Skip to main content

Cyberwar, digital identity and banks

In my keynote speech at KnowID 2019 in Las Vegas, I said that we needed think about the big picture around digital identity. I said that digital identity should be seen as a fundamental defence in the cyberwar that we are already in and that has no imaginable end. It’s possible that some of the people in the audience felt that I was being hyperbolic and that this piece of conference rhetoric was for entertainment purposes only. In which case I must refer them to the recent comments of General Sir Nick Carter, Britain's Chief of the Defence Staff, who said that our nation is “at war every day” due to constant cyberattacks. Even more interestingly, he then went on to say in the modern world there is no longer a distinction between war and peace (my emphasis).

This is precisely as the great media theorist Marshall McLuhan predicted. Indeed, I quoted him in my speech. In Culture is our Business, written nearly 50 years ago, he said that “World War III is a guerrilla information war with no division between military and civilian participation”. This is why we need to take digital identity seriously, as strategic infrastructure and as matter of national urgency. It’s not about making it easier for people to log in to The Daily Telegraph or Woking Council, although that should surely be a by-product of a well-designed system, it’s about keeping our people, our institutions and our democracy safe.

(I saw Paul Chichester, the Director of Operations at the UK National Cyber Security Centre, speaking about this at the P20 conference in London. In addition to telling the delegates that “cybercrime paid for that North Korean submarine launch”, he observed that it is the centenary of the Government Communications Headquarters (GCHQ) and that they have special exhibition about this over at the Science Museum. I’m really looking forward taking at look at this when I’m in London next!)

So what should we do?

I don’t think the answer for us it to build a centralised identity service (such as Aadhar in India) or a centralised reputation management system (such as China’s social credit score). I think we need to think about more sophisticated and more flexible federated options. I think we should start building an identity infrastructure for the modern world and that we should probably start with the banks. Citi put out a paper about this last month: it’s called “The Age of Consent” and it discusses the idea of a federated financial sector solution, something along the line of the Scandinavian bank ID services. (I contributed to the paper.)

You can see the author, Tony McLaughlin of Citi, talking about it here on Finextra TV saying that “if we fix digital identity, we fix payments”, and he’s got a point. Banks have an obvious and significant interest in creating the new infrastructure because it’s good for banks. But it’s also good for everyone else, so it’s not only a way for banks to save money, it’s also a way for banks to create new products and services that mean new revenue streams. In fact, it could be that digital identity is not simply an additional revenue stream in the future but that identity is bigger than payments to banks. You can watch Alessandro Baroni, CMO of equensWorldline, saying just this today on another Finextra TV interview.

In the UK, it is time for the regulators to demand action from the banks. When I was last asked to log in to a web site to buy something (last weekend) I was presented with the option to “Log in with Amazon” but no option to “Log in with your safe and trusted bank digital identity that is part of a regulatory framework designed to protect you and comes with expectations of redress, ombudsman, accountability and, ultimately, a physical presence to resolve issues”. Why not?

Comments

Popular posts from this blog

We could fix mobile security, you know. We don't, but we could

Earlier in the week I blogged about mobile banking security , and I said that in design terms it is best to assume that the internet is in the hands of your enemies. In case you think I was exaggerating… The thieves also provided “free” wireless connections in public places to secretly mine users’ personal information. From Gone in minutes: Chinese cybertheft gangs mine smartphones for bank card data | South China Morning Post Personally, I always use an SSL VPN when connected by wifi (even at home!) but I doubt that most people would ever go to this trouble or take the time to configure a VPN and such like. Anyway, the point is that the internet isn’t secure. And actually SMS isn’t much better, which is why it shouldn’t really be used for securing anything as important as home banking. The report also described how gangs stole mobile security codes – which banks automatically send to card holders’ registered mobile phones to verify online transactions – by using either a Trojan...