Tomorrow's Transactions » digital identity http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 Identity, so I hear, is the new money http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/ http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/#comments Thu, 12 Jun 2014 10:12:57 +0000 http://tomorrowstransactions.com/?p=4483 The CSFI roundtable on my book “identity is the new money” left me utterly depressed. Every single book sold was sold for cash. I will never recover from the embarrassment and public humiliation. Still, at least they sold some. The wonderful people at the Centre for the Study of Financial Innovation (CSFI) in London did […]

The post Identity, so I hear, is the new money appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The CSFI roundtable on my book “identity is the new money” left me utterly depressed. Every single book sold was sold for cash. I will never recover from the embarrassment and public humiliation. Still, at least they sold some.

The wonderful people at the Centre for the Study of Financial Innovation (CSFI) in London did me the great honour of holding one of their super lunchtime roundtable meetings around the publication of my new book, “Identity is the New Money“. I gave a short talk on a couple of themes on the topic, starting by exploring Jack Weatherford’s meme about the future of money being more like the money of the neolithic past than the money of today and finishing with the three suggestions for UK policy makers that I finished the book with — and trying to justify them to a financial services audience which, judging from some of the questions, I didn’t do too badly at.

  1. We need to begin by finding a way to make the construction and use of a new infrastructure for identity a national project of significance. We need to find something that can provide the “parasitic vitality” for a new identity paradigms. We already know that in the UK, as well as in the USA, Australia and many other countries, there is no appetite for any kind of national identity scheme. But there may be an alternative formulation that helps all stakeholders: individuals, business, governments, law enforcement and everyone else. A National Entitlement Scheme. Long before the late and unlamented national identity scheme in the UK, there was (back in 2002) the original proposal for an entitlement card. This should be revisited in the light of modern technology. We can use the modern privacy-enhancing infrastructure to decouple these entitlements from the underlying identities and resolve the paradox of more security and privacy.
  2. One very specific use of the new infrastructure should be to greatly reduce the cost and complexity of executing transactions in the UK by explicitly recognising that reputation will be the basis of trust and therefore transaction costs. The regulators should therefore set in motion plans for a Financial Services Passport. This would use the same infrastructure as the National Entitlement Scheme but with a sector-specific profile. The UK’s IT industry trade association, TechUK, has a working group looking at just this idea already and together with colleagues at Consult Hyperion we have put forward the same suggestion to the Federal Reserve in response to their November 2013 consultation on the evolution of the US Payments System. Since the financial services passport would be using the same infrastructure as the entitlesment scheme, one might expect the costs to be manageable and then cost savings to UK plc significant.
  3. Finally, I should like to make a rather technical and boring plea to the relevant authorities to make the UK’s National Payments Plan adopt an explicit target for reducing the total social cost of payments in the UK. This will inevitably mean coming up with tactics to reduce cash (and cheque) usage in the UK. This target will be made significantly easier to attain using the Financial Services Passport to lower the barriers to entry for new products and services, increasing competition in the sector (especially with respect to the financially-excluded groups who are too expensive to serve using existing infrastructure).

These are straightforward calls to action and I trust that you have been persuaded to support them!

CSFI Roundtable

I won’t report the excellent and wide-ranging roundtable discussion that followed (which was held under the Chatham House rule) except to note that David Rennie — from the Identity Assurance Programme (IDA) in the Government Digital Service (GDS) — was kind enough to join me at the roundtable and talk about the government’s current initiatives and how they support the idea of shifting toward entitlement as the basis for transactional interaction.

As is the tradition at such events, my publishers were kind enough to show up in person with a job lot of the heroic tome (plus some other titles in the Perspectives series) to knock out at the back.

Untitled

Despite accepting Bitcoin, Pingit, Paym and PayPal, I’m sorry to say that every single person who bought a copy paid cash. I will never recover from the shame.

Untitled

If we can’t persuade the nation’s financial elite to use mobile payments, who can we persuade?

P.S. Available at all good bookstores and some of the bad ones too. Kindle version now available as well. For our US readers, you can buy right now online with free shipping to the US at http://bit.ly/1pdzFN0.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Identity, so I hear, is the new money appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/feed/ 1
HCE is launching http://tomorrowstransactions.com/2014/02/hce-is-launching/ http://tomorrowstransactions.com/2014/02/hce-is-launching/#respond Mon, 17 Feb 2014 13:34:04 +0000 http://tomorrowstransactions.com/?p=3913 HCE and BLE are going to make Barcelona fun this year, and they are opening up an important new role for mobile operators. The subject of Host Card Emulation (HCE: see “Why all the fuss about HCE“) seems to wander across almost every client meeting I’m in at the moment. And I’m thinking about it […]

The post HCE is launching appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

HCE and BLE are going to make Barcelona fun this year, and they are opening up an important new role for mobile operators.

The subject of Host Card Emulation (HCE: see “Why all the fuss about HCE“) seems to wander across almost every client meeting I’m in at the moment. And I’m thinking about it again this morning because we’re now only a week away from the mobile industry’s biggest annual jamboree, the Mobile World Congress in Barcelona. And last year, from a retail transaction perspective, HCE was probably the most interesting change to the landscape.

Well, the most interesting case study from Mobile World Congress last year was, as I have said before, BankInter in Spain.

[From Organisations are looking at NFC again]

A year on from that announcement, with HCE now part of the Android mainstream, BankInter have announced the commercial launch of their “Mobile Virtual Card” (MVC) product. They have had a detailed risk analysis carried out by the Fraunhofer AISEC in Germany — who concluded that the security of the HCE solution is “adequate for EMV online” (that is, where the POS goes online for authorisation) transactions — and are launching the service their customers and hoping to licence the service to other issuers. I thought it was interesting that their press release about this mentions that the technology…

…also allows the bank to autonomously define its own business model and brand image in mobile payment media, without entering into an agreement with third parties

Now, when they say “third parties” we all know that this is code for “mobile operators”. The version of mobile contactless EMV that uses a Secure Element (SE) in the (operator-controlled) UICC depends on card issuers and mobile operators developing not only some complex technology (difficult to start with, but gets easier over time, especially when you have the right consultants on board) and complex business relationships (difficult to start with, but gets harder over time, even if you have the right consultants on board). As a consequence, the early promise of mobile contactless at retail POS has not been realised. There are few suitable handsets, few suitable apps, few transactions and operator consortia (such as ISIS in the USA and Weve in the UK) have had a slow start.

You would think, then, that mobile operators should be utterly downcast at the prospect of HCE and its supposed “competitor” Bluetooth Low Energy (BLE) in the mobile mainstream this year. So with HCE and BLE all the rage, and undoubtedly the subject of countless announcements at MWC, what should they expect? Well, I think you might be surprised. With HCE as an accelerator for NFC-centric proximity apps and BLE as a complementary channel to deliver vicinity apps, I’m actually rather looking forward to MWC and the opportunity to take part in the re-energising of the contactless mobile world. I think that contactless delivers a better customer experience and will give retailers to ability to deliver some great new apps.

IMG_1078 - Version 2

But what would be the operator role in all this be? If the merchants and banks and transit companies can just build their apps and get going without having to rent space in an operator SIM? Well, as I will be discussing at the GSMA’s Digital Commerce Breakfast Workshop in Barcelona on Wednesday 26th February, they will have to deliver something of genuine value to stay involved: the service providers won’t have to use operator services, so the operators will have to deliver services that the service providers will want to use. Going back to the days of (and here’s one for the teenagers) Genie Passport at what was then Cellnet, I’ve always argued for the mobile operators central role in digital identity. The Secure Element (SE) is the obvious place to store these digital identities. And by storing digital identities that the app developers can access via standard APIs, the mobile operators can provide something of genuine value to the rest of the stakeholders, an identity infrastructure that both NFC (whether HCE or not) and BLE can use.

Unfortunately, my GSMA Breakfast Briefing on the subject is sold out, so I’m afraid if you don’t have a ticket already you won’t be able to come along, but the GSMA are organising a Twitter channel for comments and questions so I hope you’ll be able to join in all the same.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post HCE is launching appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/02/hce-is-launching/feed/ 0
Service Opportunities for Mobile Identity http://tomorrowstransactions.com/2014/01/service-opportunities-for-mobile-identity/ http://tomorrowstransactions.com/2014/01/service-opportunities-for-mobile-identity/#comments Tue, 28 Jan 2014 09:53:24 +0000 http://tomorrowstransactions.com/?p=3285 I still think that mobile identity is a real opportunity for mobile operators to provide a valuable service and occupy a key position in the future value network. At the Mobile Identity event in London last November, where I was the chair for the second day, I was challenging the speakers to identify barriers to […]

The post Service Opportunities for Mobile Identity appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

I still think that mobile identity is a real opportunity for mobile operators to provide a valuable service and occupy a key position in the future value network.

At the Mobile Identity event in London last November, where I was the chair for the second day, I was challenging the speakers to identify barriers to the large-scale deployment of identity services that use the mobile phone to provide practical and convenient identity management tools. After all, I’ve been going to conferences where the opportunities for mobile operators in the identity space have been discussed for at least a decade – and the first Consult Hyperion project on mobile identity that I can remember was in the late 1990s – yet when my card issuer suspected fraud recently they still had to call me (despite their having an app on my smart phone). Why not use the obvious characteristics of the phone to make, in this instance, card payments more secure. Actually, there are folks out there working on this sort of thing.

FICO, a leading predictive analytics and decision management software company, announced the availability of a new proximity correlation service for credit and debit card issuers which is aimed at improving the safety of payment card transactions. The new FICO service which several UK banks are planning to deploy has been developed in partnership with ValidSoft.

[From FICO adoption of ValidSoft Technology brings Safety of Payment Card Transactions to UK Banks - MarketWatch]

This is only one use case. Christophe Enzinger from the GSMA Mobile Identity Program made the point that mobile identity is infrastructural and has applications across communications, commerce, health and other sectors. I agree (strongly) with this infrastructural view. So how, in practice, can the mobile operators take advantage of this potential? Christophe’s very good suggestions included making upfront customer propositions around security and previously, making these essential components of the offer from operators to consumers, and Philippe Clement (the Head of Group Identity Marketing at Orange) develop edsome ideas around the practical deployment of such’s services by talking about identity APIs and their use in apps.

The Icelandic case study presented by Haraldur Bjarnson (the CEO of Audkenni) showed one approach. Their bank-owned consortium, which has been delivering identity services using the Icelandic debit card system (the debit cards have a digital ID certificate on them and about 40% of consumers have activated it), is shifting to a mobile electronic identity solution instead. This includes swapping consumers’s SIMs for SIMs with a PKI application on board. This, I think, is an interesting decision. It costs money to send out new SIMs and it’s a hassle for the users, so the operators must be pretty sure that the consumers will want and will use these services.

Rupert Hill from EE extended the discussion beyond personal by talking about the machine-to-machine (M2M) opportunities. As I had only just written something about the missing identity layer in the “Internet of things” I was very interested to see him attaching such a high priority to the Internet of things in the context of identity services.Some of the issues that need to addressed here are really rather complex. How can I delegate authority to my car? How will you know that it is my car? How will my car know that you are really a policeman? Solving these problems could be a huge business for the mobile operators is they could a) solve them and b) turn the solutions into a business.

What business, though? There are, as we have discussed before, different roles for mobile operators in the identity value network. Sergio Cozzolino from Telecom Italia talked about the difference between providing identity infrastructure and providing identity services, and explored the really useful distinction between mobile operators as identity providers and mobile operators and identity brokers. As Sergio noted, these different roles have different liability models and can allow stakeholders to develop the best business solutions choosing the appropriate liabilities. He talked through the use of SIM-based Secure Element (SE) and PKI applications as the mobile operators preferred solution. (He also, to be fair, explained the obstacles to success with this architecture).

I found the day really useful as it was an opportunity to chat with practitioners in order to get an accurate picture of the state of the sector, but afterwards I remember thinking that I was not sure that my initial challenge had been met. I still don’t really understand why the operators don’t get together and do something in this space. It seems completely ridiculous that with a smartphone running my card issuer’s app in front of me, I still have to phone them up, punch in a PAN and try to remember the answer to “security” questions to get anything done. And it’s even more ridiculous that they have to phone me up, and ask me yet more “security” questions when they want to interact with me, despite the phone company knowing perfectly who I am and where I am. Nevertheless, if you look around, you can see signals for change and mobile operators beginning to exploit potential around identity and authentication, so I think that my continued optimism about the potential for mobile operators to provide mobile identity services remains justified.

Payfone will use an AT&T application programming interface (API) toolkit to access network data that adds to Payfone’s existing service. Using the API toolkit, Payfone’s service will allow businesses to confirm that the device being used during a transaction is authenticated on AT&T’s mobile network.

[From Payfone Strikes Deal with AT&T to Verify Mobile Identity | AT&T]

As I have long been enthusiastic about this more infrastructural approach and the use of APIs to “cement” mobile operators into that infrastructure, I’m very keen to learn more about the latest developments in this areas. So the very good news is that I’m going to get the chance to discuss these issues with the operators themselves — and a great many other people  — at the Mobile World Congress in Barcelona. The GSMA have very kindly invited me to chair a session on “Service Opportunities for Mobile Identity” on Thursday 27th February from 11.30 to 13.00 and I’m genuinely looking forward to it. We’ll be in Hall 4, Auditorium 5 and I will have the honour and pleasure of charing Bjørn Hansen (Chief Scientist, Telenor Research), Siim Sikkut (National ICT Policy Advisor, Government Office of Estonia), Robert Blumenthal (EVP Business Development at SecureKey Technologies) and Steve Shoaff (CEO of Unbound ID). I look forward to seeing you all there and joining in the debate.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Service Opportunities for Mobile Identity appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/service-opportunities-for-mobile-identity/feed/ 1
Real-time identity http://tomorrowstransactions.com/2011/01/real-time-identity/ http://tomorrowstransactions.com/2011/01/real-time-identity/#respond Mon, 17 Jan 2011 16:37:26 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/01/real-time-identity/ [Dave Birch] An agreeable evening at the Real-Time Club once again, this time listening to Aleks Krotoski warning about the potential "balkanization" of the net (I paraphrase: she didn't use that word). The discussion was held under the Chatham House rule, so I can't mention who said what, but I will highlight a couple of strands of thought that emerged during the tough question and answer session.

The post Real-time identity appeared first on Tomorrow's Transactions.

]]>
Naturally, given my obsessions, I was struck by a subset of the Real-Time Club discussions about identities on the web at their evening with Aleks Krotoski. In particular, I was struck by the discussion about multiple identities on the web, because it connects with some work we (Consult Hyperion) have been doing for the European Commission. One point that was common to a number of the discussions was the extent to which identity is needed for, or integral to, online transactions. Generally speaking, I think many people mistake the need for some knowledge about a counterparty with the need to know who they are, a misunderstanding that actually makes identity fraud worse because it leads to identities being shared more widely than they need be. There was a thread to the discussion about children using the web, as there always is in such discussions, and this led me to conclude that proving that you are over (or under) 18 online might well be the acid test of a useful identity infrastructure: if your kids can’t easily figure out a way to get round it, then it will be good enough for e-government, e-business and the like.

I think the conversation might have explored more about privacy vs. anonymity, because many transactions require the former but not the latter. But then there should be privacy rather than anonymity for a lot of things, and there should be anonymity for some things (even if this means friction in a free society, as demonstrated by the Wikileaks storm). I can see that this debate is going to be difficult to organise in the public space, simply because people don’t think about those topics in a rich enough way: they think common sense is a useful guide which, when it comes to online identity, it isn’t.

On a different subject, a key element of the evening’s discussion was whether the use of social media, and the directions of social media technology, lead to more or less serendipity. (Incidentally, did you know that the word “serendipity” was invented by Horace Walpole in 1754?) Any discussion about social media naturally revolves around Facebook.

Facebook is better understood, not as a country, but as a refugee camp for people who feel today’s lack of identity-forging social experience.

[From Facebook: the heart in a heartless world | spiked]

I don’t agree, but I can see the perspective. But I don’t see my kids fleeing into Facebook, I see them using Facebook to multiply and enrich their interpersonal interactions. Do they meet new people on Facebook? Yes, they do. Is that true for all kids, of all educational abilities, of all socio-economic classes, I don’t know (and I didn’t find out during the evening, because everyone who was discussing the issue seemed to have children at expensive private schools, so they didn’t seem like a statistically-representative cross-section of the nation).

Personally, I would come down on the side of serendipity. Because of social media I know more people than I did before, but I’ve also physically met more people than I knew before: social media means that I am connected with people who a geographically and socially more dispersed. I suppose you might argue that its left me less connected with the people who live across the street from me, but then I don’t have very much in common with them.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Real-time identity appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/01/real-time-identity/feed/ 0
Masters key http://tomorrowstransactions.com/2010/11/masters-key/ http://tomorrowstransactions.com/2010/11/masters-key/#respond Tue, 23 Nov 2010 17:43:27 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/11/masters-key/ What I can't help but wonder about in this context is whether the content actually matters: suppose you can't read my e-mail, but you can see that a lot of mail addressed to Osama bin Laden is coming from my house?
... If we rely on mass surveillance via keyword searches, reading a billion e-mails hoping to find the one that tells where the suicide bomber is going to strike next may not be the most efficient (or practical) way forward - apart from anything else there are too many false positive - but it is plausible that the technology might improve enough in the future to make it worthwhile.
... I have no idea whether this is still true or not - it's not in the new government's Manifesto for a Networked Nation - but it is clear to me that we need a national strategy and perhaps even a European strategy, and we need to start with a digital identity infrastructure at the base. But to get to this, we need an education campaign to try to explain the core identity engineering principles to the arts graduates who are in charge of policy, and I have no idea how to do that.

The post Masters key appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] This whole internet thing is getting more and more complicated. I’m trying to work out what government policies toward the internet are, so that I can help our clients to develop sound long-term strategies with respect to digital identity. To do this, we need to understand how the security environment will evolve and what the government’s attitude to security is. Should people be allowed to send data over the internet without interference? The US government thinks so.

Since 2007, Congress has inserted a total of $50 million of earmarks into the State Department’s budget to fund organizations dedicated to fighting Internet censorship.

[From Rebecca MacKinnon: No quick Fixes for Internet Freedom - WSJ.com]

Uh oh. This cannot be popular with people in favour of internet censorship, such as U2′s boss.

U2 manager Paul McGuinness said that the only reason the music industry had tanked over recent years was not because outfits like U2 peddled the same boring crap that they did in the 1980s, but because of the introduction of broadband.

[From Comment: Broadband only useful for pirates - U2 manager screams blue murder | TechEye]

Setting aside the fact that the British music industry earned more money than ever before last year, U2 are totally wrong to expect the rest of society to pay to uphold their business model in face of all technological change. Bono is wasting his time calling for Chinese-style internet censorship in order to maximise record company profits, or at least he is if the US government is going to continue funding the opposition.

Talking about Chinese-style internet censorship, there were some very frightening reports in the newspapers this week.

A state-run telecoms firm is accused of diverting traffic including data from US military and government websites, and some in Britain, via Chinese servers. Experts fear that the authorities could have carried out “severe malicious activities” as a result of the 18-minute operation, even harvesting sensitive data such as the contents of email messages or implanting viruses in computers worldwide.

[From China may seek to 'control the internet', US report on web hijack warns - Telegraph]

But hold on. If you were trying to steal top secret e-mails from the Pentagon, why would you redirect all internet traffic? If you do that, people will notice, won’t they? Surely it makes more sense to just take sneaky copies of the e-mails, doesn’t it? When I read the story, I assumed it was a DNS error, the sort of thing that happens all the time.

In fact, it’s so simple, that it happens every year to somebody through sheer accidental misconfiguration… Sometimes it’s China, and sometimes it’s Con-Ed.

[From China's 18 Minute Mystery - Renesys Blog]

I’m sure this is the explanation. But some of the newspapers pointed to a more disturbing aspect of the story.

While sensitive data such as emails are generally encrypted before being transmitted, the Chinese government holds a copy of an encryption master key which could be used to break into redirected traffic.

[From China 'hijacks' 15 per cent of world's internet traffic - Telegraph]

Wait? What? There’s an encryption master key for the internet? That sounds like a bit of seriously bad design, doesn’t it? Who’s idea was it to make an encryption system for the internet and then create a master key that could break it? If there’s a master key, then I want it: I can download porn and make it look like I’m Rupert Murdoch, withdraw money from other people’s bank accounts and launch nuclear missles and, and…

Don’t panic. Just take a deep breath and remember that the only people who understand less about the internet than politicians are journalists. This story is, naturally, bunk. There is no “master key” for internet encryption, and what little internet traffic there is that is encrypted is safe for the time being. The source of the ridiculous “master key” story seems to be the New York Times, which says (with no attribution) that

While sensitive data such as e-mails and commercial transactions are generally encrypted before being transmitted, the Chinese government holds a copy of an encryption master key, and there was speculation that China might have used it to break the encryption on some of the misdirected Internet traffic.

[From Chinese Scrutinized for Meddling With Web Traffic - NYTimes.com]

Think about it for a second: if the Chinese government has a copy of the master key for the internet, then that means that someone else has the original and whoever that is can read all of the Chinese government’s internet traffic! So if such a master key did exist, then no-one would use the encryption system and they’d use an alternative instead. What a load of rubbish.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Masters key appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/11/masters-key/feed/ 0
China syndrome http://tomorrowstransactions.com/2010/11/china-syndrome/ http://tomorrowstransactions.com/2010/11/china-syndrome/#respond Wed, 17 Nov 2010 12:05:59 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/11/china-syndrome/ What I can't help but wonder about in this context is whether the content actually matters: suppose you can't read my e-mail, but you can see that a lot of mail addressed to Osama bin Laden is coming from my house?
... If we rely on mass surveillance via keyword searches, reading a billion e-mails hoping to find the one that tells where the suicide bomber is going to strike next may not be the most efficient (or practical) way forward - apart from anything else there are too many false positive - but it is plausible that the technology might improve enough in the future to make it worthwhile.
... I have no idea whether this is still true or not - it's not in the new government's Manifesto for a Networked Nation - but it is clear to me that we need a national strategy and perhaps even a European strategy, and we need to start with a digital identity infrastructure at the base. But to get to this, we need an education campaign to try to explain the core identity engineering principles to the arts graduates who are in charge of policy, and I have no idea how to do that.

The post China syndrome appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] What should government policy on identity be? Not specifically our government, or EU governments, or any other government, but governments in general. Or, let’s say, governments in democratic countries. OK, that’s a very big question to tackle. Let’s narrow it down to make a point: what should government policy on the internet be? No, that’s still too big and perhaps to vague. Let’s focus down further on a simple internet question: should the government be allowed to see what is going through the internet tubes. Of course! One of their jobs is to keep me safe from drug-dealing Nazi terrorist child pornographers who formulate devilish plots with the aid of the web.

According to reports, the FBI is asking for the authority to require all Internet communications platforms build in a “backdoor” allowing law enforcement easy wiretapping access

[From Should Government Mandate "Backdoors" for Snooping on the Internet? | Center for Democracy & Technology]

In parallel, the FBI is talking to technology companies about how they could be making it easier for criminals to see your credit card details and for the government to read to your e-mail.

Robert S. Mueller III, the director of the Federal Bureau of Investigation, traveled to Silicon Valley on Tuesday to meet with top executives of several technology firms [including Google and Facebook] about a proposal to make it easier to wiretap Internet users.

[From F.B.I. Seeks Wider Wiretap Law for Web - NYTimes.com]

This, superficially, sounds likes a good idea. Who could object? We don’t want the aforementioned Nazi drug-dealing child pornographers plotting terrorist acts using the interweb tubes with impunity. No right-thinking citizen could hold another view. But hold on…

In order to comply with government search warrants on user data, Google created a backdoor access system into Gmail accounts. This feature is what the Chinese hackers exploited to gain access.

[From U.S. enables Chinese hacking of Google - CNN.com]

It’s not that simple, is it? If you create a stable door, then sooner or later you will find yourself bolting it long after the horse has had it’s identity stolen. What I can’t help but wonder about in this context is whether the content actually matters: suppose you can’t read my e-mail, but you can see that a lot of mail addressed to Osama bin Laden is coming from my house? Surely that would be enough to put me under suspicion and trigger some other law enforcement and intelligence activity?

If we rely on mass surveillance via keyword searches, reading a billion e-mails hoping to find the one that tells where the suicide bomber is going to strike next may not be the most efficient (or practical) way forward – apart from anything else there are too many false positive – but it is plausible that the technology might improve enough in the future to make it worthwhile. Unfortunately, there’s no way of keeping that technology to the good guys.

Another concern is that wiretapping requirements in software have a tendency to be used not just by governments bound to the rule of law. For instance, TKTK was lambasted last year for selling telecom equipment to Iran that included the ability to wiretap mobile phones at will. Lost in that uproar was the fact that sophisticated wiretapping capabilities became standard issue for technology thanks to the US government’s CALEA rules that require all phone systems, and now broadband systems, to include these capabilities.

[From FBI drive for encryption backdoors is déjà vu for security experts]

I suppose that one way forward might be to focus on symmetry. If society is to be more transparent, then the only way forward is to make that transparency omnidirectional, if you see what I mean. Let the government read my e-mail if they let me read theirs. Unfortunately…

Federal investigators have identified several dozen Pentagon officials and contractors with high-level security clearances who allegedly purchased and downloaded child pornography, including an undisclosed number who used their government computers to obtain the illegal material

[From Pentagon workers tied to child porn - The Boston Globe]

It looks as if there is a paradox here. There is just no way forward. We want to peek, but we don’t want them to peek We want privacy, but we don’t want them to have privacy.When it comes to identity, politicians suffer from the China syndrome: that is, they want anonymity for Chinese human rights campaigners and Iranian dissidents but not for kids downloading MP3s or Islamic terrorists plotting to blow up Paris. As a consequence, they have no actual strategy. As I mentioned

In fact, US (and other governments’) policy in this isn’t just confused and pointless, it’s actually dangerous. If you create a mechanism to spy on people, you cannot assume that it will only be the good guys who use it

[From Digital Identity: Joe Bloggs]

You have some people from the government talking about transparency and freedom and others talking about censorship and spying: so what is the policy? In the UK, there is no vision for digital identity infrastructure, but there are some tactics. A few months ago, for example, we were all going to get a government web page.

He is now set to use a speech on Monday to unveil plans to give every voter a unique identifier allowing them to apply for school places, book GP appointments, claim benefits, get a new passport, pay council tax or register a car.

[From Every citizen to have personal webpage - Telegraph]

I have no idea whether this is still true or not – it’s not in the new government’s Manifesto for a Networked Nation – but it is clear to me that we need a national strategy and perhaps even a European strategy, and we need to start with a digital identity infrastructure at the base. But to get to this, we need an education campaign to try to explain the core identity engineering principles to the arts graduates who are in charge of policy, and I have no idea how to do that. Suggestions gratefully received.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post China syndrome appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/11/china-syndrome/feed/ 0
Tripped up http://tomorrowstransactions.com/2010/10/tripped-up/ http://tomorrowstransactions.com/2010/10/tripped-up/#comments Mon, 11 Oct 2010 22:13:19 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/10/tripped-up/ Incidentally, another large and well-known country closely associated with our economic future (albeit a virtual one) has just abandoned plans to try and force Chinese-style real-name registration after a revolt by citizens (well, subscribers): Blizzard has reversed a controversial decision that would have forced thousands of Starcraft and World of Warcraft (WoW) players to use their real names on the company's online forums [From Blizzard stands down over forum controversy | TG Daily ]
...Is it "astroturf", something that looks like a real review but has actually been posted by Simply making people register their details would be a start, but it would undoubtedly lead to a sharp fall in TripAdvisor's user numbers and its revenue, so it is unlikely to be countenanced.
... Many sites (eg, Amazon and eBay) will only let you review things that you have bought through them, which is great, but that doesn't help in the general case, reviewing hotels or doctors or schools or MPs or movies or just about anything else. All of these would like to establish that same baseline (ie, you can't comment on some service unless you have consumed it) but can't figure out a way of doing that would protect privacy (because the reviews won't be honest if people think that they might be tracked down and sued for libel for complaining about shoddy service ).

The post Tripped up appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Many people have a real problem with the apparently anonymous nature of the interweb. I say “apparently” because, of course, unless you work really hard at it and really understand how the internet works, and really understand how your PC works, and really plan it carefully, you’re not really anonymous in the proper sense of the word.

Our sense of anonymity is largely an illusion. Pretty much everything we do online, down to individual keystrokes and clicks, is recorded, stored in cookies and corporate databases, and connected to our identities, either explicitly through our user names, credit-card numbers and the IP addresses assigned to our computers, or implicitly through our searching, surfing and purchasing histories.

[From The Great Privacy Debate: The Dangers of Web Tracking - WSJ.com]

I’m surprised that politicians, in particular, who keep going on about how terrible internet anonymity is, don’t understand a little more about the dynamics of the problem. If they did, they would realise that anonymity isn’t what it seems.

You might think, after enough major stories about “IP addresses” hit the news wires, everyone in political life would be aware that “anonymity” on the Internet is limited.

But someone in Sen. Saxby Chambliss’ (R-GA) office didn’t get the memo. In the aftermath of this week’s failed vote on the military’s “don’t ask, don’t tell” policy, someone named “Jimmy” registered an account at the gay news blog Joe.My.God. just to say, “All Faggots must die.”

[From Outed! Senate staffers, anti-gay slurs, and IP addresses]

In the general case, you are not anonymous on the interweb, but economically-anonymous, which I propose to label “enonymous”, and that’s not the same thing at all. If you threaten to kill the President, you will be tracked down, and the state will spend the money it takes on it. But if you call Lily Allen a a hereditary celebrity and copyright hypocrite (not my own views, naturally) then it’s not worth the state’s money to track you down. If Lily wants to spend her own money on tracking you down and taking a civil action for libel, then fair enough, that’s the English way of limiting free speech. If the newspapers want to spend their own money on it, fine. For issues of great national interest, such as spurious death threats to the nation’s sweetheart, Cheryl Cole, The Sun can step in.

Yesterday The Sun traced the sender of a chilling anti-Cheryl message that blasted her over Zimbabwean Gamu’s TV exit. Wannabe rapper Sanussi Ngoy Ebonda, 20, admitted penning the sinister rant, which accused Cheryl of “da biggest mistake of your life” and included a threat to attack other girls sharing her name.

[From Cheryl Cole boosts security at mansion | The Sun |Showbiz|TV|X Factor]

So even though there’s precious little anonymity, should we allow enonymity to be the norm? There are plenty of people who think not, and they’re not all English libel lawyers. Surely common sense is on their side? Isn’t it wrong to let people hide behind pretend names?

Let’s focus on a specific and straightforward example. The comment pages on newspaper, magazine and other media web sites. Many such sites require registration but are still essentially enonymous. Is it right that enonymous commenters can say bad things about celebrities, politicians, business leaders? Would people be as horrible about public figures if they were forced to identify themselves?

Would the online debate among commenters be stifled by requiring commenters to sign their real names?

[From What did you say your name was? | Analysis & Opinion |]

The Chinese government certainly hope so.

China is considering measures to force all its 400m internet users to register their real names before making comments on the country’s myriad chat-rooms and discussion forums, in a further sign of tightening controls on freedom of speech.

[From China to force internet users to register real names - Telegraph]

We already know this doesn’t work, incidentally, because the Chinese already tried this for Internet cafes, supposedly to deal with the problem of young people spending too much time in virtual worlds. The only result was an instant, and profitable, black market in ID card numbers, whereby kids would get the ID numbers of people who weren’t going to play in cybercafes (eg, their grandparents) and used them to log in instead of using their own. There was an alignment of economic incentives here, because the cybercafes would not make money by turning people away.

Cafés that did not ask for identification often still had a registration book at the front desk, in which staff members were seen to write apparently random identification numbers and names during their free time.

[From HRIC | 中国人权]

Incidentally, another large and well-known country closely associated with our economic future (albeit a virtual one) has just abandoned plans to try and force Chinese-style real-name registration after a revolt by citizens (well, subscribers):

Blizzard has reversed a controversial decision that would have forced thousands of Starcraft and World of Warcraft (WoW) players to use their real names on the company’s online forums

[From Blizzard stands down over forum controversy | TG Daily]

I simply would not allow my kids to log in with their real names. I’m happy for them to log in using one of their multiple e-mail addresses. They’ve had pseudonymous e-mail addresses since they were old enough to go online. This isn’t just paranoia about people grooming children for sexual exploitation (the UK takes this kind of thing very seriously) and such like. There are lots of really good reasons for not wanting to use your identity in online debate and comment. I wrote once before about being shocked by some hate e-mails I received when I once posted some comments in a discussion about interest rates (“interest is the work of the devil”, “we know how you are” etc etc). Now, I still enjoy participating in online debates, but do so pseudonymously: my friends know who I am.

That, incidentally, may not be much of a protection, because the mapping of social graphs can soon locate you within a group of friends even if none of those friends disclose who you are. A determined third-party can learn very interesting things from those graphs and, unless everyone is anonymous or pseudonymous under certain conditions, figure out who you are.

Iran appears to be in two minds about whether to embrace or stymie technological progress. On the one hand, Twitter accounts helped the opposition mobilise demonstrations in the wake of last year’s contested presidential election… On the other hand, by monitoring Twitter traffic, Tehran was able to identify who was organising the protests.

[From FT.com / FT Magazine - Who controls the internet?]

As I’ve said before, in cyberspace no-one knows you’re a dog, but no-one knows you’re from the FBI either. Thus our government, the US government and many others are caught in two minds, just as the Iranians are. On the one hand, they are supposed to be in favour of free speech, but on the other hand, well, you know Danish cartoonists, criminals, child pornographers, terrorists, enemies of the state, dissidents, apostates etc.

Now, maybe you don’t care. You’re “not doing anything wrong.” Well, Hoder wasn’t doing anything wrong when he went to Israel and blogged about it in Farsi. But he’s serving 20 years in jail in Iran.

[From Emergent Chaos » Blog Archive » AT&T, Voice Encryption and Trust]

But back to online commenting in our democracy. It’s not a simple issue, and “common sense” is not a good guide to anything in the virtual world, but it is clearly the case that in that virtual world some people behave inappropriately. You only have to read The Guardian newspapers online “Comment is Free” or Guido Fawkes, the UK’s top political blog, to see how appalling, disgusting, racist, misogynist, anti-semitic and just plain thick the general public can be. I am one of those old-fashioned liberals who thinks that the response to bad free speech should be more free speech, not less. I think we should be wary about limiting the anonymity of people who comment online, even if we could think of a way of doing so.

The Nazareth District Court has upheld the right of the Walla Web portal to refuse to hand over the IP addresses of commenters accused of defaming a journalist.

“The good of online anonymity outweighs the bad, and it must be seen as a byproduct of freedom of speech and the right to privacy,” Judge Avraham Avraham wrote in his ruling last week.

The court also said the critical remarks concerning Yedioth Ahronoth reporter Israel Moskovitz, posted online in 2008, were unlikely to harm his reputation since they were poorly written and appeared only once, and readers were not likely to take them seriously.

[From Uphold talkbacker's anonymity in defamation trial, court says - Haaretz - Israel News ]

Actually, for journalists to complain about online comments, criticism and even abuse is a tiny bit worrying, since their business depends on such.

It doesn’t take long to find articles on CNN that quote anonymous officials. For them to rage against “cowards” who won’t stand behind what they say, and then to regularly quote “anonymous” sources, seems pretty damn hypocritical. Phillips claims anonymity online is “very unfair.” Phillips also attacks the media for “giving anonymous bloggers credit or credibility.” But again, CNN quotes all kinds of anonymous sources all the time.

[From CNN Claims 'Something Must Be Done' About Anonymous Bloggers | Techdirt]

On balance, then, I think a free society not only permits certain kinds of anonymity but actually depends on them, because we need informed and honest public debate to function properly. This was well-put in the Washington Post recently.

For every noxious comment, many more are astute and stimulating. Anonymity provides necessary protection for serious commenters whose jobs or personal circumstances preclude identifying themselves. And even belligerent anonymous comments often reflect genuine passion that should be heard.

[From Andrew Alexander - Online readers need a chance to comment, but not to abuse]

I couldn’t agree more. However, as the Post goes on to note, we have to recognise that people can be pretty horrible and we need a way to deal with that. Not banning anonymity, but managing the anonymousness (if there is such a word) in a better way.

The solution is in moderating — not limiting — comments. In a few months, The Post will implement a system that should help. It’s still being developed, but Straus said the broad outlines envision commenters being assigned to different “tiers” based on their past behavior and other factors. Those with a track record of staying within the guidelines, and those providing their real names, will likely be considered “trusted commenters.” Repeat violators or discourteous agitators will be grouped elsewhere or blocked outright. Comments of first-timers will be screened by a human being.

[From Andrew Alexander - Online readers need a chance to comment, but not to abuse]

This — in essence, baby steps toward a reputation economy — could be toughened up by using better identity infrastructure, but it’s not a bad place to start. But there are areas where the better infrastructure is more of a priority. Newspaper comments are one thing, but there are businesses that depend on online comments, and a good example is the burgeoning group review sector.

There’s a general problem with the review sites on the interweb. They are one of the things that the interweb can do well and they perform a very useful social function. But… you can’t trust them. If you’re looking at a hotel review on a travel web site, how do you know whether the review is “real”? Is it “astroturf”, something that looks like a real review but has actually been posted by

Simply making people register their details would be a start, but it would undoubtedly lead to a sharp fall in TripAdvisor’s user numbers and its revenue, so it is unlikely to be countenanced.

[From Tripadvisor reviews: can we trust them? - Telegraph]

Many sites (eg, Amazon and eBay) will only let you review things that you have bought through them, which is great, but that doesn’t help in the general case, reviewing hotels or doctors or schools or MPs or movies or just about anything else. All of these would like to establish that same baseline (ie, you can’t comment on some service unless you have consumed it) but can’t figure out a way of doing that would protect privacy (because the reviews won’t be honest if people think that they might be tracked down and sued for libel for complaining about shoddy service).

There is way to do this. Remember the old DigiCash technology? Why not build an extension to OpenID so that you can collect tokens from service providers. Then in order to post a review of some service, you have to present the token (in order to prove that you have consumed the service). But the tokens would be cryptographically-blinded.

Here’s the marketeture for how to do it. I go stay at the San Francisco Hilton. I’m a member of their loyalty club, so I log in to their web site using OpenID or something. Once logged in, my plug-in generates a random number and blinds it. It then send the random number to Hilton. They know I’ve stayed, from my loyalty club number (or you could do it from a credit card or whatever), so they use their private key to sign the token, thus forming a digital certificate, which they send back to me. On receiving the certificate, my plug-in unblinds it. Now I have a digital certificate that proves I stayed at the San Francisco Hilton some time in 2010 (say), but no-one (not even Hilton) can link that token to me.

Now I log in to TripAdvisor using my OpenID plug-in. Up pops a menu (based on all of the certificates in my plug-in) asking me to rate the various things, one of which will be the San Francisco Hilton. TripAdvisor can now post the review knowing for certain that I did stay at the hotel. Now imagine this not only generalised — to movies, doctors and everything else — but also taken for granted as the way that things work: so that anonymity is valued part of the online interaction landscape.

The NSTIC proposal places no value on anonymity; indeed, it evinces an apparent lack of understanding of what anonymity really means. It takes for granted the need for authentication (if we pay in cash, why does a merchant, much less a common carrier or government agency, need to know about us other than that our money isn’t counterfeit?) and confuses a policy that purportedly restricts disclosure of our identity with actual non-knowledge of our identity.

[From Papers, Please! » Blog Archive » Public says “No” to national cyberspace ID proposal]

If we in Europe decide to develop our own kind of European Strategy on Trusted Identites in Cyberspace (ESTIC) then I think it should not only include both conditional and unconditional anonymity but should strive to make it clear that, like pseudonymity, these types of online persona will be the norm, not the exception.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Tripped up appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/10/tripped-up/feed/ 4
Joe Bloggs http://tomorrowstransactions.com/2010/08/joe-bloggs/ http://tomorrowstransactions.com/2010/08/joe-bloggs/#respond Mon, 02 Aug 2010 09:10:28 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/08/joe-bloggs/ [Dave Birch] Having just come from a meeting about the management of multiple identities and the potential commercial structure of a proposition based on pseudonyms, I found myself reading some excellent and thought-provoking comment on the issue of anonymity vs. pseudonymity vs. absonymity starting with a US perspective over at Public Citizen. The First Amendment […]

The post Joe Bloggs appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Having just come from a meeting about the management of multiple identities and the potential commercial structure of a proposition based on pseudonyms, I found myself reading some excellent and thought-provoking comment on the issue of anonymity vs. pseudonymity vs. absonymity starting with a US perspective over at Public Citizen.

The First Amendment protects the right to speak anonymously, and if the bar to such discovery is set too low, much citizen and consumer discussion about the important issues of our day, including the doings of corporations and politicians, will be chilled and hence lost to the marketplace of ideas. If it is set too high, valid claims may be lost. We at Public Citizen have litigated many cases devoted to setting this balance correctly.

[From CL&P Blog: Two new cases on Internet Anonymity]

I can’t say I understood everything (or, indeed, anything) in the legal argument, but I think I agree with the conclusion (applied by the US courts in the examples given) that “commercial” speech is not the same as “political” speech. Companies bashing each others’ products via “astroturf” blogs are not (and should not) be subject to the same privileges as political opponents questioning policies. But, naturally, it is a very fuzzy boundary, and one of the key issues is anonymity. If you are allowed to post anonymously, then it’s hard to

If you read through both stories you see that judges basically seem to be making it up as they go along as to what standards to use in deciding whether or not online anonymity is protectable

[From More Mixed Rulings On The Right To Be Anonymous Online | Techdirt]

Now, I would have thought that one of the reasons why we have judges is precisely so that they can make things up as they go along. If the law was written by people like me, it would be in XML and given the facts of the case as a set of propositions would be capable of delivering justice through an algorithm that would decide the outcome in polynomial time. But it isn’t, so we need judges. Sometimes they come up with odd rulings — look at the fuss about the UK judge who recently ruled that it’s not against the law to smash stuff up if it belongs to people you really don’t like — but, generally speaking, they combine law and common sense.

Unfortunately, as I have constantly complained, common sense is a bad guide to what to do about identity.

We don’t want paedophiles and nazis to be able to groom unsuspecting, innocent children online. Who could disagree with that? In the UK, this “common sense” drove a furore about Facebook that has led to an completely pointless resolution (along the lines of “something must be done, this is something, so let’s do it”).

how can the police help with every teen who is struggling with the wide range of bullying implied, from teasing to harassment? Even if every teen in the UK were to seriously add this and take it seriously, there’s no way that the UK police have a fraction of the resources to help teens manage challenging social dynamics. As a result, what false promises are getting made?

[From danah boyd | apophenia » Facebook’s Panic Button: Who’s panicking? And who’s listening?]

I would be utterly shocked if the presence of this button makes even the slightest difference. The kids who are smart enough to press it when they are approached are presumably smart enough to know that they are being approached, if you see what I mean, and the kids who press it because they are being bullied by their peers in some way are not going to get any help, so what’s the point? The “Facebook murder” that Danah refers to might just as well have been called the “Ford Mondeo” murder, since both technologies were crucial to the crime, and as she points out having this button would not have averted the tragedy.

What’s the alternative? Do we adopt the Chinese approach?

leading Chinese Internet regulator has vowed to reduce anonymity in China’s portion of cyberspace, calling for new rules to require people to use their real names when buying a mobile phone or going online, according to a human rights group.

In an address to the national legislature in April, Wang Chen, director of the State Council Information Office, called for perfecting the extensive system of censorship the government uses to manage the fast-evolving Internet, according to a text of the speech obtained by New York-based Human Rights in China.

[From China seeks to reduce Internet users' anonymity - The Globe and Mail]

This sounds like the sort of thing that will go down well with the Labour MP Geraint Davies who is currently trying to get a law on the books to fine Visa and MasterCard if their cards are used to buy child pornography. He is particularly exercised by anonymous pre-paid cards that he says are routinely used by paedophiles (and, I’m sure, drug dealers, terrorists, tax evaders etc etc). And yet… I can’t help feeling that we cannot have a healthy society unless it allows certain kinds of anonymity.

The Nazareth District Court has upheld the right of the Walla Web portal to refuse to hand over the IP addresses of commenters accused of defaming a journalist. “The good of online anonymity outweighs the bad, and it must be seen as a byproduct of freedom of speech and the right to privacy,” Judge Avraham Avraham wrote in his ruling last week. The court also said the critical remarks concerning Yedioth Ahronoth reporter Israel Moskovitz, posted online in 2008, were unlikely to harm his reputation since they were poorly written and appeared only once, and readers were not likely to take them seriously.

[From Uphold talkbacker's anonymity in defamation trial, court says - Haaretz - Israel News ]

It sounds like this very sensible judge has found a decent balance so I don’t see why we can’t have the same kind of balance here. William Dutton makes a typically excellent observation on this.

Freedom of expression often requires anonymity, and many other activities and services have no need for identification of users. While not everyone agrees, creating what some of us called an ‘accountability versus anonymity’ debate, it is an important issue.[ii] Often there is only a need to authenticate that a person has a right to the service, such as being over a certain age. Therefore identity systems online must support this full range, and not require a level of identification greater than required by a particular service.

[From Online Identities: Selected Observations on the Big Picture at William H. Dutton]

It’s not fair to pick on the odd confused UK MP about this. Government in general simply doesn’t know what to do: there is no strategy — the Government’s “Manifesto for Network Nation” does not mention identity even once in its 59 pages — and it therefore has no considered opinion on the topic. The same is true in the US.

The speech made it obvious that State Department officials do not have a coherent view on online anonymity. On the one hand, they want to crack down on intellectual property theft and terrorists; on the other hand, they want to protect Iranian and the Chinese dissidentss. Well, let me break the hard news: You can’t have it both ways and the sooner you get on with “anonymity for everyone” rhetoric, the more you’ll accomplish.

[From Is Hillary Clinton launching a cyber Cold War? | Net Effect]

In fact, US (and other governments’) policy in this isn’t just confused and pointless, it’s actually dangerous. If you create a mechanism to spy on people, you cannot assume that it will only be the good guys who use it!

The news here isn’t that Chinese hackers engage in these activities or that their attempts are technically sophisticated — we knew that already — it’s that the U.S. government inadvertently aided the hackers… In order to comply with government search warrants on user data, Google created a backdoor access system into Gmail accounts. This feature is what the Chinese hackers exploited to gain access.

[From U.S. enables Chinese hacking of Google - CNN.com]

The government should be putting in place a system that provides certain kinds of anonymity in certain circumstances and — as I constantly bleat — make it central to their “Digital Britain” strategy that pseudonymity is the default.

But while no government-backed identification system could ever be expected to provide users with strong anonymity of the kind that will protect you from the government itself, more limited degrees of anonymity are still useful. While you’d want to stay far away from any products of NSTIC if you’re anonymously posting videos of the police to your blog, if your aim is to anonymously blog about something like living with HIV, then NSTIC will probably work.

[From White House wants to help you "blog anonymously"]

I disagree with this. It is entirely possible to construct identities within the USTIC framework that have both conditional and unconditional anonymity. For example: Barclays Bank could give me an identity “joe.bloggs!barclays.co.uk” and I could then happily potter around the Internet, banking and shopping and commenting and participating and everything else. If I turn out to be a nazi pedophile grooming children to sell them glue online, then the police can take a warrant to Barclays who will then tell them who I am. What’s the problem? Meanwhile, I have a persistent identity for online participation that cannot be traced back to me by dastardly marketeers, puppets of foreign powers or FBI agents who are pretending to be nazi pedophiles and trying to groom me.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Joe Bloggs appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/08/joe-bloggs/feed/ 0
Simple cases http://tomorrowstransactions.com/2010/07/simple-cases/ http://tomorrowstransactions.com/2010/07/simple-cases/#comments Mon, 26 Jul 2010 10:58:58 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/07/simple-cases/ [Dave Birch] I’ve been looking at a survey undertaken by UK Online’s “myopinion” panel in connection with the Technology Strategy Board’s VOME project that Consult Hyperion are involved in. Researchers from the Information Security Group (ISG) at Royal Holloway, University of London worked together with UK online to conduct a survey of privacy attitudes and […]

The post Simple cases appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] I’ve been looking at a survey undertaken by UK Online’s “myopinion” panel in connection with the Technology Strategy Board’s VOME project that Consult Hyperion are involved in.

Researchers from the Information Security Group (ISG) at Royal Holloway, University of London worked together with UK online to conduct a survey of privacy attitudes and behaviours. Focusing on our concerns about privacy while using the internet, the survey reveals that online identity theft is currently the greatest fear for internet users.

[From Online identity theft is the greatest fear for internet users]

The great majority of respondents (almost all of them, in fact) use the Internet daily from home, work or school. In this group, their top concerns about privacy are:

  1. “Online identity theft”
  2. “Spying on online activity”
  3. Payment card data being intercepted.
  4. Merchant mischarging.
  5. Having to provide too much personal information when purchasing online.

I noticed an odd gender imbalance, in the sense that women report being more concerned about privacy than men do, but men were much more likely than women were to actually do anything about it, presumably because doing something means (to a large extent) technological activities such as turning on firewalls.

There were a cluster of concerns just below the top five that caught my eye.

  1. People online not being who they say they are.
  2. E-mails not being from the people who they say they’re from.
  3. E-mails being read by someone other than the person you sent them to.

Now, on the one hand, technologists might dismiss these issues and say that they are a result of the way that e-mail works and that we should educate people about that. Normal people (eg, my good lady wife) do not see it like this. She is genuinely puzzled as to why technical geniuses can’t figure out how to stop her from getting spam e-mails that purport to be from friends, and the like. It’s a bit of an inditement, really, that we don’t have even the most basic identity infrastructure in place for the simplest of services, and I think the public can reasonably be annoyed about this.

I think these concerns also show that we haven’t managed to get even the simplest elements of identity infrastructure working. A decade ago I would have assumed that by now I would be able to flip a switch on our Outlook server to junk all emails that didn’t have a valid digital signature (set aside what valid means for a moment). But it just hasn’t happened, despite all of the technology being in place.

There were two more concerns than I hadn’t really though much about.

  1. E-mail being inappropriately forwarded.
  2. E-mail being printed out.

It’s clear from these concerns that people simply do not see e-mail the way that we (ie, technical persons) do. I remember, many years ago, reading something by Phil Zimmerman in the original PGP manual. Phil said, in essence, that you should think of e-mail as being like postcards that anyone can read and do what they like with. That’s how I’ve always thought of it. Perhaps it’s time for government campaign, possibly under the Race Online 2012 banner.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Simple cases appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/07/simple-cases/feed/ 1