Tuesday, September 8, 2015

Another Illinois Facebook face recognition lawsuit

Gillen v Facebook (Scribd)

Note: BIPA = Biometric Information Privacy Act

I have removed two footnotes in original.
NATURE OF ACTION

1. Plaintiff brings this action for damages and other legal and equitable remedies resulting from the illegal actions of Facebook in collecting, storing and using Plaintiff’s and other similarly situated individuals’ biometric identifiers and biometric information (referred to collectively at times as “biometrics”) without informed written consent in violation of the BIPA.

2. The Illinois Legislature has found that “[b]iometrics are unlike other unique identifiers that are used to access finances or other sensitive information.” 740 ILCS 14/5(c). “For example, social security numbers, when compromised, can be changed. Biometrics, however, are biologically unique to the individual; therefore, once compromised, the individual has no recourse, is at heightened risk for identity theft, and is likely to withdraw from biometric-facilitated transactions.”

3. In recognition of these concerns over the security of individuals’ biometrics – particularly in the City of Chicago, which was recently selected by major national corporations as a “pilot testing site[] for new applications of biometric-facilitated financial transactions, including finger-scan technologies at grocery stores, gas stations, and school cafeterias,” 740 ILCS 14/5(b) – the Illinois Legislature enacted the BIPA, which provides, inter alia, that a private entity like Facebook may not obtain or possess an individual’s biometrics unless it: (1) informs that person in writing that biometric identifiers or information will be collected or stored, see id.; (2) informs that person in writing of the specific purpose and length of term for which such biometric identifiers or biometric information is being collected, stored and used, see id.; (3) receives a written release from the person for the collection of his or her biometric identifiers or formation, see id.; and (4) publishes publically available written retention schedules and guidelines for permanently destroying biometric identifiers and biometric information, see 740 ILCS 14/15(a).

4. In direct violation of each of the foregoing provisions of § 15(a) and § 15(b) of the BIPA, Facebook is actively collecting, storing, and using – without providing notice, obtaining informed written consent or publishing data retention policies – the biometrics of its users and unwitting non-users.

5. Specifically, Facebook has created, collected and stored over a billion “face templates” (or “face prints”) – highly detailed geometric maps of the face – from over a billion individuals, millions of whom reside in the State of Illinois. Facebook creates these templates using sophisticated facial recognition technology that extracts and analyzes data from the points and contours of faces appearing in photos uploaded by their users. Each face template is unique to a particular individual, in the same way that a fingerprint or voiceprint uniquely identifies one and only one person.

6. Plaintiff brings this action individually and on behalf of all others similarly situated to prevent Facebook from further violating the privacy rights of Illinois residents, and to recover statutory damages for Facebook’s unauthorized collection, storage and use of unwitting non-users’ biometrics in violation of the BIPA.
A wrinkle in this lawsuit is that the plaintiff is not, and never has been, a registered Facebook user and therefore could not have agreed to Facebook's terms of service.

Friday, September 4, 2015

Serious ROI in remote patient monitoring

How one health system saves $90,000 per patient (Healthcare IT News)
NAH [Northern Arizona Healthcare] saw hospitalizations drop from 3.26 mean per patient to 1.82 and days hospitalized drop from 13.98 mean per patient to 5.13 and, based on the health system's data about the first 50 patients six months prior to enrollment and six months after enrollment, that added up to savings of approximately $92,000 per patient.
The "biometrics" discussed in the article aren't biometrics for identification, but ID biometrics will certainly be a part of the picture as these kinds of technologies are adopted more widely.

New DHS plans for biometrics should inform current corporate CIO's

DHS Outlines Plans to Enhance Use of Biometric Tech (Find Biometrics)
America’s Department of Homeland Security has released a new strategic framework on how it plans to move forward implementing biometric technologies. Entitled “DHS Vision Statement on Enhanced Biometric Capabilities”, the document indicates a tightening embrace of the technology.
The full DHS vision statement can be downloaded here [.pdf; 13 pages].

Interesting excerpt:
The DHS Office of Biometrics and Identity Management (OBIM) operates and maintains the DHS Automated Biometric Identification System (IDENT) and provides identity management services and expertise across DHS. Front‐end capabilities (i.e. biometric collection devices, applications, interfaces and supporting infrastructure) are each managed and maintained independently by the components, with limited collaboration. National Security Presidential Directive (NSPD)‐59 / Homeland Security Presidential Directive (HSPD)‐24 “Biometrics for Identification and Screening to Enhance National Security,” charges federal executive departments and agencies to use mutually compatible methods and procedures in the collection, storage, use, analysis, and sharing of biometric information. Access to external federal biometric databases however, through bilateral interoperability agreements, is not fully implemented, requiring DHS components to employ mission centric solutions for integrating certain biometric exchanges with the Federal Bureau of Investigation (FBI) and the Department of Defense (DoD). This requires DHS components to work independently with the FBI and DoD to integrate with each biometric system for access to data that assists in identifying and adjudicating subjects. The current IDENT system, although able to store multi‐modal biometrics, offers matching capability for fingerprints only, limiting operational components’ ability to implement the use of alternate biometrics that may better suit operational needs. Current DHS Component systems tend to be encounter‐based – instead of person‐centric – requiring biometrics collection processes to be repeated, rather than just verified. Connectivity for systems that collect biometrics in the field is inconsistent, often not allowing real‐time access to federal biometric databases. Further, existing biometric collection systems in the field are dated, many are at end‐of‐life, impacting the quality of the biometrics collected, which affects overall performance.
Current and prospective CIO's should reread that paragraph. The future of identity management is large-scale, multimodal, interconnected and updated as soon as possible, and provides access to virtual and physical resources. The earliest adopter of large-scale biometrics is coming to grips with the challenges of biometrics 2.0. At SecurLinx, we have designed our technology and approach to help our customers cope with the dead-ends and cult-du-sacs associated with gradual adoption of new ID technologies and provide them the flexibility to take advantage of the opportunities afforded by emerging technology.

Thursday, September 3, 2015

Mature talk on authentication...

Security vs. usability—that's the choice we make with passwords (Phys.org)
We all need some kind of authentication process if we are to access information systems at work or at home. We know why we need to do it: to make sure we have access to our data and unauthorised people don't.

So why do we routinely ignore such advice[...]?
Not all passwords protect equally valuable access. It turns out that many people are choosing weak passwords on low-priority systems like retail and media sites, and stronger authentication measures on high-priority systems like finance and work-related systems.

This sheds light on why even rigorous security measures like biometrics are being applied to instances where people are willing to jump through more password-related hoops but find the password regime horribly inconvenient.

Thursday, August 20, 2015

Windows Hello face recognition not fooled by Australian twins

Microsoft's facial recognition software does something amazing when it encounters twins (Business Insider)
Each set of twins set up an account for one and then the other attempted to log-in — and the software held. According to The Australian, there was not one instance of Windows Hello allowing the wrong twin access to the computer.
The headline to the contrary, notwithstanding, Microsoft's facial recognition software pretty much does nothing when it encounters a legitimate user's identical twin.

MasterCard announces two biometrics pilots

MasterCard puts faces and fingers under microscope (Mobile World Live)
MasterCard and First Tech Federal Credit Union, a US financial institution, will pilot the authentication of payments using facial and fingerprint recognition, in what they claim is a first for the country.

Separately, MasterCard is running another biometrics trial with International Card Services (ICS), the leading credit card provider in the Netherlands.

Biometric ID at issue in California Uber fight

Uber driver background checks 'not good enough' (BBC)
At a press conference, George Gascon, district attorney in San Francisco, said problems with the data that Uber relied on to check drivers meant it could miss some former criminals. For instance, he said, 30,000 registered sex offenders were not in the database Uber used.

An alternative screening system used by other cab firms called Livescan did catch people who were on the sex offenders list, said Mr Gascon.

ID overhaul exposes ghost pensioners in Trinidad & Tobago

4,000 fraudsters lose benefits (Entorno Inteligente)
The Biometric Card will technologically exceed its predecessor, the Debit Smartcard, said Newallo-Hosein, and will translate biological information into digital recognition.

As a result the social safety net will become tight yet more efficient than at present.

Wednesday, August 19, 2015

Market forecast for fingerprint access control systems

Fingerprint access control systems: Market analysis by technology and market segment; forecasts to 2022 (Grand View Research)
The industry can be segment based on application as commercial, consumer electronics, military & defense, government, healthcare, banking & finance, and others. Government and commercial is anticipated to be key application segment over the forecast period.

Commercial fingerprint access control systems market is expected to be dominant over the next seven years, and accounted for over 30% of the overall revenue in 2014. Government application segment is expected to grow at a CAGR of over 6.5% from 2015 to 2022.

Tuesday, August 18, 2015

Market forecast for healthcare biometrics

Biometrics in the Healthcare Industry (Tractica)
...[S]tarting from a base of $250 million in 2015, Tractica forecasts that global healthcare biometrics revenue will reach $3.5 billion by 2024, with cumulative revenue for the 10-year period totaling $12.5 billion at a compound annual growth rate (CAGR) of 34%.

Monday, August 17, 2015

You know better but I know him

If we go to biometric IDs, will hackers try to steal your face? (CreditCards.com)
How much damage could a data thief do with your biometrics? According to experts from three different biometric modalities, the threat of someone virtually slipping into your skin is based far more on Hollywood-fueled paranoia than how biometrics are actually secured and deployed in the real world.
An analysis of iris, vein and heartbeat biometrics follows from there.

The piece also serves as a useful counterpoint to this one at InfoWorld which has biometric authentication technology as "Doomed security technology No. 1," where the author's formulation,
"After all, using your face, fingerprint, DNA, or some other biometric marker seems like the perfect log-on credential -- to someone who doesn't specialize in log-on authentication."
begs the retort: After all, using your face, fingerprint, DNA, or some other biometric marker seems like it is destined for history's dustbin -- to someone who doesn't specialize in biometric authentication.

Thursday, August 6, 2015

Microsoft and Synaptics working on fingerprint hardware

Synaptics TouchPads to work with Windows Hello (WinBeta)
The new TouchPads would be able to read your fingerprint to enable Windows 10’s new biometric login feature Windows Hello, which aims to eliminate the use of passwords by replacing them with either fingerprints, facial recognition, or iris scanning.
Morphing the touch pad mouse sensor hardware into a fingerprint reader would be pretty cool. Getting the ID transactions right, though, will be a pretty heavy lift, technically, depending on the use model.

More baseball stadium biometrics...

Yankees announce improved security and entrance measures for fans (Crain's) — Yankee Stadium visitors soon will be able to avoid long security lines by registering their fingerprints with a biometric identity service used at 12 U.S. airports.

In another deployment the St. Louis Cardinals (baseball's second-most successful franchise in history) have installed iris biometrics for player and staff access control in more secure locations.

Tuesday, August 4, 2015

Kudos to Morpho

MorphoTrak Leads With Face Comparison Training (Financial Content)
MorphoTrak, a U.S. subsidiary of Morpho (Safran), announced today that it will offer vendor-independent training* in face comparison, filling an acknowledged gap in the field of computer-aided face recognition and facial identification. Automated face recognition systems are common in both law enforcement and civil applications, yet facial matching software can only present the reviewer with potential matches. It is up to the human reviewer to decide whether two facial images belong to the same individual.


*“Vendor-independent training” means that the techniques the course will teach work for all face examiners, no matter what face recognition software they are using.
Kudos to Morpho. Facial recognition is a powerful tool for well-trained users. This challenge is well known among those who have worked to place facial recognition capabilities into the hands of law enforcement and security professionals.

Computers don't look at the world the way we do. Whether that's a good thing or not depends on what you're trying to accomplish. For facial recognition in a law enforcement context, it's a good thing to have a radically different point of view applied to a challenge.

First, faces are probably the most meaningful objects in human existence. It's not too much of an exaggeration to say that for millennia human survival has depended upon our abilities at one type of facial recognition: recognizing people you know. Sorting through hundreds of thousands of pictures of people we don't know in order to match the two that are of the same person, however is not something we're inherently good at.

Computers can do that in less than a second, then give the two pictures to a human which is very good at making the single comparison — if that person understands their role in the machine-human partnership well.

Training is the key.

Microsoft, privacy and biometrics

Microsoft moves to quell Windows 10 privacy fears (Daily Nation)
According to the company's privacy statement, some of the information collected include "your typed and handwritten words", emails, conversations users have with the digital assistant, Cortana, location data and selections, such as stocks a user follows in a finance app, or the team a user supports in a sports app. Articles detailing privacy concerns have appeared in The Guardian, Newsweek and the Financial Times.

In the statement supplied Monday, the company says Microsoft does not sell the information customers provide it, but makes it available to employees and third-party engineers to improve Microsoft services.

Users can choose the level of information they send to it and selectively remove the information that Cortana, the digital assistant, tracks, while no biometric data from Windows Hello is shared with third parties, the company said.
It looks like the attention Microsoft is getting for privacy concerns surrounding Windows 10 is mostly to do with default settings. It also appears that Microsoft treats biometric information differently by default, not sharing it even with trusted third-party developers.

Two of the issues, surrounding Wifi Sence and how Windows Update Delivery Optimization (WUDO), are covered very well by The Hacker News which provides simple instructions for how to address them by changing default settings.

Reading through both of the Hacker News pieces, a picture of Windows 10 emerges that shows Microsoft giving serious thought to how make connectivity simpler with Wifi Sense while making the Windows ecosystem more resilient to the security threats already out there and those that easier connectivity implies with WUDO.

Friday, July 31, 2015

US: San Jose airport/Alaska Airlines test program for fingerprint boarding

Alaska Airlines: Fingerprints replace boarding passes (Desert Sun)
Those who signed up for the test went through an enrollment process that took about 20 minutes. After that, they were permitted to use their fingerprints to access the TSA screening area through the CLEAR lane. Fingerprint readers at the boarding gates were able to pull up a passenger’s boarding pass for the gate agent to review.

“The feedback was very positive,” said Tolzman. “On a survey scale of ‘dissatisfied’ to ‘delighted’ over 85 percent of the participants were delighted with the system.”
With the Colorado Rockies stadium access, that's news of two innovative CLEAR deployments in two days.

Thursday, July 30, 2015

US: Professional baseball team offering fans fingerprint fast lane

Rockies Fans to Get Biometric Fast Access to Ballpark (Find Biometrics)
There will be a dedicated Fast Access entrance set up, and those who have already registered for CLEAR’s air travel eGates will be able to get in right off the bat, while newcomers can sign up at the event provided they have a driver’s license.

Wednesday, July 29, 2015

Windows 10 is here

Microsoft's big day is here and for biometrics that means Hello, biometric authentication for Windows 10 devices.

The promo is quite snappy.




But even though the promo piece concentrates on face recognition, Hello face logins are limited to the Intel Real Sense 3D camera. With limited options for external face hardware, how about fingerprints? Does Hello support a wider range of fingerprint hardware? It appears that it does.

Foraging around the internet, I found this May, 2015 piece by Richard Hay at WinSuperSite.com that details his experience integrating an off-the-shelf budget fingerprint reader with a beta version of Windows 10 Hello. It seems pretty straightforward. That means that the fingerprint login is probably going to be easier for most people who want to take advantage of Hello, at least on desktops. Carrying a USB connected piece of hardware won't work as well for mobiles running Windows 10, but it makes sense to expect Windows phones with onboard fingerprint readers soon, especially given Microsoft's investment in Hello..

My personal preference on fingerprint hardware is for sensors that capture the whole image of the fingerprint instantly over the swipe readers, but they are more expensive.

All the early Hello press revolves around access to the device, and it's true that Windows and fingerprint hardware manufacturers have supported a lot of this functionality for years, now. It remains to be seen how deeply into the operating system the biometrics go. Still, one fewer password is welcome.

Tuesday, July 28, 2015

India: Biometric verification required for student ID and attendance

Biometric attendance must for jr colleges (Pune Mirror)
"We have made biometric attendance mandatory for all junior colleges. This will also let us compare statistics of students opting for specific colleges and give us data about students admitted to that college under the centralised admission process. While this system will leave no room for bogus admission at any city college, it would also make students serious about attending their lectures. Their casual attitude regarding college will change," said Ramchandra Jadhav, DyDE.
A large potion of that educational institutions must do revolves around identity management.

Banking biometrics taking off in West Africa

A couple of stories out today from West Africa's largest country, Nigeria, and perhaps its most respected, Ghana, tell of adoption of large-scale biometric deployments in finance.

Nigeria Inter Bank Settlement System (NIBSS) has disclosed that over 18 million customers have so far enrolled for the Biometric Verification Number (BVN) exercise (The Sun)

Eight foreign remittance firms join Ghana's e-Zwich (Modern Ghana)

Thursday, July 23, 2015

Biometric sign-on

Biometric SSO - A secret weapon to protect your data (Engadget)
The advantages of using biometric SSO solutions for securing enterprise information are huge. Firstly, utilizing biometric SSO authentication provides stronger authentication and security instead of relying on traditional passwords. It is nearly impossible to steal or duplicate biometric characteristics for authentication purposes. Besides, biometric characteristics are unique for every person in the world; even identical twins have different biometrics. Hence, biometric SSO achieves the highest level of identification accuracy. Secondly, implementing a biometric SSO technology is considered as a cost effective solution to reduce financial losses from being compromised by weak password management policies. Thirdly, the variety of biometric SSO modalities available such as fingerprint, iris, vein, and palm brings a huge flexibility to organizations to achieve better return on investment.
Often overlooked, biometric hardware itself provides an enormous security benefit. From this 2012 post on biometrics in schools...
Biometrics provide for far more secure information because the biometric sensor hardware itself provides a layer of protection that a keyboard never can provide passwords. In the standard Username/Password regime, the hardware used, the keyboard, offers no additional security. With username/password authentication, a hacker needs only a keyboard to fill in the proper fields and she gains access to the network. If that username/password is a superuser or administrator credential, an organization may see some turnover in the CTO function.

Biometric authentication is very different animal because with biometrics, the hardware layer does provide extra security. If the hacker steals a biometric or unencrypted biometric template (a long character string), she can't just type it in even if she finds the place in the programming that handles the template. It has to come from the fingerprint sensor. The template resulting from a verification attempt is like a single use password created during the interaction of a physical object (body part) with certain known sensor.

Security integrators and IT professionals in the IoT era

Role Of Security Integrators In The Internet Of Things Era (Source Security)
Networking IoT devices may seem like an information technology (IT) function, typically handled by a chief information officer (CIO). However, says Martens, CIOs will be preoccupied with complex issues far beyond physical security. Therefore, identifying where IoT sensors are placed, how they are managed and how they interact will fall to facility managers. And they will depend on their security integrators’ expertise more than ever.
Technology is pushing the security and IT functions closer together, most obviously because they are increasingly provided over the same infrastructures. There's a lot of good insight at the link.

Market analysis from IndustryARC

Next Generation Biometrics Market is estimated to be $5.9 billion in 2014 and is growing at a healthy CAGR of 22% (IndustryARC)
The market is characterized by established brands with high revenue; high R&D capital reserves and well instituted distribution channels. But, the market place is also being disrupted by firms with innovative solution that have emerged to solve specific problems. With cost effective solutions offering greater security, companies will be able to position themselves uniquely.



Tuesday, July 21, 2015

Fujitsu: Iris biometrics for mobile devices

Iris Scanner Unlocks Smartphones Using Infrared LEDs (Electronic Design)
The growing number of smartphone thefts, both in the United States and abroad, has prompted manufacturers to incorporate more resilient security methods into their designs. Fujitsu Ltd., for instance, recently unveiled the Arrows NX F-04G smartphone, which uses infrared light-emitting diodes (IREDs) to support iris scanning authentication.
A suitable illumination source had been a major hurdle for iris biometrics on mobile devices. Fujitsu demonstrated a prototype mobile device using iris technology in March, 2015.

Monday, July 20, 2015

Jamaica: Face rec audit for passport issuance

Jamaica uses biometrics to secure passport issuance system (Security Document World)
The Jamaican Government has announced it will attempt to prevent passport application fraud by adding a biometric facial recognition system to its current passport issuance and control system (JPICS).
Every passport issuer should be doing this.

Thursday, July 16, 2015

A Millennial's vision for biometric banking

A Millennial’s Mindset: Money and Biometrics (Finextra)
The best thing for me would be a fast, easy and secure process, designed around me. Why can’t I use my biometric data to have a joined up experience? Without removing body parts, it is hard to steal from you. Biometrics would enable me to identify myself immediately.
We agree; and we're working on it.

If it seems like things are moving slowly, it's only because there's a lot that had to be done on the infrastructure side first. A whole lot.

US: Biometric entry-exit system getting off the ground in Atlanta

Fingerprint scanner tested on foreigners leaving Atlanta (Security Info Watch)
U.S. Customs and Border Protection officers began using the devices last week to scan some foreign passengers on selected flights at Hartsfield-Jackson Atlanta International Airport, agency spokeswoman Jennifer Evanitsky said Tuesday. The test will be expanded in the fall to airports in Chicago, Dallas, Houston, Los Angeles, Miami, Newark, New York, San Francisco and Washington.
The US Congress first required such a system in a law passed in 1996.

Wednesday, July 15, 2015

Assessing the damage related to fingerprints in hacked government database

How Much Damage Can OPM Hackers Do With a Million Fingerprints? (Nextgov)
Though the idea of hacked fingerprints conjures up troubling scenarios gleaned from Hollywood's panoply of espionage capers, not much is currently known about those that OPM said were swiped in the data breach, which began last year and has been privately linked by officials to China. In fact, the agency said it didn't even know yet specifically which personnel have had their prints compromised.
The linked article is really good in that it spends a great deal of analysis of the unknowns, and there are many.

While a collection of images of the fingerprints of US government employees — if that is an accurate description of that was taken — certainly has its uses, not all potential uses are equal or equally likely.

In terms of identity fraud, the 1.1 million government employees who had their fingerprints stolen may not be a whole lot worse off than the 20 million or so other government employees who had their personal information stolen minus the fingerprints, though that is cold comfort indeed to the victims. If the individuals whose information was stolen are given the precise details of the personal information that is now "out there" they will be able to make informed decisions about how they wish to manage their affairs going forward. That includes how they might interact with biometric ID management technologies in the future both in and outside of government applications.

The intelligence value of the fingerprints of government employees is different story. With time, money, and pictures of a million fingerprints, it is possible to build a fingerprint watch-list. Probably, not all of the pictures of fingerprints will be of a high enough quality to be enrolled in an automated system today but more time and more money could help. From there, the new watch-list could be accessed by a new or existing biometric ID technology deployment such as a checkpoint serving whatever purposes its owner has for it.

There is probably a lot the government still doesn't know about what was stolen, and even more that hasn't been shared with the public and more importantly with the individuals whose information has been compromised. It will also take some time for the stolen information to be put to use. The Office of Personnel Management has a lot of work ahead of it.

Monday, July 13, 2015

FBI's Rap Back program will use biometrics to alert government agencies of felony arrests of their employees

D/FW Airport to be among first users of FBI criminal history tracking effort (Dallas Morning News)
D/FW Airport and Boston’s Logan International Airport were the two selected by the Transportation Security Administration to pilot the FBI’s Rap Back program. The program allows the TSA to continuously track employees for felony-level arrests, rather than relying on individuals to self-report their crimes.

Biometrics figure in Accenture "Digital Trust in the IoT Era" consumer research

Security: Moving away from passwords to less penetrable security (PDF - Accenture)
Consumers are feeling less secure about the reliability of usernames and passwords to protect their personal data and are increasingly frustrated with the often tedious and inconvenient process of having to manage and remember multiple passwords and usernames. To address this challenge, innovative biometric authentication methods for connecting to the internet, such as use of human finger and palm prints, irises and voice recognition, are being developed rapidly.


The landing page for Accenture's Digital Trust in the IoT Era report is here.

Friday, July 10, 2015

ID management in the cloud

Biometric Cloud-Based Offers Attractive Deployment (Engadget)
Cloud-based biometric technology offers attractive deployment possibilities, such as smart spaces, ambient intelligence environments, access control applications, mobile application, and alike. While traditional (locally deployed) technology has been around for some time now, cloud-based biometric recognition technology is relatively new. There are, however, a number of existing solutions already on the market...

Thursday, July 9, 2015

Ireland: Biometrics helping reduce welfare fraud

Welfare fraudster caught using facial recognition software (Irish Times)
A father of three who committed €25,000 worth of social welfare fraud until he was caught using facial recognition software has been jailed for 18 months.

Younger consumers lead biometrics demand

How mobile identity can unlock the DNA of trust for the financial sector (Information Age)
More than two-thirds of UK consumers think that using biometrics – such as voice, fingerprint, iris and facial recognition – would be more secure and help reduce the risks of fraud. These findings were consistent with consumers across Australia, Singapore, Indonesia, Malaysia, the United Kingdom and United States.

Wednesday, July 8, 2015

Australia gearing up for huge biometrics tender

CrimTrac to extend national biometric identification database (The Financial Review)
CrimTrac, the federal biometric information repository, wants more freedom to flexibly access other databases, such as national location data, as the national broadband program gradually progresses towards a fully functional, nationally available high-speed data network.

It is looking for a specialist information technology supplier to tool up a more flexible, versatile operating installation which can incorporate a range of new techniques as they become available, and can cope with the ever-spreading list of mobile devices being deployed in the field by policing agencies.

Tuesday, July 7, 2015

You can use biometrics, too

Biometric Technologies Are Competent To Use In Homes Or Any Establishments (World TVPC)
So as you can see using biometric scanners as a means to secure your home or office building is absolutely necessary. It is one of those things that you would be thankful for that human ingenuity worked towards your favor instead of against it.
Much of the discussion of biometrics tends to represent the technology as something foisted upon ordinary people by governments or corporations. That is changing.

Not with a bang, but a whimper

Biometic Security Measures Put Slow Squeeze on Passwords (IT Business Edge)
One of the touchstones for the computer age and, more specifically, its insecurities and dangers, is the password. Very slowly, however, the password may be on its way out, both for stationary and mobile users. In favor are various biometric security measures.
Lots of good links in the article.

Monday, July 6, 2015

FBI face rec leads to fugitive pedophile

FBI using facial recognition despite privacy concerns (Valley News - Fargo, ND)
For 19 years, Lynn Cozart eluded authorities after being convicted of sexually assaulting his three children.

He failed to show up for his sentencing hearing and seemed to drop off the map. So in a desperate bid to track down the Pennsylvania native, an FBI agent submitted Cozart's mug shot to the agency's newly created Next Generation Identification (NGI) system, which among other things uses facial recognition software to identify suspects.
The story continues at the link. With input from privacy advocates and law enforcement officials.

Friday, July 3, 2015

Security insights from Unisys

Unisys Security Insights: U.S.
A Consumer Viewpoint - 2015
(Unisys - Browser-based PDF)

Source: Unisys

The survey, in general is concerned with data security and has interesting survey data reflecting the relative data security concerns of the United States public broken down by industry.

Blink once for "yes"

MasterCard is testing a new way for you to pay with your face (Engadget)
MasterCard announced on Thursday that it's looking to add a layer of biometric security to its credit cards and all user will need to do is simply take a selfie. The system will create a digitized map of your face, convert that map into a hash and compare it to the hash stored on Mastercard's servers.

Here's a quick demo:



Thursday, July 2, 2015

Forecast: Global Smart Security Market 2015-2019

Latest report on the global smart security market that is estimated to grow at a CAGR of 18.59% over the period 2014-2019 (Sandler Research)
Smart security solutions are used to monitor the activities and behavior of people in areas that are more prone to unauthorized access or damage, such as enterprises, educational institutions, commercial buildings, and utility infrastructure. Smart security includes advanced security systems such as IP surveillance cameras, biometric access control systems, integrated perimeter intrusion prevention systems, and wireless alarms. Thus, these solutions can secure an area from miscreants, terrorist activities, and data theft.

Adoption of intelligent security solutions for cities and their infrastructure not only provides security but also peace of mind to the residents.

The analysts forecast global smart security market to grow at a CAGR of 18.59% over the period 2014-2019.

Tuesday, June 30, 2015

Not a bug, but a feature

Massive errors mar Aadhaar enrolment (Times of India)
The enrolment process for Aadhaar in Odisha is dogged by massive rejection of data due to errors. According to the directorate of census operations here, enrolled biometric data of 40 lakh people stand rejected by the Unique Identification Authority of India (UIDAI), the Aadhaar body, as on June 15.
Some facts:
Odisha is a state in eastern India. The wiki has its population at 43.73 million as of 2014.
1 lakh = 100,000
1 crore = 10,000,000
All numbers not quoted from the article are in more familiar units.


The article goes on to say a lot about the numbers. 31,700,000 out of 38,400,000 people (82%) of the eligible population have been registered successfully.

The 4 million rejected applications are divided as follows.

2 million were rejected because they were submitted by operators who have been barred from submitting applications. UID works by outsourcing enrollment to private operators who are then paid by the government for accepted applications. Operators who have submitted too many error-riddled or fraudulent applications have been banned from the market.

1 million have been rejected for being duplicate applications, as is proper.

That leaves 1 million true "errors," or failed enrollments that are potentially valid and are described as those submitted on behalf of "very old people and children (between five to 10 years), whose finger prints and iris scans were not registered properly." Now, it may turn out that some of these failed enrollments are duplicate applications as well and it will probably turn out that many (if not most) of these people can be enrolled on a second pass where extra care is taken during the enrollment process. Nevertheless describing 1 million failed enrollments out of 32.7 million presumably legitimate applications as "massive errors" seems uncharitable.

Also, UID contains a "Biometric Exception Clause" which allows for creating UID numbers for people whose biometrics cannot be enrolled. As of May 2015, across India, around 618,000 (0.07%) of UID numbers have been issued with biometric exceptions.

Israel continues toward biometric ID

Knesset Extends Biometric ID Trial Program (Arutz Sheva)
The law was passed in part to prevent identity theft and the loss, theft and destruction of the blue ID cards issued by the Interior Ministry, which had spiraled out of control in the decade prior to 2007. It was later revealed that more than half of those requesting new documents had a criminal background.

US visa delays: It'll all be over soon

US visa processing back to normal after computer glitch (Dawn)
US visa processing has returned to full strength after hardware problems, the State Department said on Monday, noting that 410,000 visas were issued in a week as officials scrambled to clear a huge backlog.
According to the article, 410,000 visas have been issued in the last week. Compared to the average of 50,000 daily visa requests (350,000 per week), that would clear about 60,000 applications in the backlog if June is an average month for visa applications.

Monday, June 29, 2015

UC Davis develops mobile ultrasound fingerprint reader

Ultrasonic fingerprint sensor may take smartphone security to new level (Science Daily)
The basic concepts behind the researchers' technology are akin to those of medical ultrasound imaging. They created a tiny ultrasound imager, designed to observe only a shallow layer of tissue near the finger's surface. "Ultrasound images are collected in the same way that medical ultrasound is conducted," said Horsley. "Transducers on the chip's surface emit a pulse of ultrasound, and these same transducers receive echoes returning from the ridges and valleys of your fingerprint's surface."

Friday, June 26, 2015

Malaysia: UN Commision recommends biometrics for Burmese refugees

Introduce Biometric ICs To Regulate Refugee Situation In Malaysia, Suggests UNHCR (Malaysian Digest)
In the face of the recent influx of ethnic Rohingyas fleeing from persecution in Myanmar, Malaysia finds itself caught between encountering a humanitarian crisis and having to deal with the security and social problems that are bound to arise when asylum-seekers are allowed to swarm into the nation.
UNHCR is the United Nations High Commission for Refugees.

There's a lot of information on this tragic situation at the link.

Australia: Parliament divided on increasing border biometrics

Government biometrics bill meeting resistance (CSO)
If passed, the Migration Amendment (Strengthening Biometrics Integrity) Bill 2015 would expand the types of biometric identifiers that customs authorities can collect and the circumstances and places in which they can gather them.
 

Philippines: Electoral commission deletes some quantity of valid biometric voter registrations

Biometric data of early registrants lost - Comelec (InterAksyon)
Comelec spokesman James Jimenez did not say how much data had been lost, only acknowledging it was “not a very large number.”

He said they have written and otherwise informed affected voters “to come in and provide biometrics again.”
Biometric registration is mandatory for participation in the general election next year.

Thursday, June 25, 2015

Find Biometrics conclues monthlong focus on healthcare

Healthcare Month: The Remote Care Revolution (Find Biometrics)
Biometric technology, as we outlined in this month’s primer, can be used not only for security in healthcare and patient identification but also as a way of taking the hospital home. While the former two of these technology paradigms is focused on authentication and the latter on monitoring and data analytics, they both serve to address the same larger issue in hospitals and clinics: resource efficiency.
There is a wealth of great information at FindBiometrics.com

The line between Security and IT is getting blurrier

Bridging the gap between physical and logical access (Security Info Watch)
With the push by many end-users to migrate their physical access control systems to the IT network in recent years has also come an increased demand for solutions that can streamline both physical and logical access in a way that is less burdensome on workers.
Read the whole thing.

Wednesday, June 24, 2015

Useful perspective on face recognition technology

Is facial recognition tech really a threat to privacy? (BBC)
Facebook has decided not to offer its photo-sharing app Moments in Europe because of regulator concerns over its facial recognition technology.

And earlier this week, talks between US tech firms and privacy campaigners broke down over fears about how the industry is planning to use the tech.

So why is there so much concern over facial recognition tech, and is it justified? We unpick some of the issues.

ID and the internet of things

The Internet of Everything: Is your company ready for machine intelligence? (VentureBeat)
While most of us are familiar with biometric authentication, machine learning may make authentication effortless. “It’s about convenience,” says Zaki. “Our vision is that authentication should be happening in the background continuously.”

If you’re typing on your phone, your fingerprint can be immediately detected; if you’re looking at your screen, your iris can be scanned. Multifactor authentication can include a number of things...
It's going to be a programmatic challenge, but creating a "smart environment" that takes in bits of information from all available sources in order to identify individuals for logical and physical access control is becoming a possibility.

US: Making progress on visa issuance problems

US begins to fix visa problems, big backlog to clear (India Today)
"The database responsible for handling biometric clearances has been rebuilt and is being tested," Kirby said, adding that 33 U.S. embassies and consulates, representing 66 percent of normal capacity, are now online and issuing visas.
The exact nature of the problems that caused the US visa system to ground to a halt hasn't been made clear to the public. In articles informing this post and the previous one, "hardware" and "database" have been the only technical specifics mentioned. It's hard to say what went wrong without knowing exactly how the State Department's system was built, but it looks like things are returning to normal.

More progress will help clear the backlog of visa applications.

Friday, June 19, 2015

US: Visa systems issues related to hardware failure

Hardware glitch in Washington freezes US visa issuance worldwide (Times of India)
The State Department said the June 9 failure was preventing it from processing and transmitting the mandatory security-related biometric data checks routinely carried out at embassies and consulates worldwide, and it could take up to a week to fix it.
This Wednesday release from the State Department doesn't contain much detail that isn't included in the Times of India article linked above.

US: Face recognition ID check trial concluded at Dulles Airport

First phase of facial recognition trial at Virginia airport ends (Planet Biometrics)
The system captures live facial images of travelers entering the U.S., and compares those images against those stored electronically in travelers' passports.
The most interesting thing is that this hasn't been standard operating procedure for years already, as it's hard to conceive of a simpler facial recognition application. The hardest part would seem to be retrieving the image from the chip embedded in most modern passports.

Thursday, June 18, 2015

Forecast: Next Generation Biometrics Market to 2020

Next Generation Biometrics Market by Application, Technology, Function & Geography - Global Forecast to 2020 (Report Linker) — According to this report, the next generation biometrics market is expected to reach $24.4 billion in 2020, at a CAGR of 17.9% between 2015 and 2020.

Tuesday, June 16, 2015

US: Face recognition code of conduct confab loses privacy advocates

The National Telecommunications and Information Administration (NTIA) has convened a privacy multistakeholder process regarding the commercial use of facial recognition technology. On December 3, 2013, the NTIA announced that the goal of the second multistakeholder process is to develop a voluntary, enforceable code of conduct that specifies how the Consumer Privacy Bill of Rights applies to facial recognition technology in the commercial context.

Privacy Advocates Walk Out in Protest Over U.S. Facial-Recognition Code of Conduct (The Intercept)
“At a base minimum, people should be able to walk down a public street without fear that companies they’ve never heard of are tracking their every movement — and identifying them by name – using facial recognition technology,” the privacy advocates wrote in a joint statement.
The quoted article is full of links to NTIA online resources.

An "open letter" of resignation on the part of the named privacy advocates lists their concerns here.
Concluding paragraph:
We hope that our withdrawal signals the need to reevaluate the effectiveness of multistakeholder processes in developing effective rules of the road that protect consumer privacy – and that companies will support and implement.
Ultimately, of course, these are political questions rather than technological ones, but the focus on one type of technology (facial recognition) is a little difficult to understand. If it's wrong for a private corporation to track an unsuspecting individual's every movement, identifying them by name, why single out facial recognition (the means) rather than the tracking (the end)?

The privacy advocates, however, have a point in their favor. The effectiveness of confabs of privacy advocates, sub-cabinet-level administrators, and corporate executives in defining a society's scope for privacy in public should be questioned.

Also mentioned in the article is the fact that the states of Texas and Illinois have passed laws limiting the use of facial recognition technology to identify individuals in public without their affirmative consent.

Amazon envisions another way to unlock a phone: Ear photos

Forget Fingerprint Scanners, Amazon is Interested in Using Your Ears to Unlock the Phone — Here’s Why it’s Better (Technology Personalized)
The world’s largest e-commerce company was granted a patent last week that reveals company’s intention to ease up the unlocking mechanism in a phone when a user receives a call without any security tradeoff.

No need to forget fingerprint scanners just yet, though.

Monday, June 15, 2015

UK: Leicestershire police trial face recognition at music festival

Download Festival: Facial recognition technology used at event could be coming to festivals nationwide (The Independent)
Around 90,000 people attending the five-day rock event in Derby will have their faces scanned by “strategically placed” cameras, which are then compared with a database of custody images across Europe.

The force has trialled the system since April 2014 in “controlled environments”, but this is the first time the portable NeoFace surveillance technology, made by NEC Corporation, is being used outdoors in the UK on this scale.

Leicestershire police said it hoped the system would enable them to find organised criminals who prey on festivalgoers who are often victims of theft.
This sounds a lot like the 'Snooper Bowl' deployment we had a role in back in 2001.

Facial recognition surveillance in an uncontrolled environment with non-participating individuals still presents significant technical challenges. Among them are lighting, pose angle, and perhaps most significantly, training users on how to evaluate the information the facial recognition system generates.

See also: Leicestershire Police defend facial recognition scans (BBC)

Friday, June 12, 2015

Peru: Prepaid mobile sales will require fingerprint verification against national ID database

...with an assist from Microsoft Translator

From now prepaid mobile lines will be sold with fingerprint identification of users (Osiptel)
The operators will be required to verify the identity of users wishing to hire mobile public services in their offices, in the form of prepaid. This identification will be held from today through biometric fingerprint verification systems, which will be connected with the RENIEC database.
Full implementation is to be accomplished by January 1, 2017.

Thursday, June 11, 2015

Biometrics industry overview

Breaking Down Biometric Security (TechZone360)
Biometric security isn’t a new phenomenon, but until recently its real life applications and benefits have been underutilized by companies in most industries. However, recent buzz worthy announcements like Apple using Touch ID for enhanced security as part of Apple Pay and Miami International Airport integrating biometric fingerprint data into their passport control kiosks, are proving that biometric security is finally poised to become the norm.
Read the whole thing. The piece does a really good job of tying together various issues in the overall biometrics landscape.

Wednesday, June 10, 2015

Changing of the Guard at Secure Identity & Biometrics Association

SIBA Names Troy Potter of L-3 National Security Solutions as Chairman; SIBA Selects Commercial Identity Expert to Lead Growing Member Association (SIBA)
SIBA is a non-profit association that was established in February 2014 to steadfastly promote responsible policy, education and implementation of solutions that protect and secure identity across private and public platforms.

Potter was chosen because of his vast experience in both the government and industry. He served as the Identity Services Branch (ISB) Deputy Assistant Director at the U.S. Visitor and Immigrant Status Indicator Technology (US-VISIT) program and was US-VISIT's Biometrics

Systems Program Manager for a number of years, responsible for the management and oversight of one of the largest biometrics systems in the world. Today Potter is the vice president of L-3 NSS' Global Solutions Sector and leads all L-3 NSS Border Security and Biometrics programs.

Forecast: Global biometrics market in the healthcare industry will reach at CAGR of 31.95% by 2018

WhaTech.com
The Global Biometrics market in the Healthcare industry has also been witnessing the rapid technological advancement. However, the strong competition from inexpensive non-biometric technologies could pose a challenge to the growth of this market.

Friday, June 5, 2015

Canada announces biometric requirement for visa holders

Biometric data collection evolves and expands in Canada (CBC)
Citizenship and Immigration Canada told CBC News that digital photos and fingerprints are "the only biometrics data applicants will have to provide" under the government's plan for expanded collection of data. Visitors will have to pay $85 to cover the cost of data collection.
Travelers who don't need a visa to travel to Canada are, apparently, unaffected.

Wednesday, June 3, 2015

Then again, probably not

Brain's reaction to certain words could replace passwords (Binghampton University)
According to Sarah Laszlo, assistant professor of psychology and linguistics at Binghamton University and co-author of "Brainprint," brain biometrics are appealing because they are cancellable and cannot be stolen by malicious means the way a finger or retina can.
"Just 12 more globs and some wiring and you can check
your email!"

Image source: Biosemi.com

When the alternative is the terrifying prospect of a stolen retina*, I guess you can't be too careful.

But, let's not get ahead of ourselves. Though there is little doubt that if any behavioral biometric can be used as a reliable identifier, evidence for that uniqueness could probably be found in the brain, measured, and used for ID purposes. Even so, brain prints as ubiquitous biometrics face every obstacle we discussed in our post, The challenges confronting any new biometric modality, and then some.

The linked article doesn't make any mention of the sensor to be used to collect brain prints, much less offer a vision for how a future identification scenario might work.

This is one of those subjects that is intensely interesting from a Ph.D. candidate's point of view (invention) but not so much from an engineering or business perspective (innovation). Brain prints as a biometric will face significant — I dare say insurmountable — challenges in finding their way into wide use as a commercial ID management application any time soon.

The 94% accuracy is an issue, too.

*See also:

Iris ≠ Retina

Iris (left); Retina (right)


In fairness, the penultimate paragraph in the article quotes Zhanpeng Jin, who brings a more moderate perspective to the piece.

Tuesday, June 2, 2015

The automation revolution will be biometric

Robot check-in: The hotel concierge goes hi-tech (BBC)
It will be staffed by 10 life-like robots, with only two flesh-and-blood staff members on the premises.

The robots will greet guests, carry bags, and even clean rooms once a guest leaves. Complete with an eerily realistic female face, they are designed to speak several languages and respond to guest enquiries in the 72-room hotel.

The aim is to create an all-round hi-tech experience, including facial recognition software to open doors.

The automation revolution will be biometric (cont'd)

Self-Service Technology Market is Expected to Reach $31.75 Billion, Globally by 2020 (Press Release via NJ.com)
The technological advancements such as wireless communication and remote management would also facilitate the overall market growth. In addition, the integration of biometric security services such as fingerprint recognition, which ensure secured financial transactions, would boost the market growth.

Monday, June 1, 2015

Ubiquitous banking biometrics by 2020

Biometrics to become the predominant method to identify bank customers by 2020 (Goode Intelligence)
Growth in the banking industry will be accelerated by a number of factors including the arrival of electronic devices with built-in biometric support (notably smart mobile devices), the adoption of biometric-friendly authentication standards such as FIDO, the pressing need to combat rising banking fraud and identity theft, the growth of mobile banking and the emergence of wearable banking.

Thursday, May 28, 2015

US: IBIA wants NIST to do more for biometrics

NIST Urged to Expanded Role of Biometric Authentication (Find Biometrics)
...IBIA Vice Chairman Walter Hamilton pointed to recent years’ “surge in the use of biometric technologies for mobile banking and other e-authentication applications,” adding that “NIST should support this trend by providing guidance on how to ensure the effective implementation of biometrics as an authentication token rather than narrowly limiting its use.”

Enrolling a fingerprint in Windows 10

Windows Hello Biometric Authentication at Work in Windows 10 - Video (Softpedia)

Video (no audio) at the link.

Also, there is no mention of the fingerprint hardware used.

Still, if you've never seen a fingerprint enrollment before, you can see one now.

Wednesday, May 27, 2015

Biometrics for library convenience

Enabling patrons to log in and check out with a swipe of the finger (American Library Association)
Paul Sawyier Public Library implemented a biometric identification system in October 2008. Since then, patrons who sign up for a library card have the option to enroll in the finger identification system, which is required only when using the public computers and the media box located in the lobby. To check out materials or log on to computers using the system, a patron simply places his or her finger on the biometric scanner located at each station. Patrons checking out other materials can use their library cards as they always have.

Asia-Pacific region lagging in counter-terror biometrics

Interpol pushes for more use of biometrics to ID terrorists (Computerworld)
Interpol is calling for Asia Pacific authorities to make better usage of biometrics to identify members of terrorist groups such as ISIS.
...
“Europe provides 26 more times fingerprint data than the APAC region and 623 times more DNA data. Yet, we know the [APAC] region has the technology and does make use of it at national levels.”
The Europe-Asia comparison is even more dramatic considering the size of their respective populations.
Biometric facial matching for outbound Aussie passengers accelerated (Government News)
Australia’s Immigration and Border Protection authorities have revealed an accelerated plan for the rollout of new automated biometric facial recognition gates at Australian airports for outbound Australian passport holders and some travellers departing the country as part of $630 million counter-terrorism sweep.

Tuesday, May 26, 2015

India: Income tax department sees value in UID

I-T department exploring ways to seed PAN with Aadhaar (Live Mint)
The income tax department is exploring ways to hasten the pace of seeding permanent account number, or PAN, with the unique identity number Aadhaar, a move that will weed out duplicate PANs and help the government’s drive against tax evaders.
This would allow the Income Tax Department to maintain its own ID numbering system for its own purposes — they may tax entities such as corporations that don't have biometrics, after all — while harnessing Aadhaar for detecting tax fraud among individuals.

China: Regulators reluctant to allow online bank account creation

Chinese Regulators Put Brakes on Facial-Recognition for Payment (PYMNTS.com)
Currently, in China, a customer must physically appear at a bank to have his or her identity verified by an employee before he or she can open an account. There is a push in the industry, the report points out, for facial-recognition software to replace the need for a customer’s physical presence to conduct banking business.
China seems to be drawing a regulatory distinction between what ID requirements should be in place in order to open a bank account versus what ID requirements banks can use for authenticating transactions.

Wednesday, May 20, 2015

IBIA objects to TSA's planned identity management protocols for PreCheck

IBIA questions TSA plan on PreCheck expansion (Planet Biometrics)
The International Biometrics and Identification Association (IBIA) has objected to plans by the Transportation Security Administration (TSA) to exclusively use just biographic data solutions in an expansion of the PreCheck travel screening program.
There's an interesting quote in the piece that compares what the TSA is proposing to the fraud prevention techniques commonly used by credit card companies.

That alone should give pause. For credit card companies, fraud is an actuarial problem. Credit card companies earn 3-4% on every transaction plus interest fees for carried balances. There's plenty of room for both fraud and profit in that model.

The TSA's job is different, and perhaps their fraud prevention techniques should be, too.

Latest SecuGen Hamster fingerprint reader looks pretty slick

SecuGen Hamster Pro 20 (SecuGen)

Earlier versions of the optical fingerprint reader were much taller.

Souce: SecuGen
 

Tuesday, May 19, 2015

India: Biometric UID is good politics

For Modi government, UID the wild card that came good (Economic Times)
According to the Economic Survey, Aadhaar card enrolments were increasing at a rate of 2 crore per month. The government had seeded over 10 crore bank accounts with registered Aadhaar numbers by December 2014.
1 crore = 10 million

Friday, May 15, 2015

Massachusetts contemplating biometrics to curb welfare fraud

Bill proposes Mass. study implementation of fingerprinting, biometrics to reduce welfare fraud (MassLive)
Under the provision, the Department of Transitional Assistance and the Office of Health and Human Services would be required to study the feasibility of using biometrics - which includes fingerprints - to reduce fraud in public benefit programs.

The language, part of a $15.4 million amendment assembled by the House Committee on Ways and Means, cleared the House on a 158-0 vote Tuesday afternoon.
New York City actually implemented a system like this a few years back. It worked, too. Mayor Bloomberg liked it. Governor Cuomo didn't. Survey data at the time indicated that a majority (53%) of Americans favored such an approach.

See:
New York City: Fingerprints for Auditing Food Stamps (October, 2011)
Governor Proposes to Prevent New York City From Using Biometrics To Stem Welfare Fraud (May, 2012)

USAA mobile biometric authentication opt-in data

Biometrics Find Support from an Unlikely Demographic: Seniors (American Banker)
More than 400,000 USAA customers, five of whom are over 90 years old, have opted in to use biometrics (face, voice or touch) to authenticate themselves to the company's mobile banking application.
The median age for customers opting for biometrics is 3.5

About 7.5% are over the age of 65.

Four are in their nineties.

New biometrics advisors to focus on use cases

Market Research Firm Announces Biometrics Advisory Service (Find Biometrics)
Tractica’s approach is to focus on use cases, which Lockhart says “define the biometrics market opportunity.” The company has classified 142 use cases, and offers a profile specific to each with respect to “business function, industry, and modality.” And the advisory service consider a wide range of biometric modalities, from the widespread (fingerprint scanning, facial recognition) to the more obscure (electrocardiogram and DNA recognition).
Technology isn't an application, so the focus on use cases is appropriate.

Wednesday, May 13, 2015

Face rec in China

Current facial recognition technology can do more than guess your age, as businesses are finding out (Global Times)

Concluding quote:
Besides traditional application for a secure entry or time clock system, facial recognition technology can be used in other fields such as remote identification.

The market for facial recognition technology is ultimately decided by the population. China has an immense population, which makes it a potentially huge market, according to the report from Bosi Data Research Center.

"But customers should know that multimodal biometric identification is much safer than single biometric identification, especially when the technology is used in finance," Lü said. "We can't ensure the facial recognition technology can be 100 percent accurate, and it's safer if you can use other biometric identification together."
There's more good information at the link.

Fujitsu and NTT DoCoMo team up for mobile iris biometrics

NTT DoCoMo launches smartphone with iris unlock feature (PC World)
The Fujitsu prototype incorporated a high-speed, high-accuracy iris recognition algorithm developed by California-based Delta ID. Fujitsu said the error rate for the prototype is about one in 100,000.

Available in green, black and white, the Arrows NX F-04G is slated to be released at the end of this month in Japan for around ¥55,000 (US$460). There are no plans to sell it outside Japan.
I somehow missed the first mention of this collaboration in early March.

Friday, May 8, 2015

India UID: Interesting de-duplication and exception stats

Over 9 crore Aadhaar enrolments rejected by UIDAI (Zee News)

Out of 823.3 million enrollments, 97.3 million (Approx. 12%) have been rejected for reasons of either quality or duplication.

This may seem to be high to some, or low to others. In the big picture, there is (or should be!) a cost-benefit analysis at the beginning of the project that gets at the expense of the process vs. the infallibility of the process. On the first pass, it might make sense to get the highest proportion of good enrollments with the most convenient process, then to engage in a more expensive enrollment process applied only to more difficult enrollments.

It's also important to note that the 97.3 million rejected enrollments contain both duplicate applications, which must be rejected and other applications where clerical error, fraud, or un-enrollable biometrics are the reason for rejection.

Another interesting statistic in the article is that only about 618,000 UID numbers have been issued under the "Biometric Exception Clause" which allows for creating UID numbers for people whose biometrics cannot be enrolled. That comes out to around 0.07%.

What that means is that (depending on the number of people waiting for a biometric exception) using a data set approaching a billion individuals, at least 99.3% of the population of India is biometrically enrollable within the existing UID enrollment process.

Note: The article uses the Indian numbering units crore and lakh.

1 crore = 10,000,000
1 lakh = 100,000


See also: UID applications without biometrics highly likely fraudulent

Payments: Visa has some catching up to do

Visa Focuses on mPayment Expansion, Biometric Security (Find Biometrics)
Visa is ramping up its efforts to get into the digital payments game with an expansion of its digital wallet service and more intensive investigations into biometric security.

Forecast: Key biometrics industries and applications - 2024

Biometrics Market Forecasts (Tractica)
Tractica’s forecasts indicate that key industries in the biometrics market over the next decade are likely to be finance, consumer devices, healthcare, and government, followed by enterprise applications, defense, education, law enforcement, and non-government organizations. Key use cases that are likely to drive biometrics revenue over the next decade include consumer device authentication, mobile banking, automated teller machines (cashpoints), government IT systems, point-of-sale transactions, pharmacy dispensing, and wearable device authentication.

Wednesday, May 6, 2015

Fingerprints help end 55-year fugitive search

Fingerprint ruse IDs Florida man as longtime Ohio fugitive (MSN)
Authorities in Florida say a ruse to get a man's fingerprints led to his arrest as a convicted killer who escaped an Ohio prison farm and disappeared for most of six decades.

Brevard County deputies say investigators with the U.S. Marshals Service in Ohio sought help to check out the man while chasing leads about Frank Freshwaters, an Akron man who escaped in 1959. Major Tod Goodyear says they created a ruse to get the man to sign papers, then matched the fingerprints to those from the decades-old arrest.

Biometrics aid in aid delivery

IOM Uses Biometrics to Aid Displaced in Democratic Republic of the Congo (MENAFN)
The lack of identity documents for IDPs in the Eastern DRC poses a challenge in targeting humanitarian assistance. Almost 80 per cent of adults living in sites having no form of identity documents. In response IOM launched a biometric registration pilot project in eight displacement sites around the city of Goma in June 2014.

Between June 2014 and April 2015 IOM took the fingerprints of nearly 16000 IDPs. In the context of food distributions the collected information is used to ensure that humanitarian aid reaches the most vulnerable and avoids duplication and fraud.
Biometrics are an inexpensive, fast and accurate way of setting up ad hoc ID systems from scratch. Those interested in development and disaster recovery, take note.

Monday, May 4, 2015

US: Federal prosecutors want to use voice biometrics in court

Prosecutors want to use hi-tech evidence in trial to identify voices of terrorists (Daily Mail)
Terrorism prosecutors in Brooklyn want to use sophisticated voice recognition evidence — the same technology used to identify ISIS butcher “Jihad John” — for the first time in a federal trial in the U.S., the Daily News has learned.
The novel part of this that prosecutors wish to use the technology in a Federal trial.

Voice biometrics have made news in a criminal trial before. This 2012 piece by Jeff Weiner of the Orlando Sentinel describes voice biometrics used by an expert witness in the trial of George Zimmerman.

Tuesday, April 28, 2015

US GAO: To reduce fraud, MediCare smatrcards need biometrics

Smart cards would do little to curtail Medicare fraud: GAO (McKnight's)
...[K]ey [smartcard] benefits, including the ability to electronically exchange beneficiary medical information and electronically convey beneficiary identity and insurance information to providers, would do little or nothing to deter fraud, experts said.

Adding certain layers of protection to smart cards like biometric biometric information or a picture ID could help to deter fraud, the GAO said.
Note: GAO = Government Accountability Office

SIBA head testifies before congressional committee on border biometrics

Senate Homeland Security Committee calls SIBA's Kephart to testify (Secure
Identity & Biometrics Association (SIBA))

Testimony before the Senate Homeland Security & Governmental Affairs Committee
Tracking the arrival and departure of foreign visitors to the United States is an essential part of immigration control, law enforcement and national security. The need for arrival controls is obvious, but recording departures is also important; without it, there is no way to know definitively whether travelers have left when they were supposed to. Biometric entry/exit and transfer solutions are proven in their feasibility, low cost, added security value, increased efficiencies, travel convenience, and accuracy. Good products are available off the shelf. They are flexible and built, and can be customized, for many environments. The biometric, secure document and identity management industry is well-versed in integration with back-end data systems while building in flexibility for the future. Biometric solutions such as facial recognition, fingerprints and iris scans assure identity when coupled with biographic information found in travel documents. Using only biographic information, however, such as names or passport numbers, provides no assurance that the person departing is the one whose original arrival was recorded.
The quote above is taken from the pdf linked to the article at top. The 29-page document is an excellent resource for those interested in the topic.

Biometrics a factor in World Bank's optimism on India

While India’s Economy has Turned the Corner, Wider Reforms are Needed to Boost Economic Growth (World Bank)
The report points out that India’s government has begun to implement reforms to unlock the country’s investment potential - to improve the business environment; liberalize FDI; boost both public and private investment in infrastructure; quickly resolve corporate disputes; simplify taxation, and lower corporate taxes. States are set to receive more resources and spending power, and the government has reiterated its resolve to implement the GST by April, 2016, a move that is widely expected to meaningfully increase India’s tax to GDP ratio. New models of delivering benefits through direct transfers to bank accounts, together with the biometric identification of beneficiaries, are expected to reduce leakages.

Monday, April 27, 2015

India: UID milestone

Aadhaar world’s largest biometric ID system (Times of India)
The Aadhaar card has emerged as probably the world's largest biometric identification programmes in the world with the Unique Identification Authority of India (UIDAI) issuing nearly 82 crore cards.
1 crore = 10,000,000

We haven't been spending as much time on issues of economic development as we have at other times in the past, but India's major ID initiatives are creating a lot of opportunities to lift millions out of poverty.

Friday, April 24, 2015

Best comments thread I've seen in a while...

Biometrics May Ditch The Password, But Not The Hackers (NPR) — The piece itself is rather de rigueur, but the comments are a great way to start Friday.

It looks like that Paypal piece was pretty widely read.

Consent and Trust

Biometric Data Without the Big-Brother Angst (American Banker)
At the end of the day, biometric data is really just another type of personal data that banks hold, access and use with the trust of customers and employees. But obtaining consent should not just be seen as merely a bureaucratic necessity. It is part of a process by which banks can maintain and enhance trust — which only becomes more important in the age of big data and virtual relationships.

Thursday, April 23, 2015

Older Andriod versions had more vulnerabilities

Is Samsung's Galaxy S5 'leaking' YOUR fingerprints? Flaw means hackers can intercept and steal biometric data (Daily Mail); Forbes piece, here.
The pair told Thomas Fox-Brewster from Forbes that the flaw lies in older versions of the Android operating system, up to and including Android 4.4.

Subsequently, anyone running Android 5.0 or above are not at risk and the security experts are advising people on older models to update as soon as possible.
The semi-technical press seizes upon biometrics as a proxy for personal data. This is old news, but here's a great example.

A close reading of the article reveals that earlier releases of Google's version of the Android mobile OS weren't as secure as they are now. This will come as news to few. The article points out that, "Once inside they can monitor all data sent to and from the phone, as well as data recorded by the handset's built-in sensors, including the fingerprint scanner."

Get it? Exploiting the security flaw means that the whole device is compromised: Email apps, microphone, location information, and possibly even the contents of phone calls themselves, but according to the author and editor(s), the news value is in the possibility of capturing a fingerprint image. Of course, it's their outfit; it's their call.

For readers here, instead of "OMG fingerprinst[!]," I'd emphasize that:

Not all mobile operating systems are created equal.
Different mobile applications offer a different mix of privacy costs and benefits.
Installing OS updates and patches is very important.
If the OS is compromised, the applications it runs are vulnerable.

Left out of the information readily available online about this hack is how the people at FireEye got their malware onto the hardware in the first place. Past "hacks" of biometric systems have been executed on a playing field that is far more favorable than the real world to the the hackers, where all the other layers of the security regime are stripped away from the one security link they want to test. Here's a particularly striking example. If FireEye rooted the phone, side-loaded their malware onto the device, and went from there, this isn't a hack in any real sense — it's a malware test.

That hypothetical scenario would mimic a real world example where a user lost their phone and bad guys got it, loaded software on it and then returned the mobile device to the user who continued as if nothing had happened. In the security world, if you lose control of the hardware, all bets are off for anything that isn't encrypted (with a strong key).

So, without more information, it's hard to say how big a deal this is, or in many (most?) cases, was. In the bigger picture, this is a Google Android OS story. The subtext is that users who care about mobile device security should be thoughtful about what device/OS/app combinations they adopt, keep their device's software up to date, and be careful about malware.

As automated and convenient security including biometrics becomes better and more common, the highway robbers of the 21st Century are increasingly forced to turn to social engineering techniques rather than frontal assaults on security technology.

See: The Con is Mightier than the Hack



Wednesday, April 22, 2015

Monday, April 20, 2015

Looking for cyborg customers, or, I forgot to take my Paypill

Kill all passwords by eating them says PayPal (Techworld)
He says external body methods like fingerprints are “antiquated”, and that internal body functions like heartbeat and vein recognition using embedded and ingestible devices are the future, to allow “natural body identification”. LeBlanc says internal devices could include brain implants, and that ingestible devices could be powered by stomach acid that runs batteries.
Time will tell, I guess, but user acceptance has been has been a big issue for identity management solutions using biometrics. A bank asking customers to put something in their body in order to access their money would seem to be of another character entirely.

Perhaps the analysis is meant to provide a perspective on what far-distant ID management technologies will look like. Even then, with the exponential growth of the computing power in "externally carried computers" i.e. smartphones, it's hard to see how gaining a foot or so of proximity distance by moving the token inside the body lowers error rates enough to justify the mess.

The subtext is this, though:

"We know how to identify machines. People are a pain. If we can just turn the people into enough of a machine, all our problems are solved." In other words, engineering! There's a problem here, though. If you turn the machines into people, the machines will probably get harder to identify.

At SecurLinx, we'll keep at it just in case.

Thursday, April 16, 2015

US: Social Security Number is an unreliable identity management technology

Should We Kill the Social Security Number? (Huffington Post)
That's right: Social Security numbers were not intended for identification. They were made to track how much money people made to figure out benefit levels. That's it. Before 1972, the cards issued by the Social Security Administration even said, "For Social Security purposes. Not for Identification." The numbers only started being used for identification in the 1960s when the first big computers made that doable. They were first used to identify federal employees in 1961, and then a year later the IRS adopted the method. Banks and other institutions followed suit. And the rest is history.
Author: Adam Levin, Former Director New Jersey Division of Consumer Affairs; Chairman of Credit.com and Identity Theft 911.

There's a lot of good data in the article about just how much fraud is perpetrated against the IRS, fraud that is at least partly due to over-reliance on the Social Security number for ID purposes.