mobile user
Device fingerprinting is the practice of giving all end user systems a unique signature

RSA 2009: Benefits and dangers of device fingerprinting

Financial institutions bullish on new system, but privacy concerns loom

Shaun Nichols in San Francisco

Security experts and privacy advocates weighed the merits of device fingerprinting on Thursday.

The RSA conference panel discussed current and emerging forms of the practice, which involves identifying each device used to access an account with a unique tag or signature.

Advertisement

With each device assigned its own 'fingerprint', administrators can then be instantly alerted to potential fraud.

For some companies, the practice is already paying big dividends. Wachovia Bank online customer protection specialist Chirs Mathes said: "Device fingerprinting gives us a very powerful tool to look at devices as they are coming in. If I have already identified a device as being owned by a bad guy, I can decide whether or not I even want to let them in the front door."

The practice is not, however, without its critics. Electronic Frontier Foundation civil liberties director Jennifer Granick warned that the information banks gather from the digital fingerprints could be used for more than just security.

"The question is what kind of privacy protection is there, and the answer is very little," said Granick.

"One thing we really do not want is for this information to be shared with affiliates who do advertising or marketing, because then you have the same problem we have with cookies, but much worse."

While the situation appears to put security and privacy at odds, there may be a system that can allow for a compromise.

41st Parameter founder and chief executive Ori Eisen suggested that banks look to adopt so-called 'tagless' fingerprinting, which uses components such as JavaScript and system profiling rather than simpler cookie or IP tracking 'tag' components.

Eisen said that not only could the tagless system be far more accurate and reliable than tag systems, but the collected data would also be less likely to raise privacy concerns.

"What we are going to ask is 300 questions that you could ask about the vendor's APIs, but none of it is personally identifiable information, I would never know who is on the other end."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Unisys logo

Unisys reveals new security trends

At RSA 2009, IT services firm talks of recent survey and new offerings

sweets

RSA 2009: Layer up for security, say experts

Panel warns against relying on monolithic systems

RSA 2009: McAfee's DeWalt touts Predictive Security

Interconnected system lets multiple security apps share data on potential threats

RSA 2009: FBI agent gives inside story of Dark Market bust

Agent Mularski reveals how his undercover operation helped foil a major cybercrime ring

Related whitepapers

Related jobs

Most watched

Salesforce.com on the new Chatter service

Company explains the need for collaboration service

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events, plus T-Mobile sells customer data

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events,...

Apple iPhone apps

Top 10 articles, 20 Nov 2009

An App Store upset for Apple, and a scandal at...

Biz Stone

Twitter founder details commercial account plans

Biz Stone says paid-for accounts will give users access to...

Cloud computing

Enisa launches comprehensive cloud security report

EU security agency provides checklist for firms looking to vet...

Primary Navigation