Sunday 30 March 2014

The Scottish on-line security experiment


On-line, you can have convenience. Or you can have security.
One or the other.
But not both.

Stolen Twitter passwords 'worth more than credit card details'.

That's what it said in the Telegraph a few days ago, 28 March 2014. Credit card details are only worth between $2 and $40 these days on the black market, whereas your Twitter password can be worth between $16 and $325. That's what Michael Callahan of Juniper Networks says. And he's a security expert.

You're probably getting bored with these stories. They appear every day in the media. And every month on the DMossEsq blog, see for example Cybersecurity, and GDS's fantasy strategy. And "When it comes to cyber security QinetiQ couldn’t grab their ass with both hands". And Hyperinflation hits the unicorn market. And ...

It's boring. But it's still important.

The Telegraph article ends with this advice:
Callahan said it was vital for people to use different passwords for each site, so that if one account is compromised it will not allow the hackers access to their whole digital lives
He's not a security expert but even DMossEsq says that. Repeatedly. See for example Identity assurance – convenient? It'll make your life so much easier. And GDS – the user experience of misfeasance in public office. And Digital-by-default, an open letter to the House of Commons Science and Technology Committee (para.14). And ...

But the Government Digital Service (GDS) disagree. They're the people in charge of the identity assurance programme. And when the UK's first so-called "identity providers" were appointed, this is what we read, the opposite of Callahan:
Providers announced for online identity scheme

The Post Office, Cassidian, Digidentity, Experian, Ingeus, Mydex, and Verizon are the successful providers chosen to design and deliver a secure online identity registration service for the Department for Work and Pensions.

... providers will be required to offer a simplified registration process, minimise the number of usernames and passwords a customer will need to remember ...
It's hard work/inconvenient having multiple logon details.

GDS want to make life more convenient for us all. Keep all your logon details in a personal data store (PDS), they say, and the PDS can log on for you to your Amazon account or your electricity account or your bank account and so on and so on, world without end. All you have to remember is the logon details for your PDS. Much more convenient.

And much less secure.

As Mr Callahan says.

And DMossEsq.

On-line, you can have convenience. Or you can have security. One or the other. But not both.

GDS just can't take security seriously. See for example RIP IDA – JFDI security. Security is over-rated, according to GDS, and should always be trumped by usability/convenience.

Who's right?

How can we decide?

We need to conduct an experiment.

As luck would have it, there's an experiment coming up. A big one. In Scotland. Please see Connecting the nation – Scotland's empowered future: "Scotland’s proud heritage of innovation beckons, and Mydex CIC is proud to be part of enabling that future".

(Can a proud heritage beckon?

Never mind.)

Scotland has a Digital Participation Charter and Mydex are going to help her on the road to Estonia. They have a trust framework. They aim to make every on-line transaction dependent on Mydex.  And they will "empower" everyone with a PDS. Armed with one of these dematerialised ID cards, no Scot will ever again have to remember more than one password. That may be convenient. But will it be secure?

The Scots will soon find out.

And so thereby will we.

The Scottish on-line security experiment


On-line, you can have convenience. Or you can have security.
One or the other.
But not both.

Stolen Twitter passwords 'worth more than credit card details'.

That's what it said in the Telegraph a few days ago, 28 March 2014. Credit card details are only worth between $2 and $40 these days on the black market, whereas your Twitter password can be worth between $16 and $325. That's what Michael Callahan of Juniper Networks says. And he's a security expert.

You're probably getting bored with these stories. They appear every day in the media. And every month on the DMossEsq blog, see for example Cybersecurity, and GDS's fantasy strategy. And "When it comes to cyber security QinetiQ couldn’t grab their ass with both hands". And Hyperinflation hits the unicorn market. And ...

It's boring. But it's still important.

Friday 28 March 2014

Time for someone to take the personal information economy seriously

1938 Sears Spring/Summer Catalog
"The roots of mail order date back to the middle ages. In 1498, Aldus Manutius of Venice, a publisher, brought out a catalog of 15 texts which he had published, which were precursors of the paperback books of today" – so says Bonnie Unsworth in her A Brief History of Mail Order Catalogs.

Rather more recently, "the real beginning of mail order was the result of the experiences of a traveling salesman in the mid west, named Montgomery Ward. He published a catalog sheet that listed 163 items right after the Civil War. Within two years, the catalog grew to 8 pages, and then to 72 pages. By 1884, the catalog contained 240 pages with thousands of items, almost everyone of which was illustrated with a woodcut".

While they had Montgomery Ward and Sears Roebuck in the US, here in the UK we had Great Universal Stores, always known affectionately as "GUS".

Mail order was big business and the philanthropic Sir Isaac Wolfson amassed a fortune at GUS. The Wolfson Foundation has awarded charitable grants worth over £1 billion since 1955.

Not just big business, mail order was a credit business. There was no point Mr Ward repeatedly sending the products they had ordered to people who didn't subsequently pay for them. Ditto Sir Isaac. They needed to know before despatch that a given customer wasn't too likely not to pay.

The Manchester Guardian Society was established as a credit rating agency in 1826 in the UK. 1897 saw the formation of the Merchants' Credit Association in the US. The Ramo-Wooldridge Corporation and Thompson Products merged to form TRW in the 1960s. TRW's leading light, Simon Ramo, predicted the cashless society as early as 1961 – enter the credit card. GUS created Commercial Credit Nottingham in 1980, injected TRW into it in 1996 and the whole lot became Experian.

Once you've collected a lot of data about a lot of people – including the UK electoral roll data which Experian picked up en passant – you can do a lot more with it than just calculate a credit rating. That's an important job, oiling the wheels of commerce, but you can also for example sell your data to political parties, seeking to identify floating voters and persuade them to come down on their side of the party fence.

You can help new and established businesses target their marketing. You can do demographic analysis. You can, famously, offer to help the Department for Work and Pensions to find benefit cheats.

And perhaps you can provide the basis for identity assurance, should some government want to make public services, say, digital by default.

That raises questions about the privacy of personal data and the security with which it is maintained. We seem to have quite good laws in the UK protecting that privacy and adequately ensuring the related security – laws which Experian and its UK competitors have a good record of obeying.

They have fewer data broking laws in the US. It is the desire to make good that omission that lies behind the work of Senator Rockefeller's Commerce, Science, & Transportation Committee which we alluded to the other day.

The UK's privacy laws are permanently under threat from attackers like Google, Facebook, Francis Maude (passim), the Health and Social Care Information Centre (care.data), Professor Sir Nigel Shadbolt (ODI, midata), Stephan Shakespeare (PSI) and the Government Digital Service (identity assurance). Not to mention the NSA, GCHQ and every other halfway competent intelligence service in the world. Among others.

Perhaps the walls of civilisation will withstand the siege. Perhaps they won't. Who knows.

One thing we do know is that there's nothing new about mail order or its descendants such as Amazon. Their history can arguably be traced back to fifteenth century Venice.

And there's nothing new about the market in personal data. It already has laws associated with it, suppliers like Experian, trade associations like the DMA, and marketing "gurus" wielding techniques that have grown up over several decades, if not centuries.

You know that.

Everyone knows that.

Except, it seems, the new world born yesterday delegates at last week's seminar on the personal information economy, PIE2014. See, for example, Business scents ‘boom’ in personal information economy:
Business leaders are starting to respond to an emerging market in personal information affecting all individuals and organisations across public and private sectors.

In an interview recorded at last week’s Personal Information Economy 2014 event in London, Alan Mitchell, strategy director of Ctrl-Shift, told the Information Daily that "overall, business is not very well informed, and people are only just beginning to think about it, but it is growing rapidly."
"Starting to respond"? Google and Facebook already have annual turnovers measured in the tens of billions of dollars.

"Not very well informed"? What do these people think Google and Facebook are and always have been if not very well informed data brokers?
There are still many unknowns about the personal data market and how it will operate, including business models, issues of trust, and what new technologies are starting to enable around security, privacy, data extraction and analysis.
Unknown to whom? Everyone else seems to know that the market is already operating. There are over a million apps already available on Google Play, for example.
In a separate interview at the same event, Professor Sir Nigel Shadbolt, Chairman of the government’s Midata initiative set up to increase consumers’ access to their own data, said that the personal information economy was a "booming, burgeoning area", that was already subject to "a bit of a landgrab".
Google has detailed records of the preferences of everyone who uses the web. Facebook has more regular monthly users than the population of most countries. Amazon operates the biggest cloud services business in the world. The banks – necessarily – record our every financial transaction. The mobile phone network operators – necessarily – continuously record our location, accurate to the nearest few metres, wherever we are in the world. Not just our location, but who we call and who calls us. "The entire NHS hospital patient database for England was handed over to management consultants who uploaded it to Google servers based outside the UK". HSCIC want to do the same with our GP health records. "A bit of a landgrab"?

Ctrl-Shift, the organisers of PIE2014, have "Storified" the seminar, please see Seizing the opportunity: the next 18 months. In what way are they going to seize this decades-old opportunity over the next 18 months?


No doubt Sir Martin Sorrell's people will be happy to come up with another name for Mr Auwera.

Professor Sir Nigel himself is supposed to have said "Everybody is going to be a sensor" at PIE2014, and "Any friction is an impediment; additional steps destroy uptake". Once you're in this childish milieu it's probably hard to resist joining in, the frivolity is catching ...

.. but he's not naïve or commercially unaware and he must somehow make people realise that the personal information economy is not some new hippy commune in which people can witter on about "uncanny valleys" and "trust serums". It's a mature and rich market with political power, a market in which people are bartering their personal data for "free" web-based services.

The pretence is that these services "empower" us in some hippy sense of the word. Once all our data has been sucked up into the cloud, once we are all utterly dependent on these services, let's see just how long they continue to be offered free at the point of delivery and how long it takes for the new empowerment to turn into a more traditional subjection.

We have already got to the point where the Pied Pipers can ring up the President of the United States of America to tell him to get out of the way, please see Mark Zuckerberg tells Barack Obama he is 'frustrated' over US government surveillance. And the President accepts the call.

Professor Sir Nigel's colleague at Southampton University and at the Open Data Institute, Professor Sir Tim Berners-Lee, seems to be a certified member of the commune:
Armed with the information that social networks and other web giants hold about us, he said, computers will be able to "help me run my life, to guess what I need next, to guess what I should read in the morning, because it will know not only what's happening out there but also what I've read already, and also what my mood is, and who I'm meeting later on
There doesn't seem to be anyone else. Unless he really does want people to become no more than sensors, feeding data back to the Google brain, it's up to Professor Sir Nigel to forswear meretricious phrase-turning and to devise a serious response.

----------

Updated 29.4.18

There we were four years ago saying that a credit referencing agency can analyse and sell its "data to political parties, seeking to identify floating voters and persuade them to come down on their side of the party fence".

No-one turned a hair.

It was entirely uncontroversial ...

... until it was suggested that Donald Trump won the US presidential election thanks to Cambridge Analytica and that Leave won the Brexit referendum thanks to ditto.

Why the change?

It doesn't matter.

What matters is that now at last people are paying serious attention to their personal information. Cambridge Analytica and Facebook are in the dock for collecting our personal information and making money out of it. So are Google. Others will join them.

Can we add Experian to the list?


And Equifax? They lost the personal information of 145 million people.

And Callcredit:


All three companies – Experian, Equifax and Callcredit – either supply information to the Government Digital Service's GOV.UK Verify (RIP) "identity providers" or they actually are "identity providers".

Would you say "I don't mind Cambridge Analytica having my personal information"? You may well be perfectly happy with that ...

... but if not, why is it more acceptable for Experian to have your personal information, or Equifax or Callcredit?


Updated 13.8.18

Time was when we all knew that the key to winning general elections was social media. Both of the main UK political parties tried. Their supporters wished them well. "May the best man win", as we used to say. No more – Emma's Diary fined £140k for flogging data on over a million new mums to Labour Party:
Data-brokering biz Lifecycle Marketing (Mother & Baby) has been fined £140,000 by the Information Commissioner's Office (ICO) for illegally collating and flogging personal information of more than a million people.

The Buckinghamshire-based business, also known as Emma's Diary, issues advice on pregnancy and childcare. It sold the information to Experian Marketing Services, specifically for use by the Labour Party.
A loss of innocence?

No.

A return to adulthood.

Time for someone to take the personal information economy seriously

1938 Sears Spring/Summer Catalog
"The roots of mail order date back to the middle ages. In 1498, Aldus Manutius of Venice, a publisher, brought out a catalog of 15 texts which he had published, which were precursors of the paperback books of today" – so says Bonnie Unsworth in her A Brief History of Mail Order Catalogs.

Rather more recently, "the real beginning of mail order was the result of the experiences of a traveling salesman in the mid west, named Montgomery Ward. He published a catalog sheet that listed 163 items right after the Civil War. Within two years, the catalog grew to 8 pages, and then to 72 pages. By 1884, the catalog contained 240 pages with thousands of items, almost everyone of which was illustrated with a woodcut".

While they had Montgomery Ward and Sears Roebuck in the US, here in the UK we had Great Universal Stores, always known affectionately as "GUS".

Mail order was big business and the philanthropic Sir Isaac Wolfson amassed a fortune at GUS. The Wolfson Foundation has awarded charitable grants worth over £1 billion since 1955.

Not just big business, mail order was a credit business. There was no point Mr Ward repeatedly sending the products they had ordered to people who didn't subsequently pay for them. Ditto Sir Isaac. They needed to know before despatch that a given customer wasn't too likely not to pay.

The Manchester Guardian Society was established as a credit rating agency in 1826 in the UK. 1897 saw the formation of the Merchants' Credit Association in the US. The Ramo-Wooldridge Corporation and Thompson Products merged to form TRW in the 1960s. TRW's leading light, Simon Ramo, predicted the cashless society as early as 1961 – enter the credit card. GUS created Commercial Credit Nottingham in 1980, injected TRW into it in 1996 and the whole lot became Experian.

Wednesday 26 March 2014

The magic of modern public administration

Here's a new TLA for you (three-letter acronym) – "VRA".

"VRA" is voice risk analysis. VRA software listens in on phone calls and tells you whether someone is lying.

If you'll believe that, you'll believe anything.

As the Guardian tell us:
Voice risk analysis has been mired in controversy since scientists raised doubts over the technology soon after it reached the market. In 2007 two Swedish researchers, Anders Eriksson and Francisco Lacerda, published their own analysis of VRA in the International Journal of Speech, Language and Law. They found no scientific evidence to support claims for the device made by the manufacturer.

Lacerda, head of linguistics at Stockholm University, told the Guardian that VRA "does nothing. That is the short answer. There's no scientific basis for this method. From the output it generates this analysis is closer to astrology than science. There was very good work done by the DWP [the Department for Work and Pensions] in the UK showing it did not work ...".
So what?

Here in the UK you get a 25 percent discount on your Council Tax if you live on your own. Some people lie. DWP don't think VRA will identify them. Neither do Messrs Eriksson and Lacerda. Nor, it can safely be asserted, do DMossEsq's millions of readers.

But according to the Guardian article at least 24 local authorities in the UK do believe in magic. Redcar, for example, Middlesbrough, West Dorset and Wycombe among them. "South Oxfordshire ... says that [their VRA] system helped reduce the number of people claiming the single person discount by 3% ...".

Their system is supplied by one of the UK's big government contractors, Capita, who say that: "The technology was never used in isolation. It is only used in cases which are deemed 'high risk', when earlier stages of the review have indicated that more than one person may be living at the property".

The Local Government Association say that: "No one is going to be prosecuted for benefit fraud on the result of voice analysis tests alone".

If VRA doesn't identify suspected fraudsters in the first place and it doesn't provide sufficient evidence to prosecute them, then its contribution to South Oxfordshire's 3 percent reduction is, as Lacerda says, to use the technical term, "nothing". Or as False Economy, a trade union-funded campaign group, put it: "Capita is a firm with a long rap sheet of expensive failure. Neither they nor their technological snake oil should be trusted".

"Astrology"? "Snake oil"? Remind you of anything? The belief in the efficacy of biometrics is akin to the belief in astrologyPublic administration and the McCormick spectrum?

Mass consumer biometrics is a stage prop in the security theatre that the authorities produce and VRA performs, by analogy, in anti-fraud theatre. It may look modern. Technology may impress some people. The authorities may seem to be "doing something". But they're not. Apart from wasting our money.

----------

Updated 1.4.14
Truth or lie - trust your instinct, says research

We are better at identifying liars when we rely on initial responses rather than thinking about it, say psychologists.

Generally we are poor at spotting liars - managing only slightly better than flipping a coin.

But our success rate rises when we harness the unconscious mind, according to a report in Psychological Science ...

The magic of modern public administration

Here's a new TLA for you (three-letter acronym) – "VRA".

"VRA" is voice risk analysis. VRA software listens in on phone calls and tells you whether someone is lying.

If you'll believe that, you'll believe anything.

As the Guardian tell us:
Voice risk analysis has been mired in controversy since scientists raised doubts over the technology soon after it reached the market. In 2007 two Swedish researchers, Anders Eriksson and Francisco Lacerda, published their own analysis of VRA in the International Journal of Speech, Language and Law. They found no scientific evidence to support claims for the device made by the manufacturer.

Lacerda, head of linguistics at Stockholm University, told the Guardian that VRA "does nothing. That is the short answer. There's no scientific basis for this method. From the output it generates this analysis is closer to astrology than science. There was very good work done by the DWP [the Department for Work and Pensions] in the UK showing it did not work ...".
So what?

Monday 24 March 2014

RIP IDA – April is the cruellest month

No need to say it, it goes without saying, it should be obvious to all but, just in case it isn't obvious to all, IDA is dead.

IDA is the Cabinet Office Identity Assurance programme. And it's dead.

----------

Anyone remember this?
Press release
Providers announced for online identity scheme

13 November 2012

Successful providers chosen to design and deliver a secure online identity registration service.

The Post Office, Cassidian, Digidentity, Experian, Ingeus, Mydex, and Verizon are the successful providers chosen to design and deliver a secure online identity registration service for the Department for Work and Pensions.

The identity registration service will enable benefit claimants to choose who will validate their identity by automatically checking their authenticity with the provider before processing online benefit claims ...

Notes to Editors:
...

2. In May 2012 DWP issued an invitation to tender to 44 suppliers.

3. The value of the 18-month framework contracts is £25m.

4. The Identity Assurance programme is a Government-wide initiative led by the Cabinet Office which will in time be available to all UK citizens who need to access online public services.

...

6. Universal Credit, which will go live nationally in October 2013, replaces the current complicated paper based benefits payment system we have now with a new online application that meets the needs of claimants and employers in today’s digital world.

7. One further provider is expected to sign up in the next few weeks - completing the eight chosen to design and deliver a secure online IDA service for Universal Credit.
Once upon a time there were seven "identity providers" – the Post Office, Cassidian, Digidentity, Experian, Ingeus, Mydex, and Verizon. Then there were eight – as per note 7, PayPal signed up later. Then there were five – Cassidian, Ingeus and PayPal pulled out. 39 of the original 44 (note 2) aspitants are gone.

Universal Credit did not go live in October 2013 (note 6). To date, no benefit claimants can choose an "identity provider" to verify their identity and there are no online benefit claims services. No sign of it so far, how long before the Cabinet Office provide identity assurance across all Government departments to all UK citizens (note 4)? They haven't said.

As Whitehall press releases go, Providers announced for online identity scheme must count as one of the most misleading ever. Is there an appropriate award? The Nostradamus Trophy?

There can't be much of that £25 million left 17 months later and there's only a month to go before the contracts come up for renewal (note 3).

With their exclusivity period at an end, will the surviving five "identity providers" face competition from Google? Or Facebook?

Not with only £25 million on the table, they won't. Will that become £250 million for the next 18 months? Or will the government stop paying the "identity providers" and leave us to pay for our dematerialised ID cards ourselves?

Will the surviving five renew their contracts? Or will they prudently cut their losses and depart the field with their reputations relatively intact?

In which case, what will the UK's political parties fill up their May 2015 manifestos with under the heading of "modernisation"?

RIP IDA – April is the cruellest month

No need to say it, it goes without saying, it should be obvious to all but, just in case it isn't obvious to all, IDA is dead.

IDA is the Cabinet Office Identity Assurance programme. And it's dead.

----------

Anyone remember this?
Press release
Providers announced for online identity scheme

13 November 2012

Successful providers chosen to design and deliver a secure online identity registration service.

The Post Office, Cassidian, Digidentity, Experian, Ingeus, Mydex, and Verizon are the successful providers chosen to design and deliver a secure online identity registration service for the Department for Work and Pensions.

The identity registration service will enable benefit claimants to choose who will validate their identity by automatically checking their authenticity with the provider before processing online benefit claims ...

Notes to Editors:
...

2. In May 2012 DWP issued an invitation to tender to 44 suppliers.

3. The value of the 18-month framework contracts is £25m.

4. The Identity Assurance programme is a Government-wide initiative led by the Cabinet Office which will in time be available to all UK citizens who need to access online public services.

...

6. Universal Credit, which will go live nationally in October 2013, replaces the current complicated paper based benefits payment system we have now with a new online application that meets the needs of claimants and employers in today’s digital world.

7. One further provider is expected to sign up in the next few weeks - completing the eight chosen to design and deliver a secure online IDA service for Universal Credit.
Once upon a time there were seven "identity providers" – the Post Office, Cassidian, Digidentity, Experian, Ingeus, Mydex, and Verizon. Then there were eight – as per note 7, PayPal signed up later. Then there were five – Cassidian, Ingeus and PayPal pulled out. 39 of the original 44 (note 2) aspitants are gone.

Universal Credit did not go live in October 2013 (note 6). To date, no benefit claimants can choose an "identity provider" to verify their identity and there are no online benefit claims services. No sign of it so far, how long before the Cabinet Office provide identity assurance across all Government departments to all UK citizens (note 4)? They haven't said.

RIP IDA – 16 June 2014

No need to say it, it goes without saying, it should be obvious to all but, just in case it isn't obvious to all, IDA is dead.

IDA is the Cabinet Office Identity Assurance programme. And it's dead.

----------

Hat tip-and-a-half: Brian Krebs

Operating until recently sometimes out of New Zealand and sometimes out of Vietnam, Mr Hieu Minh Ngo is currently locked up in New Hampshire as a guest of the Justice Department and looks like spending the next 45 years in prison in the US.

An entrepreneurial young man – he's only 24 now, 69 when he gets out – Mr Ngo had two illicit web-based businesses, superget.info and findget.me, which have between them sold the personal details of more than half a million Americans. Their 1,300 customers make money fraudulently by using this information to take out loans in the victim's name, for example, or to make false tax refund requests.

Mr Ngo's companies bought this information from a legitimate company, Court Ventures, which, in turn, bought it from another legitimate company, US Info Search.

How did the information cross the line between the legitimacy of Court Ventures and the criminality of superget.info and findget.me? Rather suspiciously – Mr Ngo paid Court Ventures with monthly wire transfers from Singapore.

So far we've had new Zealand, Vietnam, Singapore and the US. We can throw in Guam, too – the US Secret Service contacted Mr Ngo and offered him some illegal business which required him to leave Vietnam, where they couldn't arrest him, and come to Guam, where they could and did.

It's all quite exotic for us Brits. Interesting in its way. But nothing to do with us, surely.

Wrong.

In March 2012, Court Ventures was bought by our very own Experian. Mr Ngo carried on paying his monthly bills by Singapore wire transfer for over nine months before the Secret Service approached Experian and told them what was happening.

This whole story comes from Brian Krebs, who operates krebsonsecurity.com and who has taken part in the investigation of Mr Ngo. He first wrote about it in October 2013, Experian Sold Consumer Data to ID Theft Service. He returned to it a fortnight ago, Experian Lapse Allowed ID Theft Service Access to 200 Million Consumer Records. And a very embarrassing story it is, too – Experian didn't identify the problem themselves either during the due diligence period before buying Court Ventures or for the first nine months that they owned the company. Their own procedures failed. They had to be told by the Secret Service.

The matter is still under investigation, Experian can't say all they would no doubt like to, in their defence, but they have given this statement to Mr Krebs:
Experian acquired Court Ventures in March, 2012 because of its national public records database. After the acquisition, the US Secret Service notified Experian that Court Ventures had been and was continuing to resell data from US Info Search to a third party possibly engaged in illegal activity. Following notice by the US Secret Service, Experian discontinued reselling US Info Search data and worked closely and in full cooperation with law enforcement to bring Vietnamese national Hieu Minh Ngo, the alleged perpetrator, to justice. Experian’s credit files were not accessed. Because of the ongoing federal investigation, we are not free to say anything further at this time.
15 criminal charges have been brought in New Hampshire – Mr Krebs provides the charge sheet – and Mr Ngo has pleaded guilty and will be sentenced on 16 June 2014.

Meanwhile, the story has moved on from New Hampshire to Washington DC, where Senator Rockefeller's Committee on Commerce, Science, & Transportation is investigating all aspects of the "data broker" industry.

On 18 December 2013 the Committee took evidence from, among others, Mr. Tony Hadley, Experian's Senior Vice President of Government Affairs and Public Policy. Mr Hadley makes his opening statement starting at 1:30:35. Committee member Senator McCaskill confronts him with the Ngo case starting at 2:22:45.

See what you make of it.

Bear in mind that, over here in the UK, Experian is currently one of the five remaining "identity providers" appointed by the Government Digital Service to provide identity assurance (IDA) for GDS's plans for public services to become digital by default.

They're not just one of the UK's "identity providers". They're easily the leading UK "identity provider". Without them, IDA dies.

Over in the US, Experian hold data on 200 million Americans. Experian are acting as "identity providers" to Obamacare. When the New Hampshire judge sentences Mr Ngo to an estimated 45 years behind bars, there's going to be some consternation. There hasn't been much coverage of the case in the UK if any but, on 16 June 2014, the ripples are going to lap up on these shores.

And when they do, can Experian survive as an "identity provider" to IDA? Should they? Will they want to?

GDS themselves are lukewarm to the point of being uninterested in security. That leaves the "identity providers" to shoulder the burden alone. No major retail bank is prepared to put itself forward as an "identity provider". No UK mobile phone network operator ditto. The "identity providers" GDS would probably like to retain – Google and maybe Facebook – are unacceptable. It's Experian or no-one.

Experian is one of the best-performing shares in DMossEsq's pension scheme. It is with considerable pain, therefore, that the verdict handed down round here at DMossEsq Towers is, no-one. RIP IDA.

----------

Updated 15.6.14

It's the big day tomorrow, 16 June 2014 – Hieu Minh Ngo appears in court to be sentenced and the judge may have something to say about how Experian managed to provide him, unknowingly until the US Secret Service alerted them, with the wherewithal to commit fraud.

Updated 27.6.14

Computer Weekly say German government terminates Verizon contract over NSA snooping fears.

What fears? Verizon are quoted as saying: “Our view on the matter is simple: the US government cannot compel us to produce our customers’ data stored in data centers outside the US and, if it attempts to do so, we would challenge that attempt in court”. Clearly the German government disagrees and has terminated the contract anyway.

The US lawyers Mayer Brown disagree. And so do Facebook, who are quoted as saying that they put up a "forceful" defence against disclosing "nearly all data from the accounts of 381 people who use our service" but had to comply in the end.

Verizon is one of the five remaining "identity providers" accredited by the Government Digital Service (but not tScheme) for their hopeless identity assurance service (IDA).

But for how long?

Can Verizon be good enough for the UK but not good enough for Germany?

Updated 28.6.14

The judge was meant to deliver his decision in the matter of Mr Hieu Minh Ngo on 16 June 2014. Here we are 12 days later and the scrofulous DMossEsq still hasn't reported it. What's going on?









Updated 10.3.15

As we were saying, "on 18 December 2013 the Committee took evidence from, among others, Mr. Tony Hadley, Experian's Senior Vice President of Government Affairs and Public Policy". Has anything happened since then?

Yes, hat tip ElReg, the Data-broker Accountability and Transparency Act has been drafted.


RIP IDA – 16 June 2014

No need to say it, it goes without saying, it should be obvious to all but, just in case it isn't obvious to all, IDA is dead.

IDA is the Cabinet Office Identity Assurance programme. And it's dead.

----------

Hat tip-and-a-half: Brian Krebs

Operating until recently sometimes out of New Zealand and sometimes out of Vietnam, Mr Hieu Minh Ngo is currently locked up in New Hampshire as a guest of the Justice Department and looks like spending the next 45 years in prison in the US.

An entrepreneurial young man – he's only 24 now, 69 when he gets out – Mr Ngo had two illicit web-based businesses, superget.info and findget.me, which have between them sold the personal details of more than half a million Americans. Their 1,300 customers make money fraudulently by using this information to take out loans in the victim's name, for example, or to make false tax refund requests.

Mr Ngo's companies bought this information from a legitimate company, Court Ventures, which, in turn, bought it from another legitimate company, US Info Search.

How did the information cross the line between the legitimacy of Court Ventures and the criminality of superget.info and findget.me? Rather suspiciously – Mr Ngo paid Court Ventures with monthly wire transfers from Singapore.

So far we've had new Zealand, Vietnam, Singapore and the US. We can throw in Guam, too – the US Secret Service contacted Mr Ngo and offered him some illegal business which required him to leave Vietnam, where they couldn't arrest him, and come to Guam, where they could and did.

It's all quite exotic for us Brits. Interesting in its way. But nothing to do with us, surely.

Wrong.