Tomorrow's Transactions » Identification and Authentication http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 What about a financial services passport? http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/ http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/#respond Wed, 09 Jul 2014 19:53:08 +0000 http://tomorrowstransactions.com/?p=4510 The problems around KYC for new financial services, especially for new entrants, might be mitigated by the introduction of a financier services passport based on modern technology and not stupid bits of paper. There was a great story on BBC Radio recently. It caught my attention because it demonstrated faults with our useless and outdated […]

The post What about a financial services passport? appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The problems around KYC for new financial services, especially for new entrants, might be mitigated by the introduction of a financier services passport based on modern technology and not stupid bits of paper.

There was a great story on BBC Radio recently. It caught my attention because it demonstrated faults with our useless and outdated cheque payments system and our useless and outdated identity infrastructure at the same time.

A listener posted a cheque for £36,000 to his bank. It was stolen and paid in by someone else to an account in approximately his name. £20,000 was withdrawn. Barclays, his bank, have agreed to refund him only the balance of £16,000. What are his rights? And will the new cheque imaging service be any safer and quicker?

[From BBC Radio 4 - Money Box, Wonga woes]

During the episode, the bank is quoted as saying that their cashiers are not experts in identification. Indeed, They are not. Which is why the business case for KYC and AML and ATF stuff is so confused. What is the point of asking people to present documents that cannot possibly be verified? How is the poor chap at the bank counter expected to know whether my Portugese fishing licence is still valid or not? Clearly the fraudster had to present some documents to open the account.

If you’re applying for a Barclays Bank Account or a Premier Current Account you’ll need to show us 2 valid and original documents from the list below -  one from the proof of ID list and the other to give proof of your current UK address. The same document cannot be used to verify both your identity and your address.

[From Identification for bank accounts]

Clearly, the documents presented were fraudulent. I’m not picking on Barclays, obviously. This is a general problem across jurisdictions and banks. While it is complicated and expensive and annoying for legitimate customers and business to comply with stupid KYC requirements, it is apparently trivial for the criminals to do so.

There is no point having an identity infrastructure where it is impossible to verify identity. On the other hand, an infrastructure that means identity is verified at every turn is invasive and open to abuse. We have a system that delivers neither, and costs a fortune.

KYC Exchange estimates that whereas a KYC request might take 30 – 50 days to turn around using standard industry measures, its own system can do the same work in five minutes. The time saved for a bank initiator is estimated at approximately 90%, while the receiving bank saves around 40-50%, according to von Hänisch.

[From Cost of KYC too high says Swiss start up » Banking Technology]

Maybe KYC Exchange could then issue a Financial Service Passport of some kind? There’s a thought. I’ve been with Barclays for 37 years: perhaps they could provide me with some sort of app on my smartphone that I could use to present KYC credentials when I want to take out insurance or get a mortgage or rent a house or anything. This is the sort of thing that I think we will be discussing at techUK next Monday, where Ian Jenkins of Deloitte and I will be chairing a discussion around the concept:

A ‘financial services passport’ refers to an aspirational digital identity, issued by UK financial services providers, and mutually recognised across the financial services industry. Such an interoperable digital identity could be utilised to correctly identify and authenticate end-users with appropriate security in a wide variety of circumstances and across a wide variety of channels.

[From Workshop: Towards a Financial Services Passport]

Look forward to seeing you there.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post What about a financial services passport? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/feed/ 0
Payment system regulation as barrier to payment system innovation http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/ http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/#respond Mon, 16 Jun 2014 15:01:17 +0000 http://tomorrowstransactions.com/?p=4485 If we want more innovation, we need more competition, not more regulation. There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one. More transparent record keeping would allow law enforcement to […]

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

If we want more innovation, we need more competition, not more regulation.

There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one.

More transparent record keeping would allow law enforcement to trace the transfer of funds and identify those responsible for the illicit use or theft of virtual currency.

[From Virtual Currencies, Real Theft - Javelin Strategy & Research Blog]

Indeed it would, and some might argue that that transparency be extended to legacy infrastructure as well. (It’s not really the topic of this post but remember than transparency need not subvert privacy. You could have pseudonymous dark pools but force the release of linked identities given a warrant, for example.) If, however, transparency is taken to mean thorough KYC/AML/ATF procedures (henceforth known as CDD, or customer due diligence) that identify all participants to a transaction to all observers, then it will force criminals, terrorists and corrupt politicians to abandon electronic means of exchange and go back to cash. If that happens, then we are all worse off. Having some traceability is better than having none at all, as I’ve argued before. And it’s not as if having rigorous CDD solves the problem.

Worse still, the increased cost associated with a tougher stance on KYC does nothing to make the system any more secure, and may in fact drive up risk rather than reduce it.

[From Cost of KYC too high says Swiss start up » Banking Technology]

I suppose you could argue that what is driving the players at the moment is not risk but liability. So long as they can shift the liability onto someone else, no-one really cares who you are. The system is broken.

The two set up 68 accounts in 19 different cities using 24 aliases to handle the transfer of funds and sent the bulk of the money to individuals in Nigeria, who set up the operation. Money was also wired to addresses in the UK, Ecuador, India, the United Arab Emirates, and the US, none of which has been recovered.

[From Mother/daughter team jailed for million-dollar internet dating scam • The Register]

Hold on. 68 accounts using 24 aliases? What was the point of the billions of dollars spent on KYC, AML and ATF? And why am I going on about this anyway? Well, in her keynote at Payments Innovation 2014, Mary Starks (the acting MD for the UK’s new Payment System Regulator) said that on the whole regulators “don’t do innovation”. I was on the panel with her, so I made what I think was a reasonable point that the best regulatory approach to innovation is competition, and that a focus on reducing the barriers to entry to payments markets that do not involve systemic risk is probably sufficient. We don’t need to imagine what people might come up with, we just want to make it easy for them to do so.

When it came to the discussion that followed, I used CDD as an example of such a barrier. The costs and complexity of CDD can make it very difficult for new entrants, especially those dealing with low-value payments, the excluded and specialist niches to get off the ground. One of the reasons for this is that there is no infrastructure for them to plug in to, so everyone has to build everything from scratch.

Surely all of this dialogue about passports and utility bills, declarations and signatories and KYC and AML is pushing a demand for a new digital infrastructure to cure all of this mess.

[From Digital identities demand a digital infrastructure | Banking View]

Karen Wendel from Identrust talked about the infrastructural approach in her presentation as well, and this all links to the discussions about the idea of a financial service passport (or a “pay name”) at techUK last year. I really think that the idea of pseudonymous, strongly-authenticated CDD-inside identities is an idea whose time has come. I should be able to participate in a transaction as John Doe, provided that I can prove that someone (e.g., my bank) knows who John Doe actually is and that is is someone who has been approved after CDD. You don’t need to know who I am to do business with me, so long as you know that someone knows who I am.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/feed/ 0
Identity, so I hear, is the new money http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/ http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/#comments Thu, 12 Jun 2014 10:12:57 +0000 http://tomorrowstransactions.com/?p=4483 The CSFI roundtable on my book “identity is the new money” left me utterly depressed. Every single book sold was sold for cash. I will never recover from the embarrassment and public humiliation. Still, at least they sold some. The wonderful people at the Centre for the Study of Financial Innovation (CSFI) in London did […]

The post Identity, so I hear, is the new money appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The CSFI roundtable on my book “identity is the new money” left me utterly depressed. Every single book sold was sold for cash. I will never recover from the embarrassment and public humiliation. Still, at least they sold some.

The wonderful people at the Centre for the Study of Financial Innovation (CSFI) in London did me the great honour of holding one of their super lunchtime roundtable meetings around the publication of my new book, “Identity is the New Money“. I gave a short talk on a couple of themes on the topic, starting by exploring Jack Weatherford’s meme about the future of money being more like the money of the neolithic past than the money of today and finishing with the three suggestions for UK policy makers that I finished the book with — and trying to justify them to a financial services audience which, judging from some of the questions, I didn’t do too badly at.

  1. We need to begin by finding a way to make the construction and use of a new infrastructure for identity a national project of significance. We need to find something that can provide the “parasitic vitality” for a new identity paradigms. We already know that in the UK, as well as in the USA, Australia and many other countries, there is no appetite for any kind of national identity scheme. But there may be an alternative formulation that helps all stakeholders: individuals, business, governments, law enforcement and everyone else. A National Entitlement Scheme. Long before the late and unlamented national identity scheme in the UK, there was (back in 2002) the original proposal for an entitlement card. This should be revisited in the light of modern technology. We can use the modern privacy-enhancing infrastructure to decouple these entitlements from the underlying identities and resolve the paradox of more security and privacy.
  2. One very specific use of the new infrastructure should be to greatly reduce the cost and complexity of executing transactions in the UK by explicitly recognising that reputation will be the basis of trust and therefore transaction costs. The regulators should therefore set in motion plans for a Financial Services Passport. This would use the same infrastructure as the National Entitlement Scheme but with a sector-specific profile. The UK’s IT industry trade association, TechUK, has a working group looking at just this idea already and together with colleagues at Consult Hyperion we have put forward the same suggestion to the Federal Reserve in response to their November 2013 consultation on the evolution of the US Payments System. Since the financial services passport would be using the same infrastructure as the entitlesment scheme, one might expect the costs to be manageable and then cost savings to UK plc significant.
  3. Finally, I should like to make a rather technical and boring plea to the relevant authorities to make the UK’s National Payments Plan adopt an explicit target for reducing the total social cost of payments in the UK. This will inevitably mean coming up with tactics to reduce cash (and cheque) usage in the UK. This target will be made significantly easier to attain using the Financial Services Passport to lower the barriers to entry for new products and services, increasing competition in the sector (especially with respect to the financially-excluded groups who are too expensive to serve using existing infrastructure).

These are straightforward calls to action and I trust that you have been persuaded to support them!

CSFI Roundtable

I won’t report the excellent and wide-ranging roundtable discussion that followed (which was held under the Chatham House rule) except to note that David Rennie — from the Identity Assurance Programme (IDA) in the Government Digital Service (GDS) — was kind enough to join me at the roundtable and talk about the government’s current initiatives and how they support the idea of shifting toward entitlement as the basis for transactional interaction.

As is the tradition at such events, my publishers were kind enough to show up in person with a job lot of the heroic tome (plus some other titles in the Perspectives series) to knock out at the back.

Untitled

Despite accepting Bitcoin, Pingit, Paym and PayPal, I’m sorry to say that every single person who bought a copy paid cash. I will never recover from the shame.

Untitled

If we can’t persuade the nation’s financial elite to use mobile payments, who can we persuade?

P.S. Available at all good bookstores and some of the bad ones too. Kindle version now available as well. For our US readers, you can buy right now online with free shipping to the US at http://bit.ly/1pdzFN0.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Identity, so I hear, is the new money appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/feed/ 1
Bots and pluggers http://tomorrowstransactions.com/2014/05/bots-and-pluggers/ http://tomorrowstransactions.com/2014/05/bots-and-pluggers/#respond Thu, 15 May 2014 01:49:57 +0000 http://tomorrowstransactions.com/?p=4435 What if my Twitter followers and Facebook “friends” aren’t real after all. It doesn’t bother me, but it might bother other people! What if social media end up as a vast network of bots talking to other bots? Had a conversation yesterday with someone about a new startup. I hope they won’t mind me mentioning that […]

The post Bots and pluggers appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

What if my Twitter followers and Facebook “friends” aren’t real after all. It doesn’t bother me, but it might bother other people! What if social media end up as a vast network of bots talking to other bots?

Had a conversation yesterday with someone about a new startup. I hope they won’t mind me mentioning that one element of the conversation was about determining whether social media accounts were “real” or not. This reminded me what Sherry Turkle from MIT (who wrote the brilliant, seminal book on online identity, “Life on Screen“) said last year, when talking about the specific issue of twitter bots and fake social media accounts, that this is a really serious and really important problem because the inability to distinguish between real and fake accounts

will and should undermine trust

[From Twitter, Bots And Fake Accounts - Business Insider]

Indeed. I went to a marvellous panel session about this at SXSW, and I wrote at the time that there was a need to prove what you are (e.g., human) that is entirely distinct from the need to prove who you are:

An internet passport should be something different: whereas a mundane passport is valuable because it proves who you are, an internet passport should be valuable precisely because it doesn’t.

[From In cyberspace, no-one knows you’re a dogbot - Tomorrow's Transactions]

Given that the industrial-scale manufacturing of fake social media accounts is already widespread, you might wonder exactly who the fake accounts are for? I found this example in the WSJ quite interesting.

Rapper Tony Benson says hiring Mr. Vidmar to promote his account on Twitter is “the best decision I ever made.” Mr. Vidmar’s robots made the rapper, known as Philly Chase, a trending topic so often around Philadelphia that he attracted attention from local newspapers. Prominence on Twitter led to gigs, fans and ways to promote his videos, Mr. Benson says.

[From Inside a Twitter Robot Factory - WSJ.com]

In the early days of the pop business, as it was then called, record companies used to employ “pluggers”. In those days, the pop charts were compiled from the sales records of a small number of record shops. The identity of the shops was supposed to be secret, but the record companies of course knew which ones they were. So they would send their pluggers to buy copies of their own records to push their artists up the charts. Good for Tony Benson, who has found a way to replace pluggers with plugbots.

Much modern spam isn’t designed for consumption by humans at all; instead, it’s “robot-readable”, created by one non-human entity for the attention of another – specifically, the “spiders” that crawl the web compiling data for Google – in the hope of pushing a junk page higher up the list of search results.

[From Why Spam Works - Business Insider]

Is Twitter becoming a vast network of bots talking to other bots? What a fascinating idea to play with, and what a wonderful proto-case study for the future of business. I stand by my prediction of long ago. One day, IS_A_PERSON may be the most valuable online credential of all.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Bots and pluggers appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/bots-and-pluggers/feed/ 0
The real wallet wars are about to begin, and they’re not about payments http://tomorrowstransactions.com/2014/01/the-real-wallet-wars-are-about-to-begin-and-theyre-not-about-payments/ http://tomorrowstransactions.com/2014/01/the-real-wallet-wars-are-about-to-begin-and-theyre-not-about-payments/#comments Thu, 09 Jan 2014 18:43:08 +0000 http://tomorrowstransactions.com/?p=2919 The most important thing in digital wallets will be identity, not money. If you’re sick of listening to me about this, listen to @Jack. When I was putting together a few slides on the future of electronic wallets for one of our clients, I thought I would start by lining up a heavy hitter on […]

The post The real wallet wars are about to begin, and they’re not about payments appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The most important thing in digital wallets will be identity, not money. If you’re sick of listening to me about this, listen to @Jack.

When I was putting together a few slides on the future of electronic wallets for one of our clients, I thought I would start by lining up a heavy hitter on my side to help convince corporate middle management that wallets are a serious topic and are worth investing time and money in.

Microsoft (MSFT) will introduce its own version of “wallet” software for electronic commerce, but the company does not intend to compete with Internet payment firms, an executive said today. “We are creating a wallet that will allow payment companies to plug in their payment systems,” said Jonathan Weinstein, Microsoft group product manager… “Wallet” software contains a buyer’s payment methods for purchases on the Net, such as credit card numbers, electronic cash, digital IDs, and electronic checks.

[From Microsoft to open digital wallet - CNET News]

Sounds pretty interesting, until you notice that the article is dated 26th March 1997. Seventeen years ago. I’m not picking on Microsoft, I’m just using them as an example. They;re actually doing some interesting work in the wallet world. Last year, one of Consult Hyperion’s top software developer chaps wrote about his experiences at the Microsoft Digital Wallet Foundry in London, working on software for the Microsoft Windows Phone wallet.

The purpose of the Digital Wallet Foundry events is to inspire disruptive ideas about digital wallets in a variety of sectors, and to encourage those ideas to be developed into demonstrators or proof of concepts.

[From Hammering out an app at the Digital Wallet Foundry]

He built a great app, as did others at the event. But I still don’t have a digital wallet that stores my debit card, my driving licence and my bus ticket. Why is this all taking so long? Why don’t I have a mobile wallet on my iPhone right now, from Microsoft or from anyone else? Why did I have to type in my name, address, card number, expiry date and security code into the travel ticketing application that I used this morning?

Payments players with digital wallet aspirations — including Visa, MasterCard, Google, PayPal, Apple and Isis — are all vying for customers’ virtual pocket books in a race to truly electronic transactions. Yet none have had much luck, so far.

[From Digital Wallet Race Is Far From Over - American Banker Article]

The truth is that almost all of the payments that I make with my mobile — recently these have included car parking (RingGo), taxi (Hailo), coffee (Barclaycard OnePulse), bus (Arriva) and my eldest son (Barclays Mobile Banking) — are made using “domain-centric” apps, not payment apps. And what is central to these apps is me. For several of these transactions, I don’t even know how I paid. I can’t remember which cards or accounts I registered or selected and I don’t really want to be bothered about this when I’m doing something like getting on a bus. So long as it’s only me that can use the app, the payment mechanism is essentially uninteresting. Identity is, as they say, the new money. If you are wondering who “they” are people like… well, there’s me, of course, but there are also important and influential people, like Jack.

‘‘It’s not about payment,’’ Jack Dorsey, a founder of Square, a PayPal competitor, says. ‘‘It’s about identity. And it’s about the experience that a merchant can create, which is what actually builds loyalty. We believe that it’s important that the technology, the mechanics of payments, actually fade away to the background.’’

[From EBay’s Strategy for Taking On Amazon - NYTimes.com]

If we’re going to get somewhere with wallets, we need to change our view of wallets. Maybe wallet is an infrastructure built around what we at Consult Hyperion have taken to calling recognition, not an application built around what we have for a long time called payments. As I said a couple of years ago,

The impending wallet wars are about more than control over the consumers’ payments, they are about control over identity.

[From You searched for wallet identity - Tomorrow's Transactions]

That’s why the tactics around wallets are switching this year and you’ll be reading more and more about the real competition in the wallet world: not between Visa and MasterCard or between Barclays and Lloyds, but between banks and Facebook, telecommunications operators and Apple, retailers and Google.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post The real wallet wars are about to begin, and they’re not about payments appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/the-real-wallet-wars-are-about-to-begin-and-theyre-not-about-payments/feed/ 3
The internet of things needs some thinking through http://tomorrowstransactions.com/2013/11/the-internet-of-things-needs-some-thinking-through/ http://tomorrowstransactions.com/2013/11/the-internet-of-things-needs-some-thinking-through/#respond Mon, 04 Nov 2013 05:57:59 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/11/the-internet-of-things-needs-some-thinking-through/ My thing might be able to talk to your thing, but should it?

The post The internet of things needs some thinking through appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] There was a story in the British newspapers recently about an Italian criminal family (literally, a father and son) who were arrested for selling fake Romanée-Conti wine (a Burgundy that is one of the most expensive in the world at £14,000 a bottle). The police say that the fake labels applied to the bottles of plonk were “near perfect”. Aha. My eyes pricked up at this. A genuine problem, for which there may be a technological solution that some of our clients could benefit from supplying.

The NFC tags are located behind the label on the winery's Vintage 2010 range, with bottles selling at €2,000 to €2,500 each.

[From French winery picks NFC tags for authentication • NFC World]

Setting aside the interesting technical question of whether these tags are actually NFC or not, I have to report that this is not a new use case for contactless. I wrote up the use of RFID in the drinks business in Korea three years ago when we were looking at some identity-related business cases for one of our telecoms clients.

When the whiskey is bottled, the caps have an RFID tag added to them. This is coded with a URL and an identifier. When a customer, or a shopkeeper, or a policeman, or in fact anyone else wants to check whether the whiskey is real or not, they touch the cap with their phone and the URL launches a web site that knows the provenance of the identifier and can tell you when and where it was bottled as well as some other information. When the customer opens the bottle, the tag is broken and can no longer be read.

[From Digital Identity: There's whiskey in the jar-o]

I happened to find myself sitting next to Erik Harvey from iProof, one of the leading companies in this field, at the WIMA NFC event in San Francisco this week, and he made the very sound point to me that to work for all the stakeholders, systems such as these must involve the consumers. If consumers don’t tap on or scan the labels then there’s no data flowing around the system. We need consumers to be an active part of the anti-counterfeiting activity or it won’t work: they have to want to take part. I think, with the appropriate messaging, that they would. After all, who wants to be embarrassed serving a fake wine at dinner and, aside from that, who doesn’t want to learn more about a wine that they try and like? I’ve often seen people use their mobile phones to take the picture of the label on a bottle at a restaurant, presumably because they find the wine delicious and may want to order it again in the future.

This problem of epicurean counterfeiting is not confined the exclusive French vineyards. It’s a problem the world over, although it takes different forms in different cultures.

The bird's nests can be sealed in a box with an RFID tag that contains a microchip embedded with details about the harvest. A handheld scanner emits a radio frequency to unlock that information.

[From BBC News - RFID technology thwarts bird's nest counterfeiters]

Now, as have pointed out more than once in this context, the tag by itself isn't very useful (especially since absolutely no-one bothers implementing the security layer of NFC). The people who steal authentic labels from designer goods factories will steal authentic RFID tags as well. What is critical is the ability to determine provenance and this mean mutual authentication as well as a managed infrastructure.

Without an infrastructure that includes end-to-end digital signatures there's no way round this. The phone needs to know the chip is authentic. The database needs to know who is asking, and the consumer needs to know who is answering.

[From Digital Identity: There's whiskey in the jar-o]

The security of stuff in the internet of things (IoT) is a really, really interesting subject. It has implications that go way beyond protecting connoisseurs from embarrassment.

Rob Wainwright, director of the EU’s crime-fighting agency, said Europe’s black market in counterfeit foodstuffs, pharmaceuticals and machine parts doubled to a value of about €2bn in the early years of the recession.

[From Crime gangs look to clean up as Europe’s black market balloons - FT.com]

The odd couple of billion here or there doesn’t seem like a big deal to me, especially when the same article notes that VAT fraud is at least fifty times bigger, but taking counterfeit medicine or flying in a plane with a counterfeit part does seem like a big deal to me and I’d rather it didn’t happen. I hate  to say it, but perhaps some form of European co-operation might be needed…

One more thing. I don’t see that the security and privacy issues that come along with the IoT have been thought through at all. I tried to make this point a few years ago, using my pants as the target object, when I was looking at the use of RFID in high-value consumer goods. We need to develop an additional layer that delivers both enhanced security and enhanced privacy. It’s one thing for dinner guests to scan my wine bottle to see that it is a real Romanée-Conti and another for them to scan my Rolex to check that it is indeed a first-class far-eastern knock-off, but it’s quite another for them to be able scan my underpants and determine that they date from 1983. How do we turn tags on and off? How do we grant and revoke privileges? How do we allow or deny requests for product or provenance? These are difficult questions.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post The internet of things needs some thinking through appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/11/the-internet-of-things-needs-some-thinking-through/feed/ 0
Scary movie http://tomorrowstransactions.com/2013/10/scary-movie/ http://tomorrowstransactions.com/2013/10/scary-movie/#respond Thu, 31 Oct 2013 15:49:33 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/10/scary-movie/ Securty, privacy, identity, credentials are a real opportunity for telcos. I'd hate to see them left for dead.

The post Scary movie appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Well, it’s Halloween. I never much cared for it, as I was brought up on the traditional British November 5th celebration of intolerance, Guy Fawkes night, when we remember, remember the failure of our first great religious terrorist, Guido Fawkes and joyously dance around burning effigies of noted criminals, spiritual leaders and so on. To take my mind off of it, I went off to Digital Disruption 2013 to see how our clients on the telecommunications side of things might take advantage of changing technology.  I ran into a French lady there.  She was a little overdressed, if you ask me, but I don’t know too much about fashion so I was in no position to judge!  Anyway, as she seemed to venerate the fashions of a now-distant past, I went over to ask whether she saw much future for NFC or not.  I asked for her perspectives on the MNO NFC efforts underway in France.  She seemed a little puzzled, and I thought perhaps her English was not too good, and I tried again, only this time speaking loudly and slowly.  But nothing.  Perhaps I was talking at too high a level, so I went down a notch.  It took me a while to explain to her the difference between NFC interfaces and card emulation interfaces, but eventually she screamed with delight at my incisive analysis of the varying technology roadmaps associated with secure element-based NFC payments and “NoSE” (No Secure Element) applications.

Untitled

She told me that she had to go and have her head chopped off, so I went looking for someone else to talk to.  One of the stimulating topics of conversation that I thought of was the difference between “chip and signature” and “chip and PIN” and why the inclusion of PIN at the top of a card CVM list would lead to one or even two orders of magnitude less fraud.  I fancied this as a sound conversational stratagem because it would inevitably lead to a quite heated discussion about US market strategy.  I mentioned this to a gray-haired chap standing next to me and he stared at me blankly!  So I explained it all again, but this time in a little more detail.  He must have been a visitor as he didn’t seem to understand me either, even when I showed him a collection of cards with different CVMs.

Untitled

Oh well, I spotted some people dancing and I thought it would be fun to join them.  I saw one nice looking lady delegate so I thought I’d ask her to dance.  She seemed a little vacant to me but it had been a long day, so I thought I would try and cheer up with a funny story about the development of smart watches.

Untitled

As you can see she thought it was hilarious!  When I got back to the hotel, I blogged about it so that you can all enjoy it.  She made some comment about how much the living must envy the dead and vanished, unlike Tony Poulos who is surprisingly hard to get rid of unless you happen to pass a bar serving free beer, which we did.  I then ran into a group of dedicated electronic transaction fans who I noticed were following me.  I didn’t quite catch what they were talking about, so I thought I’d introduce myself and see if they were fans of the “Atlantic Model” of federated identity management along the lines of the US NSTIC and UK IDA initiatives.  I took their silence to be agreement.

Untitled

They seemed genuinely surprised when I told them some of my ideas for separating the fundamentally different telco activities of identity provision and credential and reputation management and how the telcos might provide open, transparent and non-discriminatory access to the basic identity services for third-party credentials.  I didn’t quite catch what they said about it (rather amusingly, it sounded like “kill me”, but I think they were actually saying “tell me”) but by that time most people had gone and the area was deserted.  I was thinking about the different strategies being adopted by our clients in the USA and Europe, particularly because of the European regulatory, when I bumped into a chap who appeared to have the haunted look of a banker who had been studying the European Commission’s consultation document of direct access to bank accounts by licensed third-parties.  He seemed quite interested but unfortunately I didn’t have time to finish my explanation of the Single European Payment Area (SEPA) and the current state of pan-European migration to the new SEPA Credit Transfer and SEPA Direct Debit standards before the lights went out at midnight and I was forced to find my way out in the dark.

Untitled

While I was doing this, surrounded by people working at the forefront of the telecommunications sector, preparing my notes for the session that I was going to chair on Data Security and Privacy, I became mildly excited.  You know, if identity really is the new money, that could be great for the telcos because they are obvious contenders to provide the identity infrastructure.  But, of course, the telcos in general and the MNOs in particular might decide to leave these crucial elements of the new economy to other players:  Facebook, maybe, or Apple or Google.  If that happens, then some of our most important clients will find themselves bypassed by service providers who see the telcos as nothing more than dumb pipes.  Now that’s really scary.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Scary movie appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/10/scary-movie/feed/ 0
Dave Birch has a lovely pair of knees http://tomorrowstransactions.com/2013/10/thats-a-lovely-pair-of-knees-youve-got/ http://tomorrowstransactions.com/2013/10/thats-a-lovely-pair-of-knees-youve-got/#comments Wed, 30 Oct 2013 07:58:24 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/10/thats-a-lovely-pair-of-knees-youve-got/ He just doesn’t want to be identified by them.

The post Dave Birch has a lovely pair of knees appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] I was tangentially involved in discussion about biometrics while working on a technology roadmap for one of our clients in the financial services sector. I was arguing my usual point, which is that mass market biometrics are about convenience, they are not a security play. In passing the issue of biometric accuracy was raised, and a useful discussion ensued. I. I'd like to amplify a point that was made in passing and introduce some data points.

The Unique Identification Authority of India (UIDAI) has successfuly conducted a proof of concept iris authentication study in the Mysore district of Karnataka, achieving accuracy levels of above 99.2 per cent, an official press release said here today.

[From UIDAI’s iris authentication proof of concept study successful | NetIndian]

At population scale, 99.2% is not very good. If you had a 99.2% effective contraceptive, the average woman using it would get pregnant every year. In closed environments, matching an iris against a token-based template as a PIN or password replacement is plausible but population-scale iris matching against a database for identification requires more thought. In the UK, the government shut down the IRIS system for border control back in 2012 in favour of e-passport scanning. Of course, iris isn't the only biometric that might be used in the future.

A new lab is working to perfect special shoe insoles that can help monitor access to high-security areas, like nuclear power plants or special military bases. The concept is based on research that shows each person has unique feet, and ways of walking.

[From Shoe ID Lab Developing Biometric Shoe To Identify Individuals Based On How They Walk

Yep. Feet. If I want to log in to your Facebook using this technology, I'll have to walk a mile in your shoes, so to speak. But gait is not the only lower-limb biometric on the horizon.

A new study involving magnetic resonance imaging suggests that MRI knee scans could be used as an almost foolproof form of identification. For the study, Dr. Lior Shamir, an associate professor at Lawrence Technological University in Southfield, Mich., analyzed knee scans of 2,686 people. He found that the scans accurately identified about 93 percent of the test subjects.

[From Knee Scan Identification: MRIs May Be Better Way To ID Travelers, Study Suggests]

In my books, 93% identification accuracy isn't "almost foolproof", it's "almost useless". Imagine the diligent anti-terrorist super-team at Heathrow Terminal 5 are on the lookout for the noted terrorist Dave the Jackal, who is known to be travelling incognito in a Facebook-blue burkha. Armed with an MRI scan of his knees, obtained by waterboarding a Cairo chiropractor, they set the scanners loose on a Monday morning. Now, Heathrow Terminal 5 carries about 65,000 passengers per day. The scanner will, broadly speaking, correctly identify 60,000 of them as not being the Jackal and send 5,000 of them for detailed investigation as potential Jackals. Say a few hundred an hour. What's the point of this?

Is this just another example of typical media innumeracy? I think not. I think it represents an underlying belief that we will be moving to biometric identification. There's a faith in biometrics, a belief that at some point in the future the biometric technologies will be so advanced that their identification will, indeed, be foolproof. The curve of technology might be taking us in that direction, but we're a long way off it just yet. This is why biometric authentication against a secure token makes for better strategy in our space. Biometrics as a PIN replacement, not biometrics as a card replacement. Or, indeed, biometrics as a phone replacement.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Dave Birch has a lovely pair of knees appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/10/thats-a-lovely-pair-of-knees-youve-got/feed/ 2
Enhancing data security and privacy - this should be an MNO business http://tomorrowstransactions.com/2013/10/enhancing-data-security-and-privacy-this-should-be-an-mno-business/ http://tomorrowstransactions.com/2013/10/enhancing-data-security-and-privacy-this-should-be-an-mno-business/#comments Tue, 29 Oct 2013 13:29:26 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/10/enhancing-data-security-and-privacy-this-should-be-an-mno-business/ Mobile operators seem like the obvious people to provide some interoperable security infrastructure for the new economy.

The post Enhancing data security and privacy - this should be an MNO business appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] I’ve been living the hell that is our identity infrastructure in 2013 because my eldest son just started university, and this means dealing with student finance. He is applying for student loans, so he had to create an account with the Student Loan Company, which means that I had to create a parent account which also meant that I had to create a parent account for my wife. I created these accounts and then filled out the financial information that they asked for (last year’s P11Ds and P60s which they could have got from HMRC), then they needed something else. So…

  1. Go to student finance web site at DirectGov.
  2. It asks me for an e-mail address and password, neither of which I can remember.
  3. I click on “forgotten password” (which is where they should probably take you in the first place) and they e-mail me a password reset.
  4. I reset the password, but the system tells “your new password can’t be the same as the old password”! Doh! So that’s what my password was!
  5. I choose another password.
  6. Hurrah! I can log in.
  7. It asks me for the 2nd, 4th and 6th letters of the street I lived on when I was ten years old.
  8. I wasn’t sure what I’d answered for this question, but luckily I got it right.

This is what should have happened…

  1. Go to student finance web site at DirectGov.
  2. Choose my bank as my identity provider.
  3. Open my bank app on my mobile phone and enter my PIN (or put my finger on the home button fingerprint scanner).
  4. Continue with student finance web, now correctly recognised.

Meanwhile, my son filled out the online stuff (remember, all of this is completely and utterly pointless since my wife and I are above the income threshold so we cannot obtain any financial support) and then discovered that he had to provide proof of identity. I assumed, this being 2013, that he would be able to log in to student finance using his bank card (since his bank has already KYC, AML and ATF’d him) or select one of the UK’s approved identity providers — say the Post Office, for example — and log in using one of them. Of course not. Much as our Victorian forefathers might have done, he was required to obtain a declaration of his identity from an upstanding member of the community (thanks Gloria!) and go down to a Post Office and send it, along with his original birth certificate, off to Doncaster. I imagine he’ll never see it again, but I paid for secure overnight delivery anyway. That was six quid. Six quid that I might, in an advanced economy, have spent on registering for an ID linked to, for example, his smartphone SIM.

It may be two years, it may be ten, but soon enough the identity credential will look very much like Facebook, YouTube, or Amazon: It will be an app or functionality embedded within an app on your smart mobile device.

[From DigitalIDNews | On the path to a ‘virtual’ identity credential]

This is the sort of thing that I will be pestering the delegates about, I imagine, at Digital Disruption 2013 tomorrow and Thursay, because I really think that the mobile operators should be developing a more strategic approach to identity and building an understanding of where their corporate strategies will take them in this area. I’m chairing the track on Enhancing Data Security and Privacy and I’m really looking forward to hearing the latest thinking in this critical area of business.

P.S. We received some more forms for him to sign a couple of days ago. Physical forms. In the post. That we have to send to him so that he can manually sign them and then post them back to the SLC. I swear that twenty years ago I never imagined that we would still be doing this in 2013.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Enhancing data security and privacy - this should be an MNO business appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/10/enhancing-data-security-and-privacy-this-should-be-an-mno-business/feed/ 1
Cloudy, chance of rain http://tomorrowstransactions.com/2013/09/cloudy-chance-of-rain/ http://tomorrowstransactions.com/2013/09/cloudy-chance-of-rain/#comments Mon, 30 Sep 2013 09:29:42 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/09/cloudy-chance-of-rain/ There are significant business implications to combining federated identity with the cloud - mobile operators take note.

The post Cloudy, chance of rain appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] At the Management World event in Nice earlier this year ("Navigating the Digital Storm") I was flattered to be asked to chair the discussion session on Delivering Enterprise Cloud Services. I was keen to get a general perspective on the telecommunication sector's approach to this growing market. Naturally, I also thought I might be able to steal one or two decent ideas to pass on to our telecommunications clients who are looking to find a niche around enterprise cloud. I don't know very much about enterprise services as it's not really my day-to-day focus so I think I was asked to chair because some of the telcos felt that the "identity issue" was key to unlocking this market and, since I'd been droning on incessantly about identity for as long as any of them could remember, they thought I might be able to help direct some of the questioning.

It turned out to be a really interesting session. Before we talk about identity I just want to pull out a few things from my notes which I think might be relevant to the discussion. One of the discussions was around UBS. In round terms, UBS spends around $4 billion every year on IT. Of this, somewhere round about $1 billion per year is to deliver net new functionality to the business. That sounds pretty cool and it sounds like UBS must be delivering some incredible new services. Until, that is, you discover that almost all of the net new functionality is to do with regulatory requirements and changes in compliance. There is actually precious little resource going into delivering new products and services because the regulatory burden is so overwhelming. The smallest changes require colossal expenditure. Just witching from windows XP to Windows 7 cost something like $300 million. Imagine the pressure is on the bank IT department trying to support managers who want to use smart phones and iPads, desktop traders, homeworkers, contractors using goodness knows what and all of the other components of the modern enterprise. It is literally a nightmare.

Even in a small company such as Consult Hyperion you see a microcosm of these issues on a daily basis. It's no surprise that it many companies, people who are used to their Samsung S4, iPad Mini and smart TV at home get fed up with their enterprise IT infrastructure and, irrespective of company policies, start using Gmail and Dropbox, Yammer and a variety of other services.

Facebook has started to roll out a new file-sharing capability — and Dropbox shouldn't be the only worried party. The addition of a low-security file-sharing tool to the world's most popular social networking site could open a world of security pain on businesses and home users alike.

[From Facebook file-sharing could be security, piracy nightmare | Social networking - InfoWorld]

But back to the discussion. There is obviously an intimate relationship between enterprise use of (secure) cloud and enterprise identity infrastructure. Right now, most enterprises use proprietary identity management software that was never designed for cloud use and restricts not only the ability to take advantage of cloud services but also forms a barrier to organisational interworking that could be facilitated by the cloud.

Here's an example. A few weeks ago one of our retail banking clients asked me to prepare some material for them. The material included PowerPoint slides and notes and an audio file. When you tried to send it to the customer, it was too big for their email system so I put on Dropbox and sent them the link instead but they couldn't access it because Dropbox is blocked by their IT department. In order to get the file, they had to get me added as an authorised user to their "internal cloud" which took the best part of the day and then I used a special username and password to login and upload the file. Incidentally, a couple of days later when the client had asked me to make a few small changes and upload a new version of the slides, I had been deleted from the system and so had to go through the whole process again.

With an infrastructural, federated solution, it should have been entirely possible for the bank to accept Consult Hyperion credentials and provision limited access (in practice by issuing a certificate that I could then use to login on any device). It is easy to say, very difficult to implement. This is where, I thought, the telcos might have something to offer. But they'll have to move quickly, but the enterprise cloud players have a strategy toward identity (because they see it as strategically important) whereas the telcos (and the banks?) don't.

I expect Oracle customers using Oracle applications via SaaS will increasingly use their Oracle Cloud identity as the identity for a chunk of their user populations, rather than trying to maintain multiple identities in their on-premises system. Since Oracle is already maintaining a cloud identity for every Oracle Cloud user, that identity is portable as far as the user is concerned.

[From Trend Watch: Identity Management Top 5 « Discovering Identity]

Quite. And Oracle are not the only serious player to have realised the power of transforming identity management from something to do with single sign-on to a strategic element of their proposition.

At his company's first YamJam conference in San Francisco, Sacks just revealed plans to move beyond the surface resemblance to take on Facebook's core function of identity, and apply it to the workplace.

[From Yammer's Facebook-Like Strategy - Business Insider]

For LinkedIn and such like, this is an important step. It is easy to see how it might work in practice: I want access to an enterprise cloud so I log in using my LinkedIn identity and since the bank has access via that identity to my professional social graph it can make some pretty decisions about whether to let me in and what I might be allowed to look at.

Cloud growth has also led to APIs playing a more critical role in the connected business. Companies such as Salesforce.com encourage business users to create their own apps by providing access to enterprise-grade services such as workflow, approvals and even data models.

[From APIs: Driving the connected apps revolution | VentureBeat]

Where could the mobile operators, for example, play in this space? If they had a standard API for identity services they could offer this to Oracle, Salesforce, Yammer and everyone one to provide a global recognition service that brings together hardware-based two-factor authentication (using the SIM) with federated identity and value-added services around location, roaming and so forth. I can see that it would be rather convenient to log in to a client's cloud using my phone and my LinkedIn identity and surely it would be more secure than the sort of simple password-based non-security we deal with at the moment. Tom Noyes, who I always take seriously, calls this a "breakout business" for mobile operators and I'm sure he's right. Whether they can develop a co-ordinated strategy to exploit this opportunity is, naturally, another matter.

There are, of course, significant business implications, which is why guys like Salesforce take it so seriously. If I used my LinkedIn identity, say, to log in to various clients and online resources during the day, then LinkedIn would know what I was up to. If they see me log in to my good friends at Indeed.com, they might reasonably deduce that I am looking at the job market and send an alert to the numberless hordes of recruitment consultants who are constantly trying to link to me. I'm puzzled by the number of organisations that look at this with equanimity. It is huge.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Cloudy, chance of rain appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/09/cloudy-chance-of-rain/feed/ 2