • The chip inside the banknote. Why do we need a chip inside the banknote? Well, we want the banknote to be secure: we don’t want it to be counterfeited or altered. And we need the banknote to be able to communicate intelligently with terminals.
  • The antenna connected to the chip. We want our smart banknote to work like an Oyster card, so that you only need to tap it to some form of terminal for it to work.

How would such a note be used? Well, imagine that you have a banknote that says “£10″ on it. You to the coffee shop and spend £1.50 on a coffee. You tap the note on the till to pay, and the display now changes to say “£8.50″. When you get to work, your friend reminds you that you owe him £8 from the pub. You give him the note and he gives you a 50p coin in change. Your friend can absolutely trust that the value represented by the note is indeed £8.50 because the tamper-resistant chip and the cryptography it deploys make it impossible to counterfeit.

It’s hard to imagine the implications so a technology combination so radical in everyday use. Take just one aspect: the expense and complexity of engraving plates, adding holograms, printing fine detail and everything else that is needed to make notes hard to counterfeit

Modern banknotes contain up to 50 anti-counterfeiting features, but adding electronic circuits programmed to confirm the note’s authenticity is perhaps the ultimate deterrent, and would also help to simplify banknote tracking.

[From Banknotes go electric to outwit counterfeiters - tech - 21 December 2010 - New Scientist]

A smart banknote needs none of these, because its security depends on cryptography and the chip tamper-resistance. The state-of-the-art here is already more than adequate for purpose. There are other differences too: since the smart banknote works using contactless communications, there’s no reason for it to be a rectangle. The best smart banknote might be a ball, or a strip or a disc.

What would a banknote look like without security printing, freed from the tyranny of form factor and with a display that changes? That’s an interesting question. Since it’s about technology, it’s easy for people like me to imagine how a smart banknote might work. It’s much harder to imagine what it might look like, and that’s why Consult Hyperion have a launched a competition for artists to design a smart banknote. It’s going to work like this: the competition will run for a month from 21st January 2011 to 21st February 2011. During that time, artists are invited to submit a picture, sketch, diagram, draft, model or any other means of communicating their vision to art (at) chyp.com for consideration. All of the entries will be displayed at the Digital Money Forum website.

The artist Austin Houldsworth, who presented at the 12th Digital Money Forum in 2009, has been commissioned to review the entries and create a shortlist. The shortlisted candidates will be informed by 25th February 2011 and invited to come along to the Digital Money Forum on Thursday 3rd March to present their concept to our judging panel and you, the delegates. The panel will then select the winning entry and present them with a prize: in this case, an Apple iPad (although naturally the prestige associated with award outweighs the value of this base material prize).

As an aside, the Curator of Modern Money at the British Museum, Catherine Eagleton, will be speaking at the 14th annual Digital Money Forum in London in March, so if you would like to ask anything about the money objects featured in the radio series, don’t miss the opportunity to come along and meet a genuine expert.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Why bother with the new $100 bill?

The US is soon to release a new $100 bill. But why? What do they do with $100 bills? They're not, as you might imagine, needed to support commerce and trade.

In 2001 the Federal Reserve estimated that 90 percent of the $100 bills ordered by the Federal Reserve (which accounts for the overwhelming majority of C-notes ordered nationwide) were paid out to foreign banks

[From Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? - By Timothy Noah - Slate Magazine]

Around two-thirds of all of the US dollars in "circulation" are not in the US at all and are unlikely to be repatriated. This represents a tremendous interest-free loan from the rest of the world to Uncle Sam. But is this income sufficient to outweigh the negative effects of cash?

So why do we keep printing $100 bills? As with any valuable export, we worry that if the C-note ceased to be available to foreign criminals and dictators, another paper currency would take its place. The leading candidate would be the 500 euro note,

[From Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? - By Timothy Noah - Slate Magazine]

Well, that's true, and the conspiracy theory that the European Central Bank (ECB) only had the 500 euro note printed in order to replace the $100 bill in the stashes of drug dealers and tax evaders is widely recirculated. But that's a reason to scrap 500 euro notes, not to print more $100 bills, especially when the $100 bills have to be completely re-designed anyway.

But the biggest upgrade is a blue "3D Security Ribbon"… The strip contains a series of images of bells and digits; tip the note, and the images come into 3D relief. "It only takes a few seconds to check the new $100 note and know it's real," says Larry R. Felix, Director of the Treasury's Bureau of Engraving and Printing.

[From US Treasury: New 100 dollar bill needs 3D tech - CSMonitor.com]

Sounds exciting. But why bother? Why not just forget about the $100 (and, for that matter, the $50 bill)? After all, high-denomination notes have been withdrawn before, and for much the same reason. We have to weigh up the overall impact on society and try to make the right decision, and sometimes that decision might mean a radical change.

In 1969, the Treasury stopped issuing $500, $1,000, $5,000 and $10,000 bills specifically to impede crime syndicates — the only entities that were still using such large bills after the introduction of electronic money transfers.

[From Turn In Your Bin Ladens - NYTimes.com]

And before I get deluged with e-mails calling me a New World Order stooge intent on introducing the Mark of the Beast across the USA, let me merely point out that if the public were to desire anonymity for payments (they don't, by the way) then it's possible to create anonymous electronic money: this is an implementation choice, not any sort of technological constraint. Of course, the fact that the US government stops producing high-denomination notes doesn't necessarily mean that they will disappear…

Malaysian police have arrested a Lebanese man allegedly carrying fake currency with a face value of $66 million after he tipped a hotel staff with a $500 note, an official said Friday.

The largest U.S. note currently in wide circulation is a $100 bill. But police found bundles of $1 million, $100,000 and $500 notes in the man's hotel room in Kuala Lumpur on Sunday, said Izany Abdul Ghany, head of the city's commercial crime unit.

[From $500 Tip Leads Police to $66 Million in Fake Bills - ABC News]

If only all counterfeiters were that good!

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Benjamin 3D

[Dave Birch] The US is soon to release a new $100 bill. But why? What do they do with $100 bills? They’re not, as you might imagine, needed to support commerce and trade.

In 2001 the Federal Reserve estimated that 90 percent of the $100 bills ordered by the Federal Reserve (which accounts for the overwhelming majority of C-notes ordered nationwide) were paid out to foreign banks

[From Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? - By Timothy Noah - Slate Magazine]

Around two-thirds of all of the US dollars in “circulation” are not in the US at all and are unlikely to be repatriated. This represents a tremendous interest-free loan from the rest of the world to Uncle Sam. But is this income sufficient to outweigh the negative effects of cash?

So why do we keep printing $100 bills? As with any valuable export, we worry that if the C-note ceased to be available to foreign criminals and dictators, another paper currency would take its place. The leading candidate would be the 500 euro note,

[From Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? - By Timothy Noah - Slate Magazine]

Well, that’s true, and the conspiracy theory that the European Central Bank (ECB) only had the 500 euro note printed in order to replace the $100 bill in the stashes of drug dealers and tax evaders is widely recirculated. But that’s a reason to scrap 500 euro notes, not to print more $100 bills, especially when the $100 bills have to be completely re-designed anyway.

But the biggest upgrade is a blue “3D Security Ribbon”… The strip contains a series of images of bells and digits; tip the note, and the images come into 3D relief. “It only takes a few seconds to check the new $100 note and know it’s real,” says Larry R. Felix, Director of the Treasury’s Bureau of Engraving and Printing.

[From US Treasury: New 100 dollar bill needs 3D tech - CSMonitor.com]

Sounds exciting. But why bother? Why not just forget about the $100 (and, for that matter, the $50 bill)? After all, high-denomination notes have been withdrawn before, and for much the same reason. We have to weigh up the overall impact on society and try to make the right decision, and sometimes that decision might mean a radical change.

In 1969, the Treasury stopped issuing $500, $1,000, $5,000 and $10,000 bills specifically to impede crime syndicates — the only entities that were still using such large bills after the introduction of electronic money transfers.

[From Turn In Your Bin Ladens - NYTimes.com]

And before I get deluged with e-mails calling me a New World Order stooge intent on introducing the Mark of the Beast across the USA, let me merely point out that if the public were to desire anonymity for payments (they don’t, by the way) then it’s possible to create anonymous electronic money: this is an implementation choice, not any sort of technological constraint. Of course, the fact that the US government stops producing high-denomination notes doesn’t necessarily mean that they will disappear…

Malaysian police have arrested a Lebanese man allegedly carrying fake currency with a face value of $66 million after he tipped a hotel staff with a $500 note, an official said Friday.

The largest U.S. note currently in wide circulation is a $100 bill. But police found bundles of $1 million, $100,000 and $500 notes in the man’s hotel room in Kuala Lumpur on Sunday, said Izany Abdul Ghany, head of the city’s commercial crime unit.

[From $500 Tip Leads Police to $66 Million in Fake Bills - ABC News]

If only all counterfeiters were that good!

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The US administration is creating a new sector of the economy: the identity business

Last year I said that I thought that the US National Strategy for Trusted Identities in Cyberspace (NSTIC) was heading in the right direction. I'm very much in favour of the private sector providing multiple identities into a framework that it used by the public sector and vice versa. I'm in favour of choice: if I choose to use my Barclays identity to access the DVLA or my DWP identity to access O2 it shouldn't matter to the effective and efficient use of online transactions. There was one area where I felt it could have presented a slightly different vision, and that's in the use of pseudonyms, which I think should be the norm rather than the exception.

People should consider it normal to get a virtual identity from their bank or their mobile phone operator in a pseudonymous name so that they can browse, transact and comment without revealing anything about themselves other than the facts relevant to a transaction.

[From Digital Identity: USTIC]

James Van Dyke, when discussing NSTIC (which seems have become known unofficially as "Obama's Internet Identity System") warned about

Apocalyptic fear-mongers. Yes I’m ending with the crazies here, but hear me out. The extreme cable networks and televangelists will surely jump on this as the digital incarnation of the Mark of either the Beast or “(gasp!) Obama liberals. Historians will recall that social security numbers were supposed to be an apocalyptic conspiracy.

[From Obama’s Internet Identity System: Could This Change Everything? - Javelin Strategy & Research Blog]

I don't think the danger is the crazies — although I feel a little sheepish writing this a couple of days after a crazy did, in fact, murder several people and seriously injure a congresswoman — but the journalists, politicians, commentators and observers who don't really understand the rather complex topic of digital identity. Or, as "Identity Woman" Kailya Hamlin (who some of you may remember from the first European Internet Identity Workshop that Consult Hyperion sponsored with our friends from Innopay and Mydex back in October) said about NSTIC:

I am optimistic about their efforts and frustrated by the lack of depth and insight displayed in the news cycle with headlines that focus on a few choice phrases to raise hackles about this initiative

[From National! Identity! Cyberspace!: Why we shouldn't freak out about NSTIC. | Fast Company]

She's bang on with this. Here's a couple of typical examples from the blogosphere:

CNET reported on January 7, 2011 that Obama has signed authority over to U.S. Commerce Department to create new privacy laws that require American citizens to hold an Internet ID card.

[From Internet Anonymity: Obama Pushes for an American Internet ID]

And

President Obama has signaled that he will give the United States Commerce Department the authority over a proposed national cybersecurity measure that would involve giving each American a unique online identity

[From Obama administration moves forward with unique internet ID for all Americans, Commerce Department to head system up -- Engadget]

As far as I can see, NSTIC being managed by the Commerce Department has nothing to do with "privacy laws" and the idea that it will require Americans to have an "Internet ID" is a journalistic invention. The actual situation is that NSTIC is to go from being an idea to an actual system:

The Obama administration plans to announce today plans for an Internet identity system that will limit fraud and streamline online transactions, leading to a surge in Web commerce, officials said. While the White House has spearheaded development of the framework for secure online identities, the system led by the U.S. Commerce Department will be voluntary and maintained by private companies,

[From Internet Identity System Said Readied by Obama Administration - BusinessWeek]

What this means is not that Americans will get an "Internet Driver's License" but that they will be able to log in to their bank, the Veteran's Administration, the DMV and their favourite blogs using a variety of IDs provided by their bank, their mobile phone operators and others.

[White House Cybersecurity Coordinator] Howard Schmidt stressed today that anonymity and pseudonymity will remain possible on the Internet. "I don't have to get a credential, if I don't want to," he said.

[From Obama to hand Commerce Dept. authority over cybersecurity ID | Privacy Inc. - CNET News]

As long as it's a matter of choice, I really don't see a problem with this. The idea of NSTIC is that it is the infrastructure that is standardised, and this is good. We need standards for credentials and such like so that I can use my Woking Council ID to log in central government services and my Barclays Bank ID so that I can log in to do my taxes online: but I might pay Barclays for an additional ID that has some key credentials (IS_A_PERSON, IS_OVER_18, IS_NOT_BANKRUPT, that sort of thing) but does not reveal my identity. This sort of Joe Bloggs (or, for our cousins over the water, John Doe) identity would be more than adequate for the vast majority of web browsing and if other people want to wander the highways and byways of the interweb with a Manchester United, Prince or BBC ID, then it's up to them. Let a thousand flowers bloom, as they say (well, as Chairman Mao said).

If the crazies want to be concerned about a single ID mark of the e-beast infocalypse, they're perfectly entitled to, but I don't understand why they are convinced it will come from the government in general or Obama in particular – there are half-a-billion people out there (including me) who have already handed over their personal information to a single unaccountable entity.

Facebook Login lets any website on the planet use its identity infrastructure—and underlying security safeguards. It's easy to implement Facebook Login, simply by adding few lines of code to a web server. Once that change is made, the site's users will see a "Connect with Facebook" button. If they're already logged into Facebook (having recently visited the site), they can just click on it and they're in. If they haven't logged in recently, they are prompted for their Facebook user name and password.

[From Facebook Wants to Supply Your Internet Driver's License - Technology Review]

Now, at the moment Facebook Connect just uses a password, so it's no more secure than banks or government agencies, but it could move to a 2FA implementation implementation in the future. Widespread 2FA access to online services really should have become a business for banks or mobile operators already (think how long Identrus has been around) but it just hasn't happened: I can't use my Barclays PINSentry to log on to Barclaycard, let alone the government or an insurance company. But suppose my Facebook login required access to my mobile phone so it was much more secure: you know the sort of thing, enter e-mail address, wait for code to arrive on mobile phone, enter code (a proper UICC-based digital signature solution would be much better, but that's another topic). Then I could use Facebook Connect for serious business. This would have an interesting side-effect: Facebook would know where I go on the web, which seems to me to be much more like the mark of the e-beast.

An interesting side benefit for website operators is that Facebook Login provides the site with users' real names (in most cases) and optionally a variety of other information, such as the users' "friends" and "likes."

[From Facebook Wants to Supply Your Internet Driver's License - Technology Review]

Which is, of course, why I don't use it. On the other hand, if Facebook decided to use cryptography to secure and protect this sort of information, they could at a stroke create a desirable internet passport: by "blinding" the passport to prevent service providers from tracking the identity across web sites Facebook could significantly improve both convenience and privacy for the average users.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Internet driver’s license?

Last year I said that I thought that the US National Strategy for Trusted Identities in Cyberspace (NSTIC) was heading in the right direction. I’m very much in favour of the private sector providing multiple identities into a framework that it used by the public sector and vice versa. I’m in favour of choice: if I choose to use my Barclays identity to access the DVLA or my DWP identity to access O2 it shouldn’t matter to the effective and efficient use of online transactions. There was one area where I felt it could have presented a slightly different vision, and that’s in the use of pseudonyms, which I think should be the norm rather than the exception.

People should consider it normal to get a virtual identity from their bank or their mobile phone operator in a pseudonymous name so that they can browse, transact and comment without revealing anything about themselves other than the facts relevant to a transaction.

[From Digital Identity: USTIC]

James Van Dyke, when discussing NSTIC (which seems have become known unofficially as “Obama’s Internet Identity System”) warned about

Apocalyptic fear-mongers. Yes I’m ending with the crazies here, but hear me out. The extreme cable networks and televangelists will surely jump on this as the digital incarnation of the Mark of either the Beast or “(gasp!) Obama liberals. Historians will recall that social security numbers were supposed to be an apocalyptic conspiracy.

[From Obama’s Internet Identity System: Could This Change Everything? - Javelin Strategy & Research Blog]

I don’t think the danger is the crazies — although I feel a little sheepish writing this a couple of days after a crazy did, in fact, murder several people and seriously injure a congresswoman — but the journalists, politicians, commentators and observers who don’t really understand the rather complex topic of digital identity. Or, as “Identity Woman” Kailya Hamlin (who some of you may remember from the first European Internet Identity Workshop that Consult Hyperion sponsored with our friends from Innopay and Mydex back in October) said about NSTIC:

I am optimistic about their efforts and frustrated by the lack of depth and insight displayed in the news cycle with headlines that focus on a few choice phrases to raise hackles about this initiative

[From National! Identity! Cyberspace!: Why we shouldn't freak out about NSTIC. | Fast Company]

She’s bang on with this. Here’s a couple of typical examples from the blogosphere:

CNET reported on January 7, 2011 that Obama has signed authority over to U.S. Commerce Department to create new privacy laws that require American citizens to hold an Internet ID card.

[From Internet Anonymity: Obama Pushes for an American Internet ID]

And

President Obama has signaled that he will give the United States Commerce Department the authority over a proposed national cybersecurity measure that would involve giving each American a unique online identity

[From Obama administration moves forward with unique internet ID for all Americans, Commerce Department to head system up -- Engadget]

As far as I can see, NSTIC being managed by the Commerce Department has nothing to do with “privacy laws” and the idea that it will require Americans to have an “Internet ID” is a journalistic invention. The actual situation is that NSTIC is to go from being an idea to an actual system:

The Obama administration plans to announce today plans for an Internet identity system that will limit fraud and streamline online transactions, leading to a surge in Web commerce, officials said. While the White House has spearheaded development of the framework for secure online identities, the system led by the U.S. Commerce Department will be voluntary and maintained by private companies,

[From Internet Identity System Said Readied by Obama Administration - BusinessWeek]

What this means is not that Americans will get an “Internet Driver’s License” but that they will be able to log in to their bank, the Veteran’s Administration, the DMV and their favourite blogs using a variety of IDs provided by their bank, their mobile phone operators and others.

[White House Cybersecurity Coordinator] Howard Schmidt stressed today that anonymity and pseudonymity will remain possible on the Internet. “I don’t have to get a credential, if I don’t want to,” he said.

[From Obama to hand Commerce Dept. authority over cybersecurity ID | Privacy Inc. - CNET News]

As long as it’s a matter of choice, I really don’t see a problem with this. The idea of NSTIC is that it is the infrastructure that is standardised, and this is good. We need standards for credentials and such like so that I can use my Woking Council ID to log in central government services and my Barclays Bank ID so that I can log in to do my taxes online: but I might pay Barclays for an additional ID that has some key credentials (IS_A_PERSON, IS_OVER_18, IS_NOT_BANKRUPT, that sort of thing) but does not reveal my identity. This sort of Joe Bloggs (or, for our cousins over the water, John Doe) identity would be more than adequate for the vast majority of web browsing and if other people want to wander the highways and byways of the interweb with a Manchester United, Prince or BBC ID, then it’s up to them. Let a thousand flowers bloom, as they say (well, as Chairman Mao said).

If the crazies want to be concerned about a single ID mark of the e-beast infocalypse, they’re perfectly entitled to, but I don’t understand why they are convinced it will come from the government in general or Obama in particular – there are half-a-billion people out there (including me) who have already handed over their personal information to a single unaccountable entity.

Facebook Login lets any website on the planet use its identity infrastructure—and underlying security safeguards. It’s easy to implement Facebook Login, simply by adding few lines of code to a web server. Once that change is made, the site’s users will see a “Connect with Facebook” button. If they’re already logged into Facebook (having recently visited the site), they can just click on it and they’re in. If they haven’t logged in recently, they are prompted for their Facebook user name and password.

[From Facebook Wants to Supply Your Internet Driver's License - Technology Review]

Now, at the moment Facebook Connect just uses a password, so it’s no more secure than banks or government agencies, but it could move to a 2FA implementation implementation in the future. Widespread 2FA access to online services really should have become a business for banks or mobile operators already (think how long Identrus has been around) but it just hasn’t happened: I can’t use my Barclays PINSentry to log on to Barclaycard, let alone the government or an insurance company. But suppose my Facebook login required access to my mobile phone so it was much more secure: you know the sort of thing, enter e-mail address, wait for code to arrive on mobile phone, enter code (a proper UICC-based digital signature solution would be much better, but that’s another topic). Then I could use Facebook Connect for serious business. This would have an interesting side-effect: Facebook would know where I go on the web, which seems to me to be much more like the mark of the e-beast.

An interesting side benefit for website operators is that Facebook Login provides the site with users’ real names (in most cases) and optionally a variety of other information, such as the users’ “friends” and “likes.”

[From Facebook Wants to Supply Your Internet Driver's License - Technology Review]

Which is, of course, why I don’t use it. On the other hand, if Facebook decided to use cryptography to secure and protect this sort of information, they could at a stroke create a desirable internet passport: by “blinding” the passport to prevent service providers from tracking the identity across web sites Facebook could significantly improve both convenience and privacy for the average users.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.