Re: Fwd: Seeking Feedback on Capability URLs Draft
John Kemp <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
Hi Rob, On 05/28/2014 02:29 AM, Rob Meijer wrote: > On Tue, May 27, 2014 19:27, Raoul Duke wrote: >> if Mr W3C Dan A. hasn't chimed in on this list, if anybody would want >> him to, he's probably happy to talk with people here. [email protected] >> :-) >> _______________________________________________ >> cap-talk mailing list >> [email protected] >> http://www.eros-os.org/mailman/listinfo/cap-talk >> >> > > Maybe we could discuss the main issues here and keep Dan in the Cc list. > > I think there are two issues that should be addressed separately: > > 1) Is the criticism of different caps for attenuated resources justified > and are caps and web good practice really fundamentally incompatible, or > are caps that provide attenuated access to a resource conceptually in fact > caps to different resources? Personally, I believe that yes, they can be thought of as different resources. I did try to address this issue as feedback on the W3C TAG list today: http://lists.w3.org/Archives/Public/www-tag/2014May/0042.html I don't know if I've expressed the same intent of your comment here, but it sounds similar :) I am also somewhat fuzzy on whether this is a real web architecture issue - does the concern actually really matter when you examine the use-case in detail and how one might implement it even without cap URLs? > > 2) Can we somehow communicate that the resulting advice of using more > identity and less caps has many security drawbacks? That the cure may be > worse than the ailment. > > Regarding '1' I would argue that for a cap URL for attenuated access, the > resource being designated is in fact conceptually an attenuation proxy. I don't know the specific terminology to know whether that is true, so it looks like I should read your references below. Cheers, - johnk > > Regarding '2 part of the slides + speaker notes of my 'Defeating trojans' > may be relevant ( > http://ohm2013.capibara.com/slides/ohm2013_trojans_with_notes.pdf page > 59..78 and 86..95). The PDF can be a bit of a mess in some pdf viewers, > the slides (without speaker) notes are also on slideshare > (http://www.slideshare.net/RobMeijer3/ohm2013-trojans-slides page > 1..20,28..37) > > Regarding '2' I would also suggest : > > * A cooperative species (Bowles & Gintis) > http://press.princeton.edu/titles/9474.html > * Zebra Copy (Alan Karp & Jun Li) > http://www.hpl.hp.com/techreports/2007/HPL-2007-105.pdf > * Patterns of Safe Collaboration (Fred Spiessens) > http://www.evoluware.eu/fsp_thesis.pdf > > Rob > > > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk >