[cap-talk] Webkeys vs. the web
Raoul Duke
raould at gmail.com
Wed Apr 1 23:25:50 EDT 2009
> A webkey will have a random-looking object ID that the user would have to
> assume might be specific to their account.
from a usability+security standpoint, i don't feel it is OK to require
that users parse URLs to decide if they are something they shouldn't
copy-and-paste to another person, and to figure out precisely what
another person would then see if they followed it.
sincerely.
More information about the cap-talk
mailing list