Re: Fwd: Re: [Cryptography] Encryption opinion
David Barbour <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAAOQMStedRNiq=GBNXHEci14qq8Vzo5-LwoOR4w4QQaLpGNWCA@mail.gmail.com> |
On Thu, Aug 28, 2014 at 2:06 PM, <[email protected]> wrote: > I wonder about the extent to which this kind of reasoning -- reasoning > before the fact about the unconfined entities *to which* authority is > granted -- would be an important part of a usably secure interface. Because > our job is not merely to transfer capabilities at the behest of the > end-user willy nilly. We are presumably building this whole infrastructure > because there exist capabilities C and recipients R such that it is not a > good idea to transfer C to R. How may that be represented? > > In reasoning about this de facto network of trust and suspicion among the > actors represented by the objects with which an end-user interacts, is > there a place for a trusted third party to which these decisions can be > outsourced? Something like a Consumer Reports? Is that the place where the > specific, day to day grunt work currently done by anti-virus companies can > be better applied? > > There are patterns by which we can restrict transfer of capabilities based on 'proof of identity', where said identity might correspond to a proof-of-work certificate, public key, and maybe a shorthand name (cf. namecoin). The difficulty is 'investing' this identity in a useful way, i.e. tying it to a reputation and history and endorsements. You could create policies such as: "this resource is sensitive, but may be transferred to entitites approved by __foogle__". You could model such policies in a capability system in terms of handing foogle an unsealer that it can pass to entities it approves. _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk