He’s Just a Stereotype. He Takes His Meth in Grams.

A post in Terrible Maps showed 12 regions in California. I pointed out that was too few.

“In reality, locals get much more granular. A single “SoCal” bucket is amusing; even people from coastal Orange County think people from inland Orange County are alien creatures.

“He’s from…BREAKING.”

“And I live in the IE, which is even more alien.”

Then, a few minutes later.

“Dang autocorrect. Of course I meant BREA.”

Forget about Brea

Returning to my original thought, there is a specific perception of the Inland Empire which we all know about. Warehouses and meth labs are but two examples of the IE stereotype. Not that anyone speaks in detail about logistics per se.

Oh, and the California Institution for Men near (but technically not within) Chino, California.

“The Californians” occasionally touched on the IE.

“What are you doing here? You’re supposed to be in the Chino Correctional Center in Southern California.”

“Well I escaped! I ran down an on ramp and hauled ass across the 5. And then I hitched a ride on the back of a taco truck down to where the 101 meets the 10, you know…”

Not that the 5 is anywhere near Chino…

Google Gemini. Spot the meth lab, the warehouse, and the prison.

Isn’t that…special?

The Specials, “Stereotype.”

Is a 0.0001% EES Border Threat Level Meaningless?

I just reshared Tom Topol’s latest LinkedIn article to my Bredemarket Identity Firm Services readers on LinkedIn and Facebook, focusing on this quote:

“Between October 2025 and April 2026, the EES registered over 52 million border crossings. Entry was refused more than 27,000 times, including to almost 700 people who were identified as posing a security threat to the EU. Several thousand additional travelers were flagged for overstaying the Schengen 90/180-day rule…”

Is Europe over-emphasizing the threat?

But that isn’t how he begins the article.

“Europe’s Biometric Border and the Price of 700 Threats in 52 Million Crossings”

I did the math, and if you only count ACTUAL security threats, rather than visa overstays that COULD become security threats, you’re talking about a very small percentage: 0.0013461538%.

Topol asks:

“The question is not whether the EES caught anything. It is whether what it caught justifies what it costs: in financial terms, in operational disruption, and in the permanent erosion of informational privacy for hundreds of millions of innocent travelers.”

Let’s look at operational disruption. Topol cites GDPR Article 35’s requirement that “a Data Protection Impact Assessment must justify the necessity, suitability, and proportionality of any system processing biometric data at scale.” Topol cites a Spanish case that failed to obtain the required assessment (covered by Biometric Update), then extrapolates that EES is a net burden.

Topol acknowledges the deterrent effect—if fraudsters know their biometrics will be captured, they won’t attempt the fraud—but then notes that the argument “is also entirely unverifiable, and it has historically been used to justify the expansion of every surveillance system ever built.”

Bringing it all back home

Take the experience in my own country.

This isn’t a border issue, but when I joined the biometric industry in 1994, Los Angeles County was beginning to use fingerprint biometrics to ensure that the right people received government benefits—and the wrong people didn’t. Back in those pre-iPhone days only criminals gave their fingerprints, so this and other programs had an unsavory taint in the public’s eye. Yes the county saved money, but was this because fraudsters stayed away, or because legitimate users feared their fingerprints would go to the LAPD? The use of fingerprints for welfare benefits has disappeared today.

Returning to border crossings, our own entry-exit system has been justified by statements such as Senator Lindsey Graham’s 2015 claim about the 9/11 terrorists:

“All the hijackers who attacked — attacked us on 9/11 were visa overstays. So it’s more than just the border. You have got to control your visa program.”

According to FactCheck, Graham was off by 89%. Only two of the 19 terrorists were visa overstays. While the terrorists took advantage of flaws in the visa system, they had the visas.

Emotionally, I’m not convinced

Having spent over 30 years in this industry, I’m not about to chuck security out the window.

Emotionally I can’t do it.

And not because of the OVERLY emotional arguments, the “Jane never celebrated her seventh birthday because a cold-blooded smelly killer took her life.”

I’m talking about run-of-the-mill emotion.

And I have a challenge for you.

Tonight, when you go to bed, leave the front door of your house unlocked. After all, the chances of harm from an unlocked front door are minuscule.

I bet Topol locks HIS door at night.

Philmoco Biometric Consulting: Arkansas Fingerprint Expertise

It’s true that most of your independent consultants aren’t newcomers in their industries. (If they are newcomers, they aren’t any good.)

That’s certainly the case with Phillip Moore’s latest endeavor, Philmoco Biometric Consulting. He has worked with fingerprints for decades.

I worked with Phil after Safran acquired Motorola’s “Printrak” biometric business unit and merged it with Sagem Morpho to create MorphoTrak. (He came from Sagem Morpho, I from Printrak.) Oddly enough, we primarily worked on driver’s license proposals together (which was actually the domain of our chief competitor, Safran’s own MorphoTrust).

Before Sagem Morpho and MorphoTrak, Phil worked for NEC, Crossmatch, Smith Heimann Biometrics, and Identix. After MorphoTrak, Phil worked for Fulcrum Biometrics and other fingerprint firms.

So he knows fingerprints.

And now he’s dispensing his expertise on his own terms…to a specific geographic audience.

“I help Arkansas organizations understand fingerprinting requirements, workflows, and equipment needed to offer compliant fingerprinting services.”

Compliant with what? Compliant with requirements to submit fingerprints to the U.S. Federal Bureau of Investigation’s Next Generation Identification (NGI) system and not having them get rejected.

So if you’re performing fingerprinting in Arkansas, Phil’s your expert. Reach him via Facebook.

“Accept Without Posting” Issue Resolved…Even Though I Appeared To Be Very Evil

Here’s the resolution to the “Accept Without Posting” issue that I discussed on Saturday.

You’ll recall that I initiated a Zelle transfer to my account at “the blue bank,” but the blue bank “placed this transfer on hold so they can conduct further review.”

With no word on what the blue bank was reviewing. And the “blue bank” representative whom I spoke with on Saturday didn’t know either.

  • I had already ruled out the simple explanations, such as either the sending Zelle account or the receiving Zelle account didn’t exist.
  • I figured that perhaps my use of Zelle was the issue. The day before I sent the “on hold” transaction, I had sent another transaction. I figured that two transactions in two days tripped up some odd alert of possible account draining.

Neither of these turned out to be the issue.

On Monday (just after I had rated the “blue bank” 5 out of 10 for its handling of the issue; coincidence, or no?) I received a call from someone at my local “blue bank” branch.

Turns out that the issue was the COMMENT that I attached to the Zelle transfer.

My comment referenced another individual. Without revealing this person’s personally identifiable information (PII), I will state that his first name begins with a K, his last name begins with a P, and he is a “Junior.” So because acronyms are wonderful, I referred to this person as “KP2” in the Zelle transfer field.

Which was an extremely evil thing to do, because that tripped up an anti-money laundering check.

“AML.” Google Lyria. Public Domain.

Basically, anti-money laundering checks verify that a person isn’t transferring money for a sanctioned person.

And I didn’t trip up just ANY anti-money laundering check.

This one was bad.

AML catches evil people.

Really bad.

AML catches evil people.

How bad?

  • Let’s look at ISO 3166 country codes. The alpha 2-digit country code for the Democratic People’s Republic of Korea (North Korea) is…KP. KP-02 is the specific administrative code for South Pyongan Province (Pyeonganbuk-do).
  • And the Korean People’s Army includes a II Corps that is sometimes abbreviated as…KPA II Corps or KPA 2nd Corps.

Back to the call I received from my local “blue bank” branch. The representative didn’t go into all that, but just said that my comment about “KP2” looked like a reference to North Korea.

I burst out laughing.

I gave the “blue bank” representative the full name of K[REDACTED] P[REDACTED] Junior, explained that there were five “KP”s, and that I used numbers to tell them apart.

Ironically, both “KP2” and “KP4” are veterans. I wonder if they realize their initials associate them with this guy.

Kim Jong Un. By Mil.ru, CC BY 4.0, https://commons.wikimedia.org/w/index.php?curid=177498377.

Anyway, my answer satisfied the banker, the hold was removed from the Zelle transfer, and I received the money within minutes.

And I know to be careful when using acronyms beginning with the letter “K” in financial transactions.

Third/Fourth Party Risk Management and Age Verification

Let’s say a bar wants to check the ages of its patrons, but does not want to use the patron’s physical ID card (in my country, usually a driver’s license).

But a bar cannot perform digital age verification on its own. The bar has to contract with some other entity that knows how to do this.

This freaks some people out…massively.

“New cybersecurity research indicates that one of the world’s leading age verification providers collects and shares highly sensitive personal data—including facial photos and device fingerprints—with third parties.”

The research, conducted by the Georgia Institute of Technology and UC Irvine, focused on one of the big age verification vendors, Yoti.

“The research team determined that the process Yoti uses to verify a person’s age broadcasts the person’s personal information to third- and fourth-party companies….

“According to the researchers, the data is…sent to credit card companies, IP geolocation services, and data brokers. The researchers found that the information being shared can be used to identify and track devices. For example, a single verification attempt may transmit a user’s facial image, IP address, and device fingerprint to credit card companies.”

Yet to my knowledge the researchers did not propose an alternative.

Other than having each entity develop its own age verification system. Perhaps someone like Meta could do that, but Frank’s Bar certainly couldn’t.

Age verification is not unique in terms of data sharing. Third Party and Fourth Party Risk Management vendors encounter these issues all the time. And yes, sometimes companies that have other companies’ data are hacked. That’s why they use TPRM in the first place.

And don’t forget that if you don’t use digital age verification, you’re going to use physical age verification, where the guy behind the bar learns EVERYTHING about you. I don’t think that’s necessarily better.

It’s time to think through the consequences of abandoning technology.

What is AI “Retreading”?

You’ve probably noticed my repeated ridicule of companies who ONLY talk about their use of AI. And my concurrent wonder about how car companies never talk about “tire intelligence,” or “TI.”

After all, tires are critically important to car companies, just as AI is critically important to tech companies. But car companies don’t hammer their prospects by interjecting “TI” into every conversation and advertisement.

So it’s time to delve into tires…and one important aspect of the tire industry.

Sailun and retreads

Retreading:

“Retreading has been part of the commercial tire industry for decades, yet for some fleets, hesitation still remains.”

And for individuals. I am personally reluctant to buy a retread.

But Sailun, a tire manufacturer, believes my reluctance is outmoded.

“Concerns around safety, consistency, and durability are often rooted in outdated perceptions of how today’s retread process works. In reality, modern programs follow controlled, standardized procedures shaped by engineering, inspection protocols, and widespread industry adoption.

“Today, nearly 90% of large trucking fleets rely on retreads, and an estimated 44% of commercial truck tires currently in service are in their second life or beyond.”

For details on how some tires (cough, cough, Sailun) are ideally suited for retreading, read the article.

Now let’s delve into AI.

Your favorite LLM…and retreads

Is there an AI equivalent to retreads?

The question initially sounds silly. Every AI prompt is brand new.

But there’s a cost to always getting new responses. A huge cost.

“An anonymous AI consultant told Axios that one of its clients accidentally spent half a billion dollars in a single month because it never bothered to put a usage limit on employee access to Anthropic’s Claude. That is… a lot. Like to the point of straining credulity.”

Even big companies don’t have half a billion dollars to waste on tokens. They would have to fire EVERYBODY, including all their executives and their boards of directors, to fund that level of AI use.

But before a company does something as drastic as actually firing an executive, perhaps it could look at a “retread” strategy.

Take the knowledge gained from AI prompts and store it for future reference without requiring tokens to be burned.

(Bredemarket does this all the time, even though I’m not charged by the token.)

Admittedly the re-use (retreading) of old information lessens exposure to new, updated information. But if AI is getting dumber anyway, that’s a good thing.

Promo For “It’s Time”

I still haven’t natively shared yesterday’s “It’s Time” video on my socials.

And I probably won’t until early Monday morning Pacific Daylight Time (mid-morning in the East). I want to maximize its visibility.

But I plan to reel in Sunday scaries folks by sharing this teaser.

“It’s Time” promo. Google Lyria/Gemini.