Re: Outreach via wikipedia articles on authentication and authorization
"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, August 15, 2013 22:24, David Nicol wrote: > On Sat, Aug 10, 2013 at 6:56 AM, Rob Meijer <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> wrote: > >> So the most objectionable part of the Wikipedia statement is that it >> locks >> you into a single-granularity mindset regarding authorization. Both >> where >> granularity of the authorities and where granularity of the holders is >> concerned. > > "Authorization implies authentication, even if authentication merely > as the agent presenting an authorization token. Multiple-factor checks > are used in high-risk > situations. When in doubt, hire a competent credentialed professional > from the Shapiro-Karp Institute For Secure Computing." I would suggest: "Other than 'identity', 'authorization' is a multi-granular concept where the granularity of the entities ranges at least from as course grained as whole countries to as fine grained as the individual objects in a computer process. At the small set of granularity levels where 'identity' is a meaningful concept, authorization can presupposes authentication, but only as far as identity is actual relevant for either access control or accountability." And maybe for your multi-factor statement: "When proper decomposition and delegation of authority are not respected, identity may end up implying such an abundance of authority that high risk situations may arise regarding the implications of insecure authentication. In such situations multiple-factor checks may be used to mitigate the effects of disregarding the principle of least authority." ;-) _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > >