PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Verifying Your Identity Online

Posted on April 21, 2010 by pogowasright.org

From Jules Cohen, Director, Online Privacy and Safety, Microsoft:

This week I travelled to Washington, D.C. for the International Association of Privacy Professionals (IAPP) Global Privacy Summit. The event is a great opportunity for members of the global privacy community to connect, debate the pressing privacy issues of the day and look ahead to future challenges.

Scott Charney, the leader of Microsoft’s Trustworthy Computing group, delivered today’s keynote address focused on our End to End Trust vision for a safer, more trusted Internet.

[…]

In the physical world, when you need to prove your identity to access a particular good or service, you typically pull out the appropriate ID from your wallet. Depending on the context, this might be a driver’s license, student ID, ATM card, employee ID or any other of the physical identity documents that people carry. The card is scrutinized and the recipient makes a trust decision whether or not to allow access to the requested good or service.

Today, we don’t have a similarly robust or interoperable identity verification system online. Instead, we rely on a patchwork of user names, passwords and other easily compromised pass-phrases to “prove” who we are online. Unfortunately, compromised usernames and passwords can typically be entered online by anyone, from anywhere on the Web, and don’t have anywhere near the fidelity of physical identity documents.

For online transactions that require a high level of information assurance and protection, we need a more secure and verifiable model — one where the level of trust and assurance much more closely resembles identity in the physical world.

Technology can help us develop a system of electronic identities that extends to the Web the type of trusted identity verification enabled by ordinary plastic ID cards. As we move down this path we’ll encounter a variety of challenges. One of the most critical ones will be building these new systems in such a way that they support data protection and privacy principles.

At Microsoft, we’re investing in technologies to address these challenges. We recently released a cryptographic-based technology called U-Prove under the Open Specification Promise. The U-Prove technology can enable people to prove their identity by disclosing only the minimum amount of information necessary to complete a transaction, and does so in such a way that one use of an ID is not linkable to any other use of that ID. 

Read more on Microsoft on the Issues.

Thanks to the reader who sent this in.

Category: Online

Post navigation

← Are Buzz, Facebook and Twitter creating ‘social insecurity’?
Coalition Petitions Homeland Security to Suspend Airport Body Scanners →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim

RSS Recent Posts on DataBreaches.net

  • Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
  • N.W.T.’s medical record system under the microscope after 2 reported cases of snooping
  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy