5 ms·
Why is the federal government's involvement necessary? We have a (mostly) workable PKI system for SSL certificates. Why does a consumer-focused PKI require go
by recampbell 16y ago
Why is the federal government's involvement necessary? We have a (mostly) workable PKI system for SSL certificates. Why does a consumer-focused PKI require government coordination?
I think the lack of a widely deployed PKI for authenticating consumer's identities is an indicator that a novel approach is required, but what can the federal government do that an independent (perhaps multi-national) organization could not?
- wmf 16y agoYou've gotten to the real issues here. If the problem is lack of industry consensus (i.e. N standards instead of one), maybe the government can bully the industry into picking one.
- protomyth 16y agoI'm really not sure we are at the point where we should be picking. We are still very early and e-commerce seems to be doing fine without it.
- wmf 16y agoWe are "very early" in the sense that we're in the same place as 1996: usernames, passwords, credit card numbers, and SSL. (Or maybe we're worse off, since we didn't have much phishing in 1996.) What is it going to take to get some progress here?
- webXL 16y agoIt's not the government's job to pick winners and losers. Think about the words you selected: bully and progress. Together those don't sound very democratic to me. It's ends justifying the means thinking that gets well-intentioned people into trouble. Progress is people wising up about security, not forcing them to use certain technologies.