Showing posts with label Proof of Identity. Show all posts
Showing posts with label Proof of Identity. Show all posts

Sunday, 19 February 2017

Tipping the balance

Security is often seen as a trade-off for usability – a poor customer experience risks your product being unloved and unused; poor security leaves you at risk of a fine, sanctions, reputational damage or a swift and terminal death of your product, service or organisation.  As a product owner usability issues are usually quite tangible.  We can see through the users eyes the clumsiness that security measures introduce.  Often security is about risk, or intangible issues.  Judgements are made on likelihood and impact; we gaze into the crystal ball to imagine what would happen in the event that the security risks come true or the issues are exploited.  This crystal ball gazing often results in the wrong balance being struck – which invariably leads to poor outcomes regardless of which side we’ve come down on.



Authentication is one such area of functionality that product owners get badly wrong.  As the front door for customers to your product or service, getting authentication right is imperative.  Single factor authentication is generally inadequate for anything important and poor implementations of less important access undermine the entire ecosystem.  Two factor authentication is often clunky and not user friendly – having to run out of the building to get a mobile phone signal to receive your SMS one-time-passcode, carrying around an authentication token that you have with you at all times apart from when you actually need it, or needing to authenticate into another service to be able to authenticate into the service that you actually want to use.

To get authentication right, context is everything – if we factor in what the user is wishing to do, and combine with behavioural knowledge that we have of the user we can increase both security and usability.

Let’s look at a traditional use case: When I get into my car, I place my smartphone into its cradle and it connects itself, via Bluetooth to my car’s audio system.  As I’m driving along, I give a command to the smartphone’s virtual assistant – and recognising my command it says “you’ll have to unlock your phone so I can do that” – which I can’t do… as I’m driving.

Now if we look at the same use case with applied context: my phone is in my car so the chances of someone else using it are less.  While I still might not want to open full functionality – I don’t want someone to steal my phone, car and empty my bank account – I can authorise more functionality without the need for any further authentication.  I can also use behavioural information to further reduce the security risk – do I normally get my schedule narrated while I’m driving to the station?  The introduction of new credential use can be facilitated too – while voice biometrics may not be very reliable in a noisy environment, I can increase the matching tolerance due to the more granular levels of context applied.


This use of multifactor authentication and authorisation allow a much richer balance of security and usability to be achieved.  Behavioural biometrics and multifactor authentication could allow product owners to tip the balance in the favour of both usability and security.


Read my other posts
Let's get physical - how to get fit for the digital era by leveraging the offline world
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
You don't know what you're doing Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA



Connect with Bryn on Linked In: Bryn Robinson-Morgan

Sunday, 2 August 2015

Unblocking Digital Identity

When it comes thinking about citizen identity schemes, centralisation is so Y2K.  A decentralised or federated model would remove the bureaucracy, put the customer at the heart, delegate control to the user and balance security and usability.  Though look out federation, there is a new kid in town.  Distributed is where identity is at - or is it?

Blockchain, the distributed ledger solution behind Bitcoin, is becoming the hot topic of the digital identity world.  It ticks many of the important boxes - privacy by design, cryptographically secure, robust architecture, irrefutable provenance, consent and control with the user.  So Identity on the Blockchain could be the next big thing for citizen eID.

Though before giving up on federation we should put Bitcoin in context.  Relative to the British Pound (born 775), Bitcoin is a mere pup (born 2008/9) - though to compare it with another digital disrupter, by the time Facebook was 6 years old it had over 600m users - Bitcoin has less than 4m.  Having an unregulated, community owned technology is arguably more of a negative than a positive - particularly when it comes to things of value.  It is estimated that around a third of the Bitcoins created are now classed as zombie coins - the cryptographic keys required to transact them lost at the bottom of a rubbish tip.  And with no central authority there is no redress, no one to hold accountable other than the end user themselves.

Though the lack of a central authority has created a marketplace for a federation of exchanges and wallets; performing as an intermediary between the end user and the overall community.  Though in an unregulated marketplace how can you trust these intermediaries?  With loss of their customer's crypto keys and pending criminal prosecutions it would seem the answer to that question is that you can't.

While the Blockchain may be a future technology upon which citizen identity could be based it is also worth considering that the concept of the distributed ledger for identity has been used successfully for quite some time.  In the UK the General Register Office has been operating the exact model since the late 18th century - with births, deaths and marriages being recorded in local registers, that issue certificates to the end user, that they control as the central authority.



Bitcoin and Blockchain are technology led solutions that have gained a niche use in financial payments.  The same technology will have a role to play in pure play identity and access management solutions and it may solve use cases within the citizen eID space - though doing this from a customer led perspective to find the technology solution will have a greater chance of success.

The core challenge for a successful citizen identity scheme is to hit the sweet spot between allowing the real person to claim and assert their identity and preventing anyone else from doing the same.  Balancing how easy you can make the former and how difficult you can make the latter comes above whether your solution is centralised, federated or distributed. 

So maybe centralisation isn't quite so Y2K after all.  Maybe federation will solve the issues.  Maybe the future is Blockchain or another distributed ledger model.  Though if you were looking for the best solution - maybe, just maybe, a model based on the best of all of them could be the real future? 


Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan

Friday, 20 February 2015

The Kids Are All Right

Age 19, when you're throwing up on your own shoes, privacy, security and liability don't matter; what the "going grey" generation call convenience, does. If you can get a taxi cab to deliver you safely to your door, you will happily give full access to your identity (the location of your comfy bed with a tactically placed bin at the side of it) and financial information (promise not to take the long way round). 

This week, in the UK, the first integration of Apple's Touch ID came to banking applications. Cue uproar on how the technology has already been spoofed. Any security person worth their salt knows fingerprint biometrics aren't secure. Yes they may be more convenient than pass codes, but a high resolution camera or a shiny surface combined with a silica moulding kit and you have a security breach quite literally on your hands (well fingers).
 
The trouble is, that by the time you're old enough (in the "going grey" generation) to know the pitfalls, and you're suitably well established in your industry to be able to inform standards and best practice, you're no longer representative of the "yoof" generation who you're delivering products for. Nothing kills a great idea for the younger generation than their grandparents thinking it's cool. When your Gran sends you a snap of her running over someone in her mobility scooter, it's time to delete your account and move on to the next craze. 



So are the people setting the standards and defining best practice really focussed on the right things? Are they really best placed to do so? For a banking application, is Touch ID too much security rather than not enough?  Organisations want to know that the person making the transaction is authorised to do so, to enable them to prevent fraud, meet regulatory requirements, protect their customers and generally do the right thing. Yet from the customers perspective all they're concerned about is that if money goes from their account that they didn't authorise that they'll get it paid back.
 
Ultimately the role of the "going grey" generation is to warn, counsel and support the next generation. Informed choice rather than condescending control, and guided resolution rather than an "I told you so" attitude. Understanding the needs, views and opinions of "the kids" will drive better solutions focussed on outcomes of practical use. The younger generation don't value convenience; they expect it as a minimum!  Whilst sometimes this may result in loss or distress for either party, consequences are thought about after the event and there is a customer perception (rightly or wrongly) that someone else will help clean up any fall out.

A new view on authentication is that it is something that occurs as part of the transaction rather than something the user knowingly does.  Mitigating risk at other points before, during and after the transaction, will enable less reliance on strong authentication methods.  Does the transaction fit within the normal patterns of behaviour?  Is it being performed from a trusted device?  Is the location identifiable and known?  Is the value within acceptable risk tolerances?  Can the transaction be reversed?  And for what time period is it recoverable?  

Within all this, the concept of informed choice by the end customer also needs to be considered. Rather than industry experts having an outcry of nay saying about technologies such as Touch ID being used for banking, rather they should be focussed on the needs of the customer and giving them more credit for being able to make informed choices. If any fraudulent transaction could be recovered then zero authentication transactions would be less risky. 

Figuring out how, when at 3am your customer's account has been debited £50 that they can't recall authorising, you can resolve the dispute is a far more noble cause than worrying about the authentication method used to verify the transaction - particularly if your customer arrived home safely and able to sleep in their own bed, with their head rested on their bin. 

After all, the kids are all right. 



Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan

Thursday, 15 January 2015

The ridiculous mouse

“A mountain has gone into labour and was groaning terribly.  Such rumours excited great expectations all over the country.  In the end however, the mountain gave birth to a mouse.”
Phaedrus 4.24

At some point in our lives we’ve all been lectured that we only get out of life what we’re prepared to put in; and while on the whole there is a strong element of truth in this mantra, there are always tasks and activities where no matter what amount of effort we put in, the reward will never live up to expectation.  My own boyhood dreams of being a professional footballer (soccer player) weren’t dashed by my lack of effort - I was never going to make the grade due to having two legs made for standing and none for that were made for kicking.

The inspiration for this post comes from observing a customer insight session for an online identity assurance transaction.  The young man in the spotlight told the session facilitator how a lack of acceptable identity evidence impacted his life – how he was unable to open a bank account as he didn’t have the required documents to prove his identity to the banks standards; how he couldn’t get a mobile (cell) phone contract for the same reasons.  This was a guy who had genuinely tried, yet for all his effort there was no reward – and so eventually he’d stopped trying.   Instead he found other ways around the problem – his wages were paid into someone else’s bank account.  His partner had taken out an additional mobile phone contract.  This was a bright, savvy and confident individual who had been disenfranchised by a society who wouldn’t allow him access to basic services due to their inability to identify him.

Having partaken in a great deal of user experience sessions, this guy’s story was far from unique to me – financial and societal exclusion due to the inability to meet identity requirements is not uncommon.  What stood out for me about this young man though was the way in which he embraced digital identity – not only did he show an amazing comprehension of the technology and verification methods, he also saw the benefits to him of going through the registration process.   He understood with aplomb how the investment in time now would enable him to assert his identity in a simple yet secure way in future.

The joy of seeing a user react with such delight was tempered by the harsh reality that he was unlikely, at least in the near future, to be able to achieve the requirements to reach the required level of assurance.  For all the effort he would go through he would get no reward – his digital identity would afford him no more inclusion.

The rigid pass / fail nature of the four levels of assurance defined by the OMB and NIST which have been adopted as the de facto global standard are still mired in the constraints of face to face verification.  A digital identity is capable of providing a far more granular level of assurance backed by a rich data packet to enable the service provider to take a risk based approach.  In a mature marketplace the identity score should more likely take the form of the credit score – where identity providers constantly monitor and evaluate to provide real time granular scoring.  A scoring mechanism would exist where the individual’s pattern of behaviour and existence activity varies the confidence of the assurance given at any moment in time.

In the meantime, whilst the sector matures and evolves, the short term step must be to relax the four level model.  There is a need to introduce proportionate, defined, mid-levels of assurance.  Whilst service provider’s compliance department may still clamour for least risk approach, a more customer centric view is needed.  The registration should take the user through a journey proportionate to the transaction they are undertaking, in response to the data available to verify them.  Without being more pragmatic and proportionate, the same people who are currently excluded will continue to be so.  Service and Identity Providers cannot expect customers to labour if all they can reward them with is a ridiculous mouse.

Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan