U.S. Federal report warns of RFID misuses

By Declan McCullagh, CNET News.com
Tuesday, May 31, 2005 11:09 AM

Radio frequency identification is becoming increasingly popular inside the U.S. government, but agencies have not seriously considered the privacy risks, federal auditors said.

In a report published Friday, the Government Accountability Office said that 13 of the largest federal agencies are already using RFID or plan to use it. But only one of 23 agencies polled by the GAO had identified any legal or privacy issues--even though three admitted RFID would let them track employee movements.

"Key security issues include protecting the confidentiality, integrity and availability of the data and information systems," the GAO said. "The privacy issues include notifying consumers; tracking an individual's movements; profiling an individual's habits, tastes and predilections; and allowing for secondary uses of information."

RFID is a catchall term for a broad array of technologies that includes everything from battery-powered "active" tags, such as those used in highway toll booths, to "passive" RFID tags that measure a fraction of a millimeter in each dimension, not counting the antenna in the device.

Agencies already are experimenting with passive RFID technology. Among the list of planned or actual uses: the Department of Defense for tracking shipments; the Department of Homeland Security for immigration and baggage tracking; the State Department for electronic passports; the Department of Veterans Affairs for "audible prescription reading."

In addition, under the Real ID Act, the Department of Homeland Security is responsible for designing a standardized ID card that could be RFID-outfitted.

Few privacy concerns exist when RFID is used merely to track warehouse pallets. But when RFID chips are embedded in ID cards or otherwise linked to personal information, the GAO warned, the privacy risks increase dramatically.

"Consumers have raised concerns about whether certain collected data might reveal personal information such as medical predispositions or personal health histories and that the use of this information could result in denial of insurance coverage or employment to the individual," the report said. "For example, the use of RFID technology to track over-the-counter or prescription medicines has generated substantial controversy."

California's Senate this month approved a ban on the use of RFID tags in driver's licenses and other state-issued forms of identification.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Keep IMAP e-mail messages locally using OfflineIMAP

Open Source

Vincent Danen discusses the uses of OfflineIMAP for synchronizing local and remote IMAP mailboxes and providing a good method for backing up e-mail.


Read more »



Time to map out

Blog thumbnail

Before anything else, let me devote a few words to the fallen journalists and other victims of the brutal massacre that occurred last week in the southern province of Maguindanao...... by Melvin G. Calimag

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web