Continuations for web programming; Capabilities for security. False promise?
Looking at the limited success of capability-based security, and also at the perhaps limited actual utility of the neat "continuation-based web service" concept, I'm just wondering if anyone would agree that these are both examples of a simple concept that is initially appealing for its elegance, but actually doesn't quite solve the whole problem? Discuss...