Thursday, October 14, 2010

Unisys Poll: 63% of credit card users would prefer fingerprint

[Almost] Two-Thirds of Consumers Prefer Credit Card Verification by Fingerprint (EarthTimes.org; UPDATE: broken link removed)
Responding to the question, "Which do you believe is the safest method to prove your credit card is being used by you?" the online poll found that 63 percent of more than 300 respondents preferred fingerprints as the best method for identity verification and authentication as compared to photo identification (20 percent), PIN numbers (13 percent) and handwritten signatures (six percent).

This poll gets at the "compared to what?" question we frequently ask here. It explicitly asks respondents to compare a biometric modality to what techniques/technologies are currently in use and, unsurprisingly, consumers find the status quo wanting.

I also think it's worth noting that the second-preferred choice, Photo ID (20%), is also a biometric. The photo on the ID is the database image and the customer's face is the probe image. The biometric matching algorithm is within the brain of the person making the comparison.

So, 83% of those surveyed believe biometrics serve their information security better than PIN's and signatures.

Wednesday, October 13, 2010

Biometrics: Humans as Keys

The Future of Biometrics by research consultancy Acuity Market Intelligence (ElectronicsNews.com.au)

Here's a good summary of a recent industry report on some challenges and opportunities in the ID management sphere.
Any remaining problems with biometrics will no doubt be ironed out with time, as new technological developments emerge, and standards are developed for the technology However, the industry is more interested in the bigger picture, integrating biometrics into existing and new applications, not so much as a standalone one-size-fits-all security technology, but as enhanced solutions to existing and new challenges.

Tuesday, October 12, 2010

Ears provide new way of identifying people

"With biometrics, a lot of the problems is what happens when people get old. With facial recognition, the systems are often confused by crows feet and other signs of ageing. Your ears, however, age very gracefully. They grow proportionally larger and your lobe gets a bit more elongated, but otherwise your ears are fully formed from birth."

Ears have been in the biometrics news a lot the last few days.

Pros:
-Facial recognition accuracy is degraded as the pose angle diverges from a full frontal view. As pose angles get bigger, an ear will come into view. Tying an ear-recognition system to a face recognition system could make more identifications possible, especially with a non-participating subject.

Cons:
-Ears aren't really that stable. They grow throughout life, as the quote above addresses.
-As high school wrestlers can attest, ears are easily deformed by trauma.
-Hair obscures significant portions of the ear in a significant percentage of the population.

That's not to say that they aren't or won't be useful.

As a wise man once said: "Biometric X is a great biometric, if it's the only one you have."

There are bound to be applications where the ear is the only anatomical identifier at hand and for those applications ear-recognition algorithms will be useful.

Friday, October 8, 2010

Thursday, October 7, 2010

Giving identity to Delhi’s homeless

HindustanTimes.com
For Abida Begum (20), a homeless woman who makes Rs 100 a day washing clothes in the untidy sprawl of Delhi's Nizamuddin Basti, India's Unique Identity (UID) project will, hopefully, stop constant police probing and harassment.
...
“I am told that I can open a bank account with the card (number) given. We were unable to open one, all this time, because I could not give proof of address or who I am,” said Ibrahim, who's been living in the Capital for more than 10 years.
Can you imagine an existence where you couldn't identify yourself to anyone who didn't know you already?

This post mirrors these two dealing with Afghanistan.
Biometrics: Giving Afghans an identity
Biometrics: Giving Afghans an identity UPDATE

Wednesday, October 6, 2010

Busted: Woman, 81, jailed in vote-fraud case

Woman, 81, jailed in vote-fraud case (MySanAntonio.com, via Drudge)
Bexar County deputies Monday night arrested a woman accused of using her long-dead sister's identity to vote twice in the 2008 general election.
...
The Texas Department of Public Safety's image verification system matched the photo on Comparin's driver license to the one on the “Collins” license, according to the affidavit.

Brazilian election biometrics have 93.5% success rate

(News.Xinhuanet.com)
The website of the Diario Catarinense, from Port Alegre, the state capital of Rio Grande Do Sul, said that 742 biometric machines had been installed in the city, and only three removed from service due to problems, or around 0.4 percent. An official at the TSE said the machines should be rolled out to the whole nation in 2014.

Among English language media outlets, this topic seems to have generated interest in the Chinese press and not elsewhere.

I tried without success to chase down the Porto Alegre article for any Portuguese speakers out there. If any readers happen across it, I'll certainly post a link.

UPDATE:
This may be the article referenced by Xinhua:
Eleitores do município de Canoas (RS) aprovam urna biométrica

Nely Menetrier, 84 anos, também se mostrou satisfeita com a urna biométrica.

– Gostei da nova urna, foi fácil e rápido.
Translation:
84 year-old Nely Menetrier also expressed satisfaction with the biometric ballot box. "I liked the new ballot box; it was easy and fast."

Voting is compulsory in Brazil so technologies that make the process more manageable will have a large impact. It wouldn't shock me if more votes are cast in Brazil than any other country.

Did their voices betray them?

Did their voices betray them? The discovery of an alleged terror plot against Europe owes at least some of its success to "voiceprint" technology that allows law enforcement to electronically match a voice to its owner.

The technique – which some compare to fingerprinting – can be a powerful anti-terror tool, officials increasingly believe. Law enforcement agencies are already considering how a voice database could help thwart future plots.

Cogent-3M merger overcomes shareholder action

Pasadena-based Cogent, the developer of fingerprint and other biometrics devices, reported this morning that a Delaware court has denied a shareholder motion to block the acquisition of the firm by 3M.

Friday, October 1, 2010

Contract awarded for $142M FBI project

Once completed, the new facility will allow the FBI CJIS Division, which already has the largest centralized collection of biometric information in the world, and the Department of the Army, which has also developed military biometrics database systems in coordination with the FBI, to make advances into other identification technologies, such as DNA, iris, palm prints and facial recognition.

Wednesday, September 29, 2010

It's on: India Launches Project to ID 1.2 Billion People

The project, which seeks to collect fingerprint and iris scans from all residents and store them in a massive central database of unique IDs, is considered by many specialists the most technologically and logistically complex national identification effort ever attempted.

As the gathering of villagers cheered and applauded, Ranjana Sonawane became the first in the country to receive the Unique Identification Number (UID) card at a ceremony.

Pushback on the National Research Council (NRC) Report

"The report is out of date and misleading at best," says Michael DePasquale, CEO of BIO-key International. "The fact that it relies on data gathered over five years ago does a disservice to the industry, and to those individuals who have been pushing technological advancements since 2004. Over the last six years, the technology has made significant contributions to not only our national security, but also to protecting access to a wide variety of commercial applications including smartphones, laptops, offices, homes, commercial networks, point-of-sale terminals and medical storage cabinets."
The full report is available here (Registration Required).

There are many fault lines running through the biometrics sphere and nowhere are they better explained than in the classic NATIONAL BIOMETRIC TEST CENTER COLLECTED WORKS 1997-2000 (1.8MB PDF). I refer specifically to Chapter 1, section II 'Classifying Applications' (page 13 in your PDF reader, page 3 according to the document's internal numbering). Without a decent understanding of the categories into which biometric applications fall, confusion is inevitable.

The categories are:
Cooperative v. Non-cooperative
Overt v. Covert
Habituated v. Non-habituated
Attended v. Non-attended
Standard Environment
Public v. Private
Open v. Closed

Some of these distinctions refer to the individual to be identified while some refer to the technology.

Every one of the above factors will impact the technical suitability of a solution or the user's acceptance of a system to some degree or another and the Attended/Non-Attended (technical suitability) and Public/Private (social acceptability) categorizations are supremely important.

The report seems to have caused confusion in its readers along these two lines: attended vs. unattended systems, and public vs. private use. This quote from the report is emblematic:
Biometrics recognition has been applied to identification of criminals, patient tracking and medical informatics, and the personalization of social services, among other things. In spite of substantial effort, however, there remain unresolved questions about the effectiveness and management of systems for biometric recognition and societal impact of their use.

This post touches on the confusion resulting from a lack of attention to the attended/unattended distinction.
The system described in Mainz, above is an unattended system used on non-cooperative, non-habituated individuals in a public, non-standard environment. 60% is nothing to sneeze at and the proper frame of reference is 0% (the number of people identified in the absence of a system) not 100%. So, Mainz went from 0% identifications to 60% in the daytime (possibly) without any spending on human resources and this is failure?

This post, in part, examines whether your identity management solution is ever truly unattended:
Biometric identity management systems are not replacements for current security systems and protocols. They are augmentations of those systems. Very few security solutions are completely unstaffed.

The lock on your front door is apparently unstaffed, but is it? If you live in an apartment or are staying in a hotel and you lock yourself out, the front desk staff will verify your identity and issue you a new key. If you live in a house, a locksmith can verify your identity and gain access to your abode for you.

This post deals with the public/private distinction.
Bryan Glick at ComputerWeekly.com understands that the rejection of a statist, top-down approach does not mean that identity management systems are unnecessary or that all proposed systems will be rejected by a free public.

Glick then draws attention to a 2008 report by Sir James Crosby, then at HM Treasury, entitled Challenges and Opportunities in Identity Assurance (.pdf). The 47-page report contains a breadth of information that makes it a great introduction for how to begin thinking about the challenges associated with large-scale biometric identity management deployments. It is very accessible and deserves to be read widely.
At an early stage, we recognised that consumers constitute the common ground between the public and private sectors. And our focus switched from “ID management” to “ID assurance”. The expression “ID management” suggests data sharing and database consolidation, concepts which principally serve the interests of the owner of the database, for example the Government or the banks. Whereas we think of “ID assurance” as a consumer-led concept, a process that meets an important consumer need without necessarily providing any spin-off benefits to the owner of any database. This distinction is fundamental. An ID system built primarily to deliver high levels of assurance for consumers and to command their trust has little in common with one inspired mainly by the ambitions of its owner. In the case of the former, consumers will extend use both across the population and in terms of applications such as travel and banking. While almost inevitably the opposite is true for systems principally designed to save costs and to transfer or share data.
They say a horse by committee gets you a camel. I'll withhold final judgment on the NRC report until I've gone through it in more detail.

Tuesday, September 28, 2010

Australian Government launches security research network

ZDNet.com.au
Nominated researchers must be members of the Research Network Secure Australia and clear its professional background checks.

Deputy national security advisor Margot McCarthy said the network will tighten coordination on matters of national security in the public and private sectors.
This is a good idea.

Creating a directory of the pre-vetted security experts available to a country should foster the development of good working relationships within the security sector which should in turn make for better responses in a security crisis.

The directory is online here and contains rich contact information such as phone numbers and (sometimes multiple) email addresses.

If you're in Australia and have acute need of an expert in biometrics and securing biometric templates, give Boztas Serder a call or shoot Calic Dragana an email.

Security is about people and national security is no exception.

Monday, September 27, 2010

Monday Roundup

Three topics seem to be dominating biometrics news today:

Biometrics 'Inherently Fallible' (RedOrbit.com)
For perspective, see Saturday's post.
More articles: Bing News

WVU seeks volunteers for biometrics study (WVPubcast.org; Text & Audio)
Blog post here.
More articles: Bing News

Boston & Secure Communities (Boston.com)
More articles: Bing News

Saturday, September 25, 2010

National Research Council: Biometrics 'Inherently Fallible'

Regular visitors will be familiar with the themes in this article.

No security system is infallible. Biometric identity management solutions are getting so much attention precisely because existing identity management solutions are extremely fallible.

What determines the desirability of a biometric identity management solution is not infallibility but return on investment (ROI) -- a measure of the efficiencies such a system can bring to an organization's identity management function offset by the costs associated with adoption of the new solution. In many cases the ROI is reflected in productivity gains among staff responsible for an organization's identity management function.

It is very important, however, that potential adopters of biometric ID management solutions be aware of the issues the article raises.
The report notes that careful consideration is needed when using biometric recognition as a component of an overall security system. The merits and risks of biometric recognition relative to other identification and authentication technologies should be considered. Any biometric system selected for security purposes should undergo thorough threat assessments to determine its vulnerabilities to deliberate attacks. Trustworthiness of the biometric recognition process cannot rely on secrecy of data, since an individual's biometric traits can be publicly known or accessed. In addition, secondary screening procedures that are used in the event of a system failure should be just as well-designed as primary systems, the report says.
Identity management is about people, after all. These systems can really help organizations, but they're not magic.

Friday, September 24, 2010

Biometrics: Giving Afghans an identity UPDATE

 Following on this post last month comes this from Wired.com...

Army Reveals Afghan Biometric ID Plan; Millions Scanned, Carded by May
Scanning prisoners’ irises is just Step 1. In Afghanistan, local and NATO forces are amassing biometric dossiers on hundreds of thousands of cops, crooks, soldiers, insurgents and ordinary citizens. And now, with NATO’s backing, the Kabul government is putting together a plan to issue biometrically backed identification cards to 1.65 million Afghans by next May.

Interesting nugget:
There are all kinds of hurdles to the plan, however. At the moment, Afghanistan’s two main biometric databases don’t talk to one another, limiting their effectiveness.
SecurLinx customers don't encounter these problems and we can fix them for customers in need of increased interoperability. Our middleware increases the ROI on existing identity management systems.

Face Rec: Getting So Much Better All the Time

Granted, integrated face recognition/video surveillance systems are not perfect—false positives do happen. Still, “Accuracy has improved nearly two full orders of magnitude since the large scale studies [that were] published in 2002,” says Ken Nosker, president of Fulcrum Biometrics. “In the latest independent study published by NIST, researchers have shown that seven tested algorithms performed as good as or better at matching faces than humans were able to do.

Thursday, September 23, 2010

Behavioral Biometrics or Public Lie Detectors?

CIO.com
The linked article is confusing and heartening at the same time.

It is easily divided into two parts: a discussion of the efforts of some in the research community to bring lie detectors out of interrogation rooms and into contact with the public, and a brief summary of findings that public views on biometric identity management techniques differ from the way so-called privacy advocates frame the issues.

The reason that it is confusing is that the two parts of the article don't belong together.

The discussion of the Future Attribute Screening Technology (FAST) prototype has virtually nothing to do with public acceptance of biometric identity management techniques.

The techniques described under the label Behavioral Biometrics are akin to lie detector tests. They rely upon the detection of changes in bodily function resulting from some outside stimulus such as interrogation and seek to determine intent. Moreover, FAST attempts to automate this analysis as much as possible. This is like going from "Lie To Me" to "Minority Report".

["Lie to Me" is a current* TV show chronicling the adventures of one Dr. Lightman (Tim Roth), the world's greatest human lie detector. "Minority Report" takes place in a dystopian future where criminals are caught before crimes are committed.]

There's ample evidence that the "Lie To Me" scenario is at least reasonable. It is possible to train professional interviewers that can ferret out lies and attempts to deceive with some high degree of accuracy. In fact, these professionals are actively doing the job FAST attempts to automate every day in our airports and police stations.

While I am unqualified to make assertions of fact regarding the feasibility of developing a machine that functions with high reliability along the lines envisioned by FAST's creators, it is my guess that FAST, or a similar system, is not only possible in theory but highly likely to exist in reality in the not-too-distant future so long as current growth rates in human scientific knowledge and computational power continue.

But even if we accept that a FAST-like system will be technically possible in the future, say fifteen years from now, no current researcher could possibly say anything useful about whether or not the culture fifteen years from now would find it acceptable to use such tools in public places upon ordinary people without probable cause. Predictions about social views on technology fifteen years in the future more appropriately belong to the genre of science fiction than opinion polling.

None of this is to discredit University of Pittsburgh Dr. Lisa Nelson's
study of biometrics and the public views about it [that] reveals tolerance and support when it comes to government use of biometrics to protect public safety.

Although privacy advocacy groups are supposed to represent the public, Nelson said her studies based on focus groups show that "there are differences between public perception and how privacy advocates were framing the issues," with the larger public apparently far more willing than privacy-advocacy groups to accept biometrics when it's used for purposes of protecting against terrorism or identity theft.
This summary of Dr. Nelson's findings rings true. There does seem to be a significant disconnect between self-appointed privacy advocates and the public they claim to represent where issues of biometric identity management are concerned. But this has little bearing on FAST and other far-off technologies. To tie Dr. Nelson's findings to FAST does a disservice to Dr. Nelson and perhaps even misrepresents the views of FAST's creators.

*UPDATE: The show has since been canceled.

Canadian border going hi-tech

TorontoSun.com
The five-year project to electronically secure the borders involves immigration, the RCMP and Canada Border Services Agency. Federal immigration spokesman Karen Shadd said under the program, applicants will have to provide fingerprints and a photograph as part of their digital visa application.
Expect this trend to continue, and not just among developed nations.

Wednesday, September 22, 2010

Global Biometric Market to Grow 22% Annually Between 2011 - 2013

MarketResearch.com
Both public and private sectors worldwide are witnessing rapid adoption of biometrics as an accurate, reliable and cost-saving way for better and advanced security surveillance. Over the years, the biometric technology has developed from a new technology used in a narrow band of closed environment applications to a useful, practical, fit-for-purpose tool used across a wide range of industries and in a variety of applications.
The full report is available for download for $1600. I have not seen the full report but the linked page provides a quick overview of industries and geographies where biometrics adoption is heating up.

Florida condo to use fingerprint reader for access to clubhouse, block access to delinquents

Expect more condo and homeowner communities to use locks, devices for common area access (Sun-Sentinel.com)

After the obligatory hand-wringing, this article addresses the management of condo complexes and how they are meeting their identity management challenges using biometrics.
"There is some resistance. A few people worry about ID theft," said Tersigni, adding she thinks there is no more risk in providing a fingerprint to endorse a check at the bank. "Others are all for it because this helps us keep the area safer. We always know who is coming in and going out and when."

And, Tersigni explains, the device does not store fingerprints. It uses biometrics to convert a user's fingerprint into a binary code based on 65 unique points of the fingerprint and stores that code for comparison later when a visitor uses the device outside the clubhouse door. To gain entry, visitors press a finger onto a small screen, allowing it to identify them and remotely unlock the clubhouse door. The system stores one fingerprint code per owner.
My condo management staff certainly does seem to spend a lot of time and effort in regulating who gets to use the facilities.

When a segment of the public views any place they are able to access as a place they are entitled to access, and absent rigorous identity management systems, the value proposition that management companies offer condo owners can be eroded considerably.

Tuesday, September 21, 2010

Biometrics Firms Reach Beyond Government Gigs

Biometrics Firms Widen Net (Wall Street Journal)
In this article the WSJ uses the 24-Hour Fitness and L-1 sale stories to provide the reader with a state-of-the-industry update.
Revving up the industry's growth will depend in part on getting more corporate clients to embrace the technology to provide access to offices, factories, medical and financial records and computer networks.

WVU researchers compiling biometrics data

West Virginia Public Broadcasting (Text & Audio at the link)
West Virginia University researchers are working with the FBI to build up a database including finger prints, eye and facial images.

For the second year in a row, WVU researchers in computer sciences are working with the FBI to gather information about biometrics, including facial shapes, finger prints, and even audio and video samples.
West Virginia University is at the cutting edge of the science of biometric identification. In order to advance the state of the biometric art, they need test subjects to "donate" the raw data that they use in their work.

The linked article and accompanying audio gives great insight into where some of the best minds in the field think biometric ID management is headed.

While this blog is more concerned with market-based product innovation than basic science, our company simply couldn't do what we do without our crosstown neighbors and scientific brethren at WVU.

Citizen or subject: The politics of personal identity

When IT Meets Politics (ComputerWeekly.com, UK)
The issues of personal identity are central to a global information society in which we are routinely expected to conduct transactions with those whom we have not met before, cannot remember or may never physically meet. The supporting technologies, from smart cards, encryption and biometrics to secure and efficient databases and networks, have been in regular use for decades. The reasons for the current controversy over ID systems have little or nothing to do with technology developments: save in the sense that they may be used as an excuse for promoting a solution which serves political objectives.
The linked article is an excellent survey of the forces at work within the identity management sphere. It does a great job of addressing the questions:
  • What do governments want from an ID management system?
  • What do citizens want in the bargain?
  • How does trust play a role?
  • What makes for a sustainable and acceptable ID management framework?
These are important questions and rarely are they addressed with such careful attention to history and context as they are here.
Please read the whole thing.

Monday, September 20, 2010

Safran seals the deal to acquire L-1

Safran Enters Into a Definitive Agreement With L-1 Identity Solutions for the Purchase of L-1 Biometrics and ID Management Solutions Businesses (Yahoo Finance)
The transaction is subject to L-1' shareholder and regulatory approvals, including review by the U.S. Antitrust Authorities, the Committee on Foreign Investment in the United States (CFIUS), as well as the satisfaction of other customary closing conditions.
And from the AP: (via MSNBC)
Paris-based Safran says the combination of L-1's biometric and enterprise access businesses with its existing U.S. security business, Morpho, will have joint sales of about euro1.4 billion ($1.8 billion), with U.S. sales accounting for almost half of that.

UPDATE:
Safran (Morpho) will take the biometrics business and Britain-based BAE will purchase L-1's consulting business.

Wednesday, September 8, 2010

Tech. in West Virginia

Jeff Imel is a success story for state tech leaders. The owner of Air Robotics, LLC relocated his company to West Virginia from Indiana 18 months ago and it is a decision he says he praises daily. He now thanks the state for helping his business, that is an aerospace company that designs and manufactures blended wing body Airborne Vehicle Systems, to thrive.

“I tell all my colleagues that West Virginia is the place to be. The opportunities here with the support places like the Robert C. Byrd Institute provide is comparable to none across the country,” Imel said.

That is the same message Tech Connect WV wants to provide to the rest of the world.
The linked article is a good summary of the successes and challenges associated with the development of the technology sector in West Virginia.

The weekly State Journal is also among the best printed publications in the state.

Tuesday, September 7, 2010

Who can go where without a visa?

The Henley Visa Restrictions Index
Brit's can go to 166 countries without acquiring a visa first. Iraqis and Afghanis, not so much.
In today's globalized world, visa restrictions play an important role in controlling the movement of foreign nationals across borders. Almost all countries now require visas from certain non-nationals who wish to enter their territory. Visa requirements are also an expression of the relationships between individual nations, and generally reflect the relations and status of a country within the international community of nations.
Full list here: [PDF].

WVU seeks volunteers for biometrics research

WVGazette.com [Charleston, WV]
West Virginia University is looking for volunteers to help with biometrics research.
...
Participants must be 18 or older and get $40 worth of gift cards for their time
College kids have it easy these days! Back in my day, it was all blood, plasma and drug trials.

AuthenTec And UPEK Announce Merger

TheStreet.com
AuthenTec (NASDAQ: AUTH), a leading provider of security, identity management and touch control solutions, and privately-held UPEK, a leading supplier of fingerprint solutions for consumer, business and government applications, announced that the companies have combined, creating the world’s largest provider of fingerprint sensors and identity management software, as well as biometric and embedded security solutions. AuthenTec will remain headquartered in Melbourne, Florida and will be led by newly named CEO Larry Ciaccia, who previously served as AuthenTec’s President and Chief Operating Officer.

This merger seems to fit into the second category of consolidation as outlined in this post.

Friday, September 3, 2010

German gov downplays biometric ID card hack

Nicht ein biggie [TheRegister.co.uk]
German hackers successfully used off-the-shelf kit to extract personal data from the federal government's supposedly secure ID cards, but the government has downplayed the significance of the attack.
This is one of those "compared to what" situations.

No security regimen is perfect.
Wise adopters of biometric ID management solutions will:
  • Complete an honest assessment of the security of their current solution
  • Tally the costs associated with the current solution
  • Compare these data to the value proposition of a contemplated improved solution
  • Compare any gains in security to the change in the costs associated with the solution.
In other words, the guiding principle should be Return on Investment (ROI), not distance from perfect.

It is often possible to save money and improve security at the same time.

The German government appears to be of the opinion that the new system, even if imperfect, is more secure than the old system. I'll accept that as a given.

One thing Germany might consider: Would it be better to put a template generated by the fingerprint on the card rather than an image of the fingerprint itself?

There are good reasons for wanting the entire fingerprint, but storing it on the card itself reduces the security of the information and will probably lead to a larger opt-out rate than would be the case if the card only held the template.

Another article on this story can be read at TheLocal.de.

Wednesday, September 1, 2010

Industry Consolidation: 3M acquires another security firm

Hot on the heels of their offer for Cogent, 3M announced that it will buy Attenti Holdings, an Israeli company which markets GPS-based solutions used for monitoring people awaiting trial or on probation, as well as the elderly in aged care facilities.


3M makes second foray into security sector FT.com (reg. req.)


In Monday's post, I used news of 3M's offer for Cogent to make the prediction that we will be seeing a lot more mergers and acquisitions in the identity management space. There are many reasons to believe that this will be the case:

-The underlying technologies are becoming more robust and costs are declining offering significant returns on investment to their customers.

-More customers are making more investments and the pure ID management firms are starting to show profits.

-Big Tech. firms are sitting on a lot of cash (see Hewlett-Packard's stock buy-back and bidding war with Dell over 3PAR).

-Growth rates are good; worldwide demand is surging, especially in the developing countries.

So, with the exception of 3M and L-1's uncompleted sale, what's the hold-up?
Mathew Christy, an analyst with Standard & Poor’s Equity Research, said: “The security space has higher growth and higher margins than other parts of 3M’s business which has typically grown sales at around 8 or 9 per cent a year”.

However, Mr Christy noted that given the overall size of the company, the acquisitions would add less than 1 per cent of revenues and would do little to change the company’s momentum one way or the other.
Mr. Christy has precisely identified the current running counter to the rapid consolidation scenario.

The potential deals are too small to impact the bottom lines of huge firms in any meaningful way.

This brings up several possibilities for the future of market consolidation in the ID management space:

Big firms are sitting on so much cash and, rather than using it for stock buy-backs and dividend distributions, they will spend it on acquisitions in order to carve out space in what is certain to become a huge and profitable industry.

Consolidation will occur in two stages: Small firms bought by medium-sized firms and then repackaged for sale to huge firms -or- consolidation among the small firms leading to firms large enough to make significant bottom-line contributions to the large firms.

The consolidation of the ID management industry will happen later as the market sheds more light on the quality of individual ID management firms.

Organic growth (with acquisitions along the way, of course) will lead to a new household name as the flagship firm in the identity management industry -- a new Microsoft, Oracle or IBM, for instance.

Tuesday, August 31, 2010

War & Peace and Biometric Databases

As the war draws down, however, the collection of so much personal information has raised questions about how data gathered during wartime should be used during times of peace, and with whom that information should be shared.
Lost in the sea of articles about 3M's acquisition of Cogent and caste in the Indian census, is this article contemplating:

The future of the biometric data the US military has generated during the Iraq war [Boston.com].

It's an important question, balancing the legitimate duties and needs of a new government with the potential harm that could come to innocent individuals in the event that the information is misused; and the article does the issue justice.

The good news is that the government of Iraq is democratic. It is a nascent democracy, but a democracy nonetheless. Historically, democratic societies have been better at balancing the rights of individuals with the primacy of the state than non-democratic regimes.

The fact that this is an issue at all, reflects that Iraq has entered into a new phase of its history. If Iraqis were living under a dictatorship or existing in a colonial status, this article never would have been written.

Monday, August 30, 2010

India UID - The Hardware

With 8 gizmos in a case, Nilekani sets out to give 1.2 bn people an identity. [IndianExpress.com]
Packed into what look like two medium-sized suitcases are eight essentials — an iris scanner, a fingerprint machine, a camera, a laptop, a computer screen linked to the laptop, an Internet data card, a pen drive and a printer.

Armed with kits like these, Nandan Nilekani and his team at the Unique Identification Authority of India (UIDAI) will kickstart one of the most ambitious exercises in recent times — distribution of unique identification numbers to India’s 1.2 billion people.
This article deals with the technical and human elements of the Indian UID-worker's job.

Time-and-attendance ROI

Put your finger on a more efficient system. The Globe & Mail [Canada]
"Just about everyone we talk to, whether they're 25 employees or 2,500, is interested in the conversation about biometrics," says Ed van Hooydonk, director of business development at Mitrefinch's Canadian operation in Mississauga, Ont.
This article belongs among the increasingly frequent media treatments of biometrics and ROI that seek to inform rather than alarm.

3M to buy Cogent for more than $900 mln

Guardian.co.uk
Diversified U.S. manufacturer 3M Co on Monday said it agreed to buy Cogent Inc for more than $900 million, paying a nearly 18 percent premium for the biometric identification systems company.
...
3M makes systems for creating and validating documents like passports, as well as products used at national borders. It said the deal will help it expand in the market for law enforcement systems, and estimates the $4 billion biometric market will grow by 20 percent a year.
Expect more news like this. The biometric identity management industry is due for some consolidation and there's a lot of cash sitting on the sidelines of this economy.

UPDATE:
Big shareholder of Cogent opposes buyout terms [LA Times]
Atlanta-based money manager Pointer Capital said in a letter to Cogent’s board on Tuesday that it believed the firm was worth at least $15 a share, or 43% more than the $10.50-a-share 3M buyout that Cogent accepted on Monday.

Thursday, August 26, 2010

Corruption is a stubborn thing

Now, ghost fingerprints on MCD rolls KeralaNext.com [India]
NEW DELHI, India: It was in November 2009 that the Municipal Corporation of Delhi, thanks to its biometric system, discovered it had more than 22,000 "ghost employees" on its payroll. But indicating another ghost of a scam, Delhi Police sleuths say even this multi-crore* biometic apparatus is faulty -- it doesn't recognize finger impressions, nor does it detect duplications.
It sounds like someone should call SecurLinx.

Biometric identity management systems are not magic. If you're just using a thumb print, there is nothing to prevent corrupt officials at the MCD from simply re-enrolling an accomplice over and over, slowly re-building his ghost worker fiefdom.

Our software allows customers to use multiple biometric systems simultaneously. It also facilitates the auditing of enrollment databases in order to cut back on shenanigans like those afoot at the MCD.

In response to the quoted section above: The apparatus is not faulty, the implementation was faulty. The apparatus allowed the discovery of 20,000 ghost workers. That's some good ROI.

The fact that the implemented system has cracks and that corrupt officials are still at the MCD is not a technological failure. It is a human failure.

Identity management is about people.

*Crore = 10,000,000

AmberVision picking up steam

Participation in AmberVision encouraged: News & Sentinel [Parkersburg, WV]
On Aug. 21 RESA 5 volunteers distributed information on the program at stores in Parkersburg. Information also was sent home this week with all Wood County Schools students.

"RESA 5 was pleased to be involved with informing members of our communities about AmberVision," said Ron Nichols, executive director of RESA 5. "AmberVision is a key component for the safety of children and the authorities' ability to find them if the need arises."

Thanks to all the volunteers who helped spread the word about AmberVision last Saturday.

Identification Technology and Citizen Privacy [Audio]

Federal News Radio 1500 AM [Washington, DC Radio]
The rapid convergence of security technologies combined with growing concerns about individual privacy are creating a need to understand the purpose of identification and credentialing in your environment and the impact on the public.
We couldn't agree more.
The discussion appears to have occurred on June 15. We missed it at the time but the discussion is still relevant.

Download audio here.

Wednesday, August 25, 2010

Biometrics: Giving Afghans an identity

Army.mil
There have been a couple of villages that have been enrolled because the village elder said they wanted to prove that they support the Government of the Islamic Republic of Afghanistan and are against Taliban, Yelverton said. "It allows non-criminal males to have an easier time finding work, because if they haven't been involved in criminal activity, it helps," said U.S. Army Capt. Michelle Weinbaum, Task Force 435, Task Force Biometrics operations officer, and a native of Cranston, R.I. "It's not only proof of involvement, but also proof of non-involvement."
Can you imagine an existence where you couldn't identify yourself to anyone who didn't know you already?

This article really illuminates the challenges faced by both the Afghan government and the U.S. military. It appears possible that the efforts of the 101st Airborne Division could lead to the development of the kind of information necessary to increase the effectiveness of the Afghan government and allow the citizens of Afghanistan to create and deepen their civil institutions.
"Afghans enrolling Afghans really works. "Not only did they do an awesome job, Afghans lined up to get enrolled by other Afghans."
Afghanistan hasn't had a census since 1979, and that one was never completed.

From the CIA World Factbook for Afghanistan (2010 est.):
Age structure:
0-14 years: 43.6%
15-64 years: 54%
65 years and over: 2.4%

Median age: 18 years
It seems that only about 25% of the Afghan population was even alive for the last (incomplete) census. It's hard to help a population when you don't know much about it. Perhaps these efforts can begin to develop the information necessary to help make Afghanistan a better place for its citizens. After all, it's about people.

India's UID project: The caste factor

In this post we noted that the Indian government had approved the collection of caste information with the census for the first time since 1931.

For those interested in the subject of the history of caste and the Indian census, this article from Frontline [India] offers insight.
THE inclusion of caste in Census 2011 has been a vexed question for the polity. The uncertainty over the issue has now come to an end with the Group of Ministers (GoM) on Caste Census giving its consent for the exercise. Finance Minister Pranab Mukherjee, who led the GoM, announced in the Lok Sabha on August 12 that only the modalities remained to be sorted out.

In the past few months, caste-based enumeration has been the subject of opinion columns of newspapers, talk shows on television and discussions on the Internet. A conference on “Caste Census: Towards an Inclusive India”, held on July 23 at the Centre for the Study of Social Exclusion and Inclusive Policy (CSSEIP) of the National Law School of India University (NLSIU), Bangalore, provided another forum to discuss the issue at length.
Identity management is about people.

UPDATE: I forgot to include the link to the Frontline article. It's fixed now, with apologies.

Tuesday, August 24, 2010

A finger's touch allows entry to UA Rec Center [Arizona]

Arizona Daily Star
There was always something inconvenient about the University of Arizona's Student Recreation Center, but you couldn't put your finger on it.

Now you can.

Starting this week, Rec Center members no longer will need to use their ID cards - called CAT Cards - before exercising.

Instead, they'll scan a finger.
Here's another good example of a balanced article that describes the benefits of a biometric identity management system. I believe it is also the first time the finger vein biometric modality has appeared in a linked article.

Biometrics, home from the war, returning to a good desk job

Pentagon using biometrics for smarter warfare, facilities, business processes (SmartPlanet.com)
  • At Eglin Air Force Base, Fla., the Air Force uses a device that scans hand prints to clear veterans who are receiving treatment at the Veterans Affairs clinic for access to the base hospital.
  • At Fort Belvoir, Va., the Army uses iris scanning technology to provide keyless entry to sensitive areas.
  • The Navy uses biometrics equipment to confirm identifies as they board foreign vessels.
Alas, the vast majority of the comments reflect that we in the industry still have a lot work to do in fostering a public dialogue about the role biometric identity management systems can/should play in a wired society.

Monday, August 23, 2010

Privacy and Transparency

When contemplating the cost-benefit of public biometric deployments many in the developed democracies tend to think first of privacy. 

The public in developing countries more frequently views biometric deployments in terms of transparency.


Friday, August 20, 2010

The West Virginia Board of Education, the West Virginia Department of Education and Regional Education Service Agencies have partnered with Wal-Mart and Gabriel Brothers to spread the word about AmberVision

“The West Virginia Department of Education is encouraging all parents to sign up for Ambervision,” says state Superintendent of Schools Steve Paine. “The minutes after a child is reported missing are the most critical. The faster information is released to the public, the more likely a child will be returned home safely.”

L-1 Identity nears sale

Reuters
L-1 said it would announce a deal, which analysts said could be around the $1 billion mark, in the coming weeks.

Wednesday, August 18, 2010

Siemens getting roughed-up in the Bulgarian press

New Crash Looms for Bulgaria's Biometric ID System
novinite.com (Sofia)
The reason is the fact the maker of the software, the German Siemens, had not delivered the needed forms, Dimitrov said, adding the company is not fulfilling most of their commitments.

According to the Deputy Minister, by May 30 Siemens had to deliver 400 000 covers for the new biometric data passports, but only 393 000 were received two and half months later, while nothing has yet arrived from the additional 300 000 covers, ordered by the Interior.
In a biometric passport deployment like this, software development and passport manufacturing are two very different functions. They have to meet somewhere, though, and Siemens is the prime contractor. Nevertheless, it's difficult to see how an original shortfall of only 7,000 passport covers explains the difficulties associated with the Bulgarian passport deployment.

For background on Bulgaria's experience with its biometric passport rollout, see this article of April 23, 2010 from the Sofia Echo.

Indians to receive UID number by February

All citizens will get a 10-digit unique identity (UID) number by February. The biometric card will have 13 mandatory things such as the impression of your eyes and fingerprints and all information about your family.
Crore = 10,000,000
Currency:
Rs. 50 = USD 1.75 (8/18/2010)

Tuesday, August 17, 2010

Phillippines Bureau of Immigration adopts biometric Time-and-Attendance system for all staff

To instill discipline and professional work ethics in the bureaucracy, the Bureau of Immigration (BI) implemented a policy of strictly requiring its officials and employees to personally register their daily attendance through a biometrics-based ‘bundy clock’ system.
It bears repeating: Systems like this can help the people get good value from their public servants.

Human-Trafficker & repeat offender busted by fingerprint ID system

Orozco-Larios was driving a 1998 Pontiac minivan when a Seward County sheriff's officer stopped him and found that Orozco-Larios and his eight passengers were illegal aliens. Four passengers were female children who were not accompanied by parents.
I wonder what work Orozco-Larios had in mind for the four unaccompanied female children.

These technologies can be a real force for good in the world.

See also: AmberVision to begin operations in Mexico, especially the video comments by Guanajuato, Mexico Mayor Niceforo Guerrero.

AmberVision is a non-profit application of SecurLinx technology dedicated to returning missing persons to their families.

Monday, August 16, 2010

California gym uses fingerprint sensor instead of entry card

SacBee.com
At 24 Hour Fitness, the entire fingerprint isn't actually scanned; random points on the print are recorded and then assigned a unique number, said regional vice president Troy Croghan. And the company never sells member information, he said.

Although the new system is optional, 97 percent of members who have been asked have signed up, Croghan said.

"For a majority of our members, this has proven to be an easier way to gain access to the club," he said.

Croghan also touted the increased security with the elimination of lost or stolen membership cards, as well as the green benefits of no longer depending on plastic cards.

It's good to see more articles attempting to inform readers of how biometric identity management technologies work and focusing on a cost-benefit analysis rather than lazily tossing around terms like "fingerprinting" and "Big Brother".

Gina Kim of the Sacramento Bee did a great job on this article.

UPDATE:
For a useful counterpoint, see this article on the same event. Find an uninformed gym user, a company man and two "privacy advocates" and the piece pretty much writes itself!

New Zealand and Australian immigration officials have begun sharing fingerprint information

NZHerald.co.nz
"It's a small scale arrangement but it's significant in that this is the first time that we have been running a biometric matching agreement international from an immigration point of view."

Bilateral agreements are often much easier to negotiate and implement than multilateral agreements.

Friday, August 13, 2010

Security Industry Association opposed to bill restricting use of biometrics security solutions in Alaska

SourceSecurity.com

Hot on the heels of the Canadian Privacy Commissioner's attack on fingerprint biometrics for medical school applicants comes word that Alaska is contemplating:
Bill (SB 190) from Alaska State Sen. Bill Wielechowski (D-District J) mandates that "A person may not retain or analyse, or disclose or distribute to another person, biometric information on an individual without first obtaining the informed and written consent of the individual" (Law enforcement and other parties authorised by state or federal law would be excluded).

The text of the bill is available here.

It seems like the bill is primarily concerned with DNA. If the bill limited itself to the restriction of DNA analysis, it would make more sense.

The issue - Biometric identification

TES.co.uk
When an image of a child’s fingertip is taken, most of the data is discarded, but certain points of the image are remembered and converted into an algorithm - a series of letters and numbers. This is the data that is stored and matched against children’s fingertips on a daily basis. “It would be extremely hard to reverse the process and turn the numbers back into an image,” says Mr Rossiter. “All you would have is a series of random points.”

Kudos to TES Connect for this balanced, informative, and fair article.

Tucked away at the bottom of this article is a very good memorandum offering guidance from the Information Commissioner’s Office [UK]. It can be can be found here in PDF format.

Thursday, August 12, 2010

British Government: Anti-RFID passport cover 'preys on fears'

A Home Office spokeswoman said: "The data encoded to the chip in the biometric passport is securely stored and contains no more personal data than the information printed on the data page of a passport.

"There is no evidence to suggest anyone's personal data has been stolen from a passport's RFID chip. The passport chip does not have the same communication protocol and therefore it is not physically possible for the chip to be read from the distance suggested."
I've made no secret of my curiosity about the RFID-blocking passport holder.

The Home Office seems to be responding to the article that inspired
this post (and probably many others).

Biometric cards save grain worth Rs. 20 cr. a month

Bangalore: Issue of biometric bar-coded ration cards to households in the last few months by the Food and Civil Supplies Department has helped eliminating nearly 8.5 lakh bogus ration cards from PDS.
Glossary:
lakh = 100,000
crore = 10,000,000

These technologies can increase the efficiency of social safety nets, reducing corruption and increasing the likelihood that the public will support governmental efforts to reduce poverty.

The Indian government has approved the inclusion of information on caste in the ongoing population census.

The controversial decision was taken by a group of ministers, headed by Finance Minister Pranab Mukherjee.
The enumeration of caste in India has evoked a divided response, even as the pressure of other backward class (OBC) groups forced the ministerial panel’s nod. The last caste census was carried out in India in 1931.
Janata Dal-United (JD-U) member Sharad Yadav also joined the protests, urging Speaker Meira Kumar to allow the protesting members to speak over the matter and ask the government to explain its position. 
We've drawn attention to the Indian census before, focusing mainly on the technological challenges India faces in attempting to create a comprehensive multi-modal biometric register of its adult population.
As these three articles indicate, the challenges aren't limited to the technological realm. The social challenges associated with the effort are gargantuan as well.

Wednesday, August 11, 2010

Privacy commissioner seeks to block finger-printing of Canadian med-school applicants

Canada.com (Link was broken earlier, fixed now. UPDATE: Now altogether dead.)
UPDATE: A summary of the article is here.

This article has it all:
  • Abuse of the term "fingerprinting" (see also, this post).
  • International trade & politics
  • Inflated expectations of privacy
  • A public official called a Privacy Commissioner
The long and short of it is that Canadian medical schools rely on the MCAT admissions test administered by an American firm: the Association of American Medical Colleges (AAMC). This firm, in order to maintain its value proposition, uses a pretty rigorous identity management regime that includes the use of a fingerprint biometric so that it is very difficult to take the test for someone else.

Now anyone who is on the demand side rather than the supply side of of the medical industry (or who isn't a Privacy Commissioner) is likely quite comfortable with the status quo. After all, if you really want to enter into a profession that allows you to prescribe medication, make people unconscious, cut people open, hold life in your very hands while being highly regarded by society and well compensated for your efforts, is identifying yourself with a high degree of certainty too much to ask?

The Privacy Commissioner of Canada, however, has a useful bogey man: The Patriot Act. The official name of the law is the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 and its 131 pages can be read here.

The Privacy Commissioner is concerned that Canadian citizens that take the MCAT and only apply to Canadian medical schools could one day have their fingerprint record accessed by the U.S. government, because those records are stored in the United States, and has found that this state of affairs violates Canada's Personal Information and Electronic Documents Act (PIPEDA) (I don't get the acronym either).

I'm neither a lawyer nor an expert on the Patriot Act so I will withhold judgment on the likelihood that a non-terrorist, Canadian MCAT taker who never applied to an American medical school will have their civil rights violated by the U.S. government using a subpoena of the AAMC under the Patriot Act. Curiously, the Privacy Commissioner, who hopefully is a lawyer and an expert on the Patriot Act, makes no such judgment, either. I searched in vain for the legal documents relevant to the case and perhaps she addresses the likelihood there. Nevertheless, the concerns of the Privacy Commissioner aren't so well founded that she can produce any medical school applicant that has suffered at the hands of the AAMC and Patriot Act, but one wouldn't be doing one's job as Privacy Commissioner if one waited for actual things to happen before launching legal action.

There are some simple things that the AAMC could change that would seem to ease the Commissioner's stated concerns, such as storing those records in Canada or gaining informed, expressed consent from the test takers, but
Stoddart is asking the court to order AAMC to develop an alternative procedure for verifying the identity of people registering for the MCAT in Canada that does not involving collecting fingerprints.
I have an idea. A private detective will follow all Canadian medical school applicants from the time they take the MCAT to the time they enroll in a medical school.

Total cost: $25,000 per test.

All Canadian MCAT test takers will have to take this form of the test; we can't have impoverished aspiring Canadian physicians ruthlessly separated from their privacy by foreigners for mere "financial" considerations.

Happy now, Privacy Commissioner?
Canadian medical school applicant?

Vending Machines Of The Future

MyFoxNY.com
Next Generation Vending and Food Service is experimenting with biometric vending machines that would allow a user to tie a credit card to their thumbprint.
O vending machine, whatever will become of you?

It does seem that I see a lot fewer vending machines than I used to. It is also possible that the move away from cash could be one explanation. In that light it is appropriate for the vending machine to evolve to meet the spending habits of modern consumers by integrating non-cash purchases as efficiently as possible.

But is it possible that there are other forces at play here? More and more people live within a few miles of a big box store that stays open all night and these 24-hour big box stores are adding more and more self service checkout lanes.

Have we simply super-sized vending machines?

Tuesday, August 10, 2010

An Interview with Gartner's John Pescatore

BankInfoSecurity.com
Podcast here.
Really, what has to happen in most of these trends, whether it is mobility or consumerization or cloud, the business is heading in that direction for some business advantage, quite often cost reduction. It is cheaper to use web-based email than Microsoft Exchange, or cloud-based computing is cheaper than building your own data center.

So, wherever there are those cost reductions, some part of it has to be dedicated to adding back in the security that has gone away.

I've found Gartner's analysts and the quality of their work to be top-notch.

Facial recognition implementation and messaging: A cautionary tale

Big Brother facial recognition cameras being rolled out in NCP car parks
DailyMail.co.uk
Cutting-edge cameras will scan drivers' faces and check them against a crime database as they enter car parks, it emerged last night.

NCP, which is trialling the system at 40 sites, hopes it will help identify potential car thieves.

But privacy campaigners reacted with fury, saying the technology could criminalise innocent people.

Forgiving the unfortunate phrasing of the last quoted sentence (I'm not sure it's technically possible to "criminalise innocent people"), this article makes several points of which would-be consumers of biometric identity management systems should be aware.

1. There are people who are extremely suspicious of these systems and they aren't very moderate in their assessment of the motives of those who install these systems.

2. The non-technical press seeks out and amplifies the point of view of those who are suspicious of these systems.

Given 1 and 2 above, adopters of biometrically-enabled identity management systems should make sure that they are in a position to explain why they are doing what they are doing. They should be able to communicate how the accompanying improvements in business processes benefit the business's bottom line and improve the value proposition the business is able to offer to its customers. This post offers a great example. This quote from the linked article falls a bit short:
Lee Holland, the company's regional director, said: 'We hope that our customers will view this as a positive move to help improve the security we offer at our car parks.

'Our aim is to help customers to feel comfortable that they are parking in an environment which is extra-vigilant when it comes to dealing with the small minority involved in car crime.'

"I hope this makes you feel safer" isn't likely to compensate the customer for the extra cost of the system which will show up in the price of the parking service or the inevitable inconvenience associated with false positive and/or false negative identifications.

As a practical matter, the technical and public relations challenges are much easier when these systems are applied to managing the identities of staff rather than customers. As a parking garage customer, I might derive some benefit from the knowledge that all garage staff were thoroughly vetted using state of the art ID management techniques while the inconvenience associated with that task falls upon someone else. If you're going to use those tools on me, your customer, I will require compensation.

I guess it's possible that the problem NCP is trying to solve is that its customers are stealing from each other at an unacceptable rate. It's also possible that the thieves are a small minority of NCP customers and that NCP has good quality photos of these people for use in the facial recognition database. But if these things are true, why not just come out and say it?

I'd like to offer a few caveats to the above analysis:
It is possible that the linked article is not meant to be fair and that the article does Lee Holland and NCP a disservice. I have accepted the article at face value (no pun intended). If taking the article at face value was a poor decision on my part, the part of my analysis dealing with NCP and Lee Holland is bound to be off. Nevertheless, if my analysis is wrong because the article is unfair, the points made in the first half of this post are buttressed rather than undermined.

Monday, August 9, 2010

Is Trust the next "Killer App"?

FederalNewsRadio.com (Washington, DC)
Panel Discussion
Air Date: August 12th, 2010 at 11 AM (GMT-5)
How does one assure trust in Cyberspace? As citizens, government, and business enterprise increase the amount of information that is shared online, fundamental questions arise around security requirements, data and identity management, and infrastructure. Trusted online environments can reduce costs, expand services, and are critical to protecting how, and to whom, information is shared.
This is part of the "Expert Voices Presented by Booz Allen" series.

The Coalition for a Secure Driver's License presents Indiana Bureau of Motor Vehicles with Homeland Security Award

Press Release here: Yahoo.com (July 26, 2010)
Coalition for a Secure Driver's License site here.
"Indiana's focus on a secure credential is a benefit to all Hoosiers," stated Indiana BMV Commissioner Andy Miller. "The credential no longer is used exclusively as evidence a person can drive; it is now the most commonly used form of identification. As the agency issuing the identification, we need to ensure that each person is who they say they are. We greatly appreciate the recognition from the Coalition for a Secure Driver's License and will continue to provide secure credentials, while maintaining our commitment to customer service."
The CSDL site offers a wealth of information about what makes an identification document secure.

The Great Privacy Debate

It's Modern Trade: Web Users Get as Much as They Give - Wall Street Journal
Only one thing is certain here: Nobody knows how this is supposed to come out. Cookies and other tracking technologies will create legitimate concerns that weigh against the benefits they provide.
Tracking Is an Assault on Liberty, With Real Dangers - Wall Street Journal
Through the sites we visit and the searches we make, we disclose details not only about our jobs, hobbies, families, politics and health, but also about our secrets, fantasies, even our peccadilloes. 

I think Mom's advice is still the best: Don't write down anything you wouldn't want everyone to know. Only now, "write down" covers more real estate than it used to.

Related thoughts from Eric Schmidt, Google CEO. I think he's expressing fantasy rather than certainty when he asserts:
"True transparency and no anonymity", he says, is the way forward - and there's nothing we can do to prevent it.

Friday, August 6, 2010

Ageing irises could confound biometric checks

A BIOMETRIC trait is not just unique, it is also for life. That is one of the claims often made for biometric-based security systems like iris recognition. Now it appears that iris scans can produce subtly different patterns over time, so the older the image of a person's iris stored on a computer, the more likely that the system will fail to match it to a new scan of their iris.
Iris has been touted as the most durable biometric available for identity management applications that are practical for some uses given today's technology.

That still may be the case. Biometric identity management systems are not replacements for current security systems and protocols. They are augmentations of those systems. Very few security solutions are completely unstaffed. 

The lock on your front door is apparently unstaffed, but is it? If you live in an apartment or are staying in a hotel and you lock yourself out, the front desk staff will verify your identity and issue you a new key. If you live in a house, a locksmith can verify your identity and gain access to your abode for you.

The deployment of biometric identity management solutions has more to do with making better use of the existing security staff rather than putting computers in charge of security. 

Using the example from the linked article -- the false rejection error rate increases by 75% over four years -- it is not clear that this is a big problem for iris matching technology.

First, if the false rejection rate the day after you enroll in the system is one rejection in 1,000 verifications, then your odds of having to check in with the security guard are 1/1,000 or a .1% chance. Four years later, your odds are .175%.

Compare that number to the odds of getting to work without your prox-card or ID badge. If the false reject rate is lower than the forgotten ID rate, it is appropriate to proceed to a comparison of the costs of each alternative. 

The scientific- and business communities are concerned with two very different metrics. The scientists are, and should be, obsessed with perfection -- forcing error rates seen in the lab into the infinitesimal. Businesses/consumers should concentrate on ROI asking: If I do this, will I be better off than I was?

Thursday, August 5, 2010

AmberVision Goes International

Here's a round-up of the press coverage of our Memorandum of Understanding with the city of Guanajuato, Mexico. We are excited to be working with Guanajuato and we are eager to apply the AmberVision model and technology internationally.

AmberVision Goes International (State Journal)

Wednesday, August 4, 2010

AmberVision to help families in Mexican city






A city in Mexico is getting access to a high-tech, missing-persons alert service free of charge, thanks to its sister city of Morgantown.

The city is Guanajuato: UNESCO World Heritage site and home to some of the friendliest people you could ever hope to meet.

www.ambervision.org

Tuesday, August 3, 2010

U.S. State Dept. seeks police powers

UPI.com

The U.S. State Department has asked Congress to give the passport agency law enforcement status, saying it is needed to combat fraud.

The linked article provides an update to this post of July 29.

Monday, August 2, 2010

'Gross insecurity' of high-tech locks exposed

Wired.co.uk
It wouldn’t be DefCon without a noted lock hacking team demonstrating the gross insecurity of some of the latest security locks, such as a biometric lock that could be easily cracked with a paper clip.

Some of the physical access control products hacked were of poor design. Some are well designed. All can be overcome by professionals. The existence of the legitimate locksmith industry is proof that we know this and that we, in fact, depend on it.

Security is about context. A typical home's front door lock really isn't meant to make it impossible to gain improper access. Rather, it is meant to raise the costs of gaining improper access.