Homeland Security Director Defends Real ID
An anonymous reader writes "Homeland Security chief Michael Chertoff is defending the upcoming rollout of the national ID card as vital for the nation's security. Chertoff reminded reporters of the importance of the initiative after this week's uncovering of an ID-forging ring. The Real ID Act of May 2005 dictates the uses and requirements for the documentation, which by 2008 may be required for everything from travel to banking. Just the same, the HSD has yet to dictate how exactly the cards will work. " From the article: "The Homeland Security chief, who is nearing his two-year mark with the agency, was likely trying to quell rampant skepticism about the IDs voiced by some privacy advocates, immigrants and other groups. Some have said they fear that the IDs are a stepping stone to a veritable police state, complete with ready surveillance of individuals. Some have argued that the idea of creating more tamperproof IDs is only a marginally better way to screen out those intent on committing terrorist acts because ID cards don't even begin to tackle a core crime prevention challenge: determining a person's unspoken intentions. "
Speaking for all college students out there (even though it's been 10 years since I've been one), I say "down with national ID cards!" How are our college students supposed to enjoy the company of their elders in fine drinking establishments without easily forged IDs? Punishing the resourcefulness of underage drinkers that are no threat to national security is just a crime.
Crack - Free with every butt and set of boobs
Can't remember the name of the book, but I know how this ends. Some guy who doesn't like me steals my ID card and/or replaces it with an invalid one, and I end up in jail because I can't prove who I really am. Federated identity is important; we can't have a single authoritative source for IDs or this sort of abuse will definitely happen.
mandelbr0t
"Please describe the scientific nature of the 'whammy'" - Agent Scully
So how exactly would these new ID cards be forge-proof? If people are already forging IDs, what's to stop them from forging these new ones? And what problem does this national ID card solve?
Comment removed based on user account deletion
It's not "mandatory", but any state that does not abide by the Real ID requirements won't recieve any federal funding for roads and such.
Which is a tactic that is abused even more than the interstate commerce clause. They take our money as federal tax and then ransom it back to us to make us do things we don't want to do.
But, if people enter the US from other countries, they'll be using their passports for ID, not this thing, so... um... what was the point again?
Ah, but if they made everyone, even people visiting from other countries, get one of these, then it's much more secure than showing the passport. And how would they get one? They'd need some other ID first... like, for instance, a passport...
So, what possible good can this do? Well, I guess it'll make it harder for underage kids to buy beer. Other than that? Nothing, really...
If the masses can keep you down, you're not the Ubermensch.
I'm not exactly in favor of a national ID card, but this new program for implementing one makes me marginally happy. Why? Because we already have a national ID card, and it's a terrible one, trivial to abuse, trivial to forge, and used in contexts where it makes no sense: the Social Security Card. When the SSN card was first introduced, it was derided as a national ID card, but the proponents promised it wasn't. Well, it was, and we can see that by looking around us now. Do you want a driver's license? Well you better have a valid SSN card because one is required to get a license (this is a new rule as of summer 2006, so many of you might not realize this yet). Do you want a bank account? Need one. You need one for everything. My local video store demanded my actual physical SSN card before they would rent me a video. (I almost refused but I really really wanted to see Weekend At Bernie's II.)
So, shit, even though I don't want there to be a national ID card, the one coming soon is sure to be better than the one we have now.
I just really hope my new Social Conformity Number is 54601.
Imagine that you are a US Senator, elected to that position by the legislature of your state. A bill is proposed that will demand that the same legislature enact a certain law, and the state executive branch enforce it to the satisfaction of some national executive agency, or have funds withheld. Now imagine you want to be re-elected by that legislature. How do you think you're going to vote?
The result of these changes is that more and more decisions are being made in the US Congress and by the faceless mass of bureaucrats in national agencies, rather than in state capitals, county courthouses, and city halls. The concentration of power favors well-funded lobbyists who represent powerful interests, for whom the return on their investment can be huge; against diffuse interests of common citizens.
Instead of 50 different 'distros' of government, with the chance to learn from each other and merge improvements that succeeded elsewhere, we get stuck with a single implementation. Any flaws in that monoculture are global and potentially catastrophic.
[100% ISO 646 Compliant]
SVM, ERGO MONSTRO.
The DHS is run by over promoted bureaucrats who know absolutely nothing about security. We all know this, here is why this time:
:)
First lets talk about passwords. One thing I run into that people who set corporate policies for passwords often do not understand is that the password strength is very rarely the weak point in an attack. Quite often the requirements will be sent to something crazy like 20 characters, no repeating characters, enforced alphanumeric, (you all know the usual strong password requirements) and they feel that is it. Oh, but to reset a forgotten password all you need to know is your mother's maiden name or some such. THAT is the weak link, you have effectively made every user's password their mother's maiden name. All of the other password strength requirements are irrelevant.
"How does this relate, finkployd, you arrogant prick?" I hear most of you asking. Simple, how does one get one of these super duper realID cards? I strongly suspect it is by showing OTHER, PRE-EXISTING forms of ID. How else would it work? The problem of how to distribute these cards in such a way that you know they are being generated for and sent to the proper people pales in comparison to actually designing the damn thing in the first place. It will certainly depend in some way on existing forms of ID, meaning it is absolutely no more secure then them.
Of course the government and financial institutions will inevitably consider it to be the absolute last word in authentication, so expect that if your identity is ever stolen via a false realID card, nobody will ever believe you. YOU will be financially (and likely criminally) responsible for anything done if your realID is spoofed. Good luck everyone, we are screwed
Finkployd