Re: Fwd: Re: [Cryptography] Encryption opinion
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD54190DED8@G4W3222.americas.hpqcorp.net> |
I don’t see any security issue in your Amazon examples. What’s the protected resource, and what’s the threat to that resource? Your printer example is an irreducible problem. If I give you a permission, taking you to court is the only recourse I have if you abuse that permission. It doesn’t matter if PrintCo blabs or shares the document with National Busybody who blabs. I hold PrintCo responsible and collect any penalty provided under my contract with PrintCo. Similarly, it’s up to PrintCo to collect from SleazeHost under terms of their contract if the release is due to SleazeHost’s poor security. Not allowing the transfer of a capability to a recipient falls under Voluntary Oblivious Compliance. The Horton protocol shows how we might do that with capabilities. However, the possibility of credential sharing limits us to voluntary compliance. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk