Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another interesting feature of capability-based systems (that is outside Zanzibar's scope) is that capabilities can themselves be used to gain access to an object. This is because they are unforgeable tokens, meaning they essentially have authentication baked into them. Zanzibar leaves the authentication piece to an external service and focuses on providing the ability to define, store, and query access rights for subjects.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: