Re: Fwd: Re: [Cryptography] Encryption opinion
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAG7xX7ow5_faCha-zK9b9eW7JFDe=DLbb4FUDdA=e5Yy=XPBDQ@mail.gmail.com> |
Sorry to keep self-replying but thoughts keep popping up in my mind. :) Consider another example, a social network we'll call SleazeBook [tm]. Let's say I'm using it through some ocap UI that allows me to drag and drop stuff into UI representations of various actors. As long as SleazeBook presents just one large "page" and I understand that everything I drag into SleazeBook is in a big wash with everything else, then I'm fine. But then SleazeBook chooses to use the ocap features of my UI layer to claim that there are two distinct "regions" -- the Buddy Corner and the Public Forum. Anything I drag into the Buddy Corner is only shared with my Buddies. Stuff in the Public Forum is shared with the public. Now these are two objects that my UI shows as visibly distinct. Now are they indeed distinct? It depends on how much I trust SleazeBook not to inadvertently or maliciously share stuff from my Buddy Corner with the public! In other words, the fact of that distinction is only "according to" SleazeBook. Why do I think this stuff is central to building a usable ocap UI? Well, because we currently live in a world where executing third-party code on some Website is for the most part considered a hack worthy of a security advisory. But we *propose* a world where, by the power of ocaps, third-party code is merely a new form of media; something that is shared freely and embedded in all sorts of places. I claim that this, more than anything else, is the power of ocaps -- to make the world safe for objects! But if indeed that is our goal, then how do we represent -- and *pre*sent to the user -- the complex security scenarios that result? Ihab -- Ihab A.B. Awad, Palo Alto, CA _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk