Technology Review - Published By MIT
Log in to My.TechnologyReview.com | Register
Advertisement
[1] 2 Next »

Friday, February 02, 2007

Using the Internet Anonymously?

New open-source software by IBM could let people minimize their digital footprints, potentially curbing online fraud.

By Kate Greene

smaller text tool iconmedium text tool iconlarger text tool icon
New open-source software from IBM could make using the Internet safer by letting people make purchases online and sign up for Web services without having to divulge personal information.
Credit: IBM's Zurich Research Laboratory

Think about the last time you bought a DVD, booked a flight, rented a car, or signed up for a service or newsletter on the Internet. At some point, you had to fill out a form that asked for a lot of personal information. While it's a hassle unto itself, filling out forms can lead to a bigger problem: each time you give out your information, you provide an opportunity for your information to be picked off by identity thieves.

As more services migrate online, and as tactics of identity thieves become more sophisticated, people will need better ways to manage their information, says Nataraj Nagaratnam, chief architect of identity management for IBM Tivoli.

Nagaratnam and other IBM researchers have developed open-source software that they think can help. Called Identity Mixer (Idemix), the digital identity management software lets people make online transactions--from filling out forms to purchasing plane tickets--without disclosing personal information. The software lets a person use artificial identity information, in the form of digital "tokens," to make online transactions. Using these encrypted tokens, which are issued by trusted sources such as the Department of Motor Vehicles (DMV) or a bank, a person can effectively be anonymous to Web services such as Amazon.com or Expedia, never giving out his or her information.

In a typical online purchase, Idemix could obviate the need for a person to fill out a form or reveal her credit-card number. Instead, she could use a token that vouches for her, verifying that she is who she says she is and that she has the appropriate funds and credit to make a purchase.

In addition, these tokens would provide only the information that is needed. For instance, if you're renting a car online and need to verify that you're older than 25, a token from the DMV could verify that you can legitimately rent without divulging your birth date, license number, or address. Otherwise, you reveal more than you need to about yourself, says John Clippinger, senior fellow at the Berkman Center for Internet and Society at Harvard Law School. "It's like using a passport when you buy a Coke."

To explain digital identity management, Clippinger draws from a real-world example: we have wallets that hold identifying cards such as a license or credit cards, he says, but we don't have an analogy in cyberspace. "It's hard to make people appreciate things like privacy and [online] identification," he says, "but I think these things are going to become much more critical."

[1] 2 Next »

Comments

  • Tokens?
    makornitzky on 02/02/2007 at 9:33 AM
    Posts:
    10
    Avg Rating:
    5/5
    Fine -- until someone starts counterfeiting them
    Rate this comment: 12345
  • and then...
    rwn3 on 02/02/2007 at 10:31 AM
    Posts:
    6
    Avg Rating:
    4/5
    to deal with the information already out there.  Both IBM's and Microsoft's products are a step in the right direction.
    Rate this comment: 12345
  • One-Word Investment Tip...
    Monsterboy on 02/02/2007 at 6:10 PM
    Posts:
    53
    Avg Rating:
    4/5
    Porn.
    Rate this comment: 12345
  • not really anonymous
    dat on 02/03/2007 at 7:53 PM
    Posts:
    2
    DMV would still know what you did last summer. So maybe the theives won't know, but someboy must know.
    Rate this comment: 12345
  • it's not a question of anonymity
    dat on 02/03/2007 at 10:12 PM
    Posts:
    2
    It's a question of whether we are absolutely able to choose who to pass information to.
    Rate this comment: 12345
  • Other Tools
    ztracy on 08/10/2007 at 8:18 AM
    Posts:
    2
    Appalachian from MIT's Simile is a tool that exists to manage OpenIDs from within Firefox.  I wonder how this tool could be integrated with Idemix.  If they could it would mean a much less cumbersome online experiences. 

    Rate this comment: 12345
Advertisement

Current Issue

Technology Review July/August 2008
The Business of Social Networks
The future of the Web is social. But can social-networking sites ever make money?
•  Subscribe
Save 41%
•  Table of Contents
•  MIT News

Magazine Services

Career Resources

MIT Technology Insider

Stories and breaking news from inside MIT about the latest research, innovations, and startups--in a convenient monthly e-newsletter. Subscribe today
Advertisement

More Technology News from Forbes

Advertisement
Advertisement
Advertisement
TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology