* Identifying someone doesn't necessarily tell you much
endif; ?>In my last column, I started to discuss the REAL ID Act, which is currently back in the news because of a resurgence of strong opposition to its activation in 2008. I mentioned that I choose to dismiss one class of objections altogether: the notion that because there are ways around the restrictions of the REAL ID Act, it should be abandoned.
A much more serious objection to REAL ID as a security measure is rooted in how we use identification and authentication for security.
Bruce Schneier wrote clearly about this issue in an essay from a February 2004 “Crypto-Gram” newsletter. In “Identification and Security,” he makes the point that identification does not in itself tell us anything about the threat posed by an individual. Instead, an identifier allows authorities to compile profiles about individuals based on their recorded behavior – behavior that would be harder to compile without a unique, consistent identifier. Consider how much harder it is to track people who travel by bus and pay cash for their tickets than those who travel by air and use credit cards; but then ask yourself if travel patterns are sufficient to allow effective identification of terrorists.
The 9/11 terrorists all had identification papers – some authentic, some forged. You can read extensive excerpts from _9/11 and Terrorist Travel: A Staff Report National Commission on Terrorist Attacks Upon the United States_ on the Amazon Web site.
If a suicide bomber is sitting beside you on your flight from Chicago to Tampa, I really don’t think that knowing that person’s name before or after the explosion makes very much difference – in the absence of specific intelligence about that specific person. Simply having employees of state departments of motor vehicles demand birth certificates, green cards, U.S. passports or other acceptable documentary evidence of legitimate standing as legal residents of the U.S. tells us NOTHING about the risks posed by any individual.
More in my third and last commentary on this problem next time.




