Showing posts with label IDAP. Show all posts
Showing posts with label IDAP. Show all posts

Monday, 21 November 2016

I didn’t say you could touch me

The use of biometrics in user authentication is thriving with fingerprint sensors becoming more common and technology evolving for reliable facial and voice recognition being used within apps.  Next generation smartphones may also contain iris scanning capability thanks to micro form factor components that can be included in the existing footprint.   This convenience is driving a wave of innovation in how organisations identify their customers.  As with any trend, a flood of ideas is generated - with associated risks too.

Over the past month I have heard several industry speakers explain how they’ll use these on-device biometric capabilities to verify the identity of new customers.  Which brings the first misunderstanding which can be quickly addressed; unless you have an established link between the biometric and the identity, you can’t verify your customer.  Facial recognition offers opportunities of comparison against the established physical identity documents, such as passport or driving licence.  Though this is nothing new and the quality issues with this are on validating the document and getting a sufficient quality image of the printed photo.



There’s no commercial source of verified voice biometrics, so there is nothing to compare against.  And whilst some physical documents contain fingerprint samples, the ability to access these presents a major hurdle without additional hardware.  The other issue with a fingerprint is that sensors used in smartphones don’t present the fingerprint for comparison.  The device simply signals the authentication has occurred.  The case may likely be the same for other on-device biometric authentications.

Which brings us onto another risk with authentication on a multipurpose device based credential.  The iPhone allows up to five fingerprints to be registered and used to authenticate using TouchID.  I can choose to take prints of my thumb and four fingers from one hand; digits from both hands; or I can register the fingers of myself and four friends; in fact, which digits, from which hands and from which people is entirely my choice.  Authorising others to unlock my phone doesn’t mean that I’m authorising them to sell my car.

Now this is nothing new from any other form of credential.  I can authorise you to use my bank card by giving it to you and telling you my PIN.  With on-device biometrics I can do the same thing though I need to clearly consent to the activities that I’m authorising.  If I normally log into my banking app using a password, they can’t simply enable TouchID authentication without tying the consent back to me first.

Smartphones have revolutionised how we interact digitally with our customers.  Biometrics bring a new realm of convenience.  Before we start implementation, we need to ensure that we understand the implications and get the design right.

We still need to have robust identification of the customer.  We still need explicit consent from that customer.  And we need to ensure that their responsibilities should they delegate authority (whether we encourage it or not) are understood and accepted.  Getting it wrong will lead to accusations of inappropriate touching; and no one wants that.

Read my other posts
Let's get physical - how to get fit for the digital era by leveraging the offline world
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing Poor security practices are putting users at risk 
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan


Tuesday, 28 June 2016

I not the person I used to be

Digital identities are set to revolutionise how we transact with business, with governments and with each other.  A secure binding of our real world identity to a secure digital token that will allow us to perform trusted transactions online.

At the moment, there is a lot of focus on how we onboard the real world identities and create the initial trusted binding to the digital token.  In India, the Aadhaah identity scheme have been creating a national register of identities for over 6 years - collecting the biometrics of over 1 billion residents.  In the UK, the GOV.UK Verify scheme has 8 private sector identity providers competing for the enrolment of citizens at the point in time when service provision is required.  Norway, Sweden and Canada use Bank issued identity credentials.  The different models used are based on national circumstances, customs and practices.  Though the common theme is that this initial registration process is a huge commitment for both the identity provider and the end users.

The other area of focus is on authentication; once we’ve bound the real world identity to the digital token, how we allow the end user to assert their ownership time and time again.  Credentials range from the humble password, through the convenient if you have it to hand usb key, to mobile apps / codes.  With the war on the password recently being stepped up by Google, we’ll start to see biometrics, behaviour and characteristic probability added to the mix.  

The biggest challenge though is how to maintain the link between the real world and the digital token.  Things in the real world have an annoying habit of changing - so how to keep the digital token in sync whether through genuine change or fraudulent use is an area that needs to be addressed before the hard work of on boarding is corrupted.  The monitoring, fraud controls and background rechecks that are sufficient today will be lacking tomorrow as more trust and more services become reliant on the digital identities that exist.



Using authentication to strengthen the binding of the real world identity to the digital token over time is an exciting opportunity.  If the identity provider can distinguish to a high degree of probability that I am the one authenticating against my digital token then they no longer need to check against mortality records to ensure that I am still alive in the real world.  If they know that I sign in from my home location, they can also confirm to a high degree of probability that my real world address is still valid.  The reverse of this is that they can also identify that my digital token may be being used fraudulently, either by me or another party (identity theft).

The propagation and growth of the digital identity market makes the need for more intelligent re-proofing and re-checking back to the real world identity a higher priority than it currently is.  Time or frequency based checks that are sufficient today will be reduced to real time verification.  Whilst the authentication services may not be sufficiently mature yet (in terms of implementation) to allow our behaviours and characteristics to be used for asserting our identity now is the time to start looking at how they can be used for protecting and verifying the link between our real world identity and the digital representation of it.

There are certainly challenges around privacy and data consent to be addressed - though if we don’t start doing the thinking now we’ll lose the trust and therefore the hard work that went in to establishing the original link.  Otherwise, how confident will service providers be in 2 years time that my digital identity is still the person I used to be?


Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA



Connect with Bryn on Linked In: Bryn Robinson-Morgan

Thursday, 17 December 2015

Bring your own downfall

The dinner party in the 1970's was the way to show off to your friends how sophisticated you were - treating them to prawn cocktail starters, chicken kiev for the main course and an artic roll for dessert.  And of course, you'd also have raided your nearest Marks & Spencer's supermarket for a bottle of their finest generic White Table Wine.  You see, back in 1973, you only had a choice from a handful of wines - so it was easy to pick something that no-one would enjoy while at the same time appearing to be the height of the social scene.

Fast forward to the nineties and not only were there hundreds of bottles of wine to choose from, there was also a huge range of beers, spirits and alcopops - something to suit everyones tastes.  You'd be faced with spending £30 on a bottle of wine to please the Leadbetters while your other guests would still rather have a beer or some vodka.  And so began the rise of "bring your own bottle" - the novel concept of allowing your guests to bring what they would enjoy rather than forcing your taste on them.

The concept of "Bring Your Own" didn't just stop at what drink you'd take to your neighbour's party - it morphed into freedom of choice for the office worker.  No longer did employers insist that their workers suffer the 3 year old, previously enjoyed, locked down to the point of being unusable, corporate laptop (often with a range of crumbs and other nastiness trapped in the keyboard); instead they would welcome their staff to the future "bring your own device".  Now employees could bring their shinny state-of-the-art Macbook into the office and use it to access the corporate network.  No more waiting for half an hour in the morning for the prehistoric corporate laptop to boot up; no more having to close one program down to free up memory to open another.  And even better, some employers gave their staff an allowance from the money they saved by not having to give them a work PC.

Yet for some reason, BYOD still remains "the future" at a large number of organisations.  Security, inter-operability, tax issues, regulation, health & safety... the list of excuses goes on.  Even some of the organisation who allow BYOD wrap so many conditions around it, such as installing software to block or diminish the experience of personal use on your own device, that employees become disenfranchised with the idea.

For the organisations who haven't embraced BYOD there's trouble looming.  The next wave of "Bring Your Own" is customer focussed.  Bring Your Own Authentication/Credentials/Identity will disrupt how the consumer interacts with business in the digital era.  If customers can't remember passwords, they'll chose a different type of credential that works for them... and they'll want to use it with whichever company they chose.  If they've proved their age once and now have a verified attribute they'll want to assert it anytime they are required to - regardless of who verified their age and whom they're now asserting it to.

Digital disruption, powered by the ability to bring your own identity, has already started - Chip & PIN, which had a painfully slow global adoption, is already seeing the impact of the digital wallet.  Retailers, including Marks & Spencer, have embraced consumer choice for convenience, with banks and card providers often reluctantly falling into line, as their customers reach for their mobile device to authenticate their payments.  Portable KYC, identity passports, attribute exchange and federated authentication will gather pace over the next 12-18 months; organisations who are still looking inwards at how they respond to BYOID will lose ground to those who are looking outwards at what role their organisation will play.

Customers will look to convenience, organisations will look towards trust, security and liability, when deciding what identity standards to adopt - the market has a lot of work to do to mash these together.  The visionary, customer centric companies, will move towards a risk appropriate framework.   One that provides a rewarding experience for their customers.

For those companies who keep looking inwards, if you're still offering your customers the identity experience comparable to White Table Wine in a year's time, you might just bring your own downfall. 

Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan

Tuesday, 7 April 2015

Tick to Agree

Do our customers really trust that we do the right things for the right reasons when it comes to their data?  The digital economy is founded upon data that belongs to our customers. We may source it, store it, aggregate  it, make sense of it, commercialise it... yet if we share it just how informed should the consent be from the people who own it?

We've witnessed tiny tremors that have been described in the media as a backlash; though in the scheme of things the customer reaction was nothing more than tomorrow's chip paper.  Sony may have lost a heap of credit card numbers but its customers were soon distracted by a free game to download; Google may be evil but their customers don't have time to search for a new search engine; Facebook may have the right to replace you with a substitute human should your own life become too dull but their customers want to know when their friends are drunk. (There may be some artistic licence at work here I admit :)

The fact is that to date nothing has occurred that has truly caused a customer backlash in the way in which we organisations trade their data. Even the most outraged, moralistic, educated and knowledgeable customer still ticks the terms and conditions box without instructing a lawyer. They still swipe their loyalty card at the checkout to buy the newspaper with the headlines about the latest data privacy breach. And they still send emails and check the adverts specially tailored for them that magically appear. 





We wouldn't give our customer's money away quite so nonchalantly; so is doing the right thing with their data treating it in the same manner?  Rather than getting our customers wrapped up in 56 pages of terms and conditions written by the legal department on how we intend to use their data it would seem much fairer that our marketing department wrote our key terms. The same points on how we source it, store it, aggregate it, make sense of it, commercialise it - written in easy to understand bullets. 

If we start being transparent with our customers about our role in the use of their data we may have to rethink our data strategy. How we commercialise their data; what, how and when we share may have to be done in more innovative and customer centric ways. 

The alternative is that we continue to ride on the wave of customer apathy.  We can continue to tell customers that we might do bad things, on purpose or by accident, with their data but never mind because you agreed we could. 

Over the next 5-10 years the tide is turning and the wave of apathy will come crashing down. Simply with the amount of data we will hold and the value it contains, the organisation who doesn't treat their customer's data like their customer's money will be the one to drown. 

Now is the time to start building our customer's trust by doing the right things for the right reasons when it comes to their data.

Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me
Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA

Connect with Bryn on Linked In: Bryn Robinson-Morgan