Re: Fwd: Re: [Cryptography] Encryption opinion

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD54190CA06@G4W3222.americas.hpqcorp.net>
Ihab wrote:


è * Without ambient authority, how do you implement a one-click "Buy button" on a product page from a publisher that takes you to a pre-filled order form at a merchant to buy the thing that is discussed on the publisher's page?

Why would you need ambient authority for this?  Maybe I don’t understand the example.  Are you thinking about Amazon acting as a reseller?  That’s easy.  The merchant gives Amazon a buy capability for the item, which Amazon delegates to the user.  The user delegates to Amazon a capability to the user’s address info, which Amazon delegates to the merchant.  What am I missing?


è * How do you represent the flow of authority between entities that may or may not have deals with one another? Are my assets on Facebook exposed to Microsoft? The other way 'round?

Why can’t I just transfer to Microsoft the capability for the Facebook asset I want to share?  I don’t see why they need a deal with each other?

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp

From: [email protected] [mailto:[email protected]] On Behalf Of [email protected]
Sent: Wednesday, August 27, 2014 5:08 PM
To: General discussions concerning capability systems.
Subject: Re: [cap-talk] Fwd: Re: [Cryptography] Encryption opinion


On Wed, Aug 27, 2014 at 2:07 PM, Bill Frantz <[email protected]<mailto:[email protected]>> wrote:
From: [email protected]<mailto:[email protected]> (Jerry Leichter)
For capability-based systems, I think *the* hard problem is configurability:  How do you turn an access policy defined in human terms into a set of capabilities that accurately and completely implements the policy?  Given a set of capabilities, how do you turn it into something human beings can actually understand?  The *implications* of security policies - what is *actually* granted or forbidden, not as a result of the explicit policies but as a result of what they imply - is something that's difficult or impossible to understand, whether the policies are stated in English or in some formal capability language.  In human-based systems, we get around our lack of understanding by allowing humans to override the policies (which also opens the system up to social engineering).  When we freeze the enforcement of such policies into code, we often produce unusable systems.

Note that I'm not claiming capability-based systems *can't* work.  I'm saying that *even on the theoretical side*, we need to do more work on *known issues*; and on the practical, fieldable, fielded side - we have almost no experience.

Claims that capability-based systems can, *in practice*, solve the difficult issues of end-point security at Internet scale simply cannot be supported today.

For what it's worth, I'm going to argue that the author of these remarks is 100% spot-on. Well, maybe not 100%, but 95% -- or high enough, at any rate, as to warrant a great deal of attention from our little community here.

The author speaks of "policies". I am inclined to grant him the courtesy of his choice of terminology. I think we here are more accustomed to talking about configurations of the object graph, but in the end, I think we're talking about the same thing.

Pace efforts like CapDesk, SCoopFS, and others, it is not clear to me that we yet have a general purpose system for implementing in terms of object capabilities all the stuff that users of the Internet use the Internet to do today. Examples include:

* Without ambient authority, how do you implement a one-click "Buy button" on a product page from a publisher that takes you to a pre-filled order form at a merchant to buy the thing that is discussed on the publisher's page?

* How do you represent the flow of authority between entities that may or may not have deals with one another? Are my assets on Facebook exposed to Microsoft? The other way 'round?

We do have Tyler's Web Introducer, but that has yet to be fielded in a wide enough class of applications as to show how it can cleanly solve or replace all the use cases people want, or provide enough benefit to everyday users that they are willing to drop some of these use cases.

In other words: I do not believe the problem of usable ocap security and user interfaces is solved. To that extent, the author is in my view correct.

Ihab

--
Ihab A.B. Awad, Palo Alto, CA

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.