Saturday, August 8, 2009

Political Blogcritics appraisal of Beat The Chip

"I think the issues you raise on your blog mostly fall on the serious side. RFID and the entire privacy issue are very real threats which need to be exposed and opposed. I've written some articles on the subject over the years, but there's so much more going on that I can't give it as much attention in the current environment.
The recent news about being able to read RFID chips from up to 30 feet away with easily obtainable hardware is very troubling.

If you'd ever like to write on the subject for blogcritics[...]We'd love to have more participants in the Politics section.
- Dave Nalles,
Blogcritics online.

Biometric requirement could make E-Verify worth billions

Industry closely watching Schumer bill that would require biometric data
  • Real ID Repeat?
  • Schumer's support critical
  • A question of how
Sen. Charles Schumer (D-N.Y.) enthusiastically supports adding a biometric identifier to the federal E-Verify employment eligibility verification system, which is setting the stage for potentially one of the largest federal biometric opportunities.

His newly proposed biometric identification program could be huge, potentially encompassing the entire U.S. workforce of 140 million employees. Naturally the biometrics industry is paying attention. Contractors are excited, but they also are tamping down their expectations while trying to sort through the political and social implications of the potential multibillion-dollar identity plan.

“Obviously, it will be a big boost for the industry,” said David Coleman, senior consultant at International Biometric Group consulting firm.

“This is clearly a big opportunity — one of the biggest in the United States,” said Neville Pattinson, vice president of government affairs and business development at Gemalto North America. ::: 4 Pg Article HERE:::

FLOGGER: Fun With DHS Press Releases!

National ID bashing with CATO's policy brand Jim Harper

Let’s fisk a DHS press release! It’s the “Statement by DHS Press Secretary Sara Kuban on Markup of the Pass ID Bill by the Senate Homeland Security and Government Affairs Committee.” Here goes [DHS news release in italics]:
On the same day that Secretary Napolitano highlighted the Department’s efforts to combat terrorism and keep our country safe during a speech in New York City,
This part is true: Secretary Napolitano was in New York speaking about terrorism.
Congress took a major step forward on the PASS ID secure identification legislation.
There was a markup of PASS ID in the Homeland Security and Governmental Affairs Committee. It’s a step — not sure how major.
PASS ID is critical national security legislation
People who have studied identity-based security know that knowing people’s identities doesn’t secure against serious threats, so this is exaggeration.
that will break a long-standing stalemate with state governments
Thirteen states have barred themselves by law from implementing REAL ID, the national ID law. DHS hopes that changing the name and offering them money will change their minds.
that has prevented the implementation of a critical 9/11 recommendation to establish national standards for driver’s licenses.
The 9/11 Commission devoted three-quarters of a page to identity security — out of 400+ substantive pages. That’s more of a throwaway recommendation or afterthought. False identification wasn’t a modus operandi in the 9/11 attacks, and the 9/11 Commission didn’t explain how identity would defeat future attacks. (Also, using “critical” twice in the same sentence is a stylistic no-no.)
As the 9/11 Commission report noted, fraudulent identification documents are dangerous weapons for terrorists,
No, it said “travel documents are as important as weapons.” It was talking about passports and visas, not drivers’ licenses. Oh — and it was exaggerating.
but progress has stalled towards securing identification documents under the top-down, proscriptive approach of the REAL ID Act
True, rather than following top-down prescription, states have set their own policies to increase driver’s license security. It’s not necessarily needed, but if they want to they can, and they don’t need federal conscription of their DMVs to do it.
– an approach that has led thirteen states to enact legislation prohibiting compliance with the Act.
“. . . which is why we’re trying to get it passed again with a different name!”
Rather than a continuing stalemate with the states,
Non-compliant states stared Secretary Chertoff down when he threatened to disrupt their residents’ air travel, and they can do the same to Secretary Napolitano.
PASS ID provides crucial security gains now by establishing common security standards for driver’s licenses
Weak security gains, possibly in five years. In computer science — to which identification and credentialing is akin — monoculture is regarded as a source of vulnerability.
and a path forward for ensuring that states can electronically verify source documents, including birth certificates.
We’re on the way to that cradle-to-grave biometric tracking system that will give government so much power over every single citizen and resident.

See? That was fun!

PASS ID: A kinder, gentler National ID
MORE COMMENTARY FROM JIM via PODCAST

12 Minute Hacks for RFID & More on DefCon Fed Scare

These updates in from Slashdot.org

Death Metal writes with this excerpt from Computer Weekly, which casts some doubt on the security of the UK's proposed personal identification credential:"The prospective national ID card was broken and cloned in 12 minutes, the Daily Mail revealed this morning. The newspaper hired computer expert Adam Laurie to test the security that protects the information embedded in the chip on the card. Using a Nokia mobile phone and a laptop computer, Laurie was able to copy the data on a card that is being issued to foreign nationals in minutes."
FourthAge writes"Federal agents at the Defcon 17 conference were shocked to discover that they had been caught in the sights of an RFID reader connected to a web camera. The reader sniffed data from RFID-enabled ID cards and other documents carried by attendees in pockets and backpacks. The 'security enhancing' RFID chips are now found in passports, official documents and ID cards. 'For $30 to $50, the common, average person can put [a portable RFID-reading kit] together,' said security expert Brian Marcus, one of the people behind the RFID webcam project. 'This is why we're so adamant about making people aware this is very dangerous.'"

Thursday, August 6, 2009

WIRED Digest: Words of warning from those who care

BTC - A relative sent me these two news items from Wired Magazine out of concern for my personal safety. Since we are on a WIRED kick this morning, we included alot we've missed.

Digitized Stalking Is the New World Order

The EFF writes that threats to “locational privacy” include:
* Monthly transit swipe-cards.
* Electronic tolling devices (FastTrak, EZpass, congestion pricing)
* Cellphones.
* Services telling you when your friends are nearby.
* Searches on your PDA for services and businesses near your current location.
* Free Wi-Fi with ads for businesses near the network access point you’re using
* Electronic swipe cards for doors.
* Parking meters you can call to add money to, and which send you a text message when your time is running out.

“In the world of today and tomorrow, this information is quietly collected by ubiquitous devices and applications, and available for analysis to many parties who can query, buy or subpoena it or pay a hacker to steal a copy of everyone’s location history,” the report said. “It is this transformation to a regime in which information about your location is collected pervasively, silently, and cheaply that we’re worried about.”

Read the report here.


c/o Charlie Sorrel for WIRED - GADGET LAB

As an ex-Brit, I’m well aware of the authorities’ love of surveillance and snooping, but even I, a pessimistic cynic, am amazed by the governments latest plan: to install Orwell’s telescreens in 20,000 homes.

£400 million ($668 million) will be spent on installing and monitoring CCTV cameras in the homes of private citizens. Why? To make sure the kids are doing their homework, going to bed early and eating their vegetables. The scheme has, astonishingly, already been running in 2,000 family homes. The government’s “children’s secretary” Ed Balls is behind the plan, which is aimed at problem, antisocial families. The idea is that, if a child has a more stable home life, he or she will be less likely to stray into crime and drugs.

It gets worse. The government is also maintaining a private army, incredibly not called “Thought Police”, which will “be sent round to carry out home checks,” according to the Sunday Express. And in a scheme which firmly cements the nation’s reputation as a “nanny state”, the kids and their families will be forced to sign “behavior contracts” which will “set out parents’ duties to ensure children behave and do their homework.”

And remember, this is the left-wing government. The Shadow Home Secretary Chris Grayling, batting for the conservatives, thinks these plans are “too little, and too late,” implying that even more obtrusive work needs to be done. Rumors that a new detention center, named Room 101, is being constructed inside the Ministry of Love are unconfirmed.

UPDATE: Further research shows that the Express didn’t quite have all its facts straight. This scheme is active, and the numbers are fairly accurate (if estimated), but the mentions of actual cameras in people’s homes are exaggerated. The truth is that the scheme can take the most troublesome families out of their homes and move them, temporarily, to a neutral, government-run compound. Here they will be under 24-hour supervision. CCTV cameras are not specifically mentioned, not are they denied, but 24-hour “supervision” certainly doesn’t rule this out from the camera-loving Brits.

It remains, though, that this is still excessively intrusive into the private lives of citizens, cameras or not. I have added links to the source and also more reliable reports.

Thanks to everyone who wrote in.

>>SIN BINS FOR WORST FAMILIES :THOUSANDS of the worst families in England are to be put in “sin bins” in a bid to change their bad behaviour, Ed Balls announced yesterday.


Wednesday, August 5, 2009

Israeli Privacy Council opposes biometric database

BTC-  Israeli privacy advocates are volleying against biometrics. SOMEONE CALL CHERTOFF QUICK TO TELL HIM BIOMETRICS AREN'T GOOD ENOUGH FOR AMERICA EITHER.

It warns of the risk of information leaks and says it will be the death knell for citizens' privacy.

Noam Sharvit
www.globes-online.com
5 Aug 09 16:30

The Public Council for the Protection of Privacy today asked Prime Minister Benjamin Netanyahu not to set up a biometric database, because of the risk of information leaks and concern that it will be the death knell for citizens' privacy.
The council was set up to advise the minister of justice, and comprises legal and technology experts. The council expresses opinions on aspects of privacy and information security of bills and government measures and advises the registrar of databases.

In the letter to Netanyahu, the council said that the establishment of a biometric database, its maintenance and security, would likely carry a heavy financial burden. Countries that have considered setting up such databases estimate their cost in the billions of dollars, and the estimates are constantly rising.

The council argues that, because of these costs, the US government recently cancelled its Real ID program. The British government does not mandate citizens to carry biometric ID cards and will probably cancel the entire project because of its huge cost and broad public opposition.
The council adds that it supports the issuing of smart ID cards and travel documents, and does not oppose documents with biometric features. However, it does not believe there is a need for a central biometric database for these purposes, because there are simpler and better alternatives for fraud prevention during the issuing process. For example, Germany issues biometric passports and ID cards without a central database because of concerns about the over-concentration of power that would harm individual rights.

Published by Globes [online], Israel business news - www.globes-online.com - on August 5, 2009

Feds at DefCon Alarmed After RFIDs Scanned

Wired Magazine, Kim Zetter 

LAS VEGAS — It’s one of the most hostile hacker environments in the country –- the DefCon hacker conference held every summer in Las Vegas.

But despite the fact that attendees know they should take precautions to protect their data, federal agents at the conference got a scare on Friday when they were told they might have been caught in the sights of an RFID reader.

The reader, connected to a web camera, sniffed data from RFID-enabled ID cards and other documents carried by attendees in pockets and backpacks as they passed a table where the equipment was stationed in full view.

It was part of a security-awareness project set up by a group of security researchers and consultants to highlight privacy issues around RFID. When the reader caught an RFID chip in its sights — embedded in a company or government agency access card, for example — it grabbed data from the card, and the camera snapped the card holder’s picture.

But the device, which had a read range of 2 to 3 feet, caught only five people carrying RFID cards before Feds attending the conference got wind of the project and were concerned they might have been scanned.::MORE HERE:::