Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

RFID policy panel raises privacy concerns

Lack of authentication means identity thieves could set up fake readers

By Grant Gross, IDG News Service
April 06, 2005
 

Radio frequency identification (RFID) technology has many current and future benefits, but U.S. policymakers need to be aware of potential privacy and security problems of the rapidly evolving technology, a privacy advocate and a security expert said Wednesday.

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

A parade of RFID vendors and users championed the potential of the technology at a U.S. Department of Commerce workshop on RFID and its policy implications, but Paula Bruening, staff counsel at advocacy group the Center for Democracy and Technology, warned that RFID is one example of a growing trend toward businesses collecting and using their customers' personal data.

While most current forms of RFID aren't capable of compromising privacy by doing things such as tracking customers' movements, the technology is rapidly moving forward and may soon catch up to consumer and privacy advocates' fears, Bruening said. "We need to be forward-looking and address privacy concerns around this technology," she said.

RFID uses small processors and antennas that are integrated into a paper or plastic label. Those chips can then be read by an electronic scanner, and unlike barcodes, RFID chips withstand dirt and scratches. As the range of RFID scanning grows beyond the current 25 feet (7.6 meters), RFID could allow corporations and governments to track people's movements and purchases, privacy advocates have said.

But representatives of RFID technology vendors including Texas Instruments  and Microsoft, along with users PepsiCo  and General Motors, talked of the potential for RFID to revolutionize the way companies manage their inventories, fight counterfeiters and stop shoplifters.

No one offered concrete cost savings numbers, however, and Pam Stegeman, vice president of the Grocery Manufacturers of America, noted that because of the cost of RFID chips and readers, the technology is still not for everyone. Companies that often carry counterfeited or stolen products, or that ship mixed products on pallets, can most benefit from RFID, she said. RFID isn't a good solution for companies that sell many low-cost items, she said. RFID labels now cost about $0.50 each.

Already, RFID technology is used to track livestock, to find lost pets and to pay for gas and subway fares simply by passing an RFID-enabled card close to a reader. Applied Digital, an RFID hardware vendor, even received U.S. government approval in October 2004 to offer RFID chips that can be implanted in humans, just as the chips are now implanted in dogs and cats. Such chips could contain a person's health records that doctors could access in emergencies, said Scott Silverman, Applied Digital's chairman and chief executive officer.

"This is going to be bigger than cell phones," said Jeff Fischer, chief RF architect at Reva Systems, another RFID hardware vendor.

With large retailers including Wal-Mart Stores and Target requiring their suppliers to move to RFID on shipping containers, the technology will become more prevalent in the next couple of years. But Tom Kellermann, senior data risk management specialist at The World Bank Group, warned audience members at the U.S. Department of Commerce forum that like Wi-Fi and other wireless technologies, RFID has major security challenges.

"Radio frequency is impossible to secure," Kellermann said.

RFID labels don't check readers for authentication, so identity thieves could set up their own readers that impersonate legitimate ones, he said. And as with other wireless technologies, criminals will find ways to exploit RFID and "grab money out of the air," he added.

Kellermann advised companies against using RFID for financial transactions, even though oil company Exxon Mobil is already using RFID in its Speedpass "contactless" gas purchasing program, and major credit card companies are rolling out their own contactless cards. Mark MacCarthy, senior vice president for public policy at Visa International Service Association, predicted other retailers would begin rolling out contactless payment terminals within months.

Bruening encouraged policymakers in Washington, D.C., to engage in a debate broader than RFID, focusing more on what companies can do with their customers' personal information.

RFID has the potential to expand what people around you know about you, and its uses are worth a policy debate, said James Lewis, director of the Technology and Public Policy Program at the Center for Strategic and International Studies, a Washington think tank. "When you walk down the street now, people can see you," he said. "(With RFID), people will be able to see you and know more about you."

However, Lewis also warned policymakers not to focus new rules on all uses of RFID when many existing uses cause no privacy or security problems. "If you're putting a chip in the ear of a cow, is there really a privacy concern?" he said. "A one-size approach won't work." And although rules on the proper use of RFID are needed, they could be industry rules instead of ones set by the government, Lewis added.





 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




FIVE WAYS TO REDUCE IT COSTS IN 2009
The demands on IT have never been greater, particularly in light of lower revenue and uncertain demand for the goods and services. There are many ways that IT can help organizations adjust to this new economic environment. Learn about five key technology trends that can immediately impact your organization's bottom line, and how to build a strategy to implement these technologies within your current budget. Sponsored by: Riverbed

»  Click here to view this Webcast
  Enterprise Data Security Solutions Guide
Data security used to be about outside threats. These days the biggest challenge for data-driven organizations is the management of secure information from the inside out. Data is available on laptops, your network and even USB devices, but not always secure. Read this Solutions Guide to learn the best ways to keep it safe. Sponsored by ISC2

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2009, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity