<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Paul Karger: Privacy and Security Analysis of the Federal Employee Personal Identification and Verification Program</title>
	<atom:link href="http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/feed/" rel="self" type="application/rss+xml" />
	<link>http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/</link>
	<description>Every system has a user.</description>
	<pubDate>Thu, 20 Nov 2008 21:16:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>By: Anand</title>
		<link>http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-46641</link>
		<dc:creator>Anand</dc:creator>
		<pubDate>Sat, 21 Apr 2007 03:59:33 +0000</pubDate>
		<guid isPermaLink="false">http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-46641</guid>
		<description>Sir,I want to kno the process to certify the product for FIPS210.I want to kno the necessary requirement for FIPS 210.Wht is the time require to certify the product &#38; norms on basis of which the product is certified.We want to certify our smartcard based access control reader.

Waiting for your reply.</description>
		<content:encoded><![CDATA[<p>Sir,I want to kno the process to certify the product for FIPS210.I want to kno the necessary requirement for FIPS 210.Wht is the time require to certify the product &amp; norms on basis of which the product is certified.We want to certify our smartcard based access control reader.</p>
<p>Waiting for your reply.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anshuman Sinha</title>
		<link>http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-46631</link>
		<dc:creator>Anshuman Sinha</dc:creator>
		<pubDate>Sat, 21 Apr 2007 02:27:58 +0000</pubDate>
		<guid isPermaLink="false">http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-46631</guid>
		<description>Anand,  Let me know how I can guide.  Cheers.</description>
		<content:encoded><![CDATA[<p>Anand,  Let me know how I can guide.  Cheers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anand</title>
		<link>http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-17413</link>
		<dc:creator>Anand</dc:creator>
		<pubDate>Sat, 09 Dec 2006 06:03:54 +0000</pubDate>
		<guid isPermaLink="false">http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-17413</guid>
		<description>Dear Sir,

I want to know more about the FIPS 201 standard.I am working with company dealing in Smartcard based reader,biometric based reader for access control &#38; time attendance system. We want to cerify our product 
Can you please guide inthe same.

Thanking You</description>
		<content:encoded><![CDATA[<p>Dear Sir,</p>
<p>I want to know more about the FIPS 201 standard.I am working with company dealing in Smartcard based reader,biometric based reader for access control &amp; time attendance system. We want to cerify our product<br />
Can you please guide inthe same.</p>
<p>Thanking You</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anshuman Sinha</title>
		<link>http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-13575</link>
		<dc:creator>Anshuman Sinha</dc:creator>
		<pubDate>Mon, 06 Nov 2006 20:53:37 +0000</pubDate>
		<guid isPermaLink="false">http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-13575</guid>
		<description>Another minor slip ...  

HSPD-12 requires identification for not only federal physical entities like buildings, but also information systems, logical access to federal electronic resources and data that is almost as crucial and secret.

PIV 1 has some security weaknesses as well which is worth noting before recommending it as an alternate to PIV II.  PIV I in many ways is not vendor neutral ...</description>
		<content:encoded><![CDATA[<p>Another minor slip &#8230;  </p>
<p>HSPD-12 requires identification for not only federal physical entities like buildings, but also information systems, logical access to federal electronic resources and data that is almost as crucial and secret.</p>
<p>PIV 1 has some security weaknesses as well which is worth noting before recommending it as an alternate to PIV II.  PIV I in many ways is not vendor neutral &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ping</title>
		<link>http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-5786</link>
		<dc:creator>Ping</dc:creator>
		<pubDate>Fri, 14 Jul 2006 18:31:45 +0000</pubDate>
		<guid isPermaLink="false">http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-5786</guid>
		<description>Oops!  Thanks for the correction.</description>
		<content:encoded><![CDATA[<p>Oops!  Thanks for the correction.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Karger</title>
		<link>http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-5785</link>
		<dc:creator>Paul Karger</dc:creator>
		<pubDate>Fri, 14 Jul 2006 18:28:25 +0000</pubDate>
		<guid isPermaLink="false">http://usablesecurity.com/2006/07/14/paul-karger-privacy-and-security-analysis-of-the-federal-employee-personal-identification-and-verification-program/#comment-5785</guid>
		<description>There is a slight error in the description above.

FIPS 201 does require encryption for contact cards, but the strong keys that are there by default are restricted to the contact interface.  Your can use encryption on the contactless, but you have to use a different key (which you can get, but it's optional).

See the paper for more details on this.</description>
		<content:encoded><![CDATA[<p>There is a slight error in the description above.</p>
<p>FIPS 201 does require encryption for contact cards, but the strong keys that are there by default are restricted to the contact interface.  Your can use encryption on the contactless, but you have to use a different key (which you can get, but it&#8217;s optional).</p>
<p>See the paper for more details on this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
