Ditch Your Passwords? US Gov To Issue Secure Online IDs
forbes.com
forbes.com
You need this to use the online benefits and tax systems and so on.
And it works horribly.
The hassles I've seen people have running Java and so on is horrifying. And the security - or lack of it - is staggering. It basically only works under Windows and on increasing insecure legacy browser configurations and so on.
They also use some PDFs with scripts in sometimes for forms that you have to 'sign'. I don't understand why they do this, but they do.
All in all, No No NO!
1) the problems of having to teach users how to enable Java applets. Having done time on a customer support desk in a past life, I know full well that talking someone technologically inept through something like that would be hell on Earth.
2) and a point about how this idea works out less secure in practice as you're allowing 3rd party code to run natively on your machine, desensitising users to running 3rd party Java applets (or even encouraging people have the enabled to run by default). And scripts running inside PDFs are a known vector for attack as well.
I also disagree with the practice of pushing proprietary solutions which are only able to work on a single platform - which it sounds like their solutions are in-spite of Java and PDF being open and cross platform standards (I'm having to take the OPs word on that point - as I'm not a resident of the same country)
From a convenience-viewpoint, I think it works quite well, but I don't know how secure it is if an adversary is determined enough. It's basically (birth number) + (personal password) + (either a key sent to your phone or a randomly chosen PIN from a paper you've been sent through regular mail)
>> According to the recently [Dec 2012] published Kaspersky Security Bulletin 2012, Oracle Java was the most frequently exploited software by cybercriminals during the year, with Adobe Reader and Adobe Flash Player ranking in the second and third places, respectively.
http://www.kaspersky.com/about/news/virus/2012/Oracle_Java_s...
The problem I have is that I need to carry around a card reader for my credit card to get BankID working because my the credit card has the BankID signature in a chip to be able to use the software. I use the bank SEB.
If they were to mandate use of this system for, say, forum comments, I'd be worried. All they're proposing is a more secure and efficient way to identify yourself in situations where you already need to use a real identity.
Think of all the money the US taxpayers will save by not needing all that NSA gadgetry anymore! They'll just log in as you when they want to know what you're up to
The problem is that they're outsourcing identity provision - ref. "...such as banks, governments, healthcare organizations, and others..." in the linked article.
The article also (correctly) states that "The credential exchange will be designed to transmit credential information securely without knowing users’ actual identities."
This is neat, for sure, but isn't always required (how would a health care provider be useful if they didn't know who you are), and is only half of what they should be doing.
So the relying party shouldn't always need know who the user actually is, but (much more importantly) the identity provider should never need to know where the user is conducting his or her affairs.
As an example:
You're laid off at work, and need to claim benefits. You have a mortgage, and because you feel you can get a new job before you run out of savings that service the mortgage, you don't want your bank to know that you're been laid off. But guess what, your bank is your identity provider, and will know that you've logged into the jobless benefits site. So the bank flies your mortgage into the side of the mountain. No survivors, call off the search.
Providing this kind of asynchronous privacy (where, at the user's discretion, the relying party cannot determine who the user is, and the identity provider cannot determine who the relying party is) is not difficult. U-Prove is tech from Microsoft (acquired from Credentica) that does it, and is open-source.
I get that there are ways that the bank could screw if they're your identity provider. What you stated is not one of them.
Lately I've began to realize that within the next 5 years my Internet usage will be extremely minimal(if at all) unless there is some kind of huge change.
I'd rather just cancel all of my accounts on major websites than be forced use this creepy ID system.
I love that USPS, a government entity so far in the red, has the ability to award any money at all...
It seems like all the govt issuing a secure online id will do is add another unused standard to the pile without changing the behavior that makes things less secure in the first place.
http://xkcd.com/927/ sums this problem up nicely.
This is rarely, if ever, the case. I can't actually think of any technical standards whose dominance originates from a successful government mandate.
Thus proving my point. The US government has on multiple occasions attempted to propel the metric system into dominance in the United States, hand has consistently failed every time.
> Maybe the mini USB connectors used for charging mobile phones counts, too.
And yet my iPhone still has has a proprietary charging port.
Reminds me that it's also the same with A-sized paper, with basically just the US and Canada stuck with letter/legal/whatever.
I'm a bit confused about the paper sizes thing, though A4 and Letter are simply two different paper size standards.
[1] http://www.dw.de/european-commission-says-standard-mobile-ch...
This isn't the same as the government attempting to mandate standards for public use, especially with the intent to alter the way people are already using technology.
In your list, only GPS represents a technology originally used by the military, whose initial military specification still mostly describes its current function. Everything else, and especially the Internet - which grew out of a DARPA project, but certainly isn't one any longer - is either a vague category (electrical/safety standards), areas in which standards have not originated from government mandates (telephony, the Internet, time zones), or areas in which government attempts to shift standards have been demonstrable failures (metric usage in the US).
These aren't "standards" in the sense that they define the parameters for ineroperability of technology in widespread use by many disparate parties.
I doubt if they can make it stick in areas where people have a choice.
This was created by the USPS. Government agencies can't even agree on a standard to use amongst themselves. Through the public in this mess, and now the wikileaks mess and this thing ain't going anywhere.
Doesn't mean you couldn't implement your own secondary key though. Sign it with your ID and use that key for key exchange and you've defeated the escrow.
The existing system is archaic, fundamentally insecure, and horrendously broken from a UX standpoint. As far as privacy, the federal government is already an identity provider required by many services (in the form of social security numbers). I have no objection to it performing that role more securely and efficiently.
Best line of the article: "The cloud-based service follows federal guidelines to protect privacy, said SecureKey, although exactly what that means after the Snowden revelations is not clear."
Seems unlikely to fly; surely some big megacorp - or cartel of them - wants an exclusivity deal to make government approved ids.
BTW does anyone find it ironic that libertarian leaning programmers are so high in demand, and well paid, by the surveillance state.
The drugs that were consumed when they came up with this must be government issue only. Stuff's too hard for the streets..
Also, the crypto is as secure as a wet paper bag..
It's a big joke.
http://ccc.de/system/uploads/126/original/stellungnahme-dema...
Are you calling us all armchair dissidents?