> And it seems a bit odd to be so fixated on essentially the 1988
> blue-book, from which most of the rest of the design followed.
> Surely there have been some more significant errors made since?
> (Snowdonia for example, to pick my own recent fav;-)

Snowdonia does prove the need for pervasive data level security at Fort
Meade. They don't seem to be having much luck.

I suggest that we help them out so that we don't have more Snowden stories.
Build some good specs for end-to-end and data level security and test them
out in the real world before they start using them.

A beta test of two billion people or so should easily be sufficient.

