Bank Automation News

No products in the cart.

Subscribe
  • News
  • Data
  • Transactions
  • Events
    • Bank Automation Summit
    • Apply to Speak
    • Apply to Demo
  • Podcast
  • WEBINARS
    • On-Demand Webinar: Emerging fintechs: New technologies you need to know now
    • Webinar Library
Log In
No Result
View All Result
  • AI
  • Business Banking
  • Core
  • Cloud
  • Payments
  • Retail Banking
  • Risk & Security
Bank Automation News
  • News
  • Data
  • Transactions
  • Events
    • Bank Automation Summit
    • Apply to Speak
    • Apply to Demo
  • Podcast
  • WEBINARS
    • On-Demand Webinar: Emerging fintechs: New technologies you need to know now
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
Bank Automation News
No Result
View All Result

Introducing Digital Identity Week on Daily Fintech

Daily FintechbyDaily Fintech
December 15, 2016
in Archive
Reading Time: 9 mins read
0
Share on Facebook

unboundid-digital-identity

Are you really sure I am not a dog? Maybe I am a really smart dog with an AI implant pretending to be a human. Disclosure, Daily Fintech is written by a stealth mode AI venture as a proof of concept.

Seriously folks, you cannot know my Identity. To read a free post you don’t care. If you are going to send me money, you do care. You do not want to send money to my dog.

This week on Daily Fintech is all about Digital Identity (KYC as seen by the bank). This is part of a series where we look at the impact of different disruptive technologies on Finance. In the past we have covered Blockchain, Artificial Intelligence, Regtech, Chatbots, XBRL, Wearables and Open API.

Digital Identity touches on almost everything Fintech. It is the foundation of trust and trust is the foundation of value exchange. In it’s KYC guise, it is core to RegTech. 

Do you hate the trade-off between security and productivity involved in passwords? You can do it properly (long complex passwords that are different for each service and that you change regularly). which gives you security but is too much of a time suck for most humans. Or you can leave your digital door wide open to hackers. 

Do CAPTCHAs annoy you? Ever wonder how secure they really are? 

Do you find the easy way out of entrusting your identity to some big social media service that becomes your gateway to the Internet and knows your most intimate secrets a bit disturbing?

If so, you are not alone. Welcome to the world of Digital Identity, which is trying to find a solution for you.

Today is the briefing about Digital Identity. Then we resume normal programming by focusing each day on use cases within different customer segments:

Tuesday = Wealth Management and Capital Markets

Wednesday = Small Business Finance

Thursday = Insurance 

Friday = Consumer Banking & Finance.

Government Issued Identity Artefacts

In the West we are used to proving our identity with simple artifacts such as driver’s license, passport or social security number. In the Rest (Of the World), verifiable identity is the on ramp to financial inclusion. This was brought vividly home to me when waiting in line at a Post Office in NYC and witnessing the desperation of a homeless person being refused a PO Box because she had no physical address. Without that PO Box she would be refused the job she had applied for. She would be an unperson without any official identity.

What if you are a refugee or live in a failed state? What if a Government Issued Identity Artefact is simply not an option?

In India they are tackling this through the Unique Identification Authority of India also known as Aadhaar. This an example of “first the Rest then the West” (leapfrogging old technology). The Indian Aadhaar system does two key things:

  • first, enrolls people by taking 13 biometrics (10 fingers, 2 iris scans and a photo).
  • then, issues a unique 12-digit random identifier (11 random numbers and one check digit to be precise)

When a person uses their Ardhaar Number (for example to access a bank account), they present their 12-digit number and then the entity they are interacting with does an authentication step (to prove they are indeed the person the number they are presenting points to).  This authentication step then replies back yes/ no (the presented biometric either matches the one on file or it doesn’t).

This is far more secure than something like a Social Security Number in America which is easily hacked by identity thieves.

Biometrics – “what part of your anatomy does Sir/Madam wish to use?”

Biometric security, which aims to replace passwords and CAPTCHA, comes down to a simple question. Which body part do you want to use to identify you?

– Finger. This one scares me. It is hackable, by simply recording somebody’s fingerprint and putting that on thin film. I can change my password if I am hacked, but I cannot change my finger.

– Eye: Iris recognition does not seem ready for prime time yet.

– Voice. This has a nice old-fashioned ring to it. Voice recognition is like the banker who recognized your voice. The tech has been brewing for a while and seems ready for prime time. VoiceVault and Nuance are the two leading contenders. Voice is probably better for high value transactions than getting a coffee or paying for a subscription. Talking to my phone in the line for my coffee seems too much like the movie Her.

– Typing rhythm. I never understood why BioPassword did not do better, it seemed so simple and elegant. Maybe mobile changed typing rhythm and created new rhythms around swipe.

There may be something new that emerges out of smart watches, such as pulse recognition, but that hits the universality problem ie not many people have smart watches.

That is why the Indian Ardhaar system takes 13 biometrics. It also uses low cost, robust/proven technology. This is not a laboratory experiment. It is a mass market deployment where every fraction of a penny counts.

FIDO – authentication with low friction

No, this is not your faithful dog.

The FIDO Alliance is an Identity Management consortium with 250+ members that are famous names in banking, insurance, e-commerce, authentication technology, payments, cellphone SIM suppliers and consumer electronics. The FIDO Alliance develops protocols and standards to authenticate users via their personal devices, so that users can get rid of passwords.

FIDO uses a hardware cryptographic device called Universal Second Factor (U2F), which generates a new key pair for every service that you connect to.

U2F does not rely only on biometrics. That is why it can claim the title Universal.

FIDO is designed to get the balance right between security and friction/ease of use. So FIDO allows for any of the factors of authentication to be used, such as:

– cryptographic tokens (think of this as something your device does for you to help authenticate you)

– biometrics

– somewhere you are (based on a geo-location service)

– something you know – a one-time password that is cryptographically created (and as any cold war espionage buff will tell you, one time passwords work very well).

The U2F protocol does not identify a user, it merely proves that someone has the device with control over a registered key.

Device based authentication from the past has major issues:

  • Magnetic strip card. This is your conventional credit card. These are fading out because they is so open to fraud. It only costs about $50 to buy a mag strip writer, and it’s easy to get your hands on cards to copy them.
  • Proximity card or RFID. These cards transmit stored information via RF (Radio Frequency). It is used more for identifying products (for example in a supply chain) than for people. For people there are privacy issues. For example, a Passport with RFID tags could be used by governments to remotely identify citizens of a given country by physical location (and in the wrong authoritarian hands that is dangerous).
  • Chip Cards. These are sometimes called Smart Cards or more technically Challenge/Response cards and Cryptographic Calculators. They perform a cryptographic calculation. Sometimes the card will have memory, and sometimes it will have an associated PIN (“Chip & PIN”) and sometimes not (“CHIP and Signature”). They are not fully secure on their own – being vulnerable to power-analysis attacks. The mobile money revolution can be seen as chip cards moving from plastic to just another service on your phone (which of course has a chip).

Authentication is not the same as Identification. You still need to identify yourself – for example, key in a 12-digit number if you are Indian. That is a pain point for new services that want to entice you in. You won’t key in a long identifier for a service you don’t know much about. That is why we need Identity Portability.

OpenID Connect – Identity Portability

OpenID Connect is about being able to use a common identifier across multiple sites (identity portability). As Open ID originated pre FIDO, they also did some authentication, but it now we can see FIDO as the solution to authentication and the two should be seen as complementary.

You have come across the idea of identifier portability when you log into a website using a service such as Facebook, LinkedIn, Twitter or Google (referred to as an Identity Provider service in this context). This approach lets users leverage one account across a multitude of sites across the web and gives people control over which attributes of their identity are asserted and to whom in a secure and privacy-controlled fashion.

OIDC doesn’t authenticate the user but rather conveys that authentication across the network. This is where FIDO plus OIDC is so powerful. The user can protect their primary identity using FIDO and use it all over the web using OIDC.

Something You Are and the privacy challenge

Digital Identity is such a thorny problem, fraught with technical, legal, societal and political issues, because your Personally Identifiable Information (PII) aka your digital exhaust (the trails you leave on the Internet) will define how you live your life (whether you get financing, get a job, get citizenship and so on).

This is what can change society and business at a fundamental level. There is a reason why Microsoft worked so hard to get Passport established – the upside is massive. There is also a reason why any company that gets close to this prize – whether it is Facebook or Apple or Microsoft – eventually gets consumer pushback.

As Ethereum’s Vitalik Buterin points out:

“10 years from now it may be harder to change identity providers than it is to change countries”

PII is so critical because this data determines your access to:

  • capital (how credit-worthy you are).
  • a job or customers (what you have done)
  • friends (who you know)
  • Your access to healthcare (your medical records).

The problem with your PII stored in centralized data centers is that data can be hacked and your identity can be discovered through data science technology. For example, one service provider may store your medical records and another your financial records and in both cases your identity may be masked from the service provider, but it is technically possible to identify an individual person from this data.

Maybe that data should be stored somewhere safer such as the Blockchain.

Sovereign Woman on the Blockchain

Blockchain technology can meet two fundamental needs:

  • Trustless and decentralized. Your Identity is not under the control of any institution (either Government or commercial).
  • Immutable. Nobody can change a record; they can only append a new record.

In this vision of the future, the human is sovereign and is in charge.

Consumer control over Identity enables granularity – you can have my driver’s license but not my passport or medical records and you can only have it for this one transaction. This could enable the Doc Searls vision of Vendor Relationship Management (VRM). I have been fascinated by VRM since I wrote about it for ReadWrite back in 2007. Some tech disruptions have to wait for a trigger to turn inevitable into imminent. The blockchain based identity systems may be that trigger. A similar vision is articulated in the book called Pull by David Siegel. This is a fundamental reordering of commerce. For all the talk of “customer first” a world where customers are really in charge will be a wrenching transformation for most companies.

This will challenge all the business models driven by big data. Translation of big data:

“We will assemble data about you so that we (or our customers) can sell to you in a way that suits us and maximizes our profit”.

The reordering of commerce enabled by consumer control over PII changes that to:

“I will buy from you when and how it suits me”.

It is also a fundamental change in our relationship with government. We are used to a world where our identity is granted to us by government. If humans control their own ID our relationship with government also changes.

This fundamental reordering could be made possible by Blockchain technology.

Image Source

Daily Fintech Advisers provides strategic consulting to organizations with business and investment interests in Fintech & operates the Fintech Genome P2P Knowledge platform.

Tags: digital identityThe Tech in FinTechtheme weeks
Previous Post

CapOne Tests Voice Tech Applications with Cortana

Next Post

Anthemis Ecosystem Development: 6 Months In

Related Posts

Image by CanStock
Archive

Blend Labs integrates acquisition’s mortgage automation process

August 20, 2021
Photo by CanStock
Archive

Chilean fintech looks for slice of giant money transfers market

August 5, 2021
Image by CanStock
Risk & Security

Listen: How banks can protect themselves against cybersecurity risks

August 3, 2021
Next Post

Anthemis Ecosystem Development: 6 Months In

Please login to join discussion

Stay Informed with Our Newsletters

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

RETAIL BANKING

Huntington Bank’s new branch in Spartanburg

Huntington Bank resolves outage

May 7, 2025
bank

Barclays, Banco Santander, Lloyds plan product expansion

May 5, 2025
satisfactiin

Online banks lead FIs in customer satisfaction

May 2, 2025

SPONSORED

Just Released! 2025 Strategy Benchmark

May 1, 2025

Leverage Treasury Management to Turn Fraud Prevention Into a Strategic, Revenue-Generating Opportunity

April 1, 2025

A growth mindset in banking requires AI

March 27, 2025
  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 Manage Cookie Consent

Connect

twitter linkedin podcast podcast podcast
© 2025 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • AI
    • Business Banking
    • Core
    • Cloud
    • Payments
    • Retail Banking
    • Risk & Security
  • DATA
  • TRANSACTIONS
  • EVENTS
    • Bank Automation Summit
  • PODCAST
  • WEBINARS
    • Upcoming Webinar
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • NEWS
    • All News
    • AI
    • Business Banking
    • Core
    • Cloud
    • Payments
    • Retail Banking
    • Risk & Security
  • DATA
  • TRANSACTIONS
  • EVENTS
    • Bank Automation Summit
  • PODCAST
  • WEBINARS
    • Upcoming Webinar
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

THIS WEBSITE USES COOKIES

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “I CONSENT”, you consent to the use of ALL the cookies.

Cookie settingsI CONSENT

Review our Cookie Policies
.
Manage Cookie Consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
__cfruidsessionCloudflare sets this cookie to identify trusted web traffic.
__RequestVerificationTokensessionThis cookie is set by web application built in ASP.NET MVC Technologies. This is an anti-forgery cookie used for preventing cross site request forgery attacks.
_abck1 yearThis cookie is used to detect and defend when a client attempt to replay a cookie.This cookie manages the interaction with online bots and takes the appropriate actions.
34f6831605sessionGeneral purpose platform session cookie, used by sites written in JSP. Usually used to maintain an anonymous user session by the server.
a64cedc0bfsessionGeneral purpose platform session cookie, used by sites written in JSP. Usually used to maintain an anonymous user session by the server.
ak_bmsc2 hoursThis cookie is used by Akamai to optimize site security by distinguishing between humans and bots
ARRAffinitysessionARRAffinity cookie is set by Azure app service, and allows the service to choose the right instance established by a user to deliver subsequent requests made by that user.
ARRAffinitySameSitesessionThis cookie is set by Windows Azure cloud, and is used for load balancing to make sure the visitor page requests are routed to the same server in any browsing session.
AWSELBsessionAssociated with Amazon Web Services and created by Elastic Load Balancing, AWSELB cookie is used to manage sticky sessions across production servers.
bm_sz4 hoursThis cookie is set by the provider Akamai Bot Manager. This cookie is used to manage the interaction with the online bots. It also helps in fraud preventions
cf_ob_infopastThe cf_ob_info cookie is set by Cloudflare to provide information on HTTP Status Code returned by the origin web server, the Ray ID of the original failed request and the data center serving the traffic.
cf_use_obpastCloudflare sets this cookie to improve page load times and to disallow any security restrictions based on the visitor's IP address.
CONCRETE5sessionThis cookie is set by the provider Concrete5 web content management system. This is a necessary cookie used for maintaining the user session between pages.
connect.sid1 monthThis cookie is used for authentication and for secure log-in. It registers the log-in information.
cookielawinfo-checkbox-advertisement1 yearSet by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category .
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
cookiesession11 yearThis cookie is set by the Fortinet firewall. This cookie is used for protecting the website from abuse.
crmcsrsessionGeneral purpose platform session cookie, used by sites written in JSP. Usually used to maintain an anonymous user session by the server.
ep20130 minutesThis cookie is set by Wufoo for load balancing, site traffic and preventing site abuse.
JSESSIONIDsessionThe JSESSIONID cookie is used by New Relic to store a session identifier so that New Relic can monitor session counts for an application.
LS_CSRF_TOKENsessionCloudflare sets this cookie to track users’ activities across multiple websites. It expires once the browser is closed.
PHPSESSIDsessionThis cookie is native to PHP applications. The cookie is used to store and identify a users' unique session ID for the purpose of managing user session on the website. The cookie is a session cookies and is deleted when all the browser windows are closed.
sxa_sitesessionThis cookie is used to identify the webiste visitor's session state across page requests on server.
ts3 yearsPayPal sets this cookie to enable secure transactions through PayPal.
ts_c3 yearsPayPal sets this cookie to make safe payments through PayPal.
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
wordpress_test_cookiesessionThis cookie is used to check if the cookies are enabled on the users' browser.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
CookieDurationDescription
__cf_bm30 minutesThis cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
_zcsr_tmpsessionZoho sets this cookie for the login function on the website.
663a60c55dsessionThis cookie is related to Zoho (Customer Service) Chatbox
bcookie2 yearsLinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID.
bscookie2 yearsLinkedIn sets this cookie to store performed actions on the website.
e188bc05fesessionThis cookie is set in relation to Zoho Campaigns
geosessionThis cookie is used for identifying the geographical location by country of the user.
iamcsrsessionZoho (Customer Support) sets this cookie and is used for tracking visitors (for performance purposes)
langsessionLinkedIn sets this cookie to remember a user's language setting.
languagesessionThis cookie is used to store the language preference of the user.
lidc1 dayLinkedIn sets the lidc cookie to facilitate data center selection.
optimizelyEndUserId1 yearOptimizely uses this cookie to store a visitor's unique identifier which is a combination of a timestamp and a random number. Different variations of web parts are shown to users that optimizes the website's user experience.
tableau_localesessionTableau uses this cookie to determine the preferred language and country-setting of the visitor - This allows the website to show content most relevant to that region and language.
UserMatchHistory1 monthLinkedIn sets this cookie for LinkedIn Ads ID syncing.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
CookieDurationDescription
AWSELBCORS20 minutesThis cookie is used by Elastic Load Balancing from Amazon Web Services to effectively balance load on the servers.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
CookieDurationDescription
__gads1 year 24 daysThe __gads cookie, set by Google, is stored under DoubleClick domain and tracks the number of times users see an advert, measures the success of the campaign and calculates its revenue. This cookie can only be read from the domain they are set on and will not track any data while browsing through other sites.
_ga2 yearsThe _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
_gcl_au3 monthsProvided by Google Tag Manager to experiment advertisement efficiency of websites using their services.
_gid1 dayInstalled by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously.
ajs_anonymous_idneverThis cookie is set by Segment to count the number of people who visit a certain site by tracking if they have visited before.
ajs_group_idneverThis cookie is set by Segment to track visitor usage and events within the website.
ajs_user_idneverThis cookie is set by Segment to help track visitor usage, events, target marketing, and also measure application performance and stability.
browser_id5 yearsThis cookie is used for identifying the visitor browser on re-visit to the website.
CONSENT2 yearsYouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data.
sid1 yearThe sid cookie contains digitally signed and encrypted records of a user’s Google account ID and most recent sign-in time.
uid1 yearThis is a Google UserID cookie that tracks users across various website segments.
vuid2 yearsVimeo installs this cookie to collect tracking information by setting a unique ID to embed videos to the website.
WMF-Last-Access1 month 21 hours 5 minutesThis cookie is used to calculate unique devices accessing the website.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
CookieDurationDescription
_dc_gtm_UA-1038974-41 minuteUsed to help identify the visitors by either age, gender, or interests by DoubleClick - Google Tag Manager.
_fbp3 monthsThis cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website.
_pxhdpastUsed by Zoominfo to enhance customer data.
fr3 monthsFacebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin.
IDE1 year 24 daysGoogle DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile.
test_cookie15 minutesThe test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies.
VISITOR_INFO1_LIVE5 months 27 daysA cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface.
YSCsessionYSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages.
yt-remote-connected-devicesneverYouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
yt-remote-device-idneverYouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
yt.innertube::nextIdneverThis cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.
yt.innertube::requestsneverThis cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
CookieDurationDescription
049fc2ef5beb27056b07d9e4c4d13fd3sessionNo description
akaalb_http_misc_subssessionNo description
AnalyticsSyncHistory1 monthNo description
BIGipServermsocu-web-2-rr.webfarm.ms.com.10882sessionNo description
bm_misessionNo description available.
CX_4061522881 yearNo description
DCID20 minutesNo description
debugneverNo description available.
DrupalVisitorMobilesessionNo description available.
ep2033 monthsNo description available.
frbatlanta#langsessionNo description
geo_info1 yearNo description available.
GoogleAdServingTestsessionNo description
li_gc2 yearsNo description
loglevelneverNo description available.
loom_anon_commentsessionNo description available.
loom_referral_videosessionNo description
mkjs_group_idneverNo description available.
mkjs_user_idneverNo description available.
MorganStanley.ClientServ.Common.IPZipAccess.IPZipCookie.DEFAULT_COOKIE_NAMEpastNo description
NSC_us_nbsl-83+63+21+25-91sessionNo description
nyt-a1 yearThis cookie is set by the provider New York Times. This cookie is used for saving the user preferences. It is used in context with video and audio content.
nyt-gdpr6 hoursNo description available.
nyt-purr1 yearNo description available.
OCC_Encrypted_CookiesessionNo description
polleverywhere_session_id14 daysNo description
ppnet_2020sessionNo description available.
ppnet_2777sessionNo description available.
reuters-geosessionNo description
shell#langsessionNo description
smcx_0_last_shown_atsessionNo description available.
tableau_public_negotiated_localesessionNo description available.
vary1 monthNo description
www#langsessionNo description
X-Vive-CountrysessionNo description
xn_uuid1 monthNo description
Save & Accept
Powered by CookieYes Logo