Identity in Vegas

Greyscale backing image

Identity, authentication and authorisation are amongst the hottest of hot topics in our world right now. Even if we put Apple and it’s new face recognition technology to one side, there’s no shortage of excitement at the intersection of biometrics and electronic transactions. Remember this from earlier in the year?

A UK supermarket has become the first in the world to let shoppers pay for groceries using just the veins in their fingertips.

From British supermarket offers ‘finger vein’ payment in worldwide first

As I wrote at the time, this came only a few weeks after people forwarded me a link from to Time Out, calling attention to a new payment mechanism using a new biometric identification technology to effect retail payments in a new way. The system, called Fingopay, uses a scanner at POS to recognise customers in pubs and bars by the pattern of veins in their finger and then charges a linked payment account. I did remark on the overuse of “new”, as the first time that Consult Hyperion blogged about this technology was more than a decade ago,  talking about mass market uses of biometrics and looking in the particular case study of Japanese banking, and it wasn’t new then! The technology has reappeared as a “new” solution to these same problems a great many times since then. It seems like every couple of years or so some stories about this new technology and new way to pay reappear. For example…

The BBC were kind enough to invite me on to their lunchtime “You and Yours” magazine programme to discuss this innovation. I think they were a tiny bit surprised, to be honest, when I told them that the technology was eight years old! I also told them, in the spirit of openness and integrity that is associated with the good name of Consult Hyperion throughout the civilised world, that we had been retained by Hitachi some years ago to carry out a study on the security of this product and its suitability for certain financial services applications.

From We’ll be giving Barclays the finger next year | Consult Hyperion

The truth is that the idea of using fingers instead of cards goes back a long way (I can remember Piggly Wiggly exploring it in 2004) and reappears with regularity. So what’s different this time? Well, for one thing, we now have open banking. With strong customer authentication (SCA), risk-based authentication at POS and standard APIs for third-party access to accounts, retailers and other will soon be able to process payments themselves by obtaining payment institution (PI) licences and obtaining consumer consent for access to their bank accounts. Thus, putting your finger on a reader in store and having the retailer instruct an immediate instant payment transfer from your account to the retailer account looks like a more promising model this time around.

It’s the combination of technology (convenient biometric authentication), business (non-bank third party services) and regulation (open access) that means that the payments world is going to see more change in this space in the next year than in the previous ten. Almost every payment conference in that decade has highlighted the “identity problem” yet no-one was going anything about it. Now we have mass market solutions just around the corner.

Anyway, all of this is a roundabout way of saying how excited I am to be chairing the Money2020 workshop “Identity is Fundamental” in Las Vegas next week. We’re going to be talking about the latest trends in identification technology, authentication in the mass market and much more. And we have a detailed case study from Canada, as we have Toronto Dominion and SecureKey talking about the Canadian banks’ ambitious project to fix the identity problem with, amongst other things, the blockchain. You’d be mad to miss it, so look forward to seeing you in the Titian Room on Level 2 of the Venetian next Wednesday at 8.30am. Oh, and if you want to say hi to me or any of the Consult Hyperion team in Las Vegas next week, just email, tweet or message me on LinkedIn.

From “Top of Wallet” to “Front of Phone”

Greyscale backing image

Over the last few weeks, I have been working with the team inside Consult Hyperion trying to understand the potential impact of the European Union’s PSD2 regulation on our clients’ business. One thing is for certain: it has generated a large number of not-quite-three letter acronyms that will ensure high scores in any game of Acronym Bingo running during a presentation on the subject.

It is clear that the Account Service Payment Service Provider’s (ASPSP or bank to you and me) mobile application will play an important role in any PSD2 compliant transaction. Every time I want to make a bank to bank payment to a new payee, a message will appear in my mobile banking application asking me to verify the transaction and authenticate myself. Will this be the reason I need to keep the mobile banking application on my phone?

Personally, I sit down once a month in front of a computer to do my expenses and pay my bills. I have sufficient standing orders to maximise the return on my Santander 123 account. The rest are settled using Faster Payments, when there are sufficient funds in my account. Being a payment geek, over the years I have loaded several banking applications and PingIt onto my phone. None of these survived the transfer to my next phone as I was not using them. The alternative (my PC and contactless Amex card) are more convenient or deliver the customer experience I need. But perhaps that is changing.

At Consult Hyperion’s excellent Tomorrows Transactions Forum in London earlier this year, Greg Wolfond, CEO of SecureKey, outlined the customer experience to be delivered by the blockchain-based digital identity and attribute sharing service they are building in Canada, with the support of local banks. At the centre of this service was a push notification from the bank, via their mobile banking application, that a third party wanted confirmation of my age or address and a request for permission for the bank to share those details with the third party. To me the bank is the logical place to keep valuable personal information. Most have been doing it for over 100 years usually in the form of paper documents – birth, marriage certificates and Land Registry Property Deeds. However, in a connected world third parties need to be able to access this information when I give them permission. This process must be instantaneous, as I am likely to be on the third party’s website or in their store signing up for a service when the request comes through. I will be in a similar place when I want to make a PSD2 compliant payment.

Earlier this summer, I sold the last of my larger toys, a Laser 1 dinghy. Kids have left home, wife prefers to ramble with the dog, sailing club just too far away, water too cold …. The list of reasons why I should keep it was getting too long.

I posted the boat on Apollo Duck, (think eBay for the sailing community) assuming people would come to view it, we would agree a price, they would give me a cheque, I would bank it and they come back a week later to pick up the boat, when the funds were in my account. Everything was going to plan, until it came to payment. Rather than pull out a pad of paper, he opened his Barclays’ mobile banking application, asked for my bank details and transferred the funds using Faster Payments. Five minutes later the funds were in my account and we were packing the boat up for him to take away. The whole process, from viewing to take away was reduced from 7 days to just over 90 minutes. We did not move from my front lawn, except to access my PC to check that the funds had gone into my account.

This appears to have been the vision of those very clever people in the European Union when they drew up the PSD2 regulations. However, is the mobile banking application the right channel for such services?

In the UK smartphone penetration rates are around 81% of all mobile phone users. However, this figure varies according to the subscribers age, from 90% of subscribers aged between 16 and 24 to 18% of those over 64 . The older generation are likely to have more savings spread across multiple products from multiple providers. If they prefer not to load the mobile banking application onto their phone are there alternative solutions which they can use to authenticate themselves to multiple ASPSP?

Barclays UK does a very good job verifying me using my payment card and their PinSentry device or mobile application across all the channels that I access their services. I can also use the PinSentry device with cards from other banks which support the CAP User Interface Specification, but don’t tell Barclays. There are other solutions from organisations such as FiTeq which remove the need for the separate CAP reader and the payment schemes who are promoting the use of their 3D Secure service for use with other payment solutions.

One of the drivers behind PSD2 was to drive innovation and competition. Is SCA the first place we will see this?

AMLD4.1, AMLD5 or 5AMLD?

Greyscale backing image

I recently came across a statistic that surprised me.

Approximately 50% of new bank accounts are opened by customers that have recently arrived in the UK to work or study.

http://www.openidentityexchange.org/wp-content/uploads/2016/10/Digital-Identity-Across-Borders-FINAL-Feb2016-2.pdf

I had wrongly assumed that the majority of new bank accounts openings in the UK would be from students just about to go off to University, like my son, and that migration whilst high (as the media keeps telling us) would still be a minority. But based on some back-of-the-envelope calculations it appears that the 50% number is about right.

As the OIX report above points out, these new arrivals in the UK are very difficult to perform KYC (“Know Your Customer”) on due to the lack of data. They have no history in the UK. This is exactly where eIDAS should be able to step in. For example, a person arriving from France should be able to use their French government-issued eID as one piece of evidence to help meet KYC requirements. The proposed new AML legislation – the amendment to the fourth AML directive – which I have seen referred to as AMLD4.1, AMLD5 and 5AMLD, explicits call out to eIDAS as a potential solution.

There are however some issues with this:

Firstly, to become part of the eIDAS scheme, governments have to “notify” their eIDs into the scheme. To date only Germany has done so.

Secondly, eIDAS provides a switching infrastructure that makes all eIDs interoperable but initially this will only available to the public sector. If a private sector organisation, such as a bank, wishes to leverage an eID it will need to find another way to access or read it.

Thirdly, the mobile channel is becoming increasingly important with banks needing to be able to onboard customers directly in that channel, as well as performing identification and verification of existing customers when provisioning a mobile app. Several of the existing eIDs are smart-card based. These will only be readable by phones if the cards themselves are contactless (which many of them are). They will not however be readable on iPhones, even with the limited opening up of the NFC interface expected in iOS11.

There is clearly therefore a need for some alternative mobile based technology. Fortunately such technology exists in the form of mobile document and selfie capture and verification. One of the vendors in this space, Mitek, kindly commissioned Consult Hyperion to write a paper on this very topic which I had the privilege of presenting at Money2020 last week. You can download the paper here:

At last, NDEF

Greyscale backing image

A decade ago I remember writing that one of the problems with QR codes is that there is no security. Some years later I wrote an article pointing out that NFC ought to be safer than QR codes because NFC included a standard for digitally-signing tags (although I did also note that no-one used it) whereas anyone could easily create bogus QR codes.

Well, I might not go so far as to call [QR codes] evil, but they certainly have the potential to enable person or persons unknown to act with evil intent.

From A quick response to the problem | Consult Hyperion

I suggested, in connection with a couple of projects we were working on at the time, that the mobile operators do something about this by creating a digital signature standard for QR codes so that phones could be set by default to ignore unsigned codes. None of this happened, as I’m sure you are aware and QR codes became popular precisely because any app could read any code anywhere.

The security problem never went away though. I notice in the South China Morning Post that in March 2017 some 90m Yuan was stolen via QR code scams in Guangdong alone (a suspect in the case replaced merchants’ legitimate bar codes with fake ones that embedded a virus to steal personal information) and that in China as a whole, a quarter of viruses and trojans come in via QR. Despite the incredible success of QR there, we need to do better.

Even the man who invented QR codes says that they are an interim technology.

From Never mind the last mile, what about the last millimetre? | Consult Hyperion

Now, also back in the day, I had originally assumed that Apple would add NFC to the iPhone. I was wrong about this for years, so eventually I assumed that they were going to bypass the technology and go to Bluetooth. Yet what I said at the time still holds: NFC is undeniably convenient.

NFC is a convenience technology, and Apple loves convenience

From Quick response | Consult Hyperion

I wasn’t just guessing about this, I was drawing on Consult Hyperion’s early experiences with NFC (remember the Nokia 6131?) of tag reading and writing, including not only the usual payments and ticketing stuff but also such fun applications as getting information about clothes at London Fashion Week. I also noted surveys at the time that showed that NFC generated better results for merchants, but only once consumers could get it working. As my good friend Osama Bedier, then head of Google Wallet, pointed out, this is was some barrier because of the amount of “futz” it took to get NFC working.

But there was another reason that I was so interested in NFC as QR alternative back in this days.  To go back to the security point, I was interested in thestandard for adding digital signatures to NDEFs (the “NFC Signature RTD Technical Specification”) to build a safe tag infrastructure. After hawking this around a few different projects, to general disinterest, I figured that the telcos weren’t interested in using it to deliver secure infrastructure, so I said…

“Someone else will build this business (Apple? They seem to be getting all sorts of NFC-related patents at the moment) and then the operators will once again complain about being pipes. Is Tom Noyes right to say that “…Apple and Google will be further ahead in coordinating value in new networks”

You don’t know ‘jack | Consult Hyperion

Well, well. Tom was right as usual, even if it took a few years for the hand to play out. At WWDC, Apple announced that IOS11 will indeed include the ability to read NDEF data from tags.

“Using Core NFC, you can read Near Field Communication (NFC) tags of types 1 through 5 that contain data in the NFC Data Exchange Format (NDEF).”

via Apple adds support for NFC tags to iPhone 7 and Apple Watch • NFC World

So now, more than a decade after our first NFC experiments, both IOS and Android can read standard tags and action them. I want to make a couple of quick points about this before I head off down to our Hyperlab and see what our developers make of the new toolkit.

First of all, this technology will inevitable be used for triggering in-app payments that work in a very convenient way for consumers. Instead of having to open your Tesco Payqwiq app and then scan a code from the POS, the POS will function as a tag (and remember it can potentially rewrite a dynamic tag on the fly): you can just tap the phone on the POS and the operating system will automatically open the Payqwiq app and route the data to it.

Secondly, since tags are inexpensive, they will be used for a variety of different applications. Tickets for pop concerts, information about products, name badges, all sorts of things that can be read by a phone rather than by a specialist reader, Therefore I expect new standards for NDEF content to spring up. One of my favourite apps, back in the day, was a phone number tag that men could put in their back pocket at a nightclub: admirers could wave their phone in an appropriate area to get the number and send a text message. Here we are trying experiments with different types of clothing (which turned out to have very different NFC-friendly characteristics!) a decade ago.

Lastly, note that NFC tags can be read through packaging. Unlike QR codes that need to be printed on the outside of a box, tags can be inside. Where would this matter? Well, take a current UK example. Cigarettes now have to be in plain packaging. Tobacco companies don’t like this – for obvious brand reasons – but they do have a point: plain packaging makes like easier for counterfeiters. So suppose packs had a cheap tag inside: then your phone could tell you whether you’ve got real Marlboro or a knock off. You download the Marlboro app, then from then on when you tap a pack if the app doesn’t pop up with a big green tick you know you’ve been done. I’ve written about this sort of thing before ( for example, wine and whiskey) so it’s hardly a new idea.

Note, however, that IOS11 also includes ARKit to add augmented reality. So, when you look at your pack of plain cigarettes through your app (after you’ve tapped, so the phone reads the tag and knows that they are real Marlboro) you don’t see plain packaging any more you see… well whatever.

NFC Example

All in all, Apple’s announcement – whether the culmination of a clever plan or a response to Android market share – is a big deal. I found a whole bunch of blank NFC tags in my desk drawer so I’m off to start programming them now.

Why can’t digital identity be easy, like payments?

Greyscale backing image

 

I have often seen payments (especially the card networks) used as an analogy for digital identity. In fact, I brought up the analogy myself at the fun OIX meeting in Amsterdam last Thursday. Certainly when you look at something like GOV.UK Verify there are some striking comparisons:

  • A central scheme with a brand, rule book, governance body and switching infrastructure (i.e. Verify itself),
  • Issuers (i.e. the private sector identity providers), and
  • Merchant acquirers (well merchants anyway, in the form of government relying parties).

We have to keep reminding ourselves that these card networks did not appear overnight. What we have today is a result of 60 or more years of evolution. Admittedly the pace of change has increased significantly but we need to recognise it often takes time to build scale and gain adoption. There are special cases of course. PayPal, for example, grew out of a significant pain point within eBay – which gave it immediate scale.

There is however one key difference between payments and identity. You cannot sell stuff online without a means to receive payment and normally that means integrating with a payments scheme that works for your customers. You can however sell stuff without leveraging an external identity scheme – you just give the user an ID and password specific to the service. This is however bad news for users – resulting in the fragmented personal data and password mess we find ourselves in today. There needs to be an incentive for merchants to do something different to this. Perhaps merchants need a big stick? Like GDPR for example. Merchants are going to have to be a lot more careful with personally identifiable information in the future. One thing they could do is use an identity provider to hold that data and in the process reduce their risk.

Individuals also need to realise that their personal data is valuable, just like their money. That is going to require some education because so far they’ve been taught to share data without considering the consequences.

In the UK, arguably the most significant digital identity initiative over the past 5 years has been the GOV.UK Verify programme. They are at the stage where they need to grow. The scheme is up and running and so they are now busily signing up citizens and services. It is a critical point in its development. We are very pleased that David Rennie who leads industry engagement on the programme will be taking time out of his busy schedule to join us at Tomorrow’s Transactions. Come along and find out how it is going.

You can also get added to our mailing list here.

HonorBuddy for business meetings is round the corner

Greyscale backing image

There’s a lot of pressure on me to be in two places at once these days, so I was happy to see Google file and trivial and obvious “patent” on how to help busy executives achieve this using new (well, pretty old, actually) technology by gluing an LCD display and a wireless web cam to a drone.

Google is hoping to patent a small videoconferencing “telepresence” drone for collaborating with colleagues from remote locations, according to an application that was made public today. The drone is designed to fly indoors and move from room to room.

From Pocket: Working from home? Google wants to create a drone to go to meetings for you.

Not only is this more trivial than it appears at first glance, it already exists in essence. Here, for example, is photographic proof of me annoying Tony Moretta, the CEO of Digital Jersey, in precisely this fashion by sending a meeting bot (an iPad glued to a Segway, basically) to talk to him while I sat comfortably with my iPhone in a distant location (well, the room next door to be honest, but you get the point).

RoboDave

As Tony himself pointed out, this implementation suffers from the Dalek Deficiency, in that he can escape my dreary lecture about the difference between a digital currency and a cryptocurrency by heading downstairs to the gents. Fair point. But with the google-powered flying Dave-o-Drone there will be no escape (unless they’ve fixed the door on the gents, of course).

This doesn’t actually solve my problem because although I can attend remote events in this manner, and thus cut down on travel time, I can still only attend one at a time. Surely if Google were being truly creative they would connect their Go-master AI into the drone so that I could send a bot to the meeting instead of going in person? A great many of the meetings I attend would be adequately served by a bot programmed to deliver a few key phrases at the right juncture. For example:

  • “What’s in the blocks?”; 

  • “That’s not identificaton, that’s authentication”; and

  • “There’s no transaction type for doing that on the network”. 

That’s should take care of most eventualities. It’s hard enough to tell whether people are actually listening on a conference call or not so how we’ll be able to tell whether it’s a bot or a person sitting in by drone will be a whole new ball game. I can forsee a time when we’re going to need a new version of the Turing test specifically for management meetings otherwise one day I will undoubtedly end up like this guy who is playing World of Warcraft when he realises that he is the only actual human playing the game and all of the other players are bots. Pay attention because one day this will happen in a meeting about EMV Next Generation or something.

Warning: NSFW.

My only goal left in life is to become the Leroy Jenkins of Consultants. And, I have to say, whoever comes up with a working HonorBuddy variant for business meetings will become rich beyond the dreams of avarice. I’ve said it before, and I’ll say it again, IS_A_PERSON will be the most valuable credential off all in the not too distant future.

007.com

Greyscale backing image

It’s really hard to be James Bond these days. Apart from health & safety restrictions on the use of poison umbrellas and the legal restrictions on the murder of henchmen (even foreign ones), and all the paperwork around the expenses and what is VATable and what isn’t, you’ll be rumbled in an instant by your Facebook account. Because you don’t have one.

It is not simply a question of keeping details offline, either, but the opposite: individuals or identities without deep, broad online presences are precisely those likely to raise suspicion. “The challenge of having a credible digital footprint is significant,” Mr Inkster said. Fake Twitter or Facebook accounts alone do not make the grade.

From The spy who liked me: Britain’s changing secret service – FT.com

If I come across someone in a work context, and they are not on LinkedIn, then I assume that they are either in the witness protection programme or have been in prison. Unfair, possibly, but that’s where we are. And of course if you are not yourself on Facebook, then it’s only a matter of time before some schmuk snaps you and you’re in the system whether you like it or not. You could be out and about with an important business contact having a very important business discussion about important business issues, for example, but because of the camera angle and the perspective a snapshot of this event might be entirely misconstrued.

Blue Hat Red Hat

 

And once you’re in the system, you are no longer anonymous whatever you might think about being off the grid. Wherever you are and whatever you are doing, you’re in someone’s SnapChat or Instagram feed.

Give Facebook two pictures, and it can tell you with 97 percent accuracy whether they’re the same person, roughly the same accuracy as a human being in the same spot.

[From Why Facebook is beating the FBI at facial recognition | The Verge]

In the good old days, the good old spies had to stake you out and track you down and stalk you and then murder you in a dastardly and complex fashion,  often involving laser beams. Now they just run the face recognition software until you pop up somewhere and then… it’s radioactive sushi time. Until my plan for Facebook-blue burkhas for all is accepted by the mainstream I’m afraid I can see no way round this. The Bond villain of the future isn’t Mr. Big on an island with a pet cheetah and anti-aircraft missiles but a kid in his underwear eating pizza and running face matching algorithms.

By the way, I noticed in the newspapers that while it may be increasingly difficult for spies to convince people that they are not spies, it is apparently much easier for people to convince other people that they are spies.

Mark Acklom convinced her he was a spy and defrauded her of £850,000 

From Gloucestershire woman fell for ‘charismatic’ fraudster who claimed he worked for MI6 | Daily Mail Online

I don’t want to pick on this poor woman, and I know only too well how easily women can fall under the spell of handsome Englishmen, but honestly had she never heard of LinkedIn? If a match.com counterparty was trying to convince me that they are from MI6, I would fully expect to open up their LinkedIn profile and see a convincing employment narrative going back many years. And if they didn’t have a Facebook profile, then I’d naturally assume them to be a fraudster not an undercover agent.

Spies are an interesting use case when you start to think about the series business of population-sale identity they present a problem. If the purpose of a national identity system is to uniquely identity someone, then you don’t want it to ping back “James Bond” when 007 has to use the biometric identification system at the casino entrance. Which means that in the general case, people must be able to have multiple identities. When Bond presents an ID with the alias Dave Birch on it, then the casino system should ping the government (or whoever) to ask “is this Dave Birch” and get back a “yes”, rather than ping them with “who is this” and get back “James Bond”. As I wrote many years ago,

As was well-put on Ideal Government recently, multiple identities are part of the solution, not part of the problem of information age identity.

From Age vs. identities | Consult Hyperion

Population-scale solutions should start with multiple identities, not add them as a special case. The very specific case where the pseudonym and the absonym coincide should be seen as nothing more than one of a spectrum of identity mappings.

Strong Consumer Authentication with Gloria Hunniford, Gold Membership and Gary Munro

Greyscale backing image

I was relaxing watching the marvellous BBC programme “Rip Off Britain” the other day. It was a live episode [online here] featuring the noted and venerable British television celebrity Gloria Hunniford. The subject of the programme was bank security and it featured Gloria herself investigating how she was ripped off by bank fraudsters. Basically, a woman who looked nothing like her used a fake driving licence to withdraw more than a hundred grand from her Santander account.

‘It was easier for four strangers to access my money than it is for me!’ Rip Off Britain’s Gloria Hunniford slams bank security after frauds stole £120,000 from her account 

From Rip Off Britain’s Gloria Hunniford slams bank security after frauds stole from her

The bank teller involved was initially suspected of being part of the fraud and was prosecuted but acquitted on the grounds that she hadn’t the slightest idea who Gloria Hunniford was. Fair enough. It would be like prosecuting me for being unable to pick Kim Kardashian out of a police line up.

It’s easy to make fun of bank security (as I have) but there is a real problem behind this story. A bank doesn’t want to annoy good customers but it has to have security in place to at least mildly inconvenience fraudsters if nothing more. And the bank security has to cope with all sorts of circumstances. What if you drop your smartphone down the toilet? I’ve done that. And here’s another good example.I once ran out of petrol in my car. So I called the AA (I’m a Gold Member of that, too) and

they told me that they couldn’t bring petrol because it’s against health and safety regulations, so they towed me to a garage. I filled up the car, wandered in to pay and… discovered I’d left my wallet at home. (Not the first time I’ve done this.). Having thought about it, and left the car keys with the clerk at the filling station, I phoned my bank. It turned out that there was a branch a few minutes walk away, so I set off to find it. On the phone, I answered some security questions, and when I got to the branch there was (if memory serves) £30 waiting for me. Hats off to Barclays.

From Taxis, Boris Johnson and another step closer to VC Day | Consult Hyperion

Now, I don’t remember what those security questions were, but I’m pretty sure that a determined fraudster would know the answers or know how to talk themselves round them. But I do want to live in a world where when I forget my wallet I can till get some cash out the bank!

One problem, in the Gloria Hunniford case, is that asking a customer to present a driving licence as proof of identity is the kind of “security theatre” that I was talking about in Sydney this week as a guest of the lovely people at Australia Post.

The bank clerk has no way to know whether the driving licence is real or not, so asking for it and looking at it is like taking part in a play about security where everyone is an actor who knows their lines but there is no actually security involved at any point. Surely this is one of the crucial differences between old identity and new identity, between dumb identity and smart identity, between analog identity and digital identity.

Had the bank digital identity interacted with the customer digital identity rather than the clerk interacting with the bogus Gloria, then there would have been mutual verification and real security. Imagine what the conversation at the counter could be…

Bogus Gloria Hunniford (BGH): “Hello, I’m Gloria Hunniford and I’d like to withdraw £150,000 from my account”.

Santander Bank Clerk of the Future (SCF): “Certainly Madam, let me check your Financial Services Passport.”

At this point, she pulls up the details of Gloria Hunniford’s account on her screen and the system sends a message encrypted using Gloria Hunnford’s public key. This is sent to the Santander app on Gloria Hunniford’s mobile phone.

BGH: “Sorry my phone was carried away be a seagull on the way to the bank so I don’t have my Financial Services Passport”.

SCF: “No problem Madam, we have a spare phone here.”

The bank clerk picks up the branches’ spare Samsung S7 and runs the Santander app. She puts in the Gloria Hunnford’s sort code and account number and when the app asks for verification, she holds it up and asks “Gloria” to log in using face verification (or voice or iris or whatever).

BGH: “Ah, unfortunately, I tripped over a paving stone yesterday and smashed my face into a Ford Focus. Due to my emergency plastic surgery, I’m afraid I will fail the face verification process”.

SCF: “That’s no problem Madam, we can re-enroll you. Please come back with your fingerprints, your voice and a barely legible photocopy of a gas bill from six months ago”.

Now, there is some actual security, because the real Gloria Hunniford will see a message pop up on her phone about authorising a withdrawal at the Santander branch and she will either hit the “no” button or the “no, and please connect me to the  whitehall1212.police.org.uk emergency fraud chatbot so that I can alert the plod to a crime in progress”.

Look, the banks in Europe have to implement Strong Consumer Authentication (SCA) anyway, so why not implement properly so that you can authenticate yourself the same way whether on the phone, in the branch, browsing the web or mucking about with your phone? I imagine this is the sort of thing that my colleague Gary Munro will be talking about on 9th November 2016 as he is one of the experts taking part in the techUK seminar on strong authentication in PSD2. You’d be mad to miss it.

“Knowing Me Knowing You, Ah–Ha !” – Strong Authentication in PSD2

From TechUK

The fact is that if we really want to replace security theatre with some actual security, we have the technology. 

 

Inclusion, identity and privacy

Greyscale backing image

Financial inclusion is necessarily built on a foundation of customer identity, but the rush to inclusion and the consequent focus on mass registration in many countries has placed at risk the citizens’ rights to privacy – even where these are recognised in law.  But the mere fact of being excluded should never mean that someones right to privacy is in any way diminished.

With support from Omidyar Network, Consult Hyperion has undertaken a global review of the privacy and data protection aspects of digital identity services, with particular reference to their relevance for financial inclusion. We have reviewed the various digital identity initiatives around the world from a privacy perspective. Building on this framework, we have developed a ‘roadmap’ for digital identity that ensures that privacy, and the needs of regulatory authorities, can be built into digital identity services, ensuring the drive towards financial inclusion can be at its most effective. We hope that this roadmap will be a useful contribution to the industry as it considers how best to deliver digital identity to those most in need.

The key elements of this roadmap are as follows.

Put the individual at the centre of privacy protection

This does not only mean giving individuals control over how their personal data is used; it needs to be reflected in the entire approach to the digital identity system. In order to avoid low levels of take-up and use, it is essential that the emphasis be placed on user needs, rather than vendor-driven use cases or so-called “gold standard” solutions.

Provide an effective legal environment

An effective legal environment must be in place that contains, and can enforce, legal remedies to prevent or punish abuses of personal data.  An effective legal environment will also increase confidence that any contractual measures put in place as part of the trust framework to ensure privacy can be enforced.

Design in privacy from the start

There is widespread recognition that privacy should be designed into any system from the start rather than bolted on as an afterthought.  Privacy–by–design requires a careful understanding of the expected goals of the identity system, an appreciation of the distinctive characteristics of the context of use and an awareness of the technological capabilities and privacy risks associated with proposed next generation digital identity systems.

Separate identification from authentication and authorisation

Many existing identity systems combine identification and authentication activities within the scope of the identity provider. Separating out identification from authentication allows for the relatively rapid roll out of basic digital identity credentials, perhaps issued to all but based on low assurance identity data. The quality of the digital identity can be enhanced over time, in part simply through a history of ownership and use or by incorporating additional data points.

Furthermore, if the basic digital identity credentials only show that the citizen is unique and identifiable and not include other data attributes by default, this will allow future developments to minimise disclosure of data. Today identity systems often include a default data set that is always shared, even when it is not necessary for the service being accessed.

Improve authentication then identification

In an ideal world, it would be desirable to move directly to high quality identification and high quality authentication.  In practice, however, the time and effort to improve the quality of these aspects of digital identity are different.  In general, improvements to authentication quality are likely to be quicker to achieve than improvements in identification quality.

Provide a viable commercial model that disincentivises abuse of personal data

Whilst the monolithic identity providers like Facebook and Google offer easy to use digital identity credentials, their business models could run counter to consumer privacy as key revenue streams come from sharing individual and aggregate customer data. Whilst it is possible to constrain such actions contractually and technologically, long term the commercial model must be designed so that incentives to protect privacy are aligned.

Consider who will pay for the identity system

If identity credentials are to become a key infrastructure for a society, then important questions of how they are to be paid for arise.  There are different models of charging for infrastructure provision that can be drawn upon, but choosing the right payment model can be problematic whether the identity provider is a government agency or a commercial body.

Address questions of liability

Service providers should not be held liable for actions based on properly authenticated identity claims. What then of the liability of the identity providers?  Here the complexity of the liability model grows as benefits and risks are shared unequally.  In extremis, the identity provider privatises the some of the benefits (e.g. payments for authentications) but socialises the risks (e.g. complete failure of trust in the identity system as a whole).

Review the role of compulsion

For countries introducing new identity credentials, questions of consent and compulsion become particularly significant from a market and rights perspective.  They may cause significant disruption to the roll out of system.  In such cases it is frequently stated that the new identity system is voluntary, not compulsory and that individuals can always choose not to have an identity credential. In this case, as the critical mass of credential holders develops, effective compulsion can arise. However, evidence from Europe suggests that the various electronic identity cards are used infrequently because most people have infrequent access to public services and those that do have more frequent access rarely need to formally identify themselves each time.

All of the underlying issues, and the elements of the proposed roadmap, are explored in detail in the report available here. It’s very detailed piece of work, so you might want to being with the Executive Summary that is available here. We are genuinely curious about your views and look forward to all feedback.

“Identity for Blockchain” vs “Blockchain for identity”. What’s in it for Airbnb?

Greyscale backing image

Recently I had the pleasure to moderate a panel on “Blockchain and Identity” at the KYC & Identity conference organised by ECN in London. It was a well-organised event with speakers and participants from major institutions such as the European Commission, Barclays, Open Identity Exchange (OIX) and such. The conference, excellently chaired by Jon Shamah (from EEMA, the European Association for e-Identity & Security), had an interactive and friendly format, very useful to facilitate discussion.

Sally on KYC-Identity conf

Our panel (with UBS and Zerado) was the only one dedicated specifically to Blockchain, but one could hear the word mentioned here and there: almost inevitably discussions of the problems and future of identity led to Blockchain. And this is not a surprise: Blockchain & Identity is a hot topic, which Consult Hyperion has been exploring for a while with our clients.

Let’s take two different approaches to thinking about importance of this topic: “Identity for Blockchain” and “Blockchain for Identity”.

First, “Identity for Blockchain”, assumes that if Blockchain platforms (developed for many different use cases) are to gain widespread adoption, we need to understand how the identity dimension for these systems would look like. It is quite obvious that existing ways to manage identity won’t work for “the new magic blockchain enabled world”. At the moment, dozens of major institutions are developing blockchain platforms (or more precisely, shared ledger technologies = SLT). Take R3CEV for example, a consortium of 40+ international banks such as Barclays and Goldman Sachs, that has recently announced “Corda” shared ledger protocol for financial use cases. Linux foundation, IBM, DAH and others work on the “Hyperledger” project – a multipurpose standardized blockchain software stack. Assuming these technologies gain adoption that is at least 10% as widespread as the industry’s attention to them today, there will be a need for a robust and reliable identity layer to manage KYC, AML, authentication and authorisation processes for shared ledger applications.

Second approach could be called “Blockchain for Identity” and it formulates a separate self-sustained class of use cases. It assumes that Blockchain technology can enable solutions to known identity problems and can solve them better than current models are able to do. This week, blogposts from my colleague Dave Birch (Director of Innovation at Consult Hyperion) have been focusing on this latter approach, which we will explore further here.

So what problems does a “blockchain for identity” solve?

I would argue that the one of two key problems at question is lack of interoperability of identity information across organisations and marketplaces, in each of the three domains: identification, authentication and authorisation (see the series of “Putting Identity on the Blockchain” from Dave this week). KYC-sharing use case falls under this umbrella, but KYC is just one bunch of the identity data that can be shared. Nathan Blecharczyk, a co-founder and CTO at Airbnb (who have recently hired a bunch of blockchain experts), talks about sharing user’s reputation:

“The question is whether there’s a way to export [a user’s reputation] and allow access elsewhere to help other sharing economy models really flourish.”

– Nathan Blecharczyk, a co-founder and CTO at Airbnb.

From http://qz.com/657246/airbnb-just-acquired-a-team-of-bitcoin-and-blockchain-experts/

Isolated identity systems create silos of ID information. Such disparate systems and fragmentation of ID markets limits the ways in which useful identity information can be generated, derived and enriched (not just shared). Therefore an associated problem is poor quality and lack of meaningful identity data. One example of rich identity data is (or at least should be) credit ratings. Another interesting example that has just been mentioned in another context is reputation:

Within the context of Airbnb, your reputation is everything, and I can see it being even more so in the future, whereby you might need a certain reputation in order to have access to certain types of homes”

– Nathan Blecharczyk, a co-founder and CTO at Airbnb.

From http://qz.com/657246/airbnb-just-acquired-a-team-of-bitcoin-and-blockchain-experts/

Why suggest that Blockchain can help with this? To answer this question, let’s look at one of the key characteristics of the Blockchain technology – the immutability (unchangeability) and transparency of historical transaction records. All the identity transactions executed on Blockchain remain in the history and cannot be deleted or altered. This means that history of identity transactions can be held in a sort of public registry (this does not imply that actual personal data is transparent – let’s put aside the privacy issues for a moment). And therefore the history of identity transactions across organisations can become a basis from which new identity information is derived (through aggregation, referencing & vouching, statistical analysis, cross-attestations etc).

I call reputation an identity derivative (because it is derived from the attributes of an identity, it is not an attribute itself) that can be dynamically changed and simultaneously used in a Blockchain environment. Another connected identity derivative is “provenance”. Proof of provenance shapes one of the promising business cases for Blockchain. For example, “provenance” attributes can be used by insurance companies as a source of reliable information about the history, reliability and origin of a document, a digital good or a physical good with digital representation. See our favourite example of Everledger, a Barclays accelerator startup that records provenance of diamonds on the blockchain.

Thus, the promise of “Blockchain for Identity” is to tackle the problems mentioned above: lack of interoperability and lack of meaningful identity data. Potential is – to enable sharing of identity information and to create enriched identity derivatives that could in turn open doors to new business cases in trade, commerce, capital markets – any area in which identity-based decisions are made on daily basis really.

Identity is fundamental to businesses and markets today – so changing how it works could drastically transform to the way businesses operate.

Big risk. And big opportunity.

 

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.