In the near future, most of us will want to:

  1. be able to walk into the supermarket, collect our stuff, and walk straight out with the payment already processed in the background
  2. receive instant coupons, or 2-for-1 offers, or other value add services WHILE shopping
  3. receive a warning if an item contains something to which we are allergic
  4. receive a reminder from your fridge / freezer / cabinets that you are low on certain products while you are walking down the relevant aisle
  5. …and so on.

However, you cannot have any of these things unless you made the necessary information available to the supermarket chain you are in. And they will not make these things available TO you unless they have good assurance that you, are in fact, you.

To enable just those 4 things listed above, you had to release a significant amount of personal data, all of which can have privacy implications:

  1. requires a number of things – from biometrics (facial recognition for example) to financial account access
  2. requires a comprehensive and always growing record of your choices, preferences, and habits
  3. requires details of certain bits of medical data
  4. requires your entire kitchen / bathroom / bedroom to be enabled for the Internet of Things, as well as a highly detailed geolocation on your whereabouts
  5. …and so on.

Are you OK with that?

I am, but I know many who are not, and I also know that as the generations progress, there will be less and less concern over these ‘conveniences’, as they will have become common place. I will go as far as to say that within the next 10 years, any supermarket NOT providing some of all of these services will not be able to compete, and possibly become Internet-Free corner stores where you’ll find the world’s ‘privacy paranoid’ shopping for their tin-foil helmets and electronic cloaking devices.

The bottom line is that the concept of privacy itself is changing. The generation of kids in secondary schools today has never known life without the Internet, and in most industrialised nations, every kid has a mobile phone. They are always plugged in, always connected, and, as never before, a vast majority of their lives is recorded somewhere online. They are active on social media, SMS, chat, email, and every other technology designed to stay in touch 24/7.

Our idea of privacy is not theirs, and everything from racial prejudice to the stigma attached to nudity will standardise and globalise, and I cannot help but think for the better. Your children’s education will no longer be tied entirely to the doctrines of the previous generations, and self perpetuating ignorance has no place in a time when every piece of knowledge is at your fingertips. Not that this will stop those determined to be an arse.

I’m certainly not talking about some utopia here, ignorance in all its forms will never go away, but if the vast majority of your life is an open and available book, your complete identity becomes an ultimate form of authentication, and the security OF your identity only gets better as your life progresses.

The current ability to authenticate only against static data will no longer suffice (passwords, secret questions etc.), and the coming methods of identity management and authentication will completely change the face of privacy.

I see this as a good thing, but I’ll leave it to the folks hiding away in Faraday cages to make sure that Big Brother doesn’t get everything his way.

 

Why, in the face of threats, do we humans either spend an inordinate amount of time blaming others, or insist on patching the symptoms instead of solving the root cause?

  • Target: I had my credit card data stolen, so let me buy millions of dollars of new PEDs
  • ICO: The NHS lost some data, so let’s fine them.
  • Rest of the World: The NSA is reading our emails, so let’s encrypt them.

Every one of these reactions has completely missed the point, and are the definitive closing the barn door after the horse has bolted.

Question: Do you tell your deepest secrets to your loved ones in a very loud voice in the middle of a room crowded with strangers? Or do you wait until you’re alone, and even then talk quietly just in case?

And yet you think you should have privacy on the Internet?  You could not yell any louder than that. Forget your RIGHT to privacy, focus on YOUR ability to KEEP things private.

Even with encryption, who has the best equipment and expertise; you, or the NSA? Or worse; you, or organised crime? They are extremes, so let’s bring it closer to home; you, or your IT admin? How about; you, or your children?

So now, instead of solving the problem, security vendors are going to inundate you with offers to encrypt your data, encrypt your communications, encrypt your very identity, and they will all fail. 2014 should be the Year of Identity Management & Authentication, or to put it more facetiously; The Year of Only You Being You.

Here’s a ridiculously long and complicated analogy of your identity;

Imagine that you are a 1,000 piece puzzle, and when all of the pieces are together, only then can you see the full picture. As the puzzle is broken up and distributed across many hundreds of separate locations, the picture fades from each piece until it’s just plain white. Anyone stealing even a couple of hundred pieces will never be able to re-create you, never know what the picture is, or even where to find the rest of it.

Now, image that access to your most private information was tied to the complete picture, would that not be infinitely better than a username and password, or a 4 digit PIN?

Your true identity, the everything that is you, is made of things that cannot be put into a mechanism for authentication. Yet all we have right now is 3 factors: something you know (password), something you have (physical token), and something you are (biometrics). What about your likes and dislikes? Your future plans? Your everyday interactions?

All of theses things and infinitely more make up your true identity, and until we can come up with a way to get a whole bunch of them into a practical and seamless method of authentication, your data will be at risk, regardless of encryption. Yes, encryption may add a layer of security, somewhat akin to building your fence higher than your neighbours, but any commercial encryption product that will be pushed for home PC or mobile users will be practically useless.

Instead, privacy will come from the exact same source as identity managements’ will; very wide distribution of data with extremely limited ability to piece it all together. Some may disagree with my previous blog on the benefits of ‘profiling’, but you cannot have a robust identity without it. Bitcoin has proved that you do not need single databases/sources of storage for this stuff, the interconnectivity of the Internet’s individual systems can provide that with the right front end.

So, bottom line; don’t waste your money on expensive encryption solutions unless those solutions are performing the above distribution (bitcloud for example), but then it’s not encryption as we know it, it’s the next generation of privacy.