Reviews and reviewers

[Dave Birch] There’s a long running debate going on about whether people should be able to post online without disclosing their “real” identity. This is getting especially heated around online review sites. Remember this row — one of many — about� Trip Advisor?

He said he is considering suing the site over what he claims is a “dishonest” review published about one of his hotels and accused the internet giant of trying to “bully” him into silence using threatening letters

[From� Duncan Bannatyne to campaign against 'cowardly' trip adviser - Telegraph]

Look, review sites aren’t going to go away. And they are a good thing. I happened to be talking about reviews to my wife yesterday. She regularly uses a particular web shop to buy all the usual household stuff that neither of us can be bothered to go to the shops for: in yesterday’s case, a new mop for the kitchen floor. She uses that particular site precisely because it publishes bad reviews as well as good ones. When she last looked for a new mop, the one she looked at had very bad reviews. Yesterday, she looked again and there was a new mop, with good reviews. So she bought it. How can you trust good reviews unless you see the bad ones as well?

We need review sites: they are way to make a market more transparent and improve the quality of goods and services. Therefore, making the reviews work is important. How do you do this?

Here’s a question to get the thinking underway: if you let people post under assumed names, will they post rubbish? Can you trust a review site where you don’t know who anyone is either, whether they are astroturfing for corporate puppet masters or opening up information for the people? I travel a lot, so I post a lot on Trip Advisor. But I don’t post under my “real” name – I don’t see why who I am is material. Consequently, I was most interested to read a thorough corroboration of my theory that a pseudonymous interweb is a better interweb.

The platform, which enables people to comment across multiple websites via the same identity, has just released data showing that pseudonymous participation is actually the healthiest type.

[From� Disqus data shows pseudonymous commenters are best « Mariamz]

Well, well. I can think of many reasons why this is true (one of the main ones being that people reveal their real likes and dislikes, prejudices and opinions, views and perspectives under pseudonyms whereas they are alway constrained when using their “real” names) and it certainly matches with my experiences in online chat and debate environments.

Personally, whether it’s positing abusive messages about government ministers or arguing about the merits of a return to the gold standard, I always use pseudonyms unless I am posting in a professional capacity, in which case (I  sincerely hope) my expertise and experience is relevant to the discussion at hand. In some cases I use the same pseudonym across multiple sites, in other cases I use a specific pseudonym.

Pseudonymous identifiers are random identifiers that change for each relying party (so my identity at relying party A might be 123 while my identity at relying party B might be 345). Good pseudonymous identifiers are large random values (so that they are unpredictable) and are not reused across multiple users (so the same identifier is never used at different relying parties for the same or different users).

[From� Conor's Web Log of Esoterica: Pseudonymity would help]

Right. So pseudonyms deliver the best online interaction. But, I will hear you say, who can this scale? With interaction through pseudonyms, there will always be people — even if a tiny minority — getting up to no good. What if you are small business and you get a review like this?

The review said: “Robbed My RAM and Touched 9 Year Old What a scam artist, he stole RAM from my computer and replaced it with smaller chips hoping I wouldnt notice and also I later found out touched my 9 year old inappropriately. A Violator and a rogue trader. DO NOT DO TRADE WITH THIS MAN!”

[From� BBC News - Google removes 'paedophile' claim on review website]

How can you take a civil action against someone for posting a defamation or libel or malicious accusation or whatever? How can you make sure that someone posting a review is actually a customer?

The solution is to institute a simple system of pseudonymous tokens — cryptographic tokens, I mean — so that you the customer can only post a review of something if you have a token showing that you used it, and it should take a court order for the token provider to reveal the person who had the token. This is technologically trivial and can easily be achieved using well-known and well-understood techniques for cryptographic “blinding”. A “blinding” service would work something like this: when you register at the hotel, the hotel chain e-mails you a URL. Later on, you log in to that URL and the system generates a “blinded” token that the hotel chain digitally signs and sends back to you. Whereupon you unblind it. To write a review, you must submit the token. The review site can easily check the digital signature from the hotel chain that proves that you did stay at the hotel during the previous month (or whatever) but doesn’t link to your identity. The hotel can be sure that you were a customer, but neither they nor the review service know who you are. If you post something that is against the law, a court can then order the blinding service to turn over the connection.

It’s not only review sites that might make use of such a service because there are many sites where� who you are is material to the discussions and there may be not entirely honest reasons for using a pseudonym.

The chief executive and chairman of cashless payments vendor USA Technologies has resigned over “inappropriate” comments he posted on the Yahoo Finance message board… George Jensen posted approximately 450 comments on the forum, primarily under the alias ‘investor.texas’.

[From� Finextra: USA Technologies CEO quits over message board posts]

Which reminds me of something. A linguistic clarification to distinguish between pseudonyms (which are identifiers) and personas (which are bundles of attributes around an identifier). Robin Wilton is surely right to insist that there is a difference

However, a persona can also consist of a number of attribute assertions (“I am male, single and over 20″), without containing either a ‘genuine’ identifier (Kal-El) or a pseudonymous one (Clark Kent) – therefore I maintain that personas and pseudonyms as distinct rather than identical.

[From� Racingsnake -
the blog of Future Identity: Liberty, pseudonymity and personas
]

Personas may use anonyms, pseudonyms or absonyms. But I’m having second thoughts about the word “absonym” that I made up to mean the “real name” of something. It bothers me that the derivation mixes Latin (“absolute”) and Greek (“name”). I’m wondering about going all Greek with “alethnym” (“true name”) or just going for something that mixes more wildly but sounds better (such as “pravdanym” using Russian or “verinym” trimming the Latin “veritas” or “emenym” abusing the Hebrew “meet” and simultaneously evoking the stage name “eminem” to get down with the kids). Suggestions?

Anyway, you get the idea. Technology has a solution to a real societal problem. Perhaps the way to actually get something done would be to put forward that solution, using existing technology, but inside the kind of framework envisaged in the NSTIC. It would be easy for a US newspaper, say, to require commenters to have a digital identity from a US provider. These digital identities should be pseudonymous as a default: thus, I can post political comment or hotel reviews or jokes about celebrities or whatever. If I actually libel someone (under proper libel laws, not the UK’s libel laws) then someone can get a court order to ask the identity provider to reveal the digital identity that they were provided with (this, of course, may in some circumstances be another pseudonym).

Here’s a simple example: let’s say that my mobile operator were to give me the identity “citizendave”. I go around logging in to various web sites as citizendave using the mobile handset as part of a 2FA process. Now suppose I log in somewhere and post a libel. The target goes to court and gets an order: this is delivered to O2 (digitally-signed by the Attorney General, naturally) and O2 will then return my name and billing address. Without the court order, cryptography means that no-one can find out who citizendave is. This seems like a reasonable accommodation.

By the way, this is a serious issue – it’s not all about people writing abusive hotel reviews. A couple of years ago Bob Gourley, the former CTO of the U.S. Defense Intelligence Agency, summed the issue up as fundamental and important question about the future identity infrastructure. He said:

We must have ways to protect anonymity of good people, but not allow anonymity of bad people. This is going to be much harder to do than it is to say. I believe a structure could be put in place, with massive engineering, where all people are given some means to stay anonymous, but when a certain key is applied, their cloak can be peeled back.

[From� A CTO analysis: Hillary Clinton's speech on Internet freedom | IT Leadership | TechRepublic.com]

What should be done? I saw this in a comment on an article about the internet and anonymity.

If we create a technology that allows one person, in the privacy of his living room, to create multiple identities to ruin a person or business, then we should create a legal mechanism to allow victims with the same ease to stop it.

[From� Anonymity and the Dark Side of the Internet - NYTimes.com]

I think this is, essentially, correct. I was listening BBC Radio 5 yesterday and there was a story about a woman whose life was ruined by an ex-boyfriend impersonating her online (it’s not that difficult to pretend to be someone on IM or whatever) and how hard it was for her (or the police) to stop it. So there is a real need to get on and so something about this but not in the privacy-destroying North Korean-style “you have to show a passport to log on” way that will lead to disaster.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

I love the way they think

[Dave Birch] The subject of identity infrastructure came up again yesterday and this led on to a discussion about banks, identity providers, attribute providers and business models. When we are thinking about identity infrastructure in the mass market, a very simple identity vs. attribute example often comes to mind. It’s the apparently simple case of age verification: how do you prove to a web site that you are over 18 or to an bar in the US that you are over 21 or to a bus company that you are over 65, or whatever. I think this is a pretty reasonable measure of how a system intended for the general public is going to work. Talking about this in the meeting, the example of Facebook came to mind, where there is an utterly prosaic, immediate and important use case. You have to be 13 to exist on Facebook.

Now, one interesting question is… why? Why do Facebook ban under-13s? I mean why not under-18s? or under-12s? I mean 13 sounds rather arbitrary and there’s no obvious reason for it that springs to mind. So I began to look for a rational reason for this, thinking that it was a Facebook policy. But it isn’t. The reason for this abitrary and capricious age boundary is, as I should have suspected, a consequence of government regulation of the interweb tubes.

Internet companies have set up the rules against under-age users because they must comply with the federal Children’s Online Privacy Protection Act (COPPA), passed in 1998, which says web sites that collect information from children younger than 13 must obtain parental consent.

Obtaining that consent is complex and expensive, so companies like Facebook and Google, which owns YouTube, reject anyone who tries to sign up using an age below 13.

[From� Facebook Users Who Are Under Age Raise Concerns - NYTimes.com]

Unusually, across the spectrum of wise political steering in cyberspace, this legislation has not turned out precisely how the politicians and lobbyists intended.

The Children’s Online Privacy Protection Act is a well-intentioned piece of legislation with unintended consequences for parents, educators, and the public writ large. It has stifled innovation for sites focused on children and its implementations have made parenting more challenging.

[From� danah boyd | apophenia » Why Parents Help Children Violate Facebook’s 13+ Rule]

I realise that Facebook-13 seems like a very particular and specific issue, but I think it is entirely representative of a class of problems in the new, online world. The way that people talk about this issue illustrates—I would at least postulate—how they think about stuff like online identity at a deep level and is a rather useful guide to technologists and legislators.

In Victoria’s fifth-period honors English class, all 32 students said they had faked their birth year to gain access to one site or another… Jerry Ng, Victoria’s 14-year-old cousin, agreed. “It’s one thing to lie to a person,” he said. “But this is lying to a computer.”

[From� Facebook Users Who Are Under Age Raise Concerns - NYTimes.com]

I love this comment, which is utterly revealing about how the so-called “screenagers” think about the world. A new ethics, discontinuous to our pre-post-industrial moral paradigm. Talking of which, perhaps an alternative to a sophisticated modern identity management system and the new mental models to with it is simply to clear the plebs off the playing field.

The Pope has warned of the dangers of social networking sites such as Facebook and MySpace, saying that communication between people online must not stop face-to-face conversations.

[From� Pope warns Facebook can’t replace human contact - Telegraph]

There’s a heritage to this kind of pedagogical panic.

Similar concerns arose in the 18th century, when newspapers became more common. The French statesman Malesherbes railed against the fashion for getting news from the printed page, arguing that it socially isolated readers and detracted from the spiritually uplifting group practice of getting news from the pulpit.

[From� A history of media technology scares, from the printing press to Facebook. - By Vaughan Bell - Slate Magazine]

God knows what he would make to the newspapers I saw at Woking train station this morning. The front pages included a splash about whether bread is bad for you, voyeuristic photographs up a female pop star’s dress (I think she was a pop star – I didn’t recognise the name or, for that matter, anything else) and something about the X-Factor. All this at time when the eurozone is in crisis and people are being machine-gunned on the streets of Syria. But back to Facebook.

Whether Facebook is responding to changing social norms or, in fact, leading the charge is an unresolved question

[From� FT.com / FT Magazine - Facebook’s grand plan for the future]

This is very important question. I think that people are disoriented about post-industrial society and confused about the fractal online/offline (or� virtual/mundane) boundary. Facebook provides a way to think about some of these things. I don’t think it’s right to say that it it “leading” the change but I think it is fair to say that until a new model emerges, Facebook will continue to provide a kind of substitute. I think that we should have an identity infrastructure that does not have a mundane analogue, where you can prove that you are an adult or a child without disclosing who you are and that this should be the basic test of fitness of any proposed solution. At the moment, Facebook doesn’t provide this, because it’s still trapped in industrial age identity thinking.

Facebook insists on what it calls authentic identity, or real names. And it is becoming a de facto passport vendor of sorts, allowing its users to sign into seven million other sites and applications with their Facebook user names and passwords.

[From� Rushdie Wins Facebook Fight Over Identity - NYTimes.com]

I’m sure it does. But doesn’t this have dangers associated with it?

The information leak can be exploited by social-engineering scammers, phishers, or anyone who has ever been curious about the person behind an anonymous email message. If the address belongs to any one of the 500 million active users on Facebook, the social-networking site will return the full name and picture associated with the account.

[From� Facebook bug spills name and pic for all 500 million users • The Register]

Yet another good reason for not having your Facebook account your real name, as indeed I don’t (for either of my accounts). My point is that what Facebook has now isn’t the identity infrastructure we need for the information age, but unless someone else gets to work on building it, we’ll end up with what Facebook has and we’ll be stuck with it.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers


These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Friends with things

[Dave Birch] I enjoyed the presentation that Christophe Langlois (Visible Banking) gave to the Financial Services Club in London and particularly the enjoyed the question and answer session afterwards. Christophe was talking about banks’ use of social media and was comparing and contrasting some different approaches that explored further in his new book “Customer Experiences without Borders” (which I won a signed copy of at the event, hurrah!). During the question and answer session, I made the point about the mismatch in the use of social media.

I don’t want to be friends with my bank—after all, I’m a typical consumer so I hate banks—but I do want to be friends with my bank account. Why can’t Barclays let me friend my current account so I can see its status updates like “Premium card fee £10.00”, “Direct Debit British Gas £37.85” and “Counter Credit £5.00” and so forth?

[From� Friends and relations]

This is a point that I amplified in Retail Banker Interactive, finishing up with plea.

So a plea to my account, card and service providers: I don’t want to be friends with you, because you are corporations and not mates, but I do want to be friends with my stuff: my money, my cards, my phone. How hard can it be?

[From� Social media is not just another communication channel - Blogs - Retail Banker Interactive]

A discussion about this continued over drinks, and I am indebted to David Harris from� salesforce.com for bringing a fascinating example to my attention. Apparently, Toyota are going to have a system whereby you can be friends with your car, which is a great idea.

For example, if an EV or PHV is running low on battery power, Toyota Friend would notify the driver to re-charge in the form of a “tweet”-like alert. In addition, while Toyota Friend will be a private social network, customers can choose to extend their communication to family, friends, and others through public social networks such as Twitter and Facebook.

[From� Toyota USA Newsroom | Salesforce.com and Toyota Form Strategic Alliance to Build ‘Toyota Friend’ Social Network for Toyota Customers and Their Cars]

So your friends could be friends with your car too. You might wonder why anyone would want to do this, but consider this: my sister has borrowed my wife’s car for a couple of days while she goes looking for another car, so it would be great if my sister could be friends with my wife’s car (and it would make sense for me to be friends with my wife’s car and vice versa) for a time.

What I’m not sure about is if I would want these connections to be in my hilariously-entitled “real name” or via a network like Facebook. I’m not paranoid, but I don’t want to be bombarded with crap all the time because Facebook has noticed that one of my brake pads is wearing a little thin and has sold this information to a hundred different brake pad companies around the world. And I’m sure it will only be a matter of time before some guy tracks down and murders his ex-girlfriend because she forget he was friends with her car so knows where she is.

There’s a layer of infrastructure missing here and I hope that the Cabinet Office’s Identity Assurance Programme that we were discussing yesterday is going to take this into account. They’ve finally got a budget so I hope that some of the input from the Working Groups can now be acted on.

Cabinet Office minister Francis Maude has earmarked £10m for implementation of the government’s Identity Assurance (IDA) programme,

[From� Government earmarks £10m for Identity Assurance and targets over £500m savings - 10/31/2011 - Computer Weekly]

So what has being friends with my bank account got to do with the Cabinet Office? We need an identity infrastructure for things as well as for people. I need to delegate permission to access my wife’s car to my sister just as I need to give permission for my sister to be friends with my wife’s car for a while. Right now, there’s precious little security around people, but even less around things, largely because the “internet of things” wasn’t designed with security in mind.

Typically, the person who designs the embedded software system for a car or a power grid system or a generating system are engineers who learn programming maybe as part of their engineering course, but they are not trained computer scientists or computer engineers. The point is that someone whose primary job is understanding control theory is not someone who knows anything about software vulnerabilities.

[From� The internet of things | Interviews | Opinion, News, Analysis | BCS - The Chartered Institute for IT]

If this sounds esoteric, it isn’t. It’s a real issue that should be taken seriously as input to the deployment of devices right now. Here’s a straightforward example from Rob Bratby.

The deployment of smart meters is one of the most significant deployments of what is often described as ‘the internet of things’, but its linkage to subscriber accounts and individual homes, and the increasing prevalence of data ‘mash-ups’ (cross-referencing of multiple databases) will require these issues to be thought about in a more sophisticated and nuanced way.

[From� Watching the connectives | A lawyer’s insight into telecoms and technology]

So I should be able to make friends with my electricity meter and under some circumstances I might need to be friends with my father’s electricity meter but I don’t want burglars and ne’erdowells to be friends with it. It seems to me that we already sort of know how to do this sort of thing: we understand public / private key pairs, tamper-resistant stores for private keys, certificates, selective disclosure and everything else. But we’re going to end up using Facebook Connect, because it’s all too complicated for the marketing people to understand and we haven’t yet found a way of explaining it to them.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers


These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Friends and relations

[Dave Birch] While I was sitting through a presentation (a very good presentation, I might add) on social media strategy for one of our client's financial services business, it struck me that they were slightly misjudging the more interactive and transactional nature of social media, doing great stuff but treating social media as another customer communication channel. I'm naturally more interested in social media for transactions: social commerce. I've given a couple of talks about this recently, pointing out the opportunities that social commerce opens up.

One prediction says social commerce will top $30 billion globally by 2015 with Facebook-generated sales one of the primary drivers.

[From Infographic: The history of F-commerce | SMI]

There are many different ways that financial services organisations can exploit this. A good example, to my mind, is the way in which Amex works with Foursquare.

Just after announcing that it passed 10 million users, location-based check-in service Foursquare has said it is partnering with American Express to give members even better deals when they check in at merchants’ stores across the country.

[From Foursquare partners with American Express for deal check-ins | VentureBeat]

This is a terrific proposition and it's well implemented (through statement credits, so no coupons or vouchers or anything are needed). And, to follow this example, Amex also has a Facebook pages where its large number of fans can come to learn about products and services, share with the community of card holders and so on. Great stuff. And it isn't only financial services organisations that are integrating themselves into social media to create new kinds of social commerce.

That is because the well-known mobile service provider is now allowing its customers to log on to Facebook to purchase phone credit.

[From O2 details new contactless payment technique]

Wow, that's pretty interesting.

Pre-paid subscribers will now be able to access a secure app on the social networking website, where they will put in credit card details in order to purchase top ups.

[From O2 details new contactless payment technique]

Credit card details? Not Facebook credits? But you get the picture. Something like Facebook can be used to create a more intimate transactional environment without having to develop software, making it easy for consumers to "friend" and "like" and so forth. Personally, I don't find this sort of thing particularly appealing because to me it's the wrong kind of social relationship: I want something more granular.

Here's what I mean. I don't want to be friends with my bank—after all, I'm a typical consumer so I hate banks—but I do want to be friends with my bank account. Why can't Barclays let me friend my current account so I can see its status updates like "Premium card fee £10.00", "Direct Debit British Gas £37.85" and "Counter Credit £5.00" and so forth? I quite like the text messages that Barclays sends me but would prefer something more immediate and more detailed (I often call this "streaming commerce") so that I can make decisions and respond.

Similarly, I don't especially want to be friends with MBNA, but I do want to be friends with my MBNA American Express card. If i see a status about about my payment being use, that would be really useful. If I see a status update from my card that appears to have gone on holiday to Kazakhstan while I'm in Peckham, I can press a button somewhere and get straight through to lost and stolen cards. I wouldn't mind if the status updates where now and then promotional messages instead of transaction reports, that would be handy. It would due like my friend telling me that there's double reward points in Sainsbury's today, so something like that. I'm using "friend" generically, of course, I don't mean to imply that Facebook is the one and only way to implement a social media strategy.

Facebook usage in the UK fell nearly 4pc in July to its lowest level since 2009, sparking concerns that the social network has hit its peak and may be declining in popularity.

[From Facebook usage falls to three-year low - Telegraph]

I don't use Facebook that much—it's really for sharing with my brother and sister, other family members and a few old friends—and I've not got a crystal ball to see whether we'll still be using it in a couple of years.

Many of the smartest people I know are leaving Facebook as well. I predict we’ll see many people leaving over the coming months and adopting Twitter.

[From The Facebook Exodus and the Future of Human Communication « Far Beyond The Stars | Cyborgs, second selves and cybernetic yogis]

My idea would work even better with Twitter. Suppose Barclays knew my twitter name—maybe they could ask me when I log in for home banking and get permission to send tweets to me—and connected it to my bank account. Now, whenever Barclays gets a new follower on twitter it can scan it's customer database to find out if that twitter name belongs to a customer. If it does, they can starting sending out all status changes as Direct Messages (DMs). That would be simple and great.

I'd love to follow my John Lewis MasterCard on Twitter in this way instead of having to log in to find out what it's been up to. Since I use Twitter all day and every day anyway, it would be a much better channel for payment products to develop a more intimate relationship with me. And think of the practical benefits: if I get a tweet from my debit card telling me it's just been used to withdraw money from an ATM in Belarus, I can call Barclays right away to block it from further misbehaviour. This doesn't seem terribly complex: all Barclays need to know is my twitter name and then it can use the Twitter API to post tweets and only allow me to follow them.

If I could follow my transactional instruments, I could also (in time) feed their tweets, status updates, notifications and so on into other software for mash-ups. I don't know what kind of mash-ups – I'm not smart enough for that – but I'm sure there are people out there who could do great stuff with the data. So a plea to my account, card and service providers: I don't want to be friends with you, because you are corporations and not mates, but I do want to be friends with my stuff: my money, my cards, my phone. How hard can it be?

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

I’m certainly me

[Neil McEvoy] I’ve been at the EEMA e-Identity conference in Tallinn, Estonia. I’ve heard a lot of people say that relying parties need to know the ‘level of assurance’ that can be ascribed to someone’s claimed identity, or in some attribute associated with an identity. A somewhat stronger version of this that I’ve also heard is that they must know the ‘probability’ that a claimed identity (or attribute) is correct.

This leaves me perplexed. If I see a die that looks like a regular cube, I can postulate that there is a one in six probability that if I throw it once I will get a six. I have implicitly assumed a couple of things; that my vision is sufficiently acute to spot any irregularity in its shape, and that the die is of an even density (strictly speaking, that the distribution of mass has cubic symmetry). I can test my proposition by throwing the die (say) 96 times. If I get roughly 16 of each number, my confidence will be increased (in a way which can be quantified) that it is a true die and that my initial postulation is correct. The points here are that:

  • my assertion on the probability rests on a limited number of assumptions
  • it can be tested
  • the more tests I do, the more confidence I can have
  • the past is a reliable guide to the future.

None of these are the case when trying to assess the veracity of a claim to a certain identity. If you receive a bundle of bits that encodes ‘Neil McEvoy’ (with some ancillary bits that indicate that some process, designed to validate the claim to my identity, has occurred), you cannot know the probability that I caused that bundle to reach you. I either did or I didn’t; but the number of ways in which I might not have is not known to you—or anyone.  Neither would you generally be in a position to repeat the process a hundred times and check the number of times that it is me or isn’t me. And, even if you could, there is no way that you can be sure that the past experience is a reliable guide to the future.

If we want an analogy with a die, it is that you receive some bits from me that purport to represent one throw of one die. Now, a die may not have been thrown—I could have made it up. It may have been thrown and I reported the wrong number, by accident or design; someone may have told me to type ‘6’ while holding a gun to my head; someone may have tricked me by handing me a die with two sixes and no ones; someone may have stolen the credentials I use to ‘prove’ that I entered a report; someone may have broken the cryptographic algorithm used to sign the transmission; or, for that matter, some Rumsfeldian ‘unknown unknown’ may have occurred. I think it is pretty clear that the probability that a report reaching you is truthful cannot be calculated, nor divined by any experiment.

So what should a relying party want? Clearly, not to be told by a provider that they can provide electronic identities that are 99.9% truthful, for such a person is a fool or a knave. By all means, he should expect the provider to have confidence in his service; but that is worth nothing unless he puts his money where his mouth is. The provider who accepts liability and has the balance sheet or the insurance to meet any losses that might ensue from your reliance on a false claim, that they have endorsed, is the only one that is worthy of your business. They will have every incentive to employ cost-effective business processes and technical measures that will limit the necessity for meeting claims.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Technologist can’t square circles, but we can help

What do the politicians, regulators, police and the rest of them want us (technologists) to do about the interweb tubes? It might be easier to work out what to do if we had a clear set of requirements from them. Then, when confronted with a problem such as, for example, identity theft, we could build systems to make things better. In that particular case, things are currently getting worse.

Mr Bowron told the MPs this week that although recovery rates were relatively low, the police detection rate was 80 per cent. However, the number of cases is rising sharply with nearly 2m people affected by identity fraud every year.

[From� FT.com / UK / Politics & policy - MP calls cybercrime Moriarty v PC Plod]

So, again, to pick on this paricular case, what should be done?

Mr Head also clarified his position on the safety of internet banking, insisting that while traditional face-to-face banking was a better guarantee against fraud, he accepted that society had moved on. “If you take precautions, it’s safe,” he said.

[From� FT.com / UK / Politics & policy - MP calls cybercrime Moriarty v PC Plod]

Yet I remember reading in The Daily Telegraph (just googled it: 20th November 2010) there was a story about an eBay fraud perpetrated by fraudsters who set up bank accounts using forged identity documents, so face-to-face FTF does not, as far as I can see, mean any improvement in security at all. In fact, I’m pretty sure that it is worse than nothing, because people are easier to fool than computers. I would argue that Mr. Head has things exactly wrong here, because we an integrated identity infrastructure should not discriminate between FTF and remote transactions.

I think this sort of thing is actually representative of a much bigger problem around the online world. Here’s another example. Bob Gourley. the former CTO of the U.S. Defense Intelligence Agency, poses a fundamental and important question about the future identity infrastructure.

We must have ways to protect anonymity of good people, but not allow anonymity of bad people. This is going to be much harder to do than it is to say. I believe a structure could be put in place, with massive engineering, where all people are given some means to stay anonymous, but when a certain key is applied, their cloak can be peeled back. Hmmm. Who wants to keep those keys

[From� A CTO analysis: Hillary Clinton’s speech on Internet freedom | IT Leadership | TechRepublic.com]

So, just to recap, Hillary says that we need an infrastructure that stops crime but allows free assembly. I have no idea how to square that circle, except to say that prevention and detection of crime ought to be feasible even with anonymity, which is the most obvious and basic way to protect free speech, free assembly and whistleblowers: it means doing more police work, naturally, but it can be done. By comparison, “knee jerk” reactions, attempting to force the physical world’s limited and simplistic identity model into cyberspace, will certainly have unintended consequences.

Facebook’s real-name-only approach is non-negotiable – despite claims that it puts political activists at risk, one of its senior policy execs said this morning.

[From� Facebook’s position on real names not negotiable for dissidents • The Register]

I’ve had a Facebook account for quite a while, and it’s not in my “real” name. My friends know that John Q. Doe is me, so we’re linked and can happily communicate, but no-one else does. Which suits me fine. If my real name is actually Dave bin Laden, Hammer of the Infidel, but I register as John Smith, how on Earth are Facebook supposed to know whether “John Smith” is a “real” name or not? Ludicrous, and just another example of how broken the whole identity realm actually is.

For Facebook to actually check the real names, and then to accept the liabilities that will inevitably result, would be expensive and pointless even if it could be achieved. A much better solution is for Facebook to help to the construction and adoption of a proper digital identity infrastructure (such as USTIC, for example) and then use it.

The implementation of NSTIC could force some companies, like Facebook, to change the way it does business.

[From� Wave of the Future: Trusted Identities In Cyberspace]

That’s true, but it’s a good thing, and it’s good for Facebook as well as for other businesses and society as a whole. So, for example, I might use a persistent pseudonymous identity given to me by a mobile operator, say Vodafone UK. If I use that identity to obtain a Facebook identity, that’s fine by Facebook: they have a certificate from Vodafone UK to say that I’m a UK citizen or whatever. I use the Vodafone example advisedly, because it seems to me that mobile operators would be the natural providers of these kinds of credentials, having both the mechanism to interact FTF (shops) and remotely, as well as access to the SIM for key storage and authentication. Authentication is part of the story too.

But perhaps the US government’s four convenient “levels of assurance” (LOAs), which tie strong authentication to strong identity proofing, don’t apply to every use case under the sun. On the recent teleconference where I discussed these findings, we ended up looking at the example of World of Warcraft, which offers strong authentication but had to back off strong proofing.

[From� Identity Assurance Means Never Having To Say “Who Are You, Again?” | Forrester Blogs]

Eve is, naturally, absolutely right to highlight this. There is no need for Facebook to know who I really am if I can prove that Vodafone know who I am (and, importantly, that I’m over 13, although they may not be for much longer given Mr. Zuckerberg’s recent comments on age limits).

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Paleo-crypto

In some of the workshops that I’ve been running, I’ve mentioned that I think that transparency will be one of the key elements of new propositions in the world of electronic transactions and that clients looking to develop new businesses in that space might want to consider the opportunities for sustained advantage. Why not let me look inside my bank and see where my money is, so to speak? If I log in to my credit card issuer I can see that I spent £43 on books at Amazon: if I log in to Amazon I can that I spent £43 but I can also see what books I bought, recommendations, reviews and so on. They have the data, so they let me look at it. If I want to buy a carpet from a carpet company, how do I know whether they will go bankrupt or not before they deliver? Can I have a look at their order book?
Transparency increases confidence and trust. I often use a story from the August 1931 edition of Popular Mechanics to illustrate this point. The article concerns the relationship between transparency and behaviour in the specific case of depression-era extra-judicial unlicensed wealth redistribution…

BANK hold-ups may soon become things of the past if the common-sense but revolutionary ideas of Francis Keally, New York architect, are put into effect. He suggests that banks be constructed with glass walls and that office partitions within the building likewise be transparent, so that a clear view of everything that is happening inside the bank will be afforded from all angles at all times.

[From Glass Banks Will Foil Hold-Ups]

I urge you to clink on the link, by the way, to see the lovely drawing that goes with the article. The point is well made though: you can’t rob a glass bank. No walls, no Bernie Madoff. But you can see the problem: some of the information in the bank is confidential: my personal details, for example. Thus, it would be great if I could look through the list of bank deposits to check that the bank really has the money it says it has, but I shouldn’t be able to see who those depositors are (although I will want third-party verification that they exist!).

Why am I talking about this? Well, I read recently that Bank of America has called in management consultants to help them manage the fallout from an as-yet-nonexistent leak of corporate secrets, although why these secrets be prove embarrassing is not clear. In fact, no-one knows whether the leak will happen, or whether it will impact BofA, although Wikileaks’ Julian Assange had previously mentioned having a BofA hard disk in his possession, so the market drew its own conclusions.

Bank of America shares fell 3 percent in trading the day after Mr. Assange made his threat against a nameless bank

[From Facing WikiLeaks Threat, Bank of America Plays Defense - NYTimes.com]

Serious money. Anyway, I’m interested in what this means for the future rather than what it means now: irrespective of what Bank of America’s secrets actually are because

when WikiLeaks, a whistle-blowing website, promised to publish five gigabytes of files from an unnamed financial institution early next year, bankers everywhere started quaking in their hand-made shoes. And businesses were struck by an alarming thought: even if this threat proves empty, commercial secrets are no longer safe.

[From Business and WikiLeaks: Be afraid | The Economist]

Does technology provide any comfort here at all? I think it does. Many years ago, I had the pleasant experience of having dinner with Nicholas Negroponte, John Barlow and Eric Hughes, author of the cypherpunk manifesto, at a seminar in Palm Springs. This was in, I think, 1995. I can remember Eric talking about “encrypted open books”, a topic that now seems fantastically prescient. His idea was to develop cryptographic techniques so that you could perform certain kinds of operations on encrypted data: in other words, you could build glass organisations where anyone could run some software to check your books without actually being able to read your books. Nick Szabo later referred back to the same concepts when talking about the specific issue of auditing.

Knowing that mutually confidential auditing can be accomplished in principle may lead us to practical solutions. Eric Hughes’ “encrypted open books” was one attempt.

[From Szabo]

Things like this seem impossible when you think of books in terms of paper and index cards: how can you show me your books without giving away commercial data? But when we think in terms of bits, and cryptography, and “blinding” it is all perfectly sensible. This technology seems to me to open up a new model, where corporate data is encrypted but open to all so that no-one cares whether it is copied or distributed in any way. Instead of individuals being given the keys to the database, they will be given keys to decrypt only the data that they are allowed to see and since these keys can easily be stored in tamper-resistant hardware (whereas databases can’t) the implementation becomes cost-effective. While I was thinking about this, Bob Hettinga reminded me about Peter Wayner’s “translucent databases“, that build on the Eric’s concepts.

Wayner really does end up where a lot of us think databases will be someday, particularly in finance: repositories of data accessible only by digital bearer tokens using various blind signature protocols… and, oddly enough, not because someone or other wants to strike a blow against the empire, but simply because it’s safer — and cheaper — to do that way.

[From Book Review: Peter Wayner's "Translucent Databases"]

There are other kinds of corporate data that it may at first seem need to be secret, but on reflection could be translucent (I’ll switch to Peter’s word here because it’s a much better description of practical implementations). An example might be salaries. Have the payroll encrypted but open, so anyone can access a company’s salary data and see what salaries are earned. Publish the key to decrypt the salaries, but not any other data. Now anyone who needs access to salary data (eg, the taxman, pressure groups, potential employees, customers etc) can see it and the relevant company data is transparent to them. One particular category of people who might need access to this data is staff! So, let’s say I’m working on a particular project and need access to our salary data because I need to work out the costs of a proposed new business unit. All I need to know is the distribution of salaries: I don’t need to know who they belong to. If our payroll data is open, I can get on and use it without having to have CDs of personal data sent through the post, of whatever.

I can see that for many organisations this kind of controlled transparency (ie, translucency) will be a competitive advantage: as an investor, as customer, as a citizen, I would trust these organsations far more than “closed” ones. Why wait for quarterly filings to see how a public company is doing when you could go on the web at any time to see their sales ledger? Why rely on management assurances of cost control when you can see how their purchase ledger is looking (without necessarily seeing what they’re buying or who they are buying it from) when you can see it on their web page? Why not check staffing levels and qualifications by accessing the personnel database? Is this any crazier than Blippy?

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Virtual, like dollars

[Dave Birch] I keep coming back to the topic of virtual worlds, because I’m convinced that they contain some pointers about the future of our “real” economy, even thought the real/virtual boundary is getting rather blurred. Why are US Dollars called “real” when they are backed by nothing, whereas World of Warcraft gold pieces are called “virtual” because they are backed by nothing?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

I guess you didn’t read tomorrow’s papers, the elf gets fireballed this afternoon

[Dave Birch] Last week’s British newspaper headlines about a top snooker player offering to throw frames for large amounts of Eastern European cash is only the latest in a long and increasingly frequent series of sports betting scandals. You may, for example, have been following an interesting story coming from Asia concerning corrupt practices, illegal gambling rackets and other malfeasance in a major sport. No, not cricket’s Indian Premier League (IPL)…

Sports officials suspended the founding commissioner of a popular cricket league in India on Monday and asked him to respond to claims that he had rigged team auctions and improperly structured a broadcasting deal… The suspension is the latest development in what many analysts have described as the biggest scandal in Indian cricket since at least 2000, when several prominent players were accused of fixing matches.

[From Indian Premier League’s Chief Is Suspended in Cricket Scandal - NYTimes.com]

I’m not talking about the real world (as usual) but the virtual one. In Korea, there is a scandal just as big as the IPL one going on but it stems from people with broadband rather than balls.

The largest scandal in e-sports history is currently unfolding in Korea, with revelations that a number of current pro gamers are involved with match set-ups and illegal betting… the story is said to touch many A-list StarCraft celebrities – including sAviOr, Ja Mae Yoon – one of the best-known and most successful players of all time… At this stage, we hear that various pro gamers have been found intentionally losing matches, as well as leaking their team’s replay files to illegal gambling groups.

[From StarCraft cheating scandal rocks Korea « GamePron]

For those of you not familiar with the genre, Starcraft is a computer game from Blizzard (the same people behind World of Warcraft), but the players are spaceship pilots instead of wizards.

After its release, StarCraft rapidly grew in popularity in South Korea, establishing a successful pro-gaming scene. Professional gamers in South Korea are media celebrities, and StarCraft games are broadcast over three television channels dedicated to the professional gaming scene. Professional gamers in South Korea have gained television contracts, sponsorships, and tournament prizes, allowing one of the most famous players, Lim Yo-Hwan,to gain a fan club of over half a million people. One player, Lee Yun-Yeol, reported earnings in 2005 of US$200,000.

[From StarCraft - Wikipedia, the free encyclopedia]

Just to reiterate: there are three TV channels dedicated to this game! It must happen here too as the broadband penetration rises toward Korean levels, and while I can’t imagine turning on the TV to watch someone else playing World of Warcraft, I can at least see that it would be more interesting than the BBC’s Reithian triumph, “Hole in the Wall“.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Where’s the virtual Home Office when you need them?

[Dave Birch] Let’s be clear: there is something interesting happening around virtual worlds.  I’m not entirely sure what it is, and nor is anyone else, but the primal soup of computer-mediated communications, social networking and immersive 3D graphics is brewing and something will evolve.  This has ramifications for the world of digital identity because, apart from anything else, it changes the way that we think about identity (and multiple identity).  It seems to me that virtual worlds are beginning part of mainstream thinking: my evidence for this is that the moral panic that accompanies all new technologies that enter the mainstream is now under way.

Technorati Tags: , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.