Re: [friam] Delegation is the Cornerstone of Civilization: Sharing in Sandstorm.io
Kenton Varda <[email protected]> Mon, 11 May 2015 12:18:28 -0700
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAJaLmO4W=VECPO3FWR2Tjasrtc9qqpQjxvVLnhX7PwtGg3X=sA@mail.gmail.com> |
On Fri, May 8, 2015 at 7:46 AM, 'Mark S. Miller' via friam < friam-/[email protected]> wrote: > Speaking only for myself: > > I am not aware of any user testing of this issue. User testing is of > course great if someone foots the bill. But we should also remember that we > all make zillions of decisions based on intuition and guesses not backed by > studies. We cannot afford to do anything else. So lack of user study should > indeed raise our uncertainty, but it should not mean "we have no idea until > a study is done". Rather, we do what we do with a zillion decisions we make > all the time without being able to afford a study -- we argue and criticize > and build systems and see how people like them. > You might as well be speaking for me, because I make exactly this argument (which I came to independently) all the time. :) In the case of Sandstorm, we plan to do some user testing, but as an early-stage startup it is simply not possible for us to intensely test everything -- not only because of the dollar cost, but the time cost. Ultimately we have to take a risk and bet on our intuitions -- and I suspect most startups succeed or fail on the accuracy of their founders' intuitions rather than on their discipline in user testing. In any case, I do not believe than any user test results would cause us to change our mind about the underlying security model we are implementing. Instead, if user testing showed problems, we would solve them by improving the UI on top of it and by implementing "policies" that match user expectations. We can express basically anything we need by inventing policies. Policies are enforced on a "best effort" basis whereas the underlying capability-based security model is strict. (Of course, since you can't prevent delegation with any security model, any model that claims to do so is in fact doing it on a "best effort" basis itself. We're just being honest about it.) FWIW, I am well aware that security people have a bad record with usability. Server infrastructure developers have a similarly awful record, but I think Sandstorm has already demonstrated our ability to do better there (60-second demo: demo.sandstorm.io), and I am confident we will similarly get sharing right. :) -Kenton _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk