[Cryptography] Toxic Combination

Anne & Lynn Wheeler lynn at garlic.com
Mon Dec 8 14:48:00 EST 2014

Older observations. In the mid-to-late 90s, the CA industry was floating
a $20B/annum business case around wallstreet ... supposedly the financial industry
would front $100/customer/annum individual digital certificates. That didn't happen,
but they were heavily lobbying gov. to mandate $100/public/annum digital certificate.

We had gone into large financial institution that had been con'ed into doing
a CA-based online financial infrastructure. They had spent $50M on pilot ... but
when they told the board that the CA was asking that they send them 14M account
records which the CA would convert to 14M digital certificates and only charge
$1.4B ... the board shut the whole operation down.

We were then brought in to help wordsmith the California electronic signature
act which was under heavy lobbying pressure from the CA industry to mandate
digital certificates.

