Showing posts with label Hogwarts. Show all posts
Showing posts with label Hogwarts. Show all posts

Tuesday, April 17, 2012

Two Dimensions of Trust

In my post Magic Quadrant or Sorting Hat, I compared Gartner's Magic Quadrant (used to classify software vendors and products) with the Hogwarts Sorting Hat (used to classify young witches and wizards).
  • Leaders: Gryffindor
  • Challengers: Slytherin
  • Visionaries: Ravenclaw
  • Niche Players: Hufflepuff
Gartner's Magic Quadrant is a 2x2 matrix, whose two dimensions are Vision and Ability-to-Execute.

Following my previous post on Sharing Trust, I was thinking about a contrast between two key Hogwarts characters - Hagrid and Snape - based on the two dimensions of Trustworthiness and Ability-to-Execute.

Hagrid is regarded as extremely trustworthy. In the very first chapter of the first Harry Potter book, Dumbledore says he would trust Hagrid with his life. Professor McGonagall agrees, but points out that Hagrid can be a little unreliable. Later in the book, he is tricked by Voldemort into revealing a key vulnerability in the security arrangements protecting the Philosopher's Stone - security experts would call this "social engineering". So he doesn't score so well on ability-to-execute.

Snape, on the other hand, is a very accomplished and creative wizard, who scores extremely high on ability-to-execute. As we progress through the series, it becomes clear that he is successfully deceiving either Dumbledore or Voldemort - or possibly both. But this of course raises serious questions about his trustworthiness.

Trustworthiness - but for whom? Dumbledore trusts both Hagrid and Snape absolutely; other characters trust them with reservations, and only because Dumbledore does. And J.K. Rowling is careful not to present Dumbledore as omniscient - he is hoodwinked on several occasions, most notably by a clever impersonation in the Goblet of Fire.

So there are two ways of trusting people. We can regard them as trustworthy but fallible. Like Hagrid, or for that matter Dumbledore himself. Or we can regard them as reliable but remain suspicious of their true motivation and allegiance. Like Snape, or for that matter Voldemort. Ultimately, this is a question of authenticity.

Saturday, December 26, 2009

Magical Problem-Remover

"Even if you don't believe in magic" tweets @j4ngis, "Would it not be great if magic could remove ALL problems?"


I can see that this is a seductive fantasy. But we only have to open the pages of Harry Potter to see some of the reasons why this fantasy won't work. J.K. Rowling repeatedly emphasizes three important points about the power of magic.

1. Magical solutions to common problems are often incredibly clumsy and ineffective when compared to their muggle equivalents. When people in the magical world wish to communicate with one another, they are forced to resort to owls, fairy dust, magic mirrors and other devices, instead of just picking up the phone or sending a tweet.

2. Many of the problems faced by people in the magical world are caused by previous acts of magic. So maybe they would be better off with no magic at all.

3. And muggles are better off not knowing that magic is possible, because they will be tempted to seek magical solutions instead of taking responsibility for their own lives.


Am I really interested in magic? No, but I'm interested in technology, which sometimes seems to be almost the same thing. JK Rowling's magical world is a satirical reflection of our own, with stupid governments, narrow-minded people, and technology that doesn't work properly or has unintended side-effects - what Mary Catherine Bateson calls The Revenge of the Good Fairy.

And my final reason why magic cannot remove all problems is that magic is compelled to follow what I call Fairy-Tale Logic - a rigorous logic that produces an inevitable outcome. Which leaves no room for the kind of authentic and creative solution that I am sure @j4ngis believes in as much as I do.

Thursday, May 14, 2009

Fairy Tale Logic

Peter Evans-Greenwood makes some interesting points in response to my post on Three Wishes, but I don't agree with his interpretation of fairy tale logic as incomplete and inconsistent. As I see it, fairy tales follow a rigorous logic that produces an inevitable outcome. (From Freud to Lacan and Matte Blanco, psychoanalysts have explored the strange but inevitable logic of dreams and the unconscious.)

It is this logic that makes fairy tales so powerful, not merely as entertainment but as rich sources of metaphor. See Magic Fairy Tales as Source for Interface Metaphors

Magic follows strict rules. J.K. Rowling put a great deal of effort into creating an internally consistent magical world for Harry Potter and his friends to inhabit; although some minor logical anomalies do appear, these are trivial compared to the main elements of magic upon which the plot relies. And within the context of the Rapunzel story, climbing hair is consistent and makes perfect sense.

Now here's the relevance of this for consultants working with organizations. When we look at families or organizations from the outside we may say "that behaviour doesn't make sense", but for the people inside the family or organization the behaviour seems perfectly logical or inevitable or both.

In order to intervene usefully into such situations, the therapist or consultant needs to be in touch both with the external logic (this doesn't make sense) and with the internal logic (this is inevitable, this is how we do things).

(I read somewhere that in post-war Britain, American management consultants had some advantage over British management consultants. At that time, one of the biggest perceived issues was something called "Industrial Relations" - in other words, conflict and distrust between management and labour. Whereas British consultants were constrained by their perceived background, American consultants were outside the British class system, could pretend to know nothing about the role of the trade union in British politics, and could ask dumb but necessary questions.)

Dysfunctional organizations may sometimes be logically incomplete or inconsistent. But more often they are obsessively complete and consistent. (J.K. Rowling paints a disturbingly plausible satire of government in the Ministry of Magic - see Harry Potter and the Half-Crazed Bureaucracy). We can learn a lot from the structure of magic.

Thursday, May 25, 2006

Identity Differentiation

Kim Cameron asks
"if there is some blood alcohol level after which informed consent no longer applies?"
According to an informal view of identity, there is some blood alcohol level at which you are no longer the same person. Can a sober person repudiate the past or future actions of his drunk alterego? Or vice versa?

I thought this would be a good opportunity to republish some of my earlier notes on Security and Identity and Signatures.
It is not unusual for decisions of trust to make a distinction between different identities of the same person. Let's say I have a friend called John. JOHN-SOBER and JOHN-DRUNK are two different identities, with recognizably different patterns of behaviour and risk. I am happy to lend my car keys to JOHN-SOBER, but not to JOHN-DRUNK.

If a person has a gun to his head, or his children are held hostage, his behaviour is likely to be uncharacteristic. ("You are not yourself today.") Signatures and voice patterns change under stressful conditions, including duress and torture. If this uncharacteristic behaviour is detected at a security checkpoint, then it might be appropriate to hinder a person's entry, until the identity difference is resolved.

This is about a difference in identity, not just a difference in behaviour. I am not refusing John my car keys because of his slurred speech; I am refusing them because he is drunk It may be his slurred speech that alerts me to the fact that he is drunk; but if he convinces me that his slurred speech on this occasion is a result of a visit to the dentist, I may let him have the car keys. Conversely, if he learns to speak normally even when drunk, I shall just have to find a different way to determine when he is drunk and when sober.

After his attempt to blow up the Houses of Parliament, Guy Fawkes was taken to the Tower of London and tortured to extract a confession. His signature - an important token of identity - degenerated under torture, and on his confession it is barely legible. There are serious questions about the validity and authenticity of confessions extracted under torture. The Guy Fawkes example indicates that the identity of the person signing the confession may be brutally transformed by torture, or perhaps even destroyed. We also know that identity and character may be tranformed by brainwashing - which we may sometimes regard as just another more subtle form of violence. In other contexts, identity may be altered by advertising or other modes of influence.

And can Hogwarts parents trust Professor Lupin with the care of their children? Not when there's a full moon. Remus Lupin has two identities - man and werwolf. As man, he is an excellent teacher. As werwolf he is a danger to himself and others. However, the werwolf identity manifests itself only at the full moon; at other times Lupin is perfectly safe. [Hogwarts Security]
Can "user-centric" identity deal with these cases? How does "user-centric" identity deal with context-dependent identity?

Thursday, September 8, 2005

Hogwarts Security 2

In my previous post, I suggested that the ineffectual security mechanisms in the Harry Potter books could be read as part of J.K. Rowling's ongoing satire against technology. The books also include a good dose of political satire, regularly presenting the Minister for Magic and his aides in a poor light.

In the Prisoner of Azkaban, Hermione possesses a Time Turner, which allows her to be in two places at once. She and Harry use this device to frustrate the plans of the Ministry of Magic, while retaining a cast-iron alibi. And yet Hermione's possession of the Time Turner had previously been authorized by the Ministry of Magic - presumably by a separate department. Clearly the wizarding world has failed to embrace Joined-Up-Government.

All through the Half-Blood Prince, wizards mock the stupid authentication mechanisms invented by the Ministry of Magic.

"You have not asked me, for instance, what is my favourite flavor of jam, to check that I am indeed Professor Dumbledore and not an imposter, ... although of course, if I were a Death Eater, I would have been sure to research my own jam preferences before impersonating myself."

"I still don't understand why we have to go through that every time you come home. ... I mean, a Death Eater might have forced the answer out of you before impersonating you." "I know, dear, but it's Ministry procedure and I have to set an example."

In my view, Rowling has perfectly captured the kind of bureaucratic panic that causes Government Departments to disseminate such half-baked security schemes.

Into The Machine (updated now with a sensible title and a new URL) is an excellent blog documenting the serial follies of the British Home Office. And here is a great video of the British Home Secretary, singing the benefits of the UK Identity Card scheme. [updated to add] ... and I've just discovered this sequel thanks to Robin Wilton.

Tuesday, September 6, 2005

Hogwarts Security

The Harry Potter books by J.K. Rowling provide some excellent illustrations of some important issues in relation to Identity, Trust and Security. Here are some of the issues I had identified from the first four books.
A recent discussion on Bruce Schneier's blog (September 2005) has identified a number of further issues arising from books 5 and 6.
  • The danger of trusting your friends since they may be covertly controlled by your enemies (the Imperius curse)
  • The vulnerability of certain defences against coordinated attack by several (possibly weaker) opponents. This is already indicated in Book 4, in which Mad-Eye Moody, the most security-conscious wizard in the entire series, is overpowered by Barty Crouch and Wormtail.
  • Brent Dax suggests that the Fidelius Charm is a version of DRM.
Elsewhere, I have used the concept of Marauder's Map to describe the network models constructed by hostile attackers.

The Harry Potter books can be read as a satire on technology. From this perspective, the following criticisms of J.K. Rowling are grossly unfair.
  • Should Rowling be sued for teaching poor security systems to the children!?
  • Logic and consistency are not Ms Rowling's strong point.
But Rowling is describing an imaginary world in which there are many security vulnerabilities. (Some of these vulnerabilities have not been exploited yet, but there is another book to come.) Surely this is better than teaching children that magic (or for that matter technology) can provide perfect security.

[updated to add]
As Laurabelle writes in her blog, "Sometimes magic just isn’t the best tool for the job."

Friday, September 2, 2005

Wash Out

"The Moving Finger writes: and, having writ,
Moves on: nor all thy Piety nor Wit
Shall lure it back to cancel half a Line,
Nor all thy Tears wash out a Word of it."

In June 2004, the private firm Innovative Emergency Management Inc won a large contract from the US Department of Homeland Security to develop an emergency hurricane plan for New Orleans. IEM produced a press release, which was posted on its website.

In August 2005, Hurricane Katrina devastated New Orleans. A curious side-effect of this devastation was that the press release seems to have disappeared from IEM's website. Unfortunately for IEM, a politically motivated blog called Lenin's Tomb captured (and has now published) the before-and-after, which can also be found on other internet archives.

Difficult to delete or hide stuff on the Internet, isn't it?

You have to be smarter than that to erase a memory, as Professor Slughorn found in one of the Harry Potter novels. Internet archives are unforgiving and implacable (when you want to forget something), although they can also be hopelessly muddled (when you want to find something). But I still think it's a bit rich for Leninists (of all people) to complain about a bit of innocent and clumsy airbrushing.


Tuesday, April 17, 2001

Networks of Trust - Who Betrayed Harry Potter's Parents?

The best-selling children’s novel, Harry Potter and the Prisoner of Azkaban, illustrates several important points about trust.

Harry’s parents are hiding from the Dark Lord ("He Who Must Not Be Named"). James Potter can nominate one friend to guard the secret of his whereabouts, and chooses his strongest and apparently most trustworthy friend – Sirius Black. But for Sirius, being the obvious choice makes him immediately vulnerable to attack: in systems engineering terms, he is a single point of failure. He decides that the Potters’ secret would be better guarded by a less obvious person, and delegates the responsibility to a weaker wizard – Peter Pettigrew – who immediately betrays the Potters.

This is an example of transitive betrayal. It illustrates the following points:
  • The strongest component is the most obvious place to attack – and this makes it vulnerable. A powerful adversary trying to break the system, or to breach its security, may well think it worth investing effort into finding how to break the strongest component. (The system is as weak as its strongest link.)
  • This leads to the Decoy pattern. A highly visible component draws fire, but isn’t really worth attacking. This is like sending an armoured truck out of the front gate containing the sandwiches, while the gold bullion slips quietly out of the back gate in an unmarked, unarmed van. (The system is stronger than its strongest visible link.)
  • However, the Decoy pattern is worthless once the illusion is broken. Strength that depends on secrecy is always vulnerable to leakage. A linear (one-to-one) delegation chain is as strong as its weakest link.
  • To delegate responsibility to weaker components, we need to use the Distributed Delegation pattern – where the system now relies on the concerted strength of all the components working together, rather than being vulnerable to the weakness of each. Parallel (one-to-many) delegation is much stronger than linear delegation.
  • Trust is transitive – whether you like it or not. If you trust a component or service from company X, and this depends on a component or service from company Y, then you are implicitly trusting company Y as well, although you may not even know that company Y exists.


Extract from an article published in the CBDI Journal, April 2001.