Re: Outreach via wikipedia articles on authentication and authorization

"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
On Fri, August 9, 2013 21:53, Mike Samuel wrote:
> 2013/8/9 Dirk Pranke <[email protected]>:
>> Not that this isn't a fascinating line of discussion, but I think we've
>> wandered away from Mike's original question and my objection (which I
>> didn't
>> see a great answer for; did I miss something)?
>>
>> -- Dirk
>
> I was hoping to get an illustrating example out of this discussion,
> though how to mask identity until abuse is reported under Horton is
> probably too specific.

The broader concept that identity may be completely outside of the system
that only logs revocable-anonymity tokens however might be.
The token itself, though created through a process of authentication, has no
authorization value for the system itself, and thus would make fitting the
Wikipedia statement to this example rather far-fetched.

Separate from that, as I stated earlier, there are many cases where
authority is sufficiently attenuated and/or decomposed and/or revocable to
make even the question of accountability irrelevant. While I would like to
know who to hold accountable for taking my bike out of my shed when my
bike went missing, accountability for who ate the last cookie seems
somewhat less relevant ;-) That is, at finer granularity authority,
identity becomes irrelevant and authentication useless

Thirdly, and most importantly, there is a lot of authorization happening
at levels of granularity (at the holder of authority side) where identity
has long stopped being relevant. The range of holder granularity where
authentication is relevant is smaller than the range of granularity where
authorization is. If one 20 line object authorizes an other 20 line object
of code to to make use of the value of a single field in a configuration
file, than this action is far removed from the slightest notion of
identity.

So the most objectionable part of the Wikipedia statement is that it locks
you into a single-granularity mindset regarding authorization. Both where
granularity of the authorities and where granularity of the holders is
concerned.



> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.