Re: A new type of phishing attack
"James A. Donald" <jamesd-twz8Zj9/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On 2014-09-14 03:59, Guido Witmond wrote: > I hold a capability to an item at a service, say an email at a mailbox. > My problem is making sure I present it to the correct mailbox-service of > all those billion hosts out there. If I connect to the wrong host, the > email might end up at the front page of a newspaper... You have a petname system for all the entities you have relations with - not everything in the universe, but everything you have a logon relationship with. If you are trusting a host with something valuable, you probably have a logon relationship with that host. You logged on to each entity that you are passing capabilities around with using a Zero Knowledge Password proof Capabilities are useful because they can be passed around. Let us suppose, however, that they get passed around with their history. Ann has a capability that can be exercised on the host Dave. She issues this capability to Bob, who issues it to Carol, who uses it on Dave. Dave says, OK, because this capability comes from Dave. Now if Ann issues the capability to an important secret to Bob, who issues it Carol, who issues it to the secret police who are spying on Ann, then Ann is hosed, because Dave concludes that Ann authorized issue of this secret to the secret police. But at all times, everyone knows who they issued the capability to. > How can I be sure that a recipient of a capability I hold won't > accidentally leak it after I gave it to them? Well you cannot, because that is what a capability is. If Carol decides to deliberately rat on Ann, Ann is hosed. Capabilities are useful because they can be passed around. But a logon system makes it harder for Carol to *accidentally* rat on Ann.