It’s simple, this money laundering stuff

Greyscale backing image
[Dave Birch] I wanted to send some money from my UK bank account to my US bank account.

I logged in to do this via my bank’s online service but noticed that they want to charge me £25 for sending a few bytes of data. So I googled around for alternatives and I noticed that the UK Post Office are advertising a free service. So I decided to give it a try.

Remember, I do this so you don’t have to.

I logged on and set about creating an account, which didn’t take too long. But I couldn’t use my account to send any money. There was no “make a payment” option. I couldn’t figure out why, but by then I was too tired to think about it any more so I forgot about it. The following day, I saw an e-mail from Post Office International Payments saying that “To activate this facility we will require a conversation with you over the telephone”. I got a cup of tea and dialled. The nice lady at the other end of the line said that she needed to ask me a few questions because I had failed some kind of identity check.

Well, I suppose I could see why I I’d been flagged: after all, I’ve only lived at the same address for the last 17 years and only had the same bank account for the last 35 years. She asked me if I’d ever lived abroad. I said yes and she asked me where. I started by saying that in the early 1980s I lived in Indonesia. She asked me what I was doing there. I told her I was working on there. She asked me what I was doing, so I began to explain to her about the Palapa B-1 regional satellite system. I thought that if I explained my pioneering role developing X.25/X.28 software to run data networks over a slotted ALOHA satellite channels it would help with my KYC. I imagine that this is the sort of thing that can trip up even the most dedicated terrorists and money launders. If I had, for example, said that the Hughes HS-376 satellite launched in June 1983 used three solar panels then she would have hit the panic button immediately, because as most Post Office employees are well-aware, the spin-stablised 376s had only two solar panels.

After going through the places where I had lived abroad, which took some time, we then moved on to why I wanted to send the money to the US. I explained that I was an international drug dealer and that I needed cash to purchase supplies of Ketamine. No, I’m only joking, although once again I suppose that had I really been an international drug dealer, that’s just the sort of question that would have tripped me up.  I actually told her that I go to the US frequently, that I don’t want to use my UK credit card because of the rubbish rates and penal F/X charges and that I was a bit annoyed with my prepaid US dollar card because it doesn’t always work. So I was going to use my US debit card instead and so needed to top up my checking account.

The conversation continued, ranging over how often I was thinking about sending money to the US and so on. At the end, she told me that they would be back in touch to let me know when I would be allowed to send money. Oh well. I was leaving for the US tomorrow, so I ended up transferring money over to my prepaid card anyway. When I got to the US, there was an e-mail telling me that I could now send money, so I logged back in to the Post Office and sent the £250, which if memory served took about four days to get to the US. I should have drawn it out in cash and brought it with me on the plane, as that would have been three-and-a-half days quicker.

If I have to go through this bullshit — which was colossal waste of their time and money as much as it was of mine — to send £250 to the US, I wonder how third-world kleptocrats manage to salt away billions? The only conclusion that I can draw is that stringent KYC/AML imposes high costs and inconvenience on people like me — and holds up the progress of new payment and other financial services innovations — but is no more than minor inconvenience to drug dealer, money launderers, corrupt politicians and tax avoiders worldwide. That one phone call has already cost the Post Office more than the F/X margin that they’ll make on my transaction, and to what end?

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Control centre

Greyscale backing image
[Dave Birch] Andre Duran, the CEO of Ping Identity, and a chap who knows a thing or two about digital identity, said earlier in the year that there are four “megatrends” that are changing the landscape for interaction. These are…

…cloud, social, mobile and big data. The world looks very different today than it did even five years ago. And so our thinking and our solutions must change with it.

[From 4 Megatrends That Will Transform Online Identity – Forbes]

I don’t think anyone would disagree. Digital identity is core to the connection between these trends, which I’m sure is one of the reasons why the accountants Deloitte flagged up digital identity as one of their “technologies to watch” or something similar for 2012. So they’re on my page, as I believe the young people say. But it’s one thing to say “digital identity” and another to turn it into an element of organisational strategy, and one of the main reason why is that the term is diffuse. To me, digital identity means something quite specific. But that’s not, I think, generally true.

Former Twitter CEO Evan Williams noted in a blog post this weekend that online identity is one of the thorniest issues any web-based service has to deal with — in part because the word “identity” means a number of different things.

[From Online Identity Isn’t a Transaction — It’s a Feeling: Tech News and Analysis «]

True. And I suppose I might reasonably be accused of sticking to more technology-centric or “tool-centric” definition, but I prefer to do that because it is more specific.

This is a very tool-centric, or marketing-centric approach, and leaves out — or dismisses — all the messy and interesting philosophical aspects of identity. Consider issues like publicy: How much of these various aspects of identity do you want to be revealed? Or context-based identity: you are a different you with the bowling league, at work, or on Suicide Girls.

[From Evan Williams | evhead: Five Easy Pieces of Online Identity | Stowe Boyd]

Digital identity means different things to different people, naturally, but I think one of the common threads that I am beginning to see is control. Could it be that “control” is the key concept that will bring digital identity alive for businesses and consumers alike?

Personal, which Forrester Research has identified as a leader in the emerging personal identity management space, is focused on empowering consumers to take control over their own data. Doug Wheeler, co-founder and COO of Personal, described the company as a “private network where users store all of life’s important details in bite size pieces called data ‘gems.’

[From CMOs: Are You Ready For the Next Technology Revolution? – Forbes]

I make no comment about whether their technology or business is any good, but refer to this snippet in order to make a different point: that technologists like me will get nowhere without the marketing guys. It’s “data gems” that sell, not “digitally-signed NDEFs containing references to personally-identifiable information”. One of my constant complaints about the world of digital identity, data privacy and the apparently paradoxical online world that delivers simultaneously more security and more privacy is that it remains disconnected from the marketing and commercial side of organisations such as, for example, mobile operators.

Fighting technology with technology seems most promising—by replacing ID cards with phones.

[From Fake ID cards: Identity crisis | The Economist]

I think the first serious “identity in phone” project that Consult Hyperion worked on was for the Japanese company NTT Data, and that was a decade or so ago. Yet the concept doesn’t seem to making much progress in the mainstream. I’d quite like to use a standard phone-based identity to access most services and it drives me to distraction to have to deal with hundreds of different usernames, password, PINs, secret words and personal questions to get what I want to get online. I have all of them stored in an app on my phone anyway (I happen to use “SplashID”, which is pretty good, but I’m always forgetting to add things into it) and I’d really like to avoid problems like this morning, when I had to do something in Firefox and it asked me for a “Master Security Password” that I had absolutely no memory of).

Why the slow going? Maybe it’s something to do with the packaging. If we could package the digital identity message properly, with a common understanding of the term and a shared narrative that animates it, so that we can connect with the commercial guys, then I think we could reasonably expect growth. You’d think the accountant-style persons in operators and elsewhere would be all over it, because the scale of the problem is huge and the opportunity to do something about it — because of the frameworks that are coming into place, the technologies available to us and the experience already built up — is immediate.

Cases of online fraud have increased threefold compared to 2010, partly due to consumers having a large number of web accounts, according to new research.

[From Online fraud: too many accounts, too few passwords | News | TechRadar]

But. There’s still not a lot happening. I have a memory of a Vodafone woking on something around a decade ago, and Turkcell have some services live, but there’s a disconnection somewhere. Mobile operators seem, to me, to be the natural providers of a digital identity infrastructure and one of the natural providers of identity and attribute services that could take advantage of it. How? Earlier this year, Assaf Bielski wrote a succinct prescription when commenting on the slow uptake of service (e.g., the Estonian mobile ID, which has only 30,000 users).

The best way to to this is to engage with the rest of the digital identity community that tries to solves these problems globally (see earlier post), and add the MNO assets, the mobile device and the SIM to it, and not to treat it as a stand-alone service.

[From What about mobile ID | It’s all about ID]

Exactly. Who cares about “Joyn“. I want standard, open and interoperable digital identity with the keys in tamper-resistant hardware. Why don’t the mobile operators start with OpenID on their own sites (so I don’t have to mess about remembering different passwords for O2, Orange, 3 and Virgin) and then enable 2FA OAuth2 using SIM-based keys. Eating your own dog food, I believe our transatlantic cousins call it. If millions of mobile customers began using it for operator services, then it would presumably become attractive for other service providers to use it and thus become a market for value-added services.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Hey, you, get off of my cloud (™)

Greyscale backing image
[Dave Birch] You may have seen Matt Honan’s story — it was all over the web recently — about being hacked in a particularly disastrous way.

Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information — a partial credit card number — that Apple used to release information. In short, the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification.

[From How Apple and Amazon Security Flaws Led to My Epic Hacking | Gadget Lab | Wired.com]

This is what the geek’s geek, the Woz, says about it:

I say the more we transfer everything onto the web, onto the cloud, the less we’re going to have control over it

[From Steve Wozniak: Cloud Computing Will Cause ‘Horrible Problems In The Next Five Years’ – Business Insider]

Control is the key issue here, at least to me, because my mental model of privacy is largely about control. Controlling who can or can’t see your data is what privacy is, isn’t it? And if it is, then the mechanism for control, and the security that goes into that mechanism, is fantastically important. If someone cracks this, they are really on to something.

There are some cost savings that are immediately apparent. With the cloud there is no hardware or software to install. If your cloud vendor insists on buying either one, then they are not a true cloud provider.

[From Are the Costs of Cloud Security Too Good to Be True? | Cloud Computing on Ulitzer]

No hardware? No, I don’t buy that. The cloud doesn’t need hardware, but cloud security does. The mechanism for controlling your data in the cloud has to have a certain minimum level of security associated with it, and to me that means somewhere in the loop there has to be some tamper-resistant hardware. Like the SIM in a mobile phone.

Now, the mobile platform has all the right attributes to make safe the next generation of consumer payments. In particular, NFC devices come with “Secure Elements”: certifiably secure tamper resistant chips in which the crypto-magic happens, and where the mission critical apps run.

[From Now is not the time to go soft]

There’s a whole other blog post to be written here, about SIM- vs. Handset- vs. External Secure Elements (SEs) and the myriad ways in which the manufacturers and mobile operators have messed up this potentially revolutionary infrastructure, but that’s not the point I wanted to make here. Note that I am not saying that mobile security is perfect. I know that it isn’t, partly because of the risk analysis work we do for clients in the mobile transactions space and partly because of the Ph.D research on the topic that Consult Hyperion has been sponsoring at the Univeristy of Surrey.

banks must assume that what used to be a primary layer of defense through out-of-band authentication — the mobile phone — is now compromised.

[From How to Protect Mobile Banking from Fraud – Bank Think Article – American Banker]

This is true. The current generation of mobile phones are vulnerable to certain kinds of attack and while the attacks might not be too scaleable right now, they might be in the future. As an aside, I should point out here that in the regions with the biggest volume of mobile payments (e.g., Kenya) it is clear from the figures that when frauds occur they occur because of human failures or collusion, not because the mobile device is attacked. Nevertheless, there are certain things that are risky with mobile phones, such as putting passwords or PINs in the them (because of the potential for key loggers). This won’t be true for too much longer because of the arrival trusted processing in standard handsets (such as the Trusted Execution Environment, TEE, from ARM).

The level of risk doesn’t mean we shouldn’t use start using phones for two-factor authentication immediately – they are way, way better than passwords – just that the system needs to have realistic controls and management. Actually, I think there’s more of an imperative. We need to get people used to authenticating using the handset because the handset is going to become, as Peter Vander Auwera noted, an identity remote control for the cloud.

A mobile experience that truly represents your identity — in a way that both resembles and enhances an in-person conversation but still affords you control over how you portion out your attention and provides context — could tie the knot for the myriad communication channels available.

[From The First Company To Build Your Identity Into Your Phone Wins The Next Decade | TechCrunch]

I don’t think I agree with Rebekah about what identity is, exactly, but I do strongly agree with the spirit of her argument. The device formerly known as the mobile phone is the transparently obvious place to store and manage your identities (whatever they are). The imminent arrival of better handset security (the TEE) and, especially given Apple’s acquisition of Authentec, the imminent arrival of convenient biometric authentication will mean a fundamental change in the structure of our and other industries. Stuff will go to the cloud, and we’ll remote control our stuff from our secure devices.

What this all boils down to is that we might as well start now and begin the migration. We are still using passwords when there’s simply no excuse for doing so. Software cannot protect us: unless we have tamper-resistant hardware to store our identities, we cannot realise the full benefits of the cloud. When it comes down to, given the state of technology, secure electronic transactions need chips — software just isn’t good enough — as well as convenient interfaces so that applications can work simple, securely and efficiently.

What would happen if our data was stored (encrypted) in the cloud and attached to identities that were actually secure? Imagine choosing your default identity on your phone and then going about your day, accessing all of your data without even realising that it was being pulled down from the cloud and decrypted on the fly. Sounds pretty good. But who is going to put that identity into your phone? Who is going to provide the infrastructure, the identity providers and the attribute providers? You’d think it would be, for example, banks. Or maybe even mobile operators themselves. Who knows. But they ought to get moving, because other people aren’t standing still.

But all of this may change thanks to social networking. The forcing function that allows distributed identity to flood into the enterprise may be a simple side effect of the solution that we use to share information between Facebook and Twitter. It’s a testament to the massive soft power wielded by such companies that they may indirectly change how corporate America does IT forever.

[From The Next IT Revolution: Bring Your Own ID – Forbes]

If my Twitter ID was a secure, then surely it would save my employer money to let me use that ID rather than create and manage a new one. And why wouldn’t I use that same Twitter ID to access my bank account? Is it too late? We’re already at the point where people are beginning to prefer using their Facebook and Twitter identities over site- or service-provider specific identities. I’m pretty sure most people would be happy to use these identities in almost all circumstances – if they sure that they were secure. 

According to data collected by Monetate, 41 percent of shoppers prefer logging into an eCommerce platform through a social media account rather than a separate login — up from 28 percent just a year ago.

[From Social Commerce – Consumers Love Shopping Through Facebook — But Expect To Be Compensated | PYMNTS.com]

Of course, as I explained back in 2007 in the noted tome “Digital Identity Management“, we already have the technology to make all of this work. Tamper-resistant SIM chips, PKI and biometrics. We can build an architecture that separates my virtual identities from my digital identities and binds them to my physical identity. To establish control over my part of the cloud, I select an identity on the phone and then use it to give access. So there is an authentication (lets say biometrics with passphrase and challenge/response fallback) that connects me to my digital identity and then there is a connection between one of the virtual identities bound to that digital identity and the data in the cloud. Simple, really. 

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

Social banking

Greyscale backing image
[Dave Birch] I was reading about “social media lessons from banking insiders” in a report published by the noted Swiss co-operative KPMG International. The report asks the question (on page 2) “Will customers really want to be ‘friends’ with their bankers?”. Now, as everyone already knows, the answer to this is no. I cannot imagine any circumstances under which I would to earn “thank you points” on Facebook from my bank in return for the amount of money I have on deposit with them. I would much prefer them to fire the social media gurus and consultants behind this sort of idea and give me another 0.5% on my savings account instead. And further integration inside the Facebook framework doesn’t seem to have much to offer either.

In my opinion, banks that are enabling or attempting to enable transactions via a Facebook app are barking up the wrong tree. I’ve seen nothing to suggest that customers want this or would even use this. In fact, I’ve seen evidence of the contrary.

[From Celent Banking Blog » Are Bank Facebook Apps the Future of Digital Banking?]

That’s not to say, of course, that Facebook is irrelevant to banks. For one thing, as I’ve bored on about at length before, if there were a transactional element to social media integration then banks might have some really good products and services to offer in that space.

I don’t want to be friends with my bank—after all, I’m a typical consumer so I hate banks—but I do want to be friends with my bank account.

[From Friends and relations]

But that’s by the by. KPMG make a very interesting point on page 16, where they note that the lack of security infrastructure means that banks in any case have no way of knowing whether social media data comes from real customers, competitors, corporate saboteurs, mischievous hackers, agents of foreign powers or dogbots. This, it seems to me, opens up an interesting and immediate route for exploring the bank/Facebook boundary to find value. I was thinking that while the bank doesn’t know if you are a person or a dogbot e-mailing them or tweeting about them, and they can’tt use CAPTCHAs or similar to find out, they might be able to find out if you are human if they began exploring your social graph. Which leads on to the obvious further thought that using customers’ social graphs as an adjunct to conventional credit references and other cardboard-era identity management might deliver some interesting results.

He submits his information to the online-only PotterBank.com, but halfway through the application process, the website asks for his Facebook login. Then his Twitter. Then LinkedIn… A new wave of startups is working on algorithms gathering data for banks from the web of associations on the internet known as “the social graph,” in which people are “nodes” connected to each other by “edges.”

[From As Banks Start Nosing Around Facebook and Twitter, the Wrong Friends Might Just Sink Your Credit | Betabeat — News, gossip and intel from Silicon Alley 2.0.]

Suppose that this works. Then it has security benefits because the social graph ought to prove much more difficult to forge that a photocopy of a gas bill — the gold standard for authentication in the UK — and, some people suspect, it may have additional benefits because the social graph could be more accurate than a conventional credit reference agency when it comes to deciding whether you want someone as a customer or not.

Brett King, CEO of Movenbank, has a radical idea: a “credit score” built — at least in part — on consumers’ social media activity. Sound crazy? Maybe, but the idea has attracted the attention of big league investors who just pumped $2.41 million into King’s startup.

[From Is The World Ready For Social Media Credit Scores? | The Financial Brand: Marketing Insights for Banks & Credit Unions]

Brett is on to something. Whether his “CRED” score and algorithm is correct or not I couldn’t say, but the core of the idea — that if your Facebook friends are bank robbers, you might well be more likely to turn out to be a bank robber — seems wholly plausible. The social graph might be a better predictor of future activity (and future financial services requirements) than past credit scores. The social graph can tell things about you — like you’re going on holiday or getting married or moving to Hong Kong — that an intelligent and customer-centric organisation can act on in a supportive win-win framework. In Christophe Langlois‘ “A practical guide to social media in financial services” he talks about “Know Your Followers” (KYF) as the social media equivalent of “Know Your Customer” (KYC) in compliance. Obviously, KYF isn’t yet a legal requirement, but you get the idea. If organisations develop tools, algorithms and techniques for exploring the social graph then they might find that social media identity, or some kind of social media-based financial services identity, is far better than traditional KYC, credit agencies and old utility bills and predicting which customers they do or do not want.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

Adding MYTH to financial services

Greyscale backing image
[Dave Birch] I’m as exasperated as everyone else about the hopeless nature of identification and authentication for financial services. When I log on to my bank at home, I have a dongle. I can log on from my smartphone using a password (that I’ve forgotten) or I can call the telephone banking centre using a different password (that I’ve also forgotten, so when I last called I had to go through a set of security questions again). If I log into my bank’s credit card subsidiary, I don’t use the dongle but an entirely different password. The dongle used for my work bank account with bank A is entirely different to (and incompatible with) the dongle for my home account from bank B.

This is bonkers: a nearly optimal waste of everyone’s time and money. It’s impossible to understand how we go into this mess, but it should be a lot easier to get out of it. A key reason for this is that consumers now have their own devices — smartphones and tablets — that are capable of supporting strong identification and authentication. There’s no need of the banks to provide smart cards, dongles or anything else. The brilliant Eve Maler (“@xmlgrrl”) notes this shift.

The category that quickly became my favorite was “bring-your-own-token.” BYOT is Forrester’s term for the various methods (sometimes called “tokenless”) that leverage the devices, applications, and communications channels users already have.

[From Strong Authentication: Bring-Your-Own-Token Is Number Three With A Bullet | Forrester Blogs]

BYOT doesn’t quite work for me. Maybe “COD” (customer-owned-device) or “MYTH” (MY THingy) would be catchier. Nonetheless, Eve is spot on. We all know what that thingy would be, by the way.

Fighting technology with technology seems most promising—by replacing ID cards with phones.

[From Fake ID cards: Identity crisis | The Economist]

Without diverting into architecture, it seems transparently obvious that the consumer’s own phone should be their key. In effect, this would enable consumers to deal with a single token and authentication service. That should mean that they are able to take advantage of a framework such as the National Strategy for Trusted Identity in Cyberspace (NSTIC) in a convenient and manageable way. They would be able

to be known anywhere online and reduce passwords down to one password. Those benefits are easy. The core question remains as to how identity is proven by the Identity Provider (IDP). The document says the right things here, but the devil remains in the details of how this will be achieved. How would I, Colin Henderson, be personally identified and associated with my online ID such that a bank would trust it?

[From More on the NSTIC but still not enough on the policy for ID verification « The Bankwatch]

I don’t think this is what will happen in practice, because there is a difference between asserting that an identity is unique and authentication, and asserting that that identity is you or me. I think it will work differently, and in a better way, but since I refuse to provide free consultancy to the government on this, I won’t say how… oh, all right then. Here’s one way it could work…

I log in to some service, let’s say the tax authority, using the complicated question/answer, username/password, e-mail/mobile phone or whatever else it is they use at the moment.

Once I’ve logged in, having established my identity to the satisfaction, not to mention legal minimum standard, for the service provide, I tell them that I’d like to log in future using Barclays’ OpenID service (I’ve made this up, there is no such thing). I put in my debit card number and a message pops up on my phone asking for my personal number. I enter the number. The tax site says OK.

From then on, I can log in to the tax authority using my Barclays’ OpenID service. Barclays isn’t, in this example, telling the tax people that I am Dave Birch or what my NI number is or anything else. All it is doing is tell the tax people that this is the same identity that they, not Barclays, have associated with the tax identity. This isn’t only about banking or financial services. It is, for example, how I had anticipated things would work under the Cabinet Office’s proposed Identity Assurance (IDA) scheme. I go to, say, DWP and authenticate myself to them using whatever antiquated process they see fit, but presumably involving national insurance numbers, mothers’ maiden names and that sort of thing. Once they know who I am, I present my token (imperfectly, in the short term, my mobile phone number). From then, I can log in to DWP using my mobile phone number.

It would be very nice to move towards a minimum standard for token access to private and public services, a sort of standard remote control for cloud identity, though, and preferably one based on open standards. If we bring together MYTH and OAUTH/UMA/OpenID Connect, then, is the problem solved? Can the Cabinet Office or the Payments Council or whoever then mandate the change? Not quite. There are requirements for identity management in the financial services space that are not the same as in other spaces.

For some of the eighty and ninety years olds who spoke to the researchers mobility problems and a lack of experience with modern bank accounts meant they received help from others in making financial transactions. Most commonly, would ask trusted third-parties such as family members or caregivers to withdraw money on their behalf. What is required is some mechanism for delegating small well defined financial tasks to another individual in a way that limits the risk of abuse of the necessary relationship of trust by either party.

[From www.CUHTec.org.uk – New Approaches to Banking for the Older Old]

This is a very good example of the kind of service that needs to be delivered in the financial services space. If I have a senile parent, for example, they wouldn’t delegate their passport to me. But they might need to delegate control over their virtual identity for financial services to me. So I should be able to link the MYTH for my bank account to my father’s bank account for certain limited purposes.

It should be a priority in the financial sector to develop the requirements for the identity and attribute services that they need and a priority for (amongst others) mobile operators to begin developing services that meet those requirements. This is the sort of thing that I will be talking about at the Identity.next conference “Making (y)our business with digital identity” in The Hague on 20th-21st November 2012 so I look forward to seeing you there and discussing what the financial sector’s real requirements for digital identity might be.  

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

Real names, real problems

Greyscale backing image
[Dave Birch] There is an assumption, which is reasonably well-founded I think, that many social media companies want to develop “Real Names” policies of one form or another not to prevent trolling or to protect the kiddies in one way or another, but to help with the commercialisation of their services and the monetization of the identities that they hold. Whereas the identity “Dave Birch of Consult Hyperion” may be worth something to commercial organisations (debt collectors, payday loan sharks and so forth)  — according to real names thinking — the identity “Leadbelly Gutbucket, mightiest of the Dwarven heroes of Ravenscrag Pass” may not. Hence the drive to find out who people really are.

Real Names is slithering into the whole fabric of the company’s offerings, whether specific sites benefit from what will often be “over-identification” or not.

[From IdentityBlog – Digital Identity, Privacy, and the Internet’s Missing Identity Layer]

One of the smokescreen reasons for wanting real names is trolling. I might think that it is my right as an Englishman to post abuse about the Chancellor of the Exchequer on The Telegraph web site, but others think that if I were forced to use my real name to log in then I would be more polite. I say smokescreen, because we don’t even have to guess whether a rigorously-enforced real names policy will make any difference to civility in online discourse, because we already know it won’t. What’s more, we know something else too: if you make people smear their “real” identities all over the internet because of such a policy, thus delivering the “over–identification” noted above, then that will make identity theft worse.

Korean sites were also inundated by hackers, presumably after valuable identities.

[From Surprisingly Good Evidence That Real Name Policies Fail To Improve Comments | TechCrunch]

The Korean case study shows clearly that a real names policy does not reduce trolling because the morons who troll are, well morons. Someone who posts racist abuse on Twitter, such as the noted association footballer Mr. Rio Ferdinand, really ought to understand that other people will read it and take offence since Twitter is a public communications channel (it’s not confined to football: look at the athletes sent home from the Olympics for sending racist tweets). What’s more, the real names policy does more harm than good, because it provides even more sources for the bad guys to obtain the real names that they need to commit other crimes. I read in the minutes of the recent Eurim meeting on the European Commission’s proposal for a regulation on electronic identification and trust services for electronic transactions in the internal market that

Identity fraud is the top enabler for all aspects of crime in Europe, and a major contributor to the Euro-crisis. The level of fraud in Europe last year was estimated at €500 billion, with an estimated €2 trillion for 2011-12. Europol have announced that unless this is addressed, they will be unable to contain crime.

I absolutely guarantee that a misplaced real names policy will make this worse. If you collect real names, things will always end up going wrong. You simply cannot assume that any information you give to organisations will remain private, no matter how well-intentioned.

Witnesses who complained about anti-social behaviour on a crime-hit estate were given police protection after a council error led to their personal details handed to troublemakers… Police are now patrolling a housing estate around the clock to protect the residents involved.

[From Council handed names of residents who complained about anti-social behaviour to trouble-makers – Telegraph]

Oh dear. Doesn’t sound like “real names” are working out too well in that case. Especially since there was no reason for the council to obtain the “real names” of the complainants. This is a case where “real attributes” are the key. The council needed to know that the complainants were council tenants living in a particular area. If we had an identity infrastructure befitting a modern economy (we don’t) then the tenants would have been able to submit their complaint by smartphone and have the text followed by a blinded cryptographic token attesting to their status but from which it would be mathematically infeasible to determine their identity. So no matter what the berks at the council do, the identities reman secret.

One thing that might really help the real names nutters, by the way, is making it easier to spot what are actually real names. If I create a Facebook profile as Theogenes de Montford, for example, how do you know whether that’s a real name or not? It would help if there were a relatively short list of real names, so I suggest that Facebook puts some lobbying money into Sweden.

Activists are lobbying for parents to be able to choose any name for their children (there are currently just 170 legally recognized unisex names in Sweden).

[From Hen: Sweden’s new gender neutral pronoun causes controversy. – Slate Magazine]

This seems like an odd story until you realise that in Sweden can you only choose a legally-approved name for your child. Sensible policies for a better interweb: Facebook should make a list of allowable real names and make you choose a combination of them. That way, any disloyal subject of Her Majesty trying to post abuse about the Chancellor of the Exchequer using a made up name could be instantly spotted and blocked.

P.S. In case you’re interested, Theogenes de Montford is indeed a real name.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

In cyberspace, no-one knows you’re a dogbot

Greyscale backing image

[Dave Birch] We've been talking about real names and real faces and such like for a while. But it looks like there's an even bigger problem lurking out there on the interweb frontier, and it's one that I've been interested in for a long time. 

a study by Steven Gianvecchio at Mitre Corporation, a non-profit technology consultancy in Mclean, Virginia, found that up to 85 per cent of participants in Yahoo chatrooms were bots, as were 15 per cent of Twitter users (IEEE/ACM Transactions on Networking, vol 19, p 1557).

[From Silicon sirens: The naughty bots out to seduce you – 20 June 2012 – New Scientist]

Never mind no-one knowing whether you are a dog or not, no-one knows whether you're even real or not. In fact, we might push a little harder and ask whether it even matters whether you are real or not! Actually, that does matter to a lot of people…

In a recent post on its company page, Limited Run—a New York company that offers website solutions to artists and musicians—claimed 80% of the clicks from its Facebook ads were from bots.

[From Facebook Accused of Click Fraud by Advertiser – Business Insider]

So it's not an academic question. Knowing whether you are dealing with a real person or not is of tremendous importance (in a way that knowing who you are dealing with is not) and we don't seem to have got much further than those stupid, annoying boxes where you have to type in some words that you can't really see properly. Perhaps we should adopt more direct methods.

Erwin Van Lun, founder of Chatbots.org, favours a more drastic approach. He says rather than creating tools to detect bots, it should be humans who have to prove their identities to use the internet.

[From Silicon sirens: The naughty bots out to seduce you – 20 June 2012 – New Scientist]

Erwin is wrong in the general case — no-one should have to prove anything in order to use the Internet — but right in the particular case. It is entirely reasonable that I should be able, for example, to prevent someone registering for commenting on my blog unless they prove that they are human first (almost all of the registrations on my personal blog appear to be bots). But as I noted above, proving you are human is not the same thing as proving who you are, which is why I confidently predicted some time ago that…

Surely one of the most important attributes that OpenID could share is "is_a_real_person" or something similar.

[From Digital Identity: Supply and demand always win]

Once again, this is emphatically not the same thing as saying that people should have to prove who they are to get online and we should not allow the perfectly reasonable need to keep bots out of some areas to send us down a dangerous path.

"Governments are responsible for citizens and issue them passports to travel the world. They should also say, 'We are responsible for your behaviour on the internet, so we will issue you an internet passport'," he says. "That's where it's heading."

[From Silicon sirens: The naughty bots out to seduce you – 20 June 2012 – New Scientist]

Well, I hope that's not where it's heading as that would be a disaster. If you have to have a Syrian government internet passport to get on the web, I shouldn't imagine that that passport would remain valid for too long after you'd visited http://www.assadout.com or whatever. An internet passport should be something different: whereas a mundane passport is valuable because it proves who you are, an internet passport should be valuable precisely because it doesn't. Perhaps we should reset our mental model of passports for the online world. In the olden days, a passport was something that you got from the place you were going to, not the place you were coming from. It allowed a traveller to enter via a city gate ("porte").

In medieval Europe, such documents were issued to travellers by local authorities, and generally contained a list of towns and cities into which a document holder was permitted to pass. On the whole, documents were not required for travel to sea ports, which were considered open trading points, but documents were required to travel inland from sea ports.

[From Passport – Wikipedia, the free encyclopedia]

So, in order to enter the city of Facebook, I should get a Facebook passport. Not a password, note, but a passport. Passwords are a disaster (I will blog more about this shortly). Passports are different because, in my strange world, passports must be based on tamper-resistant hardware and be capable of authenticating their carrier. In order to get a Facebook passport, all I should need to do is prove that I am over 13 and I can do that with a blinded certificate (making it impossible for Facebook to collude with anyone to uncover any of my personal details that I don't want to reveal) given to me by, say, my school. Perhaps other web sites will accept my Facebook passport, or maybe they will want me to get one of their passports. In order to get into my UK bank account I should have to have a UK financial services passport. If I want to play World of Warcraft, then I should get a World of Warcraft passport.

Now, having one passport seems easier. And so it is in the realm of mundane travel. You can imagine what a hassle it would be to have to have hundreds of passports for visiting different cities around the world. But in the virtual world this is nothing. My phone could easily store hundreds of passports. And, actually, I'm sure it will.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

You don’t have to be psychic, but it helps

Greyscale backing image
[Dave Birch] When I said that I was genuinely surprised to find my talk on digital identity featured on TED, I meant it. I’ve really enjoyed the conversations that it has sparked with colleagues and clients alike, particularly around the issues of anonymity and pseudonymity. I think that some people find these issues a little esoteric when first raised, because we’re not accustomed to think about identity as a spectrum. We’re used to the idea that you have an identity and that’s that. But as the real world continually shows, the more sophisticated view of identity gives us a better framework for dealing with problems and that suggests, to me at least, that digital identity is the way forward.

The Times points out that Inspector Winter, the anonymous police blogger and Twitterer who made such a name for himself with his “front line” accounts of the London riots in the summer that he got commissioned by this newspaper for a first-person piece, is in fact not a policeman at all. He is a man called Ellis Ward, a 29-year-old fantasist and fraudster who is in jail for credit-card fraud and is under investigation for impersonating a police officer.

[From The Times continues its tradition of revealing the identity of police bloggers – Telegraph Blogs]

Here is a perfect example of how cryptography can help. The newspaper needed proof that a blogger was a policeman, but should not be able to identify that policeman or collude with (potentially corrupt) third-parties to uncover the policeman’s identity. (The policeman will not blog if his identity can be uncovered but society as a whole is better off if he does.) How does psychic identity achieve this? It’s through a technique called “blinding”. This is not even remotely new or innovative: It’s twenty years since the cryptographer David Chaum published his seminal article in Scientific American on “Achieving Electronic Privacy” (August 1992, p.96-101) in which he said…

I have developed an extension of digital signatures, called blind signatures, that can restore privacy.

[From Achieving Electronic Privacy]

The idea is this: Alice is a policewoman. She generates a random number: let’s call it her WHISTLEBLOWER key. She multiplies this by a number known only to her, the blinding factor, to form the blinded product. She signs the blinded product with her Police Federation key and sends it to them. They know she is a policewoman from the signature.

They extract the blinded product to make a new certificate containing the blinded product and sign it with their key to create an IS_A_POLICEOFFICER certificate which they send back to Alice. Alice divides out the blinding factor so that she now has an IS_A_POLICEOFFICER certificate that contains her WHISTLEBLOWER key but cannot be traced back to her.

Now, let’s say Alice has to prove to The Times that she is a police person. So she pops in to an internet cafe and creates a Hotmail account. She sends a message to The Times signed with the WHISTLEBLOWER key together with the IS_A_POLICEOFFICER certificate. The newspaper checks that the Police Federation’s signature is valid. It is, so they know that owner of the WHISTLEBLOWER key is, indeed a police officer. But even if they send the certificate to the Police Federation, they do not know who Alice is.

Now when the newspaper wants to communicate with Alice they encrypt the message using her WHISTLEBLOWER key and send it to her Hotmail address. Since Alice has the private key that belongs to the public WHISTLEBLOWER key, she is the only person in the world who can read the message. The message can be published on The Times website or in a blog or anywhere else. It doesn’t matter, because no-one else can decrypt the message. Under this kind of scheme, it would be very difficult to forge an e-mail because any newspaper you send it to would expect your to provide a certificate attesting some relevant attribute: that you are an MP or you are French or you have a Portugese fishing licence.

The forged email, sent in May, was subsequently “leaked” to the Independent newspaper, which exposed the message as a fake after attempting to trace the sender.

[From Tory MP caught up in Syrian propaganda row with fake ‘colonialist’ email – Telegraph]

This may seem complicated, but it isn’t really and, what’s more, it could easily be under the hood. You could image seeing a menu on your phone that says “create a new identity” and then being offered the choice of a personal identity, a persona (an identity used to create pseudonyms) or a “whistle blowing” identity as described above. Perhaps this might be a corner of the new digital economy that it makes sense for newspapers (and other news sources that want to be trusted) to invest in. After all, they have a direct interest in sorting real from fake sources as well as a tradition of protecting those sources. Why not issue blinded certificates to sources and have them mutually-recognised by news organisations that belong to some kind of international OIX-style group?

Digitally-signed e-mail has been around for years and virtually no-one uses it. But perhaps using cryptography to prove who you are is not as interesting as using it to prove what you are.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Friendly fire

Greyscale backing image
[Dave Birch] Some time ago, in the early days of Twitter, I happened to be involved in some work concerning a financial institution’s social media strategy. I was rather rude about the idea of setting up a Facebook page, because I couldn’t see the point, but it was nothing to do with me or any of the other technical persons. I was reminded of this episode this morning, when I read about another organisation’s Facebook-related travails.

It wasn’t long before Barclays’ Facebook page devolved into a minefield of jokes lambasting the company, which only served to highlight the socioeconomic rift between the banking institution and its customers.

[From Epic Fail: Barclays’ Facebook Debacle Highlighted the Chasm Between the Bank and Its Customers]

Well, given current circumstances this is hardly unexpected. As a naturally curious person, I thought I’d go and look at a few bank Facebook pages to see what sort of things they did. But I gave up almost immediately, since I realised that I’d have no way of knowing which of them might be real or not. Here’s what I got when I searched for Lloyds, for example. Real? Who knows. It’s certainly boring enough to have come from a bank, but that’s not much of a clue. Still, given Facebook’s noted “real names” policy, it probably is true and I’m sure it’s safe, just like the NatWest page that I found. I went to the Barclays Online Banking Facebook page and I couldn’t even work out what it was. This Barclays’ page looks quite plausible, but as a security-concious consumer I wasn’t sure whether to click on anything or not. Perhaps the British Bankers’ Association has some list of the real Facebook pages. I’ll check.

In the meantime, I expect that if I call NatWest they can point me to the their public key certificate that I can use to check the digital signature on the Facebook page so that… no, just joking. But all of this begs a more general question. What was the Facebook page for? What could customers do? Open accounts? Send money? Pay bills? No. As is generally true of Facebook pages for financial institutions, it was all about communications. There’d be no point a bank e-mailing my kids since they never read e-mail, so I suppose if you could persuade them to “friend” your bank you might be able get the odd status update into their field of vision.

At the Credit Suisse Research Institute 2012 meeting, experts discussed the benefits of social media over traditional communication tools, as well as the constraints – the most significant of which regards the current regulatory environment.

[From Credit Suisse – Banking on Social Media]

In fact, all of this potentially interesting discussion was actually about marketing. I’m no expert on marketing or social media, but I would imagine that the key to social media strategy is interaction and the whole web 2.0 thang about user-generated content and such like. For any organisation to just use a Facebook page to broadcast marketing messages seems like a missed opportunity for a richer connection with customers. If this is the right line of thinking, then the strategy ought to consider what customers might actually want to do in that context. For banks, I suspect that what they want to do is transact. What about the benefits of social media over traditional transaction tools? As I’ve said before (many times)

I’m naturally more interested in social media for transactions: social commerce.

[From Friends and relations]

I’ve bored some of our clients about this enough over the last couple of years, and I won’t rehearse the arguments here, but I will say that I think there’s evidence that the social commerce approach for financial institutions is sound. Customers want to do banking in their context and given that their context is increasingly within social media, it makes sense to move banking there.

Facebook announced that it is testing an online-banking service with Australia’s Commonwealth Bank expected to debut this year. The new system lets people make payments to other Facebook users, and will become a test of how well Facebook can handle the deep-science realities of financial privacy and security.

[From Facebook Announces Online-Banking Test – Forbes]

If Facebook do crack the privacy and security side of things, then they will become the route to banking for a great many consumers, frankly, and I don’t know whether financial organisations of all kinds have yet developed an effective strategy to deal with social media gatekeepers other than to pay them. Perhaps if their products and services could develop a direct relationship with the customer using social media channels (rather than simply provide those products and services inside the social media context) then they can become valued by customers.

I don’t want to be friends with my bank—after all, I’m a typical consumer so I hate banks—but I do want to be friends with my bank account.

[From Friends and relations]

My Barclays mobile banking app works really well and I can’t imagine any circumstance under which I’d bother going to their Facebook page, even if I could work out which one it is, but I might be tempted to venture outside the app if for richer social media interaction. At the moment Barclays interaction with me is basically limited to alerts by text message, which is fine, but does waste their money as well as limiting the amount of information. I’d rather have richer data sent through Twitter or as Facebook updates or whatever. Why can’t I have every transaction on any of my accounts sent through to me? 

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Security isn’t the killer app for digital identity

Greyscale backing image
[Dave Birch] Over at the London “Internet Identity Day“, there was a fleeting discussion that I thought deserved more reflection. It was about the extent to which secure e-mail or secure document transfer is a driving application for digital identity. I’d been thinking about it a couple of weeks ago because Cory Doctorow’s review of Tom Watson’s book on the Murdoch “hacking” scandal touched on an aspect of the story that has been bothering me.

But what on Earth are all these rich and powerful people doing sending unencrypted emails? Why do ministers of the government use voicemail servers operated by big, dumb phone companies like Vodaphone, instead of privately maintained Asterix instances run by Parliament’s IT department… How is it that lawyers and clients send cleartext documents to one another, and how is it that ministers and civil servants keep the nation’s most important information on unencrypted hard drives?

[From Dial M for Murdoch: exhaustive account of the UK tabloids’ criminality and the resulting coverup – Boing Boing]

I saw a similar comment in a newspaper discussion (apologies for not remembering where) about the Barclays rate-fixing scandal. A reader wondered why any bank would employ traders stupid enough to commit a conspiracy to e-mail and instant messaging logs that the knew were being monitored unless they were a) genuinely unaware that what they were doing was wrong or b) idiots who didn’t understand how the interweb tubes work. Surely, you would think, if you were a clever trader who want to conspire with peers you would devise some sort of code that didn’t look like a code, a bit like the British fishermen in the cod wars.

From 1928, the British trawlers were equipped with radio and started passing coded messages between themselves to alert each other when Coast Guard vessels were in and out of harbour. “Grandmother is well” meant that the Coast Guard were in port, for example. In an early example of governments attempting to legislate new technology, the plucky Icelanders made it illegal send to coded wireless messages. This had no impact whatsoever, of course: British seafood companies simply devised new code systems for the trawlers to use. Think about it: how on Earth would an Icelandic wireless operator know whether “Tottenham Hotspur are the pride of North London” was a coded message or gibberish?

[From Digital Identity: Codpiece]

Why didn’t they use secure messaging anyway, just in case rival traders were peeking at their stuff? I may know. A while back, one of Consult Hyperion’s financial services customers was working on a project that they wanted to keep under wraps, so they asked us (along with some of the other suppliers) to encrypt and sign all project documentation. So we all went over to using S/MIME. It took, as I recall, a few days of constant messing about to get the right certificates distributed and installed in Outlook, then we were good to go. It lasted about a day before the customer’s IT department asked us to turn off encryption, because the spam filters at their end were escrowing all encrypted messages because they thought they might be viruses, or something like that. So we turned off encryption and went with signing only. This lasted about a day more, then we were asked to turn that off too because it didn’t worked properly with the corporate e-mail gateway. So we went back to what we were doing before, which was putting documents into passworded zip files. 

OK, so perhaps I do understand why Ministers of the Crown are sending plaintext. Hardly satisfactory, and not only because agents of foreign powers might have access to the Right Honourable Member for News International’s e-mails. With no identity infrastructure, and therefore no workable encryption infrastructure on top of it, there’s nothing that can be done about this. But with a working identity infrastructure, as was pointed out at ID Day, this becomes a straightforward problem to solve: you encrypt e-mails with a key that is backed-up and made available to law enforcement after due process and you sign e-mails with a private key that is kept in tamper-resistent hardware and never disclosed. If hackers, journalists or the council get into your e-mail, it’s all encrypted and they can’t read it. End of. It’s  not rocket science. I’m not saying that technology can completely override traders. For example, we’ve all pressed “reply to all” by mistake and sent messages to people who weren’t supposed to see them. 

A banker at UBS has allegedly cost the Swiss bank an estimated $10m (£6.2m) in fees after he sent an email detailing General Motors’ upcoming flotation to more than 100 people.

[From Rogue email ‘costs UBS $10m in GM fees’ – Telegraph]

But what is the demand for secure e-mail, secure messaging and secure storage? After all, secure e-mail has been around in principle from the earliest days of the interweb and still no-one uses it. The idea of the “digital post office” comes round from time to time to build on this.

Australia Post has announced it will create a “Digital MailBox” for every Australian, as of April 2012.

[From Australia Post launches inbox and cloud storage for all • The Register]

Perhaps the time is right, but I can’t help observing that a great many such initiatives have come and gone. I just don’t think that this sort of thing will be the “killer app” for identity infrastructure. People say they care about security but they send e-mails in plain text, conduct criminal conspiracies on instant messaging and leave files on password “protected” cloud stores. I think we should look elsewhere, at areas where identity security is a real problem. Reid Hoffman made a good point about this in Forbes a while back.

Validated check-ins and reviews: One potential downside of most consumer review sites is that published opinions are dominated by a small, vocal minority. There’s value in getting a broader sampling of people to share their views. A growing percentage of reviews on sites like Yelp and check-ins on sites like Foursquare will over time be tied to actual transaction activity. When you and your friends buy, you’ll be asked via email or text message if you’d like to check-in or provide a review. As a result, more customers will provide feedback and recommendations, and the information they provide will be better validated, in connection with actual transaction activity. A review or check-in will carry additional weight when it’s been validated.

[From The Credit Card Is The New App Platform – Forbes]

As I have long advocated, linking reviews to wallets is a good idea but it needs a bit of special sauce to ensure honesty: pseudonymity. When you pay your hotel bill, your wallet sends a blinded token to the hotel which then signs and returns it. Your wallet unblinds the token. When you log in to Trip Advisor, or whatever, you can send the token to them. The token proves that you stayed at the hotel, but is mathematically unlinkable. Trip Advisor and the hotel and the other viewers can know for sure that you stayed in the hotel but your Trip Advisor account can remain anonymous. It’s a win-win-win and would put code into wallets that would give us all of the other security we want (e.g., secure messaging) as a byproduct.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

 

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.