Can Your Software Capture Irises with an Android Camera?

Iris solution vendors, I hope you saw the latest and greatest from SAM.gov (PEO-TIS: Contactless Iris Collection Collaboration Event (CE)):

CONTACTLESS iris?

Now wait a minute.

Is anyone actually proposing CONTACT iris collection?

And I’m not talking about the old system of putting your iris really close to the camera. I’m talking about the iris TOUCHING the collection device, like many fingerprint systems do today.

I don’t think so.

But let’s look at the meat of the opportunity.

SOFWERX, in collaboration with USSOCOM Program Executive Office Tactical Information Systems (PEO-TIS), will host a series of events to complete a study of mobile devices (Android-based cell phones and tablets) with built-in cameras for their use in unaided iris localization and collection, including resolution testing and image distortion analysis.

Note the word “unaided.” It’s a lot easier to capture irises if the capture device does the work for you. Soldiers in the field don’t have time to precisely position the camera with an uncooperative subject.

A previous study indicated that it is possible to conduct iris localization using a mobile device camera, but a wider population pool is required to validate these results. A wider population of 500-1000 is adequate to prove the basic viability of the biometric algorithm. 

Hey, it’s not a million people, but it’s not bad.

If you’re an iris solution vendor and register by August 28, here’s the timeline:

  • Phase 1: 30 September 2026 Collaboration Event (CE)
  • Phase 2 – 27 October 2026 to 27 November 2026 Submissions to the Assessment Event (AE) Open
  • Phase 2a – 11 November 2026 Q&A Telecon
  • Phase 3 – 30 November 2026 to 14 December 2026 Downselect
  • Phase 4 – 19 January 2026 [sic] to 21 January 2026 [sic] Assessment Event (AE)
  • Phase 5 – Path Forward

See the SAM.gov announcement for more details.

Since this effort is primarily technical, Bredemarket can’t drive the effort. But if you need assistance in content, proposal, or analysis materials before, during, and after the event, talk to me.

A Less Serious Observation of Memorial Day

Last year I wrote a very serious observation of Memorial Day, noting that it is not just a pool party and grill day.

“To be blunt about it, Memorial Day is a day about death, and if you can’t handle this truth, go back to the pool.”

I encourage you to read this to understand what Memorial Day is about.

Riverside National Cemetery picture Sigris Lopez, CC BY-SA 4.0. Source.

Since I covered the serious side of Memorial Day last year, today I will instead acknowledge that it IS a day for many to relax.

Patriotic shorts inspired by Danie Wylie, but with an Inland Empire feel. (For the IE and other tech firms that need marketing and writing services…tomorrow.)

Google Gemini.

Simplified For The Agency, Not Simplified For The Vendor

When you write something, read it first to ensure that you don’t burst out laughing after reading it.

If you read SAM.gov for fun, you may have seen Notice ID DCSA_2026_HS002126QE023 for Michigan Fingerprint Channeling. Offers are due on April 23, so if you can satisfy the requirements, get working.

As the acronym-aware probably already know, this was issued by the Defense Counterintelligence and Security Agency (DCSA), part of the U.S. Department of Defense (with the secondary title the Department of War).

Why?

“DCSA has a recurring need for a simplified method of filling the anticipated repetitive needs for fingerprint channeling for the purpose of obtaining Criminal History Records Information (CHRI) from the state of Michigan.”

Because it’s a bad thing to make things hard, so DCSA needs a simplified method.

This is explained in the Performance Work Statement that is attached to the Solicitation Form. Another attachment is the Pricing Workbook.

So to make things simple for DCSA, you need to review all three of these documents and provide the approprirate responses.

And don’t forget to review ALL of the incorporated contract clauses, such as this one:

252.232-7006 Wide Area WorkFlow Payment Instructions. (Jan 2023)
WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (JAN 2023)
(a) Definitions. As used in this clause-
“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.
“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).
“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.
“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by
Defense Federal Acquisition Regulation Supplement (DFARS) 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall-
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before
submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/
(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this
contract or task or delivery order:
(1) Document type. The Contractor shall submit payment requests using the following document type(s):
(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.
(ii) For fixed price line items-
(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.
Invoice 2-in-1
(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and
receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.
Invoice 2-in-1
(iii) For customary progress payments based on costs incurred, submit a progress payment request.
(iv) For performance based payments, submit a performance based payment request.
(v) For commercial financing, submit a commercial financing request.
(2) ) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.

OK, that’s not the whole thing. I stopped copying it at the actual Routing Data Table itself.

This is of course a cost of doing business with any large entity, whether it’s the federal government or a multi-billion dollar firm. This who want money from these large organizations put up with it.

And laugh to themselves about the desire for things “simplified.”

The Benefits and Detriments of…um…Targeting

I’ve previously stated that Bredemarket is not the ideal content provider for B2C lifestyle brands. I’ve targeted a target audience of B2G/B2B identity, biometric, and technology firms instead.

Precise targeting can be very good…or it can be very bad.

A Targeted Weapon

Efficiency and progress is ours once more
Now that we have the Neutron bomb
It’s nice and quick and clean and gets things done

From the Dead Kennedys

Some of you may not remember the neutron bomb…and some of you do.

Since 1945, the common depiction of nuclear devastation was of catastrophic damage to people and buildings within a large area.

But then the concept of the neutron bomb was developed. Britannica explains:

“A neutron bomb is actually a small thermonuclear bomb in which a few kilograms of plutonium or uranium, ignited by a conventional explosive, would serve as a fission “trigger” to ignite a fusion explosion….

“Its blast and heat effects would be confined to an area of only a few hundred metres in radius, but within a somewhat larger radius of 1,000–2,000 metres the fusion reaction would…be extremely destructive to living tissue….”

As the popular press summarized it, neutron bombs, unlike older uranium or hydrogen bombs, would spare the buildings and kill the people.

What was missed was that the neutron bomb will kill fewer people in a smaller area.

The benefit of the neutron bomb?

The limited damage area promoted a theory in which neutron bombs could be used on the battlefield to target a limited group of enemy troops. This limited range would theoretically confine the damage to military targets without damaging “a whole civilization.”

But this benefit is also a detriment, as Britannica notes.

“However, other military strategists warned that fielding a “clean” nuclear weapon might only lower the threshold for entering into a full-scale nuclear exchange…”

And of course some opponents objected to the very idea of killing ANY people while leaving the buildings intact. Capitalist values at the forefront?

If you’ve never heard of the neutron bomb, they pretty much disappeared after the end of the Cold War.

Which is odd when you think about it, because the end of the Cold War made countries more likely to conduct small-scale wars against each other. From a military tactical perspective (ignoring the strategic or moral issues), neutron bombs seem perfect for such exchanges.

On DOJ/DoD/DHS ABIS Interoperability

The image at the top of this post was taken from the NIST website and is a from an interoperability slide in a 2016 FBI presentation. Although the reference to “IAFIS” suggests that the image was created long before 2016. No NGI, and no HART either.

Because—while this may make some uncomfortable—biometric interoperability between the Departments of Defense, Homeland Security, and Justice is critically important.

For years after 9/11, the (then) systems from the three Departments were NOT interoperable.

Which made it difficult to identify if a military person or citizenship applicant was a criminal.

Today, while the three current systems use three different data interchange standards (based upon work by NIST), they CAN talk to each other.

We just have to ensure that the interoperability is legal and proper.

Yes, the “Two Presidents” Scenario Could Really Happen

My recent post about two “Presidents” with the power to launch nuclear attacks sounds technologically very difficult, but it’s not impossible. Even biometric modification can happen if an adversary has enough money.

Grok.

But as is true with anything, the technology is easy. The business part is the difficult part.

And most would argue that there is absolutely no way that a scam like this could be pulled off, especially since it would require inside cooperation.

Perhaps you’d better sit down.

August 9, 1974

Washington, DC was in a very confused state on August 9, 1974. When the day began, Richard Nixon was President and Gerald Ford was Vice President. Several hours later Ford would be President and there was no Vice President. (If Ford had suddenly died, Speaker of the House Carl Albert would have become President. If you thought the events of 1973 and 1974 were wild enough, imagine if Albert had become President.)

The morning of August 9 was carefully choreographed, but I am going to concentrate on two events involving Richard Nixon, Alexander Haig, and Henry Kissinger.

  • The first occurred at about 10:35 am when President Richard Nixon’s helicopter lifted off from the South Lawn, headed toward what was then Andrews Air Force Base.
  • The second occurred later, at about 11:35, when White House Chief of Staff walked into the office of Henry Kissinger, in Kissinger’s capacity as Secretary of State. Haig’s arrival was expected, as was the signed letter that he bore from President Nixon (en route to California). The letter was short.

“I hereby resign the Office of President of the United States.”

Kissinger indicated his receipt of the resignation and maintained communications with critical people, including Vice President Gerald Ford.

But there was one other critical person: the Secretary of Defense, James Schlesinger.

And there was one very important part of the choreography that wasn’t mentioned publicly that day.

Back to the Helicopter

I don’t know if “biscuits” existed in 1974, but footballs certainly did. And certainly the concept of continuity hadn’t yet matured to the Carter-Mondale level. But everyone agreed that according to the Constitution, on that day Richard Nixon remained President of the United States until he didn’t.

But according to reality, Nixon was…stressed.

“Schlesinger feared that the president, who seemed depressed and was drinking heavily, might order Armageddon. Nixon himself had stoked official fears during a meeting with congressmen during which he reportedly said, “I can go in my office and pick up a telephone, and in 25 minutes, millions of people will be dead.” Senator Alan Cranston had phoned Schlesinger, warning about “the need for keeping a berserk president from plunging us into a holocaust.””

And Schlesinger acted. When a liberal Democratic Senator demands action from a conservative Administration, sometimes things happen.

While some of the 1974 actions of Schlesinger, Kissinger, and Haig during the “final days” are murky, there is general agreement that Schlesinger gave a rather unusual order to the military.

“[I]n the final days of the Nixon presidency he had issued an unprecedented set of orders: If the president gave any nuclear launch order, military commanders should check with either him or Secretary of State Henry Kissinger before executing them.”

This is entirely against the Constitution. If the Vice President and Cabinet doubted the sanity of the President, the proper avenue was a 25th Amendment removal—not an inferior official disobeying the instructions of the Commander-in-Chief.

However, in those strange days, in which many things happened in secret, one can understand why Schlesinger did what he did.

But there was one other critical decision that was made on August 9.

Remember when President Nixon boarded the helicopter?

“[T]he most critical tool of the modern presidency had already been taken away from him. He never noticed it, but the nuclear “football” didn’t travel with him as he boarded the helicopter, and later, Air Force One for his flight back to California.”

Yes, the football. The thing that was ALWAYS with the President because the USSR could launch a nuclear attack at any moment.

Remember that Nixon was still President an hour after boarding the helicopter, when Kissinger received a visit from Haig. But if the U.S. had been attacked during that hour, the President couldn’t respond.

And the Vice President didn’t have the power to respond.

The football appears to have been in the custody of military aides outside the East Room, awaiting the moment that Gerald Ford would take the oath of office. (Although he was already President once Kissinger indicated his receipt of the resignation letter.)

But…who controlled the football?

Schlesinger?

Kissinger?

Carl Albert?

In the end nothing bad happened, but it could have.

And it’s therefore entirely possible that the aforementioned “two Presidents” scenario could happen.

Two Footballs, Two Biscuits, Two Presidents: A Cybersecurity Nightmare.

Last year I wrote about a biscuit and a football, but I wasn’t talking about the snack spread on game day.

Google Gemini.

I was talking about the tools the United States President uses (as Commander-in-Chief) for identity verification to launch a nuclear attack.

But sometimes you have to pass the football. If the President is temporarily or permanently incapacitated in an attack, the Vice President also has a football and a biscuit. Normally the Vice President’s biscuit isn’t activated, but when certain Constitutional criteria are met it becomes operative.

Other than this built-in redundancy, the system assumes one football, one biscuit, and one President.

If you’re a cybersecurity expert, you know this assumption is the assumption of a fool.

  • It is not impossible to have duplicate functional footballs and duplicate functional biscuits.
  • And it is not impossible to have duplicate functional Presidents, with identical face, voice, finger, and iris biometrics. Yes, it’s highly unlikely, but it’s not impossible. If the target is important enough, adversaries will spend the money.
Grok.

And most of us will never know the answer to this question, but how do government cybersecurity experts prevent this?

Biscuit-based Identity Authentication and Authorization

Some of us authenticate ourselves to unlock our smartphones. Others authenticate to access confidential corporate information. A few authenticate to wield the power to annihilate the world.

The football and the biscuit

In the United States, the President (Commander-in-Chief) has a “biscuit.”

Google Gemini.

“The nuclear biscuit is a card with authentication codes that acts as the President’s personal key to unlocking America’s nuclear arsenal.

“The biscuit acts a lot like a two-factor authentication device or app. Its codes are updated regularly, and it works in connection with the nuclear football to verify the President’s identity. Without the biscuit, the President can’t order a nuclear strike, even if they have the football itself.”

Factors of authentication

Here are the three authentication factors that the biscuit reportedly uses.

“Something you have is quite an obvious one, you needed to have the actual Biscuit and the codes within. 

“Something you know is when you opened the Biscuit. It had many codes printed on the cards and all were false apart from one. The President would have been told the position of the real code when he first took office. He would also be told each time the Biscuit was changed. 

“For something you are, the phone line the President would need to contact has no number. It can only be contacted via a secure military phone. This phone would be handed to the President by one of his security team who would obviously not hand this phone to anyone but the President.”

Now you can argue that the phone line is not a TRUE something you are factor. A devious security team member could hand the phone to someone who SOUNDS like the President.

And there’s another complication.

Passing the football

Let’s say that a President is away from Washington. Say, at a school in Florida.

And all of a sudden attacks are launched in multiple U.S. cities.

What if an attack were launched in Florida, incapacitating the President, either temporarily of permanently?

In such an attack, the country and the world cannot afford to wait for hours for the football to be flown to wherever Richard Cheney is. 

U.S. National Archives. Link.

The solution? Two footballs (at least).

“Believing that the vice president should be a partner in national security policymaking, President Jimmy Carter assigned a football to Vice President Walter Mondale and this became the practice for future U.S. administrations.”

Outside the U.S. Russia has a similar system called the “Cheget,” and other nuclear countries presumably have similar procedures to authenticate the persons or persons authorized to launch nuclear weapons.

Your football and biscuit

If you are an identity vendor or customer, you may have your own authentication and authorization procedures. While a breach of your procedures won’t result in the annihilation of civilization, it could create its own damage.

Do you need help describing the security of your identity solution?

Talk to Bredemarket.

Business Concerns Always Override Technology Concerns

The Institute for Defense and Government Advancement (IDGA) recently released some survey results. Now I don’t want to simply reproduce the results; go here to download your own copy of the report.

But I do want to say this.

“A large number” of IDGA survey respondents expressed concern about “Interagency information sharing.”

  • This is NOT a technology concern. The technologies exist to enable information sharing. For example, one of Bredemarket’s clients recently made the technological changes necessary to allow an application, designed to interface to agency A, to instead interface to agency B.
  • No, this is a business concern—or in this case a governmental concern. A matter of setting up the processes to allow Bob from agency A to exchange data with Judy from agency B. Even though Bob thinks that Judy is a bozo, and vice versa.

And while we’re on the topic…

If you’re worried about Big Government (the FBI and the CIA and the BBC, BB King, and Doris Day) (or INTERPOL and Deutsche Bank, FBI and Scotland Yard) combining all their information to entrap you, your fears may be difficult to realize. Yes, there are cases in which the agencies share data. But there are also cases where they don’t, because it’s in an agency’s interest to keep its data to itself.

Agencies usually ask the question “How can I GET the data from the Bureau of Stuff?” They normally don’t ask the question “How can I GIVE my data to the Bureau of Stuff?”

And that’s why agencies run into problems sharing data.

Dig It.
Computer World.