Slashdot Mirror


Single Government ID Moves Closer to Reality

NewbieV writes "The Washington Post is reporting that "federal officials are developing government-wide identification card standards for federal employees and contractors to prevent terrorists, criminals and other unauthorized people from getting into government buildings and computer systems." The project is known as the Personal Identity Verification Project, and is being managed by the National Institute of Standards and Technology (NIST)."

25 of 239 comments (clear)

  1. Oh? by mythosaz · · Score: 5, Insightful

    Wow, similar IDs for government employees? This might prove as dangerous to our freedom as, say, Military IDs.

    1. Re:Oh? by Staplerh · · Score: 4, Insightful

      Wow, similar IDs for government employees? This might prove as dangerous to our freedom as, say, Military IDs.

      Oh, give me a break, who modded this 'Flamebait'. Give me a break, he had a valid point.

      If you don't want a Federal ID card for employees/contractors, don't join the Federal government? This is more akin to a Military ID card than a 'national ID card'. I think this is a great analogy, and if I had meta-mod points I'd mod that unfair.

      --
      "There's no success like failure, and failure's no success at all."
      - Bob Dylan
    2. Re:Oh? by Xoro · · Score: 2, Insightful

      Oh goody, in your world the government is controlled by market forces and voluntary participation. That means I can choose not to pay taxes or follow the laws if I don't like them.

      You pinhead.

      The system is for government employees. Surely you can decide if you want to become a government employee or not?

      --
      Kill, Tux, kill!
  2. I'm against this.. take three guesses why? by Ckwop · · Score: 5, Insightful

    Oh dear jesus god no. If you're going to put all your eggs in one basket at least guard the basket well! The problem is that by unifying all the ID card systems they don't defend the basket as much as they should.

    This point can be illustrated well with Safes. If it costs fifty pounds to break into a safe and only put forty pounds worth of valuables in the safe my safe is secure. If I get ten of these safes, each with forty pounds in them then the total of four hundred pounds worth of valuables is secure. Now let's say I decide to replace my ten safes with a single safe! A safe that only takes three hundred and fifty pounds to break in to is no good; I need a safe that is secure in the face of a four hundred pound attack or more.

    The problem with centralising identifications systems is that the new scheme is rarely more secure than numerous schemes it replaces. Except, Except, this time this one ID acts as identification for many types of service and this makes everything less secure. Just for the sake of argument. Let's suppose I choose to attack the system in a certain way. Let say I want to obtain a real "fake"; that is, a card that is authentic but I've paid an employee that produces the cards to put bogus information on to the card. Rather than finding two friends in two different branches of government to supply me with a real card in a fake name I only have to find a single person. This type of weaking isn't just true for this limited type of attack - this weaking is there across the board.

    Having different IDs is a simple security mechanism. It's the same reason that Microsoft's Passport technology is dying. Yes it might be more convient to have a single "sign in" but it means that you've produced a single global failure point for the entire system. Such systems are brital so please, I ask these people: hire some security professionals to make these decisions. Silly politicians making "security" decisions is about as helpful as putting a football coach in control of skyscrapper construction.

    Simon.

    1. Re:I'm against this.. take three guesses why? by floodo1 · · Score: 2, Insightful

      single system = single point of failure
      which means when a single point fails, it ALL fails.

      --
      I KUT J00 M4NG!!!
    2. Re:I'm against this.. take three guesses why? by kun · · Score: 3, Insightful

      I agree, a single point of failure is just asking to be taken advantage of. However, a single well-secured standard is much better than several well-secured standards, since the latter gives more points of possible attack. I.e a well defended main gate or several gates with the security spread amongst them... Sadly, it looks like those who designed the system are going for the single point of entry which is secured in a "let's get this done as soon as we can" fashion... Just take a look at this maze of a flow diagram! http://csrc.nist.gov/piv-project/PIV_model.pdf If their plan is to confuse people with respect to the actual usage of the card... thus foiling false identification attempts with a spaghetti bolognese of verification methods then I think they're succeeding!

    3. Re:I'm against this.. take three guesses why? by Talrias · · Score: 2, Insightful

      A safe's security does not depend on its contents if the contents are hidden (which most safes are, and so will ID cards). A locked box containing the Crown Jewels is no less safe than a box locked with the same type of device, containing 10 euros.

      I think you are confusing the consequences of having the safe broken into with the ability to break into the box.

      Chris

      --
      aterr - an open source threaded discussion board.
    4. Re:I'm against this.. take three guesses why? by complete+loony · · Score: 3, Insightful

      But, a manager in building A should only be able to grant access to builing A, and query if you have permission to access building A, not the entire government. And anyone should be able to query the system to confirm your identity. Of course the system might be vulnerable to attacks that elevate privliges.

      --
      09F91102 no, 455FE104 nope, F190A1E8 uh-uh, 7A5F8A09 that's not it, C87294CE no. Ah! 452F6E403CDF10714E41DFAA257D313F.
    5. Re:I'm against this.. take three guesses why? by NoMoreNicksLeft · · Score: 4, Insightful

      Except that this isn't about protection from terrorists at all, its about control-freakism on a rampage.

      The terrorist that defeats this, will be one with a valid ID as janitorial staff. Not someone trying to fake an ID as a junior senator. Duh.

      Don't you wonder a little bit, that they're rushing to protect all the official buildings, when people like you and I will still be unsafe in public buildings? Do they think this will have protected us at the airport prior to 9/11, or in the towers? Even the pentagon, that was attacked, wasn't infiltrated with a fake ID, but with a 757 hellbent for the ground. Duh.

      Centralization is a fetish for the elected nazi wannabees. It won't do a damn bit of good for you and me, and only a fool can't dream up at least one way for it to be abused...

    6. Re:I'm against this.. take three guesses why? by SilverspurG · · Score: 3, Insightful

      In short, I fail to see the downside if the system is implemented by someone with the slightest of clues.

      Oh Lord. MOD THIS FUNNY.

      You have seen the people who've been hired as security screeners at airports, haven't you? You are familiar with the perfection of implementation that DC is famous world-wide for, aren't you? You are familiar with the first rule of thumb which every 18-year old learns if they have to do any sort of real labor,"Good enough for government work."

      And, again, what is a 1024-bit cryptographic signature going to give me at work that the security guard at the front desk wouldn't have caught to begin with in terms of identification? In the hiring process new employees are paraded around for everyone to see. Some unknown can't just walk in with an ID card and pretend he's worked there for years. Even visitors from off-site, who legitimately work for our company, are introduced to the front desk and escorted around.

      --
      fast as fast can be. you'll never catch me.
  3. Or... by Anonymous Coward · · Score: 5, Insightful

    A single ID can be forged and used by terrorists for access to any government building! Brilliant!

    1. Re:Or... by mcg1969 · · Score: 4, Insightful

      Let's forget terrorists for a moment, do you really believe these badges would be designed so that an employee of the Department of Agriculture can gain access to an NSA building?

    2. Re:Or... by Zocalo · · Score: 4, Insightful
      Exactly. These things will almost certainly be like swipe cards on steroids with multiple levels of validation as to what and what isn't permitted. In a typical swipe card system you divide your secured areas into zones, then assign each swipe card access on a zone by zone basis. That covers the "something you have" aspect of security, and you can still add in the "something you know" (keypad or other password system) and "something you are" (biometic) if you wish. Hell, you can even keep the people standing around with guns too if the situation merits it.

      I've been at large multi-building, multi-location sites that have implemented this kind of thing using smartcards. The obvious gains of increased convenience, cost savings through having a common system and ease of management are all there, but a loss in operational security isn't. It's not that such systems are invulnerable (they're not by a long shot), but they are no more vulnerable than individual systems and it's *much* easier to be sure ex-employees are completely locked out.

      --
      UNIX? They're not even circumcised! Savages!
    3. Re:Or... by chill · · Score: 2, Insightful

      No, I believe one of those badges given to a sub-contracted janitor would get them into an NSA building. Or do you believe the super agents scrub their own toilets at work?

      It also depends on how they are implemented. I believe a stolen smart chip from card A, implanted into easier-to-get card B would be a major threat.

      The devil is in the details.

      --
      Learning HOW to think is more important than learning WHAT to think.
    4. Re:Or... by chill · · Score: 2, Insightful

      If an agency like the NSA or CIA requires security clearance for their cleaning staff, and some do, then it is very likely that the same staff will be used for multiple locations and rotated around.

      Getting clearance is expensive and it isn't just done on a whim. Once they have someone with clearance, that person is going to be used as often as possible.

      If a person temporarily loses clearance, they will be rotated to a non-clearance required position until their clearance is reinstated. It happens all the time with military contractors.

      --
      Learning HOW to think is more important than learning WHAT to think.
  4. reaching? by sailforsingapore · · Score: 4, Insightful

    This is a ways away from a "single government ID". That makes it sound like we are all going to get barcodes on our necks, this is simply a way to streamline the process of verifying federal employees, just as corporations have for years...this is not a problem. It becomes an issue when the ID starts to become mandatory for the non-governmental public, where the potential for abuse is.

  5. Online single sign on by SilverspurG · · Score: 4, Insightful

    Does anyone really think that you should have a single sign on name and password for every online service, site, e-mail account? Would you want that single sign on to be linked with all of your bank accounts? Why is it bad to have everything linked together? What makes identity theft easier?

    Forget trolling about tin-foil hats or paranoid people who have nothing to hide. Let's get back to the nuts and bolts of why, from the very beginnings of nature, squirrels put nuts in many different places.

    --
    fast as fast can be. you'll never catch me.
  6. Government-issued IDs are already here. by Pendersempai · · Score: 4, Insightful

    Drivers' licenses are ubiquitous and necessary. They are marked with identifying data and a unique number. They have your picture. Authorities are allowed to ask for it, and in general citizens are expected to cough it up. They must be checked by private parties in certain circumstances (to prove your age, for example), and in other circumstance private parties insist on checking your drivers' license as a prerequisite to doing business with you (Blockbuster, e.g.)

    Granted, each state keeps track of its own citizens' licenses, so I suppose that's one difference between the status quo and the ballyhooed National ID Card. But really, what else are we afraid of? Why don't we just bite the bullet and make citizens' identification cards necessary? The states can take care of issuing them and tracking the relevant data, and we can have laws about when authorities are not allowed to ask for identification, or when a citizen is not obligated to identify himself, just like we do with licenses. But not arbitrarily tying our ID cards to driving would be much more efficient. Why should it be harder for a blind man to identify himself at will simply because he cannot drive?

    So to everyone terrified of national ID cards, wake up: that reality arrived long ago.

  7. Security is related to competence, not plastic by t_allardyce · · Score: 2, Insightful

    Im pretty sure most break-ins come from things like "can you swipe me in? i left my card in the car" or "i work for bob but they havnt put me on the system yet" and "hey can i just use your computer for a minute to print this?"

    --
    This comment does not represent the views or opinions of the user.
  8. Threat analysis by TrumpetPower! · · Score: 2, Insightful

    Let's say you're a terrorist. And, further, let's say you want to hurt Americans. What will you do?

    1) try to get into a government facility with a faked ID to do your terrorizing;

    b) get a job at said government facility and then do your terrorizing with legitimate access;

    or III) strap a bunch of explosives to your body, go to a movie theatre, buy a ticket, sit down, and blow yourself up halfway through the opening credits?

    Cheers,

    b&

    --
    All but God can prove this sentence true.
  9. Sure. by Dirtside · · Score: 2, Insightful
    federal officials are developing government-wide identification card standards for federal employees and contractors to prevent terrorists, criminals and other unauthorized people from getting into government buildings and computer systems.

    Yeah. I'm sure that this new ID card will "prevent terrorists, criminals and other unauthorized people from getting into government buildings and computer systems."

    I smell someone trying to convince people that security can be had in a product, rather than requiring constant vigilance, like it really does.

    --
    "Destroy science and religion. Science would re-emerge exactly the same; but not religion." - Penn Jillette, paraphrased
  10. Spain had ID cards by permaculture · · Score: 3, Insightful

    UK Parliamentary Committee Releases Report Damning ID System http://www.privacyinternational.org/article.shtml? cmd%5B347%5D=x-347-63601

    Spain has ID cards, but that didn't prevent the Madrid train bomb: http://news.bbc.co.uk/2/hi/europe/3500452.stm

    The British Parliament has abandoned their new ID cards for the Houses of Parliament despite the recent security breaches, as some hundreds have 'gone missing'.

    Reasons against ID cards: http://www.bbc.co.uk/dna/ican/A2319176

    ------------

    ID cards might well:

    * Worsen harassment of ethnic minorities: They'll provide another pretext for stop-and-search, often directed at ethnic minorities

    * Have little impact on counter-terrorism: Sophisticated terror networks would soon be able to produce counterfeit cards or papers enabling people to get legitimate cards

    * Have little effect on illegal working: Employers who are already willing to break the law won't be put off by identity cards

    * Lead to 'function creep': The functions of the card will grow over time as it stores more personal information. More people could demand to see it, effectively making it compulsory to carry one

    * Lead to loss of privacy: There will be a massive database containing an unprecedented amount of personal information on people

    * Be costly and impractical: There is scepticism about the cost and operability of the scheme, as well as the government's ability to manage the technology

    ----------------

    Doubts over ID card scheme http://news.bbc.co.uk/1/hi/technology/2688697.stm

    --
    Environmentalism is the new Victorianism. Everyone ties on a green corset and pretends we're virtuous.
  11. The human factor by parvati · · Score: 2, Insightful

    What proponents of high-tech IDs tend to overlook is the importance of having people involved. A few years ago, I worked in a hospital/research center in NYC that had very tight security (for example, everyone was finger-printed before being issued an ID). The ID itself would presumably not be impossible for someone--especially someone motivated--to fake, but the security guards were another matter. They lived at the entrance to the building, and they pretty much recognized everyone who worked there. If they didn't recognize you, they stopped you, checked your ID, and called up to wherever you said you were going. This isn't a system that would work for a bulding accessible to the general public, but the majority of government buildings are only frequented by the people who work there ... for these buildings, attentive security guards are at least as important as fancy IDs.

  12. Not really by Safety+Cap · · Score: 1, Insightful
    Checking IDs at restricted access places like military bases, NASA, NSA, etc. makes a hell of a lot of sense.
    Every single one of the 9/11 hijackers had IDs.

    Timothy McVeigh had ID, too.

    IDs do nothing for security at all, except lure gullible people into believing they do something to promote security. The proposed Federal IDs can tell you if a known terrorist is trying to get a job in the government. If a person is a "known terrorist" why in god's green earth hasn't she/he been picked up yet? Oh wait...

    --
    Yeah, right.
    1. Re:Not really by crawling_chaos · · Score: 3, Insightful
      Passwords can be cracked. Should we stop using them? Locks can be picked. Do you leave your house door open?

      Properly handled IDs do contribute to security, but they are not a panacea. Nor is anything else for that matter. Security is a process, not a technology, but dismissing a unified government employee ID as "totally useless" is just disengenous. At a minimum, it increases security by lowering the training burden on the officers responsible for checking on access rights. Can it be defeated? Sure. Is it harder to defeat than the hodgepodge of identification systems currently in use by federal agencies? Yes, it is. The current FDA IDs are a joke, for example. I would bet any talented forger would have no trouble producing a reasonable copy of one with today's technology.

      --
      You can only drink 30 or 40 glasses of beer a day, no matter how rich you are.
      -- Colonel Adolphus Busch