Cruising with ‘relative’ identity

Opinion
Apr 11, 20073 mins

* More about cruise ship security

Last issue I looked at identity and security procedures used by cruise ships and port security agents. The ship ties a photo of you to a barcoded ship’s card issued after you provide positive photo ID (driver’s license or passport, typically) while the port security folks use both the photo ID and the ship’s card to determine that you are entitled to enter the ship (based on the ship’s card) and you are the person named on the card (via the photo ID).

But, I asked, what of someone on the cruise who never leaves the secured area of the port?

You register your “off the ship” status when going down the gangway by inserting your barcoded ship’s card into a reader. Upon re-boarding, you re-read the card which brings up a photo for the security officer to check against your face and either allow or deny you the authorization to board. Seems straightforward, right?

But, upon initially checking in for the cruise, there’s a time between when your ship’s card is issued and your photo is taken. Specifically, we got the ship’s cards (after positively identifying ourselves with passports), left that room, joined a line to have our carry-on luggage screened (flash the ship’s card to get access), stood in another line to have a ship’s photographer take one of those “we’re getting on the boat” pictures that they’ll try to sell you later – but which isn’t the security picture – then got in another line to actually go up the gangway and, for the first time, insert our ship’s card into a reader. At this point a digital picture is snapped and that picture is associated with the card you presented. Can you spot the problem?

After getting the ship’s card, there’s nothing to stop me (and my wife, we’re not “swingers” after all!) from swapping cards with our friends (call them Bob & Carol. Or Ted & Alice if you prefer) before going up the gangway. The subsequent action would associate my picture with Bob’s (or Ted’s) name! Could this be exploited by a nefarious person?

Not really.

You see, the ship’s security people don’t really care if my name is Bob, Ted or Dave – they just care that the same person who gets off the ship in port is the same one trying to get back on. As long as my face and ship’s card match the ones in their database, they’re satisfied.

This is what I call “relative” identity and, in fact, is part of the foundation of the OpenID movement. That’s right. OpenID isn’t about who you really are, just that the person with the username “SweetLips” is the same person who used that name yesterday, last week, last month, last year and tomorrow, next week and next year. It’s an instance of what the privacy folks call pseudonymity, and a fascinating “real world” example of something we’re trying to achieve in cyberspace.