Re: Joins on capabilities that have passed through different membranes

<[email protected]> Tue, 5 Jan 2016 08:24:55 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <CAG7xX7oWXu2xt_z-PVQbctoVaf-96JHNE+2M6QtuK8b64PTg4Q@mail.gmail.com>
--===============5000144133759417524==
Content-Type: multipart/alternative; boundary=089e013a2a26973127052898ad9a

--089e013a2a26973127052898ad9a
Content-Type: text/plain; charset=UTF-8

On Tue, Jan 5, 2016 at 4:41 AM, David Bruant <[email protected]> wrote:

> Can you provide a concrete example of why one would want to perform the
>> join instead of just using the two capabilities separately?
>>
>
I'm going to take a guess. This is a problem we talked about extensively
during the early parts of the Caja project, and discussed with our security
PMs. From what I recall, we did not have a good answer.

* Let's say I have a document I own and have read/write access to. Let's
call my capability to it [rwdoc].

* I share a read-only cap to that document with Kenton. I say something
like, "Hey Kenton, check out this stuff I wrote up at [rodoc]. Regards."

* Months later, Kenton replies to me, saying, "Hey Ihab, I think you need
to add the following information to [rodoc], because some new stuff came
up! Kthxbai."

* The cap [rodoc] arrives in my user agent -- browser or whatever. Now
what? There is no simple "correct" solution.

-> If my user agent automatically amplifies it to [rwdoc], that means the
agent has ambient authority. In fact, that's what happens with browsers and
cookies today! And when you make the situation a bit more complex, with
Kenton's original example, you end up with the joining problem he has
raised.

-> If my user agent does nothing, then I have "two ways" to get to one
logical document, and we don't know how to explain this state of affairs to
end-users.

I think this is a UX research problem. :)

Ihab

-- 
Ihab A.B. Awad, Palo Alto, CA

--089e013a2a26973127052898ad9a
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">=
On Tue, Jan 5, 2016 at 4:41 AM, David Bruant <span dir=3D"ltr">&lt;<a href=
=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt;=
</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .=
8ex;border-left:1px #ccc solid;padding-left:1ex"><span><blockquote class=3D=
"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding=
-left:1ex">Can you provide a concrete example of why one would want to perf=
orm the join instead of just using the two capabilities separately?<br></bl=
ockquote></span></blockquote><div><br></div><div>I&#39;m going to take a gu=
ess. This is a problem we talked about extensively during the early parts o=
f the Caja project, and discussed with our security PMs. From what I recall=
, we did not have a good answer.</div><div><br></div><div>* Let&#39;s say I=
 have a document I own and have read/write access to. Let&#39;s call my cap=
ability to it [rwdoc].</div><div><br></div><div>* I share a read-only cap t=
o that document with Kenton. I say something like, &quot;Hey Kenton, check =
out this stuff I wrote up at [rodoc]. Regards.&quot;</div><div><br></div><d=
iv>* Months later, Kenton replies to me, saying, &quot;Hey Ihab, I think yo=
u need to add the following information to [rodoc], because some new stuff =
came up! Kthxbai.&quot;</div><div><br></div><div>* The cap [rodoc] arrives =
in my user agent -- browser or whatever. Now what? There is no simple &quot=
;correct&quot; solution.</div><div><br></div><div>-&gt; If my user agent au=
tomatically amplifies it to [rwdoc], that means the agent has ambient autho=
rity. In fact, that&#39;s what happens with browsers and cookies today! And=
 when you make the situation a bit more complex, with Kenton&#39;s original=
 example, you end up with the joining problem he has raised.</div><div><br>=
</div><div>-&gt; If my user agent does nothing, then I have &quot;two ways&=
quot; to get to one logical document, and we don&#39;t know how to explain =
this state of affairs to end-users.</div><div><br></div><div>I think this i=
s a UX research problem. :)</div><div><br></div><div>Ihab</div><div><br></d=
iv><div>--=C2=A0<br></div></div><div>Ihab A.B. Awad, Palo Alto, CA</div>
</div></div>

--089e013a2a26973127052898ad9a--

--===============5000144133759417524==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk

--===============5000144133759417524==--