Comments on: Hey, you, get off of my cloud (™) http://tomorrowstransactions.com/2012/08/hey-you-get-off-of-my-cloud/ Thought leadership from Consult Hyperion Tue, 09 Sep 2014 00:19:19 +0000 hourly 1 http://wordpress.org/?v=4.0 By: David Moss http://tomorrowstransactions.com/2012/08/hey-you-get-off-of-my-cloud/#comment-325 Mon, 03 Sep 2012 09:43:02 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/hey-you-get-off-of-my-cloud/#comment-325 Indeed. So therefore I should be able to log in using Twitter and the DVLA need not waste money on an e-ID single sign-on of whatever.
Matt Honan’s Twitter account was taken over and used to broadcast homophobic and racist comments in his name. Why would you want to log on to DVLA using an insecure Twitter account?

DVLA don’t offer SSO to us consumers. You are solving a non-existent problem.

Why would DVLA accept a Twitter ID? Only if they had first issued a credential authorising that ID to use certain resources. But having done that, why bother to involve Twitter at all, DVLA have already done the access control work themselves?

With DVLA, the use case one’s mind lights on is paying road tax. AML aside, DVLA probably don’t care who pays them for a tax disc as long as someone does.

What about cases where government is paying money out, as opposed to receiving it? Will DWP pay benefits to a Twitter ID? Under what circumstances would that be a responsible way to spend public money?

Do you want the social networks to become part of the UK Constitution? Why?

That’s what would happen if their IDs were used for public services. As seems all too possible if you watch what G-Cloud and GDS are up to at the moment.

]]>
By: David Moss http://tomorrowstransactions.com/2012/08/hey-you-get-off-of-my-cloud/#comment-324 Fri, 31 Aug 2012 01:41:21 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/hey-you-get-off-of-my-cloud/#comment-324 DVLA would know only that a particular Twitter ID links to a particular DVLA identity.
I’m not sure if you’re talking about a possible future world here, but as things stand now DVLA know exactly which cars, if any, are registered in your name, they have your postal address and possibly your email address, they ask for your mobile phone no., which you may or may not give them, and even if they don’t have your debit/credit card details from when you pay your road tax, they know a man who does. They check whether your car is MOT’s and, if it is, they will know where you had it done. They also check whether your cars are insured and, if so, when the premium is due – they may discover at the same time who your insurance company is. In your scenario, they will also know your Twitter ID.

[Dave Birch] Indeed. So therefore I should be able to log in using Twitter and the DVLA need not waste money on an e-ID single sign-on of whatever.

I assume that you broach this DVLA use case to demonstrate some benefit. What is the benefit of adding Twitter and your iPhone and your fingerprint to the recipe? You don’t see a problem (see below), but I don’t see a benefit.

I agree with your assertion. But only for very large values of “only”.

I don’t see a problem with this.
You’ve identified one problem yourself, in the opening paragraph of your post – the experience of Matt Honan.

As to the fingerprint, we are agreed and have both asserted from the start that this is not a matter of identification. The question is, can today’s mass consumer biometrics technology supply authentication?

No. Not if you try to keep the false match rate (FMR) as close to zero as possible. Because in that case flat print fingerprinting has a false non-match rate (FNMR) of about 20%.

How come matching doesn’t fail 20% of the time on your iPhone? Because the matching threshold has been lowered from the high security requirements of applications like police work, border control and … banking.

With the threshold lowered, the FNMR falls but the FMR rises – the two are inversely proportional.

The downside of a low FNMR is that more and more impostors could pass themselves off as Dave Birch. They would be able to authenticate payments to their friends drawn on your bank accounts and all authenticated by the watered down security provided by today’s mass consumer biometrics.

That’s no way to run a payments system.

Especially not if we’ve got PKI in the mix and, thus, non-revocation.

]]>
By: Consult Hyperion http://tomorrowstransactions.com/2012/08/hey-you-get-off-of-my-cloud/#comment-323 Wed, 29 Aug 2012 10:49:21 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/hey-you-get-off-of-my-cloud/#comment-323 Once again: this is nothing to do with identification. While I agree with you about the problem of uniqueness, it is not material this discussion, which is only about authentication. When you pick up your iPhone, your finger on the home button will authenticate you as the authorised user of the iPhone, and that is all. The iPhone doesn’t care who you are.

If my Twitter ID was guaranteed to be linked to my iPhone and my iPhone is linked to me by my fingerprint, then why wouldn’t I use it to log in to the DVLA? Neither Twitter nor the iPhone would know my DVLA identity, and the DVLA would know only that a particular Twitter ID links to a particular DVLA identity. I don’t see a problem with this.

]]>
By: David Moss http://tomorrowstransactions.com/2012/08/hey-you-get-off-of-my-cloud/#comment-322 Sun, 26 Aug 2012 11:34:17 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/hey-you-get-off-of-my-cloud/#comment-322 1. Biometrics
I’m not proposing the use of biometrics for identification but as a convenience technology for authentication.
The trustworthy experts in mass consumer biometrics – e.g. Professor John Daugman – are the first to agree that the technology cannot deliver identification. Not if that means using it to ensure that there is a one-for-one correspondence between people and the unique template of their biometrics stored on the population register.

How would you prove uniqueness? One way and another, you’d have to compare each template against every other template on the register. How many comparisons would that be? nCr, where n is the population size and r is 2. Say the UK population is 60,000,000. You’d have to perform 60000000 X 59999999 / 2 = 1.8 X 10^15 comparisons.

Suppose the equipment used was reliable enough to make only 1 mistake in every 1,000,000 matches. That is, once every million matches it wrongly considers the two templates to match. Then you would have 1.8 X 10^9 false matches to investigate and resolve manually.

How long would it take to resolve 1.8 billion false matches? Too long. It would never be done. Today’s mass consumer biometric technology can’t prove uniqueness, it can’t deliver identification and only snake oil salesmen pretend that it can.

Which leaves us with “authentication”, as you call it. That job is millions of times easier. You just have to prove that the fingerprint, or whatever, whose template is stored on the population register, matches the fingerprint of the person conducting the financial transaction. It’s a one-to-one test, not a one-to-many test.

All trials suggest that the false non-match rate for fingerprints using today’s flat print fingerprinting technology is about 20%. About 20% of transactions would fail. It may be millions of times easier than identification but it still doesn’t deliver a usable banking system. You can’t have 20% of transactions failing.

Flat print fingerprinting is quite reliable compared with face recognition. For get face recognition, it’s a bad joke.

Iris scanning is more reliable than flat print fingerprinting when it comes to authentication. The false non-match rate is about 4% for able-bodied people, 9% for the disabled. That’s still not good enough for a banking system. And there is an additional problem. About 10% of the able-bodied can’t register their iris scan in the first place. They would be excluded from banking. And that figure rises to 39% for the disabled.

There are no known trial results for large-scale tests of voice biometrics.

Combining several biometrics to make one composite biometric doesn’t help.

Forget mass consumer biometrics for the moment and concentrate on passwords/phrases and PINsentries, because that’s all we’ve got.

http://dematerialisedid.com/PDFs/UKPSBiometrics_Enrolment_Trial_Report.pdf

2. Identity providers
GDS talk about creating a new market in identity assurance. Where are these identities to come from? They don’t say. We are left to guess – the banks, the phone companies, the utility companies, … And we are left to look at the references they make, principally Google, to whom we might add Facebook and Twitter, as you do.

http://digital.cabinetoffice.gov.uk/2012/02/10/west-coast/

Google, Facebook and Twitter are all used by most people for free. Which tells you that there’s something up. We users are not paying. We are not in control. We have no recourse.

You have yourself pointed out the importance of control when it comes to a person’s identity. Google, Facebook and Twitter fail the control test.

You ask: If my Twitter ID was a secure, then surely it would save my employer money to let me use that ID rather than create and manage a new one. And why wouldn’t I use that same Twitter ID to access my bank account? You know the answer.

]]>
By: Consult Hyperion http://tomorrowstransactions.com/2012/08/hey-you-get-off-of-my-cloud/#comment-321 Sun, 26 Aug 2012 02:24:48 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/hey-you-get-off-of-my-cloud/#comment-321 [Dave Birch] Thanks for the thoughtful response David. A few quick points:

The M-PESA fraud is nothing to do with the SIMs, as you point, but the reason that the fraud is so low is because of the SIMs, if you see what I mean.

I do think PKI could work if it was under the hood. Some years ago we built a prototype for such a system for a Japanese IT company and it worked well.

I’m not proposing the use of biometrics for identification but as a convenience technology for authentication.

I’m not as completely pessimistic as you about GDS. I think private sector AP in a NSTIC-style framework would be workable.

]]>
By: David Moss http://tomorrowstransactions.com/2012/08/hey-you-get-off-of-my-cloud/#comment-320 Fri, 24 Aug 2012 05:40:12 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/hey-you-get-off-of-my-cloud/#comment-320 The hackers walked through Amazon and Apple’s security, took over his Twitter account and deleted all his emails, contacts, documents and photographs from his iPad and iPhone. There was no backup — his “digital identity”, as Mr Honan put it, was irretrievable. So much for cloud computing.

You open with a reference to Mr Honan’s experience, Dave, and then go on to make cloud computing sound inevitable and desirable if only tamper-resistant SIMs are added and PKI.

Tamper-resistant SIMs are used in mobiles and yet Kenya still suffers frauds in its mobile payments, as noted by you.

PKI would help but, as you noted in an earlier post, it is too hard to implement end-to-end, you and your clients couldn’t anything through the anti-virus defences.

And biometrics. Again. Their unreliability has been proved over and over again and brought to your attention over and over again but you still cleave to them — why?

Given the behaviour of Google and Facebook over the years, you must know that there is no hope that individuals will be able to maintain control of their identities. These organisations and others have no understanding of privacy and/or no respect for it. You know that.

There are only two organisations who could possibly agree with what you have written. G-Cloud, the Whitehall civil servants who continue to promote the benefits of a government cloud. And GDS, the Government Digital Service, the Whitehall civil servants who are trying to get Francis Maude to hand over identity assurance to Google and possibly Facebook.

You are in the company of G-Cloud and GDS. The reductio ad absurdum of your extraordinary post.

http://www.dmossesq.com/2012/04/amazon-google-facebook-et-al-latter-day.html

]]>