Tomorrow's Transactions » identity security technology consumer mobile http://tomorrowstransactions.com Thought leadership from Consult Hyperion Wed, 10 Sep 2014 20:33:30 +0000 en-US hourly 1 http://wordpress.org/?v=4.0 Mobile eye-D http://tomorrowstransactions.com/2008/11/mobile-eye-d/ http://tomorrowstransactions.com/2008/11/mobile-eye-d/#comments Mon, 10 Nov 2008 21:17:19 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/11/mobile-eye-d/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post Mobile eye-D appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] OK, so I’ve been thinking about mobile phones in the identity space again, because I’ve been considering a problem around remote identification in connection with a project we’re working on. The mobile phone is an obvious focus for a solution, because everyone has one and (generally speaking ) they know how to use them. Therefore, if you have to use your mobile phone in some way to identify or authenticate yourself on the web, you probably won’t mind that much. And not having to buy some kind of dongle makes it cheaper. We have to be careful with this thinking though. As we discussed recently, we must thoughtful and not tomake unwarranted assumptions about the security of the mobile handset, applications, network and systems. People think that mobile is more secure than it actually is, and not because master criminals are planting trojan horse viruses

Though he’s seen cases in which customers were sent SMS messages that tricked them into giving up passwords or other key information, he hasn’t yet seen any cases in which losses were caused by key logging programs or other malware that infiltrated cell phones.

[From Mobile Insecurity: Reality or Just hype? - 11..2008 - Bank Technology News Article]

What we need is for end-to-end security to become standard on mobile phones and, to my mind, what that really means as a first step is a digital identity infrastructure that is rooted in the SIM. This, in itself, is not that hard. A SIM Toolkit (STK) application for creating and verifying digital signatures together with a key pair is all that is needed to get started. But so long as the handset itself remains insecure, there will always be the possibility of viruses capturing PINs and so on. If the manufacturers could get together to add some kind of trusted processing to the handset (which, incidentally, would mean that mobile phones could become approved PEDs and become part of PCI-DSS solutions) it would open up a whole new field of value-added business.

On the other hand, perhaps I’m being overly sensitive to risk for cultural reasons. In Japan, where the mobile phone is an integral part of the culture and not regarded as technology any more, there is at least one bank that has adopted the mobile channel wholeheartedly.

At eBank, applicants do not need to fill in application forms by hand or visit the bank, says Saiki. “They can do all of it by sending applications by PC and mobile phone. It is necessary to send identification, but they can send the picture on their driver’s licence or other ID using a camera function of a mobile phone, which is legal in Japan

[From E-bank Japan sets mobile banking example | 13 Oct 2008 | ComputerWeekly.com]

Wow. This would definitely reduce the cost of customer acquisition for all sorts of businesses! I’m not sure if it gets us where we want to be in terms of real security though. We need end-to-end security (like the mobile digital signature service that Turkcell have launched) and then we can transform the identity space by using the mobile phone instead of custom devices, passwords or nothing at all to secure our online selves.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Mobile eye-D appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/11/mobile-eye-d/feed/ 1
SOS SMS http://tomorrowstransactions.com/2008/10/sos-sms/ http://tomorrowstransactions.com/2008/10/sos-sms/#respond Wed, 29 Oct 2008 07:45:27 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/10/sos-sms/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post SOS SMS appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] The use of the mobile phone as an identity and authentication platform is, to my mind, inevitable. The capability and connectivity of the mobile handset makes it a million times more useful for identity, access control, credential management and most other digital identity functions. And, of course, the place can also act as a verification tool. One thing that holds up development in this area is the lack of trusted infrastructure in the handset (the handset environment is not protected: anyone can run software on the phone). But what about the network? Can we trust that? SMS provides a useful lesson. There are plenty of banking and payment services, for example, that use text messaging for transactional services:

Users simply send a text message to RBC Mobex with the dollar amount and the recipient’s cell phone number. Funds are then taken from the sender’s Mobex account and moved to the recipient’s Mobex account. The recipient also receives an instant text message on their cell phone to let them know when the money has been sent to them.

Amounts of up to $100 per day can be sent to anyone with a mobile phone serviced by any Canadian wireless carrier, even if they do not have an RBC Mobex account. Recipients just need to register for the payment service to access their funds. The RBC Mobex account is a stored value account and enrollment is through the RBC Mobex web-site, where money can be loaded from any bank account with any financial institution in Canada, or by using a credit card.

[From Payments News: Canada: RBC's Mobex Mobile Payment Service - September 29, 2008]

There’s an IVR callback with online PIN for transactions over $25, so there are limited opportunities for fraudsters. Provided that the allowed actions are limited, this kind of scheme works well, although there have been problems in some countries (eg, South Africa) where criminals have been able to obtain replacement SIMs from corrupt operator employees. Yet the fact that it may be hard to make bogus transactions does not mean that text messaging is ideal for identity and authentication services, nor does it mean that we should see services that use unencrypted text as reliable.

I saw Charles Brookson, the head of the GSMA security group, make a very interesting point recently. Charles was talking about the use of SMS fo rmobile banking and payment services and he made the point that SMS has, to all intents and purposes, no security whatsoever. The spoofing of SMS originating numbers, in particular, is trivial (this is why M-PESA, for example, encrypts and signs all SMS messages using a SIM Toolkit application).

This means that even “simple” transaction notification services can be a problem. If you are, let’s say, a Citibank customer and you get a text message when you use your MasterCard for a purchase of more than $10 or whatever threshold you have set. You’ll undoubtedly get used to seeing these messages all the time. So when a message arrives, purporting to be from Citibank (after all, it has their originating number so it appears on your phone display as “Citibank”) and asking you call a number to check on a transaction, you’ll call and give your account number, mother’s maiden name and whatever else, thinking you are talking to Citibank but actually talking to some fraudsters. In other words, because people will believe SMS to be secure, even though it isn’t, they will believe the identity of the caller, which could be storing up some big problems.

We need end-to-end security (like the mobile digital signature service that Turkcell have launched) and then we can transform the identity space by using the mobile phone instead of custom devices, passwords or nothing at all to secure our online selves.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post SOS SMS appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/10/sos-sms/feed/ 0