National ID card systems are very complex - compulsory schemes exist in about 100 countries. Four major components are required:
- A physical card with personal information, and anti-counterfeiting measures
- A database of card numbers and identities, accessible to authorized persons
- A system to check cards against the database, such as wireless terminals
- Registration procedures to verify applicant identities
- What assets are we trying to protect?
- What are the risks to those assets?
- How well does our proposal mitigate those risks?
- What security problems does our proposal cause?
- What trade-offs would our proposal require?
- Assets? We are trying to 'prevent crime and terrorism', so there's no specific answer.
- Risks? All kinds of crime and terror
- Mitigation? The Sept 11 terrorists all showed ID - real and forged - before boarding their planes. ID cards have many failure modes: no ID card has been created which can't be counterfeited; security personal are human, so will make mistakes; there will always be innocent people without cards, making it impossible for ID to be always compulsory. The weakest point in the system will be the database: it will always contain some outdated or erroneous entries; it's impossible to have a perfect 'database of bad guys'; registration and verification can fail; biometric information can be added to counterfeit cards.
- Problems? Blind trust in the system; enables identity theft and makes it more damaging; all Government databases are subject to misuse e.g. police officers illegally checking the criminal records of their neighbours; communications between user terminal and central database can be intercepted.
- Trade-offs Combined cost of cards, databasing, registration, maintainance and terminal installations will be billions of pounds; Social costs are higher - national ID systems routinely abused; Not an effective way to spend money
Updated: Problems and trade-offs - more details.
Summary: There are no specific risks which ID cards can effectively mitigate, and they create many new, serious risks. A national ID card and database system is extremely costly both financially, and in civil liberties terms.
no subject
Date: 2005-05-25 09:28 am (UTC)http://www.itconversations.com/shows/detail119.html
no subject
Date: 2005-05-25 10:17 am (UTC)no subject
Date: 2005-05-25 02:00 pm (UTC)