The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits



Topics:  

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

RFID: Future Consumer-Data Battleground


Posted by , Aug 16, 2005 04:26 PM

I hate to be the one to say I told you so, but earlier this month, I declared in a posting here that the next big acknowledgement of a customer data compromise was right around the corner, and almost on cue, Sonoma State University in California and the University of North Texas separately revealed just a few days later that hackers recently swiped a combined 100,000 student records from the schools. So that got me thinking--what can I warn you about that would further my budding powers of prognostication? And it came to me rather quickly: RFID, the future frontier for consumer-data breaches.


In all the discussion of RFID's expected payoff in the areas of supply-chain visibility and real-time business processes, concerns over consumer privacy have been somewhat muted by promises that it will be a long wait before RFID finds its way into our homes in a big way. But find its way there it will, and when it does, there better be some pretty stringent security measures in place to keep our wallets and hidden shoeboxes from becoming low-hanging fruit in the eyes of hackers everywhere.

While it's not likely that an RFID tag embedded in a package of disposable razors is going to pose a whole lot of data-theft risk to consumers (we'll leave the privacy issues to another discussion), long-standing plans for RFID-enabled loyalty cards, credit cards, and passports, to say nothing of a potential national ID card, must have identity thieves drooling in anticipation.

Let's take loyalty cards, since they figure to get wrapped in less security than the more sensitive items mentioned here. Much of the talk about RFID in loyalty cards has revolved around the hotel industry and the desire to simplify check-in and streamline transactions while at a property. A loyalty card with a tag could be used to identify and check in a guest before he or she even walks up to the front desk (or a kiosk, for that matter), or charge his or her room for a meal or a gift-shop purchase. So what kind of data is behind a loyalty card? The usual name, address, phone number, and possibly E-mail address for starters. But depending on the comfort level of the guest in sharing data, not to mention the IT architecture that supports a loyalty program, it's possible a credit-card number could potentially be linked to that card. There could even be demographic data, such as income level, or personal preferences, such as favorite activities.

So would someone please offer me assurances that an enterprising identity thief--or even just a particularly ambitious phisher--couldn't drive through residential neighborhoods with RFID readers, zapping information from people's homes and then using it for nefarious purposes? I may be off my rocker here, but I believe there still haven't been enough assurances to date that can significantly ease such concerns. And what really scares me is that I'm not sure anyone can really offer any. All of which leads me to this not-so-happy thought: When it comes to consumer-data breaches, I'm convinced we're still very early in the curve.

« I'm Sticking With Travelocity Because Of Its Lousy Customer Service | Main | Per-Core Software Pricing For The Desktop? »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. HPC Joins the Dummy Revolution?
  2. Detecting Scalability Problems With Intel Parallel Universe Portal
  3. Just Say No To SFAQL Parallelism


Join The InformationWeek Group On LinkedIn


                           


  1. Motorola's CLIQ Improves With New Software Update
  2. Latest Motorola Android Phone To Feature HDMI Out?
  3. Video Calling Now Possible With iPhone
  4. Carriers Selling Info About You To Government


  1. U.S. Health IT Office Reorganizes
  2. Symplified Offers Federated ID For Cloud
  3. Acer Ranked Second In Global PC Market
  4. Microsoft Warns Piracy Surge Brings Malware
  5. Lenovo Offers AT&T Tech Support With PCs
  6. Google Accelerates Internet With Public DNS Service

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007