Permission Denied
Andrew Martin · 2025
Abstract Access to a computer, and the data it contains, and much else beside, is generally subject to some sort of policy. The policy may be determined according to the identity of the person (or system) undertaking the access, proof of that identity (authentication), and a series of authorization rules governing who can do what. This is great in principle, but in practice the rules are near-impossible to get right: they will be too permissive or too strict. This plays out in many settings, not least in managing modern Internet of Things situations, and digital assistants. Authentication may also take many forms, appropriate to the circumstances—passwords, PINs, biometrics, and a combination of these.