Re: Outreach via wikipedia articles on authentication and authorization
"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, August 9, 2013 21:53, Mike Samuel wrote: > 2013/8/9 Dirk Pranke <[email protected]>: >> Not that this isn't a fascinating line of discussion, but I think we've >> wandered away from Mike's original question and my objection (which I >> didn't >> see a great answer for; did I miss something)? >> >> -- Dirk > > I was hoping to get an illustrating example out of this discussion, > though how to mask identity until abuse is reported under Horton is > probably too specific. The broader concept that identity may be completely outside of the system that only logs revocable-anonymity tokens however might be. The token itself, though created through a process of authentication, has no authorization value for the system itself, and thus would make fitting the Wikipedia statement to this example rather far-fetched. Separate from that, as I stated earlier, there are many cases where authority is sufficiently attenuated and/or decomposed and/or revocable to make even the question of accountability irrelevant. While I would like to know who to hold accountable for taking my bike out of my shed when my bike went missing, accountability for who ate the last cookie seems somewhat less relevant ;-) That is, at finer granularity authority, identity becomes irrelevant and authentication useless Thirdly, and most importantly, there is a lot of authorization happening at levels of granularity (at the holder of authority side) where identity has long stopped being relevant. The range of holder granularity where authentication is relevant is smaller than the range of granularity where authorization is. If one 20 line object authorizes an other 20 line object of code to to make use of the value of a single field in a configuration file, than this action is far removed from the slightest notion of identity. So the most objectionable part of the Wikipedia statement is that it locks you into a single-granularity mindset regarding authorization. Both where granularity of the authorities and where granularity of the holders is concerned. > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > >