--
You received this message because you are subscribed to the Google Groups "friam" group.
To unsubscribe from this group and stop receiving emails from it, send an email to friam+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/CANpA1Z2D-mdscZ8H6%3DtjCrjW%3D0-DqyHKV_hkfR4Vmv89D5qw-Q%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z2D-mdscZ8H6%3DtjCrjW%3D0-DqyHKV_hkfR4Vmv89D5qw-Q%40mail.gmail.com.
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAKQgqTYsYan51J%2BpZBk-3Ty71Zcxw6j8AkM-WzmBUAg-wKF-KQ%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/F34BC653-C48F-4605-A37A-EF0052BC65AC%40gmail.com.
I feel like a point is that Alice asked Bob for instructions thus is two-way. Alice has the chance and responsibility to error/sanity/security check the instructions, ideally.Whereas me sending my demon print job to the print daemon to overwrite /etc/password ha ha is one-way. That is a confused deputy.
I feel like a point is that Alice asked Bob for instructions thus is two-way. Alice has the chance and responsibility to error/sanity/security check the instructions, ideally.Whereas me sending my demon print job to the print daemon to overwrite /etc/password ha ha is one-way. That is a confused deputy.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAJ7XQb5sL_1kaSpurWr2x3G9vbU%2BCy0JjZo60Tv9pmAJxj_q%3DQ%40mail.gmail.com.
I feel like a point is that Alice asked Bob for instructions thus is two-way. Alice has the chance and responsibility to error/sanity/security check the instructions, ideally.Whereas me sending my demon print job to the print daemon to overwrite /etc/password ha ha is one-way. That is a confused deputy.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAJ7XQb5sL_1kaSpurWr2x3G9vbU%2BCy0JjZo60Tv9pmAJxj_q%3DQ%40mail.gmail.com.
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAKQgqTYsYan51J%2BpZBk-3Ty71Zcxw6j8AkM-WzmBUAg-wKF-KQ%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/84018285-c368-4712-8343-812d6bcbc2f8%40charlielandau.com.
It’s not a confused deputy, but a malicious trustee.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAJ7XQb4eqQ17PkjRvYon3RKFpFUTSLxHV9G54dMXwE%2B1_N9Wdw%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z0yJMLM5SaTSdMi5_oz7%2BdkaZ5HA5Y%3Dp6nO%3DBYYOa4mUA%40mail.gmail.com.
Feels like an important in fact essential distinction,no?it can only be a deputy if it is not me.if it is me i have nobody to blame but myself.which is a different category of problem.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAJ7XQb7jYzfPnEHj7pg6zt1K0ydskVh5ryLhxrxYB1vir8nE-Q%40mail.gmail.com.
Ah, yes, right - ocap does sound like a way to do it.(but it is not in my mind confused deputy. Only would be if Bob were directly writing to files which is not how it was originally stated iiuc.)
Ah, yes, right - ocap does sound like a way to do it.(but it is not in my mind confused deputy. Only would be if Bob were directly writing to files which is not how it was originally stated iiuc.)
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAJ7XQb5JP-%2BZx_zmgPJxX_UdFYoLcjau2EkVNAg0-m11rB_hgQ%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CACTLOFrH2TxGL9kK_aALSOedqs9HY1zb7e0G9vDYxYQ4wp3ZHg%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAJ7XQb67uYYmFBHtsVwroTDZc3eKjj%2BdGW3DUgBfQwJYHTRFfQ%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z3RC_EnUtDybBktZwUV08JV4Bdi%2BbtY3%3Dax%2BYefPriWOQ%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAKQgqTa9N7cqqwDB4hn%2B0rpo3VM3r4vxSuJZQ1MG0Fk_wXczOw%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEkmWrMA4fJrB7TX19DqmOP0F3gXem%2BvSKSbU3c7pCPROg%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z0ioMD2c0g3tPEeT61X58-_7bG-YdH-EgJ7OCzicsSZZg%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CANpA1Z08KB_4FiAPw3xc28aC7QAeTi%2BuS0qU2Hb%2BsE16eFp%3DcQ%40mail.gmail.com.
Does it make a difference which system the file is on? What if Bob starts sending arbitrary ocaps? Does alice need to compare ocaps?
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAGC3UEnkYK6C6Ac18B0Wc3brdunx2t6LP-EbTEaW-5Beo4VkkA%40mail.gmail.com.
Does that make it a simpler example to explain the problem? Several people I have talked to find Norm's example unconvincing.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAFwScO9APt8%3DHinpyfLo%3Drag8Or6RHhradfJMTMVa9RcOTT1gA%40mail.gmail.com.
This sounds more like Mike Stay's misinterpretation of my question. He was concerned that Bob might return incorrect results (poisoned pizza), while I was worried that Bob might get Alice to give the (unpoisoned) pizza to her grandmother who has digestive problems by telling Alice the wrong room number.
On Thu, Jun 12, 2025 at 5:27 PM Alan Karp <alan...@gmail.com> wrote:This sounds more like Mike Stay's misinterpretation of my question. He was concerned that Bob might return incorrect results (poisoned pizza), while I was worried that Bob might get Alice to give the (unpoisoned) pizza to her grandmother who has digestive problems by telling Alice the wrong room number.Does acting based on received information make you a deputy of the provider of the information? This conversation seems like it could easily slippery-slope into scenarios of trustless paralysis.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAFwScO-upw%3DCG0iLfHSpOF-PG6n%3D2b%3DWw85BQZ9UafuiNTwvNg%40mail.gmail.com.
On Fri, Jun 13, 2025 at 3:11 AM David Nicol <david...@gmail.com> wrote:On Thu, Jun 12, 2025 at 5:27 PM Alan Karp <alan...@gmail.com> wrote:This sounds more like Mike Stay's misinterpretation of my question. He was concerned that Bob might return incorrect results (poisoned pizza), while I was worried that Bob might get Alice to give the (unpoisoned) pizza to her grandmother who has digestive problems by telling Alice the wrong room number.Does acting based on received information make you a deputy of the provider of the information? This conversation seems like it could easily slippery-slope into scenarios of trustless paralysis.I'm trying to separate concerns specific to the application, such as the result of some computation, from access control concerns.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAFwScO9xVR_XRvM5YbeqsEF99K1dZhNaW2Q2cxQS6runGCGB7Q%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAFwScO9xVR_XRvM5YbeqsEF99K1dZhNaW2Q2cxQS6runGCGB7Q%40mail.gmail.com.
It seems that what Alice actually has is a set of files, which contain whatever Bob says should go there.
On 6/11/25 5:13 PM, Mike Stay wrote:
Seems more like a type error to me. Alice should expect a set of files of a type that depends on the given word. Bob is providing the service on an open network where Bob is just sending bits, then Alice should either expect Bob's responses to contain a proof that they're a serialization of the right type or Alice should prove it to herself.
On Wed, Jun 11, 2025 at 4:00 PM Alan Karp <alan...@gmail.com> wrote:
--Alice has some files, each for a different subset of her data. For simplicity, say that there is a file for each letter of the alphabet, and a word goes into a file if the word contains the corresponding letter. Bob runs a service that tells Alice which files to update for a given word. If he is malicious, Bob will specify a file not in that set, which Alice will overwrite using her permissions.
--------------
Alan Karp
You received this message because you are subscribed to the Google Groups "friam" group.
To unsubscribe from this group and stop receiving emails from it, send an email to friam+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/CANpA1Z2D-mdscZ8H6%3DtjCrjW%3D0-DqyHKV_hkfR4Vmv89D5qw-Q%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/CAKQgqTYsYan51J%2BpZBk-3Ty71Zcxw6j8AkM-WzmBUAg-wKF-KQ%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "cap-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cap-talk+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cap-talk/84018285-c368-4712-8343-812d6bcbc2f8%40charlielandau.com.