My comments on the article "The right way to mend immigration" by Senators Charles E. Schumer and Lindsey O. Graham
Friday, March 19, 2010
You can read the article here:
http://www.washingtonpost.com/wp-dyn/content/article/2010/03/17/AR2010031703115.html?hpid=opinionsbox1
Biometrically the crux of the article focuses on the following paragraph "We would require all U.S. citizens and legal immigrants who want jobs to obtain a high-tech, fraud-proof Social Security card. Each card's unique biometric identifier would be stored only on the card; no government database would house everyone's information. The cards would not contain any private information, medical information or tracking devices. The card would be a high-tech version of the Social Security card that citizens already have. "
Upgrading the Social Security card is a wonderful idea. Too many illegal immigrants use existing numbers to falsify their identity and mask as legitimate workers. While public opinion may be out on the immigrant trying to earn a living (albeit being in the country illegally) the true owner of the Social Security number can be penalized by having their identity compromised, needing to pay taxes on behalf of the other worker, not to mention having utilities, credit cards, and other services opened to a false identity. This form of identity theft can be quite damaging to the victim.
I applaud the efforts recognizing that it is too easy to learn the 8 digit code, a social security number, that unlocks a world of services within the United States.
The Senators are not aware of the conditions of establishing a unique biometric identifier. It needs to be collected, enrolled, validated and generated somewhere: i.e. a database. Not allowing the government to store in a secure database would cause the necessary information to be kept on commercial enterprises which are going to be less secure. Authenticating only to the card would trigger a great production of counterfeit cards that would send back a positive match; which would certainly raise the bar for fraudulent documents but not eliminate it.
Most importantly the Senators seems to overlook an important fact: If we suspect that 11 million immigrants are already in this country working illegally (let’s assume all of them have jobs) we are still talking about less than 3% of the working population. Burdening 97% may be too much for the public to bear.
Personally I favor national biometric identity cards; but let's plan for that being what it is and what it could do in terms of replacing many of the existing state and federal breeder documents such as Social Security Cards, Driver's Licenses, Sheriff's IDs, and a host of others. Creating something that would enable more services, rather than restrict for a few, is the right way to go and gain public acceptance. Dare I say, even enthusiasm.
Wednesday, March 24, 2010
Friday, February 26, 2010
Fake fingers from China
These images are from internet-based businesses in China. They are advertising a series of finger attachments complete with random fingerprints. The purpose is to provide people with a method of defeating fingerprint identification ranging from time/attendance to border access. The price is $15 US per unit.
I have no idea what level of sales have been achieved or what level of usage is occurring. It’s interesting that the average person on the street can obtain the product. It makes me wonder how far state-sponsored efforts have progressed.
The image of the simpler wrap shows a method that claims to pass liveness testing. I cannot be for certain if any of the products would spoof modern readers although that is clearly the intent. A person could slip on the fingers and then use a fingerless-glove, bandages, or something else to hide the prosthetic.
Like pirating, we are starting to see the escalation between security and countermeasures.
I have no idea what level of sales have been achieved or what level of usage is occurring. It’s interesting that the average person on the street can obtain the product. It makes me wonder how far state-sponsored efforts have progressed.
The image of the simpler wrap shows a method that claims to pass liveness testing. I cannot be for certain if any of the products would spoof modern readers although that is clearly the intent. A person could slip on the fingers and then use a fingerless-glove, bandages, or something else to hide the prosthetic.
Like pirating, we are starting to see the escalation between security and countermeasures.
Monday, February 15, 2010
New Hampshire bill would ban biometrics in ID cards
Acting out of concerns for residents' privacy, the New Hampshire Legislature is considering a bill that would ban the use of biometrics data in identification cards. But at least two trade groups oppose the legislation, saying biometrics technology has a number of security benefits, namely around ID management. The bill would prohibit biometrics data, including fingerprints, retinal scans and DNA, from being used in state or privately issued ID cards, except for employee ID cards. In addition, it would ban the use of ID devices or systems that require the collection or retention of an individual's biometric data. Under the bill, biometric data would also include palm prints, facial feature patterns, handwritten signature characteristics, voice data, iris recognition, keystroke dynamics and hand characteristics.
http://www.scmagazineus.com/new-hampshire-bill-would-ban-biometrics-in-id-cards/article/163509/
Denying an entire technology, even a disruptive one, seems a little draconian. I agree that any biometric implementation should have privacy concerns woven in from the start. Perhaps the legislation should focus on assuring protection, rather than prohibiting technology. I am sure that many of the residence of New Hampshire would want a new Passport (with biometric enabled microchip) or perhaps those who have trouble remembering their bank PINS could use an alternative (biometric).
http://www.scmagazineus.com/new-hampshire-bill-would-ban-biometrics-in-id-cards/article/163509/
Denying an entire technology, even a disruptive one, seems a little draconian. I agree that any biometric implementation should have privacy concerns woven in from the start. Perhaps the legislation should focus on assuring protection, rather than prohibiting technology. I am sure that many of the residence of New Hampshire would want a new Passport (with biometric enabled microchip) or perhaps those who have trouble remembering their bank PINS could use an alternative (biometric).
Labels:
biometrics,
ID cards,
Identity Management,
privacy,
Smartcards
Friday, February 5, 2010
Tapes used to spoof fingerprint readers. Need for film detection for fingerprint readers
Tapes used to spoof fingerprint readers. Need for film detection for fingerprint readers
Two South Korean women have managed to fool Japan’s expensive biometric border-control system by using special tapes on their fingers; the invisible tape carries the finger prints of another person, and the South Korean broker who supplied the tape also provided false passports to go with it.
You can read about the incident here: http://homelandsecuritynewswire.com/japanese-biometric-border-fooled-tape
Many fingerprint readers now have some liveliness testing incorporated. In its simplest form this would be an observer confirming that the presented finger belongs to the applicant. There are electronic liveliness checks as well such as detection of blood vessels, temperature, and even perspiration changes along the fingerprint ridges.
Much has already been done for counterfeit iris detection based on texture analysis to detect when individuals are wearing contact lenses. In summary the 'ridge' of the lens is detected; although there are many ways to find this including the use of the infrared spectrum. Links on iris detection are as follows:
1) figment.csee.usf.edu/~sfefilat/data/papers/TuBT6.1.pdf
2) www.nd.edu/~kwb/RingBowyerBTAS_2008.pdf
It seems that similar research needs to be incorporated into fingerprint scanners, to deter the circumvention by use of tapes. Tape ridges, or their material, could be detected through an application of additional spectrum analysis instead of pure pressure sensors currently available in most fingerprint reader models.
Labels:
circumvention,
fingerprint,
iris,
liveliness,
spoofing
Monday, February 1, 2010
Fun news for fingerprinting
Priest checks fingerprints for mass attendance
Reuters Fri Jan 29, 11:46 am ET
WARSAW (Reuters) – A Polish priest has installed an electronic reader in his church for schoolchildren to leave their fingerprints in order to monitor their attendance at mass, the Gazeta Wyborcza daily said on Friday.
The pupils will mark their fingerprints every time they go to church over three years and if they attend 200 masses they will be freed from the obligation of having to pass an exam prior to their confirmation, the paper said.
The pupils in the southern town of Gryfow Slaski told the daily they liked the idea and also the priest, Grzegorz Sowa, who invented it.
"This is comfortable. We don't have to stand in a line to get the priest's signature (confirming our presence at the mass) in our confirmation notebooks," said one pupil, who gave her name as Karolina.
Poland is perhaps the most devoutly Roman Catholic country in Europe today and churches are regularly packed on Sundays.
(Reporting by Kuba Jaworowski, editing by Paul Casciato)
Reuters Fri Jan 29, 11:46 am ET
WARSAW (Reuters) – A Polish priest has installed an electronic reader in his church for schoolchildren to leave their fingerprints in order to monitor their attendance at mass, the Gazeta Wyborcza daily said on Friday.
The pupils will mark their fingerprints every time they go to church over three years and if they attend 200 masses they will be freed from the obligation of having to pass an exam prior to their confirmation, the paper said.
The pupils in the southern town of Gryfow Slaski told the daily they liked the idea and also the priest, Grzegorz Sowa, who invented it.
"This is comfortable. We don't have to stand in a line to get the priest's signature (confirming our presence at the mass) in our confirmation notebooks," said one pupil, who gave her name as Karolina.
Poland is perhaps the most devoutly Roman Catholic country in Europe today and churches are regularly packed on Sundays.
(Reporting by Kuba Jaworowski, editing by Paul Casciato)
Saturday, January 30, 2010
Secure Credentialing in Concert with RFID
Secure personal identification combined with the tracking capabilities of RFID will soon transform secure shipping and cargo transport. Through the use of secure and speedy authentication, organizations can add extra layers of security that overcome the current holes in RFID implementations, and allow a greater acceptance from the public for implementation. Coupling cargo tracked with RFID and the capabilities of a credential with Secure ID capabilities will mean that all cargo and all personnel are accounted for and linked together in real time. Administrators will know the last authorized handler of each piece of cargo, where the cargo is in real time, detect deviations en route, and be assured that only those people who are authorized can access sensitive freight, tracking people’s actions and cargo location together.
Shared technologies will allow:
Data Privacy Protection:
Linking People to Cargo
Local Authorization for Inventory Movements:
Package- and User-based Physical Access:
Scenarios where this combination of technologies may soon be applied include HAZMAT drivers, weapons transport, banking records and even passports. Credentialing systems are already underway for the major ports of the world and will be used to link card to identity to ship to cargo, where cargo is monitored already with RFID.
In the future, the drivers can also be linked to the truck, and the truck to the cargo. All this can be tracked through GPS vehicle tracking. The future world of secure shipping will allow owners of cargo to track in real time the exact location of crate, each driver, each truck, and be sure that they are all supposed to be traveling together.
Shared technologies will allow:
Data Privacy Protection:
- Users can have differentiated access to read the information on the RFID tag based on privileges held in their card. RFID tags created according to scramble number schemes can be used in concert with smart card capabilities; only those tags to which users have been given “rights” will be seen, added to cargo lists, or be shipped to certain geographic locations. This allows individuals to control data collection and sharing while preventing covert tracking and profiling applications based on package content.
Linking People to Cargo
- Cards used for access to vehicles or facilities can be matched against cargo RFID to automatically reconcile cargo itineraries against known cargo and personnel movements. By linking people’s locations with RFID cargo locations, administrators can reduce fraud and determine the who, when and where if any package loss occurs.
Local Authorization for Inventory Movements:
- Smart cards can act as secure, digital lists of instructions, inventory, and package recipients, allowing people who sign for packages to be verified through the use of PKI, biometrics and other digital means. If RFID packages are moved by an unauthorized person, future privileges of that user can be locked, and flags can be raised to administration.
Package- and User-based Physical Access:
- Biometric IDs, RFID and GPS position transmitters will work together to allow secure access only to authorized persons with authorized cargo at only intended destinations. Through biometric authentication to truck ignition systems, administrators will be assured that trucks stay within specified corridors on their way to the cargo’s intended destination, know who is driving, and even remotely disable and lock trucks that deviate, have wrong users or wrong cargo
Scenarios where this combination of technologies may soon be applied include HAZMAT drivers, weapons transport, banking records and even passports. Credentialing systems are already underway for the major ports of the world and will be used to link card to identity to ship to cargo, where cargo is monitored already with RFID.
In the future, the drivers can also be linked to the truck, and the truck to the cargo. All this can be tracked through GPS vehicle tracking. The future world of secure shipping will allow owners of cargo to track in real time the exact location of crate, each driver, each truck, and be sure that they are all supposed to be traveling together.
Friday, January 29, 2010
Haiti, Hurricane Katrina, and Identity Management
The tragedies of Haiti have me pulling up an article I wrote regarding identifying those affected by crisis. Originally published as part of the BearingPoint "IDM Insider" July, 2006
Through the use of common credentialing and identification techniques, much of the fraud that occurred during Hurricane Katrina could have been avoided. For example, debit cards issued to hurricane victims could have been activated only after individuals had passed an identity authentication and verification of ownership and occupancy process. The identity solutions should take care not to cause undo intrusion to the participants, but yet be complete enough to verify their identity and link with adjudication for assistance decisions. Such a solution would be upgraded from each deployment so that there would be consistent improvement between deployments.
Below is a list of common fraud scenarios identified by the GAO, and the corresponding IdM solutions that could be implemented to deter, identify and counteract such behavior.
KATRINA AND IDENTITY MANAGEMENT
As documented by the Washington Post, over $1.4 Billion was provided in assistance to fraudulent Hurricane Katrina victims. While it is imperative to provide people with assistance as quickly as possible during a crisis, this must be balanced by assuring that support is properly disseminated among the true victims and proper oversight of taxpayer dollars are performed. Such control is needed because frequently the damage caused by malfeasance is far greater than the cost of implementation. Through the use of common credentialing and identification techniques, much of the fraud that occurred during Hurricane Katrina could have been avoided. For example, debit cards issued to hurricane victims could have been activated only after individuals had passed an identity authentication and verification of ownership and occupancy process. The identity solutions should take care not to cause undo intrusion to the participants, but yet be complete enough to verify their identity and link with adjudication for assistance decisions. Such a solution would be upgraded from each deployment so that there would be consistent improvement between deployments.
Below is a list of common fraud scenarios identified by the GAO, and the corresponding IdM solutions that could be implemented to deter, identify and counteract such behavior.
- Fraud Committed: Use of different Social Security numbers for the same person - Identity Management Redress: Many social security validation programs exist and could be incorporated for validity of issuance and ownership as well as single use within the program. A more intricate program could compare biometric information for uniqueness of the registered individuals such as done through systems that incorporate 1:N matching.
- Fraud Committed: Identity theft of others, specifically those in prison - Identity Management Redress: Since the crisis was localized, each State could have provided a “qualification” list from their local DVMs as an initial method for address verification and acquiring a picture ID. Since state and federal prisoners’ data was stolen and used to apply for assistance, it is reasonable to check future crisis registrants against such data for exclusion.
- Fraud Committed: Addresses outside of assistance area, and bogus address used - Identity Management Redress: Combining a mapping software with location tabs to verify physical location of the damaged address would provide the needed geography and legitimacy assistance. Such software is easily found and integrated with, Google maps is an excellent example.
- Fraud Committed: Registrants not occupying provided address - Identity Management Redress: Address Verification System are commonly used for credit and finance applications that can be integrated as part of a verification system.
Labels:
Crisis,
Haiti,
Hurricane Katrina,
Identity Management
Subscribe to:
Posts (Atom)