Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

4/15/2011
02:54 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Feds Look To Private Industry To Build National ID Infrastructure

White House officially releases its National Strategy for Trusted Identities In Cyberspace (NSTIC) plan

If there was an underlying message in today's official unveiling of the White House's National Strategy for Trusted Identities In Cyberspace (NSTIC), it was that the federal government wants you to know it has no intention of building a secure authentication infrastructure itself for the Internet -- that's the role of the private sector, and the government just wants to facilitate it.

NSTIC, which was first announced by the administration last June, is basically a national strategy for trusted digital identities, and a nationwide, federated identity infrastructure aimed at replacing the increasingly precarious username-and-password model. NIST was named late last year as the lead agency for coordinating the program.

The goal is an ecosystem for users and organizations to conduct online transactions securely and privately and to ensure the identities of all parties are trusted.

Andy Ozment, White House director for cybersecurity policy, said today in a press briefing that the NSTIC aims to accomplish four things: to protect consumer privacy on the Internet; to protect consumers from identity theft and online fraud; to drive economic growth by moving more services online that are currently limited to "brick-and-mortar"; and to create a platform for new and innovative services online.

"Passwords are easily broken and extremely hard to remember," Ozment says. "And nobody knows you're a dog on the Internet."

Proving users are who they say they are on the Internet is difficult to do today, he says.

Although cybersecurity coordinator Howard Schmidt last year reiterated that a national ID card was not on the table, administration officials again emphasized that there will be no national identity card, and that the main change to the new NSTIC draft issued today is that it shows that private industry will build it.

"We put out a public draft in June, which is unusual for a national strategy. But it had to be real coordination between public and private entities," said Jeremy Grant, senior executive adviser of ID management at the National Institute of Standards and Technology (NIST), in the briefing today. "We've gotten great feedback that we've since incorporated into the draft.

"The real clarity here is on the role of the private sector leadership ... I do think the most prominent change here is how it's clear that the private sector is in the lead here," Grant said.

But the missing link is just who will issue these new digital credentials. Avivah Litan, vice president and distinguished analyst with Gartner, says that's a major hurdle to the NSTIC. "It's great that you have the White House and Howard Schmidt behind this concept. But who's going to issue the credentials, and what's the liability equation? No one is stepping up to that role," Litan says.

There's plenty of federated identity technology out there today, she says. "No one wants to be the issuing identity provider," Litan says. "Until we get that, these systems are going to sit there. You've got to have a business case for it."

Other countries with national identity programs do so via the government or banks, for instance, she says.

While several vendors are already on board to support the NSTIC program in some way, including executives from Google and PayPal, as well as the Center for Democracy and Technology and the American Bar Association Identity Management Legal Task Force, some security vendors have their reservations, especially when it comes to privacy.

"Our company's mission has always been to reduce identity theft by letting people find and protect personally identifiable information. To the extent NSTIC reduces the use of Social Security numbers in the marketplace, we support it. However, to the extent it creates new opportunities for identity fraud, we suggest improvements and regulations. Without proper regulatory safeguards, NSTIC may do more harm than good," says Todd Feinman, CEO of Identity Finder. "We look forward to helping the Department of Commerce implement smart policy that will protect consumer privacy."

Meanwhile, NIST plans to host NSTIC workshops starting in September, and to help launch pilot programs in 2012.

The full NSTIC document is available for download here (PDF).

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25137
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via the alert_name or alert_message parameter to the /a...
CVE-2020-25138
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via /alert_check/action=delete_alert_checker/alert_test...
CVE-2020-25139
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via la_id to the /syslog_rules URI for delete_syslog_ru...
CVE-2020-25140
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur in pages/contacts.inc.php.
CVE-2020-4531
PUBLISHED: 2020-09-25
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the sy...