Showing posts with label intelligence. Show all posts
Showing posts with label intelligence. Show all posts

Wednesday, July 15, 2015

Assessing the damage related to fingerprints in hacked government database

How Much Damage Can OPM Hackers Do With a Million Fingerprints? (Nextgov)
Though the idea of hacked fingerprints conjures up troubling scenarios gleaned from Hollywood's panoply of espionage capers, not much is currently known about those that OPM said were swiped in the data breach, which began last year and has been privately linked by officials to China. In fact, the agency said it didn't even know yet specifically which personnel have had their prints compromised.
The linked article is really good in that it spends a great deal of analysis of the unknowns, and there are many.

While a collection of images of the fingerprints of US government employees — if that is an accurate description of that was taken — certainly has its uses, not all potential uses are equal or equally likely.

In terms of identity fraud, the 1.1 million government employees who had their fingerprints stolen may not be a whole lot worse off than the 20 million or so other government employees who had their personal information stolen minus the fingerprints, though that is cold comfort indeed to the victims. If the individuals whose information was stolen are given the precise details of the personal information that is now "out there" they will be able to make informed decisions about how they wish to manage their affairs going forward. That includes how they might interact with biometric ID management technologies in the future both in and outside of government applications.

The intelligence value of the fingerprints of government employees is different story. With time, money, and pictures of a million fingerprints, it is possible to build a fingerprint watch-list. Probably, not all of the pictures of fingerprints will be of a high enough quality to be enrolled in an automated system today but more time and more money could help. From there, the new watch-list could be accessed by a new or existing biometric ID technology deployment such as a checkpoint serving whatever purposes its owner has for it.

There is probably a lot the government still doesn't know about what was stolen, and even more that hasn't been shared with the public and more importantly with the individuals whose information has been compromised. It will also take some time for the stolen information to be put to use. The Office of Personnel Management has a lot of work ahead of it.

Wednesday, August 6, 2014

US government adding biometrics to terrorism watchlist database

More than 1 million people are listed in U.S. terrorism database (Washington Post)
The documents obtained by The Intercept also indicated that the government, with the assistance of the CIA, is in the midst of a major effort to obtain biometric data on people in the database. The records say analysts have added 730,000 biometric files to the database; some of those files include fingerprints, iris scans and facial photographs.

As of last year, the database contained 860,000 biometric files related to 144,000 people.
There's a lot of really interesting information at the link.

Thursday, May 16, 2013

Biometrics: A New Intelligence Discipline

New technological choices bring challenges (C4ISR Journal)
The intelligence community is pushing to make biometrically enabled intelligence — the art of identifying people by fingerprints, digital mugshots, iris scans or DNA — a regular part of business.
...
But other technologies are coming online. Facial recognition algorithms could someday riffle through mugshot databases to find matches much as fingerprint algorithms do today. Iris-matching technology is another field under development. Authorities around the world are rapidly switching from fingerprints to iris scans for verifying the identities of travelers and workers, and iris databases are growing. And some biometrics experts are aiming for multimodal biometrics in which fingerprint matches would be combined with facial recognition and other measurements to determine someone’s identity with maximum confidence.
Read the whole thing.

Friday, November 30, 2012

Australia to test drive ABIS developed for US by Northrop Grumman

Australia to test biometric system (UPI)
Australia's Defense Department has received a trial proof of concept for an automated biometric information system from Northrop Grumman.

The proof of concept, modeled after the U.S. Department of Defense Automated Biometric Identification System, will be used to produce biometrically enabled intelligence.

Friday, July 27, 2012

“It brings together data from all the sensors.”

It looks like the US Military is developing the Mother of All (Data)bases — a military intelligence MOAB, if you will.

Integrated Intelligence Framework Takes Shape (GlobalSecurity.org)
This state-of-the-art battlefield intelligence, reconnaissance and surveillance architecture will enable analysts from every service to take data from multiple military and government sensors and databases and compile them into a single, easy-to-access format, he explained.

DCGS-Army, already fielded in Afghanistan as it undergoes operational testing and evaluation, provides a glimpse into that intelligence enterprise.

“It brings together data from all the sensors,” Wells said, regardless of whether they’re based in space, on aircraft or on the ground -- even biometric data collected by a soldier at a local forward operating base -- and incorporates it into a single platform.
See also:
What if? Online Real-Time Searchable Sensor Data

The original MOAB is here. (You Tube)

Monday, May 21, 2012

Spycraft & Military Intel in a Biometric World

Mission Nearly Impossible (StrategyPage)
The use of biometrics does its job very well keeping out spies, terrorists and saboteurs. The downside is that it also limits the activities of your own spies. This has led to efforts by espionage agencies to get around this "problem." The espionage organizations will not comment on what, if any, solutions they have come up with. That is to be expected.

Meanwhile, the U.S. has developed tools that enable combat troops to use biometrics on the battlefield.
Read the whole thing.

See also: U.S. Military Departs Iraq, Takes Huge Biometric Database with It

Wednesday, December 21, 2011

U.S. Military Departs Iraq, Takes Huge Biometric Database with It

U.S. Holds On to Biometrics Database of 3 Million Iraqis (Wired)

Two things are going on here. First, the United States is keeping the biometric (and other) information it gathered on some three million Iraqis over the length of its involvement in Iraq. Second, the military is not going to share that information with the Iraqi government it leaves behind, though it would be a simple and inexpensive thing to do. After all, information is not like cake — you can have your data and eat (or share) it, too.

The digital database is the property of Central Command’s intelligence shop in Tampa, Florida. It is conspicuously not in the control of the Iraqi government. Taylor says that the Iraqis might be able to access the database’s contents if they go “through the [U.S.] embassy” in Baghdad.

“Common sense-wise, we still have an interest there in helping our Iraqi partners,” Taylor explains, “and that information might be helpful to them should there be any issues.”

Taylor doesn’t say why the U.S. didn’t hand over its biometrics toy to the Iraqis. But there’s an obvious reason: Iraq’s sectarian divides have not healed. And a database filled with uber-specific information about approximately 10 percent of Iraq’s population could represent a wish list for a death squad, militia or insurgent group — some of which are aligned with Iraqi political parties.
This thought-provoking article addresses the issue of what happens to biometric information (or any other military intelligence, for that matter) when a military campaign is wound down.

Don't read it expecting firm and definitive answers, though. The article raises as many questions as it answers. John at the M2SYS blog does an excellent job of making explicit the questions the Wired article begs.

Answering the questions, however, will require a political, legal and military analysis rather than a technical analysis. After all, ID management is about people.

UPDATE: John at M2SYS, asks via Twitter:


I think it's highly unlikely that there will be a privacy backlash, at least among Iraqis.

The Iraqis (esp. Sunnis) friendly toward the U.S. military who had their biometrics captured are probably extremely relieved that the U.S. military has decided not to give the current Iraqi government their info. As for Iraqis of more violent intent, they're already lashing back and it's not over privacy concerns.

Once the U.S. military made the decision that it was going to keep the biometric database information — and it would have been truly astounding had it decided otherwise — exercising caution in how the data is shared lowers the risk that harm will come to individuals in the database and arguably demonstrates respect for the privacy of any ordinary Iraqis in the database.

It's also important to draw a contrast between violations of privacy that lead to more spam, phishing and identity fraud and the kind of privacy violation that can lead to political persecution, torture, prison and loss of life. My guess is that Iraqis worry more about the latter than the former and the former isn't very likely to result from the U.S. military's possession of the biometric data in question.

On another note, nothing prevents the U.S. from co-operating with the Iraqi government using the biometric data it has gathered on a case-by-case basis in the future. They simply decided not to turn over the whole database now, no questions asked.

Thursday, July 14, 2011

System Never Forgets a Face

Article by Thom Shanker, Ocala.com - Florida

Here's another great biometrics article that shares all the traits of the Slate.com article posted today: historical context, utility, broader applicability, and an honest assessment of the issues surrounding the technology and the role of the democratic political process. There are also some good quotes from the high-ranking military brass that have the most experience with large-scale biometric deployments.

One thing made it easier. Just a month before the April jailbreak, Afghan officials, using technology provided by the United States, recorded eye scans, fingerprints and facial images of each militant and criminal detainee in the giant Sarposa Prison.

Within days of the breakout, about 35 escapees were recaptured at internal checkpoints and border crossings; they were returned to prison after their identities were confirmed by biometric files.

One escapee was seized during a routine traffic stop less than two miles from his home village. Another was recaptured at a local recruiting station where he was trying to infiltrate Afghan security forces.

Read the whole thing.

Thursday, July 7, 2011

Biometrics, Military Intelligence and International terror groups

Intelligence: Pakistan Gets It (Strategy Page)
...[T]hree years ago the U.S. revealed that many terrorists it arrests, or kills, in Iraq, Afghanistan and elsewhere around the world, already had arrest records in the United States and other nations. They knew this because early on in the war on terror, the Department of Defense adopted many practices that major police departments have long taken for granted, and that Pakistan is just now coming to appreciate.

One of the more useful techniques used by the American military to build its database is biometrics.
International Affairs, military style, with an "it's about people" thread.