Confused deputy

12 views
Skip to first unread message

Alan Karp

unread,
Jul 21, 2026, 8:26:23 PM (6 days ago) Jul 21
to <friam@googlegroups.com>, cap-talk
Is there a proof that it's impossible to express a confused deputy vulnerability in a capability system?

(Asking for a colleague)

--------------
Alan Karp

William ML Leslie

unread,
Jul 21, 2026, 9:05:53 PM (6 days ago) Jul 21
to fr...@googlegroups.com
On Wed, 22 Jul 2026 at 10:26, Alan Karp <alan...@gmail.com> wrote:
Is there a proof that it's impossible to express a confused deputy vulnerability in a capability system?

(Asking for a colleague)

You can! A deputy can put their capabilities in a map, and let the client choose one.

If, instead, you use a capability provided by the client, then the client must have authority to use the resource provided, definitionally.

So you might say: you can construct a deputy that it is impossible to confuse in a capability system.  You can still opt to be a confused deputy, if that's something you want to do.

--
William ML Leslie
Never interrupt the enemy when they're pivoting to AI.

Douglas Crockford

unread,
Jul 22, 2026, 7:54:44 AM (5 days ago) Jul 22
to friam
I think there is an overriding principle: You can always compromise your own security.

    Miscreant: Give me your private key.

    Deputy: Ok.

A capability system can not in itself prevent that. But it does make the situation easier to reason about so as to avaoid confusion.

Alan Karp

unread,
Jul 22, 2026, 12:33:24 PM (5 days ago) Jul 22
to fr...@googlegroups.com
That is not a confused deputy vulnerability.  A confused deputy uses its permissions on a resource designated by somebody else.

--------------
Alan Karp


--
You received this message because you are subscribed to the Google Groups "friam" group.
To unsubscribe from this group and stop receiving emails from it, send an email to friam+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/bf0f10ca-f5f9-4e6e-8e2f-78afb94966ecn%40googlegroups.com.

Alan Karp

unread,
Jul 22, 2026, 12:42:26 PM (5 days ago) Jul 22
to fr...@googlegroups.com
On Tue, Jul 21, 2026 at 6:05 PM William ML Leslie <william.l...@gmail.com> wrote:

So you might say: you can construct a deputy that it is impossible to confuse in a capability system.  

Is there a formal proof of that?

--------------
Alan Karp


--
You received this message because you are subscribed to the Google Groups "friam" group.
To unsubscribe from this group and stop receiving emails from it, send an email to friam+un...@googlegroups.com.

Mark S. Miller

unread,
Jul 22, 2026, 2:20:40 PM (5 days ago) Jul 22
to fr...@googlegroups.com
There is a precise but non-formal argument in Cap Myths Demolished. For formal proofs about Confused Deputies, I'd look in Fred Spiessens thesis or Toby Murray's thesis. Loosely, Cap Myths Demolished says that if the deputy *only* uses ocaps for designation, then it is not vulnerable to a confused deputy attack. But this is such a severe restriction even in an ocap system that many "normal" deputies will not satisfy this restriction. Most "normal" deputy code will nevertheless not be vulnerable to confused deputies, even though you cannot prove it invulnerable by this straightforward argument.

The informal heuristic I use is less severe than "only ocaps for designation" but usually fits well enough: A deputy that does not engage in rights amplification is probably not vulnerable to confused deputy attacks.

Note: I specifically say "(in)vulnerable to confused deputy attack" rather than "can(not) be confused", because the confused deputy attack, despite the name, has nothing to do with confusing the deputy.



Alan Karp

unread,
Jul 22, 2026, 10:19:22 PM (4 days ago) Jul 22
to fr...@googlegroups.com
Thanks for the pointers.  Section 8.1 of Speissen's thesis is what I was looking for.  (We'll see if it satisfies my colleague, but at least it will keep him busy for a while.)  Murray's thesis never mentions confused deputy. 

--------------
Alan Karp


Reply all
Reply to author
Forward
0 new messages