Lessons learned from the ‘Underwear Bomber’

Opinion
Jan 4, 20103 mins

* Recent terrorist act shows the limitations of siloed data

You might know him as the “Underwear Bomber” (the “Pants Bomber” in the United Kingdom) or, in less exalted circles, the “Crotch Bomber.” But however you refer to him, it’s clear that Umar Farouk Abdulmutallab has been the major topic of conversation over the past 10 days. What hasn’t been touched on yet (at least I haven’t seen it) is the lesson this can teach us about identity systems.

Let’s review: The bomber’s father went to the U.S. embassy in Nigeria in November to report his worries that his son (who, he said, had “disappeared”) was becoming radicalized and he father feared he might become a tool for terrorists. At the same time, the CIA was hearing reports about someone identified as “The Nigerian” who was being groomed in Yemen to take a leading terror role. Both of these reports were reviewed by appropriate authorities and information was placed in several data stores as a consequence.

No one, though, seems to have the ability to reconcile these data stores and rationalize the information. This is a problem we’ve talked about in IdM for years: siloed data!

Wikipedia defines an information silo as: “… a management system incapable of reciprocal operation with other, related management systems.” Identity silos also are incapable of interacting one with another. Simplified sign-on and federated identity are two technologies used to overcome the problems of identity silos without actually eliminating them. User provisioning systems are the major weapon used (within an organization) to foster a non-siloed environment. There is some progress being made.

Unfortunately, those who believe that a false sense of privacy should be the overriding aim of any data gathering and dispersal system provide the “cover” for those who wish to maintain siloed data. Whether it’s business, education or government, the majority of those fighting to maintain data silos are doing so as a way of protecting turf, not user privacy.

During the early years of the 21st century, when trying to install enterprise-wide user provisioning systems, we quickly found that the technology was easy — it was the people that were the hard part. Everyone who controlled a silo of identity had to have their grasping fingers clawed away from the data. It was felt that giving up control of the distribution (not the initiation  or the maintenance) of that data was somehow denigrating to that gatekeeper.

Is it any wonder, then, that the CIA, the NSA, the State Department and their counterparts with other governments around the world show such reluctance to share data? With provisioning, it was often necessary to get the CEO involved in order to “free up” the data needed. Perhaps the CEOs of our governments should take notice.

For those of us in identity, it’s time to stop placing restrictions on the correlation of data. I’m not against privacy, but that should be handled by laws and contracts. Shackling our technology doesn’t protect anyone in the long run. Siloed data is simply wrong.