Wednesday, August 18, 2010

Siemens getting roughed-up in the Bulgarian press

New Crash Looms for Bulgaria's Biometric ID System
novinite.com (Sofia)
The reason is the fact the maker of the software, the German Siemens, had not delivered the needed forms, Dimitrov said, adding the company is not fulfilling most of their commitments.

According to the Deputy Minister, by May 30 Siemens had to deliver 400 000 covers for the new biometric data passports, but only 393 000 were received two and half months later, while nothing has yet arrived from the additional 300 000 covers, ordered by the Interior.
In a biometric passport deployment like this, software development and passport manufacturing are two very different functions. They have to meet somewhere, though, and Siemens is the prime contractor. Nevertheless, it's difficult to see how an original shortfall of only 7,000 passport covers explains the difficulties associated with the Bulgarian passport deployment.

For background on Bulgaria's experience with its biometric passport rollout, see this article of April 23, 2010 from the Sofia Echo.

Indians to receive UID number by February

All citizens will get a 10-digit unique identity (UID) number by February. The biometric card will have 13 mandatory things such as the impression of your eyes and fingerprints and all information about your family.
Crore = 10,000,000
Currency:
Rs. 50 = USD 1.75 (8/18/2010)

Tuesday, August 17, 2010

Phillippines Bureau of Immigration adopts biometric Time-and-Attendance system for all staff

To instill discipline and professional work ethics in the bureaucracy, the Bureau of Immigration (BI) implemented a policy of strictly requiring its officials and employees to personally register their daily attendance through a biometrics-based ‘bundy clock’ system.
It bears repeating: Systems like this can help the people get good value from their public servants.

Human-Trafficker & repeat offender busted by fingerprint ID system

Orozco-Larios was driving a 1998 Pontiac minivan when a Seward County sheriff's officer stopped him and found that Orozco-Larios and his eight passengers were illegal aliens. Four passengers were female children who were not accompanied by parents.
I wonder what work Orozco-Larios had in mind for the four unaccompanied female children.

These technologies can be a real force for good in the world.

See also: AmberVision to begin operations in Mexico, especially the video comments by Guanajuato, Mexico Mayor Niceforo Guerrero.

AmberVision is a non-profit application of SecurLinx technology dedicated to returning missing persons to their families.

Monday, August 16, 2010

California gym uses fingerprint sensor instead of entry card

SacBee.com
At 24 Hour Fitness, the entire fingerprint isn't actually scanned; random points on the print are recorded and then assigned a unique number, said regional vice president Troy Croghan. And the company never sells member information, he said.

Although the new system is optional, 97 percent of members who have been asked have signed up, Croghan said.

"For a majority of our members, this has proven to be an easier way to gain access to the club," he said.

Croghan also touted the increased security with the elimination of lost or stolen membership cards, as well as the green benefits of no longer depending on plastic cards.

It's good to see more articles attempting to inform readers of how biometric identity management technologies work and focusing on a cost-benefit analysis rather than lazily tossing around terms like "fingerprinting" and "Big Brother".

Gina Kim of the Sacramento Bee did a great job on this article.

UPDATE:
For a useful counterpoint, see this article on the same event. Find an uninformed gym user, a company man and two "privacy advocates" and the piece pretty much writes itself!

New Zealand and Australian immigration officials have begun sharing fingerprint information

NZHerald.co.nz
"It's a small scale arrangement but it's significant in that this is the first time that we have been running a biometric matching agreement international from an immigration point of view."

Bilateral agreements are often much easier to negotiate and implement than multilateral agreements.

Friday, August 13, 2010

Security Industry Association opposed to bill restricting use of biometrics security solutions in Alaska

SourceSecurity.com

Hot on the heels of the Canadian Privacy Commissioner's attack on fingerprint biometrics for medical school applicants comes word that Alaska is contemplating:
Bill (SB 190) from Alaska State Sen. Bill Wielechowski (D-District J) mandates that "A person may not retain or analyse, or disclose or distribute to another person, biometric information on an individual without first obtaining the informed and written consent of the individual" (Law enforcement and other parties authorised by state or federal law would be excluded).

The text of the bill is available here.

It seems like the bill is primarily concerned with DNA. If the bill limited itself to the restriction of DNA analysis, it would make more sense.

The issue - Biometric identification

TES.co.uk
When an image of a child’s fingertip is taken, most of the data is discarded, but certain points of the image are remembered and converted into an algorithm - a series of letters and numbers. This is the data that is stored and matched against children’s fingertips on a daily basis. “It would be extremely hard to reverse the process and turn the numbers back into an image,” says Mr Rossiter. “All you would have is a series of random points.”

Kudos to TES Connect for this balanced, informative, and fair article.

Tucked away at the bottom of this article is a very good memorandum offering guidance from the Information Commissioner’s Office [UK]. It can be can be found here in PDF format.

Thursday, August 12, 2010

British Government: Anti-RFID passport cover 'preys on fears'

A Home Office spokeswoman said: "The data encoded to the chip in the biometric passport is securely stored and contains no more personal data than the information printed on the data page of a passport.

"There is no evidence to suggest anyone's personal data has been stolen from a passport's RFID chip. The passport chip does not have the same communication protocol and therefore it is not physically possible for the chip to be read from the distance suggested."
I've made no secret of my curiosity about the RFID-blocking passport holder.

The Home Office seems to be responding to the article that inspired
this post (and probably many others).

Biometric cards save grain worth Rs. 20 cr. a month

Bangalore: Issue of biometric bar-coded ration cards to households in the last few months by the Food and Civil Supplies Department has helped eliminating nearly 8.5 lakh bogus ration cards from PDS.
Glossary:
lakh = 100,000
crore = 10,000,000

These technologies can increase the efficiency of social safety nets, reducing corruption and increasing the likelihood that the public will support governmental efforts to reduce poverty.

The Indian government has approved the inclusion of information on caste in the ongoing population census.

The controversial decision was taken by a group of ministers, headed by Finance Minister Pranab Mukherjee.
The enumeration of caste in India has evoked a divided response, even as the pressure of other backward class (OBC) groups forced the ministerial panel’s nod. The last caste census was carried out in India in 1931.
Janata Dal-United (JD-U) member Sharad Yadav also joined the protests, urging Speaker Meira Kumar to allow the protesting members to speak over the matter and ask the government to explain its position. 
We've drawn attention to the Indian census before, focusing mainly on the technological challenges India faces in attempting to create a comprehensive multi-modal biometric register of its adult population.
As these three articles indicate, the challenges aren't limited to the technological realm. The social challenges associated with the effort are gargantuan as well.

Wednesday, August 11, 2010

Privacy commissioner seeks to block finger-printing of Canadian med-school applicants

Canada.com (Link was broken earlier, fixed now. UPDATE: Now altogether dead.)
UPDATE: A summary of the article is here.

This article has it all:
  • Abuse of the term "fingerprinting" (see also, this post).
  • International trade & politics
  • Inflated expectations of privacy
  • A public official called a Privacy Commissioner
The long and short of it is that Canadian medical schools rely on the MCAT admissions test administered by an American firm: the Association of American Medical Colleges (AAMC). This firm, in order to maintain its value proposition, uses a pretty rigorous identity management regime that includes the use of a fingerprint biometric so that it is very difficult to take the test for someone else.

Now anyone who is on the demand side rather than the supply side of of the medical industry (or who isn't a Privacy Commissioner) is likely quite comfortable with the status quo. After all, if you really want to enter into a profession that allows you to prescribe medication, make people unconscious, cut people open, hold life in your very hands while being highly regarded by society and well compensated for your efforts, is identifying yourself with a high degree of certainty too much to ask?

The Privacy Commissioner of Canada, however, has a useful bogey man: The Patriot Act. The official name of the law is the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 and its 131 pages can be read here.

The Privacy Commissioner is concerned that Canadian citizens that take the MCAT and only apply to Canadian medical schools could one day have their fingerprint record accessed by the U.S. government, because those records are stored in the United States, and has found that this state of affairs violates Canada's Personal Information and Electronic Documents Act (PIPEDA) (I don't get the acronym either).

I'm neither a lawyer nor an expert on the Patriot Act so I will withhold judgment on the likelihood that a non-terrorist, Canadian MCAT taker who never applied to an American medical school will have their civil rights violated by the U.S. government using a subpoena of the AAMC under the Patriot Act. Curiously, the Privacy Commissioner, who hopefully is a lawyer and an expert on the Patriot Act, makes no such judgment, either. I searched in vain for the legal documents relevant to the case and perhaps she addresses the likelihood there. Nevertheless, the concerns of the Privacy Commissioner aren't so well founded that she can produce any medical school applicant that has suffered at the hands of the AAMC and Patriot Act, but one wouldn't be doing one's job as Privacy Commissioner if one waited for actual things to happen before launching legal action.

There are some simple things that the AAMC could change that would seem to ease the Commissioner's stated concerns, such as storing those records in Canada or gaining informed, expressed consent from the test takers, but
Stoddart is asking the court to order AAMC to develop an alternative procedure for verifying the identity of people registering for the MCAT in Canada that does not involving collecting fingerprints.
I have an idea. A private detective will follow all Canadian medical school applicants from the time they take the MCAT to the time they enroll in a medical school.

Total cost: $25,000 per test.

All Canadian MCAT test takers will have to take this form of the test; we can't have impoverished aspiring Canadian physicians ruthlessly separated from their privacy by foreigners for mere "financial" considerations.

Happy now, Privacy Commissioner?
Canadian medical school applicant?

Vending Machines Of The Future

MyFoxNY.com
Next Generation Vending and Food Service is experimenting with biometric vending machines that would allow a user to tie a credit card to their thumbprint.
O vending machine, whatever will become of you?

It does seem that I see a lot fewer vending machines than I used to. It is also possible that the move away from cash could be one explanation. In that light it is appropriate for the vending machine to evolve to meet the spending habits of modern consumers by integrating non-cash purchases as efficiently as possible.

But is it possible that there are other forces at play here? More and more people live within a few miles of a big box store that stays open all night and these 24-hour big box stores are adding more and more self service checkout lanes.

Have we simply super-sized vending machines?

Tuesday, August 10, 2010

An Interview with Gartner's John Pescatore

BankInfoSecurity.com
Podcast here.
Really, what has to happen in most of these trends, whether it is mobility or consumerization or cloud, the business is heading in that direction for some business advantage, quite often cost reduction. It is cheaper to use web-based email than Microsoft Exchange, or cloud-based computing is cheaper than building your own data center.

So, wherever there are those cost reductions, some part of it has to be dedicated to adding back in the security that has gone away.

I've found Gartner's analysts and the quality of their work to be top-notch.

Facial recognition implementation and messaging: A cautionary tale

Big Brother facial recognition cameras being rolled out in NCP car parks
DailyMail.co.uk
Cutting-edge cameras will scan drivers' faces and check them against a crime database as they enter car parks, it emerged last night.

NCP, which is trialling the system at 40 sites, hopes it will help identify potential car thieves.

But privacy campaigners reacted with fury, saying the technology could criminalise innocent people.

Forgiving the unfortunate phrasing of the last quoted sentence (I'm not sure it's technically possible to "criminalise innocent people"), this article makes several points of which would-be consumers of biometric identity management systems should be aware.

1. There are people who are extremely suspicious of these systems and they aren't very moderate in their assessment of the motives of those who install these systems.

2. The non-technical press seeks out and amplifies the point of view of those who are suspicious of these systems.

Given 1 and 2 above, adopters of biometrically-enabled identity management systems should make sure that they are in a position to explain why they are doing what they are doing. They should be able to communicate how the accompanying improvements in business processes benefit the business's bottom line and improve the value proposition the business is able to offer to its customers. This post offers a great example. This quote from the linked article falls a bit short:
Lee Holland, the company's regional director, said: 'We hope that our customers will view this as a positive move to help improve the security we offer at our car parks.

'Our aim is to help customers to feel comfortable that they are parking in an environment which is extra-vigilant when it comes to dealing with the small minority involved in car crime.'

"I hope this makes you feel safer" isn't likely to compensate the customer for the extra cost of the system which will show up in the price of the parking service or the inevitable inconvenience associated with false positive and/or false negative identifications.

As a practical matter, the technical and public relations challenges are much easier when these systems are applied to managing the identities of staff rather than customers. As a parking garage customer, I might derive some benefit from the knowledge that all garage staff were thoroughly vetted using state of the art ID management techniques while the inconvenience associated with that task falls upon someone else. If you're going to use those tools on me, your customer, I will require compensation.

I guess it's possible that the problem NCP is trying to solve is that its customers are stealing from each other at an unacceptable rate. It's also possible that the thieves are a small minority of NCP customers and that NCP has good quality photos of these people for use in the facial recognition database. But if these things are true, why not just come out and say it?

I'd like to offer a few caveats to the above analysis:
It is possible that the linked article is not meant to be fair and that the article does Lee Holland and NCP a disservice. I have accepted the article at face value (no pun intended). If taking the article at face value was a poor decision on my part, the part of my analysis dealing with NCP and Lee Holland is bound to be off. Nevertheless, if my analysis is wrong because the article is unfair, the points made in the first half of this post are buttressed rather than undermined.

Monday, August 9, 2010

Is Trust the next "Killer App"?

FederalNewsRadio.com (Washington, DC)
Panel Discussion
Air Date: August 12th, 2010 at 11 AM (GMT-5)
How does one assure trust in Cyberspace? As citizens, government, and business enterprise increase the amount of information that is shared online, fundamental questions arise around security requirements, data and identity management, and infrastructure. Trusted online environments can reduce costs, expand services, and are critical to protecting how, and to whom, information is shared.
This is part of the "Expert Voices Presented by Booz Allen" series.

The Coalition for a Secure Driver's License presents Indiana Bureau of Motor Vehicles with Homeland Security Award

Press Release here: Yahoo.com (July 26, 2010)
Coalition for a Secure Driver's License site here.
"Indiana's focus on a secure credential is a benefit to all Hoosiers," stated Indiana BMV Commissioner Andy Miller. "The credential no longer is used exclusively as evidence a person can drive; it is now the most commonly used form of identification. As the agency issuing the identification, we need to ensure that each person is who they say they are. We greatly appreciate the recognition from the Coalition for a Secure Driver's License and will continue to provide secure credentials, while maintaining our commitment to customer service."
The CSDL site offers a wealth of information about what makes an identification document secure.

The Great Privacy Debate

It's Modern Trade: Web Users Get as Much as They Give - Wall Street Journal
Only one thing is certain here: Nobody knows how this is supposed to come out. Cookies and other tracking technologies will create legitimate concerns that weigh against the benefits they provide.
Tracking Is an Assault on Liberty, With Real Dangers - Wall Street Journal
Through the sites we visit and the searches we make, we disclose details not only about our jobs, hobbies, families, politics and health, but also about our secrets, fantasies, even our peccadilloes. 

I think Mom's advice is still the best: Don't write down anything you wouldn't want everyone to know. Only now, "write down" covers more real estate than it used to.

Related thoughts from Eric Schmidt, Google CEO. I think he's expressing fantasy rather than certainty when he asserts:
"True transparency and no anonymity", he says, is the way forward - and there's nothing we can do to prevent it.

Friday, August 6, 2010

Ageing irises could confound biometric checks

A BIOMETRIC trait is not just unique, it is also for life. That is one of the claims often made for biometric-based security systems like iris recognition. Now it appears that iris scans can produce subtly different patterns over time, so the older the image of a person's iris stored on a computer, the more likely that the system will fail to match it to a new scan of their iris.
Iris has been touted as the most durable biometric available for identity management applications that are practical for some uses given today's technology.

That still may be the case. Biometric identity management systems are not replacements for current security systems and protocols. They are augmentations of those systems. Very few security solutions are completely unstaffed. 

The lock on your front door is apparently unstaffed, but is it? If you live in an apartment or are staying in a hotel and you lock yourself out, the front desk staff will verify your identity and issue you a new key. If you live in a house, a locksmith can verify your identity and gain access to your abode for you.

The deployment of biometric identity management solutions has more to do with making better use of the existing security staff rather than putting computers in charge of security. 

Using the example from the linked article -- the false rejection error rate increases by 75% over four years -- it is not clear that this is a big problem for iris matching technology.

First, if the false rejection rate the day after you enroll in the system is one rejection in 1,000 verifications, then your odds of having to check in with the security guard are 1/1,000 or a .1% chance. Four years later, your odds are .175%.

Compare that number to the odds of getting to work without your prox-card or ID badge. If the false reject rate is lower than the forgotten ID rate, it is appropriate to proceed to a comparison of the costs of each alternative. 

The scientific- and business communities are concerned with two very different metrics. The scientists are, and should be, obsessed with perfection -- forcing error rates seen in the lab into the infinitesimal. Businesses/consumers should concentrate on ROI asking: If I do this, will I be better off than I was?

Thursday, August 5, 2010

AmberVision Goes International

Here's a round-up of the press coverage of our Memorandum of Understanding with the city of Guanajuato, Mexico. We are excited to be working with Guanajuato and we are eager to apply the AmberVision model and technology internationally.

AmberVision Goes International (State Journal)

Wednesday, August 4, 2010

AmberVision to help families in Mexican city






A city in Mexico is getting access to a high-tech, missing-persons alert service free of charge, thanks to its sister city of Morgantown.

The city is Guanajuato: UNESCO World Heritage site and home to some of the friendliest people you could ever hope to meet.

www.ambervision.org

Tuesday, August 3, 2010

U.S. State Dept. seeks police powers

UPI.com

The U.S. State Department has asked Congress to give the passport agency law enforcement status, saying it is needed to combat fraud.

The linked article provides an update to this post of July 29.

Monday, August 2, 2010

'Gross insecurity' of high-tech locks exposed

Wired.co.uk
It wouldn’t be DefCon without a noted lock hacking team demonstrating the gross insecurity of some of the latest security locks, such as a biometric lock that could be easily cracked with a paper clip.

Some of the physical access control products hacked were of poor design. Some are well designed. All can be overcome by professionals. The existence of the legitimate locksmith industry is proof that we know this and that we, in fact, depend on it.

Security is about context. A typical home's front door lock really isn't meant to make it impossible to gain improper access. Rather, it is meant to raise the costs of gaining improper access.

Friday, July 30, 2010

DNA not viable as access control biometric

FierceGovernmentIT.com

The article states that DNA tests require a 3 hour turnaround time and a $50-$500 price tag for each query. Very few identity management applications are practical within these constraints.

Most time frames for DNA analysis floating around on the web are 3 days for rush jobs and up to 6 weeks for normal testing. In some things, time and money are interchangeable but this isn't true for everything.

Taking the data in this article at face value, it seems that a 6 week DNA analysis could be done for $50 and the price will go up as the turn-around time is shortened. There is also the fact that all DNA analyses are not equal. Searching for a Y chromosome to determine gender will take far less time than using DNA to discriminate among siblings.

That DNA isn't viable as an access control biometric is a drastic understatement.

On the other hand, if DNA is all you have to go on, it's a great biometric.

UID selects Accenture, Satyam, L-1 for biometrics contract

The Unique Identification Authority of India (UIDAI) has selected three consortiums, led by tech firms Accenture, Mahindra Satyam and L-1 Identity Solutions, respectively, to provide technology solutions to capture the fingerprints and iris scans (known as biometrics) of the country’s 1.2 billion people. The consortia include algorithm and system integration providers.

Thursday, July 29, 2010

Bad guys could read RFID passports at 217 feet, maybe a lot more


OK, I must acknowledge that my repeated references to the RFID blocking passport wallet on offer from ThinkGeek.com here and here have been a bit tongue-in-cheek, though I love the site and its humorous product descriptions.

I figured that if there was a real danger that the information was insecure, the designers of the passport could and would take countermeasures, perhaps by integrating a stainless steel wire mesh into the covers of the document itself, making it readable only when the booklet is opened (this could make the document more durable, too).

Alternatively, I thought a that criminal operation that relied upon waving an RFID reader a few centimeters from where an individual carries their passport would face labor costs that couldn't be justified by the benefits of collecting the data the first place.

If this article is accurate, I'm not so sure this isn't something people should at least be aware of. The apparatus described in the article is like moving from rod-and-reel fishing, to using drag-nets, with the commensurate efficiency gains.

Undercover Feds Able to Easily Obtain Fraudulent e-Passports [USA]

“The U.S. passport is the gold standard for identification. It certifies an individual’s identity and U.S. citizenship, and allows the passport holder to travel in and out of the United States and to foreign countries, obtain further identification documents, and set up bank accounts,” [Md. Sen. Benjamin] Cardin said. “We simply cannot issue U.S. passports in this country on the basis of fraudulent documents. There is too much at stake.”
Identity management is about people and trust.

Because the U.S. government, and the society from which its power is derived, is among the most trusted in the world, the identity documents that it issues are accepted with near universality.

The integrity of the process and the people involved in it is what confers legitimacy upon the document and its bearer and makes modern globalized travel (among other things) possible. This integrity of person and process, however, also raises the incentives to obtain a fraudulent U.S. passport precisely because it is so trusted.

In the linked article, the reason given for the State Department's issuance of five passports requested with fraudulent information is essentially that the system in place is under stress due to the  volume of identifications that it is requested to make with absolute certainty. Because the errors by the Bureau of Consular Affairs stem from over-stressing the passport issuing apparatus rather than corruption, it makes sense to try to improve how passports are issued rather than who issues them.

Technology can really help with this sort of challenge. Giving better tools to those trying to do the right thing makes the world a better place. Giving better tools to those who aren't trying to do the right thing can have the opposite effect.

In so many of the articles I read about new identity management technologies there seems to be an unstated premise that we in the industry are attempting to develop autonomous systems in order to control the behavior of ordinary people.

What is closer to the truth is that we are trying to help ordinary people make better decisions about who they can trust.

A lot about what makes living in the information age a wonderful thing is that we have the power to forge relationships (commercial, financial, romantic, etc.) with a quantity of individuals that is orders of magnitude larger than anything humans have ever experienced. This fact has forced people to come up with new tools to assess who is and who is not trustworthy.

Granted, these tools aren't always technological. The use of branding to confer trust is a very old technique indeed and it's actually pretty close to what the Senator is talking about in the quote above. The U.S. brand confers the trust that the identity document is accurate and authentic, but the U.S. can and does use technology in maintaining the value of its brand. If the brand wasn't worth protecting, no amount of technology could confer trust.

The linked article is worth reading in its entirety.

Wednesday, July 28, 2010

Biometric system to verify eligibility for SRA, says CM

Help Wanted:
Ghosts need not apply.

Biological changes may put UID out of bounds for kids

Children up to 15 years do not have sharp patterns of fingerprints, the metric used to uniquely identify each one of them and more importantly, for authentication. The iris — the coloured portion of the eye — that is to be used to issue a unique identity number, too, does not fully develop before seven years.

“The iris starts achieving 90% stability in size only after six years of age. A normal iris starts assuming stability only by eight years,” said Dr Rakesh Gupta, consultant eye surgeon at Max Balaji Hospital in New Delhi.

Fingerprint patterns assume stability at an even later stage, around 16 years, said Dr V Khanna, a South Delhi-based skin specialist. “Fingerprints are very feeble in children and difficult to capture,” he said.
A few posts here have dealt with the use of biometric identifiers for children.


From ghost workers (yesterday's post) to "fake babies"...
A case in point is the Janani Suraksha Yojana, which hands out incentives to mothers. Earlier this week, a fake babies scam was unearthed in Bihar where 300 women claimed to have delivered up to five babies in a span of 60 days to avail an incentive of Rs 1,000 for each baby.
India, in building a comprehensive biometric identity management system in the world's second-most-populated country, is attempting something that has never been attempted before. It is the identity management moon-shot. It is worth keeping an eye on.

Tuesday, July 27, 2010

Fake pensioners arrested [Nigeria]

The Head of the Civil Service of the Federation, Stephen Oronsaye, said the biometric enrolment of pensioners embarked upon by his office has started to yield some of the desired results.

Mr. Oronsaye made this known when four suspected fake pensioners, three men and a woman, arrested at the Lagos Centre in the course of the exercise were paraded by the Police in Abuja.
This is great news and a cause for optimism in Nigeria. Many see the implementation of biometric identity management systems as enhancing government power over the people. As this article shows, they can also be implemented to increase the people's power over their government.

Ghost workers are a tried and true corruption technique. Their use impoverishes the society and undermines faith in democratic institutions.

It is difficult to overestimate the damage that corruption inflicts upon the world's poor. Biometric identity management systems can help restore the power of the people over their governments ensuring that scarce government resources are devoted to spurring economic and social development rather than lining the pockets of those who would violate the public trust for their own narrow interests.

Related thoughts and analysis of Nigerian ghost workers (with numbers) here.

Monday, July 26, 2010

Japan Tests Gender-Aware Billboards

Japan is testing a billboard that can tell the difference between male and female faces - and display appropriate ads accordingly. The system is running now in subway stations around Tokyo, CNET writes. A consortium of 11 railway companies launched a one-year pilot project to test the signs. Its aim, according to CNET, is to collect data on what sorts of people look at which ads at what times of day.
The CNET article linked above mentions that facial recognition is involved.

Tools developed for identity management can be applied to other challenges such as gender determination for the purposes of marketing in public places even though gender determination by humans is an extremely complicated process. Most facial recognition systems used for identification don't attempt to evaluate the gender of the individual. This is due to the fact that in a security context (logical and physical), the exact identity of the individual is more important to those who deploy theses systems than is gender. The users' tolerance for mistakes in the security context is low.

In a marketing context, the rules of the game change. A static billboard for a gender-specific product will appeal to some proportion of the population. Due to differences in age and gender that proportion is likely far short of 50%.

A system that tries to figure out age and gender doesn't have to be correct all the time in order to provide a positive return on investment (ROI) by increasing the percentage of impressions that have a chance of impacting customer behavior.

Moreover, the costs of the system making an incorrect judgment approach zero and the rewards for "tricking" the system are zero.

Even better, if the system is "tricked" by, for instance, a man with highlights and wearing lipstick, the system still works if you are advertising lipstick.

Sophisticated adopters don't let perfect be the enemy of the good.

British Passports Use Face Biometric


The chip inside the passport contains information about the holder’s face – such as the distances between eyes, nose, mouth and ears. These details are taken from the passport photograph that you supply. They can then be used to identify the passport-holder. The chip also holds the information that is printed on the personal details page of your passport.

This scheme would be useful in preventing the falsification of UK passports even if there is no true biometric matching involved.

If the chip in the passport contained only a digital copy of the passport that the government issued, a forger would need to forge the document and the chip. A forger that "found" a "lost" passport would have to alter the passport with a picture of its new user and find a way to get that new photo onto the chip. 

The UK passport chip uses RFID technology.  Travelers might want one of these.

Thursday, July 22, 2010

Press Release: AmberVision Unveils Program to Help Protect Oregon's Children



(Portland, Oregon) – An advanced technology tool is now available to Oregon police departments that will provide parents greater peace-of-mind for their children’s safety.

A nationally used database system called AmberVision, designed to help law enforcement officials in cases of missing children, is being introduced to school districts and parents in the state of Oregon.  Jim Isaacson, Oregon representative for AmberVision, says “AmberVision heightens the awareness of missing children through the community and media, and provides parents a proactive opportunity to enhance their child’s safety."

One of the most important tools law enforcement needs in missing children cases is immediate access to a high-quality photograph of the child in question.  AmberVision provides the ability for law enforcement agencies to access a child’s picture and description quickly.  It also provides them the ability to instantly distribute this critical information to other agencies, media, officers in the field, etc., all in an effort to save valuable time.

By registering online for AmberVision, parents have the ability to upload a current digital picture and description of their child to a secure database. Parents also have the ability to modify and update this information, as needed, via a username and password they create.  In cases of missing and abducted children, law enforcement officials, with read-only access, can view the data and within minutes, distribute it to the necessary parties.

The cost of enrollment for parents to utilize the database is $11.99 per year, per child.  “It’s an easy, user-friendly enrollment process (www.ambervision.org).  The overall goal of AmberVision (not for profit foundation) is to heighten child safety awareness to parents and communities, provide law enforcement another tool to aide in the safe recovery of a child, allow all children to participate regardless of their financial condition, and provide parents a proactive opportunity to participate in their child’s safety.

Through the AmberVision Foundation, free enrollment is offered to children who participate in the school lunch program”, Isaacson said.  

AmberVision has been implemented in communities throughout the country.  Isaacson said, “Some Oregon schools have already distributed information to parents, and we plan to share AmberVision with all communities throughout the State”.

The system, funded by a grant from the Department of Justice in 2005, was originally developed as a paper-based program called AmberView and tested in the state of West Virginia.  After deemed a success, the program was converted to an online service and offered nationally as AmberVision in late 2009.  SecurLinx, a leader in biometric identity management systems and technology partner to AmberView, has created the AmberVision Foundation in order to help keep our communities safe for children and their families.

Wednesday, July 21, 2010

To avoid ID, more are mutilating fingerprints


Some think these systems don't work.
So desperate was one man to conceal his identity that he began biting his fingers and drawing blood while being booked.

Some have used eyedroppers filled with acid or pressed their fingers onto burning metal to blot their fingerprints. Others have spent thousands of dollars to hire shady doctors to surgically alter their fingertips, hoping to scar them beyond recognition.
I guess these guys disagree.

AmberVision: Helping West Virginia Authorities Find Missing Children

WSAZ.com (Huntington/Charleston, WV)
The Ambervision program will kick off this fall in all West Virginia public schools. Parents will have access to a database that will allow them to change or add pertinent information about their child's appearance.
In the video below, Lisa Cordiero of the WV Board of Education does an excellent job of describing how AmberVision will work in West Virginia as well as the history behind the AmberVision Foundation.






Tuesday, July 20, 2010

Biometrics: it's not about the technology

Info4Security.com
Thanks to @heidishey for bringing my attention back to this excellent article by Bruce Lyman, CEO at Argus Global.

Good technology underpins many processes, both inside and without the business and, as many end users will know, understanding how technology works is rarely integral to its usefulness.

Indeed, technological excellence can in some part be measured by how little we need to know about a product to be able to use it. Such is the case with biometric technology, where the biometric itself is only part of the story.

Our real interest concerns (a) how easy it is to use on a daily basis, and by staff of varying technical aptitude and (b) what are the possible outcomes of using this technology?

Mr. Lyman goes on to examine biometric deployments in terms of Return on Investment (ROI), a topic close to our heart.
  • Security ROI: the cost of making a mistake
  • Productivity ROI: improvements to the business
  • Financial ROI: making the strongest case


Iris vs. Finger

The future of iris scanning - ZDNetAsia.com

UPDATE: This post gets a fair amount of traffic. The link above no longer seems to work. A cached version of the article linked above may be available here. The page takes a while to load.
Biometrics has received a lot of bad press during its short life. Fingerprint technologies have issues many businesses, and security professionals, would rather not deal with. And then there is the cost. So is there a technology that may provide security, involve low maintenance costs, minimize management headaches, and is acceptable to users?
Author Tom Olzak does a good job of comparing fingerprint authentication systems to systems that use the eye's iris and he makes excellent points about their strengths and weaknesses.

As we like to say, there is no "universal donor" in biometric identity management deployments. In some cases fingerprints are the best, in others, face recognition will be the way to go. Function dictates form. A successful deployment requires a deep understanding of the use model.

Monday, July 19, 2010

FBI National Academy Associates, Boston

SecurLinx and AmberVision will be in Boston for the exhibition associated with the FBINAA festivities this weekend, July 24 & 25.

The Law Enforcement Exhibition is scheduled for Saturday and Sunday in the Hynes Convention Center, Hall C.

Law enforcement officers from the Boston area not attending the conference may obtain a Law Enforcement Day Pass to tour the exposition Saturday or Sunday. Department-issued photo ID required.

If you're in the area, please come visit us:
Booth 212.

Sunday, July 18, 2010

Missing biometrics create unique problems for UID project

TheEconomicTimes (India) [Warning: site tries to open 5 pop-ups!]
This has been getting a lot of attention in the Twitterverse and elsewhere.
Scores of people the Aadhaar project will help the most do not have the sharp, curving lines on their fingers as depicted in its logo. Millions of Indians working in agriculture, construction workers and other manual labourers have worn-out fingers due to a lifetime of hard labour, resulting in what is euphemistically referred to in technical literature as ‘low-quality’ fingerprints. This is precisely the demographic that UID aims to help — those that are outside government records and welfare schemes.

While the UIDAI uses two other metrics — an iris scan and a photograph — in issuing the unique identity number, fingerprinting will be the metric used in authentication. This means a passport applicant with worn-out fingers may present his newly-issued UID number as a conclusive proof of identity, but could find the application rejected. The authentication process using a fingerprint scanner could classify the applicant’s worn-out fingers as a so-called ‘false negative’.
The Indian UID project has captured the public's attention. People are becoming aware of the promises and challenges of large scale biometric identity management deployments. This is a good thing.

On the technical front, "worn out" fingerprints don't present an insurmountable challenge to the Indian project. An ID management system that increases efficiency in the vast majority of transactions while presenting no new obstacles in the rare cases is a valuable system.

The proper way to evaluate a proposed identity management system is to compare the system currently in use to the expected performance of the envisioned system while balancing the costs of the new system against the improvements upon the old way of doing things. Too often, those skeptical about biometric ID management deployments start from the position that anything less than automated perfection is failure*. This attitude can impede the adoption of cost-saving improvements in critical organizational processes.

In adopting a multi-modal approach -- the UIDAI seems to have allowed for the use of iris for backup authentication as well as providing a photograph and an ID number -- it does not appear that India is creating an ID management system that will be unable to serve those with "worn out" fingerprints or those with disabilities that would prevent them from using a fingerprint based system.

*Similar thoughts here.

Friday, July 16, 2010

Safran Said to Be in Talks to Purchase Most of L-1 Identity Solutions Inc.

In March, we drew attention to reports that Bob LaPenta was putting L-1 on the auction block. It appears that the process is picking up steam.

From Bloomberg.com:
Safran is among the bidders pursuing a deal to buy L-1’s businesses that help customers track biometric data, said the people, who declined to be identified because the talks are private. U.S.-based L-1 is likely to be split up, with another buyer acquiring a separate unit that sells consulting services to U.S. intelligence agencies, said one of the people. No deal is likely to be reached for several weeks, the person said.
More information about Safran is available:
Safran-Group.com
BusinessWeek.com

Interesting questions for the future:
Will L-1 be bought whole or will it be sold off piecemeal?
Does the answer to the question above offer a verdict on L-1's strategy of acquisition rather than organic growth?

Thursday, July 15, 2010

High-Tech Corridor Susceptible to Shrinking Federal Appropriations

The State Journal (West Virginia)
Here's a little hometown analysis of the impact that our federal legislators have had on the economy of West Virginia and what the death of Sen. Byrd, the primary defeat of Rep. Mollohan, and the commensurate loss of federal funding could mean to the area.
“When Sen. Byrd moved the FBI fingerprint operation into Clarksburg, as much of a visionary he was, I’m not sure even he could have fathomed the growth that that created for the state,” said Rick Gill, CEO of the Washington, D.C.-headquartered National Biometric Security Project, which maintains an operation in Morgantown.
Both of the cities in the quote are in West Virginia's I-79 Hi-Tech Corridor.

Wednesday, July 14, 2010

Facial Profiling: Will face-recognition technology get an accused killer off the hook?

San Francisco Weekly
In what legal and scientific experts say is a groundbreaking case, a San Francisco Superior Court judge allowed biometric facial-identification technology, along with accompanying testimony from an expert witness, to be admitted as evidence in a high-profile criminal trial.

And in a curious turn, biometrics — the science popularized for its use in attempts to catch terrorists — was being used in San Francisco to try to exonerate an accused gang member and murderer.
As pointed out here, biometric identity management systems are tools that work both ways. The technology can be used by defendants as well as prosecutors.

This lengthy article, however, is pretty pessimistic about face-rec in general. To this point, I would draw attention to the fact that there is a huge difference between attended and unattended systems (a more complete resource for how to categorize different systems is here).
Several years ago, a surveillance experiment at a train station in Mainz, Germany, found that automated facial recognition had a success rate of only 60 percent during the day and as low as 10 percent at night, when poor lighting made identification more difficult.
The system described in Mainz, above is an unattended system used on non-cooperative, non-habituated individuals in a public, non-standard environment. 60% is nothing to sneeze at and the proper frame of reference is 0% (the number of people identified in the absence of a system) not 100%. So, Mainz went from 0% identifications to 60% in the daytime (possibly) without any spending on human resources and this is failure?

Poorly calibrated expectations are a real issue in the biometrics sphere. We in the industry need to make sure that we are setting reasonable expectations for our customers and helping them to craft systems that meet their needs. We have an obligation to deliver value and an incentive to educate our customers.

Monday, July 12, 2010

International Biometrics & Identification Association to Focus Efforts on the Growing Issue of Identity Management

Forbes.com
The International Biometrics & Identification Association (IBIA) today announced that it has expanded its mission to focus on the overall issue of determining identity. This new mandate, one which will see biometric and other technologies play an increasingly important role, has been deemed critical by the IBIA, given the rise of authentication issues facing data security, identity theft, immigration and homeland security.

This makes sense. Biometrics are a means to an end. Identity management is the goal.

Saturday, July 10, 2010

Poway Tells Skaters to Give Them the Finger

msnbc.com
Park-goers will be required to have their fingerprints and photos on file with the city, the paper said.

This kind of usage can be confusing.

All fingerprint access control systems store a template generated from a person's fingerprint. It is not possible to "reverse engineer" a template into a complete image of the fingerprint that created it. In this limited use case it cannot be said that fingerprints are on file with the City.

Other fingerprint access control systems do store an image of the fingerprint as well as the template generated from it. In this use case, it is accurate to say that fingerprints are on file with the City.

The article implies that the system in place in Poway is of the latter sort.

Related thoughts about a different system can be found here.

Friday, July 9, 2010

Why face recognition isn't scary -- yet

CNN.com
For those interested in facial recognition, the article linked above provides insight in to the uses and limitations of the technology. It also provides information about a few places where people can gain firsthand experience with facial recognition applications using their family photos.

Thursday, July 8, 2010

The epic marketing challenge for UID

LiveMint.com

On the technical side, biometric identity management is about the physical facts of a person in a given environment, communication, databases, sensors, permissions, etc. Once an organization works through these details, a successful biometric deployment becomes possible.

But there is a social component to almost all identity management deployments outside of prisons. ID management (biometric or not) only works if it isn't subverted by the users. If users are careless with keys, passwords and proximity cards; if doors are propped open or those with access allow others to "tailgate," the effectiveness of the ID management system is undermined.

India's UID project (once again) provides a useful window into how organizations manage the cultural side of a large-scale identity management deployment and the things that must be considered. The linked article provides insight into the India project's efforts at stakeholder marketing.
Combined, they have more than 150 years of marketing experience.

All were headhunted by Maruwada, who looked to bring the country’s most experienced minds in communications, marketing and advertising to tackle what is arguably the UIDAI’s most important challenge—marketing the idea of a universal government identity to citizens from every caste, region and religion.
As they say, read the whole thing.

Identity management is about people.

Wednesday, July 7, 2010

AmberVision State-Wide Rollout

Ambervision to help West Virginia authorities recover missing children (Herald Dispatch - Huntington, WV)
"The Department of Education is committed to keeping West Virginia's children free from harm," said state Superintendent of Schools Steve Paine. "Ambervision adds to our ability to keep every child safe and increases the chances of a good outcome in the unfortunate event of a missing child."
The AmberVision system will be adopted state-wide in West Virginia this fall.

Biometrics and Governance

CCTVs to monitor DC (Deputy Commissioner's) office employees: (The Times of India)
HUBLI: The ‘I don't care' attitude of the government employees who are accustomed to coming late, taking multiple breaks for tea, cigarettes and chatting during office hours will be a thing of past, at least in Dharwad.

The CCTV cameras and biometric machines which hitherto were only seen in corporate and other private offices have found its way into the deputy commissioner's office in Dharwad, making it probably the first DC office in the state to install it in a bid to discipline the government servants, who normally are blamed for taking their work lightly.
Many see the implementation of biometric identity management systems as enhancing government power over the people. As this article shows, they can also be implemented to increase the people's power over their government.

Tuesday, July 6, 2010

Farm of the Week: Producer clocks in with IT system to control costs

YorkshirePost.co.uk
"It might sound hard, but more accuracy means more fairness, for both staff and customers," says Mr Machin. "Thirty percent of our costs are labour. The more we pin costs down, the more choice we have about how to distribute rewards. And the better we get at pricing our produce, the more customers we bring in."
This article shows how new technologies, including biometric identity management technologies, are helping small businesses generate the data that help them operate with the same type of information large companies have been using for ages.

These identity management technologies combined with Enterprise Resource Planning (ERP) techniques are allowing small businesses to arrive at a precise calculation of costs, taking the guesswork out of pricing decisions. Moreover, the return on investment is significant.
"I would say our original investment in the time and management system has repaid already. The wages calculation, for example, used to take a couple of days. Now it is a matter of hours."

Friday, July 2, 2010

UPEK Terminates AuthenTec Proxy Contest and Merger Proposal after Grady's Resignation as Chairman of AuthenTec's Board of Directors

From ConsumerElectronicsNet.com
In his letter Grady explicitly says: 'My decision results from my increasing discomfort with the Company's de facto embrace of the status quo, and tolerance of management leadership's actions to resist value-creating transactions. I believe that the Board and management of AuthenTec should take decisive action to enhance shareholder value, but that view, supported in concept, is not reflected in actions. Enhancing shareholder value needs to be more than a talking point.'
The events described in this article concern two fingerprint sensor manufacturers, but you can expect to see many more articles of this nature over the next few years.

The biometric identity management sector will see rapid consolidation for several reasons:
  • The most coveted customers for biometric identity management solutions are very large organizations, while the suppliers of goods and services tend to be very small companies. The big companies know that the little companies don't have the depth to support them. This doesn't mean that deals don't get done. The small tech. firms can and do partner up with large scale IT integrators to meet the needs of large customers, but this model presents its own challenges.
  • Investors in early- and development-stage tech start-ups would like to see the beginnings of a possible exit strategy. It's not that they all want out; it's just that all investors are investors because they would like to earn a return. Without shareholder liquidity, an exit from an investment and the actualization of the commensurate gain or loss is difficult.
  • The current investment and economic environment means that firms in the sector will fail and their assets will accrue to the remaining firms.
  • The firms, themselves, and their boards will see growth opportunities and increased liquidity and heightened ability to support their customers without outside assistance as they grow larger through acquisition.

Thursday, July 1, 2010

India Proposes Tighter Laws for National ID Project

CIO.com
The Indian agency assigned by the government to issue identity numbers has proposed stiff penalties, including imprisonment, for anybody found misusing personal biometric and other information that it collects.
We've had our eye on the Indian census for a couple of different reasons: the size, scope, ambition and audacity of the effort is unprecedented.

We have focused most of our attention on the technical aspects of the project. The article linked above deals with some of the cultural issues that must be addressed in any biometric identity management implementation, especially one on the scale of the India project.

At the end of the day, identity management is about people.

Wednesday, June 30, 2010

Biometric IDs to plug leaks in rural job scheme

livemint.com

The plan is to roll out a GPS-enabled system to address the issue of ghost workers and misuse of job cards.

Corruption can make it difficult to get help to the needy. Biometric identity management systems can help ensure that more of a government's social services spending reaches its intended recipients.

Tuesday, June 29, 2010

How safe are you in the 'identity ecosystem?'

Government Computer News (GCN.com)
The White House’s plan for an “identity ecosystem” seems to be built on good intentions – using trusted digital identities to allow secure online transactions without the need for passwords – but its designers will have to sell the details of the plan if they are to win over our readers.
Related:
From the Jerusalem Post
Knesset passes law regulating electronic signatures

Monday, June 28, 2010

Sen. Robert Byrd of West Virginia dead at 92

From the Charleston Gazette (WV)
In 1989, he was elected president pro tempore of the Senate -- a largely ceremonial post -- and named chairman of the Appropriations Committee. It was there that he began funneling federal projects and money to West Virginia in earnest. The first big salvo came in 1991, when FBI officials announced they would build their new fingerprint identification center just outside Clarksburg.
Sen. Byrd has been instrumental in making the I-79 development corridor a hotbed of biometrics-based entrepreneurship. He will be missed.

Friday, June 25, 2010

Voice – The Killer App

From WirelessWeek.com
The value of voice is rarely assessed and certainly, from a telephony perspective, voice is as commoditized as tapwater. However, the ability to use voice as a biometric signature may be coming of age, particularly as we are on the cusp of a whole host of mobile transaction services where authentication of the end user will be paramount.
To date, voice biometric deployments aren't very common. There are, however, many types of transactions in the health care and financial sectors where voice is the only biometric available.

Thursday, June 24, 2010

India Census Update: Biometric process may need more time

Deccan Herald (Bangalore, India)
We've commented on the Indian Census here and here.

The process of collecting biometric data to provide national identity cards for residents of 183 coastal villages in the state took seven months. “Now we are talking about 30,000 villages, its a huge process”, Anil Kumar said.

Wednesday, June 23, 2010

Stillwater schools support plan to get data on kids to police in case of abductions

St. Paul Pioneer Press

Our own AmberVision child recovery system made the news this morning. AmberVision uses parent-supplied information, including a child's photo, in order to issue alerts over a wide area as soon as possible. Moreover, police in participating jurisdictions can use their blackberry or Windows CE enabled smart phone for facial recognition matches of missing persons.
"No matter what the circumstances are, every minute seems like hours. Every minute is critical," Stillwater police Chief John Gannaway said. "If you have that pertinent information at your fingertips, it's 100 percent beneficial."
Developed under grants from the U.S. Department of Justice, AmberVision was introduced nationally in August 2009. The AmberVision Foundation is a not-for-profit entity.

Tuesday, June 22, 2010

Local Hospital Uses Biometric Palm Scans to ID Patients

From SanDiego6.com
"PatientSecure is a nonintrusive and very precise method of identifying patients, ensuring they are matched to their own personal medical records and protecting them against medical fraud and identity theft," said Dan Gross, executive vice president of hospital operations for Sharp HealthCare.
The system described in the article seems to serve as an anti-fraud business solution rather than to increase patient safety as in this case, not that there's anything wrong with that.

Monday, June 21, 2010

Visa to drop signatures on credit card purchases by 2013

From Secure Computing (Australia)
Current technology is too "easy" to skim.
In the biometrics arena one often finds oneself in conversation with a biometrics skeptic. That biometrics skeptics exist is only natural and, of course, the burden of persuasion is and should be on those making arguments against the status quo.

Biometrics skeptics should have a proper grasp of the status quo in order to understand what they are defending.

Is signing a piece of paper every time you make a credit card purchase secure?

Is paying with a check secure? Checks display home addresses, signatures, bank account numbers, and frequently, even more information.

Is accessing your home with a funny-shaped piece of metal secure?

Are these things easier or harder to forge than biometrics?

These questions aren't necessarily technological questions and the answers are highly dependent on non-technical factors.

Visa seems to believe that signatures are not secure (see article) for credit card transactions.

You can write a check to a family member, put it in a greeting card and mail it with minimal risk (depending upon the family member).

Using checks for mail-order is probably a bad idea.

I hear stories of towns "where nobody locks their doors." For these folks, the funny-shaped piece of metal is more than adequate. Others might want something a little more robust.

So the question of whether or not such-and-such biometric identity management technology is "secure" makes little sense without the corresponding question: "Compared to what?"

Thursday, June 17, 2010

Chinese woman slipped through biometric identification checks

A Chinese woman arrested on suspicion of robbery has been found to have entered Japan unlawfully after changing her fingerprints to slip through airport biometric identification checks, investigative sources said Thursday.
Identity management is a lot like an arms race.

Tuesday, June 15, 2010

A unique ID for the masses

Following up on this post about the Indian census...

UID–GOI’s technology leap
The UIDAI project is expected to touch every adult citizen. A voluminous database and the sheer magnitude of this task requires robust security with no room for vulnerabilities writes Subhankar Kundu.
Indian moon shot indeed. This isn't just the world's largest biometric database, it is by far the world's largest biometric database.

Friday, June 11, 2010

Landlord's plan to use biometric security system raises concern

CBC News
Biometric deployments must be managed from a technological and human perspective. Biometric ID management systems are new and there is a lot of misinformation and misunderstanding out there.

Ultimately, these technologies will succeed because they make people's lives better and save them money, but they must be adopted in a manner consistent with established social norms.

The landlord in this case has obviously made some missteps.

The adoption of Biometrics is about where eCommerce was in 1999. To be honest, at that time I was one of the one's saying "Who would put their credit card number into a web site!?" Now I can't imagine going to a shoe store or buying music in a bricks-and-mortar store.

eCommerce grew as the early adopters rarely became victims of fraud and they shared their experiences with others. This is as it should be.

Anyone who attempts to force their customers into a system like this, especially as it relates to access to their homes, should be very careful.

Friday, June 4, 2010

Secure Communities in the news

ICE's Secure Communities program is getting a lot of attention.

SW Idaho to use fingerprints to ID illegal aliens - KHQ - Spokane, WA (6/4/2010)
Arizona immigration debate heats up in D.C. area - WTOP - Washington, DC (6/3/2010)
Secure Communities to Start in SF on Tues - SFGate - San Francisco, CA (6/1/2010)
U.S. Immigration and Customs Enforcement Secure Communities fact sheet.

Thursday, June 3, 2010

North American Biometrics Market Witnesses Growth Spurt, Finds Frost & Sullivan

redOrbit.com
New analysis from Frost & Sullivan, North American Biometrics Market, finds that the market earned revenues of $364.4 million in 2009 and estimates this to reach $1,588.6 million in 2016.
This is an excellent article summarizing findings from an excellent source for information about the biometrics market: Frost & Sullivan.

Tuesday, June 1, 2010

Mal-intent may be the future of security

The Sacramento Bee
This isn't related to identity management or biometrics but it is related to security.

Biometrics are used to establish a person's identity with a high degree of confidence so that the entity making the identification can accomplish further goals.

Identifying mal-intent does not seek to identify an individual but rather it seeks to predict undesired behavior through the detection of other behaviors.

Interestingly, both types of system represent attempts to predict the future.

One system -- the biometric one -- attempts to predict the future based on the identification of trusted or untrusted individuals. The assumption is that if I know who you are, I can make an educated prediction about what you will do.

The behavioral system, attempts to predict the future based upon what someone is doing now. If I know that people who do what you are doing tend to progress to other sorts of behavior, I can predict that you will also progress to that behavior. Or can I?

That's what the scientists are trying to figure out. Can you automate the judgments made by highly trained human observers of human behavior? Do people like Dr. Lightman from 'Lie to Me' exist? If so, can what they do be automated?