![]() |
|
|
ID卡片: 保護國家或一門戶開放主義為fraudsters ?
星期二, 2009年1月27日
Stewart Hefferman探索政府的潛在的陷阱?s全國ID卡片計劃,提出詢問它也許是脆弱的對克隆,如果更多想法isn ?t放入它的實施。 公眾、全國新聞和甚而安全專家的成員主要被反對英國?s全國ID卡片計劃初次公開展出。 政府仍然堅持計劃在它的與恐怖主義的戰鬥將幫助并且改進國家安全,在奔跑由它的部署決定,根本缺點現在變得明顯。 對公民自由的關心和被誇大的要求在計劃?s零件在與在旁邊恐怖主義的戰鬥,什麼憂慮我多數是這: 它是否實際上做什麼它在錫認為? 它是否真正地將加強我們的國家安全或者對fraudsters打開我們的後門? 家庭秘書Jacqui史密斯?s最近公告關於計劃為了販商能收集生物統計的數據是完全不負責任的。 它似乎十分荒謬放公共數據入手第三方,當數據損失是一樣普遍的時,像它今天。 它?s明白,即然政府意欲連接ID卡片計劃入它的其他服務。 I ?ve關注ID卡片用途這樣引伸,因為首先宣佈的他們。 不幸地,那裡?s沒有問題這使計劃脆弱濫用。 ? 論及扮演問題? 大關心ID證明是扮演,并且,不幸地,政府?s ID卡片計劃doesn ?t去任何地方在附近足够在論及這個問題。 要增加侮辱到傷害,連接民族性記數器(NIR)入各種各樣不同的數據庫,所有容易接近由各種各樣的政府職工,更加進一步惡化問題。 二個主要弱點是,首先,對生物統計的安全的在信賴,并且,第二,特選為集中化數據存儲。 一起,這些留給ID卡片式帳簿脆弱對克隆。 生物統計的技術,然而,不是一枚銀色子彈。 單獨生物測定學不足够了防止欺騙。 儘管強的加密,荷蘭生物統計的護照在發射以後崩裂了。 假想?假證明? British e-passports were cloned within minutes only to be passed as genuine by passport reader software used by the UN agency that sets standards for e-passports, despite using pictures of Osama Bin Laden and a suicide bomber! ? Stronger verification technology? The fingerprint biometric security systems currently used in the TWIC programme failed to properly authorise one in 50 enrolees? credentials. Clearly, stronger verification technology needs to be in place. What?s needed if the ID card scheme is to work is a belt-and-braces approach. Storing the encrypted biometric data on the card would make it impossible for even the most sophisticated fraudster to manipulate. Even authorised personnel ? and, therefore, any successful hackers or corrupt employees ? would only be able to view binary code, and not the finger, iris or facial recognition data itself. They would also be unable to determine how the encryption algorithm operated, and thus couldn?t clone the card. There?s no doubt that the way the information is stored and structured needs to be carefully implemented. Storing the data centrally was always a civil liberties concern. I always wondered why on earth the UK Government needed individual information to be stored on both the card and a central database. It?s not necessary to store the data centrally. Other countries such as France and Italy have stipulated that biometric information be stored only on the cards themselves. This way, that data is still within the possession of the individual. So, it was only necessary if they were planning to extend the usage of the cards in future. It?s now clear to all of us that was the intention all along. More importantly, storing this data centrally and then linking it into a variety of databases is a security concern. From a security point of view, central storage makes the most sense in an online world but, if you?re also storing data on the cards themselves, that invalidates the security argument. ? Audit trail is an essential? If the data must be stored on a central database, then biometric data needs to be kept separately from any other personal data in order to make it difficult for hackers to link the information needed to steal someone?s identity or clone a card. Back-end systems need to enable an audit trail of those personnel who have accessed individual records on those back-end systems. It?s not yet safe to say that a 100% secure solution exists ? suggesting that you have one is an open invitation for hackers to have a go. All we can do is minimise the risk as much as possible. In that respect, the UK Government?s scheme still has some way to go. In itself, that begs the question as to whether the Government has already sown the seeds of the scheme?s disaster? ? Stewart Hefferman is chief operating officer at TSSI SystemsHave Your Say: ID cards: protecting the nation or an open door for fraudsters? Please read our posting guidelines before posting. Alternatively you can discuss this report here. Related News
|
HAS Greasball Gordon Brown - lost his murps? Last post by Unregistered @ 12:36 AM Go to Forum
| Latest Topics
Google and Gaza Last post by Nostalgia @ 12:18 AM UFO wind turbine prang site: Exclusive photos Last post by paul w @ 11:46 PM Too Posh to Pay ITV1 9pm Last post by Unregistered @ 10:30 PM Village plunged into darkness as UFO's appears above. Last post by Nostalgia @ 10:00 PM 9/11 Citizen Investigation. Last post by Unregistered @ 09:50 PM How intelligence agencies really do gang stalking - My story Last post by Unregistered @ 09:01 PM BBC staff secretly air Gaza appeal while BBC Head speaks against it Last post by Nostalgia @ 08:39 PM Government must release cabinet minutes on lead-up to Iraq war Last post by initiatrix @ 07:00 PM Community Outcast Last post by Gavinh @ 06:04 PM Email This Page To A Friend Latest Headlines
More Breaking News Archive
|
The views expressed in the RINF news wire and newsletter are the sole responsibility of the author (s) and do not necessarily reflect the views of the webmaster. RINF.COM: Breaking News & Alternative Media is Copyleft - Copy & Distribute Freely. News Forum |