White House releases trusted Internet ID plan
- 16 April, 2011 03:20
- Comments
The U.S. government will coordinate private-sector efforts to create trusted identification systems for the Internet, with the goal of giving consumers and businesses multiple options for authenticating identity online, according to a plan released by President Barack Obama's administration.
The National Institute of Standards and Technology (NIST) will work with private companies to drive development and adoption of trusted ID technologies, White House officials said. The National Strategy for Trusted Identities in Cyberspace (NSTIC), released by the Department of Commerce on Friday, aims to protect the privacy and security of Internet users by encouraging a broad online authentication market in the U.S.
"The fact is that the old password and username combination we often use to verify people is no longer good enough," Commerce Secretary Gary Locke said at an NSTIC release event hosted by the U.S. Chamber of Commerce. "It leaves too many consumers, government agencies and businesses vulnerable to ID and data theft."
Because of online fraud, many people don't trust the Internet, Locke added. "It will not reach its full potential -- commercial or otherwise -- until users and consumers feel more secure than they do today when they go online," he said.
About 8.1 million U.S. residents were victims of ID theft in 2010, Locke said. The cost to business is high: a company with 500 employees spends about US$110,000 a year managing employee IDs, according to the Department of Commerce.
The trusted ID technologies described in NSTIC would allow online users to dump passwords in favor of credentials that can be used on multiple websites. The Obama administration hopes that multiple trusted ID technologies will emerge, officials said.
Consumer participation in trusted ID technologies will be voluntary, they added.
NIST will host three workshops starting in June to focus on problems with development and adoption of online ID authentication technologies, Obama administration officials said. Businesses, consumer groups, privacy advocates and other interested members of the public will be invited, they said.
The plan aims for several trusted ID pilot projects to be launched in 2012, and the administration hopes to see a robust trusted ID market in the U.S. in three to five years, officials said.
The White House released a draft version of NSTIC in June. The new version more explicitly emphasizes that the private sector will drive forward the trusted ID market, with government playing a coordinating role, administration officials said.
After the draft release, some critics raised privacy concerns about NSTIC, suggesting it is the administration's effort to create a national ID. The emphasis on private sector leadership should debunk that argument, Locke said.
"Other countries have chosen to rely on government-led initiatives to essentially create national ID cards," he said. "We don't think that's a good model, despite what you might have read on blogs frequented by the conspiracy theory set. Having a single issuer of identities creates unacceptable privacy and civil liberties issues. We also want to spur innovation, not limit it."
Privacy advocate Susan Landau, a fellow at Harvard University, praised the new version of NSTIC, saying it will allow Internet users to remain anonymous for many online transactions. The plan calls for online businesses to collect the minimal amount of information necessary from credential providers in order to process the transaction, administration officials said.
"NSTIC certainly sets out the right vision here," added Leslie Harris, president and CEO of the Center for Democracy and Technology (CDT), a privacy advocacy group. "It gives consumers more control and more choice about their online identities. It makes it clear that it's voluntary."
Representatives of several vendors, including Google and Paypal, praised the effort. Several vendors demonstrated trusted ID technologies at the event, with Northrop Grumman, Microsoft and other partners demonstrating a cloud-based credential system for mobile devices.
Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- 8 reasons why Citrix NetScaler beats the competition
- Revolutionizing Enterprise Storage Infrastructure with Enterprise Flash Technology
- SOA Best Practices and Design Patterns
- Case Study: BNP Paribas Deploys Oracle Exadata to Accelerate Information Processing - The Hardware Perspective
- BPM Basics for Dummies
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Forrester Research | Your Enterprise Database Security Strategy 2010
With increasingly sophisticated attacks and rising internal data theft, database security merits a stronger focus that goes beyond traditional authentication, authorization, and access control. Learn how to secure your database - Read this strategy guide. -
The State of Data Security
Recognize how your data can become vulnerable, including the latest issues stemming from unprotected data on mobile devices and social media sites. Understand the compliance issues involved, and identify data protection strategies you can use to keep your company’s information both safe and compliant. -
Pathways Advanced ICT Leadership Development Program Brochure and Course Outline 2012
Developed by the CIO executive Council in conjunction with Rob Livingstone Advisory, Pathways Advanced is a 12-month CIO delivered, small group, mentor based professional leadership development program. Pathways Advanced brings together best practice, thought leadership and business insights for today’s most promising ICT professionals

















Comments
Post new comment