On the money

[Dave Birch] As I blogged before, Consult Hyperion has joined forces with Identrust to sponsor the Digital Identity Forum track on “Identity is the new money” at this year’s European e-Identity Management conference in London on 9th-10th June 2010. Having been through the usual juggling as people drop in and out, get called away to meetings and mess up their calendars, the final line-up is now as fixed as it can possibly be:

The Digital Identity Forum: Identity is the New Money
Sponsored by Consult Hyperion and Identrust

Session 1: Chaired by John Bullard, Identrust

13:15 John Skipper, PA Consulting
13:45 Vincent Jansen, Innopay
14:15 Sonia Rossetti, RBS
14:45 Giles Sergant, Touch2ID

15:15 Tea

Session 2: Chaired by David Birch, Consult Hyperion

15:45 Expert Panel on the Identity Business

Joe Norburn, Identrust
Robin WIlton, FutureIdentity
Jan Dart, Bell ID
Todd Facemire, Barclays

16:45 Expert Panel on Identity and the Consumer

Peter Bradwell, DEMOS
Henry Potts, UCL
Marc Dautlich, Olswang
William Heath, MyDex

17:45 Close.

Look forward to seeing you there. By the way, the promotional code EID10DIF will give your delegates 20% OFF of one or two day passes.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Identity is the new money

[Dave Birch] There’s a lot going in the world of identity, as anyone following this weeks Internet Identity Workshop will attest to. A decade after the web went mass market, we still have no mass market identity infrastructure in place, despite all of the efforts made by a wide variety of suppliers, standards bodies, open source groups and governments. It’s not because there aren’t technologies that can help — there are plenty — but because the technology is only part of the problem. The key technologies, in fact, are pretty well understood and in “closed” systems such as the DoD they are already deployed on a large scale (and here there has already been some progress on interconnection).

For example, Northrop Grumman is preparing to issue its new OneBadge identification cards to thousands of employees. The OneBadge card design and policies meet federal and DOD standards, said Keith Ward, director of enterprise security and identity management at Northrop Grumman. The company expects to be one of the first federal contractors to use a centralized public-key infrastructure as part of its identity management program, Ward said. The company participates in CertiPath, an entity created by several defense contracting firms that is part of the federal government’s trust network through a bridge relationship with the Federal Bridge Certification Authority.

[From Contractors prep interoperable identity management systems]

Look at all of the technologies that are in place here: PKI, smart cards, certification, federation and so on. Nevertheless technology is an important part of the equation, and we need to pay attention to the emerging technologies, because it will take some real effort by a coordinated industry grouping in order to get worthwhile (ie, involving tamper-resistant hardware) authentication deployed and this will need to be linked to a framework (such as the new OpenID Connect) that can easily be adopted by web sites, mobile services and across other channels.

One such grouping is obviously banks and payment schemes. And here, I think, there is a growing recognition that identity and authentication need new thinking.

The Visa card with one-time code offers banks an innovative solution to authenticate consumers through an alpha-numeric display and a 12-button keypad built into a conventional credit, debit or prepaid card. It is a neat solution for consumers to use and also contains a battery designed to last three years. The product has been developed in conjunction with EMUE technologies.

[From Leading banks join pilots of the innovative Visa card with one-time code]

Over on the Digital Money blog, we’re always very interested in developments in identification and authentication. Why are these these so important in the payments world? I think that the dynamic is this: if there is an infrastructure in place to manage identity, and that infrastructure includes clear division of responsibilities and clear assignment of legal liabilities, then it takes a big chunk of the costs out of building and running a new payment system. A general trend in the next phase of electronic payment evolution will be the unbundling of the payment, the identification and other services (such as fraud management).

There are different opinions about how the unbundled identification part might be implemented. I’ve written before that I think that a mobile, SIM-based approach might be the best way forward. The SIM provides the tamper-resistant hardware that we need to store the keys, the mobile phone provides the connectivity and interfaces and mobile operator provides the business model. There has to be a business to make identity work.

So what is the business model? For the operator, it’s incremental messaging revenue; in the first deployment, with Turkcell, the identifications were charged at the same rate as text messaging. According to Turkcell, this resulted in an average of 21 extra messages a month for each user who signed up for Mobile Signature; as a typical user sent 95 messages a month, that amounts to a 20% boost to messaging ARPU.

[From Case Study: Mobile Signature solution approaches key growth milestone – Convergence Conversation]

There are plenty of other possibilities, and if anyone tells you they know how this will work out, they’re wrong. But if they tell you that identity and authentication technologies will shape future payment strategies, they’re right. As I heard someone remark in a meeting a few months ago, if I were a bank, I’d want to be part of the identity value chain rather than a commoditised and low-margin payments value chain.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Dying for mail

[Dave Birch] I found the South-by-Southwest (SXSW) interactive sessions that I went to, without exception, first class. It may be because of the spectrum of people that they attract, or it may just be something in the Austin air, but I got caught up in a number of exceptionally stimulating discussions, all of which gave me new things to think about. Here’s an example: I signed up for a session on Digital Wills run by Corvida Raven from she-geeks. She ran an outstanding session, and I can’t resist blogging around it despite the morbid tone of some of the discussions that resulted from it! First of all, let me say that this is an aspect of the online world that I have been interested in for some time. I wrote a piece about it for The Guardian way back in 2004, reflecting on the fact that I had been making a will and had gone and got a booklet about it (I think from the bank, but I can’t remember) and I was remarking that it didn’t seem to cover my data.

It wasn’t mentioned in the booklet of sample will elements I was using. That covered topics such as houses and kids, but it should have had additional specimen clauses along these lines: “I leave the 100GB external Firewire drive containing all of my emails and the back-ups of all of my personal documents, my iPhoto library and my iTunes to my wife. This volume was encrypted by Mac OS X using AES-128 and the password is the name of the band we saw together on our first date followed by the age of our first female cat when she died.”

This may seem silly, but could become a serious problem in the future. My wife will need my username and password for Barclays, BT, British Airways and our family blog – and there was nothing about that in the booklet, either.

[From Second sight, Dave Birch | Technology | The Guardian]

This isn’t a sophisticated enough solution, of course. What we really need, as a society, is proper security and privacy technology and we are an awfully long way from seeing this introduced at all, let alone introduced into probate law or custom and practice. Nothing much has changed since my article, as Cory Doctorow reinforced last year.

What I found surprising all through this process was the lack of any kind of standard process for managing key escrow as part of estate planning.

[From Tales from the encrypt: the secrets of data protection | Technology | guardian.co.uk]

There are clearly some business opportunities here, and not only for lawyers! Some organisations have already decided to take the digital afterlife seriously.

Facebook may not have been the first to create a specialized policy for deceased users, but it was one of the highest profile because of the way it handled the issue. Instead of merely agreeing to let a family member take control of the account, the company instead decided to take things a step further and let people turn someone’s account into a memorial.

[From Death and social media: what happens to your life online?]

This is nice, but it seems to be still fairly rare. Take e-mail as a fairly standard requirement. If you die, Yahoo will delete your e-mail. But I may not want my e-mail to be deleted. Can I ask Yahoo not to delete my e-mail? No. But hold on, how do they know I am dead? If I just give my Yahoo password to my wife, then presumably she can carry on using it or archive the messages or even delete them. But what I if leave her the password and tell her not to delete them but just to save them for posterity and not read them? This is all getting a bit complicated.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Practical identity

[Dave Birch] It’s all very well people like me going on about keys, certificates and zero-knowledge proofs but what are the problems that an identity infrastructure has to solve down at the coal face, so to speak. Here’s an example from a newspaper I happened to be reading (The Daily Telegraph “Money” section, 13th March 2010). I won’t repeat the entire story, which concerns an elderly, partially-disabled woman who had UKP500 stolen from her bank account at Santander. The bank discovered the fraud, to their credit, and asked the women to come to the branch so that they could sort things out. However, they demanded that she product either a valid passport, a valid driving licence with a picture on it or a birth certificate. She (along with countless other people) had none of these. Despite the fact that she had had an account with them for many, many years, the process derailed The charity Age Concern, quoted in the article, noted the expense of obtaining new passports for people who have no intention of travelling anywhere and also noted that elderly people are sometimes asked to produce utility bills (to get a mobile phone contract, say) that they do not have because they live in care homes or with relatives and that there is a further serious problem where they ask family members to deal with financial services, government and other organisations on their behalf. If you can’t prove who you are to the bank where you have had an account for decades, how on earth is your daughter supposed to deal with the bank on your behalf?

One practical suggestion might be for Age Concern to operate a service to provide fake passports to its members. It could do this at low cost, and since fake British passports do not have to be particularly high quality to suffice (the bank just photocopies them anyway), this could provide a simple and cost-effective means to help their members.

Dubai airport is not just a two bit arrival and departure lounge for a small Arab country. It is a veritable cross roads for global airline traffic – one of the 10 most important international hubs in the world. Yet its passport scanning machines failed to recognise that all 11 passports were not just fakes but quite awful fakes.

[From Snowblog – What the Dubai murder says about airport security]

I doubt the elderly lady’s local bank branch has “passport scanning machines” of any description, so my suggestion is entirely practical. On the other hand, if we decide to opt for legal solutions, what should we do? If we are going to have a shot at improving the identity infrastructure to the benefit of society, then it has to work in these cases, which are hardly rare or extreme. This simple, practical case should serve as a benchmark: how can an older person use whatever system is proposed in order to ring up a bank and get something done with their own money.

In this light, how does the banking industry manage identity in the future… Would you have predicted 15 years ago that we’d still be using IDs and Passwords today? Will we still be using them 15 years from now?

[From Predicting the Future of Identity | Future Banking Blog]

Actually fifteen years ago I did predict, more than once, that we wouldn’t be using passwords by now. I thought then, and I still think now, that passwords aren’t really security of any kind. Never mind elderly people trying to remember passwords on the phone, I can’t remember passwords on the phone. I was speaking one of my card providers recently, having called to query a declined transaction, and was genuinely shocked to be asked for my password. I had no memory of having set a password on this account at any time in the past, so had to go through the whole set-up all over again. (Which was pretty annoying, but not as annoying as being asked for my card number yet again, ten seconds after I had punched all sixteen digits into the keypad!!).

As I sat down to write the rest of this post, the combination of prosaic, archaic and potentially catastrophic palaver that is the process of opening an account in modern Britain was once again raising blood pressure in our household. Having got annoyed with the poor customer service from one of our credit card issuers, I cancelled the card (a card, incidentally, that I spend around £3,000 per month on, since I travel a lot for business) and appealed to the twitterverse for suggestions as to alternatives. A testament to my middle class status, the most popular suggestion was the John Lewis Partnership Card that delivers shopping vouchers for Waitrose and John Lewis, so I went off to their web site and immediately applied. Hurrah! It said something like “congratulations, you’re accepted”. My happiness was short lived, as it soon became apparent that they weren’t going to send me a card at all, but a form to fill out and sign. Whatever. When it turned up I signed it, my wife signed it and I sent it back, then went away on business.

My wife phoned me after a few days wondering where her new card was. When I got back, I discovered that my card had arrived but hers had not. So I gallantly gave her mine (one of the great advantages of PIN cards over signature or biometric cards), and started going through the rest of the backlog of mail. Eventually I came across a letter to me explaining that John Lewis could not send my wife her card without further proof of identity because of know-your-customer and anti-money laundering regulations. My wife has only lived in the UK since 1986 and has only had a Barclays account for 20 years, so you can see why they might be suspicious. She follows a pattern well-known to FATF investigators of international organised crime: live at the same address for the last 15 years, use your Barclaycard to buy food at the same Waitrose every week and work for Surrey County Council, presumably a known hot-bed for narco-terrorism.

In order to prove her identity, and therefore get her card, she had to (in hommage to the founding of the John Lewis partnership in 1929) post them her council tax bill and last month’s bank statement. International terrorists would find these completely impossible to forge <sarcasm=”on”> as they contain advanced anti-counterfeiting watermarks, holograms and embossing </sarcasm=”off”>. Of course, this being 2010, you might have thought that my wife would merely have to log in to John Lewis using her Barclays’ dongle and Barclays would federate her identity (which they must have already established to the satisfaction of financial regulators) but I’m afraid even these rudimentary steps toward an identity infrastructure have yet to be taken.

In summary: everyone’s time and money continues to be wasted and we are no closer to having an identity infrastructure for the 21st century than we were at the dawn of the web.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Dog’s life

[Dave Birch] There was a news story in the UK recently about the very sad death of a young woman who was lured to a remote spot by a man who met her on Facebook. The man was pretending to be a teenage boy. Facebook became the focus of the story, with the usual calls for something to be done. So is the sky falling in because of social networking?

You could just as easily argue that criminals are easier to catch because of Facebook, or any other new technology. The police can use them too, can’t they? Doesn’t social networking make it easier for the police and others to work together? Couldn’t Twitter help detectives? Can’t detectives subscribe to RSS feeds on cases of interest? (Frankly, I doubt it, but you get my point.)

[From 15Mb: yet another blog from Dave Birch » Blog Archive » The “Ford Mondeo Killer”]

People might think they’re anonymous, but they’re not. A rational policy on law and order would surely try to get more criminals to carry out their crimes online, because it’s easier to catch them in the virtual world than in the real one.

When a YouTube video came to its attention on Friday in San Francisco, the FBI had a Philadelphia man in custody the next day

[From How the FBI busted one YouTube nutjob in under a day]

It’s the same logic as with money laundering. If you raise high barriers by making people prove who they are before going online then they will either go to great lengths to avoid the rules (thereby enriching middlemen) or just avoid going online, in which case they cannot be tracked or traced at all. I wrote an article for SPEED (“Moving money and securities worldwide”) magazine’s Spring issue, noting that if criminals were to abandon suitcases full of 500 euro notes for platinum pieces in Everquest (frankly unlikely, but there you go) then surely it would be easier for law enforcement officers to masquerade as half-orc barbarians in Norrath than as criminals in the real world and therefore follow the money.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

IS_A_PERSON

[Dave Birch] I have explained before why, of the many credentials that might be associated with a digital identity as part of a commercial, sustainable business model, the IS_A_PERSON credential might be the trigger for the evolution of a more comprehensive infrastructure. Once again, a news story comes along to back me up.

The defendants, however, worked with computer programmers in Bulgaria to develop a technology that allowed a network of computers to impersonate individual visitors to online ticket vendors. The ticket vendors did not immediately recognize the purchases as computer-generated, so these “CAPTCHA Bots” let Wiseguy Tickets to flood ticket vendors as soon as tickets went on sale and purchase tickets faster than any human.

[From Four Indicted in CAPTCHA Hacks of Ticket Sites – Reviews by PC Magazine]

I’m in favour of making ticket agencies illegal and forcing all events to sell all tickets by auction on eBay, the appropriate market-clearing mechanism, but that’s a separate point. The problem that the services providers are wrestling with is that they don’t know whether they are dealing with a person or a bot, and that’s an important problem to solve in a wide range of applications. Commerce, games and even blogs have this problem.

If you have a blog where it is important that people, not bots, contribute then you might well demand to see a certificate with the IS_A_PERSON credential, even though you don’t actually care which person it is.

[From Digital Identity: Talkin’ bout my reputation]

An anonymous virtual identity with the credentials IS_A_PERSON and IS_OVER_18 would serve most people for most purposes most of the time, including buying tickets from Ticketmaster: Ticketmaster could cost-effectively and efficiently issue me with a Ticketmaster virtual identity with their own credentials once presented with my “real adult” identity and associated payment details.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Why virtual identities are real to some of us

[Dave Birch] The real world is a horrible place, especially near where I live. No wonder that I prefer to sojourn in cyberspace. Is this because I am a geek, an outlier? No, it’s because I’m normal.

There’s a fairly strong argument that internet is, in fact, much, much better than the entire “real world”. It’s just easier being a human being there — not surprisingly, given that human beings invented it for human beings to be in; unlike the world, which we did not and are, let’s face it, still busking our way through.

[From Goodbye cruel world, I’m moving to the internet | Caitlin Moran – Times Online]

A few years ago, I wrote a couple of pieces that touched on this theme, including an article on “Opening a Branch in Narnia” for Financial World magazine after Alex Krotoski, Richard Bartle and I ran a seminar on virtual worlds for the CSFI. In this I noted that

One could imagine a flight to virtual communities, where mathematics (in the form of cryptography) provides a defence against crime and disorder that the metal barriers of a gated community cannot. If the community decides on a new law—no swearing in public places, let’s say—then they can enforce it instantly and 100% effectively by downloading a software update. If there are members of the community who don’t like it, they can go to another community instead.

[From Opening a Branch in Narnia An edited version of this article appeared in Financial World magazine, July 2006.]

Building on the Lessig-amplified “code is law” meme, I pointed out that whatever (in that case) Tony Blair might want for the country, he couldn’t just change a couple of parameters and reboot. The real world doesn’t work like that.

But the virtual one does.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

I can see an article of some sort. Anyone called David?

[Dave Birch] Well, my paper on “Psychic ID: A blueprint for a modern national identity” has been accepted for the new Springer journal “Identity in the Information Society” (IDIS). I didn’t completely understand the form I filled out, not being familiar with the world of academic journals, but I think the essence of it is that I can put a PDF of my original on my web site provided it contains a link to the actual journal article, so once I can sort that out I will do so. But the main reason for this post is just to note how what started off as an idea in a discussion — basically, trying to visualise 21st-century digital identity management using Dr. Who’s psychic paper as a reference point, having given up on trying to explain keys, certificates and all the rest of the crypto-infrastructure — became a presentation and then a paper and finally a peer-reviewed paper that I’m rather proud of. I’ve found a way to explain to non-technical audiences — well, British non-technical audiences at least — that the combination of widely-available devices and intelligence can deliver an identity management infrastructure that can achieve much more than they imagine.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Commercial activities

[Dave Birch] Identity management technologies have to get into the consumer space and go with the grain of what companies and their customers want to do. Clearly we can’t just start from scratch and redesign all commercial interactions on top of a (currently non-existent) identity infrastructure. Yet the technology that we need to improve the customer-business interaction is coming together, so it would be a good idea to try and figure how it can be made useful or attractive.

The good news is that these problems are already being addressed. Technology now makes possible an identity infrastructure that simultaneously addresses the security and public service needs of government as well as those of private sector organisations and the privacy needs of individuals. Privacy-enhancing security technologies now exist that enable the secure sharing of identity-related information in a way that ensures privacy for all parties involved in the data flow.

[From IdentityBlog – Digital Identity, Privacy, and the Internet’s Missing Identity Layer]

The (albeit limited) marketplace concept of identity management as a way making logging in to web sites and filling out online forms less painful is there, so it would be a good place to start.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Business and identity cards

[Dave Birch] We've decided to run a number of events linking the Digital Identity Forum to sister organisations with shared interests. The first of these will be joint seminar with EEMA at the British Computer Society in London on January 29th next year. This seminar, sponsored by Consult Hyperion, will be looking at the business opportunities that might arise from the introduction of the UK national identity card. You can register for the seminar at the EEMA web site. IPS will be presenting and we're hoping that all of their prime contractors will join an expert panel to share ideas on how British businesses can create new value around the scheme. We'll have an in-depth case study from Belgium to examine the business ecosystem that has grown up around the smart identity card introduced there. Look forward to seeing you there.

[Read more…]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.