We Survived Gummy Fingers. We’re Surviving Facial Recognition Inaccuracy. We’ll Survive Voice Spoofing.

(Part of the biometric product marketing expert series)

Some of you are probably going to get into an automobile today.

Are you insane?

The National Highway Traffic Safety Administration has released its latest projections for traffic fatalities in 2022, estimating that 42,795 people died in motor vehicle traffic crashes.

From https://www.nhtsa.gov/press-releases/traffic-crash-death-estimates-2022

When you have tens of thousands of people dying, then the only conscionable response is to ban automobiles altogether. Any other action or inaction is completely irresponsible.

After all, you can ask the experts who want us to ban biometrics because it can be spoofed and is racist, so therefore we shouldn’t use biometrics at all.

I disagree with the calls to ban biometrics, and I’ll go through three “biometrics are bad” examples and say why banning biometrics is NOT justified.

  • Even some identity professionals may not know about the old “gummy fingers” story from 20+ years ago.
  • And yes, I know that I’ve talked about Gender Shades ad nauseum, but it bears repeating again.
  • And voice deepfakes are always a good topic to discuss in our AI-obsessed world.

Example 1: Gummy fingers

My recent post “Why Apple Vision Pro Is a Technological Biometric Advance, but Not a Revolutionary Biometric Event” included the following sentence:

But the iris security was breached by a “dummy eye” just a month later, in the same way that gummy fingers and face masks have defeated other biometric technologies.

From https://bredemarket.com/2023/06/12/vision-pro-not-revolutionary-biometrics-event/

A biometrics industry colleague noticed the rhyming words “dummy” and “gummy” and wondered if the latter was a typo. It turns out it wasn’t.

To my knowledge, these gummy fingers do NOT have ridges. From https://www.candynation.com/gummy-fingers

Back in 2002, researcher Tsutomu Matsumoto used “gummy bears” gelatin to create a fake finger that fooled a fingerprint reader.

Back in 2002, this news WAS really “scary,” since it suggested that you could access a fingerprint reader-protected site with something that wasn’t a finger. Gelatin. A piece of metal. A photograph.

Except that the fingerprint reader world didn’t stand still after 2002, and the industry developed ways to detect spoofed fingers. Here’s a recent example of presentation attack detection (liveness detection) from TECH5:

TECH5 participated in the 2023 LivDet Non-contact Fingerprint competition to evaluate its latest NN-based fingerprint liveness detection algorithm and has achieved first and second ranks in the “Systems” category for both single- and four-fingerprint liveness detection algorithms respectively. Both submissions achieved the lowest error rates on bonafide (live) fingerprints. TECH5 achieved 100% accuracy in detecting complex spoof types such as Ecoflex, Playdoh, wood glue, and latex with its groundbreaking Neural Network model that is only 1.5MB in size, setting a new industry benchmark for both accuracy and efficiency.

From https://tech5.ai/tech5s-mobile-fingerprint-liveness-detection-technology-ranked-the-most-accurate-in-the-market/

TECH5 excelled in detecting fake fingers for “non-contact” reading where the fingers don’t even touch a surface such as an optical surface. That’s appreciably harder than detecting fake fingers that touch contact devices.

I should note that LivDet is an independent assessment. As I’ve said before, independent technology assessments provide some guidance on the accuracy and performance of technologies.

So gummy fingers and future threats can be addressed as they arrive.

But at least gummy fingers aren’t racist.

Example 2: Gender shades

In 2017-2018, the Algorithmic Justice League set out to answer this question:

How well do IBM, Microsoft, and Face++ AI services guess the gender of a face?

From http://gendershades.org/. Yes, that’s “http,” not “https.” But I digress.

Let’s stop right there for a moment and address two items before we continue. Trust me; it’s important.

  1. This study evaluated only three algorithms: one from IBM, one from Microsoft, and one from Face++. It did not evaluate the hundreds of other facial recognition algorithms that existed in 2018 when the study was released.
  2. The study focused on gender classification and race classification. Back in those primitive innocent days of 2018, the world assumed that you could look at a person and tell whether the person was male or female, or tell the race of a person. (The phrase “self-identity” had not yet become popular, despite the Rachel Dolezal episode which happened before the Gender Shades study). Most importantly, the study did not address identification of individuals at all.

However, the findings did find something:

While the companies appear to have relatively high accuracy overall, there are notable differences in the error rates between different groups. Let’s explore.

All companies perform better on males than females with an 8.1% – 20.6% difference in error rates.

All companies perform better on lighter subjects as a whole than on darker subjects as a whole with an 11.8% – 19.2% difference in error rates.

When we analyze the results by intersectional subgroups – darker males, darker females, lighter males, lighter females – we see that all companies perform worst on darker females.

From http://gendershades.org/overview.html

What does this mean? It means that if you are using one of these three algorithms solely for the purpose of determining a person’s gender and race, some results are more accurate than others.

Three algorithms do not predict hundreds of algorithms, and classification is not identification. If you’re interested in more information on the differences between classification and identification, see Bredemarket’s November 2021 submission to the Department of Homeland Security. (Excerpt here.)

And all the stories about people such as Robert Williams being wrongfully arrested based upon faulty facial recognition results have nothing to do with Gender Shades. I’ll address this briefly (for once):

  • In the United States, facial recognition identification results should only be used by the police as an investigative lead, and no one should be arrested solely on the basis of facial recognition. (The city of Detroit stated that Williams’ arrest resulted from “sloppy” detective work.)
  • If you are using facial recognition for criminal investigations, your people had better have forensic face training. (Then they would know, as Detroit investigators apparently didn’t know, that the quality of surveillance footage is important.)
  • If you’re going to ban computerized facial recognition (even when only used as an investigative lead, and even when only used by properly trained individuals), consider the alternative of human witness identification. Or witness misidentification. Roeling Adams, Reggie Cole, Jason Kindle, Adam Riojas, Timothy Atkins, Uriah Courtney, Jason Rivera, Vondell Lewis, Guy Miles, Luis Vargas, and Rafael Madrigal can tell you how inaccurate (and racist) human facial recognition can be. See my LinkedIn article “Don’t ban facial recognition.”

Obviously, facial recognition has been the subject of independent assessments, including continuous bias testing by the National Institute of Standards and Technology as part of its Face Recognition Vendor Test (FRVT), specifically within the 1:1 verification testing. And NIST has measured the identification bias of hundreds of algorithms, not just three.

In fact, people that were calling for facial recognition to be banned just a few years ago are now questioning the wisdom of those decisions.

But those days were quaint. Men were men, women were women, and artificial intelligence was science fiction.

The latter has certainly changed.

Example 3: Voice spoofs

Perhaps it’s an exaggeration to say that recent artificial intelligence advances will change the world. Perhaps it isn’t. Personally I’ve been concentrating on whether AI writing can adopt the correct tone of voice, but what if we take the words “tone of voice” literally? Let’s listen to President Richard Nixon:

From https://www.youtube.com/watch?v=2rkQn-43ixs

Richard Nixon never spoke those words in public, although it’s possible that he may have rehearsed William Safire’s speech, composed in case Apollo 11 had not resulted in one giant leap for mankind. As noted in the video, Nixon’s voice and appearance were spoofed using artificial intelligence to create a “deepfake.”

It’s one thing to alter the historical record. It’s another thing altogether when a fraudster spoofs YOUR voice and takes money out of YOUR bank account. By definition, you will take that personally.

In early 2020, a branch manager of a Japanese company in Hong Kong received a call from a man whose voice he recognized—the director of his parent business. The director had good news: the company was about to make an acquisition, so he needed to authorize some transfers to the tune of $35 million. A lawyer named Martin Zelner had been hired to coordinate the procedures and the branch manager could see in his inbox emails from the director and Zelner, confirming what money needed to move where. The manager, believing everything appeared legitimate, began making the transfers.

What he didn’t know was that he’d been duped as part of an elaborate swindle, one in which fraudsters had used “deep voice” technology to clone the director’s speech…

From https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/?sh=8e8417775591

Now I’ll grant that this is an example of human voice verification, which can be as inaccurate as the previously referenced human witness misidentification. But are computerized systems any better, and can they detect spoofed voices?

Well, in the same way that fingerprint readers worked to overcome gummy bears, voice readers are working to overcome deepfake voices. Here’s what one company, ID R&D, is doing to combat voice spoofing:

IDVoice Verified combines ID R&D’s core voice verification biometric engine, IDVoice, with our passive voice liveness detection, IDLive Voice, to create a high-performance solution for strong authentication, fraud prevention, and anti-spoofing verification.

Anti-spoofing verification technology is a critical component in voice biometric authentication for fraud prevention services. Before determining a match, IDVoice Verified ensures that the voice presented is not a recording.

From https://www.idrnd.ai/idvoice-verified-voice-biometrics-and-anti-spoofing/

This is only the beginning of the war against voice spoofing. Other companies will pioneer new advances that will tell the real voices from the fake ones.

As for independent testing:

A final thought

Yes, fraudsters can use advanced tools to do bad things.

But the people who battle fraudsters can also use advanced tools to defeat the fraudsters.

Take care of yourself, and each other.

Jerry Springer. By Justin Hoch, CC BY 2.0, https://commons.wikimedia.org/w/index.php?curid=16673259

From EUDCC to GDHCN: The Evolution of Vaccine Certificates

Back in 2021, it seemed that I was commenting on the EU Digital COVID Certificate (EUDCC) ad nauseum. The EUDCC is the “vaccine passport” that was developed to allow people in member EU countries to prove their COVID vaccination status in another EU country.

From the EC site.

My most recent post on the EUDCC was written on August 30, 2021, and discussed the International Air Transport Association (IATA) endorsement of the EUDCC as a global standard. But did it matter? I took a look at how global standards are adopted (hint: brute force):

If a lot of people like something, it’s a standard.

If a trillion dollar company likes something, and I like something different, then the thing that the trillion dollar company likes is a standard.

If two trillion dollar companies like two different things…it can get messy.

From https://bredemarket.com/2021/08/30/iata-endorses-the-eudcc-but-will-it-matter/

August 2021 was the last time that I wrote about the EUDCC in the Bredemarket blog. Until now.

Enter…WHO?

You know how standards are adopted by brute force from big players? Well, one big player has forced itself into the discussion. That player is the World Health Organization, commonly known as WHO.

It seems to me they give these vaccine certificates now-a-days very peculiar names. By Public Domain – Snapshot Image – https://archive.org/details/ClassicComedyTeams, Public Domain, https://commons.wikimedia.org/w/index.php?curid=25914575

But according to Masha Borak at Biometric Update, the WHO is just recognizing that the “EU” Digital COVID Certificate has expanded far beyond the EU.

Stella Kyriakides, the European commissioner for health and food safety (announced) that the voluntary certificate program has already been taken up by almost 80 countries.

From https://www.biometricupdate.com/202306/united-nations-taking-over-eu-covid-certificate-program-july-1

Last I checked there were not 80 countries in the EU. So this health standards thing took off after the initial hiccups. Although the Wikipedia list of non-EU adopting countries does not include two big players—the United States and China (the same two countries I cited in my August 2021 post).

Therefore, it made sense for WHO to get in on the act with its Global Digital Health Certification Network, allowing worldwide responses to post-COVID issues.

WHO’s Global Digital Health Certification Network is an open-source platform, built on robust & transparent standards that establishes the first building block of digital public health infrastructure for developing a wide range of digital products for strengthening pandemic preparedness and to deliver better health for all….

The GDHCN is builds (sic) upon the experience of regional networks for COVID-19 Certificates and takes up the infrastructure and experiences with the digital European Union Digital COVID Certificate (EU DCC) system, which has seen adoption across all Member States of the EU as well as 51 non-EU countries and territories. The GDHCN has been designed to be interoperable with other existing regional networks (e.g., ICAO VSD-NC, DIVOC, LACPass, SMART Health Cards) specifications. 

From https://www.who.int/initiatives/global-digital-health-certification-network

On the surface it sounds great, but we’ll see what happens when it goes live (Borak states that the go-live date is July 1).

And we’ll see how it expands:

To facilitate the uptake of the EU DCC by WHO and contribute to its operation and further development, WHO and the European Commission have agreed to partner in digital health.

This partnership will work to technically develop the WHO system with a staged approach to cover additional use cases, which may include, for example, the digitisation of the International Certificate of Vaccination or Prophylaxis. Expanding such digital solutions will be essential to deliver better health for citizens across the globe.

From https://www.who.int/news/item/05-06-2023-the-european-commission-and-who-launch-landmark-digital-health-initiative-to-strengthen-global-health-security

And most importantly, we’ll see which countries participate—and which countries don’t.

Three Ways to Identify and Share Your Identity Firm’s Differentiators

(Part of the biometric product marketing expert series)

Are you an executive with a small or medium sized identity/biometrics firm?

If so, you want to share the story of your identity firm. But what are you going to say?

How will you figure out what makes your firm better than all the inferior identity firms that compete with you?

How will you get the word out about why your identity firm beats all the others?

Are you getting tired of my repeated questions?

Are you ready for the answers?

Your identity firm differs from all others

Over the last 29 years, I (John E. Bredehoft of Bredemarket) have worked for and with over a dozen identity firms, either as an employee or as a consultant.

You’d think that since I have worked for so many different identity firms, it’s an easy thing to start working with a new firm by simply slapping down the messaging that I’ve created for all the other identity firms.

Nothing could be further from the truth.

Designed by Freepik.

Every identity firm needs different messaging.

  • The messaging that I created in my various roles at IDEMIA and its corporate predecessors was dramatically different than the messaging I created as a Senior Product Marketing Manager at Incode Technologies, which was also very different from the messaging that I created for my previous Bredemarket clients.
  • IDEMIA benefits such as “servicing your needs anywhere in the world” and “applying our decades of identity experience to solve your problems” are not going to help with a U.S.-only firm that’s only a decade old.
  • Similarly, messaging for a company that develops its own facial recognition algorithms will necessarily differ from messaging for a company that chooses the best third-party facial recognition algorithms on the market.

So which messaging is right?

It depends on who is paying me.

How your differences affect your firm’s messaging

When creating messaging for your identity firm, one size does not fit all, for the reasons listed above.

The content of your messaging will differ, based upon your differentiators.

  • For example, if you were the U.S.-only firm established less than ten years ago, your messaging would emphasize the newness of your solution and approach, as opposed to the stodgy legacy companies that never updated their ideas.
  • And if your firm has certain types of end users, such as law enforcement users, your messaging would probably feature an abundance of U.S. flags.

In addition, the channels that you use for your messaging will differ.

Identity firms will not want to market on every single social media channel. They will only market on the channels where their most motivated buyers are present.

  • That may be your own website.
  • Or LinkedIn.
  • Or Facebook.
  • Or Twitter.
  • Or Instagram.
  • Or YouTube.
  • Or TikTok.
  • Or a private system only accessible to people with a Top Secret Clearance.
  • Or display advertisements located in airports.
From https://www.youtube.com/watch?v=H02iwWCrXew

It may be more than one of these channels, but it probably won’t be all of them.

But before you work on your content or channels, you need to know what to say, and how to communicate it.

How to know and communicate your differentiators

As we’ve noted, your firm is different than all others.

  • How do you know the differences?
  • How do you know what you want to talk about?
  • How do you know what you DON’T want to talk about?

Here are three methods to get you started on knowing and communicating your differentiators in your content.

Method One: The time-tested SWOT analysis

If you talk to a marketer for more than two seconds about positioning a company, the marketer will probably throw the acronym “SWOT” back at you. I’ve mentioned the SWOT acronym before.

For those who don’t know the acronym, SWOT stands for

  • Strengths. These are internal attributes that benefit your firm. For example, your firm is winning a lot of business and growing in customer count and market share.
  • Weaknesses. These are also internal attributes, but in this case the attributes that detract from your firm. For example, you have very few customers.
  • Opportunities. These are external factors that enhance your firm. One example is a COVID or similar event that creates a surge in demand for contactless solutions.
  • Threats. The flip side is external factors that can harm your firm. One example is increasing privacy regulations that can slow or halt adoption of your product or service.

If you’re interested in more detail on the topic, there are a number of online sources that discuss SWOT analyses. Here’s TechTarget’s discussion of SWOT.

The common way to create the output from a SWOT analysis is to create four boxes and list each element (S, W, O, and T) within a box.

By Syassine – Own work, CC BY-SA 3.0, https://commons.wikimedia.org/w/index.php?curid=31368987

Once this is done, you’ll know that your messaging should emphasize the strengths and opportunities, and downplay or avoid the weaknesses and threats.

Or alternatively argue that the weaknesses and threats are really strengths and opportunities. (I’ve done this before.)

Method Two: Think before you create

Personally, I believe that a SWOT analysis is not enough. Before you use the SWOT findings to create content, there’s a little more work you have to do.

I recommend that before you create content, you should hold a kickoff of the content creation process and figure out what you want to do before you do it.

During that kickoff meeting, you should ask some questions to make sure you understand what needs to be done.

I’ve written about kickoffs and questions before, and I’m not going to repeat what I already said. If you want to know more:

Method Three: Send in the reinforcements

Now that you’ve locked down the messaging, it’s time to actually create the content that differentiates your identity firm from all the inferior identity firms in the market. While some companies can proceed right to content creation, others may run into one of two problems.

  • The identity firm doesn’t have any knowledgeable writers on staff. To create the content, you need people who understand the identity industry, and who know how to write. Some firms lack people with this knowledge and capability.
  • The identity firm has knowledgeable writers on staff, but they’re busy. Some companies have too many things to do at once, and any knowledgeable writers that are on staff may be unavailable due to other priorities.
Your current staff may have too much to do. By Backlit – Own work, CC BY-SA 3.0, https://commons.wikimedia.org/w/index.php?curid=12225421

This is where you supplement you identity firm’s existing staff with one or more knowledgeable writers who can work with you to create the content that leaves your inferior competitors in the dust.

What is next?

So do you need a knowledgeable biometric content marketing expert to create your content?

One who has been in the biometric industry for 29 years?

One who has been writing short and long form content for more than 29 years?

Are you getting tired of my repeated questions again?

Well then I’ll just tell you that Bredemarket is the answer to your identity/biometric content marketing needs.

Are you ready to take your identity firm to the next level with a compelling message that increases awareness, consideration, conversion, and long-term revenue? Let’s talk today!

Why Your Business Needs an Obsessive Content Marketer

Compulsions and obsessions can be bad things, or they can be good things if channeled correctly.

What if Bredemarket provided me an outlet to chnnel my compulsions and obsessions to help your business grow?

Compulsions and obsessions

I recently wrote a three-post series (first post in the series here) that frequently used the word “compulsion.”

I almost used the word “obsession” in conjunction with the word compulsion, but decided not to make light of a medical condition that truly debilitates some people.

I used the word compulsion to refer to two things about me:

Writing compulsion, or writing obsession. Designed by Freepik.

While compulsions and obsessions can certainly be bad things, when harnessed properly they can provide good for the world.

Like a butterfly.

Animotion on embracing an obsession

When people of a certain age hear the word “obsession,” they may think of the 1980s song by the band Animotion.

From https://www.youtube.com/watch?v=hIs5StN8J-0

Unfortunately for us, 90% of the song deals with the negative aspects of a person obsessing over another person. If you pick through the lyrics of the Animotion song “Obsession” and forget about what (or who) the singer is obsessing about, you can find isolated phrases that describe how an obsession can motivate you.

  • “I cannot sleep”
  • “Be still”
  • “I will not accept defeat”

But thankfully, there are more positive ways to embrace an obsession.

Justin Welsh on embracing an obsession

While Justin Welsh’s July 2022 post “TSS #028: Don’t Pick a Niche. Embrace an Obsession” is targeted for solopreneurs, it could just as easily apply to those who work for others. Regardless of your compensation structure, why do you choose to work where you do?

For Welsh, the practice of picking a niche risks commoditization.

They end up looking like, sounding like, and acting like all of their competition. The internet is full of copycats and duplicates.

From https://www.justinwelsh.me/blog/dont-pick-a-niche-embrace-an-obsession

(For example, I’d bet that all of the people who are picking a niche know better than to cite the Animotion song “Obsession” in a blog post promoting their business.)

Perhaps it’s semantics, but in Welsh’s way of thinking, embracing an obsession differs from picking a niche. To describe the power of embracing an obsession, Welsh references a tweet from Daniel Vassalo:

Find something you want to do really badly, and you won’t need any goals, habits, systems, discipline, rewards, or any other mental hacks. When the motivation is intrinsic, those things happen on their own.

From https://twitter.com/dvassallo/status/1547230105805754369

I trust you can see the difference between picking something you HAVE to do, versus obsessing over something you WANT to do.

What’s in it for you?

Welsh was addressing this post to me and people like me, and his message resonates with me.

But frankly, YOU don’t care about me and about whether I’m motivated. All that you care about is that YOU get YOUR content that you need from me.

So why should you care what Justin Welsh and Daniel Vassllo told me?

The obvious answer is that if you contract with Bredemarket for your marketing and writing services, you’ll get a “pry my keyboard out of my cold dead hands” person who WANTS to write your stuff, and doesn’t want to turn the writing process over to some two-year-old bot (except for very small little bits).

Regarding the use of two-year-old bots:

“Pry my keyboard,” indeed.

Do you need someone to obsess over YOUR content?

Of course, if you need someone to write YOUR stuff, then I won’t have time to work on a TikTok dance. This is a good thing for me, you, and the world.

As I’ve stated elsewhere, before I write a thing for a Bredemarket client, I make sure that I understand WHY you do what you do, and understand everything else that is relevant to the content that we create.

As I work on the content, you have opportunities to review it and provide your feedback. This ensures that both of us are happy with the final copy.

And that your end users become obsessed with YOU.

So if you need me to create content for you, please contact me.

Feel free to share YOUR favorite 1980s song if you like.

Even if it’s THIS song that your favorite temperamental writer detests.

From https://www.youtube.com/watch?v=aDgHXiWgKlE

How Can Your Identity Business Create the RIGHT Written Content?

Does your identity business provide biometric or non-biometric products and services that use finger, face, iris, DNA, voice, government documents, geolocation, or other factors or modalities?

Does your identity business need written content, such as blog posts (from the identity/biometric blog expert), case studies, data sheets, proposal text, social media posts, or white papers?

How can your identity business (with the help of an identity content marketing expert) create the right written content?

For the answer, click here.

(Part Three of Three) Why is There So Much STUFF on the Bredemarket Identity LinkedIn Page These Days?

I’ve spent the first two entries in this post series (Part One, Part Two) talking about my compulsion to share identity information to Slack or LinkedIn or other places.

And you’re probably asking a very important question.

So what?

Talking about my compulsion isn’t really a good customer-focused thing to do.

Unless my compulsion benefits you in some say.

And for some of you, it does.

If you are a professional in the identity industry, you want to remain up-to-date on all the goings-on. And there are a number of sources that provide that information. But in many cases, you have to read the entire article.

That’s where my long-established practice of quoting excerpts can help.

Through force of habit, most of my shares to the Bredemarket Identity Firm Services LinkedIn showcase page begin with a relevant excerpt, and sometimes I include an editorial comment based on my 25-plus years in the identity industry. If the excerpt (and/or editorial) interests you, you can click on the link and read the article. If the excerpt/editorial doesn’t interest you, you can skip the article entirely.

This saves you time that you can devote to other tasks.

And now for the CTA

CTA stands for call to action, and my call to action is this.

Would you like to read the identity-related content that I’m starting to post again to the Bredemarket Identity Firm Services LinkedIn showcase page?

It’s really easy to do so.

  1. Log into your LinkedIn account.
  2. Go to the page: https://www.linkedin.com/showcase/bredemarket-identity-firm-services/.
  3. Click the “Follow” button.
To see my new content, click the “Follow” button at https://www.linkedin.com/showcase/bredemarket-identity-firm-services/

It’s so easy even a wildebeest can do it.

Black wildebeest. By derekkeats – Flickr: IMG_4955_facebook, CC BY-SA 2.0, https://commons.wikimedia.org/w/index.php?curid=14620744

(Well, if they have a wildebeest keyboard.)

(Part Two of Three) Why is There So Much STUFF on the Bredemarket Identity LinkedIn Page These Days?

Part One of this post series talked about my compulsion to write stuff.

Designed by Freepik.

And it also touched upon my compulsion to share stuff. Specifically, articles about identity.

I’ve already told how I’ve created or managed five services over the years to share identity industry information, but I’ve never told any of the behind the scenes story regaridng the creation of the fifth identity information service. This one was created for Incode Technologies, which was (and is) very different from Bredemarket, and very different from IDEMIA, Safran, and Motorola.

Behind the scenes on the fifth identity information service

By the time I joined Incode, I had spent much of my life as an employee working for large bureaucratic multinational companies.

  • I worked for Motorola when there was only one Motorola.
  • MorphoTrak was part of the huge Safran Group (until it wasn’t).
  • IDEMIA was, and is, a combination of dozens of previously independent companies that eventually merged into one big firm.

I was used to process. Motorola WAS process, and Safran and IDEMIA weren’t slouches at process either. You can’t build aircraft parts just by, um, winging it.

But now I found myself at Incode, a rapidly growing startup. It used (and uses) newer tools that didn’t even exist when I worked for Motorola. For example, it used Slack as one of its primary methods to communicate with employees.

As I perused the Slack channels offered at my new employer, a new idea popped into my mind. OK, it was actually a pretty old idea from my perspective, but it would be new to my coworkers.

“Why don’t I create a Slack channel devoted to identity industry information?”

But of course one does not simply create a corporate Slack channel.

Before establishing a Slack channel on a corporate platform, I knew (with the same certainty professed by certain generative AI services) that you obviously need to go through a lengthy approval process. You probably have to get signatures from the corporate headquarters, IT, and probably a few other organizations besides. I mean, I knew this, based upon extensive data that I had acquired up to 2021. (Actually mid-2022, but some of you get the reference.)

So I went to my boss Kevin, told him I wanted to create a Slack channel for identity industry information, and asked him what the official Incode approval process was to create the channel.

From https://www.youtube.com/watch?v=VMin0i_h8PI

(And you wonder why my younger marketing coworkers said “OK Boomer” to me at times.)

Kevin was a patient boss. I don’t know what was going through his mind when I asked the question, but he simply smiled and said, “Just create it. And if no one uses it in a couple of weeks, just delete it.”

(They didn’t do that in La Défense or Issy-les-Moulineaux or Schaumburg, or even in Reston or Billerica or Alexandria or Tacoma or Anaheim or Irvine.)

So I did simply create the new corporate Slack channel, posting articles of interest to it, and letting my coworkers know about the channel’s existence.

And soon other people started posting to the channel.

And soon people other than myself were inviting other people to the channel.

I didn’t delete it.

So the fifth identity information service took off, and I settled into a routine. On many mornings, I did the one thing that experts say you shouldn’t do. I started my morning by reading my corporate email.

(Despite being a Sage, I’m still a Revolutionary/Rebel/Maverick.)

And as I read my various alerts and emails I’d find articles of interest, identify a brief excerpt that encapsulated the main point of the article, and share the excerpt (occasionally with an editorial comment) and article to the Slack channel.

Compulsively.

Of course, because I was devoting time to the company-only fifth identity information service, the Bredemarket LinkedIn showcase page (the fourth identity information service) wasn’t receiving that much attention. Bredemarket wasn’t doing any identity consulting anyway, so I was spending my limited Bredemarket time pursuing other markets. And pouring my identity compulsion into Incode’s Slack channel.

‘Til Tuesday

From https://www.youtube.com/watch?v=uejh-bHa4To

(Couldn’t resist.)

Then on Tuesday my routine was shattered. For purposes of this post, I’ll simply say that I no longer had access to that fifth identity information service, or to any of Incode’s Slack channels.

But I still had my identity information sharing compulsion.

I was still reading articles (albeit from other sources), and I still had the urge to share them on the Slack channel, but then I remembered that I couldn’t.

That’s when I started hearing the plaintive call of the wildebeest.

Black wildebeest. By derekkeats – Flickr: IMG_4955_facebook, CC BY-SA 2.0, https://commons.wikimedia.org/w/index.php?curid=14620744

My old forgotten friend the wildebeest was soothingly telling me that I could go back to the fourth identity information service and share identity stuff there again.

I hadn’t shared anything to that Bredemarket LinkedIn showcase page in over two weeks. But starting that Tuesday, I started sharing several items a day, successfully redirecting my compulsion and sharing to a new target.

So what? I’ll explain why this whole story is important to YOU in Part Three.

(Part One of Three) Why is There So Much STUFF on the Bredemarket Identity LinkedIn Page These Days?

Often I write my Bredemarket posts to target a specific audience. Technologists. Leaders of businesses in California’s Inland Empire. People who like wildebeests.

Well, this post series is specifically targeted to people who follow the LinkedIn showcase page Bredemarket Identity Firm Services. By the time you finish reading this post series, you may choose to follow the page also.

When people scan the posts on that LinkedIn showcase page, they’ll see that earlier in the year, I was posting infrequently, and then a few days ago I started posting all sorts of stuff on the page.

Why?

Well, there’s a story behind that.

Why I am like Charlton Heston, sort of

By Trailer screenshot, from DVD The Ten Commandments, 50th Anniversary Collection Paramount, 2006 – The Ten Commandments trailer, Public Domain, https://commons.wikimedia.org/w/index.php?curid=2216811

Charlton Heston (1923-2008) was a famous actor, and from his roles there were a number of lines that were associated with him.

One of the most famous ones is “Take your stinking paws off me, you damn dirty ape!” from Planet of the Apes.

From https://www.youtube.com/watch?v=Cdmqn9JIuzc

But later in life he was associated with a line that wasn’t spoken on a movie set, but in the Charlotte (North Carolina) Convention Center. The line? “From my cold, dead hands.”

From https://www.youtube.com/watch?v=5ju4Gla2odw

In this case Heston was talking about guns; he was giving a speech to the National Rifle Association.

But that “cold, dead hands” line can be applied to other things, as I did when I created the Bredemarket website about three years ago and created the “Writing, writing, writing” section of the “Who I Am” page.

I am John E. Bredehoft, and I have enjoyed writing for a while now.

And for a while I’ve been able to make a living at it. With the exception of my first jobs as a paperboy and a library assistant, every one of my positions has required some level of writing. Articles for my college newspaper. User manuals. Zines (in my previous brief foray into business, Gresham Press.) Requests for proposals. Responses to requests for proposal. Marketing requirements documents. And other documents that I’ll address a little bit later.

And when I wasn’t getting paid to write, I was writing for free. A college dorm newspaper, the Eastport Enquirer. Nearly a dozen personal blogs since 2003, a few of which are still running. Two professional blogs.

I guess I’m a “you can pry my keyboard out of my cold dead hands” type.

From “Who I Am.”

Yes, that’s me. A compulsion to write stuff.

Designed by Freepik.

My other compulsion

I also compulsively share stuff that other people have written, especially when it relates to a topic that interests me.

Such as identity.

I’ve told the basic story about how I created (or managed) online places where I could share stuff about identity. First at Motorola, then at MorphoTrak, then at IDEMIA. Then at Bredemarket: the aforementioned Bredemarket Identity Information Services LinkedIn showcase page (and Facebook group).

And I’ve told the basic story about how I created a fifth “identity information service,” this time for my then-new employer Incode Technologies.

But I didn’t tell the “behind the scenes” part about the creation.

I’ll tell that in Part Two.

Updates, updates, updates…

When keeping your websites updated, I advise you to do as I say, not as I do. Two of my websites were significantly out of date and needed hurried corrections.

Designed by Freepik.

I realized this morning that the “My Experience” page on my jebredcal website was roughly a year out of date, so I hurriedly added content to it. Now the page will turn up in searches for the acronym “ABM” (OK, maybe not on the first page of the search results).

Then I had to return to this website to make some hurried updates, since my April 2022 prohibition on taking certain types of work is no longer in effect as of June 2023. Hence, my home page, my “What I Do” page, and (obviously) my identity page are all corrected.

Oh yeah, I updated my Calendly availability hours also. Which is good, because I already have two meetings booked this week.

Which reminds me…if you need Bredemarket’s services:

Testing my sixth authentication factor on Omnitrans bus passes

I know that Bredemarket has pivoted away from full-time identity work in favor of part-time work with local businesses in Ontario, Eastvale, and other cities, but a recent local activity illustrated a possible identity issue that I’d like to explore here. So allow me this tangent; I’ll get back to my Ontario, California content marketing expert content later.

Identities and bus passes

Remember my trip to Eastvale yesterday? I had to use a bus to get there. And to do this, I bought a day pass.

Omnitrans Day Pass, July 23, 2022.

Now this is not the most robust proof of identity. As I recently noted in my JEBredCal blog (one of my other Google identities), it’s extremely easy for multiple people to use this day pass at different times during the day. Even the 7-day and 31-day passes, which must be signed and may be compared against an identity document, are not necessarily free from fraud.

However, this is not critical to Omnitrans, who would rather put up with a small amount of fraud than inconvenience its riders with multiple identity checks.

Identity proofing is more critical in some situations than it is in others.

From https://jebredcal.wordpress.com/2022/07/24/how-important-is-that-identity/.

Of course, if Omnitrans really wanted to, it could achieve the need for fraud prevention by using relatively frictionless forms of identity proofing. Rather than demaning to see a rider’s papers, Omnitrans could use passive methods to authenticate its riders. I won’t go into all the possible methods and their pros and cons here.

However, I would like to explore one possible identity proofing method to see if it would solve the Omnitrans pass use issue.

Returning to my sixth authentication factor

Can my self-proclaimed sixth factor of authentication provide a solution?

You’ll recall that many identity experts recognize five factors of authentication:

  • Something you know.
  • Something you are.
  • Something you have.
  • Something you do.
  • Somewhere you are.

Well, because I felt like it, I proclaimed a sixth factor of authentication.

  • Why?

I said, because I felt like it!

Whoops, “why?” is the sixth authentication factor. I still haven’t rendered it into the “somexxx you xxx” format yet.

Can Omnitrans use the “why?” factor to test the reasonableness that any particular trip is performed by the person who originally bought the pass?

Possibly.

Applying the “why?” question to bus boarding data

Assume the most challenging scenario, in which Omnitrans knows nothing about the person who purchases a 31-day pass. The person pays in cash and is wearing a face mask and sunglasses throughout the entire transaction. Therefore, the only identity information associated with the pass is the location where the pass was purchased, the date/time it was purchased, and some type of pass identification number. For this example, we’ll assume the pass number is 12345.

So Omnitrans really doesn’t know anything of importance about the holder of pass 12345…

…other than how it is used.

I’m making the assumption that Omnitrans logs information about every use of a pass. Since you don’t need to use your pass when you leave the bus, the only information available is when you board the bus.

So let’s look at some fake data.

Date and TimeBusLocation
Monday, July 25, 2022, 6:39 am87Euclid & Holt, Ontario
Monday, July 25, 2022, 6:35 pm87Amazon LGB3, Eastvale
Tuesday, July 26, 2022, 6:39 am87Euclid & Holt, Ontario
Tuesday, July 26, 2022, 6:35 pm87Amazon LGB3, Eastvale
Wednesday, July 27, 2022, 8:42 am87Euclid & Holt, Ontario
Wednesday, July 27, 2022, 6:35 pm87Amazon LGB3, Eastvale
Thursday, July 28, 2022, 6:39 am87Euclid & Holt, Ontario
Thursday, July 28, 2022, 6:35 pm87Amazon LGB3, Eastvale
Thursday, July 28, 2022, 7:20 pm61Plum & Holt, Ontario
Thursday July 28, 2022, 9:52 pm61Ontario Mills, Ontario
Friday, July 29, 2022, 6:39 am87Euclid & Holt, Ontario
Friday, July 29, 2022, 8:35 am87Amazon LGB3, Eastvale
Friday, July 29, 2022, 10:00 am66Vineyard & Foothill, Rancho Cucamonga
Friday, July 29, 2022, 11:26 am14Fontana Metrolink
Friday, July 29, 2022, 11:53 am82Fontana Metrolink
Friday, July 29, 2022, 12:08 pm66Fontana Metrolink
Hypothetical logging of trips on Omnitrans Pass 12345.

Even if you are not familiar with California’s Inland Empire, you can probably classify these trips into the following categories:

  • Trips that are probably legitimate.
  • Trips that may or may not be legitimate.
  • Trips that are probably fraudulent.
  • Trips that are definitely fraudulent.

For the most part, you can’t know with certainty about the legitimacy of most of these trips. Here’s a story that fits the facts.

  • Jack Jones starts his new job at Amazon on Monday, and works Monday and Tuesday with no incident. Jack overslept on Wednesday and was written up. He made sure to arrive at work on time Thursday, and at the end of the day he celebrated with a dinner at a restaurant in the Ontario Mills shopping center. After arriving at work on Friday, Sara Smith picked his pocket and took his pass, fleeing the scene an hour later and making her way to Fontana. She creates several clones of the bus pass and sells them at a discount before fleeing herself. Therefore, all trips beginning on Friday at 8:35 am are fraudulent.

But that might not be the true story. This one also fits the facts.

  • Jack Jones starts his new job at Amazon on Monday, and works Monday and Tuesday with no incident. On Wednesday Jack calls in sick, but lets his housemate Bob Brown (who also works at Amazon) use his pass on Wednesday and Thursday. By Thursday evening, Jack is feeling better, retrieves his pass from his housemate, and goes to Ontario Mills for the evening. On Friday Jack goes to work and is fired. He boards the 87, misses his stop in Ontario, and stays on the bus until he reaches Rancho Cucamonga. Despondent, he decides to visit his friend in Fontana. However, his Fontana friend, Sara Smile, secretly created several clones of Jack’s bus pass and sells them at a discount. Therefore, the Wednesday trips, the Thursday day trips, and all Friday trips beginning at 11:26 am are fraudulent.

Or perhaps some other set of facts fit the data.

  • It’s possible that the pass was stolen before it was ever used and all of the trips are fraudulent.
  • Or perhaps every trip before arriving in Fontana is legitimate, but how can we tell which one (if any) of the three trips from Fontana was undertaken by the true passholder?

But the data that Omnitrans captured provides a way to challenge the pass holder for possibly fraudulent trips.

  • If Omnitrans is really suspicious for some reason, it may choose to challenge every trip that didn’t take place at the “regular” times of 6:39 am or 6:35 pm. “Why are you boarding the 87 bus at this hour of the morning?” “Why are you boarding the 61 bus?”
  • Or Omnitrans may assume that all of the trips are reasonable and don’t necessitate a challenge. Yes, someone can go to work late. Yes, someone can go to Ontario Mills for the evening. Well, all of them are reasonable until Friday at 11:53 am, when a passholder boards a bus at the same location where the same passholder supposedly departed at 11:26 am.

Now even if strict identity checks are used with the “why?” statement, the data alone can’t detect all fraud. If Jack Jones and Bob Brown both work the day shift at Amazon, but on alternate days, how can Omnitrans detect the days when Jack Jones leaves Ontario at 6:39 am, vs. the days when Bob Brown leaves Ontario at 6:39 am?

Again, no identity proofing method is 100% foolproof.

But the “why?” question may detect some forms of fraud.

Or are there really only five factors of authentication after all?

Now I’ll grant that “why?” might not be a sixth factor of authentication at all, but may fall under the existing “something you do” category. This factor is normally reserved for gestures or touches. For example, some facial liveness detection methods require you to move your head up, down, right, or left on command to prove that you are a real person. But you could probably classify boarding a bus as “something you do.”

Anyway, thank you for engaging my tangent. If I can think of a “why?” example that doesn’t involve something you do, I’ll post it here. That will help me in my hopeful (?) quest to become the inventor of the sixth factor of authentication.

What about the businesses in cities where my bus trips took place?

But back to the businesses in Ontario, Eastvale, Rancho Cucamonga, Fontana, and other cities: need some content help? I can create esoteric long-winded content like this, or (what you probably want) more concise, customer-focused content that conveys your important message. My regular work includes case studies, white papers, proposal services, and other types of content. If you need someone to help you create this content: