Feeds

US.gov tunes out scathing RFID privacy report

DHS committee study 'disavowed'

Combat fraud and increase customer satisfaction

An external security advisory committee reporting to the US Department of Homeland Security has produced a highlight critical report (PDF) advising against the use of RFID technology in government documents.

But the scathing analysis remains stuck in limbo, as a draft report, while the government pushes ahead with plans to include RFID tags in everything from passport and diving licences to library cards.

The Data Privacy and Integrity Advisory Committee of the DHS concludes that RFID chips are useful in inventory management but aren't suitable for human identification, where privacy issues remain a concern. Using RFID tags to identify miners or firefighters more quickly may be a sensible use the technology. Where the technology falls down is where it's used to verify identity, where the experts reckon it offers little advantage over previous technology while creating the possibility that data held on RFID chips might be intercepted by undesirables.

"RFID appears to offer little benefit when compared to the consequences it brings for privacy and data integrity. Instead, it increases risks to personal privacy and security, with no commensurate benefit for performance or national security," the report states.

The experts advise that "RFID be disfavored for identifying and tracking human beings. When DHS does choose to use RFID to identify and track individuals, we recommend the implementation of the specific security and privacy safeguards".

The draft report was criticised by the RFID lobby when it came out in summer but a Homeland Security spokesman denied suggestions that anyone is trying to spike the study. "The committee is still soliciting input and the draft report is on its website, so I guess they are proceeding," he said.

Civil liberties group the Center for Democracy and Technology is also critical of the report because of its failure to recognise the reality that RFID technology is already widely deployed. The committee needs to produce suggestions on how the RFID-chips can be more securely deployed instead of advising government to avoid the technology. Jim Dempsey, the policy director for the CDT, told Wired that the report was "off-target".

Jim Harper, a Cato Institute fellow and member of the advisory committee, remains hopeful that the committee will vote to publish the report so that it can influence the PASS card, an RFID-based system designed to act as an alternative to passports for US citizens returning from neighbouring countries such as Mexico and Canada from 2008. "If we don't have a report out before the (PASS card) comment period ends, then we are irrelevant," Harper told Wired. ®

SANS - Survey on application security programs

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.