Social “hacks” are going to be replaced by computations across the social graph

Greyscale backing image
[Dave Birch] At this year’s South-by-Southwest Interactive (SXSW) in Austin, Texas, I went along to a session called “Identity + 30“, which was run by Sam Lessin, Head of the Identity Product Group at Facebook. The idea of the discussion was, if I understood it properly, not to be “right” about what identity would actually be a generation from now, but to create a framework for discussing identity now. Sam is a pretty interesting guy, and he got me thinking right from the start of his session, which I mean as a serious compliment, because to be completely honest this was not true of all the sessions I went to.

The core of his argument was that when sharing is expensive, or when it makes an individual less well-off, then people don’t share. Society has to deal with this, trade being the root of our prosperity, so it develops trust networks to connect more trading partners and collect more information about those trading partners. Sam had a useful way of thinking about this, which was the idea of what he called “social hacks” to deal with the historical problem that the speed of bits and the speed of atoms are different (I might disagree with the shape of his pseudo-graph, but I think his points hold). These hacks (diplomas, badges, dress codes and banking) help us to get by, but they are by no means optimal.

However, we now have what Sam called the “superpower” of being able to instantly communicate with anyone else on Earth so we will no longer need those hacks. I may be paraphrasing incorrectly, but I think his way of looking at the existing business models around identity as being hacks in response to incomplete identity, credential and reputation information is a good way of framing some problems and a very helpful way of exploring the solutions that new technology can present. I strongly agreed with his big picture technology roadmap and have written before about about the “William Gibson World” where all of the technologies that will have any impact on corporate strategies to any foreseeable horizon already exist, something I always emphasise when we are working on client roadmaps. The trick is to look out of the corner of your eye and see where the technologies are being used for purposes that might disrupt business models, not to imagine new technologies. Given my predilection for using Dr. Who as my design authority, I also enjoyed Sam’s choice of common culture SF narratives to describe the future! His view is that the current generation is moving toward a “Borg system” not a “Hal system”, so new business opportunities are about the mass sharing of structured data.

Anyway, on to some of Sam’s key points, all of which were excellent:

  1. Information will centralise and cluster. (APIs are better than protocols.)
  2. We will share a lot more about ourselves. (Economics, not culture, will dictate this.)
  3. Everywhere will become local. (“I want to go where everyone knows my name” Cheers-style.)
  4. Only poor people will own things. Rich people will just rent whatever they want.
  5. Social capital will get ever more fungible, so (for example) going to Harvard will mean less than it does now, which means that it will be worth less than it is now. You can see exactly where this headed. Just look at the way we use LinkedIn right now. In the old world, I would use the social hack of finding out which university your degree came from as a sort of proxy for things I might want to know about you, but I no longer need to do that because I can go via LinkedIn and find out if you are smart, a hard worker, a team player or whatever. So there’s no premium for you learning, say, biochemistry at UCL rather than Swindon Polytechnic: so long as you know the biochemistry, my hiring decision will be tied to your social graph.
  6. The cost of using social capital for transactional purposes will fall below the cost of trust intermediaries such as notes and coins, so there will be no need for cash any more. In other words, identity is the new money.

(When Sam put up that last point I nearly cried, because earlier this year I was commissioned to write a book on exactly that topic! I thought I was the only genius that had realised that trade based on social graphs would eliminate physical means of exchange, so now I am crushed. Back to the drawing board, even though I hadn’t actually drawn very much so far.)

The argument here is, to my mind, unanswerable. Suppose I am wandering through Woking market and I want to buy a doughnut. I give the trader £1. The trader doesn’t have to trust me, he only needs to trust the £1, and the cost of failing to detect that my £1 is a counterfeit is quite small (despite the large number of fake £1 coins in circulation in the UK) compared to the cost of establishing my trustworthiness and creditworthiness. Other traders deal with this problem by paying banks and card schemes to manage the problem for them, but this costs them money. But now I imagine that I wander up to the trader to buy a hot dog and through his Google Glasses my face is outlined in green, which means that the system recognises me and that I have good credit. The trader winks at me, and a message pops up on my phone informing me that I am being charged £1. I press “OK” and we go about our day.

More than £4m worth of fake one pound coins have been seized by detectives.

[From Police Seize Record Haul Of Counterfeit Coins – Yahoo! News UK]

Until the invention of the mobile phone and its connection with the interweb tubes, I think it was reasonable to assume that for small transactions there was no way of using identity, credentials and reputation in small transactions, which is why it made sense to continue to use notes and coins to settle retail transactions. But now? The replacement of notes and coins in this way all hinges on the trader recognising me. Once this has been achieved, the issue of trust can be instantly resolved by computations across the social graph. If I understood correctly, this is why Sam said that “trust & trade” is the layer above the basic “recognition & memory”.

Money is technologically equivalent to a primitive version of memory.
Kocherlakota, N. “Money is Memory”. Journal of Economic Theory 81, p.232-251(1998).

Is it possible to imagine a trust and trade layer based on the social graph rather than third-party credentials? Yes. I remember that at the excellent Nixon McInnes “Social in the City” seminar last year, Will McInnes made a really important point right at the beginning of the day. “Who do we trust”, he said. “We trust people like ourselves.” Quite. And I also remember that in the discussion on trust at the Digital Agenda for Europe Assembly for 2012, I got into a mild argument with someone in the break, because I said that the idea of sticking web badges on sites (“this is a trusted European e-commerce merchant” badge, as an example) was ridiculous, and a strangely Victorian approach to vetting tradespeople. We need those badges as a pre-networked society substitute for actual information about trust. (Clearly, what Sam would label a “social hack”.) Once the social graph enables you to determine trust, they don’t make any sense. Look at it this way. Why would I care whether a hotel has the “British Tourist Board Seal of Approval” (I’ve no idea whether this exists – I just made it up) when I can go on Trip Advisor to see what everyone thinks about it? Or, more especially, I can go and see what my friends, my work colleagues and in general, people like me think about it?

I don’t know about Sam’s thought experiment of New Jersey suburbs becoming cool, but I thoroughly enjoyed his session and greatly appreciated his window into the kind of thinking that is going on in Facebook.

Incidentally, Sam referred in passing to “peak cash”, which I thought was such a nice idea that I have sworn to plagiarise it mercilessly. I’m working on a blog post around this for next week sometime.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

Who’s calling?

Greyscale backing image
[Dave Birch] An interesting e-mail arrived today (the contents and counterparties are not relevant to this post) but it made me think about “real names” again. I have to get together a talk for developers at the Microsoft Digital Wallet Foundry, and I thought this might be a good topic. So I went back to my notes to see if I could find a fun “case study” to focus thinking around convenience and security in ID. I came across this.

As Sheryl Sandberg said this week, when caller ID first came out, it was declared a violation of privacy.

[From Fear For Your Safety, Not Your Privacy | TechCrunch]

That’s because caller ID is a violation of privacy. Which is why you can turn it off. If I’m phoning British Gas customer service, I can leave caller ID on and benefit from the efficiency that having my Calling Line Identifier (CLI) connect to their CRM brings. But if I’m phoning the council to complain about the crack house next door, then I might decide to remain anonymous and turn it off. If I want to avoid the near-contininous stream of calls from ambulance-chasing lawyers about PPI, I might want to screen incoming calls by CLI (although this is a useless strategy against spammers because they use international “out of area” codes). Bear in mind, too, that spoofing caller ID is trivial, so it doesn’t deliver any actual security. If it wasn’t trivial to spoof it, there would be no need for legislation such as

The Truth in Caller ID Act of 2009, which was signed into law Dec. 22, 2010, prohibits caller ID spoofing for the purposes of defrauding or otherwise causing harm.

[From Caller ID and Spoofing | FCC.gov]

Thanks goodness there’s a law against such spoofing, because it means that no-one does it. No, wait… that’s not really true. No one does it except for criminals who are, for example, spoofing bank numbers to make phishing attacks or in more sinister enterprises such as getting people raided by SWAT teams by making bogus emergency calls that appear to come from the victim’s address (“SWATting”). So I call the police using your home phone number in the caller ID and tell them that someone has gone postal in the house, at which point heavily armed law enforcement officials storm your house and (hopefully, from my point of view, shoot you). This just happened to the well-know blogger Brian Krebs.

His office phone rang while he was vacuuming, but he ignored it. That, it turns out, was an unfortunate choice, given that the call came from law enforcement who were trying to verify what would turn out to be a spoofed emergency call showing Krebs’s number on caller ID.

[From Hackers launch DDoS attack on security blogger’s site, send SWAT team to his home | Naked SecurityNaked Security]

In other words, CLI is about convenience. It doesn’t deliver security. Worse still, it delivers “anti-security” because people believe it delivers security when it doesn’t. CLI did develop an acceptable privacy settlement – since you can turn it off – and people started to use it despite the lack of security. I can’t be bothered to look, but I’m sure page 697 of my phone company terms and conditions says that I’m not allowed to spoof CLI.

“The name you use should be your real name as it would be listed on your credit card,” Facebook says.

[From Facebook’s fake-name fight grows as users skirt the rules | The Verge]

Why? It’s of no help to anyone: anyone except marketers who are being sold the data, that is. My friends know that Leadbelly Gutbucket is me, and so they friend me and we use and enjoy Facebook together (as I do, in fact). But the corporations don’t know that this is me, unless I choose to tell them. I don’t believe that any name I see on Facebook is real. How would Facebook know? They didn’t do an Experian check on me when I created my account.

“Pretending to be anything or anyone is not allowed.”

[From Facebook’s fake-name fight grows as users skirt the rules | The Verge]

This is a completely different point. And Facebook are completely right about this: you shouldn’t be able pretend to be anyone else. Personation is obviously wrong. For example, did you see the Italian “Catch me if you can” story? It is a super tale of fake identity updated for the modern age.

A man who posed as an airline pilot and traveled in the cockpit of at least one plane was arrested in Turin Airport using forged identity cards and wearing a pilot’s uniform… The 32-year-old, whose real name was not released, allegedly created a fake identity as a Lufthansa pilot named “Andrea Sirlo,” complete with a Facebook page that included fake flight attendant friends… The national military police tracked down the suspect from photos on his Facebook profile, in which he is shown posing in uniform and sunglasses in front of airplanes.

[From Fake Italian pilot traveled in cockpit, police say | Reuters]

But if I create a Facebook account in the name of David Beckham and then IM a transfer request demanding a move to Swindon Town, is that really impersonation or just a joke? One more point. The real names fuss is not a Facebook phenomenon and I don’t mean to suggest it is. If you want a non-Facebook example you need look no further than our own legislature.

an embarrassing photograph emerged which showed him wearing the name-tag ‘Michael Green’ – an alter ego used by the MP when posing as a self-help guru – at an internet conference in the US in 2004.

[From Maybe it’s because I’m a Watforder: ‘Double life’ Tory chief can’t decide if he was born in London or Herts | Mail Online]

I’m not sure I’m against alter egos. What is the problem with having a “pen name” for the novel that you are writing? And how you can you “pose” as a self-help guru. Surely he was just practicing what he preaches. If I say that I’m a self-help guru, then I am. Now, you may want to see some credentials or learn about my reputation as a self-help guru, but in a world where you do not need my name as an (imperfect) proxy to those details, what does the name matter?

There are many points to be made from these stories, but the main ones I want to make are that the whole identity thing is more complicated than it seems and it needs new thinking and a new narrative and that reputations are more important than names and finding a way to securely manage credentials and reputation is the way forward for the new economy. To my mind, these are critical components of the new digital wallet, because virtual none of your day-to-day transactions depend on your name.

In the end, I decided it would be too boring to tread too much of the same pseudonymity ground as I did my last TEDx talk (which now has almost 173,000 views, I’m rather excited to report!) so I’ve gone for a more sweeping topic: “Identity is the New Money”. Look forward to seeing you at the Modern Jago in May!.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Don’t bank on identity

Greyscale backing image
[Dave Birch] More than one correspondent has asked me why no banks are on the initial list of approved identity providers (IDPs) for the British government identity assurance (IDA) framework. I belong to the IDA working group on privacy and security and, as you might imagine, Consult Hyperion has provided (and is providing) paid professional services to a number of organisations in the private and public sectors who are developing identity-based products and services. So I think I have a reasonable and well-informed perspective. Unfortunately, it also means that I have to be very careful about what I say, as you might also imagine. But speaking generally, and without reference to any specific clients or projects, I’d say there are three main reasons:

  1. I had an e-mail from a bank person (not Barclays) who said that they had looked at starting an identity business but as it would only generate net revenue of $200m/annum after five years, it wasn’t worth pursuing. In other words, it’s classic Christenson disruptive innovation – the new opportunity is too small compared to core business.
  2. It’s a cross-silo and cross-sector opportunity covering both cost reductions and new businesses so it doesn’t fit corporate structure very well. If some form of identity infrastructure is to address both of these opportunities then it is going to cut across the whole sector, let alone individual banks and there isn’t much appetite for this at the moment.
  3. The business units don’t understand the underlying technology, and I’m afraid it’s one of those areas where you can’t brainstorm the products and services that might be delivered without some rudimentary understanding of federation, digital signatures and such like.

I’m a Barclays Premier customer and I’ve had an account there since 1977. Barclays know absolutely everything about me and my finances and they’ve given me a dongle to authenticate myself to them (which works fine) but I can’t use that dongle to log in to Barclaycard, let alone HSBC. What’s more, under the government-mandated expensive (heading toward a billion quid) and pointless account switching system that will go live in a year or two, despite my 36 years with Barclays, if I walk into Lloyds to open an account they’ll treat me as if I’ve just got off the boat and demand that I go home and come back with some high-security documentation (e.g., a photocopy of an old gas bill).

Identity Fraud accounts for over 50% of all frauds recorded in 2012… The takeover of customer accounts increased by 53% from 2011, meaning that data driven identity crimes now constitute the vast majority of all fraud in the UK.

[From Fraud increase driven exclusively by identity crime, says CIFAS | 18 January 2013 | Stock Market Wire]

Identity fraud is out of control in the US as well, albeit for slightly different reasons, one of the key ones being the use of Social Security Numbers as “identity”. Although, rather hilariously, it seems that the criminals principal source of social security numbers isn’t dedicated teams of Eastern European super-hackers working under their direction but…

The most common method used for stealing identities appeared to be data breach notification letters. Approximately one in four recipients of these kinds of messages ended up being a victim.

[From Javelin: Identity fraud reports increased by more than a million last year | ZDNet]

This is the Law of Unexpected Consequences on stilts, isn’t it? No. Actually, it is the Law of Expected Consequences, since it is exactly as predicted at the time of the great HMRC CD debacle in the UK. I can remember saying, one more than one occasion, that the stupid decision to send out breach notification letters to every household in the UK — a letter that included the full name, address and national insurance number (doh!) of the recipients — would undoubtedly lead to more identity fraud being perpetrated than the loss of the CDs (if they ever existed, which, to be honest, I doubt).

We all need much better security around account access but to make it affordable we need standard, federated solutions operating inside cross-sector frameworks. We need to stop building bank-specific, or even banking-specific, solutions. And we need to make security into an essential element of the customer proposition, part of the business, not part of the back room technology infrastructure.

Here’s one idea of what could happen. When you open a bank account, you should be given a UK financial services identifier (your “money name”), just like you get a Facebook name or a Twitter name. Let’s say it’s £Barclays_Dave. The bank should provide 2FA against that money name. When I go to Lloyds to open an account, I should be able use my money name to open an account on the spot with no messing around with old gas bills. Alternatively, I should be able to open an account with old gas bills and get a new money name (e.g., £Lloyds_Dave) if I prefer.

It wouldn’t cost anything at all, or at least not very much. Banks could fund the system by having the Payments Council auction the “vanity” money names to the highest bidder. I’m sure Richard Branson would pay a million for £Virgin and Roger Moore another million for £007. It’s about time banks had some innovation in the identity space before they simply give the business away to organisations with a better understanding of the technology and it’s possibilities.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

“Identity is the new Money”. Brilliant – I wish I’d said that

Greyscale backing image
[Dave Birch] Sebastien Taveau, the CTO of Validity Inc. (who will be speaking at our Tomorrow’s Transactions Forum in March, by the way), was kind enough to quote me in his review of 2012.

He coined the following statement that has become my favorite of the year.

“Identity is the new money”.

It is simple, powerful and summarizes exactly where the ecosystem is going.

[From Looking Back Forward | Validity Inc. | Biometric Sensors for Mobile Devices]

Seb is much too kind. I may well be guilty of popularising the aphorism in the context of payments and organisational strategies towards secure electronic transactions in the retail space, but I didn’t invent it. I heard it for the first time a few years ago in connection with the ill-fated UK national identity card scheme. I was at the time a member of the Home Office’s Advisory Forum and was interviewed by Sir James Crobsy, who had been called in by the then-Chancellor Gordon Brown to prepare a report on the scheme. It was Sir James who brought the phrase to my attention.

If, as Sir James Crosby said in his report on the U.K. ID card scheme, “identity is the new money”, then banks should already have generated strategic plans to accumulate the former, now that they’ve run out of the latter.

[From Digital Identity: I’m sure banks have a strategy for this kind of thing]

As time has gone by, I have become more convinced that there is a deep truth in the apparently simple statement and I’d like to explain why. But to do that, we have to first explore what money means. One of the problems that always comes up when discussing money is that the word means several different things. I want to focus on just two here: money as a generalised means of exchange between buyer and seller and money the subset of means of exchange that do not involve credit. In other word, cash. Identity changes the requirements for and use of both kinds of money.

If you know who all of the counterparties to a transaction are, and can establish their “credit” then there is no need for cash. Identity substitutes for cash: when I go into Waitrose and pay with my John Lewis MasterCard, it’s an identity transaction. The terminal in Waitrose establishes that I have access to a line of credit that means that Waitrose will be paid. No actual money moves between my card and the Waitrose till. On the other hand, when I buy an apple from a market stall and pay for it with a pound coin, the stallholder doesn’t need to waste any time or money trying to establish who I am, because he doesn’t need to trust me. He just needs to trust the pound coin, which he self-assays. It’s not that there are no counterfeit pound coins, because there are, but that there are too few of them to disrupt commerce (and, to be honest, if you give the smallholder a counterfeit coin and he later detects the fraud, he will probably just palm it off on someone else).

As a thought experiment, then, imagine that cash vanishes and we interact through identity. In that case, identity becomes the key to transactions and a crucial individual resource that needs to be looked after by responsible organisations. This is the idea behind the Digital Asset Grid put forward by the Innotribe team at SWIFT, the worldwide interbank messaging service, at last year’s SIBOS. Whether you think DAG is the right specific approach or not, there’s something to be said for begin strategic planning around the transition to identity-based transactions.

What does all this mean at a macro level? It means that the action in the payments world will shift further toward identity over the coming year. One of the reasons why the Single European Payment Area (SEPA) hasn’t transformed cross-border commerce in the way that had been hoped is that a great deal of cross-border commerce rests on identity, which is undoubtedly why the Commission has switched its attention and proposed new rules to enable cross-border and secure electronic transactions in Europe.

The proposed Regulation will ensure people and businesses can use their own national electronic identification schemes (e-IDs) to access public services in other EU countries where e-IDs are available. It also creates an internal market for e-Signatures and related online trust services across borders, by ensuring these services will work across borders and have the same legal status as traditional paper based processes.

[From EUROPA – Press Releases – Digital Agenda: new Regulation to enable cross-border electronic signatures and to get more value out of electronic identification in Digital Single Market]

You can see where they are coming from. The UK, however, does not have a national e-ID and is unlikely to have one for the foreseeable future. We’ve taken another path, using a framework approach and private sector identities, so a pan-European solution will have to work with public and private sector identities in a single framework. This line of thinking suggests that a fruitful line of enquiry might be to look into a pan-European trust framework that these identities can belong to.

In digital identity systems, a trust framework is a certification program that enables a party who accepts a digital identity credential (called the relying party) to trust the identity, security, and privacy policies of the party who issues the credential (called the identity service provider) and vice versa

[From What is a Trust Framework? | Open Identity Exchange]

Let’s hope that the Commission can help something like this to develop, because the real barrier to cross-border trade within the Single Market is not money, but identity.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Tubular bells and whistles

Greyscale backing image
[Dave Birch] As I’ve written before, there are reasons for preferring an identity and authentication infrastructure that is based on tamper-resistant hardware with local authentication rather than passive identification technologies, largely because it allow the individual control over multiple identities, which I regard as an important contribution to the “privacy settlement” that we are going to need to negotiate in the online future, so naturally I was pleased to see that some security experts at Google have come to the same conclusion, albeit a few years later.

In a research paper, two security experts at the web giant have outlined a future in which the main way of guaranteeing we are who we say we are online will be possession of a physical token, perhaps embedded in smartphones or even jewellery.

[From Google aims to replace passwords with ID ring – Telegraph]

Whatever will they think of next 🙂

I can’t resist flagging up this example because some years ago we worked on a project for a client in the financial services sector who was looking at combining RFID tokens with passwords to make effective two-factor authentication (2FA). The idea was that the, for example, ATM would contain an RFID reader based on ISO 15693 using read-only tags with a range of around two metres. So as you walk up to the ATM it recognises that you are nearby. Then you key in a PIN or a password and the ATM checks this online against the tags that it has lit up. If there’s a match, you get the cash. Anyway, the reason I’m mentioning this (and I’m sure that the client won’t mind me saying it) is because one of the storyboard ideas that we wanted to prototype was jewellery. We went off to talk to a company that had already put tiny RIFD tags in jewellery (it was used for stock management and tracking) and established that the idea was feasible but for one reason or another the client decided that it would be better to make a custom dongle for online use only and leave the ATMs and branch counters alone. These have met a mixed reaction from customers.

the only thing is these blasted little security fobs that you have to keep keying in. I used mine so much that the battery ran out so I had to go and find a replacement locally.

[From Mike Oldfield: ‘Tubular Bells made me a million but the tax bill came to £860,000’ – Telegraph]

That’s why the Google researchers’ other futuristic plan, which is to embed the token in a smartphone, is certain to take off. I’ve even thought of a good name for it: the “secure element”. Not very sexy, but perhaps the marketing wallahs will salvage something from it. The device formerly-known-as-the-mobile-phone is the obvious choice for the remote control to cloud identity. No-one wants another dongle when they’ve already got their phone with them all the time. I know it sounds far-fetched, but I have a dream that one day I’ll be able to log in to my bank by simple tapping my contactless bank card against my laptop or smartphone…

By the way, thinking about futuristic businesses at Google, I remembered reading about another ground-breaking enterprise that they are involved in.

Last week, it was reported that Google founders Larry Page and Sergey Brin and others are investing in a new company called “Planetary Resources” that wants to mine asteroids.

[From Here’s How Google’s Founders Can Mine Asteroids And Become Trillionaires… – Business Insider]

How can they not call this the Weyland-Yutani Corporation?

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Witness for the prosecution

Greyscale backing image
[Dave Birch] Identity issues have been steadily climbing the agenda with many of our clients and as we put more thought into the subject, more complexities are uncovered. It’s not going to be easy to develop the next-generation identity infrastructure that we all seem to want and one of the main reasons why it is difficult is that none of us can agree on what it should be. Not in technology terms (although we can’t agree on that either) but in terms of the vision. What do we want from next generation identity?

One day we’ll see a blending between our virtual identity and our physical identity. In many ways, the web is the backbone for what’s coming next. We’ll see the integration of digital services and apps into our real-world environment.

[From One Day…Our Physical And Virtual Identity Will Blend – PSFK]

I’m sceptical about this, because I think that in the future people will have multiple virtual identities. This is a fundamental conceptual disagreement. It isn’t resolvable in technology space. In terms of vision, there is no overlap between this view and the view of, say, Charles Raab, Professor at the AHRB Research Centre in Intellectual Property and Technology, School of Law, University of Edinburgh. When speaking at “The Life of Mobile Data” at the University of Surrey back in 2004 Charles said that “In the world of post-modernism, it is no longer clear that any one identity is ‘real'”. I still think this one of the most insightful comments I ever heard on the topic, and one that continues to have a profound impact on my thinking in this area.

But what does it mean? Here’s a practical and immediate example. The British government has announced that it is to reform the Witness Protection Scheme (WPS) which, as the name suggests, protects people who have given evidence in criminal trials. The people and their families are given new identities and moved to another part of the country to start a new life. There are currently 3,000 people under protection in this way.

The UK’s first national witness protection scheme has been launched to overhaul the currently “inconsistent” approach to keeping vulnerable people safe, the Ministry of Justice has said.

[From BBC News – Witness protection scheme launched in UK]

Witness protection is one of those cases that makes the design of an identity system interesting and complex. During my time as a member of the Home Office Advisory Forum in the days of the proposed UK national identity card, witness protection was one of the factors that persuaded me that a token-based solution was the way forward, rather than some form of purely biometric solution.

There’s a great danger in accepting an infrastructure of passive identification where you, the target, do not have a choice in how you are identified. It may seem superficially attractive to have network-based solutions that do not require tokens, but I really don’t want websites to use a plug-in that identifies me every time I visit them. This is not because I’m in the witness protection programme but because I want a very basic choice of interacting as Dave Birch the private citizen or Dave Birch the executive officer of Consult Hyperion or John Doe.

In such a system, how does the identity infrastructure know which identity to use? I suppose one way of determining which identity might be returned would be to look at the nature of the request. Imagine a national identity service that was solely based on personal characteristics. It doesn’t matter whether they are your fingerprint, face, typing pattern or anything else. The chap at the pub wants to know whether you are 18 or not, so he captures the relevant characteristic (let’s use fingerprints for the purposes of discussion) and fires it off to the identity service. The identity service sees that your fingerprints appear twice in the record: once for your “real” identity and once for your “witness” identity. Since it is a pub asking, the service sends back your witness identity and life goes on. But, for example, if it is a policeman asking, then the system might return both identities. This would of course be insanely dangerous because, as is well documented, unauthorised access by policeman and others to existing databases is rampant and it will be no trouble for criminals to determine previous identities. In the case of the ill-fated UK national identity card, unauthorised access to the identity database started even before the system went live.

Nine U.K. government workers have lost their jobs after misusing their access privileges to view personal information on public citizens stored in the government’s national identity database… 34 U.K. local council employees were found to have illegally accessed the Customer Information System (CIS) database, according to a news report. The CIS is one of three systems that will constitute the U.K. government’s national identity database…

[From Nine U.K. Workers Fired For Tapping Into National Identity Database –]

It’s one thing to have trusted and vetted and responsible council workers rummaging around in a National Identity Database, but imagine what happens when just about anyone gets access to that database and it is recording who is in the WPS. Actually, you don’t have to imagine it because we already know.

The British Broadcasting Corporation (BBC) indicated in a 2009 article that, according to a report by a Mexican magistrate, [translation] “the majority of protected witnesses who have cooperated with the judicial system in Mexico have been assassinated”.

[From UNHCR | Refworld | Mexico: The use of government databases by third parties to locate persons; privacy issues; security of information about witnesses in the witness protection program (2008-September 2011)]

If you are a spy, or an undercover policeman, or in the witness protection programme, or perhaps even a restaurant critic, you may have perfectly legitimate reasons (in some cases very literally a matter of life and death) for wanting one identity asserted over another. Who controls this? In a token-based environment, there is no problem. A policeman stops me in the street and wants to know who I am. I take out my phone and touch it against his phone. His phone requests and authenticated identity, my phone asks me for a PIN or pass code which I enter, and my phone sends back my driving licence which includes a photograph that is displayed on the policeman’s phone. In this latter case, my personal characteristics might form part of the process but for the purposes of local authentication against the token: thus I might be required to speak into my phone or present my fingerprint to the phone, or whatever, but this would be used only within the phone for template matching. Google has apparently come out in favour of tamper-resistant hardware tokens, which ought to finally give impetus to this approach in the mass market.

An identity service founded on the principles of post-modern relativism thus has no problem dealing with the multiple identities. In essence, it would treat all identities as pseudonyms. The use of the pseudonym that happened to coincide with your “real” name would not be a special case. To see what I mean, imagine that my name is Jelly Dave (an epithet earned through my knowledge and skill in using gelignite to open safes). I fall out with Mr Big, the head of my gang of bank robbers, and I decide to turn Queen’s Evidence and start a new life. Quite straightforward: my digital identity is revoked and I’m given a new one. I use that digital identity to obtain a new pseudonym from the national identity service (in essence, I send them my blinded public key, they send me back a signed public key certificate and then I remove the blinding) and I’m now Telly Dave, a couch potato from Woking. If a policeman stops me in the street, my phone tells him that I’m Telly Dave. If he is corrupt, it doesn’t matter, because there is no link between Telly Dave and Jelly Dave. The pub, the policeman and everyone else is provided with a pseudonym, not the underlying real identity. And since neither the pub nor the policeman has access to the biometric register that ensures uniqueness, they never the Meaningless but Unique Number (MBUN) that connects the pseudonym to the physical entity.

(The key to making all of this work is to separate the relationship between the “real” person and the pseudonym through the mediating relationship of digital identity, but that’s not really what I want to discuss here.)

Incidentally, I know we only tackling part of the problem here because the witness protection issue is about to get substantially more complex (unless my idea of issuing standard Facebook-blue burkhas to the population takes off). Using digital identity infrastructure it is easy to give you a new pseudonym, but it is not easy to give you a new social graph. Witness protection in the age of Facebook is a whole lot more complicated because protecting your privacy in an online age is a minefield, as “Real Names Randy” Zuckerberg just found out. My new identity of Telly Dave is sooner or later going to get tagged in a photo somewhere that will end up with Mr Big. So without knowing anything about the WPS itself, or how the government proposes to restructure it and centralising, I would think that it has a massive job on its hands to set about forging the social graph for spies, undercover policeman, protected witnesses and restaurant critics in the face of services like Andrew Nash’s new venture Trulioo, which helps to uncover phoney Facebook identities. I would imagine that services like this will make it much harder for the WPS to maintain social graphs for people who need protection. Someone out there must have thought about this, so I’m desperately keen to read about potential solutions. Links please!

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Data sharing sounds good, but it is dangerous

Greyscale backing image
[Dave Birch] It’s not appropriate to say where, but I recently happened to be in a seminar where I saw a member of the German parliament talk about the sharing of data between law enforcement agencies. He used the example of the Austrian and German police exchanging fingerprints and DNA samples and pointed out that cross-border searches had had “many thousand” hits (i.e., a fingerprint gathered at a German crime scene shows up in a search by Austrian police). He called for all EU27 countries to share this kind of data.

Naturally, we are all in favour of tracking down the perps (sorry, been thinking about Judge Dredd again — “I am the law”) across borders, but hold on. Am comfortable about my fingerprints, DNA and personal data being shared with, say, Swiss law enforcement agencies? I may be traducing them unfairly but I have no knowledge of the rigorous data protection and security enforcement procedures within the Swiss government. No, wait, I do…

According to a report from Reuters, sensitive information on counter-terrorism shared by several foreign governments was potentially compromised by a massive data theft at a Swiss intelligence agency. The data heist, according to what European national security sources told Reuters, was by an unnamed IT technician for the NDB, a Swiss intelligence agency.

[From Report: Swiss Spy Agency Warns Of Huge Data Leak from Insider | SecurityWeek.Com]

Even in the UK , with the most stringent data protection laws and ruthless enforcement, we find civil servants being disciplined all the time for unauthorised access to databases (and they are only the ones that are caught). Journalists, private investigators and criminals do not seem to have too much difficulty in getting access to personal data held by government departments and agencies as far as I can see.

Around 25 civil servants are being reprimanded each week at the Department of Work and Pensions for breaching rules governing its vast database, figures show.

[From Civil servants caught looking at private files in personal data breaches – Telegraph]

Still, at least the UK doesn’t have a national identity scheme with a database that stores everyone’s personal details in a structured and easily-accessible form…

Greek police have arrested a man on suspicion of stealing the personal data of roughly two thirds of the country’s population, police officials in Athens said on Tuesday. The 35-year old computer programmer was also suspected of attempting to sell the 9 million files containing identification card data, addresses, tax ID numbers and licence plate numbers.

[From Man arrested in Athens over ID theft of most of Greek population – thestar.com]

Sharing personal data to track down bad guys sounds like an Apple Pie policy (for UK readers: a Bread and Butter Pudding policy), one that you can’t possibly be against. The problem is, of course, that once the data genie is out of the bottle there’s no way of getting it back in again. I remember some of the discussions around TSB Encore project: once you’ve got a copy of my data, there’s no technological way for me to stop you doing anything you like with it (if there was, Hollywood would be using it). So it’s better not to share the data in the first place, except that doesn’t help us catch the bad guys.

I can understand why the Government wants more data sharing to improve the efficiency of public services but I can’t see how this isn’t going to end up in a Data Chernobyl unless we develop a more sophisticated approach to data sharing: encrypted storage, pattern-matching of encrypted data, pseudonymous identity infrastructure and all those other good things.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Layered approach

Greyscale backing image
[Dave Birch] We’re all getting a little jaded about the continuous stream of reports about password breaches (I don’t know even breach is even the right word, seeing as the most common password used by everyone is “password”). But this one caught my eye, because in this case it wasn’t the password that was stolen but the knowledge needed to obtain it.

It seems that the cyberthieves gained access by taking over a Global Payments administrative account “by answering the application’s knowledge-based authentication (KBA) questions correctly.”

[From StorefrontBacktalk » Blog Archive » Could Global Payments Breach Finally Kill KBA Questions?]

This madness has got to stop. Any organisation that wants to be taken even slightly seriously has to move to better authentication at the earliest opportunity. But what might this authentication look like in the mass market? Last month MasterCard hosted a great day at their new innovation centre in Dublin to show off their technology platforms and explore some practical ideas about the future of payments.

MasterCard has made Dublin the location of its latest MasterCard Labs office. The ‘innovation hub’ will lead the development of technology for the company’s worldwide operations and will foster projects in the areas of coupon purchases, biometric authentication, near field communication and gesture control.

[From MasterCard unveils Labs office in Dublin | TechCentral.ie]

There were some great demonstrations of the PayPass contactless wallet and PC payments as well the integration of secure (i.e., chip-based) payments into the new digital media age. One of our senior consultants, Tony Pickup, was there and so I asked him for his professional opinion of what was on show. Rahter interestingly told me:

The demo that caught my eye may be not as “sexy” as the contactless and mobile stuff, but it demonstrate a potentially important change in the way we may access funds in the future. This was a demo of the South African entitlement card distribution process and funds distribution to a market expected to be 10 million by the end of 2012. This service may show how remote card account management may develop in the next few years.

The South African Social Card service uses a layered approach to biometrics and their use. The idea is that on registration a voice biometric is captured to support account management, a fingerprint biometric is captured and loaded onto an EMV card only. Also once the biometrics are taken the user is asked to set-up a PIN to enable chip and PIN authentication for purchases at physical POS. The fingerprint biometric is used for authentication purposes when a person presents themselves for an entitlement. This is clever as the biometric is checked by the EMV card using the data collected to prove the customer is ‘alive’., there is no need to collect or match fingerprints in a central database. The voice biometric is used to ensure that if a customer needs to re-issue a card it can be done efficiently. However, this multi-model approach also offers the ability to use the voice biometric if the person is unable to present themselves or their finger to prove their entitlement and access the funds granted to them.

This may show the future for remote authentication and layering biometrics to authorise different types of transactions, but it certainly indicates to me that it is identity, not money, that will be the crucial field of competition in the near future. I’m sure that Visa, MasterCard, Amex and others are all on the case, for the simple reason of economics: if you know who the counterparties to a transaction are, then the payment and settlement part becomes easy.

Kris Ranganath, director of technology and solutions of NEC, pointed out that the latest developments in biometrics focus on multimodal fusion matching, or “person-centric identification”. This means that any available biometric data generated by a person can be used for verification. This, he noted, is unlike the past when tools depend solely on a single mode of a person’s biometrics such as fingerprints.

[From Biometrics more accurate, but uptake ‘disappointing’ – ZDNet Asia News]

So what is the path into the mass market? There is no silver bullet for authentication, not even biometrics, but some intelligent multi-modal application can quickly shift authentication into a sweet spot for most transactions, most of the time. Buy a pack of gum, tap. Buy a pair of shoes, chip and PIN. Buy a car, chip and PIN and fingerprint. Buy a house, chip, PIN, fingerprint and voiceprint. Launch nuclear missile, chip, PIN, fingerprint, voiceprint and DNA. That kind of thing, although we don’t need to wait for all of these technologies to reach mass market security. There really is no excuse for not implementing better authentication now and I’ve often wondered why we don’t use bank-issued chip and PIN cards to do it: if they can do it in South Africa, we can do it here.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

The battle of the internet security experts

Greyscale backing image
[Dave Birch] A very entertaining spat has broken out in ranks of the governing classes. Broadly speaking, it’s between the “Real Names Randi” Zuckerberg school and the people who know something about the issue school. The trouble started when noted internet security expert Andy Smith gave some sound advice to the nation.

Andy Smith, internet security chief at the Cabinet Office said real names and addresses could increase security concerns. He advised users to submit “fake” details as this was a “sensible thing to do”.

[From Whitehall official: ‘Give fake details to protect online identity’ – Public Service]

Andy is spot on, although possibly unaware that providing fake details is in direct violation of Facebook’s policy. His advice will indeed lead to less identity theft, and we don’t have to guess at that because (as I will discuss later) we have the data. Still,

Simon Milner, Facebook’s head of policy in the UK and Ireland, was not particularly happy at Smith’s comments. He apparently had a “vigorous chat” with the Cabinet Office official afterwards to persuade him to revise his view.

[From Top civil servant calls for Brits to fake online identity – Cabinet Office says it’s the only way to be safe | TechEye]

However vigorous Mr. Milner’s chat might have been, there are almost no circumstances where it is necessary to use real names and we only use them now because we lack a proper identity infrastructure. By and large, we use the real name as a proxy to the attributes that are actually needed to execute a transaction. Andy’s comments elicited an immediate and vituperative response from noted internet security expert Helen Goodman MP.

Ms Goodman, shadow culture minister, told BBC News: “This is the kind of behaviour that, in the end, promotes crime.

“It is exactly what we don’t want. We want more security online. It’s anonymity which facilitates cyber-bullying, the abuse of children.

“I was genuinely shocked that a public official could say such a thing.”

[From BBC News – Give social networks fake details, advises Whitehall web security official]

Ms. Goodman’s confused opinions on security and privacy — and the false dichotomy implicit in the security vs. privacy paradigm she draws on — are representative of the shallow thinking and lack of informed discussion in this area.

How Helen Goodman voted on key issues: Voted very strongly for introducing ID cards.

[From Helen Goodman MP, Bishop Auckland – TheyWorkForYou]

I wasn’t able to assess her background in online security and identity management from her online biography, but I’m sure her opinions must be founded on some knowledge of the field.

Helen… went to Somerville College, Oxford, where she read Politics, Philosophy and Economics. After leaving Oxford, Helen’s first job was as a researcher for Philip Whitehead MP. She became a civil servant at the Treasury in 1980 and rose to become Head of the Central Strategy Unit in 1995… From 2002 until entering Parliament, she was Chief Executive of the National Association of Toy and Leisure Libraries.

[From Biography » Helen Goodman MP – Working hard for all in Bishop Auckland]

In an age where government seems more and more to be about sentiment and sensitivity rather than evidence and knowledge, I suppose her comments are unsurprising. I’m not for one moment suggesting that Ms. Goodman’s concerns are not wholly real and heart felt. I’m sure they are.

Mrs Goodman, MP for Bishop Auckland, in the North-East of England, said she had been contacted by constituents who have been the victims of cyber-bullying on major social networking sites by people hiding behind fake names.

[From BBC News – Give social networks fake details, advises Whitehall web security official]

I don’t doubt that this is true. But so what? People bully under their real names too, and it doesn’t make any difference. If they have broken the law, they can easily be traced, since the interweb tubes will lead the plod directly to them. Or, indeed, directly to the plod.

A man arrested over claims that he tormented a mother with abusive online messages is a serving police officer.

[From Police Officer Arrested Over Internet Troll Abuse Of Woman, Nicola Brookes]

I’m not picking on Ms. Goodman here, just using her to illustrate a point. After all, her fellow old Oxfordian and noted internet security expert The Honourable Edward Vaizey MP agrees with her that the Cabinet Office’s advice is incorrect, leaving us none the wiser as to the government’s actual policy on this (hint: it doesn’t have one).

Culture minister [The Honourable Edward] Vaizey said he had not seen Mr Smith’s remarks but told the BBC that he “wouldn’t encourage people to put false identities on the internet”.

[From BBC News – Give social networks fake details, advises Whitehall web security official]

The Honourable Edward’s plan to make it easier to track down people through interweb tubes may not be driven by commercial interests, but it certainly aligns with them.

Randi [Zuckerberg] and I share a passion to end cyber bullying and protect kids online. However, our approaches to online safety differ greatly.

Randi Zuckerberg wants to end online anonymity.

[From Facebook’s Randi Zuckerberg Wants to End Online Anonymity: Free Speech or Real Names?]

Look, I’m not here to shill for Andy Smith. Andy and I have disagreed about things before, and while I make not comment on whether he is an Epic F***ing Secure Hero or not, he certainly is an internet security expert. His comments were informed and relevant and exposed the lack of policy integrity. I don’t know why politicians don’t take the time to think this through. They always reach for the same knee-jerk response: some sort of internet passport or driving licence so that you can tell who is posting abuse about government minister on The Daily Telegraph web site (hint: me).

if there was an Internet Driving License that you had to use to log in to web sites, that would almost certainly make the situation far worse, since these website would now know exactly who you are, and this information would then be freely obtained by perverts, the secret police, News International or whoever else wants to pry. Why is this better than anonymity (which doesn’t exist anyway – look what happened to the not-Anonymous-at-all hackers).

[From Let’s not panic about online identity]

Since I wrote this, incidentally, some pretty convincing evidence has come to light to support my view. South Korea has rescinded its “real names” law.

In 2007, South Korea temporarily mandated that all websites with over 100,000 viewers require real names, but scrapped it after it was found to be ineffective at cleaning up abusive and malicious comments (the policy reduced unwanted comments by an estimated .09%).

[From Surprisingly Good Evidence That Real Name Policies Fail To Improve Comments | TechCrunch]

In fact the results of the “real names” law were predictably perverse. Identity theft went up, because real identities were stolen from the thousands of web sites that now had to ask for them and store them. And since people became used to be asked for their real identity, it was easier for dodgy web sites to get them to hand them over!

if you make people smear their “real” identities all over the internet because of such a policy, thus delivering the “over–identification” noted above, then that will make identity theft worse.

[From Real names, real problems]

I fully expect The Honourable Edward Vaizey MP to begin drafting another law shortly. After all, if we are not allowed to mask our real  identities online, why should we be allowed to mask them offline either? In a country covered by CCTV cameras, it seems perverse that people should be allowed to, for example, wear masks of celebrities (or, indeed, anyone else) in public places. The steady advance of automated face recognition technology means an inevitable identity Chernobyl.

Any science fiction film that doesn’t show everyone wearing burkhas in public will look as dated as Soylent Green.

[From Never mind real names, what about real faces]

Look. I don’t mean to suggest that Ed and Helen are idiots. That’s clearly not true. But what I am suggesting is that we need a better-informed public discussion and debate to determine public policy and the balancing of interests between competing pressures needs to be made explicit. How should we determine whether Mumsnet or the EFF are right? In back rooms or in public consultation (by which I mean consultation in public, not with the public – I don’t really care what they think since they are almost completely uninformed).

We (the public) have no idea what we want. We want anonymity for Syrian dissidents but not for pedophiles. We want anonymity for hospital nurses blowing the whistle on incompetent surgeons but not for looters. We want anonymity for celebrities in some circumstances but not others. Most of all, and most paradoxically, we want the authorities to spy on other people but not on us.

[From We don’t know whether we want real names or not]

So what I want to know from the Honourable Edward Vaizey, Helen Goodman MP and the Cabinet Office is this: what is the policy, and what is the strategy to implement it? And if you’re short of an idea or two about a vision for online identity in the 21st century, why not put your feet up, get a cup of tea, and cop a load of this. The security vs. privacy balance is only for people who haven’t put any intellectual effort into this serious, important and urgent area of public policy. Joanna Geary sums up the situation very nicely in her “Comment is Free” piece today.

A Whitehall adviser has been slammed for telling people to make up data. But less anonymity doesn’t equal more security

[From Being wary of handing over personal details to websites isn’t ‘outrageous’ | Joanna Geary | Comment is free | guardian.co.uk]

Hear, as they say in Parliament, hear.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

He’s no fraud

Greyscale backing image
[Dave Birch] Browsing the March 2012 “Banking Technology”, I came across some analysis of the record UK fraud figures for last year. These show that the biggest fraction of fraud, identity fraud, grew 10% (fraud overall grew 9%) to account for almost half of all detected frauds. The biggest growth, incidentally, was in account takeover fraud, which grew 18% (boosted, as I understand it, by a big increase in telephone phishing). I made a note at the time, and this came to mind when the good people at Experian invited me along to their annual Identity and Fraud Forum. They asked me to come along and talk about the medium term future for retail payments, but naturally most of the other talks were about, well, identity and fraud.

You can read about all of this in Experian’s free fraud report, but I’d like to highlight one of the trends that I heard. Not in card fraud, as the card fraud hotbeds are the same as always – Reading, for example, and Luton – and it is by and large a London-centric kind of fraud with the highest incidence in the suburbs (I guess this where people with the cards with high limits live?). But another thing I noticed in the figures were that people on benefits have their identities stolen at a rate considerably higher than their incidence in the general population. I suspect that this is because their identities are being stolen by other benefit claimants to make fraudulent claims.

Nigerian couple tried to claim £3.8m in ‘eye watering’ benefits scam… Thomas used 1,400 stolen identities to complete 2,495 handwritten tax and benefits claims forms… HMRC suspicions were raised when he used the same address for all the claims

[From Nigerian couple tried to claim £3.8m in ¿eye watering¿ benefits scam using 1,400 identities | Mail Online]

Astonishing. It took 2,495 claims from the same address to raise suspicions. Shouldn’t like, half a dozen cause alarm bells to ring somewhere? Fortunately, we won’t have to worry about this sort of thing for too much longer.

Private security companies will be commissioned to develop a system of “identity assurance” to check that only real claimants can get benefits.

[From Cyber attacks threaten welfare reforms, ministers warn – Telegraph]

I could suggest a series of rudimentary checks to begin with, like limiting the number of claims from the same private address to say, a thousand or so. But my point is that two things are being confused here: working out who you are and working out whether you are entitled to benefit (most benefit fraud is not identity fraud but misrepresentation of circumstances: not lying about who you are, but lying about whether you’ve been working or having children or being disabled or whatever). Working out whether you are real is only the first step in fixing this problem.

As an aside, one of the reasons why I enjoyed the Experian event so much was that their after dinner speaker was Bennett Arron, the comedian who tells the fascinating and funny (and slightly scary) story of how his identity was stolen and I got to chat to him as well as listen to him speak. When he talks about how easy it was for fraudsters to steal his identity and cause no end of misery, he is talking about something that happened a few years ago. But you’ve got to ask yourself how much has changed? I listened to a talk from a couple of ex-policemen talking about how they tracked down some terrorists by following their money trail, and it seemed trivial for the terrorists to obtain large numbers of bank accounts, credit cards and mobile phones. We haven’t even started to do something about identity yet.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.