An Abundance of Data is the New Oxygen…Maybe

I previously wrote about how clean data is the new oxygen (stealing a phrase from someone else), but sometimes more data is better. Sometimes.

Let me use the fingerprint example. If you have a single fingerprint from one person, you have data that you can use to match against a person’s tenprint record.

Grok.

But if you have two fingerprints, then you have twice as much data for the match. And Mister Math tells us that ten fingerprints yields much more data.

Now there are cases where you don’t have all ten search prints. Perhaps you’re taking latent prints from a crime scene and the suspect didn’t carefully leave all ten prints. Or you’re using contactless fingerprint capture and for some reason didn’t get the full tenprint record. But if you can get all ten fingerprints for search, then your match accuracy increases.

But is an abundance of data better?

Only if it’s clean.

If finger numbers are misclassified, or if fingerprints from multiple people are mixed in the same individual record, or if the minutiae are not marked correctly, then the dirty data messes up your process.

Which is why the quality of data in a fingerprint database is important.

And if you need to talk about your fingerprint product’s quality assurance measures, Bredemarket can help. Book a free meeting with me to discuss your needs.

Revealed, Alternate Version

I went ahead and created my original concept of this reel.

Revealed, Alternate Version.

The third version, using Frank Zappa’s “A Little Green Rosetta,” was only created as an Instagram story and will therefore disappear from public view by Tuesday evening.

I guessed that’s supposed to encourage you to subscribe to the Bredemarket Instagram account, but I don’t think Green Rosetta is a strong selling point. Too bad “Watermelon in Easter Hay” doesn’t fit the reel subject matter.

Revealed

On Monday afternoon, I was writing “draft 0.5” of a document for a Bredemarket client. Among other topics, the document noted how the quality of biometric capture affects future identification capability.

By Monday evening…this happened.

Revealed.

By the way, the accompanying music is “Dramatic Emotional Piano” by makesound music.

Although when I was originally conceptualizing the silhouette, I was thinking of the instrumental interlude toward the end (about 4 minutes in) of Elton John’s “I’ve Seen That Movie Too.

Yeah, that song’s over fifty years on. Something I will address on my personal LinkedIn profile later this evening.

I Know This “Scam of the Day”: LinkedIn Employment Scams

I read “Scam of the Day” on Scamicide…well, daily. And the January 17 edition discussed a scam I know all too well.

“A recent development is scammers using the name of legitimate companies that are hiring and approaching their victims through LinkedIn’s direct messaging feature.  They then create counterfeit websites that look like the websites of the legitimate companies they are posing as and ask the job seekers for personal information…”

And you can guess what happens with that personal information. It doesn’t land you a real job, that’s for sure.

In addition to the tips that Scamicide provides, I have an additional one. BEFORE you provide your resume, before you send them a connection request, or definitely before you engage on Telegram or WhatsApp, ask this question:

“Can you provide me with your corporate email address?”

This usually shuts scammers up very quickly.

But don’t forget that while job applicants are avoiding fraudulent employers, legitimate employers are avoiding fraudulent applicants…perhaps from North Korea.

Who or What Requires Authorization?

There are many definitions of authorization, but the one in RFC 4949 has the benefit of brevity.

“An approval that is granted to a system entity to access a system resource.”

Non-person Entities Require Authorization

Note that it uses the word “entity.” It does NOT use the word “person.” Because the entity requiring authorization may be a non-person entity.

I made this point in a previous post about attribute-based access control (ABAC), when I quoted from the 2014 version of NIST Special Publication 800-162. Incidentally, if you wonder why I use the acronym NPE (non-person entity) rather than the acronym NHI (non-human identity), this is why.

“A subject is a human user or NPE, such as a device that issues access requests to perform operations on objects. Subjects are assigned one or more attributes.”

If you have a process to authorize people, but don’t have a process to authorize bots, you have a problem. Matthew Romero, formerly of Veza, has written about the lack of authorization for non-human identities.

“Unlike human users, NHIs operate without direct oversight or interactive authentication. Some run continuously, using static credentials without safeguards like multi-factor authentication (MFA). Because most NHIs are assigned elevated permissions automatically, they’re often more vulnerable than human accounts—and more attractive targets for attackers. 

“When organizations fail to monitor or decommission them, however, these identities can linger unnoticed, creating easy entry points for cyber threats.”

Veza recommends that people use a product that monitors authorizations for both human and non-human identities. And by the most amazing coincidence, Veza offers such a product.

People Require Authorization

And of course people require authorization also. They need authorization:

It’s not enough to identify or authenticate a person or NPE. Once that is done, you need to confirm that this particular person has the authorization to…launch a nuclear bomb. Or whatever.

Your Customers Require Information on Your Authorization Solution

If your company offers an authorization solution, and you need Bredemarket’s content, proposal, or analysis consulting help, talk to me.

On Acquired Identities

Most of my discussions regarding identity assume the REAL identity of a person.

But what if someone acquires the identity of another? For example, when the late Steve Bridges impersonated George W. Bush?

White House photo by Kimberlee Hewitt – whitehouse.gov, President George W. Bush and comedian Steve Bridges, Public Domain, https://commons.wikimedia.org/w/index.php?curid=3052515

Or better still, what when multiple people adopt an identity?

Google Gemini.

And by the way, Charlie Chaplin said that he NEVER entered a Charlie Chaplin lookalike contest…and came in third.

Grok.

Of course, these assumed identities require alterations that liveness detection should detect.

As a biometric product marketing expert should know.

Landscape.

Singer/songwriters…and Deepfakes

I was just talking about singers, songwriters, and one singer who pretended to be a songwriter.

Of course, some musicians can be both.

Willie Nelson has written songs for others, sung songs written by others, and sung his own songs.

But despite the Grok deepfake I shared last October, Willie is not known as a rapper.

This is fake. Grok.

CIBS: Keeping Secrets From NGI

An interesting item popped up in SAM.gov. According to a Request for Information (RFI) due February 20, the FBI may have interest in a system for secret biometric searches.

“The FBI intends to identify available software solutions to store and search subjects at the classified level.  This solution is not intended to replace the Next Generation Identification System Functionality, which was developed and implemented in collaboration with the FBI’s federal, state, local, tribal, and territorial partners. The solution shall reside at the Secret and/or Top-Secret/SCI level with the ability to support data feeds from external systems.  The solution must allow the ability to enroll and search face, fingerprint, palmprint, iris, and latent fingerprints, and associated biographic information with a given set of biometrics.”

Now remember that the Next Generation Identification (NGI) system is protected from public access by requiring all users to adhere to the CJIS Security Requirements. But the CJIS Security Requirements aren’t Secret or Top Secret. These biometric searches, whatever they are, must REALLY be kept from prying eyes.

The RFI itself is 8 pages long, and is mysteriously numbered as RFI 01302025. I would have expected an RFI number 01152026. I believe this was an editing error, since FBI RFI 01302025 was issued in 2025 for a completely different purpose.

Whatever the real number is, the RFI is labeled “Classified Identity-Based Biometric System.” No acronym was specified, so I’m self-acronyming it as CIBS. Perhaps the system has a real acronym…but it’s secret.

If your company can support such a system from a business, technical, and security perspective, the due date is February 20 and questions are due by February 2. See SAM.gov for details.