Re: Fwd: Re: [Cryptography] Encryption opinion
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAG7xX7rDVtiETGK1QEFk_0zVZGF=Bn+LOiCMWw=by5FybYSqKA@mail.gmail.com> |
On Sep 1, 2014 2:35 PM, "Terry Hayes" <[email protected]> wrote: > In other words, we know how to implement these patterns, but (unfortunately) nobody does it. I guess. Fwiw, if so, we should make these ideas more public though. Because -- > Instead, current implementations focus too much on who somebody is, rather than whether they should be able to do what is requested. That point is actually tangentially supported by an anecdote about OAuth. As specified, the latter is arguably an ocap protocol. However, when last I checked, a few years ago, all the client libraries available were limited to a fixed enumeration of "scopes" (think: MAIL, DOCS, ...) and had no support for the (I guess preposterous) notion that one would want to mint a new "scope" for each resource (= object). So it's like, even when the basic tech is there, folks don't think to use it in an ocap manner. Ihab _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk