Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Monday, June 20, 2016

Is Digital Transformation Better With Digital Identity?

While I find the definition of a digital identity cold and the idea of being known by some kind of serial number abhorrent, I question how effective the new digital world will be without some kind of verifiable and secure identity. I'd like to explore some of the benefits of having a digital identity for everyone and everything will help the digital age and transformation to it by following digital identity evolution over time.



The Wiki Definition is as Follows:


A digital identity is information on an entity used by computer systems to represent an external agent. That agent may be a person, organisation, application, or device. ISO/IEC 24760-1 defines identity as `set of attributes related to an entity'.



















Source: ForgeRock 


Enabling "The Outside in" Customer Experience:

Imagine if there were preferences of all your customers known and available to all organizations. Assuming that the customer could control the level of intimacy, organizations could actually know enough to delight an individual customer. This would be an additional level of usefulness beyond just customer journey analysis and could lead to behavior analysis to help customers of all types cope and lead to delight in many circumstances and moods. 

Sensing State Through Things: 

If all sensors, controllers, software and software agents would have a unique and standard identification, they could talk to each other and collaborate on decisions and work to support people organizations and things. As digital identity evolves things could dynamically collaborate and bid on work itself in an intelligent way guided by policies, rules and constraints. 

Sensing Context Through Relationships: 

As organizations, people and machines interact in patterned relationships, beneficial outcomes and relationships can emerge into better practices mined from real interactions over time. Patterns of success and possibility can tracked through emerging relationships and rules and constraints could merge for optimal performance over time. 

Security of  Identities:

One of the most crucial corner stones of a digital identity is air tight security. The identity and associations must be kept save and be unhackable. For people bio-metric authentication seems to be gathering steam, but it might require several methods to be foolproof. 

Secure Exchange within Relationships:

The banking industry along with government bodies are working towards free exchange through secure means. At the moment, Blockchain  looks real promising for very secure exchange that is almost unhackable by the nature of the number of computer cycles it takes within a short time frame. 

Net; Net:

As much as it bothers me, it seems that digital identity is eventual with all of it's blessing and potential for risk. I just hope they don't implant us with chips like the government has suggested. For digital to be truly successful we will be a secure and rich digital identity. 





Monday, December 14, 2015

Art Projects for 4Q Quarter 2015

I concentrated on digital art this quarter and have some pieces to share with you. I managed to be shown in Art Scope Miami this month, so that was exciting. One of these days, I'll make a featured artist and head out to one of these big events. I hope you enjoy these and let me know if any appeal to you :) You can check out my web sites for older pieces.

Web Presence: http://www.james-sinur.com/  & http://www.jamessinur.com/




Digital Art: 

The Blues:




Cool Ripples:




Marble Explosion:



Color on Fire:



Paintings: 


Lava Flow:




Mystical Mesa:









Thursday, September 24, 2015

Blog Activity for 3Q 2015

I thought you might find it interesting what folks are interested in reading about process related topics on my blog.The hot topics were business rules, fast data, security and dealing with legacy in the digital world, but that might have been influenced by the fact that I did a series on each topic. I would sure like to hear what topics you would be interested in, so I can more meet your needs. Please post a comment, if you think there is a need for a particular topic. 


Direct Links Below in Ranking Order:

http://jimsinur.blogspot.com/2015/09/rules-can-be-cool-or-they-can-be-cruel.html
http://jimsinur.blogspot.com/2014/07/internet-of-things-and-process-yields.html
http://jimsinur.blogspot.com/2014/11/reaping-benefits-of-intelligent.html
http://jimsinur.blogspot.com/2015/04/target-innovative-process-and-business.htmlhttp://jimsinur.blogspot.com/2015/08/components-of-fast-data-architecture.html
http://jimsinur.blogspot.com/2014/07/god-now-has-one-of-his-gems-back.html
http://jimsinur.blogspot.com/2015/08/fast-data-is-better-than-big-data.html
http://jimsinur.blogspot.com/2015/07/great-security-doesnt-ruin-party-time.html
http://jimsinur.blogspot.com/2014/09/behavior-modeling-key-missing-context.html
http://jimsinur.blogspot.com/2015/03/processes-are-going-hybrid-for-new.html
http://jimsinur.blogspot.com/2015/08/announcing-new-series-on-business-rules.html
http://jimsinur.blogspot.com/2015/09/rules-for-legacy-modernization-and.html
http://jimsinur.blogspot.com/2015/09/just-say-no-to-hard-coded-logic.html
http://jimsinur.blogspot.com/2015/09/art-projects-for-3q-quarter-2015.html
http://jimsinur.blogspot.com/2015/09/executive-insights-delights-audiences.html
http://jimsinur.blogspot.com/2015/07/racing-to-digital-while-managing-legacy.html

:
Where in the world are the hits coming from?  The US is always number one by a wide margin and is not shown here. There is no surprise that France, Russia & Germany are at the top, but I am surprised that Sweden jumped on board displacing Turkey.










Monday, July 20, 2015

On Top of the World with Secured Shared Processes

Like it or not, we are headed towards participation in shared processes. Processes that share across internal and external organizational boundaries. It might be taking a value or supply chain or a process outsourcing effort and making the policies, rules and constraints, more changeable by any of the partners or customers. This means that these process definitions, rules and performance dash boards will be visible to many outside your organization at a minimum or alterable at the maximum. Some of these process parameters will be global and shared with very tight security and others will be local and loose. Either way great security is necessary to optimize and protect these shared processes and their contributing components to stay on top of the world. As depicted in one of my favorite groups, Imagine Dragons, in the official video below:






















https://www.youtube.com/watch?v=w5tWYmIOWGk


Staying on Top of  Securing Process Flows:

If your processes are pretty static & dumb or if they are smart & nimble to determine their own direction, they all need security that is top notch. There should be security that is granular enough to identify who has the right to change the process flows (human or bot) that guarantees an end to end flow that delivers the results that all of the parties in the shared process can support. This starts with simple authentication of the individuals / bots making the changes and includes guarantees that all parities agree to the change. A unsecured change to a process could be devastating to any one of the participants or partners in the end to end process where the shared portions are unauthorized.

Staying on Top of  Securing Policies,  Business Rules & Constraints:

Even the most simple of rules in a shared process can have positive or negative effects to the overall process, the shared portions of that process or individually owned portions of a process. It's really difficult to outsource or share processes that differentiate value chains and individual processes when the rules that govern them are outside the organization. This is why great security over global and shared policies, rules and constraints have to be identified to require global agreement before changes can happen in our speed hungry world. Those business rules that only have local impact will also be secured and authorized, but not to the same extent.

Staying on Top of Securing Transparency of the Outcomes:

Visibility to all parties in essential in local and shared processes. Shared processes are likely to have a global performance management dashboards that highly shared to see the operations on a moment by moment basis and impact of any new changes authorized by the global partner networks. Every one's view of that corporate performance might be different, but the data / information will be consistent. Changes to that data will require significant collaboration and security, Local variations to the performance measures and views will again require a lighter security touch.

Net; Net:

There are many partners, parties and pieces to a shared process that have to measured properly for the proper level of security. If processes are just between your organization and a customer, then the security must be there, but not to the same level of scrutiny. Shared processes have to have top security methods, tools and techniques to stay on top of the world !!


Additional Reading on Security:

http://jimsinur.blogspot.com/2015/07/great-security-doesnt-ruin-party-time.html
http://jimsinur.blogspot.com/2015/07/imagine-no-passwords-its-easy-if-you-try.html
http://jimsinur.blogspot.com/2015/06/security-is-boat-anchor-to-digital.html







Tuesday, July 14, 2015

Great Security Doesn't Ruin Party Time

As organizations roll out most excellent / smarter processes and applications to compete in the digital world, the opportunity for abuse increases. The number of smart resources dynamically contributing to changing goals and desired outcomes will be increasing and the power that these resources posses will make them a target for those with bad intentions. These smart processes can be lead the wrong direction easily as they are built to auto-adjust to changing conditions thereby producing unexpected consequences in the hands of the wrong people. Those with bad intent can change the goals, decisions, and actions of processes and applications and hurt many as a consequence. Security will have to step it up while becoming less visible and easy to deal with in the new digital world. See http://jimsinur.blogspot.com/2015/06/security-is-boat-anchor-to-digital.html

















Misguiding Processes with Patterns & Goals:

The kind of dynamic and real time processes and applications that will be emerging in the digital world will be susceptible to bad consequences through fooling the process into pursuing the wrong sets of goals by feeding these processes with false patterns. Most of the new processes will be able to sense events and patterns of events and those with bad intent can mislead a processes into sensing the wrong events and changing the goals to undesirable under the conditions and contexts.


Misguiding Processes with Decisions:

These dynamic processes will likely be dependent big data and embedded algorithms. Those with bad intent could alter the algorithms or the data bound for the analysis. Switching the combinations and sequence of these algorithms could have a bad and maybe undetectable effect until later down stream. This could be true of cognitive services (COGs) or machine learning where constraining rules and policies could be tampered with in real time.


Misguiding Processes to Act Improperly:

Besides messing with the goals or decisions, the actual actions could be altered in real time to create havoc. If for instance a fire drone was being flown for observation purposes it's code could be altered to interfere with outcomes rather than help. In the case of fire observation, the drone could be directed in the flight paths of retardant craft and cause misses and delays at a minimum.


Net; Net:

Great security starts and making sure that the participants in the processes are authenticated and the persons authorizing change to the processes are authenticated in a fool proof manner. In additions there should be extra controls on key pieces of code and code sequences. There should be a security sensitivity analysis based on likely and unlikely scenarios in addition to authentication.

See http://jimsinur.blogspot.com/2015/07/imagine-no-passwords-its-easy-if-you-try.html

Monday, July 6, 2015

Imagine No Passwords: It's Easy If You try

You may say I'm a dreamer, but I'm not the only one. Well it is a bit of a dream, but It will happen and is a must for digital organizations to move forward quickly to transform and adapt to change. See http://jimsinur.blogspot.com/2015/06/security-is-boat-anchor-to-digital.html

Biometric technologies hold big promise and have for years, but they all seem to have problems. We are seeing all of them roll out at the same time. The question is which one dominates and makes passwords passe?  Let's dig a little into each approach. 
















Voice:

Voice authentication seems well-suited to smartphones: They’re already designed to handle the human voice, and include technologies like noise filtering and signal processing. Approaches to speaker identification vary, but they all have to handle variations in speech, background noise, and other differences. As long as there is not static pin, there is hope here to foil recordings. Voice prints will have to be guarded in way that does not allow local phone storage and spying to be successful.


Finger Printing:

Typically, users swipe a finger over a narrow one-dimensional scanner, and the system compares the data to an authorized user. The process of scanning and matching is complex, but as the technology has evolved, accuracy has improved and costs have come down. But fingerprint readers have downsides. The most obvious are injuries like burns and cuts — imagine being locked out of your phone or computer for a week because a potholder slipped. Stains, ink, sunscreen, moisture, dirt, oils, and even lotion can interfere with fingerprint readers, and some fingerprints just can’t be scanned easily.

Facial Recognition:

Another biometric scan technology is facial recognition. This technology is considered a natural means of biometric identification since the ability to distinguish among individual appearances is possessed by humans. If there is movement that can be detected to prove life versus a captured image, this approach seems promising. Bad lighting, glasses, smiles, goofy expressions, hats, and even haircuts can cause problems. Even the best facial recognition systems struggle with angled images, and people’s faces can change radically with age, weight, medical conditions, and injury.

Iris Scanning:

Iris recognition also has pitfalls. Users would likely have to hold a device closed to their face, with decent lighting and little to no motion. Most eyewear would have to be removed, and some drugs and medications can deform an iris pattern by dilating or constricting pupils try passing an iris scan following an eye exam. iris scanners can be fooled by quality photographs, or even contact lenses printed with fake irises. As a result, right now the technology is mostly used in human-supervised situations — like immigration and passport control — rather than automated systems.

Tattoos & Pills:

Pills and tattoos could replace passwords as new and radical solutions to the authentication problems. You could easily tattoo, inject or ingest electronic ids onto or into people. Of course there would be great push back to these forms of invasive forms of branding. Maybe you could make these approaches cool, but the resistance would be great unless there were negative consequences for not conforming. Of course, this is an idea from DARPA. I would die first. 

Net; Net:

Biometric approaches depend things not changing and nobody else being able to duplicate the biometric of choice. Once they are breached, there is little to do, but to change approaches or create a random and evidence of life approach. I'm not normally a betting man, but I think voice has the best shot with a little hashing & randomizing because phones are getting better at killing background noise.   

Some of the materials in this blog were sourced from Goeff Duncan. 

Tuesday, June 30, 2015

Security is the Boat Anchor to Digital Progress

Have you ever tried to row a boat whose anchor is still stuck on the bottom of the lake or  the ocean? It's really a fruitless and frustrating experience. This is how I would describe the effect that the lack of great and easy security is having on the whole digital experience today. In the coming weeks, I expect to dig a little deeper into the nature of the problems and write specifically how the lack of easy and great security has on our progress toward a better digital experience enabled by great process leveraging cognitive resources. Security is holding back a better customer experience, a more powerful and cognitive set of processes and process sharing to enable seamless value / supply chains.








Security and the Customer Experience:

Why in the world do we have to remember user IDs and passwords for each organization that we do business with these days? Every organization has a different set of rules for passwords ergo causing us to remember IDs and passwords galore. To fight this and weak memory moments, we create lists of IDs and passwords and squirrel them away in some remote spot on our computers or paper file drawers which have their own security risks. This is pure insanity and starts us off with a sour attitude towards the customer experience nearly every organization we do business with even though the processes might be OK. This sets a lousy tone for the whole customer experience. Add the fact the processes don't really know what we want and how we want to be treated. and you have a mess. You can make this misery mobile as a first step, but the point is that the customer journey starts off on a bad foot. It's time for a change !!

Security and the Powerful Processes:

Why in the world should we have to deal with dumb processes with a simple mobile access that knows nothing about us and our preferences? Processes should know who we are based on additional data, policies and rules we give organizations. Based on our history with an organization, the processes should orient themselves around us and give us the knowledge to service ourselves or be serviced by representatives that are not so specialized as to have us pick the right department to work with for results. This kind of powerful process will create a higher promoter score for the organizations. This again is dependent on better security of IDs, passwords, data and rules. It's time for a change !!

Security and Shared Processes: 

Why in the world do we have to stitch together sub-processes and the manage the result of each to contribute to a set of end goals and outcomes? As cognitive and intelligent processes get shared across organizational lines (internal or external), processes will have to have bullet proof security protecting all the policies, data, rules, constraints and authorizations. As end to end processes act in a seamless manner across legal entities, the value of air tight security raises to a critical level. When this includes shared resources such as intelligent devices like smart sensors,  robots or cognitive services (COGS) in the cloud, security is one big issue to wrestle with in the future. This kind of process is starting to emerge in adaptive case management and large scoped end to end processes.
It's time for a change !!

Net; Net:

We have been sweeping security under the rug like that fact that we left the anchor out on our new digital boat. We can't row our way out of this one. It's time to pull the anchor and make some progress navigating the new digital sea. Why can't security become easy and fool proof?