Search the web
Sign In
New User? Sign Up
rest-explore
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.

Messages

  Messages Help
Advanced
Messages 387 - 416 of 445   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
387
From: "Chuck Hinson" <cmhinson@...> ... First, I think it's entirely reasonable to generate a long, random character sequence in place of use of a...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 1, 2003
1:28 pm
388
... I dont disagree, and I have the same nervousness about using something as both the name and the access token. While I know almost nothing about...
Chuck Hinson
cmhinson@...
Send Email
May 1, 2003
2:01 pm
389
From: "Michael Day" <mikeday@...> ... embedding ... it ... Except for two things: 1) the query still needs the recipient to identify themselves to the...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 1, 2003
2:03 pm
390
From: "Michael Day" <mikeday@...> ... Good list! To me, RNA currently provides the infrastructure for the first four, but only because this is...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 1, 2003
2:07 pm
391
From: "Michael Day" <mikeday@...> ... choose ... time I ... being ... easily ... Also, it occurred to me this morning that the <notifications> was...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 1, 2003
2:14 pm
392
From: "Chuck Hinson" <cmhinson@...> ... Not entirely, I think. If you were sending a notification to multiple recipients, for instance, you would have to...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 1, 2003
2:19 pm
393
A number of the arguments made in this sub-thread about authentication have made incorrect reference to security aphorisms. I thought it would be helpful if I...
Tyler Close
tjclose
Offline Send Email
May 1, 2003
3:20 pm
394
... Just so that no one gets confused, I want to add emphasis to this part. The crux of "something you have and something you know" is that you are...
Tyler Close
tjclose
Offline Send Email
May 1, 2003
4:06 pm
395
... [. . .] ... Why make a special case? And why force PUSH to only send one notification at a time? It seems like an arbitrary restriction that reduces the...
Chuck Hinson
cmhinson@...
Send Email
May 1, 2003
4:23 pm
396
... I hesitate to reply since my knowledge of security is pretty limited. Perhaps I stretched the have/know aphorism a little far, but the way I look at it,...
Chuck Hinson
cmhinson@...
Send Email
May 1, 2003
4:37 pm
397
... Hmm. OK. Well now that you put it that way, it seems that I've been working with a bad definition all these years. I guess a better term for what I was...
Chuck Hinson
cmhinson@...
Send Email
May 1, 2003
4:54 pm
398
... That is also incorrect. "security through obfuscation" refers to a security mechanism with no theoretical backing. Typically, this means that the security ...
Tyler Close
tjclose
Offline Send Email
May 1, 2003
6:54 pm
399
Tyler, My comments inline ... Tyler Close <tyler@...> wrote: ... That is also incorrect. "security through obfuscation" refers to a security...
Kaleem Aziz
kaleemaziz
Offline Send Email
May 1, 2003
7:06 pm
400
... Which is exactly what I meant by security through obfuscation. I'm not sure what you mean when you say it is also incorrect. ... None of which I dispute...
Chuck Hinson
cmhinson@...
Send Email
May 1, 2003
7:32 pm
401
From: "Tyler Close" <tyler@...> tracks, and I thought you might want to know. ... First, this is not a messaging protocol. This is a notification...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 2, 2003
12:59 am
402
... If you want to POST multiple notifications, you could always make multiple POSTs of single notifications over a persistent HTTP/1.1 connection. So,...
Michael Day
mikeday@...
Send Email
May 2, 2003
4:53 am
403
... Thanks, I had never heard the word "nonce" used outside of Shakespeare :) In that case, replace what I said about "security through obscurity" with ...
Michael Day
mikeday@...
Send Email
May 2, 2003
4:58 am
404
... I think the discussion would benefit from your input on security issues, particularly if you have some ideas in mind on security models that could be...
Michael Day
mikeday@...
Send Email
May 2, 2003
5:08 am
405
I've rewritten this message based on Tyler's comments on incorrect aphorisms. There are five methods of authentication: 1. No authentication. Useful for public...
Michael Day
mikeday@...
Send Email
May 2, 2003
5:18 am
406
From: "Michael Day" <mikeday@...> ... However, a recipient should not make any such assumption about the uniqueness of the user/password combination....
Seairth Jacobs
seairthjacobs
Offline Send Email
May 2, 2003
2:01 pm
407
... Thank you. ... I do have some ideas. I hope you will give them due hearing and not jump to premature and uninformed decisions. ... Well, the first step is...
Tyler Close
tjclose
Offline Send Email
May 2, 2003
2:30 pm
408
... One of the features you are aiming for with RNA, is notification that a recipient has read a message. You intend to support this feature by recording that...
Tyler Close
tjclose
Offline Send Email
May 2, 2003
3:34 pm
409
From: "Tyler Close" <tyler@...> ... discover ... fails, ... There seem to be two parts to this: 1) An anonymous access of the resource. In this case,...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 2, 2003
4:11 pm
410
... Yes, this is the case I am considering. ... This claim is false. ... I assume that if a recipient decides that he does not want to register a...
Tyler Close
tjclose
Offline Send Email
May 2, 2003
5:04 pm
411
... I think I guessed the wrong place in your protocol for the access control check. It looks like the check takes place later. Either way, the recipient is...
Tyler Close
tjclose
Offline Send Email
May 2, 2003
5:42 pm
412
... I think I've missed something here. It seems to me that all you've done is tricked Bob into thinking he wants to access the resource by providing a...
Chuck Hinson
cmhinson@...
Send Email
May 2, 2003
6:06 pm
413
From: "Tyler Close" <tyler@...> ... impersonation ... notification. ... Okay. I don't see why, but I'm willing to be shown that I am wrong. ... ...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 2, 2003
6:36 pm
414
... The problem is that the ACL model makes it very difficult to not be careless with your authority. Assume the recipient has the authority to read a large...
Tyler Close
tjclose
Offline Send Email
May 2, 2003
8:19 pm
415
From: "Tyler Close" <tyler@...> ... access ... retrieved. ... can ... Okay. I agree with this. ... But this *is* the scenario right now, if I...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 3, 2003
5:58 pm
416
From: "Chuck Hinson" <cmhinson@...> ... I've been continuing to give this some thought. At this point, I'm still not sure whether notifications should...
Seairth Jacobs
seairthjacobs
Offline Send Email
May 5, 2003
3:13 am
Messages 387 - 416 of 445   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2007 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help