Yes, SAML has a security and privacy considerations sub group (and spec chapter). I see that XACML has not established such a group. We certainly should do so. On a theoretical note, human activities are inherently imperfect. Safety engineering tries to prevent errors and minimize their effects. However in the security business you always have to start by assuming something works (at least mostly) or else there is no place to stand. This is the true technical meaning of trusted. A prime example is the TCB concept. In my former life as a consultant, I remember several conversations in which the person I was talking to was making such drastic assumptions about the untrustworthiness of certain components, that it seemed impossible to make any statement about the security properties of the system in question. Security is a form of risk management and it is necessary to weigh both the probability of compromise and its impact. Hal >