Re: Outreach via wikipedia articles on authentication and authorization
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD53E6BD857@G4W3222.americas.hpqcorp.net> |
I was replying to you, but to a different objection. Let me reply to Continuing your example, if I steal your car keys and drive off in your car, the car might "think" I was authorized, but you (and most people) probably wouldn't. Clearly, an access decision was made, but in what sense can we say that authorization and authentication happened? The key was authorized? You were authorized? I wasn't ... That is no different than if you had stolen my credentials and proven to my car that you are me. On the Internet you are whomever you can prove yourself to be, which is a variant on the “nobody knows you’re a dog” meme. The car hasn’t made a mistake, I have by letting you steal my credentials. I don’t believe there is anything that can be done about this problem. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk