Biometrics are great as long as we understand.

Biometrics are probabilistic, therefore not 100% accurate every time

They should not be shared in central databases. If they are there must be safeguards and strict privacy policies associated with their use

The better approach is to use the biometric to unlock your device or prove you are present.

Your device should then be cryptographically authenticated by the relying party.

The relying party should maintain a list of devices (Authenticators) you register.

The device proves uniqueness.

The Biometric proves presence on that unique device at that moment in time.

Frictionless authentication of the device.

Active verification when the risk demands assurance of the individual who is authorizing or instructing.

Biometrics – Do we end up in a surveillance state

http://www.planetbiometrics.com/article-details/i/10211/desc/guest-post-experience-a-seamless-lifestyle–idemia/

https://www.aclu.org/other/whats-wrong-public-video-surveillance

https://www.govtech.com/policy-management/Study-Surveillance-Cams-Worth-Money.html

As we think about the world we are living in and the world we want to live in. We must balance friction and convenience against the potential risks which will emerge as technology blossoms and expands to touch ever part of our lives. This morning I got a text informing me of the 200 million cameras the Chinese had watching their citizens. I immediately remember the CATV system in London and

CCTV Camera technology on screen display

what parts of the City it covers. Its goal record everyone’s movements to protect against terrorists. Airlines are talking about ticketless travel and some are speaking of passport-less and ticketless airports. We wonder if Alexa is recording our every word and we know our PC, Tablet, Baby monitor & mobile phone cameras and microphones can be used by: who knows who, to watch who knows what, whenever they so please?

Is this the world we want to live in? Or would we prefer our cities to enact laws like those recently enacted in San Francisco. This law is meant to ban the use of these various cameras and listening devices from being used to identify everyone they see or hear.

This conversation then immediately bleeds into the question of our right to privacy. With all that the internet offers for free and what all these devices are capable of sharing; we’ve given our privacy away.

How often do you wonder why the ads you see seem to attempt to sell you exactly what you recent read about? How often do you wonder why you no longer can easily find the site you are looking for? Instead you have to filter through the search list to get past all the ads. How many of us even understand the information people can glean from what we do and were we are; when we use or carry our devices around?

On one side of the discussion is reality. As has been the case for as long as I can remember.  TV, radio, newspaper, magazine, browser, social media, much web content and mobile app are funded by advertising dollars. Spent by those who want to convince some of us to buy what is on offer. It is these advertising dollars which pays for the content and ultimately decides what will survive the test of time. On the other side are the politicians, regulators, lobbyist and corporations who are focused on one thing. Helping people prosper or worse protecting some so they can continue to prosper.

The acquisition of wealth, the construction of infrastructure, the destruction of our enemies or the support for those without; is all about money.

If we seek to protect our privacy and be assured, we will not live in a surveillance state. We must be willing to read the fine print and be ready to pay for what is now free.  We must be ready and willing to take the extra time to pull out our passport, enter our user name, present our boarding pass. We must insist on the necessary friction to protect our identity and our freedoms.

If convenience is what we insist on.  Be assured, companies will happily build solutions to remove friction. Beware, removing friction, when it comes to  your identity or privacy, means you will allow people and organizations to collect and store everything they can about you/  Their goal to identity you and without friction, with the purpose of serving you or better said profiting from your actions.

All of this is more than the Uber experience.  Uber recognizes your phone and account not you.

This will be a world where the system behind the camera will see you, compare your face to all the faces on file and determines it is you. Therefore, knowing who you are, it can do what it is told to do; because it is you.

Biometrics carry risks.

Hacking Our Identity: The Emerging Threats from Biometric Technology

As I skimmed through this article I was reminded of the reality of biometrics.  It is a statistical algorithm designed to compare what was registered to that was just sensed.  It is an imprecise process.  The author reminds us of the importance of our identity in each and every interaction we engage in.  She further ponders the question, of the potential threats to the biometric solutions that countries, people and enterprises are embracing, as we work to address the questions of Authentication and Identification in our complex digital and physical world.

The article asks the questions:

      • Do the countries and enterprises understand the technology and processes used to support biometrics as a means of authentication.
      • Do they appreciate the need to secure and protect this most sensitive of data?
      • Is the data they store able to be used to compromise the individual of the integrity of that which it seeks to protect?
      • Are we at risk of creating a surveillance society?

Finally there is the question of the accuracy of biometric matching.  It is interesting to observe the comparison of the accuracy of biometric matching to PIN or password matching.  We all recognize the challenges of PIN and password.  It is not the concept it is the question of how many complex PIN or passwords is the human mind capable of retaining without writing them down or storing them someplace that can be compromised.

As I have argued in other blogs, the answer must be in the possess of something unique which has a False Reject Rate FRR and a False Accept FAR Rate, both approaching zero.  Clearly the PIN or password has such a characteristic the challenge is in remembering so many.  An object or a thing “Something You Have”, be it a card, phone, watch or bracelet with a Restricted Operating Environment inside e.g. secure element, TEE or TPM, secured using strong cryptography, paired with a biometric makes the most sense.

From Password and PIN to Biometrics

The Evolution of Authentication

When first we sought to create secure and convenient means of identification, we relied on user names paired with passwords and PINs.  These values are typically stored centrally within the relying party’s database.  Often times, these values are encrypted at point of entry, and once received by the relying party passed through a one-way function, before being stored in the database.  This use of cryptography to encrypt the PIN or Password in transit and perform the one-way function before storing the result is simply to prevented the PIN or Password from being captured in transit or reverse engineered.

Each time the user logs in, they enter their password or PIN, it is received by the relying party, run through the same one-way function and compared to the value stored at user registration

Over the last 30 or so year there has been mounting concern as to the long-term viability of depending on the user being able to remember, create a unique & complex value and accept responsibility to frequently change their passwords and PINs.  Especially given the myriad of sites and digital relationships we each continue to establish.

To assure the integrity of passwords and PINs, the challenge is making sure the length and randomness creates difficultly and minimizes the chance someone can guess what the Pin or password is.  By adding special characters and insisting on password and PIN policies, the rely party has attempted to reduce risk and the chance for rouge penetration.

Unfortunately, people forget their password, phish & vishing attacks work, key-loggers and other clever ways of obtaining the user name and password have increased.  The threat of rouge intrusions and the resulting reputational and financial lose is out of control.

As these loses escalated, the cost of the various techniques to support more secure authentication have been developed.  The market always understood if we could merge a unique object something you Have, with a secret you Know or a biometric something you Are; you would be able to establish a superb form of multi-factor authentication.  Many, such as the ICAO, EMV and PIV specifications, embraced the idea of cryptography operating within a secure element or smart card. They further embraced the idea of loading the registered biometric rending into the chip and incorporate the matching algorithm within the software.  By then using an external PIN pad or biometric sensor, multi-factor authentication could be enabled.  Unfortunately, at considerable cost.

In Europe, in order to secure access to websites they looked to physical objects capable of displaying a onetime password as the answer.  In some cases, the user had to first enter a PIN then a number displayed on the screen and then type the value displayed on the device into a field in browser window. Something you have with a secret, a one-time password, unique to each event.

Clearly PINs and passwords carry with them two flaws.  They need to be remembered and they need to be typed in.  Biometrics on the other hand offer convenience and do not require the user to remember a complex set of characters.  Fortunately, the size, cost and complexity of biometric sensors has decreased significantly and it is viability to integrate sensors into a user operated device.  The first company to offer a phone with a biometric fingerprint sensor was Motorola, quickly followed by Apple on their iPhone 5S.  Today it is rare to find a mobile phone which does not included a biometric sensor and related algorithms.

Now with an identifier (user name), a device with a unique digital signature and the ability to support biometrics, all the virtues of multi-factor authentication and the wonders of biometrics such as: fingerprints, veins, retina, iris, EKG, behavior or selfies are available to assure the registered user is present.

All because the sensor can capture the biometric and software will render the output of the sensor into images, patterns or templates.  The sensor and the related software have unique characteristics as to how the matching processes work.  It then simply requires us to accept that the output of the sensor becomes the input into the matching algorithm.

The last concern – how do we measure the reliability of the biometric sensors and algorithms.  To help people understand the reliability of these sensors and matching algorithms, there are an assortment of acronyms such as: FRR, FAR and PAD.  These three are the ones I am most familiar with.  They measure and quantify the risk of false acceptance or false rejection and provide a measure of the assurance of life.

We now can leverage the biometric sensors in user devices

Paired with the assurance the device is unique

And be confident the registered user is present.