Tomorrow's Transactions » digital identity electronic identity cards trust reputation http://tomorrowstransactions.com Thought leadership from Consult Hyperion Wed, 10 Sep 2014 20:33:30 +0000 en-US hourly 1 http://wordpress.org/?v=4.0 Category error http://tomorrowstransactions.com/2008/08/category-error/ http://tomorrowstransactions.com/2008/08/category-error/#comments Mon, 25 Aug 2008 21:48:22 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/08/category-error/ , ,

The post Category error appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] A common mistake in government-related discussions around identity is completely misunderstand the nature of the problem itself:

people need to prove who they are many times during a day.

[From In Development » Just what is ‘identity’?]

No, they don’t. People need to prove that they are entitled to do something or are allowed to do something several times during a day, which is actually an entirely different issue. Mind you, it’s an often-repeated mistake, even amongst those who should know better but haven’t really thought it through. When he was the Home Office Minister for ID cards, Andy Burnham said that “I take the view that it is part of being a good citizen, proving who you are, day in day out”. How wrong can you be? Other than the current Home Office Minister for ID cards, Meg Hillier, who said that we should see ID cards as “passports in-country”. Or, indeed, the Home Office Minister for ID cards before him, Tony McNulty, who said that

“There are now so many almost daily occasions when we have to stand up and verify our identity.”

[From BBC NEWS | Politics | Labour admits ID card 'oversell']

I blame the education system, but blog readers may have some other explanations as to why this same, fundamental, error is propagated by people who ought to have some grasp of the issues.

This core misunderstanding of identity is what makes it so difficult for a proper debate, and therefore a proper requirements specification, to emerge. Which, as far as I know, it hasn’t. The number of times that you have to prove who are you are very limited: when you open a new bank account and perhaps when you enroll at a place of education. The rest of the time, your identity is irrelevant and applying the full panoply of miracle technologies, from face recognition to portable fingerprint scanners, to the problem is a waste of money.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Category error appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/08/category-error/feed/ 2
Industrial-scale identity theft http://tomorrowstransactions.com/2008/08/industrial-scal/ http://tomorrowstransactions.com/2008/08/industrial-scal/#respond Fri, 15 Aug 2008 09:25:04 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/08/industrial-scal/ ,

The post Industrial-scale identity theft appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Well, not really identity theft at all, but stealing credit card details on a massive scale then using them to obtain goods or services fraudulently. These ones got caught.

Federal prosecutors have charged 11 people with stealing more than 41 million credit and debit card numbers, cracking what officials said on Tuesday appeared to be the largest hacking and identity theft ring ever exposed.

[From 11 Charged in Theft of 41 Million Card Numbers - NYTimes.com]

Judging by the ever escalating figures for credit card fraud, however, plenty of others are still getting away with it. Are the figures telling us something very specific about authentication: that online PINs and passwords are not only not a particularly good authentication mechanism but may actually make matters worse? The prosecutors allege that the criminals stole card details and PINs as they were passing (apparently unencrypted) over wireless networks and then used the fake card to details to manufacture cards and then used the PINs with the cards to withdraw cash from ATMs. No PINs, no cash out of the ATM.

As far as anyone can tell, identity theft (as opposed to credit card fraud) is actually going down. The dynamics of this, I suppose, are that in a new environment people are initially very vulnerable to scams of many kinds, but over time they begin to wise up. In fact, they seemed to have wised up fairly quickly…

The number of identity fraud victims has decreased for the fifth year in a row, according to the 2008 Identity Fraud Survey Report conducted by Javelin.

[From Javelin Strategy and Research » Hacking case shows companies’, consumers’ vulnerability]

Both bank and their customers are making steady progress (which is not to say that there’s isn’t room for considerable improvement). The fraudsters are getting smarter and targeting their attacks, but presumably it’s getting steadily more difficult to persuade the average U.K. interweb junkie that you are the widow of former Nigerian strongman Sani Abacha, simply because of increased awareness and not because of any technology solution.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Industrial-scale identity theft appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/08/industrial-scal/feed/ 0
Public transports http://tomorrowstransactions.com/2008/08/public-transpor/ http://tomorrowstransactions.com/2008/08/public-transpor/#respond Fri, 01 Aug 2008 18:20:19 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/08/public-transpor/ , , ,

The post Public transports appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Stuart Kwan, Director identity and Access at Microsoft, kicked off something a while back by talking about the need for some sort of "identity bus" that can allow different systems, components, applications to tap into an effective digital identity infrastructure. It doesn’t exist as an architecture, let alone products, but people do understand what he means.

 

The "identity bus" is, of course, still just a vision, but at least it is a beginning. Understanding and building toward an identity industry that is "the identity bus" should be the mission of every serious identity vendor out there.

[From Identity Bus: More than meets the eye | CSO Blogs]

Kim has been talking about this as well. There’s a lot to commend this way of thinking. From the technical side, we all understand what a bus implies: standards and interfaces, "plug and play", commodity units. Whether this is realistic in the identity space needs further discussion, because the industry may not be yet know enough about what is wanted, what the real requirements are, in order to be able to come up with some building blocks of lasting value. Yet in a discussion this afternoon, in connection with the use of mobile phones in the identity infrastructure, I did start to think that perhaps instead of endless industry bodies, government studies and new experiments, it might be better to just start plugging a few bits and piece together.

So how might an identity bus function? I think we can all understand the markitecture: my application uses the buses to exchange some identity information with your application, without having to know anything about your application or (more importantly in the strategic context of this discussion) you. Now, while it is possible to imagine how to do this at the low level, it’s much harder to see how it might come together at the business level, for the same reasons that have dogged PKI in the B2B space since the very beginning. Outside of closed user groups, there aren’t the trust relationships there in the first place. That’s why they can’t be implemented using the technology. It’s not because the technology doesn’t exist, but because the relationships don’t.

But let’s suppose that at one level, the national level, there is one organisation that is "trusted" in the sense that lawyers understand (to do with the transfer of liabilities). Then we could make some progress. At the national level, we can take the identity bus idea here and reformulate it as the identity utility, regulated by the government in some way (because the government’s national identity scheme would be connected to it) but provided largely by the private sector. The utility "pipes" identity to where it is consumed. The government identity need not be used in transactions, but it would serve to substantially reduce the cost to other private sector organisations of them issuing their own identities: What I mean by this is that it will be simpler, cheaper and more efficient for (say) Lloyds TSB to issue me with some form of electronic ID (who knows — a 2FA OpenID, or something like that) if they can use a government identity service to cut a whole lot of of cost and overhead out of the process.

So I can kind of see how it might all work, at least in outline. For business, though, we need to consider the meter as well. Should we charge a flat fee for the use of the utility or a small amount each time someone gets on the bus (oops, analogy overload)? There’s no reason for it to be free, but there’s a reasonable debate to be had around the best way to charge. Apart from anything else, there’s the psychological factor: Something that’s free isn’t valued.

Well, whether the bus transporting identity around or the utility piping identity for consumption is the better metaphor who knows, but they both help to improve the richness of discussion. We need some way of communicating the vision of digital identity at work and these will do.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Public transports appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/08/public-transpor/feed/ 0
Engineering eID http://tomorrowstransactions.com/2008/07/engineering-eid/ http://tomorrowstransactions.com/2008/07/engineering-eid/#respond Mon, 28 Jul 2008 12:55:05 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/07/engineering-eid/ [Dave Birch] There's infrastructure dddjd xxx bank. These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

The post Engineering eID appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] What are differences between the proposed German identity card and the proposed UK identity card? Well, for one thing we already know how the German card will work and what applications it will contain. In fact it will contain three: the ePass application for police and border control, the opt-out eID application for e-business and e-government and the opt-in eSignature application. It has some interesting functions, such as proof of age without disclosing age, and supports end-to-end online security because it has a mutual authentication scheme built in. If someone wants to authenticate you using your card, they have to provide a digital certificate (issued to them by the German government) that contains a map of the attributes (eg, address) that the service provider is allowed to use. Since the card and the service provider thus have an encrypted end-to-end channel, they are immune to man-in-the-middle attacks.

A function I find particularly interesting is the pseudonym function. A service provider can request an identity that is known only to that service provider and the card will generate a pseudonym according to a published algorithm. Since this involves using the service providers public key, service providers cannot know other service providers pseudonyms, a simple means to increase both security and privacy for very little effort. If there is a specification for the U.K.’s identity card that is currently being procured then I haven’t seen it, but I’d lay a pound to a penny that it does not include this kind of privacy-enhancing technology (PET) because I have never seen it in any of the management consultants presentations, government strategy documents or discussion forums. What a shame. Why do Germans deserve this kind of security but we Brits don’t?

Is this just my bias as an essentially technical person or is the German approach — to develop technical specifications that include advanced functionality and then procure against them — better than the U.K. approach of “output-based specification”? The problem with that latter approach is that even as procurement is well under way, no-one seems to know what the scheme is going to do. If you are a U.K. business and you need to plan for a cycle of investment that will include a shift to the use of identity cards, you need some certainty. Suppose you’re an ATM manufacturer and you want to offer British banks so kind of ID card function: you’re already designing products that will be sold next year and manufactured the year after that for installation the year after. Yet if you phone up the Identity & Passport Service to ask for a specification, you’ll get nowhere. This isn’t helping.

I hate to keep on repeating the same point, but somehow we are not setting the bar high enough on ID.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Engineering eID appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/07/engineering-eid/feed/ 0
You’ve got my identity, now what? http://tomorrowstransactions.com/2008/07/youve-got-my-id/ http://tomorrowstransactions.com/2008/07/youve-got-my-id/#comments Tue, 22 Jul 2008 18:09:06 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/07/youve-got-my-id/ , ,

The post You’ve got my identity, now what? appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Let’s suppose you are a master identity criminal and you’ve pulled off a heist: You’ve got away with the HMRC disks, or the POS keylogger or the hospital laptop. You’ve got my identity. Now what are you going to do with it? Open a bank account? Pretend to be me to commit acts of international terrorism?Take out a mortgage? Stalk someone via social networks? Get a credit card? Actually, it’s none of the above.

Wireless-phone accounts were the most frequent types of new accounts opened using ID theft, according to the report. These criminal cellphone account openings increased from 19 percent to 32 percent of new account fraud last year, exceeding fraudulently opened credit cards, loans, checking or savings accounts.

[From Javelin Strategy and Research » The Savvy Consumer: Don’t be taken in by drop in identity theft]

Generally speaking, most kinds of identity theft are really financial frauds of one form or another. If you want to sneak into NORAD, then you’re unlikely to find a useful ID floating around on the Net, you’d be targeting a more specific identity, blackmailing someone, that kind of thing. So if run-of-the-mill identity theft is about getting a bank loan in a bogus name, then I wonder if it might be economically more efficient for society as a whole to make getting bank loans harder to get rather than racking up costs defending against identity theft. if, in the U.S., you needed more than a plausible name, address and social security number combination to get a loan, then stealing the name, address and social security would presumably become less interesting to criminals.

Does this mean the nightmare described by Philip K. Dick in “Flow my tears, the policeman said” — the novel kindly sent to me by a blog reader, about which I can only say that I read it cover-to-cover on a single flight and spent the rest of the day thinking to myself “How can an author be so great?” — where you cannot do anything in the public sphere without waving your ID card over a reader? It’s plausible: if, say, banks can meet their KYC obligations by reading your ID card and the government accepts liability for the accuracy of the identification, then why would they do anything else?

There’s no determinism about this though. The alternative vision, of Little Sisters not Big Brother, can deliver: You shouldn’t need to provide your identity except in exceptional cases (eg, getting a mortgage, not buying gum) and your identity should remain protected until you do something wrong.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post You’ve got my identity, now what? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/07/youve-got-my-id/feed/ 2
2.5FA http://tomorrowstransactions.com/2008/07/25fa/ http://tomorrowstransactions.com/2008/07/25fa/#comments Tue, 15 Jul 2008 08:56:45 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/07/25fa/ , , ,

The post 2.5FA appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] 2FA is clearly important. But what kind of 2FA? At the moment, the "something you know" plus "something you have" version is in vogue, and a great many organisations have been rolling out tokens of one form or another. In the U.K., Barclays (to name but one) have already rolled-out 2FA to the mass market:

 

Gemalto announced it has passed the 1 million mark for Barclays customers using PINsentry, its cryptographic smart card reader. The bank started deploying its authentication program in July 2007 and since then not one PINsentry online customer has suffered fraud.

[From 1 million Barclays customer using smart card reader : SecureID News]

As I’ve said before, I’m a happy PINsentry customer, even though I know it doesn’t provide total security. But it’s a bit limited. I can’t use it to log in to anything else: I’d much rather that Barclays offered a 2FA OpenID login using the PINsentry and then I could use my Barclays OpenID to log in not only to the bank but to any other sites that needed that kind of security (eg, the government). Simon Willison’s excellent OpenID blogged alerted me to the fact that other people are already thinking in that direction.

 

Microsoft are accepting OpenID for their new HealthVault site, but with a catch: you can only use OpenIDs from two providers: Trustbearer (who offer two-factor authentication using a hardware token) and Verisign.

[From Simon Willison’s Weblog]

So OpenID/2FA is not only feasible, it’s a good idea. But we don’t want to end up with a 2FA necklace — with the tokens from half-a-dozen banks plus eBay plus our corporate networks plus plus plus — that we have to carry with us at all times and this could happen if banks and other service providers don’t accept each other’s OpenIDs in a rich enough way.

One way to do away with the necklace, of course, would be to use a device that everyone already has: the mobile phone. The addition of a proximity interface means that the phone can interface to cards just as the PINsentry does, so the PINsentry just becomes a bit of software in the phone (you can’t do this at the moment, of course, because the mobile phone keypad is not an approved PIN entry device, but it will be possible in the future with more security in the handset. An obvious alternative would be to use the mobile phone for a different 2FA login to OpenID (or whatever). This seems like a promising way forward, particularly if the SIMs have end-to-end cryptography on board. But would such a 2FA be enough? What about adding another hardware factor to make a kind of 2.5FA, as they have done over at Cell-cash:

 

Cell-cash requires two elements – a cellphone and a special bluetooth security dongle, carried separately from the phone… losing the phone doesn’t compromise security in any way; there is no sensitive information stored there. And forgetting the dongle at home means that it can’t be used in any way, since it’s linked to one specific phone.

[From Stellar Startups: E-wallet security, dongle style | Jerusalem Post]

Personally, the chances of me remembering both the phone and the dongle when I want to make a transaction might be somewhat limited, but I can see that it would be attractive to some people. Does "phone + dongle + PIN" improve much on "phone + PIN" ? I’m not sure that it does (because I don’t understand the arithmetic of this space: 2FA+2FA doesn’t equal 4FA, does it?), but I’ll be curious to see how it is used in practice: Perhaps it will make consumers feel more secure, which as we all know is as important as actually making them more secure.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post 2.5FA appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/07/25fa/feed/ 1
Out of band, out of mind http://tomorrowstransactions.com/2008/07/out-of-band-out/ http://tomorrowstransactions.com/2008/07/out-of-band-out/#respond Mon, 14 Jul 2008 09:36:25 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/07/out-of-band-out/ , , ,

The post Out of band, out of mind appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Using SMS to provide an out-of-band 2FA scheme for access to online services sounds like a reasonable idea. But it depends on customers to do the right thing, and this is generally a bad idea in security terms. One study of a scheme that required customers to copy a pass code from their phone to a web page (to confirm online transactions) found that customers did not notice when the message included incorrect details. My guess is that this is a general result: once you train customers to perform some simple action in order to obtain security, they won’t do any of the other cross-checks and because they think (for no reason) that SMS is somehow secure, then SMS-based approaches may be even more exposed. This is a shame, because it may hinder the development of mobile services, such a banking. People are increasingly comfortable with using their mobiles for banking, we all know that. According to TowerGroup, 90% of those who tried mobile banking at Bank of America have remained active with 99% checking balances, 87% looking at transaction history, 10% making funds transfers, and 5% paying a bill. But if they begin to read in the newspapers about mobile security being subverted, those numbers will fall.

Our position on the use of SMS in transactional services has been that the right place to begin is with simple transaction notification. It is true that out-of-band 2FA OTP solutions might be attractive, but in practice it might be better to wait for more sophisticated mobile digital signature solutions (such as are used in Turkey, for example) so that encrypted messages can be sent to the handset for digital signing. This completes the entire authentication process in a secure out-of-band way. Why is that important? Well, because SMS does not have that comparable level of security. This means that it can, will and has been exploited by fraudsters. Look at what happened in South Africa.

One of the banks operates a scheme that sends one-time passcodes to the customer’s mobile phone. The customer then uses the passcode to authorise an online transaction. Sounds pretty secure: how would the fraudsters be able to break into the bank systems and get the codes? Well, they didn’t. Like all fraudsters they went for the weakest link. The customer’s SIM card gets falsely declared stolen by the fraudster at the service provider. A replacement SIM card is issued, rendering the customer’s original SIM card void. What this means is that all security messages and codes sent to the customer by Standard Bank are sent to the fraudsters who utilise the customer’s replacement SIM card. Using the bank’s secure OTP, the criminals were able to change and add beneficiaries and transfer money out of the customer’s account using the original information obtained through the phishing compromise.
2FA doesn’t automatically mean security.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Out of band, out of mind appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/07/out-of-band-out/feed/ 0
Yoof http://tomorrowstransactions.com/2008/05/yoof/ http://tomorrowstransactions.com/2008/05/yoof/#respond Wed, 07 May 2008 15:54:27 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/05/yoof/ ,

The post Yoof appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Dealing with the government online is precisely the kind of activity that is subverted by bad identity management. Case in point:

 

Ambitious plans to switch the majority of provisional licences from postal to online could not be taken up by one of the largest group of customers – teenagers – because they couldn’t prove their identity. Only 40,000 out of the 1 million people seeking a provisional licence were able to complete an online application. The remaining 960,000 had to stick to postal applications. One of the main reasons, according to the NAO, was that online applicants had to have either a new digital passport or a credit record to prove their identity.

[From DVLA plan fails ID test | Special Reports | Guardian Unlimited Politics]

The government has portal for accessing public services — DirectGov — but it’s of limited usefulness, precisely because of this issue. And I’d lay a pound to a penny that the new ID card won’t make the slightest difference, since I’ve not heard a single minister or official say anything about using it in this way. Speaking of which, young people won’t have to worry about this problem for much longer because they’ll soon be able to get a splendid new identity card that will solve that problem for them. As the Home Secretary said recently

 

We will start to make identity cards available to young people on a purely voluntary basis in 2010. I believe there are clear attractions in the scheme. It will make it easier to enrol on a course, apply for a student loan, open a bank account, or prove your age – especially as we get tougher on sales of alcohol to those under-age.

[From BBC NEWS | Politics | In full: Smith ID card speech]

Anyone familiar with the U.K. will recognise the wisdom of making it more difficult for children to buy alcohol.

With public confidence in the new identity card so high, it’s surprising that some private sector organisations are yet to get behind the scheme and are even setting up alternatives:

 

The Age Watch system is due to be installed later this month at a store in the south-east of England, understood to be a Budgens. If successful, it could be rolled out across the UK. The technology has been developed to be used in convenience stores at the point of sale to capture images of customers that will be scanned against a database of known offenders.

[From Budgens trials facial recognition to fight underage sales - Talking Retail]

This seems a remarkable initiative to me. I don’t imagine there’s the slightest chance of it working (the most recent NIST face recognition vendor tests reported a False Accept Rate of 20% for matching uncontrolled images and controlled captures), yet the retailer rates it a more worthwhile investment than waiting till 2010 and then asking teenagers to present an ID card.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Yoof appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/05/yoof/feed/ 0
e-Dictum meum pactum http://tomorrowstransactions.com/2008/05/e-dictum-meum-p/ http://tomorrowstransactions.com/2008/05/e-dictum-meum-p/#comments Fri, 02 May 2008 11:58:40 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/05/e-dictum-meum-p/ [Dave Birch] There's infrastructure dddjd xxx bank. These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

The post e-Dictum meum pactum appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] There’s a story about identity in The Economist magazine that I read on the plane to Washington ("My bow is my bond", p.98, 26th April 2008) that connects directly with something I’m working on for a client at the moment. Naturally, neither the client or the assignment will be discussed here, except to note that I’ve been playing around with some ideas on value-adding identity services for the mass market. I’d also recently received an e-mail from an august body, which won’t be discussed here either, asking if I’d like to provide (for free!) some ideas on how to get private companies to use the U.K. identity card: I ignored the request, of course, but I did jot down a few notes. For both of these reasons, the story caught my eye.

The story concerns a fraud against Lehman Brothers in Japan. They lent a Japanese company $350 million, The load was guaranteed by a well-established Japanese trading house. Bankers from Lehman met an executvie from the trading house — at the trading house’s office — to sign the contract. When the firm in question defaulted, Lehman went to the trading house to get their money, but the trading house claimed no knowledge of the deal. The executive had been an imposter and the contract was fake. When someone gives you their business card, you assume that it is true (by custom and practice — you don’t explicitly validate it) and when they put a letterhead in front of you, you take it to be real. Oops.

Now imagine how it should work. I’m down at the printers and I order 500 copies of some flyer: let’s say, for example, the Consult Hyperion newsletter, that august journal CHYPpings. What’s the point of me showing them a business or a letterhead? Or physically signing anything? What should happen is this…

I open up my phone and select my identity application — downloaded from the operator, or the government or wherever — and it asks me who I want to be, In the pop-up menu is "Dave Birch from Consult Hyperion", "An Executive Officer of Consult Hyperion", "David Birch" and "The Notorious 15Mb".

The virtual identities in the pop-up menu are actually public key certificates stored in the handset. Each one has a corresponding private key in the SIM (some of the virtual identities share the key pairs, or digital identities as we call them).

     
  • "Dave Birch from Consult Hyperion" is signed by Consult Hyperion.
     
  • "An Executive Officer of Consult Hyperion" shares the same public key as "Dave Birch from Consult Hyperion" but it is signed by Barclays Bank because Executive Officers are allowed to sign cheques (etc).
     
  • "David Birch" is signed by me.
     
  • "The Notorious 15Mb" is signed by WordPress to prove that I own the blog 15Mb.

Don’t try and resolve the certificate chains, they’re just made-up examples. Anyway, I select the second. So when I touch my phone to the other guy’s phone, that virtual identity is transferred to his phone. His phone resolves the certificate chain (his phone already has Barclay’s root certificate cached) and away we go. Now he has a business card that is far more useful than a piece of cardboard: not only does it go straight into his phone book, but it can be coloured green because it’s been attested to by a third party that he trusts (ie, Barclays). And digital signatures mean that no-one can forge their "business card".

The identity transaction between us is taking place not in some kind of virtual reality but in what Umberto Eco would call a "hyper reality": not reaiity as it is, but reality as it should be. Not an emulation of cardboard business cards but something better than cardboard business cards. This really ought to be a guiding principle in the identity cards world.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post e-Dictum meum pactum appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/05/e-dictum-meum-p/feed/ 2
Engineering principles http://tomorrowstransactions.com/2008/04/engineering-pri/ http://tomorrowstransactions.com/2008/04/engineering-pri/#respond Tue, 29 Apr 2008 19:15:18 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/04/engineering-pri/ [Dave Birch] There's infrastructure dddjd xxx bank. These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

The post Engineering principles appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Privacy and security aren’t additional extras, costly options for new system. They are (or should be) part of the fabric. You can choose how to implement systems in either a privacy-enhancing or privacy-reducing way. Take, for example, congestion charging. There are a couple of ways to do this: you could do it the way they do in Singapore, where you have a prepaid card that communicates via RF with an overhead gantry. When you go through a gantry, the system attempts to take a fee from the card. If the transaction goes through (it’s an offline purse transaction) then you’re on your way. If you borrow a mate’s car, you can take your card and put it in his car, no problem. But if you don’t have a card, or you don’t have any money on your card, then you get photographed. Alternatively, you can do it the British way. In London, all cars get photographed and then automatic numberplate recognition is used to try and work out who to charge. In many cases, it works and the correct account of a poor person is charged. I say poor person, because rich people register their Lambourghinis as taxis and avoid the charge

 

Cleangreencars has discovered that there are an unusually high number of luxury cars that have been granted the private hire designation, including two Maserati Quattroportes, three Maybach 62 and eight Rolls Royce Phantoms.

[From Taxi!? London luxury car owners register Maseratis, Rolls Royces as C-charge-free private hire vehicles - AutoblogGreen]

Incidentally, if you can’t be bothered to send your chauffeur round to register the Porsche as a private hire, you can always just leave the Belgian plates on it, because the supercomputer running the system is not connected to other supercomputers in other European countries…

 

I drove for 4 years in london with a german plate, many times in the zone (once it was introduced), never paying and my ex never got a ticket sent to her place in HH where the car was registered.

[From London congestion charge for foreign cars]

In fact, as that tax-avoiders’ handbook The Independent notes,

 

there are a number of ways to exploit the loopholes in this system as a private, law-abiding motorist if you are willing to be a little inventive.

[From Congestion charge loopholes: Now just learn the Knowlege... - Features, Motoring - The Independent]

Bit I digress. My point is that we have choices, and not building privacy-enhancing technology into a system is making a positive choice to have a data catastrophe at some point downstream.

This is why my natural inclination is to have privacy-enhancing technologies (PETs) at the core not only of the design of new system but of the paradigm that they are described and animated inside. However, I think that trying to explain why they should be at the core is getting to be a Sisyphean task. Clients are busy, they are trying to focus on the bottom line (as they see it) and they don’t see privacy as part of the customer proposition. And the PET solutions that I advocate are, let’s face it, a bit complicated: you need to know a bit about security, cryptography and communications and the like to begin to picture the possibilities. Hence, it occurs to me that for many clients who find the whole privacy thing just too complicated, it may be better just to shut up about the long-term benefits of privacy and just advise them to implement Microsoft’s Cardspace instead. Why? Well, because…

 

Microsoft to adopt Stefan Brands’ Technology

[From IdentityBlog - Digital Identity, Privacy, and the Internet's Missing Identity Layer]

I’m looking forward to hearing how Credentica’s technology is going to be integrated into Cardspace and I just can’t wait to try it out.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Engineering principles appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/04/engineering-pri/feed/ 0