Re: [friam] Re: UX resources for object capabilities

Marc Stiegler <[email protected]> Sat, 7 Nov 2015 11:32:32 -0700
Newsgroups gmane.comp.capabilities.general
Message-ID <CAK=cCVW9s8q3JGrMDOs75soUkxPye3rDNBHPvmDT0qzMSARQjA@mail.gmail.com>
for anyone who tried to open decideright2.com to see how it works live, my
site was down. It is now fixed.

--marcs

On Wed, Nov 4, 2015 at 6:25 PM, Marc Stiegler <[email protected]> wrote:

> In the ocap systems I have been a part of building, the distinction
> between user and administrator blurs almost completely out of existence.
> The administrator is a user with great authority, and he creates users with
> less authority; users with less authority can create a user with any amount
> of authority up to the amount the creating user holds.
>
> 3 interesting examples for your audience:
>
> http://www.hpl.hp.com/techreports/2006/HPL-2006-116.pdf
>
> Is a tech report about using the ocap language Emily, built atop OCAML
> using an ocap verifier, to build sash, a framework for writing
> least-privilege bash commands. This is a small but complete example of a
> powerbox and apps that are invoked with user-specified very limited
> authority. The powerbox holds all the user's authority, the app gets only
> what the user specifies, designated in a way that any unix bash user can
> understand even though no acls are involved: the act of designation is the
> act of authorization, so you're mainly doing what you'd do with bash
> commands mainly different in that that bash commands are launched with vast
> abusable power. This one may "sing" for your unix audience more easily than
> the other 2, they can actually read the code.
>
> https://www.youtube.com/watch?v=cJThfgXMBA4
>
> Is a 2 minute video of the everyware desktop. So, the everyware desktop
> runs in a browser, and manages authorities all over the blinkin' web. But
> the principles are the same, and IMHO anyone who writes a new user desktop
> in this day and age should not be fooling around with desktops that govern
> only local authorities anyway. Anyway, the desktop in the demo is the
> user's visual representation of his powerbox that holds all his authorities
> over documents, chat threads, etc. This video shows an actual flow of
> authority from user to user (desktop to desktop) in a simple secure
> cooperation scenario. For people who think the distinction between
> administrator and user is important, it might be interesting to note that
> Homer is actually the root administrator for a full everyware system, and
> Madge could be either an account holder on that system, who got her desktop
> via a series of desktop sub-creations rooted in Homer, or could have her
> desktop on a different everyware system, we neither know nor care, because
> ocap authorities flow transparently user-to-user regardless of
> administrative boundaries.
>
> http://decideright2.com
>
> Is the location where you can create an account for the DecideRight2
> decision analysis application. Your home page -- reached via an ocap OAuth
> bookmark --
> is once again a visual representation of your powerbox, i.e., it contains
> all your system authorities; in this case each authority is an ocap
> reference to a decision analysis document. Each document enables grant of
> limited authority to edit and/or read a single decision. While least
> directly relevant to the unix OS problem, it has the merit that this one
> you can actually operate live, to see how it all works.
>
> --marcs
>
> On Mon, Nov 2, 2015 at 8:09 PM, William ML Leslie <
> [email protected]> wrote:
>
>> "User driven access control: rethinking permission granting in modern
>> operating systems (Oakland 2012)" is a great place to start.  From
>> there, many of the cited papers are handy too.
>>
>> You can get the paper from __apf__'s list here:
>>
>>
>> https://docs.google.com/document/d/1N5uTePbaHGGz70nX5zc28Cil026f80oR_ypAxo5ar40/edit
>>
>> --
>> William Leslie
>>
>> Notice:
>> Likely much of this email is, by the nature of copyright, covered
>> under copyright law.  You absolutely MAY reproduce any part of it in
>> accordance with the copyright law of the nation you are reading this
>> in.  Any attempt to DENY YOU THOSE RIGHTS would be illegal without
>> prior contractual agreement.
>> _______________________________________________
>> cap-talk mailing list
>> [email protected]
>> http://www.eros-os.org/mailman/listinfo/cap-talk
>>
>
>

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk