How do these ideas make it through to implementation?

Greyscale backing image
[Dave Birch] In the US, there is something called the Enhanced Drivers Licence (EDL) which is used not primarily as a means to demonstrate someone's entitlement to drive a motor vehicle but as a proxy identity card.

The Smart Card Alliance says it recommends an immediate review of the decision to use EPC Gen 2 RFID technology in US travel documents. “The Alliance is prepared to endorse the correct use of any technology that provides adequate protection of privacy and identity information. However, as the US Passport Card and EDL programmes were being defined, the Smart Card Alliance went on record advising against using an insecure EPC Gen 2 RFID solution that puts the privacy and security of US citizens’ personal information at risk.”

[From Security Document World – Biometrics, Passports, ID Cards and Visas]

Who cares? After all, what does it matter if a fraudster gets hold of your driving licence details. All they can look up is whether you have a licence or not, right?

Still, victims-rights and privacy advocates remain concerned about one important Real ID requirement, which dictates that state DMVs interlink their databases and make all their drivers' records and identity documents available. The final rule says that both an individual's "full legal name" and "true address" must be stored in the DMV database, regardless of what's displayed on the card and encoded on its bar code. It also requires that motor vehicle departments scan and store "source documents," such as birth certificates, to verify a driver's license applicant's identity.

[From Real ID worries domestic violence groups | Tech news blog – CNET News.com]

Hhhmmmm. There may be some interacting unexpected consequences around the collision between identity and entitlement here. This is what happens when you jumble together entirely different concepts under the banner of "common sense".

The China syndrome

Greyscale backing image
[Dave Birch] A couple of days ago and I again mentioned the government's "break the glass" plan for a national identity scheme. In other words, what is the emergency plan to be followed should the integrity of the system itself fail. The point about the "break the glass" plan is a serious one. While I have no evidence that the government has such a plan, I'm sure they must do. If hackers, mafia extortionists or opposition MPs get into the database then someone has to be able to press a button to sound the alarm, to raise the drawbridge to other government systems and to initiate the meltdown process of re-issuing keys (or whatever else needs to be done).

What kind of meltdown might require the government to break the glass? Well, just for amusement purposes (since it could never happen, because the Home Security said that the ID card system will use "military" security) let's suppose that a disgruntled member of staff steals the entire biographical database. Let's say a fifty million individual records (5 x 10^7). Each individual record comprises 50 data items — actually in the UK Identity Cards Bill it was slightly more than 50 — so that's 5 x 10^1. Let's say each data item is 1KB. They're not, but whatever. So now we have a database of 5 x 5 x 10 x 10^7 or 25 x 10^8 or a couple of terabytes. That's it, a couple of a terabytes. I can buy a 2TB USB hard drive on Amazon right now for a couple of hundred quid and by the time the database is up and running, it will be fifty quid. So I can store the entire database for next to nothing, chuck it in my car and zoom off with it.

When they come in in the morning and notice it missing, there needs to be a big red button on the wall that they can smash the glass and press. Ah, you might say, it seems unlikely that a vetted civil servant will deliberately and flagrantly break the data protection act or whatever. Well I imagine that's what they thought in Chile, before a civil servant started publishing their national identity register on the Internet. We shouldn't let this kind of thing stop us from building a better identity infrastructure, but we should use it to help us build a better one, by which I mean one that depends on open peer review for its security.

Privacy invasion by design

Greyscale backing image
[Dave Birch] I've been reading the excellent report on Privacy by Design that was published by the Information Commissioner's Office in December. As I'm sure many of you will know, the report was written by Forum friend Toby Stevens of EPG. As therefore might be expected, it is a thorough piece of work that makes practical recommendations. As I was reading through it, I began to wonder to what extent the implicit assumptions about what is "good" or "bad" (the report is not that simplistic, by the way) are purely cultural and therefore to what extent the idea of some kind of identity infrastructure that can deliver appropriate privacy, identity, credential, reputation and other structures on an international, web-wide basis is really plausible.

No digital identity, no digital Britain

Greyscale backing image
[Dave Birch] I haven't had time to read the Carter report on Digital Britain yet, but I will try and catch up with it sometime soon. I've had a quick look at a few bullet points and not seen anything particularly interesting. There's been plenty of comment from sources that I pay attention too, though.

The long awaited (and somewhat delayed) Digital Britain interim report has been released, and, like the Gowers Report on intellectual property before it, this one seems way too "balanced" for its own good… For example, it says that the country should have universal broadband (of at least 2 Mbps), but doesn't explain how. It just offers up some vague statements about hoping that private sector ISPs reach that goal, and urging the BBC to promote the wonders of broadband to those who haven't signed up yet… The same sort of vague uselessness is found in the part on copyright and file sharing.

[From Digital Britain Report: Blank Promises, Vague Statements And Everything Is Hedged… | Techdirt]

It's hard for the people putting these sorts of reports together to take any real stance on issues, I'm sure, because they have to obtain some consensus. But perhaps some more real vision is needed at times like these, and that necessarily will mean that some sectors of industry will have to accept change. Because our customers are more interested in the transactional side of things, I'm always looking to see how the plans of the great and good will stimulate new business and what the impact on industry might be. Unfortunately, the early comments that I've been reading are not promising: apparently, one of Carter's suggestions is to impose a tax on broadband access and give the money to industries that have failed to adopt new business models in response to technological change. At first, I assumed he must be talking about sheep farmers, because the law dating back to 1572 requiring everyone to wear wool hats on Sunday isn't being properly enforced any more, but it turns out that he was talking about pop stars and record companies.

Carter appears to ask traditional industries to look to new business models, but offer them a subsidy at everyone else's expense if they can't find any. What's more, the voice of those industries is given disproportionate weight. Now, while it is generally true that at the dawn of new businesses this must always be true — since the new businesses that might grow up around broadband don't yet have a voice to be heard — that's no reason no to extend the range of voices to be heard. As the Open Rights Group say,

We are looking at the report in detail, but we are extremely concerned that the voice of consumers and citizens is being marginalised.

[From The Open Rights Group : Blog Archive » Digital Britain: leaving consumers out of the picture]

Indeed. Not only will citizens be marginalised, they will also be penalised.

Under the proposed scheme, the government would legislate a "Code on unlawful file-sharing" that ISPs would have to follow.

[From "Digital Britain" to legislate graduated response for ISPs – Ars Technica]

Why telephone companies aren't required to follow a "Code on unlawful bank robbery" that requires them to monitor telephone conversations and report the planning of bank robberies to the police, I don't know, but what I do know is that fining kids and kicking their parents off the Internet is not the way to build a healthy and prosperous 21st century business.

Help or hinder?

Greyscale backing image
[Dave Birch] I've been spending a lot of time on biometrics recently, trying to work out the best way for our customers to exploit some advances in the technology. In particular, especially given the ICO's recent "Privacy by Design" report, I've been trying to think of ways to make biometric authentication support identification in a reasonable business model that allows for appropriate privacy settings. One of the reasons why this is complicated is that the temptation to use biometrics for identification purposes is very strong.

Biometric authentication has a role in maintaining and defending our control of our own identity and personal data. This emerging technology makes it virtually impossible to assume someone else's unique identity.

[From Understanding anonymity and the need for biometrics | The Industry Standard]

But biometric authentication of what? If it is biometric authentication of a single, unvarying, "full disclosure" identity (eg, a national ID card of some description) then it's hard to justify the architecture. In other words, why bother with authenticating people against some identity token when you can just match them to their identity in some sort of database: instead of showing the supermarket an ID card to prove you are old enough to buy cigarettes, why not have the supermarket send your fingerprints off to a database and have the database tell the supermarket how old you are? There's no need for card. Or is there?

We have to expect that people will see us when we are in public and that our open public acts will be just that. But we have to worry that, in an anonymous world without authenticated identity, privacy will be violated when others can assume our identifying characteristics and take control of transactions and interactions outside the home that are indeed personal and unique to us.

[From Understanding anonymity and the need for biometrics | The Industry Standard]

With the right identification and authentication architecture, the card provides a means to prove authentication without necessarily disclosing identification. Thus, my ID card can tell you that I am its rightful owner (by matching my, say, fingerprint with an on-card template) and that I am 18. But there is no reason for it to tell you who I am.

A good solution, but only if you don’t understand the problem

Greyscale backing image
[Dave Birch] It’s all for the kiddies. There’s a terrible problem out there on the interweb: there are people who aren’t children who are pretending to be children and there are children who are pretending to be not children. Therefore, something must be done.

MySpace is now encouraging users to post their real names to their profiles. This is quite a shift – like many sites, MySpace used to refer to a ’screen name’ rather than ‘real name’.

[From Privacy Value Networks » Blog Archive » The danger of ‘real names’?]

Well, it might be considered an inconvenience that your children’s identities should be disclosed to the entire world online, but it’s for the greater good, right? And if we know who the children are online, then we can protect them, and help retailers to avoid accidentally selling knives to teenagers, and that’s a good thing too.

Child-safety activists charge that some of the age-verification firms want to help Internet companies tailor ads for children. They say these firms are substituting one exaggerated threat — the menace of online sex predators — with a far more pervasive danger from online marketers like junk food and toy companies that will rush to advertise to children if they are told revealing details about the users.

[From Ping – Online Age Verification for Children Brings Privacy Worries – NYTimes.com]

Perhaps this whole anonymity vs. absonymity argument around online identities is actually important, and perhaps we should be doing some thinking about it instead of leaving it to people (eg, Ministers) who don’t really understand the problem or the solution.

Paying for innovation

Greyscale backing image
[Dave Birch] So who, exactly, is going to pay for innovation in the payments field? Should individual stakeholders incrementally innovate or shoudl we make co-ordinated attempt to improve the payment system and share the cost? Should we regulate and let the market sort things out or should we try to constrain some of the paths through the roadmap. Hhhmmm. In this, as in so many things, Australia proves a useful case study. They had one of the first and best-developed EFT-POS systems in the world, but of late it has been looking a little antiquated.

Australia’s central bank has criticised the nation’s four largest commercial banks for shirking on investments in payment systems technology, resulting in a lack of innovation and neglect of systems like EFTPOS.

[From RBA criticises payments innovation: News – Hardware – ZDNet Australia]

This is, of course, the very same Australia that capped interchange fees, so reducing banks income from cards and therefore reducing their incentive to invest. The results are not surprising. If we use online payments market share as a proxy for innovative new products, then the result has been a steady loss of market to more innovative competitors.

Research from Nielsen Online has tagged PayPal as the most preferred online payment method in Australia and the UK. There are more than 141 million PayPal accounts worldwide. In 2007 more than $47 billion in payments were processed by the service.

[From The Better Banking Blog: PayPal vs Credit Cards]

In Australia, it was the merchants who were the winners. They obtained reduced merchant services charges because of reduced interchange and, broadly speaking, pocketed the difference. Was this what the regulators wanted? It’s hard to imagine that this is the case, so the lesson to be learned here is (surely) that we need a clearer vision of what we want before we set off, if you see what I mean. If we want some real innovation, then simply focusing on interchange isn’t going to deliver anything.

Greater utility

Greyscale backing image
[Dave Birch] The economist John Kay wrote an excellent, excellent piece in Prospect magazine at the turn of the year. In it, he says, amongst other things, that

The modern financial services industry is a casino attached to a utility. The utility is the payment system, which enables individuals and companies to manage their daily affairs… Modest levels of speculative activity may improve the operation of the utility

[From Essays: ‘Making banks boring again’ by John Kay | Prospect Magazine January 2009 issue 154]

His imagery is not only, as always, accurate and thought-provoking but also valuable because it gives us a context for thinking about the way to take the payment system forward.

Straight bananas

Greyscale backing image
[Dave Birch] Normally the only stories about European standards that you read in the newspapers here in Britain are the ones about straight bananas (actually, I think that the rules on banana curvature were recently relaxed) or people going to jail for advertising brussels sprouts in imperial measures (although, once again, the EU’s stringent policy appears to have been abandoned). But I read in last month’s Cards & Payments that the European Commission are upset about EMV being chosen as the standard for the SEPA Cards Framework (SCF) because they view it as “non-European” (worse still, and more specifically, they view it as American). The EU Competition Commissioner, Neelie Kroes, recently labelled the worldwide standard for card payments as “proprietary”.

Perhaps there is some displacement going on here. Perhaps the Commission are upset because they pushed for SEPA and SCF. It is now clear that SCF will lead to an increase in the average merchant service charge in Europe as low-cost domestic debit schemes are replaced by more expensive international credit and debit schemes (ie, Visa and MasterCard branded cards). But it’s an interesting development to move on and begin the attack on EMV.

It’s always, always the same

Greyscale backing image
[Dave Birch] One of the reasons why a digital identity infrastructure ought to be more than just building a big database of everyone and then letting everyone have access to it is that the infrastructure will inevitably be abused by those on the inside, no matter how much effort goes into keeping out the bad guys on the outside.

Missouri Citibank employee Brandon Wyatt… accused of tapping Citibank's computers for customer information, then using it to set up checking accounts online with competing banks, including Bank of America, Washington Mutual and AmTrust. Wyatt allegedly wire transferred customer funds from Citibank to the new accounts, then cashed them out with additional transfers, checks, debit card purchases and ATM withdrawals. His take, according to federal prosecutors in St. Louis, was at least $380,000.

[From Fed Blotter: Citibank Worker Allegedly Plunders Customer Accounts | Threat Level from Wired.com]

It's hard to see how you can stop this from happening completely in an economic way, but what you can do is make sure that there is an audit trail so that someone how decides to have a go at this kind of fraud has a reasonable expectation of being caught. Although I have to say that armed bank robbers have a reasonable expectation of being caught (and a reasonable expectation of a long sentence if they are caught) but they still do it. Anyway, my point is that if you take people personal data and put it in a honeypot, there is only one outcome. A database is not an infrastructure.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.