Never mind real names, what about real faces

Greyscale backing image
[Dave Birch] Predictions are difficult, as they say, especially about the future. Earlier in the year, we were trying to imagine what financial services would look like 50 years from now. There are different approaches to this kind of futurology. 

The year was 1999, and Steven Spielberg was preparing to turn Philip K. Dick’s short story “The Minority Report” into a $100 million action movie starring Tom Cruise. There was just one problem… he wanted his film to be a realistic depiction of how things might actually look in 50 years. So Spielberg convened an ad hoc think tank: He invited a small group of the foremost thinkers in science and technology, along with a handful of people involved with the movie, to hang out for a weekend and talk about the future.

[From Inside Minority Report’s ‘Idea Summit,’ Visionaries Saw the Future | Underwire | Wired.com]

They missed something. Something that occurred to me while watching Soylent Green, one of my wife’s favourite films. We watched it again a few months ago. It has a great story, great acting and is wonderfully directed. But it doesn’t work for me any more. The future New York, that looked so real to me a few months ago, looked odd. After a while I realised why: no mobile phones. No movie set in a future that is now, or soon, works any more without mobile phones in. It looks funny to see people walking around without mobile phones. This made me ask the “Spielberg Question”: What would an accurate science fiction movie of future New York look like?

I think I’ve got an idea. It begins with “real” names (again). I’d been thinking about “real” names on Facebook in the context of using the social graph as an alternative to conventional credit checking agencies, and it occurred to me that a combination of the social graph and face recognition might tell you which social graphs a person belonged to, irrespective of which social graph the profile that they gave you belonged to, if you see what I mean. So you could form a pretty accurate opinion about someone given a picture of them and no other details. Last week, I discovered that Mark Zuckerbeg, being considerably smarter than me, had already thought of this.

The social network this week acquired Face.com, a face-recognition technology company whose Facebook and mobile apps can identify people’s faces in photos.

[From Why faces matter to Facebook – CNN.com]

Note that you can change your privacy settings so that if you are tagged by face recognition in a photo that someone uploads, the tags are not made public. But they are still there, of course, in Facebook’s database. This made me wonder if the face recognition could be used for identification for Facebook’s own purposes.

Facebook on Thursday began asking certain popular users to upload photos of their government issued identification cards to help the social network test a new accounts verification service… Facebook did not elaborate on how exactly it will go about verifying the IDs or the accounts supposedly attached to them.

[From Facebook Asking Some Users To Upload Government Issued IDs | TPM Idea Lab]

This seemed a bit pointless to me, unless Facebook could have access to the government databases in order to verify the documents. Unless… what if Facebook has no intention of using your Portugese fishing licence to identify you by contacting the Portugese fishing authorities to find out of the licence is valid and who it was issued to and what supporting documentation was provided? What if they just want the photo so that they can feed it into the face recognition database. Once the face recognition can tie your profile to a real identity, any real identity, then it’s suddenly worth a lot more to certain kinds of apps.

A Wall Street Journal examination of 100 of the most popular Facebook apps found that some seek the email addresses, current location and sexual preference, among other details, not only of app users but also of their Facebook friends.

[From Selling You on Facebook – WSJ.com]

Now hitherto this sort of thing didn’t bother me, because none of my Facebook profiles are in my “real name”. I tend to use Facebook Connect to log in to things here and there because I’m very lazy and because the “default” Facebook profile that I use is, in itself, an experiment. On more than one occasion, however, I’ve gone to log in to something using Facebook and then cancelled out when the site asks for access to the social graph that includes my actual friends. Apparently plenty of people don’t, and I can see the argument that it’s much harder to forge a social graph then an identity. But that’s now, because social graphs are new.

I’m sure there are plenty of people like me who have been growing entirely false social graphs for some years now. I do it as an experiment, but I suspect other people will be doing it for more sinister purposes. It will surely be a matter of time before criminals sell fake social graphs, just as they see fake identity packages right now. Look at last week’s example in the UK: criminals were selling identity packs that included bogus utility bills, letters addressed to the fake identity and other “support” around counterfeit passports and driving licences and that sort of thing.

The Metropolitan Police has warned it is working to track down 11,000 customers of a gang that specialised in providing fake IDs.

[From BBC News – Identity theft gang’s customers wanted by police]

Can we get round this by getting people to hold up a driving licence to a webcam? By itself, no. Since Facebook has no idea whether the photocopied driving licence that I’m scanning in is real or not, or whether it’s mine or not, or whether it’s me that’s holding it up or not, that’s not going to help. China has already tried the Facebook approach anyway.

People with computers and Internet connections at home have no problem with the new rules, which generally do not effect them. Lower income individuals, including migrant workers, are hit much harder by the new rules. Some parents, believing that their children will continue going to Net cafes despite the new rules, expressed concern that the restrictions will drive them to “black cafes” that may be unsafe.

[From China’s Internet Cafes Respond to ID Check Rules | China Hearsay]

In other words, the requirement for increased identification and authentication merely drives people to access in completely unregulated an unauthorised ways. But there’s another Chinese system that Facebook might want to look into. David Moss commented on the accuracy of face recognition systems that are not good enough for prime time yet. But they are improving all the time. If Laos can do it, I’m pretty sure Tesco or British Airways can.

I crossed from Laos to China last year and imagine my surprise when my name was called out before I had even crossed the white line in front of the immigration control desk.

The officious looking guy was actually quite chatty and he revealed they were trying to improve their service by greeting people personally. He showed me my mug shot on their screen alongside their reference visa photo.

Turns out that the visa photo you supply (all nicely trimmed with a special device they supply) are fed into their face recognition system so upon arrival they are able to greet you!

[From No hiding place – facial biometrics will ID you, RSN • The Register Forums]

Why does Facebook need you scan any documents at all when they can just let their face scanning software potter around in the database and match up tagged photos with profiles? This will make Facebook an electronic Chonqing.

The Chongqing Municipality has signed a contract with China Electronics Technology Group Corporation (CETC) to build China’s biggest video surveillance system, based on the Internet of Things (IoT) technology, the China News Service (CNS) reported Monday. The video surveillance system will cover Chongqing at its entirety with cameras and wireless sensors… Over half a million cameras will be installed in the main districts of the city.

[From Chongqing to build China’s biggest IoT video surveillance system – GlobalTimes]

So in the future your face will constantly be monitored both online and offline. Hence my prediction about future New York. Any science fiction film that doesn’t show everyone wearing burkhas in public will look as dated as Soylent Green. Think about it. One reasonable working definition of “privacy” is the one founded on choice: it’s about choosing what you reveal to people. So, how can you make this choice in a world of ubiquitous face recognition, social graphs and annoying “friends” with camera phones? The answer is the burkha, hence my new business venture. Facebook blue burkhas for the connected citizens of the future who want some, or indeed any, privacy.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

 

Barcode everyone at birth

Greyscale backing image
[Dave Birch] For a variety of reasons, identity and identity management are back in the mix. With yet more in the newspapers here about internet trolls and the perils of “anonymity”, I think I can see the early signs that personal identity in the 21st century is going to be a political battleground. Something, frankly, needs to be done. But what? The BBC’s “60 second idea” slot had an interesting idea about identity.

This week science fiction writer Elizabeth Moon argues that everyone should be given a barcode at birth… “If I were empress of the Universe I would insist on every individual having a unique ID permanently attached – a barcode if you will; an implanted chip to provide an easy, fast inexpensive way to identify individuals.

[From BBC – Future – Technology – ‘Barcode everyone at birth’]

As far as the barcode I idea goes, I’m afraid Elizabeth is behind the curve. A group of Eastern European entertainment entrepreneurs had this idea some time ago and have been conducting a rather revolting pilot scheme.

Spanish police arrested 22 suspected pimps who allegedly used violence to force women into prostitution and tattooed them with bar codes as a sign of ownership

[From Barcode Pimps: Gang Suspected Of Tattooing Women Forced Into Prostitution Arrested By Spanish Police]

Maybe not barcodes. Actually, the idea of implanting chips isn’t in the least bit new either. We used to have fun a few years ago talking about examples such as the Barcelona nightclub that used the Verichip as a substitute for a VIP Card. I wrote about this back in 2006!

It sounds bizarre, I know, but remember that everyone’s current favourite case study for this sort of thing is the Baja Beach nightclub in Barcelona, where patrons were offered the choice between a card and a chip and some of them chose the chip.

[From Digital Identity: Chip ’em all]

People were very surprised that some of the patrons opted for a chip, but I wasn’t. It sounded rather fun to me. In fact, I tried to persuade the company involved to inject a chip into my arm on stage at a Digital Identity Forum (I think back in 2007) but they absolutely wouldn’t because their insurance didn’t cover the UK. Nevertheless, I think the chip idea needs a little more thinking through. For one thing, it’s already been tried for non-entertainment purposes, and the result indicates to me that it might more properly be considered as a convenience technology than a security technology.

With kidnappings spiraling out of control in Mexico and extensive evidence of police complicity, Mexico is apparently seeing rising demand for anti-kidnapping chips sold by a company called Xega. In essence, they’ll install an RFID chip under your arm so you can be tracked if kidnapped.

[From Soaring Demand For RFID Chip Implants In Mexico As Kidnappings Continue To Rise | ThinkProgress]

Well, that sounds like Elizabeth’s idea in prototype, so I wonder how it has been working out.

This is, of course, not a foolproof solution as in one case “an armed gang invaded Fernandez’s home, sliced open his arm with a pair of scissors and extracted a satellite-enabled tracking device, leaving the chip and a streak of blood behind.”

[From Soaring Demand For RFID Chip Implants In Mexico As Kidnappings Continue To Rise | ThinkProgress]

Uh oh. Chipping people isn’t going to help. Chips make sense in the case where the convenience of RFID is married to the chip tamper-resistance in environments where people want both of them. Like the nightclub.

An Ohio company has embedded silicon chips in two of its employees – the first known case in which US workers have been “tagged” electronically as a way of identifying them.

[From US group implants electronic tags in workers – FT.com]

We’re probably close to the point where camera technology and face recognition algorithms will render this implementation redundant so what I would say to Elizabeth is that we already have unique identifiers given to us a birth — such as our DNA — and they are not really the problem. The problem is the two-sided digital identity binding that we’ve written about so many times before: how do we bind the physical person to the digital identity, the problem that is solved through biometrics, and how do we bind the digital identity to the virtual person, the problem that is solved through certificates. No-one needs to barcode anyone.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

 

 

I’m authentically not real

Greyscale backing image
[Dave Birch] The whole “identity thing” has been obsessing me because I’ve been invited to give my first TEDx talk at TEDxSussexUniversity later this week and I decided to talk about identity. I thought I’d try my PsychicID idea out on a different (i.e., not identity specialists) audience to test it out further. As far as I’m concerned, the need for it is growing.

According to Sheryl Sandberg, Facebook’s chief operating officer, and Richard Allan, its director of policy in Europe, a critical mass of people only want online interactions supported by “authentic” identity.

[From Online identity: is authenticity or anonymity more important? | Technology | guardian.co.uk]

They’re not even wrong about this. Authenticity and anonymity are not on the same axis. My Facebook profile is entirely authentic, it just doesn’t share my mundane non-unique sort-of-identifier (i.e., name). So what? Why would anyone need to know that my Facebook profile is in my “real name”? Well, apart from people who want to harass children, for example…

In an recent investigation, the TV station MSNBC found that many university sports departments now require students to “friend” their coach, giving officials access to their “friends-only” posts.

[From 12-year-old US girl suing school over Facebook comments row – Telegraph]

It’s really interesting to see how the “etiquette” around this is evolving. I picked up on it a few years ago and had the feeling then that the way the Facebook generation see identity will redefine they way society as a whole will come to see it in time, which is why attempts to force “old” identity notions on to them are doomed.

The kids aren’t stupid: they live in that world and they can distinguish their multiple virtual identities. Faced with a privacy violation that undermines a virtual identity, they slash and burn.

[From Digital Identity: Bring it on]

Quite. And why shouldn’t they? Why shouldn’t I have two Facebook identities, one for my work friends and one for my friends and family? And if want them to be able to connect me, then that should be up to me. I can easily have an identity that is authentic and anonymous.

The issue here isn’t anonymity. It’s privacy. Facebook should be looking at ways to deploying Privacy Enhancing Technologies (PETs) as part of its fundamental infrastructure. This is at the heart of my view of digital identity: that the only way to meet the requirements for security and privacy is stop seeing them as opposites or countervailing forces to be balanced, but as the simultaneously achievable goals of a properly designed identity infrastructure.

Many people do think eID could and should be implemented without full identification, i.e. more granular disclosure with pseudonymity – see e.g. Dave Birch’s brilliant and very readable paper “Psychic ID: A blueprint for a modern national identity scheme” (PDF).

[From Tech and Law: PETs – Stephan Engberg’s response]

So this is what I’m going to talk about on Friday: why Dr. Who should be our national design authority for identity infrastructure for 21st century because Dr. Who (and not Martha Lane Fox or the Cabinet Office) has a narrative about the future of identity, authentication and credentials that everyone can understand and buy into. And he’s already shown us that he uses NFC. We’ll see how it goes.

But back to the problem space. If my Facebook profile is the name of Ziggy Startup, and all my friends know this, then what’s the problem? It’s not really anonymous is any sense: if Ziggy Startup starts making off illegal posts, then it won’t take long for the police to get a warrant for the IP address and password and Ziggy will be off down the nick.

A man was jailed yesterday for posting videos and messages mocking the deaths of teenagers including a girl who threw herself under a train.

[From Internet ‘troll’ jailed for mocking dead teenagers on Facebook – Telegraph]

These people are pathetic, revolting and deserve the appropriate penalties, but they’re not a reason to make a fundamental and unrecoverable mistake in the design of the future online world. Since we don’t have a national narrative around the future of identity, it’s been abandoned to competing national security and commercial imperatives. Indeed, some observers would say that this is what’s really going on with all the fuss about “real” names at the moment.

Is it possible that free and expressive social logons will take over where bank and government identities have failed to interoperate? Or will the higher risk management standards of serious online transactions remain beyond reach of the cyber brands?

[From A new theory of digital identity – Networks – SC Magazine Australia – Secure Business Intelligence]

The battle over “authentic” identities is a power struggle. If the social networks are able to enforce it (I’ve no idea how they might do this, but let’s say they can) then they have a fantastic business opportunity because they will be able to leverage their arbitrage around personal data even further: how much more will advertisers pay for a list of people interested in whatever-the-f**k-it-is if they get the real identities too? If you know who everyone is, then you have much less risk to manage anyway. But the nightmare (for my clients anyway) is that they’ll end up having to offer Facebook Connect as a login otherwise they get no customers, and then Facebook know exactly what customers are doing all of the time.

On the one hand, I think good for them. The banks are doing nothing sensible in this space: they are messing around with one-time-passowrds by SMS, EMV-calculators thingies and a variety of incompatible dongles, when they should be working on an industry standards-based infrastructure. But is it good for us to abdicate responsibility for identity infrastructure and hand the whole thing over to Facebook?

I love Facebook. I use it many time every week to keep in touch with friends and family. What they should be doing is introducing optional 2FA (to end the problem of “fraping”, for one thing) and moving to an NSTIC framework to accept identities from identity providers that meet certain standards. So if I turn up at Facebook with a Barclays identity that says I’m Ziggy Startup, then that should be fine. Facebook don’t need to know who I am, all they need to know that someone knows who I am. If they insist that they need to know my “real name”, then it’s because they expect to exploit this for commercial opportunity – it has nothing to do with protecting children.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

Frenemy of the state

Greyscale backing image
[Dave Birch] More on Facebook’s “real names” nonsense. Their S1 filing admits to 1 in 20 bogus accounts, but who knows what the real figure is. None of my Facebook accounts are in my “real name” and I doubt I’m the only one.

“There may be individuals who have multiple Facebook accounts in violation of our terms of service, despite our efforts to detect and suppress such behavior. We estimate that false or duplicate accounts may have represented approximately 5-6% of our MAUs as of December 31, 2011.”

[From Major Changes In Facebook’s Amended S-1: Mobile Ads, Zynga, Yahoo Patents, Credit | TechCrunch]

I don’t really care about this, except for the fact that if people believe that Facebook, or any other online space is a “real name” space, then that does more harm than good because people who don’t really understand how all of this works could be misled and I can see how that might lead to problems. Still let’s hope that some people (e.g., sex offenders) do use their real names…

A new app will let you check all your Facebook friends against the National Sex Offender Registry.

[From Are Your Facebook Friends Sex Offenders?]

This isn’t all about dating scams, crime and teenage bullying. It’s national security as well. How Facebook know whether someone’s name is real or not I have no idea, and I certainly don’t believe for one moment that they are capable of distinguishing agents of foreign powers from “legitimate” users. Nor, for that matter, is anyone else.

NATO’S most senior commander was at the centre of a major security alert when a series of his colleagues fell for a fake Facebook account opened in his name – apparently by Chinese spies

[From How spies used Facebook to steal Nato chiefs’ details – Telegraph]

I read this with a certain nostalgia. When I worked at the Supreme Headquarters Allied Personnel Europe (SHAPE) Technical Centre in the Hague in the early 1980s, my first day on the job began with an extensive lecture on the security responsibilities attendant on our clearance level. I was working on a project concerned with keeping secure communications networks up and running in the event of a Russian nuclear attack, which was quite interesting, and once we had been sternly advised to be wary of beautiful tall blonde Eastern European women striking up conversations with us in supermarkets, I spent literally every waking hour of my young life praying for this to happen. It never did, but if there are any beautiful tall blonde Eastern European women who have any interest in white-noise jamming of direct sequence spread spectrum satellite channels, here are my contact details:

STC Card

My point: people are misled by the social network environment and so they make poor decisions. We already know that men will do almost anything if asked to by an attractive woman:

The story also revealed another sad truth, a reflection on human nature. Men will do anything for an attractive woman, without even bothering to check whether she’s real or not.

[From Digital Identity: Linked]

And we already know that woman will do anything for a handsome non-existent soldier. Absent a working identity infrastructure, we really shouldn’t let people meander along under the impression that social media identities a real. Which, by the way, did make me wonder about the wisdom of publicising the NATO story. Wouldn’t it have made more sense to to pretend to go along with the “Chinese spies” and feed them misinformation rather than let them know that you had blown their cover. Haven’t these NATO guys ever read “The Zimmerman Telegram“? I thought this was high up on the reading list for anyone entering a career in a security-related profession. It would be have been infinite to friend the American brass with a convincing bogus Ahmadinejad and then start posting stuff about shipping centrifuges to Tibet and such like.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


Reviews and reviewers

Greyscale backing image
[Dave Birch] There’s a long running debate going on about whether people should be able to post online without disclosing their “real” identity. This is getting especially heated around online review sites. Remember this row — one of many — about Trip Advisor?

He said he is considering suing the site over what he claims is a “dishonest” review published about one of his hotels and accused the internet giant of trying to “bully” him into silence using threatening letters

[From Duncan Bannatyne to campaign against ‘cowardly’ trip adviser – Telegraph]

Look, review sites aren’t going to go away. And they are a good thing. I happened to be talking about reviews to my wife yesterday. She regularly uses a particular web shop to buy all the usual household stuff that neither of us can be bothered to go to the shops for: in yesterday’s case, a new mop for the kitchen floor. She uses that particular site precisely because it publishes bad reviews as well as good ones. When she last looked for a new mop, the one she looked at had very bad reviews. Yesterday, she looked again and there was a new mop, with good reviews. So she bought it. How can you trust good reviews unless you see the bad ones as well?

We need review sites: they are way to make a market more transparent and improve the quality of goods and services. Therefore, making the reviews work is important. How do you do this?

Here’s a question to get the thinking underway: if you let people post under assumed names, will they post rubbish? Can you trust a review site where you don’t know who anyone is either, whether they are astroturfing for corporate puppet masters or opening up information for the people? I travel a lot, so I post a lot on Trip Advisor. But I don’t post under my “real” name – I don’t see why who I am is material. Consequently, I was most interested to read a thorough corroboration of my theory that a pseudonymous interweb is a better interweb.

The platform, which enables people to comment across multiple websites via the same identity, has just released data showing that pseudonymous participation is actually the healthiest type.

[From Disqus data shows pseudonymous commenters are best « Mariamz]

Well, well. I can think of many reasons why this is true (one of the main ones being that people reveal their real likes and dislikes, prejudices and opinions, views and perspectives under pseudonyms whereas they are alway constrained when using their “real” names) and it certainly matches with my experiences in online chat and debate environments.

Personally, whether it’s positing abusive messages about government ministers or arguing about the merits of a return to the gold standard, I always use pseudonyms unless I am posting in a professional capacity, in which case (I  sincerely hope) my expertise and experience is relevant to the discussion at hand. In some cases I use the same pseudonym across multiple sites, in other cases I use a specific pseudonym.

Pseudonymous identifiers are random identifiers that change for each relying party (so my identity at relying party A might be 123 while my identity at relying party B might be 345). Good pseudonymous identifiers are large random values (so that they are unpredictable) and are not reused across multiple users (so the same identifier is never used at different relying parties for the same or different users).

[From Conor’s Web Log of Esoterica: Pseudonymity would help]

Right. So pseudonyms deliver the best online interaction. But, I will hear you say, who can this scale? With interaction through pseudonyms, there will always be people — even if a tiny minority — getting up to no good. What if you are small business and you get a review like this?

The review said: “Robbed My RAM and Touched 9 Year Old What a scam artist, he stole RAM from my computer and replaced it with smaller chips hoping I wouldnt notice and also I later found out touched my 9 year old inappropriately. A Violator and a rogue trader. DO NOT DO TRADE WITH THIS MAN!”

[From BBC News – Google removes ‘paedophile’ claim on review website]

How can you take a civil action against someone for posting a defamation or libel or malicious accusation or whatever? How can you make sure that someone posting a review is actually a customer?

The solution is to institute a simple system of pseudonymous tokens — cryptographic tokens, I mean — so that you the customer can only post a review of something if you have a token showing that you used it, and it should take a court order for the token provider to reveal the person who had the token. This is technologically trivial and can easily be achieved using well-known and well-understood techniques for cryptographic “blinding”. A “blinding” service would work something like this: when you register at the hotel, the hotel chain e-mails you a URL. Later on, you log in to that URL and the system generates a “blinded” token that the hotel chain digitally signs and sends back to you. Whereupon you unblind it. To write a review, you must submit the token. The review site can easily check the digital signature from the hotel chain that proves that you did stay at the hotel during the previous month (or whatever) but doesn’t link to your identity. The hotel can be sure that you were a customer, but neither they nor the review service know who you are. If you post something that is against the law, a court can then order the blinding service to turn over the connection.

It’s not only review sites that might make use of such a service because there are many sites where who you are is material to the discussions and there may be not entirely honest reasons for using a pseudonym.

The chief executive and chairman of cashless payments vendor USA Technologies has resigned over “inappropriate” comments he posted on the Yahoo Finance message board… George Jensen posted approximately 450 comments on the forum, primarily under the alias ‘investor.texas’.

[From Finextra: USA Technologies CEO quits over message board posts]

Which reminds me of something. A linguistic clarification to distinguish between pseudonyms (which are identifiers) and personas (which are bundles of attributes around an identifier). Robin Wilton is surely right to insist that there is a difference

However, a persona can also consist of a number of attribute assertions (“I am male, single and over 20”), without containing either a ‘genuine’ identifier (Kal-El) or a pseudonymous one (Clark Kent) – therefore I maintain that personas and pseudonyms as distinct rather than identical.

[From Racingsnake –
the blog of Future Identity: Liberty, pseudonymity and personas
]

Personas may use anonyms, pseudonyms or absonyms. But I’m having second thoughts about the word “absonym” that I made up to mean the “real name” of something. It bothers me that the derivation mixes Latin (“absolute”) and Greek (“name”). I’m wondering about going all Greek with “alethnym” (“true name”) or just going for something that mixes more wildly but sounds better (such as “pravdanym” using Russian or “verinym” trimming the Latin “veritas” or “emenym” abusing the Hebrew “meet” and simultaneously evoking the stage name “eminem” to get down with the kids). Suggestions?

Anyway, you get the idea. Technology has a solution to a real societal problem. Perhaps the way to actually get something done would be to put forward that solution, using existing technology, but inside the kind of framework envisaged in the NSTIC. It would be easy for a US newspaper, say, to require commenters to have a digital identity from a US provider. These digital identities should be pseudonymous as a default: thus, I can post political comment or hotel reviews or jokes about celebrities or whatever. If I actually libel someone (under proper libel laws, not the UK’s libel laws) then someone can get a court order to ask the identity provider to reveal the digital identity that they were provided with (this, of course, may in some circumstances be another pseudonym).

Here’s a simple example: let’s say that my mobile operator were to give me the identity “citizendave”. I go around logging in to various web sites as citizendave using the mobile handset as part of a 2FA process. Now suppose I log in somewhere and post a libel. The target goes to court and gets an order: this is delivered to O2 (digitally-signed by the Attorney General, naturally) and O2 will then return my name and billing address. Without the court order, cryptography means that no-one can find out who citizendave is. This seems like a reasonable accommodation.

By the way, this is a serious issue – it’s not all about people writing abusive hotel reviews. A couple of years ago Bob Gourley, the former CTO of the U.S. Defense Intelligence Agency, summed the issue up as fundamental and important question about the future identity infrastructure. He said:

We must have ways to protect anonymity of good people, but not allow anonymity of bad people. This is going to be much harder to do than it is to say. I believe a structure could be put in place, with massive engineering, where all people are given some means to stay anonymous, but when a certain key is applied, their cloak can be peeled back.

[From A CTO analysis: Hillary Clinton’s speech on Internet freedom | IT Leadership | TechRepublic.com]

What should be done? I saw this in a comment on an article about the internet and anonymity.

If we create a technology that allows one person, in the privacy of his living room, to create multiple identities to ruin a person or business, then we should create a legal mechanism to allow victims with the same ease to stop it.

[From Anonymity and the Dark Side of the Internet – NYTimes.com]

I think this is, essentially, correct. I was listening BBC Radio 5 yesterday and there was a story about a woman whose life was ruined by an ex-boyfriend impersonating her online (it’s not that difficult to pretend to be someone on IM or whatever) and how hard it was for her (or the police) to stop it. So there is a real need to get on and so something about this but not in the privacy-destroying North Korean-style “you have to show a passport to log on” way that will lead to disaster.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


Say aaarrggh!

Greyscale backing image
[Dave Birch] There’s a clearly a desperate need for a 21st-century trust infrastructure for both people and things in Italy. Here’s some news from the Internet of Things.

Work by the University of Turin’s mountain pastoral department has given consumers the ability to check individual cheeses, wheel by wheel, and get a large dollop of information to back up the evidence of their taste buds… The University of Turin’s Giampiero Lombardi said the consumer accesses the information through QR codes and an RFID tag printed onto the cheese wheel wrapper… For individual farmers, setting up the database and ability to use QR codes and RFID tags cost between 700-2000 Euros, but the researchers are hoping that farmers from each Alps grazing zone will collaborate on the equipment to lower the individual price.

[From Italian cheese puts traceability to the test – National Rural News – Agribusiness and General – General – Stock & Land]

Since QR codes are trivial to copy, and cheap RFID tags not much better, the security of this system rests on the integrity of the database, and maintaining that is expensive, hence the price tag. But nevertheless good luck to them, because there are undoubtedly parts of Italy where the reporting of cheese origin falls below the high standards that consumers might expect. I wonder if the crackdown on bogus cheese is part of the Italian government’s renewed interest in shrinking less-regulated parts of the economy.

Under the new rules all payments in cash will be forbidden above a €1,000 threshold. The threshold was previously fixed at €2,500, surely a bit too high for a country struggling with endemic tax evasion like Italy;

[From Open Europe Blog]

Hurrah! Go for the belly of the beast, that’s what I say. Anyway, what I wanted to say was that the apparent existence of black-market illegally labelled cheese does not put me off of visiting Italy (I shall be in Rome in April for the EPCA). But this does.

One in five Italian dentists is unqualified, along with an estimated 10,000-15,000 doctors, it was reported today.

More than a thousand people were charged in Italy last year with unauthorised exercise of a medical profession. They included fake doctors, spurious dentists and even a few sham nurses.

In an average year, according to police figures, about 1,000 people have been convicted of the offence. But the penalty is only a fine of up to €516 (£440).

“We catch phoney dentists who laugh in our face,” Captain Marco Datti of the carabinieri told the daily La Repubblica. “They say: ‘I’ll just pay €500, change premises and start again’.”

[From Health warning over Italy’s fake dentists and phoney doctors | World news | The Guardian]

I’m sick of the sight of that diploma, as anyone in our office will tell you! In the last couple of months I’ve been there half a dozen times to get a new crown, fix a broken tooth, get a filling. I hate going to the dentist. (My present dentist excepted, naturally.) Still, at least here in Britain we can sure that we are visiting a real dentist. Oh, wait…

The UK’s dental regulator, the General Dental Council (GDC), has successfully prosecuted two individuals for practising dentistry illegally.

The cases bring the total number of successful prosecutions by the GDC to five in the last six months.

[From Dentistry.co.uk | News | Two fake ‘dentists’ fined]

How much effort is it to print out a fake diploma and stick it on a wall. The one of the wall of my dentist’s office looks very impressive, but I haven’t the slightest idea how to verify it. There’s no chip, no digitally-signature, no biometric link to the dentist. I can’t even read what it says because it’s in Latin.

If I seem obsessed with the dental example, it’s because I am a total baby at the dentist. So these kinds of stories literally make me sick. My hands are shaking as I type this…

A bogus dentist is facing court in the US after detectives discovered his makeshift surgery – stocked with DIY rather than dental tools. And officials in Palm Beach, Florida, believe that there may be as many as 300 unlicensed dentists in the city and surrounding counties.

[From BBC News | Health | Fake dentist ‘pulled teeth with pliers’]

Now I don’t want to go to Florida either! What if I get toothache? What if I’m rushed to a dental survey only to be operated on a by a boy from (very probably) Brazil? From now on, I’m going to use this as the very real test case for any proposed mass-market trust infrastructure. When I break a tooth in Boca Raton, how is the infrastructure going to tell me whether the man in the white coat is actually dentist?

Seriously. How?

Never mind the boring, standard, examples and use cases for (e.g.) NSTIC. How will NSTIC help me to know that I have booked an appointment with a big cheese not a bogus one?

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


Still cloudy

Greyscale backing image
[Dave Birch] Lots of people were talking about “payments in the cloud” ($Cloud) at the last event I went to (the WIMA NFC conference in San Francisco). The basic idea is that your payment credentials are stored somewhere in the cloud and you access them from your PC, mobile phone, iPad or wristwatch whenever and wherever you need them. So here’s what I maws just musing over in connection with a project some of our guys are working on at the moment. Are a username and password secure enough to make this a scale solution? Well, let’s look around at the $Cloud examples that we already have.

iTunes gift cards worth $200 are now sold on a Chinese Website for merely $3. But that’s not a crazy sales promotion from Apple — it’s actually a group of Chinese hackers who broke Apple’s gift certificate algorithm and are now using a key generator to sell bargain gift cards on the Internet.

[From Hacked: $200 iTunes Gift Card for Only $2.60 | PCWorld]

After all, usernames and passwords are not particularly strong form of authentication. But then neither is the magnetic stripe, and yet there are billions of them is use all around the world despite the fact that they can be copied at will. Generally speaking, even in the US, payment card fraud is manageable even through magnetic stripes are so trivially counterfeit able, so one might imagine that could payments based on username and password might have similarly manageable levels of fraud too, since there will be all sorts of fraud prevention and detection built in to the cloud.

Just added a $25 gift card I received yesterday, and this morning it was cleaned out.

[From iTunes store account hacked: Apple Support Communities]

That back end has got to be quite sophisticated and is time-consuming and expensive to build, but if you are only going to rely on a password to secure your payment system, then you are going to be attacked all the time, just as the experiences of existing cloud payment services bear out.

I got the emails this morning about a purchase on a unauthorized device. 2 games were downloaded and a crap load of in game add ons to the total of $124. They shut down my account and I had to go in and reset my password this morning. After a email and phone call they are refunding all my money as they can clearly see and know it was not one of my devices.

[From iTunes store account hacked: Apple Support Communities]

Now, of course, while the payment system is “closed” and the goods that are being purchased are virtual, then the losses can be tolerated even if the system is attacked all the time. But once the payments can start crossing boundaries, then there are real problems.

The new pact means that if a customer purchased $20 worth of Ghost Recon Credits on Facebook, Facebook would still earn its 30 percent cut of the revenue, but players would be able to access the points in the Ghost Recon game on Apple devices. The reverse is true as well.

[From Surprise! Facebook Credits and Apple’s iTunes Play Nice With Each Other. – AllThingsD]

Now having to refund third parties hurts much more than cancelling some digital purchases, so in this example it’s hard to see how either Facebook or Apple can go much further. Passwords either won’t scale at all, or will scale but in a very expensive way. We need an alternative key to the cloud. Personally, I’d rather use my phone and a PIN. This seems to me to be the right balance, an effective way of implementing two-factor authentication (2FA) in the mass market. Typing in my username and password is annoying on a phone and, since viruses and trojans will undoubtedly cause the same problems in that world as they do on PCs, not really that much of a barrier to the bad guys. The main $Cloud service that I use is PayPal and they get around the username/password problem by using the phone: when I log in to make a payment, as I did this very morn, they send an SMS to my phone. The SMS contains a six digit code. It’s not a perfect solution (there are vulnerabilities in the SMS solution) but it’s good enough to tip the risk balance away from the bad guys. Thus the PayPal $Cloud is already chip and PIN, it’s just that the chip is the SIM card and the PIN is six digits instead of four.

Thinking along these lines, the natural synthesis is to have the mobile operator provide some kind of (preferably PKI-based) digital identity infrastructure for the $Cloud guys to use — since it would be cheaper and better for them to have access to a SIM-based digital ID than to build their own — and build value-added payment services on top of.

That is why solving digital identification is almost the same as building a fraud-proof digital payment system.

[From Mobile Banking: Digital identification and mobile payments]

Is this the long-term solution then, the SIM and PIN? No. I think I’ll stay with my longer-term predictions about the phone/payment nexus. Surely voice will be both the interface and the biometric of choice: your private key will be protected inside a secure element, it will authenticate your voice pattern and pass both the voice and the identification (as a standard digital certificate) off to a server for execution. Imagine using a future version of Siri that could authenticate via voice identification as well as execute instructions by understanding what you are saying. Apple probably has.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


I love the way they think

Greyscale backing image
[Dave Birch] The subject of identity infrastructure came up again yesterday and this led on to a discussion about banks, identity providers, attribute providers and business models. When we are thinking about identity infrastructure in the mass market, a very simple identity vs. attribute example often comes to mind. It’s the apparently simple case of age verification: how do you prove to a web site that you are over 18 or to an bar in the US that you are over 21 or to a bus company that you are over 65, or whatever. I think this is a pretty reasonable measure of how a system intended for the general public is going to work. Talking about this in the meeting, the example of Facebook came to mind, where there is an utterly prosaic, immediate and important use case. You have to be 13 to exist on Facebook.

Now, one interesting question is… why? Why do Facebook ban under-13s? I mean why not under-18s? or under-12s? I mean 13 sounds rather arbitrary and there’s no obvious reason for it that springs to mind. So I began to look for a rational reason for this, thinking that it was a Facebook policy. But it isn’t. The reason for this abitrary and capricious age boundary is, as I should have suspected, a consequence of government regulation of the interweb tubes.

Internet companies have set up the rules against under-age users because they must comply with the federal Children’s Online Privacy Protection Act (COPPA), passed in 1998, which says web sites that collect information from children younger than 13 must obtain parental consent.

Obtaining that consent is complex and expensive, so companies like Facebook and Google, which owns YouTube, reject anyone who tries to sign up using an age below 13.

[From Facebook Users Who Are Under Age Raise Concerns – NYTimes.com]

Unusually, across the spectrum of wise political steering in cyberspace, this legislation has not turned out precisely how the politicians and lobbyists intended.

The Children’s Online Privacy Protection Act is a well-intentioned piece of legislation with unintended consequences for parents, educators, and the public writ large. It has stifled innovation for sites focused on children and its implementations have made parenting more challenging.

[From danah boyd | apophenia » Why Parents Help Children Violate Facebook’s 13+ Rule]

I realise that Facebook-13 seems like a very particular and specific issue, but I think it is entirely representative of a class of problems in the new, online world. The way that people talk about this issue illustrates—I would at least postulate—how they think about stuff like online identity at a deep level and is a rather useful guide to technologists and legislators.

In Victoria’s fifth-period honors English class, all 32 students said they had faked their birth year to gain access to one site or another… Jerry Ng, Victoria’s 14-year-old cousin, agreed. “It’s one thing to lie to a person,” he said. “But this is lying to a computer.”

[From Facebook Users Who Are Under Age Raise Concerns – NYTimes.com]

I love this comment, which is utterly revealing about how the so-called “screenagers” think about the world. A new ethics, discontinuous to our pre-post-industrial moral paradigm. Talking of which, perhaps an alternative to a sophisticated modern identity management system and the new mental models to with it is simply to clear the plebs off the playing field.

The Pope has warned of the dangers of social networking sites such as Facebook and MySpace, saying that communication between people online must not stop face-to-face conversations.

[From Pope warns Facebook can’t replace human contact – Telegraph]

There’s a heritage to this kind of pedagogical panic.

Similar concerns arose in the 18th century, when newspapers became more common. The French statesman Malesherbes railed against the fashion for getting news from the printed page, arguing that it socially isolated readers and detracted from the spiritually uplifting group practice of getting news from the pulpit.

[From A history of media technology scares, from the printing press to Facebook. – By Vaughan Bell – Slate Magazine]

God knows what he would make to the newspapers I saw at Woking train station this morning. The front pages included a splash about whether bread is bad for you, voyeuristic photographs up a female pop star’s dress (I think she was a pop star – I didn’t recognise the name or, for that matter, anything else) and something about the X-Factor. All this at time when the eurozone is in crisis and people are being machine-gunned on the streets of Syria. But back to Facebook.

Whether Facebook is responding to changing social norms or, in fact, leading the charge is an unresolved question

[From FT.com / FT Magazine – Facebook’s grand plan for the future]

This is very important question. I think that people are disoriented about post-industrial society and confused about the fractal online/offline (or virtual/mundane) boundary. Facebook provides a way to think about some of these things. I don’t think it’s right to say that it it “leading” the change but I think it is fair to say that until a new model emerges, Facebook will continue to provide a kind of substitute. I think that we should have an identity infrastructure that does not have a mundane analogue, where you can prove that you are an adult or a child without disclosing who you are and that this should be the basic test of fitness of any proposed solution. At the moment, Facebook doesn’t provide this, because it’s still trapped in industrial age identity thinking.

Facebook insists on what it calls authentic identity, or real names. And it is becoming a de facto passport vendor of sorts, allowing its users to sign into seven million other sites and applications with their Facebook user names and passwords.

[From Rushdie Wins Facebook Fight Over Identity – NYTimes.com]

I’m sure it does. But doesn’t this have dangers associated with it?

The information leak can be exploited by social-engineering scammers, phishers, or anyone who has ever been curious about the person behind an anonymous email message. If the address belongs to any one of the 500 million active users on Facebook, the social-networking site will return the full name and picture associated with the account.

[From Facebook bug spills name and pic for all 500 million users • The Register]

Yet another good reason for not having your Facebook account your real name, as indeed I don’t (for either of my accounts). My point is that what Facebook has now isn’t the identity infrastructure we need for the information age, but unless someone else gets to work on building it, we’ll end up with what Facebook has and we’ll be stuck with it.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers


Pseudos corner

Greyscale backing image
[Dave Birch] There was an interesting twittervation going on about pseudonyms, stimulated by this post

I do want to talk about what the “no pseudonyms” policy adopted at G+ means for women, LGBT folk, and civil servants.

[From Why Google+ hates women « Bug Girl’s Blog]

Hey! What about me! I want pseudonymity too! It isn’t about people being able to “hide”, it’s about given people choices about how they interact and the ability to interact in different ways via different persona. I don’t think this in conflict with having an identity infrastructure, I think it should be part of that infrastructure. As far as I’m concerned we need an infrastructure more than ever, which is why I find this kind of comment puzzling.

It won’t work; and if it did, you would have to trust big government to stay benign as it tracks your every online step. As for the latter, ask the citizens of Egypt, Tunisia, China, Iran, and other countries that closely monitor their citizens’ Internet usage (or block it in whole or part).

[From Internet Evolution – Robert McGarvey – Why an Internet ‘Driver’s License’ Won’t Work]

Let’s put to one side the question of whether the US wants to monitor or block citizen’s internet usage (although generally on behalf of Disney rather than democracy) and address the central point. What has NSTIC got to do with trusting the government? Most people will use IDs provided by their bank, mobile operator, sports team or favourite pop group. I really, really doubt that the DMV will be able to compete for the business.

Olden suggests building a single sign-on from a handful of IDs that are in wide use. Think Facebook, Gmail, perhaps Yahoo. Facebook alone is emerging as a kind of de facto single sign-on with 500 million users… So scratch Commerce’s NSTIC, and find ways to lace together the passwords we already use.

[From Internet Evolution – Robert McGarvey – Why an Internet ‘Driver’s License’ Won’t Work]

This is confusing two entirely different issues. Issue no.1 is what framework we use for identity, and NSTIC seems to me to be as good as any other (although, as I have often written, I would have liked to have seen an emphasis on pseduonymity as the norm). Issue no.2 is which identities we use. If we only use the same, single identity everywhere that we go through the interweb tubes, then the “owner” of that identity will indeed be able to monitor our journey. I don’t care whether that owner is the Feds or Facebook, I don’t want it to happen.

Personally, I would want a pseudonymous identity from someone like my bank. That why I could do stuff online, and people online could interact with me knowing that the bank knows who I am, if you see what I mean. I don’t think that managing a few identities will be at all different, thanks to the magic of the mobile phone. I spotted an interesting comment on this mobile future in a very positive review of Google Wallet in the Wall Street Journal.

Google Wallet can’t hold your driver’s license or other official forms of identification, so even if it takes off and works everywhere, you’ll still have to carry your license with you.

[From The Digital Solution: Google Mobile App Aims to Turn Phones Into Wallets – WSJ.com]

In the long run, as we all know, it’s the digitisation of identity that will have the biggest impact on society and it’s very interesting to me that the arrival of mobile wallets has stimulated these thoughts.

It would be easy to carry an MIC, or “Mobile Identification Card” on my phone, instead of a physical card in my leather wallet (Google, are you listening?)

[From Invasion of the Invisible Wallet – Forbes]

So what would it take to get my bank pseudonym and (in the US example) the driver’s license into the Google Wallet? We have the technology and we have a framework—NSTIC in the USA and Identity Assurance in the UK—but we need some thing to kick-start and coagulate the swirling possibilities. If we’re all agreeing that government identities are going to do it, then perhaps we should focus on something else.

Government agencies could (and should, in my opinion) become attribute providers, so there’s no reason why the couldn’t issue an electronic drivers license in the NSTIC framework. You provide your proof of identity to the DMV along with a digital identity (in essence a public key from a key pair held in the secure element of the Google phone and accessible from the Google Wallet) and the DMV sends you back a public key certificate (your public key together with the relevant attributes signed by a DMV private key). This would combine my private sector identity and my public sector attribute to deliver the Google Wallet fantasy mentioned above.

Federal Chief Information Officer Steven VanRoekel last week released a long-awaited memorandum requiring that, over the next three years, agencies launching or upgrading sites that prompt people to obtain a username and password also must be compatible with logon services handled by certified third-party vendors.

[From White House may cut purse strings to enforce online credentialing | Ready-Sourcing.com – World Industrial Sourcing News covering national and international Trading affairs.]

It’s a small step, but requiring government sites to offer (in essence) NSTIC-compatible access alongside usernames and passwords will help to get things moving: companies will begin to develop software that offers this possibility. Yes there’s a long way to go, but I think both public and private sector organisations can at least begin to formulate strategy bounds and think about the strategic role of identity in their futures.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


Cash-back

Greyscale backing image
[Dave Birch] The amount of cash in the US has gone up so some people are wondering whether this means that there is a cash “fightback” underway or whether it’s just a blip.

Several interesting hypotheses for this cash increase trend include:

Cash-based budgeting: Many nationally recognized “consumer financial advocates” (Suze Orman ring a bell?) have encouraged consumers to cut up their credit cards and get back to “cash based personal accounting… using budgeting tools like envelopes to track spending and minimize the “Starbucks Effect” of spending too freely and too often on expensive little treats. Despite behavioral economic evidence that suggests this type of “budgeting” does not necessarily improve the overall economic health of consumers, there may well be a number of consumers who eschew electronic payments in order to pursue this type of strategy.

[From Cash Usage: Reports of My Death Have Been Greatly Exaggerated – pymnts.com]

But cash doesn’t leave a record, so surely if you really wanted to manage a budget you would use a pre-paid card, a debit card or a credit card so you could go online and see where your money is going. Since online good and services seem to be cheaper than offline, you’d also end up spending more money, wouldn’t you?

The “Mattress Effect”: As the credit crisis worsened in 2008-2009, the failure of both large and small banks made national headlines, creating nervousness and uncertainty among many consumer deposit holders. Some observers suggest that this may have caused a portion of the population to avoid the traditional banking sector and keep their savings/reserves on hand in the form of cash.

[From Cash Usage: Reports of My Death Have Been Greatly Exaggerated – pymnts.com]

The proportion of savings held in demand deposits has been falling continuously for the last 60 years, not because people are keeping their money in cash but because they keep it in “near money” (such as Cash Management Accounts) made more liquid by information technology. But if you thought that banks were going to collapse and that the deposit insurance wouldn’t pay out because the entire economic infrastructure is going to collapse too, then what use would dollar bills be? You’d be better off buying toilet paper, because after the apocalypse, it might be the only luxury people can afford. People who put their money under the mattress are being ripped off (by inflation) while they sleep even when their cash isn’t being stolen or lost.

Increase of “informal economic activity”: With greater unemployment and economic uncertainty, the incidence of cash usage to avoid government tracking/tax implications may be on the rise, as individuals pursue casual employment opportunities “under the table” or small businesses look to avoid increased tax burdens by reducing the electronically traceable portion of their overall receipts.

[From Cash Usage: Reports of My Death Have Been Greatly Exaggerated – pymnts.com]

This, I suspect, is closer to the truth. Legitimate purchases are made with debit cards, for everything else there’s cash. When the financial crisis began, the trend to debit was continuing unabated.

PIN-based transactions grew 13% last year while signature debit transactions grew 9%. Those respective growth rates were the same as in 2008 but exceeded forecasts of 7% for each type. The average number of monthly point-of-sale debit transactions per cardholder remained unchanged at 17.3.

The median ticket declined from $22 in 2008 to $18 last year, which means consumers increasingly favor debit cards for small-ticket transactions, according to Ballard. Hayes notes that 58% of debit transactions are now for less than $20,

[From News]

Look, the big picture is clear. The overall use of cash to support the economy is falling. Over the last decade, it’s fallen considerably.

In our 1999 study, cash accounted for 39% of consumers’ in–store payments. Last year, cash payments made up just 29% of the payments mix — a dramatic shift for a country where cash has long remained king, even in the face of alternative payment options and emerging electronic channels

[From BAI Online | Banking Strategies | Jan/Feb 2009 | World of Choice: Consumer Payment Preferences]

But this has nothing to do with the amount of cash. The Federal Reserve’s latest statistics on currency show that both the value and volume of US currency “in circulation” continues to rise while the use of cash for transactions continues to fall. Have a look at the graphs here.

Currency in Circulation: Value

[From FRB: Data for Currency and Coin Services]

Who is using this cash? It’s not being used to support commerce and industry, so it must be being used for something else. If the conjecture earlier is correct, then it is clear that this cash isn’t being used for budgeting or to stuff mattresses, it is fuel for the “black” economy and in the case of Federal Reserve Notes, fuel for the global black economy, not just the domestic one.

Forget China: the $10 trillion global black market is the world’s fastest growing economy—and its future.

[From The Shadow Superpower – By Robert Neuwirth | Foreign Policy]

So, can the demand from the global criminal fraternity serve to prop up demand for greenbacks? It appears not: even with the assured patronage of the world’s drug dealers, money launderers and corrupt politicians…

Aite forecasts total cash usage will decline at about a 3% annual rate between 2010 and 2015

[From Untitled]

Cash isn’t launching a fightback. There are cashless environments in the US, and they are spreading.

Toll roads across America are starting to go cashless as a way to speed things up. The E-470 toll road that does a half-circle around Denver officially went all-electronic on the 4th of July… The President George Bush Turnpike in northern Texas turned off the cash flow on July 1st, giving motorists two options; pay through a Toll-Tag account, or get a bill in the mail… Those drivers without Toll-Tag accounts will have a ZipCash account created for them and will receive a bill in the mail (at a 45 percent higher cost).

[From Going Cashless In A Moving World | Culture Wars]

This isn’t a US phenomenon. There are examples from all around the world that show that cash is falling into disfavour. In the UK

the majority of people (57%) refuse to carry around one or two penny coins. Half of Blighty’s residents… give away small change. Unbelievably some even reported that they throw coppers and silver in the bin (trash)!

[From Barclaycard and Barclays Study finds the writings on the wall for cash « Near Field Communications / Smart mCommerce]

I don’t think this is an unusual finding. Small coins are near-worthless and nothing more than an annoyance. I used to keep cash in a dish on the kitchen table because I needed it to pay my bus fare, but now that I pay my bus fare on my iPhone, the coins are just a waste of space.

A new survey shows Australian spending patterns are changing, with one in five respondents saying they would like to eliminate cash altogether

[From Cash losing favour amongst shoppers | IR News | Inside Retailing]

The colonials certainly are revolting, but they still use cash more than we do. In the UK, cash has just dipped below 60% of all retail spending, whereas in Australia it remains slightly higher.

The proportion of transactions conducted using cash declined over the last three years, falling from 70 per cent to 64 per cent, according to a recent study. Figures from the Reserve Bank of Australia (RBA) showed that plastic and online payments have started to replace cash for purchases between $25 and $50, reports the Australian.

[From Cash transactions drop as Aussies favour debit cards – Mozo]

As readers of this blog will know, I’m fascinated by the evolving Australian situation because it is a living laboratory for the regulation of interchange.

“Visa is of the view that cash is an expensive, out-date payment option that does not well serve the interests of a modern economy like Australia’s, even in relation to smaller value purchases. It is a payment method that contains numerous embedded costs including production, replacement, handling, storage, transport, security, higher fraud rates, lack of traceability and accountability, higher rates of tax evasion and costs linked to its ease of use for the black economy, money laundering and terrorist financing.”

[From Visa calls for cash versus card review – Business – News – ZDNet Australia]

Hear hear! I hope I won’t be seen as a Visa shill if I say that I agree with them completely. The e-payment industry is just going with the grain of what the consumers want.

A study conducted by RFi last month revealed that 40 per cent of people between the ages of 18 and 34 prefer to use debit cards rather than any other payment method.

[From Cash transactions drop as Aussies favour debit cards – Mozo]

As far as I can see, then, the steady decline of cash is continuing, consumers are by and large happy with that. Governments (especially in Europe) are beginning to feel the pinch and the tax revenues lost to the less-regulated economy are becoming unaffordable. Maybe it’s time to push a little harder? Cash wastes a lot of money for banks, so maybe we should encourage the US banks to a) stop charging for debit cards b) start making cash less convenient. In the UK, Nationwide is raising the minimum on over-the-counter cash withdrawals significantly in order to reduce queues in its branches.

The UK building society is increasing the minimum cash withdrawal limit for FlexAccount customers with a Cash Card and CashBuilder customers with a Cash Card, from £30 to £100. Nationwide’s divisional director of the branch network, Graeme Hughes, told the BBC’s MoneyBox programme the change was essential… “About a third of all counter transactions are carried out by less than 8% of our customer base,”

[From Finextra: Nationwide bids to beat branch queues by stopping small value cash withdrawals]

Why do they let people make cash withdrawals across the counter at all? National Irish Bank don’t.

National Irish Bank has written to thousands of its customers this month informing them of a “new style of banking” in which branches will not handle over-the-counter cash transactions.

[From National Irish moves to cashless banking – The Irish Times – Tue, Dec 22, 2009]

Anyway, what else could be done? I think one thing to do might be to look at retail sectors where cash use is falling dramatically and then encourage the merchants (through tax breaks, as is done in some other countries) to reduce it further so that in time it becomes economically more sensible for the merchants to just give it up (because the costs are falling on fewer and fewer transactions). And perhaps here’s a place to start:

We used to pay for 90% of our beer in pubs with cash but it now we use it less than half of the time. The days of cash may be numbered with only one tenth of Londoners using cash, and a quarter of Northerners. Dave Birch, a payments expert and the director of consult Hyperion, tells “Wake Up to Money” that a cashless society may be closer than we think.

[From BBC – BBC Radio 5 live Programmes – Wake Up to Money, 14/04/2010]

Cash is fighting back? I don’t think so. I’m going to the pub over the road to explain my plan to them as soon as possible.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.