Monday, February 13, 2012

French Consumers Prefer Fingerprints over Mobile Phones for Retail Payments

Survey Shows More Interest in Biometrics than Near Field Communication (NFCWorld.com)
69% of the 1,008 people surveyed by Ifop for Wincor-Nixdorf said they were either very or quite in favour of replacing PIN codes with fingerprint biometrics at the point-of-sale, and only 36% were either very or quite in favour of using an NFC phone to make a purchase. 39% were quite opposed to the idea and 25% were very opposed.
Support for NFC actually dropped from last year's survey.

What explains this?
Is it something to do with NFC tech specifically?
Do people trust their credit card company/bank more than they trust their mobile service provider/Google/Apple?
Is smartphone penetration in France so low as to limit interest in a NFC payment system?
Is it that if you lose your phone, you can't buy a new one because you don't have a phone and you'll starve because you can't use your phone to buy food (less likely, I'll admit)?

UPDATE:
Following Vulnerabilities, Google Disables Pre-Paid Card on Google Wallet App (GottaBeMobile.com)
After a series of two vulnerabilities were discovered that targeted Google Wallet, Google’s mobile and digital wallet app on the company’s Android smartphones, Google has now decided to disable the prepaid credit card feature on the app.
...
The app makes use of NFC, or near field communications, technology. Rather than swiping a plastic credit card through a magnetic reader, users can pay for physical goods at retail stores by waving their NFC-enabled smartphone next to an NFC reader. In this manner, Google anticipates that smartphones and wallets would converge and eventually credit cards would become obsolete as users would only need to carry their smartphones to make and initiate payment.



h/t @ksikeyboards
h/t @Ess_ID_Security

UPDATE - United States: ID Technology & the Bill of Rights

I made some slight edits to the ending of the original post for clarification and to make the original more smoothly flow into the update. The original post is here.

The Fifth Amendment in the Digital Age (ZDNet - Identity Matters Blog)
Basically, if the password is a physical thing she has, than the Fifth Amendment does not protect it. But if the password is deemed to be something the defendant knows, it is protected.
...
To illustrate the principle, the Supreme Court has previously explained that a witness might be “forced to surrender a key to a strongbox containing incriminating documents,” but not “compelled to reveal the combination to a wall safe.”
As the post points out, biometric technologies complicate this further.

The Fifth Amendment guaranty that "No person shall... be compelled in any criminal case to be a witness against himself," applies (outside the military) to those who have already been indicted by a grand jury, are standing trial, and are being asked to assist in their prosecution. The example above doesn't seem to prevent the police from hiring a locksmith to open the wall safe; it merely prevents the police from compelling the accused to help them.

The Fourth Amendment is much more relevant to privacy in the ordinary sense.

The Fourth Amendment guarantees that:
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."

"Warrantless mobile device searches" (Google search) are a much hotter digital age privacy issue and it's the Fourth Amendment that seems to apply to those searches, though not necessarily to this case as I'm pretty sure they have a warrant for the laptop.

UPDATE: The attorney for the defense, having lost on the Fifth Amendment is appealing the Fifth Amendment ruling and seeking refuge in the Fourth Amendment.

Woman who pleaded Fifth in password case now citing Fourth
He said the Fourth Amendment is a better argument “for us and for the public in general.”

Fricosu’s case drew interest from civil rights groups who argued that current law needs to evolve to meet the nuances of the digital age. The prosecution, however, argued that hiding behind a password and encrypted data would make prosecution impossible in the future.

Dubois says the Fourth Amendment argument ties into the Fifth Amendment, which is also “about due process of law and fundamental fairness. ”


The court rejected the Fifth Amendment argument that focused on the password, an identity management technology, saying that the password is more akin to a physical key than a safe's combination (see above). The defense appeal of this judgement keeps the identity management issues in this case alive. The Fourth Amendment question seems to focus on the contents of the laptop and not access to them.

Still, it seems like this case has a long way to run.

Poorest of the Poor Expect to Benefit the Most from India's UID

This won't be new to regular readers but it can't be repeated often enough. World's biggest biometric ID scheme forges ahead (BBC)
Among those in the queue is Kamala, a daily wage labourer.

It's people like her, the poorest of the poor, who are expected to benefit the most from the UID. They have no proper identity papers and therefore no access to services such as subsidised food rations, a phone connection, even a bank account.

"It's so difficult to get anything done without a proper identity," she says. "We're often forced to pay bribes to get subsidised grains or fuel.

"With the UID I hope things will improve - we can buy cheap food and I can help educate my children."
Technically, the challenge India has set for itself — a unique, legitimate ID for every individual in society — reminds me of the polio mass immunization efforts of the 1950's and the goal is of no less importance.

A unique, legally recognized individual identity is a prerequisite for any sort of decent society. It is an infrastructure without which many things those in the developed world take for granted simply cannot exist: compulsory primary education, successful immunization against (and treatment of) preventable communicable disease, social safety nets, effective democracy, etc.

A legitimate ID is a prerequisite to full participation in the modern world.

The Crime Wave of 1920 and the Making of the Modern FBI

Before the dawn of the Twentieth Century, The Bertillon System was the standard for biometric identification.

In 1903 the New York state prison system had begun to use fingerprints. By 1908, all the branches of the U.S. military had adopted fingerprints. In 1924, an act of congress established the Identification Division of the FBI. The IACP's National Bureau of Criminal Identification and the US Justice Department's Bureau of Criminal Identification consolidated to form the nucleus of the FBI fingerprint files (source - and a very interesting site in its own right).

How did we get there? Read on.

The Wall Street Bombing That Made Hoover and the FBI (Bloomberg)
Shortly after noon on Thursday, Sept. 16, 1920, a powerful bomb hidden in a horse-drawn wagon exploded at the corner of Wall and Broad Streets in Manhattan. It was a pleasant late-summer day, and throngs of people had been out enjoying a lunchtime stroll, a brief respite from the great money machine, the center of American capitalism.

Now blood ran in the streets where the first U.S. Congress had convened and the Bill of Rights became law. Shrapnel scarred the walls and shattered the windows of J.P. Morgan and Co., America’s most formidable bank. The bomb killed at least 38 people and injured roughly 400. It was the deadliest terrorist attack in U.S. history, a distinction it held for 75 years. Its force reverberates today.

In Washington at that hour, J. Edgar Hoover, 25 years old, was putting the finishing touches on the federal government’s first counterterrorist force, the General Intelligence Division. Hoover wrote that he intended to combat “not only the radical activities in the United States” but also those “of an international nature”; not only radical politics, but “economic and industrial disturbances” as well.

...

Walk to the corner of Wall and Broad Streets today, and you can run your hands over the deep gouges left by the 1920 bombing. You will have to look harder to see the cameras that track your steps -- a 21st-century tribute to Hoover, the architect of the modern surveillance state. Every fingerprint on file, every byte of biographic and biometric data in the computer banks of the government, owes its origins to him.


See also:
The Bertillon System: An Early ID Management System
The History of Fingerprints (and the Death of the Bertillon System)

Sierra Leone: Amputees Association President Registers to Vote Without Biometrcs

The only biometric that everyone can provide is DNA and DNA isn't even remotely practical for voting. Good biometric deployments will plan for exceptions to the identity management routine.

Jusu Jaka Registers for 2012 elections (Awoko.org)
Alhaji Jaka will be one of hundreds of exceptional cases to go through the registration exercise without completing the process one hundred percent.

As President of the Amputees Association, Alhaji Jaka is armless, being a victim of rebels’ amputation spree during the rebel invasion of Freetown on 6th January 1999. He uses his arms with the help of a metal formulation attached to his body which he calls, ‘prospective’. He therefore did not thumb print his registration form. Thumb printing is one of the key elements in the Biometric voter registration process.

Infosec Professional Interviews SecurLinx CEO Barry Hodge on Information Security Challenges

Interview Series - Barry Hodge CEO SecurLinx Corporation (Infosec Professional)

The questions are:

♦ How has information security changed in the last 3 years?

♦ What do you think are the main threats facing organisations in 2012?

♦ Are organisations ready to deal with those threats and what can they do to protect themselves?

♦ The last 3 years has seen global organisations make significant in roads to protect data from a logical and network perspective. Does physical access control need to play a greater part and are organisations aware of it's benefits?

♦ Infosec has now become it's own profession, with job titles, budgets and certifications. What challenges do infosec professional face on 2012?

♦ What are the key questions your clients ask when looking to select a product or services offering? Experience, RoI, cost etc?

♦ With the global credit crunch effecting budgets across all areas, is security now seen as a luxury good for many projects?

I'll include only one answer here because I want you to click through to the whole interview. Here's his answer to the last question:
Security is looked at by most companies as a cost of doing business and if my competitor isn’t investing, I can let it go too. My personal opinion is that security can be a competitive advantage if it increases employee productivity and decreases cost. It is our job to design and implement solutions for our customers that do just that. Technology should facilitate the provisions of better security and lower the cost of ownership to the organization. I believe that is possible today.

SecurLinx Signs Definitive Agreement to Acquire ITM Associates

Press Release - Morgantown, WV - February 13, 2012

SecurLinx Corporation has agreed to acquire the assets of ITM Associates, Inc. of Rockville, MD. Founded in 1993, ITM has developed longstanding relationships with key accounts in both the government and commercial markets. These contractual relationships are included in the transaction.

The acquisition of ITM is a significant step in SecurLinx’ strategic plan to expand its presence in the biometric identification and security market. “ITM has a successful history and solid reputation for providing innovative, targeted and high quality commercial products and services to government and commercial customers that we can leverage immediately,” said SecurLinx CEO Barry Hodge. According to Hodge, SecurLinx will utilize ITM’s technical experience and expertise to help support its goal of making SecurLinx "the most advanced and cost effective biometric solution provider in the industry.” Additionally, SecurLinx will work to expand ITM’s existing customer base which currently includes the Environmental Protection Agency and Verizon Communications.

“The merger of SecurLinx and ITM is an exciting development,” said Bob Procelli, former COO and co-owner of ITM, “I was impressed with SecurLinx biometric identification technology when I first met Barry and his team in 2010. “But it was Barry’s vision for growing the company and expanding into new markets that impressed me the most.” According to Procelli the combination of SecurLinx and ITM is a “perfect fit of cultures, customers, capabilities and products that will be a valuable asset for meeting the goals set out by Hodge.”

All ITM employees will be retained as part of the agreement. “We welcome the addition of ITM’s customers, products, and talented staff to SecurLinx” said Hodge.

About SecurLinx: A wholly owned subsidiary of SecurLinx Holding Corporation (FRA: S8X) and located in Morgantown, West Virginia, SecurLinx is an advanced technology and software development company. The Company offers middleware products and systems applied to information sharing, secure access, and biometric identification. SecurLinx adds increased security, productivity, and seamless information management solutions in targeted markets where secure access to physical locations or information sharing networks is critical to the enterprise.

About ITM Associates: ITM provides products and services that make businesses more profitable and prosperous by bridging the gap between business operations and the enormous potential of emerging technologies. ITM's staff of professionals designs, adapts and integrates technology to (1) eliminate or reduce time-consuming information processing tasks, (2) assist executives to make more informed and timely decisions, and (3) achieve greater efficiency by extending internal information systems to customers, vendors, and strategic partners.

Big Data's Impact in the World

Privacy advocates tend to latch onto biometrics as a convenient way of expressing concerns about a world driven by Big Data even though biometrics will only ever be a tiny slice of the data pie.

Big data does, however, present opportunities and challenges that are well worth considering. The opportunities are so great that big data techniques will, and probably should be, adopted. The challenges to individual privacy are real, too.

This article provides a great overview of what is becoming possible and where we may be headed.

The Age of Big Data (New York Times)
Data is not only becoming more available but also more understandable to computers. Most of the Big Data surge is data in the wild — unruly stuff like words, images and video on the Web and those streams of sensor data. It is called unstructured data and is not typically grist for traditional databases.

But the computer tools for gleaning knowledge and insights from the Internet era’s vast trove of unstructured data are fast gaining ground. At the forefront are the rapidly advancing techniques of artificial intelligence like natural-language processing, pattern recognition and machine learning.

Those artificial-intelligence technologies can be applied in many fields. For example, Google’s search and ad business and its experimental robot cars, which have navigated thousands of miles of California roads, both use a bundle of artificial-intelligence tricks. Both are daunting Big Data challenges, parsing vast quantities of data and making decisions instantaneously.

The wealth of new data, in turn, accelerates advances in computing — a virtuous circle of Big Data. Machine-learning algorithms, for example, learn on data, and the more data, the more the machines learn. Take Siri, the talking, question-answering application in iPhones, which Apple introduced last fall. Its origins go back to a Pentagon research project that was then spun off as a Silicon Valley start-up. Apple bought Siri in 2010, and kept feeding it more data. Now, with people supplying millions of questions, Siri is becoming an increasingly adept personal assistant, offering reminders, weather reports, restaurant suggestions and answers to an expanding universe of questions.
That's just a sample. It's well worth reading the whole thing.

Friday, February 10, 2012

Mirror Displays Animal Heads that Mimic Facial Expressions

A 3-D animal avatar as your reflection (PopSci.com)
Not biometrics, but a cool use of some of the technologies we use for facial recognition, nonetheless.

Do not attempt to adjust your radio, there is nothing wrong. There isn't any sound with the video.

.

Ukraine: Parliament Overwhelmingly Rejects Biometric Passport

Not too sure what's going on here Lawmakers support Yanukovych's proposal not to introduce biometric passports (Kyiv Post)
A total of 304 out of 394 MPs registered in the hall voted on Thursday for the president's proposal to reject the law on documents confirming the identity and citizenship of Ukraine.
Other posts on the subject...


ht/ @m2sys

Samsung launches Smart TV with facial, voice recognition

The Future of Smart TV, NOW (Hindustan Times)
Wii-like motion controls will enable users to select apps, browse the web or change the channel by moving their hand through the air. The built-in camera on the ES8000 is also equipped with facial recognition technology that can automatically log you on to your Smart Hub and VoIP service Skype without needing a password or ID.

Thursday, February 9, 2012

TSA Extends Contract with Biometric Services Organization

TSA Renews Security Pact with NATA (Aviation International News)
The Transportation Security Administration (TSA) has approved a five-year extension of its partnership authorizing National Air Transportation Association Compliance Services (Natacs) to continue as a trusted fingerprint facility to process biological and biometric information for general aviation and commercial aviation worldwide.

Natacs, a partially owned subsidiary of NATA, has been partnered with the TSA since 2002. Under the revised and extended agreement, Natacs can continue to provide all pre-enrollment, enrollment, fingerprint collection and secure data transmission for TSA-conducted background checks on tens of thousands of aircrew members and flight students each year. The agreement expires in December 2016.

India: UID Costs Plummet as Accuracy Remains High

An unparalleled exercise (The Times of India)
♦ 99.86% of the population can be enrolled and uniquely identified. The other 0.14% is enrolled manually.
♦ 99.965% of all duplicate enrollments are correctly caught.
♦ A single deduplication originally cost Rs 20, now it's Rs 2.75 (from forty cents to six cents, US)
♦ The cost of an enrolment station dropped from Rs 3 lakh to Rs 1 lakh in one year. (from $6,060 to $2,020)

Much more interesting detail at the link.

Wednesday, February 8, 2012

Rhode Island: City Worker Vandalizes Biometric Time Clocks

Another local news piece that captures the economic and political angles of biometric ID management. This one's from Rhode Island.




An East Providence city worker has been fired and is in trouble with the law after police said they caught him on hidden camera tampering with a time clock.

Scott Cook, 50, of East Providence pleaded not guilty to one count of vandalism,a misdemeanor. Police said he used a ballpoint pen to scratch a biometric reader on a time clock at the city's Department of Public Works yard.

DPW employees are required to scan their finger when clocking in and out of work each day. City officials said the technology was put in place to clamp down on "buddy punching."

"[The reader] ensures the data collected by the device is linked to an individual which allows us to pay people with taxpayer money to a high degree of certainty it’s correct," said City Manager Peter Graczykowski.
Observations:
♦ Fingerprint biometrics work well for time-and-attendance, delivering a substantial return on investment.
♦ Buddy-punching is a real problem, costing taxpayers and shareholders who-knows-how-much money.
♦ Local governments forced by declining tax revenues to tighten their belts see better ID management techniques as an attractive way to save money.
♦ Buddy-punchers don't like taking a pay cut.

See also:
What Human Resource Managers Can Learn from the President of Guinea's Move to Eliminate Ghost Workers (relevant to managing a transition from loose T&A policies, to more rigorous biometric techniques).

The Economics and Politics of Biometric Time and Attendance in State Bureaucracies



h/t @m2sys

US: Biometrics-Based Global Entry Program is Here to Stay

DHS Announces Permanent Global Entry Program (Travel Agent Central)
The Department of Homeland Security (DHS) Secretary Janet Napolitano announced the publication of a final rule that would establish Global Entry—a U.S. Customs and Border Protection (CBP) voluntary initiative, which allows expedited clearance for pre-approved, low-risk travelers.

DHS says the move will streamline the international arrivals and admission process at airports for trusted travelers through biometric identification—as a permanent program.

“Global Entry expedites the customs and security process for trusted air travelers through biometric verification, while helping DHS ensure the safety of all airline passengers,” said Secretary Napolitano. “Making Global Entry permanent will improve customer service at airports across the country and enable law enforcement to focus on higher-risk travelers.” [emph. mine]
This little bit also caught my eye:
The program is available to U.S. citizens and U.S lawful permanent residents, as well as Mexican nationals.

Citizens of the Netherlands may also apply under a special reciprocal arrangement that links Global Entry with the Dutch Privium program in Amsterdam. Canadian citizens and residents may participate in Global Entry through membership in the NEXUS program.
That covers NAFTA (Canada-US-Mexico). The Netherlands represents a toehold in the Euro area. Hopefully these few existing relationships combined with the stated commitment to automation and emerging eGate technology sets the stage for a revolution in the international travel bureaucracy.

UIDAI launches online verification of Aadhaar numbers

Authentication service will be free of charge until December 2013 (Economic Times)
The Unique Identification Authority of India (UIDAI) on Tuesday launched its online authentication of Aadhaar numbers facility, which is proposed to help banks, telecom companies and government departments authenticate an Indian resident, via mobile phones, computers, tablets or other devices, connected to the internet.

New Mexico: Access to Holloman Air Force Base Requires a Fingerprint

New DBIDS requirements ensure safety, ease of access (Holloman Air Force Base)
After a brief hiatus to upgrade the software on the 49th Security Forces Defense Biometric Identification System, as of Feb. 1 hand-held scanners are being used again at all three gates at Holloman AFB.

Using barcode technology and fingerprints to verify the access authorization of everyone entering the installation, DBIDS is the latest step in helping security forces here improve safety and security for the Holloman community and its resources.

Multifactor Authentication, Middleware and the Online Security Arms Race

Julie Sartain at has an article at techworld.com that describes some of the new threats that have necessitated the adoption of multifactor authentication for online transactions and the variety of technologies available to augment standard username/password authentication, such as:

♦ Risk-based authentication
♦ Phone-based authentication
♦ Versatile authentication platforms
♦ Image-based authentication and, of course,
♦ Biometrics
As everyone in the security business knows, there is no perfect answer. Gartner's Allan points out that "whatever the desirable level of assurance, it has to be balanced against cost (deployments for hundreds of thousands of users are very cost sensitive) and user experience. We know that bank customers may change their banks if new security features such as authentication degrade the user experience: in a survey a couple of years ago, Gartner found that 3% of customers had done so, and a further 12% considered it," adds Allan.
Because there's no perfect answer, the challenge is in how to adopt new technologies that show positive return on investment without tying a mission-critical business process up in something that might not be the optimal solution over the longer term. How do you adopt new technologies in a way that preserves your ability to continue to adopt new technologies?



Our CEO, Barry Hodge, points out via Twitter that the move to multifactor authentication broaches the subject of middleware.

Middleware, as it relates to this discussion, is the software components that will allow the new authentication factor to interact with the existing authentication scheme and broader business processes.

But not all middleware is created equal.

Middleware can be written to facilitate a custom integration, or it can be written as a more flexible software layer that makes future integration decisions and changes less costly. A hardware analogy might be the difference between a soldering iron and a USB port. Both get the job done but involve entirely different levels of commitment.

Well written middleware components, such as those we've developed here at SecurLinx for biometrics, allow flexibility by reducing an enterprise's switching costs and the costs of adopting future techniques and technologies that may offer a significant returns on investment.

Middleware isn't really a glamorous topic — no Tom Cruise movies, severed eyeballs or rubber fingers — but it's incredibly important and becoming more so.

Tuesday, February 7, 2012

Privacy: How to Hide From Google

"If you are not paying for it, you're not the customer; you're the product being sold."
—blue_beetle, Metafilter discussion.

In yesterday's post, EPIC Fail, I took the privacy group Electronic Privacy Information Center (EPIC) to task for taking out it's frustrations with Google & Facebook, which are organizations, by lobbying for a ban on a technology: facial recognition.

If you share EPIC's frustrations but would like to channel them in a more productive way, Wired offers some helpful hints in a "How-To Wiki": Hide from Google

Instead of using what influence they have on trying to ban technology, groups like EPIC should be doing a better job of educating the public about the privacy implications of their everyday activities, very few of which have anything even remotely to do with facial recognition.

Helping people to understand technology so as to make informed decisions about what to share and what to keep private is a noble endeavor (see Wired article above). Going over their heads to limit their choices is not.

Often, however, EPIC is quite good at educational efforts. This is demonstrated by their role in the organization of, and participation in, the Twitter privacy chat, #PrivChat (which begins in 8 min. and features Microsoft Chief Privacy Officer, Brendon Lynch).

This is when they're at their best.

Retail Marketing Technology Online and In Person

Not really biometrics related, but...
Software mines security footage to help business owners see what people do once they're inside the store (Technology Review)


"The huge success of online shopping and advertising—led by giants like Amazon and Google—is in no small part thanks to software that logs when you visit Web pages and what you click on. Startup Prism Skylabs offers brick-and-mortar businesses the equivalent—counting, logging, and tracking people in a store, coffee shop, or gym with software that works with video from security cameras."
Online retailers are able to free-ride on investments made by their brick-and-mortar competitors (see showrooming). They also have more powerful tools available to them for the purposes of analyzing detailed reports of user activity on retail websites. Why, the page I linked to for this story has fifteen programs that track your interaction with the linked page and TechnologyReview.com isn't even selling anything directly. The image to the left shows the list as compiled by the Ghostery add-on for Firefox.

If brick-and mortar retailers can't learn as much about customers in physical stores as web retailers know about user experiences, they must compensate in other ways or they're going to continue to struggle.

See also:
Target fights Amazon showrooming with plea for special product lines (ExtremeTech.com)