Re: Fwd: Re: [Cryptography] Encryption opinion

<[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAG7xX7q59TQZ=R6DMCsbQRzbXtYRzgAYNOqw7rwq=z-1Yo-yxA@mail.gmail.com>
On Wed, Aug 27, 2014 at 2:07 PM, Bill Frantz <[email protected]> wrote:

> From: [email protected] (Jerry Leichter)
> For capability-based systems, I think *the* hard problem is
> configurability:  How do you turn an access policy defined in human terms
> into a set of capabilities that accurately and completely implements the
> policy?  Given a set of capabilities, how do you turn it into something
> human beings can actually understand?  The *implications* of security
> policies - what is *actually* granted or forbidden, not as a result of the
> explicit policies but as a result of what they imply - is something that's
> difficult or impossible to understand, whether the policies are stated in
> English or in some formal capability language.  In human-based systems, we
> get around our lack of understanding by allowing humans to override the
> policies (which also opens the system up to social engineering).  When we
> freeze the enforcement of such policies into code, we often produce
> unusable systems.
>
> Note that I'm not claiming capability-based systems *can't* work.  I'm
> saying that *even on the theoretical side*, we need to do more work on
> *known issues*; and on the practical, fieldable, fielded side - we have
> almost no experience.
>
> Claims that capability-based systems can, *in practice*, solve the
> difficult issues of end-point security at Internet scale simply cannot be
> supported today.
>

For what it's worth, I'm going to argue that the author of these remarks is
100% spot-on. Well, maybe not 100%, but 95% -- or high enough, at any rate,
as to warrant a great deal of attention from our little community here.

The author speaks of "policies". I am inclined to grant him the courtesy of
his choice of terminology. I think we here are more accustomed to talking
about configurations of the object graph, but in the end, I think we're
talking about the same thing.

Pace efforts like CapDesk, SCoopFS, and others, it is not clear to me that
we yet have a general purpose system for implementing in terms of object
capabilities all the stuff that users of the Internet use the Internet to
do today. Examples include:

* Without ambient authority, how do you implement a one-click "Buy button"
on a product page from a publisher that takes you to a pre-filled order
form at a merchant to buy the thing that is discussed on the publisher's
page?

* How do you represent the flow of authority between entities that may or
may not have deals with one another? Are my assets on Facebook exposed to
Microsoft? The other way 'round?

We do have Tyler's Web Introducer, but that has yet to be fielded in a wide
enough class of applications as to show how it can cleanly solve or replace
all the use cases people want, or provide enough benefit to everyday users
that they are willing to drop some of these use cases.

In other words: I do not believe the problem of usable ocap security and
user interfaces is solved. To that extent, the author is in my view correct.

Ihab

-- 
Ihab A.B. Awad, Palo Alto, CA

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.