ID management's weakness: Few want to use it

 

Connecting state and local government leaders

The National Strategy for Trusted Identities in Cyberspace might be a good start toward establishing an effective way to manage online identities, but the test will be industry’s ability to produce secure, user-friendly technology and convince the public to use it.

The administration’s strategy for identity management is expected to be finalized this winter. It is an effort to bring some order to the task of managing identities and personal information in an increasingly online world. It is a worthwhile goal, but its success will depend on the ability of the private sector to provide effective, user-friendly tools to implement it and then convince the public to use it.

The National Strategy for Trusted Identities in Cyberspace has been under development for about a year as the result of the president’s Cyberspace Policy Review. One of the review’s recommendations was the “the federal government — in collaboration with industry and the civil liberties and privacy communities — should build a cybersecurity-based identity management vision and strategy for the nation that considers an array of approaches, including privacy-enhancing technologies.” A draft was released in June, and the final document is expected this winter.

The strategy will not be about technology, but about creating an “identity ecosystem” where “individuals, organizations, services and devices can trust each other because authoritative sources establish and authenticate their digital identities.”

The government will help to establish the framework to enable comprehensive scheme, but industry will have to make it work.


Related stories:

National strategy for identity management nearly done

Identity management a complex process with a simple goal


Doing high-assurance online authentication of identity is not terribly hard. There are plenty of systems using factors such as digital certificates and biometrics that can do it. The problem with identity management of any kind is making it scale. The user name/password combination is the default standard for online authentication, but in the few years it has taken the Internet to engrain itself in our lives, the complexity of this scheme has outgrown the ability of humans to handle it effectively. There are schemes to help manage or reduce the number of passwords but these can add their own complexities.

Non-password schemes using tokens and certificates can be simple on a one-off basis, but they don’t scale any better than passwords. The solution is something interoperable and flexible enough that a few sets of credentials can be used across the wide variety of transactions.

“The identity ecosystem should allow an individual to select the credential he or she deems most appropriate for the transaction,” the draft strategy said.

Developing this scheme would be a good trick, but it would still be just bits and bytes and some user-friendly hardware. The really good trick will be convincing consumers to use it, and the draft makes it clear that there will be a government mandate for that:

“Voluntary participation is another critical element of this strategy,” the review states. “Engaging in online transactions should be voluntary to both organizations and individuals. The federal government will not require organizations to adopt specific identity solutions or to provide online services, nor require individuals to obtain high-assurance digital credentials if they do not want to engage in high-risk online transactions with the government or otherwise.”

This means that the credentials, and the hardware and software needed to use them, must be convenient and inexpensive to consumers. They will have to be easier to manage than keeping track of a dozen passwords. And there must be an incentive to use them, which means that providers of online services will have to accept them.

This is not likely to happen right away. We can expect a period of some shakeout before a standard is settled on. Remember the confrontations between Betamax and VHS in videotape and between Blu-ray and Sony in discs. Millions of consumers had to either sit out the contest or risk ending up with a perfectly functional but practically useless system.

If the government and private sector can arrive at a combination of ease of use, interoperable standards and general acceptance, the national strategy will have done its job.

 

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.