My new mantra

Greyscale backing image
[Dave Birch] Why do people (eg, me) say that “identity is the new money“? What does the catchphrase actually mean? I use it because I can see that we are heading into a transition period between the “old” world of electronic payments where we built dedicated networks to move money from account to account (the world of Visa and American Express, MasterCard and Diners) to a “new” world of electronic payments where there is a single network that all participants access. The money stays put in the cloud while we move our identity around access channels (the world of PayPal and M-PESA, WebMoney and QQ Coins).

The dynamics are easy to understand. The downward pressure on the pricing of commodity payments, the ubiquity of intelligent devices (of which the mobile is currently the most important) and the ease of connecting banks, retailers, processors and others, combine to create a new landscape, where most of the value of the payments layer comes from the ability to identify and authenticate the participants in the transaction.

We have long observed, in our classification, that in the long run digital identity will be more valuable than digital money. This is because authentication is difficult and expensive: if you break down the way that, say, your debit card works, and separate the authentication part (the chip and PIN) from the processing and settlement of the transaction (and all of the fraud management, customer support and so on) you can see the asymmetry between the money part — a few bytes moving from bank to bank — and the identity part.

There is an interesting area for speculation identified by this analysis. Who will provide the identity functions? Will it be the existing players who bundle identity as part of the payments business — PayPal or Barclaycard — or will it be players who deal with identity and reputation — Experian or the Passport Services — or will it be the players who with authentication and switching — Vodafone or Google — or will it be an entirely new class of organisation?

I have a suspicion that it will be the latter. Just as new economic environments have led to new kinds of organisations before, so they will again. Just as Visa arose to exploit new opportunities, so something like Visa arise to create a digital identity infrastructure that creates new value. There is some logic to the proposition that it will be the mobile operators who in some way will give birth to this new organisation. That’s because the technology required to implement digital identity is founded on public key infrastructure (PKI) and for this to work we need some secure storage, some tamper-resistant hardware, to store our private keys and to execute authentication processes. Right now, the one piece of tamper-resistant hardware that everyone has is the SIM in their mobile phone. Indeed, there are a number of initiatives around the world that are already starting to use the SIM for precisely this purposes. The examples of Turkcell in Turkey and BankID in a number of Scandinavian markets have been looked at before. I’ve bored about this at length before:

One of the world’s leading experts in this field, David Birch, spent some time with me explaining how mobile operators, in particular, could actually become ‘smart pipes’ with financial transactions. The ‘secret sauce’ according to Birch, lies in the ability for operators to provide secure identification linked to the SIM providing private and public keys for multiple providers. The resultant digital signatures would allow for ultra-secure tow level authentication via the mobile device.

[From The ‘secret sauce’? – The Insider – TM Forum Online Community]

How might this play out? In the US, we already see ACH alternatives to scheme payments emerging. An example is the “Pinpoint” card marketed by First Data ISO American Payment Systems. It provides a per-retailer loyalty scheme combined with ACH payment. Imagine something like this combined with stronger 2FA authentication at POS — perhaps using 2FA to release an identity credential or authenticating using some mobile network-based validation (eg, ValidSoft’s “proximity” transactions validation) — to create a product where the payment is a commodity but identity isn’t.

They must have been cuckoo

Greyscale backing image
[Dave Birch] Where are we going with authentication? Bruce Schneier made me think about this again with a post about the breaking of the Russian “spy ring” operating in the US.

Ricci said the steganographic program was activated by pressing control-alt-E and then typing in a 27-character password, which the FBI found written down on a piece of paper during one of its searches.

[From Schneier on Security: Cryptography Failure Story]

The Russian equivalent of “M” must be furious! “Doh! — if it wasn’t for those darn kids” etc. The idea that making a password 27 characters long (probably a pass phrase, in fact, since there are relatively few 27-letter words even in Russian) makes it secure is hilarious, since any user security expert would have absolutely predicted the scheme’s doom. But this led to muse in another direction, which is about how much time and money must be wasted messing around with these pointlessly long passwords that don’t actually add any real security, that are just another kind of performance art in the great security theatre. I looked back through some of my notes on that topic and came across an actual figure (for the US).

In the paper, Herley describes an admittedly crude economic analysis to determine the value of user time. He calculated that if the approximately 200 million US adults who go online earned twice the minimum wage, a minute of their time each day equals about $16 billion a year. Therefore, for any security measure to be justified, each minute users are asked to spend on it daily should reduce the harm they are exposed to by $16 billion annually. It’s a high hurdle to clear.

[From Boston.com]

So, in other words, if you made a law to stop everyone in the US from using passwords to log in to their bank accounts and insisted that they instead use some kind of 2FA that takes a minute (eg, look up OTP on mobile phone then type it in to web site — which wouldn’t actually protect against MITM attacks) then it would have to save $16 billion per annum to make it worthwhile. According to the FBI, US cyber-bank robbery is running about $100 million per month, or only about $1.2 billion per annum, so we’re better off doing nothing.

What? Hold on, there must be a flaw with this approach, and it must be that the overall cost of having the security must factor in potential losses and costs to rectify as well as user time. Anyway, the point is we need to make some strides in authentication.

Let’s make crime illegal

Greyscale backing image
[Dave Birch] In today’s newspaper, I read that the Blackberry is not, after all, to be banned from Saudi Arabia as it has been from UAE.

The agreement, which involves placing a BlackBerry server inside Saudi Arabia, would allow the government to monitor users’ messages and allay official fears the service could be used for criminal purposes.

[From Saudi Arabia halts plan to ban BlackBerry instant messanging – Telegraph]

I don’t know whether it’s a good thing for messages to be in the clear or not. If I were an investment banker negotiating a deal, I might worry that someone at the Ministry of Snooping might pass my messages on to his brother at a rival investment bank, for example. After all, the idea that only authorised law enforcement officers would have access to my private information is absolutely no comfort at all.

A drugs squad detective, Philip Berry, sold a valuable contacts book containing the personal details of the criminal underworld to pay off his credit card debt, a court heard.

[From Corrupt drugs detective ‘sold underworld secrets to pay debt’ – Telegraph]

The idea that law enforcement would be helpless to stem the tide of international crime unless they can tap every call, read every email, open every letter, is (if you ask me) suspect. If I am sending text messages to a known criminal, you do not need to be able to read those message to decide that you might want to obtain a warrant to find out who I am calling or where I am. The fact that I am using a prepaid phone does not, by itself, render me immune to law enforcement activity.

Beyene’s role in the heist was to buy so-called dirty telephones and hire a van to use as a blocking vehicle,

[From Gunman jailed for 23 years over Britain’s biggest jewellery robbery – Telegraph]

In fact this gang was caught because the police found one of the mobile phones they had been using. It contained four anonymous numbers, and from these the police were able to track down the gang members. It wasn’t revealed how, but there at least two rather obvious ways to go about it: get a warrant to track the phones and correlate their movements with known criminals or get a warrant to find out which numbers those other phones have been calling and follow the chain until you get to a known number. Yes, this might require some police work, which is more expensive than having everything tracked automatically on a PC, but it is better for society. This reminds of a recent discussion about anonymous prepaid phones. I’m in favour of them, but plenty of people are against them. (Same for prepaid cards.) Ah, but you and the authorities in some countries might ask: how can you catch criminals who use anonymous prepaid phones? Forcing people to

Earlier this month, the FBI revealed that the suspected Times Square bomber had used an anonymous prepaid cell phone to purchase the Nissan Pathfinder and M-88 fireworks used in the bomb attempt.

[From Senators call for end to anonymous, prepaid cell phones]

Setting aside the fact that this guy was caught (despite the dreaded “anonymous prepaid call phone”) and had been allowed on a flight despite being on the no-fly list, the politicians are, I’m sure, spot on with their informed and intelligent policy. In fact, one of them said:

“We caught a break in catching the Times Square terrorist, but usually a prepaid cell phone is a dead end for law enforcement”.

[From Senators call for end to anonymous, prepaid cell phones]

Amazingly, the very same issue of the newspaper that reports on the captured UK armed robbers contains a story about a Mafia boss caught by… well, I’ll let you read for yourself:

One of Italy’s most wanted mafia godfathers has been arrested after seven years on the run after police traced him to his wife’s mobile registered in the name of Winnie the Pooh

[From Winnie the Pooh leads to gangster’s arrest – Telegraph]

So, basically, if you require people to register prepaid mobile phones then you raise the cost and inconvenience for the public but the criminals still get them (because they bribe, cheat and steal: that’s criminals for you). I imagine that in the Naples branch of Carphone Warehouse the name “Winnie the Pooh” on a UK identity card looks perfectly plausible: they would have no more chance of knowing whether it’s real or not than the Woking Carphone Warehouse would when looking at an Italian driving licence in the name of Gepetto Paparazzo. Again it’s not clear exactly what the police did, but from elements of the story it appears to be something like: the police discovered (through intelligence) that the godfather’s wife was calling an apparently random mobile phone number at exactly the same time every two weeks. From this they determined which phone was hers (the “Winnie the Pooh” phone) and they tracked it to Brussels. But suppose some foolproof method for obtaining the correct identities of purchasers were to be found. Would this then stop crime in, say, Italy? Of course not.

In an attempt to combat the cartel-related violence, Mexico enacted a law requiring cell phone users to register their identity with the carrier. Nearly 30 million subscribers didn’t do this because of a lack of knowledge or a distrust of what could happen to that information if it fell into the wrong hands. Unfortunately, the doubters were proven right, as the confidential data of millions of people leaked to the black market for a few thousand dollars, according to the Los Angeles Times.

[From Did Mexico’s cell phone registration plans backfire?]

The law just isn’t a solution. It might even make things worse.

Who to trust?

Greyscale backing image
[Dave Birch] I’ve been involved in some involved discussions about an involved topic: trust (again). It happens that a number of the projects that Consult Hyperion is currently working on include implementing trust infrastructures in both private and public sectors. Now, we’re not alone in thinking that this is a big deal.

Newmark called some form of distributed trust system “the killingest of killer apps” for the web over the next decade (he said he wasn’t sure that was the best way to describe it, but was trying out to see how it sounded). He talked about “reputation and trust ruling the web, just the way it does in real life,”

[From Craig Newmark on the Web’s Next Big Problem – GigaOM]

Do they rule real life? Consider the transactions that I’ve made so far today. I took a bus — no trust required, I paid with cash — and then bought a train ticket — chip and PIN, so no trust in me required — and went to a couple of meetings — we’ll come back to this in a minute — took the train home — no trust in me required since I had a ticket — and then took the bus home — no trust in me required since I had a ticket.

Joe Bloggs

Greyscale backing image
[Dave Birch] Having just come from a meeting about the management of multiple identities and the potential commercial structure of a proposition based on pseudonyms, I found myself reading some excellent and thought-provoking comment on the issue of anonymity vs. pseudonymity vs. absonymity starting with a US perspective over at Public Citizen.

The First Amendment protects the right to speak anonymously, and if the bar to such discovery is set too low, much citizen and consumer discussion about the important issues of our day, including the doings of corporations and politicians, will be chilled and hence lost to the marketplace of ideas. If it is set too high, valid claims may be lost. We at Public Citizen have litigated many cases devoted to setting this balance correctly.

[From CL&P Blog: Two new cases on Internet Anonymity]

I can’t say I understood everything (or, indeed, anything) in the legal argument, but I think I agree with the conclusion (applied by the US courts in the examples given) that “commercial” speech is not the same as “political” speech. Companies bashing each others’ products via “astroturf” blogs are not (and should not) be subject to the same privileges as political opponents questioning policies. But, naturally, it is a very fuzzy boundary, and one of the key issues is anonymity. If you are allowed to post anonymously, then it’s hard to

If you read through both stories you see that judges basically seem to be making it up as they go along as to what standards to use in deciding whether or not online anonymity is protectable

[From More Mixed Rulings On The Right To Be Anonymous Online | Techdirt]

Now, I would have thought that one of the reasons why we have judges is precisely so that they can make things up as they go along. If the law was written by people like me, it would be in XML and given the facts of the case as a set of propositions would be capable of delivering justice through an algorithm that would decide the outcome in polynomial time. But it isn’t, so we need judges. Sometimes they come up with odd rulings — look at the fuss about the UK judge who recently ruled that it’s not against the law to smash stuff up if it belongs to people you really don’t like — but, generally speaking, they combine law and common sense.

Unfortunately, as I have constantly complained, common sense is a bad guide to what to do about identity.

We don’t want paedophiles and nazis to be able to groom unsuspecting, innocent children online. Who could disagree with that? In the UK, this “common sense” drove a furore about Facebook that has led to an completely pointless resolution (along the lines of “something must be done, this is something, so let’s do it”).

how can the police help with every teen who is struggling with the wide range of bullying implied, from teasing to harassment? Even if every teen in the UK were to seriously add this and take it seriously, there’s no way that the UK police have a fraction of the resources to help teens manage challenging social dynamics. As a result, what false promises are getting made?

[From danah boyd | apophenia » Facebook’s Panic Button: Who’s panicking? And who’s listening?]

I would be utterly shocked if the presence of this button makes even the slightest difference. The kids who are smart enough to press it when they are approached are presumably smart enough to know that they are being approached, if you see what I mean, and the kids who press it because they are being bullied by their peers in some way are not going to get any help, so what’s the point? The “Facebook murder” that Danah refers to might just as well have been called the “Ford Mondeo” murder, since both technologies were crucial to the crime, and as she points out having this button would not have averted the tragedy.

Cleaning up

Greyscale backing image
[Dave Birch] I opened my first bank account, with Bank X, when I went to university. I walked in to my local branch on the second or third day after arriving in Southampton and opened an account. When I started work, I transferred that account to Cobham in Surrey, near where I was working. A couple of decades ago, that branch was closed and the accounts transferred to Walton-on-Thames, which is where my relationship banker was based when they were first invented about 15 years ago. I’ve probably been to that branch three times since then, about once every five years. I’m a premium customer and pay a few quid per month for my account, so my personal banker would periodically ring up me to see if they could sell me insurance or whatever. I quite liked my first personal banker and probably met him three or four times over the decade. A few days ago I got a letter from my new personal banker, who is based in Leicester. (A note for foreign readers: I live in the south of England, southwest of London, and Leicester is in the midlands, about 150 miles away.)

I’m note sure how “personal” this relationship will be. In any case, the last time I called (in order to get a bank loan to cover some building work we were having done) I had to go through half an hour of questions about name, address, salary, monthly outgoings etc, so having a personal banker (and having had the account for 33 years) didn’t really seem to help. They still wanted to know (as my mother would always say) “the ins and outs of a cows behind” before giving me the money. To be fair to the banks, in this case, they don’t want to annoy and inconvenience customers in this way, they are being made to by the government, because they have to comply with “Know Your Customer” (KYC) and “Anti Money Laundering” (AML) rules. Generally speaking, the banks do not suffer too greatly because of this as everyone has to just grin and bear it. Had I hung up in annoyance and called Bank Y (who don’t know me from Adam) instead, I would still have had to answer the same questions. But there are cases where the implementation of KYC and AML rules may end up costing banks more than customers’ opprobrium.

In the case of Shah and another v HSBC Private Bank (UK) Ltd, the Court of Appeal has ruled that Jayesh Shah and Shaleetha Mahabeer have the right to challenge HSBC Private Bank for having delayed a $28 million transfer… the bank asserted that it had suspected that the transaction constituted money-laundering for the purposes of the Proceeds of Crime Act 2002, meaning that the transfer had to be delayed while reported to the Serious Organised Crime Agency.

Eventually, the transaction was completed and Mr Shah claimed the delay cost him over $300 million. The claimants subsequently challenged the grounds on which the bank’s suspicions were raised but a case brought by Mr Shah for compensation was thrown out at an earlier court hearing. However, last week’s Court of Appeal ruling means that Mr Shah can now pursue HSBC for his losses.

[From HSBC customer claims for anti money-laundering delay]

Interesting. As the article notes, the plaintiffs are questioning the basis on which the bank determined that the transfer was suspicious. But what I’m curious about is the cost/benefit analysis that underlays this whole raft of e-payment regulation.

According to an IFA I spoke to recently, there is not a single case of any would-be launderer being caught by this system. As you’d kinda guess, real launderers are quite capable of cobbling together the necessary fake docs, and ticking all the right boxes.

[From Burning our money: A Problem With The Laundry]

So inconveniencing everyone from billionaire businessmen to peasant farmers has not caught a single money launderer? This seems statistically unlikely, doesn’t it? Surely they would catch the odd one or two by accident given the enormous size of the money laundering market. The latest figure I could find (given only a quick Google, since I couldn’t be bothered to go downstairs to the bookcases) shows that it’s a huge and growing business.

The NCIS ‘United Kingdom Threat Assessment of Serious and Organized Crime’ in 2003 stated that the overall size of criminal proceeds in the country – and the amount that is laundered is unknown. However, customs authorities had estimated that the annual proceeds from crime in the UK were anywhere between £19 billion and £48 billion – with £25 billion being a realistic figure for the amount that is laundered each year.

[From : : Money Laundering Statistics : :]

£25 billion! This is certainly an underestimate and it comes despite all of the rules imposed on the industry.

Linked

Greyscale backing image
[Dave Birch] I rather like LinkedIn, and use it reasonably often. It’s proved a convenient way to build up my network of professional contacts in a very dynamic and useable form. Well, I say “my” professional contacts…

A recent judgement in the UK courts has forced a former employee of Hays to hand over details of the business contacts build up through LinkedIn.com whilst he was employed by them. The decision is one of the first in the UK to show the tension between businesses encouraging their employees to use social networking websites whilst trying to claim that the contacts should remain confidential at the end of their employment.

[From Bombay Crow: Who owns your online networking contacts?]

I have a slightly old-fashioned policy towards LinkedIn. When I get a connection request, I won’t accept unless it is someone that I’ve spoken to (or, preferably, met in person). The validity of this policy was demonstrated during the week, when I read the story of the security consultant who set up a fake LinkedIn site for an imaginary woman called “Robin Sage” who supposedly worked in cybersecurity for the US Navy. In less than a month, she amassed nearly 300 social-network connections among security specialists, military personnel and staff at intelligence agencies and defense contractors.

Her profile was a ruse set up by security consultant Thomas Ryan as part of an effort to expose weaknesses in the nation’s defense and intelligence communities – what Mr. Ryan calls “an independent ‘red team’ exercise.” It is not the first time “white-hat” hackers have carried out such a social-engineering experiment, but military and intelligence security specialists told The Washington Times that the exercise reveals important vulnerabilities in the use of social networking by people in the national security field.

[From Fictitious femme fatale fooled cybersecurity – Washington Times]

The story also revealed another sad truth, a reflection on human nature. Men will do anything for an attractive woman, without even bothering to check whether she’s real or not.

Ms. Sage’s connections invited her to speak at a private-sector security conference in Miami, and to review an important technical paper by a NASA researcher. Several invited her to dinner. And there were many invitations to apply for jobs

[From Fictitious femme fatale fooled cybersecurity – Washington Times]

Jobs! You’d think one of the first, basic checks that someone might make is that their employment target is real! Yet we’re told that social networking means that employers know all about us all the time.

“We’re hearing stories of employers increasingly asking candidates to open up Facebook pages in front of them during job interviews,”

[From The Web Means the End of Forgetting – NYTimes.com]

This would be fantastic, if it were true. I would love to work for someone so dumb that they think that what’s on a Facebook page has any reputational capital value at all. In half-an-hour my kids could easily make up a Facebook page that would present them as the best candidate ever for whatever job. If employers are hiring people this way, they deserve what they get.

Simple cases

Greyscale backing image
[Dave Birch] I’ve been looking at a survey undertaken by UK Online’s “myopinion” panel in connection with the Technology Strategy Board’s VOME project that Consult Hyperion are involved in.

Researchers from the Information Security Group (ISG) at Royal Holloway, University of London worked together with UK online to conduct a survey of privacy attitudes and behaviours. Focusing on our concerns about privacy while using the internet, the survey reveals that online identity theft is currently the greatest fear for internet users.

[From Online identity theft is the greatest fear for internet users]

The great majority of respondents (almost all of them, in fact) use the Internet daily from home, work or school. In this group, their top concerns about privacy are:

  1. “Online identity theft”
  2. “Spying on online activity”
  3. Payment card data being intercepted.
  4. Merchant mischarging.
  5. Having to provide too much personal information when purchasing online.

I noticed an odd gender imbalance, in the sense that women report being more concerned about privacy than men do, but men were much more likely than women were to actually do anything about it, presumably because doing something means (to a large extent) technological activities such as turning on firewalls.

USTIC

Greyscale backing image
[Dave Birch] It’s taken me a while to sit down and read through the US Government’s National Strategy for Trusted Identities in Cyberspace (USTIC) paper that is out for comment. I’ve tried not to read it just as a technical expert (what do they mean by strategy? what do they mean by trust? what do they mean by identity? what do they mean by cyberspace?) but as someone who wants to see real change in the identity landscape and a step change in the security of online transactions. Can the USTIC help this agenda? The document says early on that it is about a user-centric identity ecosystem, a world-view that I entirely support, so let’s take a look.

One not entirely trivial point before we start: one thing that did annoy me about the document was that it uses the phrase “digital identity” to mean what I would call a “virtual identity”. That is, it defines a digital identity as the set of attributes that represent an individual in a transaction, whereas I would define the virtual identity as the set of attributes that represent a digital identity in a transaction because it is the digital identity that is the bridge between the real and virtual worlds, the connection between individuals and what the US strategy calls “non-person entities” and their representation in electronic form. (I can see I’m losing this battle, but I’m not going to give up easily.) So I’m going to use my (more precise) terminology in discussing the strategy.

The document describes an identity ecosystem for use by individuals, business and government that attempts to balance the requirements for identification and “reputation” in a forward-looking manner. It talks about creating a user-centric identity ecosystem, which it defines as an ecosystem that will allow individuals to select the interoperable credential appropriate to a specific transaction. In other words, it lets people select between different virtual identities on a per transaction basis, something that we have long advocated. Now, obviously, the individual’s choice of credential cannot be entirely unconstrained. I can well imagine being allowed to log in to Citibank using a Barclay’s Bank identity but not being allowed to log into Citibank using, say, my Twitter login. Similarly, I can well imagine using my Facebook identity to get access to some basic government information about benefits but having to use my mobile phone in someway to confirm my identity to log in to obtain, let’s say, the results of the medical test — more on this example later.

I emphasised this last example, by the way, in the light of the news that PayPal and Microsoft are already conducting an “identity mash up” with a medical company.

Medtronic, PayPal, Southworks, and Microsoft recently worked together to demonstrate the ability for people to use their PayPal identities for participating in a Medtronic medical device trial, rather than having to create yet another username and password… the name, address, birth date, and gender claims provided by PayPal are relied upon by Medtronic and its partners as being sufficiently authoritative…

[From Mike Jones: self-issued » Using Consumer Identities for Business Interactions]

From the point of view of the UK, where the national identity card scheme has just been scrapped and there is no alternative identity infrastructure in place, there is much to be admired in the US approach. The idea of creating an ecosystem that is built around the idea of public and private sector co-operation, individual choice, opportunities for innovation and market-based practicality should be a matter of priority here as well because if it is not, then efforts such as Martha Lane Fox’s Manifesto for a Networked Nation will remain gimmicks: what’s the point of making the population use the web if they can’t do transactions?

Government should “think internet first” in designing services and provide support for those who need help using its online services.

[From David Cameron Supports Digital Champion’s Ambition – Make UK First Nation Where Everyone Can Use the Web « Raceonline2012’s Blog]

Right now, I can’t even use the same login identity for the DVLA and HMRC (the only two online government transactions I ever do).

Law 2.5 or 3.0 or whatever

Greyscale backing image
[Dave Birch] Now, as I’m fond of saying, the whole real/virtual thing is a bit fuzzy. One of the areas where this is frequently demonstrated is crime…

the Habbo Hotel folks have now asked Finnish police to investigate 400 cases of “theft” in their world. Seriously. Of course it is a bit more complicated than that. They’re really upset about phishing scams that let scammers get users login information, which they then use to get into their account and transfer the virtual goods away. But that’s not really “theft” and it’s a misnomer to call it that.

[From Yet Again, Real Police Called Into Virtual World Over (Not Really) Theft Of Virtual Items | Techdirt]

Correct. This isn’t theft any more than copying an MP3 is theft, but it is closer to what we might think of as theft in that it’s fraud, but it’s fraud that prevents the rightful owner of the virtual goods from enjoying their use (which is not the case when a teenager copies a friends CD).

And, really, if Habbo Hotel users are getting phished so frequently, perhaps the Habbo developers should focus on building a better login system that is not so susceptible to simple phishing scams..

[From Yet Again, Real Police Called Into Virtual World Over (Not Really) Theft Of Virtual Items | Techdirt]

This is correct. It it wrong to expect the rest of society to pay to support a business model that is founded on technology that is not fit for purpose. You wouldn’t let carmakers sell vehicles without locks to save money while simultaneously lobbying for higher spending on the police to prevent car theft.

But here’s an interesting thought experiment. If there were a working digital identity infrastructure, would it be possible to build a working law enforcement system on top of it? I think the answer is yes, because crime and punishment would both be founded on the management of reputation. Think of the example of eBay stars: if I am a top seller on eBay, then taking away my stars is a serious punishment, much worse than fining me money or, in some cases, locking me up.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.