Re: Outreach via wikipedia articles on authentication and authorization

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD53E6B8CE1@G4W3222.americas.hpqcorp.net>
Rob Meijer wrote:
> 
> In that case you shill have authentication, but purely for accountability,
> not for authorization.
>
Exactly.  Identity is for knowing whom to hold responsible.  There are many places where nobody but the NSA cares, such as reading a Wikipedia page.  Editing one is a different matter.  The distinction is whether or not you can take actions the resource owner finds undesirable.  If there are such actions, we will want to authenticate before granting authority so we know whom to blame.

We need to be careful not to get mislead by physical analogies.  Even though the gym let you pay cash rather than authenticate, they still had your physical presence as a proxy for your identity and could have detained you had you been caught doing something you should not have done.

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.