--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CAGC3UE%3DaentEAEv%2BYhVpg%2BtWERktjND-MP%2BP5w72UJD34mgLyg%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z2zZ7xy69DouQGiTd6YxjkK4u2eAgNEsOwnyYHRpkr2vw%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEnA%2BsbKT3ZxMY04LwtzNagMY%3DyHpW0yY0NThK8zNY3AGA%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z0feTbCAxEr9s5_X3GJ3qrQOKXCZw__yaVQk00NF3-rTw%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEmbW425nhdO3brE8T7yB7BW%2B8LAcezpw2LpqSdBQTgWzQ%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z3b%2BdOCPHz7Fw%2B6DBN2TQKVEwwghgkfuN4G5NGFH8G%2B_A%40mail.gmail.com.
I’ve used PEM and MOSS. I used MOSS for exchanging invoices and acknowledgements with the Bank of America. The disadvantage of this is you have to store a passphrase/password, or provide one for each set of transactions.
I worked with Jed Donnelley devising a system with GPG/PGP and Java for file system access. As I recall, this used a password as well.
Thus, I am familiar with PKI. The main issue is storing a passphrase, much like ssh-agent does.
I currently plan to upload session/gathering and petname+token via Selenium Java test framework, then I will use tokens to communicate between the web browser and the socket.io backend over secure websockets. One thing I am dealing with is CORS.
A unique id for revocation sounds cool.
I was thinking of Mark Stiegler approach, keeping a hashtable of token to permissions, which can be attenuated. I think we already discussed following a chain of pointers to the root token. A question would be following pointer in the opposite direction if send and receive are separate capabilities.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEmprgxS8kg3AfyzLxObPRAwFu5YBtx-TvbJU4-r9RJTpA%40mail.gmail.com.
Comments inline.
--------------
Alan KarpOn Thu, Oct 3, 2024 at 11:56 AM John Carlson <yott...@gmail.com> wrote:I’ve used PEM and MOSS. I used MOSS for exchanging invoices and acknowledgements with the Bank of America. The disadvantage of this is you have to store a passphrase/password, or provide one for each set of transactions.I had to look up PEM and MOSS. PEM is authentication-based, and is clearly not suitable for a capability system. I didn't see anything about a password in the description of MOSS, but it isn't suitable, either, if there's such a requirement. Neither achieved widespread adoption according to ChatGPT.I worked with Jed Donnelley devising a system with GPG/PGP and Java for file system access. As I recall, this used a password as well.I'm dubious that something Jed designed used a password unless it was to bootstrap into a legacy file system.
Thus, I am familiar with PKI. The main issue is storing a passphrase, much like ssh-agent does.As far as I knowPKI doesn't need a passphrase, but standard key management tools do. You should be able to manage private keys any way you choose.
I currently plan to upload session/gathering and petname+token via Selenium Java test framework, then I will use tokens to communicate between the web browser and the socket.io backend over secure websockets. One thing I am dealing with is CORS.I must be way out of the mainstream; I had to look up Selenium, too. Websockets appears to be a good way to communicate browser to browser, but I've never used them myself.
A unique id for revocation sounds cool.A unique ID is part of every certificate system I've ever looked at, whether used for capabilities or not.
I was thinking of Mark Stiegler approach, keeping a hashtable of token to permissions, which can be attenuated. I think we already discussed following a chain of pointers to the root token. A question would be following pointers in the opposite direction if send and receive are separate capabilities.
I don't see why you'd need the reverse lookup when send and receive are separate capabilities. You might want such a table for audit purposes, but you can construct it from the primary table.
To view this discussion on the web visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z3odBE5Fkg%3D1MX5foUVG9Dvqg625yPFbvCaKgrp6FTCSA%40mail.gmail.com.
Replies inline.
On Thu, Oct 3, 2024 at 3:39 PM Alan Karp <alan...@gmail.com> wrote:Comments inline.
--------------
Alan KarpOn Thu, Oct 3, 2024 at 11:56 AM John Carlson <yott...@gmail.com> wrote:I worked with Jed Donnelley devising a system with GPG/PGP and Java for file system access. As I recall, this used a password as well.I'm dubious that something Jed designed used a password unless it was to bootstrap into a legacy file system.
It was PGP/GPG system that required a password to unlock the private key. His thought was to use public key encryption, as he described in his paper. I implemented the system.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEksDPp2brWOcHb2%3Da-xhXj2FTsmwRCY2un%3DbysdZjXrEw%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEksDPp2brWOcHb2%3Da-xhXj2FTsmwRCY2un%3DbysdZjXrEw%40mail.gmail.com.
Websockets appears to be a good way to communicate browser to browser, but I've never used them myself.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAFwScO8%3DMGwbzDrctkx8zF%2BxDR14DZ0OpkC04T4tbj1t%3D%2BP21g%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/6102f6fb-3d17-428c-93e9-559d16d62e79n%40googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEmNRS79hszd80YisO1eyXKpTTDamFR4ENLn%3Dj-oWzRDLA%40mail.gmail.com.
Why don't you use Jitsi Meet for teleconferencing, it is an open-source alternative to Zoom and Discord.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAKqWSW6L29%3DYYjKBUEOC9PM_GxXXRS6pxroff3_KPb3ps5xAyg%40mail.gmail.com.
On Wed, Jan 22, 2025 at 1:31 AM Valerio Bellizzomi <vbell...@gmail.com> wrote:Why don't you use Jitsi Meet for teleconferencing, it is an open-source alternative to Zoom and Discord.That doesn't sound popular, but I've heard of it. Most of my community is around Zoom and Discord. Slack was tried, and there's some new thing in Europe...Zulip Chat? I already forgot the name and my password. Getting people off phone/video teleconferencing into a 3D system, even though the whole meeting is about Web3D, is kind of weird. Other systems have been devised for 3D that you've never heard of. Secret? Meta means death in Hebrew. Are people on a Quest to meet in deathverse?Really, I just want to build multi-user 3D collaboration thing that people can launch with weblinks or app links. An iframe in Discord sounds super easy, except for Oauth.Zoom sounds a lot cooler than Discord or Meta
The next place to be seems to be Blue Sky. That's a pretty cool name. Electric Light Orchestra - Mr. Blue Sky (Official Video)
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAKQgqTbC5atvQmh-K%2B1yGSbw6mwk2Ba2b1ryo1pZiyKXjDRrQA%40mail.gmail.com.