Identitet er det vigtigste af kritisk infrastruktur med skrappe krav til f.eks. fallback i form af revokability og recorability. Designfejl her skaleres eksponentielt i resten af samfundet.
I mit indlæg på Biometriens dag fokuserede jeg på et Biometrisk Borgerkort og krav hertil formuleret i "The 7 principles for biometrics Security".
http://www.danishbiometrics.org/admin/files/Stephan%20Engberg%20presentation.PDF1. Ensure upgrade ability - Change is the only certain Aspect
2. Ensure Fallback - Never collect non-revocable biometrics
3. Purpose Specification - Mix with purpose specific secrets
4. Proportionality - Exhaust non-invasive security tools first
5. Minimize Interdependence - User Control and revocable id
6. Semantic Interoperability - Don't standardize at technology level
7. Design assuming failure - Critical infrastructure fault tolerance
Jeg formulerede det centrale spørgsmål således:
"In my opinion, the critical question to answer is rather simple.
Require and ensure a technical setup that guarantee citizens are not subjected to biometrics surveillance both as part of checks against criminals and as part of simple border passing. As technologies is today, there is no sensible argument in favour for dis-empowering citizens - on the contrary - all arguments, economics, security and efficiency point in favor of Empowering the citizen."
Hvad er responsen for disse principepr - holder de?