ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

MPs slam UK ID card proposal

Munir Kotadia ZDNet.co.uk

Published: 30 Jul 2004 13:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A cross-party group of MPs published a report on Friday that slams the government's ID card scheme for being "poorly thought through" and warns that decisions surrounding the technology to be used have been "made behind closed doors" without enough expert guidance.

The fear of terrorism seems to have pushed the government into fast-tracking the national ID card scheme; although many other countries in Europe have ID cards, in their current form, the UK's proposals are technically inferior to schemes in Estonia, Italy, Belgium, Finland, Austria, Denmark and the Netherlands.

According to the report by the Home Affairs Select Committee, the government has not adequately looked into alternative technologies that would be more appropriate for an ID card system.

"The Home Office appears to be taking these key decisions without any external reference, technical assessment or public debate. Some choices, such as the nature of the chip, seem to follow a decision to use the passport as an identity card (and therefore follow ICAO) rather than any independent assessment of what would be most appropriate for an identity card," the report said.

Steve Price-Francis, the vice-president of biometric card specialist LaserCard Systems, gave evidence at the committee hearings in April. He welcomes the damning report because it highlights a lack of "technical assessment" by the government.

"This report hits the nail on the head. There is currently a serious risk that document security and identity verification will be subsidiary issues rather than integral to the fundamental design. The programme deserves a proper technical assessment of proven technology," said Price-Francis.

If identity verification is a "subsidiary issue", there will be doubts about the validity of the card, according to Richard Starnes, president of security industry group ISSA UK.

"What is the point of having an ID card if you can't verify that the card hasn't been tampered with or forged? It bypasses the primary purpose of the scheme," said Starnes.

However, Mike Small, director of security strategy at Computer Associates, believes there is confusion over exactly why a scheme is necessary at all. Small said it is important to distinguish between knowing who a person is and restricting what they have access to. "Everyone that committed the 9/11 terrorist attacks had valid ID cards. The issue wasn't knowing who they were, but stopping them from doing things they shouldn't be doing. Knowing who someone is, is only half the problem," said Small.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
165 out of 286 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

SYSTEM TEST EXECUTION LEAD / DEPUTY SYSTEM TEST LEAD - West London

Execution Lead role work within the IVV (Integration Verification and Validation) team of the Solutions Design IPT. The System Test Execution Lead is ...

Oracle Technical Architect

This includes decisions about; - The physical distribution of processing across all the tiers in the architecture, - Capacity planning of the ...

Financial Services - Financial Systems

Critical to this role are decisions on assets, strategic and tactical investments, and resource allocation. They help senior management put IBM's ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation