Tuesday, June 14, 2011

Your Face as Your Password

From PCWorld
This article gives a consumer's eye view of some of the possibilities and limits of very low cost face rec.
The future has flying cars, replicators, and computers that recognize your face and let you log in just by looking at them. While we may have to wait a bit longer for the cars and the replicators, we can have face recognition right now, and it's surprisingly affordable. I took a look at BioTrust ($13), and it took a look right back at me.

EU ministers back consolidation of population databases

A single agency will be in charge of three EU population-tracking databases under plans approved by EU ministers (OUT-LAW News)
The Council said that a "decisive political agreement" had been reached to back plans for a new agency to be set up by the summer of 2012 to manage the three databases. A proposed regulation drawn up by the European Parliament to establish the new agency receives Ministers' support, the Council said in a statement.

Biometrics word of the day

dactyloscopy

It sounds worse than it is.

FBI talks about fingerprint information sharing

Biometric Sharing Initiative - Making the World Safer (FBI.gov)
Since 2002, the Global Initiatives Unit has developed relationships with more than 50 countries and has received over 450,000 biometric records that have been added to IAFIS.

Monday, June 13, 2011

Can smart cards curb $370 billion in Medicare fraud?

Politicians eye tech to reduce losses in Medicare, Medicaid (SecureIDNews.com via @m2sys)
With the budget battle underway, the case for a strong identity credential for Medicare may be too good for Congress to pass up. Smart cards could help the federal government to reduce Medicare fraud and abuse to the tune of $370 billion in the next 10-years, says Kelli Emerick, executive director of the Secure ID Coalition.
Fraud undermines public faith in social safety nets.

Malaysia Biometrics Update: June 13, 2011

New system ID's wanted terrorist using false name (newKerala.com)

Faster auto travel as Malaysia adds terminals? (AsiaOne.com)
Golfers, others wary (ChannelNewsAsia.com)
"No problem at airports and ports" (Straits Times)

U.S. lacks automated system to track entry and departure of foreign visitors

Houston Chronicle
Nearly a decade after five suicide hijackers with expired U.S. visas helped 14 comrades carry out the Sept. 11 attacks, the Department of Homeland Security and Congress have yet to come up with a fail-safe way to check foreign visitors in and out of the U.S., leaving an unknown number unaccounted for inside the country.
Fail-safe? Many would settle for reasonably efficient.

Dr. Bojan Cukic primer on the history of biometric ID

We've posted on Dr. Cukic before.

He's back providing the quotes for a great short synopsis about the history of biometrics.

Friday, June 10, 2011

Biometric Facial Recognition Technology For Jailbroken iPhones

This is cool (Softsailor.com)
Whenever you feel bored with the old way you used to access your iOS device’s screen, download and use the first biometric facial recognition application that is able to work with your native iPhone’s front-facing camera.
Biometrics will be far more useful in enhancing privacy than eroding it. Getting low cost biometric tools into the hands of early adopters is very important to the growth of our industry.

European Regulators probe Facebook’s facial recognition

A number of European privacy regulators are investigating Facebook (FT.com)
A number of European privacy regulators are investigating Facebook’s facial recognition feature amid mounting concern about the technology, which attempts to identify people in photos uploaded to the website.

The social networking site has come under fire from the German, UK and Irish authorities for introducing the feature without permission from users.
There is a tension in these two paragraphs. "concern about the technology" or "introducing the feature without permission from users"?

The issues are often confused. Technology is neither good nor bad. What people do with technology and how they treat each other can be.

So, where are these mounting concerns best directed: facial recognition technology; the Facebook as a technology; or individual decisions by people in positions of power and trust?

This affair has more to do with transparency and consent than any particular technology.

Identity management is about people.

Thursday, June 9, 2011

Facebook Facial Recognition Implementation Raises Privacy Concerns

Face rec software suggests tags for photos uploaded to its site (TECHNEWSWORLD.com)
Facebook has raised concerns among privacy proponents with Tag Suggestions, a new feature that uses facial recognition technology to connect names to faces in uploaded photos and suggest tags to the uploader. Aside from the general privacy worries the feature has spurred, it's somewhat unclear just how long Facebook has had this feature in play.
Transparency and Consent. Organizations neglect these at their peril because their customers/users value them highly.

India UID Update: June 9, 2011

Only 5% enrol for Unique ID card in Mumbai (DNAIndia.com)
"We have been given a daily target but how is it possible to meet it if people are not coming forward. A majority of people don't know why UID is important and where to get enrolled. The lapse is both from the vendors' and the civic body's end," said an official from one of the enrollment centres, requesting anonymity.
It's not quite as bad as the headline makes it sound. They seem to be missing their goals by about 20% and 5% of Mumbai is a lot of people.

Now, get UID online (DNAIndia.com)
Once operational, citizens will be able to register through a government website and fix suitable appointments at the nearest centre for biometric registration. An official from the IT department of the state government said this will reduce registration time to less than 10 minutes.

Russian Biometric Lie-detecting Robot Bankers

A Russian A.T.M. With an Ear for the Truth (New York Times)
The machine scans a passport, records fingerprints and takes a three-dimensional scan for facial recognition. And it uses voice-analysis software to help assess whether the person is truthfully answering questions that include “Are you employed?” and “At this moment, do you have any other outstanding loans?”
As they say, read the whole thing.

Children, Schools, Policy & Technology

Cameras in the toilets; CCTV in the classroom; pupils' fingerprints kept in a database . . . (Manchester Guardian)
The article is an interesting collection of stories from the UK and the US. Taken together they show a picture of schools trying to cope with a whole range of social issues they were not created to address rather than schools acting as the Outer Party of George Orwell's dystopia.

It's worth checking out the comments, too.

Wednesday, June 8, 2011

BIO-Key poll results

BIO-Key International® Releases Survey Results and Comments on Continued Security Breaches (UPDATE: broken link removed)
The time has come for every commercial and government enterprise to recognize that traditional methods of security are no longer a deterrent to hackers and cyber thieves. Recent security breaches have proven that tokens are far too vulnerable, especially in cases where the data or information is mission critical and passwords, no matter how sophisticated, are easily compromised.

See also:
Privacy vs Security - A false choice
Unisys Poll: 63% of credit card users would prefer fingerprint
Return on Investment (ROI)

Armenia, Come on down!

Biometric passports to be issued in Armenia in 2012 (PanArmenian.net)

Malaysia roundup

M'sian Minister: We'll solve border jam (AsiaOne - Singapore)
S'poreans unhappy with Causeway fingerprinting (AsiaOne - Singapore)
Sabah Implements Biometric System (Bernama.com - Malaysia)

The press items from Singapore highlight the inconvenience of the new procedures. The press from Malaysia focuses on the societal problems that the new system is expected to help address.

Singapore is, by some measures, the world's busiest port and is essentially a city-state on an island at the tip of the Malay Peninsula. Any change in the border policy of one country will be intensely felt by the other. There is also quite a history between the two countries, to say the least.

Hopefully the future holds a situation where the benefits arising from the important and legitimate needs for travel and commerce between the two countries and are maximized while those vulnerable to mistreatment are protected.

The pressure is on.

See also:
Malaysia Considers Amnesty for Illegal Immigrants (NY Times)

Biometrics for people who can't identify themselves

Georgia police ID comatose suspect by fingerprints (Link Inactive)
More info here (SavannahNow.com)

It looks like the comatose man is a suspect in a crime which (I guess) goes part way to explaining why his family wouldn't ID him. I don't know the law, but can you ID someone to doctors and not the police? It would seem to be extremely risky to the patient's health to withhold critical information, such as medical records which contain identifying information, from the doctors charged with the patient's care.

Stripped of the criminal context, this case is useful in pointing out that there are situations where caregivers and civil servants come into contact with people who are unable to identify themselves. There are many ways various biometric modalities can be used to help.

Tuesday, June 7, 2011

IATA Floats Airport Security Revamp

Iata unveils queue-busting airport security prototype (Travolution)
Passengers should be able to get from kerb to boarding gate with dignity. That means without stopping, stripping or unpacking, and certainly not groping. That is the mission for the Checkpoint of the Future. We must make coordinated investments for civilized flying.

Secure, hassle-free Checkpoint of the Future aims to make air travel 'civilized' (UK Independent)
Today's checkpoint was designed four decades ago to stop hijackers carrying metal weapons," said Bisignani. "Since then, we have grafted on more complex procedures to meet emerging threats. We are more secure, but it is time to rethink everything. We need a process that responds to today's threat.
The PDF linked at the bottom of the first article shows that the International Air Transport Association (the industry) gets it.

India UID: Making it stick

No UID, no salary for govt staff (Mid-Day.com)
A government resolution making Unique Identification (UID) card a must for all its employees before the end of the month has left the staff scrambling for forms to complete the enrollment. The Government Railway Police (GRP) and the Pune Municipal Corporation (PMC) have issued circulars to its employees stating their salaries would not be deposited unless they enrolled for the UID card.
That'll motivate them.

Monday, June 6, 2011

Understanding the Three Factors of Authentication

InformIT from Pearson Education
Authentication is the first step in access control and there are three common factors used for authentication: something you know, something you have, and something you are. This article provides you with good understanding of the three factors of authentication and how they can be used together with multifactor authentication.

Malaysia Biometric system 'will be fixed'

New Straits Times
Hishammuddin said he would continue to monitor the situation and share information with countries which had used similar system, adding that the biometric scanning was still at an early stage and needed time to integrate with other existing system.
Some people had to wait for 90 minutes in order to get through customs.

There are always a few hiccups when changing security processes.

When Brazil changed its procedures on January 1, 2004, people had to wait up to nine hours. It was so bad that the mayor of Rio hired samba dancers to hand out roses and T-shirts to keep the peace.

Thankfully, countries have learned from Brazil's experience and have gotten better at managing the changes required to implement biometric technologies.

Privacy vs Security - A false choice

Did anyone ever tell you not to flash your cash around in public?

The idea is that showing your roll might attract the attention of would be thieves, pickpockets or muggers.

So in this case keeping your affairs private enhances security. There is no tradeoff.

There are many cases like this. How many of you have heard people say things while on a mobile phone in a public space that would give a malefactor all the information they need to commit a crime with little chance of detection?

How many horrible people have used information about young people they have met online in terrible ways?

We don't value privacy highly because it is the currency with which we purchase security. One of the many reasons we value privacy so highly is that it enhances security even as it is retained.

Now consider the recent data breaches that have led to a loss of privacy and, as a consequence, the reduction of the security of individuals.

Even if the security protocols of the companies involved were weaker than the ones that were actually breached, template-only biometric authentication would provide far more privacy and security than the current username/password regime.

A database including Name, Username, email address and password is far more valuable than one including Name, Username, email address and biometric template. The reasons are somewhat technical, but you can't just type a template into a computer to gain access.

Granted, biometrics are more expensive. But you can trade money for security.

Friday, June 3, 2011

Israel: Biometric ID database to be launched in November

Pilot project will test database (Jerusalem Post)
Knesset Science and Technology Committee chairman MK Meir Sheetrit (Kadima) and MK Avraham Michaeli (Shas) both voted in favor of the database at the end of a long discussion in which rights groups opposed the policy on privacy grounds.

Reading this article and the one that provided the inspiration for the post linked below, put me in mind of this quote from Israeli Prime Minister Benjamin Netanyahu in his recent address to the U.S. Congress:
You think you have contentious debates here in Congress? Come visit the Knesset for one day, be my guest.

See also, Privacy and Security in Israel.

Municipal Corporation of Delhi Chief: I ain't afraid of no ghosts

The Municipal Corporation of Delhi Chief doesn't believe in ghosts (Asian Age)
The MCD has told the Delhi high court that there were no ghost employees on its payroll and accused the media of raising a non-existent scam.

Earlier post on the subject here.

It's not the tech, it's the people: Canada & India

In an international version of "it's not about the tech, it's about people"...
Canada appears to be heading for another diplomatic dust-up with India (The Star - Toronto)
That amount is not enough to introduce biometrics in every Canadian overseas mission, so immigration officials are now trying to decide which countries should be first.

Security hotspots like Pakistan and Yemen are at the top of the list, but there was room for one large-volume nation as well, according to sources, and India is the recommended choice over China.

The decision could damage relations between Canada and India, which have only recently begun to improve.
This really seems to be more about the rivalry between China and India than biometrics.

I think the author nails it in the concluding paragraphs. I'd also add that, given India's UID project, if the Canadian customs information on Indian citizens is shared back with India, India would be in a position to gain a better picture of how Indian passports are used than China would be if China was in India's place.

L-1 Identity says US begins 45-day probe of Safran deal

[Reuters] L-1 Identity Solutions Inc said the Committee on Foreign Investment in the United States (CFIUS) was investigating the face-recognition software maker's sale to French defense company Safran.
L-1 is much more than a "face-recognition software" maker.

Thursday, June 2, 2011

Privacy Leadership: What it Takes

Those anxiously awaiting the next installment of our privacy series, might find this interesting.

Today's Threats Require a New Breed of Privacy Officer (GovInfoSecurity.com) via @heidishey
"Privacy's focus is increasingly on transparency now," Herath says. "This is fundamentally creating new challenges for professionals in their approach toward privacy and data protection."

For instance, the new generation of workers blurs the lines of personal and professional communication in their use of social media, and the type of information that is collected by these sites is often not in the control of an organization. Moreover, it can be used to cause reputational or fraudulent damages.

Australia National Security Science and Technology department plans public outreach

NSST aims to tackle biometric bogeyman perceptions (Computerworld.com.au)
A government organisation that funds biometrics projects, such as tracking large groups of people congregating in one area, is planning to reach out to the community to lessen fears about biometric technology.

Speaking at the A/NZ Biometrics Institute conference in Sydney, Dr Helen Cartledge, told delegates that the National Security Science and Technology (NSST) wants community input in order to improve the perception of biometrics in Australia and also make policy changes.

India: Biometrics curb corruption and help the poor

Curbing Corruption (Times of India)
Sources said that the department was left with no other option as it has failed to achieve the expected attendance outcome, even after conducting frequent raids in various government schools during the past six months.

Helping the Poor (Deccan Herald)
Currently, funds under these schemes are disbursed through post offices or co-operative banks. The beneficiaries were facing difficulties in accessing their branches, which are mostly situated in talukas.

UPDATE
...and more corruption (Times of India)
Jaiswal issued suspension orders of these health employees following a series of complaints received from NMC health committee chairperson Alka Dalal. She has many times pointed out that although the biometric machines installed at various zones have brought down proxy attendance since the workers have to be physically present, they continue to remain missing in their wards during work hours and are only seen at the ward offices at the designated time to mark their in-out time.

Canadian border guards want face rec

Border workers push for biometric screening (CTV News)
Canada's front-line border officers back the idea of a perimeter security arrangement with the United States, with a few caveats.

The Customs and Immigration Union wants more intensive screening of travelers, including a biometric face-recognition tool to pinpoint security threats and wanted criminals.
Facial recognition often gets knocked around a bit because casual observers think it is supposed to function well as an unattended system. Maybe one day it will, but not yet.

That, however, doesn't make it useless. It is a valuable tool in the hands of trained personnel.

Computers don't look at the world the way we do. Whether that's a good thing or not depends on what you're trying to accomplish. For facial recognition in a law enforcement context, it's a good thing to have a radically different point of view applied to a challenge.

First, faces are probably the most meaningful objects in human existence. It's not too much of an exaggeration to say that for millennia human survival has depended upon our abilities at one type of facial recognition: recognizing people you know. Sorting through hundreds of thousands of pictures of people we don't know in order to match the two that are of the same person, however is not something we're inherently good at.

Computers can do that in less than a second, then give the two pictures to a human which is very good at making the single comparison.

The computer does this by treating the face as a mathematical formula. It finds the eyes, then the nose, then other points, measures the distances and angles between the points and turns that all into a long number. Then it does that for everyone in the database. Then it just compares numbers to see which ones come close to matching. It doesn't care about age, race, or gender. It'll match a white man and a black woman. It will match a picture of an old person taken one year ago with a picture of a young person taken today (i.e. a match that's impossible because people don't get younger).

People don't do that. When you ask a person to describe someone they're likely to tell you they were Hispanic, middle aged, round faced, good looking, brown eyes, etc. The computer says: Their eyes were 57.55 mm apart; tip of nose 25 mm below that line 2mm off center to the left, etc.

People and Face Rec make a good team because it's hard to fool them both at the same time. People can't memorize the faces of 1000's of people they don't know & you can fool them by cross-dressing or disguising yourself as a much older person. Computers don't know anything about gender, ethnicity, age or attractiveness, but they can do the math on 1000's of faces in an instant.

Malaysia Biometric system in force at all entry points

The Star/Asia News Network
The National Foreigners Enforcement and Registration System was introduced yesterday without any major hiccups.

Deputy Home Minister Datuk Wira Abu Seman Yusof said foreigners entering the country would now have their thumbprints taken electronically.

"The process went on smoothly and the department has not received any complaints so far.

"However, the system is new and there are bound to be minor glitches," he told The Star.

Tuesday, May 31, 2011

Privacy/Security Politics

In contrast to our philosophical take on the privacy debate, Salon.com offers a more political angle.

Why "security" keeps winning out over privacy

Teaming to Win starts today

The Teaming to Win conference is today and tomorrow in Roanoke, WV. Its purpose is to advance and improve small business prospects in West Virginia, and to facilitate educational opportunities which promote higher business standards, methods and practices.

Your humble diarist will be in attendance tomorrow.

Friday, May 27, 2011

Philippines House approves biometrics voter registration bill

Newsbytes Philippines
A bill that seeks to institutionalize the use of biometrics in voter registration is close to being becoming a law after the House of Representatives recently approved it on third reading.

The Senate version is still pending (Business World Online)

Australian Govt plans biometrics working group

zdnet.com.au
The national science and security division within the Department of Prime Minister and Cabinet (DPC) is looking to establish a new working group with industry to tackle biometric security initiatives.

Thursday, May 26, 2011

Ghanaian Newspaper wholeheartedly endorses biometric voter ID

To the worlds democracies ID management is an existential issue.

Entrenching The Will Of The People (Daily Graphic via Modern Ghana.com)
While calling on the EC to expedite action on the process, we urge all political parties, civil society groups, the media, the generality of the people and the international community to lend this process all the encouragement and support so that biometric voting can take place in the 2012 presidential and parliamentary elections.

Without doubt the application of the biometric register for the 2012 elections would not only further enhance the credibility and integrity of the polls but also further anchor the country's already enviable democratic system and stature.

Biometric technology used in Osama bin Laden’s death

Bojan Cukic, WVU professor and biometrics expert (Daily Athenaeum)
"Crossing the borders, accessing medicine cabinets in hospitals, even logging in onto our laptops is simply easier more convenient and more secure with biometrics", he said.

More on Bojan
We, on the business end of biometrics, owe a considerable debt to scientists like Dr. Cukic.

Earlier post on SEEK

Tuesday, May 24, 2011

1.5 billion smart credentials to ship

The increasing use of smart cards and biometric capture has changed the way government and healthcare citizen ID documentation is viewed, managed and deployed (Help Net Security)
Many governments are adopting smart, chip-based solutions for several reasons:
  • To help combat fraudulent and criminal activities
  • To improve return on investment and bundle several applications in one document to create efficiencies for government departments
  • To make the documents more user-friendly, flexible, and secure for citizens.
1.5 Billion is an astounding number.

More at the link.

T&A in NYC: Update

After fraud probe, NYC's payroll system clocks in (Wall Street Journal - link inactive)
The program's cost has ballooned from $68 million to more than $700 million.
Earlier posts:
Big-Time fraud in NYC time-and-attendance initiative (12/17/2010)
NYC payroll chief resigns after fraud probe (12/24/2010)

Biometric ID management technologies have the ability to help institutions to combat fraud but the implementations aren't inherently immune from corruption.

Nevertheless, even after the extreme cost overruns that increased the projected cost by a factor of ten, I wouldn't be surprised to see NYC recognize a positive ROI.

From Wikipedeia:
[In 2006] The New York City government's budget is the largest municipal budget in the United States. The city government spends about $50 billion a year, employs 250,000 people, spends about $15 billion to educate more than 1.1 million children, levies $27 billion in taxes, and receives $14 billion from federal and state governments.

$700M / 250,000 employees = $2,800 per employee

Depending upon the scope of inaccuracies in the NYC bureaucracy and the comprehensiveness of the system implemented, recognizing a ROI for the system might not take long at all.

Friday, May 20, 2011

It's not the tech; It's the people. Google edition

Google has apparently discovered a morally repellent use of technology. Good for them. This says more about Google than biometrics.

Google Was for Facial Recognition Before Schmidt Was Against It (Yahoo)
Google warns against facial recognition database (The Telegraph)
Google's Eric Schmidt: Ex-CEO's Most Memorable Quotes (PCWorld)

Some may note the irony that this blog is brought to you via Google's Blogger service.

Google offers a lot of good products. You tend to pay in information about yourself. Often the bargain is acceptable. Sometimes, as with their more controversial pursuits, the relationship isn't consensual.

That's why the individuals working at Google are so important. Google's tech isn't the problem; (sometimes) their use of it is.

Review the quotes in the last article linked above.

It's not the tech; it's the people.


UPDATE:
Biometrics firm OmniPerception responds to this issue with
Opinion: Facial recognition technology satisfies privacy concerns raised by Google (OmniPerception.com)
Stewart Hefferman the CEO of OmniPerception said that history has many examples where technologies have had the potential to be misused, frequently through a lack of understanding, until it has been properly legislated or a strong framework of standards has been implemented.

Two on India fighting waste with biometrics

For rural RTO staffers, workday start at noon (Times of India)
Last week, a TOI team visited the RTO office and found that out of the 41 employees, hardly 10 had reported on time. Many seniors also reached after 12 noon.
State to consider mode of payment for beneficiaries (The Hindu)
The proposal to change the mode is under examination of the government in view of the Central Bureau of Investigation unearthing, in September last, a major scam in the disbursement of old age pension, according to an official of the Social Welfare and Nutritious Meal Programme Department.
Not only does the UID project give government an increased ability to identify citizens, of far more importance to ordinary Indians, it gives citizens an increased ability to hold their government accountable. Implementation of biometric time and attendance systems within government bureaucracies can reduce or eliminate ghost workers and stem corruption.

To understand why India is doing what it is doing, please consider this post.

Can't Hide From SEEK

In other international fingerprint news, a look at what the military is doing with biometrics in Afghanistan (StrategyPage.com)
SEEK (Secure Electronic Enrolment Kit), this is a portable electronic toolkit that collects biometric from people.

US, Indian domestic LE orgs conclude fingerprint collection confab

Because Crime is International (AndhraNews.net)
"Transnational criminals and terrorist organizations threaten all countries, and training seminars such as this one are an excellent method for the U.S. and India to partner together to enhance our shared capabilities.

Thursday, May 19, 2011

Indefinite retention of DNA samples is unlawful under European human rights law, Supreme Court rules

Police guidelines that allow DNA samples taken during criminal investigations to be retained indefinitely are unlawful, the UK's highest court has ruled (Out-Law.com)
The judges made their ruling in a case involving two men who were appealing against decisions not to delete DNA information stored about them.

One of the men, GC, had a DNA sample, fingerprints and photographs taken after he was arrested on suspicion of assaulting his girlfriend, the summary of the ruling said. The charges were subsequently dropped. The other man, C, was acquitted of rape in 2009 and had requested that his finger prints and DNA be deleted from police records, the summary said.

"Their requests were refused as there were no exceptional circumstances within the meaning of the ACPO guidelines," the summary of the Supreme Court ruling said.
They didn't exactly strike it (the practice) down, either.

A UK Supreme Court summary (2 page pdf) of the case is available here.

This is a very interesting issue precisely because it isn't an easy issue.

Singapore to adopt face recognition at border control points

Govt to award S$1.1b worth of public sector infocomm projects (ChannelNewsAsia.com)
The Immigration & Checkpoints Authority (ICA) plans to implement a biometric system - called the Flexi Immigration Clearance System (Flex-i) - that recognises a person's face at immigration checkpoints and allows the person to enter the country in record time.

The project is the first of its kind in Singapore and will allow ICA to toggle between automated and manned counters for immigration clearance.

Tuesday, May 17, 2011

Privacy and Security in Israel

The debate about the future of Israel's nationwide ID management system is really heating up. The future system will include biometrics. The article deals with how the pilot system is to be organized and distributed and how the information is to be stored.

I've really undersold the article, here. There are some fireworks in there (the adverbs especially) as well as links to other news items about the topic.

How vulnerable will Israel's future biometric database be?
(ynet News)

Biometrics to monitor for teacher fraud in India

Municipal Corporation of Delhi to use technology to curb absentieesm by teachers in its primary schools (ZeeNews.com)
"It was found that a number of teachers either report late to school or mark their attendance and leave for the day. Through this biometric system attendance such things can be checked," said Mahender Nagpal, chairman of the Education Committee of the MCD.

From the MCD homepage:
The Municipal Corporation of Delhi is among the largest municipal bodies in the world providing civic services to more than estimated population of 13.78 million citizens in the capital city. It is next only to Tokyo in terms of area. Within its jurisdiction are some of the most densely populated areas in the world. It has also the unique distinction of providing civic services to rural and urban villages, Resettlement Colonies, regularised unauthorised colonies, JJ Squatter Settlements, slum 'basties, private 'katras' etc.

Monday, May 16, 2011

Fingerprints don't expire

Electronic chip in ID card for Emiratis lasts five years (Zawya.com)
Abu Dhabi: The Emirates Identity Authority (EIDA) has fixed a five-year validity period for Emirati national ID cards because of the five-year life span of the electronic chip in the card, the authority explained yesterday in a statement.

The lifespan of the electronic chip in the national ID card is five years, Eida said.

And there may be biological changes in an individual with ageing which affects biometrics like fingerprinting. “Such changes have to be recorded in the system,” Eida said.
There are all sorts of good reasons to have ID cards expire but, barring severe bodily trauma such as permanent scarring or actually losing digits, changes to fingerprints aren't one of them.

Baby footprints are taken at birth and, given adequate skill and care in recording them, they are reliable over extremely long periods of time. FBI print experts have identified the adult victims of such disasters as fires and airplane crashes by using the footprints of the individuals taken in infancy.

Anybody know why they use baby footprints instead of hand prints?

Australia-New Zealand Biometrics Institute eyes state of the industry

I love the metaphors that pop up in biometrics news headlines.
In this case, the eyes are the biometric modality that makes an appearance (see above).

Follows up 2010 survey, which showed increasing acceptance of biometrics (Computerworld)

A/NZ Biometrics Institute
But don't go there hoping to find the 2010 survey results. They're behind a pay wall.

Thursday, May 12, 2011

TWIC Isn't Keeping Ports Secure, GAO Says

Less Secure than state driver's licenses (National Journal)
Despite nine years of fine-tuning and more than $400 million in funding, a government-issued picture ID card used at U.S. ports provides less security than the average state-issued driver's license, a federal auditor told lawmakers Tuesday.
One of the biggest problems with the TWIC system is interoperability. If you own one location where your customers receive a service, it's all fine and good to have a proprietary, un-networked identity management system. If you're trying to control access at facilities scattered across the globe and managed by many different agencies, you have an ID management challenge of a completely different order.

Part of the solution is technical and part is political.

Interoperability is a term that covers a bit of both the technical and political aspects of ID management.

The solution to the TWIC problem is either a top down agreement among all ports to adopt the same ID management protocols and verification system or a strong standards based solution with a robust middleware integration.

SecurLinx can be of much help with the latter.

Wednesday, May 11, 2011

Access Control: Badge Wars

The woman who controls access to Baghdad's Green Zone is one of the most powerful Americans in Iraq (Slate.com)
BAGHDAD, Iraq—Army Lt. Col. Kimberly Johanek is one of the most powerful Americans left here. Not even the U.S. ambassador or the four-star commander in charge of U.S. forces has the authority to do what she does.
...
Johanek is trying to encourage the Iraqis to use biometrics, which match fingerprints or iris scans against a database. It is a highly reliable but expensive identifier that embeds a chip in a badge that can be matched against information stored in a database. The U.S. military uses such biometrics on its badges. But the Iraqis only have five biometric-badge readers, and neither government is willing to turn over their databases to read each other's badges.
This lengthy but informative article underscores one of our common themes: ID management is about people.

7 things to know about India's UID

Here's a good backgrounder on what India is up to with it's UID program.

Some frequently asked questions answered on "Aadhaar" (Times of India)
What is Aadhaar?
A tool for social empowerment and inclusion, Aadhaar is a 12-digit number being issued to all residents by the Unique Identification Authority of India (UIDAI). This number is stored in a central database and linked to some basic demographics and biometric information -- photo, 10 fingerprints and iris -- of each individual.

Related thoughts:
Doesn't the concern about identity theft among rich country citizens prove the value of a legitimate identity?

If your identity is so valuable to you that you worry about it being stolen, why would you deny one to a poor person?

Biometric ID management techniques remind me of cell phones in Africa; they allow countries to skip a rung on the development ladder. They can be used among populations where some of prerequisites (especially very high literacy rates) that were necessary to develop effective ID management regimes in the developed countries are, for now, missing.

Biometrics fights against TB

H/T @m2sys

A non-profit organization is using the magic of Biometrics to fight the TB menace (itVARnews.net)
The biometrics attendance system is being used by this NGO in its bid to eradicate tuberculosis in the city which has about 217 per one lakh* people afflicted by the disease.

As part of this ‘Operation Asha’ fingerprinting data is collected from patients and even potential patients with the help of councilors and by collecting fingerprint data from the patients during each visit, counselors at the centers are able to deliver personalized care to ensure that anyone infected is staying on their entire course of medication until they are completely free from tuberculosis.
The creativity of the scientific community in applying biometric ID management techniques to some of the world's most vexing problems is truly amazing.

ID management is about people, after all. Humans have understood the technical aspects of killing Mycobacterium tuberculosis for decades. It's bridging the gap from the lab to populations that is the hard part.

*One lakh = 100,000

Using Economics to Help the World’s Poor

Mr. Banerjee and Ms. Duflo have pushed anti-poverty programs in developing countries to become more serious about evaluating whether they are actually improving people’s lives. (New York Times Economix blog)
Since they will no doubt want more specific suggestions, here are two policies that I think every poor country should implement. A small universal cash grant to everyone over 12, based on biometric identification. This guarantees that no one has to face the humiliation of being totally indigent, and from our evidence, makes people more productive as well. Making it universal is important, so that they do not attempt to identify the poor (which is very difficult to do effectively in poor countries).
Rigorous identity management techniques are crucial to the success of programs designed to help lift the world's most vulnerable people.

First, they are important to establishing the scientific validity of a given approach.

Second, they are necessary to prevent the corruption that de-legitimizes social programs.

Tuesday, May 10, 2011

Part VI: Filling in the framework, subjectivity and interpretation

Introduction
Part I: The Right to Privacy
Part II: The Nature of Consent
Part III: Transparency
Part IV: A Framework for the Consideration of Privacy Issues
Part V: Filling in the framework; Absolute advocacy dos and don'ts

Part VI: Filling in the framework, subjectivity and interpretation
The last chapter ended with the assertion that it was reasonable to take an absolutist position on privacy issues in only three of the sixteen entire sections of the proposed privacy framework. In two (green) sections it is reasonable, perhaps incumbent on privacy advocates to lobby, influence, cajole and otherwise perform their proper, responsible role in society. In one of those sections (red), they have an absolute duty to forebear from any and all activity, lest they invite the label of hypocrite at best and aspiring tyrant at worst.

There is also a third region of the framework where things aren’t settled -- where in some cases there would be room for uninvited third parties and sometimes there wouldn’t be room for uninvited third parties to advance the societal privacy debate. In order to complete the traffic signal metaphor and with sincere apologies to any number of African countries, let’s use yellow.

How one fills in the rest of the framework is necessarily going to reflect a fair degree of subjectivity.

Using the colors:
Green -- It’s everybody’s business;
Red -- It’s none of your business;
Yellow -- Let’s talk about it;

there are an infinite number of ways individuals can fill in the chart.

The point of this exercise isn’t to determine precisely where the boundaries are, it is firmly to establish that these categories exist and to start a conversation that can begin to generate consensus about where, approximately, they lie.

The minimal case, outlined above and in Part V would look like this:
Someone else might fill it in like this:
This
Or this
Outside of the red and green areas isn’t some zone of silence where nobody has any right to an opinion. One is free to express an opinion on anything one wishes. Others are also free to mock, scorn or ignore that opinion.

One that wishes to tread into the yellow area should be prepared first to state the issue, explain why it’s worthy of public consideration and how their recommendation improves the status quo.

Monday, May 9, 2011

Credential theft out of control

Ineffective, weak or stolen credentials continue to wreak havoc on enterprise security, while stolen passwords and credentials are out of control. (ITWeb.co.za)
The 2011 report investigated approximately 760 data breaches and finds that hacking (50%) and malware (49%) were the most prominent types of attack, with many of them involving stolen credentials and passwords.

As in previous years, the vulnerabilities created by conventional access credentials feature among the report's key findings.
The username/password bloom is off the ID management rose.

The Glorious End Of User Names And Passwords

Will your iris unlock the world? (Forbes)
It's about ROI (return on investment), after all. But it's also about people.
Yes, the idea that your identity will be, captured on camera and put in a data base may set off the ultra liberal and conservative elements within our society. But the real issue here is not for those who worry about the government monitoring your activities; where you are going or what you are buying. This is about protection--the real issue is what it would cost both you, in your personal life, and the government, in its attempt to be as secure and fraud-free as possible, not to employ this technology?
I agree with the author's premises. Username/Password as an ID management technique is pretty far past its sell-by date when it comes to managing access to anything the user considers important. The status quo is unsustainable.

There is substantial ROI in adopting biometric ID management techniques. Biometrics will not be foisted upon an unwilling populace. They will be demanded by informed people who wish to conduct their affairs in a more secure and efficient environment.

I do, however, disagree with some of the author's conclusions.

There is no "magic bullet" biometric modality: not iris; not face; not voice; not finger; palm vein, DNA, etc. -- nor will there be for the foreseeable future. They all have limitations flowing from the environment in which they are deployed and the individuals they must serve.

I'm also very sensitive about overpromising and underdelivering the promise of biometric identity management. This derives from our experience of the damage done to the reputation of the biometrics industry as a result of such behavior in the past. Following 9-11, there was no shortage of those claiming to be able make all identity management dreams come true through biometrics. They raised big money and a lot of people got burned. Not all of this was unpredictable or solely the industry's fault. A lot of people who might have known better threw a lot of money around and someone was going to be there to catch it. But real damage was done.

The author of the linked piece is also quoted in this Fast Company article.

See also: Iris Biometrics in the news

Friday, May 6, 2011

Pre raid bin Laden Face-Rec confirmation

Facial Recognition Software Helped SEALs Nab Osama bin Laden (FOX - Sacramento, CA)
During the years long process of tracking down public enemy number one, a break came in September 2010. That's when Osama bin Ladin was captured exercising in the yard of his Abbottabad compound by a satellite armed with facial recognition software.
Add this to the list of reasons not to do bench presses... at least not outside.. if you're a known terrorist.. and the number one target of the world's most lethal organizations.

CIA analyst 1: Holy crap! Is that bin Laden down there pumping iron?
CIA analyst 2: Where?
CIA analyst 1: Right there, next to the burning trash pile.
CIA analyst 2: Well I'll be.. sure looks like him. Run him through the face rec!

We posted here about the post-mortem face rec verification. This is the first I've seen of a face-rec verification before the raid.

UPDATE: Most every initial report about the events surrounding the bin Laden take-down have been wrong so some skepticism is in order. I can't vouch for the fact that there was satellite based recognition. But if a satellite can get a decent-quality image of a person's face, there is no technological reason why that image cannot be processed through a facial recognition system. Since face recognition is exactly that, face recognition, not top-of-the-head recognition, the bench press (where the exerciser is on his/her back ) is one possible way that a satellite would get such an image.

Clubs to keep fighting proposed pokies reforms, despite concessions

The Australian
As independent MP Andrew Wilkie confidently declared he had the numbers to push gambling reforms through parliament, Clubs Australia said the blueprint for change handed down by a parliamentary committee today was a “dog's breakfast”.

Clubs Australia executive director Anthony Ball said the pre-commitment scheme, allowing players to set a limit on how much they are willing to lose, would cost clubs billions and force taxpayers to pay massive compensation to venues.

“This is a mandatory pre-commitment scheme which is a licence to punt,” he said.

“There is not a scintilla of evidence that this will help problem gamblers. This is just a system designed to inconvenience recreational gamblers.”
We've followed this closely.

It's nice to see the Clubs Australia folks finally starting to stand on their hind legs. Problem gamblers and privacy-loving Australians everywhere need them right now.

Problem gamblers deserve the tools they need. The proposed rules are worse than the status quo.

For an explanation of why and much more on the subject please consider the posts at the link.

South Africa Criminal record checks go biometric

IT Web
SA's newest credit information bureau, Inoxico, last week unveiled a biometric fingerprint scanning facility as the sector needs to comply with the police's digital system.

The move is expected to speed up industry queries into whether prospective employees have criminal records. CIO Marius van Niewenhuizen adds the biometric facility will also help clear job applicants who are incorrectly thought to have records, because of inaccuracies when data is captured.(emphasis mine)
The bolded section is often overlooked in the Identity management conversation.

Thursday, May 5, 2011

Malaysia to start fingerprinting visitors

Foreigners entering and leaving the country will have both index fingers scanned at Immigration checkpoints beginning next month (New Straits Times)
The procedure is a new security feature to curb transboundary crime and terrorism.

Called the biometric fingerprint security system, it is aimed at enhancing security in the immigration clearance process, which currently involves only the stamping of passports and matching photographs in the passports to faces.

And Also:
Malaysia to start fingerprint check of foreigners (Press Trust of India)
Immigration officials said that with rampant forgery of travel documents nowadays, the biometric system would allay this worry.
Immigration Department director general Mr Alias Ahmad said such a security measure was deemed necessary in view of the increasing number of foreigners who had abused their privileges as visitors.
It is commonly assumed that governments implement biometric ID management techniques in some Orwellian effort to control people. But governments have obligations to their citizens and to neighboring countries. They have a duty to their citizens to prevent their victimization by those who would do them harm and they have a duty to neighboring countries not to provide a safe haven for those who would victimize citizens of neighboring countries.

Malaysia's strategic location abutting some of the world's most important sea trade routes subjects it to risks that it has an obligation to address (see: Don’t mess with Malaysia, human traffickers warned (The Star)). Biometric technologies can help countries develop the efficient and needed law enforcement mechanisms that other countries spent much more time and money to implement.

Malaysia (CIA World Factbook)

Wednesday, May 4, 2011

Israel to issue 'world's most secure passport'

Biometric passports will include computer chip with photo, finger prints (ynet)
After years of delays Israel is finally getting ready to embark on a new age of biometric identification. In the coming months, Israeli citizens will be asked to replace their old passports and identity cards with new sophisticated means of identification.
Perhaps because Israel's other security methods are so effective, Israel is actually somewhat late to the biometric passport party.

Tuesday, May 3, 2011

Part V: Filling in the framework; Absolute advocacy dos and don'ts

Introduction
Part I: The Right to Privacy
Part II: The Nature of Consent
Part III: Transparency
Part IV: A Framework for the Consideration of Privacy Issues

Part V: Filling in the framework; Absolute advocacy dos and don'ts
Using the framework proposed in Part IV, there is certainly proper role for privacy advocacy in a free and open society.

With any interaction that can be categorized as mandated/opaque or mandated/vague a privacy advocate can be seen as simply using their right to free speech to argue for their own individual privacy rights. Since mandated interactions are mandated by the government and laws, ideally, are enforced equally, any change the privacy advocate spurs affects everyone. In a democracy this is completely appropriate.

The same can be said for interactions falling within the mandated/customary and mandated/transparent categories, but these are likely to be well-worn areas in the marketplace of ideas with little space for advocates to advance the public debate.

The other region of the framework that will attract advocates is the area of the opaque interactions to the right of the mandated section. But since the further right you move along the x-axis, the more consensual the interaction, the character of the advocates’ actions changes. Activity in this region is no longer petitioning the government for changes to the laws under which everyone must live; it is more nuanced than that. Activities in this region must attempt to educate individuals about the nature of these interactions or they short-circuit an individual’s freedom of choice by attempting to make the issue a legal one. Depending upon the issue at stake, either activity might be appropriate, but there is a real and substantial difference between the advocate’s activities re mandated and more consensual interactions.

So there are two regions of the framework that are sure to attract privacy advocates, where they have a legitimate role even though the nature of that role might change substantially.

There is also at least one region of the chart where there is absolutely no role for a privacy advocate who wishes to avoid invading the privacy of others and earning the label of hypocrite. That region is, of course the explicit/transparent area. An advocate who wishes to intrude upon this area does not wish to protect an individual’s right to privacy; he wishes to dictate the behavior of private individuals according to his own aesthetic.

The chart below shows the area of the previously suggested framework where it is reasonable to take an absolutist position. Advocates have an absolute right to act within the green area, and an absolute duty to refrain from activity in the red area (click to enlarge).


Part VI: Filling in the framework, subjectivity and interpretation

Biometrics critique or parody of a biometrics critique?

Osama bin Laden’s Identity Confirmed With Biometrics Technology. You’re Next — and You Should Care (Forbes)
But don’t forget this. Iris-recognition technology already has evolved to the point where authorities can very quickly scan members of a crowd from a distance of 10 feet, a figure expected to increase dramatically. That means that they can scan your eyes without your consent. Forget about Apple tracking your iPhone or the government infringing your Fourth Amendment rights with GPS technology. Iris tracking allows authorities to track you with extraordinary precision. Tom Cruise taught us that. And if you’re willing to be tracked without consent and place your faith in your iris’ uniqueness to vouch for your identity, remember that technology is always fallible. It will fail, and citizens will be misidentified, in some cases with grave consequences when not also confirmed by DNA matching.
I'd have to say that it's more likely a parody of an anti-biometrics article than a real anti-biometrics article because the arguments are transparent howlers.

Exhibit A: "Tom Cruise taught us that."
Exhibit B: "if you’re willing to be tracked without consent..." this is very close to an oxymoron.

No serious person would write those two things especially in consecutive sentences. Either this is class A parody or I weep for Yale, Steve Forbes and horses everywhere.

Monday, May 2, 2011

bin Laden & Face-Rec

It's not absolutely clear whether the recognition was done pre- or post-mortem (I'd assume the latter) but..

bin Laden identity confirmed with facial recognition (Washington Post)
U.S. forces flew to bin Laden’s hideout in helicopters about 1 a.m. Monday (late Sunday afternoon in Washington). Bin Laden was shot in the head after he and his guards resisted the U.S. attackers, the Associated Press reported. U.S. personnel identified him by facial recognition.

UPDATE: Looks like it was post-mortem (Politico) - way down at the end...
U.S. forces took photographs of the body, and officials used facial-recognition technology to compare them with known pictures of bin Laden.

Friday, April 29, 2011

People are sick of passwords

It's becoming obvious that users interacting with more and more networked systems and services are being crushed under the burden passwords impose if they are to be used effectively to maximize security.

Pass On Passwords (Harvard Crimson)
Think for a moment about your bank account password. There's a good chance it's a string of letters and numbers you know by heart, could type in your sleep, and have been using for years. You probably use it for at least one other website, too—a security study last year found that 73 percent of people use their bank password elsewhere.

Template only biometric applications are far superior to passwords and they sidestep the concerns raised about biometrics in this article. Middleware providers like SecurLinx can ensure against ID management risks even in the event that the templates are stolen, even if the customer doesn't even know they have been stolen.

Biometrics work.
Passwords are lame.

I believe we are nearing a tipping point where ordinary individuals begin more vocally to demand biometric ID management solutions. The status quo doesn't work and we're not going to be taking a time machine back to the single-password bliss of 1995.

Hotel security: biometric identification coming

There are lots of good ROI opportunities for hotels that embrace biometric identity management technology.

The most significant installation that comes to mind is fingerprint room access. I don't have the numbers but the card key system has to be pretty expensive to maintain and it's not particularly secure.

The card key process is so error prone that reception staff rarely ask me any clarifying questions or require me to present an ID before they reissue a card key allowing access to my room.

Reception-less check-in for affinity programs might also be another high value application.

Vanguard (Nigeria)
The Nigerian Tourism Development Corporation (NTDC) has said that biometric system of identification in hotels will go a long way in stemming the increasing rate of criminal activities in the industry.

Wednesday, April 27, 2011

'Identity Ecosystem' Initiative

A small investor perspective on the companies in the identity management sphere that have expressed support for the initiative...

The Obama Administration on April 15th launched an initiative to create an ‘Identity Ecosystem’ (SeekingAlpha.com)
The vision is to create an ecosystem whereby individuals, businesses, and other organizations enjoy greater trust and security as they conduct sensitive transaction online. The ecosystem would enable consumers who want to participate to obtain a single ‘trusted credential’ from a public agency or private secure ID provider that can then be used to obtain access and conduct transactions with online businesses without having to give confidential personal information to each business as is the case right now.

90% of organizations have problems with password resets

In a revealing survey of IT managers...
5% claim that it placed a huge drain on resources (Net-Security.org)
65% said that, if reliably deployed, biometrics or voice print technology would probably or definitely play an increasing role in IT security.
More survey results at the link.

There is a lot of scope for positive ROI in applying biometrics to logical access control.

Tuesday, April 26, 2011

Part IV: A Framework for the Consideration of Privacy Issues

Introduction
Part I: The Right to Privacy
Part II: The Nature of Consent
Part III: Transparency

Part IV: A Framework for the Consideration of Privacy Issues
As discussed in section one, the right to privacy is an individual right to decide for oneself what information to share. Moreover, the exercise of other fundamental rights requires the individual to sacrifice privacy in the service of what they determine to be a higher value. Anyone who cares to disagree will inadvertently prove this assertion because one cannot maintain absolute privacy while expressing ones thoughts and beliefs. They would have to sacrifice some measure of their privacy in order to exercise their freedom of expression to communicate their disagreement.

Privacy, therefore, is akin to currency. It’s fine for a person to trade it for things they consider to be of higher value. It’s wrong to steal it. Some transactions, in retrospect, are seen to have been a good deal; some may seem less so. One person may be quite willing to engage in transactions that are beyond the comprehension of another person. Consent matters and consent reaches its most fulsome expression when the terms of the exchange are transparent.

Having established a conception of the Right to Privacy, the Nature of Consent, and Transparency, we are in a position to lay out a framework for public debate on privacy issues and, later, the scope for the role of self-appointed third parties in that debate.

All transactions bearing upon an individual’s privacy can be described in terms of the transparency of the exchange and the level of individual consent to the exchange.

(click image to enlarge)

Transparency
-Opaque. The individual has absolutely no knowledge about how the relevant privacy information may be used or by whom it may be used.
-Vague. The information may be used in ways that the person who shares the information would not reasonably suspect.
-Customary. The information may be shared in ways that the person would reasonably suspect.
-Transparent. The terms and conditions stating the exact circumstances under which the information may be shared are published and acknowledged to be understood by both parties.

Consent
-Mandated. An individual has no legal right to withhold information they might wish to keep private. Refusal to cooperate may entail incarceration or fines.
-Contingent. In order to engage in a certain relationship or arrangement or partake of a privilege an individual is required to share information they might otherwise prefer to keep to themselves.
-De facto. Through convention or common acceptance -- so widely understood as not to require explicit codification. Common sense.
-Explicit. Formally accepted -- signified by positive acts such as gestures, speech, oaths, affirmations or contracts.

Although, there is room for disagreement as to the exact character of each individual privacy transaction (which of the chart's boxes it fits into), they can all be placed somewhere on the chart above.

Hopefully, the above framework can start to break Privacy into more manageable pieces in furtherance of enhanced understanding of this issue that is so important to us all.

Next:
Part V: Filling in the framework; Absolute advocacy dos and don'ts
Part VI: Filling in the framework, subjectivity and interpretation

Monday, April 25, 2011

New Aussie gambling system memo leaked

So, what was the point again? (News.com.au)
The Gillard Government is moving to introduce the system of mandatory pre-commitment in clubs and pubs next year as part of its deal with Independent Tasmanian MP Andrew Wilkie to retain his support to remain in government.
Oh, that's right; I remember now.

Earlier posts on the subject:
Australian gaming industry may be catching on
Biometrics shut out of Australian problem gambler program
Most Unfair biometrics article in a long time
More on Australian Politics and Gambling

Alabama joins Secure Communities

Thirteen Alabama counties will begin participating in the Secure Communities system Tuesday (AL.com)
Alabama is the last state in the South to begin using a federal program for locating and possibly deporting illegal immigrants with criminal records.
Jefferson, the most populous county in Alabama, is not included.

In the map below, the participating counties are gray. The red lines show the approximate positions of Alabama's interstate highways.


Thursday, April 21, 2011

A fingertip solution?

Much of today's news seems to be coming from the UK.
Here's an article that applied biometric fingerprint technology to the challenges faced by those in positions of responsibility for the elderly.

Fingerprint recording technology has the potential to make life easier for elderly and vulnerable people (PublicService.co.uk)
Fingerprint biometric systems can help to support the safety and security of many people, ranging from the elderly and infirm to someone with an armful of shopping. For the elderly and vulnerable, it can help by allowing them to signal that they are up, are active during the day and have gone to bed safely. The technology is available to accurately scan and record fingerprints with reader technology that is robust and reliable. The other attraction is its simplicity in use, just requiring the reader to place the finger on a pad to take a positive scan. The pad won't be lost like a key or swipe card.

Electronic scanning of fingers or eyes is a simple registration technique for schools

But new laws could make it complicated (TES.co.uk)
Supporters of biometrics insist that concerns over privacy and data security are misplaced. Once a fingertip image has been taken electronically, it is then converted into a meaningless series of letters and numbers and the original image deleted. And while fingerprinting may have criminal associations, there is now a move towards face-recognition systems, which are unthreatening and user-friendly.

“We don’t ask parents’ permission, because all that’s required is a simple photograph,” says Kelli Foster, head of sixth-form at Sir Christopher Hatton School in Northamptonshire, where face-recognition technology allows sixth-formers to clock in and out. “But if the law changes, I’m sure our students will persuade their parents to sign up because they like the system. They won’t want to lose it.”
THE PROPOSED CHANGES

- Schools will not be allowed to process biometric information without written parental consent unless a student is aged 18 or over.

- Consent will be required from “each parent of the child”.

- The child’s consent will still be required.

- Alternative systems must be put in place so that, if permission is refused, children are not disadvantaged.
These technologies are being adopted because they are cheap, convenient and consumers and stakeholders are demanding them.

Most all biometric implementations in schools already have opt-out provisions. It is interesting to note that the proposed changes require an opt-in system which will impose additional costs on schools and parents and erode the return on investment (ROI) the technology provides to schools.

Wednesday, April 20, 2011

India UID: New Ways of doing business

by Nandan Nilekani (via MENAFN.com)
Another major purpose behind the UID is to address the problem of mobility in the country. With urbanization, the rate of migration too is on a high in India. And it is further expected to take a leap. By having the aadhar number, these migrants, be it the rural or urban migrants, will have a portable identity.

Nilekani further emphasized that UID will make public spending more transparent , equitable and effective . By making no duplication or diversion possible, the UID project will aim at ensuring public service delivery more convenient. "The whole concept is based on the inclusion point of view and not exclusion.
The world's poor deserve a legitimate individual identity. Biometrics can help.

Biometric Authentication the Key to Keeping Businesses and Users Happy

Biometric authentication is more convenient (ITPro.co.uk)
Biometrics aren’t just useful for protecting confidential data. Construction firm Killby & Gayford is using custom fingerprint readers (built for personnel management software supplier Simeio by Psion) that also record a signature. That means the firm can accurately log hours worked by sub-contractors on building sites and automatically generate invoices, as well as proving that workers have read the safety rules for each site and simplify checking the roll call if there’s an emergency. Using the information to generate accurate invoices has avoided concerns about spying on staff by showing the system is useful to everyone. But, equally, productivity has improved too.
A good survey of biometric modalities and applications.

Tuesday, April 19, 2011

Villages leapfrog the grid with biometrics and mobile money

In low-tech villages, biometrics and mobile money can level market spikes and allow a way for people to bypass the grid (Christian Science Monitor)
Widespread fingerprinting is controversial in Western nations, but in countries where births aren't recorded, people lack official identification, and many can't even sign their names, fingerprints might be a person's best shot at securing a bank account.
ID management is about people. Biometrics can help the worlds poor more fully participate in the markets that have lifted billions worldwide out of poverty.

Part III: Transparency

Introduction
Part I: The Right to Privacy
Part II: The Nature of Consent

Part III: Transparency
Transparency is a lot more straightforward than the right to privacy and the nature of consent. Transparency means, honest, up front and without deceit, free from sins of commission and sins of omission, making sure both sides understand the agreement rather than one side profiting from the counterparty’s difference in or lack of understanding.

Agreements lacking these qualities are murky and imprecise – opaque.

Since one must set aside some measure of privacy in order to exercise other rights (speech, contract, association), the terms under which privacy is set aside tends to be important to the individuals making the calculation. In the overwhelming majority of circumstances, people prefer to be dealt with in a transparent and straightforward way. When they are not, they will consider their privacy rights to have been violated.

Next:
Part IV: A Framework for the Discussion of Privacy Issues

Part V: Filling in the framework; Absolute advocacy dos and don'ts
Part VI: Filling in the framework, subjectivity and interpretation

Monday, April 18, 2011

Four Factor Authentication

The fourth factor is location (SCMagazineUK.com)
This is one of those articles that is a grab-bag of interesting identity management stuff.

If the fourth factor is location, we're obviously talking logical access control since with physical access control, location isn't in doubt.

For physical access control, a fourth factor might be time, i.e. your credentials only open the door at certain times of the day.

But time can also be a part of the 4th factor in logical verification if, for instance, your bank wanted to know about it if you use your bank card in the Enid, Oklahoma Wal-Mart fifteen minutes before "you" use the same card in St. Petersburg, Russia. Since you cant get from Enid to St. Petersburg in 15 minutes, there's a chance something is amiss.

As they say, read the whole thing.

See also: Biometrics in Emergencies which also touches upon the time factor in physical access control systems.

California "Do Not Track" Bill Introduced

Interest in Do Not Track legislation increased after the Federal Trade Commission issued a report in December backing the concept (mondaq.com)
The regulations issued by the Attorney General would require "covered entities" to disclose to consumers in an "easily accessible" manner information on their collection, storage, use and disclosure practices, including to whom the information is disclosed. S.B. 761 also allows, but does not require, the Attorney General to issue regulations requiring covered entities to provide consumers with access to their data and privacy policies, in a format that is "clear and easy to understand."

I think we'll be seeing more of this type of thing for several reasons: there are companies out there who sell information about individuals; the individuals don't know about it; the information is often inaccurate; negative consequences fall upon everyone but the seller of the information.

See also: Errors plague the database state

Friday, April 15, 2011

UK Headteachers condemn new biometrics legislation

Heads’ anger at ‘backward step’ on fingerprints (Liverpool Daily Post)
The Association of School and College Leaders (ASCL) warned the move will cost the education system between £20m and £45m a year.

It is thought that around 30% of secondary schools use finger or face recognition for a number of reasons, such as allowing pupils to check out library books, pay for lunch in the school canteen or access certain school buildings.

Evidence suggests that in these schools that have so-called biometric systems, 99.8% of parents have no objection to it, the ASCL said.
Fingerprint systems that store only an algorithm-generated template rather than an image of a fingerprint pose little-or-no threat to a person's biometric privacy.

On the positive side: for the student, fingerprint biometrics offer increased privacy* and safety**; the school achieves higher data integrity and increased operational efficiency. These benefits are not simply confined to the schools themselves. All taxpayers have a stake in the efficient use of educational resources.

If schools are unable to keep data secure, biometric template information is the last thing that should concern parents or civil liberties campaigners.

Schools also keep academic records, behavioral records, medical records & counseling notes which are much more sensitive than a string of binary gibberish that cannot be used to learn anything about a student.

*Privacy: If everyone uses a finger to buy lunch, no one knows who receives need-based subsidized or free lunches.
**Safety: No lunch money, no bullying to steal lunch money.

Thursday, April 14, 2011

Lockheed Martin Named Biometrics "Company of the Year" By Frost & Sullivan

Award Recognizes Leadership in Biometrics Innovation, Customer Value (WebWire press release)
Lockheed Martin has been named the North American Biometrics Operations and Integrations “Company of the Year” by Frost & Sullivan, recognizing the Corporation’s success in delivering innovative biometrics solutions that offer high levels of customer value.

South Africa: Smart ID card revived

The smart ID card project will be rolled out in the 2012/13 financial year (ITWeb.co.za)
“The full spectrum of identity management goes beyond mere issuance of secure documents; it encompasses the safe maintenance and archiving of biometric and demographic records of citizens and persons who have been permitted to reside in SA,” said Dlamini-Zuma.

Blowback: Kerry-McCain US privacy Bill of Rights

A couple of sources are all over the Kerry-McCain bill released yesterday.

Privacy 'bill of rights' exempts government agencies
(cnet.com - Declan McCullagh)
"What's a Bill of Rights if it doesn't provide rights against the government?" asks Jim Harper, director of information policy studies at the free-market Cato Institute.

Privacy bill of rights excludes big government (Examiner.com - Dan Nowacinski)
Kerry and McCain are saying, "Do as I say, not as I do.'" If they want to lead on the privacy issue, they'll lead by getting the federal government's house in order.

ICE Secure Communities adds counties in MD, MI & SC

Maryland (Press Release via Yahoo)
On Tuesday, U.S. Immigration and Customs Enforcement (ICE) began using the Secure Communities program in Alleghany, Garrett and Washington counties to help federal immigration officials identify criminal aliens in state prisons and local jails by running their fingerprints against federal immigration databases when they are booked into the system.

Michigan (Press Release via Yahoo)
U.S. Immigration and Customs Enforcement (ICE) began using the Secure Communities program in seven Michigan counties including Allegan, Barry, Calhoun, Jackson, Kalamazoo, Muskegon and Ottawa...

South Carolina (The Times and Democrat)
U.S. Immigration and Customs Enforcement has started using the Secure Communities program in Orangeburg and other counties to help identify criminal aliens in local jails by running their fingerprints against federal immigration databases.

The Maryland counties added are of local interest to us here in West Virginia. All three counties border West Virginia. Garrett county lies about 25 miles east of Morgantown.