Blog

We blog regularly about the future of digital identity and data protection, the fraught state of cybersecurity and privacy, and messes like blockchain, software engineering, and social media.

Diagnosing Google Health

The demise of Google Health might be a tactical retreat, but we need to understand...

Customer, How do I know thee?

One of the main contentions of the Identity Metasystem, NSTIC and like models is that...

Facial recognition isn’t creepy: it’s dangerous

Why do people use soft, subjective words like “creepy” to criticise facial recognition in social...

Two faced

How should we approach the question of Facebook’s facial recognition? A good place to start...

Remember that Digital Identity is a metaphor

The seminal Laws of Identity define a Digital Identity as a set of claims made...

I just don’t get Levels of Assurance

Updated August 17, 2022. IDAM practitioners and government authentication policy makers have settled on a...

Designing out identification uncertainty

A few of us have been debating Levels of Assurance on Twitter. It seems crucial...

Speaking of identity

The Identity movement is in crisis. Or at least, it should be. Recent weeks have...

NSTIC and banking don’t speak the same language

I first blogged about this over at Finextra in January, asking if banks and their...

Identity Evolves [AusCERT Conference Presentation Abstract]

This is the abstract for my paper that has been accepted in the main program...