<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.ca.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Management : IAM Trends, biometrics</title><link>http://community.ca.com/blogs/iam/archive/tags/IAM+Trends/biometrics/default.aspx</link><description>Tags: IAM Trends, biometrics</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Verified Identity Pass Goes Kaput - Where is the Data Now?</title><link>http://community.ca.com/blogs/iam/archive/2009/06/24/verified-identity-pass-goes-kaput-where-is-the-data-now.aspx</link><pubDate>Wed, 24 Jun 2009 16:15:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2587</guid><dc:creator>Merritt Maxim</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/iam/archive/2009/06/24/verified-identity-pass-goes-kaput-where-is-the-data-now.aspx#comments</comments><description>&lt;p&gt;On Monday, Verified Identity Pass &lt;a class="" href="http://news.cnet.com/8301-13505_3-10270837-16.html" target="_blank"&gt;announced&lt;/a&gt; that it will cease operation of its Clear program at 18 airports throughout the U.S.&amp;nbsp; To the estimated 250,000 frequent fliers who had signed up for Clear Pass program and shelled out $200 annually for the privilege, this news was sudden and unexpected.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The Clear program was one of three registered traveler programs that enabled travelers to obtain priority at airport security.&amp;nbsp; In light of the extra waits often encountered at airport security following the new post-9/11 rules, these registered programs seemed attractive.&amp;nbsp; With Verified Identity Pass&amp;#39; announcement, the viability of such services is now in doubt.&lt;/p&gt;
&lt;p&gt;The initial &lt;a class="" href="http://www.usatoday.com/travel/news/2009-06-23-registered-flights-travel_N.htm?obref=obinsite" target="_blank"&gt;news&lt;/a&gt; on getting refunds back is not promising.&amp;nbsp; Disregarding the financial impact of not getting a refund, there is a much more important identity question to ask, &amp;quot;What happens to the biometric data of the registered travelers?&amp;quot;&lt;/p&gt;
&lt;p&gt;Biometrics are the one credential that cannot be revoked.&amp;nbsp; Passwords can be changed, users can be removed from directories, smart cards can be locked, and certificates can expire, but your fingers, eyes and face are with you.&amp;nbsp; And while most biometric systems only store a digital interpretation of this data, the point is that Clear possesses some unique data about 250,000 people and the future of that data is in some doubt.&amp;nbsp; The FlyClear &lt;a class="" href="http://www.flyclear.com/" target="_blank"&gt;website&lt;/a&gt; has this short statement &lt;/p&gt;
&lt;p&gt;&amp;quot;Applicant and Member data is currently secured in accordance with the Transportation Security Administration&amp;#39;s Security, Privacy and Compliance Standards. Verified Identity Pass, Inc.&amp;nbsp; will continue to secure such information and will take appropriate steps to delete the information.&amp;quot;&lt;/p&gt;
&lt;p&gt;On the surface, this sounds good, but given that the company is having financial difficulties, what assurances do we have that their systems are safe from attack and that personal data will not be compromised now? If the data is going to be deleted, what assurances are there that the data will be destroyed completely?&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t mean to be an alarmist and all data may be handled correctly, but this business failure raises some important policy questions about ownership and protection of personal biometric data by third parties.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;This will be an interesting case to monitor going forward.&lt;/p&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2587" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/biometrics/default.aspx">biometrics</category><category domain="http://community.ca.com/blogs/iam/archive/tags/data+loss+prevention/default.aspx">data loss prevention</category><category domain="http://community.ca.com/blogs/iam/archive/tags/DLP/default.aspx">DLP</category><category domain="http://community.ca.com/blogs/iam/archive/tags/FlyClear/default.aspx">FlyClear</category><category domain="http://community.ca.com/blogs/iam/archive/tags/IAM+Trends/default.aspx">IAM Trends</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Identity+Management/default.aspx">Identity Management</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Security/default.aspx">Security</category><category domain="http://community.ca.com/blogs/iam/archive/tags/TSA/default.aspx">TSA</category></item></channel></rss>