Cods and chips

banning cryptography didn’t stop the bad guys (i.e., us) when they had cod, it’s not going to stop them now they have chips

British Trawler Coventry City passes Icelandic Coast Guard vessel Albert off the Westfjords in 1958 during the 1st Cod War.

Given British Prime Minister Theresa May’s remarks about the “internet giants” allowing safe harbour for terrorists and the British Home Secretary Amber Rudd’s remarks about needing the ability to access terrorist communications, there is a debate raging between technologists who understand encryption and politicians who don’t. So I thought I’d try to help both of them to communicate more effectively by updating something I wrote back in 2008 to explain the issue.

I used the “Cod Wars” between Britain and Iceland as a backdrop. It is diverting to remember those Cod Wars and the key contribution of the Icelandic people to the story of cryptography. I was reminded of that story when I read a splendid book by Mark Kurlansky called “Cod: Biography of the fish that changed the world“. Within its pages it a lovely story of the neverending struggle between security and new technology.

The Anglo-Danish Convention of 1901 gave the British permission to fish up to three miles from the coast of Iceland, a state of affairs that the volcanic colony was most unhappy about. By the late 1920s, the Icelandic Coast Guard had started to arrest British (and German) trawlers found within what it saw as its territorial waters. However, the British trawlers got smart and got harder to catch because from 1928, they were equipped with radio and started passing coded messages between themselves to alert each other when Coast Guard vessels were in and out of harbour. “Grandmother is well” meant that the Coast Guard were in port, for example.

In an early example of governments attempting to legislate new communications technology, the plucky Icelanders made it illegal send coded wireless messages. This had no impact whatsoever, of course: British seafood companies simply devised new code systems for the trawlers to use. Think about it: how on Earth would an Icelandic wireless operator know whether “Tottenham Hotspur are the pride of North London” was a coded message or gibberish?

Then came World War II. Iceland got independence from Denmark in 1944, by which time the British trawlers had been requisitioned for the war effort, so Iceland found itself with the only fishing fleet in Northern Europe and Britain’s “sole” supplier (tee hee).

Things were quiet for a while, until the First Cod War in 1958 when the might of the Royal Navy was deployed against the Icelanders. Then, in 1972, the Second Cod War started. Iceland extended its territorial waters to 50 miles and the British once again sent the fleet. But in the intervening period, the Icelanders had developed and deployed a secret weapon (literally: it was a closely-guarded secret until first use). The Icelandic Navy could never outgun the British Navy (and in any case didn’t want to actually shoot at us) so they assembled a fiendish alternative: a net cutter. When they found a British trawler, they would sail behind dragging a net cutter and the trawler’s net (worth a lot of money) would head for Davy Jones locker while the fish made for the underwater hills.

(Things did turn nasty — with ships getting rammed and live shells being fired, the Icelandic government refused to allow injured British seamen treatment — until eventually NATO made Britain back down.)

The moral of the story is that, as they used to say over at the EFF, when cryptography is outlawed, only outlaws use cryptography. The Icelandic ships couldn’t use coded wireless transmissions, but the bad guys (in this instance, us) ignored the law and were able to operate successfully beyond it. What defeated us was intelligence and economics, not the ban on coded wireless transmissions.

Making our messages open to access by the government, however well-meaning the protagonists, makes our messages open to terrorists as well. When the secret key code or backdoor code or whatever is eventally leaked on the Internet then we’re all screwed. It’s a difficult issue, I’ll admit, but on balance it’s better that the terrorists can’t read police e-mails even if that mean the police can’t read the terrorists e-mails. Of course, if I start sending a lot of WhatsApp messages to a cave in the Bora Bora mountains, then I would have thought that that might engender additional scrutiny from the security services whether they can read the messages or not.

‘The Internet Is Broken’: @ev Is Trying to Salvage It – The New York Times

xxx

“Say you’re driving down the road and see a car crash. Of course you look. Everyone looks. The internet interprets behavior like this to mean everyone is asking for car crashes, so it tries to supply them.”

‘The Internet Is Broken’: @ev Is Trying to Salvage It – The New York Times

xxx

Land grab: Governments may be big backers of the blockchain | The Economist

xxx

“While the blockchain originally sought a foothold in financial services, and digital currencies attracted early attention from investors, now interest in using the technology in the public sector is growing.”

Land grab: Governments may be big backers of the blockchain | The Economist

xxx

Trump administration rolls out social media vetting of visa applicants | Ars Technica

xxx

“In all, applicants that the government deems suspicious would be required to disclose (PDF) their previous passport numbers, five years of social media handles, telephone numbers, and e-mail addresses.”

Trump administration rolls out social media vetting of visa applicants | Ars Technica

How will the US government know that the Lord Tantamount Horseposture who kept posting abuse about the Chancellor of the Exchequer in The Daily Telegraph is actually me? Conversely, how will they know I was joking when I told Watson that I wanted overthrow the US government and replace it with a workers and peasants’ collective? Surely any sane terrorist will maintain a social media account with pictures that will go down well at US immigration?

If they ask to disclose social media handles, 

A holistic approach to future-proofing the financial system

Nobuchika Mori, Commissioner of Japan’s Financial Service Agency, writing in the Financial Times in May 2017, called for a fundamental change in the way that regulators relate to financial services marketplaces. He says that…

Regulators have made the global financial system more resilient by major regulatory reforms… But all this should not be the end of the story. It is now time to shift the focus from regulation to supervision.

From A holistic approach to future-proofing the financial system

I would rephrase this slightly, in the language of big data and blockchain, always-on digital identities and roboadvisors, to call for an era of shared ledgers, translucent transactions and ambient accountability, in which the traditional boundaries around accounting and auditing dissolve to form a new way to manage markets to the benefit of society.

This new era is what I have labelled the era of “the glass bank”. I’ve written before about the origins of this concept and the way in which it came to crystallise my thinking around the response to the Great Financial Crisis (GFC). Central to my thinking is the

In his magnificent “Fraud: An American History from Barnum to Madoff”, Professor Edward Balleisen (associate professor of history at Duke University) talks about the way in which the notion of transparency in accounting formed a fundamental response to the frauds of the modern age and an enabler for the steady shift from the centuries-old age of caveat emptor to the modern age of caveat venditor. 

Ambient accountability is the logical next step.

 

 

 

from 

Kenyan Telecom Giant Safaricom Planning to Expand M-Pesa Services across Africa – Face2face Africa

xxx

Kenya’s telecommunications giant Safaricom has announced its plan to expand its mobile money transfer services, M-Pesa, to other African countries after a successful transfer of its 35 percent stake to Vodacom, a South African subsidiary of UK’s telecommunications company Vodafone Group.

From Kenyan Telecom Giant Safaricom Planning to Expand M-Pesa Services across Africa – Face2face Africa

xxx

POST China’s SCA (PSD too!)

Some years ago I wrote an article pointing out that NFC ought to be safer than QR codes because NFC included a standard for digitally-signing tags (although I did also note that no-one used it) whereas anyone could easily create bogus QR codes.vI said at the time that you could “imagine a situation in which a powerful player like Apple, using Passbook, forces a scheme for digitally-signing QR codes and sets up a structure for key and certificate management”. I also suggested, in connection with a couple of projects that my colleagues were working on at the time, that mobile operators do the same, at least until NFC inevitable replaced QR.

While I have no inside information on the subject, I do expect a future iPhone (and, for that matter, iPad) to have NFC. NFC is a convenience technology, and Apple loves convenience

From Quick response | Consult Hyperion

 

I also noted that some surveys showed NFC generated better results for merchants, but only once consumers could get it working. As Osama Bedier, then head of Google Wallet, pointed out, this is was some barrier because of the amount of “futz” it took to get NFC working. Well, only a few years later iPhones do indeed have NFC but QR is everywhere. QR codes became popular precisely because any app could read them, precisely because anyone can use them, precisely because there is no security infrastructure, precisely because there is no futz. The result in China, where there was little card infrastructure in place beforehand, was the near-ubiquity of QR in the world’s biggest mobile payments market.

“Ogilvy & Maher and Ipsos concluded in a survey of China’s mobile payment market that ‘[Chinese] mobile payment has permeated all aspects of life and changed basic, everyday habits.’”

From “How Chinese Mobile Payments Are Quietly Conquering the World”.

It seemed to me that thought fraud would be an inevitable consequence of the QR-centric approach, and so it turned out. Last year I read in the South China Morning Post that in March 2017 some 90m Yuan were stolen via QR code scams in Guangdong alone (a suspect in one case was found to have replaced merchants legitimate bar codes with fake ones that embedded a virus to steal personal information) and that in China, a quarter of viruses and trojans were coming in via QR.

Now, while even the man who invented QR codes says that they are an interim technology,  there’s no denying that they are here to stay. Hence it makes sense to find a way to make them more secure, and the obvious way to do this is two-factor authentication (2FA). It turns out that the Chinese regulators have come to the same conclusion and have implemented the equivalent of the European Union (EU) Second Payment Services Directive (PSD2) Regulatory Technical* Standards** (RTS) on Secure Customer Authentication (SCA).

“Under new rules released by the People’s Bank of China [in December 2017], all transactions over 500 yuan (US$76) will be subject to additional levels of verification. As the transaction value passes each trigger point – 1,000 yuan, 5,000 yuan and unlimited – so the security checks will increase.”

From “China’s central bank tightens security in US$5.5 trillion QR code payment services | South China Morning Post”.

 

This makes obvious sense. Just as in the UK we have contactless for low-value payments but 2FA for higher-value payments (ie, chip and PIN for cards or CDCVM for mobile), so QR will be used for low-value payments but 2FA will be required for higher-value payments. Of course, in the Chinese system, QR works just as well on-line as in-person whereas in our system we don’t use chip and PIN online (but should do – ApplePay in-browser is easy and safe) so we still have some way to go to catch up with leading edge of fintech.

* Not “technical” in the sense that you or I would mean it.

** Not “standards” in the sense that you or I would mean it.

‘It’s the worst place to park in the world’ – why Britain is at war over parking | World news | The Guardian

xxx

The UK’s largest cashless parking service, RingGo, purports to process more than 2 million parking sessions every month, and has been used by more than 6 million individual motorists.

From ‘It’s the worst place to park in the world’ – why Britain is at war over parking | World news | The Guardian

xxx

Bank of America preps data sharing service

xxx

Bank of America says it is working with multiple financial data aggregators to provide customers with the ability to connect data from their accounts to third-party financial management applications. The US bank is following in the footsteps of Chase, Wells Fargo and Capital One, each of which has enabled data exchange deals with the likes of Intuit, Xero and Finicty… The bank bills the effort as a key plank in its API strategy, in which data will be shared using a unique token that removes usernames and passwords from circulation.

From Bank of America preps data sharing service

xxx

Design a site like this with WordPress.com
Get started