Monday, April 5, 2010

Re: [Geopriv] Deploying authorization policy

> Except that the UI really can't do this, easily (except in cases where
> the users hands these out manually).

Without wanting to go "no true Scotsman" on this discussion, the implied involvement of a user requires greater analysis.

To what extent do we expect a user to interact with URIs? While I'm happy to discuss the implications on usability, I personally don't expect a user to be so intimately involved in the process.

More likely, to my mind, is this sort of question: "Do you wish to allow this site to track your movements?" With the specific mechanism hidden thus, such concerns might be assuaged.

> This gets particularly confusing
> if you have multiple versions of similar-looking URLs with very
> different access properties:

The only reasonable response here is to treat all URLs as they should be treated - as opaque identifiers. If context identifies these as location URIs, then the safest course is to assume the worst: that it can be used to track some target.

--Martin
_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv