Re: Fwd: Seeking Feedback on Capability URLs Draft

John Kemp <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
Hi Rob,

On 05/28/2014 02:29 AM, Rob Meijer wrote:
> On Tue, May 27, 2014 19:27, Raoul Duke wrote:
>> if Mr W3C Dan A. hasn't chimed in on this list, if anybody would want
>> him to, he's probably happy to talk with people here. [email protected]
>> :-)
>> _______________________________________________
>> cap-talk mailing list
>> [email protected]
>> http://www.eros-os.org/mailman/listinfo/cap-talk
>>
>>
>
> Maybe we could discuss the main issues here and keep Dan in the Cc list.
>
> I think there are two issues that should be addressed separately:
>
> 1) Is the criticism of different caps for attenuated resources justified
> and are caps and web good practice really fundamentally incompatible, or
> are caps that provide attenuated access to a resource conceptually in fact
> caps to different resources?

Personally, I believe that yes, they can be thought of as different 
resources. I did try to address this issue as feedback on the W3C TAG 
list today: http://lists.w3.org/Archives/Public/www-tag/2014May/0042.html

I don't know if I've expressed the same intent of your comment here, but 
it sounds similar :)

I am also somewhat fuzzy on whether this is a real web architecture 
issue - does the concern actually really matter when you examine the 
use-case in detail and how one might implement it even without cap URLs?

>
> 2) Can we somehow communicate that the resulting advice of using more
> identity and less caps has many security drawbacks? That the cure may be
> worse than the ailment.
>
> Regarding '1' I would argue that for a cap URL for attenuated access, the
> resource being designated is in fact conceptually an attenuation proxy.

I don't know the specific terminology to know whether that is true, so 
it looks like I should read your references below.

Cheers,

- johnk

>
> Regarding '2 part of the slides + speaker notes of my 'Defeating trojans'
> may be relevant (
> http://ohm2013.capibara.com/slides/ohm2013_trojans_with_notes.pdf page
> 59..78 and 86..95). The PDF can be a bit of a mess in some pdf viewers,
> the slides (without speaker) notes are also on slideshare
> (http://www.slideshare.net/RobMeijer3/ohm2013-trojans-slides page
> 1..20,28..37)
>
> Regarding '2' I would also suggest :
>
> * A cooperative species (Bowles & Gintis)
> http://press.princeton.edu/titles/9474.html
> * Zebra Copy (Alan Karp & Jun Li)
> http://www.hpl.hp.com/techreports/2007/HPL-2007-105.pdf
> * Patterns of Safe Collaboration (Fred Spiessens)
> http://www.evoluware.eu/fsp_thesis.pdf
>
> Rob
>
>
>
> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.