Avi Rubin, whose Johns Hopkins research team found major security gaps in common RFID systems earlier this year, indicated the passport technology proposed by the U.S. is fraught with danger.
Tech Industry Paper - Finding Strength Through Customer Service Poised to capitalize on an upturn in the economy, technology companies are focused on retention & service. This paper, from Convergys, provides the latest research on customer experience for B2B & B2C technology customers. Learn more.
A U.S. State Department proposal to include wireless data chips in U.S. passports has been met with a wave of criticism and concern from privacy activists and security experts who fail to see any value in the wireless technology for passports. The chips could only serve to compromise personal data and put U.S. citizens at risk, they argue.
U.S. officials with the Department of Homeland Security have tried to deflect the privacy and security concerns that have dogged radio frequency identification (RFID), calling the proposed passport technology a "contactless chip" or "contactless integrated circuit" that differs from RFID.
Privacy Concerns
Avi Rubin, director of the Johns Hopkins Information Security Institute, told TechNewsWorld that there are several technologies -- such as close-proximity passes and radio bar codes -- that are all termed RFID despite significant differences.
However, Rubin, whose Johns Hopkins research team found major security gaps in common RFID systems earlier this year, indicated the passport technology proposed by the U.S. is fraught with danger to the carriers of the high-tech documents.
"I don't think changing the name is going to change any of the privacy concerns," he said. "Whatever you call them, something with radio frequency in passports is a terrible idea. I can't see the need for wireless. I can only see negatives. I can't see any positives. I only see disadvantages to this."
Wrong Technology
The U.S. State Department and DHS, however, are pursuing use of the technology in passports and in identification cards for DHS employees. Last month, the State Department proposed passports and some other identification documents would be required to use RFID tags with personal data and even biometric information made available to customs officials with scanners.
Electronic Privacy Information Center (EPIC) policy counsel Cedric Laurant told TechNewsWorld the passport tags, which, unlike the DHS employee cards, would not be protected by encryption, would allow anyone with access to an inexpensive scanner to wirelessly identify and gather information on Americans without them knowing it.
"It's not at all the technology to use for passports," Laurant said. "It doesn't make sense to use it for that."
Laurant, who said the U.S. is pushing for the same passport technology to be adopted by other nations as well, claimed the only reason for the technology was for surreptitious surveillance of U.S. citizens by the government.
Big Brother
"There is no other explainable motive for deploying that technology," he said, adding that the wireless access could be leveraged by criminals or terrorists to identify nationalities and sensitive information. Laurant said EPIC is filing comments in opposition of the passport proposal in the next few days.
Rubin -- whose research team has started a company, Independent Security Evaluators to crack RFID systems so their makers can better secure them -- said he was actually approached by DHS regarding the passport wireless technology last year, but the department did not follow up.
Rubin said he could see the need for RFID in a shipping or delivery business such as UPS, but did not see the point of the wireless technology when citizens are passing their documents over the counter to officials when traveling.
Blinded By Technology
Officials with the DHS and State Department were not immediately available for comment on the proposed passport technology. Bill Scannell, a privacy advocate who has started the Web site www.rfidkills.com, said despite efforts to find a motive, it is unclear why the U.S. is pushing the issue.
He echoed Rubin in stating that the government appeared to be using technology for the sake of using technology and not for cost or efficiency gains.
"I think they're blinded by technology," Scannell told TechNewsWorld.
He added that the plan has been met with such strong resistance "because people see the inherent dangers in this technology."
Groups Claim Amazon Patent Targets Kids' Privacy March 15, 2005
People who log onto Amazon and buy something give up their personal
information voluntarily, explained Karen Coyle of Computer
Professionals for Social Responsibility. But "if someone sends you a gift, you haven't agreed to give up your information, so it's gathering
information about people who have not agreed to be customers."
Related Stories
Oracle Buys Identity Management Firm Oblix March 29, 2005
The company offered Oracle Identity Management as part of Oracle Application Server 10g, but it had no stand-alone solution. With the need for identity management applications on the rise, Oracle's Oblix acquisition is a good move, according to IDC's Evan Quinn.
Patent Fight Pits Former Wireless, RFID Partners March 25, 2005
Symbol won a jury award from Proxim for US$23 million in 2003 based on infringement claims involving two of the four patents Symbol is asserting against Intermec. The company is seeking an injunction preventing Intermec's use of its patented technology and damages for its prior use.
Microsoft Plans RFID Software March 09, 2005
RFID will not be a major focus for Microsoft, according to Yankee Group senior analyst Laura DiDio. "It's not going to be a first, primary line of business for them, but they're going to say, 'We're here,'" DiDio said.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.