Special Feature: Electronic voting, electronic identity and electronic entitlement

Dgwb blog white border

There is a good way to fix the problems with voting, and it’s not with photocopies of gas bills or Railcards. Time for a National Entitlement Scheme.

Something must be done.

At Consult Hyperion, we are interested in electronic voting for three main reasons:

  • We are thought leaders in the digital identity space and electronic voting is a key “stress” application for digital identity;
  • We advise public sector clients on national identity and identity-related schemes (eg, the Irish Government’s Public Services Entitlement Card);
  • While people think about electronic voting in national and other political elections, there are a great many other applications of interest to our clients. A good example is the use of electronic voting for corporate purposes to replace postal voting at shareholder meetings, where the techniques developed for political elections could be used to reduce costs.

The practical deployment of, and experiences learned from the use of, new electronic voting systems are invaluable input into the wider question of identity infrastructure for a modern society, which is why we were delighted to be able to sponsor the 4th International Conference on e-Voting and Identity at the University of Surrey last year. This turned out to be an excellent event and we learned a lot about the different approaches to the problem, constraints, potential solutions and so on. As it happens, there are a great many practical problems around voting, and the solutions are complicated. But there are real social needs that must be addressed, and one of them has just reappeared in the British media.

Voters should be required to show photo ID at polling stations in Great Britain to lessen the risk of fraud, the Electoral Commission has said.

[From BBC News - Voters 'should be required to show photo ID at elections', says watchdog]

Personally, I’m in favour of voter IQ laws as well as voter ID laws, but there you go. While electoral fraud is not rampant in the UK, it is certainly not non-existent. The Electoral Commission in fact identified 16 out of the 400 local authority areas in the UK as being at risk, one of these being my own dear Woking, where we have a long and proud traditional of electoral fraud and only last year one of the candidates in local elections was found guilty of electoral fraud. The Electoral Commission highlighted the major problems that have been identified around postal voting (which I do not think should be allowed, but that’s another issue). Foreign readers might be surprised to learn that when you go to vote in the UK you simply give your name and it is crossed off of a list of eligible voters, much as it was when the first Viscount Watkinson was returned as Woking’s MP in 1950 when the constituency was created, or for that matter when Sir Talbot Buxomley was first elected MP for Dunny-on-the-Wold in the reign of George III. This arrangement is no longer immune from the suspicion of personation, so the Commission has recommended the use of photographic ID.

The research revealed that some people were concerned that a requirement for photographic identification would discriminate against certain groups of electors, who would not necessarily have any form of photographic documentation, such as a passport or driving licence.

[From Security Document World]

Similar issues are to the fore across the pond where the US voter ID situation is in a bit of a mess. If I understand the current situation properly, one of the problems with the just-introduced Voting Rights Amendment Act 2014, which is a response to the Supreme Court striking down part of the Voting Rights Act last year, is that there is potential for discrimination against people who are not able to obtain a “Voter ID” card. You can see their point. In other countries, this isn’t a problem, because everyone has some form of ID card. But in the US which, like the UK, has no identity infrastructure, then “systems” developed for other purposes will have to be sub-optimally commandeered. This is the sort of thing that is going to be proposed in, to pick a random example, Nevada.

The new voting system also would link with Department of Motorized Vehicle’s license database, allowing poll workers to visually verify the identity of the person attempting to vote.

[From Nevada secretary of state gets mixed reaction to voter verification proposal - Las Vegas Sun News]

Since the British government recently announced that it was going to put driving licence details online anyway, then I imagine there would be some pressure to use this database, despite its being known to be notoriously inaccurate. But what else do British subjects have to hand with a photograph on it, if not a passport or driving licence? My son could use his student ID card, I suppose (although I am rather against allowing students to vote, on principle) although I’ve no idea how it might be verified on the day. Perhaps they could ask us to sign to vote?

Untitled

On a recent expedition to New York I was asked for photo ID as condition of entrance to a well-known landmark. I produced the (expired) building pass for our Madison Avenue office as was waved through. Which illustrates what is to me a central problem: if I am required to produce a photo ID at a polling station, it will do nothing to prevent fraud. The polling stations are manned by local volunteers doing their civic duty, not by expertly-trained anti-fraud personnel who are skilled in the inspection and detection of counterfeit identity documents. If I show up to vote and present a driving licence, a Portugese fishing licence or an England football club supporter’s card, the polling station staff will have no means to verify it. As it happens, some UK pressure groups are against photo ID in principle anyway, because it discriminates against people who don’t have a photo ID. Consequently,

the idea of voters being requested to provide a non-photographic form of identification at the polling station was welcomed in principle by both the public and electoral administrators.

[From Security Document World]

This seems utterly stupid to me but it is certainly in the great British tradition of pointless activity! It follows the tried and tested political theory of “something must be done, this is something, therefore it must be done”. So the Mother of Parliaments will rest on a franchise that is protected by photocopies of gas bills, since as we all know, electoral terrorists dedicated to subverting democracy will be unable to forge those. Not that I can produce one anyway, because my gas bill is electronic.

Compared to this, the TSA’s decision to accept Facebook profiles as valid identity for boarding flights in the US seems sound. On balance, I judge it to be far harder to forge a plausible Facebook profile than a plausible gas bill, so if I turn up at the polling station and log in to the Facebook profile for David Birch (if there is a Facebook profile for a David Birch, incidentally, I can assure you it isn’t me) then they may as well let me vote.

The USA’s Transport Security Administration is accepting sight of a traveller’s Facebook profile as a form of ID, it has emerged.

[From Facebook profile accepted as ID at airport security | The Drum]

One can imagine that this approach might itself still be further secured by the addition of photo ID. There’s an app for that…

An upcoming app for Android, iOS, and Google Glass called NameTag will allow you to photograph strangers and find out who they are — complete with social networking and online dating profiles.

[From Facial recognition app matches strangers to online profiles | Crave - CNET]

So all we need to do is equip the polling clerks with Google Glass and job done? I don’t think so. I think we should think about what infrastructure is needed here and then work out the best to way implement it. There are a great many circumstances in which I would certainly imagine a Facebook profile to be a much better form of identification than a photocopy of my gas bill, but voting isn’t one of them, especially if there are already concerns about fraud.

But Electoral Commission chairwoman Jenny Watson said most voters could use passports, driving licences or even public transport photocards to prove who they are at polling stations. Those without any of these documents could request a free elections ID card, she added.

[From BBC News - Voters 'should be required to show photo ID at elections', says watchdog]

I am not making this up. Gas bills, Facebook profiles and railcards. That is where our democracy is in 2014. What a joke.

This is something.

The real solution is, of course, not using Railcards or football supporter’s cards, or indeed special-purpose election ID cards, but a general-purpose National Entitlement Scheme (NES). Few readers will remember this, but some time before the UK government’s last attempts to introduce a national identity card, there were consultations around a much better idea, which was a national entitlement card. As my colleague Neil McEvoy and I pointed out in Consult Hyperion’s response to this consultation, the “card” is only one mechanism for storing and transporting entitlements and in the modern age there might be better ones, such as mobile phones for example, that can not only present credentials but also validate them.

It is time to revisit that proposal to try and get the British government out of its muddle about identity infrastructure. A future administration will certainly have to introduce something, not only because of the issue of voting fraud but due to continuing concerns about illegal immigration, health tourism, benefit fraud and so forth. Suppose that the vision for national identity (based on the concepts of social graph, mobile authentication, pseudonyms and so on) focused on the entitlement rather than on the transport mechanism or biographical details? Then, as a user of the scheme, I might have an entitlement (ie, a public key certificate) on my purpose-built national entitlement card (so that’s some of the population taken care of), I might have a entitlement certificates on my bank card (so that’s the overwhelming majority of the population taken care of) and I might have certificates in my mobile phone (so that’s 99.9% of the population taken care of). Remember, these certificates would attest to my ability to do something: they would prove that I am entitled to do something (access the NHS, open my office door, buy things in Waitrose), not who I am. They are about entitlement, not identity as a proxy for entitlement. The government could give out free smart card readers (as they do in Spain) or leave it to the banks to distribute them.

In practice, I think the example set by a modern countries such as Turkey and Estonia are most attractive: I log in to the whatever with some pseudonym, the service provider sends a message to my mobile phone (over-the-air or via NFC or BLE in the future), the PKI in my SIM decodes the challenge and signs the response, and I’m connected. Securely and simply. And if other service providers want me to log on in the same way, they can issue their own certificates as well. There’s a similar approach to this in Norway except there the IDs are issued by the banks and used by the government and other private sector organisations. Imagine a national entitlement scheme that used this technology: it would be efficient and cost-effective, since it would use the phones that people already have to deliver services that they definitely want.

And, best of all, my phone would be able to check the entitlement presented by your phone, so none of us would need special equipment. I show up with my phone and claim that I am entitled to vote: my phone presents a meaningless but unique number, this is entered manually or automatically into the polling clerk’s phone which flashes up my picture if I am entitled to vote or a red cross if I am not. I show up with my entitlement card and the polling clerk reads it using their NFC interface, and so on. Instead of postal votes, the polling clerk can go to the old folk’s home and let them vote individually, certain that they are not being threatened or cajoled.

Should people be allowed to go one step further and simply log in to vote from home? For political elections, I think not. Voting must be in public in order to dispel any suspicion of coercion. Maybe it won’t have to be a polling booth any more (you could have general elections that last a week during which people can vote at Post Offices or bank branches or whatever), but it has to be somewhere public.

Therefore it must be done.

It seems to me that a national plan to finally do something useful about identity might obtain “parasitic vitality” (to use one of my favourite ID phrases) from the specific issue of voter ID. In the UK and in the US, this might be a way to both improve security around the act of voting as well as vector for deployment. Maybe electronic voting can be a focus to get the Cabinet Office’s Identity Assurance (IDA) scheme a flagship and get the public and private sector working together to deliver an infrastructure that will be of benefit to all.  I should mention in passing that we have been working with the Cabinet Office on one of their “Alpha Projects” in the North of England which, as it happened, included photo ID for authentication as one of the use cases.

I’ll be talking about the idea of National Entitlement Scheme (NES) in my keynote at the 17th annual Consult Hyperion Tomorrow’s Transactions Forum in London on 19th and 20th March 2014. Unfortunately, mine will only be the second most interesting keynote at the event, because the kick-off keynote will be by Felix Martin, the author of “Money: The Unauthorised Biography”. As always the Forum — thanks to the fantastic support from our platinum sponsors Visa Europe & VocaLink, and our sponsors Fiserv & Olswang — is limited to 100 places. Oh, and did I mention that all delegates will be getting a complementary copy of Felix Martin’s excellent book, by the way?

See you at the America Square conference centre on 19th March at 9.30!

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Will the Target breach boost EMV in the USA?

Dgwb blog white border

How exactly does switching to the “chip and PIN” system used everywhere else in the world (except North Korea, I’m told) stop the kind of thing that’s been going on at Target?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Politicians just don’t understand the Internet

Dgwb blog white border

The early days of the British government’s new cyber-filter have been predictably amusing, but they highlight a serious issue. What are the principles? What do politicians want the technologists to do?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The real wallet wars are about to begin, and they’re not about payments

Dgwb blog white border

The most important thing in digital wallets will be identity, not money. If you’re sick of listening to me about this, listen to @Jack.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Threats, risk and attacker motivation: a real life example

Margaret FordTravelling home from a meeting at the Payments Council on Monday afternoon, I was enjoying the peace and quiet of the train gradually emptying as it drew further out of town. At Sunningdale, a station normally notable only for the most prosperous passengers, a group of excitable teenagers joined the train obviously looking for trouble. Brandishing camera phones, they seemed more of an irritant than a threat.

Avidly reading advice on strategies to avoid arrest by over-zealous US police officers, quoted in an article from the latest edition of Cryptogram, I felt comfortably detached from my surroundings. The luxury of a half-empty train on the Reading line is a rare treat.

The author of the article advised that unlawful activity is best indulged in from the comfort of your own home. If you must commit crimes in public, avoid drawing attention to yourself. In particular, even if you become aware of an officer while performing an illegal act, it is better to continue rather than raise suspicion through a sudden change in behaviour.

At this point I became aware that I had unwittingly become the focus of the gang, who had moved on from threatening to punch random strangers to wielding newspapers and cigarette lighters while daring each other to take my phone. Suddenly alert to the situation, I put my phone away, muttered ‘excuse me’ and wandered gently up the carriage. They left the train at the next station.

I’d made the mistake of forgetting that my brand new phone which I regarded as a standard device for accessing content and keeping in touch, could also be seen as a status symbol with significant market value. On reflection, it gave me a tangible example of one of the key risk concepts being investigated by the TREsPASS project: attacker motivation. This had moved from the general to the specific, as an opportunity was spotted and the incident unfolded. It was clearly unpremeditated and yet in many ways predictable.

As my brother commented the next morning, teenage gangs in our area just aren’t what they were in our youth, when they would steam the length of trains in groups of twenty or more. He also gave me a great tip for protecting my phone in future, which in his experience deters all potential muggers.  Waterproof, costing only a few pence, with the option of additional cotton wool for extra authenticity: an attractive little black plastic bag with yellow drawstring, as commonly carried by dog walkers.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Card crime and nostalgia

Dgwb blog white border

In America, card fraudsters are wrapping satellite dishes in tinfoil to stop terminals from going online and then using counterfeit and stolen cards to buy gas. Amazing! I had no idea that people still used satellites for this sort of thing.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Fraud – milking the system

DGWB_Square_LIFT_small.jpgI almost fell off of my seat on the train when I read what I think may well be the official Tomorrow’s Transactions Burgundy Ribbon favourite newspaper story of the year. Yes, the head of a bank being a #crystalmethodist was good and #Higella’s revelations about Charlie and cash were good, but I think that it is very hard for anyone in the world of digital identity and digital money to top� the story of the Romanians who claimed over half a million dollars in agricultural subsidies for their cows… in Farmville.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The internet of things needs some thinking through

[Dave Birch] There was a story in the British newspapers recently about an Italian criminal family (literally, a father and son) who were arrested for selling fake Romanée-Conti wine (a Burgundy that is one of the most expensive in the world at £14,000 a bottle). The police say that the fake labels applied to the bottles of plonk were “near perfect”. Aha. My eyes pricked up at this. A genuine problem, for which there may be a technological solution that some of our clients could benefit from supplying.

The NFC tags are located behind the label on the winery's Vintage 2010 range, with bottles selling at €2,000 to €2,500 each.

[From French winery picks NFC tags for authentication • NFC World]

Setting aside the interesting technical question of whether these tags are actually NFC or not, I have to report that this is not a new use case for contactless. I wrote up the use of RFID in the drinks business in Korea three years ago when we were looking at some identity-related business cases for one of our telecoms clients.

When the whiskey is bottled, the caps have an RFID tag added to them. This is coded with a URL and an identifier. When a customer, or a shopkeeper, or a policeman, or in fact anyone else wants to check whether the whiskey is real or not, they touch the cap with their phone and the URL launches a web site that knows the provenance of the identifier and can tell you when and where it was bottled as well as some other information. When the customer opens the bottle, the tag is broken and can no longer be read.

[From Digital Identity: There's whiskey in the jar-o]

I happened to find myself sitting next to Erik Harvey from iProof, one of the leading companies in this field, at the WIMA NFC event in San Francisco this week, and he made the very sound point to me that to work for all the stakeholders, systems such as these must involve the consumers. If consumers don’t tap on or scan the labels then there’s no data flowing around the system. We need consumers to be an active part of the anti-counterfeiting activity or it won’t work: they have to want to take part. I think, with the appropriate messaging, that they would. After all, who wants to be embarrassed serving a fake wine at dinner and, aside from that, who doesn’t want to learn more about a wine that they try and like? I’ve often seen people use their mobile phones to take the picture of the label on a bottle at a restaurant, presumably because they find the wine delicious and may want to order it again in the future.

This problem of epicurean counterfeiting is not confined the exclusive French vineyards. It’s a problem the world over, although it takes different forms in different cultures.

The bird's nests can be sealed in a box with an RFID tag that contains a microchip embedded with details about the harvest. A handheld scanner emits a radio frequency to unlock that information.

[From BBC News - RFID technology thwarts bird's nest counterfeiters]

Now, as have pointed out more than once in this context, the tag by itself isn't very useful (especially since absolutely no-one bothers implementing the security layer of NFC). The people who steal authentic labels from designer goods factories will steal authentic RFID tags as well. What is critical is the ability to determine provenance and this mean mutual authentication as well as a managed infrastructure.

Without an infrastructure that includes end-to-end digital signatures there's no way round this. The phone needs to know the chip is authentic. The database needs to know who is asking, and the consumer needs to know who is answering.

[From Digital Identity: There's whiskey in the jar-o]

The security of stuff in the internet of things (IoT) is a really, really interesting subject. It has implications that go way beyond protecting connoisseurs from embarrassment.

Rob Wainwright, director of the EU’s crime-fighting agency, said Europe’s black market in counterfeit foodstuffs, pharmaceuticals and machine parts doubled to a value of about €2bn in the early years of the recession.

[From Crime gangs look to clean up as Europe’s black market balloons - FT.com]

The odd couple of billion here or there doesn’t seem like a big deal to me, especially when the same article notes that VAT fraud is at least fifty times bigger, but taking counterfeit medicine or flying in a plane with a counterfeit part does seem like a big deal to me and I’d rather it didn’t happen. I hate  to say it, but perhaps some form of European co-operation might be needed…

One more thing. I don’t see that the security and privacy issues that come along with the IoT have been thought through at all. I tried to make this point a few years ago, using my pants as the target object, when I was looking at the use of RFID in high-value consumer goods. We need to develop an additional layer that delivers both enhanced security and enhanced privacy. It’s one thing for dinner guests to scan my wine bottle to see that it is a real Romanée-Conti and another for them to scan my Rolex to check that it is indeed a first-class far-eastern knock-off, but it’s quite another for them to be able scan my underpants and determine that they date from 1983. How do we turn tags on and off? How do we grant and revoke privileges? How do we allow or deny requests for product or provenance? These are difficult questions.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Scary movie

[Dave Birch] Well, it’s Halloween. I never much cared for it, as I was brought up on the traditional British November 5th celebration of intolerance, Guy Fawkes night, when we remember, remember the failure of our first great religious terrorist, Guido Fawkes and joyously dance around burning effigies of noted criminals, spiritual leaders and so on. To take my mind off of it, I went off to Digital Disruption 2013 to see how our clients on the telecommunications side of things might take advantage of changing technology.  I ran into a French lady there.  She was a little overdressed, if you ask me, but I don’t know too much about fashion so I was in no position to judge!  Anyway, as she seemed to venerate the fashions of a now-distant past, I went over to ask whether she saw much future for NFC or not.  I asked for her perspectives on the MNO NFC efforts underway in France.  She seemed a little puzzled, and I thought perhaps her English was not too good, and I tried again, only this time speaking loudly and slowly.  But nothing.  Perhaps I was talking at too high a level, so I went down a notch.  It took me a while to explain to her the difference between NFC interfaces and card emulation interfaces, but eventually she screamed with delight at my incisive analysis of the varying technology roadmaps associated with secure element-based NFC payments and “NoSE” (No Secure Element) applications.

Untitled

She told me that she had to go and have her head chopped off, so I went looking for someone else to talk to.  One of the stimulating topics of conversation that I thought of was the difference between “chip and signature” and “chip and PIN” and why the inclusion of PIN at the top of a card CVM list would lead to one or even two orders of magnitude less fraud.  I fancied this as a sound conversational stratagem because it would inevitably lead to a quite heated discussion about US market strategy.  I mentioned this to a gray-haired chap standing next to me and he stared at me blankly!  So I explained it all again, but this time in a little more detail.  He must have been a visitor as he didn’t seem to understand me either, even when I showed him a collection of cards with different CVMs.

Untitled

Oh well, I spotted some people dancing and I thought it would be fun to join them.  I saw one nice looking lady delegate so I thought I’d ask her to dance.  She seemed a little vacant to me but it had been a long day, so I thought I would try and cheer up with a funny story about the development of smart watches.

Untitled

As you can see she thought it was hilarious!  When I got back to the hotel,� I blogged about it so that you can all enjoy it.  She made some comment about how much the living must envy the dead and vanished, unlike Tony Poulos who is surprisingly hard to get rid of unless you happen to pass a bar serving free beer, which we did.  I then ran into a group of dedicated electronic transaction fans who I noticed were following me.  I didn’t quite catch what they were talking about, so I thought I’d introduce myself and see if they were fans of the “Atlantic Model” of federated identity management along the lines of the US NSTIC and UK IDA initiatives.  I took their silence to be agreement.

Untitled

They seemed genuinely surprised when I told them some of my ideas for separating the fundamentally different telco activities of identity provision and credential and reputation management and how the telcos might provide open, transparent and non-discriminatory access to the basic identity services for third-party credentials.  I didn’t quite catch what they said about it (rather amusingly, it sounded like “kill me”, but I think they were actually saying “tell me”) but by that time most people had gone and the area was deserted.  I was thinking about the different strategies being adopted by our clients in the USA and Europe, particularly because of the European regulatory, when I bumped into a chap who appeared to have the haunted look of a banker who had been studying the European Commission’s consultation document of direct access to bank accounts by licensed third-parties.  He seemed quite interested but unfortunately I didn’t have time to finish my explanation of the Single European Payment Area (SEPA) and the current state of pan-European migration to the new SEPA Credit Transfer and SEPA Direct Debit standards before the lights went out at midnight and I was forced to find my way out in the dark.

Untitled

While I was doing this, surrounded by people working at the forefront of the telecommunications sector, preparing my notes for the session that I was going to chair on Data Security and Privacy, I became mildly excited.  You know, if identity really is the new money, that could be great for the telcos because they are obvious contenders to provide the identity infrastructure.  But, of course, the telcos in general and the MNOs in particular might decide to leave these crucial elements of the new economy to other players:  Facebook, maybe, or Apple or Google.  If that happens, then some of our most important clients will find themselves bypassed by service providers who see the telcos as nothing more than dumb pipes.  Now that’s really scary.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Dave Birch has a lovely pair of knees

[Dave Birch] I was tangentially involved in discussion about biometrics while working on a technology roadmap for one of our clients in the financial services sector. I was arguing my usual point, which is that mass market biometrics are about convenience, they are not a security play. In passing the issue of biometric accuracy was raised, and a useful discussion ensued. I. I'd like to amplify a point that was made in passing and introduce some data points.

The Unique Identification Authority of India (UIDAI) has successfuly conducted a proof of concept iris authentication study in the Mysore district of Karnataka, achieving accuracy levels of above 99.2 per cent, an official press release said here today.

[From UIDAI’s iris authentication proof of concept study successful | NetIndian]

At population scale, 99.2% is not very good. If you had a 99.2% effective contraceptive, the average woman using it would get pregnant every year. In closed environments, matching an iris against a token-based template as a PIN or password replacement is plausible but population-scale iris matching against a database for identification requires more thought. In the UK, the government shut down the IRIS system for border control back in 2012 in favour of e-passport scanning. Of course, iris isn't the only biometric that might be used in the future.

A new lab is working to perfect special shoe insoles that can help monitor access to high-security areas, like nuclear power plants or special military bases. The concept is based on research that shows each person has unique feet, and ways of walking.

[From Shoe ID Lab Developing Biometric Shoe To Identify Individuals Based On How They Walk

Yep. Feet. If I want to log in to your Facebook using this technology, I'll have to walk a mile in your shoes, so to speak. But gait is not the only lower-limb biometric on the horizon.

A new study involving magnetic resonance imaging suggests that MRI knee scans could be used as an almost foolproof form of identification. For the study, Dr. Lior Shamir, an associate professor at Lawrence Technological University in Southfield, Mich., analyzed knee scans of 2,686 people. He found that the scans accurately identified about 93 percent of the test subjects.

[From Knee Scan Identification: MRIs May Be Better Way To ID Travelers, Study Suggests]

In my books, 93% identification accuracy isn't "almost foolproof", it's "almost useless". Imagine the diligent anti-terrorist super-team at Heathrow Terminal 5 are on the lookout for the noted terrorist Dave the Jackal, who is known to be travelling incognito in a Facebook-blue burkha. Armed with an MRI scan of his knees, obtained by waterboarding a Cairo chiropractor, they set the scanners loose on a Monday morning. Now, Heathrow Terminal 5 carries about 65,000 passengers per day. The scanner will, broadly speaking, correctly identify 60,000 of them as not being the Jackal and send 5,000 of them for detailed investigation as potential Jackals. Say a few hundred an hour. What's the point of this?

Is this just another example of typical media innumeracy? I think not. I think it represents an underlying belief that we will be moving to biometric identification. There's a faith in biometrics, a belief that at some point in the future the biometric technologies will be so advanced that their identification will, indeed, be foolproof. The curve of technology might be taking us in that direction, but we're a long way off it just yet. This is why biometric authentication against a secure token makes for better strategy in our space. Biometrics as a PIN replacement, not biometrics as a card replacement. Or, indeed, biometrics as a phone replacement.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.