Who to hold responsible (was: Re: MarkM answer: RATS, DCCS, and membranes for network capabilities)
Jed Donnelley <capability-iCFHVraI1K1Wk0Htik3J/[email protected]> Mon, 12 Jan 2015 22:25:42 -0800
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
> On 1/11/2015 9:21 PM Jed Donnelley wrote (forwarding a complaint from P-1935: http://www.webstart.com/jed/papers/P-1935/ ): > >> Specifically the inability of "traditional" capability-based systems to support responsibility tracking and logging for auditing. On 1/12/2015 7:57 AM, Karp, Alan H wrote: > The idea that you can do responsibility tracking in conventional systems is an illusion. In the presence of credential sharing you never know who did something. The best you can know is who to hold responsible for the action. You can do the same with capabilities. <I admit that I find it somewhat amusing in this time frame that anybody could have ever referred to "traditional" capability-based systems - see the Levy book reference.> To respond to your point: Certainly in the face of credential sharing in conventional systems (e.g. unix, windows) the best you can know is who to hold responsible. Still, with such systems you at least have that something, the "user" whose actions can be logged and who can be held responsible for their logged actions. With "traditional" capability systems (let's just say systems in which all system actions are in response to invocations of capabilities and in which capabilities can be passed as parameters through such a capability invocation - think DVH #1) it does seem to me that accountability is lost. When an action is taken on a capability (the capability is invoked and a service process wakes up and performs the action), how can a log be generated indicating who to hold responsible for the action - even for the action on the invoked capability, let alone for actions on any capability communicated as a parameter? I'm sympathetic to this concern - certainly for DVH and indeed for most (all?) capability systems that I know. It's for this reason that I feel Horton: http://www.erights.org/elib/capability/horton/ supplies a potential solution to a relevant problem (whether practical or not remains to be seen). I believe even systems like Waterken #2 and all the capability as data systems have similar problems. In my view there has long been a tension between authorization via tokens (where you can get POLA #3 but you lose accountability) and "ambient" user authorization (where you can get more accountability, but you lose POLA). Am I missing an essential point? How do you believe "traditional" capability-based systems can know "who to hold responsible for" an action (without something like Horton)? Of course feel free to go beyond the traditional for a fuller explanation. I'd like to understand. [1. DVH = Dennis and Van Horn, 2. http://waterken.sourceforge.net/ 3. POLA = Principle Of Least Authority ] --Jed http://www.webstart.com/jed/