Re: Fwd: Re: [Cryptography] Encryption opinion
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD54190C4CE@G4W3222.americas.hpqcorp.net> |
Chip Morningstar wrote: > > Every time I hear somebody start talking about "policy" I get all twitchy and anxious. > When you're using somebody else's stuff, you've got to know what restrictions they want you to follow. "Members of the accounting department may see the accounts receivable." The fallacy in the common approach is thinking that the statement of that policy is anything more than a starting point. Actual "policy" is a dynamic thing that changes as information flows through a system. Therefore, I believe there's nothing wrong with using identity, role, or attributes to hand out an initial set of permissions or even use them to enforce VOC. It's just a mistake to use those properties to make access decisions. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 1 (650) 386-4568 http://www.hpl.hp.com/personal/Alan_Karp