Dutch TV programme Nieuwslicht (Newslight) is claiming that the security of the Dutch biometric passport has already been cracked. As the programme reports here, the passport was read remotely and then the security cracked using flaws built into the system, whereupon all of the biometric data could be read.
Passports and Fingerprints
Passports and Fingerprints - whereisyourdata.co.uk 1.6.2008
In 2008, the government has now delayed the scheme until 2012, with the costs increasing again, following the publishing of the latest Identity & Passport Service cost report for the ID scheme. The report claims that the costs will reach nearly 1 billion by 2017…
REAL ID Implementation Review: Few Benefits, Staggering Costs
ארגון הפרטיות האמריקאי EPIC פרסם דו"ח חדש על פרויקט "Real ID" של הממשל האמריקאי תחת הכותרת: "REAL ID Implementation Review: Few Benefits, Staggering Costs".
.
Technical experts familiar with the challenges of privacy protection and identification presented the Department of Homeland Security with a variety of recommendations that would have minimized the risks of the REAL ID system. The DHS made some modifications, but left the essential system in place. As REAL ID currently stands, the costs are many and the benefits are few. Public opposition to implementation is understandable."
.
"REAL ID SYSTEM CREATES NEW NATIONAL SECURITY RISKS - ...The Department of Homeland Security says in the final rule that it will be “significantly more difficult,” but not impossible, “for an individual to use a false name or provide fraudulent documents to obtain an identification.” This is the reason that any national identification system is fundamentally flawed: Individuals are told to “trust” the national ID card, but it is still possible to create a fake card, so one cannot rely on the national identification system to “prove” an individual is who she says. Contrary to the Department of Homeland Security’s claims, this system harms our national security by creating another “trusted” path for criminals to exploit...
.
The REAL ID national identification system would harm rather thanprotect privacy and security, and such a system would exacerbate the country’s growing identity theft problem. It decreases security to have a centralized systemof identification, one ID card for many purposes, as there will be a substantialamount of harm when the card is compromised.
.
A system of decentralized identification reduces the risks associated withsecurity breaches and the misuse of personal information. Technological innovation can enable the development of context-dependent identifiers. Adecentralized approach to identification is consistent with our commonsenseunderstanding of identification. ... These context-dependentusernames and passwords enable authentication without the risk of a universalidentification system. That way, if one number is compromised, all of thenumbers are not spoiled and identity thieves cannot access all of your accounts.All of your accounts can become compartmentalized, enhancing their security
.
The final rule includes few protections for individual privacy and security in its massive national identification database. It harms national security by creating yet another “trusted” credential for criminals to exploit. The Department of Homeland Security has faced so many obstacles with the REAL ID system that the agency now plans an implementation deadline of 2017 – nine years later than the 2008 statutory deadline. It is an unfunded mandate that would cost billions, with the burden ultimately being placed on the individual taxpayer.
.
Technical experts familiar with the challenges of privacy protection and identification presented the Department of Homeland Security with a variety of recommendations that would have minimized the risks of the REAL ID system. The DHS made some modifications, but left the essential system in place. As REAL ID currently stands, the costs are many and the benefits are few. Public opposition to implementation is understandable."
.
פורצים את ההצפנה של כרטיסים חכמים
12.3.08 Dan Goodin The Register- חוקרי בטיחות מידע מצאו דרך לפרוץ ולזייף בתוך דקות הצפנה של כרטיסים חכמים, המשמשים כאמצעי כניסה לאתרים ומוסדות שונים.
"If you want to get into a high-security building, spending a matter of days is OK. Now, it doesn't take days; it takes minutes for subways and military installations alike..."
"If you want to get into a high-security building, spending a matter of days is OK. Now, it doesn't take days; it takes minutes for subways and military installations alike..."
.
פרופסור למערכות מידע בבריטניה: ת"ז ביומטרית היא גניבת הזהות האולטימטיבית
7.3.08 – Time OnLine, פרופ' איאן אנג'ל, מומחה למערכות מידע ב-London School of Economics: מערכות מחשב נכשלות תמיד ומאגר לאומי יעשה זאת "big time".
פרוייקט תעודת הזהות כרוך במערכות מחשב ענקיות ומורכבות, הרבה יותר ממערכת המחשב של משרד הבריאות שדלפה לאחרונה בבריטניה – זוהי הקטסטרופה הבאה. הפוליטיקאים נאיבים מדי כדי לחשוב שלא יהיו בעיות, שהמאגר יהיה מאובטח לחלוטין בגלל שהוא ביומטרי. אבל הניסיון, לרבות דוגמאות מהתקופה האחרונה, מלמד שמערכות מחשב ענקיות שכאלה נכשלות שוב ושוב. מאגר ביומטרי בהיקף לאומי יהיה מטרה אולטמיטיבית ל"אולמפיידת ההאקרים".
מלבד כשלים טכנולוגיים שקורים בכל מאגר, תמיד נמצאים מבין העובדים שמטפלים בו מעטים שמעבירים מידע – 80% מכשלי האבטחה אינם קורים בגלל האקרים אלא בגלל עובדים מושחתים. ובמקרה של מאגר ביומטרי, המאגר יהפוך למקור לגניבות זהות, פעילות טרוריסטית.…
"Paradoxically, you only agreed to register to protect yourself from “identity theft”, and instead you find yourself victim of the ultimate identity theft - the total loss of control over your identity.
Errors won't just happen by accident. It's possible to imagine that workers on the ID database will be corrupted, threatened or blackmailed into creating perfectly legal ID cards for international terrorists and criminals. Then the ID card, far from eliminating problems, will be a one-stop shop for identity fraud; foreign terrorists, illegal immigrants will be waived past all immigration checks…
At a recent Ditchley Park conference on combating organised crime, a persistent warning from the law enforcement authorities was that criminal gangs had placed “sleepers” in financial sector companies, and they were just waiting for the one big hit. The perpetrators of 80 per cent of all computer security lapses are not hackers, but employees. Cryptographic systems don't help if the criminal has been given the keys to the kingdom. Why should the ID centre be immune, especially when there will be nearly 300 government departments logging in. Furthermore, the register will be the No 1 target for every hacker on the planet: the Olympic Games of hacking. …"
Errors won't just happen by accident. It's possible to imagine that workers on the ID database will be corrupted, threatened or blackmailed into creating perfectly legal ID cards for international terrorists and criminals. Then the ID card, far from eliminating problems, will be a one-stop shop for identity fraud; foreign terrorists, illegal immigrants will be waived past all immigration checks…
At a recent Ditchley Park conference on combating organised crime, a persistent warning from the law enforcement authorities was that criminal gangs had placed “sleepers” in financial sector companies, and they were just waiting for the one big hit. The perpetrators of 80 per cent of all computer security lapses are not hackers, but employees. Cryptographic systems don't help if the criminal has been given the keys to the kingdom. Why should the ID centre be immune, especially when there will be nearly 300 government departments logging in. Furthermore, the register will be the No 1 target for every hacker on the planet: the Olympic Games of hacking. …"
תוויות:
אבטחת מידע,
בריטניה,
זיוף וגניבת זהות,
חוסר אמינות,
מאגר,
מומחי IT,
מחטף והטעייה
ID cards are the ultimate identity theft
Computer systems always fail - and the national database will do so big time
Angell, I ID cards are the ultimate identity theft The Times, March 7, 2008
Ian Angell is Professor of Information Systems at the London School of Economics
The ID project is one of the biggest computer systems envisaged - far more complex than the failing NHS system. And it's another disaster waiting to happen. Still the politicians naively claim there will be no problems: it will be totally secure because of biometrics.
The only property that all systems have in common is that they fail. And the bigger the system - 60 million entries on a compulsory ID card database - the greater the opportunity of failure.
Errors won't just happen by accident. It's possible to imagine that workers on the ID database will be corrupted, threatened or blackmailed into creating perfectly legal ID cards for international terrorists and criminals. Then the ID card, far from eliminating problems, will be a one-stop shop for identity fraud; foreign terrorists, illegal immigrants will be waived past all immigration checks.
שגריר ארה"ב הגיש לאולמרט תלונה על מכרז התעודות החכמות - גלובס 16.12.07
לפני מספר שבועות בוטל זו הפעם השנייה בתוך כ-5 שנים מכרז תעודות הזהות החכמות של משרד הפנים. במסגרת המכרז הייתה אמורה להיבחר החברה שתספק את התעודות החכמות לתושבי ישראל…HP עומדת לפנות לערכאות משפטיות ולגופי פיקוח מקומיים אחרים (משטרה ומבקר המדינה) לגבי ההתנהלות במכרז. כדאי להבין, מקרה בו חברה בינלאומית לא מרוצה מהתנהלות מכרז ציבורי במדינת ישראל, הוא דבר סטנדרטי, כמעט מובן מאליו. אבל נקיטת אמצעים אגרסיביים לבירור מה קרה סביב המכרז, זה חידוש גדול.
תעודות הזהות החכמות אמורות לפעול וגם להיראות כמו כרטיס אשראי. התעודה עשויה ממלבן פלסטיק קשיח שבו ישולב שבב אלקטרוני, עליו מקודדים פרטים של המחזיק שמאפשרים זיהוי שלו מול מערכות מחשוב ציבוריות. באמצעות התעודה החכמה יוכלו אזרחי ישראל לגשת לשירותים שונים של ממשל זמין, להזדהות מול הרשויות באמצעות מנגנון אימות וזיהוי (חתימה אלקטרונית), לשלם מסים, לחדש רישיון נהיגה ועוד פעולות רבות אחרות. חלק ניכר מהמורכבות בתעודה קשור לאבטחה, גם מצד מכת זיוף תעודות הזהות הרגילות, וגם כדי לאפשר זיהוי אמין של המשתמש. כדי לאפשר זאת עובדים הכרטיסים החכמים כהתקני אבטחה, המותאמים אישית באמצעות נתונים ספציפיים לבעלים. האבטחה מסופקת באמצעות זיהוי המשתמש (נתונים אישיים, כולל תמונה ו/או זיהוי ביומטרי)…
ברוס שנייר על הסכנה שבפרוייקט Real ID
ברוס שנייר, מומחה לאבטחת מידע: Real-ID: Costs And Benefits
.
הבעיה הראשונה היא הכרטיס עצמו. לא משנה כמה מאובטח הוא יהיה - יזייפו אותו. אפשר להעלות את המחיר של הזיוף אבל לא להפוך אותו לבלתי אפשרי.
.
.
הבעיה הראשונה היא הכרטיס עצמו. לא משנה כמה מאובטח הוא יהיה - יזייפו אותו. אפשר להעלות את המחיר של הזיוף אבל לא להפוך אותו לבלתי אפשרי.
.
סכנות הבטיחות של המאגר הן עצומות. מדעני מחשב אינם יודעים כיצד לשמור מאגר עצום שכזה מפני פריצות מבחוץ ומבפנים. ואפילו אם יכולנו לפתור את הבעיות הללו עדיין לא נזכה בביטחון רב. ההסתמכות על ת"ז מבוסס על מיתוס בטיחות מסוכן, שאילו רק ידענו מי הוא מי יכולנו לשים ידינו על "הרעים" - למנוע מהם לעלות על מטוסים ולהסתובב חופשיים. אבל הרעיון שאכן נדע הוא מגוחך ולכן אנו מבקשים להסתמך על תעודות זהות, וזה מגוחך לא פחות. ההסתמכות על סיווג ופרופיילינג של אנשים יוצר מצב שבו אנשים רבים שאינם ראויים לאמון מסווגים כאמינים. מבצע הפיצוץ באוקלהומה, הטרוריסטים בתחתית של לונדון ומרבית הטרוריסטים של 9/11 לא היו קשורים בעברם לטרור. גורמים מסוכנים יכולים גם לגנוב זהות, ולכן הפרופיילינג לפי זהויות עלול להביא פחות ביטחון. מרבית האנשים שיתאימו לפרופילים "השליליים" אינם טרוריסטים ולכן נקבל פעמים רבות "false alarm", בזבוז משאבים חקירתיים ובטיחותיים ופגיעה באנשים חפים מפשע. וכך לגבי גנבות זהות פליליות - מי שיצליח לגנוב זהות יצליח לבצע בחסותה מעשי מרמה רבים יותר...
.
"A centralized ID system is a far greater security risk than a decentralized one with various organizations issuing ID cards according to their own rules for their own purposes. Security is always a trade-off; it must be balanced with the cost. We all do this intuitively. Few of us walk around wearing bulletproof vests. It’s not because they’re ineffective, it’s because for most of us the trade-off isn’t worth it. It’s not worth the cost, the inconvenience, or the loss of fashion sense.
.
Real ID is another lousy security trade-off. It’ll cost the United States at least $11 billion, and we won’t get much security in return. The report suggests a variety of measures designed to ease the financial burden on the states: extend compliance deadlines, allow manual verification systems, and so on. But what it doesn’t suggest is the simple change that would do the most good: scrap the Real ID program altogether. For the price, we’re not getting anywhere near the security we should..."
.
תוויות:
ארה"ב,
ביטחון,
זיוף וגניבת זהות,
חוסר אמינות,
יעילות וחלופות,
מאגר,
מומחי IT,
עלויות,
פרופיילינג
החלטת ממשלה מספר בק/12 מיום כ"ט בחשון התשס"ז-20.11.2006
החלטה מספר בק/12 מיום כ"ט בחשון התשס"ז-20.11.2006
יו"ר ועדת השרים פותח ומפרט את ההיבטים השונים של שילוב המרכיבים הביומטריים בתעודות הזהות ובדרכונים.
יו"ר הצוות הבינמשרדי לעניין השימוש ביישומים ביומטריים מציג תמונת מצב לגבי הטיפול בנושא בשירות המדינה.
השר לביטחון הפנים מתאר את השימוש בטכנולוגיות מתקדמות ואמצעים ביומטריים בדרכונים במדינות שונות בעולם ובמיוחד בארצות הברית. מדגיש את החשיבות והצורך לפעול ללא דיחוי לשילוב אמצעים ביומטרים במסמכים הרשמיים המונפקים על ידי משרד הפנים.
נציגי משרד הביטחון, משרד האוצר, משרד החוץ, משטרת ישראל, משרד המשפטים, המטה ללוחמה בטרור, שירות הביטחון הכללי, המוסד למודיעין ולתפקידים מיוחדים, רשות שדות התעופה ומשרד הפנים מציגים את עמדתם בעניין המשמעויות השונות לשילוב מרכיבים ביומטריים בתעודות זהות ובדרכונים.
יו"ר ועדת השרים מסכם:
א. נושא הזיהוי הביומטרי הוא בעל חשיבות לאומית עליונה. השימוש בטכנולוגיות מתקדמות בתעודות זהות ובדרכונים הוא חשוב והכרחי, ויש להתקדם בעניין זה בהתאם להתפתחויות ולקצב הנהגת השימוש בזיהוי ביומטרי בעולם הרחב.
ב. הנושא נוגע למשרדי הממשלה וגורמים אחרים בשירות הציבורי, וכולל היבטים ומרכיבים שונים, לרבות הגדרת צרכי המשתמשים, שינויי חקיקה, הקצאת המשאבים הנדרשים (הנפקת התעודה שתיקבע ומאפיניה, ופריסת ציוד הקצה לקריאתה), שיפור השירות לאזרח ומניעת זיוף והתחזות לשם ביצוע פעולות פליליות, מירמה ופגיעה בביטחון המדינה.
ג. מודיע כי יזמן ללשכתו את אנשי המקצוע העוסקים בנושא בגופים הממשלתיים השונים, לשם גיבוש מסמך מסכם, שיכלול את עיקרי המדיניות לשילוב מרכיבים ביומטריים בתעודות זהות ובדרכונים, ההקצאה התקציבית הנדרשת ודרך מימונה, תיקוני החקיקה הנדרשים, דרכי הפעולה, סדרי העדיפויות ולוח זמנים לביצוע.
המסמך המפורט שיגובש יובא לאישור ועדת השרים.
יו"ר ועדת השרים פותח ומפרט את ההיבטים השונים של שילוב המרכיבים הביומטריים בתעודות הזהות ובדרכונים.
יו"ר הצוות הבינמשרדי לעניין השימוש ביישומים ביומטריים מציג תמונת מצב לגבי הטיפול בנושא בשירות המדינה.
השר לביטחון הפנים מתאר את השימוש בטכנולוגיות מתקדמות ואמצעים ביומטריים בדרכונים במדינות שונות בעולם ובמיוחד בארצות הברית. מדגיש את החשיבות והצורך לפעול ללא דיחוי לשילוב אמצעים ביומטרים במסמכים הרשמיים המונפקים על ידי משרד הפנים.
נציגי משרד הביטחון, משרד האוצר, משרד החוץ, משטרת ישראל, משרד המשפטים, המטה ללוחמה בטרור, שירות הביטחון הכללי, המוסד למודיעין ולתפקידים מיוחדים, רשות שדות התעופה ומשרד הפנים מציגים את עמדתם בעניין המשמעויות השונות לשילוב מרכיבים ביומטריים בתעודות זהות ובדרכונים.
יו"ר ועדת השרים מסכם:
א. נושא הזיהוי הביומטרי הוא בעל חשיבות לאומית עליונה. השימוש בטכנולוגיות מתקדמות בתעודות זהות ובדרכונים הוא חשוב והכרחי, ויש להתקדם בעניין זה בהתאם להתפתחויות ולקצב הנהגת השימוש בזיהוי ביומטרי בעולם הרחב.
ב. הנושא נוגע למשרדי הממשלה וגורמים אחרים בשירות הציבורי, וכולל היבטים ומרכיבים שונים, לרבות הגדרת צרכי המשתמשים, שינויי חקיקה, הקצאת המשאבים הנדרשים (הנפקת התעודה שתיקבע ומאפיניה, ופריסת ציוד הקצה לקריאתה), שיפור השירות לאזרח ומניעת זיוף והתחזות לשם ביצוע פעולות פליליות, מירמה ופגיעה בביטחון המדינה.
ג. מודיע כי יזמן ללשכתו את אנשי המקצוע העוסקים בנושא בגופים הממשלתיים השונים, לשם גיבוש מסמך מסכם, שיכלול את עיקרי המדיניות לשילוב מרכיבים ביומטריים בתעודות זהות ובדרכונים, ההקצאה התקציבית הנדרשת ודרך מימונה, תיקוני החקיקה הנדרשים, דרכי הפעולה, סדרי העדיפויות ולוח זמנים לביצוע.
המסמך המפורט שיגובש יובא לאישור ועדת השרים.
הירשם ל-
רשומות (Atom)
