You are here: silicon.com > Networks > Mobile & Wireless

Mobile & Wireless

RFID security raises privacy issues

Beware of mismanaged or vulnerable systems

Tags: rfid

By Steve Ranger

Published: 8 May 2006 11:45 GMT

Awareness of consumer privacy issues and tight security must go hand in hand if RFID technology is to flourish, according to industry experts.

A set of RFID guidelines designed to help protect consumers' privacy have been released last week by a working group led by privacy body the Center for Democracy and Technology (CDT).

The best practice guidance outlines how consumers should be notified about RFID data collection, what choices consumers have and how that information should be treated by the companies which collect it.

The working group also included Eli Lilly and Company, IBM, Intel, Microsoft, the National Consumers League, Procter & Gamble, and Visa USA.

The CDT said that while many applications of RFID may raise no real privacy concerns, "when the data collected from RFID tags is linked to personally identifiable information, privacy issues can arise".

But in a research note, Gartner VP John Pescatore said that while the guidelines should help public acceptance of RFID, the industry must also work to ensure security of the technology.

Gartner said the guidelines "provide a solid privacy-protection framework for RFID industry stakeholders". And it said industry support for the best practices should help to prevent "a consumer, regulatory and legislative backlash against RFID".

But it added: "We believe, however, that minimising RFID technology and system vulnerabilities - to ensure that attackers cannot obtain confidential data by compromising systems - is equally important."

The analyst group points out most identity theft has been accomplished by exploiting mismanaged or vulnerable systems that were perfectly acceptable from a privacy perspective.

And it said industry efforts should include best practices for ensuring that security is built into the production of RFID tags and reader systems from the start, with the implementation of secure default configurations and support for standard vulnerability management processes.

Companies deploying RFID should make sure their technology providers demonstrate compliance with the CDT guidelines, and should review all RFID deployments for such compliance, Gartner warned.

But they should also make all RFID technology providers demonstrate security is an "integral element in their product design processes" and that vulnerability testing is included in their quality assurance processes.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Read and write about internet access at the airports of the world at atlarge.com.

Peter Cochrane Peter Cochrane's Blog: How the telcos could save themselves Doomed network operators could thrive with a bit of innovation

Peter Cochrane Peter Cochrane's Blog: Facebook saves teen from prison Another unexpected impact of social networking


  • Jobs
Principal Analyst / Senior Analyst - Midlands

The Principal Analyst will: -Undertake and provide intelligent analysis of data from healthcare providers to support commissioning activities within ...

Copywriter- COnsumer Technology - London - 25-32K

You will have experience working on large e-commerce sites and creating current factual content that runs within SEO and brand guidelines. Your ...

Web Team Manager

s website complies with central government guidelines and requirements for Council websites;10.Manage and contribute to the provision of support and ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: