Re: Outreach via wikipedia articles on authentication and authorization
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD53E6C0B1D@G4W3222.americas.hpqcorp.net> |
Rob Meijer wrote: > > Ok, so where is the identity or authentication in that? So bob could do > responsibility tracking, but given that neither Alice nor Carol is a person, > neither one has an identity, so neither one could have done any > authentication. As far as Bob is concerned, identities do not exist. As > far as Bob is concerned there is no such thing as authentication. So as > far as Bob is concerned, the Wikipedia statement is completely bogus. > Absolutely correct. However, without identifying a responsible party I can't evaluate my risk. I am willing to use Microsoft Word on the web at the microsoft.com domain but not at the iamabadguy.ru domain. It is the responsible party that matters, not the object. If Microsoft chooses to use a third party provided library, they will authenticate the responsible party before incorporating that library. No authentication needs to be done when invoking the library. > > Funny, in my view its 'identity' that's the red herring, not granularity. > Identity is a single granularity concepts that keeps the discussion locked > to that one single granularity. I'm talking about the granularity of the > entities that are considered to be handling pieces of authority, not the > granularity of these pieces of authority themselves. > I agree 100%. That's why we run into problems when "identity" is considered to be some globally known thing; its granularity is too large. However, the way I'm using identity via pairwise relationships between responsible parties, while not at the granularity of individual objects, is much finer grained than a global identity and avoids the problems that concern you. > IMO single granularity abstractions are a major source of abstraction > leakage, and they keep us from solving problems in a fundamental way. I > believe we need to look for and find a way to think about responsibility > tracking in a granularity neutral way, just like Marks insights on > capabilities helped us to think about authority in a granularity neutral > way. Regressing to the multi-granularity toxic concept of identity and > authentication by claiming that authentication is a necessary precursor to > authorization IMO in that context is anti-productive. > Capabilities do not eliminate the need for authentication. They just move it to another time and place in the process. We still need to authenticate responsible parties in order to make risk assessments. That authentication is done independent of the object invocations. Objects need not have the concept of identity unless we explicitly want them to ala Horton. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp