RE: ACTION-278 Hiding metadata for security reasons

>> Non-public URIs provide a weak level of security that is held to be 
>>  adequate for some usecases.
> I wonder if there is disagreement with the above statement.

Not too bad, but I'm not sure "non-public" captures the sense.
Whether something is or isn't "public" depends on whether
it has been disclosed publically, and so whether URIs are 'public' depend on where you are in the life cycle. "unguessable URIs" for me captures the spirit more:


"One pattern is using unguessable URIs as a resource identifier for a temporary-validity 'resource' which really acts as a capability to perform some action -- access a document or calendar entry, unsubscribe from a mailing list or some such. When used with time-limits and other protection mechanisms intended to slow or minimize the possibilities of accidental disclosure,  unguessable URIs may be useful in situations where requirements for confidentiality aren't high."



 

Received on Monday, 8 February 2010 03:41:59 UTC