Re: Fwd: Re: [Cryptography] Encryption opinion
Dean Tribble <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAPM7YNvfYSo3r7Wg9uLjVeb9U9ikHXDfw1tDZjvjy8iTQjvH2Q@mail.gmail.com> |
My take on policy is that it is a mechanism to manage and *bound *risk and loss in the event of access failure, or to communicate and coordinate the bound with other parties. An *organization* concerned with security can tolerate some level of mistakes, revealed documents, etc. but cannot continue to function with too much access control failure. It is often possible to separate the access decision from the access enforcement, and I would claim that you *must* use those properties for access decisions, though not for access enforcement. In a system with e.g., role-based access management, you could get (perhaps temporary) capabilities based on your current roles. The access decision from a policy point of view is the decision to give you a particular capability. The enforcement happens as a result of access via that capability. On Wed, Aug 27, 2014 at 4:34 PM, Karp, Alan H <[email protected]> wrote: > Chip Morningstar wrote: > > > > Every time I hear somebody start talking about "policy" I get all > twitchy and anxious. > > > When you're using somebody else's stuff, you've got to know what > restrictions they want you to follow. "Members of the accounting > department may see the accounts receivable." The fallacy in the common > approach is thinking that the statement of that policy is anything more > than a starting point. Actual "policy" is a dynamic thing that changes as > information flows through a system. Therefore, I believe there's nothing > wrong with using identity, role, or attributes to hand out an initial set > of permissions or even use them to enforce VOC. It's just a mistake to use > those properties to make access decisions. > > ________________________ > Alan Karp > Principal Scientist > Enterprise Services, Office of the CTO > Hewlett-Packard Company > 1501 Page Mill Road > Palo Alto, CA 94304 > 1 (650) 386-4568 > http://www.hpl.hp.com/personal/Alan_Karp > > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk