Arizona Does Not Have an Official Arizona Time Zone

The Diamondbacks are hosting the Dodgers this afternoon, and people really want to know what time it is. So, unlike Chicago, I asked Gemini.

“Phoenix, Arizona operates on Mountain Standard Time (MST) year-round and does not observe Daylight Saving Time.”

Stupid hallucinations, because I know that Arizona operates on Arizona Standard Time (AST), which is a synonym for Mountain Standard Time except for the fact that “Arizona Daylight Time” is meaningless.

Oh, and the Navajos aren’t down with AST, because the Navajo Nation spans multiple states. MST/MDT for all, thank you.

But what if I was wrong? Who could tell me if Arizona Standard Time is real or an invention?

The U.S. Department of Transportation

Today, the U.S. Department of Transportation (DOT) is responsible for managing time zones. But not measuring—Commerce does that.

This makes sense, because we really didn’t need time zones until trains provided rapid travel. Before that, you didn’t really care about such things. By 1883, the trains, not government, forced the issue:

“In 1883, U.S. and Canadian railroads adopted a four-zone system to govern their operations and reduce the confusion resulting from some 100 conflicting locally established “sun times” observed in terminals across the country.  States and municipalities then adopted one of the four zones, which were the eastern, central, mountain, and Pacific Time zones.”

Sound familiar? Although today continental Canada has more than four time zones. But I digress.

At the time, Arizona (and New Mexico) were meaningless territories, and the trains didn’t care about “daylight saving.” Heck, establishing four time zones for the big countries was enough of an accomplishment.

The (U.S.) Government wasn’t here to help until 1918.

“Federal oversight of time zones began in 1918 with the enactment of the Standard Time Act, which vested the Interstate Commerce Commission with the responsibility for establishing boundaries between the standard time zones in the continental United States.”

Decades later, when DOT was created, the Standard Time Act was replaced.

“Today, the Uniform Time Act of 1966 (15 U.S.C. §§ 260-64) establishes a system of uniform Daylight Saving Time throughout the Nation and its possessions, and provides that either Congress or the Secretary of Transportation can change a time-zone boundary.”

We will get back to Daylight Saving Time later. But what were the standard time zones?

“The time zones established by the Standard Time Act, as amended by the Uniform Time Act, are Atlantic, eastern, central, mountain, Pacific, Alaska, Hawaii–Aleutian, Samoa, and Chamorro.”

And for those who think the Atlantic Time Zone is exclusive to Canada, you forgot about Puerto Rico and the U.S. Virgin Islands.

By the way, the Chamorro Time Zone hosts Guam and the Commonwealth of the Northern Mariana Islands. Guam is UTC+10, American Samoa UTC-11. Because of the International Date Line, it’s probably tomorrow in Guam.

But what’s missing from the law? Arizona. So who invented “Arizona” Standard Time?

But first, why

Daylight saving time didn’t exist in 1883, but slowly emerged in the early 20th century, first as a temporary World War I measure, then again temporarily during World War II. Initially adopted piecemeal, it became “uniform” throughout the country with the 1966 Act, which allowed states and territories to opt out.

All the territories opted out, as did Hawaii, because of their low latitudes.

Michigan also opted out, but re-instituted DST several years later.

Arizona? It’s complicated.

  • Arizonans joined the rest of the country in changing their clocks with the advent of daylight saving time in 1918. Congress repealed the wartime law a year later.
  • President Franklin Roosevelt in 1942 imposed DST nationwide as a wartime measure, and the policy ended in 1945.
  • Arizona again implemented DST in 1967 after Congress re-established it through the Uniform Time Act.

So what happened? New Mexico liked it. As did Colorado.

“The Legislature abolished it in March 1968. Lawmakers got the bill on Gov. Jack Williams’ desk about a month before daylight saving went into effect.”

And non-Navajo Arizona has remained on standard time ever since.

Google Gemini.

And systems got confused.

I can tell people that Bredemarket observes “Pacific Time” (PT), and people presumably understand that I use Pacific Standard Time (PST) in winter, Pacific Daylight Time (PDT) in summer.

Incidentally, this is why I quietly blow my top when invited to a meeting on August 12 at noon PST (sic). But I digress.

Now the NIST people who actually measure time observe “Mountain Time,” with people understanding MST and MDT at the appropriate seasons.

But what of Arizona? Legally they’re MST now, MST forever. But that can be misinterpreted.

Hence “Arizona Time.” I couldn’t find an originator of the phrase, but it is widely adopted.

How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

The Current State of ANSI INCITS 378 / MINEX III Compliant Fingerprint Template Generators and Matchers

Vendors that develop fingerprint templates and matchers usually develop their own proprietary algorithms, but there is one instance in which the vendors work together.

ANSI INCITS 378-2009 (S2019) specifies a universal fingerprint format, and vendors can develop 378-compatible template generators and matchers.

How are these measured? By NIST’s MINEX III testing.

To find the current results dfor MINEX III compliant template generators and matchers, visit https://www.nist.gov/itl/iad/btg/minex-iii-compliant-submissions.

When sorted in NIST default order for a false negative match rate at a given false match rate (“Pooled 2 Fingers FNMR @ FMR≤10-2), the top vendors include IDEMIA, Innovatrics, and Neurotechnology.

But remember that this only matters when using ANSI INCITS 378 templates. It doesn’t matter if you’re using a vendor’s proprietary template.

So who uses ANSI INCITS 378 templates?

  • Cards and systems based upon Personal Identity Verification (PIV) templates, as specified by Homeland Security Presidential Directive 12 (HSPD-12) and FIPS 201.
  • Certain cards using Match-on-Card technology.

But most systems you encounter will NOT use ANSI INCITS 378, so the standard may not matter to you at all.

Do your customers care?

But even if you are deploying systems that use ANSI INCITS 378, your customers don’t care.

They just care about complying with federal regulations for PIV cards.

If you need help stating customer-focused benefits rather than vendor-focused features, turn to Bredemarket’s content-proposal-analysis services for identity, biometric, and technology firms.

Marketing a Biometric Product Without a Biometric Product Marketing Expert

Bob and Judy had left television production and started a biometric company. Bob handled sales, Judy engineering. As their company grew, they both realized they needed help.

Bob turned to Judy one day. “What we need is a product marketer, but not just any product marketer. We need a biometric product marketing expert. I know a guy-“

Judy cut him off. “Forget it. Any so-called expert is hampered by legacy. We need new thinking.”

As they used to say, you won’t believe what happened next!

All the features

Ron, their new hire, was a fast learner who listened to Judy for hours, soaking up everything she knew until Ron understood every feature perfectly.

Google Gemini.

Ron assembled his product marketing materials, clearly differentiating the superior technical advantages of his product. Bob then took the materials out on a sales call.

That afternoon Bob returned, dejected.

“The prospect threw the brochures in the trash.”

“Why?” Ron asked.

“They didn’t make sense and didn’t speak to their needs.”

None of the use cases

Ron belatedly realized that the materials didn’t address the benefits the prospect would realize from using Bob and Judy’s biometric solution. And the owners realized that Ron needed to understand the biometric market so that his materials resonated with customers.

Google Gemini.

So Ron studied the market carefully, spending a lot of time with cops and forensic experts before rewriting his brochures to infuse them with industry knowledge.

A well-prepared Bob flew out to meet his next prospect, a well-known sports team in Chicago.

And returned the next day, dejected again.

“They loved the first hour,” Bob reported, “although all the talk about investigative leads confused them. Then they asked about consent.”

Ron, fresh from police station booking rooms, was confused. “Who needs consent to take bionetrics?”

“Sports teams, banks, hotels, office buildings, hospitals, you name it,” Bob replied. “Especially in Illinois.”

Fumbling Towards Insolvency

Sarah McLachlan. “Found a Job” it’s NOT.

Maybe “insolvency” is harsh, but if a biometric firm doesn’t have the embedded knowledge to speak the language of its prospects and customers, the firm’s success will be limited. Immediate expertise is impossible.

“A Patient Hand.” Google Lyria. Public Domain.

Bob, Judy, and Ron may be fictional, but lack of biometric expertise happens in real life. I still remember the time I worked with a company that was bragging about its three-year old NIST FRTE facial recognition accuracy rankings. I gently explained that FRTE results change monthly, with better algorithms appearing all the time. Those old results were worthless.

And your product marketing will be worthless also, unless you understand the many products and many markets.

Bredemarket can help you speak the language of your biometric prospects. Talk to Bredemarket.

Noah Kalina Everyday and NIST Face and Iris Testing

(Image By Noah Kalina – https://flickr.com/photos/arvadacenter/7205535002/, Fair use, https://en.wikipedia.org/w/index.php?curid=69354953)

When the National Institute of Standards and Technology (NIST) performs biometric testing, it generally uses government data from law enforcement, homeland security, and similar sources.

Plus some specialized data that government databases can’t match.

On January 10, 2000, Noah Kalina took a selfie. The next day, he took another. And he kept on doing it every day, with some exceptions, for many years. (Here he is on June 1, 2026.) By centering his nose in the center of the frame, the pictures provide a consistent chronicle of Kalina’s appearance, along with the exact day on which the pictures were taken. NIST purchased rights to some of these photos to use in its age estimation testing. Since NIST knew Kalina’s true age on any given day, it could measure an age estimation algorithm’s accuracy.

But that’s not why I’m writing about Noah Kalina.

Let’s move to irises

Consider the irises of the face, how they are captured. They are usually captured with expensive cameras that take a picture from a short distance away.

But what if a normal camera captured a person, and their irises? Could the camera images yield useful information?

James Matey wanted to find out.

[The Kalina images] “provide us with interesting opportunities to explore the effects of time lapse on iris recognition employed on images that were not originally intended for iris recognition. NIST obtained a license from Kalina to use a subset (7 half years from 2009-2015) of original, high resolution, digital images in biometric studies.”

So were they useful?

“…even though the majority of the images in this dataset did not provide solid matches, there are instances where mated iris image pairs from visible light images that were not obtained for the purpose of iris recognition match with match scores corresponding to a false match rate of 0:1% at a true accept rate of 1% . Though such performance is not useful in applications such as access control, there are cases where it may be useful.”

No, your irises can’t be easily captured in 2026, but what about later?

Another Great Renaming (From 2024)

In August 2023, I talked about what I called a “great renaming” in which the National Institute of Standards and Technology (NIST) differentiated between its face recognition tests and its face analysis tests: a very important distinction and a critical update.

FRVT becomes FRTE and FATE. From NIST.

The ramifications of that renaming persist. Just last week I reminded a biometric firm that its references to “FRVT” were dated.

But what if references to biometrics are dated?

Find…what?

Over twenty years ago a publication called FindBiometrics was established that discussed you-know-what. Fingerprints, faces, irises, and all sorts of stuff.

You would think that a name that incorporated “biometrics” would be all inclusive. It certainly was twenty years ago. But as the industry evolved, the name became a little dated. While biometrics remain critically important, I have to say (with apologies to my former Motorola colleague Edward Chen) that biometrics is not “4” ALL. (You see what I did there.)

The publication realized this also, and performed its own great renaming.

“TORONTO, ONTARIO, CANADA, November 21, 2024 /EINPresswire.com/ — FindBiometrics, a leading news media platform for the biometrics and digital identity industry, is now ID Tech—a refreshed brand identity that reflects the beginning of a new era in the identity technology space.”

Why?

“…the scope of identity tech has expanded to integrate new developments in areas like artificial intelligence, blockchain, and digital ID.”

One example being mobile driver’s licenses, which can utilize biometrics but goes far beyond it. After all, biometrics (something you are) is just one of the six factors of identity verification and authentication. See below.

So now the former FindBiometrics platform is called “ID Tech,” and its URL is now https://idtechwire.com/. And biometrics now shares the stage with other factors.

Biometrics shares the stage. “Revealed” from Google Lyria; Public Domain.

But ID Tech isn’t the only place to learn about identity beyond biometrics. There’s also my book.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.

Today’s Acronyms Are NIST, FRIF, TE, E1N, and ROC

ROC (previously known as Rank One Computing) posted this about its latest resukts in the NIST Friction Ridge Image and Features Technology Evaluation Exemplar One-to-Many (FRIF TE E1N) evaluation.

“ROC’s performance in the NIST FRIF TE E1N evaluation, including #1 global ranking in Class B slap fingerprints, a critical capture format for high-scale civil and government identity programs, proves that American technology can now lead at the highest levels of global biometric performance….

“The NIST Friction Ridge Image and Features Technology Evaluation Exemplar One-to-Many evaluation, known as NIST FRIF TE E1N, evaluates one-to-many fingerprint identification at massive scale, testing how accurately algorithms can identify a subject from large enrollment repositories. Across the evaluation, ROC delivered top-tier performance in every category tested, including Class A, Class B, and Class C. “

As with every NIST biometric test, FRIF yields a massive amount of data. Just looking at the Class B slap data alone, here is what you can find, showing the top 7 entries out of 12 for the Class B Left Slap FNIR (another acronym: false negativce identification rate) at rank less than or equal to 10. Even this view excludes all other slap data and all other ranking data (1, 2, and 5).

(Data captured Friday, May 29, 2026 and may become outdated when new algorithms are tested.)

National Institute of Standards and Technology.

With this massive wealth of data, just about every vendor probably performed well in something, which is why ROC took the time to point out why Class B slap results are important.

“ROC’s most significant milestone came in Class B slap fingerprints. This performance is especially important for high-scale ABIS environments, including national ID programs, border management, civil enrollment, and high-stakes criminal justice workflows, where handling immense scale without sacrificing accuracy is mandatory.”

Although ROC may be the only entity trumpeting May results, other vendors have promotede earlier NIST FRIF TE E1N achievements, including IDEMIA, Identy.IO, Innovatrics, and Neurotechnology.

But they’re foreign. (As is Thales Group, for those keeping score.)

How Do You Talk About the Product “Plumbing”?

There are a variety of hungry people (target audiences) who look at your product marketing content. And they all have different needs.

  • When talking about an elegant water fountain, some readers only care that the fountain works.
  • Other readers want to know HOW it works. Issues such as support and maintenance are critically important to these folks, but matter little to the first group who simply wants a working fountain.

If you are forced to speak to both target audiences in a single piece of content, how do you do it?

Very carefully.

My preference is to discuss the high-level benefits at the beginning of the content, and save the more technical uptime details and/or feature lists for later in the narrative.

Unless you are ONLY speaking to technical folks, leading with the “plumbing” kills your content. Someone who wants their police agency to solve more burglaries will fall asleep at a mention of 1000 pixels per inch fingerprint resolution or NIST-compliant lower palm print image dimensions.

Stay light, and only go deep to buttress your lightness.

Close to a Milestone

One of Bredemarket’s clients is microscopically close to achieving an important milestone with a major customer. As project manager I’m performing the issue tracking and am happy. It is premature to announce this customer milestone, but hopefully the day will come.

The only drawback was that a last-minute Bredemarket / client / customer call prevented me from attending Tuesday’s live iProov / Ingenium webinar on independent testing to standards such as NIST SP 800-63-4 and CEN/TS 18099. But that’s why webinars have replays.

The Bredemarket post below is not directly related to the webinar, but is tangentially related since it discusses independent testing.

iProov’s Four Questions on Independent Testing

I hope you’re sitting down for this…but vendors make assertions that favor themselves. Or in this case “favour,” because the vendor in question is iProov.

The English company shared four questions on independent testing of vendor claims, and I think we can all predict how iProov would answer these four questions.

But that doesn’t negate the importance of the questions.

  1. Which independent lab(s) tested the system? Not just a vendor red team, or a partner story. An accredited third party.
  2. Against which standard? ISO/IEC 30107-3, CEN/TS 18099, FIDO Face Verification, or a combination? Defending against the full attack spectrum matters.
  3. At what level? Substantial, High? If the level isn’t listed, be sure to ask why.
  4. When? Standards evolve. Threat models evolve faster. Certifications can age quickly.

Yes, you can claim that customer testing is more important than independent testing.

And some have claimed that independent testing is flawed because it doesn’t test properly. (One semi-related example: because FBI EBTS Appendix F assumes that the fingerprints contact the capture surface, it is useless for contactless solutions. The powers that be are working on an alternative.)

But if your solution doesn’t have independent test or conformance results, you’d better have a good reason.