The ID of Sisyphus at the Country Club of Palo Alto

[Dave Birch] People who don’t really understand how anything actually works and have no perspective on the big picture that is needed for worthwhile risk analysis tend to grasp at reactionary ornaments when the public clamour “something must be done” reaches a particular level. Here’s an example. We know from previous experience that putting cardholder images on payment cards makes absolutely no difference to fraud. If it did, banks would do it. One of the reason why images make no difference is that retailers tell their staff not to look at them, because it’s not their problem. Retailers don’t want staff being assaulted by either criminals or disgruntled legitimate cardholders and since they are not liable for chip transactions where the correct PIN was entered, why would they bother? In the real world, you swipe the card and the light is green you get the goods. The photo ID is a good example of something that seems like it should be a good idea, but just isn’t.

Banking ombudsman in Karnataka M. Palanisamy Tuesday advised banks to issue chip-based ATM cards with customer’s photo to check frauds committed through debit or credit cards.

[From ATM cards with photo will check frauds: Ombudsman - NY Daily News | NewsCred SmartWire]

Of course, you don’t need to put the ID photo on the debit card. You could simply demand that customers produce ID when they use a chip and PIN card to buy something. I’ve noticed that this often happens in Spain: you buy something in a shop and present a chip and PIN card and enter the correct PIN and the transaction is authorised but the shopkeeper still asks for ID (I generally present my 1997 England football club supporter’s card because I leave my passport in the hotel safe) and then asks you to sign the slip as well. Asking for ID must reduce fraud, right? And ID cards that have jolly secure chips as well as photos must reduce fraud to immeasurably small levels, right?

“People have started using our principle of freedom of information as a tool to commit crime,” Lars Minnedal of the Stockholm police fraud unit told the Aftonbladet newspaper… Security experts have warned that Sweden may be soon hit with a “fraud epidemic,” as would-be criminals can get all the information they need by making a call to the Swedish Tax Agency (Skatteverket).

[From ID-card fraud 'epidemic' threatens Sweden - The Local - m.thelocal.se]

The law of unintendend-but-entirely-predictable consequences strikes again.

“The society we live in makes it possible. The problem is that we have a freedom of information principle, and people never thought of how it could be abused in the way it is today,” Minnedal added. “You can access everything on everyone and there’s no requirement to explain what you want to use the information for.”

[From ID-card fraud 'epidemic' threatens Sweden - The Local - m.thelocal.se]

How can you actually cut down on ID fraud? There are two basic approaches. You can make it harder to steal identity data (the Sisyphean PCI-DSS approach) or you can make it harder to use stolen identity data by having a working identity and authentication infrastructure (my approach, but who am I against so many?). This Swedish example illustrates perfectly how having easy-to-steal data and a non-working infrastructure delivers a perfect storm.

While Swedish identity documents are equipped with advanced security features, Minnedal lammented that many store clerks and sales people “systematically neglect” to look carefully at ID cards presented to them or lack knowledge of the card’s proper appearance.

[From ID-card fraud 'epidemic' threatens Sweden - The Local - m.thelocal.se]

Store clerks and sales people should not be required to become de facto identity verification experts. What is the point of the chip on the Swedish ID card if you are going to ignore it for verification purposes? Just as the mPOS revolution means that anyone can take payments, so it should similarly mean that anyone can check an identity card, anyone can “take identity”. Not by looking at an identity card — get with it Grandpa Sven, this isn’t 1952 any more — but by via iBeacon or by tapping it with their NFC phone or putting it in their iZettle. Then the system can check whether the card is real or not, require the cardholder to enter a PIN and a fingerprint if necessary and display the photo stored in the chip. Note that the photo will generally be ignored anyway, and eve when it isn’t, it won’t help.

Stolen second-generation ID cards are much prized by criminals engaged in fraud and money laundering as they cannot be canceled, an investigation has revealed. These cards don’t come with a secret disabling code so remain active even after their rightful owners inform police they are missing, said officials from the household registration management center in Tianjin Municipality, neighboring Beijing.

[From Crooks strike rich with ID card you can't cancel- China.org.cn]

So in China for $65 you can buy a stolen ID card of someone who looks a bit like you and you’re home and dry. In a way, that’s worse than having no ID system at all, because it means that once you are inside the wire (ie, once you’ve flashed your stolen ID card at someone and they have accepted that it’s you) then your rights and privileges are no longer questioned!

Look. Identity infrastructure should be based on the premise that anyone’s identity might be stolen but that it cannot be used by anyone other than the rightful owner. That means an infrastructure with strong authentication. I think I might host a discussion table on this topic at the first ever Bay Area Tomorrow’s Transactions Unconference in Palo Alto on Friday 4th October. Consult Hyperion are organising this with our friends at BayPay and with support from the wonderful people at Discover.

For those of you unfamiliar with our Unconference concept, the event will build on the success of the previous London, New York and Toronto Unconferences, success that is down to the expertise and enthusiasm of the participants but also the event format itself. Instead of of a succession of pre-determined Powerpoint presentations, the events mix stimulating talk from thought-leaders with global perspectives and discussion sessions which bring together the delegates, experts and selected industry observers to cover topics chosen by the delegates themselves on the day. The goal of the day will be to help professionals in the finance, payments and related industries to explore the future of the retail electronic transactions space and go back to their companies with new ideas, new strategic input and new friends.

Who knows what the delegates will choose to discuss and debate in Palo Alto next week, but I expect the topics to be covered to include the future of online identity, the mobile “wallet wars”, migration to chip cards in the US, alternative and parallel currencies, “near banking” and much more. (At the London event this year the topics discussed ranged from bank APIs to writing a movie about payments, and at the Toronto events popular topics included identity as a banking service, the end of cash and big vs. small data in business models.)

The invited thought pieces that will stimulate the discussion in Palo Alto will be:

  1. David Wolman, contributing editor at Wired magazine and author of “The End of Money” (all delegates will receive a copy of David’s book).
  2. Nate Wehunt Sr., Head of Digital Channels at City National Bank.
  3. Sam Lession, the Head of the Identity Product Group at Facebook.
  4. Me, one of Wired magazine’s global top 15 favourite sources of finance and business news, and Europe’s most influential commentator on the emerging payments scene.

Following the keynote, during the Q&A sessions, the delegates will (in best open-space style, as described at http://www.unconference.net/) note down the topics that they would like to discuss and these will be organised into sets of parallel sessions (one before lunch and two after). Delegates are then free to join in any, all or none of the discussions. The points raised in the discussions will be captured and reported. If you are responsible for strategic directions around payments, banking and finance then come along and get new ideas, new perspectives and new insights to help you to develop robust strategies to make the most of the incredible technology, business and social changes underway.

There will be a range of delegates from different backgrounds at the fall events and we hope the cross-fertilisation of ideas will be something special. As for the other events, the day will be limited to 100 delegates so that everyone gets a chance to participate in discussion, debate and learning. I hope you decide to come along. It’s $50 for BayPay members and $100 for non-members, so you’d be mad not to get yourself a ticket right here, right now. See you next Friday.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The focus on biometrics in the mass market

[Dave Birch] Well, it’s no surprise that following the launch of the new iPhone 5S with it’s new “TouchID” fingerprint sensor that the combination of the mobile phone and biometrics is a focus for discussion in our little corner of the secure electronic transactions world. As was widely anticipated following their $300m purchase of the fingerprint sensor manufacturer Authentec, Apple have added a sensor to the home button of the new iPhones so that users can authenticate themselves using, well, themselves.

Apple has just confirmed that the iPhone 5S will feature a 500ppi fingerprint sensor right in the 5S’ home button

[From Apple’s Touch ID Is A 500ppi Fingerprint Sensor Built Into The iPhone 5S Home Button | TechCrunch]

Here’s an amalgam of the conversations I had with different people following the announcement.

Person: Do you know that fingerprints can be faked? I heard about a Japanese guy who did it with jelly babies or something?

Me: Yes, I know.

Person: Your fingerprints are all over your phone, people could easily steal them.

Me: Yes, I know.

Person: Criminals might be able to find a way to make a fake finger and use it to buy songs on iTunes using your iPhone.

Me: Yes, I know.

Person: Do you know that researchers were able to reconstruct useable 3D models of fingers by accessing stored fingerprint templates?

Me: Yes, I know.

Person: So would you use the new Apple TouchID on your next iPhone?

Me: Of course.

If I sound complacent about the possibility of agents of foreign powers delving into my iPhone, it’s because I am. The Apple TouchID isn’t really about security, it’s about convenience, a point I made on BBC Radio 4′s Today programme. Convenience is something at which Apple excel. When I got on the bus last night, I had to press the home button on my iPhone to wake it up, then swipe my finger to get to the unlock screen, then enter the 4-digit passcode, then touch my Arriva app to display my ticket to the driver. With the new iPhone, when I press the home button to wake it up, it will scan my fingerprint and skip over the swipe and enter passcode stages. That may not seem like much, but when you are at the front of the queue on the bus, or checking it at British Airways, or showing a ticket for an event or trying to show a loyalty card in a shop using Passbook and paying in Starbucks using their app, it will save a few seconds. And there will be a bunch of people who currently don’t lock their iPhones but will because of the fingerprint. That’s it.

Will TouchID be more secure than a 4-digit passcode that can easily be read over someone’s shoulder? Yes. Will TouchID replace 4-digit passcodes? No. You will still have a passcode for the odd occasion when your fingerprint can’t be read or for when your wife wants to look up something on IMDB on your iPhone and can’t be bothered to go into the other room and get her smartphone. Will TouchID make iPhones magically invulnerable and capable of storing your deepest thoughts perpetually and in complete secrecy? No. Biometrics in the mass market are about convenience, not security. As I wrote some months ago:

Apple understands the location of biometrics in the consumer space: convenience, and Apple is all about convenience. Remember, these iPhones aren’t going to be used to launch nuclear missiles or identity people in databases

[From Biometric tick]

Right now, the use of TouchID is limited to unlocking the iPhone and authenticating an iTunes purchases because developers do not have access to the fingerprint subsystem, but I’m sure that (given the competitive pressures as other handset manufacturers adopt similar technology) once the subsystem is tried and tested and tuned and optimised then they will be, so when I open PingIt or PayPal I will find myself using the home button instead of entering a passcode. Crucially, given that Apple’s design influence and media mindshare are significantly ahead of its market share, the TouchID’s deployment is a boost for the whole biometric authentication sector.

Apple’s iPhone 5s Touch ID fingerprint scanning feature will kick off a biometric adoption race

[From Apple’s iPhone 5s Touch ID fingerprint scanning feature will kick off a biometric adoption race - The Next Web]

When it comes to using this kind of technology in retail payments, there are plenty of people experimenting with the options and plenty of experience in customer reaction. Consult Hyperion, for example, advised Natural Security on their system that combines biometric authentication and contactless interfaces.

Today Natural Security, in partnership with Banque Accord, BNP Paribas, Crédit Agricole, Crédit Mutuel Arkéa, Groupe Auchan, Ingenico and Leroy Merlin, has launched a pilot deployment of a new payment method that combines a smart payment card, biometrics and mid-range contactless communication.

[From Announcing the world's first consumer trial of new payment method incorporating payment cards, biometrics and mid-range contactless technology - Security Park news]

This is what makes me so confident in my prediction that consumers will like, and use, the technology. At the end of the Natural Security trial in France, some 94% of users said that they wanted to pay for all in-store purchases using the fingerprint authentication. A recent WorldPay survey in the UK had half of all shoppers saying that they wanted to use biometrics for payments. Apple’s model — local biometric authentication for the mobile device, wireless communication between the mobile device and the local environment — looks a very sensible one to me.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Don’t you know who I am?

With one or two of our clients, a year or two ago, we began to use the word “recognition” to mean a combination of fit-for-purpose identification technology with fit-for-purpose authentication technology. For commercial organisations, customer recognition is a strategic goal and developing a pathway of tactics to get there by exploiting various waystations on the technology roadmap is an immediate need, because recognition is essential for delivering value-added services. In some retail relationships, it is absolutely crucial. Here’s what I mean.

The London Times recounts a true American horror story: Mindy Kaling, writer and actress first on The Office and later on her own show, The Mindy Project, in addition to author of a successful memoir, walked into a Los Angeles boutique. And she was not recognized. This is a worst-case scenario for any Los Angeles boutique owner.

[From� Facial Recognition Alerts Stores When A Celeb Walks In | Popular Science]

Embarrassing it may be (don’t worry, I haven’t the slightest idea who she is either), I don’t think it can be correctly labelled as the absolute worst case for any boutique. That happened in Zurich recently, when the pretty much the richest woman in the world walked into a shop to buy pretty much the most expensive handbag in the world and the saleswomen not only blew a substantial commission but…

US talk show host Oprah Winfrey says she was the victim of racism during a recent visit to Switzerland. She said an assistant refused to serve her in an upmarket handbag shop in Zurich. Winfrey, one of the world’s richest women, was apparently told one of the bags was “too expensive” for her.

[From� BBC News - Oprah Winfrey 'was victim of racism' in Switzerland]

If it was me, I would have bought the shop and fired the assistant, but I suppose real billionaires are more sensitive and caring. One can only imagine the shock and trauma that Ms. Winfrey suffered when she realised that the Swiss shop assistant had absolutely no idea who she was. I’d love to think she said “do you know who I am” only to be told “no”. In our post-modern celebrity-obsessed culture, not being recognised is a fate worse than death, a problem that our emerging identity and authentication infrastructure really ought to be able to tackle.

This lack of recognition is precisely what the VIP-identification technology designed by is supposed to prevent. The U.K.-based company already supplies similar software to security services to help identify terrorists and criminals. The ID technology works by analyzing footage of people’s faces as they walk through a door, taking measurements to create a numerical code known as a “face template,” and checking it against a database.

[From� High-End Stores Use Facial Recognition Tools To Spot VIPs : All Tech Considered : NPR]

In the Swiss case, this same software could also be used to stop asylum seekers from entering the shop at all, so I imagine it will be pretty popular over there. (I’ve been invited to give in a talk in Zurich by our good friends at SIX, so I will ask around when I get there.) But is it a good thing over here? I’m looking forward to the first case of this database getting hacked for use in a mafia hit. Imagine the manpower they would save! Instead of staking you out and tailing you, they just put your picture into the shopping mall database and wait for the bell to ring.

This isn’t all about celebrities and mafia hits. We all want to be recognised, in the right context. I want BA to know that I have a Gold Card as soon as I walk in through the door because I expect to get better service. I don’t get upset when I don’t get that kind of service on United. I understand the game. I like getting a free cup of very nice coffee when I go shopping in our local Waitrose because I have a “My Waitrose” card. And there’s nothing sinister about retailers wanting to know who you are so that they can deliver a better service to you. Being recognised can be good.

Recycling bins in the City of London are monitoring the phones of passers-by, so advertisers can target messages at people whom the bins recognize… The bins record a unique identification number, known as a MAC address, for any nearby phones and other devices that have Wi-Fi turned on. That allows Renew to identify if the person walking by is the same one from yesterday, even her specific route down the street and how fast she is walking.

[From� This recycling bin is following you - Quartz]

If I was going to put a bomb in a rubbish bin in order to assassinate a top bankster, just as an example, I would want to be sure that the bomb detonated just as the target was walking past, so this sort of technology would be invaluable and it’s a shame that the City of London spoilsports banned it. But you can see why they were upset. This sort of passive recognition is different, even though it is inevitable. If we’re going to have recognition, then it needs to be secure (you can’t have privacy without security, remember) and it needs to be controlled, preferably in an explicit bargain between the customer and the retailer. I’m happy with my My Waitrose card in Waitrose, but I might be quite unhappy if I discovered that Waitrose were using it to track me elsewhere.

Now, as we discovered through our work on the Technology Strategy Board’s VOME project a couple of years ago, making that kind of bargain explicit is actually rather difficult, since a great many people don’t understand what is being traded off and it was hard work to find mechanisms to explain it to them so that they could make informed choices. (One that we explored was a� privacy card game, which was pretty fun actually.) But let’s put that to one side for a moment and assume that we can. Then, within the bounds of Data Protection laws, I think it is possible to envisage a plausible “privacy settlement” that works for the retailers, customers and regulators. That settlement means sharing some personal information, of course. This was always the business school case study around junk mail. Where there were strict privacy controls, people got more junk mail, because the senders couldn’t work out who might or might not be interested in a golfing holiday so they sent the golfing holiday brochures to everyone. As� David Cushman told me a few years ago, if you target information accurately enough, it ceases to be junk, or even and advertisement, and becomes part of a conversation and people like engaging in conversations. So people want recognition, and they want to share, but again it must be under their control and as part of a bargain they can understand and give proper consent to.

There’s another general case where recognition is evolving though. I remember seeing an excellent presentation on this last year from our friends at Sense Networks. They are currently collecting some four billion location� data points per day from smartphones in order to deliver targeted advertising. They know everything about you—where you live, where you work, where you shop, where you went yesterday—except who you are. We’re all carrying tracking devices that mean we can be individually recognised.

[Verizon's] new marketing program, Precision Market Insights, collects data information from iOS and Android users, based on geographic location gleaned from apps and sites being accessed. Verizon plans to continue to share that information with potential advertisers. Verizon emphasizes that the program is legal and doesn’t violate any federal wiretapping or other privacy laws because they keep user identities anonymous.

[From� Verizon's 'Precision Market Insights' Data Mining Policy Raising Privacy Concerns]

Setting aside the technicalities of how the data is anonymised and whether the technology used is “strong” enough, this sort of “big data” use strikes me as being reasonable. I don’t mind being tracked in that anonymous way, as part of a group, if it leads to better services for me. I don’t always want to be recognised as an individual. But then I’m not a sleb.

By the way, this sort of innovative use of new identification and verification technology is the sort of thing I might ask Mary Portas about at� Europe’s Customer Festival in London on 16th-17th September 2013 where we are both in the keynote track. Thanks to the wonderful people at Total Payments, we have a delegate place at this event to award as a prize on this blog. So if you are going to be in Islington on 16th and 17th and fancy coming along to hear about the future of loyalty, omnichannel retailing, big data and payments in the retail world, all you have to do is reply to this post with the name of the “Portas Town” famed for the short queues and excellent customer service associated with the issuing of UK identification documentation and your name will go into a draw that will be made under independent scrutiny on Friday 6th September. Look forward to seeing you there.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Monday Museum: Tokens mean credentials mean reputation

[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is the last of our summer “Monday Museum” series, this time from� 18th September 2006.

[Dave Birch] It’s hard to validate — I mean really, really validate — someone’s real identity in a transaction.  By “hard”, of course, I also mean “expensive”.  That’s why transaction mechanisms that don’t validate real identity (eg, credit cards) are easy to use and cost-effective.� Luckily, we don’t often really need actual identity validated to conduct a transaction.  What we need is reasonable assurance that the parties to a transaction are authorised.  So, when you are conceptually carded, it should be to see that you are over 21 (or whatever), not who you are.  There’s a big difference.  Over time, the credentials that are being presented begin to acquire a history, a reputation if you like.  Once can certainly envisage markets in which transactions depend on that reputation: not “snapshot” credentials or identity no matter how well validated.

The thing is that proving our actual identity is a special case: in almost all of the transactions we take part in every day, our real identity is immaterial.  It is generally used a proxy for some other credential — you’re an employee, you’re allowed to park here — because it’s the key that’s used to look up that credential in a database of some description.  Now, if it is possible to carry that credential around with you in a token capable of supporting a reasonable degree of authentication, then not only do we have a more secure system overall, we also have a much cheaper system (since we don’t need to manage or control the proxy database).

This is why we should try and change the paradigm around identity management.  Many people still think in terms of people proving who they are to log on to a web site rather than what they are: British, over 18, an eBayer with more than 100 stars and so on.  The latter example indicates why I’m curious about the potential for paradigm shift.  When I buy things on eBay, I don’t care who people are, I care about their stars.  It’s a reputation economy.

I remember writing about this in the past, using the emergence of stock markets as an example.  The first modern stock market began in Amsterdam back in the seventeenth century.  One of the interesting lessons from that time is that the courts had no mechanism for dealing with the transactions that were being undertaken: the contracts could not be enforced in court.  Yet the market grew and traders began to experiment with new instruments.  This market worked because contracts were self-enforcing with the group and the means of enforcement was reputation.  As Adam Smith noted later that century in the UK, “when a person makes 20 contracts in a day, he cannot gain some much by endeavouring to impose on his neighbours, as the very appearance of a cheat would make him lose”.  Much like eBay today, a trader’s reputation was the basis of their earning power and a low-overhead enforcement mechanism for the community.  Systems based on reputation do seem to work, although without the “security infrastructure” they are open to abuse.  They are also open to non-technological abuse, if you see what I mean (authors recommending each other’s books and that sort of thing) which is another topic in its own right.

At a personal level, reputation is a good basis for competitive advantage.  For one thing, it’s long-lasting.  It’s hard to forge a useful reputation — not that people haven’t succeeded: remember Frank Abagnale and the movie Catch Me If You Can — and difficult to buy one.  When I’m calling a plumber, I’d be much happier choosing one with lots of stars: thus, the plumber’s livelihood depends on having the stars and (the subject for another post sometime) taking away stars might be a more effective form of sanction than taking away some money.  If plumbers, policemen and everyone else had tokens that could give up (and verify) credentials, then it seems to me that many business models would be changed.

Imagine going to buy a car and having the dealer’s “stars” verified by your own ID card, phone or PDA at the same time as the dealer is verifying your “stars” from the bank.

Creating a security infrastructure that means that the eBay stars and the plumber’s recommendations can be audited and confirmed to be “real” therefore creates a platform for efficient transactions.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Monday Museum:  Chatroom paradox

[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is another in our “Monday Museum” series, from� 26th August 2006.

[Dave Birch] Chat rooms are a great place to start thinking about digital identity. Especially where children are concerned. I started thinking about this again while I was dipping into the privacy vs. anonymity debate that is swirling around our corner of the Internet yet again. If we (ie, the digital identity illuminati) can solve the chat room problem, then we’ll really have achieved something.

Chat rooms were in the news recently because UK users of Windows Live Messenger or MSN Messenger can now click a new button in the chat application to contact police with reports of suspicious behavior and instances of inappropriate sexual conduct online (eg, any mention of having viewed Celebrity Love Island). But how do you know who was being “inappropriate”?

This brings us back to the fundamental chat room paradox that we touched on last month.  To restate… Your kids want to go in a chatroom and you will only let them go into the chatroom if you know (in principle) who everyone else in the chatroom is, but you won’t let them go into the chatroom if they have to disclose who they are.   So in an “open space”, you want to everyone else to disclose their identity but keep yours secret, just in case of one the other people who has disclosed their identity is lying and is actually someone else (so that if they do something bad, the police can’t catch them).

My head hurts.

I think the solution to the paradox, as I consistently maintain, is to take pseudonymity seriously.  The problem isn’t the chat rooms themselves, but that no-one knows who is in them: it’s a problem of identity that pseudonyms could solve.  We generally take proving identity in the real world generally means proving who we are, but in the chat room we can clearly see the problem in a digital identity context.  It’s not who you are, but what you are:  are you an adult, UK subject, Manchester City fan, British Airways customer or a single parent?

Suppose that teenagers were given avatar by their school, or their parents’ bank or as in an interesting pilot scheme for children in care, a charity (for example, the Who Cares Trust, who presented on a version of this idea at the 4th Digital Identity Forum back in 2003).  Now suppose that the pseduonym (ie, public key certificate) contained a few unforgeable credentials (“I am between 14 and 18”, “I am male”) but that the children could choose any name they wanted for the ID (“I am David Beckham”). This gives the best of both worlds: the kids can log on to appropriate chat rooms, but no-one else in the chat rooms (nor the chat room operators) will know who they really are.�

My bank could give me an avatar of Donald Duck, but I couldn’t use it to get up to no good because if a police warrant asked my bank who “Donald Duck” is, it would tell them: and naturally the chat room operator — such as Microsoft — would only accept pseudonyms from reputable organisations such as my bank.  Thus, no-one in the chat room would know the real identity of the participants but none of the participants could get away with any illegal behaviour.  In just the same way, a travel agent might be happy to accept my BA Executive Club pseudonym, which leads us back into the world of federation etc..

I can’t believe how long ago it was that we started to use the “chatroom paradox” as a way to help clients think about some different aspects of identity and identity-related business. Seven years on, and I’m still writing magazine pieces about the chatroom paradox (I’ve just finished one for another journal) and the problem still isn’t fixed and the politicians and regulators still see security and privacy as opposite sides of a crazty balance.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Monday Museum: Cloning e-passports

[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is another in our “Monday Museum” series, from� 24th August 2006.

[Stuart Fiske] Because of the CHYP Electronic Passport Interoperability Service, we’ve already had a few calls about today’s Wired News story on the cloning of e-passports.   But what exactly is this story about?  Is it about uncrackable e-passports being broken open by hackers?  Or is it about someone reading the specifications and discovering that e-passports work as they are supposed to?

I don’t understand the word “crack” in the context of the electronic passports. There is nothing personal stored in the chip that is not human readable on the data page of the passport.  If you want to make a clone of the data inside the chip in my passport, you can do it by reading my passport: you don’t need to read what’s in the chip.  Obviously it saves a bit of time getting the digital photo out of the chip, but it’s just the same as the photo in the passport. “Basic Access Control” doesn’t protect the data stored in the chip: it just means that you have to have access to the physical passport in order to read the chip.  “Active Authentication” in the specifications allows the data to be linked to the specific chip, but it’s an optional extra which can be implemented if any government so chooses.  It’s a bit like the Static Data Authentication (SDA) versus Dynamic Data Authentication (DDA) issue for “chip and PIN” cards. Of course, if you have physical access to my passport you can read all the other chip data which secures my personal data as being valid, but you can’t change it, only copy it.   So you could copy my passport but what’s the point if you can’t change my data to match your face? When a passport control person puts your passport in their reader, it displays the picture inside the chip: if it doesn’t match the picture in the passport (or your face), I expect they will notice. Much as we love them, this is just not a “brilliant hackers break unbreakable code” story.  It’s a “person reads specification” story.

I don’t think much has changed in the press reporting of this kind of story over the years. The stories never reflect the kind of risk analysis that has gone into the design of such systems and as a consequence they don’t reflect real vulnerabilities.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Anonymity - privilege or right?

[Dave Birch] The issues of social media free speech, anonymity and the possibilities for action rather than words about illegal activity are much in the news in the UK this week because of the disgusting Twitter campaign against the women's rights campaigner Caroline Criado-Perez. The basic dynamic was well summarised in The Guardian by the MP Stella Creasy.

For anyone who appreciates and uses social media free speech should be inviolable. That includes ensuring abuses of that freedom do not infringe on the ability of anyone to exercise it. To challenge, call out, parody or criticise someone is to practise freedom of speech. To threaten them with rape is not.

[From Twitter's inadequate action over rape threats is itself an abuse | Stella Creasey | Comment is free | The Observer]

There is a talk about trying to get Twitter to add a "report abuse" button. Personally, I think that would be a little pointless. And while the tweets at issue are illegal, it's also pointless reporting them all to the police. There are not enough police persons in the UK to track down all of the perpetrators, even if they could. When everyone is focused on one high-profile case, I can well believe that the police will track down and arrest one or two perpetrators and send them through the court system, but for the great majority of cases this will never happen. And, as Dr. Brooke Magnanti notes in The Telegraph, what constitutes abuse is itself problematic.

On Twitter, the definition of a troll sometimes means "prolific abuser". But it's also become an umbrella term that can mean anything from "someone who disagrees with me" to "someone with fewer followers than me". It's a slippery definition that is far too often trotted out to silence dissent.

[From Feminists boycotting Twitter is not the way to end trolling - Telegraph]

We all recognise abuse when we sit, but I think it might be very difficult to explain this to a computer so that it can run some kind of automated anti-abuse Claire Perry-style filter system. Of course, we could simply say that abuse is in the eye of the beholder and instruct the police to follow up whenever anyone claims that they have been abused.

A university lecturer could be sent to prison for calling a city MP a “coward”. Alex Cline faces a two-day trial after a court heard Hove MP Mike Weatherley complained to police about the name-calling in November.

[From Brighton man faces jail for calling Hove MP Mike Weatherley 'coward' (From The Argus)]

I hate the bullies as much as anyone else. I want something done about them, but well-meaning campaigns about boycotts and such like will not do anything about this problem. I think there is a solution. Let me take you through my thinking. The place to start, I think, is by first of all by dealing with the issue of whether people should be allowed to be sort-of-anonymous in online communities. The author and campaigner Heather Brooke, mades a very good point.

But the idea that anonymity is a right and not a privilege is wrong. There needs to be good reason to avoid being accountable for what we say or write, particularly if what we say affects other people. Too often online, anonymity is the tool of the bullying coward, a means to avoid responsibility for publishing threats, abuse and lies.

[From Anonymity is a Privilege Not a Right « Heather Brooke]

This is a perspective that I think is broadly correct. If people publish threats there should be a mechanism to hold them to account. But what does it mean to a technologist? How would this "right" be implemented? I think it is important that we find a way to do this that does not abolish anonymity, which has many useful social functions — not only for whistleblowers and political activists, for people enquiring about health issues or unpopular causes, and so on — but provides a "smash the glass" option for when things go wrong.

Concurrent with the end of anonymity will, obviously, be the end of privacy.

[From 11 Big Tech Trends You'll See in 2013]

No, no, a thousand times no. We must not sit back and accept this! I think there is a better way. Here's what the "father of the Internet", Vint Cerf, says about it.

"Anonymity and pseudonymity are perfectly reasonable under some situations," Cerf said. "But there are cases where in the transactions both parties really need to know who are we talking to. So what I'm looking for is not that we shut down anonymity, but rather that we offer an option when needed that can strongly authenticate who the parties are."

[From Google services should not require real names: Vint Cerf - Yahoo! News]

He is, as might reasonably expect, absolutely correct. Real pseudonymity is a real solution. If there were organisations out there capable of linking your online persona to your mundane existence, they could act as a responsible bridge between the physical and virtual worlds. It would be like when you go to a web site to log in to something and you click on the Facebook button to log in via a standard service such as OpenIDConnect, except you'd be clicking on a button to log in via someone who actually knows who you are.

I'll use banks as the example, even though none of the UK banks currently offer anything like OpenIDConnect. But suppose they did? Suppose Barclays, which is where my current account is, were to provide such as service? Then we have workable solution that would be something like this:

  1. I go to Twitter to open an account as King_of_Wessex
  2. Twitter offers me the option of logging in by username and password, using my Facebook account or using my bank account
  3. I choose bank account, so I get bounced to Barclays and I use my dongle to log in
  4. Barclays authenticates me, and bounces me back to Twitter
  5. Twitter create the King_of_Wessex account and flag it as authenticated.

Now I can tweet to my heart's content as King_of_Wessex. No-one will know that the King_of_Wessex is me. Twitter don't know who I am because while Barclays told them "yes we have authenticated this user" they didn't tell Twitter who I am. Barclays know that they authenticated me to Twitter, but they don't know my Twitter name. This is two-sided conditional pseudonymity.

So why would we bother doing this? 

Well, Twitter could then add a setting to their accounts so that users could choose whether to accept tweets from unauthenticated users. Like most people, I imagine, I would set my account to accept tweets from all users, so as not to miss any good stuff. But if for some reasons I start getting hate tweets, or death threats or whatever, I would switch to authenticated accounts only.

Now imagine that I get a death threat from an authenticated account. I report the abuse. Twitter can (automatically) tell the police who authenticated the transaction (ie, Barclays). The police can then obtain a warrant and ask Barclays who I am. Barclays will tell them my name and address and where I last used my debit card. If it was, say, Vodafone who had authenticated me rather than Barclays, then Vodafone could even tell the police where I am (or at least, where my phone is).

Would the police be swamped with millions of reports? I think not. Most people in the public eye would, I'm sure, set their accounts to receive tweets from authenticated users only. Tweets from unauthenticated users to authenticated-only accounts would simply be discarded. The bullies could post away as much as they liked. Perhaps it is therapeutic for them. Who knows. I wouldn't matter, because their tweets wouldn't go anywhere. I have enough faith in the judicial system to believe that when an MP went whining to the police about being called "a coward" this would be dismissed as nothing more than robust free speech, but if I threaten to come round and punch the MP in the face, then the police would obtain a warrant and proceed.

So the question is: would the average nutter post rape threats to female journalists if they had to use their bank card to create an authenticated account? I would have thought that, after the first couple of jail sentences, the problem would sort itself out.

(There might be a way to fix the problem without the courts as well. There's no reason why the police could not have an automated system that simply sends the warrant to the bank and gets back the real name and address of the tweeter and just publishes it alongside the offending tweet!)

This, then, is the solution. Twitter campaigns are pointless, but using identity infrastructure is not, and fixing this problem might well be a good way to deliver impetus for the banks (and the mobile operators and others) to work together to provide a platform for the future that would greatly benefit all of us. The Cabinet Office Identity Assurance (IDA) programme is developing the framework. We have the standards that we need (OpenIDConnect and such like) and the banks have "two factor" authentication.

To summarise once more as a soundbite: let me create a Twitter account using my Barclays bank dongle to log in. Then if I tweet something that breaks the law, the police can take a warrant to Barclays and get my name and address and arrest me. Sorted.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The Monday Museum: Pseudonymity as a solution

[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is another in our “Monday Museum” series, from 20th July 2006.

[Dave Birch] I was at a workshop last week with a whole bunch of other people to discuss possible architectures for a public sector sort-of entitlement card (I can’t say what for as that would give it away, which I’m not supposed to do).  I was really cheered to hear, quite unprompted, someone put forward the idea of pseudonymity as a way to balance some security and privacy issues.  To hear the term introduced into a conversation at that level is, frankly, music to my ears.

It’s now a decade since I published my first paper suggesting that the combination of smartcards as a platform and pseudonymity as a  concept, might provide a practical solution to the problem of identity management in a networked age.  For anyone interested, it was “Smartcards and Pseudonymity” in the proceedings of “Smart Card Technologies”, an IBC conference held in London in October 1996.

To see why I’m so enthusiastic about it, consider the “chatroom paradox” that I’ve written about before:  Your kids want to go into a  chatroom to discuss [insert name of popular beat combo here].  You will allow them to do this but only if you know who everyone else in the chatroom is.  However you will not allow your children to reveal their real identities in the chatroom, so you end up with an unsatisfactory situation.  Everyone wants everybody ELSE to provide full disclosure but they don’t want to do it themselves because they don’t trust everybody else. Now imagine a situation where the school issues the children with certificates that confirm that they are in  fact of a certain age, in a certain geographic area or whatever, but the children are allowed to choose their own pseudonyms.  The  chatroom can now verify the certificates on entry so I can be sure that all the other nyms in the chatroom are actually children and not FBI agents or whoever.  Similarly the other nyms can verify that my children are actually children without having any idea who they are. If one of the nyms misbehaves, then the certificate issuer (ie, the school in this case) can easily tell the plod who the miscreant is.  Pseudonymity does not provide a means of getting away with anything. I wonder if we’re finally getting somewhere in producing a realistic solution to a key identity problem, or am I reading too much into one mention of my favorite word?�

I still think that pseudonymity provides a potential architecture for online identity that delivers both privacy and security!

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The Indian experiment is not for us

[Dave Birch] When it comes to online business in general and online finance in particular, the issue of identification and authentication continues to form a barrier to innovation and efficiency. There are different ways to approach this problem, and one of them is to have the government provide identity infrastructure as a public good designed to benefit the whole economy. Some countries do not have national identity schemes that might form a basis for this kind of cross-sector solution. The UK is one of them. What would it be like to develop one? We have a fascinating case study evolving in front of us. India is engaged in a gigantic experiment to create a national identity scheme for more than a billion people, from scratch. It is called the “Aadhaar” scheme and it involves giving a 12-digit individual identification number to citizens. The numbers are issued by the UIDAI (Unique Identification Authority of India) and they are stored against the citizen’s biometrics. The June 2013 edition of Prospect magazine has a piece on this called “Twelve billion fingerprints”, in which a chap in Mumbai puts a plastic copy of his wife’s fingerprint over his own finger and uses it to fool a biometric reader, thus highlighting some worries about the chosen technology architecture. Nevertheless, the article also notes that the potential benefits to the Indian economy are significant, because businesses of all kinds can use the identity infrastructure to greatly reduce costs.

Market regulator Sebi today said investors can use ‘Aadhaar’ cards as a valid address proof for their accounts with brokerage firms, mutual funds, portfolio managers and other capital market entities. [It] is already permitted as a valid identity proof document in the capital market.

[From Aadhaar OK as investor ID proof: Sebi]

Obviously, for this identification scheme to be of most use to business, there must be a way for banks to validate the identification numbers that are presented by customers. This process is going to be automated.

The Unique Identification Authority of India (UIDAI) is creating software that will interface between banks and the Aadhaar portal so that banks can directly access Aadhaar details.

[From ​Banks to get Aadhaar data - The Times of India]

Given the intimate relationship between social and financial inclusion, one of the most important effects of “identity inclusion” is that the financially-excluded are now given an hand on to the first steps of the financial inclusion “ladder”. It is wrong to think of this first step as a bank account as we so often do in Europe. (indeed, the European Commission are proposing to legislate on the right to a bank account even as I write) because for a great many unbanked people, or for that matter, overbanked people, the first step is a simple prepaid transaction account. India is already taking the obvious next step to integrate identity and money infrastructures by providing just such transaction accounts that can be linked with the Aadhaar scheme.

The pre-paid card, the first in the country based on Aadhaar, will be available in the National Capital Region (NCR) and will work like a mobile pre-paid card that can be topped up in the identified banks [SBI, ICICI, Axis, HDFC, Indian Overseas Bank enabling] any resident with an Aadhaar number to walk into the identified 100 outlets by these banks and open a prepaid account with a card.

[From Soon, get prepaid cards for bank account based on Aadhaar number - Economic Times]

Now, there is of course are risks in system that uses a single centralised database in this way. In the fake fingerprint example given above, the risk is that you can pretend to be someone else. But there’s a much bigger risk. Once you can get a fake entry into the database then you are “behind the wire” so to speak, and your fake identity will never be challenged. This has already happened in the Indian system.

Some have managed to beat the so-called unbeatable Unique Identification (UID) system and got fake Aadhaar numbers generated raising security concerns over UPA’s new UID based governance model.

[From UIDAI cancels 3.84 lakh fake Aadhaar numbers - Hindustan Times]

There are a variety of ways to get on to the database fraudulently but one mechanism that seems to have been exploited right from the beginning is the exception handling. Given any system of this scale, the human factor must come in to play. Since it is not possible to register everyone through the normal channel (e.g., disabled people without fingerprints, people in the witness protection programme, spies and so on) there must be exception channels and these become an attack vector.

Delhi government officials have detected a large number of fraudulent enrolments in the first phase of Aadhaar that ended in February after registering 1.3 crore people in the city. Officials in the Unique Identification Authority of India (UIDAI) said on Monday many people got themselves enrolled without providing their biometric identification. The “biometric exception” clause is essentially meant for rarest-of-the-rare cases, say, for people with high degree of physical disabilities, they said.

[From Fake enrolments in Aadhaar Phase-I spark security fear]

This sort of thing is inevitable in such a scheme. But there’s another problem with centralisation: it creates a “honeypot” for personal data. And, again, the theft of this data is hardly a hypothetical.

Biometric information from over 14 lakh people has gone missing. This could lead to vital data falling into criminal hands.

[From Biometric information of 14 lakh Aadhar applicants goes missing : Postnoon]

It’s not for me to say whether the benefits of the Aadhar outweigh the risks, since I genuinely do not know. But what I would day is that this architecture is not right for the UK or the USA. The better architecture is to have very strong authentication against a revocable token (e.g., a smartphone) and use different biometrics in the central database purely for the purposes of eliminating duplicates. The central database is there to ensure unique identities, but the transactional authentication is against the token. Without going into all of the reasons why (OK, here’s one: undercover police officers must be able to have two tokens, one for their police identity and one for their undercover identity), the more decentralised option provides simultaneously more security and more privacy. When the UK comes (as it inevitably will) to require some kind of “entitlement card”, then I hope that it chooses that option.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Biometric tick

[Dave Birch] In “Banking the World — Empirical Foundations of Financial Inclusion” by Cull et al, there is a very interesting case study on the use of fingerprinting to manage credit and repayments amongst farmers in Malawi. In Chapter 13, “Use of Biometric Technology in Developing Countries” by X. Gine, J. Goldberg, S. Sankaranarayanan, P. Sheerin and D. Yang, the authors describe how biometric technology worked in practice in a field experiment amongst paprika farmers who had applied for an agricultural loan from a government lender. The farmers were randomly allocated between a control group and an experimental group who had a fingerprint collected as part of the loan application process. Fingerprint recognition was chosen because it was cost-effective and reasonably robust in the circumstances. Despite the farmers having worn and damaged fingerprints, as you might imagine, only 2% failed to enrol with the right thumb and had to use another finger instead.

The study showed that fingerprinting led to increases in the loan repayment rate of almost half amongst the highest risk groups, but had no impact on the repayment rate amongst the low-risk groups. What an interesting result. The authors cite a rough cost-benefit analysis of the experiment which suggested that the benefits of improved repayments greatly outweighed the costs of equipment and fingerprint collection. In both the high- and low-risk groups though, the farmers now had a biometrically-verifiable credit history. Having a basic credit history is, as we all know, are really important step on the ladder of financial inclusion with very beneficial effects.

The authors also noted, however, that fingerprints aren’t tremendously accurate. If you’re going to use fingerprints to identify people from a large population this could be a big problem. On the other hand if you are authenticating people against a card (or a phone, for example) from a smaller population such as farmers who have obtained agricultural input loans in a particular district, then the speed and convenience of the fingerprint authentication make it a reasonable choice. Once you start messing around with fingerprints at population scale, then the cost and complexity rides astronomically.

Police zeroed in on Afsar after UIDAI confirmed that all the authorization fingerprints used for the enrollment of the 60 persons in biometric exception category were his. Afsar, who used to work as a data entry operator with IL&FS, had quit the job in August 2011.

[From Seven booked in Aadhaar fraud - Times Of India]

What I’m saying here is that fingerprints for authentication, in context as a convenience technology, provide what seems to be a much better cost-benefit balance than fingerprints for identification, in context as a security technology. The convenience point is at the heart of the mass market proposition, and it is undoubtedly why Apple decided to take a look at the technology*.

“Apple is not going to the trouble of adding a biometric sensor just so that you don’t have to use a four digit password. They are adding a biometric sensor so that the iPhone can become a safe and secure payment device,”

[From Some Ideas for What Apple Could do With Its AuthenTec Purchase - Technology - The Atlantic Wire]

No, they are adding a biometric sensor so that the iPhone can become a safe and secure identity management device, and one kind of identity it will manage will be financial, and one kind of financial identity will be payments. Apple understands the location of biometrics in the consumer space: convenience, and Apple is all about convenience. Remember, these iPhones aren’t going to be used to launch nuclear missiles or identity people in databases: these iPhones are going to be used to 1-1 local matching of fingerprints to stored templates to authenticate amongst persona. I think one of the first blog posts I ever wrote was about this!

* A couple of weeks before this Apple announcement, which I knew nothing about, I was interviewed for a television programme and I confidently predicted that fingerprint authentication would make its way into the next generation of mobile phones and — for reasons too boring to go into here — specifically mentioned Authentec as supplier of decent kit in the fingerprint authentication field. So I got to big up Authentec on a television programme a couple of weeks before Apple bought them for a few hundred million dollars and made me look like a guru. Thanks Apple!

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.