Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Privacy Security

Protecting Online Identity Through Cryptography 87

A new startup, Credentica, hopes to offer the ability for you to perform secure transactions using the smallest amount of personal information possible. Their goal is to both protect privacy and enhance security, which they hope will be a mutually inclusive process. "The technique employs secure multi-party computation, a branch of cryptography that can calculate meaningful answers about secret information by knowing only some non-revealing clues about that secret. The underlying theory was demonstrated in 1982 by Andrew Yao in the so-called Millionaire's Problem [...] U-Prove employs an ID token, a special kind of digital certificate that allows for minimal selective disclosure. The tokens can store all kinds of information, but users can disclose only the minimum amount of data required in any given transaction. They leave no unwanted data trails and permit both anonymity and pseudonymity."
This discussion has been archived. No new comments can be posted.

Protecting Online Identity Through Cryptography

Comments Filter:
  • Unfortunately it is all too easy to accomplish identify theft via some very uncomplicated and low-tech methods. People still click on links in emails and type their financial information into fake websites or answer questions over the phone to the nice IRS man who wants to send me a tax rebate. However, I do applaud any effort to protect folks identities.
    • Tools like these will do more do help consumers. People that really have things to hide are doing just fine with things like PGP and other encryption standards. I hope that products like this, implemented and used well, would go a long way to help the kinds of people that have no idea online-privacy is an issue...
      • Re: (Score:2, Interesting)

        by davester666 ( 731373 )
        Tools like these COULD do more do help consumers. [fixed it for you]

        Really, do you think Amazon or Google or somesmallretailer.com will settle for asking the minimum amount of information necessary to complete a transaction?

        They already ask for more info than they need, presumably for 'security' purposes [ie, so someone isn't using your credit card to buy a bunch of Dells for orphans in Russia], but they just happen to keep using that data for marketing purposes. And now that they are already collecting al
        • Data for financial transactions on most sites is processed separately from the rest of the data provided. I think it would be feasible to make a system beneficial and transparent to both sides. I would like to think that an online merchant does not have any additional utility from having my CC#, as long as they know I paid, and know it was me. I agree that a quick mass adaptation of a system like this would not be the best, and I would absolutely not feel comfortable with a single company running it all,
    • I also see the potential for even worse identity theft, from what I gather the gist of it is basically instead of asking you exactly what is required, its now asking you stuff related to what is required?

      Sort of like, they need to know that you are 21, so they ask you what your Grad year was, and what school you went to instead of how old are you?

      Maybe I dont get it, but it seems like a possibility of "Personality" theft not just Identity theft...
    • Re: (Score:3, Insightful)

      Comment removed based on user account deletion
    • Unfortunately it is all too easy to accomplish identify theft via some very uncomplicated and low-tech methods. People still click on links in emails and type their financial information into fake websites or answer questions over the phone to the nice IRS man who wants to send me a tax rebate.

      Far lower tech than that -- much identity theft is still accomplished through dumpster diving, mailbox theft, over-the-shoulder snooping, and many other techniques that have been around since way before the Intern

    • Or, say, give all their information to a website which claims it will keep it secure and only send companies the information they need?

      </cynical>
  • by Vectronic ( 1221470 ) on Saturday February 09, 2008 @01:43AM (#22358170)
    Millionaire's Problem: Alice and Bob want to find out who has more money without disclosing the amount of their fortunes to each other, or even to a mutually trusted third party. By applying special functions to their information that disguised it, Yao proved that each could know who was richer without either revealing their true holdings.

    No wonder Millionaires are so stupid... if this is what they consider a "Problem"...
    • Stupid millionaires typically don't remain so for long.
      • Re: (Score:3, Informative)

        Counterexample [parishiltonzone.com]
        another counterexample [wikipedia.org]
        • Maybe Paris Hilton and Dubya are just smarter than you think they are.

          Hey, it could happen.

          • Well, i'd like to pretend like (at least) Paris (specifically) isnt as dumb as she appears, but given that she wasnt exactly "poor" to start with, I cant really find a reason for her not to be as stupid as she appears.

            But I will give credit to some "Famous" people that are in similar positions, being a guinea pig/stooge to someone who actually has a brain as far as marketing and management goes, gathering millions and then just vanishing from publicity to live out the rest of their life in luxery... however
            • Well, i'd like to pretend like (at least) Paris (specifically) isnt as dumb as she appears, but given that she wasnt exactly "poor" to start with, I cant really find a reason for her not to be as stupid as she appears.

              She may've started with a nice kaboodle, but she's increased it significantly on her own through fashion-lines, perfumes, TV shows, and getting paid to show up at bars and clubs.

              The only evidence of her stupidity that I've seen has been what she's said on those TV shows, which I have no rea

              • Yes, because every college freshman gets DUIs and then drives on the suspended license so many times they get thrown in jail for it. Most colleges don't even allow freshmen to have cars on campus, and there's bars/parties/frats within walking distance anyway.
      • Stupid millionaires typically don't remain so for long.
        George. W. Bush.
    • by Workaphobia ( 931620 ) on Saturday February 09, 2008 @05:21AM (#22358822) Journal
      "No wonder Millionaires are so stupid... if this is what they consider a "Problem"..."

      If you think that's bad, then I have some dining philosophers that I'd like you to meet...
    • Re: (Score:3, Funny)

      by TubeSteak ( 669689 )
      http://geekz.co.uk/schneierfacts/facts/top [geekz.co.uk]
      Bruce Schneier knows Alice and Bob's secret.
  • Anonymous? (Score:2, Funny)

    by Anonymous Coward
    Forget about security on any large (sort of large) anything. Look at this site...you are immediately penalized for being anonymous.

    What a load of shit.
  • Online Drug Trade
  • This seems to be an idea about not revealing enough of yourself. But there is a risk too and that is if someone steals the ID token and forces you to reveal the key to it then it can be abused with low risk.

    Another issue is that such tokens may be forged. What are the safeties in place to verify that it isn't forged?

    Forged identities are likely to be abused by those that really doesn't want to be on the map, like terrorists and major drug dealers. The latter can probably afford a lot to be anonymous - e

    • "As long as it's returned"

      That's the magic statement, And if you can't trust them with your ID, What makes them think you can trust them with (after Blockbuster gets done with it) an $80 copy of midget porn that they demand back with a post card.

      But of course, renting "Midget Ladies of Lust" was just what they did to test the stolen ID on the way to the BMW dealership, where they really had fun...

      • by Z00L00K ( 682162 )
        Which means that you REALLY misunderstood...

        In both cases the dealers would have failed to do a sufficient verification of the ID by checking that it was valid and not reported as missing and that the person providing it did match the person holding it. So in both cases the dealers has to take full responsibility by being insufficient.

  • Book pointer (Score:5, Informative)

    by Beryllium Sphere(tm) ( 193358 ) on Saturday February 09, 2008 @03:23AM (#22358486) Journal
    For people who want background or just enjoy math, Brands's book is Rethinking Public Key Infrastructure [barnesandnoble.com].
    • Re: (Score:3, Informative)

      by Anonymous Coward
      IBM has developed IDEMIX, a pseudonymous credential system. It work on the same principle and is going to be contributed to the Eclipse project as open source! http://www.zurich.ibm.com/security/idemix/ [ibm.com] There is some white papers for those interested in the techno background.
    • by pavon ( 30274 )
      Thanks for that link. To be honest, I don't know that I'll get around to reading it due to my other school and work obligations, and the fact that security isn't my strong point (ability or interest wise), but stuff like this is what makes slashdot worth the noise.
  • by Nartie ( 1128613 )
    Why would any business want to use it? The bar that scans your drivers license gets some valuable information in the process. The porn site that asks for your credit card information to verify your age gets a credit card that they can use or sell. The bank that you ask for a loan gets all sorts of information, all of which it can sell or use to market itself. The current situation is bad for the customer, but the customer isn't the one who decides what verification system is used. None of this will change
  • and neither is privacy. This company is going to have a very hard time selling a solution to a problem they won't admit to. Most companies that gather information consider it a resource, and would rather gather it and promise privacy, than to not gather it and actually provide privacy.

    Consumers might adopt a solution like this if it were up to them, but I doubt anyone would pay for it, and no, this does require cooperation of both parties, so it is not up to them, and will not work independently on the cons
  • The notion of comparing two integers without knowing both simultaneously (or knowing intermediate results from which original
    numbers could be derived) sounds impossible. Can someone explain how the problem is solved in plain English (since IANA crypto expert).
    • Re: (Score:3, Informative)

      by Chexum ( 1498 )

      A practical application of this is at http://www.cypherpunks.ca/otr/ [cypherpunks.ca] (with a plugin for a few common AIM application, most usefully for pidgin née gaim).

      This one has an implementation called the "Socialist Millionaires Problem", which sounds the same, although I recall it being used only to tell if two secret values are the same on both side, thus augmenting the key exchange protocol with man-in-the-middle detection capabilities, provided the parties has shared knowledge about something (and somethin

    • Re: (Score:2, Informative)

      I can not explain to you how a comparison is done without leaking information (that is pretty involved), but I can understand the much simpler operation of addition.

      Imagine three millionaires in a room who wants to compute the sum of their incomes. Let us say that the millionaires can agree in advance that the sum can be represented by an integer in the range 0..100. They just need some upper limit, so the number could denote billions, trillions or whatever. Each millionaire then chooses three numbers a ran
  • During the pre-Web 1.0 days, there used to be something called as SET (Secure electronic transaction) Protocol for online payments. It worked by securing the credit card information which was only seen by the merchant's bank and not by the merchant himself. Hence, reducing theft of data and other blah. However, it failed to take off as it required additional infrastructure and internet users were daunted with certificates and e-wallets (a browser plugin).

    As I see, credentica has some kind of SDK. How would
    • by mlts ( 1038732 ) *
      Maybe a cryptographic token is the answer to this, be it an add-on to the SIM card of a cellphone, a civilian CAC, or a custom Aladdin eToken. When a purchase is done, the user has his cryptographic token (preferably by both a fingerprint swipe and a PIN) sign the order.

      For validing an ID, all it takes is a government CA adding certs onto someone's public key stating that they are above 21, not a felon, etc. Of course, all the certs are revocable, and ones that would possibly change (absence of a criminal
  • I worked at a web shop once, where clients use passwords to access their online accounts,

    At the time the database stored passwords in cleartext (guess they haven't heard of hashing then). When doing some work of course I can see everyone's passwords. People choose funny passwords. There's the obvious "password", "<my name>", or whatever.

    But there was one that was a strange 9 digit number. Later when I had a chance to talk to that person on the phone I got to learn that his password was his SSN.
  • There are plenty of simple things we could be doing already to make transactions more anonymous and secure, but companie and governments like getting all that information, and they collude to force customers to provide it.
  • terroristsdream (Score:5, Insightful)

    by noz ( 253073 ) on Saturday February 09, 2008 @09:36AM (#22359706)
    To the asshole who tagged the article `terroristsdream': terrorism is not an excuse to erode our right to privacy. Fuck off.
    • I second that! I can't understand how people actually believe nonsense like that. Lack of privacy is, by itself, a form of terrorism when taken to an extreme. I can safely say that I fear our own run-away government much more than "a few riled-up Muslims", as Brzezinski once said.
      • I can't understand how people actually believe nonsense like that. Lack of privacy is, by itself, a form of terrorism when taken to an extreme.

        I don't know about a "form of terrorism", but I'd say that trading privacy for safety, even if it worked, would be a bad trade.

        Jefferson's well-known quote is very appropriate: "The tree of liberty must be refreshed from time to time with the blood of patriots". Most people take this to mean that soldiers have to give their lives to preserve liberty, but I think there's another important truth in the statement: In some cases liberty is incompatible with safety, which means that people will die, includi

  • I think that Americans are hypocrites. who value privacy, but basically do nothing to insure it's protected.
  • by Fnord666 ( 889225 ) on Saturday February 09, 2008 @10:21AM (#22359970) Journal
    Simply put, this will not take off until businesses and corporations that warehouse our personal data are held financially liable for any losses that occur related to that data. Right now there is way too much positive financial incentive to hold onto as much consumer data as a company can, and almost no incentive not to. This situation will have to be reversed before companies will invest in a technology such as this.
  • by foniksonik ( 573572 ) on Saturday February 09, 2008 @10:42AM (#22360152) Homepage Journal
    When you pay with a credit card outside they make you verify the billing zip code. That's it. It's enough information to verify that you are either the primary card holder or know the person well enough to know their zip code. It's not cryptography in any sense but it does implement the concept of least necessary information rather well. They could ask for a lot more... your SSN or DOB for instance... but for the purposes of buying gas a zip code is just the right amount of info.
    • That's not smart. You could steal the card from the envelope it's delivered in, and instantly know the zip code. This is why cards and PIN numbers are mailed separately.
      • You have to activate cards before you can use them.... which means calling the activation number from the number you designated as your home phone.

C'est magnifique, mais ce n'est pas l'Informatique. -- Bosquet [on seeing the IBM 4341]

Working...