Re: Fwd: Re: [Cryptography] Encryption opinion

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD54190C4CE@G4W3222.americas.hpqcorp.net>
Chip Morningstar wrote:
> 
> Every time I hear somebody start talking about "policy" I get all twitchy and anxious.
>
When you're using somebody else's stuff, you've got to know what restrictions they want you to follow.  "Members of the accounting department may see the accounts receivable."  The fallacy in the common approach is thinking that the statement of that policy is anything more than a starting point.  Actual "policy" is a dynamic thing that changes as information flows through a system.  Therefore, I believe there's nothing wrong with using identity, role, or attributes to hand out an initial set of permissions or even use them to enforce VOC.  It's just a mistake to use those properties to make access decisions.

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
1 (650) 386-4568
http://www.hpl.hp.com/personal/Alan_Karp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.