4D Secure

Greyscale backing image
[Dave Birch] One of the things that I thought might happen this year is that the US government standard for ID cards might begin to spread into the commercial sector, simply because of the impact of standardisation. I wasn’t the only person who thought this, by the way.

In 2009, common access card programs will get another chance to conquer the enterprise market due to the government’s drive to implement PIV cards for all employees and contractors, the availability of standards and compatible products, the spread of standards beyond the federal government to state and local entities as well as government-linked enterprises. Most importantly, security convergence will finally receive market traction.

[From ContactlessNews | Look for renewed interest in enterprise common access card programs in 2009]

I should say that I thought this was a good thing. The PIV might not be an exact match with some corporate requirements, but on the other hand a standard means lower costs and an emerging ecosystem. So, if we want to improve corporate security, do we start designing our own, optimal solution, or go with the grain of what’s out there on the basis that it’s much, much better than nothing?

What identity is important?

Greyscale backing image
[Dave Birch] A couple of days ago I was in a discussion concerning the discrepancy between what enlightened experts (eg, me) think about identity management and what governments, civil servants and IT vendors think about identity management. One of the points I made, which I think I can defend, is that the “common sense” notion of identity, rooted in our pre-industrial social structures and pre-human cortex, is not only not very good at dealing with the properties and implications of identity in an online world but positively misleading when applied to system and service design. The fact is that virtual identity and “physical” identity are not the same thing, and they differ in ways that we are only beginning to take on board. Here’s an interesting reflection on the difference between physical and virtual identity.

I used to work on campus 5 days a week, but working at home more has coincided with the advent of blogs and twitter. My professional and personal profile on campus is now much higher than it was when I attended every day, but largely sat in my office, and occasionally ventured out for coffee.

[From Establishing Our Online Identity « Ramblings of a Remote Worker]

Interesting. An online identity in a context that makes it worth more than an offline identity, because it is more connected. The Facebook economy, so to speak. Which leads me on to…

What’s in a name?

Greyscale backing image
[Dave Birch] I got caught out in a meeting referring to the APACS Card Payment Group, which of course no longer exists. I thought I’d render a quick public service to help other people to avoid similar mistakes. Here’s your handy cut-out-and-keep guide to the UK’s new payment organisation landscape.

The Payments Council was created in March 2007 to set out the national strategy for UK payments. It has a Payments Council Board made up of banking representatives, some independent directors and an independent chairman (Brian Pomeroy). The principal UK payment schemes (listed below) have a contract with the Payments Council to set out rights and duties.

The UK Cards Association is the successor the much-loved APACS Card Payments Group (CPG). It is the trade body for the UK cards industry. Its 14 members, the major card issuers and acquirers, work together here on non-competitive issues.

Financial Fraud Action UK was created earlier this year to work alongside the UK Cards Association on the specific issue of reducing fraud.

The Dedicated Cheque and Plastic Crime Unit (DCPCU) is a specialist law enforcement unit made up from officers from the City of London Police and the Metropolitan Police and funded by the banking industry. It investigates serious and organised cheque and card fraud.

SWIFT (UK) Limited is the membership organisation representing the UK’s SWIFT users.

Good morning, thing

Greyscale backing image
[Dave Birch] OK, so I know it sounds spooky and people are uncomfortable with RIFD-at-a-distance, but there would be some advantages to being “recognised” by machines. Think about the subject from a customer service perspective rather than a security, spying and generally creepy perspective. As, in fact, some people already have been.

The Financial Services Technology Consortium (FSTC) today announced the launch of a project whose goal is to help member banks adopt radio frequency identification technology (RFID).

[From FSTC | Financial Services Technology Consortium – Press & Articles]

Why would banks want to do that? Well, it is relatively easy to implement vicinity (let’s say up to a couple of metres) read-only functionality along side the proximity (let’s say up to a couple of centimetres) read-write functionality used in contactless identity cards, bank cards and NFC phones. The chip sets are readily available. Handled correctly, this is something that a great many customers would appreciate.

Imagine a world where, when you walk into your bank, messages and adverts pop up that address you by name.

[From What high street banking will look like in 2020]

While The Times might see this as something for 2020, more technologically advanced nations are already experimenting with the technology,

Now “Yes Bank” which is a commercial bank operating out of India has been piloting an RFID system so that bank employees can identify these rich fat customers and offer them personalized services. Under the pilot RFID banking cards have been offered to select customers apart from deployment of RFID interrogators and customized gate antennas at bank premises… The moment the elite customer arrives in the bank his details are flashed on the system which enables the relationship team to identify the concerned person so that they can accord him services in the best possible manner.

[From The RFID Weblog: RFID being used to give preferential treatment to rich clients in Indian banks]

I can readily imagine using a Tesco Clubcard with this technology, or a BA Executive Club card or a transit card. As a consumers, I want to get better service where possible and the idea that everything from shopping cards to airport display boards might know who I am and deliver personalised service because of that is rather appealing. At least, it’s rather appealing provided that my identity is managed properly and my privacy is assured. This could be done at a physical level: you might, for example, have a Clubcard that only functions when you press a button on it.

This system creates a tiny, ultra-thin, pressure sensitive switch “which ensures that the device can only be read when the owner is pressing the switch”, said Peratech.

[From British firm develops RFID security technology to prevent ‘skimming’ | 20 Aug 2008 | ComputerWeekly.com]

Well, I can see how that might work for a card, although it seems a bit of a hassle in practice. But what about other form factors, particularly form factors that might make it difficult for someone to physically reach the switch. For example:

In times where a lot of hue and cry is being raised over injecting humans with RFID tags here is a video of a guy who seems pretty cool about injecting RFID chip in his hand

[From The RFID Weblog: The Do It yourself Guide to implanting RFID Chip in your hand]

Connecting things up is easy, but disconnecting them is hard! The solution, surely, is not down at the physical layer but in the logical layer above it. Extending the future digital identity management infrastructure to the Internet of things has to be the way forward and if properly designed such an infrastructure could deliver more, I think, thank many people imagine. In particular, such an infrastructure could protect privacy through the judicious use of cryptography rather than through codes of practice or goodwill.

The right to moan

Greyscale backing image
[Dave Birch] I’ve been following a few discussions about online anonymity, triggered by a couple of stories about bloggers identities being disclosed for one reason or another. One of them was the ridiculous story about an outraged model.

Of course, pretty much no one would have seen such a blog if Cohen hadn’t gone legal about it, claiming (with no proof) that she was losing jobs because of it (which seems difficult to believe).

[From Outed Blogger Plans To Sue Google; Skank Model Mess Gets Messier | Techdirt]

This what they call on the interweb the “Streisand effect“, but of course in these knowing post-modern times it could all be a clever publicity stunt and the model is not being stupid by cynically wasting taxpayers money to attract attention. Anyway, the point is that this story got yet another discussion about internet anonymity going. The general tone of the discussions in the media appears to be the usual unthinking “if you’ve got nothing to hide…”.

I take a different view. Most people do not have anonymity, it’s a myth. If I log on to The Guardian’s “Comment is Free” and post something about the destruction of the public finances under the name “General Wolfe of Quebec”, I am not really acting anonymously because it is trivial (as the recent headline stories have proved) to determine the IP address that the post came from and then go to the ISP to get the account. So although the Internet seems anonymous to people who don’t understand it (eg, models, politicians), it isn’t. And it’s not obvious whether that is good or bad. If you’re trying to track down someone posting child pornography (the usual short-circuit for the argument) then it’s bad, but if you’re trying to complain about the treatment of political prisoners in your country, then it’s good. And what’s more, whether your blogging is anonymous or not depends on the technology, not on the constitution or the judiciary.

As Ben Laurie has so clearly pointed out, unless the connection layer is anonymous, nothing else matters.

[From Digital Identity Forum: Internet]

I think that at a minimum bloggers should have conditional anonymity: that is, they should be able to use a pseudonym that is only connected to them on the production of a court order. This cannot be achieved by depending on the service providers: even if they operate with good will,

Computer scientists have recently undermined our faith in the privacy-protecting power of anonymization, the name for techniques for protecting the privacy of individuals in large databases by deleting information like names and social security numbers. These scientists have demonstrated they can often ‘reidentify’ or ‘deanonymize’ individuals hidden in anonymized data with astonishing ease.

[From SSRN-Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization by Paul Ohm]

What this, I think, implies is that there will be blogging platforms that spring up in the US to operate under the provisions of protected free speech legislation and beyond the vagaries of UK libel laws and, over time, the most interesting and valuable blogs will migrate in that direction. Those platforms will provide authenticated pseudonymous identities (using, as I repeatedly wish for, 2FA OpenID or something similar) that are contingent on cryptography. How is the nurse going to blow the whistle on a drunk surgeon without pseudonymity?

No-one should think this stuff is easy

Greyscale backing image
[Dave Birch] I’ve repeatedly said that I want the laws of mathematics and physics to protect my personal data, not to rely on the laws of the UK (or anywhere else). This is for two reasons. For one thing, I’m not confident that the people making the laws know what they’re doing (they tend to be lawyers and politicians rather than engineers or scientists). For another thing, there’s no reason to expect that the cold, hard distinction between 1s and 0s that builds the virtual world is suitable to manage the ambiguities of the legal world. Thus, even if a law is set out correctly, that doesn’t mean that it will never be replaced or altered in a perverse way. The oldest law still on the books in our United Kingdom is the Distress Act of 1267 (which outlawed private feuds, forcing people to go to court for redress in civil disputes) but not many laws have made it through eight centuries. Things change. But even if the law is right and on the books, that doesn’t mean it will be interpreted as intended. At the eema European eIdentity conference, I noticed that the Chief Privacy Officer for the Department of Homeland Security referred to the US Privacy Act of 1974 as one of the inputs to their policy. But,

The Privacy Act of 1974—the law designed to protect your rights as the government collects, uses, and shares your data—fails to consistently protect of citizens’ privacy because circuit courts disagree on how to interpret its language.

[From PolicyBeta – Blog Archive – A Remedy for Every Wrong? Why We Need a Consistent Privacy Act]

This illustrates my point. My personal data should be protected by cryptography, not by the vagaries of judicial interpretation.

SEPAaratists

Greyscale backing image
[Dave Birch] At a SEPA seminar I went to — at which, as an aside, the delegates agreed overwhelmingly with the statement that “bank payment products are inadequate for the Internet and mobile world” — we were given a curious pamphlet from the European Payments Council (EPC) called “The most popular misunderstandings about SEPA clarified”. One of the statements was “SEPA is a demand-driven initiative” (which, of course, it isn’t). The clarification from the EPC says “European integration is rarely carried forward on a wave of popular support” (I’ll say!) and goes on to say that monetary union did not materialise by distributing euro banknotes and coins and hoping that national currencies would be enthusiastically abandoned. Indeed. But that’s not say that that idea was wrong: on the contrary, national currencies would have been forced to keep their value up relative to the euro or begin losing seigniorage (and influence). That was one of the points in favour of dear old John Major’s plan for the hard e-euro.

Bring it on

Greyscale backing image
[Dave Birch] As has been mentioned once or twice, the world of social networking provides a specific and immediate kind of weapons range for testing new ideas about identity and privacy. Facebook, in particular, seems to developing an emergent properties space where all sorts of experiments are already under way with the identity concepts at their core already one step removed from the common sense” view of identity . There is one class of experiment that I find particularly fascinating, and these are about matching and comparing the “grown ups” perspective against the “kids” perspective. US examples are always more acute because they involve law suits, so let’s start there. Here’s a fabulous example.

a suit was filed in Mississippi that alleges a school official—more specifically a teacher acting in her capacity as a cheerleading coach—demanded that members of her squad hand over their Facebook login information. According to the suit, the teacher used it to access a student’s account, which included a heated discussion of some of the cheerleading squad’s internal politics. That information was then shared widely among school administrators, which resulted in the student receiving various sanctions.

[From Cheerleader sues school, coach after illicit Facebook log-in – Ars Technica]

This follows on from other recent stories about employers demanding log in passwords for social networks and so forth. If my employer wanted my LinkedIn password, I would regard it is transparent evidence of their insanity and a clear flag that our working relationship had collapsed. But if you’re a kid and it’s a teacher asking, I suppose you might feel under pressure to comply with something that’s obviously a breach of natural justice. Not surprising, in many ways, because it’s always difficult for social mores to adjust to new technologies — people used to be given instructions for answering the telephone — and this stuff is still really, really new. People don’t yet have sense of what is naturally right or wrong in the new environment.

So, people in authority behave inappropriately when faced with new technology. No big surprise. But what I found fascinating about this story — and the lesson it contains about emerging “norms” around identity in a digital age — was the reaction of some other kids faced with the same demand.

…several other students asked for their logins simply deleted their accounts using their cell phones, preventing this sort of intrusion; the schools apparently have a filter that blocks access to its Web interface from school computers.

[From Cheerleader sues school, coach after illicit Facebook log-in – Ars Technica]

In a way, I find this heartwarming. The kids aren’t stupid: they live in that world and they can distinguish their multiple virtual identities. Faced with a privacy violation that undermines a virtual identity, they slash and burn. And the school’s efforts to prevent them manipulating their virtual identities are fruitless.

Doctoring the evidence

Greyscale backing image
[Dave Birch] Health care is a very difficult environment to deal with, and no-one can underestimate the complexity and tensions in the space. I want my health details to remain absolutely private, but if I get run over by a bus then I want the doctor in casualty to have access to everything, instantly. There are basically two ways of doing this: storing my medical details with my doctor and letting other doctors access them, or taking my details and putting them in a big database for other doctors to access. In the UK, the government has naturally opted for the big database model. But as with big database models for everything else (eg, the Children’s Index) that means that privacy is hard to preserve because things will always go wrong.

Dr Paul Golik, secretary of North Staffordshire LMC and a GP in Norton-in-the-Moors, Stoke on Trent… accessed the personal details of a number of other patients registered elsewhere, including, with their consent, staff at his practice – all without being detected… ‘It’s basically open – we might as well put our names and addresses on Google,’

[From Pulse – GPs’ fears over new IT security loophole]

This is apparently the Conservative Party’s plan anyway.

Health records could be transferred to Google or Microsoft under a Tory government.

[From Google or Microsoft could hold NHS patient records say Tories – Times Online]

Why do health records have to be transferred anywhere? Everyone has to be registered with a GP, so let the GPs choose whichever service providers they want to store the data provided they comply with certain interface requirements. Then when I go to GP B while on holiday, he can put his smart card in his laptop and look up my health details at GP A (it would be easy to do: just make nhsnumber@gpa.nhs.co.uk autorespond with my health record in XML encyrpted using the public key of the requesting doctor). Of course, there might still be ways for it to go wrong, provided people are involved somewhere. Even the Germans are having problems securing national health data, although in their cases they’ve buggered it up in a “fail safe” way and lost the keys so that no-one can read the data, rather the having everyone read the data which I suppose if you’re going to make an error is the better way to do it.

Test runs with Germany’s first-generation electronic health cards and doctors’ “health professional cards” have suffered a serious setback. After the failure of a hardware security module (HSM) holding the private keys for the root Certificate Authority (root CA) for the first-generation cards, it emerged that the data had not been backed up.

[From Loss of data has serious consequences for German electronic health card – News – The H Security: News and features]

Oops.

Isn’t this stuff serious?

Greyscale backing image
[Dave Birch] OK, so I’m in a tiny minority but I think that security and privacy are important. I think that the state of security and privacy in the digital world demand a proper strategy, of which some form of digital identity infrastructure is a critical part. That’s why I’m always glad to see the government appointing people to tackle the difficult issues around the technology infrastructure that our future depends on. When I was googling something else, I discovered that Paul Murphy is Britain’s “Minister for Digital Inclusion”. This is a real post, not something I made up for the blog. In addition to pottering about at UK online centres (of which there are 6,000 in the U.K.!) his brief includes “data security and information assurance”. Imagine my surprise, then, when I read that:

Paul Murphy states that he is “not a technical person”.

[From Minister for Digital Inclusion gets Strategic – Convergence Conversation]

Shouldn’t we get someone who is?

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.