Imperfect crime

Greyscale backing image
[Dave Birch] Some years ago at the Digital Money Forum, Richard Bartle from the University of Essex characterised the economy of virtual worlds as “people buying things that don’t exist from people who don’t own them” which was, frankly, a brilliant summary. There are also, sadly, a class of people stealing things that don’t exist from people who don’t own them and this is a crime, so it was with great interest I read that

A British man has been arrested and cautioned for stealing accounts for online game Runescape… A statement from the Police National e-crime unit said: “A 23-year-old man was arrested in Avon and Somerset… on suspicion of a number of computer misuse offences.”… Once hi-tech thieves have these credentials they plunder the accounts, strip characters of their items and sell off the rare virtual goods for Runescape gold.

[From BBC News – Runescape creator pursues ‘phishing thieves’]

This is real identity theft. If criminals somehow get into my bank account and spirit the money away, I don’t really care because it’s the bank’s problem and they will give me the money back. But if the criminals take over my Runescape character, that’s a real personal violation. As I said before

a bank can easily restore my money, but it’s much harder for Facebook to restore my reputation (apart from anything else, a reputation takes time to build). Which is the worse crime?

[From Digital Identity Forum: What identity is important?]

It’s the latter, clearly. So perhaps the “standard” use case for strong authentication should be switched from logging on for home banking to logging on to Facebook, which takes us into the world of OAuth and OpenID instead of EMV and OTP. In this world, there’s already plenty of work going on around authentication, credentials and federation that could provide key portions of the infrastructure that we know that we are going to need in the mass market.

Supercollider

Greyscale backing image
[Dave Birch] As I said on Twitter, Australia is the Large Hadron Collider (LHC) of the payments world, where an expensive experiment is underway to smash payment card companies and retailers together at high energy. At the LHC, physicists have a number of competing ideas about how the universe might work and they are looking at the results of collisions to find evidence for one theory or another. In Australia, there are no ideas about the system should work. No-one knows what the correct level of interchange should be. But what is the experiment telling us? Well, for one thing (and this is a message that needs to be transmitted around the European Commission) it is telling us that the results of the collisions tend to be the unexpected.

Perhaps more vexing, Australian merchants, including retailers, restaurants and airlines, are imposing surcharges for each credit card transaction, even though fees the merchants pay card companies have fallen.

[From U.S. Looks to Australia on Curbing Credit Card Fees – Series – NYTimes.com]

Well, well. Now this can't be because all Australian merchants are corrupt and are trying to get paid in cash in order to avoid taxes, so there must be something else going in and if I were to ask an economist about this, I suspect the answer might be something to do with the imperfect nature of the competition between payment choices at the point of sale and an information asymmetry between retailers and consumers.

Digital division

Greyscale backing image
[Dave Birch] There was yet another debate about the “digital divide” in London, featuring the British government’s technology tzarina, Martha Lane Fox (note for foreign readers: Martha Lane Fox was a co-founder of the famous internet enterprise Lastminute.com), who is charged with forcing a recalcitrant populace — one-sixth of Britons say they don’t want the web — to log on to things. There are 10 million people in Britain who have never been on the Internet and the Digital Inclusion Task Force has to get 4 million of them “online” by 2012, otherwise… Actually, I don’t know what the “otherwise” clause is, so had better move on.

At the debate, they were (essentially) talking about the divide between people who order books online from Amazon and people who don’t, and I’m sure this is an important topic, but I’m not that interested in it. I once got into trouble in a meeting with a public sector customer because I said that people who weren’t on the web generally didn’t want to be, and since they could clearly afford Sky television and mobile phones, I didn’t think that it really mattered that they chose not to buy broadband. But I digress.

Is there an interesting, and more important, digital divide? Yes, there is. And it’s the digital divide between the developed world and the developing world. But it’s not what you think and, as Tomi Ahonen frequently points out, it’s got nothing to do with “one laptop per child” or submarine cables for internet access.

In the Industrialized World we have TVs, PCs, FM radios, fixed landlines and mobile phones to consider and compare and use and more than half of the population has one of each of those. In the Developing World, the only technology that reaches half the population is mobile telecoms, and all others are tiny in comparison. For the Emerging World, mobile is not only the first screen it is literally the only screen.

[From Communities Dominate Brands: The Digital Divide in Numbers: TVs, PCs, Internet users, Mobile around the world]

If we are going to deliver services to the mass of people in the developing world, services that are going to improve the lives of the mass of the population, then we need to focus those services on the mobile channel.

# The mobile device will be the primary connection tool to the internet for most people in the world in 2020.
# The transparency of people and organizations will increase, but that will not necessarily yield more personal integrity, social tolerance, or forgiveness.
# Voice recognition and touch user-interfaces with the internet will be more prevalent and accepted by 2020.

[From Pontydysgu – Bridge to Learning » Blog Archive » Digital Identities and Social Relations]

This seems like a reasonable projection given current trends and a bit of imagination and, personally, I think that the issue of transparency may well have the most impact, changing both businesses and government in ways that we haven’t taken on board yet but that’s an issue for another day. But take these points on board, particularly the reinforcing synergies between the mobile phone as the device, the mobile phone as the tool for opening up organisations and the mobile phone as locus for the voice interface (which, together with voice authentication, will transform identity and authentication).

Trans-mission

Greyscale backing image
[Dave Birch] Should people be allowed to have “anonymous” prepaid mobile phones (well, SIMs) or not? It’s a simple question, but a complicated subject. And it’s worth exploring because it helps us to have a real, focused discussion about practical privacy and security issues. The subject came up because of one of the current hot topics in the UK, which is the government’s proposed “crackdown” (although “crackup” might be a better description) on the authorised copying of copyright material. Once the government has disconnected most broadband users in Britain through the “three accusations and you’re out” policy, many desperate internet addicts will be driven to using mobile connections to continue online banking, reading about “I’m a celebrity get me out of here” behind the Murdoch paywall and playing World of Warcraft. At which point, the mobile operators will come under pressure to start disconnecting people as well. But as the always spot-on mobile industry analyst and Forum friend Dean Bubley notes

“On one hand, the government’s trying to encourage internet connectivity — bridging the digital divide — but a lot of people in lower socioeconomic groups are on prepay, and the vast majority are anonymous,” Bubley said

[From Mobile industry ‘cannot identify pirates’ – ZDNet.co.uk]

So the mobile operator won’t be able to turn over the name and address of the supposed copyright pyrate. When the letter from Apple Corporation arrives at Vodafone asking them to turn over the name and address of the person who downloaded “Love Me Do”, Vodafone won’t be able to tell them (so presumably Vodafone will then be found in contempt of court or something and their internet access will be turned off).

So what to do? Well, one approach (followed in many countries) is simply to force all prepaid phones to be registered with the authorities. In the UK, the government might use its splendid new national identity register, for example, to ensure that all prepaid phones have a passport or national identity card connected to them them. And, as in Spain, take immediate action against those terrorists, money launderers, child pornographers and criminals who refuse to do so.

Spanish mobile operators last night cut off an estimated three to four million pre-pay mobile phones whose owners had not followed government instructions to register their devices.

[From Spain cuts off 3m pre-pay mobiles • The Register]

I can see exactly why law enforcement and government agencies object so strongly to anonymous mobile phones (although they still allow people to post letters anonymously) but I think they are wrong to react in this way. The truth is, the criminals will just use other peoples’ phones and will be even harder to track and trace than they were before.

Consider the most prosaic of examples. Where I live, in a deprived part of Europe called “Surrey”, a window in the house opposite to ours was smashed by a gang of feral youths. Sadly, we didn’t see this happen so we unable to assist the local constabulary. But suppose I had seen it happen? I have, currently, four prepaid mobile phones about my person (they are used for various demos and experiments for work) so I would have just picked up one of these phones and called the police with the details of the incident and a description of the yobs.

But now suppose that my prepaid phones were now connected to me through the national identity register? Now there’s no chance that I will pick up one of them and report the crime, because I’d be worried that my name and address would get (via the police or the database) to the gang in question.

This may be a silly example, but from battered women to corporate whistleblowers there are plenty of good reasons for allowing anonymity. We need this to be part of the infrastructure.

All this does prove, though, that there is a legitimate place for digital anonymity, and I hope that any identity management system required by the US government and others will allow anonymity and not prevent it.

[From Tech and Law: Technology, domestic violence, anonymity]

Note the important qualification here: there is a legitimate place for “digital anonymity”. I would go further than that and say that without digital anonymity, we are creating the wrong kind of infrastructure for a successful and prosperous society. Now, your web site may choose to allow or decline access by digitally known, pseudonymous or anonymous identities. If you are a web site discussing Iranian democracy, you may well insist on the latter. If you are government department, you may insisit on the former. The infrastructure must cope with both.

Collision

Greyscale backing image
[Dave Birch] Here at Consult Hyperion we’ve recommended to more than one non-US customer that they look at specifying PIV solutions. Why? Because PIV does almost all of what they want, and the cost and integration advantages make it a better short- to medium-term solution. But there’s another less tangible reason for being interested in it: because once the US government has chosen something as a “standard”, then that is where the energy will go, because the suppliers are rational people. The seal of approval is very, very important. Which is why I”m not the only one who has been reflecting on just how significant the US government’s support for OpenID is. When this support was announced, Bob Blakely highlighted just how important an announcement it was.

But the identity world had its own big news today; the news is that the US Government has teamed up with the OpenID Foundation, the Information Card Foundation, the Kantara Initiative, and InCommon in creating the Open Identity Initiative.

[From Burton Group Identity Blog: US Government Identity News]

I was involved in some discussions with a government department a few months ago — long before the US government announcement — during which I suggested opening up some public services using OpenID. My reasoning was that we could experiment with “soft” OpenIDs provided by (to consumers) familiar services. If you asked a customer to log in to the DVLC using their Facebook “Identity”, then I’m sure they would manage to do this with little training and no mention of trust infrastructures and the like. Once they are comfortable with this, then you can restrict access to “hard” OpenIDs (by which I mean 2FA OpenIDs).

The central point, though, was that the government could help to create an identity infrastructure built on a diverse selection of “private” digital identities. I think that, as Burton note, the US government’s decision signals a genuine paradigm shift in this direction, a genuine change in the mental model are identity.

after years of government attempts to create identities and assign them to citizens (via such bad ideas as the UK National ID scheme and the US REAL-ID act), a government has finally recognized that individuals already HAVE identities, and that it’s a better idea, for most purposes, to use these identities than to establish a new government bureaucracy to create new identities

[From Burton Group Identity Blog: US Government Identity News]

Personally, I think that the government ought to be a “gold standard” identity provider as well as an identity oonsumer, but that’s another issue.

Verily

Greyscale backing image
[Dave Birch] I enjoyed Scott Silverman's talk about privacy and security at ID World. Scott (the devil, according to CASPIAN) is the CEO of Verichip, the company that developed the first FDA-approved RFID chip for human implantation. (It's just a passive RFID chip containing a 16-bit identification number). Apparently, they had had some 900 emergency rooms across the US signed up for the service before the "privacy backlash" started. Opponents of the system told the newspapers that the chips caused cancer, and that was that.

Now, to be honest, I'm very sympathetic to Scott. A couple of years ago, I contacted Verichip because I thought it would be fun to have a Verichip implanted in my arm ready for the Digital Identity Forum, but they said no (spoilsports). My cat has one, and I'm jealous.

Anyway, the point is that the privacy backlash was so great that the stock price collapsed and the company — which was reduced to a shell — has now been restructured as PositiveID with Scott as the majority shareholder. They have a number of initiatives, one of them being "PatientID" which will link high-risk patients (eg, Alzheimer patients) to their medical records. Now, as far as I can see (and I'm speaking from the point of view of someone with an Alzheimer's sufferer in the family) this is a splendid idea. I'm pretty privacy sensitive, but this is an application that makes absolute sense to me. If I had Alzheimer's, I'd want a chip so that if I get lost or confused, a doctor can instantly find out who I am and what my conditions and medications are. You could do it by fingerprinting me, or iris scanning or whatever. But it appears to quick and simple to use the chip instead.

Scott also mentioned their "HealthID" initiative that will link sensors to the chip: so, for example, you could have a glucose-sensing chip for some types of diabetes so that when the chip is read to identify the patient it will also report glucose levels. If I had diabetes, I would much rather have one of these than prick my finger and test drops of blood. I wouldn't want everyone to be able to read it though, and this is where the problem comes: we need to have some form of standard privacy-enhancing infrastructure that sits above the "chip layer" to make this all work properly.

Rob Schuurman, Nedap

Greyscale backing image
[Dave Birch] Rob Schuurman is the general manager of Nedap Healthcare, based in the Netherlands. They have developed award-winning products that use mobile phones and NFC to deliver practical, convenient security to a mass market. In this podcast, he talks about his practical experiences getting an NFC-based service into operation and shares some thoughts about the future of the technology in that sector.

Listen here in either [Podcast MPEG4] or [Sound-only MP3] format.

Out of control, up to a point

Greyscale backing image
[Dave Birch] I re-read an excellent post over at Emergent Chaos. It reflected an important discussion between two people, both of whom I take very seriously. To paraphrase and simplify horribly, Bob thinks that the social structures maintain privacy, Adam thinks that technological structures maintain privacy.

In a world where some people say “I’ve got nothing to hide” and others pay for post office boxes, I don’t know how we can settle on a single societal norm. And in a world in which cheesy-looking web sites get more personal data — no really, listen to Alessandro Acquisti, or read the summary of “Online Data Present a Privacy Minefield” on All Things Considered… — I’m not sure the social frame will save us.

[From Emergent Chaos: Bob Blakley Gets Future Shock Dead Wrong]

The lack of a “norm” is a good point here, and I have to say it made me think. We should be developing tools that allow people to construct their norms (within boundaries, obviously) but not setting out a norm so that the tools can only implement one model. For this reason, amongst others, I tend to come down on the more technological side of this argument, which is why I’m so keen to see privacy as part of customer propositions and privacy-enhancing technologies as part of the systems being built in both public and private sectors.

Regulation isn’t a bad thing

Greyscale backing image
[Dave Birch] One of the areas of great interest for this blog is the evolution of “alternative” payments in different environments. As a consequence, I am always very interested to see how alternative payment system differ between markets. For example, the Russian market for alternative payments is very different from the European market. This year, broadly speaking, it will break down into

  • About 14 billion Roubles spent via the leading e-wallet schemes Webmoney and Yandex.
  • About 9 billion Roubles spent via mobiles for digital content.
  • About 10 billion Roubles spent via the near-ubiquitous “terminals”, the reverse ATMs that are on every street corner in Moscow (more on these below), some of which goes into loading e-wallets and mobile prepay accounts.

So a big chunk of the alternative payments market in Russia is taken up by a payment system that simply doesn’t exist in Europe (or, in fact, anywhere else so far as I can see), which is the near-ubiquitous “cash in” terminals or, as we tend to cal them, “reverse ATMs”.

In the last ten years, a rapidly growing shadow banking system has sprouted up in Russia to service these small payments by turning cash into electronic currency, or e-money. And now that this sector has reached the $1 billion mark – and this in a crisis – and has expanded to include 10 million customers, e-money business owners are getting antsy about government regulation.

[From Crashing Russia’s all-cash culture – Fortune Brainstorm Tech]

Estimates vary, but there are somewhere in the region of 400,000 of these terminals in use right now. On literally every street corner is a terminal that Russians feed with banknotes to top up their mobile phone, pay utility bills, obtain pre-paid virtual credit cards (I did this: you feed the cash in and the Visa card number, expiration date and CVV are sent by text to your mobile phone). You can see from this screenshot the wide range of services available:

Cash-in Terminal

It seems like a bizarre market arrangement, one that the laws of economics should mitigate against. As Evgeniya Zavalishina, the General Manager of Yandex Money put it rather neatly, people are taking money out of an iron box, walking a metre and then putting the money back in another iron box. Incidentally, Evgeniya will be joining an excellent line-up of speakers at the Electronic Money Association’s 3rd annual conference in London on 24th November so if you are interested in learning more about the evolution of e-money regulation around the word, head on over to the EMA web site and sign up. But back to the iron boxes. By astonishing coincidence, the restaurant where I went to dinner with Evgeniya and other members of the Russian E-Money Association (set up by a good friend of the Digital Money Forum, Victor Dostov) had precisely such an arrangement!

Iron Boxes

How can this be economic? Surely you would expect banks to incentivise the terminals to take chip cards so that people could pay their bills with a debit card. Come to that, why can’t they do that from a bank ATM in the first place instead of going to a terminal at all?

Well, one reason might be a lack of regulation. At the excellent Russian E-Money conference I attended, one of the speakers placed Russian banks as the 53rd most efficient in the world, but the Russian non-banks as the 4th most efficient in the world (for payment services). Yet both the banks and the non-banks would benefit from a better regulatory infrastructure. The problem that was discussed at the event was that everyone knows that regulation needs to come, but no-one is sure what that regulation might look like (and some of it, such as impending regulation on data protection) simply won’t work technologically. Nevertheless, a good infrastructure for electronic payments would, I’m convinced, help both the alternative payment providers (ie, the terminal networks) to invest further and develop new services while at the same time enable banks to invest in their own terminal and enhanced ATM services. Everyone would benefit.

This reinforces something that has been said before on this blog: no regulation is not a way forward. We want to see digital money deliver real solutions to real problems all around the world and a good regulatory framework helps in this enterprise.

Thanks, thank you all

Greyscale backing image
[Dave Birch] This blog has been nominated for the Computer Weekly Blog Awards for 2009.

Now, merely being nominated is reward and testament enough, but should you feel moved to voice your support in the traditional way, then please feel free to vote early and vote often.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.