Friday | 16 May, 2008
CIO

News

New Zealand gov't ID plan lacks 'terrorism bug' infection
Australian ID-scheme critic says NZ is getting it right
Stephen Bell (Computerworld) 07 May, 2008 10:02:11

International experts in Wellington for a conference on identity last week expressed admiration for the New Zealand government's igovt identity information management scheme and the policy behind it.

One noted Australian ID-scheme critic also appeared won over, saying we benefited from not "catching the terrorism bug".

The igovt scheme signals an assumption of responsibility by government that is lacking in many identification schemes, says former Australian privacy commissioner Malcolm Crompton.

He points to the delineation by State Services Commissioner Mark Prebble of six principles, three of which (security, an all-of-government approach and fitness for purpose) serve government objectives and three (acceptability, privacy and opt-in orientation) explicitly serve the interests of the individual.

Crompton pointed by contrast to the identity provisions of the Medicare scheme in Australia, where clauses supposedly explaining the customer's rights mostly detail exclusions to Medicare's liability.

Identity information management is a question of managing a balance of trust, says Crompton. In many business and government transactions there is currently a "trust deficit" and the customer can credibly ask: "You don't trust me, so why should I trust you?"

Roger Clarke, of Australian consultant Xamax, a seasoned commentator on identity information management and privacy, commended Internal Affairs chief executive Brendan Boyle for referring to identity information management in his presentation.

Government and private industry cannot manage a customer's identity, he says; that is their property.

This is one of several "mythologies" about identity largely promulgated by suppliers of software for managing identity information, Clarke says.

"Everything sold concentrates on the supplier side," he says. "This is the first conference where I've heard about the demand side."

Inherent in the thinking behind the igovt scheme is the ability to dissociate the individual from identity information. The igovt system permits the same individual to assume several different identities. This, says Clarke, lessens the chance of it falling into the trap of the Australian services entitlement card, abandoned by the new Labor government, which everyone knew was effectively a universal identity card.

The push towards this dissociation of identity management service from the person and the management of identity by the person will become stronger, Clarke says. As people acquire more devices through which they do identity-related transactions, they will want all of those devices to talk to a single proxied identity information management service that they control.

The question of compulsion threaded its way through the first day of discussion. Though abandoned Australian and New Zealand schemes were both "opt-in", speakers noted that if enough agencies ask for a verified identity as a condition of business, it will be increasingly hard not to opt in.

Boyle talked about "legitimate public concern" over identity abuse, but other speakers suggested this was exaggerated. There were repeated references to the failure to distinguish in popular conversation between identity fraud, such as the occasional spurious transaction on a credit card, and identity theft -- the systematic assumption of another person's identity with major consequences for the victim's reputation.

According to Clarke, New Zealand has benefited from not "catching the terrorism bug."

Because we have not had a terrorism incident, we haven't fallen into a panic of demanding repeated identity checks, he says, and have been able to approach the question with more deliberation.

Market Place
 

2008 CIO Summit

19th August, 2008 Four Seasons Hotel, Sydney Developed in partnership with CIO Magazine, IDC, INTEP and the CIO Executive Council.

The world of the CIO is extremely complex and diverse. Multiple priorities demand attention and decisions are needed instantly. Individual teams need to be driven towards common goals, and businesses strive to become more mobile, agile and responsive. For CIOs, the challenge never ends.

Every year the CIO Summit identifies what is top of mind for CIOs across Australia and New Zealand, and offers insight for CIO benchmarking and vendor strategic planning alike.

Recent IDC research shows that over 59% of CIO's believe that 'to achieve their business strategies, technology should be used more aggressively than today.'

Join us on August 19th to discover how this is possible with the latest technologies including Virtualisation, Web 2.0, IP Surveillance and Software as a Service (Saas).

Click here for registration.

Please email Denyse_Robertson@idg.com.au for further information.

  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Phishing botnet expands by hacking legit sites 15 May, 2008 08:10:59

    Plants SQL injection attack tool on bots, hacks business, education sites
    A botnet is now using a SQL-injection attack tool designed to hack legitimate Web sites, a move meant to add more hijacked PCs to its collection, according to a security researcher.
  • +

    Which IT security skills are most important? 14 May, 2008 09:21:43

    There are two types of security skills that might be needed in a company: tactical security operations and strategic risk management.
    I often hear from IT executives that it is hard to recruit and retain "good security people." Many lament the shortage of skills in this area and cannot reconcile the skills offered with the positions that need to be filled. Is there really a shortage of good security people? Or just a mismatch in the skills and the jobs?
  • +

    Icy encryption tool protects laptops from "cold boot" attack, vendor says 14 May, 2008 08:36:43

    Vulnerable encryption keys erased by HyBlue's IceLock
    The vendor HyBlue says it can prevent the "cold boot" encryption hack discovered by Princeton researchers with a laptop security product announced Tuesday.
  • +

    Great Wall of Australia: Industry cops sanitised Internet 14 May, 2008 16:45:04

    Content filtering gets budget go-ahead
    Communications Minister Stephen Conroy has pushed ahead with the controversial [[artid:420013177|national content filtering scheme|ISP filtering]] with a $125.8 million budget allocation announced today.
  • +

    Hacker writes rootkit for Cisco's routers 15 May, 2008 07:07:51

    A hacker has written rootkit software that works on Cisco's routers.
    A security researcher has developed malicious rootkit software for Cisco Systems' routers, a development that has placed increasing scrutiny on the routers that carry the majority of the Internet's traffic.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

The State of Internet Security

Email security threats are having a significant impact on businesses worldwide. Discover the most critical email security-related concerns, and get expert advice, current industry data, trends and learn the essential steps to protect your corporate email.

Sponsored Links