Language Selection

English French German Italian Portuguese Spanish

GAO study of RFID technology, policy seen flawed

Filed under
Security

A recently released Government Accountability Office study of radio frequency identity device security is flawed because it omits discussion of technologies and federal policies in the arena, according to smart-card industry executives.

GAO defended the report, saying it relied on information provided by other federal agencies and did not delve deep into individual RFID programs that the agencies are implementing.

The GAO report, titled Information Security: Radio Frequency Identification Technology in the Federal Government, discusses privacy and security aspects of RFID tags used for inventory control as well as contactless smart cards used to make personnel credentials. GAO issued the report May 27.

The report cites several privacy and security issues that RFID units can pose, such as "tracking an individual's movements, profiling an individual's habits, tastes or predilections and allowing for secondary uses of information." According to GAO, "While measures to mitigate these issues are under discussion, they remain largely prospective."

But as Patrick Hearn, business development director for Oburthur Card Systems of Chantilly, Va., stated, federal law, regulations and policies mandate many privacy and security protections for the use of smart cards in federal credentialing programs.

"The security measures-encryption and authentication-listed [by GAO as 'prospective'] all exist today and are incorporated into programs such as the State Department's e-passport program," Hearn wrote in an e-mail comment on the GAO report.

Hearn also cited the existence of the Federal Information Processing Standard 140-2, which applies to contactless smart cards issued to federal employees and contractors, as well as privacy and security rules mandated in the Federal Identity Management Handbook.

Hearn noted that the standards that apply to federal use of contactless smart cards mandate compliance with the Privacy Act of 1974, the e-Government Act of 2002, Office of Management and Budget memorandums relevant to the topic and National Institute of Standards and Technology standards for smart-card security and privacy.

Full Article.

More in Tux Machines

Android Leftovers

Leftovers: OSS

  • Open-source oriented RISELab emerges at UC Berkeley to make apps smarter & more secure
    UC Berkeley on Monday launched a five-year research collaborative dubbed RISELab that will focus on enabling apps and machines that can interact with the environment around them securely and in real-time. The RISELab (Real-time Intelligence with Secure Execution) is backed by a slew of big name tech and financial firms: Amazon Web Services, Ant Financial, Capital One, Ericsson, GE Digital, Google, Huawei, Intel, IBM, Microsoft and VMWare.
  • Telecom organizations boosting support for open source
    Organizational support for open source initiatives is easing the integration of platforms into the telecom world. One key challenge for growing the support of open source into the telecommunications space is through various organizations that are looking to either bolster the use of open source or build platforms based on open source specifications. These efforts are seen as beneficial to operators and vendors looking to take advantage of open source platforms.
  • Google's Draco: Another Open Source Tool That Can Boost Virtual Reality Apps
    With 2017 ramping up, there is no doubt that cloud computing and Big Data analytics would probably come to mind if you had to consider the hot technology categories that will spread out this year. However, Google is on an absolute tear as it open sources a series of 3D graphics and virtual reality toolsets. Last week, we covered the arrival of Google's Tilt Brush apps and virtual reality toolsets. Now, Google has delivered a set of open source libraries that boost the storage and transmission of 3D graphics, which can help deliver more detailed 3D apps. "Draco" is an open source compression library, and here are more details.
  • Unpicking the community leader
    Today is Community Manager Appreciation Day. Now, I have to admit, I don't usually partake in the day all that much. The skeptic in me thinks doing so could be a little self-indulgent and the optimist thinks that we should appreciate great community leaders every day, not merely one day a year. Regardless, in respect of the occasion, I want to delve a little into why I think this work is so important, particularly in the way it empowers people from all walks of life. In 2006 I joined Canonical as the Ubuntu Community Manager. A few months into my new role I got an email from a kid based in Africa. He shared with me that he loved Ubuntu and the traditional African philosophy of Ubuntu, which translated to "humanity towards others," and this made his interest in the nascent Linux operating system particularly meaningful.
  • Open Source Mahara Opens Moodle Further Into Social Learning
    Designers, managers and other professionals are fond of Open Source, digital portfolio solution Mahara. Even students are incorporating their progress on specific competency frameworks, to show learning evidence. Mahara and Moodle have a long and durable relationship spanning years, ―so much so that the internet has nicknamed the super couple as “Mahoodle“―. A recent post on Moodlerooms’ E-Learn Magazine documents the fruitful partnership as it adds value to New Zealander Catalyst IT’s offerings.
  • U.S. policy on open source software carries IP risks [Ed: Latest FUD from law firm against Free software as if proprietary software is risk-free licensing-wise?]

Openwashing and EEE

Q&A with Arpit Joshipura, Head of Networking for The Linux Foundation

Arpit Joshipura became the Linux Foundation’s new general manager for networking and orchestration in December 2016. He’s tasked with a pretty tall order. He needs to harmonize all the different Linux Foundation open source groups that are working on aspects of network virtualization. Joshipura may be the right person for the job as his 30 years of experience is broad — ranging from engineering, to management, to chief marketing officer (CMO) roles. Most recently he was VP of marketing with Prevoty, an application security company. Prior to that he served as VP of marketing at Dell after the company acquired Force10 Networks, where he had been CMO. Read more