Re: [SPAM] Re: Joins on capabilities that have passed through different membranes

Kenton Varda <[email protected]> Tue, 19 Jan 2016 21:14:00 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <CAOP=4wiuCAEyD5jk9s=wQHUVSH62B3u6MTMp5DHnmUzrwGRxQw@mail.gmail.com>
--===============7267801414346287213==
Content-Type: multipart/alternative; boundary=001a1142cf74f304dd0529bd0e56

--001a1142cf74f304dd0529bd0e56
Content-Type: text/plain; charset=UTF-8

I don't think "If people understand email attachments they can understand
caps" is a good argument.

Email attachments have significantly higher cognitive overhead than Google
Docs does today. Yes, a lot of people get it, but at a mental cost, and
some people (probably, people that people like us rarely interact with)
could never handle it at all. Google Docs is widely considered to be a huge
improvement over that world. If we're going to tell people that we want to
go back to an email attachments paradigm, then we need a damned good reason.

And IMO, there really isn't a good reason. If we're going to argue that
humans are susceptible to confused deputy, we need examples, but I've never
heard of one. (This is in stark contrast to computers, where we have an
endless list of examples.)

If we fight battles where we don't have strong evidence to back our case,
people will stop taking us seriously.

So, I choose to concede this one.

With that said, if someone did come up with real evidence that confused
deputy is a problem for humans, it would not be hard to adjust Sandstorm to
work differently. Our model is primarily capability-based under the hood,
with automatic merging built on top as a feature.

-Kenton

On Sun, Jan 17, 2016 at 12:42 PM, Mike Stay <[email protected]> wrote:

> I have issues with their claim as well; in particular, I don't think they
> ever tried making it a coherent caps-based system, but tried to use some
> caps-like ideas in their existing system.
>
> On Fri, Jan 15, 2016 at 6:44 PM, Sandro Magi <[email protected]>
> wrote:
>
>> I'm skeptical of this UI claim. This behaviour is exactly what happens
>> when people open Word attachments directly from some e-mail clients. An
>> additional strip at the top says you're in read-only mode, and provides a
>> button to begin editing. This pattern has clearly existed for many years
>> already, and persists to this day, so it can't be so confusing as to be
>> unusable.
>>
>> Sandro
>>
>> On 05/01/2016 2:46 PM, Mike Stay wrote:
>>
>>> On Tue, Jan 5, 2016 at 11:14 AM, Alan Karp <[email protected]> wrote:
>>>
>>>> Marc Stiegler came up with a clever UI affordance to make all this
>>>> clear.
>>>> If Ihab views the document with Kenton's capability, Ihab sees a ro
>>>> view.
>>>> If Ihab opens it with his own, he sees a rw view.  In either case, he
>>>> see
>>>> the same document, which reduces any possible confusion.  Since Ihab
>>>> does
>>>> have write permission, his UI has an Edit button (actually a tab in
>>>> Stiegler's UI).
>>>>
>>> Google's UI researchers claimed to us that people would get a
>>> read-only view from somewhere and then be confused when they couldn't
>>> edit it, even when there was an edit button.  People don't look for
>>> controls they don't expect to need.
>>>
>>
>>
>> _______________________________________________
>> cap-talk mailing list
>> [email protected]
>> http://www.eros-os.org/mailman/listinfo/cap-talk
>>
>
>
>
> --
> Mike Stay
> [email protected]
>
> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>
>

--001a1142cf74f304dd0529bd0e56
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I don&#39;t think &quot;If people understand email attachm=
ents they can understand caps&quot; is a good argument.<div><br></div><div>=
Email attachments have significantly higher cognitive overhead than Google =
Docs does today. Yes, a lot of people get it, but at a mental cost, and som=
e people (probably, people that people like us rarely interact with) could =
never handle it at all. Google Docs is widely considered to be a huge impro=
vement over that world. If we&#39;re going to tell people that we want to g=
o back to an email attachments paradigm, then we need a damned good reason.=
</div><div><br></div><div>And IMO, there really isn&#39;t a good reason. If=
 we&#39;re going to argue that humans are susceptible to confused deputy, w=
e need examples, but I&#39;ve never heard of one. (This is in stark contras=
t to computers, where we have an endless list of examples.)</div><div><br><=
/div><div>If we fight battles where we don&#39;t have strong evidence to ba=
ck our case, people will stop taking us seriously.</div><div><br></div><div=
>So, I choose to concede this one.</div><div><br></div><div>With that said,=
 if someone did come up with real evidence that confused deputy is a proble=
m for humans, it would not be hard to adjust Sandstorm to work differently.=
 Our model is primarily capability-based under the hood, with automatic mer=
ging built on top as a feature.</div><div><br></div><div>-Kenton</div></div=
><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Sun, Jan 17, =
2016 at 12:42 PM, Mike Stay <span dir=3D"ltr">&lt;<a href=3D"mailto:stay@go=
ogle.com" target=3D"_blank">[email protected]</a>&gt;</span> wrote:<br><block=
quote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc=
 solid;padding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_default" styl=
e=3D"font-family:arial,helvetica,sans-serif">I have issues with their claim=
 as well; in particular, I don&#39;t think they ever tried making it a cohe=
rent caps-based system, but tried to use some caps-like ideas in their exis=
ting system.</div></div><div class=3D"gmail_extra"><div><div class=3D"h5"><=
br><div class=3D"gmail_quote">On Fri, Jan 15, 2016 at 6:44 PM, Sandro Magi =
<span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D"_=
blank">[email protected]</a>&gt;</span> wrote:<br><blockquote class=3D=
"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding=
-left:1ex">I&#39;m skeptical of this UI claim. This behaviour is exactly wh=
at happens when people open Word attachments directly from some e-mail clie=
nts. An additional strip at the top says you&#39;re in read-only mode, and =
provides a button to begin editing. This pattern has clearly existed for ma=
ny years already, and persists to this day, so it can&#39;t be so confusing=
 as to be unusable.<span><font color=3D"#888888"><br>
<br>
Sandro</font></span><span><br>
<br>
On 05/01/2016 2:46 PM, Mike Stay wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
On Tue, Jan 5, 2016 at 11:14 AM, Alan Karp &lt;<a href=3D"mailto:alanhkarp@=
gmail.com" target=3D"_blank">[email protected]</a>&gt; wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Marc Stiegler came up with a clever UI affordance to make all this clear.<b=
r>
If Ihab views the document with Kenton&#39;s capability, Ihab sees a ro vie=
w.<br>
If Ihab opens it with his own, he sees a rw view.=C2=A0 In either case, he =
see<br>
the same document, which reduces any possible confusion.=C2=A0 Since Ihab d=
oes<br>
have write permission, his UI has an Edit button (actually a tab in<br>
Stiegler&#39;s UI).<br>
</blockquote>
Google&#39;s UI researchers claimed to us that people would get a<br>
read-only view from somewhere and then be confused when they couldn&#39;t<b=
r>
edit it, even when there was an edit button.=C2=A0 People don&#39;t look fo=
r<br>
controls they don&#39;t expect to need.<br>
</blockquote>
<br>
<br></span><div><div>
_______________________________________________<br>
cap-talk mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">cap-talk@mai=
l.eros-os.org</a><br>
<a href=3D"http://www.eros-os.org/mailman/listinfo/cap-talk" rel=3D"norefer=
rer" target=3D"_blank">http://www.eros-os.org/mailman/listinfo/cap-talk</a>=
<br>
</div></div></blockquote></div><br><br clear=3D"all"><div><br></div></div><=
/div><span class=3D"HOEnZb"><font color=3D"#888888">-- <br><div>Mike Stay<b=
r><a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><=
/div>
</font></span></div>
<br>_______________________________________________<br>
cap-talk mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]</a><=
br>
<a href=3D"http://www.eros-os.org/mailman/listinfo/cap-talk" rel=3D"norefer=
rer" target=3D"_blank">http://www.eros-os.org/mailman/listinfo/cap-talk</a>=
<br>
<br></blockquote></div><br></div>

--001a1142cf74f304dd0529bd0e56--

--===============7267801414346287213==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk

--===============7267801414346287213==--