[KEYPROV] NSTIC - National Strategy for Trusted Identities in Cyberspace

Anders Rundgren <anders.rundgren@telia.com> Thu, 19 August 2010 08:41 UTC

Return-Path: <anders.rundgren@telia.com>
X-Original-To: keyprov@core3.amsl.com
Delivered-To: keyprov@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D0BCE3A6863 for <keyprov@core3.amsl.com>; Thu, 19 Aug 2010 01:41:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.349
X-Spam-Level:
X-Spam-Status: No, score=-0.349 tagged_above=-999 required=5 tests=[AWL=-0.700, BAYES_50=0.001, HELO_EQ_SE=0.35]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YFNqhU4RxSCq for <keyprov@core3.amsl.com>; Thu, 19 Aug 2010 01:41:55 -0700 (PDT)
Received: from mail.primekey.se (walter.primekey.se [195.149.137.136]) by core3.amsl.com (Postfix) with ESMTP id 797623A689C for <keyprov@ietf.org>; Thu, 19 Aug 2010 01:41:13 -0700 (PDT)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by mail.primekey.se (Postfix) with ESMTP id C9F47C3E06; Thu, 19 Aug 2010 10:38:29 +0200 (CEST)
Message-ID: <4C6CED85.4090602@telia.com>
Date: Thu, 19 Aug 2010 10:38:29 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20090817)
MIME-Version: 1.0
To: KEYPROV <keyprov@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Subject: [KEYPROV] NSTIC - National Strategy for Trusted Identities in Cyberspace
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Aug 2010 08:41:56 -0000

http://www.whitehouse.gov/blog/2010/06/25/national-strategy-trusted-identities-cyberspace

    "For example, no longer should individuals have to remember an 
ever-expanding
     and potentially insecure list of usernames and passwords to login 
into various
     online services"

    "...a digital certificate on their cell phone..."

For once a government plan that doesn't propose a singular solution 
addressing a fraction of a user's need for authentication on the Internet.

It will be challenging though since there is no *usable* way getting 
certificates in phones not to mention that smart cards cannot be 
provisioned on-line using the software provided by the great US platform 
vendors like Microsoft, Apple and Google.

If this initiative is properly run it could (unlike their EU 
counterparts) actually become the foundation for the rest of the world.

Although it may be premature I think that enhanced USB memory sticks is 
a more viable approach than eID.  You don't need a photo-ID on the 
Internet.  USB memory sticks can host any number of credentials and is 
something people actually buy for their own money.

Ladies and Gentlemen, let the fun begin!

Anders