[cap-talk] Webkeys vs. the web

Raoul Duke raould at gmail.com
Wed Apr 1 23:25:50 EDT 2009


> A webkey will have a random-looking object ID that the user would have to
> assume might be specific to their account.

from a usability+security standpoint, i don't feel it is OK to require
that users parse URLs to decide if they are something they shouldn't
copy-and-paste to another person, and to figure out precisely what
another person would then see if they followed it.

sincerely.


More information about the cap-talk mailing list