Risk
6/24/2010
11:26 PM
50%
50%

White House Preparing National Online ID Plan

The proposed system for authenticating people, organizations and infrastructure on the web at the transactional level will require an identity ecosystem.

The Obama administration is set to propose a new system for authenticating people, organizations and infrastructure on the Web. The online authentication and identity management system would be targeted at the transactional level -- for example, when someone logs into their banking website or completes an online e-commerce purchase.

Making such a system effective, however, will require creating an "identity ecosystem," backed by extensive public/private cooperation, said White House cybersecurity coordinator Howard Schmidt, delivering the opening keynote speech at the Symantec Government Symposium 2010 in Washington on Tuesday.

"This strategy cannot exist in isolation," he said. "It's going to take all of us working together." Furthermore, "we should not have to dramatically change the way we do business -- this should be a natural path forward," he said.

That path forward will hinge on a new draft of the National Strategy for Trusted Identities in Cyberspace, due to be released Friday for the first time to the public, for a three-week comment period. Formerly known as the National Strategy for Secure Online Transactions, the report offers specific strategy and implementation recommendations, and may also recommend more sweeping policy and privacy changes.

The report builds on the Obama-commissioned Cyberspace Policy Review, which analyzed the government's information and communications infrastructure defensive capabilities. One of the report's recommendations was to "build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the nation."

Simply issuing a Web-friendly biometric identification card to everyone in the country, of course, wouldn't necessarily make anyone or anything more secure, including online transactions. As the report also notes, to be effective, security tools and technology must be complemented by education. "There is always a necessity to do awareness and education of the end user," said Schmidt. "But you're not trying to teach the end user how to be a security expert."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
anon9090535562
50%
50%
anon9090535562,
User Rank: Apprentice
12/10/2013 | 7:01:45 PM
Do the Politicians even understand the Problem!
Not many people carry their Passport, ID Card or Driving license around with them.

Criminals certainly don't so the system needs to be online.

 
anon9090535562
50%
50%
anon9090535562,
User Rank: Apprentice
12/10/2013 | 6:41:56 PM
Can Anyone Compete
In fact it is better than Chip & Pin which is tedious and difficult to use.

Authentication and Transaction Signing done with ease!

 
anon9090535562
50%
50%
anon9090535562,
User Rank: Apprentice
12/10/2013 | 6:38:16 PM
National Identity
A National Connected Online Photographic Identification System for Security Services such as the Police needs to be developed. Furthermore an Online Authentication System using Smartcards and Pins, a bit like chip and pin, needs to be developed in order to curb online Fraud.

 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2382
Published: 2014-11-20
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.

CVE-2014-3625
Published: 2014-11-20
Directory traversal vulnerability in Pivitol Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVE-2014-7194
Published: 2014-11-20
TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before 1.1.1 allow remote attackers to obtain sensitive information or modify data by leveraging agent access.

CVE-2014-7195
Published: 2014-11-20
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via u...

CVE-2014-8000
Published: 2014-11-20
Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCur63497.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?