There isn’t an app for that

Greyscale backing image
[Dave Birch] Hurrah! My bank, Barclays, tell me that they have a new and improved mobile bank service. Fantastic. I go to the iTunes App Store. Nothing there. Odd. Turns out that the new and improved mobile bank service is just the web service but on a mobile phone. Oh well.

With odd serendipity, this came up at the recent Mobey Forum meeting in Helsinki. While watching a demonstration of Nokia Money, I got a text message from my son who was in London visiting his girlfriend and had run out of money. He asked me if I could send him £10 to get a train home. I was forced to reply that I could not, because we live in the UK and not in an advanced country such as Kenya, where phone-to-phone money transfer is commonplace. I fired up my iPhone and went to the Barclays page, only to discover that I couldn’t log in and send him some money because I don’t know my 12 digit user code (or whatever it is called) and I didn’t have my dongle anyway (it was back home on my desk). (In case you are worried, the day was saved because he was able to go back to his girlfriend’s house and borrow the money from her parents.)

Now, this demonstration of the utter hopelessness of mobile financial services in the UK took place under the watchful eye for Mobey Forum executive director Liisa Kannainen, who promptly showed me how she had responded to an earlier, similar, request from one of her children…

Liisa

Yes, she still uses the same paper-based Nordea Transaction Authorisation Number (TAN) system introduced in Finland for remote banking years ago, And it still works fine. So to send her kids money, she logs in on the phone and is prompted for the next TAN. She types it in and then crosses it off. Works perfectly. And she always has her TAN list with her in her purse, whereas as I never have my dongle with me away from home.

What I do have with me all the time is, of course, my mobile phone. As do almost all of the population. Surely it would make sense for both Nordea and Barclays to move to some standard mobile phone-based 2FA scheme. And then we could move to a standard set of authentication “levels”. For small transactions, just have the phone. For larger transactions, enter PIN into the phone. For very large transactions have the take your voiceprint, then enter a PIN. Something like that. And if we could use it log in for banking, then why couldn’t we use it to log in for other things as well

Exclusion and the war on lunch

Greyscale backing image
[Dave Birch] Plans are afoot in the US to increase financial exclusion by making prepaid products more expensive and less available by forcing non-bank pre-paid card providers to comply with the same rules as banks, presumably treating a $100 pre-paid card to the same degree of scrutiny and reporting as multi-million dollar bank accounts.

FinCEN has applied a limited regulatory framework since 1999 to certain prepaid products as part of the money services businesses regulations applicable to sellers, issuers, and redeemers of stored value. Under FinCEN’s proposal, non-bank providers of prepaid access would be subject to comprehensive Bank Secrecy Act (BSA) regulations similar to depository institutions.

[From FinCen Proposes New Rules for Prepaid Card Programs]

Prepaid cards are already under attack from ill-thought through regulation of the payments industry anyway. This is a bad thing, because prepaid cards — or, more generally, pre-paid transaction accounts of one form or another — are a key tool for increasing participation in financial networks. We should be looking for ways to increase financial inclusion, not reduce it.

The Center for Financial Services Innovation (CFSI) has written to Rep. Barney Frank and Senator Chris Dodd asking that prepaid cards – including government benefits cards, general purpose prepaid cards, payroll cards – be exempt from the fee determination set by the Federal Reserve Board under pending legislation.

[From Center for Financial Services Innovation Asks for Prepaid Card Exclusions]

Encouraging people to remain the cash economy does not help in the “war on terror”, or the war on tax evasion, the war on corrupt politicians or anything else. There is a net social benefit to getting people to use cards instead of cash, and we should be making it is a simple and inexpensive as possible for the excluded to participate. We should be easing the regulatory burden on non-bank prepaid schemes with a maximum balance of, say under $500 or so.

Who benefits from a national ID scheme?

Greyscale backing image
[Dave Birch] Writing in the June 2010 edition of the US magazine “Liberty” (which is a libertarian journal), Wendy McElroy made a couple of observations that resonate. She says

I am not against ID in general: it serves valuable functions.

She then goes on to distinguish between identification and certification, as distinction that is missing from many ID card-related visions. She then makes a crucial point, one I that endorse wholeheartedly.

The valid functions of ID have a common characteristic: they provide advantages to the individual who holds the ID.

Indeed, an a central reason for the tragic trajectory of the UK ID card scheme was precisely that it did not. She then makes another assertion:

Who benefits from national IDs? The state, not the individual.

I’m afraid I have to disagree with Wendy on this one. Individuals can benefit from national IDs, if they are assembled in the correct way (ie, my way) and I have no objection from the state benefiting from them too (apart from anything else, I pay for it) provided that that precondition is met. But suppose a national ID infrastructure isn’t put together in a 21st-century way? In that case, it still isn’t only that state that benefits: criminals do too. As I said a couple of years ago:

If you were going to create a criminal enterprise based on bogus ID cards, who would you target? Probably the group with the least recourse to the law: illegal immigrants. This is exactly what has been going on in Malaysia, where a fake identity card issuing syndicate which cheated hundreds of illegal immigrants has been broken up by the police

[From Digital Identity Forum: New identity crimes]

Of course, there’s a problem the other way round as well, with illegal immigrants being given documents that they are not entitled to.

In Pakistan and Malaysia a high number of illegal immigrants become legitimate because they acquire a biometric card. Illegal immigrants get into the system usually at entry points of the country. Entry points are governed by human resource. And human resource can be corrupted.

[From The Hindu : Life & Style / Society : A question of identity ]

I found a similar point being made in a story from the Yemeni News Agency.

When a Somali refugee who could not speak purely Arabic and insists that he is from Hjjah province, came to al-Thawra police station in the Capital Sana’a for ID, he was requested by the police station to present his documents. He was ready with his electoral card, neighborhoods’ supervisor recommendation and ID copies of two witnesses as identification documents to get his Yemeni ID. As the concerned policeman wanted to stop the process of granting him the ID, his co-worker rejected that saying there is no excuse to stop or delay it because he has all the required documents and it’s the election committee’s responsibility.

That’s a different case isn’t it? Why shouldn’t people with the right papers get a national ID? The chap in question wasn’t trying to bribe the police to give him an ID. Ah, but…

Police officers affirm that refugees can get IDs by giving bribes to concerned officials. These bribes are ranging from USD 500-1000. “Thousands of African refugees could obtain Yemeni IDs by bribing the brokers who have relations with civil affairs investigations and who in their turn allow the procedures to pass through,” said a police station’s officer. Many Africans had been arrested after finding out that they got IDs illegally, a policeman affirmed, but he did not mention the number, the place of their detention and the number of issues; whether they were referred to justice or not.

In fact what is going here is even more interesting: some officials not only allow illegal immigrants to bribe their way to the papers that will get them a national ID, but they have an absolute incentive to do so, which is that you can’t vote without an ID cards.

An election committee chief in Hajjah province got surprised when he discovered that the number of the registered people in the electoral district is twice the population number.

The same problem crops up time and time again. Identity documents become the target of criminal enterprise and because they don’t work properly they deliver terrific profits to the bad guys without really helping the good guys very much.

The most wanted are Serbian biometric passports, “which cost up to EUR 3,000”, the article claims.

[From B92 – News – Crime & War crimes – “Albanians pay EUR 3,000 for Serbian passports”]

You can see the problem. If the state relies on an ID card to regulate its relationship with citizens and that ID card embodies certain entitlements (that is, it is not simply an identity) then the incentive to get one shoots up, because once you have it then you are “inside the wire”, so to speak, and can act with impunity. So long as the card actually works, of course.

About 10% of the 24 million MyKad identification cards issued since 2001 had been replaced after they were found to be faulty.

[From 10% of MyKad identification cards found to be faulty]

If 1 in 10 ID cards isn’t working properly, then people will get used to that fact, so if a criminal shows up with an ID card that doesn’t work, the shopkeeper/doorman/whoever will assume that it’s broken and take it at face value, so I could stick my picture on any old ID card, that put the card in the microwave to fry the chip. This isn’t really progress, is it.

Faces

Greyscale backing image
[Dave Birch] As I blogged before, Consult Hyperion joined forces with Identrust to sponsor the Digital Identity Forum track on “Identity is the new money” at this year’s European e-Identity Management conference in London on 9th-10th June 2010. It was a really enjoyable event, I have to say, so hats off to Roger and the team from EEMA. The morning keynote came from Emer Coleman from the Greater London Authority who showed us a video about squirrels and then went on to talk about something called the “London Datastore”. I didn’t really understand her slides, which mentioned Marx, The Wire, Mini-Me from that Austin Powers movie, a tumble dryer and the Chicago School, but I think it meant that they are going to start using open source, which is a good thing, and they are going to open up some public data, such as where the new cycle hire stations will be (although they don’t know, since the sites are only indicative and you have to file a Freedom of Information Act request to find out).
This was followed by a panel discussion on the different “faces” of identity: ethical, legal and technical.

  • The ethical perspective came from Alexander Hanff, Head of Ethical Networks at Privacy International. Alexander noted the significant changes that have occurred in the UK in the last couple of weeks, with the abolition of the ID card, Children’s Index and so forth. He was rather positive about the new Coalition and said that he expected more “positive changes” to come. I have to say that I wasn’t clear on the vision, although he did mention transparency as a key element in the new identity and trust landscape, and that’s something I do agree with.
    • He did mention in passing that most businesses are unprepared for the impact of European telecoms regulation. This isn’t my field, so I didn’t entirely follow this part, but it seems that the EU is going to require the interweb to spy on its users in case they are terrorists or something.
  • The legal perspective came from Kevin Fraser, Head of Data Protection, Ministry of Justice. Kevin explained the eight key principles of data protection.
  • The technical perspective came from Forum friend Kim Cameron, Chief Architect, Identity & Access, Microsoft. Kim set out some of the drivers for cloud computing and some of the challenges that it faces. He mentioned in passing the problems of synchronising data over the interweb, which is exactly the problem that I have noticed with Microsoft Exchange and Outlook (they seem to send megabytes of data back and forth). He asked, essentially, whether the costs of identification and authentication will erode the cost advantages of the cloud (I think not, because I expect standard platforms to arise) and pointed out, entirely accurately, that none of this has really been thought through. He was advocating a claims-based model and reminded people that this is about M2M as well.

I liked having these different perspectives brought together at the beginning of the event as it made for a good foundation for observations and questions in the Digital Identity Forum stream, where John Bullard from Identrust chaired the speaking session and I chaired the panel session: though I say so myself, it was an excellent afternoon — many thanks to John Skipper, Vincent Jansen, Giles Sergant, Frank McCarthy, William Heath, Pete Bradwell, Robin Wilton and Henry Potts — and I came away with a number of new ideas to take back to our customers who are interested in developing identity-based businesses for the mass market. I was specifically curious as to whether the panel and the delegates had any feelings about the potential for banks to be identity providers, but the conversation was much more interesting and wide-ranging. I’ll put together a discussion of a few key points for the EEMA web site when I have some time.

Magic bullet it’s not

Greyscale backing image
[Dave Birch] I was in a meeting recently, the context is not relevant, where some of the Consult Hyperion team were helping a customer to develop a roadmap that included in a future transition to biometrics, and a discussion began about whether biometrics in certain kinds of mass market systems are about security or convenience (I’m convinced that they are about convenience, but that’s another discussion) and, if they are about security, whether existing biometrics are “secure enough”. “Secure enough”, though, is a complicated assertion — I’m glad to say, otherwise our risk analysis business wouldn’t be around for long — and this reminded about about a story from the Gulf about a woman who had been deported and then re-entered because her biometrics didn’t match the ones of hers on the “already been deported” register.

Although there were glitches in the system when it started, “for the past three or four years, we have not heard of a single case of someone getting around this”, the representative said.

[From Iris scan fails to stop returning deportee – The National Newspaper]

But this is illogical, isn’t it? If there were glitches in the system that allowed people to get through, then the bad guys would learn about this pretty quickly. People who are getting through on forged passports and not being recognised by the iris-recognition system are not going to report the system’s failure. So how would anyone know? It’s only when a failure comes to light through some other route that the failure is “logged”. So while the system is apparently working perfectly, in reality it isn’t. Let’s hope that a more detailed investigation in the UAE reveals that this woman’s irises were not scanned on re-entry or it will be back to drawing board for many people.

As readers will know, I like the idea of a “gold standard” biometric database, comprising iris, face and finger biometrics, to ensure the uniqueness of identity numbers (and that’s all). Adding biometrics to any identity system isn’t a “magic bullet”, but having a system that is founded on guaranteed uniqueness achieved through the use of biometrics might just be.

On the money

Greyscale backing image
[Dave Birch] As I blogged before, Consult Hyperion has joined forces with Identrust to sponsor the Digital Identity Forum track on “Identity is the new money” at this year’s European e-Identity Management conference in London on 9th-10th June 2010. Having been through the usual juggling as people drop in and out, get called away to meetings and mess up their calendars, the final line-up is now as fixed as it can possibly be:

The Digital Identity Forum: Identity is the New Money
Sponsored by Consult Hyperion and Identrust

Session 1: Chaired by John Bullard, Identrust

13:15 John Skipper, PA Consulting
13:45 Vincent Jansen, Innopay
14:15 Sonia Rossetti, RBS
14:45 Giles Sergant, Touch2ID

15:15 Tea

Session 2: Chaired by David Birch, Consult Hyperion

15:45 Expert Panel on the Identity Business

Joe Norburn, Identrust
Robin WIlton, FutureIdentity
Jan Dart, Bell ID
Todd Facemire, Barclays

16:45 Expert Panel on Identity and the Consumer

Peter Bradwell, DEMOS
Henry Potts, UCL
Marc Dautlich, Olswang
William Heath, MyDex

17:45 Close.

Look forward to seeing you there. By the way, the promotional code EID10DIF will give your delegates 20% OFF of one or two day passes.

Spot the looney

Greyscale backing image
[Dave Birch] I happened to be chatting to our friend Tony Poulos from the Telecommunications Manager’s Forum about new service possibilities for mobile operators facing commoditisation and declining ARPUs, and one of the areas he got me to brainstorm was identity services.

One of the world’s leading experts in this field, David Birch, spent some time with me explaining how mobile operators, in particular, could actually become ‘smart pipes’ with financial transactions. The ‘secret sauce’ according to Birch, lies in the ability for operators to provide secure identification linked to the SIM providing private and public keys for multiple providers.

[From The ‘secret sauce’? | Poulos Ponderings]

The mobile phone is the obvious “remote control” for identity, and I’m surprised that operators haven’t moved into this space more aggressively (there are some exceptions, of course, such as Turkcell). This led me to think, again, about the nature of the value-added identity infrastructure that might be built.

One thing, I think, is clear: the goal shouldn’t be to build a virtual version of the current identity “system”. At the moment, the online world has a dynsfunctional identity layer: it’s not really anonymous but it’s not really absonymous either.

Implementing an Internet without anonymity is very difficult, and causes its own problems. In order to have perfect attribution, we’d need agencies — real-world organizations — to provide Internet identity credentials based on other identification systems: passports, national identity cards, driver’s licenses, whatever. Sloppier identification systems, based on things such as credit cards, are simply too easy to subvert.

[From Schneier on Security: Anonymity and the Internet]

Bruce goes on to note that in the real world, half-baked identity management schemes actually make matters worse, not better. You can’t argue that having people sort-of-identified is better than having them not identified at all. It isn’t.

We have nothing that comes close to this global identification infrastructure. Moreover, centralizing information like this actually hurts security because it makes identity theft that much more profitable a crime.

[From Schneier on Security: Anonymity and the Internet]

This is why I am naturally somewhat suspicious of attempts to slap identity on the ends of the network rather than having identity management as a value-added service that is part of the network infrastructure and quite distinct from the issue of which identities will be managed (in other words, the web server has PKI built in, but it doesn’t provide the identities, it facilitates identity providers to do so). Simple solutions to this difficult problem — along the lines of the Chinese attempts to have “real-name registration” of Internet access by decreeing that everyone has to present their ID number when connecting — don’t work.

Mundie and other experts have said there is a growing need to police the internet to clampdown on fraud, espionage and the spread of viruses. “People don’t understand the scale of criminal activity on the internet. Whether criminal, individual or nation states, the community is growing more sophisticated,” the Microsoft executive said… He also called for a “driver’s license” for internet users. “If you want to drive a car you have to have a license to say that you are capable of driving a car, the car has to pass a test to say it is fit to drive and you have to have insurance.”

[From UN agency calls for global cyberwarfare treaty, ‘driver’s license’ for Web users | Raw Story]

It’s a bad analogy for a start, because cars are covered by product liability laws and Microsoft’s software isn’t, but the law on driving licences doesn’t stop cars from being stolen, used in crimes and being in accidents. If there were an Internet driver’s license, the 419 scammer wouldn’t apply for one, he’d make a fraudulent one just as he would in the physical world, and then use it to open bank accounts and so forth.

Many of the forgeries are “know your customer” documents such as utility bills and driving licences, which are then used to open bank accounts under false names.

[From Police war on fake ID factories as fraudsters net millions | News]

Ah, you might say, but in the Internet world we can use cryptography and similar geek tools to stop people from forging licences. In which case, the scammers will still get their licences.

An Irvington, N.J., man who operated a driving school pleaded guilty yesterday in federal court to bribing Pennsylvania driver’s license examiners to obtain phony licenses for his customers… Authorities said Lominy began paying bribes to a PennDOT driver’s license examiner, Alexander Steele, in early 2009 in exchange for Steele issuing licenses to his customers even though they weren’t Pennsylvania residents and hadn’t passed a written test or driving exam.

[From He admits bribing PennDOT examiners to issue fake licenses | Philadelphia Daily News | 04/02/2010]

I see reports of people being convicted for taking other people’s tests for them for money in the UK from time to time as well. So, an Internet driving licence? I don’t think this is a way to improve security. I might go further and say that compared to this, the Monster Raving Looney Party’s manifesto commitment to ban envelopes and force everyone to communicate via postcards looks more practical.

All sealed private letters to be banned – we propose that all letters must be written on postcards, and emails to be routed through police stations. (After all honest citizens have nothing to hide)

[From Official Monster Raving Loony Party – manifesto proposals]

Theatrical

Greyscale backing image
[Dave Birch] I was in the US recently, and had occasion to visit a number of office buildings. At some of these, in order to comply with security requirements, I was asked to provide “picture ID”. A couple of times, I produced my UK driving licence, which the guards looked at and then handed back, waving me through, despite the fact that they couldn’t possibly have known whether it was real or not. So what was the point? This is what is called “security theatre”, where the people involved (in this case, me and the guard) are both acting out our scripts to show security to the people around us. No actual security is involved. Were I a devotee of Osama bin Laden trying to get in to one of these buildings, I would simply have my accomplice call to make an appointment (perhaps posing as a security equipment salesman) using the same John Smith and then show up with a Western Australian driving licence in the name of John Smith with my picture on it. In fact, I’d lay a pound to a penny that I’d get in with Narnian driving licence. What is going on? If I’m going to see a contact at BigCompany, could he just use his digital identity to sign my Consult Hyperion public key, thus creating a credential certificate that I could load into my phone and that the guard could read using his PC, and which his PC could then resolve up the certificate chain to determine, in milliseconds, that I am entitled to enter the building?

In fact, what would be the point of the guard at all? I could just wander up to the building and present myself to the door: the door would ask my phone for a certificate, the phone would present it, but only if I am holding it (by my voiceprint, for example). That wouldn’t be theatre.

Back to the future of the ID card

Greyscale backing image
[Dave Birch] Well, it’s bye bye to the ID card. In the end, I shouldn’t think that my constant whining about the scheme made a ha’pence of difference and my time on the IPS Advisory Forum was probably wasted. I did make representations (invited, I hasten to add) to a couple of Conservative think-tanks in the run-up to the election, having previously made a number of representations (invited, I hasten to add) to the Government and its advisors. What I said was, in essence, that the Tory plan to scrap the ID card was almost as bad as the Labour plan to keep it. Neither the existing scheme nor the Coalition scheme (ie, nothing) actually solve any of the problems that the lack of an identity infrastructure creates and I absolutely predict that the lack of such an infrastructure will in turn create a major barrier to improving efficiency in public services: it’s going to be really difficult to move government services online, introduce more self-service and reduce fraud without some form of identification and authentication system.

It’s fair to observe that there a many people (eg, the LSE team who did the original detailed review on the Home Office’s ideas) are enjoying their “told you so” moment. The old scheme, created by the Home Office and their development partners PA Consulting back in 2004, was never going to work. It was flawed from the start, and as a showcase for the British technology industry, it was an embarassment: it provided none of the services that the identity cards systems in advanced nations (eg, Germany, Hong Kong, Estonia) provide and there was never any evidence that it would do so. There were no specifications, no toolkits, no APIs. I should say that I don’t blame the people working on the project over at IPS, many of whom I have great respect for: the project was doomed before they started work.

There has been no single narrative explaining what deficiency the card is supposed to address: instead, it has been sold as a cure-all remedy for a host of problems. One minute it was touted as tackling illegal immigration or benefit fraud; the next it was the magic bullet for terrorism and organised crime.

[From FT.com / World – MPs deride £5.4bn cure-all]

Indeed, and the card that was built was not only pointless but functionless, implementing nothing more than the existing e-passport application. It wasn’t as if they didn’t have the money to scour the planet for the best advice.

In 1997/98, the Home Office’s total spending on consultants was £7.6m. By last year, it had rocketed to £147.9m. Spending by the Identity and Passport Service – the arm of the department in charge of the ID cards project – has gone up in the same period from £237,000 to £30m.

[From High price of launching ID cards as consultants cost us £150m | the Daily Mail]

I can well remember taking part in the “consultation process” at the time. I can also well remember feeling rather angry about it: no-one paid any attention (as far I could tell) to any ideas or opinions about the scheme or the vision for identity management, only about the procurement process. In particular, just as the Home Office never paid any attention to our submissions about the original entitlement card concept (more on this in a minute), they never paid any attention to any modern conceptions of identity and set about building an electronic version of the scheme was abandoned in 1952. An electronic version of a paper card and an electronic version of a card index. There was always an alternative…

Many people do think eID could and should be implemented without full identification, i.e. more granular disclosure with pseudonymity – see e.g. Dave Birch’s brilliant and very readable paper “Psychic ID: A blueprint for a modern national identity scheme” (PDF).

[From Tech and Law]

WH is much too kind, but there you go. Anyway, we are where we are, in an identity limbo. Where do we go from here? It’s traditional for incoming administrations to want short and simple instant fixes, so here’s a practical three point plan…

  1. Turn the “Identity and Passport Service” back into the “Passport Service” and rebrand the current ID card as “Passport Plus”, an optional extra for people who are applying for or renewing passports.
  2. Start an accelerated consultation process for an Entitlement “Card” that will be mandatory within the lifetime of this Parliament for access to public services.
  3. Publish an API for using the service and provide open source software for people to start building services.

I say “Card”, of course, because any such plan would distinguish between the identity application that might reside in a smart card, phone, watch, hat, badge or implantable microchip and the smart card, phone, watch, hat, badge or implantable microchip itself. So, my Entitlement Card might have an identity application on it and my mobile phone (SIM) might have an identity application in it and they both have public key certificates with the same link to my entitlement number (or whatever) in it. I’ll have to turf out our original response to the entitlement card consultation process and tart it up.

The toolkit of technologies needed to do this — everything from digital signatures to biometrics to NFC to OpenID — is already in place. By going back to the original version of the government’s pre-Blunkett plan, the government and the industry together can create a more targeted project that can actually contribute to UK plc. I have to say, as an aside, that Consult Hyperion’s experiences advising the Irish government on their Public Services Card project has reinforced to me that focusing on a clear, simple and specific goal makes a very, very big difference to national infrastructure efforts of this kind.

Will mobile phones mean more crime?

Greyscale backing image
[Dave Birch] There was a discussion at this year’s Digital Money Forum with David Nordell from the Terror Finance blog. He called mobile payments a terrorist’s dream, but I disagreed. People always see the worst in new technologies, projecting existing crimes on to it. But the ability of new technology to fight crime is surely just as great. Mobile phones are no different from any other technology in that respect. One the one hand mobile phones can be used to commit new crimes, but on the other hand they can be used to prevent, detect and solve crimes.

Recently, two death row inmates were arrested in Nakuru GK Prison after being tracked through the assistance of mobile services firm Safaricom. More than 10 mobile phones and a number of SIM cards that were used to transact more than Sh300,000 were confiscated. The inmates colluded with people outside the prison to provided them with phone numbers of wealthy people who they called and threatened with death if they did not follow orders. Police launched investigations into how the convicts had separately received Sh350,000 and Sh40,000 in their welfare accounts when the racket that was unearthed in February.

[From Daily Nation: – News |Police probing mobile money transfer racket]

Nice mobile payment application — call people up, get them to send money back via the mobile payment system — but only if you’re a really stupid criminal, since the phone company knows where you are and will tell the police. And the police will be able to track you, and they will know the details of anyone else you call. And it doesn’t matter if it’s a prepaid phone not registered to you, because knowing where you are and who you are calling is pretty useful information.

The tracking is especially useful and in the future we will come to accept that we know where stuff is, all the time. As an aside, this doesn’t mean the end of privacy, but I think it does mean new notions of privacy.

Within seconds, a Tampa map appeared with a blinking orange dot moving away from the park. “We’re thinking to ourselves, there are our cell phones going down the road,” Jennifer Jensen said. The dot left the park, headed down McKinley Drive, headed south of Fowler Avenue and stopped less than 4 miles away from where it started… Caroline switched to satellite mode, and they were suddenly looking at the outside of the Bentley Court Apartments, 11603 N 22nd St.

[From There’s an app for that, too — Tampa cops find stolen iPhones with GPS – St. Petersburg Times]

At one level, this is just a fun “there’s an app for that story”. But think about it more as a window into the “internet of things” future. When everything is connected to everything else across an infrastructure then the idea of stealing something will become outdated (although, to be fair, some idiots still rob banks with shotguns). What’s the point of getting into my car if you can’t drive it without my RFID keyfob, what’s the point of stealing my TV if it will only decode encrypted signals if it is in range of my router and what’s the point of running off with my mobile phone if it won’t allow you to make calls unless you can mimic my voice? And what’s the point of stealing any of them at all if I can log in to any computer anywhere in the world and see where they all are?

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.