Tuesday, June 16, 2015

US: Face recognition code of conduct confab loses privacy advocates

The National Telecommunications and Information Administration (NTIA) has convened a privacy multistakeholder process regarding the commercial use of facial recognition technology. On December 3, 2013, the NTIA announced that the goal of the second multistakeholder process is to develop a voluntary, enforceable code of conduct that specifies how the Consumer Privacy Bill of Rights applies to facial recognition technology in the commercial context.

Privacy Advocates Walk Out in Protest Over U.S. Facial-Recognition Code of Conduct (The Intercept)
“At a base minimum, people should be able to walk down a public street without fear that companies they’ve never heard of are tracking their every movement — and identifying them by name – using facial recognition technology,” the privacy advocates wrote in a joint statement.
The quoted article is full of links to NTIA online resources.

An "open letter" of resignation on the part of the named privacy advocates lists their concerns here.
Concluding paragraph:
We hope that our withdrawal signals the need to reevaluate the effectiveness of multistakeholder processes in developing effective rules of the road that protect consumer privacy – and that companies will support and implement.
Ultimately, of course, these are political questions rather than technological ones, but the focus on one type of technology (facial recognition) is a little difficult to understand. If it's wrong for a private corporation to track an unsuspecting individual's every movement, identifying them by name, why single out facial recognition (the means) rather than the tracking (the end)?

The privacy advocates, however, have a point in their favor. The effectiveness of confabs of privacy advocates, sub-cabinet-level administrators, and corporate executives in defining a society's scope for privacy in public should be questioned.

Also mentioned in the article is the fact that the states of Texas and Illinois have passed laws limiting the use of facial recognition technology to identify individuals in public without their affirmative consent.

Amazon envisions another way to unlock a phone: Ear photos

Forget Fingerprint Scanners, Amazon is Interested in Using Your Ears to Unlock the Phone — Here’s Why it’s Better (Technology Personalized)
The world’s largest e-commerce company was granted a patent last week that reveals company’s intention to ease up the unlocking mechanism in a phone when a user receives a call without any security tradeoff.

No need to forget fingerprint scanners just yet, though.

Monday, June 15, 2015

UK: Leicestershire police trial face recognition at music festival

Download Festival: Facial recognition technology used at event could be coming to festivals nationwide (The Independent)
Around 90,000 people attending the five-day rock event in Derby will have their faces scanned by “strategically placed” cameras, which are then compared with a database of custody images across Europe.

The force has trialled the system since April 2014 in “controlled environments”, but this is the first time the portable NeoFace surveillance technology, made by NEC Corporation, is being used outdoors in the UK on this scale.

Leicestershire police said it hoped the system would enable them to find organised criminals who prey on festivalgoers who are often victims of theft.
This sounds a lot like the 'Snooper Bowl' deployment we had a role in back in 2001.

Facial recognition surveillance in an uncontrolled environment with non-participating individuals still presents significant technical challenges. Among them are lighting, pose angle, and perhaps most significantly, training users on how to evaluate the information the facial recognition system generates.

See also: Leicestershire Police defend facial recognition scans (BBC)

Friday, June 12, 2015

Peru: Prepaid mobile sales will require fingerprint verification against national ID database

...with an assist from Microsoft Translator

From now prepaid mobile lines will be sold with fingerprint identification of users (Osiptel)
The operators will be required to verify the identity of users wishing to hire mobile public services in their offices, in the form of prepaid. This identification will be held from today through biometric fingerprint verification systems, which will be connected with the RENIEC database.
Full implementation is to be accomplished by January 1, 2017.

Thursday, June 11, 2015

Biometrics industry overview

Breaking Down Biometric Security (TechZone360)
Biometric security isn’t a new phenomenon, but until recently its real life applications and benefits have been underutilized by companies in most industries. However, recent buzz worthy announcements like Apple using Touch ID for enhanced security as part of Apple Pay and Miami International Airport integrating biometric fingerprint data into their passport control kiosks, are proving that biometric security is finally poised to become the norm.
Read the whole thing. The piece does a really good job of tying together various issues in the overall biometrics landscape.

Wednesday, June 10, 2015

Changing of the Guard at Secure Identity & Biometrics Association

SIBA Names Troy Potter of L-3 National Security Solutions as Chairman; SIBA Selects Commercial Identity Expert to Lead Growing Member Association (SIBA)
SIBA is a non-profit association that was established in February 2014 to steadfastly promote responsible policy, education and implementation of solutions that protect and secure identity across private and public platforms.

Potter was chosen because of his vast experience in both the government and industry. He served as the Identity Services Branch (ISB) Deputy Assistant Director at the U.S. Visitor and Immigrant Status Indicator Technology (US-VISIT) program and was US-VISIT's Biometrics

Systems Program Manager for a number of years, responsible for the management and oversight of one of the largest biometrics systems in the world. Today Potter is the vice president of L-3 NSS' Global Solutions Sector and leads all L-3 NSS Border Security and Biometrics programs.

Forecast: Global biometrics market in the healthcare industry will reach at CAGR of 31.95% by 2018

WhaTech.com
The Global Biometrics market in the Healthcare industry has also been witnessing the rapid technological advancement. However, the strong competition from inexpensive non-biometric technologies could pose a challenge to the growth of this market.

Friday, June 5, 2015

Canada announces biometric requirement for visa holders

Biometric data collection evolves and expands in Canada (CBC)
Citizenship and Immigration Canada told CBC News that digital photos and fingerprints are "the only biometrics data applicants will have to provide" under the government's plan for expanded collection of data. Visitors will have to pay $85 to cover the cost of data collection.
Travelers who don't need a visa to travel to Canada are, apparently, unaffected.

Wednesday, June 3, 2015

Then again, probably not

Brain's reaction to certain words could replace passwords (Binghampton University)
According to Sarah Laszlo, assistant professor of psychology and linguistics at Binghamton University and co-author of "Brainprint," brain biometrics are appealing because they are cancellable and cannot be stolen by malicious means the way a finger or retina can.
"Just 12 more globs and some wiring and you can check
your email!"

Image source: Biosemi.com

When the alternative is the terrifying prospect of a stolen retina*, I guess you can't be too careful.

But, let's not get ahead of ourselves. Though there is little doubt that if any behavioral biometric can be used as a reliable identifier, evidence for that uniqueness could probably be found in the brain, measured, and used for ID purposes. Even so, brain prints as ubiquitous biometrics face every obstacle we discussed in our post, The challenges confronting any new biometric modality, and then some.

The linked article doesn't make any mention of the sensor to be used to collect brain prints, much less offer a vision for how a future identification scenario might work.

This is one of those subjects that is intensely interesting from a Ph.D. candidate's point of view (invention) but not so much from an engineering or business perspective (innovation). Brain prints as a biometric will face significant — I dare say insurmountable — challenges in finding their way into wide use as a commercial ID management application any time soon.

The 94% accuracy is an issue, too.

*See also:

Iris ≠ Retina

Iris (left); Retina (right)


In fairness, the penultimate paragraph in the article quotes Zhanpeng Jin, who brings a more moderate perspective to the piece.

Tuesday, June 2, 2015

The automation revolution will be biometric

Robot check-in: The hotel concierge goes hi-tech (BBC)
It will be staffed by 10 life-like robots, with only two flesh-and-blood staff members on the premises.

The robots will greet guests, carry bags, and even clean rooms once a guest leaves. Complete with an eerily realistic female face, they are designed to speak several languages and respond to guest enquiries in the 72-room hotel.

The aim is to create an all-round hi-tech experience, including facial recognition software to open doors.

The automation revolution will be biometric (cont'd)

Self-Service Technology Market is Expected to Reach $31.75 Billion, Globally by 2020 (Press Release via NJ.com)
The technological advancements such as wireless communication and remote management would also facilitate the overall market growth. In addition, the integration of biometric security services such as fingerprint recognition, which ensure secured financial transactions, would boost the market growth.

Monday, June 1, 2015

Ubiquitous banking biometrics by 2020

Biometrics to become the predominant method to identify bank customers by 2020 (Goode Intelligence)
Growth in the banking industry will be accelerated by a number of factors including the arrival of electronic devices with built-in biometric support (notably smart mobile devices), the adoption of biometric-friendly authentication standards such as FIDO, the pressing need to combat rising banking fraud and identity theft, the growth of mobile banking and the emergence of wearable banking.

Thursday, May 28, 2015

US: IBIA wants NIST to do more for biometrics

NIST Urged to Expanded Role of Biometric Authentication (Find Biometrics)
...IBIA Vice Chairman Walter Hamilton pointed to recent years’ “surge in the use of biometric technologies for mobile banking and other e-authentication applications,” adding that “NIST should support this trend by providing guidance on how to ensure the effective implementation of biometrics as an authentication token rather than narrowly limiting its use.”

Enrolling a fingerprint in Windows 10

Windows Hello Biometric Authentication at Work in Windows 10 - Video (Softpedia)

Video (no audio) at the link.

Also, there is no mention of the fingerprint hardware used.

Still, if you've never seen a fingerprint enrollment before, you can see one now.

Wednesday, May 27, 2015

Biometrics for library convenience

Enabling patrons to log in and check out with a swipe of the finger (American Library Association)
Paul Sawyier Public Library implemented a biometric identification system in October 2008. Since then, patrons who sign up for a library card have the option to enroll in the finger identification system, which is required only when using the public computers and the media box located in the lobby. To check out materials or log on to computers using the system, a patron simply places his or her finger on the biometric scanner located at each station. Patrons checking out other materials can use their library cards as they always have.

Asia-Pacific region lagging in counter-terror biometrics

Interpol pushes for more use of biometrics to ID terrorists (Computerworld)
Interpol is calling for Asia Pacific authorities to make better usage of biometrics to identify members of terrorist groups such as ISIS.
...
“Europe provides 26 more times fingerprint data than the APAC region and 623 times more DNA data. Yet, we know the [APAC] region has the technology and does make use of it at national levels.”
The Europe-Asia comparison is even more dramatic considering the size of their respective populations.
Biometric facial matching for outbound Aussie passengers accelerated (Government News)
Australia’s Immigration and Border Protection authorities have revealed an accelerated plan for the rollout of new automated biometric facial recognition gates at Australian airports for outbound Australian passport holders and some travellers departing the country as part of $630 million counter-terrorism sweep.

Tuesday, May 26, 2015

India: Income tax department sees value in UID

I-T department exploring ways to seed PAN with Aadhaar (Live Mint)
The income tax department is exploring ways to hasten the pace of seeding permanent account number, or PAN, with the unique identity number Aadhaar, a move that will weed out duplicate PANs and help the government’s drive against tax evaders.
This would allow the Income Tax Department to maintain its own ID numbering system for its own purposes — they may tax entities such as corporations that don't have biometrics, after all — while harnessing Aadhaar for detecting tax fraud among individuals.

China: Regulators reluctant to allow online bank account creation

Chinese Regulators Put Brakes on Facial-Recognition for Payment (PYMNTS.com)
Currently, in China, a customer must physically appear at a bank to have his or her identity verified by an employee before he or she can open an account. There is a push in the industry, the report points out, for facial-recognition software to replace the need for a customer’s physical presence to conduct banking business.
China seems to be drawing a regulatory distinction between what ID requirements should be in place in order to open a bank account versus what ID requirements banks can use for authenticating transactions.

Wednesday, May 20, 2015

IBIA objects to TSA's planned identity management protocols for PreCheck

IBIA questions TSA plan on PreCheck expansion (Planet Biometrics)
The International Biometrics and Identification Association (IBIA) has objected to plans by the Transportation Security Administration (TSA) to exclusively use just biographic data solutions in an expansion of the PreCheck travel screening program.
There's an interesting quote in the piece that compares what the TSA is proposing to the fraud prevention techniques commonly used by credit card companies.

That alone should give pause. For credit card companies, fraud is an actuarial problem. Credit card companies earn 3-4% on every transaction plus interest fees for carried balances. There's plenty of room for both fraud and profit in that model.

The TSA's job is different, and perhaps their fraud prevention techniques should be, too.

Latest SecuGen Hamster fingerprint reader looks pretty slick

SecuGen Hamster Pro 20 (SecuGen)

Earlier versions of the optical fingerprint reader were much taller.

Souce: SecuGen
 

Tuesday, May 19, 2015

India: Biometric UID is good politics

For Modi government, UID the wild card that came good (Economic Times)
According to the Economic Survey, Aadhaar card enrolments were increasing at a rate of 2 crore per month. The government had seeded over 10 crore bank accounts with registered Aadhaar numbers by December 2014.
1 crore = 10 million

Friday, May 15, 2015

Massachusetts contemplating biometrics to curb welfare fraud

Bill proposes Mass. study implementation of fingerprinting, biometrics to reduce welfare fraud (MassLive)
Under the provision, the Department of Transitional Assistance and the Office of Health and Human Services would be required to study the feasibility of using biometrics - which includes fingerprints - to reduce fraud in public benefit programs.

The language, part of a $15.4 million amendment assembled by the House Committee on Ways and Means, cleared the House on a 158-0 vote Tuesday afternoon.
New York City actually implemented a system like this a few years back. It worked, too. Mayor Bloomberg liked it. Governor Cuomo didn't. Survey data at the time indicated that a majority (53%) of Americans favored such an approach.

See:
New York City: Fingerprints for Auditing Food Stamps (October, 2011)
Governor Proposes to Prevent New York City From Using Biometrics To Stem Welfare Fraud (May, 2012)

USAA mobile biometric authentication opt-in data

Biometrics Find Support from an Unlikely Demographic: Seniors (American Banker)
More than 400,000 USAA customers, five of whom are over 90 years old, have opted in to use biometrics (face, voice or touch) to authenticate themselves to the company's mobile banking application.
The median age for customers opting for biometrics is 3.5

About 7.5% are over the age of 65.

Four are in their nineties.

New biometrics advisors to focus on use cases

Market Research Firm Announces Biometrics Advisory Service (Find Biometrics)
Tractica’s approach is to focus on use cases, which Lockhart says “define the biometrics market opportunity.” The company has classified 142 use cases, and offers a profile specific to each with respect to “business function, industry, and modality.” And the advisory service consider a wide range of biometric modalities, from the widespread (fingerprint scanning, facial recognition) to the more obscure (electrocardiogram and DNA recognition).
Technology isn't an application, so the focus on use cases is appropriate.

Wednesday, May 13, 2015

Face rec in China

Current facial recognition technology can do more than guess your age, as businesses are finding out (Global Times)

Concluding quote:
Besides traditional application for a secure entry or time clock system, facial recognition technology can be used in other fields such as remote identification.

The market for facial recognition technology is ultimately decided by the population. China has an immense population, which makes it a potentially huge market, according to the report from Bosi Data Research Center.

"But customers should know that multimodal biometric identification is much safer than single biometric identification, especially when the technology is used in finance," Lü said. "We can't ensure the facial recognition technology can be 100 percent accurate, and it's safer if you can use other biometric identification together."
There's more good information at the link.

Fujitsu and NTT DoCoMo team up for mobile iris biometrics

NTT DoCoMo launches smartphone with iris unlock feature (PC World)
The Fujitsu prototype incorporated a high-speed, high-accuracy iris recognition algorithm developed by California-based Delta ID. Fujitsu said the error rate for the prototype is about one in 100,000.

Available in green, black and white, the Arrows NX F-04G is slated to be released at the end of this month in Japan for around ¥55,000 (US$460). There are no plans to sell it outside Japan.
I somehow missed the first mention of this collaboration in early March.

Friday, May 8, 2015

India UID: Interesting de-duplication and exception stats

Over 9 crore Aadhaar enrolments rejected by UIDAI (Zee News)

Out of 823.3 million enrollments, 97.3 million (Approx. 12%) have been rejected for reasons of either quality or duplication.

This may seem to be high to some, or low to others. In the big picture, there is (or should be!) a cost-benefit analysis at the beginning of the project that gets at the expense of the process vs. the infallibility of the process. On the first pass, it might make sense to get the highest proportion of good enrollments with the most convenient process, then to engage in a more expensive enrollment process applied only to more difficult enrollments.

It's also important to note that the 97.3 million rejected enrollments contain both duplicate applications, which must be rejected and other applications where clerical error, fraud, or un-enrollable biometrics are the reason for rejection.

Another interesting statistic in the article is that only about 618,000 UID numbers have been issued under the "Biometric Exception Clause" which allows for creating UID numbers for people whose biometrics cannot be enrolled. That comes out to around 0.07%.

What that means is that (depending on the number of people waiting for a biometric exception) using a data set approaching a billion individuals, at least 99.3% of the population of India is biometrically enrollable within the existing UID enrollment process.

Note: The article uses the Indian numbering units crore and lakh.

1 crore = 10,000,000
1 lakh = 100,000


See also: UID applications without biometrics highly likely fraudulent

Payments: Visa has some catching up to do

Visa Focuses on mPayment Expansion, Biometric Security (Find Biometrics)
Visa is ramping up its efforts to get into the digital payments game with an expansion of its digital wallet service and more intensive investigations into biometric security.

Forecast: Key biometrics industries and applications - 2024

Biometrics Market Forecasts (Tractica)
Tractica’s forecasts indicate that key industries in the biometrics market over the next decade are likely to be finance, consumer devices, healthcare, and government, followed by enterprise applications, defense, education, law enforcement, and non-government organizations. Key use cases that are likely to drive biometrics revenue over the next decade include consumer device authentication, mobile banking, automated teller machines (cashpoints), government IT systems, point-of-sale transactions, pharmacy dispensing, and wearable device authentication.

Wednesday, May 6, 2015

Fingerprints help end 55-year fugitive search

Fingerprint ruse IDs Florida man as longtime Ohio fugitive (MSN)
Authorities in Florida say a ruse to get a man's fingerprints led to his arrest as a convicted killer who escaped an Ohio prison farm and disappeared for most of six decades.

Brevard County deputies say investigators with the U.S. Marshals Service in Ohio sought help to check out the man while chasing leads about Frank Freshwaters, an Akron man who escaped in 1959. Major Tod Goodyear says they created a ruse to get the man to sign papers, then matched the fingerprints to those from the decades-old arrest.

Biometrics aid in aid delivery

IOM Uses Biometrics to Aid Displaced in Democratic Republic of the Congo (MENAFN)
The lack of identity documents for IDPs in the Eastern DRC poses a challenge in targeting humanitarian assistance. Almost 80 per cent of adults living in sites having no form of identity documents. In response IOM launched a biometric registration pilot project in eight displacement sites around the city of Goma in June 2014.

Between June 2014 and April 2015 IOM took the fingerprints of nearly 16000 IDPs. In the context of food distributions the collected information is used to ensure that humanitarian aid reaches the most vulnerable and avoids duplication and fraud.
Biometrics are an inexpensive, fast and accurate way of setting up ad hoc ID systems from scratch. Those interested in development and disaster recovery, take note.

Monday, May 4, 2015

US: Federal prosecutors want to use voice biometrics in court

Prosecutors want to use hi-tech evidence in trial to identify voices of terrorists (Daily Mail)
Terrorism prosecutors in Brooklyn want to use sophisticated voice recognition evidence — the same technology used to identify ISIS butcher “Jihad John” — for the first time in a federal trial in the U.S., the Daily News has learned.
The novel part of this that prosecutors wish to use the technology in a Federal trial.

Voice biometrics have made news in a criminal trial before. This 2012 piece by Jeff Weiner of the Orlando Sentinel describes voice biometrics used by an expert witness in the trial of George Zimmerman.

Tuesday, April 28, 2015

US GAO: To reduce fraud, MediCare smatrcards need biometrics

Smart cards would do little to curtail Medicare fraud: GAO (McKnight's)
...[K]ey [smartcard] benefits, including the ability to electronically exchange beneficiary medical information and electronically convey beneficiary identity and insurance information to providers, would do little or nothing to deter fraud, experts said.

Adding certain layers of protection to smart cards like biometric biometric information or a picture ID could help to deter fraud, the GAO said.
Note: GAO = Government Accountability Office

SIBA head testifies before congressional committee on border biometrics

Senate Homeland Security Committee calls SIBA's Kephart to testify (Secure
Identity & Biometrics Association (SIBA))

Testimony before the Senate Homeland Security & Governmental Affairs Committee
Tracking the arrival and departure of foreign visitors to the United States is an essential part of immigration control, law enforcement and national security. The need for arrival controls is obvious, but recording departures is also important; without it, there is no way to know definitively whether travelers have left when they were supposed to. Biometric entry/exit and transfer solutions are proven in their feasibility, low cost, added security value, increased efficiencies, travel convenience, and accuracy. Good products are available off the shelf. They are flexible and built, and can be customized, for many environments. The biometric, secure document and identity management industry is well-versed in integration with back-end data systems while building in flexibility for the future. Biometric solutions such as facial recognition, fingerprints and iris scans assure identity when coupled with biographic information found in travel documents. Using only biographic information, however, such as names or passport numbers, provides no assurance that the person departing is the one whose original arrival was recorded.
The quote above is taken from the pdf linked to the article at top. The 29-page document is an excellent resource for those interested in the topic.

Biometrics a factor in World Bank's optimism on India

While India’s Economy has Turned the Corner, Wider Reforms are Needed to Boost Economic Growth (World Bank)
The report points out that India’s government has begun to implement reforms to unlock the country’s investment potential - to improve the business environment; liberalize FDI; boost both public and private investment in infrastructure; quickly resolve corporate disputes; simplify taxation, and lower corporate taxes. States are set to receive more resources and spending power, and the government has reiterated its resolve to implement the GST by April, 2016, a move that is widely expected to meaningfully increase India’s tax to GDP ratio. New models of delivering benefits through direct transfers to bank accounts, together with the biometric identification of beneficiaries, are expected to reduce leakages.

Monday, April 27, 2015

India: UID milestone

Aadhaar world’s largest biometric ID system (Times of India)
The Aadhaar card has emerged as probably the world's largest biometric identification programmes in the world with the Unique Identification Authority of India (UIDAI) issuing nearly 82 crore cards.
1 crore = 10,000,000

We haven't been spending as much time on issues of economic development as we have at other times in the past, but India's major ID initiatives are creating a lot of opportunities to lift millions out of poverty.

Friday, April 24, 2015

Best comments thread I've seen in a while...

Biometrics May Ditch The Password, But Not The Hackers (NPR) — The piece itself is rather de rigueur, but the comments are a great way to start Friday.

It looks like that Paypal piece was pretty widely read.

Consent and Trust

Biometric Data Without the Big-Brother Angst (American Banker)
At the end of the day, biometric data is really just another type of personal data that banks hold, access and use with the trust of customers and employees. But obtaining consent should not just be seen as merely a bureaucratic necessity. It is part of a process by which banks can maintain and enhance trust — which only becomes more important in the age of big data and virtual relationships.

Thursday, April 23, 2015

Older Andriod versions had more vulnerabilities

Is Samsung's Galaxy S5 'leaking' YOUR fingerprints? Flaw means hackers can intercept and steal biometric data (Daily Mail); Forbes piece, here.
The pair told Thomas Fox-Brewster from Forbes that the flaw lies in older versions of the Android operating system, up to and including Android 4.4.

Subsequently, anyone running Android 5.0 or above are not at risk and the security experts are advising people on older models to update as soon as possible.
The semi-technical press seizes upon biometrics as a proxy for personal data. This is old news, but here's a great example.

A close reading of the article reveals that earlier releases of Google's version of the Android mobile OS weren't as secure as they are now. This will come as news to few. The article points out that, "Once inside they can monitor all data sent to and from the phone, as well as data recorded by the handset's built-in sensors, including the fingerprint scanner."

Get it? Exploiting the security flaw means that the whole device is compromised: Email apps, microphone, location information, and possibly even the contents of phone calls themselves, but according to the author and editor(s), the news value is in the possibility of capturing a fingerprint image. Of course, it's their outfit; it's their call.

For readers here, instead of "OMG fingerprinst[!]," I'd emphasize that:

Not all mobile operating systems are created equal.
Different mobile applications offer a different mix of privacy costs and benefits.
Installing OS updates and patches is very important.
If the OS is compromised, the applications it runs are vulnerable.

Left out of the information readily available online about this hack is how the people at FireEye got their malware onto the hardware in the first place. Past "hacks" of biometric systems have been executed on a playing field that is far more favorable than the real world to the the hackers, where all the other layers of the security regime are stripped away from the one security link they want to test. Here's a particularly striking example. If FireEye rooted the phone, side-loaded their malware onto the device, and went from there, this isn't a hack in any real sense — it's a malware test.

That hypothetical scenario would mimic a real world example where a user lost their phone and bad guys got it, loaded software on it and then returned the mobile device to the user who continued as if nothing had happened. In the security world, if you lose control of the hardware, all bets are off for anything that isn't encrypted (with a strong key).

So, without more information, it's hard to say how big a deal this is, or in many (most?) cases, was. In the bigger picture, this is a Google Android OS story. The subtext is that users who care about mobile device security should be thoughtful about what device/OS/app combinations they adopt, keep their device's software up to date, and be careful about malware.

As automated and convenient security including biometrics becomes better and more common, the highway robbers of the 21st Century are increasingly forced to turn to social engineering techniques rather than frontal assaults on security technology.

See: The Con is Mightier than the Hack



Wednesday, April 22, 2015

Monday, April 20, 2015

Looking for cyborg customers, or, I forgot to take my Paypill

Kill all passwords by eating them says PayPal (Techworld)
He says external body methods like fingerprints are “antiquated”, and that internal body functions like heartbeat and vein recognition using embedded and ingestible devices are the future, to allow “natural body identification”. LeBlanc says internal devices could include brain implants, and that ingestible devices could be powered by stomach acid that runs batteries.
Time will tell, I guess, but user acceptance has been has been a big issue for identity management solutions using biometrics. A bank asking customers to put something in their body in order to access their money would seem to be of another character entirely.

Perhaps the analysis is meant to provide a perspective on what far-distant ID management technologies will look like. Even then, with the exponential growth of the computing power in "externally carried computers" i.e. smartphones, it's hard to see how gaining a foot or so of proximity distance by moving the token inside the body lowers error rates enough to justify the mess.

The subtext is this, though:

"We know how to identify machines. People are a pain. If we can just turn the people into enough of a machine, all our problems are solved." In other words, engineering! There's a problem here, though. If you turn the machines into people, the machines will probably get harder to identify.

At SecurLinx, we'll keep at it just in case.

Thursday, April 16, 2015

US: Social Security Number is an unreliable identity management technology

Should We Kill the Social Security Number? (Huffington Post)
That's right: Social Security numbers were not intended for identification. They were made to track how much money people made to figure out benefit levels. That's it. Before 1972, the cards issued by the Social Security Administration even said, "For Social Security purposes. Not for Identification." The numbers only started being used for identification in the 1960s when the first big computers made that doable. They were first used to identify federal employees in 1961, and then a year later the IRS adopted the method. Banks and other institutions followed suit. And the rest is history.
Author: Adam Levin, Former Director New Jersey Division of Consumer Affairs; Chairman of Credit.com and Identity Theft 911.

There's a lot of good data in the article about just how much fraud is perpetrated against the IRS, fraud that is at least partly due to over-reliance on the Social Security number for ID purposes.

Wednesday, April 15, 2015

True cybersecurity requires a conceptual shift

The user knows nothing: Rethinking cybersecurity
This position — that the adversary knows your system as well as you do, if not better, as soon as it is stood up — while extreme, led to the creation of large number factorization, the basis for all modern encryption, from PGP to RSA tokens. Under these encryption schemes, as long as the key is kept private, someone can know everything about how the security system works and still not be able to crack it.

To get to a place of true cybersecurity, another stark innovation in thinking is needed. What is needed is an Inverse Shannon's Maxim: the user knows nothing.
Coincidentally, our CTO and I were having a conversation along these lines just yesterday. It's a thrill a minute at SecurLinx!

Quick links

South Africa: Banks piling into biometric security (The Citizen)


From the Interpol World Conference:
Security experts call for tighter international border control (Albawaba News)


UK:
New biometric permit cards required for long-term stays (Cayman Compass)

Tuesday, April 14, 2015

Israel: Interior Minister foresees mandatory biometric ID

Erdan wants advanced biometric ID card mandatory for all Israelis (Jerusalem Post)
All citizens will have to gradually move to biometric identification, Interior Minister Gilad Erdan said Monday, submitting a report on the system’s pilot run to the cabinet and Knesset.

“Smart biometric documentation that cannot be counterfeited, together with use of the biometric data will allow a full security and defense package for Israeli citizens’ identities and will balance our responsibility to ensure their security with our requirement to defend their privacy,” Erdan stated.
Obviously, his stance isn't universally popular, but read the whole thing. There are a lot of good bits of information there including this one: Israel is the OECD country with the most counterfeited passports.

India: Using biometrics to protect vulnerable children

Aadhaar goes to orphanages, joins war on child trafficking (Bangalore Mirror)
Aadhaar's comprehensive database that comprises iris (retina scan) and biometric (fingerprint) information is hoped to aid enforcement agencies find missing children, curb human trafficking and check illegal adoptions. Aadhaar enrolments have begun in Karnataka for children in child care institutes run by the state government's Department of Women and Child Development. Nearly 4,000 kids and youngsters are in care of state homes and will get identity cards.
A couple of notes:

Aadhaar means "foundation." An alternate name for the Aadhaar Project is the UID Project for Universal ID.

In the quoted passage above, "child care institutes" are orphanages rather than the child care centers some readers may be more familiar with.

Forecast: Global biometrics market CAGR 14% through 2020

Global Biometrics Market Forecast & Opportunities 2020 (TechSci Research) — The global biometrics market is projected to register a CAGR of around 14% until 2020.

Monday, April 13, 2015

The attorney suing Facebook

A lawyer Silicon Valley loves to hate (Seattle Times)
Though one tech financier calls Jay Edelson “a leech tarted up as a freedom fighter,” the Chicago class-action lawyer has had an impact on the privacy issues that the Internet has made so pervasive.
Biometric tech for bikers wins Singapore award (Planet Biometrics)
Already hosting soe 40,000 enrolees, the BIKES system facilitates self- immigration clearance at designated lanes. Designed for speed and accuracy, the process takes under 16 seconds.
Singapore has been one of the more enthusiastic adopters of border biometrics.
The question: when will biometrics take over from passwords? (The Guardian) — Four smart takes on large-scale customer-facing authentication.

Wednesday, April 8, 2015

USAA and customers both embrace biometrics

Biometric Innovation Boosts USAA Fiscal Results, Customer Satisfaction (Mobile ID World)
In a synopsis, the company credited its strong performance – which saw its net worth increasing by ten percent, reaching $27 billion – at least in part to “innovations such as secure facial and voice recognition on mobile devices”.
Tying in to the post below, the article mentions that the USAA customers who use it really love Apple Pay.

A sceptical look at Apple's Touch ID for banking

Why RBS and NatWest were wrong to trust Apple on biometric security (Information Age)
Here, Richard Walters, GM and VM at Intermedia, expands on Whaley’s criticism, claiming that the biometric technology offered by Apple is not secure enough to support sensitive activities like mobile banking.
Very much worth reading in its entirety.

Tuesday, April 7, 2015

News you can use

Florida man, initially thought dead, arrested after facial recognition match (Ars Technica)
A Florida businessman accused of falsifying his death overseas was located and then arrested by federal authorities after facial recognition software returned a match to his face in passport records. Jose Salvador Lantigua now faces one federal count of providing a false statement on a passport application.
Though never easy, it's getting harder to fake your own death.

Illinois: More on the Facebook facial recognition lawsuit

Facebook lawsuit calls collection of biometrics data illegal (Biometrics Update)
According to the Illinois Biometrics Information Privacy Act, it is unlawful to acquire biometric data without first providing the subject with a written disclaimer that details the purpose and length of the data collection, and without the subject’s written consent.
Read the whole thing.

Photos aren't simply records of something that happened, mere mementos, anymore. They're search terms and search results. That has implications for both public and private entities who collect and store images of people. Ordinary snapshots are now biometric data.

Now, about those Florida school yearbooks...

New Nealand: Biometrics allow for the return of ten-year passports

Prime Minister John Key: 10-year passports in six months (New Zealand Herald)
New Zealand moved to five-year passports in 2005 in response to security concerns sparked by the 2001 terrorist attacks in the US...

In addition, developments in biometric technology have allayed concerns about passport fraud and counterfeiting.

Monday, April 6, 2015

Facial recognition technology is changing how we think about photography

SCOTLAND: Cash-strapped police spend £700k on UK database (The Scotsman)
The MPs noted a “worrying” lack of government oversight and regulation of the use of biometrics by public bodies.

It called for day-to-day independent oversight of the police use of all biometrics, and for the Biometrics Commissioner’s jurisdiction to be extended beyond DNA and fingerprints.
ILLINOIS: Does Facebook's facial recognition technology violate privacy laws? (ABA Journal)
The lawsuit, filed Wednesday, argues that the social media company was required by Illinois law to inform Carlo Licata in writing that it would collect and retain his “biometric data,” and specify when it would destroy that data.

Both Facebook and the police in Scotland have been collecting photos of individuals for years but facial recognition technology changes things. Photos aren't simply records of something that happened, mere mementos, anymore. They're search terms and search results.

That has implications for both public and private entities who collect and store images of people.

Ordinary snapshots are now biometric data. The news pieces above both show long-standing policies being scrutinized in the context of reliable facial recognition technology.

Friday, April 3, 2015

Face rec vs. the knockout game

Philadelphia teen arrested in filmed knockout punch of SEPTA passenger (New York Daily News)
Facial-recognition software reportedly helped collar a 16-year-old boy in Monday's violent Philadelphia subway attack that left a 60-year-old man knocked out cold and suffering a broken jaw.

Thursday, April 2, 2015

More fingerprint readers for mobiles

OnePlus Two release date, specs: highly advanced biometric scanner (Christian Today) — OnePlus's hardware naming convention is sure is going to be fun!


HTC One M9+ teaser images point to QHD display and fingerprint scanner (Trusted Reviews)

Wednesday, April 1, 2015

Don't forget the biometrics

Denmark issued 10,947 passports without fingerprints (Customs Today)
The different municipalities of Denmark issued flawed passports without fingerprints, stated by the Customs authority. Earlier the Customs authorities discovered the mistake and informed the affect municipalities. Passports issued from 44 municipalities after the date of February 2nd are missing biometric fingerprints due to an error made by...
I wonder how the oversight was discovered.

Apple granted patent for mobile device face unlock

Apple wants you to be able to unlock your iPhone with a selfie (Business Insider)
There's no guarantee Apple will implement the technology - the Cupertino company obtains numerous patents that it never uses. These can be precautionary, or intended to trip up or block competitors. But as the industry increasingly looks to kill traditional passwords, selfie-secured iPhones sounds surprisingly plausible.

Samsung looks to mobile iris biometrics

Iris Biometrics to Appear in Samsung Mobile Devices (Mobile ID World)
SRI International’s Iris on the Move (IOM) technology is about to see a number of integrations into mobile products. The company’s iris-scanning technology has been licensed to Samsung and will initially appear in the Samsung Galaxy Tab Pro 8.4 tablet before finding other integrations.

Tuesday, March 31, 2015

A survey of African biometric elections

Dirty hands: Why biometric voting fails in Africa - and it doesn't matter in the end (Mail & Guardian Africa)

There's so much going on in the article that I couldn't settle on a key paragraph to set it up. Long-time readers will find some of the details familiar, especially the parts dealing with Kenya and Ghana.
ASUS ZenFone 3 Will Have a Fingerprint Recognition Sensor - Rumor (Softpedia) — It looks like pretty much all smartphone manufacturers will be offering models with fingerprint sensors soon.

Monday, March 30, 2015

Mobiles as access control tokens

Mobile Access Control: Exploiting the BYOD Trend (IFSEC Global)
With today’s mobile access technologies, smart devices can be used as universal credentials for accessing multiple buildings, IT systems and other applications using NFC and bluetooth. These devices provide users with extremely convenient vehicles for opening doors and performing other tasks that require the presentation of a secure credential.
There's a lot of good information in the linked article and it's written by the director of Strategic Business Development and Innovation at HID, and you'd expect that they've been putting a lot of thought toward what access control is going to look like after prox cards.

Challenges abound in Nigeria's biometric election

Smart Card Readers: INEC’s excuse (Vanguard)
The spokesperson, who admitted this was not the only flaw identified in the new electoral process deployed during the election, said the Commission had taken note of the challenges and would effect corrections in subsequent elections to ensure that the exercise was more credible and acceptable.
While the article deals with the technical challenges of the biometric technology, and the mixed response to those, Nigeria confronts other challenges that make proper elections difficult regardless of the technology used for casting votes.

Tuesday, March 24, 2015

Pakistan linking fingerprints to mobile SIM cards

Pakistani Mobile Users Have 10 Days To Register Their Fingerprints Or Lose Their Connection (Inquisitr)
To counter the growing menace of terrorism, the Pakistan government has ordered all mobile service companies to acquire fingerprint scans of their subscribers before April 15. Subscribers failing to do so will get their mobile subscription terminated.

Monday, March 23, 2015

Forecast: Mobile biometrics revenue $3.5 billion by 2024

Starting from a base of $249 million 2015, global mobile biometrics revenue is forecast to reach $3.5 billion by 2024, with cumulative revenue for the 10-year period totaling $17.5 billion. (EFY Times)
Biometrics for mobile devices have finally reached a tipping point. The march began with the release of the Apple iPhone in 2007 and later the iPad, each subsequently matched by Android competitors. These smartphones and tablets finally have enough processing power and hardware capabilities to put biometrics directly into their users' hands. Biometrics, whether for mobile devices or large stationary systems, typically perform one of two functions: authentication, proving that someone is who they claim to be, or identification, figuring out who someone is. Nearly all consumer-facing use cases are authentication and nearly all identification uses are enterprise-facing, especially government use cases. Somewhere in the middle, financial institutions are offering their users the chance to authenticate to online banking systems with their voices or with their eyes, in place of keying a personal identification number (PIN).

Huawei adding fingerprint hardware to mobiles?

Huawei Ascend P8 leaks point to integrated fingerprint scanner (Trusted Reviews)
Although we can’t say fir certain that the P8 will play host to a fingerprint scanner, the large rectangular cut-out on the phone’s rear looks markedly similar to the fingerprint reader on the oversized Huawei Ascend Mate 7.
Huawei's customer-facing products have really come on strong in the last few years.

The Slings and Arrows of outrageous Passwords

When your body becomes your password, the end of the login is nigh (Phys.org)
The good news for us password jugglers is that there is now a greater imperative behind building higher levels of security into systems from the outset, rather than trying to add it on afterwards, and that new and better ways of doing this are being expored.
...'Tis a consummation
Devoutly to be wished.

Deep learning for better face-rec

Google: Our new system for recognizing faces is the best one ever (Fortune)
At first we’ll see systems like Google’s FaceNet and Facebook’s aforementioned system (dubbed “DeepFace”) make their way onto those company’s web platforms. They will make it easier, or more automatic, for users to tag photos and search for people, because the algorithms will know who’s in a picture even when they’re not labeled. These types of systems will also make it easier for web companies to analyze their users’ social networks and to assess global trends and celebrity popularity based on who’s appearing in pictures.

Thursday, March 19, 2015

CyberSec: So hot right now

Why Venture Capitalists Love Security Firms Right Now (MIT Technology Review)
Venture capitalists poured a record $2.3 billion into cybersecurity companies in 2014, a year marked by frequent reports of hacks on high-profile companies. Yearly investment in cybersecurity startups been on the rise for several years now, and is up 156 percent since 2011, according to CB Insights. The trend will likely continue, as 75 percent of CIOs surveyed by Piper Jaffray said they would increase spending on security in 2015.

Bridge Day biometric ballyhoo

[ed: OK, ballyhoo is probably too strong, but the alliteration demanded it.]

Bridge Day panel backtracks on security plan (Beckley Register-Herald)
Bridge Day 2015 vendors, BASE jumpers and rappellers may be able to choose this year to either pay for a background check with a contracted security company or submit to a biometric fingerprint scan for free.

The Bridge Day Commission in Fayette County passed a motion Wednesday that adds the option of the background check. The check would be conducted by a contracted, third party security company, said Bridge Commission Chairwoman Sharon Cruikshanks.

The cost of the background check will be $12 to $35, depending on which of the three companies the commission contracts.

"Biometric scans are a free option," Cruikshanks said.
This one is especially of local interest here in West Virginia. Not mentioned in the article is that this year’s Bridge Day Festival takes place on Saturday, October 17, 2015.

Background checks became a requirement for vendors and jumpers after 2001. The fingerprint innovation appears to be meant to make the process easier by requiring less text-based identifying information from people undergoing the background check.

More information and the counter-argument to these measures can be read here: Fingerprinting Plan For Bridge Day 2015 Forces Jumper Boycott.

Oh, and if you're unfamiliar with Bridge Day...
 



...it's something.

US Customs pilots face-rec for returning citizens

US customs launches biometric pilot at airports (Security Document World)
“The facial recognition software provides the [CBP Officers] with a match confidence score after the e-passport chip is scanned and the photo is taken. The score is generated by algorithms designed to detect possible imposters.”
A one-to-one search comparing the passport photo to the person standing at the customs kiosk is about as simple as a facial recognition deployment gets.

The only complicating factor is where they get the photo. If they use the photo physically present on the passport's photo page, they will probably want to contend with the security marks and holograms somehow while processing the image for matching. If they want to use the photo stored electronically on the passport's internal chip, as it appears they do, they'll need some specialized hardware that retrieves the photo and the issue of "broken" passports will arise. Still, as far as country-level biometric deployments go, this one isn't too daunting.

In a post-pilot phase, it may be desirable to use the passport number to pull the photo from a State Department database and compare that to the passport image and a live image of the person presenting their travel documents.

Wednesday, March 18, 2015

Hello, Windows. Microsoft does biometrics.

Windows 10 News: New Authentication, New Storage Savings, And Launch Timeframe (AnandTech)
Microsoft will be taking a two pronged approach to authentication. The first is the actual authentication. Windows Hello will work with several biometrics, including fingerprint scanners, facial recognition, and iris scanning, as examples. This will be used in conjunction with hardware cryptography on the device to unlock the device. Microsoft is claiming false unlocks at around one in one hundred thousand. Fingerprints are well known, but the facial recognition will not rely on just a webcam, but rather will require new hardware such as the Intel RealSense 3D Cameras to ensure that it is a real person in front of the device and not just a photo. The unlock is tied to the actual device, and none of the unlock information is ever sent off of the device. Existing fingerprint readers can be used with Windows Hello.

Tuesday, March 17, 2015

Alipay with face

Alipay to Use Facial Recognition Biometrics (Find Biometrics)
The announcement came by way of Jack Ma, the CEO of Alipay’s parent company Alibaba, who provided a few details in a speech at the Cebit trade fair in Germany.

Ma explained the development as a solution to the difficulties associated with online paymetns, which he called “a big headache,” adding, “You forget your password, you worry about your security.” He went on to say that in its facial recognition system, Alipay will offer users “a new technology.”

Yahoo allows for mobile-device-as-token to replace email passwords

Yahoo Mail Now Accessible Without Password (Latinos Post)
"You log into your Yahoo account using your normal passwords. In the security settings, you turn on on-demand passwords and register your phone. Next time you try to login, the password field is replaced by a button that says 'send my password,' and the company texts a four-character password to your phone."
There are, however, critics of this approach. See Yahoo’s attempt to kill off passwords raises security concerns at Computer Weekly.

Monday, March 16, 2015

Biometrics By Market (Security Info Watch) — Phil Scarfo, Vice President of Biometrics Global Marketing for HID Global, gives his take on the near-term future of biometrics in banking, healthcare, retail, higher education, transportation, government ID, and the corporate office.

UAE building out border biometrics

UAE will launch full biometric scanning systems at borders soon (Tnooz)
The United Arab Emirates is set to become one of the most technically advanced countries when it comes to border control. The Emirates will deploy a series of biometric e-gates at all entry points while also working to gather more biometric data to add to the fingerprints currently tracked in its biometric database.
The UAE is already one of the most eager adopters of border biometrics. That doesn't look to be changing any time soon.

Thursday, March 12, 2015

Free Frost & Sullivan webinar next Tuesday

Biometrics Key to Future Growth in Healthcare, Retail and Financial Markets (Film Imaging)
Join Frost & Sullivan's upcoming complimentary webinar, "The Future of Biometrics," to understand the potential of the market and its impact on current businesses. Industry leaders should attend this webinar to learn how biometrics will boost convergence and growth in other markets.
Looks interesting.

Wednesday, March 11, 2015

Forecast: Global Government Biometric Systems Market

The Global Government Biometric Systems Market 2015-2025 (Market Reports Store)

Key Findings
◾The global biometric systems market is estimated to value US$4.4 billion in 2015 and increase at a CAGR of 8.70% during the forecast period, to reach a peak of US$10.2 billion by 2025.

◾The market is expected to be dominated by North America, followed by Asia-Pacific and Europe.

◾Fingerprint recognition is expected to account for the largest share of expenditure in the global Government Biometric Systems market going forward, followed by facial recognition and Iris.
That Compounded Annual Growth Rate (CAGR) is probably one of the lowest I've ever seen in the biometrics sector. It, however, doesn't come as much as a surprise. The number of government customers is pretty much capped at around 200. Governments were some of the earliest adopters of biometric solutions, so most of the 200 potential customers are already in the market. Prices paid by these customers, generally, should be falling or stable. So, there are a whole host of reasons for this low estimate for growth in the government biometrics sector.
Jury awards $150K to employee who feared scanner as “Mark of the Beast” (Overlawyered - CATO) — It appears the settlement was derived from missed wages due to early retirement for refusing to use the biometric scanner, but still.

Tuesday, March 10, 2015

Visit Oman

Tourism in Oman, Skift’s Pick for top destination of 2015, is booming, with an investment program by the Sultanate of Oman’s slated to attract 12 million visitors by 2020. Passenger traffic at Muscat International Airport has grown 329% since 2007, reaching 9 million passengers since 2014.

The comprehensive program consists of a “layered approach to border control,” giving the Royal Oman Police an efficient and flexible visa processing and security clearance process, including the issuance of eVisas.
I want to go.

Database hacks stoke demand for customer-facing biometrics

As hacking grows, biometric security gains momentum (Bizcommunity)
With hackers seemingly running rampant online and millions of users compromised, efforts for stronger online identity protection - mainly using biometrics - are gaining momentum...
It's true. The recent hacks have focused attention on biometrics. The spotlight, however, has fallen on consumer-level biometric applications. That's fine by us, but the recent high profile hacks haven't been perpetrated by hackers using customer credentials to gain access to systems. That kind of hack is hugely inconvenient for individual users, but it doesn't make the news.

Most of the big, news-making hacks involve taking huge repositories of data that can be sold wholesale to organized criminals who sell the information on to the retail crooks who perpetrate their fraud using the individual accounts.

We have argued for years that the first, best place to apply biometrics to the problem of large-scale data theft is at the database level.
From an organizational point of view, for many many service providers, allowing customers and users to protect their individual accounts with passwords, exposes the organization as a whole to minimal risk. Some relatively predictable number of users who use passwords will choose poor passwords, some will become victims of phishing scams. If the costs of sorting these cases out are less than the costs associated with burdening all users with more onerous security protocols, then the password is the appropriate solution. But at some point, all databases of user/customer information should be protected with biometric access control methods because, while having occasional users pick weak passwords or get tricked into giving them away is one thing, hackers making off with the entire database of user/password information is something else altogether. Requiring biometric verification of all human database Administrator logins would go a long way to lowering the biggest risk of passwords: their wholesale theft. In many ways the Admin level is the perfect point to introduce these more rigorous security protocols. There aren't (or shouldn't be) too many Admins, so the inconvenience falls on as few individuals as possible. Admins are tech savvy, so they should be able to adapt to the new security environment quickly. They should have an understanding of why the extra step is worth the effort. It's their responsibility to keep the keys of the kingdom. Perhaps most compelling, they're the ones on the hot seat when the CEO is out apologizing to all and sundry following a data breach.
Granted, after a hack, having biometrics there to protect individual accounts should change the retail fraudster's Return on Investment (ROI) calculations. With biometrics it should be harder for him to turn the user information into money. Still the Benjamin Franklin axiom that “an ounce of prevention is worth a pound of cure” would seem to carry the day here.

Wednesday, February 25, 2015

Biometric Voter Registration Underway In Tanzania (Anadolu Agency)

Florida: Biometrics as a differentiator for luxury condos

Muse condo tower preps for groundbreaking, 60 percent sold (The Real Deal)
The developer plans to include robotic parking, facial recognition software in the elevators, biometric safes and a 75-inch in-wall television for every unit.

Monday, February 23, 2015

Security and Service

Concerns raised over mandatory fingerprinting for India visas (Travel Weekly)
The High Commission of India states on its website that, after outsourcing the process to a company called VFS, all applicants will need to be physically present at India Visa and Consular Services centres to submit an application and biometric data.

It says: “Biometric data collection, including fingerprint data and facial imagery will be a mandatory requirement for all visa applicants soon. As a result, all visa applicants will need to first apply online and, thereafter, be physically present (mandatorily) at India Visa and Consular Services centres, by appointment, for submission of visa application and biometric data enrolment.”
All security applications must strike a balance between the effectiveness of the security measures and the needs of the entity seeking enhanced security. As anyone who has ever seen a waste basket propping open an office door could tell you, better security usually requires sacrifices to efficiency. More security with more convenience is a tall order.

The article linked above highlights a case where the enhanced security of biometric visas for travelers to India from the UK has made the visa application process more complex and time consuming. In one sense, it's bound to. Collecting more information takes more time. In the India visa case, however, it is taking a whole lot more time. So much more that people involved in Indian tourism are growing worried.

The unfortunate irony is that their ability to increase security and convenience at the same time is one of the things that make biometrics such a disruptive technology.

Thursday, February 19, 2015

Biometrics for the financial "last mile"

Kenya: Biometric technology eases banking in rural areas (KBC) — Kenyans in rural areas can now open and get access to their bank accounts with ease following the roll out of a biometric technology...

Somalis panic as cash flow dries up after US remittance lifeline cut
Somalia's remittance crisis has been intensifying for years. Britain's Barclays Bank closed its accounts with Dahabshiil, the largest Somali money transfer company, in 2014.

In Australia, Westpac, the only bank partnering with Somali remittance companies, is due to close their accounts at the end of March, the report said.

"We are just lurching from crisis to crisis", said Ed Pomfret, Oxfam's Somalia campaign manager. "These governments need to take action."

Britain has been working with the World Bank on a "Safer Corridor" initiative to tighten the scrutiny of Somali money transfers through measures such as biometric identity cards for recipients in Somalia.
The "last mile" problem is usually reserved for describing the challenges of connecting retail customers with physical infrastructures such as plumbing, electricity or wired communications.

It's also a real challenge in connecting recipients of aid and remittances to the global financial system. In the Somali case above, the global financial system appears to end at Somali money transfer companies. The Kenya efforts (linked above) and others, such as India's UID project, are two examples of how people are using biometrics to extend the benefits of the global financial system to people who desperately need them.
7 things you never knew about biometrics (Gadget)

UK: Banks accommodating mobile fingerprint biometrics

Is the UK banking sector ready to sideline passwords? (Information Age)
RBS and NatWest have been the first banks to announce that they are soon to allow customers to access accounts on their smartphones using fingerprint recognition technology.

The move is a seminal one for UK financial institutions, and an indication that the era of passwords may be finally drawing to a close.
Also:
Fingerprint authentication protects youngsters from themselves (Computer Weekly)
Both the Royal Bank of Scotland and MasterCard have recently made announcements regarding fingerprint authentication services and, if research from Visa Europe is anything to go by, the technology could be the best way to help users keep their bank details secure.

The research revealed those aged between 16 and 24-years-old are very liberal with personal details.

For example, 34% of this age group have shared their debit or credit card pin numbers with someone, compared with 23% for all age groups. Some 32% have shared their smartphone password and 20% have shared internet banking passwords.

Tuesday, February 17, 2015

US: Government open to Apple Pay

Apple Pay secures key US govt contract (Planet Biometrics)
Apple’s biometric payment system is set to be used by the US Federal Government for payment cards and social security and veteran’s payments, following an announcement by US President Barack Obama.

Windows 10 and biometrics

Microsoft Announces FIDO Support For Windows 10 (The Verge)
Soon, you may be able to log in to Outlook with a fingerprint or an eyescan. At the Stanford Cybersecurity Summit on Friday, Microsoft announced that Windows 10 would support the next version of the Fast Identification Online (FIDO) spec, allowing devices to work with a wealth of third-party biometric readers and providing an easy framework for any hardware makers that want to build extra security into a laptop or phone.

The amazing durability of password technology

You Might Want To Take Another Pass At Your Passwords (GPB News)
Cormac Herley is in the 95 percent who don't. He's principal researcher with Microsoft Research, an arm of the software giant.

"Passwords are the worst system in the world, except for all the other systems," he says.

Herley recommends assigning different tiers to passwords. Using your best, most complex ones for work and banking, but devoting less effort to those that don't matter as much. But even that can be a lot to ask, even for him.

"I write the passwords down and have a photocopy at home and a photocopy in the office and a couple copies here and there."

But, could all that be compromising security?

"Well, I mean, um, yes," he says.
I also love Harley's repurposing of the democracy quote often attributed to Winston Churchill.

Forecast: Health care biometrics worth US $5B by 2020

Special Report: Biometrics in Healthcare (Biometric Update)
This report examines how biometric technology is applied to the health care industry, mainly in the United States. This report notes that “health care biometrics” is utilized for access control, identification, workforce management or patient record storage. Biometrics in health care often takes two forms: providing access control to resources and patient identification solutions. The growing demand for biometrics solutions is mainly driven by the need to combat fraud, along with the imperative to improve patient privacy along with health care safety. Biometrics are also increasing being used for medical monitoring and mobile health care.
- Rawlson O`Neil King Lead Researcher, Biometrics Research Group, Inc.


Also, and unlike with most of these market analyses, Biometrics Research Group has made the entire report available for free via download at the link above.

Monday, February 16, 2015

"Get me some biometrics, stat!"

How biometrics could improve health security (Fortune)
For the last two years, the health industry suffered the highest number of hackings of any sector. Last year, it accounted for 43% of all data breaches, according to the Identity Theft Resource Center. To help prevent these costly issues, medical companies have begun adopting an array of biometrics security systems that use data from a patient’s fingerprint, iris, veins, or face.
There really isn't an identity management challenge that health care doesn't have.

Thursday, February 12, 2015

India: What happens with lost UID numbers?

UIDAI devises a method to retrieve lost Aadhaar numbers (Business Standard)
A government official said as a person can only enrol for Aadhaar once, there needed to be a mechanism to retrace the number in case the person has misplaced all possible links to it.

“Enrolling again is not an option, as the system automatically rejects biometric details that have been registered once,” said the official.

Under the new method, a person can put in the biometrics and the system will keep prompting for more demographic details till the back-end server zeros down to 10 possible matches.

During the entire process, none of the details of the Aadhaar holders will be shown to the person or the operator till the time an exact match has been found.

This has been done keeping in mind the design of the Aadhaar project, where the system doesn’t reveal any information about the resident and only tries to authenticate the identity replying with a yes or no.

Monday, February 9, 2015

Generation Z prefers biometrics to passwords (NFC World) — In a study from the UK, 76% of consumers between the ages of 16 and 24 expressed comfort with biometric payments.

Ghana: Nearly 1 million biometric health insurance cards issued in Eastern Region

Eastern Region NHIS issues 979,002 biometric cards (Ghana News Agency)
Over 979,002 clients of the National Health Insurance Scheme (NHIS) in the Eastern Region had been issued with the new biometric cards.