Cloudy with a chance of PKI

Greyscale backing image
[Dave Birch] I had a lovely time chairing the panel on mobile payments at the April meeting of Mobile Money at the GSMA. I was lucky to have a great set of panelists, including Neil Daly who is the Mobile Money Director at the GSMA. Neil made a terrific presentation, but I can’t tell you about it because all of this slides were marked “confidential” and I don’t want to get into trouble. So, anyway, what does all of this have to do with identity? Well, during the excellent panel discussion, John Lunn from Paypal, whose opinions I always take seriously, made (I think) a profound point. He said that as payments are disappearing into the cloud, they are going to merge, so that mobile payments and internet payments and all other payments (including retail payments) become the same thing, essentially. He’s not the only person who thinks this.

Most consumers still pay offline, like in restaurants or stores. But I have no doubt that in future all these businesses will be connected to the Internet and then, virtually all payments will be made online.

[From Globes [online] – Israel business news – For PayPal, it is only the beginning]

A few days later, at the Future of Money This makes for some interesting thinking, because the use of new devices and new networks to access the cloud data means that all sorts of new services can be provided. But it also means that the evolution of digital money and digital identity will be wholly interconnected because the problem of all payments will resolve down to identifying the payment “account” associated with the individuals (or the individual and the merchant) and then authenticating that they are who they claim to be. Once these steps have been taken, then moving a few bytes around to execute the payment is not much of an effort. (Almost) anyone can do it and absolutely everyone can use it.

A software platform—perhaps in the cloud– can lower those costs by investing in linking to the multitude of software programs that handle various elements of payments. By exposing APIs, this software platform then makes it possible for entrepreneurs to quickly integrate into most relevant aspects of the payments business… A great deal of innovation can be unleashed once these APIs are exposed.

[From Why the Payments Industry Needs a Catalyst to Drive Payments Innovation – pymnts.com]

Following along this line of thinking, where are the high added-value nodes in the new value network? If anyone can provide the engine, anyone can access the APIs, anyone can come up with ideas for using the new payments platform, what is there that not anyone can do? One fruitful area for exploration might be security.

MyGovID

Greyscale backing image
[Dave Birch] What with an imminent election in the UK, there’s been more talk about e-government and the future of online services.

A MyGov dashboard that allows every citizen to personalise the explosive growth of government services on the web was proposed today by Gordon Brown… Brown said MyGov, which will eventually replace DirectGov, will end the current frustration of web users needing to identify themselves separately for different public services.

[From Gordon Brown proposes personalised MyGov web services | Technology | guardian.co.uk]

Whoa! Hold on a minute. How are the recalcitrant inhabitants of Middlesborough, forced online by the redoubtable Ms. Martha Lane Fox, going to identify themselves to their MyGov page, and how will this identification and relevant credentials be federated to the various government transactional services it will link to?

By the way, here’s my mock-up of what the MyGov dashboard might look like.

Dog’s life

Greyscale backing image
[Dave Birch] There was a news story in the UK recently about the very sad death of a young woman who was lured to a remote spot by a man who met her on Facebook. The man was pretending to be a teenage boy. Facebook became the focus of the story, with the usual calls for something to be done. So is the sky falling in because of social networking?

You could just as easily argue that criminals are easier to catch because of Facebook, or any other new technology. The police can use them too, can’t they? Doesn’t social networking make it easier for the police and others to work together? Couldn’t Twitter help detectives? Can’t detectives subscribe to RSS feeds on cases of interest? (Frankly, I doubt it, but you get my point.)

[From 15Mb: yet another blog from Dave Birch » Blog Archive » The “Ford Mondeo Killer”]

People might think they’re anonymous, but they’re not. A rational policy on law and order would surely try to get more criminals to carry out their crimes online, because it’s easier to catch them in the virtual world than in the real one.

When a YouTube video came to its attention on Friday in San Francisco, the FBI had a Philadelphia man in custody the next day

[From How the FBI busted one YouTube nutjob in under a day]

It’s the same logic as with money laundering. If you raise high barriers by making people prove who they are before going online then they will either go to great lengths to avoid the rules (thereby enriching middlemen) or just avoid going online, in which case they cannot be tracked or traced at all. I wrote an article for SPEED (“Moving money and securities worldwide”) magazine’s Spring issue, noting that if criminals were to abandon suitcases full of 500 euro notes for platinum pieces in Everquest (frankly unlikely, but there you go) then surely it would be easier for law enforcement officers to masquerade as half-orc barbarians in Norrath than as criminals in the real world and therefore follow the money.

Microplanning for ID

Greyscale backing image
[Dave Birch] I’ve mentioned (in a tedious, repetitive cycle) that there is a connection between national ID schemes, financial inclusion and payments. To put it crudely, if you “solve” the “ID problem” then the “payment problem” goes away. Let’s set aside what any of those phrases in quotation marks actually mean for a moment. Let’s also set aside the moral and social issues for a moment, and it is clear that:

If the payment system knows absolutely who you are (because of the ID card) then it becomes relatively easy to handle the funds transfer. The identification and authentication cost would, presumably, be shared between the payment application and lots of other applications.

[From [ Digital Identity Forum ]]

Now, I’m certainly not saying that that is the best possible use of technology, and have bored for Britain on the subject of pseudonymity and suchlike, but I am saying that in some circumstances this might be the best overall solution to the problem of extending financial inclusion.

Residents in Oman will soon be able to make payments electronically even if they do not possess a credit or debit card — and it’ll be thanks to the launch of ‘e-purse’ scheme here. All they require is their ID or residency card… The new facility allows people, both nationals and expatriates, to store/load money in their national ID and residency cards and use them to make payments electronically.

[From Khaleej Times Online – Electronic Payment Through ID Card in Oman Soon]

Since ID cards are mandatory in Oman, you can see the logic. What is point of giving people yet another card to carry around when they all have an ID card all the time? And given that getting the less well-off out of the cash economy is a relatively simple way to improve their lot in life, it’s an obvious social inclusion strategy.

(Yes, yes, anonymity, I know. But let’s set that aside for a moment as well.)

“Location-based” login protection

Greyscale backing image

[Dave Petch] It’s not often the case that eBay users find cause to congratulate
the internet giant, in fact quite the opposite is usually the case. 
Whether it’s seller
rebellion against fee hikes
, anger at
seller policy changes
, lawsuits against
the selling of counterfeit goods
or password
vulnerabilities in the developer program
, eBay are never far away from
controversy of some kind.

So I was therefore pleasantly surprised to discover that eBay (in the UK at least) have implemented location-based login checks,
something which would surely assist in the ongoing fight against phishing
attacks were it implemented more widely at other online merchants /
communities. It was also another great but simple example of the utility of the
mobile phone as an authentication channel.

I discovered this through the somewhat suspect process of
using my friend’s eBay login details to help him sort out an item listing issue
that he had.  He’s one of those illiterate computer users who doesn’t know
one end of the web from the other
, so he didn’t hesitate in telling me his
login and password over the phone.

My friend lives 20 miles away from me.  When I tried to
log in using his valid credentials, eBay took me to a page stating it had been
noticed I was logging in from a “location” that was not my usual one.  I
presume this was detected using my IP address, although whether it was able to
trace me to a spot in Guildford or just to the location of my ISP is not clear
(a whois of my IP address at
home tells me that I live in Hull, East Yorkshire, which is at least 230 miles
from my house but unsurprisingly not very far from my ISP).  However, for
the security mechanism in question, this was more than enough information for eBay to detect the disparity from my friend’s usual network access data.

I was then asked if I wished to be authenticated using
either a phone call (instant) or an email (short delay).  I selected
authentication by phone call (it uses the existing registered number and does
not allow you to enter a different one), my friend’s mobile rang almost
instantly, after which an electronic voice announced, “Hello, this is eBay, are
you expecting this call? If so, press #”.   My friend pressed # and
an access code was read out to him.  He reported the code to me, I entered
it at the website and in I went.

The specifics of the situation were obviously beyond that
for which the protection mechanism was strictly designed, but the process
worked very smoothly and was close to real time, it presented the user with
alternative options for added convenience and, above all, it was simple. 
Sure, it slowed me down for a minute, but my initial thought was that such a
simple mechanism would surely assist in the fight against the use of phished
credentials.  If you cannot stop the consumer from continuing to fall for
what is fast becoming one of the oldest tricks in the book, then stopping the
use of those captured credentials using simple location checking seems to be a
worthwhile next step, at least until such time that the highly
flawed
method of user authentication that we call “passwords” is replaced
by something
better
.

There
was a flaw in the process, however.  Having completed my login to the
website using my friend’s credentials, I then asked him to log in at the same
time so that he could see the effect of the changes I was making to his item
listing.  eBay allowed him straight in, although it should have been clear
at this point that it was not possible for him to be in two different locations
at the same time, at least not without considerable mind power.

Meg was absolutely right

Greyscale backing image
[Dave Birch] Some time back, the Minister for ID Cards Meg Hillier received some criticism for saying that the new ID card was just like a passport, but for use inside the country. In fact, I don’t think it would really be considered a breach of confidence to report that I once sat next to Meg at an event of some description, and she told me that she thought it had been an unfortunate turn of phrase.

Hillier is relatively new to the ID card brief at the Home Office, and has come up with several improbable and/or unfortunate claims in recent months (e.g., “we should see an identity card, like a passport, in country”)

[From Transcript disappears minister’s ‘hack-proof’ ID register claim • The Register]

But actually, she was completely correct in saying this. In the UK, the ID card scheme was (for political, not engineering, reasons) given to the Passport Service. They produced an ID card that was — guess what — a passport. The UK ID cards that have been issued so far implement nothing other than the ICAO standard for e-passports with Extended Access Control (EAC). I’m not knocking the Passport Service. If the ID card had been given to the DVLA then it would have ended up looking like a driving licence and if it had been given to the DfT then it would have ended up with an ITSO shell on it. My point is not to criticise the implementation decisions made by the Home Office and their ID Development Partner, PA Consulting, but to call for a different debate about identity and a greater vision for national identity management for the future.

I’ll illustrate what i mean with one small example. The ID cards issued in the UK have a contact plate on them, but it is only for show, since there are no services accessible through the contact interface (for the technical, there is no Answer-to-Reset, or ATR). The cards implement the ICAO standard for e-passports and nothing more. The lovely gold square is a Potemkin Plate, only there to impress politicians. Meanwhile, in Germany, they are designing a card that implements online pseudonyms to support e-commerce and other such 21st-century functionality.

The Interior Ministry has confirmed that the introduction of the multi-function card will go ahead as planned on November 1, 2010.

[From Germany set to introduce smart ID Cards in 2010 | Science & Technology | Deutsche Welle | 15.12.2009]

Why are the Germans able to introduce a national ID card that does something useful, while we are not? Are we stupider than the Germans? I don’t believe that. We have worse programmers? Doubt it. It’s a mystery. Of course, it might be that their system is designed by engineers to meet a clear specification, whereas no-one really knows what ours is supposed to be for, but who knows.

In a bit of a State

Greyscale backing image
[Dave Birch] If you build a stable door, then one day you will inevitable find yourself locking it while your horse disappears over the horizon. There's been no better illustration of this in recent times than the recent hulabaloo about Google in China. Apparently, Chinese "hackers" were found it rather easy to break into the e-mail accounts of human rights activists and so forth, because Google had been forced to build a system to do precisely that.

That's because they apparently were able to access a system used to help Google comply with search warrants by providing data on Google users, said a source familiar with the situation, who spoke on condition of anonymity because he was not authorized to speak with the press. "Right before Christmas, it was, 'Holy s***, this malware is accessing the internal intercept [systems],'" he said.

[From Google attack part of widespread spying effort]

So companies are forced to build a stable door, and then when the inevitable happens, people appear shocked. The root problem is, naturally, that there is no underlying strategy: we fight using the technology of the next war but the tactics of the last one, as someone once said but I couldn't find out who by googling. If you want proof of this, you only need consider the US government's official response to the incident in a speech by the Secretary of State, Mrs. Clinton, that cofnirmed one of my most basic criticisms of government policy in this cyber age:

The speech made it obvious that State Department officials do not have a coherent view on online anonymity. On the one hand, they want to crack down on intellectual property theft and terrorists; on the other hand, they want to protect Iranian and the Chinese dissidents. Well, let me break the hard news: You can't have it both ways and the sooner you get on with "anonymity for everyone" rhetoric, the more you'll accomplish.

[From Is Hillary Clinton launching a cyber Cold War? | Net Effect]

In fact, US (and other governments') policy in this area isn't just confused and pointless, it's actually dangerous. While I was googling for references, I discovered that the always sensible security expert Bruce Schneier had used this story to make the same point.

The news here isn't that Chinese hackers engage in these activities or that their attempts are technically sophisticated — we knew that already — it's that the U.S. government inadvertently aided the hackers.

[From U.S. enables Chinese hacking of Google – CNN.com]

You can't have privacy without security, as the relatively old saying goes. Ah, you might object, but there's a greater good argument: security without privacy is the only way society can fight the bad guys. We must be able to read people's Google mail accounts because we need to track down criminals and terrorists. And, indeed, this is sort of true. If you know that Osama bin Laden is sending me e-mail, then you might want to investigate me a little further. And I imagine that obtaining the contents of all of my e-mails, from Google, might be a convenient way to do it (although, of course, if I am a terrorist and I know that government is able to read my mail, then I will send misleading e-mail and use an alternative secure channel to conference my confederates). Anyway, you think I'm a bad guy so you want to be able to go to Google and get all my mail. This already happens, in fact.

Prosecutors obtained a CD-ROM disk from Google Inc. this week of Mr. Tannin’s e-mail messages from Nov. 20, 2006, through Aug. 12, 2007. The two funds collapsed in June 2007. Mr. Cioffi, 53, and Mr. Tannin, 48, were indicted for fraud, and Mr. Cioffi also was charged with insider trading, the first managers accused of criminal charges from a company that collapsed in the financial crisis. The hedge funds’ failure cost investors $1.4 billion.

[From E-mail Shows Fear of ‘Blow-Up Risk’ at Bear Fund – DealBook Blog – NYTimes.com]

To be honest, I'm not sure what the fuss is about. If you send something in an e-mail, then as far as I am concerned you have no reasonable expectation of privacy. If you wouldn't put it on a postcard, then you shouldn't put in an e-mail (was it Phil Zimmerman of PGP who first said that?). If these hedge fund guys really wanted to send secret messages to each other then they could have used anonymous comments on an obscure blog, rolling IM accounts changing in a pattern known only to them or, ahem, encryption. Havent't they ever watched the world's best TV drama, "The Wire"?

So I'm not saying that prosecutors shouldn't try to go and get these e-mails. But should they get them from Google? I have a book on my shelf somewhere — the title won't come to mind — which says that, essentially, the government doesn't regulate books because it can't and it does regulate TV because it can (this was a few years ago). Surely this is what is going on here. It might be harder to nail those guys without a copy of their Google e-mail, but is it plausible that without the Google e-mail they will get off? Well, in this case they got off because of the e-mails, as far as I can see.

the prosecution blew it — on two counts. First, in devising the original indictment for conspiracy and securities fraud against the two defendants, Ralph Cioffi and Matthew Tannin, it relied on damning snippets of lengthy e-mail messages that when viewed in their entirety proved to be highly ambiguous. Second, the prosecution made a reductionist opening argument claiming the men were nothing more than out-and-out liars, needlessly raising the bar in terms of what it had to prove to jurors

[From Bear Stearns Trial: How the Scapegoats Escaped – DealBook Blog – NYTimes.com]

Suppose you are a policeman. If Osama bin Laden is sending me e-mail every day, but you can't get the contents of those e-mails from Google or BT, is that worse for society than Osama bin Laden being able to read all of your e-mails? The mere fact that I'm getting e-mail, text message or care packages from a cave in Afghanistan is enough for you to put me under surveillance and from then on other methods can take over. Look, I don't know what the answer is either, but I do know that there is a question, and therefore understand that there is a danger

Jorge Krug, Banrisul

Greyscale backing image
[Dave Birch] Jorge F. Krug is the head officer of the IT Security Division of Banrisul, State Bank of Rio Grande do Sul, Brazil, and has a seat in a number of IT associations and committees, including Brazilian Bank Association (FEBRABAN)’s Digital Certification Committee, Sucesu-RS (Society of Computer Science and Telecom Users of the Rio Grande do Sul State), ASBACE (Brazilian Association of State and Regional Banks). Mr. Krug is also the head of AC-RS (Rio Grande do Sul State Digital Certification Authority). In this podcast he talks about the introduction of the Banrisul EMV card with PKI on board, a project previously discussed in detail on this blog.

Listen here in either [Podcast MPEG4] or [Sound-only MP3] format.

Are mobile payments a “terrorist dream” or not?

Greyscale backing image
[Dave Birch] A couple of years ago, I expressed some scepticism as to whether the tight know-your-customer and anti-money laundering rules would actually achieve anything and suggested that the net welfare attending a more relaxed structure might be significantly greater. In particular, I commented on the potential for mobile payments to help or hinder.

The use of mobiles to make payments is clearly a boon to terrorists (or, at least, terrorists who have never heard of 500 euro notes) as Rachel Ehrenfeld, founder of the Terror Finance Blog has noted. She calls the hook-up between the GSMA and MasterCard a “terrorist dream”. David Nordell, another finance terror blogger, says, “Person-to-person transfers via mobile phones will be almost anonymous, and completely uncontrollable unless the regulators intervene and block these new services until ways are devised to track the flow of funds.”

[From Digital Money Forum: The prepaid backlash]

A year ago, I expanded on this discussion in an article for the Journal of Internet Banking and Commerce. David Nordell was kind enough to read the whole article and recently provided a considered response. I asked him for his permission to excerpt part of it and he agreed, and I think it’s worth quoting a few passages in full. David says…

I’m afraid that you have reached entirely the wrong conclusions. For all that I agree that there is indeed an element of ‘security theatre’ in the regulatory regime for anti-money laundering and counter-terror finance there is also a great deal of genuine value in the at least some of the regulations, and they are not there just to oppress the general public. The amounts of money that are needed to actually carry out terrorist operations of the kind we saw in London in July 2005 or that planned against the airliners two years ago are small, in the order of a few thousand pounds, and therefore well within the range of a dozen e- or m-payments.

This is a point well taken. Suspicious Activity Reports (SARs) that focus on transactions above £10,000 will not, under any regime, actually catch any more than mildly unintelligent criminal, terrorists, corrupt politicians or child pornographers. According to the Serious Organised Crime Agency (SOCA) here in the UK, there were 228,834 SARs filed last year and of these 703 were referred on to the terrorist finance investigation. Naturally, the report can’t say how many of these 703 (0.3% of the SARs filed) were actually related to terrorist activity (although it does note that one of the terrorist SARs was filed by a charity and one by an estate agent, just to indicate the spread). So far as money laundering goes, and financial crime, I can’t find any figures that show whether the money spent on SARs is a good investment or not. In the Royal Society of Arts debate on white collar crime, one of the researchers put total fraud in the UK last year at about £60 billion so it doesn’t look as if SARs are making much of a dent in that, although hopefully they are deterring some major crimes. David continues…

No financial intelligence unit or police force that I know supports the idea of monitoring every possible financial transaction, whether through conventional banking or technology-enabled services; and all the professionals I know in this field understand perfectly well that the SAR regime, which is based on arbitrary reporting limits, will inevitably produce far more noise than signal. However, there is a lot of value in carrying out KYC checks, in e-money services just as much as in conventional banking: these can help to provide predictive intelligence about people who may be planning to carry out financial fraud, launder money from other criminal activity, or finance terrorist operations in planning.

I wasn’t not arguing that we should have no KYC checks, but what I was arguing for was a sensible floor below which KYC checks are not needed. I happened to be in a local branch of national financial services organisation a few weeks ago when, for dreary reasons, I had to get into a queue. The person in front of me in the queue was trying to send fifty pounds to a relative in Liverpool. The clerk told him that couldn’t, because he didn’t have a passport and a utility bill. The chap complained that he had been sending this birthday money every year for decades. The clerk was unmoved. So who benefits from this? I didn’t stop the 911 terrorists (who used credit cards in their own names) or the crotchbomber (who paid for one-way air ticket in cash) or the tube bombers (who were carrying identity documents). My argument was, and is, that we should decide where the balance should be in order to get the best result for society as a whole.

My suggestion is that we fix on 500 euros as the breakpoint. People should be allowed prepaid cards, prepaid accounts, money transfer accounts or whatever with no identification provided that the maximum balance is limited to 500 euros (it is currently 150 euros) and a maximum annual turnover over 10,000 euros (it is currently 2,500 euros). This will lower costs and ease accessibility — I might even go and get an O2 Money card — thus achieving a variety of goals including social inclusion and reduced transaction costs for the poor.

The problem, of course, is that the existing system makes it extremely difficult to cope with forged identity papers and stolen identities, which are used in the majority of cases of serious financial crime. I certainly agree with you that AML regulations do make access to the conventional financial system more difficult for people, such as recent immigrants, who don’t have the right papers to satisfy what are basically unintelligent regulatory requirements. I’ve actually witnessed an example of the stupidity of these requirements while waiting at a counter at Lloyds Bank – stupidity that the bank official himself didn’t agree with but left the prospective customer unable to open an account. Is there a better way? Yes, but I don’t agree that it should be based on just dropping KYC requirements, because this will just encourage the growth of fraud. On the contrary, I believe it should be based on making KYC more rigorous in order to exclude as many fake and stolen IDs as possible, and then as easy as possible to use in order to make the financial system inclusive.

This is a very different approach. I didn’t suggest dropping KYC requirements completely, to be fair, but I did suggest raising the requirements for the financial products that need KYC. Specifically, I suggested that there should be no KYC prepaid card or mobile money transfer accounts that have a maximum allowable balance of €500. But David’s approach suggests that pursuing the “identity is the new money” meme further might be

Fit and counterfeit

Greyscale backing image
[Dave Birch] When the first Bank of England banknotes were issued in June 1694, they must have seemed pretty secure, with their fancy engraving and the handwritten signatures. It must have been a bit of a shock in August 1694 when the first counterfeits were detected. Or should I say that the first counterfeits bad enough to be detected were detected. One of the problems that plagued the Royal Mint at that time was that the machinery to make notes and coins was being stolen by corrupt employees and sold to the criminal underworld. The machines were not really producing counterfeits, because they were the same plates and dies as being used in the mint, they were producing unauthorised versions. Banknotes have evolved a bit since then, but given the regularity of the stories about North Korea “supernotes”, the counterfeiters have kept pace.

North Korea has been producing “super notes,” counterfeit 100-dollar bills practically indistinguishable from legal tender, even since 2007 when the U.S. released North Korea from financial sanctions. North Korea has also tried to bring some of the notes into South Korea.

[From Daily NK – Super Notes Still in Production]

There’s no need to get Korean ultraforgers on board so far as the new UK national identity card goes. In fact, our indigenous forgers have been doing an excellent job, selling first-class forgeries of the UK ID card even before the UK ID card existed. Why they are bothering is not entirely clear.

Darren McTeggart tried to use the £30 card to pick up a replacement credit card from a branch of Santander – formerly Abbey – in Manchester, where the scheme was rolled out on a voluntary basis last year. Mr McTeggart, one of the first people to get the card, said: “They said it was not on their list of approved ID.

[From Man can’t prove ID with ID card – Telegraph]

I’m sure this is just a hiccough. But how are indigenous ultraforgers creating their dastardly fake ID cards? Are they breaking into the government’s factories and stealing the chips? Have they got corrupt insiders working for them? Sadly, nothing that interesting. It’s apparently so easy to forge documents like this that the police are now asking the companies who sell printers to report suspicious customers, much as banks have to do when opening new accounts.

U.K. police are trying to get wider participation from printer manufacturers and makers of specialist equipment in a voluntary program designed to cut off criminals from the tools they need to make fraudulent passports and ID cards.

[From UK Police Engage Print Industry to Stop Fake IDs – PCWorld Business Center]

Oh come on. You can’t seriously tell me that criminals can just walk into PC World and buy printers that can produce a fake ID card? I don’t believe that for a moment. Oh, wait…

The Met has shut at least 20 [fake ID] “factories” in the last 18 months and believes more than 30,000 fake identities are in circulation. Police examined 12,000 of them and established they were behind a racket worth £14 million. One £750 printer was withdrawn from sale at PC World after detectives revealed it could produce replicas of the proposed new ID card and EU driving licences.

[From Police war on fake ID factories as fraudsters net millions | News]

Whoops. I’m sure this isn’t what former Home Secretary David Blunkett had in mind when he was outlined his plans for the national ID card way back whenever.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.