Re: Outreach via wikipedia articles on authentication and authorization

Dirk Pranke <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAEoffTDM=9Km+yW9XNgX6J9YAu_hEPwJ+_DfoAA31F2N0EJJyA@mail.gmail.com>
On Fri, Aug 9, 2013 at 2:33 PM, Karp, Alan H <[email protected]> wrote:

>  Right you are.  We should change the subject line if that discussion
> goes on.****
>
> ** **
>
> I believe the objection you are talking about is in the note where you
> state that identity is only about assigning responsibility after the fact.
>

Is this a response to Mike, or to me? The objection I had was in response
to Mark Steigler's claim that authorization implied authentication:

MarcS:

>  This is how car keys work: I authenticate you by looking at you when I
hand you the keys. Then the car does not need to know who you are, it only
knows, and only cares, that you are authorized.

Me:

Continuing your example, if I steal your car keys and drive off in your
car, the car might "think" I was authorized, but you (and most people)
probably wouldn't.

Clearly, an access decision was made, but in what sense can we say that
authorization and authentication happened? The key was authorized? You were
authorized? I wasn't ...

-- Dirk

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.