Tomorrow's Transactions » » Social Media and Organisations http://tomorrowstransactions.com Thought leadership from Consult Hyperion Thu, 30 Apr 2015 13:28:42 +0000 en-US hourly 1 http://wordpress.org/?v=4.1.5 Identity might work better bottom up http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/ http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/#comments Mon, 09 Jun 2014 11:06:29 +0000 http://tomorrowstransactions.com/?p=4480 Dgwb blog white border

One way to help people obtain financial capital is by helping them to build up social capital.

Forum friend Kosta Peric from the Bill and Melinda Gates Foundation (BMGF) Financial Services for the Poor programme recently picked out four technologies as being of particular interest right now. He pointed us to:

  • bitcoin-inspired distributed systems,
  • open APIs (application programming interface) as a new way to consume business services on the internet,
  • crowd-sourced identity schemes, and
  • open source hardware and applications.

[From Four Technologies That Will Revolutionize Financial Services | copernicc]

I’m sure we’d all agree with his views on blockchain technologies and the “Amazonisation” of financial services organisation through APIs (I don’t know enough about open-sourced hardware to comment) but I think his point about crowd-sourced identity is especially interesting, as it points to a shift in the way that identities are created, managed and used. And, since I’m rather obsessed with identity right now (as our clients should be and, in some cases, are too) I thought I’d take the time to explain why I agree with him.

First, look at what the conventional, top-down notion of identity means. It means someone (the government, generally speaking) must find some way to assign an identity to everyone who needs one, record who those identities have been assigned to, and check that when the identities are presented they are genuine.

It is almost certain that the government is having difficulties establishing who is a genuine citizen purely on the basis of identification papers produced by the existing system. Some of the illegal immigrants caught in the current security swoop have Kenyan ID cards and passports but their details are not in the national database.

It has been claimed that immigration and provincial administration officials at all levels have enriched themselves by selling these sensitive documents while compromising national security.

[From KENYA: Kenyans to apply for digital identity cards, says Ruto]

There are problems with this top down approach. Apart from being expensive, it is also vulnerable. One a false identity has been entered into the system, it is no longer false (if you see what I mean). As a consequence, obtaining such an identity becomes an essential precursor to crime as well as legitimate use and therefore the identities are obtained by all sorts of people who are not supposed to have them and the system is subverted. Managing and protecting the database at the heart of this scheme is complicated and difficult. In a great many emerging markets, in particular, the national identity scheme is soon degraded: sometimes because of corruption, sometimes because of carelessness, sometimes because of errors in the concept and design. This is precisely what has happened with the Aadhar scheme in India.

What was supposed to be a unique identification number providing identification and access to a host of government benefits and services, ‘Aadhaar’ has almost unvaryingly been extended to anybody residing within Indian territories. Almost anyone, be it Indian or an illegal immigrant can get an Aadhaar Card made without any proof of identity. More importantly, they get a numbered identity.

[From Sting reveals Aadhaar documents forged for Nepal, Bangladesh citizens – IBNLive]

So how does the alternative, crowdsourced version of identity take us forward? Well, if national identity schemes don’t provide “real” security then why bother with them? Save the money. At a basic level crowdsourced identity means asking everyone who you are rather asking anyone (e.g., the government) who you are. Whereas we are used to the idea of identity as something that is granted to us by a third party, such as the government or a bank, and the idea of an identity based on reputation that grows up through our networks and long-term relationships seems rather different.

Compare the two kinds of identity and their functionality in practice. Crowdsourced identity may seem a poor substitute for national identity at first glance, but it seems to me that Kosta is onto something here for two specific reasons that I have touched on before. The first is that this kind of reputational identity is actually better than conventional national identity because it is much harder to forge or counterfeit. A good friend of mine told me a story about an industry event he attended recently where he ran into a chap late at night when he was going back to his hotel. The guy was in the hotel lobby and recognised my friend as he had been a speaker at the event. The man explained that he had been tricked by a woman in a bar into following her back to hotel room where he had been drugged and robbed. He had no money and was too embarrassed to call his wife and asked if my friend might loan him some money so that he could get home and would report his wallet lost on the train or something. My friend had never met the man before but asked him his name and who he worked for and then looked him up on LinkedIn. Having established that not only did the fellow have a full LinkedIn profile but was actually connected to my friend via several different people, my friend loaned him the money which was, of course, gratefully returned a couple of days later. Now imagine that the unfortunate chap had instead presented my friend with his Portuguese fishing licence: how would my friend evaluate that and assess the strangers plausibility from that official document?

The second reason is that these crowdsourced identities may well be far cheaper to establish and this is especially true, and especially valuable, in the developing world where official infrastructure may be unreliable at best and non-existent at worst. Here the particular combination of mobile phones and social networks is especially powerful, because mobile phones tend to deliver not only unique identity but transactional history to go with it and this can be linked through social networking in powerful ways. You might have listened to the podcast I recorded earlier this year with Shivani Siroya and and heard a very good example of this where the transactional histories from mobile payment accounts are slurped up by organisations who provide alternatives to conventional kind of credit reference agencies that we are used to in the developed world.

Shivani Siroya is currently the CEO and Founder of InVenture. InVenture facilitates financial access by providing simple mobile accounting and credit scoring tools for offline and unbanked individuals, the subject of this podcast.

[From Media – Consult Hyperion]

Taken together, I think these provide compelling support to Kosta’s intuition and it strikes a that, to use Jaron Lanier’s term in “Who owns the future?”, the “economic avatars” that arise at the intersection of the mobile phone and the social network may well prove to be more useful to a great majority of the world’s population than their “official” identities even if they have them and indispensable to them if they do not. And, by the way, if you regard the whole idea of giving people credit on the basis of social capital as ridiculous and fanciful, I guess you didn’t see this:

[Bogota] where Lenddo introduced a “social network” Visa card to 100,000 of its customers yesterday afternoon. By 4:00 p.m. today in New York, where the online lender for developing countries is based, more than 1,000 Colombians had applied for the card. Lenddo CEO and co-founder Jeff Stewart calls it the first time ever, anywhere, that approval for a credit card is based on applicants’ reputations on Facebook, Google, LinkedIn, and Twitter.

[From This Emerging Markets Credit Card Is Backed by Facebook Friends » Techonomy]

Identity is the new money, as they say. Well, as I say.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/feed/ 3
Cybersecurity awareness month – sharing in a digital world http://tomorrowstransactions.com/2013/10/cybersecurity-awareness-month-sharing-in-a-digital-world/ http://tomorrowstransactions.com/2013/10/cybersecurity-awareness-month-sharing-in-a-digital-world/#respond Fri, 25 Oct 2013 07:29:12 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/10/cybersecurity-awareness-month-sharing-in-a-digital-world/ Sharing risk information can help protect companies online. But first we need a structure for sharing.

]]>
[Margaret Ford] Educator and certifier of info-security professionals (ISC)2has just published a report on the online activities of primary school children, as part of its Safe and Secure Online programme. According to the report (available to its members at www.isc2.org.uk), 18% of 9-11 year olds have met up in person with a stranger they have met online. More worryingly so, 50% of these went alone. The report was published as part of National Cyber Security Awareness Month, celebrating its tenth anniversary this year.

A significant number of children have admitted to lying about their age in order to access popular social media sites such as Facebook. Having spent some time recently discussing online safety with 10 year olds at a local primary school, I have found that many of the children “know someone” who has an account on Facebook, despite being the account holder being well below the official minimum age of 13.

Apart from propagating some kind of digital ‘green cross code’, it can be hard to know how to approach e-safety with this age group. Many outstrip their parents in technical knowledge, and are naturally intensely curious. One approach may be to help them to build their own strategies for dealing with potentially risky situations. Materials such as videos and games can be used to encourage the children to express their concerns and work together to find ways to protect themselves online.

As part of the EU-funded TREsPASS project, Consult Hyperion is involved in exploring these same issues of trust, sharing and risk exposure at organisational, national and international levels. In the TREsPASS context, this involves the development of modelling formalisms and identification of practical ways to share risk information, to provide as much value as possible to the recipients, without overexposure of the originating organisation.

At present, the sharing of risk information is far from uniform: bilateral arrangements between organisations, governed by NDA, appear to be the norm. Multilateral sharing has evolved in some industries, especially those which involve Critical National Infrastructure and those which are heavily regulated – telecoms is an example of this. Before any meaningful sharing of risk data can take place, a sound structure for sharing has to be in place.

A key element mentioned at a recent meeting of the EU NIS working groupon information exchange and incident co-ordination is the need for a common view of normality. In cyber security, as in many other fields, this can in fact be very subjective and vary by sector, size of organisation and organisational culture. Where one company might regard repeated attacks as ‘business as usual’, another might regard those same incidents as a reason to invoke crisis management.

In order to find common ground, it is helpful to start with a common vocabulary. The FAIR taxonomy adopted by The Open Group provides a valuable structure for describing the range of risk concepts. We presented with fellow TREsPASS partner BizzDesign this week at the Open Group Conference in London, showing how the ArchiMate Enterprise Architecture tool could be extended to support risk modelling with reference to a practical case study. As a socio-technical project, TREsPASS is investigating complex social and organisational environments together with technical elements of risk.

Interesting announcements at the Open Group event included the launch of the Open FAIR Certification for risk professionals, based around the newly published updates to the FAIR risk taxonomy and risk analysis standards.

Over the course of the project, TREsPASS will produce a range of tools to support risk modelling and visualisation at enterprise level. It will also develop a risk toolkit tailored specifically to the needs of SMEs, taking into account their unique requirements and essential role in the European economy. 

Keep an eye on this blog for further developments from TREsPASS as well as our involvement with this EU project. 

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2013/10/cybersecurity-awareness-month-sharing-in-a-digital-world/feed/ 0
Social “hacks” are going to be replaced by computations across the social graph http://tomorrowstransactions.com/2013/04/social-hacks-are-going-to-be-replaced-by-computations-across-the-socia/ http://tomorrowstransactions.com/2013/04/social-hacks-are-going-to-be-replaced-by-computations-across-the-socia/#respond Mon, 08 Apr 2013 05:53:44 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/04/social-hacks-are-going-to-be-replaced-by-computations-across-the-socia/ [Dave Birch] At this year’s South-by-Southwest Interactive (SXSW) in Austin, Texas, I went along to a session called “Identity + 30“, which was run by Sam Lessin, Head of the Identity Product Group at Facebook. The idea of the discussion was, if I understood it properly, not to be “right” about what identity would actually be a generation from now, but to create a framework for discussing identity now. Sam is a pretty interesting guy, and he got me thinking right from the start of his session, which I mean as a serious compliment, because to be completely honest this was not true of all the sessions I went to.

The core of his argument was that when sharing is expensive, or when it makes an individual less well-off, then people don’t share. Society has to deal with this, trade being the root of our prosperity, so it develops trust networks to connect more trading partners and collect more information about those trading partners. Sam had a useful way of thinking about this, which was the idea of what he called “social hacks” to deal with the historical problem that the speed of bits and the speed of atoms are different (I might disagree with the shape of his pseudo-graph, but I think his points hold). These hacks (diplomas, badges, dress codes and banking) help us to get by, but they are by no means optimal.

However, we now have what Sam called the “superpower” of being able to instantly communicate with anyone else on Earth so we will no longer need those hacks. I may be paraphrasing incorrectly, but I think his way of looking at the existing business models around identity as being hacks in response to incomplete identity, credential and reputation information is a good way of framing some problems and a very helpful way of exploring the solutions that new technology can present. I strongly agreed with his big picture technology roadmap and have written before about about the “William Gibson World” where all of the technologies that will have any impact on corporate strategies to any foreseeable horizon already exist, something I always emphasise when we are working on client roadmaps. The trick is to look out of the corner of your eye and see where the technologies are being used for purposes that might disrupt business models, not to imagine new technologies. Given my predilection for using Dr. Who as my design authority, I also enjoyed Sam’s choice of common culture SF narratives to describe the future! His view is that the current generation is moving toward a “Borg system” not a “Hal system”, so new business opportunities are about the mass sharing of structured data.

Anyway, on to some of Sam’s key points, all of which were excellent:

  1. Information will centralise and cluster. (APIs are better than protocols.)
  2. We will share a lot more about ourselves. (Economics, not culture, will dictate this.)
  3. Everywhere will become local. (“I want to go where everyone knows my name” Cheers-style.)
  4. Only poor people will own things. Rich people will just rent whatever they want.
  5. Social capital will get ever more fungible, so (for example) going to Harvard will mean less than it does now, which means that it will be worth less than it is now. You can see exactly where this headed. Just look at the way we use LinkedIn right now. In the old world, I would use the social hack of finding out which university your degree came from as a sort of proxy for things I might want to know about you, but I no longer need to do that because I can go via LinkedIn and find out if you are smart, a hard worker, a team player or whatever. So there’s no premium for you learning, say, biochemistry at UCL rather than Swindon Polytechnic: so long as you know the biochemistry, my hiring decision will be tied to your social graph.
  6. The cost of using social capital for transactional purposes will fall below the cost of trust intermediaries such as notes and coins, so there will be no need for cash any more. In other words, identity is the new money.

(When Sam put up that last point I nearly cried, because earlier this year I was commissioned to write a book on exactly that topic! I thought I was the only genius that had realised that trade based on social graphs would eliminate physical means of exchange, so now I am crushed. Back to the drawing board, even though I hadn’t actually drawn very much so far.)

The argument here is, to my mind, unanswerable. Suppose I am wandering through Woking market and I want to buy a doughnut. I give the trader £1. The trader doesn’t have to trust me, he only needs to trust the £1, and the cost of failing to detect that my £1 is a counterfeit is quite small (despite the large number of fake £1 coins in circulation in the UK) compared to the cost of establishing my trustworthiness and creditworthiness. Other traders deal with this problem by paying banks and card schemes to manage the problem for them, but this costs them money. But now I imagine that I wander up to the trader to buy a hot dog and through his Google Glasses my face is outlined in green, which means that the system recognises me and that I have good credit. The trader winks at me, and a message pops up on my phone informing me that I am being charged £1. I press “OK” and we go about our day.

More than £4m worth of fake one pound coins have been seized by detectives.

[From Police Seize Record Haul Of Counterfeit Coins – Yahoo! News UK]

Until the invention of the mobile phone and its connection with the interweb tubes, I think it was reasonable to assume that for small transactions there was no way of using identity, credentials and reputation in small transactions, which is why it made sense to continue to use notes and coins to settle retail transactions. But now? The replacement of notes and coins in this way all hinges on the trader recognising me. Once this has been achieved, the issue of trust can be instantly resolved by computations across the social graph. If I understood correctly, this is why Sam said that “trust & trade” is the layer above the basic “recognition & memory”.

Money is technologically equivalent to a primitive version of memory.
Kocherlakota, N. “Money is Memory”. Journal of Economic Theory 81, p.232-251(1998).

Is it possible to imagine a trust and trade layer based on the social graph rather than third-party credentials? Yes. I remember that at the excellent Nixon McInnes “Social in the City” seminar last year, Will McInnes made a really important point right at the beginning of the day. “Who do we trust”, he said. “We trust people like ourselves.” Quite. And I also remember that in the discussion on trust at the Digital Agenda for Europe Assembly for 2012, I got into a mild argument with someone in the break, because I said that the idea of sticking web badges on sites (“this is a trusted European e-commerce merchant” badge, as an example) was ridiculous, and a strangely Victorian approach to vetting tradespeople. We need those badges as a pre-networked society substitute for actual information about trust. (Clearly, what Sam would label a “social hack”.) Once the social graph enables you to determine trust, they don’t make any sense. Look at it this way. Why would I care whether a hotel has the “British Tourist Board Seal of Approval” (I’ve no idea whether this exists – I just made it up) when I can go on Trip Advisor to see what everyone thinks about it? Or, more especially, I can go and see what my friends, my work colleagues and in general, people like me think about it?

I don’t know about Sam’s thought experiment of New Jersey suburbs becoming cool, but I thoroughly enjoyed his session and greatly appreciated his window into the kind of thinking that is going on in Facebook.

Incidentally, Sam referred in passing to “peak cash”, which I thought was such a nice idea that I have sworn to plagiarise it mercilessly. I’m working on a blog post around this for next week sometime.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2013/04/social-hacks-are-going-to-be-replaced-by-computations-across-the-socia/feed/ 0
Who’s calling? http://tomorrowstransactions.com/2013/03/whos-calling/ http://tomorrowstransactions.com/2013/03/whos-calling/#comments Mon, 18 Mar 2013 18:55:02 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/whos-calling/ [Dave Birch] An interesting e-mail arrived today (the contents and counterparties are not relevant to this post) but it made me think about “real names” again. I have to get together a talk for developers at the Microsoft Digital Wallet Foundry, and I thought this might be a good topic. So I went back to my notes to see if I could find a fun “case study” to focus thinking around convenience and security in ID. I came across this.

As Sheryl Sandberg said this week, when caller ID first came out, it was declared a violation of privacy.

[From Fear For Your Safety, Not Your Privacy | TechCrunch]

That’s because caller ID is a violation of privacy. Which is why you can turn it off. If I’m phoning British Gas customer service, I can leave caller ID on and benefit from the efficiency that having my Calling Line Identifier (CLI) connect to their CRM brings. But if I’m phoning the council to complain about the crack house next door, then I might decide to remain anonymous and turn it off. If I want to avoid the near-contininous stream of calls from ambulance-chasing lawyers about PPI, I might want to screen incoming calls by CLI (although this is a useless strategy against spammers because they use international “out of area” codes). Bear in mind, too, that spoofing caller ID is trivial, so it doesn’t deliver any actual security. If it wasn’t trivial to spoof it, there would be no need for legislation such as

The Truth in Caller ID Act of 2009, which was signed into law Dec. 22, 2010, prohibits caller ID spoofing for the purposes of defrauding or otherwise causing harm.

[From Caller ID and Spoofing | FCC.gov]

Thanks goodness there’s a law against such spoofing, because it means that no-one does it. No, wait… that’s not really true. No one does it except for criminals who are, for example, spoofing bank numbers to make phishing attacks or in more sinister enterprises such as getting people raided by SWAT teams by making bogus emergency calls that appear to come from the victim’s address (“SWATting”). So I call the police using your home phone number in the caller ID and tell them that someone has gone postal in the house, at which point heavily armed law enforcement officials storm your house and (hopefully, from my point of view, shoot you). This just happened to the well-know blogger Brian Krebs.

His office phone rang while he was vacuuming, but he ignored it. That, it turns out, was an unfortunate choice, given that the call came from law enforcement who were trying to verify what would turn out to be a spoofed emergency call showing Krebs’s number on caller ID.

[From Hackers launch DDoS attack on security blogger’s site, send SWAT team to his home | Naked SecurityNaked Security]

In other words, CLI is about convenience. It doesn’t deliver security. Worse still, it delivers “anti-security” because people believe it delivers security when it doesn’t. CLI did develop an acceptable privacy settlement – since you can turn it off – and people started to use it despite the lack of security. I can’t be bothered to look, but I’m sure page 697 of my phone company terms and conditions says that I’m not allowed to spoof CLI.

“The name you use should be your real name as it would be listed on your credit card,” Facebook says.

[From Facebook’s fake-name fight grows as users skirt the rules | The Verge]

Why? It’s of no help to anyone: anyone except marketers who are being sold the data, that is. My friends know that Leadbelly Gutbucket is me, and so they friend me and we use and enjoy Facebook together (as I do, in fact). But the corporations don’t know that this is me, unless I choose to tell them. I don’t believe that any name I see on Facebook is real. How would Facebook know? They didn’t do an Experian check on me when I created my account.

“Pretending to be anything or anyone is not allowed.”

[From Facebook’s fake-name fight grows as users skirt the rules | The Verge]

This is a completely different point. And Facebook are completely right about this: you shouldn’t be able pretend to be anyone else. Personation is obviously wrong. For example, did you see the Italian “Catch me if you can” story? It is a super tale of fake identity updated for the modern age.

A man who posed as an airline pilot and traveled in the cockpit of at least one plane was arrested in Turin Airport using forged identity cards and wearing a pilot’s uniform… The 32-year-old, whose real name was not released, allegedly created a fake identity as a Lufthansa pilot named “Andrea Sirlo,” complete with a Facebook page that included fake flight attendant friends… The national military police tracked down the suspect from photos on his Facebook profile, in which he is shown posing in uniform and sunglasses in front of airplanes.

[From Fake Italian pilot traveled in cockpit, police say | Reuters]

But if I create a Facebook account in the name of David Beckham and then IM a transfer request demanding a move to Swindon Town, is that really impersonation or just a joke? One more point. The real names fuss is not a Facebook phenomenon and I don’t mean to suggest it is. If you want a non-Facebook example you need look no further than our own legislature.

an embarrassing photograph emerged which showed him wearing the name-tag ‘Michael Green’ – an alter ego used by the MP when posing as a self-help guru – at an internet conference in the US in 2004.

[From Maybe it’s because I’m a Watforder: ‘Double life’ Tory chief can’t decide if he was born in London or Herts | Mail Online]

I’m not sure I’m against alter egos. What is the problem with having a “pen name” for the novel that you are writing? And how you can you “pose” as a self-help guru. Surely he was just practicing what he preaches. If I say that I’m a self-help guru, then I am. Now, you may want to see some credentials or learn about my reputation as a self-help guru, but in a world where you do not need my name as an (imperfect) proxy to those details, what does the name matter?

There are many points to be made from these stories, but the main ones I want to make are that the whole identity thing is more complicated than it seems and it needs new thinking and a new narrative and that reputations are more important than names and finding a way to securely manage credentials and reputation is the way forward for the new economy. To my mind, these are critical components of the new digital wallet, because virtual none of your day-to-day transactions depend on your name.

In the end, I decided it would be too boring to tread too much of the same pseudonymity ground as I did my last TEDx talk (which now has almost 173,000 views, I’m rather excited to report!) so I’ve gone for a more sweeping topic: “Identity is the New Money”. Look forward to seeing you at the Modern Jago in May!.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2013/03/whos-calling/feed/ 2
The battle of the internet security experts http://tomorrowstransactions.com/2012/10/the-battle-of-the-internet-security-experts/ http://tomorrowstransactions.com/2012/10/the-battle-of-the-internet-security-experts/#comments Fri, 26 Oct 2012 17:22:07 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/10/the-battle-of-the-internet-security-experts/ [Dave Birch] A very entertaining spat has broken out in ranks of the governing classes. Broadly speaking, it’s between the “Real Names Randi” Zuckerberg school and the people who know something about the issue school. The trouble started when noted internet security expert Andy Smith gave some sound advice to the nation.

Andy Smith, internet security chief at the Cabinet Office said real names and addresses could increase security concerns. He advised users to submit “fake” details as this was a “sensible thing to do”.

[From Whitehall official: ‘Give fake details to protect online identity’ – Public Service]

Andy is spot on, although possibly unaware that providing fake details is in direct violation of Facebook’s policy. His advice will indeed lead to less identity theft, and we don’t have to guess at that because (as I will discuss later) we have the data. Still,

Simon Milner, Facebook’s head of policy in the UK and Ireland, was not particularly happy at Smith’s comments. He apparently had a “vigorous chat” with the Cabinet Office official afterwards to persuade him to revise his view.

[From Top civil servant calls for Brits to fake online identity – Cabinet Office says it’s the only way to be safe | TechEye]

However vigorous Mr. Milner’s chat might have been, there are almost no circumstances where it is necessary to use real names and we only use them now because we lack a proper identity infrastructure. By and large, we use the real name as a proxy to the attributes that are actually needed to execute a transaction. Andy’s comments elicited an immediate and vituperative response from noted internet security expert Helen Goodman MP.

Ms Goodman, shadow culture minister, told BBC News: “This is the kind of behaviour that, in the end, promotes crime.

“It is exactly what we don’t want. We want more security online. It’s anonymity which facilitates cyber-bullying, the abuse of children.

“I was genuinely shocked that a public official could say such a thing.”

[From BBC News – Give social networks fake details, advises Whitehall web security official]

Ms. Goodman’s confused opinions on security and privacy — and the false dichotomy implicit in the security vs. privacy paradigm she draws on — are representative of the shallow thinking and lack of informed discussion in this area.

How Helen Goodman voted on key issues: Voted very strongly for introducing ID cards.

[From Helen Goodman MP, Bishop Auckland – TheyWorkForYou]

I wasn’t able to assess her background in online security and identity management from her online biography, but I’m sure her opinions must be founded on some knowledge of the field.

Helen… went to Somerville College, Oxford, where she read Politics, Philosophy and Economics. After leaving Oxford, Helen’s first job was as a researcher for Philip Whitehead MP. She became a civil servant at the Treasury in 1980 and rose to become Head of the Central Strategy Unit in 1995… From 2002 until entering Parliament, she was Chief Executive of the National Association of Toy and Leisure Libraries.

[From Biography » Helen Goodman MP – Working hard for all in Bishop Auckland]

In an age where government seems more and more to be about sentiment and sensitivity rather than evidence and knowledge, I suppose her comments are unsurprising. I’m not for one moment suggesting that Ms. Goodman’s concerns are not wholly real and heart felt. I’m sure they are.

Mrs Goodman, MP for Bishop Auckland, in the North-East of England, said she had been contacted by constituents who have been the victims of cyber-bullying on major social networking sites by people hiding behind fake names.

[From BBC News – Give social networks fake details, advises Whitehall web security official]

I don’t doubt that this is true. But so what? People bully under their real names too, and it doesn’t make any difference. If they have broken the law, they can easily be traced, since the interweb tubes will lead the plod directly to them. Or, indeed, directly to the plod.

A man arrested over claims that he tormented a mother with abusive online messages is a serving police officer.

[From Police Officer Arrested Over Internet Troll Abuse Of Woman, Nicola Brookes]

I’m not picking on Ms. Goodman here, just using her to illustrate a point. After all, her fellow old Oxfordian and noted internet security expert The Honourable Edward Vaizey MP agrees with her that the Cabinet Office’s advice is incorrect, leaving us none the wiser as to the government’s actual policy on this (hint: it doesn’t have one).

Culture minister [The Honourable Edward] Vaizey said he had not seen Mr Smith’s remarks but told the BBC that he “wouldn’t encourage people to put false identities on the internet”.

[From BBC News – Give social networks fake details, advises Whitehall web security official]

The Honourable Edward’s plan to make it easier to track down people through interweb tubes may not be driven by commercial interests, but it certainly aligns with them.

Randi [Zuckerberg] and I share a passion to end cyber bullying and protect kids online. However, our approaches to online safety differ greatly.

Randi Zuckerberg wants to end online anonymity.

[From Facebook’s Randi Zuckerberg Wants to End Online Anonymity: Free Speech or Real Names?]

Look, I’m not here to shill for Andy Smith. Andy and I have disagreed about things before, and while I make not comment on whether he is an Epic F***ing Secure Hero or not, he certainly is an internet security expert. His comments were informed and relevant and exposed the lack of policy integrity. I don’t know why politicians don’t take the time to think this through. They always reach for the same knee-jerk response: some sort of internet passport or driving licence so that you can tell who is posting abuse about government minister on The Daily Telegraph web site (hint: me).

if there was an Internet Driving License that you had to use to log in to web sites, that would almost certainly make the situation far worse, since these website would now know exactly who you are, and this information would then be freely obtained by perverts, the secret police, News International or whoever else wants to pry. Why is this better than anonymity (which doesn’t exist anyway – look what happened to the not-Anonymous-at-all hackers).

[From Let’s not panic about online identity]

Since I wrote this, incidentally, some pretty convincing evidence has come to light to support my view. South Korea has rescinded its “real names” law.

In 2007, South Korea temporarily mandated that all websites with over 100,000 viewers require real names, but scrapped it after it was found to be ineffective at cleaning up abusive and malicious comments (the policy reduced unwanted comments by an estimated .09%).

[From Surprisingly Good Evidence That Real Name Policies Fail To Improve Comments | TechCrunch]

In fact the results of the “real names” law were predictably perverse. Identity theft went up, because real identities were stolen from the thousands of web sites that now had to ask for them and store them. And since people became used to be asked for their real identity, it was easier for dodgy web sites to get them to hand them over!

if you make people smear their “real” identities all over the internet because of such a policy, thus delivering the “over–identification” noted above, then that will make identity theft worse.

[From Real names, real problems]

I fully expect The Honourable Edward Vaizey MP to begin drafting another law shortly. After all, if we are not allowed to mask our real  identities online, why should we be allowed to mask them offline either? In a country covered by CCTV cameras, it seems perverse that people should be allowed to, for example, wear masks of celebrities (or, indeed, anyone else) in public places. The steady advance of automated face recognition technology means an inevitable identity Chernobyl.

Any science fiction film that doesn’t show everyone wearing burkhas in public will look as dated as Soylent Green.

[From Never mind real names, what about real faces]

Look. I don’t mean to suggest that Ed and Helen are idiots. That’s clearly not true. But what I am suggesting is that we need a better-informed public discussion and debate to determine public policy and the balancing of interests between competing pressures needs to be made explicit. How should we determine whether Mumsnet or the EFF are right? In back rooms or in public consultation (by which I mean consultation in public, not with the public – I don’t really care what they think since they are almost completely uninformed).

We (the public) have no idea what we want. We want anonymity for Syrian dissidents but not for pedophiles. We want anonymity for hospital nurses blowing the whistle on incompetent surgeons but not for looters. We want anonymity for celebrities in some circumstances but not others. Most of all, and most paradoxically, we want the authorities to spy on other people but not on us.

[From We don’t know whether we want real names or not]

So what I want to know from the Honourable Edward Vaizey, Helen Goodman MP and the Cabinet Office is this: what is the policy, and what is the strategy to implement it? And if you’re short of an idea or two about a vision for online identity in the 21st century, why not put your feet up, get a cup of tea, and cop a load of this. The security vs. privacy balance is only for people who haven’t put any intellectual effort into this serious, important and urgent area of public policy. Joanna Geary sums up the situation very nicely in her “Comment is Free” piece today.

A Whitehall adviser has been slammed for telling people to make up data. But less anonymity doesn’t equal more security

[From Being wary of handing over personal details to websites isn’t ‘outrageous’ | Joanna Geary | Comment is free | guardian.co.uk]

Hear, as they say in Parliament, hear.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2012/10/the-battle-of-the-internet-security-experts/feed/ 1
Social banking http://tomorrowstransactions.com/2012/08/post-social-banking/ http://tomorrowstransactions.com/2012/08/post-social-banking/#comments Wed, 15 Aug 2012 09:17:59 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/post-social-banking/ [Dave Birch] I was reading about “social media lessons from banking insiders” in a report published by the noted Swiss co-operative KPMG International. The report asks the question (on page 2) “Will customers really want to be ‘friends’ with their bankers?”. Now, as everyone already knows, the answer to this is no. I cannot imagine any circumstances under which I would to earn “thank you points” on Facebook from my bank in return for the amount of money I have on deposit with them. I would much prefer them to fire the social media gurus and consultants behind this sort of idea and give me another 0.5% on my savings account instead. And further integration inside the Facebook framework doesn’t seem to have much to offer either.

In my opinion, banks that are enabling or attempting to enable transactions via a Facebook app are barking up the wrong tree. I’ve seen nothing to suggest that customers want this or would even use this. In fact, I’ve seen evidence of the contrary.

[From Celent Banking Blog » Are Bank Facebook Apps the Future of Digital Banking?]

That’s not to say, of course, that Facebook is irrelevant to banks. For one thing, as I’ve bored on about at length before, if there were a transactional element to social media integration then banks might have some really good products and services to offer in that space.

I don’t want to be friends with my bank—after all, I’m a typical consumer so I hate banks—but I do want to be friends with my bank account.

[From Friends and relations]

But that’s by the by. KPMG make a very interesting point on page 16, where they note that the lack of security infrastructure means that banks in any case have no way of knowing whether social media data comes from real customers, competitors, corporate saboteurs, mischievous hackers, agents of foreign powers or dogbots. This, it seems to me, opens up an interesting and immediate route for exploring the bank/Facebook boundary to find value. I was thinking that while the bank doesn’t know if you are a person or a dogbot e-mailing them or tweeting about them, and they can’tt use CAPTCHAs or similar to find out, they might be able to find out if you are human if they began exploring your social graph. Which leads on to the obvious further thought that using customers’ social graphs as an adjunct to conventional credit references and other cardboard-era identity management might deliver some interesting results.

He submits his information to the online-only PotterBank.com, but halfway through the application process, the website asks for his Facebook login. Then his Twitter. Then LinkedIn… A new wave of startups is working on algorithms gathering data for banks from the web of associations on the internet known as “the social graph,” in which people are “nodes” connected to each other by “edges.”

[From As Banks Start Nosing Around Facebook and Twitter, the Wrong Friends Might Just Sink Your Credit | Betabeat — News, gossip and intel from Silicon Alley 2.0.]

Suppose that this works. Then it has security benefits because the social graph ought to prove much more difficult to forge that a photocopy of a gas bill — the gold standard for authentication in the UK — and, some people suspect, it may have additional benefits because the social graph could be more accurate than a conventional credit reference agency when it comes to deciding whether you want someone as a customer or not.

Brett King, CEO of Movenbank, has a radical idea: a “credit score” built — at least in part — on consumers’ social media activity. Sound crazy? Maybe, but the idea has attracted the attention of big league investors who just pumped $2.41 million into King’s startup.

[From Is The World Ready For Social Media Credit Scores? | The Financial Brand: Marketing Insights for Banks & Credit Unions]

Brett is on to something. Whether his “CRED” score and algorithm is correct or not I couldn’t say, but the core of the idea — that if your Facebook friends are bank robbers, you might well be more likely to turn out to be a bank robber — seems wholly plausible. The social graph might be a better predictor of future activity (and future financial services requirements) than past credit scores. The social graph can tell things about you — like you’re going on holiday or getting married or moving to Hong Kong — that an intelligent and customer-centric organisation can act on in a supportive win-win framework. In Christophe Langlois‘ “A practical guide to social media in financial services” he talks about “Know Your Followers” (KYF) as the social media equivalent of “Know Your Customer” (KYC) in compliance. Obviously, KYF isn’t yet a legal requirement, but you get the idea. If organisations develop tools, algorithms and techniques for exploring the social graph then they might find that social media identity, or some kind of social media-based financial services identity, is far better than traditional KYC, credit agencies and old utility bills and predicting which customers they do or do not want.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2012/08/post-social-banking/feed/ 3
Real names, real problems http://tomorrowstransactions.com/2012/08/real-names-real-problems/ http://tomorrowstransactions.com/2012/08/real-names-real-problems/#comments Tue, 07 Aug 2012 10:57:26 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/08/real-names-real-problems/ [Dave Birch] There is an assumption, which is reasonably well-founded I think, that many social media companies want to develop “Real Names” policies of one form or another not to prevent trolling or to protect the kiddies in one way or another, but to help with the commercialisation of their services and the monetization of the identities that they hold. Whereas the identity “Dave Birch of Consult Hyperion” may be worth something to commercial organisations (debt collectors, payday loan sharks and so forth)  — according to real names thinking — the identity “Leadbelly Gutbucket, mightiest of the Dwarven heroes of Ravenscrag Pass” may not. Hence the drive to find out who people really are.

Real Names is slithering into the whole fabric of the company’s offerings, whether specific sites benefit from what will often be “over-identification” or not.

[From IdentityBlog – Digital Identity, Privacy, and the Internet’s Missing Identity Layer]

One of the smokescreen reasons for wanting real names is trolling. I might think that it is my right as an Englishman to post abuse about the Chancellor of the Exchequer on The Telegraph web site, but others think that if I were forced to use my real name to log in then I would be more polite. I say smokescreen, because we don’t even have to guess whether a rigorously-enforced real names policy will make any difference to civility in online discourse, because we already know it won’t. What’s more, we know something else too: if you make people smear their “real” identities all over the internet because of such a policy, thus delivering the “over–identification” noted above, then that will make identity theft worse.

Korean sites were also inundated by hackers, presumably after valuable identities.

[From Surprisingly Good Evidence That Real Name Policies Fail To Improve Comments | TechCrunch]

The Korean case study shows clearly that a real names policy does not reduce trolling because the morons who troll are, well morons. Someone who posts racist abuse on Twitter, such as the noted association footballer Mr. Rio Ferdinand, really ought to understand that other people will read it and take offence since Twitter is a public communications channel (it’s not confined to football: look at the athletes sent home from the Olympics for sending racist tweets). What’s more, the real names policy does more harm than good, because it provides even more sources for the bad guys to obtain the real names that they need to commit other crimes. I read in the minutes of the recent Eurim meeting on the European Commission’s proposal for a regulation on electronic identification and trust services for electronic transactions in the internal market that

Identity fraud is the top enabler for all aspects of crime in Europe, and a major contributor to the Euro-crisis. The level of fraud in Europe last year was estimated at €500 billion, with an estimated €2 trillion for 2011-12. Europol have announced that unless this is addressed, they will be unable to contain crime.

I absolutely guarantee that a misplaced real names policy will make this worse. If you collect real names, things will always end up going wrong. You simply cannot assume that any information you give to organisations will remain private, no matter how well-intentioned.

Witnesses who complained about anti-social behaviour on a crime-hit estate were given police protection after a council error led to their personal details handed to troublemakers… Police are now patrolling a housing estate around the clock to protect the residents involved.

[From Council handed names of residents who complained about anti-social behaviour to trouble-makers – Telegraph]

Oh dear. Doesn’t sound like “real names” are working out too well in that case. Especially since there was no reason for the council to obtain the “real names” of the complainants. This is a case where “real attributes” are the key. The council needed to know that the complainants were council tenants living in a particular area. If we had an identity infrastructure befitting a modern economy (we don’t) then the tenants would have been able to submit their complaint by smartphone and have the text followed by a blinded cryptographic token attesting to their status but from which it would be mathematically infeasible to determine their identity. So no matter what the berks at the council do, the identities reman secret.

One thing that might really help the real names nutters, by the way, is making it easier to spot what are actually real names. If I create a Facebook profile as Theogenes de Montford, for example, how do you know whether that’s a real name or not? It would help if there were a relatively short list of real names, so I suggest that Facebook puts some lobbying money into Sweden.

Activists are lobbying for parents to be able to choose any name for their children (there are currently just 170 legally recognized unisex names in Sweden).

[From Hen: Sweden’s new gender neutral pronoun causes controversy. – Slate Magazine]

This seems like an odd story until you realise that in Sweden can you only choose a legally-approved name for your child. Sensible policies for a better interweb: Facebook should make a list of allowable real names and make you choose a combination of them. That way, any disloyal subject of Her Majesty trying to post abuse about the Chancellor of the Exchequer using a made up name could be instantly spotted and blocked.

P.S. In case you’re interested, Theogenes de Montford is indeed a real name.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2012/08/real-names-real-problems/feed/ 1
Friendly fire http://tomorrowstransactions.com/2012/07/friendly-fire/ http://tomorrowstransactions.com/2012/07/friendly-fire/#respond Mon, 23 Jul 2012 20:21:04 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/07/friendly-fire/ [Dave Birch] Some time ago, in the early days of Twitter, I happened to be involved in some work concerning a financial institution’s social media strategy. I was rather rude about the idea of setting up a Facebook page, because I couldn’t see the point, but it was nothing to do with me or any of the other technical persons. I was reminded of this episode this morning, when I read about another organisation’s Facebook-related travails.

It wasn’t long before Barclays’ Facebook page devolved into a minefield of jokes lambasting the company, which only served to highlight the socioeconomic rift between the banking institution and its customers.

[From Epic Fail: Barclays’ Facebook Debacle Highlighted the Chasm Between the Bank and Its Customers]

Well, given current circumstances this is hardly unexpected. As a naturally curious person, I thought I’d go and look at a few bank Facebook pages to see what sort of things they did. But I gave up almost immediately, since I realised that I’d have no way of knowing which of them might be real or not. Here’s what I got when I searched for Lloyds, for example. Real? Who knows. It’s certainly boring enough to have come from a bank, but that’s not much of a clue. Still, given Facebook’s noted “real names” policy, it probably is true and I’m sure it’s safe, just like the NatWest page that I found. I went to the Barclays Online Banking Facebook page and I couldn’t even work out what it was. This Barclays’ page looks quite plausible, but as a security-concious consumer I wasn’t sure whether to click on anything or not. Perhaps the British Bankers’ Association has some list of the real Facebook pages. I’ll check.

In the meantime, I expect that if I call NatWest they can point me to the their public key certificate that I can use to check the digital signature on the Facebook page so that… no, just joking. But all of this begs a more general question. What was the Facebook page for? What could customers do? Open accounts? Send money? Pay bills? No. As is generally true of Facebook pages for financial institutions, it was all about communications. There’d be no point a bank e-mailing my kids since they never read e-mail, so I suppose if you could persuade them to “friend” your bank you might be able get the odd status update into their field of vision.

At the Credit Suisse Research Institute 2012 meeting, experts discussed the benefits of social media over traditional communication tools, as well as the constraints – the most significant of which regards the current regulatory environment.

[From Credit Suisse – Banking on Social Media]

In fact, all of this potentially interesting discussion was actually about marketing. I’m no expert on marketing or social media, but I would imagine that the key to social media strategy is interaction and the whole web 2.0 thang about user-generated content and such like. For any organisation to just use a Facebook page to broadcast marketing messages seems like a missed opportunity for a richer connection with customers. If this is the right line of thinking, then the strategy ought to consider what customers might actually want to do in that context. For banks, I suspect that what they want to do is transact. What about the benefits of social media over traditional transaction tools? As I’ve said before (many times)

I’m naturally more interested in social media for transactions: social commerce.

[From Friends and relations]

I’ve bored some of our clients about this enough over the last couple of years, and I won’t rehearse the arguments here, but I will say that I think there’s evidence that the social commerce approach for financial institutions is sound. Customers want to do banking in their context and given that their context is increasingly within social media, it makes sense to move banking there.

Facebook announced that it is testing an online-banking service with Australia’s Commonwealth Bank expected to debut this year. The new system lets people make payments to other Facebook users, and will become a test of how well Facebook can handle the deep-science realities of financial privacy and security.

[From Facebook Announces Online-Banking Test – Forbes]

If Facebook do crack the privacy and security side of things, then they will become the route to banking for a great many consumers, frankly, and I don’t know whether financial organisations of all kinds have yet developed an effective strategy to deal with social media gatekeepers other than to pay them. Perhaps if their products and services could develop a direct relationship with the customer using social media channels (rather than simply provide those products and services inside the social media context) then they can become valued by customers.

I don’t want to be friends with my bank—after all, I’m a typical consumer so I hate banks—but I do want to be friends with my bank account.

[From Friends and relations]

My Barclays mobile banking app works really well and I can’t imagine any circumstance under which I’d bother going to their Facebook page, even if I could work out which one it is, but I might be tempted to venture outside the app if for richer social media interaction. At the moment Barclays interaction with me is basically limited to alerts by text message, which is fine, but does waste their money as well as limiting the amount of information. I’d rather have richer data sent through Twitter or as Facebook updates or whatever. Why can’t I have every transaction on any of my accounts sent through to me? 

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2012/07/friendly-fire/feed/ 0
I’m authentically not real http://tomorrowstransactions.com/2012/04/im-authentically-not-real/ http://tomorrowstransactions.com/2012/04/im-authentically-not-real/#comments Wed, 25 Apr 2012 17:41:26 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/04/im-authentically-not-real/ There’s no need for Facebook to know who I “really” am

]]>
[Dave Birch] The whole “identity thing” has been obsessing me because I’ve been invited to give my first TEDx talk at TEDxSussexUniversity later this week and I decided to talk about identity. I thought I’d try my PsychicID idea out on a different (i.e., not identity specialists) audience to test it out further. As far as I’m concerned, the need for it is growing.

According to Sheryl Sandberg, Facebook’s chief operating officer, and Richard Allan, its director of policy in Europe, a critical mass of people only want online interactions supported by “authentic” identity.

[From Online identity: is authenticity or anonymity more important? | Technology | guardian.co.uk]

They’re not even wrong about this. Authenticity and anonymity are not on the same axis. My Facebook profile is entirely authentic, it just doesn’t share my mundane non-unique sort-of-identifier (i.e., name). So what? Why would anyone need to know that my Facebook profile is in my “real name”? Well, apart from people who want to harass children, for example…

In an recent investigation, the TV station MSNBC found that many university sports departments now require students to “friend” their coach, giving officials access to their “friends-only” posts.

[From 12-year-old US girl suing school over Facebook comments row – Telegraph]

It’s really interesting to see how the “etiquette” around this is evolving. I picked up on it a few years ago and had the feeling then that the way the Facebook generation see identity will redefine they way society as a whole will come to see it in time, which is why attempts to force “old” identity notions on to them are doomed.

The kids aren’t stupid: they live in that world and they can distinguish their multiple virtual identities. Faced with a privacy violation that undermines a virtual identity, they slash and burn.

[From Digital Identity: Bring it on]

Quite. And why shouldn’t they? Why shouldn’t I have two Facebook identities, one for my work friends and one for my friends and family? And if want them to be able to connect me, then that should be up to me. I can easily have an identity that is authentic and anonymous.

The issue here isn’t anonymity. It’s privacy. Facebook should be looking at ways to deploying Privacy Enhancing Technologies (PETs) as part of its fundamental infrastructure. This is at the heart of my view of digital identity: that the only way to meet the requirements for security and privacy is stop seeing them as opposites or countervailing forces to be balanced, but as the simultaneously achievable goals of a properly designed identity infrastructure.

Many people do think eID could and should be implemented without full identification, i.e. more granular disclosure with pseudonymity – see e.g. Dave Birch’s brilliant and very readable paper “Psychic ID: A blueprint for a modern national identity scheme” (PDF).

[From Tech and Law: PETs – Stephan Engberg’s response]

So this is what I’m going to talk about on Friday: why Dr. Who should be our national design authority for identity infrastructure for 21st century because Dr. Who (and not Martha Lane Fox or the Cabinet Office) has a narrative about the future of identity, authentication and credentials that everyone can understand and buy into. And he’s already shown us that he uses NFC. We’ll see how it goes.

But back to the problem space. If my Facebook profile is the name of Ziggy Startup, and all my friends know this, then what’s the problem? It’s not really anonymous is any sense: if Ziggy Startup starts making off illegal posts, then it won’t take long for the police to get a warrant for the IP address and password and Ziggy will be off down the nick.

A man was jailed yesterday for posting videos and messages mocking the deaths of teenagers including a girl who threw herself under a train.

[From Internet ‘troll’ jailed for mocking dead teenagers on Facebook – Telegraph]

These people are pathetic, revolting and deserve the appropriate penalties, but they’re not a reason to make a fundamental and unrecoverable mistake in the design of the future online world. Since we don’t have a national narrative around the future of identity, it’s been abandoned to competing national security and commercial imperatives. Indeed, some observers would say that this is what’s really going on with all the fuss about “real” names at the moment.

Is it possible that free and expressive social logons will take over where bank and government identities have failed to interoperate? Or will the higher risk management standards of serious online transactions remain beyond reach of the cyber brands?

[From A new theory of digital identity – Networks – SC Magazine Australia – Secure Business Intelligence]

The battle over “authentic” identities is a power struggle. If the social networks are able to enforce it (I’ve no idea how they might do this, but let’s say they can) then they have a fantastic business opportunity because they will be able to leverage their arbitrage around personal data even further: how much more will advertisers pay for a list of people interested in whatever-the-f**k-it-is if they get the real identities too? If you know who everyone is, then you have much less risk to manage anyway. But the nightmare (for my clients anyway) is that they’ll end up having to offer Facebook Connect as a login otherwise they get no customers, and then Facebook know exactly what customers are doing all of the time.

On the one hand, I think good for them. The banks are doing nothing sensible in this space: they are messing around with one-time-passowrds by SMS, EMV-calculators thingies and a variety of incompatible dongles, when they should be working on an industry standards-based infrastructure. But is it good for us to abdicate responsibility for identity infrastructure and hand the whole thing over to Facebook?

I love Facebook. I use it many time every week to keep in touch with friends and family. What they should be doing is introducing optional 2FA (to end the problem of “fraping”, for one thing) and moving to an NSTIC framework to accept identities from identity providers that meet certain standards. So if I turn up at Facebook with a Barclays identity that says I’m Ziggy Startup, then that should be fine. Facebook don’t need to know who I am, all they need to know that someone knows who I am. If they insist that they need to know my “real name”, then it’s because they expect to exploit this for commercial opportunity – it has nothing to do with protecting children.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2012/04/im-authentically-not-real/feed/ 1
Frenemy of the state http://tomorrowstransactions.com/2012/03/frenemy-of-the-state/ http://tomorrowstransactions.com/2012/03/frenemy-of-the-state/#respond Fri, 16 Mar 2012 09:02:23 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2012/03/frenemy-of-the-state/ People thinking that social media identities are real is a real problem, the identities being false isn’t

]]>
[Dave Birch] More on Facebook’s “real names” nonsense. Their S1 filing admits to 1 in 20 bogus accounts, but who knows what the real figure is. None of my Facebook accounts are in my “real name” and I doubt I’m the only one.

“There may be individuals who have multiple Facebook accounts in violation of our terms of service, despite our efforts to detect and suppress such behavior. We estimate that false or duplicate accounts may have represented approximately 5-6% of our MAUs as of December 31, 2011.”

[From Major Changes In Facebook’s Amended S-1: Mobile Ads, Zynga, Yahoo Patents, Credit | TechCrunch]

I don’t really care about this, except for the fact that if people believe that Facebook, or any other online space is a “real name” space, then that does more harm than good because people who don’t really understand how all of this works could be misled and I can see how that might lead to problems. Still let’s hope that some people (e.g., sex offenders) do use their real names…

A new app will let you check all your Facebook friends against the National Sex Offender Registry.

[From Are Your Facebook Friends Sex Offenders?]

This isn’t all about dating scams, crime and teenage bullying. It’s national security as well. How Facebook know whether someone’s name is real or not I have no idea, and I certainly don’t believe for one moment that they are capable of distinguishing agents of foreign powers from “legitimate” users. Nor, for that matter, is anyone else.

NATO’S most senior commander was at the centre of a major security alert when a series of his colleagues fell for a fake Facebook account opened in his name – apparently by Chinese spies

[From How spies used Facebook to steal Nato chiefs’ details – Telegraph]

I read this with a certain nostalgia. When I worked at the Supreme Headquarters Allied Personnel Europe (SHAPE) Technical Centre in the Hague in the early 1980s, my first day on the job began with an extensive lecture on the security responsibilities attendant on our clearance level. I was working on a project concerned with keeping secure communications networks up and running in the event of a Russian nuclear attack, which was quite interesting, and once we had been sternly advised to be wary of beautiful tall blonde Eastern European women striking up conversations with us in supermarkets, I spent literally every waking hour of my young life praying for this to happen. It never did, but if there are any beautiful tall blonde Eastern European women who have any interest in white-noise jamming of direct sequence spread spectrum satellite channels, here are my contact details:

STC Card

My point: people are misled by the social network environment and so they make poor decisions. We already know that men will do almost anything if asked to by an attractive woman:

The story also revealed another sad truth, a reflection on human nature. Men will do anything for an attractive woman, without even bothering to check whether she’s real or not.

[From Digital Identity: Linked]

And we already know that woman will do anything for a handsome non-existent soldier. Absent a working identity infrastructure, we really shouldn’t let people meander along under the impression that social media identities a real. Which, by the way, did make me wonder about the wisdom of publicising the NATO story. Wouldn’t it have made more sense to to pretend to go along with the “Chinese spies” and feed them misinformation rather than let them know that you had blown their cover. Haven’t these NATO guys ever read “The Zimmerman Telegram“? I thought this was high up on the reading list for anyone entering a career in a security-related profession. It would be have been infinite to friend the American brass with a convincing bogus Ahmadinejad and then start posting stuff about shipping centrifuges to Tibet and such like.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2012/03/frenemy-of-the-state/feed/ 0