Re: Outreach via wikipedia articles on authentication and authorization

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD53E6BC21D@G4W3222.americas.hpqcorp.net>
Right you are.  We should change the subject line if that discussion goes on.

I believe the objection you are talking about is in the note where you state that identity is only about assigning responsibility after the fact.  I thought I had covered that when I listed the four parts of access control and stated that identification was for knowing who to throw in jail.  MarcS made the point that to do that you need to identify who you are giving a right to, your car keys in his example.  Now, that doesn’t mean you need the person’s Social Security number, just that you are giving them to someone you can hold responsible, such as a valet parking guy.  The exchange

“I saw the valet with a green stripe in his hair hit that lamppost with my car.”
“Sir, they all have a green stripe.”

means you didn’t do enough vetting of the identity to assign responsibility.

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.