Home > Security News > RFID privacy, security should start with design
Security News:
EMAIL THIS
QUESTION & ANSWER

RFID privacy, security should start with design

By Robert Westervelt, News Editor
27 Feb 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Companies planning to deploy radio frequency identification technology (RFID) must demand that privacy and security issues are addressed in the design and procurement phases of the implementation, according to Toby Stevens, a leading privacy and identity expert. Privacy should not be a "value-add feature," said Stevens, director of the UK-based Enterprise Privacy Group, an association of public agencies and corporations working to understand and develop solutions to privacy and identity-related issues. In an interview with SearchSecurity.com, Stevens talked about whether the European Commission would mandate policy controls for RFID privacy and whether government legislation could stall widespread use of the technology. Stevens said the opinions given are his own and do not necessarily reflect those of his group's member organizations.

 It is essential that the various stakeholders work together to develop, implement and enforce their own guidelines for privacy-positive use of RFID technologies.
Toby Stevens,
director, Enterprise Privacy Group
Do you see IT vendors addressing RFID and privacy in a positive way?

Toby Stevens: To date, vendors have largely - and quite correctly - assumed that privacy is the responsibility of the integrator rather than the RFID equipment supplier. No amount of security and privacy controls can be effective if the end system is designed to ignore or circumvent privacy needs. Moreover, privacy and security implications are never fully understood in emerging technologies: it takes time to identify the problems and architect solutions. The likes of RSA and IBM are now beginning to do just that. We now have to encourage end users to recognize privacy needs and specify them in the design and procurement phases of their implementations so that privacy becomes the norm, not a value-add feature.

What role should government policy makers play in developing privacy guidelines for the use of RFID?
Stevens: There is an important distinction here between policy and guidelines. The European Commission is keen to mandate policy controls for RFID privacy, and similar moves are afoot in a number of US States. Yet there are numerous excellent guidelines out there, such as those gathered by the EC Article 29 Working Group for its analysis of RFID privacy. A number of high-profile privacy incidents arising from companies and government departments that have failed to heed this advice has spurred governments to consider legislative controls.

RFID privacy:
RSA Conference panel says privacy legislation too premature for RFID
What are some of the challenges to creating policy to protect consumers?

Stevens: What is required here is not law that specifically controls the usage of RFID technologies, but legislative guidelines to ensure that implementers, consumers and law enforcement authorities understand that privacy and data protection laws apply to RFID systems in the same way as they do to any other technology implementation. Other disruptive technologies - for example the telephone, Internet, cellphones - created security and privacy concerns, but society found a comfortable balance for them, and the same will happen for RFID.

What can be done without killing the technology?
Stevens: If policy-makers are to avoid killing off RFID, then it is essential that the various stakeholders work together to develop, implement and enforce their own guidelines for privacy-positive use of RFID technologies.


Tags: Information Security Laws, Investigations and EthicsWireless Network Protocols and StandardsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Information Security Laws, Investigations and Ethics
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity

Wireless Network Protocols and Standards
Wireless network guidelines for PCI DSS compliance
Best Wireless Security Products
MMS messaging spoof hack could have global ramifications
PCI group releases wireless security guide
802.1X Port Access Control: Which version is best for you?
Wireless Security Lunchtime Learning
An introduction to wireless security
Lesson 1: How to counter wireless threats and vulnerabilities
Risky Business: Understanding WiFi threats
Lesson 1 quiz: Risky business

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
FERPA  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts