OASIS Open Mailing List Archives  ·  All Lists  ·  idtrust-sc  ·  2007-06

idtrust-sc — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Re: RE: [idtrust-sc] FW: Geneva Security Forum-Program Involvement


I concur with many of your observations, John. In one sense, I am starting to become grateful that the US cannot get its act together wrt a national identity card or system, because laws in the US supporting individual privacy rights are significantly weaker than those in the EU. If our current administration is capable of abusing individuals' privacy and rights to the extent it has without a national identity system in place, I shudder to imagine what might be possible if national ID cards existed in the US. I believe the American consumer needs to become a little enlightened about digital privacy before the US will even come close to what the EU now takes for granted. In the meantime, we hope to create standards and guidelines for protecting information across the enterprise and establishing strong authentication controls (through PKI) to create higher levels of assurance. The standards are definitely going to be in place long before the laws are, but with just a few more TJX-like episodes and lawsuits, and I think businesses will start clamoring for laws for greater levels of security across the board, to level the playing field. Arshad Noor StrongAuth, Inc. Content-Type: multipart/alternative; boundary="----_=_NextPart_002_01C7ACF9.5439CA7D" ------ _=_NextPart_002_01C7ACF9.5439CA7D Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Patrick, =20 June may have different perspectives, but I would say that as a general = statement, Europe tends to address trust issues more deliberately and = more comprehensively, as illustrated in many EU member states building = national identity management systems for government and business = purposes, and their acceptance of the utility of national identity = schemes supported by strong security controls, including user identity = and authentication. =20 My sense is that the US is balkanized in that trust systems are = developed to address specific government and business needs, but = comprehensive digital identity systems utilizing PKI and strong, = national digital identity systems are uncommon (excepting SSL, if you = assume server identity fits the definition). Examples include the = current contention over the Real ID legislation, which sets a mandate = for drivers licenses that will serve as identity cards, but which will = be issued by the States with many different formats and at least under = the current scheme differing security standards. Continued pushback from = States on funding, privacy and other issues is also another symptom of = the US balkanized approach. Likewise, Homeland Security presidential = Directive 12 (HSPD-12) requires Federal agencies to issue identity = credentials using PKI for physical and logical access, and while the PKI = components of the NIST FIPS-201 standard are clear, the infrastructure = needed to support the cards for full functionality is not = well-addressed. =20 These are just a couple of my general observations. =20 Attached is the presentation I gave at the NIST PKI workshop. You = should be able to extract talking points for your talk. =20 I hope this is of help. =20 John=20 =20 =20 =20 __________________________________ John T. Sabo, CISSP=20 Director, Global Government Relations CA, Inc.=20 Suite 1220 1401 I Street NW Washington DC 20005 =20 Tel: +1 202-513-6304 Mobile: +1 443-629-6198=20 Fax: +1 202-513-6395 ------------------------------------ =20 This e-mail message is for the sole use of the intended recipient(s) and = may contain confidential and/or privileged information. Any unauthorized = review, use, disclosure or distribution is prohibited. If you are not = the intended recipient, please contact the sender by reply e-mail and = destroy all copies of the original message. =20 ________________________________ From: Patrick Gannon [mailto:[email protected]]=20 Sent: Tuesday, June 12, 2007 8:21 AM To: [email protected] Cc: 'Jane Harnad'; 'Carol Geyer' Subject: [idtrust-sc] FW: Geneva Security Forum-Program Involvement =20 June, =20 I have been asked to speak on the Trust & Security panel at the Geneva = Security Forum on 20 June. http://www.genevasecurityforum.org/Programmes.aspx =20 If you, or others on the IDtrust MS SC, have specific suggestions on = points I should make in my 5 minute intro, please send those suggestions = to me. In this Forum panel, we will not be using slides. For this = audience, I will have to explain (very briefly) who/what OASIS is and = will then mention the range of security-related work at OASIS, with = special mention of the IDtrust MS and the PKI Adoption TC and the EKMI = TC. =20 What I am looking for input on is "geopolitical differences in = approaches to trust issues, PKI, Digital IDs". =20 Thank you very much. =20 Patrick Gannon =20 =20 From: [email protected] [mailto:[email protected]]=20 Sent: Tuesday, June 12, 2007 2:58 AM To: 'Patrick Gannon' Cc: 'Nancy Knowlton M=E9an'; 'Daniel Stauffacher'; 'Carlos Moreira'; = 'Rosa Delgado' Subject: Geneva Security Forum-Program Involvement =20 Dear Mr Gannon, =20 We are very pleased that you will be able to join us for the inaugural = Geneva Security Forum next week and would be delighted to integrate you = into the following session: =20 20 June, 14:45-16:00 Trust and Security A look at ICANN TLD domain names, geopolitical differences in approaches = to trust issues, PKI, Digital IDs and Quantum Cryptography. =20 Eva Fr=F6lich, Interim Chair & President of the Public Interest = Registry, PIR, Sweden Patrick Gannon, President & CEO, OASIS Ram Mohan, Vice President of Business Operations, Afilias & Member of = the Security and Stability Advisory Committee (SSAC)=20 Carlos Moreira, Co-Founder, Chairman/President, WISeKey SA=20 Gerold H. Werner, Max-Consult AG, Switzerland=20 =20 Chaired by: Nitin Desai, Former UN Under Secretary General for Social and Economic = Affairs and Chairman of the Internet Governance Group =20 In the interests of keeping the discussions as interactive and dynamic = as possible, each speaker will have approximately 4-5 minutes to present = his/her key points at the beginning of the session. We will then move = directly to an interactive discussion amongst the panelists and with the = audience. Keeping this goal in mind, we will not be providing for the = use of power point or audiovisual presentations. =20 Please do not hesitate to contact me should you have any questions or = concerns. =20 With my best regards, =20 Barbara Weekes Director, Strategy and Content Geneva Security Forum =20 ------ _=_NextPart_002_01C7ACF9.5439CA7D Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]