Re: Outreach via wikipedia articles on authentication and authorization
Dirk Pranke <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAEoffTDM=9Km+yW9XNgX6J9YAu_hEPwJ+_DfoAA31F2N0EJJyA@mail.gmail.com> |
On Fri, Aug 9, 2013 at 2:33 PM, Karp, Alan H <[email protected]> wrote: > Right you are. We should change the subject line if that discussion > goes on.**** > > ** ** > > I believe the objection you are talking about is in the note where you > state that identity is only about assigning responsibility after the fact. > Is this a response to Mike, or to me? The objection I had was in response to Mark Steigler's claim that authorization implied authentication: MarcS: > This is how car keys work: I authenticate you by looking at you when I hand you the keys. Then the car does not need to know who you are, it only knows, and only cares, that you are authorized. Me: Continuing your example, if I steal your car keys and drive off in your car, the car might "think" I was authorized, but you (and most people) probably wouldn't. Clearly, an access decision was made, but in what sense can we say that authorization and authentication happened? The key was authorized? You were authorized? I wasn't ... -- Dirk _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk