When, Not If, Your PII is Exposed

The best thing for all of us to do is just flat out assume that the personally identifiable information (PII) that companies collect from us WILL be compromised.

I’ve always assumed that Madison Square Garden and the New York Knicks LIKE celebrities. They get so much free publicity from them, after all.

But Madison Square Garden didn’t adequately protect celebrity PII.

“A criminal hacker collective called ShinyHunters recently published a slew of documents exposing the MSG database….ShinyHunters had demanded ransom to delete their data, but MSG apparently didn’t meet their terms.”

But then the celebrities found out what MSG was tracking about them.

“93 entries are marked as “LGBTQIA,” such as Ricky Martin, Phoebe Bridgers, and Geese’s Emily Green….

“The database also marks some entries with risk scores, often based on social media posts, a source told Wired. ‘It doesn’t have to be that serious. You could just be critical of the team or the place itself,’ the source said.”

This is what businesses like MSG fail to recognize. A data breach doesn’t only harm the victims. It also harms the organization itself because they’re perceived as a security risk. In the case of MSG they’re also perceived as nosy, even paranoid.

Google Gemini.

Which is one of the reasons why Bredemarket collects only the minimum necessary data on its Calendly form and other forms. I don’t ask for your sexual orientation or even your favorite sports team.

I don’t ask that much.

Can Bredemarket Discuss Privacy?

Repurposed from part of a prior post.

I have discussed privacy for years, even before I started Bredemarket.

The first wave of BIPA lawsuits began a decade after the original BIPA was passed, while I was still at IDEMIA (and working with the International Biometric + Identity Association.

GDPR took effect at about the same time, which incidentally made it hard for me to recruit French nationals for internal Anaheim biometric testing. Could we guarantee their right to be forgotten?

And of course privacy accelerated after I formed Bredemarket, and Bredemarket clients had to state how they protected biometric data privacy.

In addition to my text work, there are videos.

Privacy.

Is Fingerprint Evidence “Fryed” in New Jersey?

Thanks to Mike Bowers (CSI DDS) for this story about possible changes to the admissibility of fingerprint evidence in New Jersey.

But first, some background.

Fingerprint evidence

While facial recognition results and DNA results can only serve as investigative leads, for the most part fingerprint evidence is acceptable.

Not only to convict a person, but to exonerate a person.

Archie Williams moments after his exoneration on March 21, 2019. Photo by Innocence Project New Orleans. From https://innocenceproject.org/fingerprint-database-match-establishes-archie-williams-innocence/.

I’ve previously discussed the case of Archie Williams, who was freed from prison by the Innocence Project (we’ll return to them later). Williams was sentenced to life in prison without parole in 1983 for a rape and stabbing he did not commit. So how was he freed?

“Commissioner Kimble ordered a status conference at which the court clarified it would invoke its power to obtain the truth in Williams’ case and make sure all possibilities had been explored. Because, in part, of the availability of the NGI fingerprint database and advanced technology, while maintaining their procedural objections, the state agreed to run the test. On March 14, 2019, fingerprint experts at Ron Smith & Associates, in conjunction with the Louisiana State Police Crime Lab, submitted the suitable fingerprint lifts taken from the crime scene into NGI. This search led to an identification of a known individual, Stephen Forbes, a man who had committed similar sexual assaults in the same neighborhood as the victim in Williams’ case.”

Ron Smith is no longer with us (although his associates are), but the Louisiana State Police Crime Lab obviously is, and their match decision of Stephen Forbes (deceased) was legally persuasive.

“Commissioner Kinasiyumki Kimble of the 19th Judicial District Court of East Baton Rouge, Louisiana, vacated the wrongful conviction of Archie Williams.”

A feel-good story. But is fingerprint evidence always reliable? 

Frye (and Daubert) challenges

There are two methods, used in different states, to challenge whether a piece of testimony is legally admissible. According to Bredebot, the older of the two standards is the Frye standard.

The Frye Standard (The “General Acceptance” Test): Think of Frye as the old-school, tried-and-true method. It’s often called the “general acceptance” test. Basically, if a scientific technique or principle is generally accepted by the relevant scientific community, then it’s good to go. It’s like saying, “Hey, all the smart people in this field agree this is legitimate, so we’ll allow it.” This standard is still used in a good number of states, and it’s a bit more conservative. It doesn’t delve into the nitty-gritty of the scientific method itself, but rather whether the scientific community has embraced it.”

This doesn’t only apply to fingerprints, but to any type of scientific evidence. Although the majority of states use the stricter Daubert (in which the judge, not the scientific community, determines admissibility), there are some states that still accept Frye.

Including New Jersey.

State v. French Lee

Which brings us to a recent ruling by the Supreme Court of the State of New Jersey in the case of State v. French Lee. As JD Supra reports:

“A Morgan Lewis team represented the Innocence Project’s national strategic litigation team, serving as amici in the case of State v. French Lee urging the New Jersey Supreme Court to appoint a Special Adjudicator to assist the trial court in assessing the reliability and admissibility of fingerprint evidence and to draft a model jury charge governing the evaluation of such evidence and related testimony. In a landmark, unanimous decision, the Supreme Court agreed, ordering a hearing on the admissibility and reliability of fingerprint evidence and further action to ensure the reliability of such evidence in future trials, marking a significant development in forensic standards for criminal trials in the state.”

Lee was convicted of burglary in the original trial based upon latent fingerprint evidence. When the evidence was challenged…

“The state relied on more than 100 years of judicial acceptance of fingerprint evidence under the Frye standard, emphasizing its history in New Jersey and federal courts. The trial court admitted the evidence without a pretrial hearing.”

Higher courts, however, ruled that the reliability and admissibility of fingerprint evidence must be assessed.

Perhaps the assessment will determine that fingerprint evidence is admissible provided that certain safeguards are implemented: for example, that the latent examiner is not subject to bias before making their forensic examination, or perhaps the blind secondary verification is implemented.

Or the assessment may regard fingeprint evidence as inadmissible, or not sufficient on its own merits to result in a conviction (in other words, just like facial recognition and DNA).

I cannot emphasize this enough; this is potentially a big deal.

What are vendor responsibilities?

It’s attractive to some biometric vendors to pass the buck and say, “This is not my problem. Let the agency worry about it.”

But as I’ve said before in Biometric Update, vendors must disclose responsible uses of biometric data. And that includes designing biometric systems that conform with laws and practices, including the removal of bias from biometric match decisions.

But the technology vendors can only do so much. Agencies themselves must implement policies that remove bias. It’s of no benefit if the vendor’s solution incorporates blind secondary verification if the agencies don’t use it, or even worse instruct their forensic examiners to “confirm that this guy we arrested is the one who committed the crime.”

Big red flag!

Now biometric vendors can educate their prospects on responsible biometric use. And Bredemarket can help biometric vendors develop the educational content.

24/7 Bot Answering Service

A little after 8:30 this evening, our central air conditioning started making a whining noise.

I turned the temperature up to shut the air off, then we called the service number on the magnet attached to the unit.

Even at the late hour, someone at the air conditioning service answered the phone.

I held a conversation with the person and scheduled a service appointment, but I couldn’t help but notice the unusual manner of speech.

  • The overly formal phrasing.
  • The momentary confusion when I spoke over him.
  • The odd stutter when repeating our street address—the number “6” sounded like “66.”

That’s when I realized I was speaking to a bot.

The conversation was good enough, although I still have to see if a technician shows up at the appointed time.

And yes, someone lost a job due to AI, but how much value add would a human provide at 8:30 at night?

Mexico’s Fan ID and the Form (and Order) of Consent

It’s not enough to get consent. You have to get consent that is rigorous enough. And not just in Illinois, but also in Mexico.

Biometric Update:

“Mexico’s anti‑corruption regulator has hit the Mexican Football Federation (FMF) with one of one of the country’s largest-ever privacy penalties. The FMF has been fined 42.8 million Mexican pesos (US$2.14 million) for violations linked to its Fan ID system….

“Mexico’s Ministry of Anti‑Corruption and Good Governance (SABG) said FMF failed to tell fans that the photographs collected for Fan IDs were sensitive biometric data and did not obtain the express written consent required under Mexican law.

“Instead, FMF relied on a simple website checkbox without any mechanism to prove the user providing consent was the actual data subject.”

But if your mobile application’s workflow begins with consent before identity verification, how can you change the order and perform facial recognition to positively identify the person giving consent? After all, the person hasn’t given consent to perform facial recognition to confirm the consenting person “was the actual data subject.”

Unless you resort to a manual consent method.

Google Gemini.

ROC Watch: Even if the Terrorists Win, They Won’t Win in Court

Small comfort if your loved ones die in a terrorist attack, but ROC’s (Rank One Computing’s) product ROC Watch has won a special designation, as Biometric Update reports.

“ROC continues to cement its position in the U.S. biometrics market for defense and law enforcement, with the announcement that its product suite, ROC Watch, has received a Developmental Testing and Evaluation (DT&E) Designation under the U.S. Department of Homeland Security’s (DHS) Support Anti-terrorism by Fostering Effective Technologies (SAFETY) Act.”

So what?

“ROC and customers deploying ROC Watch receive federal liability protections in the event of an act of terrorism.”

Testing and evaluation designations vs. full designations

Note that a Developmental Testing and Evaluation designation is not a full designation, but only applies for…drumroll…testing and evaluation.

Full designations are held by a number of critical infrastructure entities, including stadiums, the Evolv Expedite product, and CLEAR. There are expired certifications held by Lockheed Martin for the FBI’s Next Generation Identification System, and MorphoTrust for its ABIS.

Business concerns override technology concerns

Again, so what?

This illustrates a key principle in biometrics, and in other technologies: while technological concerns are important, business concerns are critically important. Even if your solution is a technological marvel, it doesn’t matter if it runs into legal, organizational, or other bottlenecks.

For this reason, you should always emphasize your prospects’ needs rather than the cool technology.

If you need assistance sharpening your message, Bredemarket can help.

AI Isn’t the Problem: Reputational Damage Is

AI used for evil is bad, but it’s not the worst evil.

Neal K. Shah is victimized

Neal K. Shah self-identifies as “America’s Chief Elder Officer.” And he says that he recently made the news:

“FOX Business just published a story about me – I wish they didn’t have a reason to. Scammers used AI to clone my likeness, and turned it into a WEAPON against the exact people I work to protect – older adults and caregivers.”

According to Shah, the scammers used a Meta tool called Muse Image to create fraudulent deepfakes of Shah endorsing slimeball products. Because of this and other incidents, Meta concluded that Muse Image “missed the mark” and disabled the feature.

(For now. If Muse Image reappears in 2028, don’t be surprised.)

Shah, understandably upset that elderly people were misled, blames evil AI.

“BUT the deeper problem – how trivially easy AI now makes it to impersonate real people and prey on the vulnerable… I think that may only be getting started.”

Shah is wrong. There’s an even deeper problem.

Bredemarket Technology Firm Services weighs in

On LinkedIn, I offered the following comment:

“I don’t know that AI is entirely to blame here. There were fraudsters before AI, and there will be fraudsters after AI.

“The bigger issue is when someone’s name and likeness is fraudulently used—by ANY means—and the platforms do nothing about it.”

Remember when Clifford Irving published Howard Hughes’ autobiography that Hughes never wrote? He didn’t need AI for that. And the scam was revealed when the usually tight-lipped Swiss banks revealed who was really cashing the checks for “author” Howard Hughes.

No evil AI here.

The problems occur after the scam, and aren’t affected by how the scam was perpetrated. The problem is when a platform is scammed, but the platform—a website, a newspaper, whatever—doesn’t bother to correct the record and tell the truth.

Shah:

“I reported [the scam ads] REPEATEDLY – yet they stayed up.”

Now I could have used my Bredemarket Technology Firm Services hat to suggest a solution.

But I didn’t.

I tossed the task elsewhere.

Bredebot weighs in

Now that it’s easier to generate Bredebot content, I let Bredebot write a response.

When someone creates a fake profile using your name, face, and credentials, it is a fast track to reputational damage. But what happens when you hit that “report” button and the platform does absolutely nothing?

For a long time, platforms hid behind broad immunity shields, treating identity fraud like a minor nuisance. But in 2026, the regulatory tide is turning. Relying on passive content moderation is no longer cutting it. Between the FTC’s strict crackdown on impersonation and new federal mandates like the TAKE IT DOWN Act forcing rapid 48-hour responses for deepfakes, platforms that stay passive are looking at massive civil penalties.

When a platform ignores fraud, it isn’t just failing the victim; it’s tanking user trust. It is like hiring a pack of wild wildebeests as marketing consultants, only to wonder why your wombat customers are running away in terror.

If a platform leaves you stranded, you have to document everything, escalate to regulatory channels, and protect your broader digital footprint. Identity security requires proactive defense, not corporate silence. If you need a hand navigating this landscape, John E. Bredehoft at Bredemarket can help you map out a strategy.

I couldn’t have said it better myself.

Now I just have to convince people that I did NOT endorse a death of passwords book.

This is fake. Google Gemini.

But I DO endorse THIS book. Click the pic.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
This is real. Gumroad.

Buyer Language, Vendor Language…And a Unified Taxonomy

Do buyers and vendors speak different languages? Sometimes it seems that way.

BUYER: “If we arrest the wrong people, our mayor may lose the next election.”

VENDOR: “The Really Cool ABIS offers tunable thresholds that allow minimization of false positives.”

Say what?

If you go to the mayor’s campaign manager and spout something about tunable thresholds, the campaign manager will tune you out.

Bredemarket already has a solution to this problem, but Liminal is offering another one.

Bredemarket’s solution: customer focused, benefits oriented

I can sum up my solution with the simple phrase “put yourself in your prospect’s shoes.”

Your prospect doesn’t care about your solution, or about your company. Your prospect only cares about its problems, such as a re-election campaign.

Here’s what a Bredemarket client might say to the mayor’s campaign manager.

VENDOR: “No mayor wants the political nightmare of arresting an innocent person because of a tech glitch. It damages community trust and creates a major liability. The Really Cool ABIS (Automated Biometric Identification System) can drastically cut down the risk of “false positives” (the system wrongly flagging an innocent person).

Kinda long, but I had some splainin to do.

Google Gemini.

But for a vendor to say this, the vendor (or its consultant) must really know ABIS products and function as a biometric product marketing expert.

What if you don’t have a consultant who is a biometric product marketing expert?

Let’s introduce Liminal’s magic word, taxonomy.

Liminal’s solution: A Unified Market Taxonomy

I’ve discussed taxonomies before as a way to organize information. Adobe Experience Manager supports taxonomy creation and automation of same. They’re also used by the UK Home Office in its National Police Chiefs’ Council Minimum POLE Data Standards Dictionary. (POLE is an acronym standing for Person, Object, Location, Event; it has nothing to do with John Paul II.)

Liminal uses its Market Taxonomy to bring the two factions together.

“Markets are messy. Buyers describe their problems in one language, vendors describe their products in another, regulators describe obligations in a third, and practitioners try to hold all of it in their heads at once. Finding trusted market intelligence is hard enough; agreeing on what we’re even looking at is harder still.

“That’s what a market taxonomy is for: one structure that connects what buyers need to what vendors offer, with regulations and market forces shaping the picture at every level.”

So how are they linked? The demand side (buyers) mirrors the supply side (vendors) at every level.

Liminal.

The domain maps to the solution segment. Use cases map to solutions. Requirements map to product capabilities. And translation occurs.

Google Gemini.

In short: even if you’re not a biometric product marketing expert, Liminal lets you fake it.

Taxonomy Man. Google Lyria. Public Domain.

Clinical Intent

This video has nothing to do with health, but is another repurpose of my thoughts on pivoting.

I went into Gemini Pro mode and told Google Lyria to take “Swivel and Solve” and make it longer. Then I made a new landscape video with images from several others: Forge Your Future, It’s Time, Move Now, and the Koala Identification Factors video. Oh, and also some Proving Humanity promotional material.

“Clinical Intent.” Google Lyria. Public Domain.

When I assembled the final video, the result definitely belongs in the Awareness category. Because the assortment of pictures definitely won’t convert.

It doesn’t even dwell on the pivoting message: namely, that when identity, biometric, and technology leaders face product marketing challenges, the old way may not solve these challenges. When the old way doesn’t work, pivot to something that will.

No, the video doesn’t say any of that.

But if you’ve heard of Bredemarket outside of the video, you already know the marketing and writing services I provide for identity, biometric, and technology firms.

Compelling CONTENT Creation

  • Blog posts. Among other projects, I’ve authored a multi-month blog series to attract business to a client. 
  • Case studies and testimonials. Among other projects, I’ve written a dozen case studies to justify a firm’s capabilities to its projects. 
  • LinkedIn articles and posts. The multi-month blog series was designed for repurposing as LinkedIn articles. 
  • White papers. My white papers have made the case for the superiority of my clients’ products and services.

Winning PROPOSAL Development

  • Proposal services (managing, writing, editing, other). My proposals have won business for Bredemarket clients and for my former employers.

Actionable ANALYSIS

  • Analysis services. My market, product, and competitive analyses for Bredemarket clients and former employers have not only gathered necessary information and insights, but have also suggested a path forward.

Act Now

So how can your tech firm benefit from this content?

If you are ready to stop losing prospects, act now and book a free 30 minute content needs assessment and talk to Bredemarket.

Swivel and Solve, Short and Square

Just for fun I created an alternate version of my June “Swivel and Solve” video, dumping the late shift. (And the strike force.)

Swivel and Solve (SQ).

But regardless of the form factor, Bredemarket, a leading biometric product marketing consultant, provides expert content, proposal, and analysis services.

My work has produced over $25 million in revenue for nearly two dozen firms.

To solve your challenges, visit https://bredemarket.com/mark/ and schedule a free meeting.

(“Swivel and Solve” by Google Lyria, Public Domain.)