Tomorrow's Transactions » Privacy and security http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 Fraud – milking the system http://tomorrowstransactions.com/2013/12/fraud-milking-system/ http://tomorrowstransactions.com/2013/12/fraud-milking-system/#respond Fri, 06 Dec 2013 15:28:36 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/?p=79 I almost fell off of my seat on the train when I read what I think may well be the official Tomorrow’s Transactions Burgundy Ribbon favourite newspaper story of the year. Yes, the head of a bank being a #crystalmethodist was good and #Higella’s revelations about Charlie and cash were good, but I think that […]

The post Fraud – milking the system appeared first on Tomorrow's Transactions.

]]>
DGWB_Square_LIFT_small.jpgI almost fell off of my seat on the train when I read what I think may well be the official Tomorrow’s Transactions Burgundy Ribbon favourite newspaper story of the year. Yes, the head of a bank being a #crystalmethodist was good and #Higella’s revelations about Charlie and cash were good, but I think that it is very hard for anyone in the world of digital identity and digital money to top the story of the Romanians who claimed over half a million dollars in agricultural subsidies for their cows… in Farmville.

Now, as far as I am concerned the story could have stopped right there and it would have featured in Old Dave’s Almanac, or the Tomorrow’s Transactions Reader for 2014 to give it its official name, but the story went on. The government stopped the subsidies, so now the “farmers” are suing them on the grounds that they were not told that the cows had to be real. Solid gold. That’s no.1 right there. With a bullet. I cannot even imagine a story that will knock this off its perch unless it turns out that the Queen has sold the Crown jewels and put the money into Bitcoin instead.

A gang of Romanian Farmville enthusiasts insist they never realized that the government funds given for farming are actually for real animals and not virtual ones

[From Farmville Gang Cons Romanian Government for $681,000 (€500,000) Virtual Cows Funds]

Now, obviously, what was not amazing about the story was that transylvanian hillbillies were defrauding European taxpayers through the mechanism of agricultural subsidies. This is the prerogative of yokels from Norwich to Naples and the Romanians are part of the gang, so there is no shame on them in joining this particular gravy train. Well, meat and potatoes and gravy train with a boxcar full of champagne behind it. Everyone does it.

thousands of pounds was paid out to livestock owners in Slovenia for “non-existent” cattle.

[From Imaginary cows and non-existant lemon groves 'cost EU taxpayers £1.2bn' - Telegraph]

These were, of course, non-existent real cows as opposed to non-existent virtual cows. In legal terms, this seems not to make a difference, since fraud involving imaginary agricultural assets is not, apparently, a crime in Europe so I can’t see it being material whether they are in your head or in your computer’s RAM.

The CJEU has previously held that penalties laid down in rules of the common agricultural policy, such as the temporary exclusion of an economic operator from the benefit of an aid scheme, are not of a criminal nature

[From Has the Court of the European Union let subsidy fraud off the hook? | Rosalind English | Law | theguardian.com]

I must ask a lawyer about this, because if it is not crime, then I don’t really understand what the EU’s new prosecutors are supposed to do all day. Only this year, the EU kicked off a new effort to try and get the fraud under control. Rather than adopt the inexpensive and obvious path of eliminating the boondoggies by eliminating the subsidies themselves, they have decided to set up CSI:CAP to bring offenders to justice.

The European Union loses a lot of money each year through corruption and subsidy fraud. Now, a new institution is supposed to clamp down on the problem and prosecute offenders across EU borders.

[From New EU prosecutors to fight fraud | Europe | DW.DE | 18.07.2013]

Now, I certainly don’t want to suggest that our rustic rustlers are uniquely bad. Far from it. The US, for example, is no stranger to the fantastical, bizarre, absurd and criminal world of farm subsidy. Farm subsidies in the USA are tens of billions of dollars.

The federal government pays millions of dollars in farm subsidies each year to farmers who have died, because the Agriculture Department lacks the proper controls to make sure the money it sends is going to the right people, a government audit has found.

[From Millions in U.S. Subsidies Go to Dead Farmers - NYTimes.com]

This is a blog about transactions, not politics, so it is not for me to say whether agricultural subsidies are a good thing or a bad thing. For all I know, it may entirely reasonable and a vital public policy goal to support beekeepers, for example — I think it was (ie, I can’t find out after 30 seconds googling) P. J. O’Rourke who once wrote, “remember when the US economy was rocked by wild swings in the price of honey”? — But it is undeniable that the subsidies involve colossal amounts of my (and your) cash being sprayed around.

The U.S. Department of Agriculture last year spent about $14 billion insuring farmers against the loss of crop or income, almost seven times more than in fiscal 2000, according to the Congressional Research Service… The arrangement is a good deal for everyone but taxpayers.

[From Taxpayers Turn U.S. Farmers Into Fat Cats With Subsidies - Bloomberg]

So fraud involving these antiquated transfers is going to be colossal as well. Some something has to be done. Of all the options, I rather like the proposal to use (sadly unarmed) drones to police Europe’s pastoral pirates.

EU regulators are exploring potential aerial systems that can help them spot farm subsidy cheats and violators of Common Agricultural Policy rules.

[From The EU is Considering Using Drones to Police Farm Subsidies, Enforce Environmental Rules | Popular Science]

So how can we, the electronic transactions industry, help? After all, while drones are a plausible mechanism for finding real cows — unless astute agronomists start making dummy cows that look convincing from the air (we did it with tanks and such like in WWII, I’m sure we could do it with cows) or start planting concrete cows in strategic rural locations (oh, wait…) — I wonder how they are going to check for virtual cows? It is only a matter of time before the European Court of Human Rights rules that tending a virtual cow is a part of family life in certain areas.

I was under the impression that all cows in Europe had to be traced and tracked because of mad cow disease, in which case I can’t see why we don’t just chip the lot of them and use RFID to identity them for auto-subsidies. No chip, no cash, even if you are Romanian and pathologically fond of your computer-generated calves. If the EU is serious about cutting fraud, I’m sure the electronic transactions industry can help.

By the way, in farming (as in banking and journalism) this whole “real/virtual” thing is very confusing. Which is why I prefer the word “mundane” for things that still outside once my computer is switched off.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Fraud – milking the system appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/12/fraud-milking-system/feed/ 0
Friends and relations http://tomorrowstransactions.com/2011/08/friends-and-relations-2/ http://tomorrowstransactions.com/2011/08/friends-and-relations-2/#comments Fri, 19 Aug 2011 16:19:17 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/08/friends-and-relations-2/ [Dave Birch] I don't want to be friends with my bank, I want to be friends with my bank account. That's different.

The post Friends and relations appeared first on Tomorrow's Transactions.

]]>
While I was sitting through a presentation (a very good presentation, I might add) on social media strategy for one of our client’s financial services businesses, it struck me that they were slightly misjudging the more interactive and transactional nature of social media, doing great stuff but treating social media as another customer communication channel. I’m naturally more interested in social media for transactions: social commerce. I’ve given a couple of talks about this recently, pointing out the opportunities that social commerce opens up.

One prediction says social commerce will top $30 billion globally by 2015 with Facebook-generated sales one of the primary drivers.

[From Infographic: The history of F-commerce | SMI]

There are many different ways that financial services organisations can exploit this. A good example, to my mind, is the way in which Amex works with Foursquare.

Just after announcing that it passed 10 million users, location-based check-in service Foursquare has said it is partnering with American Express to give members even better deals when they check in at merchants’ stores across the country.

[From Foursquare partners with American Express for deal check-ins | VentureBeat]

This is a terrific proposition and it’s well implemented (through statement credits, so no coupons or vouchers or anything are needed). And, to follow this example, Amex also has a Facebook pages where its large number of fans can come to learn about products and services, share with the community of card holders and so on. Great stuff. And it isn’t only financial services organisations that are integrating themselves into social media to create new kinds of social commerce.

That is because the well-known mobile service provider is now allowing its customers to log on to Facebook to purchase phone credit.

[From O2 details new contactless payment technique]

Wow, that’s pretty interesting.

Pre-paid subscribers will now be able to access a secure app on the social networking website, where they will put in credit card details in order to purchase top ups.

[From O2 details new contactless payment technique]

Credit card details? Not Facebook credits? But you get the picture. Something like Facebook can be used to create a more intimate transactional environment without having to develop software, making it easy for consumers to “friend” and “like” and so forth. Personally, I don’t find this sort of thing particularly appealing because to me it’s the wrong kind of social relationship: I want something more granular.

Here’s what I mean. I don’t want to be friends with my bank — after all, I’m a typical consumer so I hate banks — but I do want to be friends with my bank account. Why can’t Barclays let me friend my current account so I can see its status updates like “Premium card fee £10.00″, “Direct Debit British Gas £37.85″ and “Counter Credit £5.00″ and so forth? I quite like the text messages that Barclays sends me but would prefer something more immediate and more detailed (I often call this “streaming commerce”) so that I can make decisions and respond.

Similarly, I don’t especially want to be friends with MBNA, but I do want to be friends with my MBNA American Express card. I’m using “friend” generically, of course, I don’t mean to imply that Facebook is the one and only way to implement a social media strategy.

Facebook usage in the UK fell nearly 4pc in July to its lowest level since 2009, sparking concerns that the social network has hit its peak and may be declining in popularity.

[From Facebook usage falls to three-year low - Telegraph]

I don’t use Facebook that much — it’s really for sharing with my brother and sister, other family members and a few old friends — and I’ve not got a crystal ball to see whether we’ll still be using it in a couple of years.

Many of the smartest people I know are leaving Facebook as well. I predict we’ll see many people leaving over the coming months and adopting Twitter.

[From The Facebook Exodus and the Future of Human Communication « Far Beyond The Stars | Cyborgs, second selves and cybernetic yogis]

My idea would work even better with Twitter though. Suppose Twitter made a small change to their system so that a user could opt to be in “secure” mode. A secure mode user can only be followed (or searched) by users in their “secure list” or whatever. Then, my MasterCard could be secure user “mc-53XX-XXXX-XXXX-XXXX” the only name in its secure list would be “@dgwbirch”. Now, when anyone else tries to follow or search mc-53XX-XXXX-XXXX-XXXX they see nothing.

I’d love to follow my John Lewis MasterCard on Twitter in the way instead of having to log in to find out what it’s been up to. Since I use Twitter all day and every day anyway, it would be a much better channel for payment products to develop a more intimate relationship with me. And think of the practical benefits: if I get a tweet from my debit card telling me it’s just been used to withdraw money from an ATM in Belarus, I can call Barclays right away to block it from further misbehaviour. This doesn’t seem terribly complex: all Barclays need to know is my twitter name and then it can use the Twitter API to post tweets and only allow me to follow them.

If I could follow my transactional instruments, I could also (in time) feed their tweets, status updates, notifications and so on into other software for mash-ups. I don’t know what kind of mash-ups – I’m not smart enough for that – but I’m sure there are people out there who could do great stuff with the data. So a plea to my account, card and service providers: I don’t want to be friends with you, because you are corporations and not mates, but I don’t want to be friends with my stuff: my money, my cards, my phone. How hard can it be?

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Friends and relations appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/08/friends-and-relations-2/feed/ 1
What do they want us to do? http://tomorrowstransactions.com/2011/05/what-do-they-want-us-to-do/ http://tomorrowstransactions.com/2011/05/what-do-they-want-us-to-do/#respond Thu, 26 May 2011 08:08:42 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/05/what-do-they-want-us-to-do/ [Dave Birch] Politicians don't know what to do about the Internet, and there's no possibility of explaining it to them. Time for professional responsibility to set the requirements.

The post What do they want us to do? appeared first on Tomorrow's Transactions.

]]>
What do the politicians, regulators, police and the rest of them want us (technologists) to do about the interweb tubes? It might be easier to work out what to do if we had a clear set of requirements from them. Then, when confronted with a problem such as, for example, identity theft, we could build systems to make things better. In that particular case, things are currently getting worse.

Mr Bowron told the MPs this week that although recovery rates were relatively low, the police detection rate was 80 per cent. However, the number of cases is rising sharply with nearly 2m people affected by identity fraud every year.

[From FT.com / UK / Politics & policy - MP calls cybercrime Moriarty v PC Plod]

So, again, to pick on this paricular case, what should be done?

Mr Head also clarified his position on the safety of internet banking, insisting that while traditional face-to-face banking was a better guarantee against fraud, he accepted that society had moved on. “If you take precautions, it’s safe,” he said.

[From FT.com / UK / Politics & policy - MP calls cybercrime Moriarty v PC Plod]

Yet I remember reading in The Daily Telegraph (just googled it: 20th November 2010) there was a story about an eBay fraud perpetrated by fraudsters who set up bank accounts using forged identity documents, so face-to-face FTF does not, as far as I can see, mean any improvement in security at all. In fact, I’m pretty sure that it is worse than nothing, because people are easier to fool than computers. I would argue that Mr. Head has things exactly wrong here, because we an integrated identity infrastructure should not discriminate between FTF and remote transactions.

I think this sort of thing is actually representative of a much bigger problem around the online world. Here’s another example. Bob Gourley. the former CTO of the U.S. Defense Intelligence Agency, poses a fundamental and important question about the future identity infrastructure.

We must have ways to protect anonymity of good people, but not allow anonymity of bad people. This is going to be much harder to do than it is to say. I believe a structure could be put in place, with massive engineering, where all people are given some means to stay anonymous, but when a certain key is applied, their cloak can be peeled back. Hmmm. Who wants to keep those keys

[From A CTO analysis: Hillary Clinton's speech on Internet freedom | IT Leadership | TechRepublic.com]

So, just to recap, Hillary says that we need an infrastructure that stops crime but allows free assembly. I have no idea how to square that circle, except to say that prevention and detection of crime ought to be feasible even with anonymity, which is the most obvious and basic way to protect free speech, free assembly and whistleblowers: it means doing more police work, naturally, but it can be done. By comparison, “knee jerk” reactions, attempting to force the physical world’s limited and simplistic identity model into cyberspace, will certainly have unintended consequences.

Facebook’s real-name-only approach is non-negotiable – despite claims that it puts political activists at risk, one of its senior policy execs said this morning.

[From Facebook's position on real names not negotiable for dissidents • The Register]

I’ve had a Facebook account for quite a while, and it’s not in my “real” name. My friends know that John Q. Doe is me, so we’re linked and can happily communicate, but no-one else does. Which suits me fine. If my real name is actually Dave bin Laden, Hammer of the Infidel, but I register as John Smith, how on Earth are Facebook supposed to know whether “John Smith” is a “real” name or not? Ludicrous, and just another example of how broken the whole identity realm actually is.

For Facebook to actually check the real names, and then to accept the liabilities that will inevitably result, would be expensive and pointless even if it could be achieved. A much better solution is for Facebook to help to the construction and adoption of a proper digital identity infrastructure (such as USTIC, for example) and then use it.

The implementation of NSTIC could force some companies, like Facebook, to change the way it does business.

[From Wave of the Future: Trusted Identities In Cyberspace]

That’s true, but it’s a good thing, and it’s good for Facebook as well as for other businesses and society as a whole. So, for example, I might use a persistent pseudonymous identity given to me by a mobile operator, say Vodafone UK. If I use that identity to obtain a Facebook identity, that’s fine by Facebook: they have a certificate from Vodafone UK to say that I’m a UK citizen or whatever. I use the Vodafone example advisedly, because it seems to me that mobile operators would be the natural providers of these kinds of credentials, having both the mechanism to interact FTF (shops) and remotely, as well as access to the SIM for key storage and authentication. Authentication is part of the story too.

But perhaps the US government’s four convenient “levels of assurance” (LOAs), which tie strong authentication to strong identity proofing, don’t apply to every use case under the sun. On the recent teleconference where I discussed these findings, we ended up looking at the example of World of Warcraft, which offers strong authentication but had to back off strong proofing.

[From Identity Assurance Means Never Having To Say “Who Are You, Again?” | Forrester Blogs]

Eve is, naturally, absolutely right to highlight this. There is no need for Facebook to know who I really am if I can prove that Vodafone know who I am (and, importantly, that I’m over 13, although they may not be for much longer given Mr. Zuckerberg’s recent comments on age limits).

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post What do they want us to do? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/05/what-do-they-want-us-to-do/feed/ 0
Tough choices http://tomorrowstransactions.com/2011/04/tough-choices/ http://tomorrowstransactions.com/2011/04/tough-choices/#respond Sat, 02 Apr 2011 00:20:07 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/04/tough-choices/ [Dave Birch] Taking away privacy doesn't increase security, it reduces it.

The post Tough choices appeared first on Tomorrow's Transactions.

]]>
The relationship between identity and privacy is deep: privacy (in the sense of control over data associated with an identity) ought to be facilitated by the identity infrastructure. But that control cannot be absolute: society needs a balance in order to function, so the infrastructure ought to include a mechanism for making that balance explicit. It is very easy to set the balance in the wrong place even with the best of intentions. And once the balance is set in the wrong place, it may have most undesirable consequences.

An obsession with child protection in the UK and throughout the EU is encouraging a cavalier approach to law-making, which less democratic regimes are using to justify much broader repression on any speech seen as extreme or dangerous…. “The UK and EU are supporting measures that allow for websites to be censored on the basis of purely administrative processes, without need for judicial oversight.”

[From Net censors use UK's kid-safety frenzy to justify clampdown • The Register]

So a politician in one country decides, say, that we should all be able to read out neighbour’s emails just in case our neighbour is a pervert or serial killer or terrorist and the next thing we know is that Iranian government supporters in the UK are reading their neighbours emails and passing on their details to a hit squad if the emails contain any anti-regime comments.

By requiring law enforcement backdoors, we open ourselves to surveillance by hackers and foreign intelligence agencies

[From slight paranoia: Web 2.0 FBI backdoors are bad for national security]

This is, of course, absolutely correct, and it was shown in relief today when I read that…

Some day soon, when pro-democracy campaigners have their cellphones confiscated by police, they’ll be able to hit the “panic button” — a special app that will both wipe out the phone’s address book and emit emergency alerts to other activists… one of the new technologies the U.S. State Department is promoting to equip pro-democracy activists in countries ranging from the Middle East to China with the tools to fight back against repressive governments.

[From U.S. develops panic button for democracy activists | Reuters]

Surely this also means that terrorists about to execute a dastardly plot in the US will be able to wipe their mobile phones and alert their co-conspirators when the FBI knock on the door and, to use the emotive example, that child pornographers will be able to wipe their phones and alert fellow abusers when the police come calling. Tough choices indeed. We want to protect individual freedom so we must create private space. And yet we still need some kind of “smash the glass” option, because criminals do use the interweb tubes and there are legitimate law enforcement and national security interests here. Perhaps, however, the way forward to move away from the idea of balance completely.

In my own area of study, the familiar trope of “balancing privacy and security” is a source of constant frustration to privacy advocates, because while there are clearly sometimes tradeoffs between the two, it often seems that the zero-sum rhetoric of “balancing” leads people to view them as always in conflict. This is, I suspect, the source of much of the psychological appeal of “security theater”: If we implicitly think of privacy and security as balanced on a scale, a loss of privacy is ipso facto a gain in security. It sounds silly when stated explicitly, but the power of frames is precisely that they shape our thinking without being stated explicitly.

[From The Trouble With “Balance” Metaphors]

This is a great point, and when I read it it immediately helped me to think more clearly. There is no evidence that taking away privacy improves security, so it’s purely a matter of security theatre.

Retaining telecommunications data is no help in fighting crime, according to a study of German police statistics, released Thursday. Indeed, it could even make matters worse… This is because users began to employ avoidance techniques, says AK Vorrat.

[From Retaining Data Does Not Help Fight Crime, Says Group - PCWorld]

This is precisely the trajectory that we will all be following. The twin pressures from Big Content and law enforcement mean that the monitoring, recording and analysis of internet traffic is inevitable. But it will also be largely pointless, as my own recent experiences have proven. When I was in China, I wanted to use Twitter but it was blocked. So I logged in to a VPN back in the UK and twittered away. When I wanted to listen to the football on Radio 5 while in Spain, the BBC told me that I couldn’t, so I logged back in to my VPN and cheered the Blues. When I want to watch “The Daily Show” from the UK or when I want to watch “The Killing” via iPlayer in the US, I just go via VPN.

I’m surprised more ISPs don’t offer this as value-added service themselves. I already pay £100 per month for my Virgin triple-play (50Mb/s broadband, digital TV and telephone, so another £5 per month for OpenVPN would suit me fine).

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Tough choices appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/04/tough-choices/feed/ 0
Two-faced, at the least http://tomorrowstransactions.com/2011/03/two-faced-at-the-least/ http://tomorrowstransactions.com/2011/03/two-faced-at-the-least/#respond Tue, 22 Mar 2011 12:23:34 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/03/two-faced-at-the-least/ [Dave Birch] What do we really think about privacy? What should the identity infrastructure deliver when most people do not know what they want from it?

The post Two-faced, at the least appeared first on Tomorrow's Transactions.

]]>
The end of privacy is in sight, isn’t it? After all, we are part of a generation that twitters and updates its path through the world, telling everyone everything. Not because Big Brother demands it, but because we want to. We have, essentially, become one huge distributed Big Brother. We give away everything about ourselves. And I do mean everything.

Mr. Brooks, a 38-year-old consultant for online dating Web sites, seems to be a perfect customer. He publishes his travel schedule on Dopplr. His DNA profile is available on 23andMe. And on Blippy, he makes public everything he spends with his Chase Mastercard, along with his spending at Netflix, iTunes and Amazon.com.

“It’s very important to me to push out my character and hopefully my good reputation as far as possible, and that means being open,” he said, dismissing any privacy concerns by adding, “I simply have nothing to hide.”

[From T.M.I? Not for Sites Focused on Sharing - NYTimes.com]

We’ll come back to the reputation thing later on, but the point I wanted to make is that I think this is dangerous thinking, the rather lazy “nothing to hide” meme. Apart from anything else, how do you know whether you have anything to hide if you don’t know what someone else is looking for?

To Silicon Valley’s deep thinkers, this is all part of one big trend: People are becoming more relaxed about privacy, having come to recognize that publicizing little pieces of information about themselves can result in serendipitous conversations — and little jolts of ego gratification.

[From T.M.I? Not for Sites Focused on Sharing - NYTimes.com]

We haven’t had the Chernobyl yet, so I don’t privilege the views of the “deep thinkers” on this yet. In fact, I share the suspicion that these views are unrepresentative, because they come from such a narrow strata of society.

“No matter how many times a privileged straight white male tech executive tells you privacy is dead, don’t believe it,” she told upwards of 1,000 attendees during the opening address. “It’s not true.”

[From Privacy still matters at SXSW | Tech Blog | FT.com]

So what can we actually do? Well, I think that the fragmentation of identity and the support of multiple personas is one good way to ensure that the privacy that escapes us in the physical world will be inbuilt in the virtual world. Not everyone agrees. If you are a rich white guy living in California, it’s pretty easy to say that multiple identities are wrong, that you have no privacy get over it, that if you have nothing to hide you have nothing to fear, and such like. But I disagree. So let’s examine a prosaic example to see where it takes us: not political activists trying to tweet in Iran or Algerian pro-democracy Facebook groups or whatever, but the example we touched on a few weeks ago when discussing comments on newspaper stories: blog comments.

There’s an undeniable problem with people using the sort-of-anonymity of the web, the cyber-equvalent of the urban anonymity that began with the industrial revolution, to post crap, spam, abuse and downright disgusting comments on blog posts. And there is no doubt that people can use that sort-of-anonymity to do stupid, misleading and downright fraudulent things.

Sarah Palin has apparently created a second Facebook account with her Gmail address so that this fake “Lou Sarah” person can praise the other Sarah Palin on Facebook. The Gmail address is available for anyone to see in this leaked manuscript about Sarah Palin, and the Facebook page for “Lou Sarah” — Sarah Palin’s middle name is “Louise” — is just a bunch of praise and “Likes” for the things Sarah Palin likes and writes on her other Sarah Palin Facebook page

[From Sarah Palin Has Secret ‘Lou Sarah’ Facebook Account To Praise Other Sarah Palin Facebook Account]

Now, that’s pretty funny. But does it really matter? if Lou Sarah started posting death threats or child pornography then, yeah, I suppose it would, but I’m pretty sure there are laws about that already. But astrosurfing with Facebook and posting dumb comments on tedious blogs, well, who cares? If Lou Sarah were to develop a reputation for incisive and informed comment, and I found myself looking forward to her views on key issues of the day, would it matter to me that she is an alter-ego. I wonder.

I agree with websites such as LinkedIn and Quora that enforce real names, because there is a strong “reputation” angle to their businesses.

[From Dean Bubley's Disruptive Wireless: Insistence on a single, real-name identity will kill Facebook - gives telcos a chance for differentiation]

Surely, the point here is that on LinkedIn and Quora (to be honest, I got a bit bored with Quora and don’t go there much now), I want the reputation for work-related skills, knowledge, experience and connections, so I post with my real name. When I’m commenting at my favourite newspaper site, I still want reputation – I want people to read my comments – but I don’t always want them connected either with each other or with the physical me (I learned this lesson after posting in a discussion about credit card interest rates and then getting some unpleasant e-mails from someone ranting on about how interest is against Allah’s law and so on).

My identity should play ZERO part in the arguments being made. Otherwise, it’s just an appeal to authority.

[From The Real “Authenticity Killer” (and an aside about how bad the Yahoo brand has gotten) — Scobleizer]

To be honest, I think I pretty much agree with this. A comment thread on a discussion site about politics or football should be about the ideas, the argument, not “who says”. I seem to remember, from when I used to teach an MBA course on IT Management a long time ago, that one of the first lessons of moving to what was then called computer-mediated communication (CMC) for decision-making was that it led to better results precisely because of this. (I also remember that women would often create male pseudonyms for these online communications because research showed that their ideas were discounted when they posted as women.)

It isn’t just about blog comments. Having a single identity, particularly the Facebook identity, it seems to me, is fraught with risk. It’s not the right solution. It’s almost as if it was built in a different age, where no-one had considered what would happen when the primitive privacy model around Facebook met commercial interests with the power of the web at their disposal.

that’s the approach taken by two provocateurs who launched LovelyFaces.com this week, with profiles — names, locations and photos — scraped from publicly accessible Facebook pages. The site categorizes these unwitting volunteers into personality types, using a facial recognition algorithm, so you can search for someone in your general area who is “easy going,” “smug” or “sly.”

[From ‘Dating’ Site Imports 250,000 Facebook Profiles, Without Permission | Epicenter | Wired.com]

Nothing to hide? None of my Facebook profiles is in my real name. My youngest son has great fun in World of Warcraft and is very attached to his guilds, and so on, but I would never let him do this in his real name. There’s no need for it and every reason to believe that it would make identity problems of one form or another far worse (and, in fact, the WoW rebellion over “real names” was led by the players themselves, not privacy nuts). But you have to hand it to Facebook. They’ve been out there building stuff while people like me have been blogging about identity infrastructure.

Although it’s not apparent to many, Facebook is in the process of transforming itself from the world’s most popular social-media website into a critical part of the Internet’s identity infrastructure

[From Facebook Wants to Supply Your Internet Driver's License - Technology Review]

Now Facebook may very well be an essential part of the future identity infrastructure, but I hope that people will learn how to use it properly.

George Bronk used snippets of personal information gleaned from the women’s Facebook profiles, such as dates of birth, home addresses, names of pets and mother’s maiden names to then pass the security questions to reset the passwords on their email accounts.

[From garlik - The online identity experts]

I don’t know if we should expect the public, many of who are pretty dim, to take more care over their personal data or if we as responsible professionals, should design an infrastructure that at least makes it difficult for them to do dumb things with their personal data, but I do know that without some efforts and design and vision, it’s only going to get worse for the time being.

“We are now making a user’s address and mobile phone number accessible as part of the User Graph object,”

[From The Next Facebook Privacy Scandal: Sharing Phone Numbers, Addresses - Nicholas Jackson - Technology - The Atlantic]

Let’s say, then, for sake of argument, that I want to mitigate the dangers inherent in allowing any one organisation to gather too much data about me so I want to engage online using multiple personas to at least partition the problem of online privacy. Who might provide these multiple identities? In an excellent post on this, Forum friend Dean Bubley aggresively asserts

I also believe that this gives the telcos a chance to fight back against the all-conquering Facebook – if, and only if, they have the courage to stand up for some beliefs, and possibly even push back against political pressure in some cases. They will also need to consider de-coupling identity from network-access services.

[From Dean Bubley's Disruptive Wireless: Insistence on a single, real-name identity will kill Facebook - gives telcos a chance for differentiation]

The critical architecture here is pseduonymity, and an obvious way to implement it is by using multiple public-private key pairs and then binding them to credentials to form persona that can be selected from the handset, making the mobile phone into an identity remote control, allowing you to select which identity you want to asset on a per transaction basis if so desired. I’m sure Dean is right about the potential. Now, I don’t want to sound the like grumpy old man of Digital Identity, but this is precisely the idea that Stuart Fiske and I put forward to BT Cellnet back in the days of Genie – the idea was the “Genie Passport” to online services. But over the last decade, the idea has never gone anywhere with any of the MNOs that we have worked for. Well, now is the right time to start thinking about this seriously in MNO-land.

But mark my words, we WILL have a selector-based identity layer for the Internet in the future. All Internet devices will have a selector or a selector proxy for digital identity purposes.

[From Aftershocks of an untimely death announcement | IdentitySpace]

The most logical place for this selector is in the handset, managing multiple identities in the UICC, accessible OTA or via NFC. I use case is very appealing: I select ‘Dave Birch’ on my hansdset, tap it to my laptop and there is all of the ‘Dave Birch’ stuff. Change the handset selector to ‘David G.W. Birch’ and then tap the handset to the laptop again and all of the ‘Dave Birch’ stuff is gone and all of the ‘David G.W. Birch’ stuff is there. It’s a very appealing implementation of a general-purpose identity infrastructure and it would a means for MNOs to move to smart pipe services. But is it too late? Perhaps the arrival of non-UICC secure elements (SEs) mean that more agile organisations will move to exploit the identity opportunity.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Two-faced, at the least appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/03/two-faced-at-the-least/feed/ 0
How smart? http://tomorrowstransactions.com/2011/02/how-smart/ http://tomorrowstransactions.com/2011/02/how-smart/#respond Thu, 17 Feb 2011 12:37:09 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/02/how-smart/ [Dave Birch] We need to be just as rigorous in thinking about the future of machine identity as about the future of personal identity.

The post How smart? appeared first on Tomorrow's Transactions.

]]>
I had an interesting conversation with the CTO of a multi-billion company at the Mobile World Congress in Barcelona. He, like me, felt that something has been going wrong in the world of identity, authentication, credentials and reputation as we try to create electronic versions of physical world legacy constructs instead of starting from a new sets of requirements for the virtual world and working back. He was talking about machines, though, not people.

Robots could soon have an equivalent of the internet and Wikipedia. European scientists have embarked on a project to let robots share and store what they discover about the world. Called RoboEarth it will be a place that robots can upload data to when they master a task, and ask for help in carrying out new ones.

[From BBC News - Robots to get their own internet]

RoboEarth? No! Skynet, please. And Skynet needs to share an identity infrastructure with the interweb tubes, because of the rich interaction between personal identity and machine identity that will be integral to future living. The internet of things infrastructure needs an identity of things infrastructure to work properly. Our good friend Rob Bratby from Olswang wrote, accurately, that

The deployment of smart meters is one of the most significant deployments of what is often described as ‘the internet of things’, but its linkage to subscriber accounts and individual homes, and the increasing prevalence of data ‘mash-ups’ (cross-referencing of multiple databases) will require these issues to be thought about in a more sophisticated and nuanced way.

[From Watching the connectives | A lawyer's insight into telecoms and technology]

I can confirm from our experiences advising organisations in the smart metering value chain that these issues are certainly not being thought about in either sophisticated or nuanced ways.

“The existing business policies and practices of utilities and third-party smart grid providers may not adequately address the privacy risks created by smart meters and smart appliances,

[From Grid Regulator: The Internet & Privacy Concerns Will Shape Grid: Cleantech News and Analysis «]

Not my words, the Federal Energy Regulatory Commission in the US. Too right. The lack of an identity infrastructure isn’t just a matter of Facebook data getting into the wrong hands or having to have a different 2FA dongle for each of your bank accounts. It’s a matter of critical infrastructure starting down the wrong path, from which it will be hard to recover after the first Chernobyl of the smart meter age, the first time some kids, or the North Korean government, or a software error at the gas company shuts down all the meters, or publishes all of the meter readings in a Google maps-style mashup so that burglars can find out which houses in a street are empty, or the News of World can get a text alert when a sleb gets home, or whatever.

My CTO friend was, I’m certain, right to suggest that we need to start by working out what we what identity to look like in general and then work out what the subset of that in the physical world needs to look like. If we do start building an EUTIC or a UKTIC to complement NSTIC then I think it should work for smart meters as well as for dumb people.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post How smart? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/02/how-smart/feed/ 0
Theoretically private http://tomorrowstransactions.com/2011/02/theoretically-private/ http://tomorrowstransactions.com/2011/02/theoretically-private/#respond Thu, 10 Feb 2011 21:21:13 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/02/theoretically-private/ [Dave Birch] If we understood more about what privacy is, then it would be easier to implement systems that had it as a characteristic.

The post Theoretically private appeared first on Tomorrow's Transactions.

]]>
The Institute for Advanced Legal Studies hosted an excellent seminar by Professor Michael Birnhack from the Faculty of Law at Tel Aviv University who was talking about “A Quest for a Theory of Privacy”.

He pointed out that while we’re all very worried about privacy, we’re not really sure what should be done. It might be better to pause and review the legal “mess” around privacy and then try to find an intellectually-consistent way forward. This seems like a reasonable course of action to me, so I listened with interest as Michael explained that for most people, privacy issues are becoming more noticeable with Facebook, Google Buzz, Airport “nudatrons”, Street View, CCTV everywhere (particularly in the UK) and so on. (I’m particularly curious about the intersection between new technologies — such as RFID tags and biometrics — and public perceptions of those technologies, so I found some of the discussion very interesting indeed.)

Michael is part of the EU PRACTIS research group that has been forecasting technologies that will have an impact on privacy (good and bad: PETs and threats, so to speak). They use a roadmapping technique that is similar to the one we use at Consult Hyperion to help our clients to plan their strategies for exploiting new transaction technologies and is reasonably accurate within a 20 year horizon. Note that for our work for commercial clients, we use a 1-2 year, 2-5 year, and 5+ year roadmap. No-one in a bank or a telco cares about the 20 year view, even if we could predict it with any accuracy — and given that I’ve just read the BBC correspondents informed predictions for 2011 and they don’t mention, for example, what’s been going on in Tunisia and Egypt, I’d say that’s pretty difficult.

One key focus that Michael rather scarily picked out is omnipresent surveillance, particularly of the body (data about ourselves, that is, rather than data about our activities), with data acted upon immediately, but perhaps it’s best not go into that sort of thing right now!

He struck a definite chord when he said that it might be the new business models enabled by new technologies that are the real threat to privacy, not the technologies themselves. These mean that we need to approach a number of balances in new ways: privacy versus law enforcement, privacy versus efficiency, privacy versus freedom of expression. Moving to try and set these balances, via the courts, without first trying to understand what privacy is may take us in the wrong direction.

His idea for working towards a solution was plausible and understandable. Noting that privacy is a vague, elusive and contingent concept, but nevertheless a fundamental human right, he said that we need a useful model to start with. We can make a simple model by bounding a triangle with technology, law and values: this gives three sets of tensions to explore.

Law-Technology. It isn’t a simple as saying that law lags technology. In some cases, law attempts to regulate technology directly, sometimes indirectly. Sometimes technology responds against the law (eg, anonymity tools) and sometimes it co-operates (eg, PETs — a point that I thought I might disagree with Michael about until I realised that he doesn’t quite mean the same thing as I do by PETs).

Technology-Values. Technological determinism is wrong, because technology embodies certain values. (with reference to Social Construction of Technology, SCOT). Thus (as I think repressive regimes around the world are showing) it’s not enough to just have a network.

Law-Values, or in other words, jurisprudence, finds courts choosing between different interpretations. This is where Michael got into the interesting stuff from my point of view, because I’m not a lawyer and so I don’t know the background of previous efforts to resolve tensions on this line.

Focusing on that third set of tensions, then, in summary: From Warren and Brandeis’ 1890 definition of privacy as the right to be let alone, there have been more attempts to pick out a particular bundle of rights and call them privacy. Alan Westin‘s 1967 definition was privacy as control: the claims of individuals or groups or institutions to determine for themselves when, how and to what extent information about them is communicated to others.

This is a much better approach than the property right approach, where disclosing or not disclosing, “private” and “public” are the states of data. Think about the example of smart meters, where data outside the home provides information about how many people are in the home, what time they are there and so on. This shows that the public/private, in/out, home/work barriers are not useful for formulating a theory. The alternative that he put forward considers the person, their relationships, their community and their state. I’m not a lawyer so I probably didn’t understand the nuances, but this didn’t seem quite right to me, because there are other dimensions around context, persona, transaction and so on.

The idea of managing the decontextualisation of self seemed solid to my untrained ear and eye and I could see how this fitted with the Westin definition of control, taking on board the point that privacy isn’t property and it isn’t static (because it is technology-dependent). I do think that choices about identity ought, in principle, to be made on a transaction-by-transaction basis even if we set defaults and delegate some of the decisions to our technology and the idea that different persona, or avatars, might bundle some of these choices seems practical.

Michael’s essential point is, then, that a theory of privacy that is formulated by examining definitions, classsifications, threats, descriptions, justifications and concepts around privacy from scratch will be based on the central notion of privacy as control rather than secrecy or obscurity. As a technologist, I’m used to the idea that privacy isn’t about hiding data or not hiding it, but about controlling who can use it. Therefore Michael’s conclusions from jurisprudence connect nicely connect with my observations from technology.

An argument that I introduced in support of his position during the questions draws on previous discussions around the real and virtual boundary, noting that the lack of control in physical space means the end of privacy there, whereas in virtual space it may thrive. If I’m walking down the street, I have no control over whether I am captured by CCTV or not. But in virtual space, I can choose which persona to launch into which environment, which set of relationships and which business deals. I found Michael’s thoughts on the theory behind this fascinating, and I’m sure I’l be returning to them in the future.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Theoretically private appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/02/theoretically-private/feed/ 0
Tripped up http://tomorrowstransactions.com/2010/10/tripped-up/ http://tomorrowstransactions.com/2010/10/tripped-up/#comments Mon, 11 Oct 2010 22:13:19 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/10/tripped-up/ Incidentally, another large and well-known country closely associated with our economic future (albeit a virtual one) has just abandoned plans to try and force Chinese-style real-name registration after a revolt by citizens (well, subscribers): Blizzard has reversed a controversial decision that would have forced thousands of Starcraft and World of Warcraft (WoW) players to use their real names on the company's online forums [From Blizzard stands down over forum controversy | TG Daily ]
...Is it "astroturf", something that looks like a real review but has actually been posted by Simply making people register their details would be a start, but it would undoubtedly lead to a sharp fall in TripAdvisor's user numbers and its revenue, so it is unlikely to be countenanced.
... Many sites (eg, Amazon and eBay) will only let you review things that you have bought through them, which is great, but that doesn't help in the general case, reviewing hotels or doctors or schools or MPs or movies or just about anything else. All of these would like to establish that same baseline (ie, you can't comment on some service unless you have consumed it) but can't figure out a way of doing that would protect privacy (because the reviews won't be honest if people think that they might be tracked down and sued for libel for complaining about shoddy service ).

The post Tripped up appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Many people have a real problem with the apparently anonymous nature of the interweb. I say “apparently” because, of course, unless you work really hard at it and really understand how the internet works, and really understand how your PC works, and really plan it carefully, you’re not really anonymous in the proper sense of the word.

Our sense of anonymity is largely an illusion. Pretty much everything we do online, down to individual keystrokes and clicks, is recorded, stored in cookies and corporate databases, and connected to our identities, either explicitly through our user names, credit-card numbers and the IP addresses assigned to our computers, or implicitly through our searching, surfing and purchasing histories.

[From The Great Privacy Debate: The Dangers of Web Tracking - WSJ.com]

I’m surprised that politicians, in particular, who keep going on about how terrible internet anonymity is, don’t understand a little more about the dynamics of the problem. If they did, they would realise that anonymity isn’t what it seems.

You might think, after enough major stories about “IP addresses” hit the news wires, everyone in political life would be aware that “anonymity” on the Internet is limited.

But someone in Sen. Saxby Chambliss’ (R-GA) office didn’t get the memo. In the aftermath of this week’s failed vote on the military’s “don’t ask, don’t tell” policy, someone named “Jimmy” registered an account at the gay news blog Joe.My.God. just to say, “All Faggots must die.”

[From Outed! Senate staffers, anti-gay slurs, and IP addresses]

In the general case, you are not anonymous on the interweb, but economically-anonymous, which I propose to label “enonymous”, and that’s not the same thing at all. If you threaten to kill the President, you will be tracked down, and the state will spend the money it takes on it. But if you call Lily Allen a a hereditary celebrity and copyright hypocrite (not my own views, naturally) then it’s not worth the state’s money to track you down. If Lily wants to spend her own money on tracking you down and taking a civil action for libel, then fair enough, that’s the English way of limiting free speech. If the newspapers want to spend their own money on it, fine. For issues of great national interest, such as spurious death threats to the nation’s sweetheart, Cheryl Cole, The Sun can step in.

Yesterday The Sun traced the sender of a chilling anti-Cheryl message that blasted her over Zimbabwean Gamu’s TV exit. Wannabe rapper Sanussi Ngoy Ebonda, 20, admitted penning the sinister rant, which accused Cheryl of “da biggest mistake of your life” and included a threat to attack other girls sharing her name.

[From Cheryl Cole boosts security at mansion | The Sun |Showbiz|TV|X Factor]

So even though there’s precious little anonymity, should we allow enonymity to be the norm? There are plenty of people who think not, and they’re not all English libel lawyers. Surely common sense is on their side? Isn’t it wrong to let people hide behind pretend names?

Let’s focus on a specific and straightforward example. The comment pages on newspaper, magazine and other media web sites. Many such sites require registration but are still essentially enonymous. Is it right that enonymous commenters can say bad things about celebrities, politicians, business leaders? Would people be as horrible about public figures if they were forced to identify themselves?

Would the online debate among commenters be stifled by requiring commenters to sign their real names?

[From What did you say your name was? | Analysis & Opinion |]

The Chinese government certainly hope so.

China is considering measures to force all its 400m internet users to register their real names before making comments on the country’s myriad chat-rooms and discussion forums, in a further sign of tightening controls on freedom of speech.

[From China to force internet users to register real names - Telegraph]

We already know this doesn’t work, incidentally, because the Chinese already tried this for Internet cafes, supposedly to deal with the problem of young people spending too much time in virtual worlds. The only result was an instant, and profitable, black market in ID card numbers, whereby kids would get the ID numbers of people who weren’t going to play in cybercafes (eg, their grandparents) and used them to log in instead of using their own. There was an alignment of economic incentives here, because the cybercafes would not make money by turning people away.

Cafés that did not ask for identification often still had a registration book at the front desk, in which staff members were seen to write apparently random identification numbers and names during their free time.

[From HRIC | 中国人权]

Incidentally, another large and well-known country closely associated with our economic future (albeit a virtual one) has just abandoned plans to try and force Chinese-style real-name registration after a revolt by citizens (well, subscribers):

Blizzard has reversed a controversial decision that would have forced thousands of Starcraft and World of Warcraft (WoW) players to use their real names on the company’s online forums

[From Blizzard stands down over forum controversy | TG Daily]

I simply would not allow my kids to log in with their real names. I’m happy for them to log in using one of their multiple e-mail addresses. They’ve had pseudonymous e-mail addresses since they were old enough to go online. This isn’t just paranoia about people grooming children for sexual exploitation (the UK takes this kind of thing very seriously) and such like. There are lots of really good reasons for not wanting to use your identity in online debate and comment. I wrote once before about being shocked by some hate e-mails I received when I once posted some comments in a discussion about interest rates (“interest is the work of the devil”, “we know how you are” etc etc). Now, I still enjoy participating in online debates, but do so pseudonymously: my friends know who I am.

That, incidentally, may not be much of a protection, because the mapping of social graphs can soon locate you within a group of friends even if none of those friends disclose who you are. A determined third-party can learn very interesting things from those graphs and, unless everyone is anonymous or pseudonymous under certain conditions, figure out who you are.

Iran appears to be in two minds about whether to embrace or stymie technological progress. On the one hand, Twitter accounts helped the opposition mobilise demonstrations in the wake of last year’s contested presidential election… On the other hand, by monitoring Twitter traffic, Tehran was able to identify who was organising the protests.

[From FT.com / FT Magazine - Who controls the internet?]

As I’ve said before, in cyberspace no-one knows you’re a dog, but no-one knows you’re from the FBI either. Thus our government, the US government and many others are caught in two minds, just as the Iranians are. On the one hand, they are supposed to be in favour of free speech, but on the other hand, well, you know Danish cartoonists, criminals, child pornographers, terrorists, enemies of the state, dissidents, apostates etc.

Now, maybe you don’t care. You’re “not doing anything wrong.” Well, Hoder wasn’t doing anything wrong when he went to Israel and blogged about it in Farsi. But he’s serving 20 years in jail in Iran.

[From Emergent Chaos » Blog Archive » AT&T, Voice Encryption and Trust]

But back to online commenting in our democracy. It’s not a simple issue, and “common sense” is not a good guide to anything in the virtual world, but it is clearly the case that in that virtual world some people behave inappropriately. You only have to read The Guardian newspapers online “Comment is Free” or Guido Fawkes, the UK’s top political blog, to see how appalling, disgusting, racist, misogynist, anti-semitic and just plain thick the general public can be. I am one of those old-fashioned liberals who thinks that the response to bad free speech should be more free speech, not less. I think we should be wary about limiting the anonymity of people who comment online, even if we could think of a way of doing so.

The Nazareth District Court has upheld the right of the Walla Web portal to refuse to hand over the IP addresses of commenters accused of defaming a journalist.

“The good of online anonymity outweighs the bad, and it must be seen as a byproduct of freedom of speech and the right to privacy,” Judge Avraham Avraham wrote in his ruling last week.

The court also said the critical remarks concerning Yedioth Ahronoth reporter Israel Moskovitz, posted online in 2008, were unlikely to harm his reputation since they were poorly written and appeared only once, and readers were not likely to take them seriously.

[From Uphold talkbacker's anonymity in defamation trial, court says - Haaretz - Israel News ]

Actually, for journalists to complain about online comments, criticism and even abuse is a tiny bit worrying, since their business depends on such.

It doesn’t take long to find articles on CNN that quote anonymous officials. For them to rage against “cowards” who won’t stand behind what they say, and then to regularly quote “anonymous” sources, seems pretty damn hypocritical. Phillips claims anonymity online is “very unfair.” Phillips also attacks the media for “giving anonymous bloggers credit or credibility.” But again, CNN quotes all kinds of anonymous sources all the time.

[From CNN Claims 'Something Must Be Done' About Anonymous Bloggers | Techdirt]

On balance, then, I think a free society not only permits certain kinds of anonymity but actually depends on them, because we need informed and honest public debate to function properly. This was well-put in the Washington Post recently.

For every noxious comment, many more are astute and stimulating. Anonymity provides necessary protection for serious commenters whose jobs or personal circumstances preclude identifying themselves. And even belligerent anonymous comments often reflect genuine passion that should be heard.

[From Andrew Alexander - Online readers need a chance to comment, but not to abuse]

I couldn’t agree more. However, as the Post goes on to note, we have to recognise that people can be pretty horrible and we need a way to deal with that. Not banning anonymity, but managing the anonymousness (if there is such a word) in a better way.

The solution is in moderating — not limiting — comments. In a few months, The Post will implement a system that should help. It’s still being developed, but Straus said the broad outlines envision commenters being assigned to different “tiers” based on their past behavior and other factors. Those with a track record of staying within the guidelines, and those providing their real names, will likely be considered “trusted commenters.” Repeat violators or discourteous agitators will be grouped elsewhere or blocked outright. Comments of first-timers will be screened by a human being.

[From Andrew Alexander - Online readers need a chance to comment, but not to abuse]

This — in essence, baby steps toward a reputation economy — could be toughened up by using better identity infrastructure, but it’s not a bad place to start. But there are areas where the better infrastructure is more of a priority. Newspaper comments are one thing, but there are businesses that depend on online comments, and a good example is the burgeoning group review sector.

There’s a general problem with the review sites on the interweb. They are one of the things that the interweb can do well and they perform a very useful social function. But… you can’t trust them. If you’re looking at a hotel review on a travel web site, how do you know whether the review is “real”? Is it “astroturf”, something that looks like a real review but has actually been posted by

Simply making people register their details would be a start, but it would undoubtedly lead to a sharp fall in TripAdvisor’s user numbers and its revenue, so it is unlikely to be countenanced.

[From Tripadvisor reviews: can we trust them? - Telegraph]

Many sites (eg, Amazon and eBay) will only let you review things that you have bought through them, which is great, but that doesn’t help in the general case, reviewing hotels or doctors or schools or MPs or movies or just about anything else. All of these would like to establish that same baseline (ie, you can’t comment on some service unless you have consumed it) but can’t figure out a way of doing that would protect privacy (because the reviews won’t be honest if people think that they might be tracked down and sued for libel for complaining about shoddy service).

There is way to do this. Remember the old DigiCash technology? Why not build an extension to OpenID so that you can collect tokens from service providers. Then in order to post a review of some service, you have to present the token (in order to prove that you have consumed the service). But the tokens would be cryptographically-blinded.

Here’s the marketeture for how to do it. I go stay at the San Francisco Hilton. I’m a member of their loyalty club, so I log in to their web site using OpenID or something. Once logged in, my plug-in generates a random number and blinds it. It then send the random number to Hilton. They know I’ve stayed, from my loyalty club number (or you could do it from a credit card or whatever), so they use their private key to sign the token, thus forming a digital certificate, which they send back to me. On receiving the certificate, my plug-in unblinds it. Now I have a digital certificate that proves I stayed at the San Francisco Hilton some time in 2010 (say), but no-one (not even Hilton) can link that token to me.

Now I log in to TripAdvisor using my OpenID plug-in. Up pops a menu (based on all of the certificates in my plug-in) asking me to rate the various things, one of which will be the San Francisco Hilton. TripAdvisor can now post the review knowing for certain that I did stay at the hotel. Now imagine this not only generalised — to movies, doctors and everything else — but also taken for granted as the way that things work: so that anonymity is valued part of the online interaction landscape.

The NSTIC proposal places no value on anonymity; indeed, it evinces an apparent lack of understanding of what anonymity really means. It takes for granted the need for authentication (if we pay in cash, why does a merchant, much less a common carrier or government agency, need to know about us other than that our money isn’t counterfeit?) and confuses a policy that purportedly restricts disclosure of our identity with actual non-knowledge of our identity.

[From Papers, Please! » Blog Archive » Public says “No” to national cyberspace ID proposal]

If we in Europe decide to develop our own kind of European Strategy on Trusted Identites in Cyberspace (ESTIC) then I think it should not only include both conditional and unconditional anonymity but should strive to make it clear that, like pseudonymity, these types of online persona will be the norm, not the exception.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Tripped up appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/10/tripped-up/feed/ 4
Listening in http://tomorrowstransactions.com/2010/08/listening-in/ http://tomorrowstransactions.com/2010/08/listening-in/#respond Mon, 30 Aug 2010 16:45:21 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/08/listening-in/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post Listening in appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Who should we be listening to when formulating digital identity strategy? Consumers? Experts? Politicians? Lobbyists? Consultants? Consider, for example, the issue of privacy. This is complicated, sensitive, emotive. And some of the voices commenting on it are loud. Take a look at the “Wal-Mart story” — the story that Wal-Mart are going to add RFID tags to some of their clothing lines — that has naturally attracted plenty of attention. One particular sets of concerns were founded on the idea that consumers could not have the tags “killed” and so would be tracked and traced by… well, marketeers, advertisers, sinister footsoliders of the New World Order, the CIA and so on. So what is the truth?

The tags are based on the EPC Gen 2 standard, which requires that they have a kill command that would permanently disable them. So the tags can, in fact, be disabled. Wal-Mart does not plan to kill the tags at the point of sale (POS), only because it is not using RFID readers at the point of sale.

[From Privacy Nonsense Sweeps the Internet]

As a consumer, I don’t want the tags to be turned off, because that means that the benefits of the tags are limited to Wal-Mart and not shared with me. I’d really like a washing machine that could read the tags and tell me if I have the wrong wash cycle. And there are plenty of other business models around tags that might be highly desirable to consumers.

If it adds £20 to the price of a Rolex to implement this infrastructure, so what? The kind of people who pay £5,000 for a Rolex wouldn’t hesitate to pay £5,020 for a Rolex that can prove that it is real. Imagine the horror of being the host of a dinner party when one of the guests glances at their phone and says “you know those jeans aren’t real Gucci, don’t you?”. Wouldn’t you pay £20 for the satisfaction of knowing that your snooping guest’s Bluetooth pen is steadfastly attesting to all concerned that your Marlboro, Paracetamol and Police sunglasses are all real.

[From Digital Identity: The Rolex premium]

So does the existence of convenience, business model, consumer interest and practicality mean I have no privacy concerns? Of course not! So what is a reasonable way forward?

Wal-Mart is demanding that suppliers add the tags to removable labels or packaging instead of embedding them in clothes, to minimize fears that they could be used to track people’s movements. It also is posting signs informing customers about the tags.

[From Wal-Mart to Put Radio Tags on Clothes - WSJ.com]

That seems like a reasonable compromise: make it easy for people to cut the tags off if they don’t want them. So is that the end of the story? I don’t think it is.

What could possibly violate our privacy with tracking pants in a store to make sure there aren’t too many extra-large sizes on the shelves?

[From Privacy wingnuts « BuzzMachine]

The thing is, I agree with Jeff Jarvis here that some people are, indeed, “wingnuts”. But that does not mean that there are no genuine concerns and it does not mean that anyone who is concerned about privacy (eg, me) is a wingnut. But what it does mean, I think, is that we need to implement new identity technologies in a privacy-enhancing fashion and make the “privacy settlement” with the public more explicit so that there is an opportunity for informed comment to shape it. It seems to me that some fairly simple design decisions can achieve both of these goals, something that I’ve referred to before when using Touch2id as an example.

Stephan Engberg is a member of the Strategic Advisory Board of the EU ICT Security & Dependability Taskforce and a person who I always take seriously.

To me Touch2Id is a disaster – teaching kids to offer their fingerprints to strangers is not compatible with my understanding of democracy or of what constitutes the basis of free society. The claim that data is “not collected” is absurd and represents outdated legal thinking. Biometric data gets collected even though it shouldn’t and such collection is entirely unnecessary given the PET solutions to this problem that exist, e. g chip-on-card.

[From IdentityBlog - Digital Identity, Privacy, and the Internet's Missing Identity Layer]

First of all, Touch2ID doesn’t teach “kids” anything, since kids aren’t allowed to have it. That’s sort of the point of it. You have to be 18 to get the card. Secondly, even if the shopkeeper did somehow tamper with the terminal to collect the fingerprints… so what? The shopkeeper doesn’t know who they belong to, since the cards do not carry identifying information. Ah, but the shopkeeper could take a picture of the person in the shop, match it against Facebook photographs and then store it with the fingerprint… yes, well, once you start thinking like that, there’s no way forward. You may as well argue that we’ve no way of knowing whether Touch2ID is in fact a front for Al-Qaeda and is collecting the fingerprints of people who buy alcohol in order to round them up in the future.

I’m not commenting to shill for Touch2ID — they are perfectly capable of defending themselves — but I do think that their approach (pseudonymous match-on-card) is the right way forward in an imperfect world. Then we can have interoperability at the virtual identity level. Stephan goes on to say that some people think he is an extremist. I don’t. In fact, I agree with what he says about the importance of Privacy Enhancing Technologies (PETs) in wider society.

Strong PETs must be applied to ensure principles such as net neutrality, demand-side controls and semantic interoperability. If they aren’t, I am personally convinced that within 20 or 30 years we will no longer have anything resembling democracy – and economic crises will worsen due to Command & Control inefficiencies and anti-innovation initiatives

[From IdentityBlog - Digital Identity, Privacy, and the Internet's Missing Identity Layer]

This is why I have been so outspoken about the previous British government’s hopeless national identity management strategy, because such as strategy has to built on PETs, not built on management consultant waffle about privacy. Sorry, that was unfair. Not all management consultants produce waffle about privacy. In fact, I’ve just been reading a July 2010 survey on Consumers and Convergence from the well-known Swiss co-operative KPMG International that contains some very interesting results about privacy and some thought-provoking comment on the same. It says this about Personally-Identifiable Information (PII):

Consumers have a paradoxical view of privacy. Consumers of all ages express more anxiety about data privacy than they have previously, but they’re also more willing than ever to give up PII if they get something of value in return. Nearly eight out of ten global consumers (79 percent) said they are concerned about unauthorized access of PII. But nearly six in ten (58 percent) said they would be willing to allow their online usage and profile information to be tracked if it resulted in lower costs.

It also contains some very interesting comparisons between G7 and BRIC countries on attitudes to privacy. At the end of it, though, I can’t help feeling that consumers’ attitudes about privacy are still too immature, confused and ill-informed to guide us. We (ie, the identity industry) need to integrate PETs into systems whatever consumers think: if we do and then we don’t want to use them, fine, but if we don’t, then we can’t go back.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Listening in appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/08/listening-in/feed/ 0
Let’s make crime illegal http://tomorrowstransactions.com/2010/08/lets-make-crime-illegal/ http://tomorrowstransactions.com/2010/08/lets-make-crime-illegal/#respond Mon, 09 Aug 2010 22:16:12 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/08/lets-make-crime-illegal/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post Let’s make crime illegal appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] In today’s newspaper, I read that the Blackberry is not, after all, to be banned from Saudi Arabia as it has been from UAE.

The agreement, which involves placing a BlackBerry server inside Saudi Arabia, would allow the government to monitor users’ messages and allay official fears the service could be used for criminal purposes.

[From Saudi Arabia halts plan to ban BlackBerry instant messanging - Telegraph]

I don’t know whether it’s a good thing for messages to be in the clear or not. If I were an investment banker negotiating a deal, I might worry that someone at the Ministry of Snooping might pass my messages on to his brother at a rival investment bank, for example. After all, the idea that only authorised law enforcement officers would have access to my private information is absolutely no comfort at all.

A drugs squad detective, Philip Berry, sold a valuable contacts book containing the personal details of the criminal underworld to pay off his credit card debt, a court heard.

[From Corrupt drugs detective 'sold underworld secrets to pay debt' - Telegraph]

The idea that law enforcement would be helpless to stem the tide of international crime unless they can tap every call, read every email, open every letter, is (if you ask me) suspect. If I am sending text messages to a known criminal, you do not need to be able to read those message to decide that you might want to obtain a warrant to find out who I am calling or where I am. The fact that I am using a prepaid phone does not, by itself, render me immune to law enforcement activity.

Beyene’s role in the heist was to buy so-called dirty telephones and hire a van to use as a blocking vehicle,

[From Gunman jailed for 23 years over Britain's biggest jewellery robbery - Telegraph]

In fact this gang was caught because the police found one of the mobile phones they had been using. It contained four anonymous numbers, and from these the police were able to track down the gang members. It wasn’t revealed how, but there at least two rather obvious ways to go about it: get a warrant to track the phones and correlate their movements with known criminals or get a warrant to find out which numbers those other phones have been calling and follow the chain until you get to a known number. Yes, this might require some police work, which is more expensive than having everything tracked automatically on a PC, but it is better for society. This reminds of a recent discussion about anonymous prepaid phones. I’m in favour of them, but plenty of people are against them. (Same for prepaid cards.) Ah, but you and the authorities in some countries might ask: how can you catch criminals who use anonymous prepaid phones? Forcing people to

Earlier this month, the FBI revealed that the suspected Times Square bomber had used an anonymous prepaid cell phone to purchase the Nissan Pathfinder and M-88 fireworks used in the bomb attempt.

[From Senators call for end to anonymous, prepaid cell phones]

Setting aside the fact that this guy was caught (despite the dreaded “anonymous prepaid call phone”) and had been allowed on a flight despite being on the no-fly list, the politicians are, I’m sure, spot on with their informed and intelligent policy. In fact, one of them said:

“We caught a break in catching the Times Square terrorist, but usually a prepaid cell phone is a dead end for law enforcement”.

[From Senators call for end to anonymous, prepaid cell phones]

Amazingly, the very same issue of the newspaper that reports on the captured UK armed robbers contains a story about a Mafia boss caught by… well, I’ll let you read for yourself:

One of Italy’s most wanted mafia godfathers has been arrested after seven years on the run after police traced him to his wife’s mobile registered in the name of Winnie the Pooh

[From Winnie the Pooh leads to gangster's arrest - Telegraph]

So, basically, if you require people to register prepaid mobile phones then you raise the cost and inconvenience for the public but the criminals still get them (because they bribe, cheat and steal: that’s criminals for you). I imagine that in the Naples branch of Carphone Warehouse the name “Winnie the Pooh” on a UK identity card looks perfectly plausible: they would have no more chance of knowing whether it’s real or not than the Woking Carphone Warehouse would when looking at an Italian driving licence in the name of Gepetto Paparazzo. Again it’s not clear exactly what the police did, but from elements of the story it appears to be something like: the police discovered (through intelligence) that the godfather’s wife was calling an apparently random mobile phone number at exactly the same time every two weeks. From this they determined which phone was hers (the “Winnie the Pooh” phone) and they tracked it to Brussels. But suppose some foolproof method for obtaining the correct identities of purchasers were to be found. Would this then stop crime in, say, Italy? Of course not.

In an attempt to combat the cartel-related violence, Mexico enacted a law requiring cell phone users to register their identity with the carrier. Nearly 30 million subscribers didn’t do this because of a lack of knowledge or a distrust of what could happen to that information if it fell into the wrong hands. Unfortunately, the doubters were proven right, as the confidential data of millions of people leaked to the black market for a few thousand dollars, according to the Los Angeles Times.

[From Did Mexico's cell phone registration plans backfire?]

The law just isn’t a solution. It might even make things worse.

Let’s face it, RIM couldn’t possibly have afforded all of the advertising they’ve got over the last few days. What does the story say to the average punter? “Hey, they’re not banning Nokias or iPhones, so if you use one of those then your e-mail will end up in the hands of your competitors”. So with the new arrangements in place, the police will have no problem intercepting dastardly criminal conspiracies being formulated using e-mail, right? Well, no. A friend of mine recently asked me how he could e-mail so partners that he was thinking about starting a business with without his current employer knowing (he periodically needed to contact them in working hours, and knowing nothing about IT, he assumed that his public sector employer was reading his e-mail) so I directed him to Hushmail (disclaimer: some years ago I was a non-executive advisor to Hushmail).

Right now there’s no way to encrypt your email using PGP on the iPhone through the Mail program. Instead, consider using Hushmail, which supports PGP encryption. It’s a webmail service, so you can access it from Safari.

[From Secure Your iPhone | Mac|Life]

Surely most criminals, though, will simply use SSL connections to Google Mail, Hotmail and so on. This is what I never understood about the RIM/UAE story when it first blew up, until I read in the FT that

A statement from CITC on Sunday saying mobile operators’ servers were being tested suggested that RIM and the Saudi authorities may be focusing on personal use of the BlackBerry messaging service.

[From FT.com / Middle East - Saudi Arabia fails to impose BlackBerry ban]

In the article I read on Saturday, it said that there were concerns about boys and girls messaging each other. Anyway, what does all of this mean? Well, if you provide a trapdoor in service, even for the very best of reasons, it will eventually be exploited.

Apparently, Chinese “hackers” were found it rather easy to break into the e-mail accounts of human rights activists and so forth, because Google had been forced to build a system to do precisely that.

[From Digital Identity: Privacy and Security]

Dean Bubley is surely right when he says that all of this fuss — UAE Blackberry ban, French three strikes etc — will simply drive people how want to keep their communications private (eg, terrorists, file sharers, nazi pedophlles, investment bankers and so forth) to encrypt everything end-to-end and assume that all networks are wholly compromised.

I have a feeling that this whole “interception” approach may backfire spectacularly on those governments trying to enforce it. This could just catalyse the whole market for private crypto solutions, not just on BlackBerries, but on all smartphones.

[From BlackBerry BBM intercept - workarounds probable? - Convergence Conversation]

A few weeks ago, Neelie Kroes (the European Commissioner for Digital Europe) talked about bringing European values around privacy to bear on new technology. OK. So what are the European values around electronic messaging and what is the best way for us technologists to implement them?

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Let’s make crime illegal appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/08/lets-make-crime-illegal/feed/ 0