Blogging a noisy and socialistic view on politics, security, and whatever may take my fancy. "All the world now is in the Ranting humour" - Samuel Sheppard, 1647
Showing posts with label biometrics. Show all posts
Showing posts with label biometrics. Show all posts
Sunday, October 30, 2011
What these people need is a national biometric identity register
The creation of a database containing all 9 million Israelis' demographic, family, and medical information plus identifying biometrics has not necessarily developed to their advantage. Bonus points for use of the phrase "Hasidic criminal underworld". They'll make you an offer it takes years of painstaking theological scholarship to understand.
Thursday, September 03, 2009
Read this now
A classic piece at The Register on biometrics and stupidity: read David Moss and you'll be more competent than anyone in government on this issue. It's the false positives, of course; but the truly shocking thing is that despite everything, the ID scheme still depends on the n=10,000 trial from 2004 that they deny is a trial.
Go, read.
Go, read.
Sunday, June 07, 2009
Accidental Guerrilla, Part 3: Space
A lot of The Accidental Guerrilla concerns ideas of terrain, space, and time. In fact, quite a bit of it could be considered an architectural approach to counter-insurgency. This is not surprising; a major theme is the idea that the conflict environment - the state of being at war or potentially at war, the disrupted social and political structure, the faltering infrastructure, the global black market - is the enemy. After all, it is one of the reasons people seek survival through certainty by calling on the deliberate guerrillas to influence their other political relationships.
One example of this is the one I've already written up - the armoured patrol vehicle as urban submarine, a self-defeating machine that itself divides the counter-insurgents from the people in an ironic reversal of their own thinking.
Kilcullen goes almost New Urbanist on this; discussing the Iraq experience, he argues that a huge flaw in the US strategy was that they had to commute to the battle, travelling in monster armoured vehicles, without contact with the civilian population, but still vulnerable to IEDs and ambushes on the over-predictable road routes between their camps and their areas of operation. The answer was to redeploy into the cities and move into positions that let them walk to work; I tell you, Richard Florida got nothing on him.
Similarly, a major aim of his campaign plan was to control access to Baghdad, counterattacking the NOIA encirclement strategy and preventing insurgent "commuters" from the Sunni semi-urban belt getting into the city. You could almost call it a critique of suburban warfare.
This concern with space is also a major theme of the case study on Kunar and road building. The construction of a road was intended to get access and control of the narrow flood plain at the bottom of the valley, which is where everyone lives, rather than up on the mountains. Nothing much grows on the tops and it's tough to get up there or back down, so the only important places up there are a few tactically important hilltops.
Road access meant that it was easier to force the Taliban to go quiet, either by climbing into the mountains or by going underground. More importantly, it made it possible to keep them there, and to deliver economic benefits. But perhaps the biggest changes it provided were as follows:
Firstly, it changed the topography so that the government side were in the villages, looking out, and the Taliban were outside, looking in. The US or Afghan government fire was outgoing; the Taliban's, incoming.
Second, it made it worth arguing where different groups' authority ended; without the road, it was bounded by the difficulty of travel. Once they had to argue about it, the government or the traditional authorities could be called in to arbitrate the dispute, boosting their authority and making them useful. In a sense, the Kunar case study is all about creating a demand for government, or at least competing with the Taliban to supply it.
An interesting question, though; the whole paradigm of The Accidental Guerrilla is based on experience in places where the state is absent, illegitimate, or never established. But many of the same phenomena happen in places where the state, or the structure of traditional authority, once existed but has broken down.
Further, the international jihadis are trying to move (as Kilcullen says) from expeditionary terrorism, where their operations are set up in the home base and carried out remotely, to a guerrilla model where they are set up by sympathisers recruited in the target state. This implies that the process will have to take place in an environment where the state exists here and now.
I'm less convinced by his arguments regarding this; obviously, the naked city has as many possible base-areas as it has people, but as Daniel Davies pointed out, the current European takfiris seem to have less access to firearms than a typical criminal gang, and one of the most worrying possibilities in this line is indeed that they cross-fertilise with ordinary decent criminals. Kilcullen's practical recommendations in this line are mostly commonsensical, although he is very keen on Cold War analogies with efforts to start non-communist unions and the like, and the other activities of the Blearsministerium.
However, despite the technological implications of auto-immune warfare, he also believes that "biometric reconnaissance" is a strategically important capability. I rather suspect that we've already been seeing the effects of this advocacy without knowing what was behind it.
One example of this is the one I've already written up - the armoured patrol vehicle as urban submarine, a self-defeating machine that itself divides the counter-insurgents from the people in an ironic reversal of their own thinking.
Kilcullen goes almost New Urbanist on this; discussing the Iraq experience, he argues that a huge flaw in the US strategy was that they had to commute to the battle, travelling in monster armoured vehicles, without contact with the civilian population, but still vulnerable to IEDs and ambushes on the over-predictable road routes between their camps and their areas of operation. The answer was to redeploy into the cities and move into positions that let them walk to work; I tell you, Richard Florida got nothing on him.
Similarly, a major aim of his campaign plan was to control access to Baghdad, counterattacking the NOIA encirclement strategy and preventing insurgent "commuters" from the Sunni semi-urban belt getting into the city. You could almost call it a critique of suburban warfare.
This concern with space is also a major theme of the case study on Kunar and road building. The construction of a road was intended to get access and control of the narrow flood plain at the bottom of the valley, which is where everyone lives, rather than up on the mountains. Nothing much grows on the tops and it's tough to get up there or back down, so the only important places up there are a few tactically important hilltops.
Road access meant that it was easier to force the Taliban to go quiet, either by climbing into the mountains or by going underground. More importantly, it made it possible to keep them there, and to deliver economic benefits. But perhaps the biggest changes it provided were as follows:
Firstly, it changed the topography so that the government side were in the villages, looking out, and the Taliban were outside, looking in. The US or Afghan government fire was outgoing; the Taliban's, incoming.
Second, it made it worth arguing where different groups' authority ended; without the road, it was bounded by the difficulty of travel. Once they had to argue about it, the government or the traditional authorities could be called in to arbitrate the dispute, boosting their authority and making them useful. In a sense, the Kunar case study is all about creating a demand for government, or at least competing with the Taliban to supply it.
An interesting question, though; the whole paradigm of The Accidental Guerrilla is based on experience in places where the state is absent, illegitimate, or never established. But many of the same phenomena happen in places where the state, or the structure of traditional authority, once existed but has broken down.
Further, the international jihadis are trying to move (as Kilcullen says) from expeditionary terrorism, where their operations are set up in the home base and carried out remotely, to a guerrilla model where they are set up by sympathisers recruited in the target state. This implies that the process will have to take place in an environment where the state exists here and now.
I'm less convinced by his arguments regarding this; obviously, the naked city has as many possible base-areas as it has people, but as Daniel Davies pointed out, the current European takfiris seem to have less access to firearms than a typical criminal gang, and one of the most worrying possibilities in this line is indeed that they cross-fertilise with ordinary decent criminals. Kilcullen's practical recommendations in this line are mostly commonsensical, although he is very keen on Cold War analogies with efforts to start non-communist unions and the like, and the other activities of the Blearsministerium.
However, despite the technological implications of auto-immune warfare, he also believes that "biometric reconnaissance" is a strategically important capability. I rather suspect that we've already been seeing the effects of this advocacy without knowing what was behind it.
Wednesday, December 10, 2008
voice stress clarity
OK, so yer lie detector. It's been something of a blogosphere hit. And in the comments, we have Nigel, who appears to know something about acoustic signal processing - in the sense of "makes speech recognition systems for Eurofighters".
It seems that rather than being a signal at a frequency between 8 and 12Hz, the signal you're interested in is a signal, of that frequency, modulated onto the main signal. So in fact, you could theoretically detect it through a telephone call. I was wrong.
However, that isn't what Nemesysco's patent claims, and they vigorously deny that what they are doing is voice stress analysis. It's not the pitch of any such signal that is discussed in the patent, either; it's the change in the numbers of thorns and plateaus.
Our acoustic expert says that this could be a way of measuring the signals required for classical VSA, just not a very good one; and anyway, he argues that VSA itself is useless, even if it was VSA they were promising to conduct. And, of course, they deny that this is their methodology. Further, VSA gives only one measurement, one of vaguely-defined stress - not the nine or so Nemesysco claim to get out of this.
Meanwhile, someone who makes the same spelling mistakes as Amir Liberman does showed up in comments to claim there was more, secret technology involved that they hadn't actually patented. Interestingly, he showed up from the same network as Nemesysco's Web site. The same network was also the source of a Wikipedia article which got deleted for advertising, in which Nemesysco claimed that their method uses 129 different measurements and isn't anything like VSA. No, sir. And there weren't 129 different metrics in their patent...
It seems that rather than being a signal at a frequency between 8 and 12Hz, the signal you're interested in is a signal, of that frequency, modulated onto the main signal. So in fact, you could theoretically detect it through a telephone call. I was wrong.
However, that isn't what Nemesysco's patent claims, and they vigorously deny that what they are doing is voice stress analysis. It's not the pitch of any such signal that is discussed in the patent, either; it's the change in the numbers of thorns and plateaus.
Our acoustic expert says that this could be a way of measuring the signals required for classical VSA, just not a very good one; and anyway, he argues that VSA itself is useless, even if it was VSA they were promising to conduct. And, of course, they deny that this is their methodology. Further, VSA gives only one measurement, one of vaguely-defined stress - not the nine or so Nemesysco claim to get out of this.
Meanwhile, someone who makes the same spelling mistakes as Amir Liberman does showed up in comments to claim there was more, secret technology involved that they hadn't actually patented. Interestingly, he showed up from the same network as Nemesysco's Web site. The same network was also the source of a Wikipedia article which got deleted for advertising, in which Nemesysco claimed that their method uses 129 different measurements and isn't anything like VSA. No, sir. And there weren't 129 different metrics in their patent...
Sunday, October 12, 2008
if you're not on the list you're not coming in
OK, so what about those identity cards for (some kinds of) foreign nationals? You'll recall that the Government promised, back in the spring, to have them out and operational in 300 days. As late as July, there were no actual contracts for the job, but they did actually manage to bring in Thales to start work. So how's it going?
Well, despite the vast cutback in scope and scale, the decision to base it on crappy existing records, and just to forget about the National ID Register for now (thus obviating the whole point)...it's already over budget by 29% and it's sliding right, from March 2009 to August 2010. Cracking; the element of the project they specially rushed forward in order to get something, anything working on time has now slid so badly that it's caught up with the rest of the project.
Meanwhile, the Home Office is issuing 5,400 fraudulent passports a year, among some 200,000 dodgy docs in circulation. Apparently "automated facial recognition" will solve it; this doesn't make very much sense, as surely the main problem is people submitting genuine photographs of themselves and falsifying the biographical section of the form.
Further, face recognition systems are poor enough (remember the one in Newham that never actually caught anyone?) at positive identification; checking the face provided against the one on file. The failure rate in the Home Office 2004 trials was about 30 per cent. But the IPS and DVLA seem to think they can rely on it to guarantee that the same person isn't already registered, and do this by matching faces to a database containing tens of millions of faces, taken under all kinds of different circumstances. What kind of false-positive rate can you expect from that?
In fact, it's worse; if they're trying to detect multiple applications or applications under false names, the evidence of an honest application will be the absence of a match. So the most common failure mode will result in the document being issued anyway, and there is no way to detect this. And you won't be able to assume that a match is proof of fraud either, because of the inevitable false positives; so the chance of successfully getting a passport or driving licence in someone else's name might actually be better.
Well, despite the vast cutback in scope and scale, the decision to base it on crappy existing records, and just to forget about the National ID Register for now (thus obviating the whole point)...it's already over budget by 29% and it's sliding right, from March 2009 to August 2010. Cracking; the element of the project they specially rushed forward in order to get something, anything working on time has now slid so badly that it's caught up with the rest of the project.
Meanwhile, the Home Office is issuing 5,400 fraudulent passports a year, among some 200,000 dodgy docs in circulation. Apparently "automated facial recognition" will solve it; this doesn't make very much sense, as surely the main problem is people submitting genuine photographs of themselves and falsifying the biographical section of the form.
Further, face recognition systems are poor enough (remember the one in Newham that never actually caught anyone?) at positive identification; checking the face provided against the one on file. The failure rate in the Home Office 2004 trials was about 30 per cent. But the IPS and DVLA seem to think they can rely on it to guarantee that the same person isn't already registered, and do this by matching faces to a database containing tens of millions of faces, taken under all kinds of different circumstances. What kind of false-positive rate can you expect from that?
In fact, it's worse; if they're trying to detect multiple applications or applications under false names, the evidence of an honest application will be the absence of a match. So the most common failure mode will result in the document being issued anyway, and there is no way to detect this. And you won't be able to assume that a match is proof of fraud either, because of the inevitable false positives; so the chance of successfully getting a passport or driving licence in someone else's name might actually be better.
Labels:
bad science,
biometrics,
geekage,
Home Office,
ID,
intelligence and stupidity
Sunday, September 07, 2008
SELECT * FROM policies WHERE irishash="0xSTUPID";
Late to the party, I know. But is this the worst example of biometrics as a religion yet? So the Shia-led, pro-Iranian government of Iraq we're desperately propping up doesn't like the Sunni, Iraqi chauvinist countergangs we organised to prop them up much. So the plan to reintegrate them, as they say, into society as law-abiding citizens ain't going so well. (Ah, Sergeant Hussein? You know how we invaded your country, overthrew the dictator, then dissolved the army you spent the last 15 years in and left you to rot on the dole while we conspired with your despised religious and class enemies? And we finally agreed to enrol you and your old mates as an auxiliary police force because we couldn't catch you? Well, thanks, we're doing it again. Yes, the first bit. Have you considered becoming a plumber? Please don't use any metalworking skills you may acquire to make EFPs, that's all we ask.)
Worse, yer man is now trying to pick a fight with the Kurds, in which case they will no doubt retaliate by grabbing Sgt Hussein's home town and telling the government in Baghdad it can't have any more oil. As a lot of the army Maliki counts on for this is actually the Kurdish army, there's a lot more that can go wrong here. So what's the plan B?
Apparently it's biometrics. All those ex-insurgents from the NOIA who signed up on our side were iris-scanned, and the information something or other with Saddam's old secret police files. Hey, I remember that the secret police files got torched. Except for the bits involving George Galloway and various other people who all by coincidence opposed the war. And the ones the Chalabi Boys nicked and the US Army had to nick back; there's a lot of different data sets wandering about, no? Of course, there's absolutely no point in looking for Sunni Arab nationalist ex-army insurgents in Saddam's old files; it was Sunni Arab nationalist army officers who compiled Saddam's old files in the first place. Perhaps they mean the Republican Guard payroll, but who knows, eh.
Anyway, the biometrics. How is this meant to help? Specifically, the iris scans. Now, if you make a bomb, your irises don't leave any traces on it. Iris-scanning implies you've caught the guy already and you want to check if he's on the list. And the point of guerrilla warfare is that the enemy doesn't know who to lock up, or else they can't catch up with them, or the people they are after hide out somewhere they'll need to stage a huge multidivisional onslaught and probably build a railway to get into. I mean, it's got to be better than having absolutely no information, but it's no solution, especially if the data is mashed up with the wrong kind of intelligence files. (Ah, Sergeant Al-Hakim. You must be proud of your years of heroic resistance to Baathist tyranny...)
It's as if they believe that having an MD5 hash of someone's iris means you can double-click on their photo and they're delivered to your desk like an Amazon.com package; or that the camera will take your soul. But then, every government thinks this, at least some of the time. Which reminds me:
Worse, yer man is now trying to pick a fight with the Kurds, in which case they will no doubt retaliate by grabbing Sgt Hussein's home town and telling the government in Baghdad it can't have any more oil. As a lot of the army Maliki counts on for this is actually the Kurdish army, there's a lot more that can go wrong here. So what's the plan B?
Apparently it's biometrics. All those ex-insurgents from the NOIA who signed up on our side were iris-scanned, and the information something or other with Saddam's old secret police files. Hey, I remember that the secret police files got torched. Except for the bits involving George Galloway and various other people who all by coincidence opposed the war. And the ones the Chalabi Boys nicked and the US Army had to nick back; there's a lot of different data sets wandering about, no? Of course, there's absolutely no point in looking for Sunni Arab nationalist ex-army insurgents in Saddam's old files; it was Sunni Arab nationalist army officers who compiled Saddam's old files in the first place. Perhaps they mean the Republican Guard payroll, but who knows, eh.
Anyway, the biometrics. How is this meant to help? Specifically, the iris scans. Now, if you make a bomb, your irises don't leave any traces on it. Iris-scanning implies you've caught the guy already and you want to check if he's on the list. And the point of guerrilla warfare is that the enemy doesn't know who to lock up, or else they can't catch up with them, or the people they are after hide out somewhere they'll need to stage a huge multidivisional onslaught and probably build a railway to get into. I mean, it's got to be better than having absolutely no information, but it's no solution, especially if the data is mashed up with the wrong kind of intelligence files. (Ah, Sergeant Al-Hakim. You must be proud of your years of heroic resistance to Baathist tyranny...)
It's as if they believe that having an MD5 hash of someone's iris means you can double-click on their photo and they're delivered to your desk like an Amazon.com package; or that the camera will take your soul. But then, every government thinks this, at least some of the time. Which reminds me:
The immigration minister, Liam Byrne, promised yesterday to start issuing ID cards to foreign nationals within 300 days - by November 2008. The first required to apply will be students and those married to British citizens or involved in civil partnerships or long-term relationships.Seven weeks to go. No contracts. No requirements document. No specs. No code. Someone's in for an epic binge-coding session, aren't they? Or is "Teh Stupid! It's Byrne's!" hoping we've all forgotten? Maybe NO2ID should put in a bid itself...
Labels:
4GW,
biometrics,
Chalabi,
Diyala,
Home Office,
ID,
intelligence and stupidity,
Iraq,
NOIA,
stupid procurement,
surveillance
Saturday, September 06, 2008
Organise, and a very wet 2600
So I took my stupid damn idea off to the stupid ideas club. When we got there, guess who? Spyblog was waiting at the rendezvous with some Dutchmen and an Argentine documentarist and half the No2ID members not currently in hospital. And after we made our way through Jock McZanu's EU Maddie monsoon (GOOD HERE ISN'T IT???) to the pub, who shows up but Rat; carrying a total of 30GB of mass storage on his person in an array of USB drives, a fob GPS, and God knows what in his piercings.
Anyway, we talked over the thing, and many other things besides; what should happen if secret police become members? wouldn't it be easier to do an open-source clone of a BMC helpdesk ticketing app? (why? why? I thought my brain would concrete) how would you sterilise an airport fingerprint reader in less than 10 seconds? So I promised to revise the proposals, and well, here they are.
Or would be, but nobody likes a 2,000 word blog post. So instead it's here on Google Documents, which probably means something badological. Read. Mark. Learn. Inwardly digest. Comment. Here at first, but if you want to take part just tell me and I'll give you write privileges. If anyone cares very much I'll get it set up on Sourceforge and set about preparing a list of functions and tables. I still think Django is the way to go, in which case the mapping of the org model into Python classes into db tables should be as straightforward as these things ever are.
Anyway, we talked over the thing, and many other things besides; what should happen if secret police become members? wouldn't it be easier to do an open-source clone of a BMC helpdesk ticketing app? (why? why? I thought my brain would concrete) how would you sterilise an airport fingerprint reader in less than 10 seconds? So I promised to revise the proposals, and well, here they are.
Or would be, but nobody likes a 2,000 word blog post. So instead it's here on Google Documents, which probably means something badological. Read. Mark. Learn. Inwardly digest. Comment. Here at first, but if you want to take part just tell me and I'll give you write privileges. If anyone cares very much I'll get it set up on Sourceforge and set about preparing a list of functions and tables. I still think Django is the way to go, in which case the mapping of the org model into Python classes into db tables should be as straightforward as these things ever are.
Labels:
action,
biometrics,
GPS,
hacker,
London,
managerialism,
politics,
programming,
protest,
Python,
socialism,
weirdness
Saturday, August 02, 2008
When the world was our lobster
So, those Oystercard outages. I wrote a sizable post on this immediately before going on holiday, but something odd happened with Wordpress's clever ajaxy bits and it vanished. Computers...anyway, we can work out various things about the problem from the few details supplied.
In the first incident, around 1% of the cards somehow became nonfunctional. We don't know how; we do know, however, that it was indeed the cards, because the fix was to bring them in and issue new ones. This raises an interesting question; why did new physical cards have to be issued? The process of issuing a card involves writing the data TfL holds on you to the blank card; there isn't much difference between this and overwriting whatever is on the card with the details held in the database. This suggests either that the affected cards suffered actual physical damage - unlikely, unless someone's running about with a really powerful RF source and a bad sense of humour - or else that TfL can't trust the information on file, and therefore needs to erase the affected records and set up new user accounts.
So, how could it happen? Card systems can work in various ways; you can do a pure online authorisation system, like debit or credit cards, where information on the card is read off and presented to a remote computer, which matches it against a look-up table and sends back a response, or you can do a pure card system, where your credit balance is recorded on the card and debited when you use it, then credited when you pay up. Or you can have a hybrid of the two. Oyster is such a hybrid. TfL obviously maintains a database of Oyster user accounts, because it's possible to restore lost cards from backup, to top-up through their Web site without needing a card reader, and to top-up automatically. But it's also clear that the card is more than just a token; you can top up at shops off-line, and the transaction between the card and the ticket barrier is quick enough that you don't need to break stride (consider how long it takes to interact with a Web site or use a bank card terminal).
Clearly, the actual authorisation is local (the barrier talks to the card), as is offline top-up, but the state of the card is backed up to the database asynchronously, and changes to your record in the database are reflected on the card, presumably as soon as it passes through a card reader. To achieve this without stopping the flow of passengers, I assume that when a card is read, the barrier also keeps the information from it in a cache and periodically updates the database. Similarly, in order to get online top-ups credited to the cards, the stations probably receive and cache recent updates from the database; if the card number is in the list, it gets an "increment £x" command.
We can probably rule out, then, that 1% of the Oyster card fleet were somehow dodgy when they started to flow through the gatelines that morning, and that the uploaded data from them caused the matching records to become untrustworthy. It's possible - just - that some shops somehow sporked them. It's also vaguely possible that bad data from some subgroup of cards propagated to the others. But I think these are unlikely. It's more likely that the batch process that primes the station system with the last lot of online and automatic top-ups went wrong, and the barriers dutifully wrote the dodgy data to the cards.
This is also what TfL says:
In this scenario, some sort of check incorporated in the database was intended to detect people using the MiFare exploit (probably looking for multiple instances of the same card, cards that didn't appear in the database, or an excess of credit over the cash coming in), but a catastrophic false positive occurred. This is a serious lesson about the MiFare hack, and about this sort of public-space system in general; the effects of the security response may well be worse than those of the attack. Someone using a cloned, or fraudulently refilled, card could at best steal a few pounds in free rides. But the security response, if that was what it was, first threatened a massive denial-of-service attack on the whole public transport system, and then caused TfL to lose a whole day's revenue.
In the first incident, around 1% of the cards somehow became nonfunctional. We don't know how; we do know, however, that it was indeed the cards, because the fix was to bring them in and issue new ones. This raises an interesting question; why did new physical cards have to be issued? The process of issuing a card involves writing the data TfL holds on you to the blank card; there isn't much difference between this and overwriting whatever is on the card with the details held in the database. This suggests either that the affected cards suffered actual physical damage - unlikely, unless someone's running about with a really powerful RF source and a bad sense of humour - or else that TfL can't trust the information on file, and therefore needs to erase the affected records and set up new user accounts.
So, how could it happen? Card systems can work in various ways; you can do a pure online authorisation system, like debit or credit cards, where information on the card is read off and presented to a remote computer, which matches it against a look-up table and sends back a response, or you can do a pure card system, where your credit balance is recorded on the card and debited when you use it, then credited when you pay up. Or you can have a hybrid of the two. Oyster is such a hybrid. TfL obviously maintains a database of Oyster user accounts, because it's possible to restore lost cards from backup, to top-up through their Web site without needing a card reader, and to top-up automatically. But it's also clear that the card is more than just a token; you can top up at shops off-line, and the transaction between the card and the ticket barrier is quick enough that you don't need to break stride (consider how long it takes to interact with a Web site or use a bank card terminal).
Clearly, the actual authorisation is local (the barrier talks to the card), as is offline top-up, but the state of the card is backed up to the database asynchronously, and changes to your record in the database are reflected on the card, presumably as soon as it passes through a card reader. To achieve this without stopping the flow of passengers, I assume that when a card is read, the barrier also keeps the information from it in a cache and periodically updates the database. Similarly, in order to get online top-ups credited to the cards, the stations probably receive and cache recent updates from the database; if the card number is in the list, it gets an "increment £x" command.
We can probably rule out, then, that 1% of the Oyster card fleet were somehow dodgy when they started to flow through the gatelines that morning, and that the uploaded data from them caused the matching records to become untrustworthy. It's possible - just - that some shops somehow sporked them. It's also vaguely possible that bad data from some subgroup of cards propagated to the others. But I think these are unlikely. It's more likely that the batch process that primes the station system with the last lot of online and automatic top-ups went wrong, and the barriers dutifully wrote the dodgy data to the cards.
This is also what TfL says:
We believe that this problem, like the last one resulted from incorrect data tables being sent out by our contractor, Transys.People of course think this was somehow connected with the NXP MiFare class break, but it's not necessary.
In this scenario, some sort of check incorporated in the database was intended to detect people using the MiFare exploit (probably looking for multiple instances of the same card, cards that didn't appear in the database, or an excess of credit over the cash coming in), but a catastrophic false positive occurred. This is a serious lesson about the MiFare hack, and about this sort of public-space system in general; the effects of the security response may well be worse than those of the attack. Someone using a cloned, or fraudulently refilled, card could at best steal a few pounds in free rides. But the security response, if that was what it was, first threatened a massive denial-of-service attack on the whole public transport system, and then caused TfL to lose a whole day's revenue.
Labels:
biometrics,
electronics,
engineering,
hacker,
ID,
trains
Sunday, March 30, 2008
ID Cards will make us safer!
Genius. Not only can the Chaos Computer Club tell you how to fool a fingerprint reader, but they've got Wolfgang Schauble's dabs.
Sunday, March 16, 2008
No. Just No. Just No.
ACPO is no longer tolerable as an organisation. It's a freefloating lobby for ever-greater authoritarianism. Seriously.
The ID card scheme is on its last legs; note that the heart of it, the NIR, has been shunted back from 2004 to 2012, whatever pretendy-wee bollocks they rush out for face-saving purposes. But the control industry keeps rolling along.
Also note this:
Gary Pugh, director of forensic sciences at Scotland Yard and the new DNA spokesman for the Association of Chief Police Officers (Acpo), said a debate was needed on how far Britain should go in identifying potential offenders, given that some experts believe it is possible to identify future offending traits in children as young as five.
'If we have a primary means of identifying people before they offend, then in the long-term the benefits of targeting younger people are extremely large,' said Pugh. 'You could argue the younger the better. Criminologists say some people will grow out of crime; others won't. We have to find who are possibly going to be the biggest threat to society.'
Pugh admitted that the deeply controversial suggestion raised issues of parental consent, potential stigmatisation and the role of teachers in identifying future offenders, but said society needed an open, mature discussion on how best to tackle crime before it took place. There are currently 4.5 million genetic samples on the UK database - the largest in Europe - but police believe more are required to reduce crime further. 'The number of unsolved crimes says we are not sampling enough of the right people,' Pugh told The Observer....
The ID card scheme is on its last legs; note that the heart of it, the NIR, has been shunted back from 2004 to 2012, whatever pretendy-wee bollocks they rush out for face-saving purposes. But the control industry keeps rolling along.
Also note this:
'Fingerprints, somehow, are far less contentious,' he said. 'We have children giving their fingerprints when they are borrowing books from a library.'When we say that the efforts to push biometrics and RFID on schools are intended to soften up the public for more state surveillance, they call us paranoid extremists. And then, the head of biometrics at ACPO says that's precisely what they are doing.
Saturday, March 15, 2008
Can Haz RFID? Noes? I HAZ FN FAL!
Via comp.risks, across the wire the electric message came: German students crack encryption on over 2bn RFID smartcards made by NXP Semiconductor. The cards in question are NXP's MiFare Classic type, and are used for public transport....but also for access control in sensitive government installations, it turns out. Inevitably, NXP threw up its hands - who could have imagined anyone would use our product against the label?
What is especially interesting is that an unnamed European country has placed troops at facilities that were supposedly secured by MiFare RFID locks; it's a real HALTING STATE moment. Time to break out the sealed bags of PAYG mobiles and bottled water, start the alerting tree, and move to your crashout location. (I know civil servants who actually did draw new mobiles, on BT Cellnet as was, for the millenium weekend.)
Of course, as the pesky student points out, it's an inherent weakness of RFID that it's, well, radio frequency identification; everything is public, so if the crypto doesn't work, the whole system becomes a menace.
Update: The mighty Bruce Schneier has much more. The cards are the ones used in the Tube.
What is especially interesting is that an unnamed European country has placed troops at facilities that were supposedly secured by MiFare RFID locks; it's a real HALTING STATE moment. Time to break out the sealed bags of PAYG mobiles and bottled water, start the alerting tree, and move to your crashout location. (I know civil servants who actually did draw new mobiles, on BT Cellnet as was, for the millenium weekend.)
Of course, as the pesky student points out, it's an inherent weakness of RFID that it's, well, radio frequency identification; everything is public, so if the crypto doesn't work, the whole system becomes a menace.
Update: The mighty Bruce Schneier has much more. The cards are the ones used in the Tube.
Labels:
architecture,
biometrics,
computer,
electronics,
GSM,
hacker,
ID,
surveillance,
updated
Tuesday, March 11, 2008
What next, ponies?
So they arrested Viktor Bout, in the same week the ID cards scheme saw its latest rightward slither and the government's ragingly impossible road-pricing scheme bit the dust. And I cleared my to-do list on our report on new forms of voice and messaging. What next, it rains ponies? as PZ Myers said. Something like that; the whole affair drove traffic on the original TYR to our first-ever four figure days (Friday and Saturday), mostly coming from a distributed googlewave, with some special features (Portuguese anti-Semitism BBSs! Something called Bourque kicking out hundreds of referrals).
I celebrated, of course, by spending part of my weekend changing Linux distro from Mandriva to OpenSUSE, and doing a book splurge; on the principle that I ought to actually read some of my fellow bloggers' work, I bought Charlie Stross's Jennifer Morgue and Halting State, and Ken MacLeod's Execution Channel. This may have been the geekiest weekend ever. But there's more; commenter EJH has forced me to finish my project for a geo-tagged RSS feed of dodgy aircraft movements, by inviting me to present it at OpenTech 2008. So today saw me off with my first-ever regular expression; sorting out different formats for time variables provided by other people is genuinely annoying.
Strangely, I still feel like I've got a million things to do; a sort of work hangover.
I celebrated, of course, by spending part of my weekend changing Linux distro from Mandriva to OpenSUSE, and doing a book splurge; on the principle that I ought to actually read some of my fellow bloggers' work, I bought Charlie Stross's Jennifer Morgue and Halting State, and Ken MacLeod's Execution Channel. This may have been the geekiest weekend ever. But there's more; commenter EJH has forced me to finish my project for a geo-tagged RSS feed of dodgy aircraft movements, by inviting me to present it at OpenTech 2008. So today saw me off with my first-ever regular expression; sorting out different formats for time variables provided by other people is genuinely annoying.
Strangely, I still feel like I've got a million things to do; a sort of work hangover.
Monday, November 05, 2007
Well, it went through!
In Texas, a man suspected of homicide has escaped from prison. How he did it tells us something about the inevitable failure of ID cards, and the importance of false positives. Via Bruce Schneier.
What happened? Well, the suspected killer was in a cell with another remand prisoner, a car thief named Garcia. He memorised Garcia's prison number and other details, and when someone stood bail for Garcia, he answered the jailers with Garcia's name and number. They took him instead of Garcia. When they took his fingerprints, they were smudged and judged useless (one wonders if this was deliberate), so they decided to check him against their spanking new biometric database.
When his fingers were scanned, the DB actually worked perfectly, which was precisely the worst thing that could have happened; up came the file, with a large photograph of the man who was standing before them, so they released him. The problem here is that the system had taught its users that if nothing weird happened, they were right. This is a common problem in user interface design; if you depend on throwing an alert box to stop something weird from happening, you better not throw too many others, or your users will be conditioned to hit Ctrl+W or Alt+F4 as a reflex.
Of course, the notion that if "it goes through", everything is OK is deeply embedded in the computer experience. As a rule, if there is a problem you experience it as the computer throwing an error message or crashing; programming, you hack away, compile, and it either compiles, in which case you run the thing, or there is a compiler error, in which case you go back to the drawing board. And if it doesn't run or does something weird or throws an error message, you go back to the drawing board. Silence is consent in computing.
What the Texan warders were really checking was the absence of an error message, not the fingerprint; further, the system design contained a major flaw in that the error condition looked OK. You check the fingerprint, and up comes a photo of the guy who's standing in front of you, which is what you would expect; the alternative condition would be very unlikely. What the system should have done was to ask for the prisoner's name and number, then check the fingerprint file, and throw a great big red-flashing alarm if the names didn't match. Its function here was authentication; is this man the same man who's been bailed? But it was designed for identification; which database record matches this chap?
What happened? Well, the suspected killer was in a cell with another remand prisoner, a car thief named Garcia. He memorised Garcia's prison number and other details, and when someone stood bail for Garcia, he answered the jailers with Garcia's name and number. They took him instead of Garcia. When they took his fingerprints, they were smudged and judged useless (one wonders if this was deliberate), so they decided to check him against their spanking new biometric database.
When his fingers were scanned, the DB actually worked perfectly, which was precisely the worst thing that could have happened; up came the file, with a large photograph of the man who was standing before them, so they released him. The problem here is that the system had taught its users that if nothing weird happened, they were right. This is a common problem in user interface design; if you depend on throwing an alert box to stop something weird from happening, you better not throw too many others, or your users will be conditioned to hit Ctrl+W or Alt+F4 as a reflex.
Of course, the notion that if "it goes through", everything is OK is deeply embedded in the computer experience. As a rule, if there is a problem you experience it as the computer throwing an error message or crashing; programming, you hack away, compile, and it either compiles, in which case you run the thing, or there is a compiler error, in which case you go back to the drawing board. And if it doesn't run or does something weird or throws an error message, you go back to the drawing board. Silence is consent in computing.
What the Texan warders were really checking was the absence of an error message, not the fingerprint; further, the system design contained a major flaw in that the error condition looked OK. You check the fingerprint, and up comes a photo of the guy who's standing in front of you, which is what you would expect; the alternative condition would be very unlikely. What the system should have done was to ask for the prisoner's name and number, then check the fingerprint file, and throw a great big red-flashing alarm if the names didn't match. Its function here was authentication; is this man the same man who's been bailed? But it was designed for identification; which database record matches this chap?
Sunday, September 02, 2007
Biometrics Are Secure!
Except when they're from Sony, of course. Sony, the company that offers you peace of mind; you *know* who hacked your stuff! I can't think of anything particularly intelligent to say about this except that it's bloody obvious something like this would happen. Recalling the original Sony rootkit, didn't someone very quickly demonstrate it was possible to get access to it over the WAN?
Sunday, July 15, 2007
CCTV Face Recognition: Not Just Evil, Useless Too
The German Bundeskriminalamt (Federal Crime Agency, BKA) recently decided to try out one of those face recognition programs on CCTV cameras placed in a railway station in the city of Mainz. And what happened? Well, having installed the software in October last year, they recruited 200 regular travellers as volunteers, whose faces were recorded in the database.
And the three systems tested successfully identified them 30 per cent of the time on average, with a best result of 60 per cent. Wonderfully, the results were best in the middle of the day - to put it another way, when there were fewest travellers. In the morning or evening, exactly when most of the 23,000 passengers on an average day were on the move, the results were as low as 10 per cent. The hit rate on moving targets was 5-15 per cent lower across the board.
Says the head of the BKA, Jörg Ziercke, "I won't reach the goal of preventing anything with such a low hit rate." He gave a figure of "near 100 per cent" as a minimum, and said he would advise the Minister of the Interior against such systems. The installation in Mainz has apparently been shut down.
The effectiveness of these and similar techniques is something of a bitter question. Since the CCTV boom of the 90s, several British jurisdictions have experimented with recognition. Famously, the system in the London Borough of Newham was exposed as never having caught anyone, and failed a challenge to spot a Guardian reporter even though his presence was announced in advance. Heathrow Airport also employed a system. Results are difficult to come by.
But the Home Office's closed-door trial of various biometric identification methods does give us some data. Their face-recognition software apparently failed in 30 per cent of cases; terrible enough, given the numbers of people the national ID card scheme is meant to process. But it seems to have been dramatically and suspiciously better than the German one - probably just an artefact of its being done under lab conditions rather than in the wild.
It can't possibly work, because biometrics don't scale.
And the three systems tested successfully identified them 30 per cent of the time on average, with a best result of 60 per cent. Wonderfully, the results were best in the middle of the day - to put it another way, when there were fewest travellers. In the morning or evening, exactly when most of the 23,000 passengers on an average day were on the move, the results were as low as 10 per cent. The hit rate on moving targets was 5-15 per cent lower across the board.
Says the head of the BKA, Jörg Ziercke, "I won't reach the goal of preventing anything with such a low hit rate." He gave a figure of "near 100 per cent" as a minimum, and said he would advise the Minister of the Interior against such systems. The installation in Mainz has apparently been shut down.
The effectiveness of these and similar techniques is something of a bitter question. Since the CCTV boom of the 90s, several British jurisdictions have experimented with recognition. Famously, the system in the London Borough of Newham was exposed as never having caught anyone, and failed a challenge to spot a Guardian reporter even though his presence was announced in advance. Heathrow Airport also employed a system. Results are difficult to come by.
But the Home Office's closed-door trial of various biometric identification methods does give us some data. Their face-recognition software apparently failed in 30 per cent of cases; terrible enough, given the numbers of people the national ID card scheme is meant to process. But it seems to have been dramatically and suspiciously better than the German one - probably just an artefact of its being done under lab conditions rather than in the wild.
It can't possibly work, because biometrics don't scale.
Subscribe to:
Posts (Atom)