Showing posts with label 4TypesOfTrust. Show all posts
Showing posts with label 4TypesOfTrust. Show all posts

Wednesday, December 21, 2005

Security Orientation

Adam Shostack identifies Three Views of Software Security, which he calls orientations. So I wondered whether these could be mapped onto the four types of trust and mistrust, and whether that reveals a fourth orientation. But the mappings turned out to be a little more complex.

Orientation
Focus
Typical assessment
Type of Trust
Government
Assurance of quality, reliability, safety, and appropriateness for use
Commercial security products aren't good enough to be used. We are losing the security war.
Authority+Network: We are not getting adequate assurances of security - neither from centralized guarantors, or from the emergent power of the network.
Hacking
Tools and techniques of exploration and exploitation at the micro and macro levels
Unwilling to confer a positive evaluation on any product or technology vendor (especially Microsoft).
Commodity+Authentic: We hackers can usually engage more deeply with the product than the vendors themselves.
Economic
People are behaving rationally, if only we can understand their motivations
Few people ask whether products are secure, so there is little explicit demand for security.
Commodity+Network: Security (or its lack) emerges from the combined behaviour of rational actors.

There are several other possible permutations, but the orientation I want to encourage is based on Network+Authentic - combining a deep engagement with the (focal) practices of technical security with a broad and dynamic social base (process-driven, community-driven). Next question: how can we foster this orientation?

Wednesday, October 12, 2005

How trust works

originally posted by John

‘Nobody can think a thought for me’ a clever bloke once observed, ‘just as nobody can wear my hat for me.’

Theoretically he’s right – clever people often are – but, practically, he’s about as wrong as he can get.

Every day other people think thoughts for us. Everyday we think thoughts for other people. If it wasn’t so - if we all suddenly had to start thinking for ourselves - our daily life would become very hard indeed. If we all started thinking for ourselves all the time, life would grind to a halt. Mere survival would become everything. Nothing would ever get done. All would be anarchy.

The magic ingredient that prevents anarchy and allows things to happen – the bit missing from the clever bloke’s observation above – is trust.

Trust makes the world go round. Everything we ever do we do is because of trust. From our most trivial acts to our most portentous, and from the absolutely personal to the earth-shatteringly global, trust is the very lubricant of life itself. If life were a computer, trust would be its irreducible machine code.

Whoever we are, whatever we’re doing, trust always allows us four possible reasons for everything we do:

  • we do things because we’re told they’re in our best interest (power)
  • we do things because they’re the done thing in the group we belong to and belonging to the group is in our best interest (network)
  • we do things out of a sense of duty or responsibility where not doing them might have consequences that are not in our best interests (commodity)
  • we do things purely out of personal choice (authentic)

As we’ll see later, these four reasons are just different aspects of trust. In trivial aspects of life their differences often blur. But when things get serious, when the stakes are high, the role of trust changes and the differences become vital. And whether we use them singly or jointly or whether we use bits and combinations from all of them to justify what we do, we use them all the time in everything we do.

So they’re pretty important. So important in fact that our entire lives take place in a space that is bounded by these four aspects of trust. We (Aidan and I in our book Trust and Mistrust) call this the trust space. Think of it as a square field and everything you do takes place in that field. At any time your precise whereabouts depend on two things: the thing you’re doing and why you’re doing it.

If you’re doing something because you’ve been told to do it then someone is thinking your thoughts for you and you might not be in the most favourable spot in the field. If you’re doing something because it’s what your group do, or you’re doing something out of a sense of duty, the same applies. The rule of the trust space is that there’s always a more favourable place, a better place to be than where you currently find yourself: a place where things work better, a place where more opportunities are revealed, a place where life itself is better. Not just for you but those you come into contact with. Moving towards that place simply requires tapping in to the way trust works.

The trust space is not a theoretical or hypothetical place. It is the true picture of how our lives work. It is the perfect world-view.

This is what it looks like in a little more detail when we’re in the middle of the field looking north.

The closer we move towards the horizon ahead of us the more we do things out of (perceived) personal choice. We call this dimension authentic trust. At the extreme left-hand end lies conformity (publicness) a place where we let all our personal choices be made for us – we let someone think our thoughts for us in other words. In doing so we give up our own thoughts. Moving towards the right-hand end our own thoughts begin to take precedence. Our choices, and the way we handle transactions with others, reflect more of our true selves as a result.

Behind us is the horizon reflecting our relationship with power. We call this hierarchical (power) trust. Moving towards this horizon we find ourselves doing things because we’re told doing so is in our best interest. The more we succumb to power the more constrained our freedom of choice becomes. Choices we make and the way we deal with other people reflect this.

To our left is the horizon reflecting how we feel about our sense of duty. The higher this sense then the fewer choices we find ourselves with. We call this commodity trust. In a perfect world we would be encouraged to look for answers to questions or solutions to problems anywhere and everywhere. In a world dominated by commodity trust decision-making is highly formalized. Only answers and solutions from this formalized set are permissible. This again is reflected in the way we do things and, by extension, into our relationships.

To our right, the final horizon reflects our needs to belong to a group. We call this need network trust. The greater our need for the security the group gives us then the more we derive our values from the group. The less our need for security the more our needs reflect our own thoughts. And we treat people accordingly.

In any given instance in our lives this is what the world looks like: our thoughts are being thought for us by those in power, by the groups we belong to, by our sense of duty and by our perceptions of what is expected of us and only rarely by our authentic selves. The way we conduct relationships and the way we undertake transactions with others reflect these thoughts. The rule – mentioned above – is that, when it comes to dealing with people in day-to-day relationships, there’s a better place forward and to the right of where we currently find ourselves in the trust space.

Monday, September 12, 2005

Technical Security and Context

There is a kind of security that can be provided by technology alone, but it is a very limited kind of security. Real security involves people and organizations as well as technical devices and technological services. So how do we evaluate technologically based statements about security?

Labelling a technology or protocol as "secure" can be meaningless or dangerously misleading. Technologies and protocols can only be secure for some purpose in some context. And we typically have to compose a number of complementary security mechanisms (social as well as technical) to arrive at anything remotely resembling a secure system / solution.

Several vendors are currently talking about RSS Security and/or Secure RSS, including Andrew Nash (Reactivity), Mark O'Neill (Vordel) and Greg Reinacker (NewsGator). These vendors are among those flogging a range of security mechanisms that are available for RSS-enabled business solutions - including authentication, authorization and encryption.

These mechanisms have no business value until they are composed with other complementary mechanisms to produce a specific business solution in a specific business context. So the important question is not whether RSS is secure or not, but how secure a particular composition is, in a given context.

Security analysis then shifts from Performance Risk (a component service not working as specified) towards Composition Risk (the component services not working together as a whole as intended) and Implementation Risk (the solution not working in its context-of-use).

So who benefits from standardized compositions? Does it help the attackers to possess details of the composition (a Marauder's Map)? Does it help the defenders to publish/share details of the composition? Do standards create a false sense of security ("lots of clever people have looked at this, so I don't need to bother")? Questions like these are well-known in the security domain.

So we appear to have three routes to a secure solution (for RSS-enabled or anything else), corresponding to three of the four types of trust.

Commodity
Trust
Adopt an off-the-shelf package of security mechanisms offered by the vendors.
Suitable for low/medium security requirements
Quick and cheap?
Authentic
Trust
Develop a specific security solution for this particular requirement. Suitable for high security requirements
Expensive & slow?
Network
Trust
Adopt industry standard or "Open Source" composition.
??
??

Technorati Tags:

Thursday, March 31, 2005

Trusting Commons

Can we trust Wikipedia? Does Wikipedia give us the truth? James Governor applies the Invisible Hand argument to this question. He points out that there are perhaps just as many errors in traditional encyclopaedias, and mentions both Grove and the Encyclopaedia Britannica.

In our writings, we identify four types of trust. The Encyclopaedia Britannica pretends to offer a form of trust based on authority, but it is in fact a commercial product and relies ultimately on commodity trust. In contrast, Wikipedia offers a form of trust based on the network. Is that good enough?

Instead of asking the binary question: can we trust, yes or no. The key is to ask the discriminating question: for what kinds of question does Wikipedia offer good/better/best answers? Clearly if you want uptodate information about an important but relatively nonpolitical event (such as the Tsunami). the Wikipedia is a pretty good resource. But if you want impartial information about a controversial topic, you may need to exercise caution.

The question of trust/truth in relation to Wikipedia is similar to the question of trust/truth in relation to Google. Can we trust Google? What I'm asking here is not a question about the commercial ethics of the company, but about the use of any Internet search engine as a method of obtaining a true and fair picture of a given topic.

A Google enquiry suffers from some of the same problems as a Wikipedia enquiry. If there is a consensus, you will get the majority view. If there is no consensus, you will get a confused view. You often find the same stupid ideas and ill-informed opinions replicating from one website to another. If there is a coherent minority view, you may never find it. And if you want an original view, you may need to disconnect from the Internet and do some real thinking or discussion instead.

More on Google

Monday, July 26, 2004

Four Types of Trust

This post is partially based on the book Trust and Mistrust by Aidan and John, who are occasional contributors to this blog.


Trust is a property of a system or relationship based on expectations of reasonable and fair behaviour. Trust and mistrust are commonly regarded as complementary opposites.


Trust

  • Trust is commonly regarded as a positive good - the lubricant of business relationships. Like oil, it is slippery and difficult to grasp. 
  • We define trust as a property of a system or relationship based on expectations of reasonable and fair behaviour. In some situations, trust is regarded as simply the absence of mistrust. 
  • We generally trust people and situations, unless we have some specific reason to distrust them. However, this may sometimes be insufficient basis for positive trust.

Mistrust

  • There is a clear difference between a simple absence of trust, and positive mistrust. Mistrust is supposedly a consequence of past actions. In fact, it is often a consequence of a complex set of beliefs, perceptions, associations and interpretations. 
  • Mistrust is usually more difficult to deal with than simple absence of trust. How do I deal with other people's mistrust of me, whether this is fairly deserved or not? Do I tackle false beliefs head-on, or do I try to dissociate myself from the events that triggered the mistrust, or do I simply switch my identity and reappear under a new guise?

Practical Questions

  • How can we assess the level of trust in a given situation?
  • How can we increase the level of trust? 
  • How should we deal with people, companies and situations we mistrust? 
  • How can we respond to the declared or inferred mistrust of others? 

Four types of trust (and mistrust)

Centralized
  • Authority (Top Down) Trust - Trust is guaranteed by reference to some authority, and is typically configured hierarchically. This mode of trust is found in a range of centralized identity management (authorization/authentication) including Passport, Verisign and Identrus. 
  • Commodity (Contract) Trust - Trust is supplied as a product or service. It carries a price and expected service levels.  
Decentralized
  • Network (Web) Trust - Trust is conferred by the collective action of a distributed network. The internet is trusted to do certain things because there is no single point of failure. Competitive markets are trusted to set fair prices.
  • Relationship (Authentic) Trust - Trust is inherent in an authentic and committed engagement with business partners. 

Police force example

A police force is an organization that generally requires high levels of trust. All four types of trust are relevant to a police force.

  • Authority (Top Down) Trust - For many citizens, the police force both symbolizes and realises a form of social authority. This authority is reinforced by police procedure, and by wearing the uniform. Members of certain communities or subcultures sometimes have a hostile attitude to this authority. Defence lawyers may attack police procedure in order to undermine trust in police evidence. 
  • Commodity (Contract) Trust - Trust in the quality of service provided by the police. Service targets - crime rates, crime clear-up rates, speed of response. These are primary political concerns.  
  • Network (Web) Trust - The police do not operate in isolation but in collaboration with other bodies such as social services, health, education and the judiciary, as well as community groups. Trust in the police force depends on complex institutional and often semi-formal arrangements with these bodies, and may be affected by problems elsewhere in this network. 
  • Relationship (Authentic) Trust - Trust created by personal relationships between individual police officers and the community.



Aidan Ward and John Smith, Trust and Mistrust (Wiley 2003)


Originally posted at http://www.users.globalnet.co.uk/~rxv/trust/index.htm