Re: Macaroons: capabilities vs credentials
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD5419AE87A@G4W3222.americas.hpqcorp.net> |
Tony Arcieri wrote: è I suspect what you're getting at is Macaroons allow use cases which aren't tightly coupled to the resource, to the form that your "handle" to that resource involves a Macaroon and nothing more (i.e. the server can know based on your macaroon alone *exactly* what you're trying to do), and without that sort of explicit binding from resource to authority, confused deputies can arise, and that's a problem. I like to say that OAuth 2 isn’t terrible because bearer tokens can be used as capabilities. It isn’t good because they don’t have to be used that way. Based on my brief reading of the macaroon paper, I’d say that macaroons aren’t terrible for the reason you give. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk