I have a rather orthogonal comment to this.

If you search for "Payments" or "GPEA" (Government Paperwork Elimination Act)
in the FIPS-201 and SP800 documents you get zero hits.

This part will be the biggest difference between PIV and its yet to be
launched European counterparts.

That is, the well-known US obsession for "security" comes at a price:
Limited utility.  In the EU we can't afford programs with such a limited
scope except maybe for the 51:th state (The UK).

There is a background to all this.  Which Internet standard used by all 
"Netizens"
has the lowest degree of security and credibility?  That ought to be e-mail.
The e-mail security add-on (S/MIME) was mainly designed by NIST/FPKI/IETF 
(essentially the same guys with different hats on) which has never gotten widely
used as it does not scale outside of tightly managed circles.  As we all know
this has led to a very costly spread of e-mail-based viruses, spam and phishing.
PIV is actually closely related to this proven deficient security architecture.
The alternative takes another angle on security which is built on proven methods
of establishing trust on a global scale, mainly borrowed from the financial 
sector.

What's a bit odd is that almost all the technology for the likely alternative
("a scalable and secure architecture for information exchange and 
collaboration")
is actually coming from US SW and HW vendors!

Anders

_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to