Re: Fwd: Re: [Cryptography] Encryption opinion
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD54190FBF0@G4W3222.americas.hpqcorp.net> |
Ihab wrote: è The issues are that they rely on clickjack-able ambient authority via cookies. In both cases, Ihab's blog can designate a page containing Alan's private Amazon info using a generic URL. I don’t see that the ambient authority is an issue in this particular case. Ihab’s blog may determine which page I see at Amazon, but Ihab has no authority over that page even with ambient authority. è I'm sure there's a way to do similar stuff with ocaps in a principled and less sloppy manner than how it's done today. The question is how to make it usable. Ihab’s blog has a form that takes a sealed box holding whatever capability I need to exercise on the Amazon site. è But to persevere for the sake of learning, the cases you note are _ex post facto_. If we could sue the Nigerian scammers, the world would be so much better in so many ways. But the fact is, we can't. I said that our only resource is the courts, not that they were necessarily effective. ☺ As for the rest of your comments, all I can say is that we make ourselves vulnerable to others in order to get some benefit. The issues you raise affect the decision of whether the vulnerability is worth the benefit. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk