Government interface

Greyscale backing image
[Dave Birch] For e-government to take off, it is transparently obvious that population scale identification and authentication infrastructure (beyond e-mail address and alphanumeric passwords) will have to be in place. If not, the pain associated with every single online interaction with the public sector will grow far beyond the point where the bulk of the population will want to get involved and there will be a hard limit on the efficiency of the delivery of public services. No-one, surely, can be against that. Yet we don’t seem to making much progress towards this. Even in cases (in the UK) where online service delivery works very well indeed (eg, vehicle tax), it does so in silos.

Now, many people will (quite rightly) point out that there is a fundamental danger to the idea of using a single identity across all services. There’s a particular danger to using to the same identity across public and private sector services.

In yet another security breach, the US State Department said 400 passport applicants, and maybe more, have had information stolen. Passport applications containing personal information, including Social Security numbers, were accessed and used to open fraudulent credit card accounts. A fraud ring bought information from a government employee. The information was used to apply for cards. Cards were intercepted by another insider in the post office before they were delivered. The passport applicants had no idea their identity had been stolen.

[From National ACH: Government Employees Selling Identities]

Now, that’s the kind of fraud that imagine was dismissed out of hand by the government’s management consultants when they were procuring the system. “Insiders in the Post Office connecting to insiders in the State Department? Oh, come on! That’s like a Tom Clancy novel, it will never happen.”

It this sort of thing — and it seems to happen all the time — that means that many people react against the very idea of a government identity or a government identity management system, although I draw a different conclusion: we need a better (privacy-enhancing) design for a government identity management system, perhaps building on the schemes used in countries such a Germany and Austria where identities are cyptographically-partitioned between service providers.

(Obviously, I trust the Government even less. I’d much rather have O2 manage my ID than the Home Secretary. SIMs are more secure, cheaper and better-managed than the UK’s ridiculous Stalinist ID card system).

[From Dean Bubley’s Disruptive Wireless: Thoughts on managed identity services by mobile operators]

What we want, surely, is the best of both worlds. I want my SIM to hold a number of identities, including government ones, that I can choose to use on a per-transaction basis. And I don’t think it’s far-fetched to expect this kind of modern infrastructure.

More anecdotes

Greyscale backing image
[Dave Birch] Erik van Winkel from our friends at Edgar Dunn as a nice piece in the current Journal of Payment Strategy and Systems (vol. 3, no. 2) looking at the potential for new entrants in the European payments sector in response to the arrival of the Payment Services Directive (PSD). At our seminar on this topic earlier in the year, I asked the panelists about the likely categories of new entrants, and we spent some time discussing whether telcos and retailers might be prime candidates. Erik sets out his own thoughtful classification of potential new entrants as follows:

  • International organisations already providing processing spaces for acquirers;
  • Large pan-European retailers who might immediately benefit from self-acquiring and synergies with loyalty and CRM schemes;
  • E-commerce businesses such as PayPal, Google and Amazon who might be able to offer European consumers some modern, customer-friendly options;
  • Mobile operators. Erik thinks that if banks and telcos cannot agree on common business models then telcos may well decide to launch their own initiatives. Some operators (eg, Vodafone) already have successful m-payment systems running outside Europe and may decide to try them out inside Europe given the right conditions.

An excellent analysis. I think Erik’s point about mobile operators is a particularly good one. We’ve been told over and over again that “mobile operators don’t want to be banks” and I’m sure they don’t. But a Payment Institution (PI) isn’t a bank. The point of setting up a PI is not to compete on banking services to run payment services more efficiently. Saying the mobile operators don’t want to be banks is one thing, saying that they don’t want to get into the payments business quite another.

The long and short of it

Greyscale backing image
[Dave Birch] I was at the European Patent Forum in Prague talking about biometrics in an enjoyable seminar on Privacy and Identity Theft, along with Ivo Teutloff from EPO and Max Snijder from the European Biometrics Group. The reason that the session was so enjoyable is that we’d each chosen to focus on different aspects of the topic. By coincidence, when I woke up and was sitting in my hotel room looking through my slides with BBC Breakfast TV in the background, the first item on the BBC news was the rise in card fraud, again. And this is in hand-in-hand with another massive increase in identity-related fraud in general.

A 40% increase in the number of people being impersonated indicates that the flat trend seen in 2008 (where identity fraud increased by only 0.06% from 2007) was exceptional. While last year’s figures were a surprise, the sudden and significant increase in the first quarter of 2009 heralds an unwelcome return of identity fraud as the fraudsters’ method of choice; as fraudsters assume creditworthy identities in order to swindle individuals and companies alike: stealing funds, goods and services at someone else’s expense… During this quarter, a staggering 75% increase in facility takeover (also known as account takeover) frauds – where the fraudster gains access to, and plunders the legitimately obtained accounts of innocent victims – continued the steep upward trend seen throughout 2008.

[From Fraud trends and recession go hand in hand – CIFAS Online]

If biometrics could make a dent in that, you would think that banks would be rushing to implement them. After all, as CIFAS notes, the account takeover fraud explosion has been going on for some time. Plenty of time to plan and develop a biometric countermeasure, you might think.

UK account takeover fraud grows 207% year-on-year in 2008 – study [From UK account takeover fraud grows 207% year-on-year in 2008 – study]

Yet nothing much is happening. Identity theft is growing and, in the UK at least, the government’s identity card scheme won’t do anything to help. But why? Max made a very interesting point, which goes back to my current obsession, the “narrative”. In his presentation, he pointed out that because the biometric sector had its origins in the identification problem, that is how they see the world. So they would see the retail payments problem as an identification problem, which leads to PayByTouch. On the other hand, other people (eg, me) see the retail payments problem as an authentication problem: so we need progress in what he called “anonymous” biometrics to get down to solving that particular problem. And he made a very positive suggestion that I had not considered before.

What’s the use case?

Greyscale backing image
[Dave Birch] Suppose you did have a virtual identity that did something for you that was so useful that would actually pay for it. What kind of thing should it do? At the Forum Oxford Future Technologies seminar I heard Mark Curtis of Flirtomatic say something along the lines of "we would happily use mobile operator age verification services if they worked". This struck me as a very simple, prosaic example. Just as in the physical world there are a couple of age verification schemes where teenagers can buy cards that show them to be over 18, perhaps the online equivalent would be the place to begin.

Now that people like Facebook are getting on board with OpenID, perhaps one idea might be to a create an OpenID source that supplies IDs with a single credential IS_OVER_18 and two-factor authentication. This would be, effectively, one of Bob's LLPs. Where would you use this? Well, one of the long standing mass market problem area is social networking. There have been attempt to deal with this piecemeal.

Mobile social networking service Funky Sexy Cool is offering identity verification to all its members at no additional cost, says Tim O’Connor, CEO of the New York-based company. But members have to choose to go through the process. Funky Sexy Cool enables members to find other like-minded individuals in the same geographic area to hang out with. For example, a member can send out a message to his friends saying he’ll be at a certain club or bar… Funky Sexy Cool is using ID verification technology from IDology Inc., Atlanta. IDology searches public databases to confirm an identity [and] charges about 37 cents per ID verification.

[From Social networking sites have little to no identity verification : CR80 News]

Now teenagers would, naturally, want to obtain the 2FA "device" of an older sibling or friend in order to gain access to sites, but it's not like using fake ID to buy a beer, because they'd end up logged in not as themselves but their sibling, friend etc which isn't much use in social networking.

Virtual identities and LLPs

Greyscale backing image
[Dave Birch] Over the Burton Group, Bob Blakely has been developing a line of thinking around a particular kind of virtual identity that he has called the Limited Liability Persona, or LLP and he recently posted some ideas for more specific characteristics of such a thing that I think deserve reflection. Bob's thinking is that since the invention of the limited liability company as a distinct legal entity the economy has grown and benefited, so there might be economic advantages to recognising some form of virtual identity as a distinct legal entity.

Well, since LLPs don't really exist yet, it's hard to be too specific. But in principle an LLP is a legal entity with a name:

  1. Created by an action of a court.
  2. Owned by one or more individuals.
  3. With its own resources distinct from those of its owners.
  4. In which owners can invest new resources.
  5. With its own "identity attributes" distinct from those of its owners.
  6. Whose actions are legally distinct from those of the owners (though the owners may be held accountable for those actions.
  7. Whose resources may be transferred to its owners.
  8. Which can be sold by the owners to new owners.
  9. Whose existence can be terminated by its owners.
[From Burton Group Identity Blog: The Limited Liability Persona]

This is very close to the idea of the virtual identity bound to a digital identity that we have discussed here before but with much firmer purpose. In Europe, as is many other jurisdictions, the relevant digital signature legislation already exists so that legally-binding digital signatures can be used and by inference legally-valid digital identities created. It's easy to see how Bob's ideas can be implemented except for the transfers part. If an LLP is a virtual identity that is, in essence, a public key certificate then it cannot be transferred. It must be deleted and a new virtual identity created: so let's say there is a virtual identity "Chair of Manchester City Fan Club" that it my public key signed by Manchester City Fan Club's private key. Then, when a new Chair is elected then my certificate has to be revoked and a new certificate created (ie, the new Chair's public key signed by Manchester City Fan Club's private key). So the particular attribute "Chair of Manchester City Fan Club" ends up bound to a new digital identity (key pair).

Risk and lack of reward

Greyscale backing image
[Dave Birch] One of our chaps was at a seminar concerning developing countries recently, and overheard an interesting conversation. Someone from the telecommunications world said that financial service regulators in developing countries were concerned mainly with risk, whereas telecommunications regulators were more concerned with competition. The effect of this is that mobile operators are raring to go with more services along the lines of G-Cash or M-PESA but they are being blocked by regulators who see payments as a financial service rather than as some kind of utility.

This is why I’m so worried that knee-jerk additional regulation of financial services in response to the current crisis will end up holding back the development of the payment sector, with really negative consequences in developing countries. A better payment system is an unalloyed good and it would be bad for lots of people if the evolution of new payment systems, especially in the developing world, were to be held back by inappropriate regulation. Payments are not banking, and while banking regulation may well need to be toughened up in many countries (as subject on which I am not qualified to comment), payment regulation may not.

Time for a National Privacy Card scheme

Greyscale backing image
[Dave Birch] There was a bit of media attention around the recent report on government databases from the Joseph Rowntree Foundation (the authors include Forum friends William Heath and Angela Sasse) but I’m not sure that the government was listening. The report was quite strong on the extent of the problem within government:

A quarter of all government databases are illegal and should be scrapped or redesigned, according to a report.

[From BBC NEWS | UK | Call to scrap ‘illegal databases’]

The way to protect personal data most effectively, particularly in large organisations such as the government, is not to store it in the first place. This may seem unworldly. After all, I want Tesco to provide me with a good service, so why shouldn’t I give up some of my personal data in order to get it? Setting aside the issue of whether what I bought in Tesco yesterday is “my” data or not, I am perfectly happy to have, and wield, my Tesco Clubcard. After all, it’s not in my real name and Tesco never ask me for data I don’t want to give them, so I’m more than happy for them to record what I buy. And, to their credit, I can say with hand on heart that I have never once received junk mail, spam or unsolicited phone calls for the imaginary alter-ego who shares my home, from which I deduce that Tesco have kept to their side of the bargain and not disclosed “my” data to a third party. So why am I concerned about the government having big databases of stuff about me?

Government interface

Greyscale backing image
[Dave Birch] Government identity is so important that the vigilance of the “issuers” must be unwavering. Thus, the rest of the identity management value network can function. It’s so important that one might even go so far as to say that a key role of government should be to test it’s own vigilance in an open and transparent way. In other words, shouldn’t parts of the government be checking up on other parts of the government and telling us what happened. This would be a really interesting experiment to try here in the UK, now that the government has started issuing identity cards. It would be great to have some reassurance that the process is indeed protecting us from international terrorists, dole scroungers and health tourists. The National Audit Office (NAO) could try and obtain bogus identity documents from the Identity and Passport Service (IPS) and see what happens. Just like the recent experiment in the US.

To do so, GAO designed four test scenarios that simulated the actions of a malicious individual who had access to an American citizen’s personal identity information. GAO created counterfeit documents for four fictitious or deceased individuals using off-the-shelf, commercially available hardware, software, and materials. An undercover GAO investigator then applied for passports at three United States Postal Service (USPS) locations and a State-run passport office.

[From Security Document World]

And the results? Did the ever-vigilant staff, the best IT that money can buy and the process designed by top management consultants come together to defeat these almost trivial attempts to deceive?

In its four tests simulating this approach it was successful in obtaining a genuine U.S. passport in each case.

[From Security Document World]

Uh oh.

No, wait, Titanic isn’t the right metaphor

Greyscale backing image
[Dave Birch] For many years I have consistently maintained that multiple identities (more specifically, multiple virtual identities bound to digital identities that can be authenticated against “real world” identities) are an integral part of the digital identity infrastructure of the future and emphatically part of the solution, not part of the problem. There is a technical caveat though: the virtual identities must be kept separate. As Robin Wilton notes, with his usual perceptiveness,

maintaining different ‘personas’ can contribute to personal privacy – and personal privacy is undermined when the barriers between those ‘personas’ are broken down.

[From Racingsnake – the blog of Future Identity: Is privacy only for the rich?]

So we need a good technology (firewalls, PKI, keys, tamper-resistant hardware blah blah blah, you know the score) to make the barriers and should not rely on guidelines or ombudsmen instead. However, I made a terrible mistake explaining this vision to group of people recently. I said that the partitioning of identity in this way was the equivalent of building a big ship with a series of waterproof compartments separated by strong bulkheads, so that if one compartment is holed, the ship is not threatened. What, someone said, you mean like the Titanic?

In 2018, we can start catching up with Lithuania

Greyscale backing image
[Dave Birch] One of my most frequent criticisms of the UK's national identity card scheme is that it is backward-looking, an electronic simulation of a Victorian ID card rather than an ID card for the 21st century. I gave an example of this in a talk recently by using the case of OpenID, noting that in Finland you can use your ID card to log in to OpenID, and pointing out that this bringing together of |nternet standards and national ID made sense on a number of levels. Needless to say, I have never heard OpenID mentioned in connection with the UK national ID card.

Now I hear that another country has gone over to OpenID. In this case, Lithuania.

Starting January 1st 2009 every issued Personal ID card has OpenID in it, backed up by personal digital certificate. National Certificate Center under the Ministry of Interior will be the national OpenID provider (https://openid.vrm.lt/). Provider service is currently in testing mode, it is not yet open to the general public, but it will go public anytime soon.

[From [OpenID – Eu] Republic of Lithuania goes OpenID]

Doesn't anyone else find it odd that our flagship national identity programme is so unambitious? That our roadmap to 2018 does not include services that are already rolled out in Lithuania?

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.