Sunday, 2 August 2015

Unblocking Digital Identity

When it comes thinking about citizen identity schemes, centralisation is so Y2K.  A decentralised or federated model would remove the bureaucracy, put the customer at the heart, delegate control to the user and balance security and usability.  Though look out federation, there is a new kid in town.  Distributed is where identity is at - or is it?

Blockchain, the distributed ledger solution behind Bitcoin, is becoming the hot topic of the digital identity world.  It ticks many of the important boxes - privacy by design, cryptographically secure, robust architecture, irrefutable provenance, consent and control with the user.  So Identity on the Blockchain could be the next big thing for citizen eID.

Though before giving up on federation we should put Bitcoin in context.  Relative to the British Pound (born 775), Bitcoin is a mere pup (born 2008/9) - though to compare it with another digital disrupter, by the time Facebook was 6 years old it had over 600m users - Bitcoin has less than 4m.  Having an unregulated, community owned technology is arguably more of a negative than a positive - particularly when it comes to things of value.  It is estimated that around a third of the Bitcoins created are now classed as zombie coins - the cryptographic keys required to transact them lost at the bottom of a rubbish tip.  And with no central authority there is no redress, no one to hold accountable other than the end user themselves.

Though the lack of a central authority has created a marketplace for a federation of exchanges and wallets; performing as an intermediary between the end user and the overall community.  Though in an unregulated marketplace how can you trust these intermediaries?  With loss of their customer's crypto keys and pending criminal prosecutions it would seem the answer to that question is that you can't.

While the Blockchain may be a future technology upon which citizen identity could be based it is also worth considering that the concept of the distributed ledger for identity has been used successfully for quite some time.  In the UK the General Register Office has been operating the exact model since the late 18th century - with births, deaths and marriages being recorded in local registers, that issue certificates to the end user, that they control as the central authority.



Bitcoin and Blockchain are technology led solutions that have gained a niche use in financial payments.  The same technology will have a role to play in pure play identity and access management solutions and it may solve use cases within the citizen eID space - though doing this from a customer led perspective to find the technology solution will have a greater chance of success.

The core challenge for a successful citizen identity scheme is to hit the sweet spot between allowing the real person to claim and assert their identity and preventing anyone else from doing the same.  Balancing how easy you can make the former and how difficult you can make the latter comes above whether your solution is centralised, federated or distributed. 

So maybe centralisation isn't quite so Y2K after all.  Maybe federation will solve the issues.  Maybe the future is Blockchain or another distributed ledger model.  Though if you were looking for the best solution - maybe, just maybe, a model based on the best of all of them could be the real future? 


Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing - Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan

Tuesday, 5 May 2015

Unexpected Customer Behaviour In The Bagging Area

This week saw the UK's forth largest supermarket, Morrisons, announce the return of staffed express checkouts.  As the first major retailer to make the u-turn, what now is the future strategy for self-service?  Are Morrisons responding to a change in customer shopping behaviour or did they, along with the rest of the retail market, get their strategy wrong in the first place?

The figures show that only one in three supermarket customers had used self-service; what makes this figure even bleaker is that queues at staffed checkouts have actually lengthened where self-service has been introduced.  For supermarkets, self-service checkouts have played a contributory factor in the loss of customers to smaller rivals who are seen to offer a better experience with personalised service at a lower cost. 





Lowering staff headcount to reduce operating costs is the headline benefit for most organisations who have introduced self-service checkouts.  Unfortunately when cost reduction is at the heart of your customer service strategy the outcome is fairly predictable.  Customer behaviour shouldn't have been unexpected - the impact on satisfaction levels when you introduce cost saving measures are, with the odd exception, going to be negative. 

It is unlikely though, that self-service will be removed from the customer service strategy of any retailer. And nor should it be. As someone who has implemented self-service into the retail sector, I believe that it has an even greater role to play in retail strategy in the future. Yet those organisations who implement it correctly will be the ones whose focus in on improving the customer experience through the use of technology. A by-product of this will be the cost saving through headcount reduction. 

One of the best examples of self-service is travel ticketing used on the London public transport network.  In order to migrate customers to self-service they introduced the Oyster travel card.  Within ten years of its introduction in 2003, Oyster was used in over 80% of all journeys.  So successful that self-service ticketing will allow London Underground to close all of its ticket offices by the end of 2015 - down from over 250 when Oyster was first introduced.  These are figures that supermarkets can only dream of.

The reason why self-service for London public transport has been so successful is that they used the introduction of Oyster to make self-service ticketing more convenient for their customers.  The strategy for implementation was built upon a simplified pricing policy, highly reliable infrastructure and incremental migration of more complex products as customer advocacy grew. 

For retailers, this lesson of simplifying the underlying customer experience, making self-service the convenient choice, ensuring the platform is reliable and only growing as reliability is proven and adoption grows, is one they can still use.  Simple measures that can overcome the failings of current technology or operating constraints need to be considered.  The complexity of the transaction needs to be reduced - if you need to train your staff to do a task don't expect your customers to be able to do the same task without training.  

For customers, the use of self-service check outs needs to be a preference – a choice that they make rather than something that is enforced on them by the retailer.  This preference may be subject to the context – a basket of shopping can drive significantly different behaviour than an over-flowing trolley of goods.  Putting the customer at the heart of the retailers self-service strategy will enable context to be considered, behaviours to be modelled and solutions to be designed to meet customer needs.  In an increasingly digitally enabled world, self-service will also be omni-channel; a richer experience in store and online that delivers convenience and benefit to customers that encourages the adoption of self-service and a migration away from staffed checkouts.

So whilst Morrisons may have seemingly made a u-turn, in reality they should just be revisiting their customer service strategy to make sure that when it comes to self-service, customer behaviour is not an unexpected item. 




Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing - Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan

Tuesday, 7 April 2015

Tick to Agree

Do our customers really trust that we do the right things for the right reasons when it comes to their data?  The digital economy is founded upon data that belongs to our customers. We may source it, store it, aggregate  it, make sense of it, commercialise it... yet if we share it just how informed should the consent be from the people who own it?

We've witnessed tiny tremors that have been described in the media as a backlash; though in the scheme of things the customer reaction was nothing more than tomorrow's chip paper.  Sony may have lost a heap of credit card numbers but its customers were soon distracted by a free game to download; Google may be evil but their customers don't have time to search for a new search engine; Facebook may have the right to replace you with a substitute human should your own life become too dull but their customers want to know when their friends are drunk. (There may be some artistic licence at work here I admit :)

The fact is that to date nothing has occurred that has truly caused a customer backlash in the way in which we organisations trade their data. Even the most outraged, moralistic, educated and knowledgeable customer still ticks the terms and conditions box without instructing a lawyer. They still swipe their loyalty card at the checkout to buy the newspaper with the headlines about the latest data privacy breach. And they still send emails and check the adverts specially tailored for them that magically appear. 





We wouldn't give our customer's money away quite so nonchalantly; so is doing the right thing with their data treating it in the same manner?  Rather than getting our customers wrapped up in 56 pages of terms and conditions written by the legal department on how we intend to use their data it would seem much fairer that our marketing department wrote our key terms. The same points on how we source it, store it, aggregate it, make sense of it, commercialise it - written in easy to understand bullets. 

If we start being transparent with our customers about our role in the use of their data we may have to rethink our data strategy. How we commercialise their data; what, how and when we share may have to be done in more innovative and customer centric ways. 

The alternative is that we continue to ride on the wave of customer apathy.  We can continue to tell customers that we might do bad things, on purpose or by accident, with their data but never mind because you agreed we could. 

Over the next 5-10 years the tide is turning and the wave of apathy will come crashing down. Simply with the amount of data we will hold and the value it contains, the organisation who doesn't treat their customer's data like their customer's money will be the one to drown. 

Now is the time to start building our customer's trust by doing the right things for the right reasons when it comes to their data.

Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me
Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA

Connect with Bryn on Linked In: Bryn Robinson-Morgan

Friday, 20 February 2015

The Kids Are All Right

Age 19, when you're throwing up on your own shoes, privacy, security and liability don't matter; what the "going grey" generation call convenience, does. If you can get a taxi cab to deliver you safely to your door, you will happily give full access to your identity (the location of your comfy bed with a tactically placed bin at the side of it) and financial information (promise not to take the long way round). 

This week, in the UK, the first integration of Apple's Touch ID came to banking applications. Cue uproar on how the technology has already been spoofed. Any security person worth their salt knows fingerprint biometrics aren't secure. Yes they may be more convenient than pass codes, but a high resolution camera or a shiny surface combined with a silica moulding kit and you have a security breach quite literally on your hands (well fingers).
 
The trouble is, that by the time you're old enough (in the "going grey" generation) to know the pitfalls, and you're suitably well established in your industry to be able to inform standards and best practice, you're no longer representative of the "yoof" generation who you're delivering products for. Nothing kills a great idea for the younger generation than their grandparents thinking it's cool. When your Gran sends you a snap of her running over someone in her mobility scooter, it's time to delete your account and move on to the next craze. 



So are the people setting the standards and defining best practice really focussed on the right things? Are they really best placed to do so? For a banking application, is Touch ID too much security rather than not enough?  Organisations want to know that the person making the transaction is authorised to do so, to enable them to prevent fraud, meet regulatory requirements, protect their customers and generally do the right thing. Yet from the customers perspective all they're concerned about is that if money goes from their account that they didn't authorise that they'll get it paid back.
 
Ultimately the role of the "going grey" generation is to warn, counsel and support the next generation. Informed choice rather than condescending control, and guided resolution rather than an "I told you so" attitude. Understanding the needs, views and opinions of "the kids" will drive better solutions focussed on outcomes of practical use. The younger generation don't value convenience; they expect it as a minimum!  Whilst sometimes this may result in loss or distress for either party, consequences are thought about after the event and there is a customer perception (rightly or wrongly) that someone else will help clean up any fall out.

A new view on authentication is that it is something that occurs as part of the transaction rather than something the user knowingly does.  Mitigating risk at other points before, during and after the transaction, will enable less reliance on strong authentication methods.  Does the transaction fit within the normal patterns of behaviour?  Is it being performed from a trusted device?  Is the location identifiable and known?  Is the value within acceptable risk tolerances?  Can the transaction be reversed?  And for what time period is it recoverable?  

Within all this, the concept of informed choice by the end customer also needs to be considered. Rather than industry experts having an outcry of nay saying about technologies such as Touch ID being used for banking, rather they should be focussed on the needs of the customer and giving them more credit for being able to make informed choices. If any fraudulent transaction could be recovered then zero authentication transactions would be less risky. 

Figuring out how, when at 3am your customer's account has been debited £50 that they can't recall authorising, you can resolve the dispute is a far more noble cause than worrying about the authentication method used to verify the transaction - particularly if your customer arrived home safely and able to sleep in their own bed, with their head rested on their bin. 

After all, the kids are all right. 



Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan

Thursday, 15 January 2015

The ridiculous mouse

“A mountain has gone into labour and was groaning terribly.  Such rumours excited great expectations all over the country.  In the end however, the mountain gave birth to a mouse.”
Phaedrus 4.24

At some point in our lives we’ve all been lectured that we only get out of life what we’re prepared to put in; and while on the whole there is a strong element of truth in this mantra, there are always tasks and activities where no matter what amount of effort we put in, the reward will never live up to expectation.  My own boyhood dreams of being a professional footballer (soccer player) weren’t dashed by my lack of effort - I was never going to make the grade due to having two legs made for standing and none for that were made for kicking.

The inspiration for this post comes from observing a customer insight session for an online identity assurance transaction.  The young man in the spotlight told the session facilitator how a lack of acceptable identity evidence impacted his life – how he was unable to open a bank account as he didn’t have the required documents to prove his identity to the banks standards; how he couldn’t get a mobile (cell) phone contract for the same reasons.  This was a guy who had genuinely tried, yet for all his effort there was no reward – and so eventually he’d stopped trying.   Instead he found other ways around the problem – his wages were paid into someone else’s bank account.  His partner had taken out an additional mobile phone contract.  This was a bright, savvy and confident individual who had been disenfranchised by a society who wouldn’t allow him access to basic services due to their inability to identify him.

Having partaken in a great deal of user experience sessions, this guy’s story was far from unique to me – financial and societal exclusion due to the inability to meet identity requirements is not uncommon.  What stood out for me about this young man though was the way in which he embraced digital identity – not only did he show an amazing comprehension of the technology and verification methods, he also saw the benefits to him of going through the registration process.   He understood with aplomb how the investment in time now would enable him to assert his identity in a simple yet secure way in future.

The joy of seeing a user react with such delight was tempered by the harsh reality that he was unlikely, at least in the near future, to be able to achieve the requirements to reach the required level of assurance.  For all the effort he would go through he would get no reward – his digital identity would afford him no more inclusion.

The rigid pass / fail nature of the four levels of assurance defined by the OMB and NIST which have been adopted as the de facto global standard are still mired in the constraints of face to face verification.  A digital identity is capable of providing a far more granular level of assurance backed by a rich data packet to enable the service provider to take a risk based approach.  In a mature marketplace the identity score should more likely take the form of the credit score – where identity providers constantly monitor and evaluate to provide real time granular scoring.  A scoring mechanism would exist where the individual’s pattern of behaviour and existence activity varies the confidence of the assurance given at any moment in time.

In the meantime, whilst the sector matures and evolves, the short term step must be to relax the four level model.  There is a need to introduce proportionate, defined, mid-levels of assurance.  Whilst service provider’s compliance department may still clamour for least risk approach, a more customer centric view is needed.  The registration should take the user through a journey proportionate to the transaction they are undertaking, in response to the data available to verify them.  Without being more pragmatic and proportionate, the same people who are currently excluded will continue to be so.  Service and Identity Providers cannot expect customers to labour if all they can reward them with is a ridiculous mouse.

Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan

Wednesday, 31 December 2014

Big Brother's Protection

We all know that only bad people need to fear the “Big Brother” state described so vividly in George Orwell's ‘1984’; if we don’t do anything wrong then what's wrong with the Government knowing about it?  And while we offer resigned acceptance that the Government knows everything about us and how we live our lives, even as good people who live our lives as saints, we wouldn't choose to have Big Brother watching over us.

The truth is though, that even 30 years after Orwell's vision of the world, Governments don't know everything about us; bad people do bad things every day without being caught – even those who the Government know are bad aren't always monitored sufficiently to prevent them from committing the most horrendous of acts.  So if the bad people can hide under the radar then why should the good people stand up and wave?  Privacy to conduct your legitimate, legal, saintly business is a basic human right.

We go around believing that Big Brother is watching us, are outraged when bad people do bad things without being seen and demand privacy because we're good.  So how do we create an Identity Infrastructure that supports this dichotomy?

Taking our identity as our name, address and date of birth, – a combination of details that makes us unique in the world – when we want to watch a movie the only thing that the cinema attendant needs to know about our identity is whether we are above the age restriction; a binary yes or no answer based on our date of birth.  So for a binary decision the Identity Infrastructure shouldn't need to share all our details.  Though there is also need to establish Entitlement; and while Identity and Privacy can co-exist quite easily, by adding Entitlement we muddy the waters.

At the cinema, our entitlement to watch the movie is met by having a valid ticket and receiving the binary yes from our identity regarding our age.  The ticket provides the unique attribute that allows the cinema to grant us access to their service so we don’t need to provide the unique attributes of our identity.  The cinema attendant doesn't care if we’re John Doe or Fred Bloggs or if we live at an address in the same town or not.

Governments don't sell tickets, so they need another unique attribute to establish entitlement.  To be able to access local services they can ask the same binary style questions of your identity – is your address within this area?  This is fine for a service you’re entitled to access as many times as you like, though for singular services – voting, social payments, etc. – they need to also establish uniqueness.  The common way of doing this is for them to hold your name, address and date of birth in their systems and run a matching service against the Identity Infrastructure.  Entitlement has just ripped a hole straight through your Privacy principles.

In India, their Identity Infrastructure is underpinned by the world's largest biometric database, with the aim that the entire 1 billion population will be issued with a random unique number; the ultimate Big Brother solution, or perhaps more appropriately “The Prisoner” solution.  By having such a solution though they can balance Identity, Entitlement and Privacy.  Being allocated a number could enable our ambition of being a free man.

If at the top of the Identity Infrastructure sits a single “Big Brother” database with a unique record for all citizens, supported by a layer of commercial sector Identity Providers providing a facility in which citizens establish and record their Legal Identity and associated attributes, this would enable any number of pseudonymous asserted identities that we’re free to transact our lives in effective privacy.



In this environment we can operate with relative anonymity any number of different transactions backed by a Trust Chain that only needs to be concerned with bad people; leaving the good people to go about their lives as they wish.

In 2084, Big Brother is the trusted single version of identity yet knows nothing of our Legal Identity, the movies we've been to see, the way we vote, the money we receive from the state, where we work or the blogs we post on the internet.  We may establish our Legal Identity with any number of approved Identity Providers and we may publish as many pseudonyms as we like; while ever we remain good people doing legitimate and legal things we can chose what attributes we share with service providers; service providers can happily ask binary questions about us and trust the assertion that they receive.

And when good people turn bad?  Their assigned unique randomly allocated number - the thread that underpins their identity, establishes their entitlement and protects their privacy – enables Big Brother to lay bare their every movement, every interaction that they've made – within a legal framework of course.

The Orwellian vision of Big Brother becomes like a real life big brother – one who will protect us, help us and look after us – but who is prone to snitch on us when we do something bad.


Read my other posts
Just in Case - From early adoption to maturity
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn has near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA


Connect with Bryn on Linked In: Bryn Robinson-Morgan