Re: Outreach via wikipedia articles on authentication and authorization

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD53E6BD857@G4W3222.americas.hpqcorp.net>
I was replying to you, but to a different objection.  Let me reply to

Continuing your example, if I steal your car keys and drive off in your car, the car might "think" I was authorized, but you (and most people) probably wouldn't.

Clearly, an access decision was made, but in what sense can we say that authorization and authentication happened? The key was authorized? You were authorized? I wasn't ...

That is no different than if you had stolen my credentials and proven to my car that you are me.  On the Internet you are whomever you can prove yourself to be, which is a variant on the “nobody knows you’re a dog” meme.  The car hasn’t made a mistake, I have by letting you steal my credentials.  I don’t believe there is anything that can be done about this problem.

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.