dotgnu-auth
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Auth]Re: What I percieve is wrong with IDsec (was IDsec specificat


From: Rhys Weatherley
Subject: Re: [Auth]Re: What I percieve is wrong with IDsec (was IDsec specification draft)
Date: Sun, 06 Jan 2002 10:36:06 +1000

John wrote:

> If "oneself" is you, Hans, or myself;  then I could agree that each of
> us could trust "oneself". Will I say the same of 90% of the users of
> Passport: the so-called common consumers we are trying to offer an
> alternative to? No, I would be hard put to say they can trust themselves
> to be their own privacy admins.

A principle that I always try to use where privacy and security
is concerned is to set the default to "that which causes the
least amount of harm".

If IDsec defaults to remote profiles, then the user has to take
some action to make it more private.  But if IDsec defaults to
local profiles, with every conceivable encryption and anti-
correllation option enabled, then the user has to take some
action to make it less private.

Just another viewpoint ...

Cheers,

Rhys.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]