Comment / #1634

Is anybody else confused by this? Perhaps some of this is lost in translation but I think this could use a major overhaul, if not functionally but descriptively — I'm having a hard time wrapping my head around how this security model works.