<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Xebec Studios</title><description>Mike Kiser on identity: who you are, who gets to say so, and what it costs. Technology, history and philosophy.</description><link>https://xebecstudios.org/</link><language>en-us</language><item><title>The Death of Authenticity</title><link>https://xebecstudios.org/death-of-authenticity/</link><guid isPermaLink="true">https://xebecstudios.org/death-of-authenticity/</guid><description>Authenticity is being undermined, and not just by technology.</description><pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;We live in an age that values authenticity: being true to who you are and what you value. It is ironic, then, that one of the more recent innovations of the past few years—Large Language Models, or Generative AI—is in the process of undermining authenticity itself.&lt;/p&gt;
&lt;h1 id=&quot;human-authorship-technology-editorship&quot;&gt;Human Authorship, Technology Editorship&lt;/h1&gt;
&lt;p&gt;Hold on just a minute or two, you may be saying to yourself: “We’ve long used innovation as an assistive tool!” This is certainly true; we’ve grown accustomed to using technology to assist with a variegated selection of activities that no one thinks twice about. As we perform these activities, though, the technology is assisting the human.&lt;/p&gt;
&lt;p&gt;Take assistive writing features of modern word processing products: the human produces the content, and the program corrects spelling and ensures that the sentences are well-formed and comply with known grammars. In this process, the technology performs the editing function: copy editing and some level of line editing. To put it succinctly, the human is the author, and the technology is the editor.&lt;/p&gt;
&lt;p&gt;The recent wave of generative AI reverses those roles: the human prompts the system to generate content, and then edits it to fit purpose. &lt;em&gt;The AI becomes the author, and the human is relegated to the role of editor.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This exchange of roles then leads to all sorts ethical issues around authenticity: humans are tempted to continue to claim authorship of the generated material. This creates ethical issues as they claim work that is not their own.&lt;/p&gt;
&lt;h1 id=&quot;inauthenticity-in-academia&quot;&gt;Inauthenticity in Academia&lt;/h1&gt;
&lt;p&gt;Academia is largely concerned with truth—what is authentic. Generative AI is undermining that by providing students with questionable content. Since LLMs are creating texts with “what’s likely to be next,” they can create plausible-sounding sources and data that is the opposite of truth. When prompted for sourcing, generative AI has produced plausible citations out of thin air. Universities and other school systems will need to be able to further educate students about the dangers of thinking that if a document reads well and appears substantiated that it must be true—they must safeguard what is authentic, what is true.&lt;/p&gt;
&lt;p&gt;In addition, another challenge for authenticity is created by generative AI: the ability to generate well-written papers by outsourcing the task to AI is now prevalent in higher education settings. Multiple universities have forced students to go back to in-person written or oral exams to ensure that the knowledge and written materials are, indeed, generated by the student rather than an online tool.&lt;/p&gt;
&lt;p&gt;Historically, identifying this kind of synthetic generation of material was fairly straightforward, with online tools to detect plagiarism and paper reuse. With the rise of generative AI, this check has becmoe much more difficult. OpenAI and others have been working on watermarking generated content, but it is a work in progress (with adversarial approaches to thwart any safeguards already surfacing.) One professor attempted to use ChatGPT to inform on potential users of the solution in his class, resulting in the entire class being accused of cheating (inaccurately, of course.)&lt;/p&gt;
&lt;h1 id=&quot;inauthenticity-in-the-creation-art-and-writing&quot;&gt;Inauthenticity in the Creation Art and Writing&lt;/h1&gt;
&lt;p&gt;If academia presents a clear delineation of right and wrong in exams and classwork, the world outside of academic institutions presents an ethical quagmire when it comes to generated content.&lt;/p&gt;
&lt;p&gt;For example, ghostwriting (by humans) has been a practice for centuries. At times, it’s an open secret that someone’s book or other content is actually written by a third party (and even at times the receive attribution); in other instances, the lines of authorship are not nearly as clear. Ghostwriting, though, is governed by contract law: the &lt;em&gt;true&lt;/em&gt; author has intellectual property rights over the content that they create, which they then sell to the &lt;em&gt;public&lt;/em&gt; author of the piece.&lt;/p&gt;
&lt;p&gt;With the use of generative AI, that contractural line may become blurred: who owns the rights to the generated content? Is it the AI system? Or the “prompter” of the system? Or might it be the creator of the content that the AI system drew from? (see the ongoing Getty images lawsuit as an example of this) &lt;a href=&quot;https://www.theverge.com/2023/2/6/23587393/ai-art-copyright-lawsuit-getty-images-stable-diffusion?ref=mikekiser.org&quot;&gt;https://www.theverge.com/2023/2/6/23587393/ai-art-copyright-lawsuit-getty-images-stable-diffusion&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There are no easy solutions to these situations; the level of content, the forum for which it was produced, the perceived benefit of claiming authorship, and a host of other factors speak to the ethics of claiming authorship in these cases. A New York Times best selling book is a different prospect than creating content for a low-slung personal blog, but the ethical concerns remain the same.&lt;/p&gt;
&lt;p&gt;The core truth is that with generative AI, the AI system steps forward as the author of the artwork or the written creation, while the human user steps back into the role of editor.&lt;/p&gt;
&lt;h1 id=&quot;safeguarding-authenticity&quot;&gt;Safeguarding Authenticity&lt;/h1&gt;
&lt;p&gt;Flipping these roles of author and editor erodes authenticity of any created material, and presents a series of ethical questions that must be asked. Going forward, how can we ensure that knowledge demonstrated from created material actually originates with a human and not generative AI? How can we trust or prove that someone was the creator of a particular document or piece of art? How can we—or should we—credit the AI systems we use with the proper attribution of role?&lt;/p&gt;
&lt;p&gt;Ultimately, how we guard against the temptation to claim authorship of these creations—when we are merely their editors—will either continue to erode authenticity and truth in our society, or safeguard it for future generations.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://mikekiser.org/its-not-fair-detecting-algorithmic-bias-with-open-source-tools/&quot;&gt;&lt;/a&gt;&lt;/p&gt;</content:encoded><category>Philosophy</category></item><item><title>Shared Signals, and Thanks for All the Fish</title><link>https://xebecstudios.org/shared-signals-and-thanks-for-all-the-fish/</link><guid isPermaLink="true">https://xebecstudios.org/shared-signals-and-thanks-for-all-the-fish/</guid><description>Fifteen species of dolphin fish cooperatively with people. An argument for security systems that tell each other what they see.</description><pubDate>Fri, 13 Dec 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;em&gt;“In fact there was only one species on the planet more intelligent than dolphins[1]” - Douglas Adams, Hitchhiker’s Guide to the Galaxy&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Identity security could learn a lot from dolphins—not only are they smart, but they’re playful, energetic, and creative. But one characteristic stands out above the rest: dolphins are &lt;em&gt;cooperative.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Throughout the world, there are no fewer than fifteen different dolphin species that cooperate with humans, fishing together for mutual benefit. &lt;a href=&quot;https://www.pnas.org/doi/full/10.1073/pnas.2207739120&quot;&gt;A recent study&lt;/a&gt; of one such species, tursiops truncatus gephyreus, describes how this relationship works:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/image&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;The dolphins identify the school of mullet and drive them towards the fishers onshore who are waiting with nets.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/image&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;Once the mullet is in range of the nets, the dolphins give a signal to the fishers—a deep, sudden dive that enables them to cast their nets at exactly the right time.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/image&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/image&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;As the nets haul in their catch, the dolphins zoom in and take a few fish for themselves.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/image&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;This is a mutually beneficial arrangement: the people catch more fish, and the dolphins not only get a quick meal, but they survive longer because they’re not caught up in other fishing mechanisms. It’s a win-win situation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How Shared Signals relates to Dolphins&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Why am I so fascinated by dolphins, you ask? Because it’s the perfect analogy for what we’re trying to do in the Shared Signals Working Group in the OpenID Foundation.&lt;/p&gt;
&lt;p&gt;For far too long, identity has operated in isolation. Vendors often attempt to claim that they are the only provider of information and control for an organization: “Just buy our product, and we’ll solve every problem you ever have.”&lt;/p&gt;
&lt;p&gt;In reality, though, identity is much better served by a network of informed components, sharing what they know with other pieces of the architecture in real-time. As each part of an enterprise discovers something about an identity and its context—for example, that an identity is now compromised, or that the access granted to an identity is now different because of a change to its underlying attributes, or the risk level of an identity rises dramatically because the device that the identity normally uses is no longer in compliance with organizational policy—that information can now be communicated &lt;em&gt;in a standardized way&lt;/em&gt; to all the other parts of the enterprise that might want to take action as a result.&lt;/p&gt;
&lt;p&gt;This kind of event-based communication is just like the signal that the dolphins send to the fishers: “Hey, the fish are coming. You probably want to throw your nets.” Note that the dolphins can’t force the fishers to do anything—they receive the signal, and then decide whether or not to throw their nets. The Shared Signals Framework grants that volition to the receivers of signals—they get to choose what to (or not to) do, with their choice now informed by this new, real-time information.&lt;/p&gt;
&lt;p&gt;We see a real future for standards that encourage cooperation and information sharing such as the Shared Signals Framework (SSF) and the various event types that use SSF as a transport layer: the Continuous Access Evaluation Protocol, Risk Incident Sharing and Coordination, and, soon, SCIM Events. &lt;em&gt;(Full disclosure, I’m a co-author on the SCIM Events standard within the IETF—a future post will describe the potential of event-based SCIM on identity architectures.)&lt;/em&gt; Mechanisms such as SSF provide a path forward for progress on ideals such as zero standing privilege—goals that cannot be realized without components coordinating and acting as a unified whole to secure identity in the enterprise.&lt;/p&gt;
&lt;p&gt;Whether it was the dolphins or the Shared Signals that kept your interest, I do recommend you read the &lt;a href=&quot;https://www.pnas.org/doi/full/10.1073/pnas.2207739120&quot;&gt;scientific paper on cooperative fishing&lt;/a&gt;, or at least watch the &lt;a href=&quot;https://iframe.videodelivery.net/eyJraWQiOiI3YjgzNTg3NDZlNWJmNDM0MjY5YzEwZTYwMDg0ZjViYiIsImFsZyI6IlJTMjU2In0.eyJzdWIiOiIxN2YyNGIxYzEzOGQ4ZWU2OTk4YWMxZDllZjU5MjNiMyIsImV4cCI6MTczMzQ0NTkzNSwia2lkIjoiN2I4MzU4NzQ2ZTViZjQzNDI2OWMxMGU2MDA4NGY1YmIifQ.0YpvtviVF32BnjDGriFlGS6TAk_Dvxq9LB4Kmidt8e60mOrL103DDdJwSN-J4m8mS6bi7YI525mYnG-3v62jKTRclueXyPFniO9zDYq--0Y9GBdlu6qTVbpiuZKlUSE1NQh5zLTy_Vui--RU4rmwBe5a4EpYIT1Y2P6OJEGJkbHZlOyTsVrT9CFeGz6yGdW35Lrer0NXF9_9eljDRE0xCJ1ZEsaXDQK9LlRGLAC42OtZWjVMaScXo8kb2MCVGK2jPzzjhVYwuMvrecvU4trkgt6WMK3t_gcT71ZVfbx5S6DQ-csUmuJpuxpvaiGzMtB_3FLUzbENCz4Ydbqv9MLxyA?poster=https%3A%2F%2Fvideodelivery.net%2FeyJraWQiOiI3YjgzNTg3NDZlNWJmNDM0MjY5YzEwZTYwMDg0ZjViYiIsImFsZyI6IlJTMjU2In0.eyJzdWIiOiIxN2YyNGIxYzEzOGQ4ZWU2OTk4YWMxZDllZjU5MjNiMyIsImV4cCI6MTczMzQ0NTkzNSwia2lkIjoiN2I4MzU4NzQ2ZTViZjQzNDI2OWMxMGU2MDA4NGY1YmIifQ.0YpvtviVF32BnjDGriFlGS6TAk_Dvxq9LB4Kmidt8e60mOrL103DDdJwSN-J4m8mS6bi7YI525mYnG-3v62jKTRclueXyPFniO9zDYq--0Y9GBdlu6qTVbpiuZKlUSE1NQh5zLTy_Vui--RU4rmwBe5a4EpYIT1Y2P6OJEGJkbHZlOyTsVrT9CFeGz6yGdW35Lrer0NXF9_9eljDRE0xCJ1ZEsaXDQK9LlRGLAC42OtZWjVMaScXo8kb2MCVGK2jPzzjhVYwuMvrecvU4trkgt6WMK3t_gcT71ZVfbx5S6DQ-csUmuJpuxpvaiGzMtB_3FLUzbENCz4Ydbqv9MLxyA%2Fthumbnails%2Fthumbnail.jpg%3Ftime%3D10.0s&quot;&gt;remarkable video&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We have a lot to learn from these aquatic mammals: above all, dolphins are smart because they are cooperative, and they are cooperative because they are smart.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;_I’d be remiss if I didn’t provide the entire quote in full about dolphins: ‘It is an important and popular fact that things are not always what they seem. For instance, on the planet Earth, man had always assumed that he was more intelligent than dolphins because he had achieved so much—the wheel, New York, wars and so on—while all the dolphins had ever done was muck about in the water having a good time. But conversely, the dolphins had always believed that they were far more intelligent than man—for precisely the same reasons. Curiously enough, the dolphins had long known of the impending destruction of the planet Earth and had made many attempts to alert mankind to the danger; but most of their communications were misinterpreted as amusing attempts to punch footballs or whistle for tidbits, so they eventually gave up and left the Earth by their own means shortly before the Vogons arrived. The last ever dolphin message was misinterpreted as a surprisingly sophisticated attempt to do a double-backward somersault through a hoop while whistling the “Star-Spangled Banner,” but in fact the message was this: So long and thanks for all the fish.’&lt;/p&gt;
&lt;p&gt;Adams, Douglas. The Ultimate Hitchhiker’s Guide to the Galaxy: Five Novels in One Outrageous Volume (p. 105). Random House Publishing Group. Kindle Edition._&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;</content:encoded><category>Technology</category></item><item><title>It’s Not Fair! Detecting Algorithmic Bias with Open Source Tools</title><link>https://xebecstudios.org/its-not-fair-detecting-algorithmic-bias-with-open-source-tools/</link><guid isPermaLink="true">https://xebecstudios.org/its-not-fair-detecting-algorithmic-bias-with-open-source-tools/</guid><description>Algorithms now shape bail decisions and transplant lists. The open-source tools that make them explainable enough to argue with.</description><pubDate>Fri, 03 Jun 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Wondering what to watch on Netflix tonight?&lt;/p&gt;
&lt;p&gt;&lt;em&gt;There’s an algorithm for that.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Wondering what to buy next on Amazon this afternoon?&lt;/p&gt;
&lt;p&gt;&lt;em&gt;There’s an algorithm for that.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Using algorithms and machine learning to predict future state is commonplace these days. In its best forms, it can direct us into new sources of entertainment or products that can improve our lives. As the use of these algorithms cascade across our society, however, their potential significance increases:&lt;/p&gt;
&lt;p&gt;Wondering who is likely to commit a crime tomorrow? Wondering who should be next in line for a kidney transplant? There’s an algorithm for that, too.&lt;/p&gt;
&lt;p&gt;Over the last decade or so, researchers have discovered inherent biases in many of these algorithms. In 2016, &lt;a href=&quot;https://www.propublica.org/article/machine-bias-risk-assessments-in-criminal-sentencing&quot;&gt;ProPublica reported racial bias in the recidivism algorithm&lt;/a&gt;—a risk assessment used to predict whether a defendant is likely to commit a crime in the future. &lt;a href=&quot;https://www.pennmedicine.org/news/publications-and-special-projects/penn-medicine-magazine/winter-2021/filtering-bias-out-of-kidney-testing&quot;&gt;A more recent study&lt;/a&gt; revealed that the algorithm used to predict renal failure had a similarly undetected bias.&lt;/p&gt;
&lt;p&gt;The flaws in these algorithms does not result in poor entertainment choices, however: they impact sentencing terms and decrease the likelihood of receiving essential medial care. As algorithms become ubiquitous, then, our goal must be to find and ameliorate any potential bias within them—in short, to promote the fairness of the algorithm.&lt;/p&gt;
&lt;p&gt;This is more easily said than done, of course. Bias can be hidden within the algorithm itself, within the data it is drawn on, or introduced in various other forms. Complicating matters further, not every algorithm—particularly when machine learning is used—is easily explainable. This explainability is essential: how can you decide if a system is biased or not if you don’t know why it is selecting a particular result?&lt;/p&gt;
&lt;p&gt;We are therefore presented with two challenges as we use algorithms and machine learning: transparency and fairness. These are formidable tasks, but thankfully there are a set of open-source tools that can help:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Transparency&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Three main tools seek to make machine learning algorithms explainable or transparent: LIME, SHAP, and Google’s What-If tool.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://github.com/marcotcr/lime&quot;&gt;LIME&lt;/a&gt; uses “local model approximation” to reduce the problem set to a subset of instances within the data set. It can then attempt to simplify the explanation for that subset of the data.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://github.com/slundberg/shap%0D%0A&quot;&gt;SHAP&lt;/a&gt; is a method based on a concept of Shapley value in game theory. It does a set of mathematical computations to figure out the contribution of features (as the players) to the outcome of the prediction (or the payout in game theory context).&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://pair-code.github.io/what-if-tool/%0D%0A&quot;&gt;Google’s What-If?&lt;/a&gt; tool is a visualization of the data set and allows the exploration of both data and “what-if” scenarios.&lt;/p&gt;
&lt;p&gt;Along with exploring the trained machine model and allowing examination of both data and conclusions that the model has made, it allows for the examination of “counterfactuals”: you can select a point, as we’ve done here in a sample data set, and check to see why a similar point falls under a different classification.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fairness&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;To seek out bias directly, there are a different set of tools available for use. One of the easiest to use is the &lt;a href=&quot;https://github.com/dssg/aequitas%0D%0A&quot;&gt;Aequitas Fairness Toolkit.&lt;/a&gt; It can be used for in-depth analysis with an available API, or it can be rapidly utilized via a web-based application.&lt;/p&gt;
&lt;p&gt;It results in a report that provides baselines for various groups or populations within the algorithmic model, quantifying whether or not each group is being treated equally and providing metrics such as false positives and negatives.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;RSAC 2022 Session&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you’re interested in hearing more about these tools, discussing how to use them well, or seeing them demonstrated live, &lt;a href=&quot;https://www.rsaconference.com/usa/agenda/session/Its%20Not%20Fair%20Detecting%20Algorithmic%20Bias%20with%20Open%20Source%20Tools&quot;&gt;I’ll be talking about them along with Mo Badawy, Principal Data Scientist at RSAC2022 on June 6th.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Wondering how to eliminate bias from your machine learning algorithm?&lt;/p&gt;
&lt;p&gt;&lt;em&gt;There’s an open-source tool for that.&lt;/em&gt;&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Call Me Mark Jannell: The Future of Bring Your Own Identity</title><link>https://xebecstudios.org/call-me-mark-jannell/</link><guid isPermaLink="true">https://xebecstudios.org/call-me-mark-jannell/</guid><description>An assumed name that stuck for eighteen months, and what it cost when the truth came out. On bringing your own identity.</description><pubDate>Fri, 15 Apr 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;When I was seventeen, I played one of the greatest roles of my life: “Mark Jannell.”&lt;/p&gt;
&lt;p&gt;A younger student who we’ll call “Tim” (not his name, of course) had just started at my high school, and after knowing me for several weeks, asked my name. Amused that he had forgotten it, I vowed not to tell him. I stepped away from the lunch table for a few minutes, and as I headed back, a different friend intercepted me.&lt;/p&gt;
&lt;p&gt;“I’ve told him that your name is Mark Jannell.” In case you missed the byline, that’s not my name. But for the next year and a half, whenever Tim talked to me, he called me Mark. To be honest it was a struggle, answering to “Mark” or “Jannell” for eighteen months. And in the end, even after I told him my real name, he just opted to call me “man” because he didn’t trust me any longer.&lt;/p&gt;
&lt;p&gt;While I’m not proud of this deception (ok, maybe just a little), it surfaces the issues that allowing individuals to “bring their own identity” might present.&lt;/p&gt;
&lt;h2 id=&quot;its-coming-the-blending-of-identities&quot;&gt;It’s coming: The Blending of Identities&lt;/h2&gt;
&lt;p&gt;And make no mistake, a bring your own identity model is coming. In the past few years, our lives have shifted to a digital, online model. Whether we are interacting with our government, being productive in our day job, or interacting socially, it’s increasingly online. The ubiquity of mobile devices and the recent pandemic have combined to accelerate the coalescence of the various arenas of our lives onto a single small screen. And as the distinctions between these different spheres fade, so does the need to maintain disparate identities.&lt;/p&gt;
&lt;p&gt;It rapidly becomes cumbersome to maintain separate identities for each activity, and the privacy implications of handing our entire lives over to a single enterprise or entity have already proven problematic at best. Allowing users to bring their own identity with them — controlling what portion of it is shared in each realm of interaction is emerging as a preferred model.&lt;/p&gt;
&lt;p&gt;But like my interaction with “Tim” portrays, there are concerns around trust and ease-of-use that identity practitioners must contemplate.&lt;/p&gt;
&lt;h2 id=&quot;who-do-you-trust&quot;&gt;Who Do You Trust?&lt;/h2&gt;
&lt;p&gt;Establishing trust is the obvious backbone of any secure identity interaction. Allowing users to bring their own identity does not mean abandoning &lt;a href=&quot;https://www.idsalliance.org/blog/2020/09/11/iam-best-practices-blog-series-the-importance-of-an-authoritative-identity-source/&quot;&gt;authoritative sources of information&lt;/a&gt;. Just as my friend acted as a source of truth about my name, trusted sources still need to exist to establish the original connection.&lt;/p&gt;
&lt;p&gt;Trust, then, in each of these relationships between individuals and organizations must be established, but that trust cannot rely on a central service. To centralize this trust would be to revert back to a central identity provider model, something we’ve already noted we want to avoid for privacy and scale reasons. When individuals bring their own identity, components of that identity will come from variegated source: government might contribute a taxation number, a local entity might verify local residency, social organizations might verify affiliation with relevant organizations. The building up of these relationships will take time and effort; federation has been helpful on this front, but it is more focused on real-time assertions about authentication and access than contributing bricks that can be used to construct an identity.&lt;/p&gt;
&lt;p&gt;This is what “decentralized identity” (also known as Self Sovereign Identity) seeks to facilitate: the establishment of trust with numerous organizations without the creation of scores of separate identities for each relationship. Rather than “decentralized identity,” the concept (as Gartner rightly points out) should be called “reusable identity.” Note that many analysts term this facility for establishing trust an “identity fabric” (KuppingerCole) or an “identity trust fabric” (Gartner).&lt;/p&gt;
&lt;p&gt;Individuals can then initiate their interaction with another person, an organization, or an enterprise by presenting something that the other party trusts. In reality, this is not that different than federation as it exists today, but as a wider, distributed model. It’s important to keep these overarching concepts agnostic in reference to the underlying implementation layer. Many current models use relatively standard blockchain and distributed ledger technology, but others modify the network structure with concepts such as Directed Acyclic Graphs. Regardless of the architecture, the end goal of distributed trust remains.&lt;/p&gt;
&lt;p&gt;As the relationship deepens, the other party trusts the individual and can then “vouch” for them. This happened with my friend Tim, who started introducing me to others as “Mark Jannell.” You can see quickly, however, that misplaced trust or bad claims present a threat to security in this model. Distributed trust means that there will need to be methods of revocation and correction, much like the revocation of certificates does today.&lt;/p&gt;
&lt;p&gt;This kind of system takes time to develop and cannot be done without contemplating another key component: ease of use.&lt;/p&gt;
&lt;h2 id=&quot;is-it-easy&quot;&gt;Is it Easy?&lt;/h2&gt;
&lt;p&gt;While the adoption of a new name was easy, it was nearly impossible to listen for a name in crowded hallways or even in everyday conversations. This made my attempt at method acting sketchy at best—I was constantly in danger of making a mistake and revealing the ruse.&lt;/p&gt;
&lt;p&gt;Allowing users to bring their own identity must be intuitive for end users; if it is difficult to use or understand, they will introduce risk into the organization by taking alternative paths. Steering users into a common path reduces the potential attack surface and protects the fabric of trust that was already established.&lt;/p&gt;
&lt;p&gt;The ubiquity of mobile devices is key for future security models and solutions. A generational shift is underway in which the default interface shifts from a keyboard and a wide screen monitor to a small, touch-operated screen. The computational power of phones has increased rapidly, increasing their potential to meet the demands of advanced cryptography—which will greatly facilitate verification of assertions about identity.&lt;/p&gt;
&lt;p&gt;Future users will not be signing up in a browser, but rather bringing their own identity, stored on their device, via mobile applications or phone-based personal assistants. Identity assertion and verification will be notification driven, lasting a few seconds at most. This kind of design-centered thinking inculcates best security practices in individuals without them actively thinking about it.&lt;/p&gt;
&lt;h2 id=&quot;think-before-you-act&quot;&gt;Think Before You Act&lt;/h2&gt;
&lt;p&gt;My short stint as “Mark Jannell” taught me a lot of about trust and ease of use in a bring your own identity model. Trust, as always in security, is essential to this new class of relationships and must be established and then protected from abuse. Ease of use, it turns out, is a key factor in protecting that trust and promoting the adoption of good identity patterns. I’m sure that I could have learned these lessons in some other way, but I’ll never forget my half year answering to a pseudonym.&lt;/p&gt;
&lt;p&gt;But if we meet at an identity gathering in the future, please just call me “Mike.”&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Now With More Privacy! The Rise of Nutritional Labelling and Customer Choice</title><link>https://xebecstudios.org/privacy-and-nutrional-labeling/</link><guid isPermaLink="true">https://xebecstudios.org/privacy-and-nutrional-labeling/</guid><description>Apple put nutrition labels on apps. A bank printing its own would first have to know what data it holds, and who can reach it.</description><pubDate>Thu, 08 Apr 2021 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;“You are what you eat.” Many a dinner table has heard these words uttered by a parent encouraging their children to make healthy eating choices. At times, these choices are obvious: an apple or a serving of peas has a greater health benefit than a chocolate dessert. When the nutritional value of a particular food is not as clear, then government entities such as the Food Standards Agency steps in to ensure that mandatory nutritional information is included on packaging.&lt;/p&gt;
&lt;p&gt;These “nutritional labels” can guide consumers as to the harm and benefit of that particular foodstuff, responding to their desire to make wise choices.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Nutritional Labels for Financial Applications&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A similar desire is rising among consumers surrounding their privacy. No longer a nice-to-have, application providers such as Apple have begun labelling applications being sold on its platform with the equivalent of a &lt;a href=&quot;https://www.washingtonpost.com/technology/2021/01/29/how-to-read-iphone-privacy-labels/&quot;&gt;nutritional privacy label&lt;/a&gt; as to how that application utilises personal information and the identity of the user. This is welcome addition, and, just like that label on your favourite jar of marmalade, can guide consumers to make wiser choices about their privacy.&lt;/p&gt;
&lt;p&gt;Financial institutions, dependent on retaining the trust of their customers, will do well to identify their use of sensitive data. While nutritional labels may be simple for a food and beverage company (as you create your product, jot down everything that you have placed into the cooking vessel), it is slightly more challenging for the financial industry.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Asking for the Recipe&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;There are questions that these organisations will be forced to ask themselves: What sensitive data have we collected on this particular customer? How is access to that data governed in an appropriate way? How can the organisation prove that privacy is being protected appropriately?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;What Data Exists&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Getting visibility into how the organisation uses identity and identity data is a key element into any coherent security program, particularly in portions of the business that are less structured. While applications and databases may have systematic approaches to securing this sensitive data, vast troves of this data is often lurking in files and other network-based repositories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Who Has Access&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Knowing what data is available is only the first step, of course. If it was known that there were dangerous—or even highly risky—ingredients in a product, the issue would be remedied immediately. The use of sensitive data must be placed under the same scrutiny. Do only the proper people or systems have access to this data? Or is there a dangerous mix of access and personal data that must be addressed?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Is Privacy Protected?&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;When all of the sensitive identity data has been identified and proper controls established around that data, the organisation can actually document and prove that it handles its customers’ privacy properly. Protection of this sort of data is a key element of any coherent identity program.&lt;/p&gt;
&lt;p&gt;The proper treatment of sensitive identity data for customers is not an optional feature, but a core requirement of any solution. With the addition of nutritional labels, consumers concerned about their health will not purchase products that have harmful ingredients. Similarly, the rise of privacy nutrition labelling will equip the public to make wise choices, and they will move to those institutions that transparently protect their privacy by governing identity data well.&lt;/p&gt;
&lt;p&gt;Now pardon me while I finish this plate of chips … er … steamed broccoli.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>The Technical Debt of Facial Recognition</title><link>https://xebecstudios.org/the-technical-debt-of-facial-recognition/</link><guid isPermaLink="true">https://xebecstudios.org/the-technical-debt-of-facial-recognition/</guid><description>The ACM called for a moratorium and three vendors stepped back. Shipping before it works is a debt, and someone else settles it.</description><pubDate>Wed, 11 Nov 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;In June of 2020, the US Technology Policy Committee of the Association for Computing Machinery published a &lt;a href=&quot;https://www.acm.org/binaries/content/assets/public-policy/ustpc-facial-recognition-tech-statement.pdf&quot;&gt;letter&lt;/a&gt; calling for the suspension of “current and future private and governmental use of [facial recognition] technologies in all circumstances known or reasonably foreseeable to be prejudicial to established human and legal rights.”&lt;/p&gt;
&lt;p&gt;The ACM is arguing that facial recognition is not mature enough to be used well, its potential has driven presumptive adoption of the technology, and that its use has compromised privacy and other human rights., They also believe its use should be paused until legal standards for accuracy, transparency, governance, risk management, and accountability can be established.&lt;/p&gt;
&lt;p&gt;This letter follows actions by large enterprises, which have restricted or halted access to facial recognition. In June, IBM announced that it would stop selling “general purpose” facial recognition software, and Amazon and Microsoft soon announced bans on selling facial recognition technology to law enforcement until legislation is passed to govern the technology. Recent headlines have demonstrated how facial recognition systems are perpetuating bias in law enforcement, hiring, and school surveillance. The industry is right to pause the development of this technology while they ponder potential side effects and develop an ethical approach to facial recognition.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Lather, Rinse, Repeat: With a Twist&lt;/strong&gt;&lt;br&gt;
Technology and ethics are often opposing forces. This call for careful deliberation is similar to previous ethical discussions of machine learning models. The letter cites ACM’s earlier statement on algorithmic transparency and accountability as a foundation for this latest round of ethical exploration. Concepts such as transparency and accountability are common in ethical frameworks, but they haven’t historically led to a call for a pause in access to technology.&lt;/p&gt;
&lt;p&gt;Many technologies are difficult to understand or their impacts are hard to gauge. With facial recognition, the opposite is true. News coverage in the past few years has led the public to understand how facial recognition works and to see their perpetuation of cultural bias and discrimination (see &lt;a href=&quot;https://www.ted.com/talks/joy_buolamwini_how_i_m_fighting_bias_in_algorithms?language=en&quot;&gt;Joy Buolamwini’s TEDTalk&lt;/a&gt; and the &lt;a href=&quot;https://www.ajl.org/&quot;&gt;Algorithmic Justice League&lt;/a&gt; for more detail). People are quick to realize the dangers of ubiquitous surveillance, even if they’re not the targets of active discrimination (Thanks, George Orwell!). This understanding of the technology and risks means that facial recognition is having a unique moment; a caesura in the rush to innovate, a unique pause for moral introspection.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Admirable, But Questions Remain&lt;/strong&gt;&lt;br&gt;
This pause is needed. All too often, ethics lags technology. With all apologies to Jeff Goldblum, there’s no need to be hunted by intelligent dinosaurs to realize that we often do things because “we can rather than that we should.” This ACM’s call for restraint is appropriate, although a few issues remain.&lt;/p&gt;
&lt;p&gt;What about the facial data that already exists from currently deployed systems? This is not unique to facial recognition, but rather one that is well known from GDPR compliance and other use cases.&lt;/p&gt;
&lt;p&gt;The stoppage is intended for private and public entities, but personal cameras — and an opening for facial recognition — are rapidly becoming ubiquitous. Log in to your neighborhood watch program for a close-to-home example. (What street doesn’t have a doorbell camera?) Public life is being monitored and passive data on our habits and lives is continually collected; any place that there is a camera, facial recognition technology is in play.&lt;/p&gt;
&lt;p&gt;The call by the ACM could be stronger. They urge the immediate suspension of use of facial recognition technology anywhere that is __“__known or reasonably foreseeable to be prejudicial to established human and legal rights.” What is considered reasonable here? Is good intent enough to absolve misuse of these systems from blame, for instance? The potential harm of these systems — and the repurposing of its data — is often not readily apparent. By the time the bias is observed, the damage has been done. Given the risks and the uncertainty involved, it would be better to remove the call’s dependency on expected harm. The use of facial recognition should be suspended until its ethical impact can be documented and governed properly.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Government Response&lt;/strong&gt;&lt;br&gt;
Governments have taken notice of public concern, of course, and have responded with proposed legislation. Several US cities, including &lt;a href=&quot;https://www.boston.com/news/local-news/2020/06/24/boston-face-recognition-technology-ban&quot;&gt;Boston&lt;/a&gt;, Portland, and &lt;a href=&quot;https://www.nytimes.com/2019/05/14/us/facial-recognition-ban-san-francisco.html&quot;&gt;San Francisco&lt;/a&gt;, have banned the use of the technology. (See: &lt;a href=&quot;https://www.banfacialrecognition.com/map/&quot;&gt;US map of use and bans of facial recognition&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;There is also action on the national level. Currently proposed legislation in the US seeks to &lt;a href=&quot;https://www.congress.gov/bill/116th-congress/senate-bill/847&quot;&gt;govern&lt;/a&gt; or &lt;a href=&quot;https://thehill.com/policy/technology/504583-democratic-lawmakers-introduce-legislation-banning-government-use-of-facial&quot;&gt;declare a moratorium&lt;/a&gt; on facial recognition technology. In Europe, a five-year hiatus on the use of facial recognition in public spaces was proposed last year but was &lt;a href=&quot;https://www.reuters.com/article/us-eu-ai/eu-drops-idea-of-facial-recognition-ban-in-public-areas-paper-idUSKBN1ZS37Q&quot;&gt;subsequently dropped this past January.&lt;/a&gt; These efforts are welcome, but if ethics lags technology, legislation is slower still.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Adversarial Technology&lt;/strong&gt;&lt;br&gt;
Another approach may be useful as well. Recently, researchers have developed “adversarial technology,” using innovation to equip people to defeat location tracking, artificial intelligence, and other components of surveillance systems. These have run the gamut from using &lt;a href=&quot;https://adversarialfashion.com/&quot;&gt;fashion to defeat license plate camera systems&lt;/a&gt; to full on &lt;a href=&quot;https://www.youtube.com/watch?v=U1wb4_bIVbc&quot;&gt;fabrication of fake identities and personas to throw off location and online tracking.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This &lt;a href=&quot;https://www.theverge.com/2020/8/4/21353810/facial-recognition-block-ai-selfie-cloaking-fawkes&quot;&gt;adversarial approach has now been developed for facial recognition as well&lt;/a&gt;, with the most notable being &lt;a href=&quot;http://sandlab.cs.uchicago.edu/fawkes/&quot;&gt;Fawkes,&lt;/a&gt; an open source tool released by researchers from the University of Chicago. Rather than making physical changes to a person’s face, it seeks to mask photographs with slight alterations. Though these changes are not prominent to the human eye, this tricks the facial recognition system into misidentifying the person — cloaking the individual’s true identity. Over time, an increasing set of altered photos is incorporated into the collection of images that facial recognition systems use to catalogue and identify people, polluting its knowledge base and protecting the true identity of the individual.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A Pause for Reflection&lt;/strong&gt;&lt;br&gt;
The ACM is right to call for a suspension in the use of facial recognition to address bias and abuse, but our path towards ethical use of this kind of technology is likely not a straight, clear line. A combination of approaches is necessary to make responsible progress; consistent reporting on surveillance technology, governmental regulation, a sense of corporate responsibility, and adversarial technology all have their role to play. These approaches take time, and the ACM is correct to call for a break to allow these approaches time to develop.&lt;/p&gt;
&lt;p&gt;It’s time to address our ethical debt.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>The Color of 2020</title><link>https://xebecstudios.org/the-color-of-2020/</link><guid isPermaLink="true">https://xebecstudios.org/the-color-of-2020/</guid><description>In the beginning, blue did not exist. In short order, it came to be associated with health, power, and affluence. Will the same soon be said of working from home?</description><pubDate>Thu, 28 May 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;In the beginning, blue did not exist.&lt;/p&gt;
&lt;p&gt;At specific points in history, life shifts: rhythms change, patterns of behavior evolve rapidly, and cultural values reshape themselves. The current global pandemic is one of these societal salients.&lt;/p&gt;
&lt;p&gt;It’s not the first time that this kind of transformation has taken place, of course, and examining a similarly radical revolution can inform how we view the current environment. If the color of the world is indeed changing, then it’s only appropriate that one of the parallels that we examine be the astonishingly rapid rise of the color blue.&lt;/p&gt;
&lt;p&gt;Red, white, and black were the colors of ancient cultures; from &lt;a href=&quot;http://www.visual-arts-cork.com/artist-paints/prehistoric-colour-palette.htm#colours&quot;&gt;cave paintings&lt;/a&gt; to the dyeing of fabrics---blue was more difficult to source, process, and manipulate, and so it remained a second-rate color, especially in the western world.&lt;/p&gt;
&lt;p&gt;The lack of blue in art and clothing meant that blue had little symbolic value; even up until the high Middle Ages, it was not even used for depicting the sky---most artists showed the sky as red, gold, or white. Whereas some colors took on cultural significance because of their widespread usage (the example of a small girl dressed in red, taking a pot of white butter to her grandmother, dressed in black in &lt;a href=&quot;https://sup.sorbonne-universite.fr/catalogue/traditions-et-croyances/formes-et-difformites-medievales&quot;&gt;‘The Little Red Riding-hood’&lt;/a&gt; story comes to mind), blue was nonexistent in terms of meaning.&lt;/p&gt;
&lt;p&gt;All of this, however, changed within a few decades in the 13^th^ century. Artistic expression was driven by development of the &lt;a href=&quot;https://www.smithsonianmag.com/arts-culture/why-colors-you-see-art-museum-cant-be-replicated-today-180953332/&quot;&gt;“Chartres blue”&lt;/a&gt;, a new, brighter, and more luminous blue in glass form, heralded a widespread adoption of the color in stained-glass windows in churches throughout Europe. Advances in clothing production also elevated the status of blue in textiles. A massive increase in production of &lt;a href=&quot;https://en.wikipedia.org/wiki/Isatis_tinctoria&quot;&gt;woad, the raw material used in dyeing fabric blue,&lt;/a&gt; along with the associated rise in demand for the color, led to entire regions such as Languedoc (France) and Thuringia (Germany) becoming wealthy as they specialized in the production of blue and its associated products. By the end of the 13^th^ century, a stable, bright blue cloth was widely available.&lt;/p&gt;
&lt;p&gt;And as blue became more widely available, its semantic impact skyrocketed. Blue embedded itself into religion, as the new color was used to represent the &lt;a href=&quot;https://www.theguardian.com/lifeandstyle/2015/apr/17/colour-blue-rich-divine-ancient-egyptians-virgin-mary&quot;&gt;robes of the Virgin Mary.&lt;/a&gt; It was also incorporated into the heraldry of various important families, and royalty was no exception to this affection for the new color. While the &lt;a href=&quot;https://www.fleurdelis.com/royalcoatofarms.htm&quot;&gt;King of France&lt;/a&gt; was the first to adopt blue into his royal color palette, it was soon in use by the King of England, and later by kings in Germany and Italy.&lt;/p&gt;
&lt;p&gt;In just a few short decades, then, blue went from having no cultural significance to representing some of the highest values of society: the purity of the Virgin, the power and prestige of royalty. The spectrum of meaningful color had expanded in short order, and the world was different as a result.&lt;/p&gt;
&lt;p&gt;The world we live in is currently undergoing a similar seismic change. Previous patterns of working and living have been forcibly modified. One of the most foundational of these movements comes at the hands of “shelter-in-place” orders being enacted in various parts of the world: employees, no matter their industry or profession, are being forced to work from home.&lt;/p&gt;
&lt;p&gt;The concept of working from home is not a novel. With the adoption of mobile devices and the increase in broadband availability both in private and public areas, a small segment of the workforce had already adopted this model. Like the color blue, however, it was a secondary option, and its cultural impact was limited.&lt;/p&gt;
&lt;p&gt;The spectrum of work has now shifted. Shelter in place orders have forced a global workforce to work from home. What had been an alternative mode of work has now become the primary—all within a few short months, if not weeks. Remote work is color of 2020, and it is likely here to stay. Once blue arrived, innovation and investment drove production and created entirely new industries, and the forced adoption of this new mode of work will force a similar chromatic shift. People have a new color in their palette, and the world will be shaded differently.&lt;/p&gt;
&lt;p&gt;In the wake of this transformation, the cultural impact of this shift awaits. In short order, blue came to be associated with health, power, and affluence. Will the same soon be said of working from home?&lt;/p&gt;
&lt;p&gt;Certainly, from a business perspective, the value of this new way of working is already evident, particularly for organizations that have already developed the infrastructure to accommodate a pattern of remote work. This is not merely an installation of IT services such as a VPN, but also requires reconsideration of the established security mindset. While many of them may not have the scale to handle a complete and immediate transition to home-based employees, their transition to this brave new world will be smoother due to their preemptive investment in a revised security strategy.&lt;/p&gt;
&lt;p&gt;This new approach to securing resources deemphasizes perimeter defense and elevates the role of identity. Various systems and names have been introduced (or reintroduced) to facilitate the practical development of these systems; zero trust and CARTA are a few strategies among many that attempt to translate this vision into a practical reality.&lt;/p&gt;
&lt;p&gt;Businesses that have already begun this shift are likely to be less impacted by the maelstrom of change; while none welcome this new reality, organizations well-equipped for this new cultural value will be healthier in both the short and long term. Fewer disruptions in their business and continuity in their economic model will mean that they have a stronger chance of not just surviving, but being in the ascendancy as the crisis transitions into a different, hopefully milder, phase.&lt;/p&gt;
&lt;p&gt;Even organizations with a solid security strategy, however, are subject to market forces. It is possible that the new dominance of remote work will alter the landscape of enterprise. Just as the rapid proliferation of the internet drove some organizations into the stratosphere and left others behind to languish in the “brick and mortar” mindset (the easiest example of this dichotomy is Amazon and local booksellers), working from home at this sort of scale has the potential to divide enterprise into strata of success. As a result, remote work may become semantically linked with health and with power---or their business-speak equivalents “profitable” and “innovative”---similarly to the new connotation blue acquired after it was employed by religion and royalty in the Middle Ages.&lt;/p&gt;
&lt;p&gt;But the more profound potential for the cultural impact of working from home centers around individuals. In just a few short weeks the quarantine has shone a bright light on existing inequalities that are all-too-easily ignored.&lt;/p&gt;
&lt;p&gt;The pandemic is revealing a &lt;a href=&quot;__GHOST_URL__/the-color-of-2020/(https://www.nytimes.com/2020/03/27/business/economy/coronavirus-inequality.html&quot;&gt;caste system,&lt;/a&gt; one of whose demarcation lines is the ability to work from home. This flexibility is primarily dictated by both the availability of reliable broadband access and the specific occupation in question. Rural residents with limited network access, &lt;a href=&quot;https://www.stlouisfed.org/on-the-economy/2020/march/covid-19-workers-highest-unemployment-risk&quot;&gt;or those in specific sectors&lt;/a&gt;: the service industry, shipping and transport, food distributors, and government officials often have no viable option to work from a remote location—to say nothing of the healthcare workers who find themselves thrust to the front line of the pandemic.&lt;/p&gt;
&lt;p&gt;For others, the ability to continue to work while staying home confers a wide range of benefits. The first is obvious: steady employment. With &lt;a href=&quot;https://fivethirtyeight.com/features/this-jobs-report-was-bad-the-next-one-will-be-worse/&quot;&gt;unemployment rapidly escalating&lt;/a&gt;, the pandemic is already having an effect on &lt;a href=&quot;https://www.theguardian.com/world/2020/apr/07/coronavirus-global-leaders-urge-g20-to-tackle-twin-health-and-economic-crises&quot;&gt;economies worldwide&lt;/a&gt;. If working from home means retaining a job, this primary benefit lays the foundation for the others that follow. The second advantage lent by remote work may be a bit more hidden: continued education for their children. &lt;a href=&quot;https://www.forbes.com/sites/unicefusa/2020/03/25/helping-children-adjust-to-remote-learning-during-the-covid-19-pandemic/#71a0877d6a82&quot;&gt;Schools in 130 countries&lt;/a&gt; have closed, disrupting the learning of over 1.2 billion students. The same reliable network access which allows them to continue working also provides for the continued education of their children and puts those pupils at an advantage to their peers. Finally, the most striking benefit that working from home while quarantined bestows is a better health outcome. If the point of stay at home orders is to prevent interaction with outsiders, preventing the spread of COVID-19, then by complying with these guidelines and working from their homes ensures that those individuals and their family are less likely to fall ill.&lt;/p&gt;
&lt;p&gt;These are not minor benefits: affluence, education, and health. And if the pandemic and working from home are revealing an existing caste system, it is also reinforcing it. Those with the ability to work from home are finding their wealth protected, their children keeping pace academically, and their expected health outcomes confirmed.&lt;/p&gt;
&lt;p&gt;After only a few short weeks of stay at home orders, both businesses and individuals are already associating a work from home model and increased health, power, and influence. As the quarantine continues, that connection will only strengthen. COVID-19 has transformed remote work from a relatively unused mode of employment to the only viable option, and the benefits that that model currently conveys will ensure its association as not just a possibility, but as a preferred way to work for many.&lt;/p&gt;
&lt;p&gt;After a long period in relative obscurity, blue’s popularity exploded; the spectrum of the world expanded and blue rose to become &lt;a href=&quot;__GHOST_URL__/the-color-of-2020/(https://today.yougov.com/topics/international/articles-reports/2015/05/12/why-blue-worlds-favorite-color&quot;&gt;to the world’s favorite color&lt;/a&gt; in the space of a few short decades. Starting as an afterthought, it came to be strongly associated with positive ideals and well-being. Blue’s ascendance was astonishingly rapid, but the rate of worldwide change in this early portion of 2020 makes it seem glacial: the global pandemic has the potential to establish working from home as a cultural value—and to equate it with health, affluence, and power in only a few short months. The color of the world is swiftly changing once more.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>In Favor of the Shift</title><link>https://xebecstudios.org/in-favor-of-the-shift/</link><guid isPermaLink="true">https://xebecstudios.org/in-favor-of-the-shift/</guid><description>The shift is good for both baseball and identity.</description><pubDate>Wed, 20 May 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;In Favor of the Shift&lt;/p&gt;
&lt;p&gt;A spring without baseball allows time for reflection about the big issues in life—about what really matters. As a result of this past empty April, I’ve come to a realization: the defensive shift is good for baseball.&lt;/p&gt;
&lt;p&gt;The defensive shift occurs when the defense plays out of its typical alignment. Instead of being distributed across the field relatively evenly, the shift typically involves the third baseman or shortstop moving over to the right side of the field. At times, this shift can become extreme. One of the prime examples being this &lt;a href=&quot;https://www.mlb.com/video/dodgers-use-wall-of-infielders-c35789081&quot;&gt;four-man configuration used by the Los Angeles Dodgers in August of 2014:&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2020-06-four_man_infield.png&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;Over the past few years, many have decried this defensive tactic, claiming that it is against the spirit of fair play, or puts hitters at too much of a disadvantage. But the shift is not new. While the origin of the shift dates back to the 1920’s, it became well-known as a response to Red Sox legend Ted Williams. He had hit an unheard of .406 in 1941, in 1946 he was hitting .476 headed into May, and opposing teams were desperate to slow him down. Williams was a left-handed pull hitter, making him a candidate for a unique defense.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2020-06-image-4.png&quot; alt=&quot;&quot;&gt;
&lt;em&gt;&lt;a href=&quot;http://www.baseball-fever.com/showthread.php?56039-The-Ted-Williams-Shift&quot;&gt;http://www.baseball-fever.com/showthread.php?56039-The-Ted-Williams-Shift&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This approach to Williams found enough success that other teams duplicated it, and the Fleer company even dedicated an entire baseball card to it:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2020-06-willimas-shift-diagram-2.jpg&quot; alt=&quot;&quot;&gt;
&lt;em&gt;&lt;a href=&quot;https://marketplace.beckett.com/item/513/1959-fleer-ted-williams-28-the-williams-shift_15570564&quot;&gt;https://marketplace.beckett.com/item/513/1959-fleer-ted-williams-28-the-williams-shift_15570564&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Despite still hitting .348 from 1947 to 1957, Williams had difficulty adjusting to the shift. He hit 1000 of his 1252 ground ball outs in the 1950s to the right-hand side alone.&lt;/p&gt;
&lt;p&gt;But there are ways to beat the shift, which brings us to Mickey Mantle. He, like Williams, faced the shift during his career with the New York Yankees. Mantle, however, modified his approach to beat the shift in multiple ways: (1) Hit it out of the park: he hit 536 total home runs, good enough for 18th on the all-time list (in his 500th HR, hit in 1956, &lt;a href=&quot;https://www.youtube.com/watch?v=uh32jXgSngc&quot;&gt;you can see the shift being used against him&lt;/a&gt;.) (2) Hit to the undefended side of the field: Mantle was also a switch hitter, so he could just change sides of the plate and hit to left. (3) Bunt: this is perhaps the most controversial option, but it is one that serves the team if it advances the runner … and it won Mantle the Triple Crown (league-best batting average, home run total, and runs-batted-in) in 1956, over none other than Ted Williams himself.&lt;/p&gt;
&lt;p&gt;In August of 1956, Mantle was eight games ahead of Babe Ruth’s 60 home run pace. He outdistanced Williams by 28 home runs and 48 RBI, but the batting average was a close contest. Mantle, however, continued to beat the shift by bunting. Over the course of the year, he attempted 21 bunts, the most of his career, and hit safely in 12 of 20 at bats. Here you can see the bunts against the shift and their impact in the Triple Crown race:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2020-06-BA_comparison.png&quot; alt=&quot;&quot;&gt;
&lt;em&gt;&lt;a href=&quot;https://www.baseball-reference.com/players/m/mantlmi01.shtml&quot;&gt;https://www.baseball-reference.com/players/m/mantlmi01.shtml&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Mantle’s innovative approach had won him the Triple Crown, and the Yankees went on to win the World Series in seven games in 1956.&lt;/p&gt;
&lt;p&gt;The shift was good for Mantle—it forced him to develop his game in new ways, to develop new skills, and to exploit new opportunities. While Williams allowed his focus to be on the defense, and what was being taken away, Mantle sought new ways to develop his offense.&lt;/p&gt;
&lt;p&gt;We’re in a similar position when it comes to identity. We are often focused on what we must prevent rather than on what we can enable; we are continually reacting rather than being proactive in our identity-driven security strategy.&lt;/p&gt;
&lt;p&gt;When any shift occurs, our tendency is to hunker down in our safe zone, worrying about what could possibly go wrong. To do more than survive, though—to successfully beat any shift—we should examine our options and adapt; we should diversify and develop our game. We should play offense rather than defense.&lt;/p&gt;
&lt;p&gt;Mantle, when asked why he was bunting so much in 1956, was quoted as saying, “When I tried to bunt for a hit, it was because we had to get something started. I figured that winning the pennant was the most important thing of all. Sure, I wanted to break Ruth’s record, but not at the expense of winning. ” Like Mantle, we must focus on what the most important thing—what “winning” is for our organizations—and adapt our strategy to achieve that.&lt;/p&gt;
&lt;p&gt;Some of these strategy modifications may be home runs: Rethinking the core of identity itself. Reorienting our approach around identity—equipped with adaptive technologies such as machine learning—can flip an organization to offense, proactively providing access to users before they even know that they need it.&lt;/p&gt;
&lt;p&gt;Others are the equivalent of switch-hitting: a new perspective that we might not have considered before. Exploring the reuse of new forms of digital identity can open up new long-term opportunities for new markets and partnerships. Implementing privacy controls and securing the data of customers and employees—even before government mandates these controls—can help prove that the organization can be trusted with sensitive data.&lt;/p&gt;
&lt;p&gt;Bunting should not be neglected, either. Every small step towards securing resources with identity is a step towards “winning.” Often this means expanding the visibility of an identity program into the dark corners of previously uncontrolled apps.&lt;/p&gt;
&lt;p&gt;The shift, then, rather than being a negative for our organizations and for baseball, forces aggression, forces adaptation, forces innovation—it forces the advancement of the game. To ban the shift is to kill opportunity and to settle for the status quo.&lt;/p&gt;
&lt;p&gt;The shift is good for baseball. But don’t get me started on the designated hitter.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Dating Strategy or Malware Technique?</title><link>https://xebecstudios.org/dating-strategy-or-malware-technique/</link><guid isPermaLink="true">https://xebecstudios.org/dating-strategy-or-malware-technique/</guid><description>Can you tell the difference between a bad romance and an exploit by a nation state?</description><pubDate>Fri, 14 Feb 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;em&gt;For every item that you can correctly categorize, add one point to your total. (Answer key below)&lt;/em&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Catfishing&lt;/li&gt;
&lt;li&gt;Dogfishing&lt;/li&gt;
&lt;li&gt;Sniffing&lt;/li&gt;
&lt;li&gt;Ghosting&lt;/li&gt;
&lt;li&gt;Rooting&lt;/li&gt;
&lt;li&gt;Benching&lt;/li&gt;
&lt;li&gt;Doppelgänging&lt;/li&gt;
&lt;li&gt;Roaching&lt;/li&gt;
&lt;li&gt;Pharming&lt;/li&gt;
&lt;li&gt;Haunting&lt;/li&gt;
&lt;li&gt;Kittenfishing&lt;/li&gt;
&lt;li&gt;Phreaking&lt;/li&gt;
&lt;li&gt;Orbiting&lt;/li&gt;
&lt;li&gt;Cracking&lt;/li&gt;
&lt;li&gt;Phubbing&lt;/li&gt;
&lt;li&gt;Breadcrumbing&lt;/li&gt;
&lt;li&gt;Stashing&lt;/li&gt;
&lt;li&gt;Spoofing&lt;/li&gt;
&lt;li&gt;Submarining&lt;/li&gt;
&lt;li&gt;Snooping&lt;/li&gt;
&lt;li&gt;Mooning&lt;/li&gt;
&lt;li&gt;Throning&lt;/li&gt;
&lt;li&gt;Wardriving&lt;/li&gt;
&lt;li&gt;Tindstagramming&lt;/li&gt;
&lt;li&gt;Vulturing&lt;/li&gt;
&lt;li&gt;Zombieing&lt;/li&gt;
&lt;li&gt;Piggybacking&lt;/li&gt;
&lt;li&gt;Social Engineering&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Dating Strategy&lt;/strong&gt;: &lt;a href=&quot;https://www.washingtonpost.com/lifestyle/2019/08/12/dogfishing-when-online-daters-pose-with-adorable-pets-that-arent-theirs/&quot;&gt;2&lt;/a&gt; (really?), &lt;a href=&quot;https://www.urbandictionary.com/define.php?term=Ghosting&quot;&gt;4&lt;/a&gt;, &lt;a href=&quot;https://www.telegraph.co.uk/women/life/benching-the-dating-trend-that-could-ruin-your-love-life/&quot;&gt;6&lt;/a&gt; (my entire middle school experience both socially and athletically), &lt;a href=&quot;https://www.askmen.com/dating/dating_advice/understanding-the-roaching-dating-trend.html&quot;&gt;8&lt;/a&gt; (is askmen.com the best source for dating advice?), &lt;a href=&quot;https://www.cosmopolitan.com/sex-love/a9524120/you-must-be-haunting-me/&quot;&gt;10&lt;/a&gt; (cosmo is definitely the canonical source for this kind of info, and possibly originates most of it), &lt;a href=&quot;https://www.huffpost.com/entry/dating-kittenfishing-catfishing_n_5b44f652e4b048036ea342fc&quot;&gt;11&lt;/a&gt; (rampant on linkedin, to be fair), &lt;a href=&quot;https://www.menshealth.com/sex-women/a23070110/orbiting-after-breakup-dating-trend/&quot;&gt;13&lt;/a&gt;, &lt;a href=&quot;https://time.com/5216853/what-is-phubbing/&quot;&gt;15&lt;/a&gt; (also useful in parenting), &lt;a href=&quot;https://www.today.com/health/stashing-latest-dating-trend-here-s-how-spot-it-t115447&quot;&gt;17&lt;/a&gt;, &lt;a href=&quot;https://www.npr.org/2018/01/07/574980150/from-bae-to-submarining-the-lingo-of-online-dating&quot;&gt;19&lt;/a&gt; (I’m just as surprised as you that NPR covered this), &lt;a href=&quot;https://www.gq.com/story/mooning-is-the-new-ghosting&quot;&gt;21&lt;/a&gt; (again, a good portion of my middle school experience, but it had nothing to do with dating), &lt;a href=&quot;https://www.bolde.com/12-signs-hes-throning-you/&quot;&gt;22&lt;/a&gt; (do you need 12 steps to identify this?), &lt;a href=&quot;https://nymag.com/intelligencer/2017/09/tindstagramming-instagram-dms-after-not-matching-on-tinder.html&quot;&gt;24&lt;/a&gt; (just completely, completely wrong)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Malware Technique:&lt;/strong&gt;  &lt;a href=&quot;https://blog.trendmicro.com/trendlabs-security-intelligence/new-banking-malware-uses-network-sniffing-for-data-theft/&quot;&gt;3&lt;/a&gt;, &lt;a href=&quot;https://en.wikipedia.org/wiki/Rooting_(Android)&quot;&gt;5&lt;/a&gt;, &lt;a href=&quot;https://thehackernews.com/2017/12/malware-process-doppelganging.html&quot;&gt;7&lt;/a&gt;, &lt;a href=&quot;https://www.theinternetpatrol.com/dns-poisoning-and-dns-cache-poisoning-explained/&quot;&gt;9&lt;/a&gt; (not the worst thing that can happen to your DNS), &lt;a href=&quot;https://www.tripwire.com/state-of-security/security-awareness/how-to-protect-yourself-from-caller-id-spoofing/&quot;&gt;18&lt;/a&gt; (I’m setting a ringtone for “nuisance likely”), &lt;a href=&quot;https://www.helpnetsecurity.com/2019/08/07/warshipping/&quot;&gt;23&lt;/a&gt; (still one of my favorite techniques for the change of scenery alone), &lt;a href=&quot;https://en.wikipedia.org/wiki/Piggybacking_%28security%29&quot;&gt;27&lt;/a&gt; (if you haven’t, do an internet search for &lt;a href=&quot;https://www.youtube.com/user/DeviantOllam&quot;&gt;Deviant Ollam’s youtube series&lt;/a&gt; to see an artist at work)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Both:&lt;/strong&gt; 1 (and additional meanings as well: &lt;a href=&quot;https://www.youtube.com/watch?v=IJxZ8XIBIl0&quot;&gt;how is this even a thing?),&lt;/a&gt; 12 (Don’t Google this, trust me), &lt;a href=&quot;http://www.historyofphonephreaking.org/faq.php&quot;&gt;16&lt;/a&gt; (&lt;a href=&quot;https://www.hackerscrackersandthieves.com/kevin-mitnick/&quot;&gt;old-school action – it’s what got Mitnick hooked&lt;/a&gt;), 20, 25 (if we’re counting media coverage), &lt;a href=&quot;https://hackaday.com/tag/snooping/&quot;&gt;27&lt;/a&gt;, and, not surprisingly, &lt;a href=&quot;https://en.wikipedia.org/wiki/Frank_Abagnale&quot;&gt;28&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scoring Rubric:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1-10:&lt;/strong&gt; You’re likely skilled in either the Mad Max Beyond Thunderdome that is the online dating scene, or you’re a highly sought-after security mercenary. As this simple quiz shows, the Venn diagram for those two categories resembles a map of two seas that lie on opposite sides of Asia.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;11-20:&lt;/strong&gt; The sweet spot in the bell curve, also known as the normal or Gaussian or Laplace-Gauss distribution. (And yes, I may have been spending too much time looking at statistics and graphs during the last few weeks.) Bonus points will be awarded based on the number of these terms you can work into your next conference session or video call with your elderly parents, whichever comes first.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;20-28:&lt;/strong&gt; While your achievement is laudable, please note that the authorities (and your Tinder / Bumble / FarmersOnly contacts) will be notified for their own safety and wellbeing.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>When the Bill Comes Due: Securing Challenger Banks’ Growth</title><link>https://xebecstudios.org/when-the-bill-comes-due-securing-challenger-banks-growth/</link><guid isPermaLink="true">https://xebecstudios.org/when-the-bill-comes-due-securing-challenger-banks-growth/</guid><description>The ongoing surge in financial innovation can only be sustained by a continued demonstration that new technology is safe — and that it can be trusted with valuable assets.</description><pubDate>Wed, 29 Jan 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The moment of reckoning has come.&lt;/p&gt;
&lt;p&gt;A party of eight sit around a table, the white tablecloth strewn with the detritus of a communal meal. Coffee is slowly sipped as they contemplate how to divide the bill. Unlike in years past, this is a simple operation: mobile devices come out and money is rapidly exchanged as modern technology facilitates a multiparty transaction. In mere seconds, the issue is resolved and conversation continues unabated.&lt;/p&gt;
&lt;p&gt;This scenario is a prime example of the impact of innovation in the financial sector. New methods for individuals to govern and access their money are emerging monthly, and a new mode of banking continues to evolve.&lt;/p&gt;
&lt;p&gt;When the Financial Services Act of 2012 came into force, the barrier to entry into the banking industry was lowered significantly; over the past seven years, this has enabled various &lt;em&gt;Challenger&lt;/em&gt; banks to provide more nimble alternatives to the larger banking groups. These nascent entities have changed the way many utilize personal financial services; in-person interaction has been replaced by the ubiquitous mobile app, and new technologies such as digital currency are being rapidly introduced as ease-of-use demonstrates its importance to younger generations.&lt;/p&gt;
&lt;p&gt;This convenience does not come without a cost, however. Maturing — either as a human or as a financial institution — is not easy. Compliance with regulations is proving difficult for many of these new entrants into the market, and they also face unexpected challenges with rise of cybercrime and tactics such as phishing. For these new enterprises to grow past their initial user base, they will have to develop capabilities to address these challenges.&lt;/p&gt;
&lt;p&gt;Compliance with consumer protections, both great and small, has long been a task for any business that serve the general public. The regulations placed on financial institutions are showing themselves to be &lt;a href=&quot;https://www.ft.com/content/77ef93ec-e100-11e9-9743-db5a370481bc&quot;&gt;formidable for newcomers to the market&lt;/a&gt;, and that’s even with &lt;a href=&quot;https://eba.europa.eu/eba-publishes-opinion-on-the-deadline-and-process-for-completing-the-migration-to-strong-customer-authentication-sca-for-e-commerce-card-based-payment&quot;&gt;an extension for certain portions of regulations such as the strong customer authentication (SCA) portion of PSD2&lt;/a&gt;. And as customers place a higher premium on security as a core value, proper cybersecurity features will become essential to successful institutions.&lt;/p&gt;
&lt;p&gt;This continued emphasis on cybersecurity is a natural consequence of growth. As these new entrants into the banking market gain more market share, they become consequently more attractive for cybercriminals. Capabilities such as two-factor authentication (2FA), high-grade encryption for data (both in transit and in storage), identity-proofing, and a zero-trust security strategy based on identity will need to be woven into the very fabric of the financial solution. Ideally, these facilities would have been part of the base offering from the beginning; regardless, consumers are increasingly focused on security. The ongoing surge in financial innovation can only be sustained by a continued demonstration that new technology is safe — and that it can be trusted with valuable assets. These measures will reduce the risk to the consumer and demonstrate that these new banking institutions are taking their responsibilities seriously.&lt;/p&gt;
&lt;p&gt;The banking industry has been accelerated into the future by these upstarts, but for them to be viable in the long term, they must come to terms with the fact that true growth is marked by the capability to address the security needs created by success. By addressing these needs now — by investing in the security tools and infrastructure now — they will be prepared before the bill comes due, and their conversation with their clients can continue unimpeded.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Trust in Numbers: An Ethical (and Practical) Standard for Identity-Driven Algorithms</title><link>https://xebecstudios.org/trust-in-numbers/</link><guid isPermaLink="true">https://xebecstudios.org/trust-in-numbers/</guid><description>The story of Tarra Simmons asks &apos;Does the past predict the future?&apos; and prompts a proposal for an identity-centric approach to ethics.</description><pubDate>Fri, 22 Nov 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Who was the real Tarra Simmons? On &lt;a href=&quot;https://www.seattletimes.com/seattle-news/seattle-law-school-grads-bright-future-outshines-her-rough-past-state-high-court-says/&quot;&gt;November 16, 2017&lt;/a&gt;, she sat before the Washington State Supreme Court. The child of addicts and an ex-addict and ex-felon herself, she had subsequently graduated near the top of her law school class. The Washington State Law Board had denied her access to the bar, fearing that the “old Tarra” would return. She was asking the court to trust her to become an attorney, and the outcome of her case rested whether or not her past could be used to predict her future.&lt;/p&gt;
&lt;p&gt;Algorithms that use the past to predict the future are commonplace: they predict what we’ll &lt;a href=&quot;https://www.thrillist.com/entertainment/nation/the-netflix-prize&quot;&gt;watch&lt;/a&gt; next, or how financially stable we will be, or, as in Tarra’s case, how likely we are to &lt;a href=&quot;https://www.palantir.com/&quot;&gt;commit&lt;/a&gt; a crime. The assumption is: “with enough data, anything is predictable.” Over the last several years, headlines have repeatedly illustrated the influence of algorithms on human well-being, along with the &lt;a href=&quot;https://www.vox.com/future-perfect/2019/4/19/18412674/ai-bias-facial-recognition-black-gay-transgender&quot;&gt;inherent&lt;/a&gt; &lt;a href=&quot;https://hbr.org/2019/05/voice-recognition-still-has-significant-race-and-gender-biases&quot;&gt;biases&lt;/a&gt; that affect many of them. Before we rush to embrace artificial intelligence algorithms, how can we rush to ensure that they promote justice and fairness rather than reinforcing already existing inequalities?&lt;/p&gt;
&lt;p&gt;Recent work by IBM and the IEEE have helped to solidify an ethical approach to artificial intelligence. The following five tenets bear special attention as we seek to use technology wisely with an identity-centric mindset.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Well-Being&lt;/strong&gt;&lt;br&gt;
The first tenet of a practical ethical approach is that Artificial Intelligence must put human well-being first. That sounds well and good, but how is well-being defined? Certainly, there is a core of universal truth that grounds well-being, but much of it is culturally and organizationally dependent. Difficult choices must be made – to protect one class, another may be negatively impacted.&lt;br&gt;
Using a tool known as an &lt;a href=&quot;https://ethicscanvas.org/&quot;&gt;ethics canvas&lt;/a&gt;, these choices and outcomes may be explored and centrally documented, allowing everyone in the organization to understand the moral implications of their actions in a clear way.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Accountability&lt;/strong&gt;&lt;br&gt;
Once the ethical choices are laid out using the ethics canvas above, organizations must ensure that they are accountable for meeting the documented ethical standard. This is done in two primary ways. First, all ethical decisions must be documented as solutions are designed and architected. This encourages designers, architects, and implementers to make choices that are ethical and provides a documented record of why each choice was made.  Second, a feedback loop must be built into the solution so that the end-users (those directly impacted by the technology) have a method for holding us accountable as well.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Transparency&lt;/strong&gt;&lt;br&gt;
For users to hold us accountable, however, the reasons for our decisions must be transparent to those end users. True transparency not only answers the question of why, but it breaks down the how in a simple way. When applying this to artificial intelligence, it is critical to use language that is easily understandable to the end-user as technical jargon can quickly become complex. With some forms of artificial intelligence, this simplicity is more easily achieved than others. Take machine learning, for example — how can one know what factors an outcome was based on when the artificial intelligence learns for itself? One way to do this is to use open source tools such as &lt;a href=&quot;https://www.oreilly.com/learning/introduction-to-local-interpretable-model-agnostic-explanations-lime&quot;&gt;LIME&lt;/a&gt;, which can help identify the reasoning and essential factors for why a particular solution was chosen as the right one. This transparency is more than just disclosure for disclosure’s sake — through clear communication of its reasoning process, it builds trust in AI itself.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fairness&lt;/strong&gt;&lt;br&gt;
For AI to promote fairness, it must expose its own biases – a tricky prospect in the best of circumstances. One example of this is hiring or salary determination algorithms that use historical data, which tend to depress the value of women in the marketplace. These data sets reflect past cultural trends in which fewer women advanced as far in their careers as their male colleagues, due to familial roles or even past cultural stereotypes. This poor data becomes a self-fulfilling prophecy that locks women into the patterns of the past. When historically disenfranchised groups lack a voice in the formation of AI systems, biases in the data remain uncorrected and the result is likely to perpetuate the institutionalized bias that must be eradicated. Representation in the artificial intelligence and data science communities is weak for women and minorities (only 20% of AI faculty are women in universities worldwide) and for bias to be revealed we need their unique voices conducting research, speaking in conferences, and leading the next wave of AI projects.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User Data Rights&lt;/strong&gt;&lt;br&gt;
The other tenets of ethics find their true expression in user data rights. Rather than a nice to have, control over the data that makes up your identity is a fundamental human right.  Technology that supports data user rights—UMA and consent management, data anonymization and pseudonymization– should be second nature for identity professionals. These techniques and tactics provide the firm grounding on which the ethical standards can be fulfilled.&lt;/li&gt;
&lt;/ol&gt;
&lt;h4 id=&quot;self-evaluation-and-measurement&quot;&gt;&lt;strong&gt;Self Evaluation and Measurement&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;For an ethics standard to be practical, it must have some form of measurement associated with it. While no organization or person will ever be 100% ethical, it is important to conduct regular self-evaluations to measure progress along each access of the ethical standard:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2020-06-image-5.png&quot; alt=&quot;&quot;&gt;
&lt;em&gt;The greater the distance along an axis, the greater the maturity.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The goal is to always be improving – to be more aware of the impact of AI on human well-being, to be working for accountability internally and externally, to be increasingly transparent with our decision making, to be seeking out other voices that might go unheard, and to be using standards to improve how we protect user data rights.&lt;/p&gt;
&lt;p&gt;In the end, the court decided, unanimously, in Tarra’s favor.  The court wrote in their judgment: “We affirm this court’s long history of recognizing the one’s past does not dictate one’s future.” That is a fitting mantra as the race to embrace new predictive technology, and the assumption that with enough data, anything is predictable, lingers.&lt;/p&gt;
&lt;p&gt;Past patterns in aggregate can be helpful, but the individuals involved in the systems being built should not be lost. The seduction by the power and potential of technology, must not be allowed to outpace ethics. We must strive to use AI while keeping our humanity intact.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Strong Customer Authentication: The Potential and Peril of Biometric Authentication</title><link>https://xebecstudios.org/strong-customer-authentication-the-potential-and-peril-of-biometric-authentication/</link><guid isPermaLink="true">https://xebecstudios.org/strong-customer-authentication-the-potential-and-peril-of-biometric-authentication/</guid><description>A trip though customs prompts an exploration of strong authentication, its potential and its perils.</description><pubDate>Wed, 02 Oct 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;As I strode quickly off the plane I had taken back to the US and towards customs recently after an international trip, I reached into my satchel. Like the rest of humanity, I did not want to spend any more time in the airport than necessary, so I extracted my passport and scanned for an open machine to start the scanning process.&lt;/p&gt;
&lt;p&gt;Instead of prompting me to submit my documentation, however, the kiosk asked for a form of biometric authentication — facial recognition. Once the system took my photo, my relevant information appeared on screen for my confirmation. No document to submit, no questions to be answered. I was home in record time, the friction of the reentry process greatly reduced thanks to this new innovation. But who was storing my biometric data, I wondered? And how was it being secured?&lt;/p&gt;
&lt;p&gt;With the arrival of PSD2 and its call for Strong Customer Authentication (SCA) this September, there is potential for a similar wave of innovation to sweep across the financial industry. Strong Customer Authentication seeks to enhance security for transactions by requiring two out of three forms of authentication: (1) something the customer knows, (2) something the customer has, or (3) something the customer is.&lt;/p&gt;
&lt;p&gt;It is this last element that is emerging with the adoption of PSD2. It is widely recognised that customers have &lt;a href=&quot;https://www.engadget.com/2017/08/03/password-pwned-protection-troy-hunt-306-million-breach/&quot;&gt;difficulty in choosing and adequately protecting their passwords&lt;/a&gt; (“what the customer knows”) and asking customers to carry a second factor for authentication such as a hardware-based device likely increases the overhead for a transaction (“something the customer has”). (Mobile phones, while ubiquitous, have &lt;a href=&quot;https://www.forbes.com/sites/zakdoffman/2019/09/12/new-spyware-warning-as-1-billion-mobiles-at-risk-from-nasty-simjacking-attack/#401d7545b320&quot;&gt;recently been revealed to be too easily spoofed&lt;/a&gt; to be a useful second factor.) Thus, the biometric authentication of customers (“something the customer is”) becomes a valuable addition to the security arsenal, and it is &lt;a href=&quot;https://www.wired.co.uk/article/mastercard-biometric-card-testing-visa-gemalto-scanner-fingerprint-trial&quot;&gt;already being implemented by various vendors.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Biometric authentication holds great promise for increasing security as well as reducing the friction of transactions. Being able to pay for something at a glance is a powerful tool when used responsibly. But it also elevates the responsibility to secure the data that facilitates this ease of use.&lt;/p&gt;
&lt;p&gt;These biometric markers are fundamentally different than passwords. Passwords may be reset and changed at a moment’s notice to reestablish security controls, but biometric markers are not easily modified. Once they are made public, they are rendered useless — and a persistent threat for the exposed individuals. The &lt;a href=&quot;https://www.wired.com/story/hackers-stole-traveler-photos-border-agency-database/&quot;&gt;recent breach of a facial recognition database&lt;/a&gt; shows the dangers of not providing adequate security controls around this information, and it is more than just simple reuse of photos: the use of artificial intelligence and deep fakes to &lt;a href=&quot;https://qz.com/1699819/a-new-kind-of-cybercrime-uses-ai-and-your-voice-against-you/&quot;&gt;recreate voice&lt;/a&gt; and video increases the potential impact of a breach.&lt;/p&gt;
&lt;p&gt;As always, security is best applied in layers with identity at its core. Identity provides the key for ensuring that only the proper people or entities have access to this data, and only at the necessary time. Using well established identity standards such as &lt;a href=&quot;https://fidoalliance.org/&quot;&gt;FIDO&lt;/a&gt; ensures that identity-based policies are appropriately enforced to protect this most sacrosanct of customer data.&lt;/p&gt;
&lt;p&gt;The Strong Customer Authentication that comes with PSD2 promises to increase financial transaction security while also providing a pathway to a more frictionless customer experience. Organisations that want to serve their customers well will embrace the ease-of-use that biometrics may provide, while ensuring that they serve their customers well with security protections for those unchangeable markers. And by protecting “something that the customer is,” financial institutions can demonstrate something they are: a partner to be trusted.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>PSD2 and Two-factor Authentication: A Double Security Challenge</title><link>https://xebecstudios.org/psd2-and-two-factor-authentication-a-double-security-challenge/</link><guid isPermaLink="true">https://xebecstudios.org/psd2-and-two-factor-authentication-a-double-security-challenge/</guid><description>Open banking provides an opportunity for innovation and a challenge for consumer privacy.</description><pubDate>Wed, 07 Aug 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;September 14, 2019 is rapidly approaching, and with it the full mandate of PSD2: open banking will continue to make inroads into the financial fabric of society. While the full realisation of this concept provides opportunity to innovators, it also represents a unique privacy challenge.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;An Opportunity for Innovation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Opening up a stolid market by allowing consumers to migrate their accounts and financial information between institutions provides a unique opportunity for new ideas and solutions to thrive. Organisations which have invested well in new platforms and have been quick to adapt to technological change can capitalise on an unusual combination of new solutions provided by a trusted institution. No longer are banks restricted to simple accounting; now they can more actively manage the full spectrum of wealth for their constituents. But with that opportunity comes an inherent challenge — how can financial organisations capitalise on this moment without presenting unnecessary risk to their clients?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A Challenge for Consumer Privacy&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Historically, financial institutions have long had stringent requirements for the protections of customer data. (Unlike the recent raft of social media companies which have come under public scrutiny, their business model does not rely on selling customer data.) With the advent of PSD2 and open banking, however, these long-held views require more consideration.&lt;/p&gt;
&lt;p&gt;At its core, open banking seeks to provide freedom for customers to migrate between financial offerings. In the past, they might have felt locked-in to a particular institution, forced through historical inertia to remain with their bank or investment firm due to the high cost of switching. Through mandates that affect implementation details such as APIs, strong authentication of the consumer, and overall security, consumers are empowered to choose the best offering for them rather than merely maintaining the status quo.&lt;/p&gt;
&lt;p&gt;The implications of these changes should give pause to organisations who understand them. They signify a potential increase in both the quantity and quality of personal data that must be stewarded. Institutions that play a role in any significant transactions must now be able to verify individuals through biometric markers and other sensitive data. This level of information requires significantly more protection than mere personally identifiable information: it lies at the core of consumers’ identity.&lt;/p&gt;
&lt;p&gt;Despite this increased responsibility, these changes are welcome because they enable consumer ownership of finance through choice and consent. But choice and consent are not as easy to come by as they might seem. Ironically, even while strong authentication protects the consumer, it also necessitates the collection of ever-more-sensitive data), and the privacy challenges mount.&lt;/p&gt;
&lt;p&gt;Granting the ability to protect personal data, financial information, and biometric markers are only as effective as the level of understanding of the consumer, as depicted by the recent narrative surrounding FaceApp. Users happily traded rights to their own portraits in exchange for a vision of what their visage might look like in the future. A quick glance at the actual privacy terms reveals that they were likely uneducated as to what exchange they were actually making. Users were granting FaceApp&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“ … a perpetual, irrevocable, nonexclusive, royalty-free, worldwide, fully-paid, transferable sub-licensable license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, publicly perform and display your User Content and any name, username or likeness provided in connection with your User Content in all media formats and channels now known or later developed, without compensation to you …”&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;… a remarkable exchange for a whimsical glimpse of a possible visage to come.&lt;/p&gt;
&lt;p&gt;This incident highlights the privacy challenge behind open banking and a well-rounded implementation of PSD2: not merely protecting users’ data — which is increased through the need for strong authentication ­­— but also ensuring that end users comprehend the implications of their choices. So the privacy challenge that lies ahead is twofold: it is both technological, requiring responsible protection of sensitive data, and sociological, learning lessons about education and consent from other initiatives such as the GDPR in order to clearly empower consumers to make good choices.&lt;/p&gt;
&lt;p&gt;As open banking becomes normative with regulations such as PSD2 coming into full effect, organisations will do well to embrace the opportunity to expand their market reach while still proving themselves worthy of consumer trust by thoughtfully providing protections for the end consumer — in ways that are easily understood and that promote good choices.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>The Bernoulli Principle: Epidemiological Models for Identity</title><link>https://xebecstudios.org/the-bernoulli-principle-epidemiological-models-for-identity/</link><guid isPermaLink="true">https://xebecstudios.org/the-bernoulli-principle-epidemiological-models-for-identity/</guid><description>How the eradication of Smallpox shows a way forward for identity models.</description><pubDate>Wed, 10 Jul 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Smallpox is one of the deadliest diseases in all of human history. If you contracted Smallpox in the 18th century, you would have a one in three chance of dying within sixteen days. In the 20th century alone, Smallpox killed over 500 million people. Fortunately, it’s also the only infectious disease among humans that has been successfully eradicated.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2020-06-Table_showing_the_smallpox_death_rates_for_Sweden_1749-1855._Wellcome_M0012994.jpg&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;Daniel Bernoulli, attempting prove the efficacy of inoculation against Smallpox, published the first epidemiological model in 1760; he demonstrated that life expectancy increased due to the use of inoculation against Smallpox in the general population. In doing so, he introduced the use of epidemiological models that have been used to address the spread of not only Smallpox, but also malaria, AIDS, SARS, measles, cholera, etc.&lt;/p&gt;
&lt;p&gt;Bernoulli’s model introduced provided three separate benefits related to the spread of disease: an understanding of the mechanism of transmission, a prediction of the future expansion of infection, and, of course, control over the spread of the disease. A machine-trained model based on this epidemiological model, when combined with a network-graph representation of identity, has the potential to provide similar results related to the spread of identity and its related access. In short, applying epidemiological concepts to identity holds great promise for innovation.&lt;/p&gt;
&lt;p&gt;Just as smallpox was communicated from patient to patient, access to sensitive data and applications often spreads like a disease inside communities of identities. By understanding how access is communicated from “patient zeros” to the surrounding community, it is possible to begin to predict which identities will soon accumulate access, and then seek to discover inoculation-type tactics to restrict the spread of unnecessary access. By analyzing these “infection patterns,” the machine-trained model can provide recommendations for governing identity, enhancing decision-making, educating human users, and pairing machine learning and human learning in a “virtuous loop.” Over time, routine approvals or revocation of access could be completely automated, allowing humans to focus solely on difficult boundary cases, accelerating overall productivity for securing identity. By thus “inoculating” communities against the rampant spread of access, risk to enterprises and the community at large is reduced.&lt;/p&gt;
&lt;p&gt;There are times, however, when a model of this type should be used to promote the spread of identity rather than to restrict it. Initiatives such as ID2020 are endeavoring to ensure that underserved groups are not left behind by the promise of digital transformation: by granting them identities, they clear a path for them to access health care, exercise their voting rights, obtain education, or otherwise reap the benefits of what are assumed as basic human rights. This model could be used to examine how underprivileged communities adopt identity, seek to remove inhibitors to its acceptance, and accelerate its adoption in communities worldwide.&lt;/p&gt;
&lt;p&gt;Thus, what Bernoulli began in 1760 still finds its expression today: modeling the real world with the end goal of reducing harm and improving the quality of human life. As we seek to innovate in his footsteps, we have no doubt that he would be using the same techniques and ideas were he around today.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Living Like the 3%: A Secure User Experience on Financial Applications</title><link>https://xebecstudios.org/living-like-the-3-user-experience-on-financial-apps/</link><guid isPermaLink="true">https://xebecstudios.org/living-like-the-3-user-experience-on-financial-apps/</guid><description>Only 3% of financial apps deliver a secure experience for their users. What&apos;s the real cost?</description><pubDate>Wed, 08 May 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;What kind of financial windfall would it take to put you into the 1% — to enable you to leave your job, climb aboard your yacht, and eat avocado toast for breakfast, lunch, and dinner? The answer to that question varies depending on your location: from &lt;a href=&quot;https://www.bloomberg.com/news/articles/2019-02-04/a-global-guide-to-what-it-means-to-be-part-of-the-1&quot;&gt;$81K per year in India, to $290K in the UK, and a massive $891K in the United Arab Emirates (pretax, for those of you doing the math at home).&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;While membership in this elite club is not achievable for most of us, it is still possible to become a top-tier member of a different group: &lt;strong&gt;&lt;em&gt;the 3%.&lt;/em&gt;&lt;/strong&gt; This select group is not measured by how many homes they have nor by their investment portfolio, but rather by how well they steward the resources of others that have been entrusted to them.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.arxan.com/resources/downloads/aite-research-financial-mobile-apps&quot;&gt;A recent report published by Arxan Technologies examined 30 different financial services apps available on the Google Play store and found very few that provided adequate security for their users.&lt;/a&gt; Despite the fact that these were supplied by financial institutions, for whom trust is essential for their business, application security was found wanting.&lt;/p&gt;
&lt;p&gt;The issues discovered were wide ranging – 43% of apps were vulnerable to attacks that can run code on the mobile device itself injected into the app as it ran — allowing adversaries to run their own code as the logged-in user. Alongside this, 80% of the apps used relatively weak encryption, creating an easy attack vector for malicious actors to pilfer sensitive data embedded in and used by these apps. Furthermore, 83% of the apps chose to store sensitive data in the device’s file system, in external storage or on the clipboard — which circumvents any access restrictions that the app might normally enforce. This allows any anonymous user (or other app) to access sensitive data that should have been protected. The most common issue, however, was the lack of binary protection for these financial apps to prevent reverse engineering. This means that attackers could take the applications and decompile them to examine their source code; this allows for the discovery of other vulnerabilities to exploit along with the exposure of any sensitive data hard-coded within the app itself. This final issue automatically reduced the number of apps without issues to a grand total of 3%.&lt;/p&gt;
&lt;p&gt;Only 3% of financial apps within this study delivered a secure experience for their users, demonstrating that these financial institutions could be trusted to handle their customers’ data and finances responsibly. This, of course, is the 3% that all financial institutions should aspire to belong to; with each passing headline, customers are realising the importance of choosing financial providers who have invested in proper security controls to protect their interests.&lt;/p&gt;
&lt;p&gt;Studies such as this one call attention to the fact that with each passing day, it becomes more apparent that security cannot be an afterthought for today’s businesses. It must be a mindset that pervades all aspects of the organisation; from establishing an identity program to provide access and ensure compliance with regulation, to having access to sensitive resources enforced in depth. Moreover, organisations must ensure – as this report highlights – that application security is at the forefront of every software architect and developer so that the applications and software that represent a financial institution to the world communicates responsible handling of important customer assets and data.&lt;/p&gt;
&lt;p&gt;For those organisations that take security lightly, it is at their own peril – not only putting the relationship with customers at unnecessary risk but also finding themselves living below what one analyst called &lt;a href=&quot;https://www.securityweek.com/software-development-below-security-poverty-line&quot;&gt;“the Security Poverty Line.”&lt;/a&gt; Financial institutions wanting to thrive in today’s business environment must invest a coherent security program and deliver a secure, trustworthy interaction for clients — which will elevate them into that rarefied air of the 3%.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>A Cher-based Lament for Lost Data</title><link>https://xebecstudios.org/a-cher-based-lament-for-improper/</link><guid isPermaLink="true">https://xebecstudios.org/a-cher-based-lament-for-improper/</guid><description>Great suffering produces great art.</description><pubDate>Mon, 01 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Great suffering always produces great art, with each master artist choosing her own medium. The powerful combination of pain and creativity finds its greatest expression in the form of a lament. Merriam-Webster defines a lamentation as “an expression of sorrow, mourning, or regret.”&lt;/p&gt;
&lt;p&gt;Around World Backup Day, you may read many pieces advocating the wisdom of securely backing up your data. I’d like to take a slightly different approach by encouraging us all to contemplate a world in which no viable backups exist.&lt;/p&gt;
&lt;p&gt;This can be difficult, and, as always, we must turn to world-class works of art —created by brilliant minds among us — to engage our empathy. “If I Could Turn Back Time,” by Cherilyn Sarkisian, or “Cher” as her friends call her, is one such piece that encapsulates the anguish and heartache of not having a backup to safeguard what we treasure.&lt;/p&gt;
&lt;p&gt;For those of you not familiar with this exquisite creation, you may find it on &lt;a href=&quot;https://open.spotify.com/track/6mYrhCAGWzTdF8QnKuchXM?si=lobcZgYfQQm41eAI5Zr5UA&quot;&gt;Spotify&lt;/a&gt;, &lt;a href=&quot;https://itunes.apple.com/us/album/if-i-could-turn-back-time/114266?i=114241&quot;&gt;iTunes&lt;/a&gt;, &lt;a href=&quot;https://www.amazon.com/If-Could-Turn-Back-Time/dp/B000VSWCQG&quot;&gt;Amazon&lt;/a&gt;, or, if you are feeling particularly nautical, &lt;a href=&quot;https://www.youtube.com/watch?v=BsKbwR7WXN4&quot;&gt;YouTube&lt;/a&gt;. (The last option is not recommended for small children, people utilizing the network of their employer, or those who were not alive in the late 80s.)&lt;/p&gt;
&lt;p&gt;Choose one of the above options, press play, and let the angst wash over you. Yes, I’m serious. Go, find, click: I’ll wait …&lt;/p&gt;
&lt;p&gt;Ok, then. Now that her dulcet dirge is churning in your subconscious, let’s explore a small segment of Cher’s four-minute lament and tap into the dystopian reality that exists in a world without “do-overs:”&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;“If I could turn back time&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;If I could find a way …”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Surprisingly, Cher starts her song of woe in the key of B major with a driving, almost-upbeat guitar riff. Her fantasy at this early juncture is to roll back to how life was before what we can only at this point term “the incident.” But —alas — in the world in which she exists, without secure backups, she is locked into daydreaming about the past.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;“I don’t know why I did the things I did&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;I don’t know why I said the things I said&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Pride’s like a knife, it can cut deep inside …”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Rather than accepting responsibility for her actions, she pointedly acknowledges that she has not even performed the requisite introspection to understand her own emotions. Like many before her, she is a victim of her own hubris. “A malicious insider will never do harm to my organization,” she has told herself. “There’s no need for a backup of critical data, secured with identity.” Despite the rhythmic addition of a bass, a snare, and a kick drum, she still appears to be in denial.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;“My world was shattered, I was torn apart&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Like someone took a knife&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;And drove it deep in my heart&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;When you walked out that door&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;I swore that I didn’t care&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;But I lost everything darling, then and there …”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;After the (again upbeat) chorus, we truly plumb the depths of her loss. Shattered world views, lives torn asunder, losing everything — this is simultaneously the hyperbole of a creative genius and the real-world devastation that lies behind the headlines of the latest breach.&lt;/p&gt;
&lt;p&gt;And ultimately, just like an organization without backups, it leaves us with more questions than answers: “How can this rupture in the relationship possibly be mended?” “Was the leaving because of what she said, or was what she said because of the leaving?” Most importantly, “Did the ‘leaver’ take any sensitive data with them?” There is a deep-seated longing that cries out for forensics and remediation (exercise for the reader: identify the follow-up Cher single that addresses this experience.)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;“If I could reach the stars&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;I’d give them all to you&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Then you’d love me, love me,&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Like you used to do.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Rising up from the valley of sorrow, with a mere 39 seconds left in the track, Cher shifts things into a higher gear as she makes a surprising step up into D major:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;CRITERION STUDIOS, LOS ANGELES – 1:17 AM&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Producer: “What’s the highest note Cher can sing?”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Engineer: “It’s a D natural, this time of day.”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Producer: “Then let’s modulate to D on the last chorus&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;when she says ‘reach the stars.’”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Engineer: “But that’s a minor third, you sure?”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Producer: “Yeah, nobody will notice.”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Her voluminous emotional turmoil builds as she explores a flawed alternative to secure backups. In her delirious, grief-stricken state, we see her grasping at straws, seeking to placate the leaver with objects (stars) that she can never hope to have at her disposal.&lt;/p&gt;
&lt;p&gt;This, then, is the reality of a world without backups. A world in which the only way to fully express the agony of losing data to a mishap, or ransomware, or malicious insiders is to create a raw, powerful, musical lament with a voice that one person described as, &lt;a href=&quot;https://www.npr.org/templates/story/story.php?storyId=17232461&quot;&gt;“The voice of a middle-aged woman on a rollercoaster giving birth.”&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In short, the only way to express the anguish of not having backups secured by identity is to create exquisite art.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Last Minute Romantic Ideas for the Security-Minded</title><link>https://xebecstudios.org/last-minute-romantic-ideas-for-the-security-minded/</link><guid isPermaLink="true">https://xebecstudios.org/last-minute-romantic-ideas-for-the-security-minded/</guid><description>A quick list of ideas for the romantically-minded procrastinator.</description><pubDate>Thu, 14 Feb 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Discover Something New&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reveal something your partner, &lt;strong&gt;Facebook, and Google&lt;/strong&gt; doesn’t know about you to build mutual trust.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Light a Fire&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Nothing sparks joy like operational security. Build a bonfire, and burn any personally identifiable information, including anything that connects you to your partner.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Explore Your Intimacy&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reset a password on the social media site of your choice, and then take the resulting quiz on behalf of your partner. If you score better than 85%, you are soulmates for life. If you get less than 25%, save time by skipping to the bottom of this list.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Compose a Poem&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Poetry stirs the soul. No need to waste time fabricating it yourself, though, &lt;a href=&quot;http://mariechatfield.com/markomposition/&quot;&gt;just use Markov chains&lt;/a&gt;. For example, the following is a combination of Petrarch’s sonnets and GDPR:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;But now my worn soul and worn&lt;br&gt;
Heart learnt all others show Dim, as the sun&lt;br&gt;
Has shone for many a lovely lady&lt;br&gt;
All alone: for archiving purposes in the public&lt;br&gt;
Interest, scientific or historical research&lt;br&gt;
Purposes or statistical purposes.&lt;br&gt;
In front a column shone of crystal,&lt;br&gt;
And thereon each thought was traced&lt;br&gt;
In characters so clear, and sweet,&lt;br&gt;
Which I thought to do: personal data&lt;br&gt;
No longer necessary in relation&lt;br&gt;
To the purposes for which they were collected&lt;br&gt;
Or otherwise processed.&lt;br&gt;
As well as we, shalt know,&lt;br&gt;
Stung to the cold fear I all did prove&lt;br&gt;
The same sharp pains that first hour,&lt;br&gt;
Of April the sixth day,&lt;br&gt;
That bound me, and, alas! now sets me free.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Give the Gift of Warmth&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Get your partner something that will wrap them in your love all season: an AI-enabled scarf. What makes a scarf AI-enabled, you ask? The same thing as every AI-based security solution you’ve ever encountered: a 25% markup!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Eliminate Social Media Distractions&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;It’s difficult to be “present” while you’re surfing the ‘gram. For a truly special night, delete your social media accounts. (But retain your burner accounts — in both relationships and fires, it’s best to know where the exits are.)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Commit to Monogamy&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;While it seems like a basic concept, let’s face it, three-way relationships can be tricky. Make tonight special by unplugging all IoT devices: the evening will be oh-so-special without Alexa interrupting to recite that Oaxacan mole recipe.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Find a Shared Passion&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Cozy up together on the couch, sign into your easily located, home-based network and probe the defenses of one of the world’s leading cybersecurity agencies. They say that distance makes the heart grow fonder, something to dwell on during the subsequent arrest, trial, conviction, and time served.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;strong&gt;Have an Affair&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This may not be the best idea, but it’s still less emotionally risky than giving your partner cryptocurrency.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>I Am Spartacus: Privacy through Obfuscation and the Right to be Forgotten</title><link>https://xebecstudios.org/i-am-spartacus-privacy-through-obfuscation/</link><guid isPermaLink="true">https://xebecstudios.org/i-am-spartacus-privacy-through-obfuscation/</guid><description>The Third Servile War was over. The slave army had been defeated, and their Roman captors offered the survivors a pardon—on one condition: they must identify their leader, Spartacus.</description><pubDate>Tue, 06 Nov 2018 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The Third Servile War was over. The slave army had been defeated, and their Roman captors offered the survivors a pardon. The only requirement was that they identify Spartacus, their leader (a sun-bronzed, cleft-chinned Kirk Douglas).&lt;/p&gt;
&lt;p&gt;Rather than give away his identity, however, each of them cried out “I’m Spartacus!”—thus preserving his anonymity. The Romans could not identify him; they could not discern which of the men standing before them had been the leader of the rebellion.&lt;/p&gt;
&lt;p&gt;(Spoiler alert: they all die as a result.) In short, their actions ensured a crucial part of Spartacus’ privacy—his right to be forgotten.&lt;/p&gt;
&lt;p&gt;The right to be forgotten is considered a fundamental human right by numerous governments. Legislation such as GDPR and the &lt;a href=&quot;https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375&quot;&gt;California Consumer Privacy Act of 2018&lt;/a&gt; (CCPA), for example, aim to establish this right for EU citizens and California residents, respectively.&lt;/p&gt;
&lt;p&gt;In the past, the implementation of such regulations has revolved around search engines and the rights of users to request that their search results be removed — given they are no longer necessary or that they have a legitimate objection to their existence.&lt;/p&gt;
&lt;p&gt;(One assumes that in this case a request by Spartacus to delete coverage of his being the leader of a massive slave army would be rejected by Google as neither of those.)&lt;/p&gt;
&lt;p&gt;However, the &lt;a href=&quot;https://thenextweb.com/facebook/2018/03/21/facebook-and-cambridge-analytica-heres-what-you-need-to-know/&quot;&gt;Facebook and Cambridge Analytica scandal&lt;/a&gt; and a series of &lt;a href=&quot;https://thenextweb.com/insider/2017/09/08/143-million-equifax-customers-data-stolen-in-security-breach/&quot;&gt;large-scale breaches&lt;/a&gt; have recentered the discussion on the privacy implications of this human right.&lt;/p&gt;
&lt;p&gt;Now, privacy advocates have renewed their calls to have their account and personal data removed from social media platforms and other online services.&lt;/p&gt;
&lt;p&gt;This seems to have widespread support, as most people agree that users should have the ability to remove accounts and material that they have created in the past—but with this comes new difficulties for today’s enterprises.&lt;/p&gt;
&lt;p&gt;The solution here is clear: enterprises must offer the capability for users to delete accounts and any associated personal data. However, this is not as simple as it might seem at first.&lt;/p&gt;
&lt;p&gt;Organizations are reluctant to give up this data as it helps them to improve their business models and might prove to be profitable information to have on-hand.&lt;/p&gt;
&lt;p&gt;To realize the extent of the value of this data, one only needs to look at the cases where businesses, like free VPN services, &lt;a href=&quot;https://thenextweb.com/contributors/2018/05/28/be-cautious-free-vpns-are-selling-your-data-to-3rd-parties/&quot;&gt;resell user information to third parties&lt;/a&gt;. Enterprises need to feel compelled to part with this perceived value.&lt;/p&gt;
&lt;p&gt;Governments are attempting to make parting with their customer’s personal data more compelling by imposing fines – enter GDPR and CCPA.&lt;/p&gt;
&lt;p&gt;However, beyond the necessary business case lies technological challenges. Lingering personal data can be cause for concern, even if an online service has built-in deletion or removal options.&lt;/p&gt;
&lt;p&gt;If this personal data is located in a structured database or an application, then the process is relatively straightforward. In this case, eliminate the associated account and the data stored within that account is also removed.&lt;/p&gt;
&lt;p&gt;If the sensitive data is in files, detached from applications which are governed by the organization, these files will behave like abandoned satellites orbiting the earth, forever floating in the void of network-based file shares and cloud-based storage.&lt;/p&gt;
&lt;p&gt;If the right to be forgotten is to be realized, then an essential task is locating that personal data and enabling its deletion to ensure the privacy of the end user.&lt;/p&gt;
&lt;p&gt;As our online identities continue to expand and proliferate on the web, we must work to safeguard them as it is our fundamental right. The right to be forgotten, or to choose to withdraw from online services without leaving our data behind, is essential to our privacy foundation.&lt;/p&gt;
&lt;p&gt;Organizations who value their customers’ privacy and their right to be forgotten will demonstrate so by taking measures to protect their sensitive data – effectively yelling “I’m Spartacus!” on behalf of the user.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Houston, We Have a Problem</title><link>https://xebecstudios.org/houston-we-have-a-problem/</link><guid isPermaLink="true">https://xebecstudios.org/houston-we-have-a-problem/</guid><description>Space debris is a growing problem. So is personal data in the cloud.</description><pubDate>Wed, 06 Jun 2018 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;&lt;strong&gt;On April 2, 2018, the first Chinese space station – Tiangong-1 – came crashing down to earth. Headlines across the world stoked panic and alarm, and astronomers attempted to predict where the 9.5 tonne object would strike. This is not the first such object to threaten damage and destruction, and nor will it be the last.&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Since the beginning of space exploration, countries have raced to put objects into Earth’s orbit. As a result, there are objects in space right now providing us with telecommunications, GPS services, weather tracking and contributing to science in ways we can only imagine. But after years of being treated as international landfill, space has become increasingly more congested.&lt;/p&gt;
&lt;p&gt;There are over 14,000 objects in space that are actually junk – fragments of spacecraft, old boosters, and forgotten satellites­ ­– no longer serving any functional purpose. Not only are they junk, but they are dangerous pieces of junk, travelling much faster than a speeding bullet at 28,000 kilometres per hour.&lt;/p&gt;
&lt;p&gt;Businesses today have raced to launch data into orbit around the business in a way that echoes this rising problem of space debris. This is in part thanks to the arrival of the increase in cloud adoption and file sharing – which has seen employees take data out of structured systems and store it into cloud and network-based storage because it is convenient for their immediate job function.&lt;/p&gt;
&lt;p&gt;Whether it’s a presentation on SharePoint or a spreadsheet on Box, up to 80% of enterprise data is on the move, being downloaded, accessed, and shared outside of IT’s purview. This data is commonly called ‘unstructured data’ and it is a huge area of exposure for organisations today.&lt;/p&gt;
&lt;p&gt;The scary part of this is how much of this data is sensitive. Credit card information, healthcare records, and financial data is all on the move, orbiting organisations despite the increasing risk of cyber-attack.&lt;/p&gt;
&lt;p&gt;Even scarier? Most organisations have no idea where this unstructured data lives, what lies within that data, or who owns it. And this is the type of data that adversaries need to potentially hold an organisation, or worse, their customers, to ransom.&lt;/p&gt;
&lt;p&gt;When thinking about data orbiting our business, we must think of it like the satellites and other objects orbiting the earth – the majority of it is dangerous, has most likely been abandoned, and is not serving a purpose. This is a challenge the international community has been tackling since it first launched, and it’s time for IT teams to do the same.&lt;/p&gt;
&lt;p&gt;Since the beginning of space flight, nations collectively created a database capturing all relevant data about the objects being launched into space – dimensions, weight, mission, launch speed, trajectory – to fully understand what was out there. However, it quickly became apparent that there were disparities between what should be (what was logged into the database) and what actually was launched into space.&lt;/p&gt;
&lt;p&gt;To accurately know what was out there, governments developed and deployed laser telescopes to provide ultimate visibility and accountability into this orbiting junk for scientists across the globe.&lt;/p&gt;
&lt;p&gt;Much like the space agency and its laser satellites, organisations must seek to discover where their sensitive data resides, who has access to it and what they are doing with that data. But this is not as easy as it sounds in the enterprise, as the user frontier is also changing, adding another layer of complexity to the situation.&lt;/p&gt;
&lt;p&gt;That is, who, or rather what organisations consider an identity has evolved to include employees, contractors, partners, and more increasingly, software bots (which, like humans, are accessing data and making decisions based on it).&lt;/p&gt;
&lt;p&gt;The international community doesn’t just rely on satellites to understand the objects in Earth’s orbit – it has highly trained physicists determining the responsibility of objects based on their observed trajectory. This is a practice that enterprises need to understand too, as thanks to the huge number of applications entering the business, it’s not always obvious where data has come from, where it resides or who owns it.&lt;/p&gt;
&lt;p&gt;Visibility into the environment — knowing what data is out there and who put it there – allows organisations to determine the original actor responsible for an objects’ creation, and shows how they can establish owners for the sensitive data that is found. This provides a chain of responsibility for review, persistent protection and clean-up of sensitive data usage.&lt;/p&gt;
&lt;p&gt;This challenge of discovering and protecting an organisation’s sensitive data stored in files is one of the new frontiers of identity governance. Organisations are seeking a way to discover where this data resides and put controls in place to protect it, and the best way to do that is by governing access to this data in the same way they govern access to critical applications.&lt;/p&gt;
&lt;p&gt;Extending identity governance to data stored in files helps organisations answer the questions of who has access to what data, who should have access to it and how that access is being used. By building on the lessons learned from sixty years of space debris management, organisations can govern the new frontier of data stored in files, and at the same time, rapidly realise that the path to a more secure enterprise isn’t actually rocket science after all.&lt;/p&gt;</content:encoded><category>Technology</category></item><item><title>Admiral Nelson, Identity, and the Internet of Things</title><link>https://xebecstudios.org/admiral-nelson-identity-and-the-internet-of-things/</link><guid isPermaLink="true">https://xebecstudios.org/admiral-nelson-identity-and-the-internet-of-things/</guid><description>On October 21, 1805, the world changed. At the Battle of Trafalgar, British Admiral Horatio Nelson introduced a new strategy for naval warfare, one which points the way to an identity strategy for the Identity of Things.</description><pubDate>Mon, 09 Oct 2017 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;On October 21, 1805, the world changed. At the &lt;a href=&quot;https://en.wikipedia.org/wiki/Battle_of_Trafalgar&quot;&gt;Battle of Trafalgar&lt;/a&gt;, British Admiral Horatio Nelson introduced a new strategy for naval warfare. Instead of lining up in a firing line opposite the enemy, he sailed his fleet &lt;a href=&quot;https://upload.wikimedia.org/wikipedia/commons/d/d2/Battle_of_Trafalgar%2C_Plate_1.jpg&quot;&gt;directly into the enemy lines&lt;/a&gt;. The &lt;a href=&quot;https://upload.wikimedia.org/wikipedia/commons/7/7b/Battle_of_Trafalgar%2C_Plate_2.jpg&quot;&gt;resulting chaos&lt;/a&gt; meant that sailors could no longer rely on location to identify friend and foe. Instead, Nelson redefined his understanding of identity: legend states that he &lt;a href=&quot;https://en.wikipedia.org/wiki/Nelson_Chequer&quot;&gt;painted his ships in a unique pattern&lt;/a&gt; so that the identity of each ship was obvious. This enabled his entire fleet—every ship, every sailor—to act instantly and independently in the pursuit of victory. Knowing this, he sailed into battle with a &lt;a href=&quot;https://en.wikipedia.org/wiki/England_expects_that_every_man_will_do_his_duty&quot;&gt;single order of battle&lt;/a&gt;: “It is expected that every person will do their duty.” The British Navy won a decisive victory, and naval warfare would never be the same.&lt;/p&gt;
&lt;p&gt;Today’s organizations find themselves at a similar inflection point; the rise of the Internet of Things is changing the business landscape. One estimate cites that over &lt;a href=&quot;https://www.business.com/articles/jason-hope-iot-security-problems/&quot;&gt;50 billion devices will be internet connected&lt;/a&gt; in the next three years, and businesses are seeking to harness this new capability: &lt;a href=&quot;https://www.gartner.com/doc/3678618/survey-analysis-iam-leaders-saying&quot;&gt;Gartner estimates&lt;/a&gt; that over 73% of organizations will have an IoT initiative by next year. These initiatives will usher in a wave of devices, agents, and programs that are enticing targets for malicious actors. More significantly, 85% of those IoT initiatives expect that their identity program will support them. The Internet of Things is coming, and identity programs are expected to govern them. How can we, like Nelson, wield the power of identity? How can we seamlessly adopt them into an existing identity governance program and identity-enable them to be simultaneously productive and secure? How can we issue a single order of battle, “It is expected that every identity-enabled entity will do their duty?”&lt;/p&gt;
&lt;p&gt;Our understanding of identity must expand to incorporate this new set of entities ushered in by the Internet of Things. First, we must examine the full range of devices, agents, and programs in order to discern where they fall within the IoT spectrum and their potential threat level. The associated threat level may then be determined, along with the level of required governance. By applying well-understood existing identity models (e.g. contractor or employee), with slight modifications where appropriate, we can extend identity governance to this new class of actors, transforming the Internet of Things into the Identity of Things.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Internet of Things Spectrum and Existing Identity Models&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Internet of Things is a diverse set of devices, agents, and programs—it is helpful to think of this collection as a continuous spectrum. On the low end of the spectrum are passive devices that are connected to the network but have little autonomy. A good example of this end of the spectrum is a security camera that provides surveillance. Passive devices do not merit an identity; they instead &lt;a href=&quot;https://krebsonsecurity.com/tag/mirai-botnet/&quot;&gt;require access protection&lt;/a&gt; and a regular cycling of credentials that allow device access, something akin to Privileged Account Management.&lt;/p&gt;
&lt;p&gt;Moving up the spectrum introduces independent agents. These are often programs or “bots” that take on specific tasks for the organization. &lt;a href=&quot;https://www.gartner.com/doc/3796568&amp;#x26;srcId=1-4554397745&quot;&gt;Robotic Process Automation (RPA)&lt;/a&gt; falls squarely into this zone. Agents have some access to resources and can effect change, but these activities are limited. A customer service bot that responds to questions about order status might be a relevant example of this middle section of the spectrum. This increased access and the ability to initiate action means that governance is required and thus an identity must be assigned. However, since this access and control is limited, “bots” may be treated as contractors, with their access and control time-limited and constrained.&lt;/p&gt;
&lt;p&gt;At the upper end of the spectrum, sophisticated artificial intelligence-based programs await. Limits on access are minimal, and these programs have the ability invoke actions as necessary. The unlimited potential of AI captures the imagination, as does its dangers (&lt;a href=&quot;http://www.zdnet.com/pictures/15-of-the-best-movies-about-ai-ranked/&quot;&gt;as an entire genre of movies has illustrated&lt;/a&gt;). Clearly, these higher order actors require full governance, and therefore should be treated like full employees of the organization.&lt;/p&gt;
&lt;p&gt;All entities within the Internet of Things fall somewhere on this spectrum. Movement upwards along the continuum—from passive agents to independent agents to artificial intelligence—results in an increase in access to resources and the ability to initiate change in the environment. Consequently, it signals an associated increase in risk to the organization. It also increases the likelihood that an identity should be assigned—an identity that must be governed according to well-understood models in order to mitigate that elevated risk.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Power of Identity and the Internet of Things&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Internet of Things is changing how businesses operate, and governing these new devices, bots, and AI requires a reevaluation of identity. Just as in Nelson’s day, an evolution in strategy—one that seeks to identity-enable the Internet of Things—is essential to success. Such a strategy demonstrates the power of identity to enable businesses to embrace this new technology and to capitalize on the change that accompanies it.&lt;/p&gt;
&lt;p&gt;Organizations deploying this strategy can then, like Nelson, issue a single order of battle: “It is expected that every identity-enabled entity will do their duty.”&lt;/p&gt;</content:encoded><category>Technology</category></item></channel></rss>