First, what's the problem? http://www.cap-lore.com/CapTheory/ConfusedDeputy.html
What are capabilities? http://habitatchronicles.com/2017/05/what-are-capabilities/
Is there someplace with a massive pile of links? https://github.com/dckc/awesome-ocap
Yes, capabilities are abstract and simple. Don't worry if you don't get it at first.
In some ways the Android/iOS permissions system is a form of "capabilities". Granularity is a problem: too granular and they're tedious, not granular enough and you end up leaking your contacts to your torch app.
It's just an unfortunate pun. Capability-based security wasn't mainstream at the time they were invented. It arguably isn't now either. You can argue that Android/iOS are capability-based, but the model is pretty watered down.
Capability-based security for end users (rather than sys admins) is an unsolved problem as far as I can tell.
See this page:
https://en.wikipedia.org/wiki/Capability-based_security
A capability (known in some systems as a key) is a communicable, unforgeable token of authority.
Linux capabilities don't meet this definition. They're just permissions.
The sibling comment is also correct: