Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, February 01, 2016

Consider carefully when consenting to children's biometrics in schools

'Turning fingers into keys'
Credit: kaprik/shutterstock.com
There is a great article written by Brian Patton, University of Oxford, entitled "The trouble with taking biometric technology into schools", that appeared in The Conversation earlier this month, which every parent and student should read before considering using their biometrics in schools.

Other than copy most of the article into this post I would urge a read of the article which succinctly discusses security, effectiveness, implications of a data breach and consent.  

Schools and biometric companies supplying schools are keen to reassure parents and students that it is not a (pictorial) fingerprint that is being stored but simply a number string -  a number string completely unique and specific to your child's 'bio' body 'metric' measure.

Patton makes the valid point that:


"For other biometric data it's important to remember that what is being matched within the computer is not, say, one fingerprint against another. It is a set of data drawn from the features of the scanned body part – a numerical abstraction. Steal this key and you have effectively stolen that part of the person."

He also goes on to say that,

"...a  data breach will mean these type of scans will be untrustworthy for the pupils – for the rest of their lives.
And therein lies another issue: with the potential for life-long consequences, are pupils, some below the age of 16, competent to opt in to such a scheme? And what of those who opt out? It's one thing to ask adults to weigh up the balance between convenience and risk, but there are two likely issues that would make this harder in schools. There is an inbalance of power between those wanting to implement the technology and those subject to it.  This raises serious concerns about informed consent – perhaps one of the reasons why in 2012 using biometrics was banned in English state schoolswithout parents' consent."


It is unclear if there have been any data breaches of biometric databases in schools as the UK Information Commissioner's Office (responsible for the UK Data Protection Act), in response to a Freedom of Information request regarding compromised biometric databases specifically in education, are "unable to conduct an electronic search of our system using the term ‘biometric" and so could not supply information on if there has been any data breaches of children's biometric data in schools.

There are potentially long term, unknown consequences to this biometric technology used on the youngest generation in society - we are experimenting with it on our children in schools for daily activities that can be easily undertaken, quite adequately, without the use of biometrics.

I guess an individual will only know when their biometric data has been compromised when in the future they hit a problem regarding their biometrics.  How will they know when it was compromised, by whom and where their very personal digital identity has gone? 

In the words of Brian Drury, IT Security Consultant:

"Once a child has touched a [biometric] scanner they will be at the mercy of the matching algorithm for the rest of their lives."

Saturday, June 07, 2008

Children's biometric data at risk

Just caught the below on the Thumbs down blog run by a parent, about the complete lack of security surrounding a computer with children's biometric data on - how appalling!

"A very short comment on the school’s security:

At pick up today we walked through the nursery playground. I usually go the other way, but we both went today.

The library is inside a cottage between the Nursery and the Infant School. As I walked past the cottage door, I noticed it was wide open.

Around the corner I glanced in through the library window and saw that the room was empty. 5 minutes or so later, after a significant number of parents had walked past it, the cottage door was still open.

I poked my head inside and called “Hello! Anybody there?” Quite loudly. Reply came there none, so I walked in the three steps to the library door, tried the handle and opened it. There by the door was the computer, with the thumbscanner, just to confirm it is the one with the biometric data inside.

This is the computer about which the Governors saidreasonable security measures are taken”."

Thursday, October 11, 2007

Children's biometric data secure for their lifetime?

Over on Andy Clymer's blog he raises concerns of how children's biometric in schools may not be secure, even for their time at school.

"...a responsible biometric manufacture would secure biometric data as best they can today, but once the software has been deployed if that data is to be truly secure it needs have sufficient physical security measures in place provided by the owner to ensure that in the future the encryption based solution still has adequate merits, the moment you do not have complete ownership of the data all bets are off...and by their own admission the biometric provider in this case said their guarantees is for appx. 10 years, in the case of biometric data for kids that data is sensitive for 60-70 years."

Tuesday, October 09, 2007

Building Schools for the Future bidder builds biometric technology into schools

The Sunday Heralds reports that after the palm vein scanner was trailed in a Scottish primary school last October, Amey who introduced the vein scanner, developed by Yarg Biometrics and Fujutsu, have plans to introduce this in another 11 schools for lunch lines and possible entry into schools:

"The private firm Amey is now presenting biometric systems as part of its pitch for all new school building contracts. The company was keen to assure parents in Renfrewshire, where 11 more schools are set to adopt palm readers, that the technology was safe and data could not be stolen or misused."

Vein scanning is mildly more acceptable than fingerprint scanners, as a vein print cannot be casually left at a location as a fingerprint can and so implicate you at a certain location (other than at a vein scanner). But Amey's claim that the technology is safe and data cannot be misused or stolen is a very grand claim, as these children's biometric data needs to be secure for the rest of their life time - decades... or at the very least for the life time of a child's schooling from 4-18 years old, until 2021.

How can parents, governors and pupils be consulted on this if building these biometric systems into schools are done at local government contract level? And "opt out" alternatives should be provided.

The government (BECTA) guidelines state that, "...schools should normally involve pupils and parents in their decisions to use biometric technologies as is the case with other decisions made during the school life of children ." page 7 of the "BECTA guidance on biometric technologies in schools"

- this Building Schools for the Future(BSF)/Private Finance Initiative (PFI) scenario seems to blatantly override the recent government guidelines here, unless there is a consultation process underway with parents and pupils that hasn't been reported in this case.

If their is no "involvement" with parents and pupils, there is no consequence for the companies/schools installing it. Well, hey ho, that's non legal/statutory guidance for you.

Thursday, October 04, 2007

Biometric systems help visibly reduce wrinkle lines and bullying

At Viewlands Primary, Perth, Scotland, a fingerprint scanning system is trialled for school lunches:

...a spokesman for the council insisted fingerprinting youngsters is safe and has helped reduce bullying. - the council spokesperson shows no evidence to back this statement up. In fact there is no evidence whatsoever that proves that using biometric systems in schools reduces bullying.

The spokesman claimed 90 per cent of parents had given permission for their children to take part and it was impossible for the system to be accessed by "unauthorised" users.

"Impossible"?... a fantastical claim to be made in this day and age when peoples identities are being stolen from cash point machines, NHS records stolen - re-surfacing on e-bay and banks not disposing of customers details properly.

Monday, August 13, 2007

Gloucestershire County Council rethinking recent UK Government guidelines

Despite the UK Government recently issuing guidance for schools using biometric systems Gloucestershire County Council are deciding whether to issue their own guidance to schools in their area.

With a total of 8,400 children already fingerprinted in the Gloucestershire area, some just four years old, members of all political parties in the county council have created draft guidelines to help schools decide whether to use fingerprinting.

This article reports that Gloucestershire County Council, "...strongly recommends schools should consider the implications of the biometric data before making a decision.Liberal democrats at Gloucestershire County Council have welcomed the draft guidelines, but say they should go further.

Lib Deb leader councillor Jeremy Hilton, said:

"Using biometric technology in schools introduces a number of serious and unnecessary risks.

"Personally I would encourage schools not to introduce fingerprinting."

Jackie Hall, lead cabinet member for children and young people, will decide whether to endorse the [government] guidelines in September.

Sunday, August 05, 2007

Schools 'soft targets' for ICT theives

According to this article, figures published by the Metropolitan Police (Crime in London schools 2000-2004) show the number of burglaries at schools at 7,500 for the period.

"The problem, in part, is that schools are typically ‘soft’ targets. The problem is being further compounded, with respect to burglaries, as the government’s drive to put more computers, projectors, whiteboards and general ICT technology in schools, makes them very desirable targets for thieves."

With these staggeringly high theft figures for schools, this is a point to consider if your child is going to be using a school biometric system.

Wednesday, May 23, 2007

Irish schools eager to fingerprint children

According to this article 50 schools in Ireland have expressed an interest in installing biometrics in the past month. Costs are between 10-20,000 euros dependent on the size on the school.

John Beckett, managing director of Byamsys, the company selling the fingerprint systems, states:

“There’s no way to reproduce the data we store as a fingerprint. We don’t store the data as a fingerprint. When students check in their fingerprint is scanned and converted into a string of letters and numbers which is encrypted and then compared to the encrypted file that we have already for that person. There’s never a decryption process."

How can he state there is never a decryption process? Has he got the ability to scry into the future? See Kim Cameron's site "Just lie to sell your product" ...

Digital Rights Ireland have rightly expressed their concerns over the increase of the use of biometric technology in schools, their Chairman TJ McIntyre states:

“There is a standard that’s used across the industry for biometrics to ensure different systems are compatible... but what they [biometric vendors] don’t explain is that the information used there is capable of being reconstructed to give you soft fingerprint information and it’s still possible to be used in police work."

Bernie Goldbach of Digital Rights Ireland, “With a card you’re not exactly sure it’s the same person but most kids don’t give up cards that have money on them and they don’t lose them. They learn a bit of responsibility without losing a part of their identity."

Responsibility and ownership of ones identity is a crucial lesson for children to learn as they grow up in a digital age.

However the messages they receive from using biometrics without question in schools is a potentially dangerous lesson that we, in our ignorance, are teaching them.

The Data Protection Commissioner in Ireland has issued guidelines about the use of biometric fingerprinting in schools. The main stipulation was that parents and children over 18 had to give their consent to use the system and that schools also carry out a detailed 38 point Privacy Impact Assessment before installing biometric fingerprint systems to limit any legal claims for damages in the future from students.

The guidelines are not statutory and are simply advice.

Friday, May 11, 2007

More from Kim Cameron

Kim Cameron has been blogging some more on this issue about the minutes of a school board meeting in Florida... here.

Apart from the old sales spiel "the biometric images cannot be used by law enforcement for identification purposes. Only a mathematical algorithm remains in the system after registration, not finger images." a new slant on the technology is explained in the sales pitch given to the schools board:

"The [lunch] cards become unsanitary, because the children put them in their mouths. To solve these problems, schools are using biometric scanners in the cafeteria. The student places their index finger on a scanner" and 100's children's fingers touching a scanner, then touching their food is more hygienic because...?

I don't think I want any other children's "biometrics" on my kids fingers just before they eat.

Apart from the hygiene issues, absolutely educational establishments should be given the bare facts not a sales pitch, but at the moment it seems a free for all for the vendors of school biometric systems with the industry taking our hard earned taxes in profits. Just think where better spent this money could be used to enhance our children's education.

Kim Cameron has this to say:

"It drives me nuts that people can just open their mouths and say anything they want about biometrics... without any regard for the facts. There should really be fines for this type of thing - rather like we have for people who pretend they're a brain surgeon and then cut peoples' heads open."

and on telling the truth "There should be accountability and penalties for those who consciously mislead people like the Marlin County school board, convincing them there is no risk to privacy by preying on their inability to understand technical issues."

Tuesday, May 01, 2007

Privacy Impact Assessments...

The Information Commissioner, Richard Thomas, was interviewed this morning on BBC Radio 4's 'Today' programme. In his interview at 7.30am he talked about needing a debate on the level of surveillance in today's society and talked about needing a public debate on the subject about where the line should be drawn with regards to surveillance.

He then went on to talk about the need for companies to do privacy impact assessments before installing databases, to asses identity risks, showing how organisations minimise the impact on privacy, assessing the chances that things could go wrong and to minimise excessive surveillance.

In light on the guidelines for biometrics in schools which the Information Commissioners Office has advised on, due to be issued after May 3rd, his comments are encouraging regarding his feelings that both government departments and private companies should carry out a privacy impact assessment before installing new databases.

The Irish Data Commissioner has advised schools to carry out a privacy impact assessment before installing and using biometric technology with children... "This is an important procedure to adopt as a contravention may result in action being taking against a school or college by the Commissioner, or may expose a school or college to a claim for damages from a student." Point 8 on the guidance.

If Richard Thomas is keen for privacy impact assessments to be undertaken in the adult community then one would presume that this courtesy will absolutely be extended to our children's biometric databases quickly emerging in schools, especially as the Irish Commissioner has set a precedent in this area listing at least 36 points to consider on this.

(You can 'listen again' to the BBC interview which lasts about 5 minutes or find it in the archive for this week)

Wednesday, April 11, 2007

Valid concerns from the USA

Patricia Deubel, Ph.D, voices her comments on the use of biometrics in schools, in the article "Biometrics in K-12: The Legal Conundrum", 10th April 2007, on the site The Journal, which is a publication aimed at educators across the USA. Although not a lawyer she cites some cautionary advice using this technology with children in schools.

Biometrics are among the latest implementations for school security. There are many issues to consider, which have been voiced by parents, students, and civil liberties groups.

The Family Educational Rights and Privacy Act protects student records and might provide some protection for public disclosure of records stored in databases containing a student's biometric measurements...

And also James Carroll, writing "Fingerprint foreboding" in the Boston Globe, 9th April 2007, has his view on biometrics in schools after working for the FBI. The last part his article, below, is quite succinct:

Privacy, the dictionary says, is the state of being free from unsanctioned intrusion. But that definition seems anachronistic, with ubiquitous intrusion a new fact of life. For security, or mere efficiency, we Americans are sanctioning the end of our right to deny sanction to such invasion.

Now, of course, it is not just law enforcers in the mode of J. Edgar Hoover who have the capacity to intrude, but also MasterCard, the credit bureaus, the Google user, the phone company, the e-mail provider, the airport screener --
and the lunch room cashier in the local school.


And why shouldn't parents be uneasy?

Friday, April 06, 2007

"People have to be stark, raving mad to use conventional biometrics to improve the efficiency of a children’s lunch line"

More on biometrics in schools again, over on Kim Cameron's weblog, the Architect of Identity and Access in the Connected Systems Division at Microsoft.

This post here from him states:

"The more I learn from Alex Stoianov about the advantages of Biometric Encryption, the more I understand how dangerous the use of conventional biometric templates really is. I had not understood that the templates were a reliable unique identifier reusable across databases and even across template schemes without a fresh biometric sample.

People have to be stark, raving mad to use conventional biometrics to improve the efficiency of a children’s lunch line."

When this comes from Kim Cameron, alarm bells should be ringing loud and clear for those schools using this technology and for apathetic government departments letting this go ahead completely unregulated.

Tuesday, April 03, 2007

Biometrics scrutinised

Over on Kim Cameron's Identity Weblog he has been discussing the issues of using biometrics in schools.

Rather than duplicate points that are made in the Identity Weblog posts, reading the below is recommended, especially when it comes from the Architect of Identity and Access in the Connected Systems Division at Microsoft:

Biometric encrytion - 1st April "The fine discussion of the problems with conventional biometrics leaves one more skeptical than ever about their use in schools and pubs"

A sweep of their tiny fingers - 1st April "“As they munch their sloppy joes, these five and six year olds are happily ushering in the age of biometrics with a sweep of their tiny fingers…” Fox News"

Will biometrics grow up? - 31st March "Reading this paper will explain why it is way too early to use biometrics in schools - or pubs."

Hong Kong teaches London about civil liberties - 29th March "The school ripped out its system and destroyed all the fingerprint data it had taken from children"

U.K. wants beerdrinkers’ fingerprints - 29th March "Britain, get a grip!"

Mass fingerprinting of children will start in 2010 - 29th March "The plans are outlined in a series of “restricted” documents circulating among officials in the Identity and Passport Service"

If they don’t scan, they don’t eat - 29th March "As a professional detective, Joy Robinson-Van Gilder knows how easily fingerprint data can be obtained and misused. And as a mother, she is kicking up a one-person storm."

Make sure children are calm - 28th March "How to break four architectural laws in one go"

3,500 British schools fingerprinting their children - 27th March "British schools will be urged to seek parents’ permission before taking children’s fingerprints, under new guidelines. But calls to outlaw the controversial practice altogether have been rejected by the government."

Thursday, March 22, 2007

Irelands advice to schools when employing biometrics

The Data Protection Commissioner in Ireland has this advice for educational establishments to consider before purchasing biometric technology for use with children. Under the term biometric it includes a fingerprint, an iris, a retina, a face, outline of a hand, an ear shape, voice pattern, DNA, and body odour. Biometric data might also be created from behavioural data such as hand writing or keystroke analysis.

It details consent, proportionality, fair obtaining and processing, fair obtaining of sensitive data (i.e. photographs, health and race), transparency, accuracy, security and retention of data.

The Irish Data Protection Commissioner stipulates that the obtaining of consent is of paramount importance when schools consider the introduction of a biometric system.

The document details points for schools to consider before installing such systems, it then goes on to say:

Before a school or college installs a biometric system, the Data Protection Commissioner recommends that a documented privacy impact assessment is carried out.

This is an important procedure to adopt as a contravention may result in action being taking against a school or college by the Commissioner, or may expose a school or college to a claim for damages from a student. Data protection responsibility and liability rests with the school or college, not with the person who has supplied the system.

The lack of guidance from the UK Information Commissioners Office or government is now becoming conspicuous in it's absence, especially when the percentage of children using biometrics in schools in the UK is probably higher than any other European country.

Friday, March 09, 2007

Students fingerprints ending up in the States

Back in January I blogged about Canadian students biometric details going over the border to the States without their knowledge - this can happen to students in Europe, Asia, and Africa that sit the LSAT.

Michael Geist writes :"While the predictive reliability of the test has been the subject of considerable controversy, in recent days the LSAT [Law Schools Apptitude Test] has attracted attention for a different reason. As students file into testing centers throughout the U.S., Canada, Europe, Asia, and Africa, they must provide a thumbprint, which is used to crackdown on fraudulent test takers. The biometric data is transferred to the United States and retained by the Law School Admissions Council, the organization that administers the test."

The problem is that once the Law School Admissions Council has the student's biometric fingerprint details it could be compelled, by statutory provisions found in the USA Patriot Act, to give up this information to the US authorities which, according to Philippa Lawson of the Candian On the Identity Trail website "allows FBI access to private sector databases of customer information for counter-terrorism purposes, without any reasonable or probable cause to suspect wrongdoing by the individuals whose information is being disclosed."

She goes on the say: "Once digitally stored, biometric data - like any other data - is easily copied, transmitted, altered and searched. But unlike other personal data such as names, addresses and identification numbers, biometric data does not change. And unlike credit cards, passports, and drivers licences, biometric data cannot be invalidated and substituted once compromised.

The federal Personal Information Protection and Electronic Documents Act which came into force in 2001, is based on a set of widely accepted fair information principles. One of these principles is that organizations should not collect more personal information than necessary for the purposes that they have identified. Another is that those purposes must be reasonable."

Sounds very much like our Data Protection Act:

The Data Protection Priciples, Part I, The Principles
3. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.

Canadian privacy commissioners are currently investigating the LSAT complaints.

Saturday, February 24, 2007

Best Practice?

On 9th February this year another advisory statement was issued by the Information Commissioner's Office (ICO) telling schools how to erase children's biometric data from school computers by using professional data cleansing companies, quoted here in the last paragraph of this article:

"...under the data protection act schools must also dispose of the data using professional data cleansing companies once the child has left or if it no longer of use."

Why isn't there a concise page advising schools on how to handle children's biometrics on the ICO's website after 6 years of biometric technology in schools?

Granted the ICO is now working with BECTA and the DfES to issue guidelines, to put on BECTA's website, so the above 'data cleansing' advice will presumably be in the guidelines.

Currently LEA's, schools, governors and parents have dribs and drabs fed by ICO's spokespersons to various media outlets for them to deem what the 'best practice' in schools is with regards to biometric fingerprint technology.

In the recent case of a school scrapping a biometrics, children's biometric data was on the school computer system for over a year unused before it was deleted, and probably when the school did destroy the biometric records they didn't use a data cleansing company - but how would they to know what to do?

"The thumbprint system has not been used for more than a year...and the numerical records of the thumbprints were destroyed last week."

Monday, February 12, 2007

"Reduce your risk; only store what you really need"

I'm going to blog about Andy blogging because it's a great post making some valid points and I cannot put it any better!

So here is the link.

The article from The Register that Andy links to, 'Investigators uncover dismal data disposal' by Lucy Sherriff, is one I hadn't seen before and shows how easily disposal of data can be mishandled.

For me one of the best quotes from Dfes with regard to schools holding biometric data is:-

"They are well used to handling all kinds of sensitive information to comply with data protection and confidentiality laws."

Schools have historically failed here; a forensic computer science faculty bought hard drives off ebay, and extracted school records: [see link...]

http://www.theregister.co.uk/2005/02/17/hard_drive_data/

A colleague also told me recently how he took a school computer out of a skip...Personally I don't condemn the schools here after all their primary focus is on education and not on securing personal information.

Thursday, February 01, 2007

Poor data security in schools and still no debate

James Meikle writes here in the Guardian, about the debate (or parliamentary lack of it) concerning schools using children's biometric data for borrowing books, registration and food monitoring.

Mr Greg Mulholland MP said:

"There are parents not being asked about the use of biometric data in schools, and in some cases are not even informed [that] their children are having fingerprints or other forms of data taken. No one seems to know how long this kind of data is stored.

There clearly is potential for abuse. It is extraordinary that the government is not prepared to bring this to parliament and debate it."

The issue of schools failing to protect sensitive information was recently highlighted in the Guardian December 2006, as 'concerning':

"Schools are failing to protect sensitive information about young children, such as their home addresses and medical details, research has found.

More than half of primary schools are not keeping such information secure."

This shows the need all the more for this to be debated urgently. Apart from the insecurities in school that may stem from bad practice concerning children's data protection, when schools get burgled it's not pens and paper that gets stolen - it's computers.

Thursday, January 04, 2007

Where do your fingerprints go?

Unregulated taking of fingerpirnts from childrens as young as three in the UK?

This is happening in Canada to university applicants...

From Excaliber, York University's Newspaper, Toronto, January 3rd 2007:

If you're thinking about taking, or if you've already taken, the Law School Admissions Test (LSAT), you know all about the hours of studying it takes to prepare for the exam. But are you prepared for what happens to your thumbprint when you hand it over at the door?

What happens to the fingerprint afterward is the cause of the controversy that has spread across Canadian law school campuses.

After thumbprints are taken at the Law Schools Admission Tests (LSAT) exam, they are sent to the United States to be processed. here, American authorities, including the FBI, have access to the prints.

Claire O'Sullivan is a fourth-year contemporary studies and Spanish student at the University of King's College in Halifax. She took the LSAT this fall and is upset that she had to hand over her thumbprint before writing the exam.

She said she was never told what the print would be used for. She said she wishes more people were protesting the requirement for students to hand over their thumbprints before writing tests like the LSAT.

"I wish it never happened," she said.

Friday, October 20, 2006

German research fools biometric systems

I recently found this in the LTKA website. It's research that was done in 2002 by the Fraunhofer Research Institute in collaboration with the German Federal Institute for Information Technology Security.

It is a lengthy article but worth reading. It details a variety of easy ways to fool biometric scanners and the simple ways that the systems could be hacked - see www.heise.de/ct/english/02/11/114/

A quote near the end of the article reads:

"With the aid of data packets gathered by eavesdropping and some lines of Perl script we were able to reconstruct complete fingerprints"

Clarification on whether the systems fooled are the ones used in UK schools URGENTLY needs checking. Thankfully my children's fingerprints aren't on any systems - what a relief!