Digital Credentials Offer Enhanced Privacy
John Q Random writes "Stefan Brands's company credentica.com announced their U-Prove library and SDK implementing ID tokens — also known as digital credentials or private credentials. (Private Credentials are a cool PKI replacement and anonymous e-cash tech that allows you to prove certified attributes like age, credit rating, group membership, etc. without revealing who you are; to allow you to have a digital life without the digital dossier effect inherent in a central databases.) Following this announcement, Adam Back announced credlib, an open source implementation of Brands credentials (and the older more basic Chaum certificates). These developments relate to recent news from IBM's Zurich labs on their identity-mixer project (previously discussed on Slashdot) that is based on the less efficient Jan Camenisch and Anna Lysyanskaya credentials."
This is under the presumption that the holder/applicant is who he claims he is.
I guess it'll just get added to the to-do list of phishers and ID thieves.
And the fact that (real) sensitive data has to be included to prevent 'leading/sharing' just begs for hacking.
Virtual Betting on Facebook for non-geeks.
At first I thought is said "Digital Credentials Offer Enhanced Piracy"
"Me SmartCard an' Biometrics allow en' more booty to be plundered, yarhhh!"
I judt got a nre Kinesis keybiartf so please excusr ant egregiou typos.
When I read "digital credentials" I immediately thought "(SSL/SMIME) certs and (SSH/PGP) keys". Those are two standard and widely implemented forms of "strong" digital authentication. SSL certs are also already available in hardware tokens, etc, if you like the FOB route. (Just ask the DoD about CAC cards...)
I don't know why people keep trying to reinvent the wheel here.
Following this announcement, Adam Back announced credlib, an open source implementation of Brands credentials (and the older more basic Chaum certificates).
That certainly sounds like a credlib-able solution to the problem.
The theory of relativity doesn't work right in Arkansas.
Where is the threat to individual privacy? As I see it, the threat is companies misusing legitimately-obtained personal information. Now let's tie in privacy with today's earlier discussion about credit card fraud. To buy anything over the Net from a reputable vendor, you usually must provide your legal name, home address, and phone number in order for the credit card transaction to be approved. (Buying from less reputable vendors may actually provide more privacy because AFAIK Paypal doesn't expose all these personal details when you make a payment.) What is the chance that VISA/MC/AMEX will re-engineer their systems to be privacy-preserving?
When I read "digital credentials" I immediately thought "(SSL/SMIME) certs and (SSH/PGP) keys". Those are two standard and widely implemented forms of "strong" digital authentication.
The problem with regular certs is that they are all-or-nothing, so if you disclose your cert to a party, they now have all the information in the cert. For example, consider using a "digital drivers license" to prove your age or using a "digital student ID" to get a student discount; it's totall overkill.
The summary explains why Brands credentials are an improvement:
Private Credentials are a cool PKI replacement and anonymous e-cash tech that allows you to prove certified attributes like age, credit rating, group membership, etc. without revealing who you are (emphasis added)
You don't put things like "age" or "student ID" on a cert, and you certainly wouldn't put them on a key. Instead, you could use the verified IDs from certs/keys to look up information from a master DB, much like Brands and dozens of other interchangable knuckleheads are proposing.
Remember, whether you show up to a "verification service" with a magic cookie/ID/BrandsThing or a cert, you're still trusting a third party to only give out a piece of your total profile at a time. All the while, they're probably really selling the whole DB to random spammers, just like your average credit bureau.
Oh, thats right, I'm reading /. ;)
That's right; I'm a true tech through and through. If manuals are for wimps then TFA is for wussies too. C'mon - Slashdot editors: you need to shorten up those summaries for those of us with post-MTV-era attention spans!
I don't need this certificate myself. Can someone explain why I can't obtain one proving my age (42) and sell it to a youngster? All other attributes are masked.
)9TSS
We both know that isn't the true meaning of piracy!
You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
True of all such "private" information storage facilities...
Either the information is kept by someone and can be obtained from the issuer (whether through legitimate legal means or theft. This is valuable information. Unscrupulous people will steal, trade and sell it). You're basically trusting the issuer to keep you safe. SSL certs are kinda like this but there's no pretense of private data being stored encrypted in the cert.
OR
Once the certificate is issued there is no way to identify who it is issued to, which means the only way a security hole in the method comes to light is when massive fraud occurs or if someone brags about breaking it. PGP is kinda like this.
All this does is allow you to buy products or services annoymously from legit vendors, and only so long as the system isn't compromised. The other thing is most non-shady vendors won't want to accept this form of ID/verification. I mean it's great for porn vendors because porn is socially vilified and people don't want to admit to buying it or having it on record. For most other things, the vendor will prefer a method of verification under their control since it'll give them marketing data and also prove to be a better protection against litigation than some anonymous cert.
These posts express my own personal views, not those of my employer
They have an anti-lending option. Here's how it works: the credential can have multiple private keys, one of which has to be random and the others of which can be secrets you would not be happy to sell to a youngster. (Say like your credit card number, or any other info that could be risky to lend to someone). Without all of the private keys you cant use the credential, so the would be lender, or reseller cant transfer the credential without revealing secrets chosen to be risky to share.
The CA or credential issuer, he sees secrets when the credential is issued, however you trust him not to abuse those secrets (and maybe you paid him with the same credit card number eg). However due to the crypto magic the CA cant observe nor trace your uses of the credential back to you even with full collusion with relying parties.
In fact the privacy is unconditionally secure and the user has full control and doesnt have to trust anyone (not CA, not relying parties, etc) only that the software of his credential wallet software is correctly implemented. This software would typically be open source and peer reviewed.
It remains to be seen at this point whether the Camenisch/Lysyanskaya Idemix credentials are really "less efficient" than Brands. Certainly the CL credential work is newer. Brands' stuff is good but the field does not stand still. Until we see benchmarks putting them side by side, it is too early to say which is more efficient.
Is PKI that broken that we already need a replacement? Seems to do the job for me...
They're exactly correct. But this post puts somebody's credentials behind their position. :-)
The technology to do this one way or another has been around for years, at least since David Chaum's blinded signatures and e-cash. The problem is getting it to be marketable.
There are 2 hurdles to this product:
1. Digital certificates of any kind are hard to get Joe average user to understand and adopt. How many people use PGP style email encryption, let alone user SSL certificates?
2. More seriously, how many online business are willing, not only not to collect customer data, but to go to sigificant expense to avoid collecting customer data?
Since customer data is generally viewed as having value to businesses, you are in effect asking business to spend money to make less money. That just won't happen, unless customers demand it. And I don't see that happening anytime soon (see #1 above).
Fizz
Huh? Are you misunderstanding me on purpose?
If you kept your library lending record on such a token you'd be smoking wacky weed! You might keep some summary information like a trust rating. Or you might just keep it to basics like age, country of residency etc. The reason that anon payments would be useful is in case you didn't trust the vendor to keep your information secret. You already trust the public library not to publish your lending record. However you might not trust a porn retailer not to put you on a mailing list or publish your history. In that case verifying you're 18 without giving additional information would be useful.
As for issues with litigation what would you rather say if you were accused of selling porn to a minor? Your honour I have cert number 121332293478294 that says whoever I sold this to was over 18, or your honour I accepted payment from Mr Jarvis Flugelbund of 6 Acacia lane, Pornsville, who submitted a fax of his drivers license that clearly shows he's 32?
These posts express my own personal views, not those of my employer