Monday, July 05, 2004

Capability-based Security and the Web

Tyler Close (of Waterken) writes in the e-lang email list...

The status quo of WWW security is unfortunately mired in the ACL model. However, if you ignore the various security add-ons of the WWW, and focus solely on the underlying model, you find an amazing symmetry with capability-based security. In fact, if you push REST design principles to their logical conclusions, you arrive at some of the core principles of capability-based security.

