Tomorrow's Transactions » reputation http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 Identity might work better bottom up http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/ http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/#comments Mon, 09 Jun 2014 11:06:29 +0000 http://tomorrowstransactions.com/?p=4480 One way to help people obtain financial capital is by helping them to build up social capital. Forum friend Kosta Peric from the Bill and Melinda Gates Foundation (BMGF) Financial Services for the Poor programme recently picked out four technologies as being of particular interest right now. He pointed us to: bitcoin-inspired distributed systems, open […]

The post Identity might work better bottom up appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

One way to help people obtain financial capital is by helping them to build up social capital.

Forum friend Kosta Peric from the Bill and Melinda Gates Foundation (BMGF) Financial Services for the Poor programme recently picked out four technologies as being of particular interest right now. He pointed us to:

  • bitcoin-inspired distributed systems,
  • open APIs (application programming interface) as a new way to consume business services on the internet,
  • crowd-sourced identity schemes, and
  • open source hardware and applications.

[From Four Technologies That Will Revolutionize Financial Services | copernicc]

I’m sure we’d all agree with his views on blockchain technologies and the “Amazonisation” of financial services organisation through APIs (I don’t know enough about open-sourced hardware to comment) but I think his point about crowd-sourced identity is especially interesting, as it points to a shift in the way that identities are created, managed and used. And, since I’m rather obsessed with identity right now (as our clients should be and, in some cases, are too) I thought I’d take the time to explain why I agree with him.

First, look at what the conventional, top-down notion of identity means. It means someone (the government, generally speaking) must find some way to assign an identity to everyone who needs one, record who those identities have been assigned to, and check that when the identities are presented they are genuine.

It is almost certain that the government is having difficulties establishing who is a genuine citizen purely on the basis of identification papers produced by the existing system. Some of the illegal immigrants caught in the current security swoop have Kenyan ID cards and passports but their details are not in the national database.

It has been claimed that immigration and provincial administration officials at all levels have enriched themselves by selling these sensitive documents while compromising national security.

[From KENYA: Kenyans to apply for digital identity cards, says Ruto]

There are problems with this top down approach. Apart from being expensive, it is also vulnerable. One a false identity has been entered into the system, it is no longer false (if you see what I mean). As a consequence, obtaining such an identity becomes an essential precursor to crime as well as legitimate use and therefore the identities are obtained by all sorts of people who are not supposed to have them and the system is subverted. Managing and protecting the database at the heart of this scheme is complicated and difficult. In a great many emerging markets, in particular, the national identity scheme is soon degraded: sometimes because of corruption, sometimes because of carelessness, sometimes because of errors in the concept and design. This is precisely what has happened with the Aadhar scheme in India.

What was supposed to be a unique identification number providing identification and access to a host of government benefits and services, ‘Aadhaar’ has almost unvaryingly been extended to anybody residing within Indian territories. Almost anyone, be it Indian or an illegal immigrant can get an Aadhaar Card made without any proof of identity. More importantly, they get a numbered identity.

[From Sting reveals Aadhaar documents forged for Nepal, Bangladesh citizens - IBNLive]

So how does the alternative, crowdsourced version of identity take us forward? Well, if national identity schemes don’t provide “real” security then why bother with them? Save the money. At a basic level crowdsourced identity means asking everyone who you are rather asking anyone (e.g., the government) who you are. Whereas we are used to the idea of identity as something that is granted to us by a third party, such as the government or a bank, and the idea of an identity based on reputation that grows up through our networks and long-term relationships seems rather different.

Compare the two kinds of identity and their functionality in practice. Crowdsourced identity may seem a poor substitute for national identity at first glance, but it seems to me that Kosta is onto something here for two specific reasons that I have touched on before. The first is that this kind of reputational identity is actually better than conventional national identity because it is much harder to forge or counterfeit. A good friend of mine told me a story about an industry event he attended recently where he ran into a chap late at night when he was going back to his hotel. The guy was in the hotel lobby and recognised my friend as he had been a speaker at the event. The man explained that he had been tricked by a woman in a bar into following her back to hotel room where he had been drugged and robbed. He had no money and was too embarrassed to call his wife and asked if my friend might loan him some money so that he could get home and would report his wallet lost on the train or something. My friend had never met the man before but asked him his name and who he worked for and then looked him up on LinkedIn. Having established that not only did the fellow have a full LinkedIn profile but was actually connected to my friend via several different people, my friend loaned him the money which was, of course, gratefully returned a couple of days later. Now imagine that the unfortunate chap had instead presented my friend with his Portuguese fishing licence: how would my friend evaluate that and assess the strangers plausibility from that official document?

The second reason is that these crowdsourced identities may well be far cheaper to establish and this is especially true, and especially valuable, in the developing world where official infrastructure may be unreliable at best and non-existent at worst. Here the particular combination of mobile phones and social networks is especially powerful, because mobile phones tend to deliver not only unique identity but transactional history to go with it and this can be linked through social networking in powerful ways. You might have listened to the podcast I recorded earlier this year with Shivani Siroya and and heard a very good example of this where the transactional histories from mobile payment accounts are slurped up by organisations who provide alternatives to conventional kind of credit reference agencies that we are used to in the developed world.

Shivani Siroya is currently the CEO and Founder of InVenture. InVenture facilitates financial access by providing simple mobile accounting and credit scoring tools for offline and unbanked individuals, the subject of this podcast.

[From Media - Consult Hyperion]

Taken together, I think these provide compelling support to Kosta’s intuition and it strikes a that, to use Jaron Lanier’s term in “Who owns the future?”, the “economic avatars” that arise at the intersection of the mobile phone and the social network may well prove to be more useful to a great majority of the world’s population than their “official” identities even if they have them and indispensable to them if they do not. And, by the way, if you regard the whole idea of giving people credit on the basis of social capital as ridiculous and fanciful, I guess you didn’t see this:

[Bogota] where Lenddo introduced a “social network” Visa card to 100,000 of its customers yesterday afternoon. By 4:00 p.m. today in New York, where the online lender for developing countries is based, more than 1,000 Colombians had applied for the card. Lenddo CEO and co-founder Jeff Stewart calls it the first time ever, anywhere, that approval for a credit card is based on applicants’ reputations on Facebook, Google, LinkedIn, and Twitter.

[From This Emerging Markets Credit Card Is Backed by Facebook Friends » Techonomy]

Identity is the new money, as they say. Well, as I say.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Identity might work better bottom up appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/feed/ 3
Who thinks pseudonymity isn’t important? http://tomorrowstransactions.com/2011/04/who-thinks-pseudonymity-isnt-important/ http://tomorrowstransactions.com/2011/04/who-thinks-pseudonymity-isnt-important/#comments Tue, 12 Apr 2011 03:13:41 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/04/who-thinks-pseudonymity-isnt-important/ [Dave Birch] Some forms of business are demanding identifiers, but identifiers going forward aren't the same as they were in the past.

The post Who thinks pseudonymity isn’t important? appeared first on Tomorrow's Transactions.

]]>
OK, at the extreme risk of boring everyone to tears, let’s ask the same old question again: should you be allowed to do things on the Internet without giving away your “real” identity? Remember this was something that was discussed here a little while back, using the simple case of newspaper comments as an example. Someone has come up with an interesting way of solving for two problems simultaneously: paying for news online and making people responsible for their comments…

However, he recently went back and was surprised that, in order to comment you need to hand over your credit card, and the paper will charge you $0.99. Obviously, this is more to prove that you are who you say you are, but it does seem a bit distorted when the newspaper wants to charge people just to comment. Also, once charged, your name and hometown are automatically associated with your comments.

[From Newspaper Wants You To Pay To Comment | Techdirt]

Interesting. I think the idea of paying to comment is very interesting. I might be tempted to do that in some cases. But paying to give up your real name? I’m not so sure. I might well want to comment on something without that kind of disclosure. Back to “real names” again. The discussion goes on and on.

Why does a comment with a real name have so much more value?

[From The Real “Authenticity Killer” (and an aside about how bad the Yahoo brand has gotten) — Scobleizer]

This isn’t always true. A nurse at a hospital, forced to comment with her real name, is highly unlikely to post anything critical of a doctor. There’s a difference between an authenticated persona (so that the web site can be sure she really is a nurse at the hospital) that may be based on a pseduonym (or even a cryptographically strong unconditionally unlinkable anonym) and an authenticated identity. There may be many reasons why the latter is undesirable.

Mexico announced a plan Monday to reward people who report suspected money laundering, under a program that will allow them to get up to one-quarter of any illicit funds or property seized. Under the new plan, people can file reports in person, by telephone or by e-mail. The exact percentage of individual rewards will be determined case by case by a special committee.

[From Mexico sets rewards for reporting money laundering | ajc.com]

Would you e-mail in a tip about a suspected money launderer and expect to pick up the reward? It seems to me that this is a good example of system that demands real names for integrity but real names mean it can never work. (Although, and it’s outside the scope of this piece, it is entirely cryptographically possible to enable the payment of rewards to anonymous people).

Public servants, law enforcement and banking system employees will not be eligible for the rewards, in part because it is already their duty to report suspicious transactions.

[From Mexico sets rewards for reporting money laundering | ajc.com]

Good luck to anyone who decides to report in person, or by telephone. SIM registration is mandatory in Mexico, which means that the money launderers will find you before the police do — don’t forget, they have more money than the police do. Come to that, they have more money than anyone does.

More shocking, and more important, the bank was sanctioned for failing to apply the proper anti-laundering strictures to the transfer of $378.4bn – a sum equivalent to one-third of Mexico’s gross national product – into dollar accounts from so-called casas de cambio (CDCs) in Mexico, currency exchange houses with which the bank did business.

[From How a big US bank laundered billions from Mexico's murderous drug gangs | World news | The Observer]

Given the stringent anti-money laundering (AML) regulations in place around the globe — which meant it took me 15 minutes to put a few quid on my Travelex prepaid card at Heathrow, something I will never do again — I’m surprised that this could have happened, but there you go. Perhaps instead of hassling people trying to load low-value prepaid payment accounts, the authorities could focus on the counterparties in larger electronic transfers. Hence the discussions about Legal Entity Identifiers (LEIs) that have been going on recently. Many interbank payment messages have account identifiers only — you could send money to my account with the name Carlos Tevez and it would still get to me because it’s only the account stuff that matters — and the some law enforcement agencies want to stop this and have banks validate the names as well (it will help to track funds to and from suspects I guess).

LEI will be assigned at the over all corporate entity level and also at subsidiary levels. Its usage will be standardized Internationally. My immediate thought was, never mind systemic risk, this is the perfect means to route B2B transactions across a myriad of financial systems and payment schemes worldwide!

[From Reflections on NACHA Payments 2011 — Payments Views from Glenbrook Partners]

I’m sure I’d heard somewhere before, possibly at IPS 2010, that the plan was to use the SWIFT business identifier codes (BICs), but apparently that’s no longer the case.

Vandenreydt said SWIFT is changing its tune due to a recent meeting of the International Standardization Organization’s Technical Committee 68, where SWIFT has a seat. At the meeting, participants concluded that developing a new code would help avoid ambiguities that might be involved if existing codes are used. “[The committee] wants a pure number without country or other information,” Vandenreydt added. The BIC is made up of eight to 11 alphanumeric characters with four letters for the bank, two letters for the country, two digits for the location, and three digits for the specific branch.

The utility is still working with ISO on what the identifier would look like. Vandenreydt said that process could take up to three months, though he expects a decision to be made sooner. He noted the proposal also depends on other details about the initiative that haven’t been specified by OFR, such as how long the registration authority would have to ramp up the system, whether IDs will be assigned or requested, and how many codes are expected.

[From SWIFT Retools Legal Entity Identifier Proposal]

So here’s a positive suggestion. Forget about the 1960s notion of an identifier as a unique alphanumeric code and instead make the identifier a pseudonym attested by a bank. So we become consult.hyperion!barclays.co.uk or something similar. It doesn’t matter whether the sender, or anyone else, knows who Consult Hyperon is, because the identifier tells them that Barclays does. And for 99% of real-world transactions, that’s enough. What’s important is that we are always consult.hyperion!barclays.co.uk in all relevant linked transactions. Then, if consult.hyperion!barclays.co.uk is found to be sending money to Osama bin Laden on a regular basis, the appropriate law enforcement agencies can provide Barclays with a warrant and Barclays will disclose. For general commerce, the persistence is the critical foundation. The always-accurate Eve Maler pointed this out a while back:

The neat thing is, we do this all the time already. When you meet someone face-to-face and they say their Skype handle is KoolDood, and later a KoolDood asks to connect with you on Skype and describes the circumstances of your meeting, you have a reasonable expectation it’s the right guy ever after. And it’s precisely the way persistent pseudonyms work in federated identity: as I’ve pointed out before, a relying-party website might not know you’re a dog, but it usually needs to know you’re the same dog as last time.

[From Tofu, online trust, and spiritual wisdom | Pushing String]

Quite. But there’s another point. You don’t need to be a “real” persistent identity to have a reputation, as should be obvious. A useful reminder of this came at the end of 2010, when an anonymous critic was named the Village Voice’s “Music Critic of the Year”.

Twitter spokesperson Matt Graves called it a “milestone”; whether he’s serious or not, (“dead serious,” he later said) @discographies certainly carries a certain seriousness throughout today’s interview in the Village Voice. “Twitter,” the account holder says, “may be the first mass communications system that also functions as a meritocracy: it actively promotes good ideas and good content, regardless of where they come from.”

[From Anonymous Twitter Account Named Music Critic of Year by Village Voice]

I’m not sure that meritocracy is the right word, but I think the sentiment is accurate: you have to earn reputation to attach to your identifier, and once it’s been earned it’s hard to replicate (unlike intellectual property). So I might want to send money to @discographies without knowing or caring whether @discographies is a roomful of students or an internationally-known music critic. (And, over on Digital Money, I will point out that I want to send money to @dgwbirch — which is an entirely unique Twitter identifier — by MasterCard, PayPal, WebMoney, M-PESA or anything else, but that’s another point entirely.) Why can’t @discographies be mutated into discographics!wellsfargo.com or whatever?

It’s an entirely plausible model: banks managing reputation, because it’s more important than money. The presence of banks legitimises the market, so knowing that a bank has carried out some KYC on @discographies means that other players can treat the reputation attached to it seriously without being concerned about the “real” identity.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Who thinks pseudonymity isn’t important? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/04/who-thinks-pseudonymity-isnt-important/feed/ 2