החלטת ממשלה מספר בק/12 מיום כ"ט בחשון התשס"ז-20.11.2006

החלטה מספר בק/12 מיום כ"ט בחשון התשס"ז-20.11.2006

יו"ר ועדת השרים פותח ומפרט את ההיבטים השונים של שילוב המרכיבים הביומטריים בתעודות הזהות ובדרכונים.

יו"ר הצוות הבינמשרדי לעניין השימוש ביישומים ביומטריים מציג תמונת מצב לגבי הטיפול בנושא בשירות המדינה.

השר לביטחון הפנים מתאר את השימוש בטכנולוגיות מתקדמות ואמצעים ביומטריים בדרכונים במדינות שונות בעולם ובמיוחד בארצות הברית. מדגיש את החשיבות והצורך לפעול ללא דיחוי לשילוב אמצעים ביומטרים במסמכים הרשמיים המונפקים על ידי משרד הפנים.

נציגי משרד הביטחון, משרד האוצר, משרד החוץ, משטרת ישראל, משרד המשפטים, המטה ללוחמה בטרור, שירות הביטחון הכללי, המוסד למודיעין ולתפקידים מיוחדים, רשות שדות התעופה ומשרד הפנים מציגים את עמדתם בעניין המשמעויות השונות לשילוב מרכיבים ביומטריים בתעודות זהות ובדרכונים.

יו"ר ועדת השרים מסכם:

א. נושא הזיהוי הביומטרי הוא בעל חשיבות לאומית עליונה. השימוש בטכנולוגיות מתקדמות בתעודות זהות ובדרכונים הוא חשוב והכרחי, ויש להתקדם בעניין זה בהתאם להתפתחויות ולקצב הנהגת השימוש בזיהוי ביומטרי בעולם הרחב.

ב. הנושא נוגע למשרדי הממשלה וגורמים אחרים בשירות הציבורי, וכולל היבטים ומרכיבים שונים, לרבות הגדרת צרכי המשתמשים, שינויי חקיקה, הקצאת המשאבים הנדרשים (הנפקת התעודה שתיקבע ומאפיניה, ופריסת ציוד הקצה לקריאתה), שיפור השירות לאזרח ומניעת זיוף והתחזות לשם ביצוע פעולות פליליות, מירמה ופגיעה בביטחון המדינה.

ג. מודיע כי יזמן ללשכתו את אנשי המקצוע העוסקים בנושא בגופים הממשלתיים השונים, לשם גיבוש מסמך מסכם, שיכלול את עיקרי המדיניות לשילוב מרכיבים ביומטריים בתעודות זהות ובדרכונים, ההקצאה התקציבית הנדרשת ודרך מימונה, תיקוני החקיקה הנדרשים, דרכי הפעולה, סדרי העדיפויות ולוח זמנים לביצוע.

המסמך המפורט שיגובש יובא לאישור ועדת השרים.

ארנון הראל - מה כה מיוחד בטכנולוגיה הביומטרית?

29.10.08: מה כה מיוחד בטכנולוגיה הביומטרית? ארנון הראל, מומחה למערכות מידע, אינו מבקש לעצור את הקידמה ואת היכולת לעשות שימושים חיוביים בביומטריה. אבל הוא מתריע על הסיכונים הכרוכים בטכנולוגיה ולקרוא לאחריות ולזהירות בשימוש בה, כך שכל מערכת מבוססת ביומטריה תכיל בתוכה מלכתחילה את האמצעים הנאותים להגנה, בקרה ושליטה, שלא יעשה בה שימוש לרעה.
.
"ישנם מצבים רבים, בחיי היום-יום, בהם הפרט דוקא אינו מעוניין להזדהות ומעדיף להשאר אנונימי; ישנם גורמים רבים, שדוקא כן מעוניינים לזהות אותו, כדי לאסוף עליו מידע, למנוע ממנו פריבילגיות, להפלות אותו, להפליל אותו, לפגוע בפרטיותו, בבטחונו האישי וברכושו ולחשוף אותו לפרסום שלא ביקש. ואז חוסר האפשרות להפטר מהאצבע או העין או הפרצוף היא דוקא חסרון ואילו היכולת להשמיד או להחליף את התעוד המזהה או לשכוח את הסיסמה מהווים דוקא יתרון…
.
בעבר הלא רחוק נהננו מהעובדה שהזכרון האנושי ויכולות עיבוד המידע היו מוגבלים ואנו כפרטים יכולנו להטמע בהמון. ההתקדמות הטכנולוגית שהושגה (ועוד תושג) מאפשרת יכולות אגירה, אחזור, שילוב והצלבה, חקירה ואימות אדירות, שלא היו קיימות בעבר. בנית וניהול מאגרי מידע אודות אנשים הפכו להיות עסק כלכלי עצום ומשימה שלטונית ראשונה במעלה, וכיוון ש-"מידע הוא כוח" - הם גם מהווים מקור עצום של כוח ומוקד של אינטרסים הן לגורמים העסקיים והן לגורמי הממשל…
.
המשמעות של פגיעה בבסיס נתונים ביומטרי הנה דרמטית מעבר לכל פגיעה בבסיס נתונים אחר. סוגי נזק מסוימים אי אפשר לשקם בדרכים המקובלות. בסיס נתונים המבוסס על סיסמאות שנפגע - ניתן לבחור סיסמה אחרת. בסיס נתונים ביומטרי שהשתבש - יש קושי גדול לשחזר אותו… במקרה של מידע ביומטרי שהגיע לידיים הלא נכונות שוב אי אפשר להחזיר את הגלגל לאחור ולתקן את הנזק. נזק מסוג זה הוא מוחלט, סופי ולאורך זמן בלתי מוגבל… מסירת מידע ביומטרי גם אינה ניתנת לביטול…
.
הביומטריה דומה במידה מסוימת לאנרגיה אטומית: יש בה הרבה תועלת אבל אם היא תפול ליידים הלא נכונות היא עלולה להיות הרסנית. האם יש לנו אמצעי שמירה נאותים? האם חוקקנו, עיצבנו ובנינו את מנגנוני ההגנה שנדרשים כדי להגן מפני העברת מידע לא ראויה או מוצדקת בין מערכות ורשויות שונות? האם הגדרנו גבולות של זמן למשך האגירה של המידע הביומטרי ובקרות על בעורו כנדרש? האם הקמנו מנגנוני אבטחה והשמדה עצמית במקרה של השתלטות עוינת או שכשפג תוקפה של העילה לשיתוף המידע מלכתחילה? האם מערכות ההגנה והאבטחה שאנו מקימים לטובת מאגרי מידע לאומיים ובינ"ל מתקרבים בעוצמתם לאלה שאנו מקימים מול איומים לאומיים ובינ"ל אחרים שהם בעלי עוצמה ופוטנציאל דומים? "

צי'פ "מאובטח" שאינו מתעדכן - כמו תוכנת אנטי וירוס שאינה מתעדכנת

15.9.06 ברוס שנייר ב-Washington Post - דרכון משמש אותנו 10 שנים. שיטות ההצפנה והאבטחה המשוכללות ביותר שיותקנו בצ'יפ שבדרכון, מתיישנות מהר. כמה זמן הייתם מוכנים, למשל, להשתמש במחשב שלכם עם תוכנות אנט-וירוס וביטחון בלי לעדכן אותן?

"The other security mechanisms are also vulnerable, and several security researchers have already discovered flaws. One found that he could identify individual chips via unique characteristics of the radio transmissions. Another successfully cloned a chip. The State Department called this a "meaningless stunt," pointing out that the researcher could not read or change the data. But the researcher spent only two weeks trying; the security of your passport has to be strong enough to last 10 years.

This is perhaps the greatest risk. The security mechanisms on your passport chip have to last the lifetime of your passport. It is as ridiculous to think that passport security will remain secure for that long as it would be to think that you won't see another security update for Microsoft Windows in that time. Improvements in antenna technology will certainly increase the distance at which they can be read and might even allow unauthorized readers to penetrate the shielding..."

ארה"ב - דו"ח ממשלתי על עלויות והשלכות פרוייקט Real ID

1.9.06 דו"ח רשמי בארה"ב יכול ללמד על הכשלים והעלויות העצומות של פרויקט ת"ז ביומטרית. הסוכנויות שהוציאו את הדו"ח מציעות הצעות שונות כדי לבצע בצורה רציונאלית את הפרויקט. אבל מבקרים טוענים, שהבעיה היא בהנחת היסוד, לפיה חייבים להוציא אל הפועל את הפרוייקט.
.
The Real ID Act: National Impact Analysis. National Governors Association, National Conference of State Legislatures, American Association of Motor Vehicle Administrators (sep. 2006):
.
"ONCLUSION. As evidenced by this analysis, the Real ID Act presents significant operational and fiscal challenges to states and the federal government. Officials at all levels of government must also recognize the personal impact Real ID will have on individual citizens. The four major categories described in this report represent the most critical challenges facing states and consumers as the act’s implementation deadline approaches. Even with full funding and aggressive state implementation plans, however, the difficulties of complying with yet unpublished regulations by the statutory deadline of May 2008 are insurmountable.
.
Our organizations strongly believe the recommendations presented here offer reasonable and workable alternatives to help states meet the objectives of Real ID. It is our intention to work towards implementation of the act in a cost-effective and reasonable manner. Governors, state legislators and motor vehicle administrators encourage DHS to adopt regulations and Congress to pass legislation that incorporates the recommendations of this report. We also urge Congress to appropriate sufficient funds to allow states to implement the act. The objectives of Real ID are laudable, but only by working together will state and federal governments succeed in meeting the challenges presented by Real ID."
.
ראו למשל מה כותב על הדו"ח ברוס שנייר:
.
"The report suggests a variety of measures designed to ease the financial burden on the states: extend compliance deadlines, allow manual verification systems, and so on. But what it doesn’t suggest is the simple change that would do the most good: scrap the Real ID program altogether. For the price, we’re not getting anywhere near the security we should..."
.

בעיות אפשריות בתעודת זהות חכמה

18.6.06 עומר טרן "יומן אבטחה"
… אני גם קורא להקמת פורום מומחים בלתי תלוי שיבחן את השלכות פרויקט שכזה על פרטיות האזרחים, בטחונם ותועלות חברתיות וכלכליות שיש בפרויקט (אם בכלל), לעומת המחיר הצפוי (חברתי וכלכלי). בדומה לפרויקט שנעשה בבריטניה.
נושא תעודת הזהות החכמה נשמע מאוד מלהיב… למעשה, הכל יכול להיות הרבה יותר גרוע מכפי שהוא היום… אם לוקחים בחשבון שמטרת תעודת הזהות הדיגיטלית לאפשר ביצוע פעולות במרחב הוירטואלי, המשמעות תהיה שדווקא החשש מגניבת הזהויות שמהווה את התמריץ המרכזי (לכאורה) לפרויקטים מסוג זה עלול להתממש ולהותיר אותנו במצב חמור הרבה יותר מכפי שהוא כיום…

אלא שזה לא סוף הסיפור. היה ויום אחד חברות מסחריות יעשו שימוש בתעודת הזהות הדיגיטלית כאמצעי זיהוי, אנו נגלה שלא רק שקל לגנוב זהויות אלא שקשה להתכחש להן. … כתוצאה לגופים מסחריים יהיה תמריץ הרבה יותר קטן לאבטחת מערכות.

בשלב הזה אני מניח שצריך להסביר מדוע כרטיס חכם כתעודת זהות חכמה זה לא דבר כה מאובטח. הכרטיס עצמו יכול להיות מאוד מאובטח (אף כי ניתן לפרוץ גם את אלה). אלא שכרטיס חכם עושה שימוש בישות מארחת שרמת האבטחה בה אינה ידועה (מחשב המשתמש). ניתן בקלות יחסית להאזין להקלדות הקוד הסודי של הכרטיס על ידי המשתמש ובאמצעות סוס טרויאני למפות את כרטיס המשתמש למחשב מרוחק. ניתן במתקפה לא מורכבת מדי ולבטח אטרקטיבית להשתלט מרחוק על כרטיס חכם של משתמש.

עכשיו בואו נחבר את הנתון הזה עם כמות המשתמשים בשירותי בנקאות מקוונת בישראל (כמה מאות אלפים), עם כמות המחשבים הנשלטים מרחוק על ידי עבריינים… ונקבל מתכון לפשיעה מקוונת שיטתית.

המפקח על הפרטיות באירופה - שימוש בביומטריה לזיהוי אינו אמין

15.3.06 CENT : המפקח על הפרטיות באירופה טוען שהשימוש בביומטריה אינו אמין, ואינו מאפשר לאבטח את המידע ואת עיבודו.

"European Data Protection Supervisor Peter Hustinx criticized governments' fondness for biometrics to identify citizens and warned that greater interoperability of databases may have serious implications for people.
.
'Interoperability is mentioned not only in relation to the common use of large-scale IT systems but also with regard to possibilities of accessing or exchanging data, or even of merging databases,... This is regrettable since different kinds of interoperability require different safeguards and conditions.'
The supervisor also hit out at the use of biometrics as unique identifiers for European citizens within databases, saying that fingerprint or DNA identifications are too inaccurate and can facilitate the unwarranted interconnection of databases.

'It is regrettable that the protection of personal data has not been explored sufficiently as an inherent part of the improvement of the interoperability of relevant systems...'

... ".

Government accused of inflating ID fraud figures

The UK Government is facing criticism over its recent attempt to bolster plans for a national identity card scheme by releasing a report suggesting that identity fraud is costing the UK economy over £1.7 billion a year.

See:
The Government statistics (4-page / 83KB PDF)
The Silicon.com report

ID cards useless, says former MI5 chief

OUT-LAW News, 18/11/2005
The former head of MI5, Dame Stella Rimmington, warned on Wednesday that unless ID cards are made incapable of forgery they will be effectively useless, sparking calls from opposition parties for the scheme to be scrapped.
Delegated Powers and Regulatory Reform, which considers whether powers being granted to Government legislation are subject to sufficient scrutiny, concluded that Parliamentary scrutiny of the ID Card Bill needs to be enhanced. It described powers being sought in the Bill by the Home Secretary as "inappropriate."
Reports issued recently by three other Select Committees – the Joint Committee on Human Rights, the Constitution Committee and the Home Affairs Select Committee – also criticised the substance of the Government’s plans.

ID Card Bill powers need more scrutiny, says Select Committee

The Select Committee on Delegated Powers and Regulatory Reform has concluded that Parliamentary scrutiny of the ID Card Bill needs to be enhanced. It described powers being sought in the Bill by the Home Secretary as "inappropriate."
The Report thus adds to the weight of the three other Parliamentary scrutiny Committees who are expressing alarm on substantive privacy matters:
The Joint Committee on Human Rights (JCHR) Report stated last month that the database associated with the ID Card risks infringing the state's obligation to respect private and family life.

In the same week as the JCHR Report, the Constitution Committee reported that the ID Card scheme so alters the relationship between the state and the individual that the Home Secretary should not be in charge of the ID Card's database.

The Home Affairs Select Committee called the powers in relation to the database "unacceptable."
Each of the above reports contain detailed evidence from the Home Office concerning the provisions in the ID Card Bill. In most cases, the critical comments found in the various Committees' Reports show that this evidence has failed to assuage these Committees of their concerns.

Further official criticism about ID Card database and the lack of privacy

The Information Commissioner, the Joint Committee on Human Rights (JCHR) and Law Society have added to the criticism of the ID Card Bill prior to its second reading in the House of Lords next week.
JCHR's official findings that the scheme might not be compliant with the European Convention on Human Rights (ECHR), in particular the respect for private life (Article 8) and prohibition on discrimination (Article 14). In its Report published on Tuesday, the Committee detailed its concerns. The JCHR reported:
"That the establishment of the National Identity Register under the Bill was likely to lead to the compulsory retention of large amounts of personal information in respect of large groups of persons";
"That such retention, either under a compulsory scheme or under a scheme requiring registration to obtain designated documents, risked being insufficiently targeted at addressing the statutory aims to ensure proportionate interference with Article 8 rights";
"That the imposition of effective compulsory registration through designation of documents, including documents unrelated to the statutory aims, risked disproportionate interference with Article 8 rights, as well as unjustified discrimination under Article 14";
"That a system of phased-in compulsory registration risked disproportionate interference with Article 8 ECHR, and unjustified discrimination in breach of Article 8 read with Article 14 EHCR";
"That further safeguards should be included on the face of the Bill to ensure that the system of checks on the Register (clause 18) was compliant with Article 8";
"That the wide scope for disclosure of information from the Register (clauses 19-22) risked breach of Article 8 rights, in the absence of sufficient safeguards on the face of the Bill".
The Report concluded by saying "the Bill's provision for the retention of extensive personal information relating to all or large sections of the population may be insufficiently targeted to be justified as proportionate to the statutory aims and may lead to disproportionate interference with Article 8 rights".
The JCHR Report (55-page PDF)

ICO - disproportionate intrusion into individuals’ privacy

In a Position Statement placed on his website today, the Information Commissioner says:
The measures in the Bill go well beyond establishing a secure, reliable and trustworthy ID card. The measures in relation to the National Identity Register and data trail of identity checks on individuals risk an unnecessary and disproportionate intrusion into individuals’ privacy. They are not easily reconciled with fundamental data protection safeguards such as fair processing and deleting unnecessary personal information. An effective ID card can be established

דרכונים באוסטרליה - אפשר גם בלי מאגר ואפילו בלי טביעות אצבע

24.10.05 - הפרלמנט האוסטרלי סיכל מספר פעמים הצעות חוק ממשלתיות, שביקשו להכניס ביומטריה לדרכונים. באוק' 2005 פרסם משרד החוץ קווים לדמותו של הדרכון החדש. בלי טביעות אצבע. בלי מאגר. תאמינו או לא - האמריקאים אישרו. האוסטרלים לא צריכים ויזה.


..




The next generation of Australian passport—the 'ePassport' was introduced on 24 October 2005.
.
The ePassport is very similar to the previous Australian passport, differing only in having an embedded microchip in the centre page and a gold international ePassport symbol on the front cover. The chip embedded in the centre pages stores your digitised photograph, name, gender, date of birth, nationality, passport number, and the passport expiry date. This is the same information that appears on the printed information page of every passport.
//
Facial recognition technology is being introduced to coincide with the release of the ePassport. This technology will be used to improve identity verification and reduce identity-related fraud.

החלטת ממשלה מספר בק/99 מיום 11 אוק' 2005

החלטה מספר בק/99 מיום 11.10.2005
דיווח על ביצוע החלטה מספר 3506 (בק/82) מיום 7.4.2005
יו"ר ועדת השרים מסכם ומבקש כי משרד המשפטים יגיש לאישור הכנסת, מיד עם פתיחת מושב החורף הקרוב, את התיקון לחוק מרשם האוכלוסין (סיעף 25) כך שניתן יהיה לכלול צילום ממוחשב בתעודות זהות ובתעודות מסע (כפי שנהוג לפי רשיונות נהיגה).
משרד המשפטים ידווח לוועדת השרים, תוך 3 חודשים, לגבי מצב הטיפול בנושא.
יו"ר ועדת השרים מודה על סיום הכנת נוסח הצעת חוק הקמת מאגר מרשם אוכלוסין ביומטרי, התשס"ו-2005, ועל קידום הטיפול לקראת הבאתו לאישור הכנסת.
.
מעקב על ביצוע החלטה:
(עמוד 427 לדו"ח הערות רה"מ 56ב)
בשנת 2005 קיים צוות היישומים הביומטריים של הממשלה (להלן – הצוות) תשע ישיבות.
בין היתר נדונו הנושאים הבאים:
הקמת מעבדה לאומית לתקינה ביומטרית; היבטים משפטיים של שימוש במסמכי מסע ותעודות זהות ביומטריות; ביצוע פיילוט ביומטרי; יישום ביומטריה לשירות התעסוקה; יישום ביומטריה במוסד לביטוח לאומי; ביצוע פיילוט להנפקת מסמכי מסע ותעודת זהות ביומטריים; חקיקה בנושאי ביומטריה; מאגר תמונות לאומי; תקני "אצבע סרוקה" (שלושה דיונים).
.
בישיבת ועדת השרים לענייני ביקורת המדינה מיום 11.10.2005, הציג משרד הפנים הצעת תזכיר הצעת חוק, לשינויי החקיקה הנדרשים להכללת מזהים ביומטריים בדרכונים ובמסמכי מסע אחרים. התזכיר הועבר ליועץ המשפטי לממשלה.
.
בהתאם להחלטת הממשלה, הוקם צוות משנה, המורכב מנציגי משרדים שונים, להכנת פיילוט לפרויקט תעודת הזהות. הצוות קיים ארבע ישיבות, בהן נדונו, בין היתר, היקפי הפיילוט, גודל האוכלוסייה שתשתתף בו, מיקומו, חלופות טכניות אפשריות והיבטים משפטיים.
תזכיר הצעת החוק להכללת מזהים ביומטריים בדרכונים ובמסמכי מסע אחרים, הועבר כאמור ליועץ המשפטי לממשלה. המשנה ליועץ המשפטי לממשלה קיים עד כה שני דיונים, במגמה לקדם את הסדרת החקיקה הישראלי בכל הנוגע ליישומים ביומטריים. במהלך הדיונים נבחנו הניסיון בישראל ובעולם.
We The People Will Not Be Chipped-Resistance is NOT futile , we will NOT be assimilated

No REAL ID