Scary movie

Greyscale backing image
[Dave Birch] Well, it’s Halloween. I never much cared for it, as I was brought up on the traditional British November 5th celebration of intolerance, Guy Fawkes night, when we remember, remember the failure of our first great religious terrorist, Guido Fawkes and joyously dance around burning effigies of noted criminals, spiritual leaders and so on. To take my mind off of it, I went off to Digital Disruption 2013 to see how our clients on the telecommunications side of things might take advantage of changing technology.  I ran into a French lady there.  She was a little overdressed, if you ask me, but I don’t know too much about fashion so I was in no position to judge!  Anyway, as she seemed to venerate the fashions of a now-distant past, I went over to ask whether she saw much future for NFC or not.  I asked for her perspectives on the MNO NFC efforts underway in France.  She seemed a little puzzled, and I thought perhaps her English was not too good, and I tried again, only this time speaking loudly and slowly.  But nothing.  Perhaps I was talking at too high a level, so I went down a notch.  It took me a while to explain to her the difference between NFC interfaces and card emulation interfaces, but eventually she screamed with delight at my incisive analysis of the varying technology roadmaps associated with secure element-based NFC payments and “NoSE” (No Secure Element) applications.

Untitled

She told me that she had to go and have her head chopped off, so I went looking for someone else to talk to.  One of the stimulating topics of conversation that I thought of was the difference between “chip and signature” and “chip and PIN” and why the inclusion of PIN at the top of a card CVM list would lead to one or even two orders of magnitude less fraud.  I fancied this as a sound conversational stratagem because it would inevitably lead to a quite heated discussion about US market strategy.  I mentioned this to a gray-haired chap standing next to me and he stared at me blankly!  So I explained it all again, but this time in a little more detail.  He must have been a visitor as he didn’t seem to understand me either, even when I showed him a collection of cards with different CVMs.

Untitled

Oh well, I spotted some people dancing and I thought it would be fun to join them.  I saw one nice looking lady delegate so I thought I’d ask her to dance.  She seemed a little vacant to me but it had been a long day, so I thought I would try and cheer up with a funny story about the development of smart watches.

Untitled

As you can see she thought it was hilarious!  When I got back to the hotel, I blogged about it so that you can all enjoy it.  She made some comment about how much the living must envy the dead and vanished, unlike Tony Poulos who is surprisingly hard to get rid of unless you happen to pass a bar serving free beer, which we did.  I then ran into a group of dedicated electronic transaction fans who I noticed were following me.  I didn’t quite catch what they were talking about, so I thought I’d introduce myself and see if they were fans of the “Atlantic Model” of federated identity management along the lines of the US NSTIC and UK IDA initiatives.  I took their silence to be agreement.

Untitled

They seemed genuinely surprised when I told them some of my ideas for separating the fundamentally different telco activities of identity provision and credential and reputation management and how the telcos might provide open, transparent and non-discriminatory access to the basic identity services for third-party credentials.  I didn’t quite catch what they said about it (rather amusingly, it sounded like “kill me”, but I think they were actually saying “tell me”) but by that time most people had gone and the area was deserted.  I was thinking about the different strategies being adopted by our clients in the USA and Europe, particularly because of the European regulatory, when I bumped into a chap who appeared to have the haunted look of a banker who had been studying the European Commission’s consultation document of direct access to bank accounts by licensed third-parties.  He seemed quite interested but unfortunately I didn’t have time to finish my explanation of the Single European Payment Area (SEPA) and the current state of pan-European migration to the new SEPA Credit Transfer and SEPA Direct Debit standards before the lights went out at midnight and I was forced to find my way out in the dark.

Untitled

While I was doing this, surrounded by people working at the forefront of the telecommunications sector, preparing my notes for the session that I was going to chair on Data Security and Privacy, I became mildly excited.  You know, if identity really is the new money, that could be great for the telcos because they are obvious contenders to provide the identity infrastructure.  But, of course, the telcos in general and the MNOs in particular might decide to leave these crucial elements of the new economy to other players:  Facebook, maybe, or Apple or Google.  If that happens, then some of our most important clients will find themselves bypassed by service providers who see the telcos as nothing more than dumb pipes.  Now that’s really scary.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Dave Birch has a lovely pair of knees

Greyscale backing image

[Dave Birch] I was tangentially involved in discussion about biometrics while working on a technology roadmap for one of our clients in the financial services sector. I was arguing my usual point, which is that mass market biometrics are about convenience, they are not a security play. In passing the issue of biometric accuracy was raised, and a useful discussion ensued. I. I'd like to amplify a point that was made in passing and introduce some data points.

The Unique Identification Authority of India (UIDAI) has successfuly conducted a proof of concept iris authentication study in the Mysore district of Karnataka, achieving accuracy levels of above 99.2 per cent, an official press release said here today.

[From UIDAI’s iris authentication proof of concept study successful | NetIndian]

At population scale, 99.2% is not very good. If you had a 99.2% effective contraceptive, the average woman using it would get pregnant every year. In closed environments, matching an iris against a token-based template as a PIN or password replacement is plausible but population-scale iris matching against a database for identification requires more thought. In the UK, the government shut down the IRIS system for border control back in 2012 in favour of e-passport scanning. Of course, iris isn't the only biometric that might be used in the future.

A new lab is working to perfect special shoe insoles that can help monitor access to high-security areas, like nuclear power plants or special military bases. The concept is based on research that shows each person has unique feet, and ways of walking.

[From Shoe ID Lab Developing Biometric Shoe To Identify Individuals Based On How They Walk

Yep. Feet. If I want to log in to your Facebook using this technology, I'll have to walk a mile in your shoes, so to speak. But gait is not the only lower-limb biometric on the horizon.

A new study involving magnetic resonance imaging suggests that MRI knee scans could be used as an almost foolproof form of identification. For the study, Dr. Lior Shamir, an associate professor at Lawrence Technological University in Southfield, Mich., analyzed knee scans of 2,686 people. He found that the scans accurately identified about 93 percent of the test subjects.

[From Knee Scan Identification: MRIs May Be Better Way To ID Travelers, Study Suggests]

In my books, 93% identification accuracy isn't "almost foolproof", it's "almost useless". Imagine the diligent anti-terrorist super-team at Heathrow Terminal 5 are on the lookout for the noted terrorist Dave the Jackal, who is known to be travelling incognito in a Facebook-blue burkha. Armed with an MRI scan of his knees, obtained by waterboarding a Cairo chiropractor, they set the scanners loose on a Monday morning. Now, Heathrow Terminal 5 carries about 65,000 passengers per day. The scanner will, broadly speaking, correctly identify 60,000 of them as not being the Jackal and send 5,000 of them for detailed investigation as potential Jackals. Say a few hundred an hour. What's the point of this?

Is this just another example of typical media innumeracy? I think not. I think it represents an underlying belief that we will be moving to biometric identification. There's a faith in biometrics, a belief that at some point in the future the biometric technologies will be so advanced that their identification will, indeed, be foolproof. The curve of technology might be taking us in that direction, but we're a long way off it just yet. This is why biometric authentication against a secure token makes for better strategy in our space. Biometrics as a PIN replacement, not biometrics as a card replacement. Or, indeed, biometrics as a phone replacement.

Enhancing data security and privacy – this should be an MNO business

Greyscale backing image
[Dave Birch] I’ve been living the hell that is our identity infrastructure in 2013 because my eldest son just started university, and this means dealing with student finance. He is applying for student loans, so he had to create an account with the Student Loan Company, which means that I had to create a parent account which also meant that I had to create a parent account for my wife. I created these accounts and then filled out the financial information that they asked for (last year’s P11Ds and P60s which they could have got from HMRC), then they needed something else. So…

  1. Go to student finance web site at DirectGov.
  2. It asks me for an e-mail address and password, neither of which I can remember.
  3. I click on “forgotten password” (which is where they should probably take you in the first place) and they e-mail me a password reset.
  4. I reset the password, but the system tells “your new password can’t be the same as the old password”! Doh! So that’s what my password was!
  5. I choose another password.
  6. Hurrah! I can log in.
  7. It asks me for the 2nd, 4th and 6th letters of the street I lived on when I was ten years old.
  8. I wasn’t sure what I’d answered for this question, but luckily I got it right.

This is what should have happened…

  1. Go to student finance web site at DirectGov.
  2. Choose my bank as my identity provider.
  3. Open my bank app on my mobile phone and enter my PIN (or put my finger on the home button fingerprint scanner).
  4. Continue with student finance web, now correctly recognised.

Meanwhile, my son filled out the online stuff (remember, all of this is completely and utterly pointless since my wife and I are above the income threshold so we cannot obtain any financial support) and then discovered that he had to provide proof of identity. I assumed, this being 2013, that he would be able to log in to student finance using his bank card (since his bank has already KYC, AML and ATF’d him) or select one of the UK’s approved identity providers — say the Post Office, for example — and log in using one of them. Of course not. Much as our Victorian forefathers might have done, he was required to obtain a declaration of his identity from an upstanding member of the community (thanks Gloria!) and go down to a Post Office and send it, along with his original birth certificate, off to Doncaster. I imagine he’ll never see it again, but I paid for secure overnight delivery anyway. That was six quid. Six quid that I might, in an advanced economy, have spent on registering for an ID linked to, for example, his smartphone SIM.

It may be two years, it may be ten, but soon enough the identity credential will look very much like Facebook, YouTube, or Amazon: It will be an app or functionality embedded within an app on your smart mobile device.

[From DigitalIDNews | On the path to a ‘virtual’ identity credential]

This is the sort of thing that I will be pestering the delegates about, I imagine, at Digital Disruption 2013 tomorrow and Thursay, because I really think that the mobile operators should be developing a more strategic approach to identity and building an understanding of where their corporate strategies will take them in this area. I’m chairing the track on Enhancing Data Security and Privacy and I’m really looking forward to hearing the latest thinking in this critical area of business.

P.S. We received some more forms for him to sign a couple of days ago. Physical forms. In the post. That we have to send to him so that he can manually sign them and then post them back to the SLC. I swear that twenty years ago I never imagined that we would still be doing this in 2013.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Cybersecurity awareness month – sharing in a digital world

Greyscale backing image

[Margaret Ford] Educator and certifier of info-security professionals (ISC)2has just published a report on the online activities of primary school children, as part of its Safe and Secure Online programme. According to the report (available to its members at www.isc2.org.uk), 18% of 9-11 year olds have met up in person with a stranger they have met online. More worryingly so, 50% of these went alone. The report was published as part of National Cyber Security Awareness Month, celebrating its tenth anniversary this year.

A significant number of children have admitted to lying about their age in order to access popular social media sites such as Facebook. Having spent some time recently discussing online safety with 10 year olds at a local primary school, I have found that many of the children “know someone” who has an account on Facebook, despite being the account holder being well below the official minimum age of 13.

Apart from propagating some kind of digital ‘green cross code’, it can be hard to know how to approach e-safety with this age group. Many outstrip their parents in technical knowledge, and are naturally intensely curious. One approach may be to help them to build their own strategies for dealing with potentially risky situations. Materials such as videos and games can be used to encourage the children to express their concerns and work together to find ways to protect themselves online.

As part of the EU-funded TREsPASS project, Consult Hyperion is involved in exploring these same issues of trust, sharing and risk exposure at organisational, national and international levels. In the TREsPASS context, this involves the development of modelling formalisms and identification of practical ways to share risk information, to provide as much value as possible to the recipients, without overexposure of the originating organisation.

At present, the sharing of risk information is far from uniform: bilateral arrangements between organisations, governed by NDA, appear to be the norm. Multilateral sharing has evolved in some industries, especially those which involve Critical National Infrastructure and those which are heavily regulated – telecoms is an example of this. Before any meaningful sharing of risk data can take place, a sound structure for sharing has to be in place.

A key element mentioned at a recent meeting of the EU NIS working groupon information exchange and incident co-ordination is the need for a common view of normality. In cyber security, as in many other fields, this can in fact be very subjective and vary by sector, size of organisation and organisational culture. Where one company might regard repeated attacks as ‘business as usual’, another might regard those same incidents as a reason to invoke crisis management.

In order to find common ground, it is helpful to start with a common vocabulary. The FAIR taxonomy adopted by The Open Group provides a valuable structure for describing the range of risk concepts. We presented with fellow TREsPASS partner BizzDesign this week at the Open Group Conference in London, showing how the ArchiMate Enterprise Architecture tool could be extended to support risk modelling with reference to a practical case study. As a socio-technical project, TREsPASS is investigating complex social and organisational environments together with technical elements of risk.

Interesting announcements at the Open Group event included the launch of the Open FAIR Certification for risk professionals, based around the newly published updates to the FAIR risk taxonomy and risk analysis standards.

Over the course of the project, TREsPASS will produce a range of tools to support risk modelling and visualisation at enterprise level. It will also develop a risk toolkit tailored specifically to the needs of SMEs, taking into account their unique requirements and essential role in the European economy. 

Keep an eye on this blog for further developments from TREsPASS as well as our involvement with this EU project. 

Cloudy, chance of rain

Greyscale backing image

[Dave Birch] At the Management World event in Nice earlier this year ("Navigating the Digital Storm") I was flattered to be asked to chair the discussion session on Delivering Enterprise Cloud Services. I was keen to get a general perspective on the telecommunication sector's approach to this growing market. Naturally, I also thought I might be able to steal one or two decent ideas to pass on to our telecommunications clients who are looking to find a niche around enterprise cloud. I don't know very much about enterprise services as it's not really my day-to-day focus so I think I was asked to chair because some of the telcos felt that the "identity issue" was key to unlocking this market and, since I'd been droning on incessantly about identity for as long as any of them could remember, they thought I might be able to help direct some of the questioning.

It turned out to be a really interesting session. Before we talk about identity I just want to pull out a few things from my notes which I think might be relevant to the discussion. One of the discussions was around UBS. In round terms, UBS spends around $4 billion every year on IT. Of this, somewhere round about $1 billion per year is to deliver net new functionality to the business. That sounds pretty cool and it sounds like UBS must be delivering some incredible new services. Until, that is, you discover that almost all of the net new functionality is to do with regulatory requirements and changes in compliance. There is actually precious little resource going into delivering new products and services because the regulatory burden is so overwhelming. The smallest changes require colossal expenditure. Just witching from windows XP to Windows 7 cost something like $300 million. Imagine the pressure is on the bank IT department trying to support managers who want to use smart phones and iPads, desktop traders, homeworkers, contractors using goodness knows what and all of the other components of the modern enterprise. It is literally a nightmare.

Even in a small company such as Consult Hyperion you see a microcosm of these issues on a daily basis. It's no surprise that it many companies, people who are used to their Samsung S4, iPad Mini and smart TV at home get fed up with their enterprise IT infrastructure and, irrespective of company policies, start using Gmail and Dropbox, Yammer and a variety of other services.

Facebook has started to roll out a new file-sharing capability — and Dropbox shouldn't be the only worried party. The addition of a low-security file-sharing tool to the world's most popular social networking site could open a world of security pain on businesses and home users alike.

[From Facebook file-sharing could be security, piracy nightmare | Social networking – InfoWorld]

But back to the discussion. There is obviously an intimate relationship between enterprise use of (secure) cloud and enterprise identity infrastructure. Right now, most enterprises use proprietary identity management software that was never designed for cloud use and restricts not only the ability to take advantage of cloud services but also forms a barrier to organisational interworking that could be facilitated by the cloud.

Here's an example. A few weeks ago one of our retail banking clients asked me to prepare some material for them. The material included PowerPoint slides and notes and an audio file. When you tried to send it to the customer, it was too big for their email system so I put on Dropbox and sent them the link instead but they couldn't access it because Dropbox is blocked by their IT department. In order to get the file, they had to get me added as an authorised user to their "internal cloud" which took the best part of the day and then I used a special username and password to login and upload the file. Incidentally, a couple of days later when the client had asked me to make a few small changes and upload a new version of the slides, I had been deleted from the system and so had to go through the whole process again.

With an infrastructural, federated solution, it should have been entirely possible for the bank to accept Consult Hyperion credentials and provision limited access (in practice by issuing a certificate that I could then use to login on any device). It is easy to say, very difficult to implement. This is where, I thought, the telcos might have something to offer. But they'll have to move quickly, but the enterprise cloud players have a strategy toward identity (because they see it as strategically important) whereas the telcos (and the banks?) don't.

I expect Oracle customers using Oracle applications via SaaS will increasingly use their Oracle Cloud identity as the identity for a chunk of their user populations, rather than trying to maintain multiple identities in their on-premises system. Since Oracle is already maintaining a cloud identity for every Oracle Cloud user, that identity is portable as far as the user is concerned.

[From Trend Watch: Identity Management Top 5 « Discovering Identity]

Quite. And Oracle are not the only serious player to have realised the power of transforming identity management from something to do with single sign-on to a strategic element of their proposition.

At his company's first YamJam conference in San Francisco, Sacks just revealed plans to move beyond the surface resemblance to take on Facebook's core function of identity, and apply it to the workplace.

[From Yammer's Facebook-Like Strategy – Business Insider]

For LinkedIn and such like, this is an important step. It is easy to see how it might work in practice: I want access to an enterprise cloud so I log in using my LinkedIn identity and since the bank has access via that identity to my professional social graph it can make some pretty decisions about whether to let me in and what I might be allowed to look at.

Cloud growth has also led to APIs playing a more critical role in the connected business. Companies such as Salesforce.com encourage business users to create their own apps by providing access to enterprise-grade services such as workflow, approvals and even data models.

[From APIs: Driving the connected apps revolution | VentureBeat]

Where could the mobile operators, for example, play in this space? If they had a standard API for identity services they could offer this to Oracle, Salesforce, Yammer and everyone one to provide a global recognition service that brings together hardware-based two-factor authentication (using the SIM) with federated identity and value-added services around location, roaming and so forth. I can see that it would be rather convenient to log in to a client's cloud using my phone and my LinkedIn identity and surely it would be more secure than the sort of simple password-based non-security we deal with at the moment. Tom Noyes, who I always take seriously, calls this a "breakout business" for mobile operators and I'm sure he's right. Whether they can develop a co-ordinated strategy to exploit this opportunity is, naturally, another matter.

There are, of course, significant business implications, which is why guys like Salesforce take it so seriously. If I used my LinkedIn identity, say, to log in to various clients and online resources during the day, then LinkedIn would know what I was up to. If they see me log in to my good friends at Indeed.com, they might reasonably deduce that I am looking at the job market and send an alert to the numberless hordes of recruitment consultants who are constantly trying to link to me. I'm puzzled by the number of organisations that look at this with equanimity. It is huge.

The ID of Sisyphus at the Country Club of Palo Alto

Greyscale backing image
[Dave Birch] People who don’t really understand how anything actually works and have no perspective on the big picture that is needed for worthwhile risk analysis tend to grasp at reactionary ornaments when the public clamour “something must be done” reaches a particular level. Here’s an example. We know from previous experience that putting cardholder images on payment cards makes absolutely no difference to fraud. If it did, banks would do it. One of the reason why images make no difference is that retailers tell their staff not to look at them, because it’s not their problem. Retailers don’t want staff being assaulted by either criminals or disgruntled legitimate cardholders and since they are not liable for chip transactions where the correct PIN was entered, why would they bother? In the real world, you swipe the card and the light is green you get the goods. The photo ID is a good example of something that seems like it should be a good idea, but just isn’t.

Banking ombudsman in Karnataka M. Palanisamy Tuesday advised banks to issue chip-based ATM cards with customer’s photo to check frauds committed through debit or credit cards.

[From ATM cards with photo will check frauds: Ombudsman – NY Daily News | NewsCred SmartWire]

Of course, you don’t need to put the ID photo on the debit card. You could simply demand that customers produce ID when they use a chip and PIN card to buy something. I’ve noticed that this often happens in Spain: you buy something in a shop and present a chip and PIN card and enter the correct PIN and the transaction is authorised but the shopkeeper still asks for ID (I generally present my 1997 England football club supporter’s card because I leave my passport in the hotel safe) and then asks you to sign the slip as well. Asking for ID must reduce fraud, right? And ID cards that have jolly secure chips as well as photos must reduce fraud to immeasurably small levels, right?

“People have started using our principle of freedom of information as a tool to commit crime,” Lars Minnedal of the Stockholm police fraud unit told the Aftonbladet newspaper… Security experts have warned that Sweden may be soon hit with a “fraud epidemic,” as would-be criminals can get all the information they need by making a call to the Swedish Tax Agency (Skatteverket).

[From ID-card fraud ‘epidemic’ threatens Sweden – The Local – m.thelocal.se]

The law of unintendend-but-entirely-predictable consequences strikes again.

“The society we live in makes it possible. The problem is that we have a freedom of information principle, and people never thought of how it could be abused in the way it is today,” Minnedal added. “You can access everything on everyone and there’s no requirement to explain what you want to use the information for.”

[From ID-card fraud ‘epidemic’ threatens Sweden – The Local – m.thelocal.se]

How can you actually cut down on ID fraud? There are two basic approaches. You can make it harder to steal identity data (the Sisyphean PCI-DSS approach) or you can make it harder to use stolen identity data by having a working identity and authentication infrastructure (my approach, but who am I against so many?). This Swedish example illustrates perfectly how having easy-to-steal data and a non-working infrastructure delivers a perfect storm.

While Swedish identity documents are equipped with advanced security features, Minnedal lammented that many store clerks and sales people “systematically neglect” to look carefully at ID cards presented to them or lack knowledge of the card’s proper appearance.

[From ID-card fraud ‘epidemic’ threatens Sweden – The Local – m.thelocal.se]

Store clerks and sales people should not be required to become de facto identity verification experts. What is the point of the chip on the Swedish ID card if you are going to ignore it for verification purposes? Just as the mPOS revolution means that anyone can take payments, so it should similarly mean that anyone can check an identity card, anyone can “take identity”. Not by looking at an identity card — get with it Grandpa Sven, this isn’t 1952 any more — but by via iBeacon or by tapping it with their NFC phone or putting it in their iZettle. Then the system can check whether the card is real or not, require the cardholder to enter a PIN and a fingerprint if necessary and display the photo stored in the chip. Note that the photo will generally be ignored anyway, and eve when it isn’t, it won’t help.

Stolen second-generation ID cards are much prized by criminals engaged in fraud and money laundering as they cannot be canceled, an investigation has revealed. These cards don’t come with a secret disabling code so remain active even after their rightful owners inform police they are missing, said officials from the household registration management center in Tianjin Municipality, neighboring Beijing.

[From Crooks strike rich with ID card you can’t cancel- China.org.cn]

So in China for $65 you can buy a stolen ID card of someone who looks a bit like you and you’re home and dry. In a way, that’s worse than having no ID system at all, because it means that once you are inside the wire (ie, once you’ve flashed your stolen ID card at someone and they have accepted that it’s you) then your rights and privileges are no longer questioned!

Look. Identity infrastructure should be based on the premise that anyone’s identity might be stolen but that it cannot be used by anyone other than the rightful owner. That means an infrastructure with strong authentication. I think I might host a discussion table on this topic at the first ever Bay Area Tomorrow’s Transactions Unconference in Palo Alto on Friday 4th October. Consult Hyperion are organising this with our friends at BayPay and with support from the wonderful people at Discover.

For those of you unfamiliar with our Unconference concept, the event will build on the success of the previous London, New York and Toronto Unconferences, success that is down to the expertise and enthusiasm of the participants but also the event format itself. Instead of of a succession of pre-determined Powerpoint presentations, the events mix stimulating talk from thought-leaders with global perspectives and discussion sessions which bring together the delegates, experts and selected industry observers to cover topics chosen by the delegates themselves on the day. The goal of the day will be to help professionals in the finance, payments and related industries to explore the future of the retail electronic transactions space and go back to their companies with new ideas, new strategic input and new friends.

Who knows what the delegates will choose to discuss and debate in Palo Alto next week, but I expect the topics to be covered to include the future of online identity, the mobile “wallet wars”, migration to chip cards in the US, alternative and parallel currencies, “near banking” and much more. (At the London event this year the topics discussed ranged from bank APIs to writing a movie about payments, and at the Toronto events popular topics included identity as a banking service, the end of cash and big vs. small data in business models.)

The invited thought pieces that will stimulate the discussion in Palo Alto will be:

  1. David Wolman, contributing editor at Wired magazine and author of “The End of Money” (all delegates will receive a copy of David’s book).
  2. Nate Wehunt Sr., Head of Digital Channels at City National Bank.
  3. Sam Lession, the Head of the Identity Product Group at Facebook.
  4. Me, one of Wired magazine’s global top 15 favourite sources of finance and business news, and Europe’s most influential commentator on the emerging payments scene.

Following the keynote, during the Q&A sessions, the delegates will (in best open-space style, as described at http://www.unconference.net/) note down the topics that they would like to discuss and these will be organised into sets of parallel sessions (one before lunch and two after). Delegates are then free to join in any, all or none of the discussions. The points raised in the discussions will be captured and reported. If you are responsible for strategic directions around payments, banking and finance then come along and get new ideas, new perspectives and new insights to help you to develop robust strategies to make the most of the incredible technology, business and social changes underway.

There will be a range of delegates from different backgrounds at the fall events and we hope the cross-fertilisation of ideas will be something special. As for the other events, the day will be limited to 100 delegates so that everyone gets a chance to participate in discussion, debate and learning. I hope you decide to come along. It’s $50 for BayPay members and $100 for non-members, so you’d be mad not to get yourself a ticket right here, right now. See you next Friday.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

The focus on biometrics in the mass market

Greyscale backing image
[Dave Birch] Well, it’s no surprise that following the launch of the new iPhone 5S with it’s new “TouchID” fingerprint sensor that the combination of the mobile phone and biometrics is a focus for discussion in our little corner of the secure electronic transactions world. As was widely anticipated following their $300m purchase of the fingerprint sensor manufacturer Authentec, Apple have added a sensor to the home button of the new iPhones so that users can authenticate themselves using, well, themselves.

Apple has just confirmed that the iPhone 5S will feature a 500ppi fingerprint sensor right in the 5S’ home button

[From Apple’s Touch ID Is A 500ppi Fingerprint Sensor Built Into The iPhone 5S Home Button | TechCrunch]

Here’s an amalgam of the conversations I had with different people following the announcement.

Person: Do you know that fingerprints can be faked? I heard about a Japanese guy who did it with jelly babies or something?

Me: Yes, I know.

Person: Your fingerprints are all over your phone, people could easily steal them.

Me: Yes, I know.

Person: Criminals might be able to find a way to make a fake finger and use it to buy songs on iTunes using your iPhone.

Me: Yes, I know.

Person: Do you know that researchers were able to reconstruct useable 3D models of fingers by accessing stored fingerprint templates?

Me: Yes, I know.

Person: So would you use the new Apple TouchID on your next iPhone?

Me: Of course.

If I sound complacent about the possibility of agents of foreign powers delving into my iPhone, it’s because I am. The Apple TouchID isn’t really about security, it’s about convenience, a point I made on BBC Radio 4’s Today programme. Convenience is something at which Apple excel. When I got on the bus last night, I had to press the home button on my iPhone to wake it up, then swipe my finger to get to the unlock screen, then enter the 4-digit passcode, then touch my Arriva app to display my ticket to the driver. With the new iPhone, when I press the home button to wake it up, it will scan my fingerprint and skip over the swipe and enter passcode stages. That may not seem like much, but when you are at the front of the queue on the bus, or checking it at British Airways, or showing a ticket for an event or trying to show a loyalty card in a shop using Passbook and paying in Starbucks using their app, it will save a few seconds. And there will be a bunch of people who currently don’t lock their iPhones but will because of the fingerprint. That’s it.

Will TouchID be more secure than a 4-digit passcode that can easily be read over someone’s shoulder? Yes. Will TouchID replace 4-digit passcodes? No. You will still have a passcode for the odd occasion when your fingerprint can’t be read or for when your wife wants to look up something on IMDB on your iPhone and can’t be bothered to go into the other room and get her smartphone. Will TouchID make iPhones magically invulnerable and capable of storing your deepest thoughts perpetually and in complete secrecy? No. Biometrics in the mass market are about convenience, not security. As I wrote some months ago:

Apple understands the location of biometrics in the consumer space: convenience, and Apple is all about convenience. Remember, these iPhones aren’t going to be used to launch nuclear missiles or identity people in databases

[From Biometric tick]

Right now, the use of TouchID is limited to unlocking the iPhone and authenticating an iTunes purchases because developers do not have access to the fingerprint subsystem, but I’m sure that (given the competitive pressures as other handset manufacturers adopt similar technology) once the subsystem is tried and tested and tuned and optimised then they will be, so when I open PingIt or PayPal I will find myself using the home button instead of entering a passcode. Crucially, given that Apple’s design influence and media mindshare are significantly ahead of its market share, the TouchID’s deployment is a boost for the whole biometric authentication sector.

Apple’s iPhone 5s Touch ID fingerprint scanning feature will kick off a biometric adoption race

[From Apple’s iPhone 5s Touch ID fingerprint scanning feature will kick off a biometric adoption race – The Next Web]

When it comes to using this kind of technology in retail payments, there are plenty of people experimenting with the options and plenty of experience in customer reaction. Consult Hyperion, for example, advised Natural Security on their system that combines biometric authentication and contactless interfaces.

Today Natural Security, in partnership with Banque Accord, BNP Paribas, Crédit Agricole, Crédit Mutuel Arkéa, Groupe Auchan, Ingenico and Leroy Merlin, has launched a pilot deployment of a new payment method that combines a smart payment card, biometrics and mid-range contactless communication.

[From Announcing the world’s first consumer trial of new payment method incorporating payment cards, biometrics and mid-range contactless technology – Security Park news]

This is what makes me so confident in my prediction that consumers will like, and use, the technology. At the end of the Natural Security trial in France, some 94% of users said that they wanted to pay for all in-store purchases using the fingerprint authentication. A recent WorldPay survey in the UK had half of all shoppers saying that they wanted to use biometrics for payments. Apple’s model — local biometric authentication for the mobile device, wireless communication between the mobile device and the local environment — looks a very sensible one to me.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Don’t you know who I am?

Greyscale backing image

With one or two of our clients, a year or two ago, we began to use the word “recognition” to mean a combination of fit-for-purpose identification technology with fit-for-purpose authentication technology. For commercial organisations, customer recognition is a strategic goal and developing a pathway of tactics to get there by exploiting various waystations on the technology roadmap is an immediate need, because recognition is essential for delivering value-added services. In some retail relationships, it is absolutely crucial. Here’s what I mean.

The London Times recounts a true American horror story: Mindy Kaling, writer and actress first on The Office and later on her own show, The Mindy Project, in addition to author of a successful memoir, walked into a Los Angeles boutique. And she was not recognized. This is a worst-case scenario for any Los Angeles boutique owner.

[From Facial Recognition Alerts Stores When A Celeb Walks In | Popular Science]

Embarrassing it may be (don’t worry, I haven’t the slightest idea who she is either), I don’t think it can be correctly labelled as the absolute worst case for any boutique. That happened in Zurich recently, when the pretty much the richest woman in the world walked into a shop to buy pretty much the most expensive handbag in the world and the saleswomen not only blew a substantial commission but…

US talk show host Oprah Winfrey says she was the victim of racism during a recent visit to Switzerland. She said an assistant refused to serve her in an upmarket handbag shop in Zurich. Winfrey, one of the world’s richest women, was apparently told one of the bags was “too expensive” for her.

[From BBC News – Oprah Winfrey ‘was victim of racism’ in Switzerland]

If it was me, I would have bought the shop and fired the assistant, but I suppose real billionaires are more sensitive and caring. One can only imagine the shock and trauma that Ms. Winfrey suffered when she realised that the Swiss shop assistant had absolutely no idea who she was. I’d love to think she said “do you know who I am” only to be told “no”. In our post-modern celebrity-obsessed culture, not being recognised is a fate worse than death, a problem that our emerging identity and authentication infrastructure really ought to be able to tackle.

This lack of recognition is precisely what the VIP-identification technology designed by is supposed to prevent. The U.K.-based company already supplies similar software to security services to help identify terrorists and criminals. The ID technology works by analyzing footage of people’s faces as they walk through a door, taking measurements to create a numerical code known as a “face template,” and checking it against a database.

[From High-End Stores Use Facial Recognition Tools To Spot VIPs : All Tech Considered : NPR]

In the Swiss case, this same software could also be used to stop asylum seekers from entering the shop at all, so I imagine it will be pretty popular over there. (I’ve been invited to give in a talk in Zurich by our good friends at SIX, so I will ask around when I get there.) But is it a good thing over here? I’m looking forward to the first case of this database getting hacked for use in a mafia hit. Imagine the manpower they would save! Instead of staking you out and tailing you, they just put your picture into the shopping mall database and wait for the bell to ring.

This isn’t all about celebrities and mafia hits. We all want to be recognised, in the right context. I want BA to know that I have a Gold Card as soon as I walk in through the door because I expect to get better service. I don’t get upset when I don’t get that kind of service on United. I understand the game. I like getting a free cup of very nice coffee when I go shopping in our local Waitrose because I have a “My Waitrose” card. And there’s nothing sinister about retailers wanting to know who you are so that they can deliver a better service to you. Being recognised can be good.

Recycling bins in the City of London are monitoring the phones of passers-by, so advertisers can target messages at people whom the bins recognize… The bins record a unique identification number, known as a MAC address, for any nearby phones and other devices that have Wi-Fi turned on. That allows Renew to identify if the person walking by is the same one from yesterday, even her specific route down the street and how fast she is walking.

[From This recycling bin is following you – Quartz]

If I was going to put a bomb in a rubbish bin in order to assassinate a top bankster, just as an example, I would want to be sure that the bomb detonated just as the target was walking past, so this sort of technology would be invaluable and it’s a shame that the City of London spoilsports banned it. But you can see why they were upset. This sort of passive recognition is different, even though it is inevitable. If we’re going to have recognition, then it needs to be secure (you can’t have privacy without security, remember) and it needs to be controlled, preferably in an explicit bargain between the customer and the retailer. I’m happy with my My Waitrose card in Waitrose, but I might be quite unhappy if I discovered that Waitrose were using it to track me elsewhere.

Now, as we discovered through our work on the Technology Strategy Board’s VOME project a couple of years ago, making that kind of bargain explicit is actually rather difficult, since a great many people don’t understand what is being traded off and it was hard work to find mechanisms to explain it to them so that they could make informed choices. (One that we explored was a privacy card game, which was pretty fun actually.) But let’s put that to one side for a moment and assume that we can. Then, within the bounds of Data Protection laws, I think it is possible to envisage a plausible “privacy settlement” that works for the retailers, customers and regulators. That settlement means sharing some personal information, of course. This was always the business school case study around junk mail. Where there were strict privacy controls, people got more junk mail, because the senders couldn’t work out who might or might not be interested in a golfing holiday so they sent the golfing holiday brochures to everyone. As David Cushman told me a few years ago, if you target information accurately enough, it ceases to be junk, or even and advertisement, and becomes part of a conversation and people like engaging in conversations. So people want recognition, and they want to share, but again it must be under their control and as part of a bargain they can understand and give proper consent to.

There’s another general case where recognition is evolving though. I remember seeing an excellent presentation on this last year from our friends at Sense Networks. They are currently collecting some four billion location data points per day from smartphones in order to deliver targeted advertising. They know everything about you—where you live, where you work, where you shop, where you went yesterday—except who you are. We’re all carrying tracking devices that mean we can be individually recognised.

[Verizon’s] new marketing program, Precision Market Insights, collects data information from iOS and Android users, based on geographic location gleaned from apps and sites being accessed. Verizon plans to continue to share that information with potential advertisers. Verizon emphasizes that the program is legal and doesn’t violate any federal wiretapping or other privacy laws because they keep user identities anonymous.

[From Verizon’s ‘Precision Market Insights’ Data Mining Policy Raising Privacy Concerns]

Setting aside the technicalities of how the data is anonymised and whether the technology used is “strong” enough, this sort of “big data” use strikes me as being reasonable. I don’t mind being tracked in that anonymous way, as part of a group, if it leads to better services for me. I don’t always want to be recognised as an individual. But then I’m not a sleb.

By the way, this sort of innovative use of new identification and verification technology is the sort of thing I might ask Mary Portas about at Europe’s Customer Festival in London on 16th-17th September 2013 where we are both in the keynote track. Thanks to the wonderful people at Total Payments, we have a delegate place at this event to award as a prize on this blog. So if you are going to be in Islington on 16th and 17th and fancy coming along to hear about the future of loyalty, omnichannel retailing, big data and payments in the retail world, all you have to do is reply to this post with the name of the “Portas Town” famed for the short queues and excellent customer service associated with the issuing of UK identification documentation and your name will go into a draw that will be made under independent scrutiny on Friday 6th September. Look forward to seeing you there.

 

Monday Museum: Tokens mean credentials mean reputation

Greyscale backing image
[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is the last of our summer “Monday Museum” series, this time from 18th September 2006.

[Dave Birch] It’s hard to validate — I mean really, really validate — someone’s real identity in a transaction.  By “hard”, of course, I also mean “expensive”.  That’s why transaction mechanisms that don’t validate real identity (eg, credit cards) are easy to use and cost-effective.  Luckily, we don’t often really need actual identity validated to conduct a transaction.  What we need is reasonable assurance that the parties to a transaction are authorised.  So, when you are conceptually carded, it should be to see that you are over 21 (or whatever), not who you are.  There’s a big difference.  Over time, the credentials that are being presented begin to acquire a history, a reputation if you like.  Once can certainly envisage markets in which transactions depend on that reputation: not “snapshot” credentials or identity no matter how well validated.

The thing is that proving our actual identity is a special case: in almost all of the transactions we take part in every day, our real identity is immaterial.  It is generally used a proxy for some other credential — you’re an employee, you’re allowed to park here — because it’s the key that’s used to look up that credential in a database of some description.  Now, if it is possible to carry that credential around with you in a token capable of supporting a reasonable degree of authentication, then not only do we have a more secure system overall, we also have a much cheaper system (since we don’t need to manage or control the proxy database).

This is why we should try and change the paradigm around identity management.  Many people still think in terms of people proving who they are to log on to a web site rather than what they are: British, over 18, an eBayer with more than 100 stars and so on.  The latter example indicates why I’m curious about the potential for paradigm shift.  When I buy things on eBay, I don’t care who people are, I care about their stars.  It’s a reputation economy.

I remember writing about this in the past, using the emergence of stock markets as an example.  The first modern stock market began in Amsterdam back in the seventeenth century.  One of the interesting lessons from that time is that the courts had no mechanism for dealing with the transactions that were being undertaken: the contracts could not be enforced in court.  Yet the market grew and traders began to experiment with new instruments.  This market worked because contracts were self-enforcing with the group and the means of enforcement was reputation.  As Adam Smith noted later that century in the UK, “when a person makes 20 contracts in a day, he cannot gain some much by endeavouring to impose on his neighbours, as the very appearance of a cheat would make him lose”.  Much like eBay today, a trader’s reputation was the basis of their earning power and a low-overhead enforcement mechanism for the community.  Systems based on reputation do seem to work, although without the “security infrastructure” they are open to abuse.  They are also open to non-technological abuse, if you see what I mean (authors recommending each other’s books and that sort of thing) which is another topic in its own right.

At a personal level, reputation is a good basis for competitive advantage.  For one thing, it’s long-lasting.  It’s hard to forge a useful reputation — not that people haven’t succeeded: remember Frank Abagnale and the movie Catch Me If You Can — and difficult to buy one.  When I’m calling a plumber, I’d be much happier choosing one with lots of stars: thus, the plumber’s livelihood depends on having the stars and (the subject for another post sometime) taking away stars might be a more effective form of sanction than taking away some money.  If plumbers, policemen and everyone else had tokens that could give up (and verify) credentials, then it seems to me that many business models would be changed.

Imagine going to buy a car and having the dealer’s “stars” verified by your own ID card, phone or PDA at the same time as the dealer is verifying your “stars” from the bank.

Creating a security infrastructure that means that the eBay stars and the plumber’s recommendations can be audited and confirmed to be “real” therefore creates a platform for efficient transactions.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Monday Museum:  Chatroom paradox

Greyscale backing image
[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is another in our “Monday Museum” series, from 26th August 2006.

[Dave Birch] Chat rooms are a great place to start thinking about digital identity. Especially where children are concerned. I started thinking about this again while I was dipping into the privacy vs. anonymity debate that is swirling around our corner of the Internet yet again. If we (ie, the digital identity illuminati) can solve the chat room problem, then we’ll really have achieved something.

Chat rooms were in the news recently because UK users of Windows Live Messenger or MSN Messenger can now click a new button in the chat application to contact police with reports of suspicious behavior and instances of inappropriate sexual conduct online (eg, any mention of having viewed Celebrity Love Island). But how do you know who was being “inappropriate”?

This brings us back to the fundamental chat room paradox that we touched on last month.  To restate… Your kids want to go in a chatroom and you will only let them go into the chatroom if you know (in principle) who everyone else in the chatroom is, but you won’t let them go into the chatroom if they have to disclose who they are.   So in an “open space”, you want to everyone else to disclose their identity but keep yours secret, just in case of one the other people who has disclosed their identity is lying and is actually someone else (so that if they do something bad, the police can’t catch them).

My head hurts.

I think the solution to the paradox, as I consistently maintain, is to take pseudonymity seriously.  The problem isn’t the chat rooms themselves, but that no-one knows who is in them: it’s a problem of identity that pseudonyms could solve.  We generally take proving identity in the real world generally means proving who we are, but in the chat room we can clearly see the problem in a digital identity context.  It’s not who you are, but what you are:  are you an adult, UK subject, Manchester City fan, British Airways customer or a single parent?

Suppose that teenagers were given avatar by their school, or their parents’ bank or as in an interesting pilot scheme for children in care, a charity (for example, the Who Cares Trust, who presented on a version of this idea at the 4th Digital Identity Forum back in 2003).  Now suppose that the pseduonym (ie, public key certificate) contained a few unforgeable credentials (“I am between 14 and 18”, “I am male”) but that the children could choose any name they wanted for the ID (“I am David Beckham”). This gives the best of both worlds: the kids can log on to appropriate chat rooms, but no-one else in the chat rooms (nor the chat room operators) will know who they really are. 

My bank could give me an avatar of Donald Duck, but I couldn’t use it to get up to no good because if a police warrant asked my bank who “Donald Duck” is, it would tell them: and naturally the chat room operator — such as Microsoft — would only accept pseudonyms from reputable organisations such as my bank.  Thus, no-one in the chat room would know the real identity of the participants but none of the participants could get away with any illegal behaviour.  In just the same way, a travel agent might be happy to accept my BA Executive Club pseudonym, which leads us back into the world of federation etc..

I can’t believe how long ago it was that we started to use the “chatroom paradox” as a way to help clients think about some different aspects of identity and identity-related business. Seven years on, and I’m still writing magazine pieces about the chatroom paradox (I’ve just finished one for another journal) and the problem still isn’t fixed and the politicians and regulators still see security and privacy as opposite sides of a crazty balance.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.