Search the web
Sign In
New User? Sign Up
rest-explore
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Re: Capbailities and RNA   Message List  
Reply | Forward Message #420 of 445 |
Re: [rest-explore] Capbailities and RNA

From: "Tyler Close" <tyler@...>
> As we've discussed, and you've agreed, using a capability URL is
> the only way to prevent the Confused Deputy attack. How do you
> reconcile this with thinking that a capability URL is "a Bad
> Idea"? The agreed facts indicate the exact opposite.

A server implementation could use http://user:pwd@seairth.com/rna/r/1234,
http://seairth.com/rna/r/1234/334956923, http://seairth.com/rna/334956923,
etc. From the perspective of RNA, it doesn't matter. The URI is opaque.
However, from the implementation perspective, each has its strengths and
weaknesses. Personally, I don't think the "capability URL" is a Bad Idea.
Within my implementation that I am slowly working on, this will be the
approach I happen to be taking. However, I prefer the "user:pwd@" format
for the various reasons that I have already stated. If someone wants to use
nonces instead, that's up to them. Again, it doesn't matter to RNA.

---
Seairth Jacobs
seairth@...




Mon May 5, 2003 4:42 pm

seairthjacobs
Offline Offline
Send Email Send Email

Forward
Message #420 of 445 |
Expand Messages Author Sort by Date

From: "Tyler Close" <tyler@...> ... Nope. See below. ... Nope. See below. ... Simple impersonation. For instance, you may have an address like ...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 5, 2003
1:52 pm

... I don't understand. In the previous email, you agreed that these methods are vulnerable to a Confused Deputy attack and said that RNA passes the "user/pwd"...
Tyler Close
tjclose
Offline Send Email
May 5, 2003
3:21 pm

From: "Tyler Close" <tyler@...> ... A server implementation could use http://user:pwd@.../rna/r/1234, http://seairth.com/rna/r/1234/334956923,...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 5, 2003
4:42 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help