From: Anders R. <and...@gm...> - 2013-08-17 05:11:09
|
When I look into the OpenSC mailing list I wonder if something isn't fundamentally broken. In the end (after provisioning) all smart PKI cards do more or less the same thing; That is, performs a pretty well standardized RSA or EC operation. Wouldn't it be a better use of resources defining a standard PKI card where the operating system vendors provide the *single* driver instead of relying on installation of third-part SW? With automatic updates (of OS and Token), you wouldn't be stuck with a specific design either. The static structure of current PKI-tokens is extremely counter-productive. There are no security issues doing firmware updates on-the-fly; it just requires a bit more memory in order to be robust. Naturally this wouldn't stop anybody from continuing creating "unique" cards but a guess is that these cards would only attract a fraction of the market. Anders |