Re: Outreach via wikipedia articles on authentication and authorization

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD53E6C07C6@G4W3222.americas.hpqcorp.net>
Rob Meijer wrote: 
> 
> Only, if for example, Alice is a program used by me, Bob a plugin used by
> the program Alice, Carol a library used by the plugin Bob, David an object
> of a class defined inside of the Carol library, and Mallet a remote active
> object invoked by David, than what does that mean for your social graph?
>
There is still a responsible party for each component.  If you don't know who that is, you can't evaluate how much trust you will put in that component.  Will you let it store your New York Times password?  Will you let it store your Bank of the West password?  You don't know unless you know what contract you have with the responsible party and how likely you think it is that the contract will be honored.

When I run Alice, a program, I will decide how vulnerable I am willing to make myself to Alice based on the (implicit) contract between me and the party responsible for Alice, R(A).  If a violation occurs, I will collect any penalty from R(A).  If Alice uses Bob, R(A) will collect from R(B).  Whether or not R(A) is the same as R(B) is irrelevant to me.  If Bob wants to track delegations to Carol, that's Bob's concern and nobody else's.  It's all about encapsulation.

I think that granularity is a red herring.  I can be quite safe sharing a lot of my permissions, say all of my photos, and at high risk sharing a very fine grain permission, say the ability to sell my HP stock (unfortunately not as much risk as just a few years ago).  The place that granularity comes in is that a given party is likely to be responsible for a lot of small objects but only a few large ones.  Still, all that matters is the contract that I have with the responsible party and the degree of vulnerability I have when granting rights to objects that party is responsible for.

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.