Paradigms and pseudonyms

Greyscale backing image
[Dave Birch] I enjoyed listening to Roger Clarke at the 2nd interdisciplinary workshop on Identity in the Information Society at the LSE because I had read his work (particularly on PKI) over many years and wanted to see how his thinking had evolved. Roger made a number of excellent points, one of them being that the barriers that we need to overcome (if we are going to do anything practical about identity management) is that the models that we technologists are using, the implicit mental models of the decision-markers and the reality of the situation are all different (I’m paraphrasing greatly, obviously). Having had the chance to think about this some more, I think that I agree with his diagnosis but disagree with the treatment.

So far as the treatment goes, Roger proposed a way to deal with this some time ago and explained this in his presentation. His model is to have get around the problem of the mappings — that is, the mappings between real and virtual entities and their attributes — by separating out elements of the mapping, distinguishing between identity and entity, between identification and entification.

If I’ve understood what Roger meant, then I think I don’t quite agree with him, because I think replacing the N:N mappings between real and virtual identities by 1:N mappings to digital identities is a simpler way to model the complexity of the boundary between real and virtual in the identity space. So I don’t think about identity and entity but about the real and digital identities and stuff, and some of that stuff happens to be people, if you see what I mean.

Touch and gone

Greyscale backing image
[Dave Birch] I ran a workshop on mobile proximity security day, and one of the things we touched on in the group is the EU’s publication of their recommendations on the “identity of stuff” last week. They’ve published a 14-point action plan.

The European Commission has announced plans for Europe to play a leading part in developing and managing interconnected networks formed from everyday objects with radio frequency identity (RFID) tags embedded in them – the so-called “internet of things”.

[From EU lays out plans for the “internet of things” – V3.co.uk – formerly vnunet.com]

These are real issues, and although I’m not making any comment on the value or otherwise of the specific recommendations, there’s no doubt that the subject deserves more attention. There’s an “identity of things” problem that came up (again) in a meeting I was in last week that I think is worth sharing. It comes from the world of NFC, where the problem revolves around contactless stickers, tags, posters and that kind of thing. It’s the same problem that we looked at before, and it’s worth reviewing because there’s been no industry progress toward a solution.

A little background. The NFC Forum have announced their “N mark” which is a standard symbol to be applied to adverts, magazines, posters and such like. The idea is to show consumers (none of whom have ever even heard of NFC, let alone seen an NFC phone) where they can “tap” their phones to get some kind of service.

The NFC Forum has developed the “N-Mark” trademark so that consumers can easily identify where their NFC-enabled devices can be used. It is a stylized “N” and indicates the spot where an NFC-enabled device can read an NFC tag to establish the connection.

[From NFC Forum : N-Mark]

If you haven’t seen it, it looks like this. A simple ecosystem in the offing: you put the N-mark on things, consumers come along and touch them with other things.

Data shrinkage

Greyscale backing image
[Dave Birch] There are a flurry of stories about the British government abandoning the ID card scheme, a course of action to my mind as bad as continuing with it. What we need is a better ID cards scheme, not no ID card scheme. But who knows what might happen now that there is a new Home Secretary, but earlier in the year the Home Office made some more announcements about the introduction of ID cards in the UK. As I’ve mentioned, they’re going to start in Manchester. I was more interested in what the Home Office said about enrollment though, because as we all know this is the critical phase of an ID project from the point of view of security. A number of people expressed concern that the government was going to use high street retailers for the enrollment process, to save the cost of building specialist enrollment stations in suitable premises in major population centres in the UK (otherwise known as Post Offices). One area of concern is security, but here the retailers were quick to reassure:

High Street retailers have rejected security fears about giving them the job of fingerprinting and photographing people applying for identity cards… Trade bodies representing chains such as Boots and Snappy Snaps told the BBC they can be trusted with the data.

[From BBC NEWS | Politics | Retailers reject ID security fear]

Now, I don’t want to be the one in the glass house throwing stones, because I don’t doubt that I’ve left the odd memory stick around here and there, but I was sure I could remember seeing Boots’ name last year in connection with looking after personal data. A quick bit of web browsing and my imperfect memory was rendered perfect by the World Brain (aka Google):

Major U.K. chemist (drug store) chain Boots has joined the growing list of organizations suffering an embarrassing storage snafu after tapes containing personal details of thousands of customers and employees were stolen… The records reportedly include the bank details of 27,000 customers of Boots’ dental service, which is operated by Medisure, as well as the personal details of some 8,000 Boots employees.

[From Tape Loss Stuns UK Retail Giant – Data Security News Analysis – Byte and Switch]

Whoops! Still, it’s not like the tapes had fingerprints on them or anything like that. Hold on a second: tapes? I thought it was puzzling that in the age of SSL and the interweb, HMRC were still posting unencrypted CDs full of personal data around the place. But tapes?

Help! I can’t stop posting about SEPA

Greyscale backing image
[Dave Birch] I saw a very good talk by Gerard Hartsink, Chairman of the European Payments Council. He was talking about SEPA and the evolution of the European payments sector. The context isn’t important, but I did want to highlight one comment he made — which caused some passionate discussion — about the future of payment cards. He said that he could see a situation in 2011 or 2012 when magnetic stripe transactions would be banned in SEPA and only chip transactions would be allowed at ATM and POS. Now, before we launch into a debate on this, let me point out that he is not the only person of influence who is thinking this way.

Tony Chew, head of the technology risk supervision division of the Monetary Authority of Singapore, is advocating for a concerted global effort to phase out magnetic stripe technology entirely. “We can all go chip and PIN which will be a more effective method of combating counterfeit card fraud,” says Chew.

[From Vendor Articles: 12/6/2009 Credit card fraud rising]

It’s the rise in fraud that is causing this kind of thinking. Far from shrinking card fraud, the introduction of chip & PIN in the UK has multiplied a thousandfold the number of places where people use PINs and therefore where PINs can be stolen from. So long as there are places where easy-to-copy magnetic stripes can be used, the incentive for criminals is clear. Things are getting worse.

It is my belief – and feel free to come back and tell me that it’s me that is the idiot – that after a number of years of declining card present fraud (magnetic stripe cloning is so much easier, and a gift from the card issuers), we are now going to see a dramatic increase, and there is nothing we can do about it!

[From 2009 – is that the year we all went online?]

I happened to be reading this month’s Fraud Watch, and one of the front page stories is “ATM fraud threatens global acceptance”. The story says that “several issuers are considering blocking major cities and possibly whole countries where international card fraud is high, because there is no chance for reimbursement for those losses even though the original cards are EMV chip and PIN compliant”. (There are, as I understand, no plans for a liability shift to rectify this, particularly in the USA.) Oh dear. Incidentally, the top three destinations for ATM fraud on UK-issued cards last month were…. 1. Canada, 2. Italy and 3. the USA.

Suppose Gerrard is right? What will happen in 2012 when travellers from the USA arrive in Paris and discover the shops, hotels and ticket machines won’t accept their cards any more?

The Guildford triangle

Greyscale backing image
[Dave Birch] What is it with Britain? Digital or otherwise our degraded realm is an international identity scandal. Europe’s no.1 exporters of payment card fraud, we are apparently now the world’s worst for identity theft overall.

INTERNET users in Britain are more likely to fall victim to identity theft than their peers elsewhere in Europe and North America. In a recent survey of 6,000 online shoppers in six countries by PayPal and Ipsos Research, 14% of respondents in Britain said that they have had their identities stolen online, compared with only 3% in Germany.

[From Where your identity is more likely to be stolen | Online fraud | The Economist]

There may be a correlation here between “identity theft” and “card-not-present fraud” (Germans rarely use credit cards, least of all on the interweb), but we’ll return to that in a future discussion. Now, these statistics don’t, I think, mean the Brits are more criminally inclined. After all, fraud is an international business.

The criminals stored much of their data on computer servers in Latvia and Ukraine, and purchased blank debit and credit cards from confederates in China, which they imprinted with some of the stolen numbers for use in cash machines, investigators say.

[From Global Trail of an Online Crime Ring – NYTimes.com]

It’s more likely that Britain is a soft touch: high card penetration and use, lots of internet shopping and other factors that lead to identity theft on an industrial scale. But where does this tidal wave of fraud actually originate? I read in The Telegraph that the top 10 identity theft hotspots in the UK are all in south east England. There’s an area of white collar fraud between London, Reading and that well-known criminal outpost, Guildford. Odd. In the top 10, only St. Albans falls outside of this theft triangle. Yet the government is going to test ID cards in Manchester… Well, as well all know, ID cards won’t have the slightest impact on identity theft for at least the next decade.

ID cards have been touted as the solution to a number of real problems – terrorism, crime and so on – though none of their supporters can ever explain how having an ID card stops a mugger or suicide bomber. But they began as the answer to a classic fake problem, still routinely cited by ministers, the need to “secure our identities” against “identity theft”.

[From The ID card is on its last legs – just let it die with dignity | News]

Now, I wouldn’t call identity theft a “fake problem”. On the contrary, it’s a very real problem. But what is generally meant by identity theft, certainly in the Guildford triangle, is largely to do with payment card fraud (which is rampant in the UK) and account takeover. These are specific problems, not general identity problems. Until retailers demand that you present an ID card when you buy anything, or somehow allow them to read your identity card over the interweb, nothing much will change. Fortunately, someone is thinking this through: the UK ID card scheme may well use chip and PIN technology so that it can be accepted at retail POS. Lots of newspapers reported this, so I’ll choose to point to the report in that august journal of record from my home town, Swindon (or, “Swindon, city of the future”, as have generally called since 4th July 1995):

ID cards could be fitted with chip and pin technology to help combat identity fraud. The head of the Government agency tasked with producing the cards said there were no “technical obstacles” to adding chips to the cards and handing out pin numbers.

[From ID cards ‘could use chip and pin’ (From Swindon Advertiser)]

I rather imagined that the cards already had chips on them, but putting that to one side, the idea of making ID cards work in chip and PIN terminals isn’t totally infeasible, although I’m not completely clear as why you would want to do this. I suppose the thinking is that the shops already have the terminals. But if you are asked to put your ID card into a terminal and punch in your PIN, wouldn’t you then get annoyed at having to take it back out again, then put your chip and PIN card in and then punch in another PIN? Why not just link your bank account to your ID card?

Hello? Who’s that? Oh wait, let me google you

Greyscale backing image
[Dave Birch] Central to the direction of digital identity is the issue of the connection between real and virtual identities. How is that connection formed, who controls it, who should have access to it, that kind of thing. Now, you can see that one way to make this connection is to demand a one-to-one “hard” correspondence between the physical identity and the virtual identity, constraining the digital identity completely. To do this you would need to register anyone obtaining any kind of virtual identity. I don’t just mean on the web. A mobile phone number is a virtual identity. Oh wait…

Everyone who buys a mobile telephone will be forced to register their identity on a national database under government plans to extend massively the powers of state surveillance.

[From Passports will be needed to buy mobile phones – Times Online]

This is hardly an original idea. It’s already the case in many countries that law-abiding citizens have to provide identity documentation in order to obtain a mobile phone. Ah, you might say, that’s not going to help catch criminals — which I’m sure isn’t true, as such an initiative must necessarily catch some stupid criminals — because the criminals will just carry on using pre-paid SIMs that have not been registered. Well, yes, but surely if a government makes a law that SIMs must be registered, then it will naturally get the operators to block all of the SIMs that haven’t been registered, as they are in the process of doing in Botswana.

The process of registering all prepaid Subscriber Identity Module (SIM) cards in the country will start in September, says the Chief Executive of Botswana Telecommunications Authority (BTA), Mr Thari Pheko. Speaking at a press conference in Gaborone this week… Mr Pheko said the registration process was expected to take 17 months and will be completed on the last day of 2009, adding that unregistered cards will be taken off-air in the beginning of 2010.

[From BOPA Daily News Archive]

Something similar is underway a little closer to home, in Spain.

From November 9, 2007, people who purchased pre-paid mobile phones have been obliged to provide proof of identity, but for those who purchased phones before this date, a two-year period of grace was granted which runs out on November 9, 2009. It is estimated that more than 15 million pay-as-you-go phones are still unregistered in Spain.

[From Costa News – Mobile phone cut-off]

If there is going to be a government database of all mobile phone numbers against registered names, then surely the only way to manage the new identity world that it creates is to just put it on the web and let new businesses spring up to use it. It’s the same principal as with initiatives around health and all sorts of other personal data. If people believe that their connection to their mobile phone number is “secure” but it isn’t, then the outcomes will be perverse. The bad guys will have access to the data and the good guys won’t. Since there is no more possibility of keeping this database secure than keeping, for sake of emotive comparison, the Children’s Index secure, isn’t it better to make it available for mash-up? And, by the way, I didn’t choose this emotive example at random…

Security flaws have halted work on the internet database designed to hold the details of 11 million children and teenagers. The Department for Children, Schools and Families (DCSF) admitted last night that it had uncovered problems in the system for shielding details of an estimated 55,000 vulnerable children.

[From Security flaws halt work on ContactPoint child database – Times Online]

If you can’t keep a government database like this secure, what chance is there of keeping a government database of mobile phone IDs secure?

I hope regulators get real

Greyscale backing image
[Dave Birch] Competition is a good thing. Competition in financial services is a good. If society wants a better payments system (which it should, for many reasons) then the way to get it is by creating a regulatory infrastructure that fosters, encourages and perhaps even demands competition in the provision of payment services. This is why the Payment Services Directive (PSD) has a chance of making life better for European consumers. Should that competitive environment embrace banks and non-banks? Yes, it should. If banks and non-banks are to make progress together, then it is not clear that simply leaving them to get on with it is good enough. For one thing, banks in many countries don’t really want to compete, so if there is no explicit regulation to create a competitive landscape then there is a temptation to fall back on the old kind of competition in banking, which means competing and the regulatory level. This is the kind of situation that we see in Africa. Nigeria is a case in point.

Indications have emerged that Nigerian banks have moved against the quest of MTN Nigeria and Zain to obtain M-Banking license operations from the Central Bank of Nigeria (CBN). The regulatory body has only issued one mobile banking operating license to MoneyBoxAfrica to deplore branchless banking services across the country… the refusal of the apex bank to grant the [m-banking] license is as a result of Nigerian banks antagonistic to the idea.

[From ftr-africa.com – Financial Technology Report, Africa]

In Kenya, where the M-PESA mobile payment scheme is massive, the regulator had wisely decided to allow Safaricom to go ahead and launch that service despite bank pressure. The result has been a fantastically successful scheme that has transformed for the better the lives of million of Kenyans. But someone told me that the Kenyan regulator has now decided to revisit the situation and perhaps “tighten up” rules, inspired no doubt by the banks’ genuine concerns for customer protection and the soundness of the in-country remittance market. Incidentally, you may not be aware that M-PESA has been launched in other countries. Afghanistan, for example.

Take Afghan GSM operator Roshan; they recently licensed Safaricom’s hugely successful M-PESA system, and one of the first applications for it is paying the Afghan army.

[From Telco 2.0: March 2009 Archives]

When the alternative is transporting tons of cash through some of the most dangerous highways and byways in the world, the mobile phone offers a millionfold improvement whatever the regulators’ concerns might be. Mobile money is unstoppable.

Balancing act

Greyscale backing image
[Dave Birch] There was a great kick-off talk from Blums Pineda at the Mobile FInancial Services conference in Singapore. Now with Exicon, he was previously with Globe Telecom, home of GCash. Blums chose to focus on the balance between consumer protection and business opportunity, building on his experiences with G-Cash. He was essentially optimistic that regulators are embracing new models. As he pointed out, it’s the transaction space that is driving growth in the financial services market. In the mobile transaction space, we need regulatory certainty to encourage investment and no regulation at all is not the right kind of certainty. In the Philippines, the regulators did not over-react and use inappropriate banking regulation to constrain the evolution of payments business.

There are good reasons, as we have discussed before, why we actively want regulators in the m-payment space. That’s because while no regulation at all might minimise compliance costs for the provider, it does not minimise costs for society as a whole: consumers carry on using more inefficient forms of payment (cash, in the countries being discussed) because they have regulatory certainty. So there are great benefits to having regulation. Blums summarised these as benefits to consumers, providers and the common good. I thought he was dead right to include the common good as a separate and distinct beneficiary, serving to remind . Surprisingly, to some people, he said that one of the benefits of regulation was to encourage innovation.

The idea of regulators balancing prescriptive vs. principles-based

He gave a useful case study of the Philippine regulatory response to the development of G-Cash and Smart Money, showing how the regulators allowed the market to develop new solutions by working with the new entrants to find ways to make the regulations work. As an aside, later in the day a chap from Ernst & Young (who began by saying that, with admirable candour, that the “big four” have come “a little late” to m-payments) was drawing some lessons from the launch of Smart Money (in 2000), GCash (in 2004) and Citi (In 2008) in the Philippines. Smart Money has seven million registered users and 700K retailers, GCash two million registered users and over 600K retailers (and GCash customers have access to 6,000 ATMs) but these systems could be bigger still with bigger networks of agent, consumers and merchants. The barriers to entry are too high.

GCash need to make it easier for new members (consumers or merchants) to join system. But they also need to do something with the agent network. There is an onerous process for new agents to join the GCash network and since agents only get 1% commission for cash loads compared to 10% commission for airtime top-up, there’s not much of an incentive for them. These factors have limited the growth of the agent network which has, in turn, limited the growth of the scheme. As an aside, here’s a useful data point: Blums reckons that the shift to m-payments has eliminated nearly 80% of microfinance provider costs in the Philippines. Now, the environment there is most conducive to m-payment — 95% of Philippine towns have mobile coverage, only 60% have a bank branch. There are 10,000 ATMs but a million airtime resellers — but so the cost savings may be at high end of possibility, but the opportunity to significant cost reduction in many markets is clear.

Looking forward, he reiterated the growing need to regulate the agent networks in the m-payments space (Globe has something like 1,800 accredited partners for the GCash service), something that we have been thinking about with some of our customers and something that we will be sure to return to on the Digital Money Blog. Finally, he noted that a key element of the future platform is some form of mobile identity infrastructure. GCash has over-the-air registration, but if you use it at POS you have to present an ID card, which makes it less convenient than it might be. I couldn’t agree more, which is why I was so keen to have a mobile eID panel session at the recent Identity and Privacy Forum and I’ll be talking on this subject in Session C European eIdentity Management, the 22nd eema conference, on 25th June in London.

Give us the chance to do better

Greyscale backing image
[Dave Birch] One of the frustrating aspects of being a technologist in the identity space is that I know that the technology can deliver more than customers want. There are a number of reasons for this, but two of them will suffice to make a point. Firstly, people’s “common sense” version of identity is simply not sophisticated enough for a modern economy and, secondly, that the people who actually specify and procure systems that hinge on identity do not make privacy part of the proposition because they (incorrectly) view security and privacy as opposites. In fact, the technology can deliver both and some times it’s very easy to make it do just that. Look at the basic case study of “no fly” lists, where the problem is to check whether someone’s name appears on a list of people to be excluded…

In comparing the contents of two databases, such as an airline-passenger list and a no-fly list, for example, officials should be interested only in the names that appear on both lists. They have no need for the rest of the passengers’ names. Those mutual names can be found by first encrypting both lists using strong encryption.

[From Sharing information while preserving privacy is a technologically trivial challenge, researcher says — Government Computer News]

Quite. And if the lists are encrypted, and don’t need to be decrypted to make them work, then privacy is automatically improved without ombudsmen, best endeavours and the rest of it. A rudimentary understanding of the issues is all that is needed to deliver vastly better solutions.

The 50 year plan

Greyscale backing image
[Dave Birch] When I took one for the team and went to the SEPA session at the International Payments Summit. I did learn something new, which was that at the current rate of progress it will take about 50 years (the actual estimate was 47 years) to migrate European credit transfers to the SEPA Credit Transfer (SCT), which is not bad I suppose. After all, it takes time to develop and integrate new systems, and banks have other priorities. Neverthless, it is fair to observe that progress is slow.

What I was mainly interested in was the zeitgeist around the Payment Services Directive (PSD) rather than SEPA itself. That’s because it will have more of an impact on more of our customers. Selfish, I know. But the thinking is straightforward: for our financial sector customers in the payments business, the PSD introduces new consumer rights and so forth and this will cause them some hassle. One particular impact, which may well be under-emphasised in strategic evaluations of the PSD, is the panoply of new customer rights that come with the PSD. These include transparency. So (under articles 36 and 37) your card issuer has to tell you (when you’re buying a meal in a Greek restaurant) the maximum execution time for a payment, all charges payable and a breakdown of those charges and the actual (or reference) exchange rate. Gulp. That sounds like the Greek restaurant will have to give a British cardholder a couple of pages of A4 and make sure that the customers reads them before they punch in their PIN.

You’d think that a key impact of the PSD would be pan-European, but a couple of people I overheard were definitely sceptical. In fact, some people think it is likely to entrench national markets for the time being. I saw Bob Lyddon give a talk about this recently and he made the point that the combination of national “gold plating”, the mixed adoption of the rights of derogation and different interpretations of non-negotiable elements after national transcription (ie, the process of turning the directive into national law) means that there is a high likelihood of national markets becoming more different, not more similar. (And one country, Sweden, is opting out of it at the moment.) Thus, although a Payment Institution (PI) can theoretically passport, national differences mean that costs and complexity will not reduce for the time being.

Anyway, the point is that for banks, the PSD comes at an interesting time when transaction banking is becoming more central to strategy. The threats from both new entrants and substitutes are, according to Bob (and I agree with him), high. In these circumstances, regulation is turning from a moat that competitors cannot cross into a millstone around the incumbents necks.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.