Breadcrumb

  • Home
  • Biometric data has moved from security to risk. Here's how.

Search form

Main navigation

  • Home

Biometric data has moved from security to risk. Here's how.

Friday, 1 November, 2024 - 08:00

There's the old saying, attributed with certainty by the many to a few, that one robs a bank because that's where the money is. Bank security has moved on from heavy doors, locks and guards and, as face to face contact has dramatically reduced, the keys are technological. However, now the keys are stored in databases that are accessed via the internet.

There is a demonstrable fallacy that data is secure. No one, not governments, not huge corporations, not cloud providers or anyone else can say, with hand on heart, that data is safe.

Aside from innocent human error, even recklessness, there is always the reality of malicious activity.

Data protection standards are illusory. The only effective way to protect data is not to collect and/or hold any. And that flies in the face of the business model of many, many companies.

There is no value in here repeating the many arguments opposing the use of terms and conditions which contain clauses which cannot be severed and which contain rights over data (in all senses) or websites that provide for certain data to be kept confidential after the user requires it - and which, because this happens after the company has collected - and processed information - means that it is passed to third parties before permission is cancelled. It's important to understand the difference between "cancelled" and "revoked."

Everything from government identification details to bank information, from genealogy information to health details and even commercial information is stored on computers. It is all under attack, usually by means of an illegal connection from outside the company.

Let's be clear: what was acceptable data collection 25 years ago is often no longer acceptable.

I'll give an example: 25 years ago when my company was building an e-learning platform, we looked at using biometrics to ensure that staff in banks, etc., taking examinations for money laundering risk training were in fact the registered member of staff. It wasn't our idea: it was several banks which asked how we could be sure that a person did in fact take the exam. We looked at fingerprints using readers, either stand-alone or built into keyboards. It was doable and had additional security benefits such as authorising access to terminals and PCs. In those pre-data protection law days, we had no concerns over storing that data. Today, we would not consider doing it. In fact, no bank took it up because (get this) the cost of replacing all their keyboards with e.g. Cherry, was too high. The latest version costs around USD200 so it's not cheap.

There was another problem: bank etc. staff were not happy with the idea of giving out their fingerprints. It wasn't a security issue, then, it was simply that people had a very different view of privacy.

That sentence encapsulates the central problem in this topic: companies talk about privacy (and how they will erode it while saying they are protecting it) while treating security as a separate topic. In fact, they are inter-related.

Biometrics have moved on: everything from the way a person types through vocal cues (accent, phraseology, intonation, linguistics) through fingerprints, palmprints, iris and retina scans are used by companies who simply do not have a need to collect or store it.

Banks do; a facial recognition program attached to an ATM might prevent ATM abuse. The tech is certainly readily available. But ATMs are the most vulnerable of all a bank's operations and so that is probably undesirable.

Nigel Morris-Cotterill is at www.countermoneylaundering.com. He is the author of "Cleaning up the 'net: an action plan to combat crime on the internet"

The swing, by ordinary people, away from concerns over privacy has led to the voluntary release of highly sensitive information to a vast array of companies around the world. From LinkedIn's "verification" service operated by a third party which requires those forced to use it to accept terms that allow the passing of information to third parties with a note that there is an opt-out later, to "super apps" that include an e-wallet and therefore require a level of identification that a simple car-booking service would not.

The question is simple: who's holding all that identification data and can criminals get it?

The answer is equally simple: all kinds of companies, built by all kinds of people in all kinds of places. And yes. As breach after breach demonstrates, criminals can get pretty much any data from anywhere.

I deal with an online shopping platform that says in its terms and conditions that it will retain payment card information. I objected and told them to delete it. They said they had and if I look at my account information, it's not shown. But when I make a purchase, I'm offered the option to use that card and the number appears. So the company has expressly told me the information has been deleted but there it is, on my screen, every time I place an order. This is what I alluded to earlier: data security fails through human error or recklessness.

If we tie all of this together in a nice package we find that the more security measures are created and enforced, the bigger the incentive for criminals to collect the data upon which those security measures depend. So if your face is the key to your bank account, and your face is on social media or if you walk down a busy street where someone has a small high-resolution camera sitting on a table outside a café, tough. In short, your face is easier to steal than a password, and as we know, they aren't especially secure, are they?

----- ADVERTISEMENT ----

About this section

Opinion pieces or "Op-Eds" are the home-made bombs of the publishing world. So long as they meet editorial standards, are not intentionally offensive with a view to causing hurt or insult and are relevant to our field of endeavour, we will look at submissions.

We like contentious, we like contrarian views. We don't like pretty much any -ism . We recognise that Opinion pieces are one person's view and are not balanced (if they are balanced and reach a reasoned conclusion, they are probably more suited to the Articles section). We do not like acronyms and buzzwords.

Op-Eds are the author's personal views and do not necessarily represent the views of World Money Laundering Report or its publishers.

To submit an Opinion piece, please complete the Contact form.

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.