Risk
4/14/2011
05:36 PM
50%
50%

White House To Release Final Trusted Identity Plan

The public-private effort to strengthen online identity management and authentication will face challenges when it comes to execution, privacy, and security.

Obama's Tech Tools
(click image for larger view)
Slideshow: Obama's Tech Tools
The White House Friday will release the final version of a national identity and authentication strategy aimed at standardizing and strengthening identity management and authentication procedures for online transactions.

The plan is the result of more than a year of effort and collaboration between the White House, industry, government agencies, and privacy advocates.

But the private sector is taking a wait-and-see approach before ruling on whether the plan will resolve a long-time problem of the multiple identities and passwords people use when making online transactions, and the threats to privacy and security they pose.

The Obama administration's National Strategy for Trusted Identities in Cyberspace (NSTIC) "addresses one of the thorniest issues facing those who want to engage in significant or sensitive online transactions: the lack of standard, interoperable, and trusted systems for proving online identity," Thomas Smedinghoff, a partner in the Privacy and Data Security practice at Wildman Harrold Allen & Dixon LLP in Chicago, said in an email. Smedinghoff has reviewed and commented on drafts of NSTIC.

U.S. Commerce Secretary Gary Locke, Chair of the National Economic Council Gene Sperling and White House Cybersecurity Coordinator Howard A. Schmidt are expected to release the plan, which has been in draft release since last June, at an event at the U.S. Chamber of Commerceon Friday.

Among other things, it will recommend changes to privacy laws, possible revisions to the liability of online identity providers, and the creation of new government offices to play a leadership role in digital identity and authentication issues.

The strategy also will design and implement what it's calling an "Identity Ecosystem," which will include comprehensive identification and authentication standards and improved definition of the rights and responsibilities of various constituencies involved in online transactions including identity providers and citizens.

The ecosystem also would create an environment in which both public and private service providers can offer people secure online credentials that can work across a range of websites.

The proposal has one security provider concerned that, if not carefully monitored or regulated, the ecosystem could "turn into a free-for-all Identity marketplace."

Identity Finder, which provides security for data used in identify theft, said if not managed properly, the ecosystem could create risks such as the opportunity for "hyper-identity theft" through the creation of powerful identity credentials; a false sense of control, privacy, and security among users; and new markets in which to commoditize human identity, according to a statement.

Others in the private sector expressed concern that the plan, while a fine idea, may not achieve its goals unless the federal government takes the swift action it's promising to enact the plan.

"Like all strategies, it will only be as good as its execution," said Mike Osburn, principal at Booz Allen Hamilton, a top federal contractor who has worked closely with the government on the plan.

He said in an email that while the industry as a whole is behind NSTIC, "The litmus test will be whether it really begins to accept private credentials as a means to offer a more secure, more convenient experience for consumers."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?