Thursday, July 19, 2012

Biometrics & the FBI's Criminal Justice Information Services (CJIS)

Here's a Storify transcript of this morning's Tweet Chat about biometrics (#biometricchat).

I offer many thanks to John at M2SYS for asking me to fill in for him and Mike Kirkpatrick for taking time out of his busy schedule to lend his experience to our understanding of the FBI's use of biometrics for law enforcement and civilian purposes.

Background for the conversation is here.


July, 19 2012 Biometric Chat with Mike Kirkpatrick : Assistant Director in Charge of the Bureau's Criminal Justice Information Services (CJIS) Division from April 2001 - August 2004.



Powered by Storify
  1. SecurLinx
    Good morning and welcome to this month’s chat on#biometric technology! #biometricchat
  2. SecurLinx
    I'm honored to be filling in for John @m2sys as this month's host. Thanks for asking me, John!#biometricchat
  3. m2sys
    Good morning to you and thanks for taking over this month's chat - we really are appreciative of your guest hosting skills! #biometricchat
  4. SecurLinx
    @m2sys The pleasure is mine. AND Thank you, and welcome to Mike @MDKConsulting, for joining us.#biometricchat
  5. SecurLinx
    Today, we will be discussing #biometrics in Law Enforcement (esp. FBI). Our guest is Michael Kirkpatrick. @MDKConsulting #biometricchat
  6. MDKConsulting
    Thanks for the invite! I'm looking forward to this morning's chat #biometricchat
  7. SecurLinx
    @MDKConsulting Mike finished his FBI career as Asst. Dir. in charge of the FBI's CJIS center (Apr. 2001 - Aug. 2004) #biometricchat
  8. SecurLinx
    Those dates should give you some idea of the challenges at the FBI's CJIS. #biometricchat
  9. m2sys
    @SecurLinx Quite a tumultuous time at the FBI's CJIS...anxious to hear some of Mike's feedback and insight. #biometricchat
  10. SecurLinx
    Feel free to chip in with your own answers – answer each question (Q1, Q2, Q3, etc.) with A1, A2, A3, etc.#biometricchat
  11. SecurLinx
    Also feel free to submit your own questions during chat or ask other questions of the group. #biometricchat
  12. SecurLinx
    Q1: What was the biggest challenge CJIS faced in the transition from a paper fingerprint system to a fully fledged IAFIS? #biometricchat
  13. MDKConsulting
    A1:There were several challenges. Building the world's largest #AFIS; IdM had never been done on that scale before... #biometricchat
  14. Note: IdM = Identity Management
  15. MDKConsulting
    A1...Getting the budget to build it ($640M); there were no #fingerprint electronic transmission standards so they had to be.. #biometricchat
  16. MDKConsulting
    A1:...developed (EFTS); Most #fingerprints were still being captured on paper so had to be converted to digital images:... #biometricchat
  17. MDKConsulting
    A1:...Major #FBI workforce retraining; IAFIS didn't always work as advertised in the early days so alot of downtime #biometricchat
  18. m2sys
    Q1: Were lawmakers at the time reluctant to fund this or was it generally accepted that this was natural maturation? #biometricchat
  19. MDKConsulting
    m2sys A1: Overall, congress was very supportive but this was a high profile project, the only one of its peer projects... #biometricchat
  20. MDKConsulting
    m2sys A1:...(e.g., FAA & IRS modernizations) to succeed. It turned out to be a high risk/high reward project #biometricchat
  21. SecurLinx
    Q2: CJIS is a key part of US ID infrastructure. What is the breakdown between Law Enforcement vs civilian/licensing queries? #biometricchat
  22. SecurLinx
    FBI CJIS is used for firearm background checks, child care workers, financial services employment and more...#biometricchat
  23. BiometricUpdate
    Often wondered about this breakdown myself, actually#biometricchat #biometricchat
  24. MDKConsulting
    A2: #FBI has 2 #fingerprint streams-criminal and civil (licensing & employment checks). Currently ~55% are criminal... #biometricchat
  25. MDKConsulting
    A2:...and 45% are civil. The original IAFIS was designed to process 60K prints/day. #FBI Next Generation Identification... #biometricchat
  26. MDKConsulting
    A2: ...(NGI) now easily processes more than 185K/day. Quite a leap forward! #biometricchat
  27. MDKConsulting
    Firearm pre-sale checks (NICS) are name-based, not fingerprint-based. #biometricchat
  28. SecurLinx
    @mdkconsulting Good catch re firearms... done thru the FBI but no fingerprints involved. #biometricchat
  29. SecurLinx
    Q3: What is the next biometric modality CJIS would like to incorporate into IAFIS? #biometricchat
  30. MDKConsulting
    A3: In order of priority, palm prints, face, and iris capabilities will be added to NGI. #biometricchat
  31. BiometricUpdate
    We just wrote about the B12 MORIS system being adopted by FBI. How much time can apps like this save?bit.ly/LYXvug #biometricchat
  32. SecurLinx
    Let's go quickly to Q4 and then deal with Q3 & Q4 together... #BiometricChat
  33. SecurLinx
    Q4: Then, if the Big Three of #biometrics are Face, Finger/palm print & Iris – Where does DNA fit in?#BiometricChat
  34. MDKConsulting
    A4: There's an ongoing multi-agency effort on rapid#DNA, which will put a "quick" DNA capability at the ...#biometricchat
  35. SecurLinx
    @mdkconsulting Love the quotes around quick. Definitely quick compared to earlier DNA analysis!#BiometricChat
  36. MDKConsulting
    A4:...booking stations. We should see this in the market within the next couple of years. It'll help solve alot of cases. #biometricchat
  37. MDKConsulting
    A4: #DNA in many ways is the ultimate #biometric but still has many privacy issues associated with it as well as the past... #biometricchat
  38. MDKConsulting
    A4:...relative slowness in getting results. It can prove someone innocent as easily as proving someone guilty, which is... #biometricchat
  39. MDKConsulting
    A4:...good as all in criminal justice should be searching for the truth. #biometricchat
  40. SecurLinx
    @MDKConsulting Excellent point. Biometrics can be evidence of either innocence and guilt. #biometricchat
  41. m2sys
    @MDKConsulting Q4: So DNA quick checks will be at booking stations to circumvent lab analysis in as little as a few years? #biometricchat
  42. MDKConsulting
    @m2sys A4: These are envisioned as a "quick" check as an investigative lead rather than a full-on forensic lab exam #biometricchat
  43. m2sys
    @MDKConsulting Thank you, truly amazing advances in science for DNA processing! #biometricchat
  44. MDKConsulting
    Currently, #FBI is processing criminal fingerprints in just a few minutes. Rapid DNA is envisioned to be more like an hour. #biometricchat
  45. SecurLinx
    Q3/4b: Which (palm, face, iris, DNA) advancement in CJIS capabilities is furthest along? #BiometricChat
  46. SecurLinx
    Last question Q5: What are some near future capabilities related to #biometrics that the FBI would really like to add? #biometricchat
  47. MDKConsulting
    A5: #FBI & law enforcement are looking for smaller, faster, cheaper mobile #biometric collection devices; capability for ... #biometricchat
  48. MDKConsulting
    A5:...collection at a distance for fingerprints and iris; implementation of a national palm print capability (a high % of ... #biometricchat
  49. MDKConsulting
    A5:...crime scene latents are palm prints); and greater accuracy in facial recognition technology for large databases. #biometricchat
  50. BiometricUpdate
    @MDKConsulting is palm a priority for any particular reason, or is it just an indication of technological advancement? #biometricchat
  51. MDKConsulting
    @biometricupdate: Palm print capability will help to solve many crimes which are unsolved without it. Countries, such ... #biometricchat
  52. MDKConsulting
    @biometricupdate: ...as Australia, which have implemented palms have reported significant increases in latent matches. #biometricchat
  53. SecurLinx
    That's all folks. Our sincere thanks to @MDKConcultingMike Kirkpartick for taking the time to talk with us: FBI#biometricchat
  54. SecurLinx
    We kept him a little late but hopefully @MDKConsulting(and you) enjoyed our conversation as much as I did.#BiometricChat
  55. MDKConsulting
    Thanks! I've appreciated the opportunity to chat about one of my passions! #biometricchat
  56. m2sys
    @MDKConsulting Thank you for sharing your knowledge with us, it was extremely informative!#biometricchat
  57. SecurLinx
    Thanks @MDKConsulting! Thanks @m2sys for lending me the #BiometricChat hashtag! & to@BiometricUpdate for the questions!

Today 11 AM EDT: Twitter Biometric Chat with Mike Kirkpatrick - Biometrics at FBI's CJIS

UPDATE: 
Questions added in bold section below.

When: July 19, 2012 — 11:00 am EDT; 8:00 am PDT; 16:00 pm BST; 17:00 pm CEST; 23:00 pm SGT; 0:00 JST

Where: tweetchat.com (hashtag #biometricchat

What: Tweet chat on Biometrics and Law Enforcement with Michael D. Kirkpatrick (@MDKConsulting)

Questions:

Q1: What was the biggest challenge CJIS faced in the transition from a paper fingerprint system to a fully fledged IAFIS?
Q2: CJIS is a key part of US ID infrastructure. What is the breakdown between Law Enforcement vs civilian/licensing queries?
Q3: What is the next biometric modality CJIS would like to incorporate into IAFIS?
Q4: If the Big Three of biometrics are Face, Fingerprint & Iris – Where does DNA fit in?
Q5: What are some capabilities related to biometrics that the FBI would really like to add?

When John at M2SYS asked me to guest host the July #BiometricChat, I immediately thought of Michael Kirkpatrick. I'm happy to announce that he's agreed to join us. I offer my sincere thanks to both of them for the opportunity.


Michael Kirkpatrick
Michael D. Kirkpatrick, as the FBI's Assistant Director in Charge of the Bureau's Criminal Justice Information Services (CJIS) Division from January 2001 - August 2004, led the Division through profound IT changes especially relating to the application of biometric technologies to the challenges of law enforcement.

Back in the day (i.e. before 1999), fingerprint analysis for law enforcement purposes was a much different ball game. Everything was accomplished with paper, ink, and highly-trained, dedicated  fingerprint analysts. That made law enforcement biometrics pretty much the only biometrics game in town because there weren't really any commercial applications for that type of set-up. Sure, some professions required criminal background checks, but the fingerprinting part was mostly there to make it easier to catch people in the event they committed crimes at some later date.

Presently, the FBI maintains the world's largest collection of biometric data and facilitates information sharing between law enforcement organizations and a range of both public and private entities. The CJIS center handles more than 61 million ten-print submissions a year. Average response time for an electronic criminal fingerprint submission is about 27 minutes, Electronic civil submissions are processed within 72 minutes.

The successful transition from a paper system to an Integrated Automated Fingerprint Identification System (IAFIS), presented a range of technical, organizational and managerial challenges such as: What to do with all the paper records; What technical standards to apply to digitization; Determining what confidence level constitutes a match; How to receive input remotely and transmit results;  How to store the information securely; What policies to put in place; Determining whether current international agreements were adequate or forging new ones necessary. The list goes on and on.

Without the hard work sorting out these kinds of questions done by those at CJIS, biometric ID management applications, beginning with fingerprint biometrics, simply would not have nearly the impact in the public and private sectors that they do today. Michael D. Kirkpatrick was one of the many people who helped make it all possible.

Over the course of his career, Michael has done far too many interesting things in law enforcement and biometrics than can be listed here. Thankfully, he has posted a brief overview of some of his experiences at his site, here. He tweets at @MDKConsulting

We hope that you will spread the word among your colleagues and friends and join us Thursday, July 19 at 11am EDT.

Wednesday, July 18, 2012

Iris Biometrics: Come on Down!

It's not a real biometric modality until someone hacks it (yes, I'm talking to you foot, ear and butt). So cheer up, iris. You're in good company.

Black Hat: Hacking iris recognition systems (Bank Info Security) UPDATE: Link was wrong before, fixed now.

The article is short on detail about how and how successfully iris systems have been hacked but more information will certainly follow Black Hat's presentation on July 25 summarized as follows:
FROM THE IRISCODE TO THE IRIS: A NEW VULNERABILITY OF IRIS RECOGNITION SYSTEMS

A binary iriscode is a very compact representation of an iris image, and, for a long time, it has been assumed that it did not contain enough information to allow the reconstruction of the original iris. The present work proposes a novel probabilistic approach to reconstruct iris images from binary templates and analyzes to what extent the reconstructed samples are similar to the original ones (that is, those from which the templates were extracted). The performance of the reconstruction technique is assessed by estimating the success chances of an attack carried out with the synthetic iris patterns against a commercial iris recognition system. The experimental results show that the reconstructed images are very realistic and that, even though a human expert would not be easily deceived by them, there is a high chance that they can break into an iris recognition system.
Stay tuned.

UID: Problems and Solutions

The article by Harshal Kallyanpur linked below does a very good job of frankly confronting the challenges and mistakes of the UID process while remaining balanced about its value and the benefits of having it go forward and succeed.

UID: Soldiering on (Express Computer)
UID has by far been one of the most significant technology projects undertaken by the Government of India. Designed to give a unique identification number to every citizen in the country, the project would eliminate the need for every citizen to provide a lot of different proof of identification documents in order to get their work done.

The main purpose of the project was to ensure that each and every citizen, regardless of his socio-economic status, could partake of public services from the government. At the same time, UID will also enable an Indian citizen to provide a single proof of identity while availing of different public and private citizen facing services.

Carnegie Mellon University Sets Up New Foot Biometrics Lab

Carnegie Mellon University's Biometrics Center Selected To House New Pedo-Biometrics Research and Identity Automation Lab (Press Release)
Identity science takes a giant leap forward with a new discipline in biometrics. Carnegie Mellon University researchers at the new $1.5 million per year Pedo-Biometrics Research and Identity Automation Lab are teaming up with Autonomous ID, an Ottawa, Canada, company currently relocating operations to the U.S., to test insole sensory system prototypes for a variety of identification uses, from security to detecting the onset of such diseases as diabetes and Parkinson's.

The CMU Pedo-Biometrics Lab, headed by Electrical and Computer Engineering Professor Marios Savvides, will provide the roadmap for scientific analysis and algorithm research and development for the new pedo-biometrics discipline, which uses a specially designed insole to monitor foot movement.

Tuesday, July 17, 2012

Biometric passwords feature in list of 15 awesome DARPA technologies

15 Advanced Military Research Projects That Will Change Your Life (Business Insider)
The Defense Advanced Research Projects Agency (DARPA) gets a ton of funding to develop the science and techological future of the military. This is the agency responsible for GPS, the internet and stealth planes. They're the real deal.

We looked at their active projects to find the ones that might have massive civilian implications if they eventually produce real-world tech. For this round, we focused on only their Defense Science Office and their Information Innovation Office, two of six DARPA branches.
There's some really cool stuff there, much of it to do with speech/language and blood.

A Face Rec Rundown Ahead of the US Senate Hearings

Facial Recognition Technology Will Make You Hard To Miss (Reason)
Just in case you thought the best way to avoid having your movements automatically tracked by robo-cameras snapping your license plate as you speed on by was to get out and walk, now comes word that long-over-promised facial recognition technology is getting ... well ... more promising.

A look at digital government services

Of course, I'd say policy and technology must be good bedfellows...

Policy and technology can be good bedfellows (The Guardian)
Technology-enabled reform of public services can create friction, as the public is required to adapt to new platforms for interacting with the state and its administrators have to learn a new way of working. At its worst, this friction can result in disjoined state paralysis following the wrong kind of policy making and subsequent commissioning. At its best, it can reduce the state running costs and better fit the mould of citizens' lives, such as being able to book a GP appointment via a laptop or mobile.

Kenya: Procurement for Biometric Voter System Gets Messy

Kenya: IEBC Tender Team Quits Over Biometric Deal (All Africa)
Uncertainty hangs over the process of awarding the Biometric Voter Registration (BVR) solution kits contract after the IEBC tender committee stepped aside last week. The team quit following weeks of squabbles pitting some IEBC commissioners against its secretariat and they have been tussling over which firm is the most suitable to be awarded the tender.

The Praxedes Tororey-led committee handed in their resignation on Friday, only days after CEO James Oswago appeared to reject their second report for the multibillion-shilling tender award. Oswago had written to the Public Procurement and Oversight Authority (PPOA) seeking guidance on the recommendation to award the tender to Face Technologies of South Africa that emerged third in cost evaluation.
A discussion of vendors and prices follows.

FBI Wants a Tattoo Interpretation System

What Does Your Tattoo Say About You? The FBI Wants to Know. (Nextgov)
The FBI is consulting local police and vendors about technology currently in use that can spot crooks and terrorists by interpreting the symbolism of their tattoos, according to government documents. The inquiry follows work already underway at the bureau and Homeland Security Department to add iris and facial recognition services to their respective fingerprint databases.

The FBI on Friday issued a request for information on existing databases “containing tattoo/symbol images, their possible meanings, gang affiliations, terrorist groups or other criminal organizations.”
What is described is more of a pattern recognition system but it is related to biometrics.

See: Biometrics, object recognition and search

Monday, July 16, 2012

Sri Lanka Adopts Biometrics for Better ID Management of Expatriate Domestics in the Middle East

Hi-tech measures to stop job swindles in the Middle East (The Sunday Times - Sri Lanka)
Sri Lankans seeking jobs in the Middle East will now face electronic fingerprinting and biometric scanning prior to departure to crack down on rampant fraud and other irregularities in the recruitment trade, a senior official said yesterday. Scanning devices would be installed at the departure and arrival areas of the Bandaranaike International Airport (BIA) and at all Sri Lankan diplomatic missions in the Middle Eastern countries where there were large numbers of Sri Lankan workers, Sri Lanka Foreign Employment Bureau (SLFEB) Chairman Amal Senadhilankara said.
Click through to the whole story for a great example of the convoluted way people try to game well-intentioned systems.

A Survey of Tech-Driven Advancement in Inida

Our friends at Operation Asha get a well-deserved mention.

Technology and social change (Live Mint - WSJ)
The increasing cost of tuberculosis (TB) treatment is a serious concern in India. Funding requirements have grown 16 times. And instances of multi-drug resistance tuberculosis are rising. Therefore, monitoring the intake of medicines by TB patients for six to nine months is essential. Operation Asha’s eCompliance programme created a biometric identification system to monitor tuberculosis treatments through verifiable tracking, while coordinating phone text messaging-based technology for collecting records into a digitized system.
A high proportion of the seven cases mentioned in the piece have an ID management component.

Patco Construction v People's United Bank is a Big Deal

Court Rules Bank's Security Procedures Were Not Commercially Reasonable (Day Pitney LLP)
In an important decision last week, the U.S. Court of Appeals for the First Circuit held, as a matter of law, that People's United Bank's online banking security procedures were not commercially reasonable, even though its selected authentication technology fully complied with the Federal Financial Institutions Examination Council (FFIEC) guidelines for Authentication in an Internet Banking Environment.
This case of PATCO CONSTRUCTION COMPANY, INC. v. PEOPLE'S UNITED BANK is a really big deal but a little outside the scope of what we usually deal with around here.

The gist is that with today's decision, banks have more responsibility to shield their business customers from fraud. That responsibility, however, will entail a cost that will ultimately be borne by customers in higher fees — applied directly to this this case, wiring fees. But if not appealed and/or upheld, it means banks will be offering customers more security and charging higher prices, part of which will flow to security providers including biometric ID management providers.

A couple of good blog posts already exist out there to bring interested readers up to speed:

Technology & Marketing Law Blog: Bank ACH Fraud Victims Get Mixed Rulings (Venkat Balasubramani - June 18, 2011). This one covers the first round and mixed decisions in two different but related cases.

Thinking About Security: Decision on Appeal of Patco v. Ocean Bank (Bill Murray - July 11, 2012). This one covers more recent news.


Cross Match Technologies Purchased by Private Equity Firm

I haven't quite figured out exactly what went down.

The press release from purchasing private equity firm Francisco Partners states pretty clearly that they acquired Cross Match.
Francisco Partners, a leading technology-focused private equity firm, today announced the acquisition of Cross Match Technologies, Inc., a leading provider of high-quality, interoperable biometric identity management systems, applications, and services.
The only seller that I can find who is talking is the UK's Smiths Group PLC. Their press release:
Smiths Group plc today announces the disposal of its minority stake in Cross Match Technologies Inc for up to $77 million as part of its strategy to manage its portfolio more actively and divest non-core activities. [Emphasis mine.]
Cross Match was and is still privately held so it's not easy to find out/put a number on the price Francisco Partners paid for Cross Match. The imprecision of the selling price of Smiths Group's stake, "up to $77 million," and its proportion of the whole, make valuing the value of the transaction difficult.

Is Ghana Doing Biometric Voter Verification on Election Day?

If so, this is the first I've heard about it and it's only mentioned in passing.

EC to procure more verification machines (GhanaWeb)
“Haven gone through the registration which was challenging, the verification definitely will also present its own challenges but we don’t anticipate that the challenges related to the verification will be that difficult,” Samuel Yorke Aidoo said.

Unlike the machines used for the registration process which sometimes broke down, the verification machines, he assured, “is handheld, one machine without any connections so we anticipate that it may not give us that serious challenge…”

He, however, added that the EC is making arrangements to procure backups at electoral and zonal levels so that they can make quick interventions in case there is any breakdown.

Friday, July 13, 2012

WVU's own Bojan Cukic holds forth on the state of biometric applications.

Tipping Point Unclear For Mass Market Adoption Of Biometrics
Cukic said that most biometric devices currently available are standalone solutions that do not have access to the Internet. Were this to change, Cukic believes the use of biometrics could receive a significant shot in the arm. "I would say that we have good components, but the question remains, who is going to be the developer responsible for offering these systems in which biometrics address some of the authorization and authentication problems that we face today?" he added.
Middleware and the application development it enables will be critical to moving these technologies out of the lab and niche government installations and into positive ROI applications for profit-making entities.
Or (more succinctly...

US: Outstanding Airmen of the Year Award Winner Played Key Role in Biometric ID System

Keesler member wins Outstanding Airman of the Year (Keesler Force Air Base)
Congratulations to Staff Sgt. Angelo Banks of the 81st Security Forces Squadron.
NIST releases second draft of federal ID credential security standard for commentWhile deployed at the transit center at Manas, in Kyrgyzstan, he secured $451 million in assets, 90 combat sorties and 296 tons of cargo. He led 19 fly-away security missions to 39 hostile forward-operating bases delivering 1,300 passengers and three detainees.

Banks also played an instrumental role during the implementation of the Defense Biometric Identification System, processing base access for more than 39,000 base users. Additionally, he positively identified and arrested a suspect with a $215,000 warrant who was attempting to gain access to a high-profile event on base. Additionally, Banks has volunteered with organizations such as Airmen Against Drunk Driving and Loaves and Fishes soup kitchen.

According to Banks, doing your job well is one thing -- being professional and showing respect is another.

Daily Mail Calls for More Facial Recognition Technology at Borders?

The UK Daily Mail calls for more facial recognition technology at borders, but it is pretty hard to decode that from the article, as published.

The Daily Mail recently published an article about "facial recognition" stating that because humans can be confused while comparing a neutrally-posed facial photo to the live subject standing before them, it follows that "facial recognition technology needs to be upgraded."

I agree, with a caveat. I'm all for adopting facial recognition technology (SecurLinx does great work in this field). The upgrading will come later.

The article makes a bit of a hash of the problem by muddling the very different processes by which humans and biometric facial recognition technologies do what they do to process visual inputs and, upon a quick read, takes a psychological study of how humans process visual information related to the faces of other people and assumes that those findings apply perfectly to technological biometric facial recognition systems. They don't.

The observations of Rob Jenkins, Glasgow University Psychologist, actually argue for the increased use of facial recognition technology as currently on offer as an aide to human border agents along the lines advanced in an earlier post (Facial Recognition vs Human) & (Facial Recognition + Human).

A technology assisted human should outperform both a stand-alone technology and unaided humans.

On another note, the psychology surrounding how people (and wasps!) recognize faces is very interesting. The paper by Dr. Jenkins that seems to have the most bearing on facial recognition technology can be read here [pdf].

The paper is a little more skeptical of facial recognition technology than is warranted because the authors envision facial recognition technology as essentially aspiring to be a poor replication of the fallible neurological process rather than an augmentation of what humans do by coming at the problem from a completely different angle.
We suggest that a major attraction of using facial appearance to establish identity is that we accept it can be done in principle. In fact, we experience practical success every day because the system that has solved it is the human brain. The proliferation of ‘biologically inspired’ approaches to automatic face recognition reflects the willingness of computer engineers to model the brain’s success. Yet, psychological studies have shown that human expertise in face identification is much more narrow than is often assumed. Moreover, the process that most automatic systems attempt to model lies outside 1672 R. Jenkins & A. M. Burton Review. Stable face representations. From this perspective, disappointment in machine systems is inevitable, as they model a process that fails. Human limitations in face identification are not widely appreciated even within cognitive psychology, and seldom penetrate cognate fields in engineering and law. In §3, we offer an overview of the most pertinent limitations. For this purpose, we focus specifically on evidence from face matching tasks, as these directly address a problem that is common to security and forensic applications.




Thursday, July 12, 2012

Ibiza Hotel ❤'s Biometrics

Tequila at your fingertips: cashless clubbing arrives in Ibiza, is this the most dangerous technology ever? (Daily Mail)
Ibiza die-hards are always looking for the next big thing, and at the moment this is it.

Much cooler than an all-inclusive wrist-band, this cashless system lets showy guests pay for anything at the hotel with a swipe of their fingers, a brilliant way to impress.

And as one of the hottest new party destinations in Ibiza, the five star options are pretty extensive.

US: Biometrics (Voice) to be Applied in the Wake of Teacher Certification Scam

Details of teacher certification scam uncovered (WMC-TV 5 Memphis, TN)
Ewing confirms one of his workers spotted odd behavior that triggered a 45-count indictment against Clarence Mumford and the de-certification of more than 50 teachers in Arkansas, Mississippi and Tennessee.

"The people who serve as our test center supervisors, monitors, and room proctors are our first defense against such things," Ewing explained.

According to court documents, Mumford hired four co-conspirators to assume the identities of teachers and aspiring teachers who could not pass the PRAXIS teacher certification test.

A PRAXIS worker noticed one person taking the same test several times in one day.

But technology may be the reason it went undetected 15 years.

Investigators say Mumford manufactured fake drivers licenses with his test takers photos and the aspiring teachers' information.

Ewing says the vast majority of teachers who take the tests are honest, but changes are in store, including biometric voice scanning.

How voice enrollments and matching will work isn't spelled out. I would have thought that since ID photos were the problem, facial recognition might have helped. I mean, you have one guy with one face who took, and passed, the test like fifty times!



Action News 5 - Memphis, Tennessee

Is Residence Address an Important ID Management Detail?

Do we really need to worry about proof of address? (Economic Times)
It is possible to abandon proof of address altogether and accept an applicant's submission as authentic. Biometric tags and de-duplication software that works across multiple databases - driving licences, hospital records, school and college registers, insurance and bank accounts - would identify cases that call for further verification.

Sure, this means a lot of computerisation. So what?

Trust everyone's claimed address, verify those that give cause for doubt. This is integral to inclusive growth.
There are some really good points here.

At first I thought that, if not address, than some geographical descriptor would be necessary in many real world applications. Voting in state and local elections is geography dependent. Many public services are provided only to people in a given jurisdiction.

But author T K Arun makes a good point. In a world of perfect database interoperability and deduplication, residence address doesn't matter much, especially compared to the challenges and misery associated with having a huge population of people without ID.

From the individual angle, so long as an individual can only vote in one place, as long as they can only collect cash transfers intended for one group (for example they are prevented from simulteneously collecting subsidies for rice growers and fishermen), overall ID-based shenanigans will decrease.

On the service provider level, if databases are linked, two schools claiming to educate the same child (and billing the government for it) would have some explaining to do. For more along these lines, see Biometrics "Fix" Identity.

It's an interesting conversation and we may be headed that way, but for now, perfect interoperability and (single factor) deduplication isn't a reality.

But like we always say, don't let perfect be the enemy of good. Give the poor man an ID — even if he can't give a permanent residence address.

Wednesday, July 11, 2012

Canada, US Work Well Together on Border Issues

Canada-U.S. deal aims to smooth flow of refugees (Vancouver Sun)
the United States plan to join forces in order to better deal with "irregular flows" of refugees that turn up in North America or migrate within the continent, newly declassified documents show.

By 2014, the two countries will also begin routinely sharing biometric information about travellers, such as fingerprints.

And Canada is laying the groundwork for legislative and regulatory changes that will require all travellers - including Canadian and U.S. citizens - to present a secure document such as a passport or enhanced driver's licence when entering Canada. Such a document is already required to enter the U.S.
A border isn't really a big deal if those on both sides of it have the same rules about who can go in and out of the country.

The thing is, while sharing the world's longest international border and the world's largest trading relationship [PDF], Canada and the United States haven't harmonized their immigration and visa rules — and they don't wish to.

That's all well within the scope of each sovereign country's citizens to determine but it also implies that a lot of effort is required of both sides to make sure things operate smoothly. Biometric ID management technology can help.

Keeping Biometric System Vulnerabilities in Perspective

Biometric security hacks threaten to ruin the KeyLemon party (Wired)
As biometric security systems from companies such as KeyLemon are increasingly introduced to devices, spoofing attacks are becoming more common and sophisticated. The Tabula Rasa project aims to prevent these security breaches.
Lots of good stuff in the article. Just remember, lock-picking is spoofing, too, and if you use unattended facial recognition for access control, be very suspicious of that strange person that wants to "interview" you using her camera phone.

Tuesday, July 10, 2012

Kenya Moving Towards Biometric Voter Register

Kenya: Three Billion Tender Above Board, Says IEBC Boss (All Africa)
IEBC boss Ahmed Issack has admitted the delay in awarding the Biometric Voter Registration tender but denied foul play. Issack, the Independent Electoral and Boundaries Commission, chairman said his commission has not been threatened by any donor or vendor on the tender contrary to reports in the Star last week. He said the commission is not turning back on technology although it may not meet the huge expectations. "The regrettable delay in awarding tender and which must be the thing fueling speculation, is as a result of ensuring that due diligence is followed in the entire process," Issack said in a statement published elsewhere in this paper.

US Special Operations Command Wants Technology and Lots of It

Tech at the Tip of the Spear (GovLoop.com)
”USSOCOM is always interested in new ideas and evolving technologies generated by industry.” While some of the technologies Special Operations Command is looking into are weapons, vehicles, armor, and camouflage, a large portion of their “capabilities of interest” include advanced information technology.

For their biometric and forensic capabilities, SOCOM seeks mobile solutions to collect, compare, and match data as well as to exploit enemy networks in real time. They also seek portable field methods and systems to sense, detect, measure, and identify explosive composition and purity of explosive materials. Portable devices are also needed to detect hidden chambers, persons, or material. While such devices would be advanced sensors, they would also require mobile computing solutions.
Much more at the link.

India: Consulates in the US, UK and Pakistan to Begin Collecting Biometric Data for Visas

India to collect biometric data of all foreign visitors (Live Mint - WSJ)
The move comes in the wake of Indian investigators struggling to find out whether Syed Zabiuddin Ansari, alias Abu Jundal, an Indian arrested in connection with the November 2008 terrorist attack on Mumbai, had visited India on Pakistani passports after the attack. Jundal holds an Indian passport and two Pakistani passports.

At Least the Kids Can't Vote Twice in ARMM, Philippines

Biometrics do a good job at telling people apart, but they aren't any good for determining an individual's age independent of other reliable database information.

Fraud found in day 1 of Armm voters registration (Sun Star)
It was in Datu Odin Sinsuat that she first noticed the trend -- teens below the voting age were in the registration centers accompanied by people claiming to be their parents and herded together by people who, when asked, confirmed to be barangay workers.

Kiram (not his real name) stood outside the classroom at the Taviran Elementary School that had been converted into a voting center. He was clutching three copies of voters registration form and waiting for his turn behind the voter registration machine -- a finger scanner and web camera mounted on a computer that ran on special software.

De Villa, who was about to enter the classroom, saw Kiram and immediately asked for his age. He said he was 20 but gave the wrong birth year when pressed. A woman who immediately introduced herself as Kiram’s mother spoke up and said he was indeed 20 and was her third son.
This is the kind of story that causes the anti-biometrics crowd to say, "See I told you this stuff doesn't prevent fraud in elections." That's true, as far as it goes. Nobody should be promising that biometrics prevent fraud in elections.

In the Autonomous Region in Muslim Mindanao (ARMM) case, even though biometrics can't keep individuals that are by law too young to vote off of the voter roles, the ID technology, properly applied, can prevent any person voting multiple times. That's a good thing.

Biometric systems properly applied can drastically reduce the amount of fraud in elections. In elections, it's important to ensure that the margin of error (including fraud) is less than the margin of victory. For example: A 1% error (or fraud) rate in one direction doesn't translate to an electoral advantage in a 60%-40% election but a 5% illicit advantage makes all the difference in a 51%-49% election.

So, by helping to reduce fraud, biometrics can make it less likely that the margin of fraud will exceed the margin of victory in a given election.

Perfect is the enemy of Good. Return on Investment, not perfection, it the relevant metric.

Earlier posts on ARMM:
Philippines: Biometrics a Hot Topic in Autonomous Region
Philippines ARMM: Biometric Voter Registration Underway

Monday, July 9, 2012

Michael D. Kirkpatrick FBI Assistant Director in Charge of Criminal Justice Information Services (Ret.) to Discuss Biometrics & Law Enforcement at July #BiometricChat

When: July 19, 2012 — 11:00 am EDT; 8:00 am PDT; 16:00 pm BST; 17:00 pm CEST; 23:00 pm SGT; 0:00 JST

Where: tweetchat.com (hashtag #biometricchat

What: Tweet chat on Biometrics and Law Enforcement with Michael D. Kirkpatrick (@MDKConsulting)

Topics: The past, present and future of biometric ID management applications in law enforcement, interoperability, modalities.

To send questions for the #BiometricChat:
Email: SecurLinx blog
Twitter: @SecurLinx, hashtag #biometricchat

When John at M2SYS asked me to guest host the July #BiometricChat, I immediately thought of Michael Kirkpatrick. I'm happy to announce that he's agreed to join us. I offer my sincere thanks to both of them for the opportunity.

Michael Kirkpatrick
Michael D. Kirkpatrick, as the FBI's Assistant Director in Charge of the Bureau's Criminal Justice Information Services (CJIS) Division from January 2001 - August 2004, led the Division through profound IT changes especially relating to the application of biometric technologies to the challenges of law enforcement.

Back in the day (i.e. before 1999), fingerprint analysis for law enforcement purposes was a much different ball game. Everything was accomplished with paper, ink, and highly-trained, dedicated  fingerprint analysts. That made law enforcement biometrics pretty much the only biometrics game in town because there weren't really any commercial applications for that type of set-up. Sure, some professions required criminal background checks, but the fingerprinting part was mostly there to make it easier to catch people in the event they committed crimes at some later date.

Presently, the FBI maintains the world's largest collection of biometric data and facilitates information sharing between law enforcement organizations and a range of both public and private entities. The CJIS center handles more than 61 million ten-print submissions a year. Average response time for an electronic criminal fingerprint submission is about 27 minutes, Electronic civil submissions are processed within 72 minutes.

The successful transition from a paper system to an Integrated Automated Fingerprint Identification System (IAFIS), presented a range of technical, organizational and managerial challenges such as: What to do with all the paper records; What technical standards to apply to digitization; Determining what confidence level constitutes a match; How to receive input remotely and transmit results;  How to store the information securely; What policies to put in place; Determining whether current international agreements were adequate or forging new ones necessary. The list goes on and on.

Without the hard work sorting out these kinds of questions done by those at CJIS, biometric ID management applications, beginning with fingerprint biometrics, simply would not have nearly the impact in the public and private sectors that they do today. Michael D. Kirkpatrick was one of the many people who helped make it all possible.

Over the course of his career, Michael has done far too many interesting things in law enforcement and biometrics than can be listed here. Thankfully, he has posted a brief overview of some of his experiences at his site, here. He tweets at @MDKConsulting

We hope that you will spread the word among your colleagues and friends and join us Thursday, July 19 at 11am EDT.

Please send questions via:
Email: SecurLinx blog
Twitter: @SecurLinx, hashtag #biometricchat


We’ll publish the chat questions in an update to this post early next week.

Jamaican Fingerprint Fears and Revisiting the Issue of Biometric Time-and-Attendance Applications

Keeping up with this blog brings me to the web sites of newspapers all over the world. Most use pretty standard names (not that there's anything wrong with that), but a couple use names that are so memorable and charming that they have become my favorites. They are The Deming Headlight out of New Mexico, and The Gleaner of Jamaica.

Today The Gleaner has a piece on fingerprint biometrics for time and attendance, Fingerprint Fears, that reads like a flashback to 2009.

The arguments are well worn and the comments section is lively. But one thing that stands out is the state of Jamaican law on the subject of fingerprints. Evidently:
Under Jamaican law, a person can only be compelled to provide fingerprints in specific criminal matters. The law also allows an individual the right to refuse to give fingerprints.

Section 3A of the Finger Prints Act states that "where a person is taken into custody on reasonable suspicion of having committed an offence, that person's fingerprints and photograph ... shall not be taken unless the authorised officer informs the person of such matters as may be prescribed, and that (the person) has the right to refuse to have his fingerprints and photograph taken".
The article quotes a lawyer and the Justice Minister explaining that refusal to use a fingerprint time-and-attendance system is not grounds for dismissal for current employees. It does however seem that companies are within their rights to make future hiring contingent upon the agreement to use such a system.

Regardless of the peculiarities of the Jamaican situation, it has offered an opportunity to revisit some earlier posts that best covered this well trodden ground. Note: "Ghost workers" can be substituted for "buddy punchers" in any the posts quoted below.

Biometrics for Time-and-Attendance aren't that Controversial
Employers already have extremely sensitive information that, in the wrong hands, can be used for identity theft, harassment, discrimination and any number of other abuses. A long string of apparently random text characters (biometric template) cannot be used for any of these things.
Biometrics, Ghost Workers, ROI and Sharing the Savings
Adopting more efficient ID management systems creates winners and losers. In this case the losers are those who receive the ghost workers' salaries. While these individuals aren't necessarily sympathetic characters, they aren't necessarily powerless, either. By sharing the financial benefits of of better ID management with legitimate workers, the president of Guinea has created an "army" of organizational allies as he attempts to change the finances and culture of the military.
Farm of the Week: Producer clocks in with IT system to control costs
"It might sound hard, but more accuracy means more fairness, for both staff and customers," says Mr Machin. "Thirty percent of our costs are labour. The more we pin costs down, the more choice we have about how to distribute rewards. And the better we get at pricing our produce, the more customers we bring in."
That last one is one of the first posts at this blog and the article it links to (thanks to The Yorkshire Post, it's still active) remains one of my favo(u)rites.

Mobile Device Security Hardware Market Analysis: Now $430M; $1.9B in 2017

Mobile device hardware security expected to boom in 2017 (EE Times Asia)
The mobile device hardware security market is currently valued at approximately $430 million. It is projected that by 2017, the market will have grown and will be worth $1.9 billion. The market is currently largely made up of embedded chip security consisting of embedded chip security technology, such as ARM's TrustZone, and other semiconductor companies' security solutions. Other factors considered are revenues generated by secure elements for near field communication (NFC) and biometric sensors. However, this landscape will have changed in the next two years.

Philippines: Biometric Voter Registration Underway Autonomous Region in Muslim Mindanao (ARMM)

Comelec starts voters’ registration in ARMM (Inquirer News)
Commission on Elections (Comelec) chairman Sixto Brillantes Jr. said that they have started on Monday the 10-day voters’ registration period for the Autonomous Region in Muslim Mindanao (ARMM).

He told Radyo Inquirer 990AM over an interview that they have finished deploying their registration teams and machines and have started registration at 8 a.m. save for remote islands which will start listing voters a bit later within the day.
APRIL 23, 2012: Philippines: Biometrics a Hot Topic in Autonomous Region

Biometric Disruption and Disintermediation

India Continues Ambitious Effort To Biometrically Identify 1.2 Billion Citizens (Forbes)
Ultimately, the success of the program is not about the performance of technology, but the efforts of the people behind it. The same systems that can bring accountability and transparency can be used for mass-surveillance and digitized discrimination.
Hey, that sounds familiar.

Tarun Wadhwa is correct to focus on the organizational, entrepreneurial, aspects of UID and the disruption and disintermediation it has the potential to bring.

I believe this is the first time I've used the term disintermediation in the blog, though Fareed Zakaria used it in his iterview with Nandan Nilekani in the video here.

Disintermediation is a fancy word for the elimination of middlemen. In government programs it is often considered to be a good thing. But one of the challenges of UID is that "about 50% of the human race is middle-men and they don't take kindly to being eliminated."

Middlemen who add value in the supply chain aren't easily replaced by technology. The really smart ones adopt the technology that threatens their position, if they can.

Friday, July 6, 2012

The FBI Eyes the Future

Hello, Big Brother: FBI Is Building a Database of Iris Scans (Mashable)
By 2014, the FBI plans to test a database for searching iris scans nationwide to quickly track criminals, according to budget documents and a contractor working on the project.

The Next-Generation Identification system, a multiyear $1 billion program already under way, is expanding the server capacity of the FBI’s old fingerprint database to allow for rapid matching of additional physical identifiers, including facial images and palm prints.
Read all the way to the end for a discussion of the civil liberties issues from the inside with Tom Bush (former director if CJIS).

Two Big ID Management Projects in Africa

South Africa is rolling out its program to biometrically identify all social grant beneficiaries in order to curb double-dipping and ghost beneficiaries. (Engineering News)

 Nigeria is doing the same with pensioners. (Punch)


More posts on:
South Africa
Nigeria

Retail and CCTV Vendors are Catching on to Facial Recognition

The new face of CCTV surveillance (The Retail Bulletin)
“There have been huge advancements in both facial recognition analytics and in network camera technology, which is ultimately the source that the analytics have to work from.

“In particular HDTV cameras offer higher resolution video and enhanced clarity and sharpness, that complements the accuracy of facial recognition solutions making identification even simpler and more accurate.”
Retail outlets and CCTV vendors are catching on to the opportunities for a return on investment facial recognition technology provide.

The article neglects to mention, however, that the installed base of CCTV cameras is poorly suited to facial recognition.

Facial recognition is what it says: the recognition of faces. It's not top-of-the-head recognition; it's not profile recognition; it's not back-of-the-head recognition. In general, CCTV cameras have been installed to observe and/or record what people are doing, not who they are. They have been deployed to answer the question, "what's going on?"

This is changing and can be overcome by moving a camera down and changing its zoom to where it is capturing good face images. As CCTV installers become more familiar with facial recognition technology, results will improve dramatically.

Military Use of Biometrics in Afghanistan

The eyes have it: Biometric data and the Afghan war (The Economist)
Though The Economist obviously disagrees with the use of biometric technology in Afghanistan, the article can't help but describe the incredibly useful ways biometrics are applied by the military there.

India: President Enrolls in Biometric National Population Register

Pratibha Patil Enrolls in National Population Register (Outlook India)
"It gives me great pleasure to enroll for the NPR exercise. I appeal to all the citizens of India to enroll themselves at the earliest, as it is not just a matter of right but their duty as well," she said after her biometric enrollment including finger print and eye scan at Rashtrapati Bhavan.

Thursday, July 5, 2012

Following Attendance Scandal São Paulo City Council Self-Imposes Biometric System

After scandal, 42 of the 55 councilors say they are in favor of presence only with digital (O Estadão de São Paulo)
Google Chrome Translation (with slight edits)
After [this newspaper] uncovered fraud in the attendance record at City Hall, 42 of the 55 councilors said they were in favor of attendance at plenary sessions being recorded only by fingerprint. To change the bylaws of the house, you need the backing of 28 MPs.
The current system relies on passwords.

Nigeria Looks to Biometrics to Help with Border Security

Committees To Investigate Absence Of Biometric Capture Machines (Leadership)
The House of Representatives in Abuja on Tuesday directed its Committees on Aviation and Interior to investigate the absence of biometrics data capture machines at the nation’s entry points.

This resolution followed a motion by Rep. Emmanuel Ekon (PDP–Akwa-Ibom) and 23 others, which was unanimously adopted without debate when it was put to vote by the Deputy Speaker.
Nigeria can't be sure how much its unstable internal security situation is due to external forces until it gets better control of its borders.

It's telling that Nigeria's elected leaders are unanimous in their resolve to examine carefully how biometric systems might help. After all, Nigeria has a biometric election under its belt and it seems like the experience was a positive one.



h/t @m2sys

Indian State of Uttar Pradesh Isn't Waiting for UID

Uttar Pradesh to give foodgrain via biometric cards (Thaindian News)
Uttar Pradesh will computerise the public distribution system and issue biometric smart cards to its residents, an official said Thursday.

Chief Secretary Javed Usmani said foodgrain would be provided to people only through smart cards to flush out fake ration cards from the system.

In the first phase, 18 districts would be covered as pilot project.
Uttar Pradesh Isn't Waiting for UID. Judging by the scant information in this article, they're forging ahead anyway.

We mentioned here how Nandan Nilekani was creating competition for India Post in order to gain access to better services for delivering UID numbers to individuals.

Could the shoe now be on the other foot?

Is UID going to have to improve its performance in competition with states who appear willing to set up their own systems?

Wednesday, July 4, 2012

Another Good Site for Biometrics News: BiometricUpdate.com

The folks at BiometricUpdate.com have quickly established a solid presence on Twitter and at their site. Their stated mission is to provide daily news, opinion and information about the biometrics industry.

We've added them to the blogroll to the right. Consider giving them (and the others listed there) a look.

Video: UID's Nandan Nilekani Interview with CNN's Fareed Zakaria



A project to fingerprint 1.2 billion people (CNN)
Nilekani is the chairman of India's Unique Identification Authority. Fareed Zakaria hosts CNN's "Fareed Zakaria GPS" show.

UK: Government Abandons Major ID Management Projects

IT recruitment in public sector hits rock bottom (PC Advisor)
Major government projects involving the heavy use of IT contractors, that have been cancelled over the last two years, include the NHS national electronic database, second generation biometric passports, the ID cards programme, the Contact Point child protection database, and the development of new defence technologies.
Judging by the short description here, three of the four cancelled projects mentioned are related to ID management. Even the fourth, defence technologies, could have a large ID management component.

Summit of Central Africa leaders mulls biometric passports

Transitioning to biometric passports is on the agenda of the Economic Community of Central African States (CEMAC) meetings being held this month in Brazzaville.

UPDATE: Link to Afrique Jet was missing before.

Summit of Central Africa leaders (Afrique Jet)
CEMAC
Also on the agenda is CEMAC biometric passport for all member countries.

'The secure biometric passport will be progressively established and will coexist with the former passports so that there is no break,' Mr Ntsimi added.

Tuesday, July 3, 2012

Sahara Mall Bar Owners: Biometrics Bring Fewer: Brawls; Crimes Against Women; Customers

Now, punch in before entering bars at Sahara Mall (Hindustan Times)
All those who come to the Sahara Mall bars have to punch their thumb in the computerised machines, which also records the visitor's photograph. The machine can store up to 5,000 persons' records, after which the data is stored in a hard disk.

The mall management was prompted to install the biometric machine in the wake of increasing incidents of brawls and crimes against women. Sahara Mall, one of the city's oldest on the Mehraulli-Gurgaon (MG) Road houses five bars on its third floor. The spot earned a bad name due to frequent criminal cases in the recent past.
But really, a system like this doesn't make much sense unless bar staff or security officers use the photos and fingerprints to manage a list of people who have been banned from the mall for previous bad behavior and compare people to that list as they enter. Maybe that's what they are doing though the article doesn't mention it. Either way, it seems to act as something of a deterrent.


But the last sentence of the article really got my attention... 

 "While the safety measures have instilled confidence among women, bar managers rue that the footfalls have declined."

Maybe the headline should be:
Bar Owners Say Best Customers Fight a lot, Assault Women
According to one bar owner: "Since we got rid of all the brawlers and gropers this place is like a ghost town." 
[OK, I made that quote up.]

It's getting harder to tell bots and people apart

I'm pretty sure it's because the bots are getting smarter.

The odd alternatives to passwords (PC Pro)

Fiji Commences Biometric Voter Registration


Fiji
The voter registration systems have been provided by the Canadian Company, CODE, Inc and its biometric technology and electronic voter registry will help ensure accurate voter identification to eliminate voter fraud during elections.

Biometrics "Fix" Identity

Even if there is fraud in the identification process, biometrics can be used to fix a single identity upon an individual.

An article in today's Canberra Times about people smuggling brings home the point.
Despite some unauthorised arrivals' lack of documents, biometric capability is critical. In a few cases, unauthorised boat arrivals will be identified from international databases, particularly through fingerprints. Even if people cannot be identified, the collection of biometric data on arrival provides a basis for anchoring the identity of an unauthorised arrival, so that the Australian community can be confident it is dealing with one person and that further identity-shifting is difficult. It also leaves open the possibility of identification in the future. [Emphasis mine]
One classic use of identity fraud among professional criminals is the use of multiple ID's so as to keep a clean identity and a dirty identity. If possible, all the documents involved are "real" in that even the ID card related to the fabricated identity is issued by the legitimate authority.

When the the professional criminal with his family in the car is pulled over for running a stop sign in his neighborhood by a police man who goes to the same church, he presents his "real" ID. When he's picked up in the course of his job, say 1,500 miles away, with a trunk full of weapons and narcotics, he gives the police the ID containing bogus information.

The arresting officers call the ID authority who created the false ID card. Sure enough, he's in the database. No criminal record. Light sentence for a first offence and he can still go back to his life, get another ID, and go back to work, too.

The same pattern works well with fraud.

Pretty simple, right?

Well, yes — until biometrics.

Once ID issuing authorities institute biometric checks before issuing new ID documents, even a person who lies on their original ID application is stuck with only the one ID.* Further attempts to obtain additional ID's can be detected and investigated. Later claims of a false identity (or lost ID) can be unraveled.

This is something that might have given pause to the person who supplied Mr. Coriander with fingerprints. If he thought the only time those fingerprints could be used for a UID number, he might not have found the joke as funny.

*This applies to discrete ID management system. If ID databases aren't linked, it may be possible to maintain different identities in different databases.

Monday, July 2, 2012

Most Read Posts of June 2012

Thanks to all who visited and helped spread the word. In case you missed a couple, the following posts generated the most online interest last month.

Four Seventh Grade Girls Bring Facial Recognition to the People  (JUNE 1, 2012)

One-Time-Only ID Technologies (JUNE 4, 2012)

Canada Moving Toward Biometric Visitor Visas (JUNE 5, 2012)

What if? Online Real-Time Searchable Sensor Data (JUNE 12, 2012)

More Face Rec Tech for Entertainment (JUNE 12, 2012)

Jobs in Biometrics (JUNE 13, 2012)

Biometrics In Art: DNA Portraits (JUNE 15, 2012)

Does Apple's Siri store users' biometrics? (JUNE 28, 2012)

"Next Steps in ID Technologies" hosted by TechConnect West Virginia

Here's a record of the event as documented in the SecurLinx twitter feed and a couple of subsequent follow-ups by @m2sys and @BiometricUpdate. Many thinks to @TechConnectWVa and others for putting the event together.

UPDATE: I deleted the embedded version from Storify because it was making the whole homepage load exceedingly slow. It's too bad they don't offer a simple html export instead of the script that loads it from their servers.

You can still read the original content at Storify here.

Three Sides of the Same Coin

Late last week, while engaging in my routine news perusal, I came across a few items that while very different, struck me as being somehow connected:

Getting a facial (BCS.org - UK)

Reversing Poor Data Management Culture (This Day Live - Nigeria)

Coriander, son of Pulao, Aadhaar No 499118665246 (DNA India)

In order, they are: a high-level interview with a computer scientist interested in quantifying the behavior of the human face at both the macro and micro levels; a litany of failures to even bring order to — much less make the most of — a developing country's IT investments; and a high-profile case of how one individual can make an entire national effort look bad.

But this summary is, well, more summary: They are a visionary's perspective, a cat-herder's lament, and an embarrassing insubordination.


Each piece captures a slice of the dramatic interaction of humans and IT-based technologies (in these cases, biometrics and biostatistics) designed to identify people or interpret their physical state.

Together they inform some of the themes I'm always banging on about here. "ID management is about people." "It's not the tech, it's the people." "Technology is an management tool, but it can't run an organization by itself." "ID management systems are an amazing leap-frogging technology for the developing world." "ID perfection is not the proper metric, Return on Investment (ROI) is."

A closer examination of each article follows in...
A Visionary's Perspective,
The Cat-Herder's Lament - IT and Organizational Culture and
An Embarrassing Insubordination - It Takes a Human To Give Coriander an ID

A Visionary's Perspective

The Chartered Institute for IT has published a wide ranging interview, Getting a facial, with Professor Maja Pantic, from Imperial College, London.

Prof. Pantic has been working on automatic facial behaviour analysis. This type of research, if successful, could lead to a revolution in the way humans interact with technologies devoted to security, entertainment, health and the control of local physical environments in homes and offices.

The interview is long, wide-ranging, and worth reading in it's entirety.

I would, however, like to point out two passages that have great bearing on some of the themes we discuss regularly here.

Why computer science?
But with computers, it was something completely new; we just couldn’t predict where it would go. And we still don’t really know where it will go! At the time I started studying it was 1988 - it was the time before the internet - but I did like to play computer games and that was one of the reasons, for sure, that I looked into it. [ed. Emphasis added]

You never know where a new technology will lead, and those who fixate on a technology, as a thing in itself are missing something important. Technology only has meaning in what people do with it. The people who created the internet weren't trying to kill the record labels, revolutionize the banking industry, globalize the world market for fraud, or destroy the Mom & Pop retail sector while passing the savings on to you. The internet, much less its creators, didn't do it. The people it empowered did. 


Technologies empower people. Successful technologies tend to empower people to improve things. If a technology doesn't lead to improvement, in the vast majority of cases it will fail to catch on and/or fall into disuse. In the slim minority of remaining cases (a successful "bad" technology) people tend to agree not to produce them or place extreme conditions on their production and or use i.e. chem-bio weapons, or CFC's. There really aren't many "bad" technologies that people actually have to worry about. 


It makes far more sense to worry about people using technologies that are, on balance, "good" to do bad things — a lesson the anti-biometrics crowd should internalize. Moreover, you don't need high technology to do terrible things. The most terrible things that people have ever done to other people didn't require a whole lot of technology. They just required people who wanted to do them.


The interview also contains this passage on the working relationship between people and IT...

The detection software allows us to try to predict how atypical the behaviour is of a particular person. This may be due to nervousness or it may be due to an attempt to cover something up.

It’s very pretentious to say we will have vision-based deception detection software, but what we can show are the first signs of atypical or nervous behaviour. The human observer who is monitoring a person can see their scores and review their case. It’s more of an aid to the human observer rather than a clear-cut deception detector. That’s the whole security part.

There’s a lot of human / computer interaction involved.
It's not the tech; it's the people. 


Technology like biometrics or behavioral analysis isn't a robot overlord created to boss around people like security staff. It's a tool designed to help inform their trained human judgement. This informs issues like planning for exceptions to the security rule: lost ID's, missing biometrics, etc. Technology can't be held responsible for anything. It can help people become more efficient, and inform their judgement, but it can't do a job by itself.


Back to Three Sides of the Same Coin