Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, October 5, 2010

Privacy vs. Security on the DASH7 Wireless Sensor Networking Blog

The concepts of security and privacy are related, but different, and people often confuse the two issues. SecureRF’s CEO, Louis Parks, tackles this topic in his first posting for the DASH7 Wireless Sensor Networking Blog.

His post, Privacy vs. Security, lays down a foundation on what is security versus privacy, in a general, non-specific product way.
Future postings will cover:
  • “What is security?” and describe related tools and functions.
  • How you put these tools together to create security protocols that address real world issues.
  • Security on a DASH7 platform.
  • Addressing and describing the security needs and solutions for different applications and industries of interest to the DASH7 Alliance.
Pat Burns, President of the DASH7 Alliance, starts the conversation with his posting - Introducing Louis Parks.
The DASH7 Alliance was formed to advance the use of DASH7 wireless data technology by developing extensions to the ISO 18000-7 active RFID standard, ensuring interoperability among devices, and educating the market about DASH7 technology.  SecureRF is now a member of this organization.

Thursday, April 16, 2009

Welcome to a New Security Alliance

Contributed by Joanne C. Kelleher

A new organization, the Cloud Security Alliance is being launched next week at the RSA Conference. They plan to provide security advice to companies adopting cloud computing products.

SearchSecurity.com has an opinion piece about the challenges the new Cloud Security Alliance (CSA) will face and the RFIDSA gets a mention. The CSA is tackling 15 "Domains of Concern" and several of these items overlap with issues we face with RFID.

-------------------------------------------------------------
Cloud computing group to face challenges ahead
By Eric Ogren at SearchSecurity.com
15 Apr 2009

-snip-
"This is not the first, nor will it be the last, security alliance that was formed to get ahead of security issues that may stunt the growth of enticing new technologies. A search on "security alliances" will quickly uncover similar organizations including the Internet Security Alliance, Voice over IP Security Alliance, Document Security Alliance and Radio Frequency Identification (RFID) Security Alliance. Security practitioners are well-schooled in talking about potential security pitfalls in new technologies and in making best practices recommendations."
-snip-
Read the full piece at http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1353872,00.html#

Friday, April 3, 2009

Help Present a Balanced View of RFID Security

Bert Moore, Editor of AIM Global’s RFID Connections, discusses RFID security and privacy in his April 1, 2009 column titled RFID: Legislative Action.

"At some recent legislative hearings on whether to limit, regulate or restrict RFID in some way, advocates of RFID finally began to get their views heard. Why? Because many of the advocates weren't companies manufacturing or selling RFID, they were companies and agencies actively using the technology. They were able to point out to state legislators how the technology was actively benefitting citizens of the state. And their real world experiences helped put to rest some of the more outlandish claims of some privacy advocates.

At the same time, there are new concerns that some companies and governmental agencies are implementing RFID technology without giving adequate attention to the need for security and, therefore, privacy. Concerns about covert reading of ID cards and similar items must be addressed because they highlight real or potential system vulnerabilities that expose not only individuals but the entire system to unnecessary risk.

It is up to those in the RFID community -- both vendors and end users -- to be heard in legislative hearings and community forums in order to present a balanced view of the technology and point to ways in which it can be implemented securely so that it can continue to provide benefits while protecting the integrity of the system and personal privacy."

The RFID Security Alliance invites vendors and end users interested in this issue to join our organization.

Burt also goes on to announce the availability of a new technical report from the International Organization of Standards (ISO) which was based on the work of AIM Global. Publication ISO/IEC TR24729-4, Information technology - Radio frequency identification for item management - Implementation guidelines - Part 4: Tag data security is available for purchase from the AIM Global website.

I was pleased to see that this report “offers sufficient guidance to enable users or developers to assess potential risks and determine appropriate techniques to mitigate these risks.” The RFID Security Alliance encourages users and implementers to completing a risk assessment of potential RFID systems.

Wednesday, August 6, 2008

Karsten Nohl Discusses RFID Insecurities

Karsten Nohl, the security researcher who was part of a team that broke the crypto algorithm in the Mifare Classic RFID-based smart card, talks about his upcoming briefing at Black Hat in Las Vegas in an interview with Security Wire Weekly called Wireless Insecurities.

Nohl, a University of Virgina graduate student, has been active with the RFID Security Alliance and presented a threat model for Mifare at our May meeting. Hear his interview at http://securitywireweekly.blogs.techtarget.com/2008/08/01/sww-wireless-insecurities/