Watch out: There's an ID thief about

Danny Bradbury reports on how businesses are coping with identity fraud.

Danny Bradbury

When someone says 'get a life', they don't generally mean 'take mine'. But that's exactly what happened to more than 100,000 people in the UK last year.

ID theft - where someone steals the identity of another by conventional and electronic means - has become a huge problem.

Advertisement

According to fraud prevention service CIFAS, the number of cases of identity fraud in the UK has increased dramatically since 1999, when 20,000 cases were reported.

By 2001, this figure rose to 53,000, and last year that number had almost doubled again.

The organisation cites Cabinet Office figures suggesting that ID theft cost the UK economy £1.3bn in 2002 - just under one-tenth of the total cost of fraud in the UK.

This is not surprising, given that the top target areas for identity and impersonation fraudsters, as identified by CIFAS, are plastic cards, communications, retail finance, and banking.

Gareth Jones, director of fraud products at customer relationship management company Experian - which runs a service for the victims of fraud in the UK - says 90 per cent of ID fraud is prevented at the point of application.

That raises the question: how can we be sure, given that some ID fraud is presumably never detected?

There are signs that neither companies nor individuals are being as vigilant as they could be when it comes to ID fraud.

Statistics gathered by Experian's service for fraud victims indicate that accounts remained open for an average of 16 months before owners discovered they had been compromised.

High-tech fraudsters use phishing emails to coax account information out of unwitting internet users, but there are other more traditional ways to steal someone's identity.

According to Peter Dorrington, head of fraud solutions at software vendor SAS, many ID thieves will use the Electoral Roll to discover your name, address, and marital status.

Information about parents and birthplaces can be found in genealogy databases, and birth certificates can easily be requested.

Searching through bins is a good way to find old credit card slips and other correspondence to identify your bank, mobile phone account number, or other sensitive information. These documents can often easily be scanned and altered.

While much identity fraud still happens offline, and must be addressed by other means, IT vendors and customers alike are nevertheless working on mechanisms to reduce the opportunity for internet-based ID theft.

One of the most popular movements in this area is federated identity management.

The Liberty Alliance, a consortium including companies such as American Express, American Airlines, Sun Microsystems and Intel, is its key proponent.

Federated identity works on the principle that any friend of company A is also a friend of company B, as long as the two companies have established a trusted relationship with each other.

Theoretically, it will resolve one of the biggest issues for users of the internet: password management. Most people are bad at managing passwords for different online services such as banking, retail, and chatrooms.

Instead, they tend to use the same usernames and passwords for everything, meaning that if one of their accounts is compromised, thieves can easily gain access to everything else.

Federated identity management allows users to retain just one password and username for a group of companies that have established a circle of trust.

Entering those credentials on the web site of any one of those companies results in the exchange of an opaque handle (that doesn't include any of your personal information), which lets one company verify your identity with another.

Vendors are pushing the technology hard. "What you need is a runtime operational model, and it takes an established trust relationship," says Kevin Cunningham, director of identity marketing at Sun Microsystems, which has folded support for the Liberty specification into its server identity management product.

"Liberty as an operating model for federation is definitely a large part of the future."

However, not everyone is convinced that this future is rosy. Chris Wysopal, research and development director at security consultancy @Stake, doesn't think that companies want to be separated from their customers, even by a mechanism that the Liberty group defends as non-intrusive.

"People who are building applications want to have that one-to-one relationship with the customer,' he maintains. "They don't want anyone in between."

Building trusted relationships between companies may be a challenge, but Liberty is addressing this by offering advice to implementers in the form of White Papers.

Providing materials and developing the specifications is Liberty's sole role. It is up to member companies to fold the specifications into their systems, as Ping Identity has done.

The company, which sells an open source federated identity management system called SourceID, also operates PingID, a framework supporting numerous federated identity protocols, including Liberty's.

Linda Elliott, network president, says the framework encompasses legal frameworks and agreements to make the creation of trusted relationships possible.

It already has several members, she claims, including a Finnish telecommunications company.

This is important, because telecommunications and financial services firms are likely to pioneer the federated identity movement if it takes off, simply because they are conduits for so many consumer accounts and are generally trusted by customers.

But for now, at least some of the federated identity case studies available are focused on business-to-business use.

Market analyst Burton Group has published a report on Boeing's use of the Liberty system as a means of letting business customers access its range of 'My Boeing Fleet' customer-focused applications through their own portals.

Boeing, which deals with more than 12,000 suppliers worldwide, partnered with Southwest Airlines for the federated identity system.

Under the initiative, customers log onto their own portal and receive an encrypted cookie, which is then fed to a server inside the airline that provides data wrapped in the Software Assertion Markup Language (SAML) - a building block of the Liberty specification that encodes authorisation data.

The SAML data is then sent to the Boeing server, which verifies the data and generates a Boeing cookie for the customer's browser before redirecting the browser to the relevant internal Boeing application.

The benefit is that the user only has to sign on once to their own portal, rather than signing separately to the Boeing server.

While organisations such as Liberty look after identity management on the server, Microsoft (notable by its absence from the Liberty member roster) is tackling the client.

The Longhorn Windows client will support the Next Generation Secure Computing Base (NGSCB), Microsoft's attempt to lock down PCs so that they cannot be tampered with by unauthorised software.

Users will be able to secure their personal details in protected memory that can only be accessed by user-authorised software, meaning that legitimate programs can hide data such as credit card details from malicious Trojan horse software.

The best protection against ID fraud is awareness of the dangers, and to teach both staff and customers to be diligent.

The basic steps are very low-tech. For consumers, protecting personal information and thinking twice before giving it out is vital, while for companies, technical wizardry will be useless unless you instigate policies to properly vet customer identity.

Common sense is the best security application of all.

What protection is available now?
There are several technologies available to help protect against identity fraud. The most promising is chip-and-Pin, which began its rollout last October.

Instead of signing a slip of paper when paying by plastic card, users enter a Pin. This avoids signature fraud, while the chip verifies that the card is genuine.

Visa's Verified by Visa initiative is designed to protect online shoppers. Customers access Visa's secure server to create a password that is linked to their card. They can then enter the password to confirm their identity while shopping online with participating suppliers.

Biometric devices make it more difficult for ID fraudsters to use forged or stolen documents. By requesting a fingerprint or iris scan, organisations can be more confident that someone accessing a system is legitimate.

Heathrow Airport has already successfully trialled iris-scanning systems to help identify frequent travellers, and they are to be introduced at other airports by this summer.

BEST PRACTICE IN STOPPING IDENTITY FRAUD

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Authenticated identity from single log-in

IBM unveils federated identity server

Tivoli Federated ID Manager promises fewer passwords and enhanced security

Cyber fraud arrests

28 arrested in global web fraud sting

Worldwide organised crime network dealing in ID theft and fraud

Pets' names most common UK passwords

Users ignore security advice and stick with sentimental log-ins, finds survey

Pets' names most common UK passwords

Users ignore security advice and stick with sentimental log-ins, finds survey

Related whitepapers

Related jobs

Most watched

Social networking

Summit: How businesses should manage their brands online

In part one of V3.co.uk's interview with Dirk Singer, he dicusses social media monitoring strategies

RIM discusses new developer tools

Blackberry exec on the latest offerings for programmers

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

simon perry

Comment: Information overload is a price worth paying if it helps the planet

Analyst Simon Perry argues that the data deluge doesn't have...

Summit: Views From the Valley

V3.co.uk's US office weighs in on the information overload crisis

money

Summit: Managing information overload in a recession

Balancing exploding data with shrinking budgets

Chambers outlines Cisco's corporate plans

CEO describes broader company focus

Primary Navigation