Re: Outreach via wikipedia articles on authentication and authorization

"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
On Wed, August 14, 2013 17:15, Karp, Alan H wrote:
> Rob Meijer  wrote:
>>
>> Mallet uses my identity to determine that I am one of 10,000 law
>> enforcement people (within her 100,000,000 user-base) that she needs to
>> keep tabs on.
>
> This statement exposes the fallacious assumption that most people make
> about identity, that it is in some sense a global property.  In fact,
> identity is a set of relations in a social graph.  I am a particular
> physical being who can be thrown in jail (which is why a corporation is
> not a person with first amendment rights, John Roberts), but my identity
> is a set of labels in a social context.  I am Joey's Mom's Alan.  I am
> HP's 0394827.  I am the UN's US's SSA's 323-39-4453.  Each of these labels
> identifies me in a particular context, but that identification is
> meaningless in another context.  If you found out that 0394827 did one
> thing and Alan did something else, you'd have no way to know I did both
> without walking the family and HP social graphs.
>
> In your example, David gave Mallet the permission, so we presume that
> David and Mallet have a direct relationship.  David got the permission
> from Carol, so we presume that Carol and David have a direct relationship.
>  That does not imply that Carol's identifier appearing in the delegation
> chain  has any meaning to Mallet.  That identifier is a petname chosen by
> Bob that needs to be meaningful only to him.  We assign responsibility by
> walking the delegation chain, not by jumping to a particular point.

Only, if for example, Alice is a program used by me, Bob a plugin used by
the program Alice, Carol a library used by the plugin Bob, David an object
of a class defined inside of the Carol library, and Mallet a remote active
object invoked by David, than what does that mean for your social graph?
And what does that mean for the relevance of 'my' identity as far as Bob,
Carol and David are concerned? Pet-names are meaningless for Bob,Carol and
David, they are not persons and they all run on my machine. They are a
definite part of the delegation chain though.

Please try to keep your mind from jumping back to the big picture and lets
focus on the level where Carol is implemented. Carol is included in the
Bob project, no identity, Carol is loaded as part of Bob, no identity.
Carol is authorized on some data, no identity. Carol decomposes her
authority an authorizes David to a part of it, no identity. You can
artificially try to fit Bob and David with identities, but they are not
persons. They are relevant in accountability, sure, but that does not make
them people. You can make my identity available to be used for
accountability, but does that make sense and does that fit into the whole
POLA concept? In my view, access to identity is a very powerful authority
that should not be delegated frivolously.

I'm trying to get you to look at the finer granularity level aspects. The
place were Carol lives. I might misunderstand some of the coarse grained
aspects of identity between people in a social graph and stuff, but that's
not the granularity level that concerns me respecting the Wikipedia
statement. My claim is that, as far as Carol should be concerned, at least
if we adhere to POLA, for all practical purposes authentication is not to
be considered a precursor to authorization.

Could you tell me how you feel about that level of granularity?

Rob

> ________________________
> Alan Karp
> Principal Scientist
> Enterprise Services, Office of the CTO
> Hewlett-Packard Company
> 1501 Page Mill Road
> Palo Alto, CA 94304
> (650) 857-3967, fax (650) 857-7029
> http://www.hpl.hp.com/personal/Alan_Karp
>
>
>
> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.