Wednesday, June 30, 2010

Biometric IDs to plug leaks in rural job scheme

livemint.com

The plan is to roll out a GPS-enabled system to address the issue of ghost workers and misuse of job cards.

Corruption can make it difficult to get help to the needy. Biometric identity management systems can help ensure that more of a government's social services spending reaches its intended recipients.

Tuesday, June 29, 2010

How safe are you in the 'identity ecosystem?'

Government Computer News (GCN.com)
The White House’s plan for an “identity ecosystem” seems to be built on good intentions – using trusted digital identities to allow secure online transactions without the need for passwords – but its designers will have to sell the details of the plan if they are to win over our readers.
Related:
From the Jerusalem Post
Knesset passes law regulating electronic signatures

Monday, June 28, 2010

Sen. Robert Byrd of West Virginia dead at 92

From the Charleston Gazette (WV)
In 1989, he was elected president pro tempore of the Senate -- a largely ceremonial post -- and named chairman of the Appropriations Committee. It was there that he began funneling federal projects and money to West Virginia in earnest. The first big salvo came in 1991, when FBI officials announced they would build their new fingerprint identification center just outside Clarksburg.
Sen. Byrd has been instrumental in making the I-79 development corridor a hotbed of biometrics-based entrepreneurship. He will be missed.

Friday, June 25, 2010

Voice – The Killer App

From WirelessWeek.com
The value of voice is rarely assessed and certainly, from a telephony perspective, voice is as commoditized as tapwater. However, the ability to use voice as a biometric signature may be coming of age, particularly as we are on the cusp of a whole host of mobile transaction services where authentication of the end user will be paramount.
To date, voice biometric deployments aren't very common. There are, however, many types of transactions in the health care and financial sectors where voice is the only biometric available.

Thursday, June 24, 2010

India Census Update: Biometric process may need more time

Deccan Herald (Bangalore, India)
We've commented on the Indian Census here and here.

The process of collecting biometric data to provide national identity cards for residents of 183 coastal villages in the state took seven months. “Now we are talking about 30,000 villages, its a huge process”, Anil Kumar said.

Wednesday, June 23, 2010

Stillwater schools support plan to get data on kids to police in case of abductions

St. Paul Pioneer Press

Our own AmberVision child recovery system made the news this morning. AmberVision uses parent-supplied information, including a child's photo, in order to issue alerts over a wide area as soon as possible. Moreover, police in participating jurisdictions can use their blackberry or Windows CE enabled smart phone for facial recognition matches of missing persons.
"No matter what the circumstances are, every minute seems like hours. Every minute is critical," Stillwater police Chief John Gannaway said. "If you have that pertinent information at your fingertips, it's 100 percent beneficial."
Developed under grants from the U.S. Department of Justice, AmberVision was introduced nationally in August 2009. The AmberVision Foundation is a not-for-profit entity.

Tuesday, June 22, 2010

Local Hospital Uses Biometric Palm Scans to ID Patients

From SanDiego6.com
"PatientSecure is a nonintrusive and very precise method of identifying patients, ensuring they are matched to their own personal medical records and protecting them against medical fraud and identity theft," said Dan Gross, executive vice president of hospital operations for Sharp HealthCare.
The system described in the article seems to serve as an anti-fraud business solution rather than to increase patient safety as in this case, not that there's anything wrong with that.

Monday, June 21, 2010

Visa to drop signatures on credit card purchases by 2013

From Secure Computing (Australia)
Current technology is too "easy" to skim.
In the biometrics arena one often finds oneself in conversation with a biometrics skeptic. That biometrics skeptics exist is only natural and, of course, the burden of persuasion is and should be on those making arguments against the status quo.

Biometrics skeptics should have a proper grasp of the status quo in order to understand what they are defending.

Is signing a piece of paper every time you make a credit card purchase secure?

Is paying with a check secure? Checks display home addresses, signatures, bank account numbers, and frequently, even more information.

Is accessing your home with a funny-shaped piece of metal secure?

Are these things easier or harder to forge than biometrics?

These questions aren't necessarily technological questions and the answers are highly dependent on non-technical factors.

Visa seems to believe that signatures are not secure (see article) for credit card transactions.

You can write a check to a family member, put it in a greeting card and mail it with minimal risk (depending upon the family member).

Using checks for mail-order is probably a bad idea.

I hear stories of towns "where nobody locks their doors." For these folks, the funny-shaped piece of metal is more than adequate. Others might want something a little more robust.

So the question of whether or not such-and-such biometric identity management technology is "secure" makes little sense without the corresponding question: "Compared to what?"

Thursday, June 17, 2010

Chinese woman slipped through biometric identification checks

A Chinese woman arrested on suspicion of robbery has been found to have entered Japan unlawfully after changing her fingerprints to slip through airport biometric identification checks, investigative sources said Thursday.
Identity management is a lot like an arms race.

Tuesday, June 15, 2010

A unique ID for the masses

Following up on this post about the Indian census...

UID–GOI’s technology leap
The UIDAI project is expected to touch every adult citizen. A voluminous database and the sheer magnitude of this task requires robust security with no room for vulnerabilities writes Subhankar Kundu.
Indian moon shot indeed. This isn't just the world's largest biometric database, it is by far the world's largest biometric database.

Friday, June 11, 2010

Landlord's plan to use biometric security system raises concern

CBC News
Biometric deployments must be managed from a technological and human perspective. Biometric ID management systems are new and there is a lot of misinformation and misunderstanding out there.

Ultimately, these technologies will succeed because they make people's lives better and save them money, but they must be adopted in a manner consistent with established social norms.

The landlord in this case has obviously made some missteps.

The adoption of Biometrics is about where eCommerce was in 1999. To be honest, at that time I was one of the one's saying "Who would put their credit card number into a web site!?" Now I can't imagine going to a shoe store or buying music in a bricks-and-mortar store.

eCommerce grew as the early adopters rarely became victims of fraud and they shared their experiences with others. This is as it should be.

Anyone who attempts to force their customers into a system like this, especially as it relates to access to their homes, should be very careful.

Friday, June 4, 2010

Secure Communities in the news

ICE's Secure Communities program is getting a lot of attention.

SW Idaho to use fingerprints to ID illegal aliens - KHQ - Spokane, WA (6/4/2010)
Arizona immigration debate heats up in D.C. area - WTOP - Washington, DC (6/3/2010)
Secure Communities to Start in SF on Tues - SFGate - San Francisco, CA (6/1/2010)
U.S. Immigration and Customs Enforcement Secure Communities fact sheet.

Thursday, June 3, 2010

North American Biometrics Market Witnesses Growth Spurt, Finds Frost & Sullivan

redOrbit.com
New analysis from Frost & Sullivan, North American Biometrics Market, finds that the market earned revenues of $364.4 million in 2009 and estimates this to reach $1,588.6 million in 2016.
This is an excellent article summarizing findings from an excellent source for information about the biometrics market: Frost & Sullivan.

Tuesday, June 1, 2010

Mal-intent may be the future of security

The Sacramento Bee
This isn't related to identity management or biometrics but it is related to security.

Biometrics are used to establish a person's identity with a high degree of confidence so that the entity making the identification can accomplish further goals.

Identifying mal-intent does not seek to identify an individual but rather it seeks to predict undesired behavior through the detection of other behaviors.

Interestingly, both types of system represent attempts to predict the future.

One system -- the biometric one -- attempts to predict the future based on the identification of trusted or untrusted individuals. The assumption is that if I know who you are, I can make an educated prediction about what you will do.

The behavioral system, attempts to predict the future based upon what someone is doing now. If I know that people who do what you are doing tend to progress to other sorts of behavior, I can predict that you will also progress to that behavior. Or can I?

That's what the scientists are trying to figure out. Can you automate the judgments made by highly trained human observers of human behavior? Do people like Dr. Lightman from 'Lie to Me' exist? If so, can what they do be automated?

Friday, May 28, 2010

The Politics of Biometrics: A Shibboleth

Telegraph.co.uk - Children, 4, 'to be fingerprinted to borrow school books from library'

Anyone who terms the implementation of a fingerprint biometric system as described in this article as designed to help libraries serve their customers more efficiently "the fingerprinting of children" is either confused or or lacks respect for their audience.

"Fingerprinting" conjures up images of prison movies, the "rolled ten" and the loss of personal freedom. The fingerprinting process in the usage above is not undertaken in order to further the interests of the person providing the fingerprints. It is typically undertaken to help protect society from the person behind the fingers and carries with it a social stigma. Biometric alarmists intentionally and wrongly bring all of "fingerprinting's" social baggage and dump it onto fingerprint identity management systems.

Besides being misleading, the use of the term "fingerprinting" isn't technically accurate in this case, either. As with the fingerprints we all leave everywhere everyday, the only fingerprint that exists in the system described in the article will reside on the surface of the sensor and only until the next person uses it. According to Lesley Isherwood, the school headmaster, neither the fingerprint nor the image of the fingerprint is stored in a database.

What happens is this: A person places their finger on a sensor. The sensor reads the fingerprint and software turns the fingerprint into a unique number. For the software to work, the same finger has to be converted into the same number every time. It's the numbers that are stored, not images of the fingerprint.

This approach makes sense for a lot of reasons. First and foremost you can't lose data you don't have and no school administrator (risk averse lot that they rightfully are) wants to explain how they lost a bunch of kids' biometric information. Also, in a software environment, numbers are easier to work with than images. Moreover, most adults are rightfully protective of the innocence of children and are pretty conservative when making choices on their behalf.

Of course, an article with the headline: Children, 4, 'to be fingerprinted to borrow school books from library' is bound to have some choice quotes from a Biometric Alarmist:
“This is quite clearly appalling,” said Phil Booth, national coordinator of NO2ID, a privacy campaign group.
To be fair to NO2ID, judging by their web presence, Mr. Booth would appear to be one of the group's more committed members. The group itself seems to be pretty moderate in trying to raise issues of individual liberty and its relationship to the state in the context of digital identity management in a country (the UK) famous for its government surveillance systems. Nevertheless, the school library's system is far from self-evidently appalling. Thankfully, Mr. Booth provides some guidance for those who need some help becoming appalled.
“For such a trivial issue as taking out of library books the taking of fingerprints is way over the top and wrong.
If the taking out of library books is trivial, why not just close the library? And please don't take the child's fingerprints, she'll need those to get lunch.
“It conditions children to hand over sensitive personal information.”
No it doesn't; It conditions children that they must identify themselves to an organization in exchange for enjoying the services that organization offers. The fingerprint authentication is a substitute for a signature or an item with an attached bar code and it's not particularly sensitive.

A signature (which many 4-year-old's are unable to provide) is perhaps more sensitive than a number representing a fingerprint. Just think of the risks under the old signature-card-in-the-book-cover regime. Anyone who ever checked out a book after you could potentially forge your signature.

The use of ID cards with bar codes, an alternate identification method used by libraries, also poses a risk to the child's sensitive information in the event the cards become lost.

I do agree that children (adolescents and, alas, adults too) need quite a lot of guidance in keeping their privacy. See facebook, sexting, You Tube, etc. Something in the society is definitely conditioning young people to treat their privacy in ways that are shocking to some, but I don't think elementary school libraries are the culprit.
“The money for such a system could be spent on actual school resources. How about some more books for the library instead?"
A penny saved is a penny earned. Books are no different. One might hope that the identification system in use will prevent more books from being lost over time. It would then be up to the school to decide how to invest the savings. With the reduced risk of loss, perhaps they will buy more books. Rather than replacing lost volumes the library might even expand the number of titles they are able to offer.
“This needs to be rolled back or stopped. I would argue there is no justification for such a scheme.
There is obvious justification for such a scheme:
  1. It gives the library the ability to more efficiently serve its stakeholders by reducing transactions costs.
  2. It eliminates the necessity of a token (card). It is expensive to replace lost cards. Lost cards may be used by others. Those who have lost their cards will borrow others'. Children lose things.
  3. Reduced loss of library books, leading to a better library.
  4. It is a system that is so easy that, apparently, even 4-year-old's can use it.
Perhaps Mr. Booth means that the justifications are insufficient to overcome his objections. I would be very interested to hear his argument in more detail than is given in the article.

Thursday, May 27, 2010

South Australian prisons to get biometrics systems

ComputerWorld.com.au
The systems will provide a method of registering and verifying all persons – staff, visitors and inmates - entering and leaving the facilities, and assist in the management of persons moving in and around the facilities.
You really don't want to release the wrong person or let visitors switch places with inmates. Systems like these help a lot.

Wednesday, May 26, 2010

Hefner Middle School students are using biometric technology to buy breakfast or lunch

The Oklahoman
This is really a wonderful article touching on a lot of the things we discuss here.
"This is impressive technology,” said Jennifer Strong, director of food services and child nutrition for the school district and a Sodexo employee. "And, it definitely has the cool factor kids like. Anything we can do to make school food cool, we consider a triumph.”

Dupree Millhouse, 12, agreed. "The scan thing is much cooler,” he said. "And right now we’re the only school that has it.”
There have been a lot of efficiency gains surrounding how meals are delivered to students.

Less than 1% of parents have opted out of the system.

Monday, May 24, 2010

[Australian] Police seek national database of driver's licence photos

Brisbane Times

THOUSANDS of Australians have their identity stolen every day, costing the public billions of dollars every year.

To combat the problem, police need better access to information, including access to photos from every drivers' licence in the country, argues the head of CrimTrac, Ben McDevitt.

Friday, May 21, 2010

Goodbye ID cards - is it time to say hello to identity banks?

From ComputerWeekly.com
Much of the recent news about biometrics has been coming from the UK, with the new government there having scrapped the planned biometric national ID card and other identity management functions. Much of the news is written, of course, from a political perspective. If the personal is political, what can be more political than one's identity?
Bryan Glick at ComputerWeekly.com understands that the rejection of a statist, top-down approach does not mean that identity management systems are unnecessary or that all proposed systems will be rejected by a free public.
But there is a growing recognition that an increasingly internet-enabled society will need some form of electronic identity verification system to tackle identity fraud and provide the confidence needed to transact securely online, especially as more public services are provided over the web.
Glick then draws attention to a 2008 report by Sir James Crosby, then at HM Treasury, entitled Challenges and Opportunities in Identity Assurance (.pdf). The 47-page report contains a breadth of information that makes it a great introduction for how to begin thinking about the challenges associated with large-scale biometric identity management deployments. It is very accessible and deserves to be read widely.

Thursday, May 20, 2010

Google debates face recognition technology

FT.com
Mr Schmidt said: “Facial recognition is a good example . . . anything we did in that area would be highly, highly planned, discussed and reviewed. When you go through these things, you review your management procedures.”
Apart from Google's history with privacy issues, they do face a dilemma, as the article points out. There is no reason to limit search terms to text only. Some innovator will bring search into the visual arena and enable a picture to be used as the search term. Without new regulation, that means that at some indeterminate point in the future* someone could take a picture of a face with a cell phone and find out a lot about that person.

These tools are coming. They will bring huge productivity gains. They will be abused.

Those concerned about the effects of technologies like Google Goggles upon their family's privacy would be well advised to think about what information about them exists online and what they do now to manage who has access to it. Most of us have near-total control over what personal information ends up on the internet. If the only thing keeping online information about you "private" is the lack of better search engines, then it might be a good idea to reevaluate how much personal information you post/allow to be posted online.

It is possible, even likely, that the internet will become both more private and less private. More private as
Google increasingly respects the interests of content owners (FT again). Less private as better search brings more of the internet to users attention.



*The technical challenges of using a picture of a person's face as the only search term for a search of the internet for facts about that person are extremely daunting. If you take a picture of an apple, presumably the search would return lots of pictures and information relating to apples. If you take a picture of a person, presumably the search would return lots of pictures and information relating to people. Converting an object recognition search that has yet to be deployed into an facial recognition search is a long way off.