Showing posts with label identify theft. Show all posts
Showing posts with label identify theft. Show all posts

Saturday, January 8, 2011

The Trusted Identities in Cyberspace National ID Card Won't be a National ID Card

"Obama to hand Commerce Dept. authority over cybersecurity ID"
Declan McCullagh, CNET (January 7, 2011)

"President Obama is planning to hand the U.S. Commerce Department authority over a forthcoming cybersecurity effort to create an Internet ID for Americans, a White House official said here today.

"It's 'the absolute perfect spot in the U.S. government' to centralize efforts toward creating an 'identity ecosystem' for the Internet, White House Cybersecurity Coordinator Howard Schmidt said...."

The CNET article points out that this federal online identity authority could have gone to the National Security Agency or the Department of Homeland Security. As the author says:

"...The move ... is likely to please privacy and civil-liberties groups that have raised concerns in the past over the dual roles of police and intelligence agencies....

The Lemming isn't often on the same page as many "privacy" and "civil liberties" advocates. This time, though, it's a (slight) relief that the DHS or NSA didn't get this particular authority.

This is not a political blog, by the way, and the Lemming will get back to that.

National Strategy for Trusted Identities in Cyberspace: 'Trust Us'

"...The Obama administration is currently drafting what it's calling the National Strategy for Trusted Identities in Cyberspace, which [U.S. Commerce Secretary Gary ]Locke said will be released by the president in the next few months. (An early version was publicly released last summer.)

" 'We are not talking about a national ID card,' Locke said at the Stanford event. 'We are not talking about a government-controlled system. What we are talking about is enhancing online security and privacy, and reducing and perhaps even eliminating the need to memorize a dozen passwords, through creation and use of more trusted digital identities.'

"The Commerce Department will be setting up a national program office to work on this project, Locke said.

"Details about the 'trusted identity' project are remarkably scarce. Last year's announcement referenced a possible forthcoming smart card or digital certificate that would prove that online users are who they say they are. These digital IDs would be offered to consumers by online vendors for financial transactions...."

As far as it goes, this sounds okay. A major program like this might take a few months to get planned and organized. As for this not being a "national ID card," the Lemming is fairly confident that the national ID card will not be called a national ID card.

Still: How dim do the folks inside the beltway think the rest of us are?

The Lemming said that this isn't a political blog. It's not. Not in the sense that the Lemming claims that everything done by one particular person or group is brilliant: and that everybody who disagrees is a doo-doo head. If you're curious about this blogger, check out "About the Lemming."

Back to the national ID card that won't be a national ID card.

The National ID Card That's Not a National ID Card

Some folks - not quite the same as the lot who have fits over being seen in public and other 'privacy' issues - got their skivvies in a knot a few decades back, when Americans started getting Social Security Numbers. "The mark of the Beast" was a phrase that came up fairly often. They didn't like credit cards, either, some of them: and that's another topic.

It's the Lemming's considered opinion that there isn't anything wrong, in principle, with a national online ID system. Good grief, a global system that includes anybody in Earth orbit makes sense. ("More Postcards From the Frontier" (April 7, 2010))

The Internet is big.

It's also the Lemming's considered opinion that any sort of ID system is subject to abuse. It's that "sparks fly upward" aspect of human nature. (Job 5:7)

Does that mean that the Lemming thinks the Obama administration is planning to restrict who gets to put information and opinions online, and who gets to see what? The Lemming doesn't know: but having experienced the trailing edge of McCarthyism and done time in academia when political correctness was in flower, the Lemming is - concerned.

Assuming that the feds follow through on what's been said so far, the national-ID-card-that-isn't may be well inside the Lemming's comfort zone. Back to that CNET article.

"...Schmidt stressed today that anonymity and pseudonymity will remain possible on the Internet. 'I don't have to get a credential, if I don't want to,' he said. There's no chance that 'a centralized database will emerge,' and 'we need the private sector to lead the implementation of this,' he said.

"Jim Dempsey of the Center for Democracy and Technology, who spoke later at the event, said any Internet ID must be created by the private sector--and also voluntary and competitive..."

Those words - "private sector ... voluntary and competitive" - make this system seem a whole lot more reasonable to the Lemming.

You Want Scary? Try These On For Size

"The Lemming" is a pseudonym, but the Lemming doesn't make a secret of who and what he is: a middle-aged man living in central Minnesota. A few years ago, the Lemming settled on the screen name Aluwir for new online community accounts.

Not because the Lemming wants to hide his true identity: but because "Aluwir" is a whole lot more distinctive than something like Brian8327 or "Norski." There are even a fair number of folks named "Brian Gill" online. And, for a while, one of the other Brian Gills was in a line of work similar to mine. Which is yet another topic.

The Lemming doesn't mind - at all - that folks know it's really Aluwir/Brian Gill posting on this blog, and elsewhere online. Living in a small town, where quite a large portion of the population knows my by sight may have something to do with that. Sauk Centre is a wonderful place to live: but if you prefer to be a nonentity lost in a throng of anonymous strangers, this small town isn't for you.

The Lemming is getting off-track again.

Americans have had Social Security Numbers for several generations now, and it's the Lemming's opinion that the SSN system didn't bring on global warming, food riots, or communist oppression.

Actually, the Lemming thinks that eventually there will be a sort of more-or-less-universal ID system that should give privacy advocates, civil-liberties activists and end-times preachers fits.
DNA Database
This doesn't happen very often, but sometimes babies get mixed up in the hospital. Or kidnapped. It's not a perfect world: and that's yet again another topic.

What the Lemming foresees is an extension of procedures and technologies we have right now. Footprints of infants are, as the Lemming recalls, taken in the delivery room - along with a blood sample. The first is to identify the baby, a sort of backup to the wrist tag. The second is for some now-routine medical tests.

The Lemming can't remember running into someone who thinks that the 'footprint-and-blood-test' procedure is some kind of plot. Maybe common sense is more common than it sometimes seems.

We don't, to the best of the Lemming's knowledge, have a system for analyzing a person's DNA that's fast, accurate, and inexpensive enough for this: but that blood sample could be used to get a sample of the baby's DNA.

An interstate ID system that includes a person's DNA code? The folks who object to crooks being convicted because they left evidence at the scene of their crimes wouldn't like that a bit, the Lemming suspects. The rest of us might be glad when the system made it possible to track a missing child.
Tracking Chips
Outfits like 24PetWatch have been providing pet ID microchips for years. The chips are tiny, are injected in places that don't bother the pet, and make it possible to get a positive ID on a recovered animal.

So far, the Lemming doesn't recall anyone suggesting that they be used in people.

The Lemming doesn't see anything wrong, in principle, with the idea.

Right now, the microchips can't be picked up at a distance, so it takes something like an airport screening to find out if Bowser is really pedigree Huffelton III. Given what's happened with GPS devices, the Lemming figures it's only a matter of time before something like the cell phone network could be used to find out where a kidnap victim - or the kidnapper - is in minutes.

Could a system like that be abused? Of course it could. It could also save lives. The trick will be to work out a system of social and legal controls to keep some folks from taking advantage of others.

And that's the way it's been for thousands upon thousands of years. Which is several other topics.

Somewhat-related posts:

Wednesday, August 25, 2010

Biometrics at ATMs: Iris Recognition Tech

"ATM Biometrics Coming to a Corner Store Near You!"
Info Carnivore (August 24, 2010)

"Looks like ATM machines around North America are due for a security upgrade. This year Barnaby Jack demonstrated both local and remote ATM attacks at Black Hat 2010, and showed how easy it could be to hack an ATM and make it spit cash. Barnaby Jack also revealed a multi-platform ATM rootkit and discussed protection mechanisms that ATM manufacturers can implement to safeguard against these attacks.

"Biometric Iris Scanners Coming to A Corner Store Near You!

"One protection mechanism that we are now seeing become reality is biometrics. Although it has been in the works for years, it looks like all the futuristic spy movies we watched as kids are coming true as biometric iris scanning ATM machines are looming on the horizon, and in some parts of the world already in action. Of course you're not likely to see one in your local corner store just yet, but they may well be coming soon! According to Jeff Carter of Global Rainmakers Inc. we're all going to be connected to the iris system within the next decade...."

Well, it's about time!

I've lived in a small town in central Minnesota for over 20 years, and all but the youngest folks in checkout lines recognize me. Sometimes their automated system says they're supposed to verify my credit card: but generally my ID is my face.

By the standards of some folks, there's an appalling lack of "privacy" here. I see it as being part of a community - and that's another topic.

This iris-recognition technology will, I'm quite confident, cause problems.

Or, rather, people will use it to cause problems. Any time you've got human beings involved in something, sooner or later there's going to be trouble.

The technology, though, is the sort of thing I've been looking forward to for years. In principle, someone could forge my credit card and use it.

Eventually, someone's going to find a way of finding out what my iris looks like and be able to forge it. But until that happens, I think this sort of biometric identification technology will make identity theft a whole lot harder.
A tip of the hat to danielsnyder1, on Twitter, for the heads-up on his article.

Tuesday, May 27, 2008

Lifelock CEO Todd Davis Victim of Identity Theft, and There's a Lawsuit

"Does LifeLock really work?"
KPTM FOX 42 Omaha (May 25, 2008)

"There are a number of relatively new products on the market offering to protect us from identity theft. One of them features a marketing campaign that has people talking.

"The commercials definitely get your attention: LifeLock CEO Todd Davis parades his social security number around for everyone to see.

" 'I know I have made this information useless to the criminal,' says Davis. "We are the only company that actually stops this crime before it happens.

"For about $10 a month. But it's $10 you may not need to spend.

" 'The core services that they offer is actually available to consumers at no cost,' says Jaimee Napp of the Identity Theft Action Council of Nebraska...."

'Caveat Emptor' - 'buyer beware' - an old saying, and still a useful warning.

One more thing: "Fraud-prevention pitchman becomes ID theft victim" (CNN (May 22, 2008)). "SAN JOSE, California (AP) -- Todd Davis has dared criminals for two years to try stealing his identity: Ads for his fraud-prevention company, LifeLock, even offer his Social Security number next to his smiling mug."

And, predictably, there's a lawsuit.

Todd Davis's commercials, showing his social security number on a truck, have been described as hubris. Maybe so.

I see that as really good marketing. What disturbs me is that he apparently was selling a service that's free.

Tuesday, April 29, 2008

COFEE (Computer Online Forensic Evidence Extractor): Donuts Next?

"Microsoft hosts its own police academy"
CNET (April 28, 2008)

"Hundreds of officials from agencies around the world including the FBI, Interpol, state attorneys general, city and county police, and the Air Force are attending a three-day technology training session at Microsoft's Redmond, Wash., campus beginning on Monday."

"Officials also will be trained on a relatively new computer online forensic evidence extractor, with the acronym of COFEE, that was developed by a former Hong Kong cop who now works for Microsoft. COFEE (Computer Online Forensic Evidence Extractor), designed for use during police raids, is a USB thumb drive that captures evidence on a computer that could be lost when the computer is shut off, according to Kornblum."

Looks like law enforcement is getting tools to investigate cybercrime. Between phishing attacks, identity theft, botnets, and all the rest of Information Age crime, that's good news.

One thing came to mind, though. When will we see DONUT: (Digital Online Network Utilization Tracker)?

I've done my part, coming up with a cool name. Now it's up to someone else, to invent a working system to fit it. ;)

Wednesday, March 12, 2008

One More Worry: Hackers and Pacemakers

"Researchers: Life-Saving Heart Devices Can Be Hacked"
FOXNews (March 12, 2008)

A hundred thousand people in America alone have new pacemakers.
  • Good news:
    The new pacemakers transmit data to bedside monitors, cutting down on the number of checkups needed
  • Bad news:
    The data is unencrypted, and contains personal information, like birth date, medical ID number and, sometimes, Social Security number
  • Worse news:
    The system can be hacked. Then,
    • The right signal might be blocked
    • A wrong signal sent to the pacemaker
      • Either way, it's bad for the patient
Pacemakers with transceivers: A good idea. Add some security, and they'll be even better.

Wednesday, December 12, 2007

Lucky, or Loser? Chatroom Bot Lets You Be Both

"Flirty Chat-Room 'Bot' Out to Steal Your Identity"

I'm not sure what this is:
  • A great step forward in the development of artificial intelligence
  • An indication of how simple, shallow, and conventional 'romantic' online chats are
Maybe both.

The place: A computer's monitor, glowing in the dark somewhere.
The person: Some online chatter, seeking love, or a facsimile thereof.

Finally, the lonely netizen gets lucky! Someone's interested! All that's needed is a telephone number, and a postal address, and a photo, and maybe some more personal information.

The problem: The person on the other end isn't human. It's a 'bot' that mimics a flirty chat room user, collects personal information from credulous rubes, and passes the data along.

The official line by the software's publisher is that it's for guys who are too busy to chat up girls, and their female counterparts. It can be used by lovelorn Web surfers, but the odds are that it will be used for identity theft, too.
Unique, innovative candles

Visit us online:
Spiral Light CandleFind a Retailer
Spiral Light Candle online store

Pinterest: From the Man Behind the Lemming

Top 10 Most-Viewed Posts

Today's News! Some of it, anyway

Actually, some of yesterday's news may be here. Or maybe last week's.
The software and science stuff might still be interesting, though. Or not.
The Lemming thinks it's interesting: Your experience may vary.
("Following" list moved here, after Blogger changed formats)

Who Follows the Lemming?

WebSTAT

Family Blogs - Blog Catalog Blog Directory