Re: Rant on Capability Security [LONG]

At 06:31 PM 4/18/97 -0400, Perry E. Metzger wrote:
>I will point out that Matt Blaze was making repeated points at our
>meeting in Memphis about assuring that we don't stumble down paths
>that would make proofs of the properties of a certificate hard.
>I suspect that we will likely end up having to go through a pass of
>eliminating unneeded features that do things like making it difficult
>to reason about security relationships or which make the system too
>hard to implement.

We should definitely do that pass at the end -- and continue to examine 
later -- but I have been conscious of this need all along and believe we 
should all keep these in mind.

 - Carl

