Why PKI is a better option then biometrics or RFID tags

I’ve touched on this before, but I recently stumbled upon a link again to an early example in the real world which makes the point very obvious.

The biggest benefit about biometrics and RFID tags is also the biggest problem. Biometrics and RFID are designed to not change, and make use of things such as your finger print, and in the case of RFID tags a fixed hexadecimal number. While you can never “loose” your fingerprint like you can your password, people can’t easily duplicate your fingerprints on the spot either so they start taking body parts instead.

Of course RFID tags only become a similar problem when it’s actually embedded under your skin, but already a lot of people are doing this, or contemplating doing it for more “convenience”, and while they think they only have limited range they haven’t played with highly directional antenna, people thought blue tooth problems weren’t an issue because you had to be within 10m of the person you’re targeting, that is of course until someone started playing with high gain antennas and manged to get between 100 to 1000m range to a normal mobile phone.

The US and other governments around the world are currently pushing for contact-less RFIDs in passports, as a security measure, but time and time again these “feel good” security measures don’t do much for security and simply give the community at large a warm fuzzy feeling about how their governments are protecting them with better security measures at border crossings. Quite frankly if current estimates of 10 million illegal immigrants in the US is correct what’s to stop the big bad enemy (I refuse to say the “T” word because it’s really a pot calling the kettle black) from sneaking in the same way, oh sorry forgot that they were actually buddies with guys in power and were let in the front door!

Also this little sound bite from the CAcert Support mailing list today:

Here in Nebraska we implemented a 3D bar coding system on the drivers license, and all sorts of new security features on our licenses in 2003, making them extremely hard to duplicate. Within months the machines used to manufacture them was stolen, enabling the thieves to make perfect forgeries.

At the end of the day all these new security measures do is make it easier for governments to track and control their citizens, the bad guys will still do bad things!

