Monday Museum: Cloning e-passports

Greyscale backing image
[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is another in our “Monday Museum” series, from 24th August 2006.

[Stuart Fiske] Because of the CHYP Electronic Passport Interoperability Service, we’ve already had a few calls about today’s Wired News story on the cloning of e-passports.   But what exactly is this story about?  Is it about uncrackable e-passports being broken open by hackers?  Or is it about someone reading the specifications and discovering that e-passports work as they are supposed to?

I don’t understand the word “crack” in the context of the electronic passports. There is nothing personal stored in the chip that is not human readable on the data page of the passport.  If you want to make a clone of the data inside the chip in my passport, you can do it by reading my passport: you don’t need to read what’s in the chip.  Obviously it saves a bit of time getting the digital photo out of the chip, but it’s just the same as the photo in the passport. “Basic Access Control” doesn’t protect the data stored in the chip: it just means that you have to have access to the physical passport in order to read the chip.  “Active Authentication” in the specifications allows the data to be linked to the specific chip, but it’s an optional extra which can be implemented if any government so chooses.  It’s a bit like the Static Data Authentication (SDA) versus Dynamic Data Authentication (DDA) issue for “chip and PIN” cards. Of course, if you have physical access to my passport you can read all the other chip data which secures my personal data as being valid, but you can’t change it, only copy it.   So you could copy my passport but what’s the point if you can’t change my data to match your face? When a passport control person puts your passport in their reader, it displays the picture inside the chip: if it doesn’t match the picture in the passport (or your face), I expect they will notice. Much as we love them, this is just not a “brilliant hackers break unbreakable code” story.  It’s a “person reads specification” story.

I don’t think much has changed in the press reporting of this kind of story over the years. The stories never reflect the kind of risk analysis that has gone into the design of such systems and as a consequence they don’t reflect real vulnerabilities.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Anonymity – privilege or right?

Greyscale backing image

[Dave Birch] The issues of social media free speech, anonymity and the possibilities for action rather than words about illegal activity are much in the news in the UK this week because of the disgusting Twitter campaign against the women's rights campaigner Caroline Criado-Perez. The basic dynamic was well summarised in The Guardian by the MP Stella Creasy.

For anyone who appreciates and uses social media free speech should be inviolable. That includes ensuring abuses of that freedom do not infringe on the ability of anyone to exercise it. To challenge, call out, parody or criticise someone is to practise freedom of speech. To threaten them with rape is not.

[From Twitter's inadequate action over rape threats is itself an abuse | Stella Creasey | Comment is free | The Observer]

There is a talk about trying to get Twitter to add a "report abuse" button. Personally, I think that would be a little pointless. And while the tweets at issue are illegal, it's also pointless reporting them all to the police. There are not enough police persons in the UK to track down all of the perpetrators, even if they could. When everyone is focused on one high-profile case, I can well believe that the police will track down and arrest one or two perpetrators and send them through the court system, but for the great majority of cases this will never happen. And, as Dr. Brooke Magnanti notes in The Telegraph, what constitutes abuse is itself problematic.

On Twitter, the definition of a troll sometimes means "prolific abuser". But it's also become an umbrella term that can mean anything from "someone who disagrees with me" to "someone with fewer followers than me". It's a slippery definition that is far too often trotted out to silence dissent.

[From Feminists boycotting Twitter is not the way to end trolling – Telegraph]

We all recognise abuse when we sit, but I think it might be very difficult to explain this to a computer so that it can run some kind of automated anti-abuse Claire Perry-style filter system. Of course, we could simply say that abuse is in the eye of the beholder and instruct the police to follow up whenever anyone claims that they have been abused.

A university lecturer could be sent to prison for calling a city MP a “coward”. Alex Cline faces a two-day trial after a court heard Hove MP Mike Weatherley complained to police about the name-calling in November.

[From Brighton man faces jail for calling Hove MP Mike Weatherley 'coward' (From The Argus)]

I hate the bullies as much as anyone else. I want something done about them, but well-meaning campaigns about boycotts and such like will not do anything about this problem. I think there is a solution. Let me take you through my thinking. The place to start, I think, is by first of all by dealing with the issue of whether people should be allowed to be sort-of-anonymous in online communities. The author and campaigner Heather Brooke, mades a very good point.

But the idea that anonymity is a right and not a privilege is wrong. There needs to be good reason to avoid being accountable for what we say or write, particularly if what we say affects other people. Too often online, anonymity is the tool of the bullying coward, a means to avoid responsibility for publishing threats, abuse and lies.

[From Anonymity is a Privilege Not a Right « Heather Brooke]

This is a perspective that I think is broadly correct. If people publish threats there should be a mechanism to hold them to account. But what does it mean to a technologist? How would this "right" be implemented? I think it is important that we find a way to do this that does not abolish anonymity, which has many useful social functions — not only for whistleblowers and political activists, for people enquiring about health issues or unpopular causes, and so on — but provides a "smash the glass" option for when things go wrong.

Concurrent with the end of anonymity will, obviously, be the end of privacy.

[From 11 Big Tech Trends You'll See in 2013]

No, no, a thousand times no. We must not sit back and accept this! I think there is a better way. Here's what the "father of the Internet", Vint Cerf, says about it.

"Anonymity and pseudonymity are perfectly reasonable under some situations," Cerf said. "But there are cases where in the transactions both parties really need to know who are we talking to. So what I'm looking for is not that we shut down anonymity, but rather that we offer an option when needed that can strongly authenticate who the parties are."

[From Google services should not require real names: Vint Cerf – Yahoo! News]

He is, as might reasonably expect, absolutely correct. Real pseudonymity is a real solution. If there were organisations out there capable of linking your online persona to your mundane existence, they could act as a responsible bridge between the physical and virtual worlds. It would be like when you go to a web site to log in to something and you click on the Facebook button to log in via a standard service such as OpenIDConnect, except you'd be clicking on a button to log in via someone who actually knows who you are.

I'll use banks as the example, even though none of the UK banks currently offer anything like OpenIDConnect. But suppose they did? Suppose Barclays, which is where my current account is, were to provide such as service? Then we have workable solution that would be something like this:

  1. I go to Twitter to open an account as King_of_Wessex
  2. Twitter offers me the option of logging in by username and password, using my Facebook account or using my bank account
  3. I choose bank account, so I get bounced to Barclays and I use my dongle to log in
  4. Barclays authenticates me, and bounces me back to Twitter
  5. Twitter create the King_of_Wessex account and flag it as authenticated.

Now I can tweet to my heart's content as King_of_Wessex. No-one will know that the King_of_Wessex is me. Twitter don't know who I am because while Barclays told them "yes we have authenticated this user" they didn't tell Twitter who I am. Barclays know that they authenticated me to Twitter, but they don't know my Twitter name. This is two-sided conditional pseudonymity.

So why would we bother doing this? 

Well, Twitter could then add a setting to their accounts so that users could choose whether to accept tweets from unauthenticated users. Like most people, I imagine, I would set my account to accept tweets from all users, so as not to miss any good stuff. But if for some reasons I start getting hate tweets, or death threats or whatever, I would switch to authenticated accounts only.

Now imagine that I get a death threat from an authenticated account. I report the abuse. Twitter can (automatically) tell the police who authenticated the transaction (ie, Barclays). The police can then obtain a warrant and ask Barclays who I am. Barclays will tell them my name and address and where I last used my debit card. If it was, say, Vodafone who had authenticated me rather than Barclays, then Vodafone could even tell the police where I am (or at least, where my phone is).

Would the police be swamped with millions of reports? I think not. Most people in the public eye would, I'm sure, set their accounts to receive tweets from authenticated users only. Tweets from unauthenticated users to authenticated-only accounts would simply be discarded. The bullies could post away as much as they liked. Perhaps it is therapeutic for them. Who knows. I wouldn't matter, because their tweets wouldn't go anywhere. I have enough faith in the judicial system to believe that when an MP went whining to the police about being called "a coward" this would be dismissed as nothing more than robust free speech, but if I threaten to come round and punch the MP in the face, then the police would obtain a warrant and proceed.

So the question is: would the average nutter post rape threats to female journalists if they had to use their bank card to create an authenticated account? I would have thought that, after the first couple of jail sentences, the problem would sort itself out.

(There might be a way to fix the problem without the courts as well. There's no reason why the police could not have an automated system that simply sends the warrant to the bank and gets back the real name and address of the tweeter and just publishes it alongside the offending tweet!)

This, then, is the solution. Twitter campaigns are pointless, but using identity infrastructure is not, and fixing this problem might well be a good way to deliver impetus for the banks (and the mobile operators and others) to work together to provide a platform for the future that would greatly benefit all of us. The Cabinet Office Identity Assurance (IDA) programme is developing the framework. We have the standards that we need (OpenIDConnect and such like) and the banks have "two factor" authentication.

To summarise once more as a soundbite: let me create a Twitter account using my Barclays bank dongle to log in. Then if I tweet something that breaks the law, the police can take a warrant to Barclays and get my name and address and arrest me. Sorted.

The Monday Museum: Pseudonymity as a solution

Greyscale backing image
[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is another in our “Monday Museum” series, from 20th July 2006.

[Dave Birch] I was at a workshop last week with a whole bunch of other people to discuss possible architectures for a public sector sort-of entitlement card (I can’t say what for as that would give it away, which I’m not supposed to do).  I was really cheered to hear, quite unprompted, someone put forward the idea of pseudonymity as a way to balance some security and privacy issues.  To hear the term introduced into a conversation at that level is, frankly, music to my ears.

It’s now a decade since I published my first paper suggesting that the combination of smartcards as a platform and pseudonymity as a  concept, might provide a practical solution to the problem of identity management in a networked age.  For anyone interested, it was “Smartcards and Pseudonymity” in the proceedings of “Smart Card Technologies”, an IBC conference held in London in October 1996.

To see why I’m so enthusiastic about it, consider the “chatroom paradox” that I’ve written about before:  Your kids want to go into a  chatroom to discuss [insert name of popular beat combo here].  You will allow them to do this but only if you know who everyone else in the chatroom is.  However you will not allow your children to reveal their real identities in the chatroom, so you end up with an unsatisfactory situation.  Everyone wants everybody ELSE to provide full disclosure but they don’t want to do it themselves because they don’t trust everybody else. Now imagine a situation where the school issues the children with certificates that confirm that they are in  fact of a certain age, in a certain geographic area or whatever, but the children are allowed to choose their own pseudonyms.  The  chatroom can now verify the certificates on entry so I can be sure that all the other nyms in the chatroom are actually children and not FBI agents or whoever.  Similarly the other nyms can verify that my children are actually children without having any idea who they are. If one of the nyms misbehaves, then the certificate issuer (ie, the school in this case) can easily tell the plod who the miscreant is.  Pseudonymity does not provide a means of getting away with anything. I wonder if we’re finally getting somewhere in producing a realistic solution to a key identity problem, or am I reading too much into one mention of my favorite word? 

I still think that pseudonymity provides a potential architecture for online identity that delivers both privacy and security!

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Vote for change

Greyscale backing image
[Dave Birch] We all agree that democracy is a good idea and that letting people who are stupid and/or uninformed decide how the country should be run is much better than letting (for example) me decide how the country should be run. We all think it is most amusing that the American franchise is populated by voters with especially nutty views, but no-one seems to think it odd that they are allowed to vote.

  • 13% of voters think Barack Obama is the anti-Christ;
  • 29% of voters believe aliens exist (so do I – I just don’t think they’ve kidnapped anyone from Arkansas to date);
  • 4% of voters say they believe “lizard people” control our societies by gaining political power (someone you trust is one of us);
  • 15% of voters say the government or the media adds mind-controlling technology to TV broadcast signals (the so-called Tinfoil Hat crowd);
  • Just 5% of voters believe that Paul McCartney actually died in 1966
[From Conspiracy Theory Poll Results – Public Policy Polling]

I was thinking about this because I was thinking about electronic voting. In my keynote talk at the Fourth International Conference on e-Voting and Identity, sponsored by Consult Hyperion and IBM UK, I said that the nature of digitisation is that we end up with new processes rather than analogs of analog processes. We don’t use iTunes to buy CDs, so the nature of the music business changes. The world music industry is now bigger than ever before (it’s just that sales of recorded music are continuing to fall, but so what). Think about this in the context of voting. We might start by using electronic voting to work in exactly the same way as non-electronic voting, for example.

Estonians today vote online and pay tax online. Their health records are online and, using what the President likes to call a “personal access key” – others refer to it as an ID card – they can pick up prescriptions at the pharmacy. The card offers access to a wide range of other services.

[From BBC News – How Estonia became E-stonia]

Why stop there though? Why not use electronic voting to improve the democratic process? While there are a great many different possibilities, I thought I would construct four scenarios for using an electronic vote along these lines to improve the voting process. The first is based on engaging young people, the second is based on the “Who wants to be a Millionaire” pub quiz machines, the third is designed to add convenience while reducing costs and the fourth is based on eBay.

The Provisional Vote

When the then Lord Privy Seal, Leader of the House of Commons, Deputy Leader of the Labour Party and the Minister for Women and Equality (all the same person: Harriet Harman) said that she was thinking about giving the vote to 16 year-olds I was naturally horrified. As the parent of one at the time, I remember being puzzled as to why society would ask such a teenager about anything at all, let alone who should be running the country.

It did occur to me, however, that there might be an alternative. Just as teenagers can obtain a provisional driving licence, under which they can drive but only when accompanied by a driver with a full licence, perhaps they could be given a provisional vote. The provisional votes cast in an election would be tallied and reported, but they would not count toward the result. That way, young people can be drawn in the democratic process — getting what Ms. Harman called “the habit of voting” — and learn the mechanism of the ballot box, but their opinions would not bind the rest of us.

In this scenario then, young voters are encouraged to download the standard government voting app (I propose to call it “Angry Voters” or “Call of Duty: Democracy” or “MPcraft” or something like that) immediately after their 16th birthday. When an election comes along the government sends a reminder to the app and the teenager can then click a button or two to obtain their voting certificate. In order to encourage teenage participation in the democratic process, the app could show them a map of where the nearest polling station is and provide the occasional nudge to remind them to pop down there.

Up until their 18th birthday however, these votes would be provisional votes. The next morning the newspapers could report the result of the general election and also what the result would have been had the provisional votes been counted so that young people might feel that there preferences were being recognised.

We might find a way of integrating with social media too. Perhaps the app can automatically post an “I just voted” status update on Facebook or perhaps offer young people the chance to join various Facebook groups. I only belong to one such group (“Che Guevara was a murderer and your T-shirt isn’t cool”) but they might be a way of getting teens to at least engage in some of the key issues of the day.

The Informed Vote

Engagement is important for democracy, but it’s not obvious to me how we benefit from getting people to vote when they have no idea what they are voting about. A rather depressing Ipsos/MORI poll conducted in June 2013 and published on 9th July 2013 illustrates the extent of public ignorance.

  • Almost a third of people think that the UK spends more on dole than on pensions, when in fact it spends 15 times more on pensions than on dole;
  • A quarter of people think that foreign aid is in the UK government’s top three areas of expenditure, when it is in fact slightly more than 1%;
  • The public think that a third of the population are immigrants (it is around sixth) and that a quarter of the population are Muslims (it is around one twentieth).

In this scenario, I propose to encourage engagement and an informed populace by extending the voting app to include a game which is a little like the sort of “Who wants to be a millionaire?” machines that you get in pubs so that when the citizen enters the polling booth the app asks three quick questions and gives them a few seconds to answer each. These would be general knowledge questions of political economy. Nothing too vexing: just basic questions such as “who is the Chancellor of the Exchequer”, “how much does a pint of milk cost in Tesco today” and “what proportion of government spending goes on welfare”. That kind of thing. Each question would be multiple choice and the citizen would have a few seconds to answer. We might even have the system award some prizes to people who answer all three questions correctly in the shortest time.

The e-vote would be cast as normal, but with the twist that the vote would have appended the number of questions that the citizen answered correctly, and only those votes with a at least two out of the three questions answered correctly would be counted. This would hopefully incentivise citizens to read an occasional newspaper or watch the news on television from time.

The Continuous Vote

If people become more informed, that is a good thing but we still need to encourage them to exercise their democratic right. With an electronic voting system, there’s no real reason to restrict voting to a limited time or to specific places. The suggestion that the UK should look at the option of advance voting to allow people to cast their vote in secret at specified locations during a designated period prior to voting day (Electoral fraud in the UK–Èvidence and issues paper 2013) has already been made. But what about the places?

Electronic or otherwise, voting must be a public act otherwise we face the insurmountable barrier of coercion. There is no reason, however, for it to be in polling stations. What about using Post Office counters or bank branches? Surely it would be much cheaper to pay the Post Office or the banks £1 per vote cast than to spend the close to £100m that a general election costs now (and that doesn’t include the disruption caused by closed schools and so forth).

So, perhaps elections could take a week. Any time during that week, a citizen can pop into a bank branch and cast a vote at the counter. After all, the machine in the polling booth would just be, in essence, another mobile phone so the tellers at the bank branches could just as easily use them. I would let citizens change their mind as well. If I pop in and vote for the Monster Raving Loony Party on Monday but then on Wednesday change my mind and pop in and vote for the Communist Party of Great Britain (Marxist-Leninist branch), or indeed change my mind ten times during the course of the week, then only my last vote would count.

The Transferable Vote

This kind of scheme ought also to provide a solution to the problem of proxy voting. This provides an alternative method of voting for those who are unable to vote in person in a polling station for reasons such as illness, disability, vacations, living overseas or serving in the armed forces, and who may appoint a proxy in advance to vote on their behalf. So I can’t vote, but I can pass my vote to my sister and she can go and vote for me.

Therefore votes have to be transferable.

Noting the common heritage of the kind of e-voting scheme assumed here and Bitcoin induces another thought experiment. If votes become a bit like Bitcoins, then why can citizens transfer them? There’s no reason why we couldn’t find a way to allow the voting app to transfer votes from one app to another. We could decide that it’s allowable under certain circumstances. I don’t think it would benefit society to allow “P2P” transfers because we’re trying to get away from the corruption attendant on for example postal votes. We don’t want husbands to be else to force their wives to transfer their votes to them any more than we want husbands to be to force their wives to accept their driving licence points for speeding. But we might allow authorised exchanges, whereby citizens transfer their votes to registered organisations.

Suppose, for example, that I find the democratic process confusing and exhausting. I know little about politics and genuinely don’t know who to vote for. But I like Greenpeace, and I trust them to make the right choices on my behalf, so I’ll pass my vote to them. I’d suggest that organisational votes are not blinded, so that in the pursuit of transparency anyone could log in and see where the Greenpeace votes went.

You can see how this might work in combination with social networking to create a kind of citizen engagement in the political process that makes sense. You might, for example, a Facebook campaign against, oh I don’t know, franking underneath the Surrey Downs. At the moment the best that a committed activist can do is write letters to The Guardian, but under a transferable vote system they could set about trying to collect votes for their campaign and then donate those votes en bloc to a politician who shares their distaste for inexpensive, local energy supplies.

Treating. A person is guilty of treating if either before, during or after an election they directly or indirectly give or provide any food, drink, entertainment or provision to corruptly influence any voter to vote or refrain from voting. Treating requires a corrupt intent – it does not apply to ordinary hospitality.

Definition from the UK Electoral Commission.

This triggers a final speculation. Under English law, political parties are not allowed to “treat” individual voters. Thus is my local Tory candidate were to offer me a bottle of champagne for voting for him, he would go to jail (although, oddly, not if he offered my favourite elderflower squash, because the law on treating only covers alcoholic beverages). It is, however, entirely acceptable to treat groups of voters. A political party can say to pensioners, for example “vote for us and we will loot the future prosperity of the nation’s youth in order to excuse you from contributing more to care costs” and that is fine. This is buying votes in a non-transparent way, but it’s still buying votes.

I think a more transparent approach would be better for democracy. So why not just take your transferable vote and put it on eBay? If I don’t feel strongly enough one way or the other on any issue, I might just choose to sell my vote — in an entirely above board and transparent way — rather than donate it to the English Defence League. Again, I would suggest that whereas the votes of individuals are blinded, the votes of purchasers (whether individuals or organisations) are not, so that it is a matter of public record as to how much was paid for each vote and to which candidate the vote was given.

So where next?

I think we have the technology. We have cryptography, mobile phones and biometrics. We can build a better voting system. But what should we use it for? What are the priority problems that we should be tackling first? In the UK, I think it is remote voting that stands out.

One of the biggest problems with postal votes is that they don’t guarantee you a secret ballot.

[From Mary Ann Sieghart: How dodgy postal votes may decide our next government – Mary Ann Sieghart – Commentators – The Independent]

That is not the only problem though. Our manual, paper-based electoral system is open to fraud at many levels. A random search of the UK newspapers for this month find this:

Nasreen Akhtar, who was a polling station clerk at the Madeley Centre Polling Station, in Arboretum Ward, yesterday admitted helping her nieces, Tameena Ali and Samra Ali, to cast fraudulent votes by pretending to be someone else. Tameena Ali cast her vote for the Labour candidate, Gulfraz Nawaz, in the name of Noshiela Maqsood, who is no relation, whereas Samra Ali left before marking the ballot paper. Maqsood, 24, then lied to police, saying she had personally voted.

[From Women admit election fraud | This is Derbyshire]

We (technologists) need to come up with a solution that makes this sort of thing impossible. Or at least detectable.  But with all of these problems, where do we start? According to an article in the 18th May 2013 edition of The Spectator (“My vision for Eurovision”, p.20), in Azerbaijan the Baku police tracked down and questioned people who used their mobile phones to vote for Armenia in the Eurovision song contest. This gave me a brilliant idea: why not use Eurovision as a testbed for secure electronic voting technologies?

Remote voting is a real issue in the UK right now and it is one of the key problems that electronic voting is supposed to solve. So let’s make the next Eurovision song contest a testament to British creativity, problem-solving and algorithmic excellence rather than a testament to our song writing. If we can create a world where people in Baku can cast a vote for [insert name of popular beat combo here] in safety and confidence, we will have achieved something.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Tesco in the frontline war on… what?

Greyscale backing image
[Dave Birch] I travel a lot for work at the moment. Normally, when visiting a technologically-advanced nation (such as the Netherlands or the USA) I don’t bother with cash any more. I just use cards. In America I used to use a pre-paid US dollar card for incidentals, but now I have a Simple account so I just use my Simple sort-of-debit-card. I have a pre-paid euro card for use on the continent. These suffice. However, when I had recent occasion to visit the south of France I thought I’d better get some cash in advance since there, in the heartland of the NFC payment revolution, you can’t even use a card in a taxi, let alone a mobile phone.

For unusual reasons, we happened to pop into a Tesco superstore the day before I was off on my trip and on the way out I noticed the Tesco Currency Exchange. This jogged my memory so I said to the family “hold on, I’ll just nip and get some euros”. I presented my chip and PIN card to the cashier and asked for a hundred euros. The friendly lady clerk offered 120 euros for £105, a bargain was struck and I went to put my card in the terminal. At which point I was asked for ID. I couldn’t help but ask why, even though I knew perfectly well what the answer would be: “it’s the rules”. So I showed my driving licence. But she asked me to hand it over, so I took it out of my wallet and gave her both the chip and PIN card and the licence and then watched while she copied (by hand) my driving licence details on to her copy of the till receipt. What on Earth for?

If I’d gone to an ATM at Heathrow and drawn out a hundred euros, I wouldn’t have had to show my ID or fill out a form or whatever else. I’m genuinely baffled as to why the government should waste my time and Tesco’s money on the nonsense of ID “verification” (it wasn’t verified of course, since the clerk had no way of checking whether driving licence was mine – or even whether it was real at all) for a transaction this small. Does anyone have any theories about this? Is there something in the psychology of international money launderers that means that they are known to avoid ATMs and are therefore vulnerable to clever traps set for them at in-store exchanges? Is there a government policy against in-store currency exchanges?

At first I thought that international gangs of terrorist drug-dealing money-launderers might have targeted Tesco and that by sending out hundreds of smurfs to obtain €100 in each branch of Tesco in the United Kingdom, over a period of some months, they might amass a suitcase full of €500 notes to ship abroad in furtherance of their nefarious plans. But I think, on reflection, that it was a pointless and money-wasting irrelevance, because it turns out that the drug-dealing money-laundering terrorists will always find a cheaper and quicker mechanism for transferring funds across international borders.

One law enforcement official told The New York Times that Liberty Reserve (*), which allowed users to transfer large sums money without ever identifying themselves, was “really PayPal for criminals”.

[From Founders of ‘PayPal for criminals’ Liberty Reserve are charged with money laundering – Americas – World – The Independent]

So. It’s ridiculous to make me jump through hoops to get €100 at Tesco and it’s ridiculous that people can send arbitrarily large amounts of money anonymously. Hence there must be a balance somewhere. But what is the right balance? Since €500 is the largest denomination banknote printed by the European Central Bank (ECB) it is probably a good psychological breakpoint. If you want less than €500 in cash, whether in Tesco or at an ATM you should be able to use your ATM card to get it. If you want more than €500 in cash, then you should have to produce identity documents and have the details recorded. If you want more than €10,000 in cash… well, you can’t. Over €10,000 should be electronic-only.

By the way: if I were an international law enforcement officer, I might have been very tempted to take over Liberty Reserve rather than shut it down, because the ability to monitor criminal flows — irrespective of whether you know the “real” identity of the counterparties — might be rather valuable. Forcing the bad guys back into cash may not be the optimal law enforcement strategy. Instead of encouraging me to blow off Tesco and use the ATM in Nice instead, surely the forces of law and order should be looking at making it easier for me to get one of those prepaid Euro cards.

Finally, prepaid cards leave records. They allow transactions be traced. Most criminals want to be able to take their money and disappear off the radar, not leave tracks across several countries.

[From Scanning Prepaid Cards At The Border Won’t Stop Money Laundering – PaymentsJournal]

This is a critical point. As I’ve consistently argued across a spectrum of new cash-replacement technology options, and especially in the case of mobile payments, law enforcement agencies should be doing what they can, working in partnership with the central banks, to reduce the amount of cash in circulation and persuade criminals to switch away from cash. Erecting high KYC/AML barriers to low-value prepaid accounts, or to getting a miserable €100 from the in-store currency exchange, raises everyone’s cost, reinforces social exclusion, does not affect criminals in the slightest and has no law enforcement benefits. If anyone has some figures from a reputable source to demonstrate the contrary, I would be more than happy to link to them.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

The Indian experiment is not for us

Greyscale backing image
[Dave Birch] When it comes to online business in general and online finance in particular, the issue of identification and authentication continues to form a barrier to innovation and efficiency. There are different ways to approach this problem, and one of them is to have the government provide identity infrastructure as a public good designed to benefit the whole economy. Some countries do not have national identity schemes that might form a basis for this kind of cross-sector solution. The UK is one of them. What would it be like to develop one? We have a fascinating case study evolving in front of us. India is engaged in a gigantic experiment to create a national identity scheme for more than a billion people, from scratch. It is called the “Aadhaar” scheme and it involves giving a 12-digit individual identification number to citizens. The numbers are issued by the UIDAI (Unique Identification Authority of India) and they are stored against the citizen’s biometrics. The June 2013 edition of Prospect magazine has a piece on this called “Twelve billion fingerprints”, in which a chap in Mumbai puts a plastic copy of his wife’s fingerprint over his own finger and uses it to fool a biometric reader, thus highlighting some worries about the chosen technology architecture. Nevertheless, the article also notes that the potential benefits to the Indian economy are significant, because businesses of all kinds can use the identity infrastructure to greatly reduce costs.

Market regulator Sebi today said investors can use ‘Aadhaar’ cards as a valid address proof for their accounts with brokerage firms, mutual funds, portfolio managers and other capital market entities. [It] is already permitted as a valid identity proof document in the capital market.

[From Aadhaar OK as investor ID proof: Sebi]

Obviously, for this identification scheme to be of most use to business, there must be a way for banks to validate the identification numbers that are presented by customers. This process is going to be automated.

The Unique Identification Authority of India (UIDAI) is creating software that will interface between banks and the Aadhaar portal so that banks can directly access Aadhaar details.

[From ​Banks to get Aadhaar data – The Times of India]

Given the intimate relationship between social and financial inclusion, one of the most important effects of “identity inclusion” is that the financially-excluded are now given an hand on to the first steps of the financial inclusion “ladder”. It is wrong to think of this first step as a bank account as we so often do in Europe. (indeed, the European Commission are proposing to legislate on the right to a bank account even as I write) because for a great many unbanked people, or for that matter, overbanked people, the first step is a simple prepaid transaction account. India is already taking the obvious next step to integrate identity and money infrastructures by providing just such transaction accounts that can be linked with the Aadhaar scheme.

The pre-paid card, the first in the country based on Aadhaar, will be available in the National Capital Region (NCR) and will work like a mobile pre-paid card that can be topped up in the identified banks [SBI, ICICI, Axis, HDFC, Indian Overseas Bank enabling] any resident with an Aadhaar number to walk into the identified 100 outlets by these banks and open a prepaid account with a card.

[From Soon, get prepaid cards for bank account based on Aadhaar number – Economic Times]

Now, there is of course are risks in system that uses a single centralised database in this way. In the fake fingerprint example given above, the risk is that you can pretend to be someone else. But there’s a much bigger risk. Once you can get a fake entry into the database then you are “behind the wire” so to speak, and your fake identity will never be challenged. This has already happened in the Indian system.

Some have managed to beat the so-called unbeatable Unique Identification (UID) system and got fake Aadhaar numbers generated raising security concerns over UPA’s new UID based governance model.

[From UIDAI cancels 3.84 lakh fake Aadhaar numbers – Hindustan Times]

There are a variety of ways to get on to the database fraudulently but one mechanism that seems to have been exploited right from the beginning is the exception handling. Given any system of this scale, the human factor must come in to play. Since it is not possible to register everyone through the normal channel (e.g., disabled people without fingerprints, people in the witness protection programme, spies and so on) there must be exception channels and these become an attack vector.

Delhi government officials have detected a large number of fraudulent enrolments in the first phase of Aadhaar that ended in February after registering 1.3 crore people in the city. Officials in the Unique Identification Authority of India (UIDAI) said on Monday many people got themselves enrolled without providing their biometric identification. The “biometric exception” clause is essentially meant for rarest-of-the-rare cases, say, for people with high degree of physical disabilities, they said.

[From Fake enrolments in Aadhaar Phase-I spark security fear]

This sort of thing is inevitable in such a scheme. But there’s another problem with centralisation: it creates a “honeypot” for personal data. And, again, the theft of this data is hardly a hypothetical.

Biometric information from over 14 lakh people has gone missing. This could lead to vital data falling into criminal hands.

[From Biometric information of 14 lakh Aadhar applicants goes missing : Postnoon]

It’s not for me to say whether the benefits of the Aadhar outweigh the risks, since I genuinely do not know. But what I would day is that this architecture is not right for the UK or the USA. The better architecture is to have very strong authentication against a revocable token (e.g., a smartphone) and use different biometrics in the central database purely for the purposes of eliminating duplicates. The central database is there to ensure unique identities, but the transactional authentication is against the token. Without going into all of the reasons why (OK, here’s one: undercover police officers must be able to have two tokens, one for their police identity and one for their undercover identity), the more decentralised option provides simultaneously more security and more privacy. When the UK comes (as it inevitably will) to require some kind of “entitlement card”, then I hope that it chooses that option.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Necessity is the mother of identity

Greyscale backing image

[Dave Birch] This is a blog about electronic transactions, not politics, and I do not want to be accused of introducing a political perspective. But I think it is fair to observe that there are tensions in trying to balance the free movement of people within the European Union and the exigencies of a collapsing welfare state. I mention this only because I want to discuss the practicalities of identifying and authenticating people for the purposes of distributing welfare benefits. And, to avoid any suggestion of parochialism, let me start by noting that this is not a specifically British problem.

Once in the Netherlands, the Bulgarians registered as residents at addresses rented by accomplices, and then applied for rent and child-support subsidies. They were able to open Dutch bank accounts to receive the social subsidies, and then to return to Bulgaria and withdraw money from cash machines. The ringleaders took a cut of the proceeds.

[From Dutch uproar over Bulgarian benefit fraud – FT.com]

The best part of this story, by the way, is in the denouement. The fraud was not uncovered, as you might have thought, by diligent investigation on behalf of Dutch taxpayers or the sophisticated quantum-computing anti-fraud neural network super-computer cluster at the Dutch DWP "Big Data" analysis centre…

The fraud came to light when some villagers complained to Bulgarian police that they had not received payments they had been promised as part of the schemes.

[From Dutch uproar over Bulgarian benefit fraud – FT.com]

In Britain, the mounting panic over immigration and its relationship with welfare distribution is leading to what some observers have labelled knee-jerk irrationality. In particular, the minister "in charge of" the National Health Service (NHS) has found himself caught up a bit of row about all this sort of thing, between the scylla of ill-informed public outrage and the charbydis of soundbite politics. The minister, Jeremy Hunt, is responsible for

a new ‘do-it-yourself’ immigration law unveiled today as the centrepiece of the Queen’s Speech. It will require GPs, hospital staff and landlords to police the new legislation.

[From The Queen's Speech: Immigration Bill passes buck to doctors and buy-to-let landlords | News | The Week UK]

How a doctor or a landlord is supposed to determine who I am or what my immigration status might be I haven't the slightest idea. And if I were a landlord, I'm not sure I'd care. If someone turns up with a birth certificate (that I cannot possibly verify) showing me they were born in the UK or a Bulgarian passport (that I cannot possibly verify) telling me they are an EU citizen, I can just tick a box to say that I've seen the documents and I'm off the hook.

So what has this to do with thought leadership in secure electronic transactions? Well, there is an inevitable destination on the badly-folded roadmap in the hands of the government. The fundamental British distaste for state identity documentation (which I share) prevents rational discussion on the topic, but the truth is, in true tabloid headline style, "something must be done". Identity is a mess, and it's getting worse. In our world of retail transactions, identity is a cost and a source of chaos and frustration. But, clearly, since we still log in to our home banking and shopping services using email addresses and passwords just as we did fifteen years ago, the problem isn't bad enough to warrant concerted action. I wonder, however, if access to welfare might turn out to be the fraud straw that broke the identity camel's back, so to speak.

British citizens could be forced to carry ID cards to access free NHS care as part of crackdown on health tourism

[From British citizens could be forced to carry ID cards to access free NHS care as part of crackdown on health tourism | Mail Online]

This is not, as it happens, what the Mail's own story actually says. The story refers to an "entitlement card". There is a great difference between the two. For those not versed in the recent history of the UK's catastrophic attempts to introduce an ID card, let me simply highlight that when the then-Labour government introduced the idea of entitlement card in 2002 (Consult Hyperion were one of the organisations that responded to this consultation process – not that anyone ever paid any attention whatsoever), I thought it might be an opportunity to introduce a key Privacy-Enhancing Technology (PET) infrastructure for the new millennium and was rather in favour of the idea. The government, though, eventually abandoned the entitlement card idea. The Home Office under David Blunkett decided to introduce an identity card instead and in 2004 awarded a contract to PA Consulting as the "development partners" for such a scheme. This, which is what people are referring to when they talk about the "UK ID card", was eventually abandoned in 2008.

It was flawed from the start, and as a showcase for the British technology industry, it was an embarrassment: it provided none of the services that the identity cards systems in advanced nations (eg, Germany, Hong Kong, Estonia) provide and there was never any evidence that it would do so.

[From Digital Identity: Back to the future of the ID card]

When I was asked to give evidence to the House of Commons Science and Technology Committee in 2006, I thought that the clear distinction between an entitlement card (good thing) and an identity card (not a good thing) might persuade the government to change direction and go back to the original Home Office vision. A properly-implemented entitlement card could be a key way to provide privacy in an online age, because it would shift the standard mental model of the citizen-state nexus from "who are you" to "what are you entitled to" with identity removed from many transactions completely. All water under the bridge now.

Meanwhile, across some other water, our neighbours in Eire had decided that an entitlement card was the right way forward and they began to draw up plans for what became known as the Public Service Card. (Before the e-mails pour in, let me be transparent: Consult Hyperion are consultants to the Irish government on this project.) The card went live last year and is seen by the Irish government as an essential component of its campaign not only to reduce welfare fraud but to deliver efficient electronic government. They are looking at extending its use in a number of directions.

The Department of Health is in discussion with the Department of Social Protection, The HSE and the Department of Public Expenditure and Reform on using PSC infrastructure in support of a health Identifier.

[From e-Government Reporting]

One obvious and privacy-centric way to do this is to use a cryptographically-strong one-way function to generate the health identifier from the PSC identifier (e.g., by hashing) so that when a citizen presents a PSC it always connects to the correct health records but if bad guys get into the health records they can't get back to the PSC identifier. These are well-known techniques and, to be honest, no different to the suggestions around entitlement cards that we made to the British government back in 2002.

My point is that it can only be a matter of time before UK has to introduce a similar kind of entitlement card, so doesn't it make sense to begin a sensible and measured planning process for this now — using the Cabinet Office Identity Assurance (IDA) framework — instead of being panicked into buying some sub-optimal collection from vendors at the last minute? Rather than build an electronic identity system that embodies the concepts and values of physical identity cards from a generation ago, surely it is better to design a fit for purpose identity infrastructure for the 21st-century and then provide physical smart cards that implement it. In this model, the privacy broker in the smart card and the mobile phone, watch or hat would be no different and the ubiquitous, standardised deployment ought to trigger the rapid evolution of value-added services on top of that basic infrastructure.

I don't want the government to develop some nutty jumbo IT system to help landlords, or doctors or anyone else. I want an infrastructure. The entitlement card concept from 2002 deserves to be brought out of the cupboard and dusted off and (with Consult Hyperion's response to the consultation taken as the core specification document) and then the implementation can re-architected for the new world of mobile phones, identity assurance and the interweb tubes.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

What’s your e-mail address? Don’t tell him pike@homeguard.org.uk!

Greyscale backing image
[Dave Birch] On this sceptred isle we’re not too bothered about North Korean cyberattacks because we are going to fight them on the breaches, in the upmystreet.co.uk and in the e-fields. We shall never surrender. Who do you think you are kidding Mr. Kim Jong Un?

A Home Guard inspired Dad’s Army of computer security experts will be set up to protect Britain’s businesses and help the armed forces at times of national emergency, it has emerged today.

[From ‘Dad’s Army’ of cyber security experts to be formed to tackle growing threat of website hackers in Britain | Mail Online]

This does, at least, open up the possibility of some continued employment for me as I fight to stave off the cat food years in amongst the embers of post-employment Europe. But hold on. Just how bad is the cybersecurity situation? We are all used to reading statistics about the size of the problem (I seem to recall that Detica estimated it to be £27 billion in the UK) but let’s go and find out what the top people think about it. I imagine the head of the US National Security Agency would know.

Gen. Keith Alexander is the director of the National Security Agency and oversees U.S. Cyber Comman… he cited statistics from, among other sources, Symantec Corp. and McAfee Inc., which both sell software to protect computers from hackers. Crediting Symantec, he said the theft of intellectual property costs American companies $250 billion a year. He also mentioned a McAfee estimate that the global cost of cybercrime is $1 trillion.

[From Does Cybercrime Really Cost $1 Trillion? | Threat Level | Wired.com]

Wow. A trillion. What kind of crimes are racking up these numbers? Tidal waves of cybercriminals looting bank vaults? Could be. But it would take teams of cybercriminals working round the clock on their trivial $45m ATM raids to get anywhere near this figure. Redirecting flows of cash from their rightful owners to Mafia oligarchs safe behind their computer screens? That would be hard to distinguish from regular investment banking. On the whole, it turns out that putting a number on cybercrime seems to involve a bit of interpretation. To see what I mean, consider the example of a cybercrime that I heard discussed at a forum on the issue recently.

Blooomberg reveals that the hackers spent one month “pilfering sensitive files” about Coca-Cola’s attempt to acquire China Huiyuan Juice Group for $2.4 billion. If successful, the transaction would have been the largest foreign takeover of a Chinese company ever. The breach started with malware-infected e-mails to Coca-Cola’s senior executives which, when opened, enabled the hackers to infiltrate the network and steal proprietary information. Once revealed, the Huiyuan deal collapsed three days later.

[From Coke Cyber-Attack Raises Corporate Disclosure Issues]

That sounds terrible. A successful cyber-attack on a multinational and a billion dollar deal collapses. I thought this might make a useful case study in a workshop with a client, so I decided to investigate a little further. And I found that the “cyber-attack” was not as clear-cut as it seemed.

But some investors were relieved that the offer didn’t go through. Coke had said the acquisition would dilute earnings by three cents to four cents a share for the first full year after completion of the deal.

[From Beijing Thwarts Coke’s Takeover Bid – WSJ.com]

There may have been no cyberattack at all! It may have been the company’s own shareholders working through incumbent management. Now, I am not for one moment saying that there are no real cyberattacks. Clearly there are and some of them a considerably more serious than a few percent different in a share price.

The Moscow-based firm said it found Gauss had infected personal computers in Lebanon, Israel and the Palestinian Territories. It declined to speculate on who was behind the virus but said it was related to Stuxnet and two other cyber espionage tools, Flame and Duqu… According to Kaspersky Lab, Gauss can steal Internet browser passwords and other data, send information about system configurations, steal credentials for accessing banking systems in the Middle East, and hijack login information for social networking sites, email and instant messaging accounts.

[From Virus found in Mideast can spy on finance transactions | Reuters]

Cyberattacks are real. Cyberwarfare is real. Yes, companies should be designing and implementing more robust infrastructure and using sensible risk analysis methodologies to determine levels of exposure and appropriate countermeasures (as you would expect me to say, since this is precisely what Consult Hyperion does for payment organisations and others). But wee have to be a little cautious in responding to the trillion dollar cybercrimewave, even if it actually does exist. We don’t want to fall into knee-jerk responses that might end up making the problem worse.

A number of countries, including Russia and China, have put forward proposals to regulate aspects of the Internet like “crime” and “security” that are currently unregulated at the global level due to lack of international consensus over what those terms actually mean or over how to balance enforcement with the protection of citizens’ rights.

[From The United Nations and the Internet: It’s Complicated – By Rebecca MacKinnon | Foreign Policy]

All of which suggests to me that the problem might require something more infrastructural than a bunch of old duffers like me fiddling about with laptops in the snug. We need business to work with government to do something about it and I think that a high-level commitment to a sensible identity infrastructure might be a place to start. The longer we persist in messing around with passwords and similar pseudo-security, the more the mysterious foreign viruses will attack. One of this year’s Economist “top ten” global trends for business leaders to factor into their strategies this year is cybersecurity.

Cyberspace is the new frontline for security. Knowledge and information is a source of competitive advantage for organizations, nations and individuals. But it’s a growing challenge to retain control as mobility and the democratization of everything (commerce, politics and societies) increases – along with cybercrime and cyber war. Look for a rising tide of litigation, policies and regulation. Digital freedom or a “big brother” society?

[From Global trends for 2013: A top ten for business leaders | The Economist]

I don’t think it’s an entirely accurate dichotomy but you can see the idea they are getting at. One the one hand there are people who think that people should be able to communicate freely over the open public internet and the other hand there are those who want to control, spy on and censor inter-personal communications: the Icelandic government, Sony UKHillary Clinton and me for example (although I want to do it in a better way). Time for some better informed public discussion, I think, and a rational debate about what to do about cybersecurity.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Biometric tick

Greyscale backing image
[Dave Birch] In “Banking the World — Empirical Foundations of Financial Inclusion” by Cull et al, there is a very interesting case study on the use of fingerprinting to manage credit and repayments amongst farmers in Malawi. In Chapter 13, “Use of Biometric Technology in Developing Countries” by X. Gine, J. Goldberg, S. Sankaranarayanan, P. Sheerin and D. Yang, the authors describe how biometric technology worked in practice in a field experiment amongst paprika farmers who had applied for an agricultural loan from a government lender. The farmers were randomly allocated between a control group and an experimental group who had a fingerprint collected as part of the loan application process. Fingerprint recognition was chosen because it was cost-effective and reasonably robust in the circumstances. Despite the farmers having worn and damaged fingerprints, as you might imagine, only 2% failed to enrol with the right thumb and had to use another finger instead.

The study showed that fingerprinting led to increases in the loan repayment rate of almost half amongst the highest risk groups, but had no impact on the repayment rate amongst the low-risk groups. What an interesting result. The authors cite a rough cost-benefit analysis of the experiment which suggested that the benefits of improved repayments greatly outweighed the costs of equipment and fingerprint collection. In both the high- and low-risk groups though, the farmers now had a biometrically-verifiable credit history. Having a basic credit history is, as we all know, are really important step on the ladder of financial inclusion with very beneficial effects.

The authors also noted, however, that fingerprints aren’t tremendously accurate. If you’re going to use fingerprints to identify people from a large population this could be a big problem. On the other hand if you are authenticating people against a card (or a phone, for example) from a smaller population such as farmers who have obtained agricultural input loans in a particular district, then the speed and convenience of the fingerprint authentication make it a reasonable choice. Once you start messing around with fingerprints at population scale, then the cost and complexity rides astronomically.

Police zeroed in on Afsar after UIDAI confirmed that all the authorization fingerprints used for the enrollment of the 60 persons in biometric exception category were his. Afsar, who used to work as a data entry operator with IL&FS, had quit the job in August 2011.

[From Seven booked in Aadhaar fraud – Times Of India]

What I’m saying here is that fingerprints for authentication, in context as a convenience technology, provide what seems to be a much better cost-benefit balance than fingerprints for identification, in context as a security technology. The convenience point is at the heart of the mass market proposition, and it is undoubtedly why Apple decided to take a look at the technology*.

“Apple is not going to the trouble of adding a biometric sensor just so that you don’t have to use a four digit password. They are adding a biometric sensor so that the iPhone can become a safe and secure payment device,”

[From Some Ideas for What Apple Could do With Its AuthenTec Purchase – Technology – The Atlantic Wire]

No, they are adding a biometric sensor so that the iPhone can become a safe and secure identity management device, and one kind of identity it will manage will be financial, and one kind of financial identity will be payments. Apple understands the location of biometrics in the consumer space: convenience, and Apple is all about convenience. Remember, these iPhones aren’t going to be used to launch nuclear missiles or identity people in databases: these iPhones are going to be used to 1-1 local matching of fingerprints to stored templates to authenticate amongst persona. I think one of the first blog posts I ever wrote was about this!

* A couple of weeks before this Apple announcement, which I knew nothing about, I was interviewed for a television programme and I confidently predicted that fingerprint authentication would make its way into the next generation of mobile phones and — for reasons too boring to go into here — specifically mentioned Authentec as supplier of decent kit in the fingerprint authentication field. So I got to big up Authentec on a television programme a couple of weeks before Apple bought them for a few hundred million dollars and made me look like a guru. Thanks Apple!

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

I bet including Katie Price in this story about identity will drive up the hits

Greyscale backing image
[Dave Birch] I found an old post that I’d written in draft over a year ago, but never got round to post. I thought it made some interesting points, so I hope no-one will mind me positing it a little late!

You might well ask why misery guts like me keep going on about identity infrastructure in our cold, calculating plan to impinge on the gaiety of the nation by consigning stories like this to the dustbin of history.

A transsexual Jordan fan who stalked the glamour model is facing jail after admitting to stealing thousands of pounds from [Katie Price] using identity theft. Kerry Marshall, 18, who is currently undergoing a sex change to become a woman, managed to con a series of bank tellers into believing she was the television star.

[From Teenage transsexual tricked bank staff into thinking she was Katie Price to steal thousands of pounds from the model | Mail Online]

Amazing. Absolutely amazing. Note for foreign viewers: “Katie Price” is the pseudonym of a female English topless glamour model called Jordan. She is famous for having enormous fake breasts and better known to the average Brit than the Prime Minister (you think I’m joking – sadly I’m not), which is why the story is so staggering. Although I would be hard pressed to tell Jordan from last year’s Big Brother runner-up or employee of the month at Spearmint Rhino, you would have thought that bank staff charged with KYC responsibilities might have done a little better.

But then perhaps I’m being too harsh. Even when you make people jump through hoops to “prove” who they are (in the absence of any actual working identity infrastructure), you can still get it wrong.

the administrator of an account allegedly belonging to Wendi Deng Murdoch, which briefly received the Verified Badge after launching on Sunday, admitted that she was not, in fact, the wife of News Corp. Chairman and CEO Rupert Murdoch

[From Fake Wendi Deng account casts doubt on Twitter verification | FP Passport]

I’d be very suspicious of someone claiming to be a famous Chinese person tweeting from China — for one thing, Twitter is banned — and I’m not condoning pretending to be other people (although I wholly condone pseudonymous access). In fact, giving a fake name may sometimes have disastrous consequences, especially in environments where semi-automated systems are put on top of an unsuitable infrastructure. And it’s by no means clear that biometrics are a help here.

She gave Houston police a fake name. When police in Houston ran that name, it belonged to a 22-year-old illegal immigrant from Colombia, who had warrants for her arrest… News 8 has learned [officials] took the girl’s fingerprints, but somehow didn’t confirm her identity and deported her to Colombia, where the Colombian government gave her a work card and released her.

[From Dallas teen missing since 2010 was mistakenly deported | wfaa.com Dallas – Fort Worth]

Reading this reminded me, as so many stories about identity, of the fabulous Terry Gilliam film “Brazil“. There’s a big difference between using a false identity, using a pseudonym and using multiple identities. I must say, I have occasionally been tempted to use a false identity, generally in the queue for immigration at Heathrow airport. I thought that claiming to be an asylum seeker from the Caucasus and getting myself sent to the Home Office in Croydon might be quicker than waiting in line.

Alvarado told Salt Lake City police, a Utah state courts judge and federal immigration officials that he was actually Saul Quiroz and had emigrated from Mexico illegally. At the time, Alvarado was facing up to 15 years in prison for the possession of cocaine and heroin with the intent to distribute. Instead of going to prison, Alvarado was deported to Mexico based on his false identity, according to court records. But he then returned to the United States using his American passport

[From Man Avoids Jail By Faking Illegal Immigrant Status | Fox News]

Maybe the thing to do is to fingerprint everyone entering the US. After all, Japan is very happy with its system for fingerprinting non-citizens.

As a result of the collection of this personal data, which began at the inception of this program, the number of foreigners who were issued deportation orders or became targets for the implementation of compulsory deportation orders exceeded 1,600 before the end of February 2010.

[From Fingerprint all Japanese, for safety’s sake | The Japan Times Online]

Oh wait, I just remembered that the US does fingerprint all of us foreigners who enter the country.

A doctor from the Dominican Republic was convicted and sentenced in Boston on Thursday of offering to surgically alter the fingerprints of illegal aliens, the Department of Justice said.

[From Doctor convicted of surgery to alter immigrant fingerprints | Reuters]

As a corollary, if you did base security on fingerprinting everyone entering the US, you would naturally be very suspicious of anyone who didn’t have one, and suspect them to be a drug-smuggler from the Dominican republic.

A cancer patient was detained for hours at the US Customs because a cancer drug he was taking had caused his fingerprints to disappear.

[From The curious case of the missing fingerprints]

I know, I know, these are rare cases. As a general rule, the easiest way to stop people from impersonating famous topless models and accessing their bank account is not, as deluded technologists might think, to have a working financial services identity infrastructure with federated identity and two-factor authentication, but to demand biometric identification documentation. Not that the bank can either verify it or even assess whether it is real or not.

A German manager with Mercedes-Benz is free after being arrested for not having a driver’s license with him under Alabama’s new law targeting illegal immigrants… an officer stopped a rental vehicle for not having a tag Wednesday night and asked the driver for his license. The man only had a German identification card, so he was arrested and taken to police headquarters, Anderson said.

[From Mercedes manager from Germany arrested on Alabama immigration charge | timesfreepress.com]

Funny. But how would a US bank verify a German ID card or a UK bank verify a US driving licence? The answer is, of course, that they don’t. The take a photocopy of the biometrics identity document in order to comply with KYC regulations and then put it in a file somewhere.

Setting aside Jordan, Mexican immigrants and Dominican finger fakers, we really do need to do something. I ran into a problem the other day in the US because I always leave my “valuable” documents locked up in the safe in my hotel – I never carry either my passport or driving licence around with me. For goodness’ sake, it isn’t North Korea. But I couldn’t buy something in a store because I was asked to show ID in order to use my credit card and I didn’t have any idea with me. There really is, as Adam Banks, the Visa Europe CTO said, a crisis in identity.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.