Search the web
Sign In
New User? Sign Up
rest-explore
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Re: Capbailities and RNA   Message List  
Reply | Forward Message #419 of 445 |
Re: [rest-explore] Capbailities and RNA

On Monday 05 May 2003 09:52, Seairth Jacobs wrote:
> From: "Tyler Close" <tyler@...>
>
> > Does this mean that you are dropping authorization methods 2 and
> > 5, from Michael Day's list of 5 authorization methods?
>
> Nope. See below.

I don't understand. In the previous email, you agreed that these
methods are vulnerable to a Confused Deputy attack and said that
RNA passes the "user/pwd" in the notification.

> > Does this mean that you are rescinding your opinion that:
> > "Generating URLs containing authentication tokens seems like a Bad
> > Idea"?
>
> Nope. See below.

A "user/pwd" is an authorization token. Are you saying that the
primary authorization mechanism used in RNA is "a Bad Idea"?

As we've discussed, and you've agreed, using a capability URL is
the only way to prevent the Confused Deputy attack. How do you
reconcile this with thinking that a capability URL is "a Bad
Idea"? The agreed facts indicate the exact opposite.

Tyler



Mon May 5, 2003 3:03 pm

tjclose
Offline Offline
Send Email Send Email

Forward
Message #419 of 445 |
Expand Messages Author Sort by Date

From: "Tyler Close" <tyler@...> ... Nope. See below. ... Nope. See below. ... Simple impersonation. For instance, you may have an address like ...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 5, 2003
1:52 pm

... I don't understand. In the previous email, you agreed that these methods are vulnerable to a Confused Deputy attack and said that RNA passes the "user/pwd"...
Tyler Close
tjclose
Offline Send Email
May 5, 2003
3:21 pm

From: "Tyler Close" <tyler@...> ... A server implementation could use http://user:pwd@.../rna/r/1234, http://seairth.com/rna/r/1234/334956923,...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 5, 2003
4:42 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help