Re: Fwd: Re: [Cryptography] Encryption opinion
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAG7xX7rNRVmW3x9Hzkv36eRGo_Ao21N9Bs1t_psq=e-eP7M5Zg@mail.gmail.com> |
On Fri, Aug 29, 2014 at 8:48 AM, Sandro Magi <[email protected]> wrote: > I'm guessing that the protected resource is the user's account with > Amazon. ... So how you can distribute a public designator that references > a closely held client resource without being vulnerable to confused > deputies? If you can't, how close can you get while remaining safe? > Yes, precisely. Much better described than my version, thank you. :) > Seems like the only usable solution is the browser being aware of this > specific pattern, and executing a protocol to access the account-specific > equivalent of the linked page for you. > That's my suspicion -- that we will need specific ways for these patterns to be supported. I'm sure we can come up with some; it's just that it's going to take work. Ihab -- Ihab A.B. Awad, Palo Alto, CA _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk