Re: Outreach via wikipedia articles on authentication and authorization
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD53E6BC21D@G4W3222.americas.hpqcorp.net> |
Right you are. We should change the subject line if that discussion goes on. I believe the objection you are talking about is in the note where you state that identity is only about assigning responsibility after the fact. I thought I had covered that when I listed the four parts of access control and stated that identification was for knowing who to throw in jail. MarcS made the point that to do that you need to identify who you are giving a right to, your car keys in his example. Now, that doesn’t mean you need the person’s Social Security number, just that you are giving them to someone you can hold responsible, such as a valet parking guy. The exchange “I saw the valet with a green stripe in his hair hit that lamppost with my car.” “Sir, they all have a green stripe.” means you didn’t do enough vetting of the identity to assign responsibility. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk