Risk
6/24/2010
11:26 PM
Connect Directly
RSS
E-Mail
50%
50%

White House Preparing National Online ID Plan

The proposed system for authenticating people, organizations and infrastructure on the web at the transactional level will require an identity ecosystem.

The Obama administration is set to propose a new system for authenticating people, organizations and infrastructure on the Web. The online authentication and identity management system would be targeted at the transactional level -- for example, when someone logs into their banking website or completes an online e-commerce purchase.

Making such a system effective, however, will require creating an "identity ecosystem," backed by extensive public/private cooperation, said White House cybersecurity coordinator Howard Schmidt, delivering the opening keynote speech at the Symantec Government Symposium 2010 in Washington on Tuesday.

"This strategy cannot exist in isolation," he said. "It's going to take all of us working together." Furthermore, "we should not have to dramatically change the way we do business -- this should be a natural path forward," he said.

That path forward will hinge on a new draft of the National Strategy for Trusted Identities in Cyberspace, due to be released Friday for the first time to the public, for a three-week comment period. Formerly known as the National Strategy for Secure Online Transactions, the report offers specific strategy and implementation recommendations, and may also recommend more sweeping policy and privacy changes.

The report builds on the Obama-commissioned Cyberspace Policy Review, which analyzed the government's information and communications infrastructure defensive capabilities. One of the report's recommendations was to "build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the nation."

Simply issuing a Web-friendly biometric identification card to everyone in the country, of course, wouldn't necessarily make anyone or anything more secure, including online transactions. As the report also notes, to be effective, security tools and technology must be complemented by education. "There is always a necessity to do awareness and education of the end user," said Schmidt. "But you're not trying to teach the end user how to be a security expert."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
anon9090535562
50%
50%
anon9090535562,
User Rank: Apprentice
12/10/2013 | 7:01:45 PM
Do the Politicians even understand the Problem!
Not many people carry their Passport, ID Card or Driving license around with them.

Criminals certainly don't so the system needs to be online.

 
anon9090535562
50%
50%
anon9090535562,
User Rank: Apprentice
12/10/2013 | 6:41:56 PM
Can Anyone Compete
In fact it is better than Chip & Pin which is tedious and difficult to use.

Authentication and Transaction Signing done with ease!

 
anon9090535562
50%
50%
anon9090535562,
User Rank: Apprentice
12/10/2013 | 6:38:16 PM
National Identity
A National Connected Online Photographic Identification System for Security Services such as the Police needs to be developed. Furthermore an Online Authentication System using Smartcards and Pins, a bit like chip and pin, needs to be developed in order to curb online Fraud.

 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-2595
Published: 2014-08-31
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which all...

CVE-2013-2597
Published: 2014-08-31
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that lever...

CVE-2013-2598
Published: 2014-08-31
app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory ...

CVE-2013-2599
Published: 2014-08-31
A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption pas...

CVE-2013-6124
Published: 2014-08-31
The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary fil...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.