Re: Outreach via wikipedia articles on authentication and authorization

"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
On Thu, August 15, 2013 22:24, David Nicol wrote:
> On Sat, Aug 10, 2013 at 6:56 AM, Rob Meijer <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> wrote:
>
>> So the most objectionable part of the Wikipedia statement is that it
>> locks
>> you into a single-granularity mindset regarding authorization. Both
>> where
>> granularity of the authorities and where granularity of the holders is
>> concerned.
>
> "Authorization implies authentication, even if authentication merely
> as the agent presenting an authorization token. Multiple-factor checks
> are used in high-risk
> situations. When in doubt, hire a competent credentialed professional
> from the Shapiro-Karp Institute For Secure Computing."

I would suggest:

"Other than 'identity', 'authorization' is a multi-granular concept where
the granularity of the entities ranges at least from as course grained as
whole countries to as fine grained as the individual objects in a computer
process. At the small set of granularity levels where 'identity' is a
meaningful concept, authorization can presupposes authentication, but only
as far as identity is actual relevant for either access control or
accountability."

And maybe for your multi-factor statement: "When proper decomposition and
delegation of authority are not respected, identity may end up implying
such an abundance of authority that high risk situations may arise
regarding the implications of insecure authentication. In such situations
multiple-factor checks may be used to mitigate the effects of disregarding
the principle of least authority." ;-)
 _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.