monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] WARNING: ~/.monotone/keys CONSIDERED HARMFUL


From: Daniel Carrera
Subject: Re: [Monotone-devel] WARNING: ~/.monotone/keys CONSIDERED HARMFUL
Date: Tue, 21 Oct 2008 12:39:36 +0200
User-agent: Thunderbird 2.0.0.17 (Macintosh/20080914)

Richard Levitte wrote:
*ahem*

identification: Who do you claim to be?
authentication: Can you provide evidence that you are who you claim to be.
authorization:  Are you allowed to do this?

Cheers,
Richard ( nit-picker )

Indeed, you are right - and not only about the nit-picker part :-)

Schneier gives an interesting example from the London Underground. In Beyond Fear, chp 13 he says that in the London Underground you get an id card with your picture on it, and a ticket (which may be for a week, a month or a year). The ID card has an identification number in it. On the ticket, you write the number of the ID card. The ticket is authorization and the photo ID is authentication. Now, the ID card has a place for you to fill in your name, but you don't have to. Nobody cares if your name is on the card or not, they don't care who you are (identification). What they care is that two people don't use the same yearly pass. To do that, what you need is authentication and authorization.


Daniel.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]