Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Monday, August 5, 2013

CAPTCHA getting stretched

Evidently I'm not the only person who has found it more and more difficult to suss out what letters the CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) wants me to type.

Bid to kill CAPTCHA security test gains momentum (Canberra Times)
The official web standards body, the World Wide Web Consortium, said there are many CAPTCHA alternatives, including simple maths questions, trivia, the use of sound files and even biometric technology such as fingerprints and retinal scanning. Microsoft have launched a substitute called Asirra (Animal Species Image Recognition for Restricting Access), that asks users to identify photos of cats and dogs instead of letters.

Friday, March 1, 2013

Can respect for privacy be a competitive differentiator?

Though biometrics get quite a lot of attention from people interested in privacy, the real action is in the internet browser and online services. Just remember — If you are not paying for it, you're not the customer; you're the product being sold*.

The Microsoft "Scroogled" ad campaign against Google is interesting because it indicates that the high-level marketing types at Microsoft believe the public is open to the message that some web services are taking too much information from users compared to the value the users receive in "free" services. Whether respect for privacy is a competitive differentiator among web services remains to be seen, but the fact that Microsoft has spent real time and money on the assumption that it is should not go unnoticed.

Google Privacy Chief Blasts Microsoft’s “Scroogled” Campaign at RSA Conference (CIO)

The bulk of the article linked above is devoted to privacy standards, privacy policy and corporate management. While that's not nearly as eye-catching as a slug fest between Information Age titans, it is a much more substantial issue and one worth of serious attention.

Thursday, August 9, 2012

In a Cloud-Connected IT World, are Biometrics the Answer?

For your eyes only: New twist on Digital ID could keep you from getting hacked (ZDNet)
With so many individuals with multiple accounts on so many linked cloud services, it is inevitable that this sort of cybercrime is going to become more commonplace unless new mechanisms are put into place to prevent this form of compromise that Honan experienced.

One way of dealing with this would be to employ biometrics on all computing devices. I wrote about this at length in February 2011, which eventually led to an appearance on CBC Radio alongside prominent independent security researcher Dr. Markus Jakobsson.

Monday, February 13, 2012

Big Data's Impact in the World

Privacy advocates tend to latch onto biometrics as a convenient way of expressing concerns about a world driven by Big Data even though biometrics will only ever be a tiny slice of the data pie.

Big data does, however, present opportunities and challenges that are well worth considering. The opportunities are so great that big data techniques will, and probably should be, adopted. The challenges to individual privacy are real, too.

This article provides a great overview of what is becoming possible and where we may be headed.

The Age of Big Data (New York Times)
Data is not only becoming more available but also more understandable to computers. Most of the Big Data surge is data in the wild — unruly stuff like words, images and video on the Web and those streams of sensor data. It is called unstructured data and is not typically grist for traditional databases.

But the computer tools for gleaning knowledge and insights from the Internet era’s vast trove of unstructured data are fast gaining ground. At the forefront are the rapidly advancing techniques of artificial intelligence like natural-language processing, pattern recognition and machine learning.

Those artificial-intelligence technologies can be applied in many fields. For example, Google’s search and ad business and its experimental robot cars, which have navigated thousands of miles of California roads, both use a bundle of artificial-intelligence tricks. Both are daunting Big Data challenges, parsing vast quantities of data and making decisions instantaneously.

The wealth of new data, in turn, accelerates advances in computing — a virtuous circle of Big Data. Machine-learning algorithms, for example, learn on data, and the more data, the more the machines learn. Take Siri, the talking, question-answering application in iPhones, which Apple introduced last fall. Its origins go back to a Pentagon research project that was then spun off as a Silicon Valley start-up. Apple bought Siri in 2010, and kept feeding it more data. Now, with people supplying millions of questions, Siri is becoming an increasingly adept personal assistant, offering reminders, weather reports, restaurant suggestions and answers to an expanding universe of questions.
That's just a sample. It's well worth reading the whole thing.

Wednesday, February 8, 2012

Multifactor Authentication, Middleware and the Online Security Arms Race

Julie Sartain at has an article at techworld.com that describes some of the new threats that have necessitated the adoption of multifactor authentication for online transactions and the variety of technologies available to augment standard username/password authentication, such as:

♦ Risk-based authentication
♦ Phone-based authentication
♦ Versatile authentication platforms
♦ Image-based authentication and, of course,
♦ Biometrics
As everyone in the security business knows, there is no perfect answer. Gartner's Allan points out that "whatever the desirable level of assurance, it has to be balanced against cost (deployments for hundreds of thousands of users are very cost sensitive) and user experience. We know that bank customers may change their banks if new security features such as authentication degrade the user experience: in a survey a couple of years ago, Gartner found that 3% of customers had done so, and a further 12% considered it," adds Allan.
Because there's no perfect answer, the challenge is in how to adopt new technologies that show positive return on investment without tying a mission-critical business process up in something that might not be the optimal solution over the longer term. How do you adopt new technologies in a way that preserves your ability to continue to adopt new technologies?



Our CEO, Barry Hodge, points out via Twitter that the move to multifactor authentication broaches the subject of middleware.

Middleware, as it relates to this discussion, is the software components that will allow the new authentication factor to interact with the existing authentication scheme and broader business processes.

But not all middleware is created equal.

Middleware can be written to facilitate a custom integration, or it can be written as a more flexible software layer that makes future integration decisions and changes less costly. A hardware analogy might be the difference between a soldering iron and a USB port. Both get the job done but involve entirely different levels of commitment.

Well written middleware components, such as those we've developed here at SecurLinx for biometrics, allow flexibility by reducing an enterprise's switching costs and the costs of adopting future techniques and technologies that may offer a significant returns on investment.

Middleware isn't really a glamorous topic — no Tom Cruise movies, severed eyeballs or rubber fingers — but it's incredibly important and becoming more so.

Tuesday, February 7, 2012

Retail Marketing Technology Online and In Person

Not really biometrics related, but...
Software mines security footage to help business owners see what people do once they're inside the store (Technology Review)


"The huge success of online shopping and advertising—led by giants like Amazon and Google—is in no small part thanks to software that logs when you visit Web pages and what you click on. Startup Prism Skylabs offers brick-and-mortar businesses the equivalent—counting, logging, and tracking people in a store, coffee shop, or gym with software that works with video from security cameras."
Online retailers are able to free-ride on investments made by their brick-and-mortar competitors (see showrooming). They also have more powerful tools available to them for the purposes of analyzing detailed reports of user activity on retail websites. Why, the page I linked to for this story has fifteen programs that track your interaction with the linked page and TechnologyReview.com isn't even selling anything directly. The image to the left shows the list as compiled by the Ghostery add-on for Firefox.

If brick-and mortar retailers can't learn as much about customers in physical stores as web retailers know about user experiences, they must compensate in other ways or they're going to continue to struggle.

See also:
Target fights Amazon showrooming with plea for special product lines (ExtremeTech.com)

Monday, January 16, 2012

Why Passwords are Great

The first article below is a really good discussion about passwords and why they might be with us for a while. Still, it acknowledges that the password as a security technology is clunky in some of the applications in which it serves.

The second article sheds light on why the password is still ubiquitous and hasn't even been displaced in applications where its displacement is clearly desirable. No biometric scanning device exists that has web-enabled communication and control based on a publicly available specification. Passwords don't suffer from this complication.

A couple of Experts: We're stuck with passwords (Channel Register)
They argue researchers need to revisit the subject of how to get passwords to work efficiently rather than assuming the approach is about to be written off as hopelessly flawed and unfixable. Passwords are here to stay, even though they certainly not appropriate in all cases, because "no other single technology matches their combination of cost, immediacy and convenience that many scenarios require". The researchers are, however, careful to note that there are many cases where passwords are not the best-fit.

"Passwords have proved themselves a worthy opponent: all who have attempted to replace them have failed," the two boffins conclude. "It is fair to say that little progress has been made in the last 20 years: usability has degraded significantly, while security has not improved. The reasons, we suggest, are widespread confusion about why we are trying to replace them, what is required of a replacement, and what improvement is expected once they are replaced."
NIST wants small form-factor, tamper-resistant and handheld fingerprint sensor (Bank Info Security)
The goal of this initiative, for which NIST will provide funding, is to produce a fully functional, handheld device that's capable of biometric acquisition, and controlled through web services as specified in NIST Special Publication 500-288: Specification for WS-Biometric Devices.

NIST recognizes the ubiquity of the Internet and its impact on commerce - the agency, after all, is part of the U.S. Commerce Department - and the need for tools that can assure safe online transactions.
Those of strong constitution might consider clicking here for the NIST Solicitation (PDF), though I cannot recommend it.

ADVICE TO THE FOOLHARDY: You went ahead and clicked it anyway, didn't you?

Now, you're nine pages in and wondering, "What the heck is The Trust Territory of the Pacific Islands?"

You're now only 15 pages from the part about Research Projects Involving Vertebrate Animals.

From there, it's only a short 5-page dash to the good stuff which starts on page 39 of 62 in Section 9.0: RESEARCH TOPIC AREAS.

Welcome to flavor country.

Friday, October 21, 2011

The Fight to Secure the Current Internet is Unwinnable

The internet is used to do all kinds of things that no one, even its creators, could ever have envisioned so this article shouldn't be taken as an opportunity to have a go at the giants upon whose shoulders so many stand. Rather, it presents an opportunity to conduct a cost-benefit analysis on the evolutionary approach and the revolutionary approach — the current arms race between cops and robbers or hitting the reset button — to internet security and identity assurance.

 Internet Creators Acknowledge Security Overlooked in Original Web Framework (FT.com)
A faulty initial design – with net protocols that rely on trust and freely allow anonymity – has been compounded by the slow rollout of security gear, he says.

“I can do a very good job,” says Mr Eisen, whose company tries to keep pace with advancements in the cybercrime underworld. “But in the long run, it is essentially hopeless.”

So, what would a secure internet look like? Mr Eisen has set out plans for Internet 2 in a document called Project Phoenix. Included in his blueprint are biometric identification, encryption of all keystrokes and virtual machines created for every transaction.


h/t @TimeTrax_ET