Comfort in the Frame

No more trips to CVS for passport photos?

“Comfort in the Frame.” Google Lyria. Public Domain.

For fuller background information, see “Secretary of State Marco Rubio on Online Passport Applications, July 2, 2026.”

For more on what ICAO Document 9303 recommends regarding facial expression, see this post.

And this song.

“Neutral Expression.” Google Lyria. Public Domain.

Secretary of State Marco Rubio on Online Passport Applications, July 2, 2026

United States passport applications may soon become easier, allowing you to do nearly everything online. Even the passport photo, saving you a trip to a location where someone or some machine wilk take the passport photo for you.

From Secretary Rubio’s recorded remarks:

“Now, beyond that I would say that we are also looking at some technological changes, which we’ll be more fully able to announce over the coming months, where it’s going to be a lot easier to get a passport in terms of the dynamics of it.  You’ll actually be able to go online.  You’ll be able to do almost all of it entirely online.  One of the questions we had was most of the devices that people are using, be it a laptop or a standing computer or what have you, where you would fill out this application, they have cameras on them.  I know, it’s shocking.  But they have cameras.  They have videos that people use.

“You should be able to take that picture on that device as opposed to going somewhere.  Now, the CVS people, of course, hate this, and the Walgreens and all those other places.  (Laughter.)  But you’ll be able to take your picture from that device and be able to have it in real time, through our security system, verify the facial ID.  And it just saves you a lot of – you don’t have to go down somewhere now and get a head shot and get the little pictures that you have to cut and then submit three passport pictures.  You’ll be able to do that.  You’ll be able to do it online entirely, for the most part, with all the right numbers.  They’ll be able to verify it for you, and you should be able to get it much sooner. 

“So we’re going to make it a much more customer-friendly – we’re not ready to do that yet, but that’s really what we want to be able to do.  (Applause.)  And it should cut down on the long waits, the long lines, the appointments, the making – some people may still decide to do it that way, but this way will be available to people.  And we look forward to, like, really rolling that out in a few months when it’s ready.”

Secretary Rubio didn’t go into the technical details of how they will ensure ICAO compliance for smartphone photos. What about the lighting? What about the inter-eye distance? What if I smile?

After all, smartphone photos are by definition “unconstrained,” unlike the photos you get at your friendly neighborhood CVS Pharmacy.

Google Gemini.

Is a 0.0001% EES Border Threat Level Meaningless?

I just reshared Tom Topol’s latest LinkedIn article to my Bredemarket Identity Firm Services readers on LinkedIn and Facebook, focusing on this quote:

“Between October 2025 and April 2026, the EES registered over 52 million border crossings. Entry was refused more than 27,000 times, including to almost 700 people who were identified as posing a security threat to the EU. Several thousand additional travelers were flagged for overstaying the Schengen 90/180-day rule…”

Is Europe over-emphasizing the threat?

But that isn’t how he begins the article.

“Europe’s Biometric Border and the Price of 700 Threats in 52 Million Crossings”

I did the math, and if you only count ACTUAL security threats, rather than visa overstays that COULD become security threats, you’re talking about a very small percentage: 0.0013461538%.

Topol asks:

“The question is not whether the EES caught anything. It is whether what it caught justifies what it costs: in financial terms, in operational disruption, and in the permanent erosion of informational privacy for hundreds of millions of innocent travelers.”

Let’s look at operational disruption. Topol cites GDPR Article 35’s requirement that “a Data Protection Impact Assessment must justify the necessity, suitability, and proportionality of any system processing biometric data at scale.” Topol cites a Spanish case that failed to obtain the required assessment (covered by Biometric Update), then extrapolates that EES is a net burden.

Topol acknowledges the deterrent effect—if fraudsters know their biometrics will be captured, they won’t attempt the fraud—but then notes that the argument “is also entirely unverifiable, and it has historically been used to justify the expansion of every surveillance system ever built.”

Bringing it all back home

Take the experience in my own country.

This isn’t a border issue, but when I joined the biometric industry in 1994, Los Angeles County was beginning to use fingerprint biometrics to ensure that the right people received government benefits—and the wrong people didn’t. Back in those pre-iPhone days only criminals gave their fingerprints, so this and other programs had an unsavory taint in the public’s eye. Yes the county saved money, but was this because fraudsters stayed away, or because legitimate users feared their fingerprints would go to the LAPD? The use of fingerprints for welfare benefits has disappeared today.

Returning to border crossings, our own entry-exit system has been justified by statements such as Senator Lindsey Graham’s 2015 claim about the 9/11 terrorists:

“All the hijackers who attacked — attacked us on 9/11 were visa overstays. So it’s more than just the border. You have got to control your visa program.”

According to FactCheck, Graham was off by 89%. Only two of the 19 terrorists were visa overstays. While the terrorists took advantage of flaws in the visa system, they had the visas.

Emotionally, I’m not convinced

Having spent over 30 years in this industry, I’m not about to chuck security out the window.

Emotionally I can’t do it.

And not because of the OVERLY emotional arguments, the “Jane never celebrated her seventh birthday because a cold-blooded smelly killer took her life.”

I’m talking about run-of-the-mill emotion.

And I have a challenge for you.

Tonight, when you go to bed, leave the front door of your house unlocked. After all, the chances of harm from an unlocked front door are minuscule.

I bet Topol locks HIS door at night.

No “Neutral Expression” When Free Lyria Songs Go Full Length

My latest Google Lyria song experiment surprised me.

I was playing back the song I had created when I noticed that the new song was longer than the standard 30 seconds. In fact, it was a full length three minute song, something only previously possible with paid versions of Lyria.

So I adjusted my prompt to take advantage of the length.

It’s probably no surprise that my latest Lyria song doesn’t touch on a couple who is never ever ever getting back together. Instead, I focused on the ICAO Doc 9303 “neutral expression” requirements I discussed in passing in this October 2025 post.

“But in one of those oddities that fill the biometric world, you can have TOO MUCH expression. Part 3 of International Civil Aviation Organization (ICAO) Document 9303, which governs machine readable travel documents, mandates that faces on travel documents must maintain a neutral expression without smiling. At the time (2003) it was believed that the facial recognition algorithms would work best if the subject were expressionless. I don’t know if that holds true today.”

Google Gemini.

That should make for a catchy song, shouldn’t it? Judge for yourself in the song “Neutral Expression.”

“Neutral Expression.” Google Lyria.

Wonder if the woman liked it.

Google Gemini.

She did!

Using LLMs for KYC. What Could Go Wrong?

The title of this post uses acronyms for brevity, but the full version is “Using Large Language Models for Know Your Customer. What Could Go Wrong?”

Biometric Update links to a TrendAI post that demonstrates how the use of a large language model to analyze document data is a vulnerability to prompt attacks.

“In a real-world stack built with FastAPI, Claude Code, and a SQLite MCP backend, his team embedded malicious instructions inside a passport so that the AI agent followed them and leaked other customer records directly into the verification page.”

Google Gemini. I tried to create the image with a fake too-short onion address but Google Gemini prohibited that.

What does this mean?

“The takeaway here is that if your AI can read documents and call tools, your documents can potentially become executable attack surfaces even when guarded with strict schemas.”

Something a human wouldn’t do.

Identity Document Validation is a Toxic Dumpster Fire

I may have misjudged Biometric Update.

Most technology publications, with the notable exception of IPVM, are at least partially funded by the companies they cover. Therefore there’s an unavoidable tension between keeping the advertisers happy and casting a critical eye on the industry.

I accept this tension because it applies to Bredemarket itself. Although my clients are absolutely wonderful, there may emerge a future situation where they may be less than perfect. So naturally I have to watch my tongue.

As does Biometric Update.

Remember when IDloop asserted it offered “the world’s first FBI-certified 3D contactless fingerprint scanner,” and Biometric Update reported the claim with no comment? I said at the time:

“Biometric Update reports news as reported, and I don’t think it’s Biometric Update’s purpose to poke holes in vendor claims.”

But then Biometric Update ran a more recent story.

They said that?

Bear in mind that Biometric Update’s advertisers include vendors who offer identity document validation solutions: either their own, or from a third party.

And Biometric Update’s recent story basically said that these solutions are a toxic dumpster fire.

OK, not in those words. Biometric Update is Canadian owned, and if the publication used the words “toxic dumpster fire” it would never stop apologizing.

Google Gemini.

But the true title is eye-catching in context:

DHS RIVR results suggest most ID document validation disastrously ineffective

Not just ineffective, DISASTROUSLY ineffective. Ouch.

For those not up in their acronyms, the Department of Homeland Security’s (DHS) latest annual round of tests was called the Remote Identity Validation Rally (RIVR).

DHS set performance goals for the submitted entries and publicized the (anonymous) results.

“Four of the seven subsystems tested met the goal for system error rate. Four did not meet the threshold for FRR, and five fell short in FAR. In other words, most systems let too few legitimate IDs through, even more passed too many fraudulent IDs, and six of seven fell short on one or both sides of the assessment.”

Google Gemini.

Biometric Update didn’t reveal the…um…identity of the one vendor that performed acceptably. But that vendor may self-reveal soon enough.

On anonymity

Why do testing entities sometimes allow participants to remain anonymous?

Because they want participants.

Some biometric tests are NOT designed to identify the best algorithms, but are instead designed to view the state of the industry. And that’s what this test performed with document validation.

Presumably a future test—POND, or Performance Of Notable Documents—will measure the future state-of-the-art of identity document validation.

Hopefully the results won’t be disastrous.

For My U.S. Readers Interested in Visiting Uzbekistan

When using your passport to travel internationally, sometimes you need a visa to enter a country.

And sometimes you don’t.

“The country of Uzbekistan will lift visa requirements for U.S. travelers starting Jan. 1, 2026, offering Americans another country to visit visa-free. The police change, which was recently confirmed by the government, will allow U.S. citizens to enter visa-free for up to 30 days.”

Just don’t bring your surfboards. Uzbekistan is double-landlocked.

California Voter Proof of Identity AND Citizenship: How?

(Imagen 4)

This post provides an update on election integrity, which I haven’t discussed since March.

The update? Assemblymember Carl DeMaio wants to put a proposition on the 2026 California ballot that achieves three purposes:

  • “[R]equire the state to verify proof of citizenship when a person registers to vote.”
  • Require voters to “provide identifications at the polls.”
  • “Those who vote through mail-in ballots would have to give the last four digits of a government-issued ID such as a Social Security number.”

Let’s go through these…backwards.

Mail-in ballots

The third proposal about authenticating mail-in ballots is silly. 

The mere fact that someone knows the last four digits of a Social Security Number does NOT prove that the person is the valid holder of the Social Security Number in question. 

Frankly, I’m surprised that DHS released Leonardo Garcia Venegas just because he knew a Social Security Number. Of course, I’m also surprised that they determined his REAL ID was fake.

In-person ballots

Which brings us to the second proposal about requiring a government ID for in-person voting. 

I’ve already addressed why this is silly. The short version? Election precinct workers have neither the equipment nor the training to tell whether a government ID is real or fake.

Not an official government-issued ID. From https://www.al.com/news/2022/10/alabama-gop-chairman-made-the-photo-id-he-used-to-vote.html.

Voter registration…and re-registration

That only leaves the first one, proving citizenship at voter registration. This one is technically feasible; the feds do it all the time. The California Secretary of State could merely adapt the federal I-9 process to the state level; I’m sure Janice Kephart and her company ZipID would love to help the state with that.

Especially since the requirement for election integrity dictates that all of California’s existing voters would need to re-register to prove their citizenship.

All 22+ million of them.

Because if you DO NOT require all California voters to re-register, the whole exercise is pointless.