The Real Deal

Plans for a national ID card face obstacles and opposition

In spite of, or perhaps because of, my 30 years of military service, I remain skeptical of both the efficiency of government and how much government can be trusted to handle large volumes of private information.

It was only last year that an employee of the Department of Veterans Affairs took home the files of 25 million veterans without authorization and against department policy<\m>and it was stolen. In my opinion, the prospect of a national ID card required by the REAL ID Act of 2005 raises serious concerns about privacy, data security, cost, fairness and mission creep that should be fully scrutinized before implementation.

The Bush administration and the 9/11 Commission have promoted the REAL ID system as an important tool for homeland security, but a significant number of computer security experts say its design is flawed and insecure. Privacy advocates have raised strong concerns about an increased risk of privacy loss, identity theft, racial tracking and monitoring of citizens.

While the actual regulations and technical specs are expected to be handed down by the Department of Homeland Security this fall, the expectations are widely understood: States will be required to implement systems and databases to electronically and securely capture, store and share a significant volume of citizen documentation that proves identity, lawful status, date of birth and Social Security number. Each state must be able to share its motor vehicle database with all other states, and the database must include, at a minimum, all the information printed on state driver's licenses, plus drivers' history, including motor vehicle violations and suspensions.

DHS insists the REAL ID Act is an essential tool to fight the war on terror. In its proposed implementation plan, the department found that the threat posed by terrorist travel within the United States demands a systematic and comprehensive ID system. The act aims to weave driver's licenses and state ID cards into a machine-readable ID card with a digital photograph that is necessary to travel on an airplane, open a bank account, collect Social Security payments or take advantage of nearly any government service. States must begin to issue the new federal licenses, mandatory for all "federal purposes," by May 11, 2008, but states can request an extension until Jan. 1, 2010. Extension or not, full compliance is required by 2013. A DHS spokesman has warned that people in states that don't comply by that date will be required to use passports, as no federal agency will accept a state-issued driver's license as a valid form of ID. People will need to use passports at federal buildings and parks and for domestic air travel.

Congress passed the REAL ID Act as part of an emergency military spending and tsunami relief bill, Public Law 109-13, to carry out a proposal suggested by the 9/11 Commission that reported that some of the September 11th hijackers had fraudulently obtained state driver's licenses. But critics argue the plan is misguided, insufficiently privacy protective and prohibitively expensive. The National Governor's Association estimates the cost at $11 billion over five years. States hoping for federal help to comply with REAL ID will have to find other funding sources to pay for the technology, since on July 26, the Senate shot down an amendment that would have earmarked $300 million a year to help states pay for the technology requirements needed to comply. To date, the federal government has provided only $40 million toward implementation. The DHS budget is expected to increase another $50 million on Oct. 1.

In spite of limited federal funding, the scope of REAL ID implementation is very broad. To illustrate the various components of the process, last June, the DHS developed a concept of operations.

First, the REAL ID program governs the external inputs in the state driver's license (DL)/ID issuing system: DL/ID holders and applicants, the identity documents they are required to provide and the card stock that state DMVs will use for card production. While the institutions issuing identity documents are not directly regulated by DHS, they will be impacted by the requirements of the REAL ID program.

Second, the REAL ID program governs the operations of state and territorial DMVs with respect to: • Processes for verifying the identity of applicants and the identity documents they provide. • Storage of identity documents. • Verification of applicant data. • Appearance and security elements of DL/IDs. • Security standards for card production and issuance. • Training and clearances for key DMV employees.

Since the operations of state DMVs are governed by individual state laws and regulations, they may need to be modified based upon the proposed rule.

Third, REAL ID requires verification of applicant data with a number of federally sponsored databases. In addition, federal databases will be accessed as part of the clearance process for DMV employees.

Fourth, communications systems need to be developed or enhanced to query federally-sponsored systems and state DMV databases for data verification. These two data communications processes can be separate and respond to different requirements in the statute and REAL ID implementation. State DMVs will need to query federally sponsored systems, either directly or indirectly, to verify applicant data. On the other hand, state DMVs also will need to query other state DMV databases to ensure that applicants are not previously issued REAL ID-compliant licenses in other states. Finally, all of the components and processes impacted by REAL ID will require assessment of privacy impacts to ensure that data is appropriately safeguarded.

The real issue for states can boil down to the cost of implementing and maintaining the systems required to support REAL ID. Legislatures in 17 states have opposed the act, but most of those objections were related to concerns about paying for REAL ID, and the opposition could dwindle if more federal money is made available.

If the Real ID system is the important tool for homeland security that the administration and 9/11 Commission believe it to be, they should find a way to fund it and put in the safeguards necessary to protect our privacy. If they are not willing to do that, they should stop the charade.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.