NIST Standards for New Biometric ID Card Published
rts008 writes "eWEEK is reporting that NIST has published the biometric data specs on the new Federal ID cards for employees and contractors that will be issued in October. From the article: 'Specifically, the guidelines state that two fingerprints must be stored on the card as "minutia templates," mathematical representations of fingerprint images. [...] Guidelines require that all biometric data to be embedded in the CBEFF (Common Biometric Exchange Formats Framework) structure. This ensures that all biometric data will be digitally signed and uniformly encapsulated. This format will apply not only to PIV cards, but also to any other biometric records kept by federal government agencies.'" The published standards [PDF] are also available from the NIST web site.
Maybe this will kill Tony Blair's "We have to have biometric ID cards first so that we can create the de facto standards" argument. Or maybe that's wishful thinking on my part.
If i wanted to verify someone's information, i'd rather do so from a secure database rather than a card he gave me.
Or am i missing something?
According to the description, this card is for a new government employee ID. I'm Canadian, so I don't know for sure how this is for the US, but up here, if you work for the government, your government department is already going to have a lot of your personal information. While it's not required for all public service jobs, some positions require to get at least a minimal security clearance, and depending on how high a clearance you need to get, you might get fingerprinted. The only thing new here is that they're encoding all that digitally onto your staff ID card.
It should be rediculously easy to avoid getting one of these cards: Just don't apply for a government job.
I'm not so sure if it's legal to mandate that the employees give up their fingerprints like that.
... against unreasonable searches and seizures, shall not be violated,
Below is the part of the 4th Amendment in which I am referring. Aren't our fingerprints considered to be part of our property? Isn't mandating that they collect our fingerprints without being suspected of a crime an unreasonable search? (It's one thing to do a background check and ask for fingerprints. It's another thing to require your fingerprints be on a card you have to carry around.)
The right of the people to be secure in their persons,
Aren't static keys always inferior to dynamic keys?* (Isn't that why we're supposed to regularly change our passwords?)
Isn't biometric data static?
So why is anyone interested in biometric security?
Isn't it (perhaps counterintuitively) an inherently insecure means of indentification, by its very nature?
I must be missing something.
*(Maybe this is because anything can be duplicated and forged, given enough time. Changing your key a lot makes forging impractical?)
If you are, how is this any different than for example the generic attire/monkey-suit your employer expects you to wear?
If you are not a federal employee and/or contractor, please have a sit and keep your mouth shut.
Thank you.
P.S. Why does everything on slashdot has to be blown out of proportions?
Shoot... people are still the weakest link in any security system involving semi-intelligent primates. Even if TFA is talking about merely ID'ing someone accurately, there will always be a system to circumvent "the system."
7h3$3 4r3n'7 7h3 Ðr01Ð$ ¥0 4r3 £00|{1n9 f0r. M0v3 4£0n9. --OB1
Unfortunately, as soon as fingerprints are on cards, along with other biometrics, the cards themselves become much more trusted. One of the dangers of security is the appearance of things being more secure than the actual method. Ergo, much more trusted despite only marginally more effective security. This means that when you get the key to the castle, you have one to all the doors. Not good. This is a case of the added value of having such identification on a card being trumped by the reality that if someone gets their hands on it and the ability to use it your financial life is not going to go well for a seriously long time.
Making a security system more complex does not disallow it from being broken, it simply puts more complex holes in it. The reason anyone wants biometrics on a card is to take advantage of the gathered information, and has nothing to do with wanting more effective fraud reduction.
My little site.
P.S. Why does everything on slashdot has to be blown out of proportions?
Because whether the information is right or wrong, Slashdot makes money on the page views. They're not the drug dealer. They're not the cop. They're the informant that makes money from both sides.
-- I'm old enough to have lived through six different meanings of the word "hacker."
Lessons From The Brandon Mayfield Case
The world needs more people with your understanding and convicition. I too will not be getting another passport (when my current one runs out) or any biometrically - linked ID card if the current trends continue. I will chose not to drive to avoid this.
This is yet another example of where technology advances will support inflexibilty in rule enforcement. (other examples include red-light camera, DRM, etc.) In each example, human judgement is being taken out of the loop in the enforcement of a particular rule. Next it will be a machine that decides if you are who you say you are, not a person looking at you, knowing you, or judging the picture on a badge. This is yet another hook in someone that brings us a step closer to the possibility of tyranny.
As long as all the rules are fair, equally enforced, and democratically supported -- then there is no problem with machines enforcing the rules. The problem is that more often than not, none of these factors apply and rarely do any of them apply. Rules are often created arbitrarily by property owners / corporations (like EULAs), supported by small fractions of the people they affect (speeding laws), or simply conflict with other accepted rules (copyright/DRM and fair use).
Just don't apply for a government job
Sorry, it's not that easy. Two problems with this. First, the class of workers that work for/in the gov.t is a huge group, and we have every reason to believe that this class will grow in size.
Second, you run a slippery slope accepting things you disagree with, even if they don't affect you personally. If it's OK for gov't workers, next it will be OK for everyone. Next everyone will need a biometric ID to use a bank, or travel. Next if you have an outstanding issue with the government, -- oops, no money, can't travel, you're outta-luck buddy. Next Canada will say -- it's OK in the US, we should do that here. etc etc etc...