Showing posts with label trustandsecurity. Show all posts
Showing posts with label trustandsecurity. Show all posts

Tuesday, April 17, 2012

Two Dimensions of Trust

In my post Magic Quadrant or Sorting Hat, I compared Gartner's Magic Quadrant (used to classify software vendors and products) with the Hogwarts Sorting Hat (used to classify young witches and wizards).
  • Leaders: Gryffindor
  • Challengers: Slytherin
  • Visionaries: Ravenclaw
  • Niche Players: Hufflepuff
Gartner's Magic Quadrant is a 2x2 matrix, whose two dimensions are Vision and Ability-to-Execute.

Following my previous post on Sharing Trust, I was thinking about a contrast between two key Hogwarts characters - Hagrid and Snape - based on the two dimensions of Trustworthiness and Ability-to-Execute.

Hagrid is regarded as extremely trustworthy. In the very first chapter of the first Harry Potter book, Dumbledore says he would trust Hagrid with his life. Professor McGonagall agrees, but points out that Hagrid can be a little unreliable. Later in the book, he is tricked by Voldemort into revealing a key vulnerability in the security arrangements protecting the Philosopher's Stone - security experts would call this "social engineering". So he doesn't score so well on ability-to-execute.

Snape, on the other hand, is a very accomplished and creative wizard, who scores extremely high on ability-to-execute. As we progress through the series, it becomes clear that he is successfully deceiving either Dumbledore or Voldemort - or possibly both. But this of course raises serious questions about his trustworthiness.

Trustworthiness - but for whom? Dumbledore trusts both Hagrid and Snape absolutely; other characters trust them with reservations, and only because Dumbledore does. And J.K. Rowling is careful not to present Dumbledore as omniscient - he is hoodwinked on several occasions, most notably by a clever impersonation in the Goblet of Fire.

So there are two ways of trusting people. We can regard them as trustworthy but fallible. Like Hagrid, or for that matter Dumbledore himself. Or we can regard them as reliable but remain suspicious of their true motivation and allegiance. Like Snape, or for that matter Voldemort. Ultimately, this is a question of authenticity.

Friday, December 19, 2008

Risk and Policy in the Real World

Chandler Howell describes an interesting example of Risk and Policy in the Real World.

I have an interesting example of Policy actually making things worse for you all today. It’s not horrible, but it illustrates the point and I can talk about it, so I will.

Today someone asked me if I knew that one of the floors of a facility I visit from time to time is a “No Visitors” area. This is due to the fact that the marketing teams have product prototypes as well as all of their collateral and other materials displayed or in-progress on this floor. I had to confess that I did not realize that. Even worse, most of the people who don’t reside in the “No Visitors” zone, as well as some who do, also don’t seem to be aware of that fact.

Enforcement is, as you would imagine, non-existent. That would be rude, after all.

To make matters worse, not only is there is no access control (doors or guards), signage or other markings telling people that this floor is off-limits to visitors, but the canteen which is open longer hours than the main cafeteria (for coffee, snacks, etc.) is located on this floor. As a result, there’s a steady stream of people who, even if they are employees, really have no business wandering around this floor doing so at any given time.

So we have a situation where the people who need to display confidential information do so, safe behind the warm fuzzy blanket of their “No Visitors” policy. Everyone else wanders around their area in blissful ignorance that they shouldn’t bring their visitors through there on the way to the canteen.



My reading of this example is that Policy is being used as an ineffective patch for a failure of Architecture. In other words, there is a de facto physical architecture that involves visitors walking through this department, and an unenforced (and possibly unenforceable) policy saying they shouldn't.

If you want to protect the department, you probably need to change the physical architecture. Provide an alternative route to the canteen, and install enough barriers (like sleeping policemen) to discourage people taking short-cuts through the department. Or you move the marketing department to a different floor.

You still have the policy, but now the policy is used as a architectural design constraint rather than expecting the mere existence of a rule to alter people's behaviour.

Alternatively, you try to change the behaviour of the marketing department. After all, there are fewer of them. And they are the ones to whom it matters.

Wednesday, September 24, 2008

US Election 2008 - Trust

Can the candidates in the US election trust their running mates?

Tuesday, September 23, 2008

US Election 2008 - Sincerity versus Authenticity

(Where is my copy of Lionel Trilling's book? I thought I had one somewhere. Did I lend it to someone? Oh well, never mind, it'll turn up.)

I was just reading David Foster Wallace's account (in a book called "Consider the Lobster") of John McCain's 2000 campaign for the Republican nomination (against an opponent then referred to as "The Shrub"). Wallace (then writing for Rolling Stone) was far from being a supporter of McCain, but he was impressed by his personal qualities. It's difficult not to be impressed by McCain's biography - whether as a fantastic example of courage and fortitude or as a brilliant example of personal myth, or perhaps both.

So here's a thought. In the upcoming presidential election, Obama represents Sincerity while McCain represents Authenticity. Different kinds of truth.

A minority of voters might vote for McCain and Palin because they share their opinions and beliefs, but most Americans don't. The only reason McCain and Palin have the remotest chance of winning the election is because sackloads of American votes will be cast for who the candidates are, not for what they stand for. Megan Garber (Columbia Journalism Review) calls this the Authenticity Trap - " the West Wing logic of governance: that truth-to-self will somehow lead a president to effective leadership".

In contrast, people will mostly not vote for Obama because of who he is - a smooth Afro-American lawyer from Chicago with a foreign name - but because of what he (so eloquently) stands for. Adam Kirsch (New York Sun) finds Obama's book more authentic than Hillary Clinton's - but come on, how many American votes are going to be based on reading? (People didn't vote for Churchill because they'd read his books either.)

Perhaps more than any election in recent memory, this is the battle of the Enlightenment. The man who speaks from the heart for progress, hope and the American Dream against the man who was captured by the VietCong and will not tell a lie. George Lakoff (Huffington Post) thinks the Enlightenment frame isn't working so well for Obama these days, and wants the Obama campaign to stop reinforcing the Maverick frame for McCain.

Steven Shaviro has a rather different take on this. In More Electoral Ruminations, he contrasts Democrat hypocrisy with Republican cynicism, and avers that "It is not stupid to vote for McCain/Palin; rather, it is evil. Republicans are intrinsically, and necessarily, morally depraved."

Some of Shaviro's readers were shocked by this abrupt jump from the political discourse to the moral/ethical, so he tried to justify his position with a Note on Evil, claiming that Obama is the true follower of Kant, and resurfacing his argument (originally posted in 2004 - Nothing) that Kant's concept of radical evil applied exclusively to the Republicans.

For a much more coherent and compelling argument about the relationship between hypocrisy and cynicism, see David Runciman's new book on Political Hypocrisy. Runciman also finds for Obama, whom he compares with Lincoln, and quotes approvingly Obama's view that "It is only the politician who is able to speak his mind freely who knows when to compromise".



For a systems thinking view of the US election, see the POSIWID blog.

Monday, August 4, 2008

Peer Review in the Dock

Tonight's Science programme on BBC Radio 4 was critical of the peer review process, in which scientific articles are filtered for publication according to the comments of other researchers in the same field. [Peer Review in the Dock, 4 August 2008]

The purpose of peer review is to give us confidence in the quality of published scientific research. Like many other social institutions, it has well-known weaknesses as well as strengths. [BBC News, Science will stick with peer review]

I have often been asked to provide peer reviews on articles for journals and conferences. Sometimes I find I know much more about the subject of the article than the authors, or at least some aspects of the subject. Even when my knowledge is less, I can usually find some areas of weakness or confusion in the article, demanding (in my opinion) either a significant re-write or complete rejection.

Having gone to the trouble to provide these reviews, I used to be shocked when I discovered that papers sometimes slipped through to publication without the identified flaws being adequately corrected. Experienced authors (or their supervisors) know how to game the system, and most journals and conferences simply don't have the resources to prevent these games. Some years ago I wrote a critique of this process and identified a number of negative patterns.

The BBC programme this evening identified several more, including the famous institution bias and the publication bias. The latter is particularly important for research that involves sophisticated statistics (such as medical research), because if only publishable data are included in the analysis, then the publication criteria may themselves distort the findings. The publication bias also affects the opinions of so-called experts, whose assumptions will have been reinforced by the papers they have read.


Related post: Trahison des Clercs - AntiPatterns of Peer Review (July 2004)

Update - Further links

Liam Kofi Bright and Remco Heesen, The Perfect Time to Reform Peer Review (BSPS 2022)

Remco Heesen and Liam Kofi Bright, Is Peer Review a Good Idea? (British Journal for the Philosophy of Science 2021) 

Saturday, July 12, 2008

The Future of Cash

Adam Shostack posts on The Recent History of the Future of Cash. He points out that the choice between cash and electronic payment systems is influenced by questions of trust. In some countries with high inflation, people don't trust cash. But people also don't trust complex and unreliable electronic systems.

Lack of trust increases transaction costs. If I am constantly on guard because of unexpected charges on my account - whether this is due to error or fraud, or simply because the service provider is pocketing a fee for something - then I may have to maintain transaction archives, or copy every transaction into a separate spreadsheet or database. Adam links to a post by Gary Leff, who prints out everything he can think of because he is expecting to be cheated out of some complicated deal on frequent flier miles. This kind of thing is symptomatic of the shallow and short-sighted version of the Support Economy.

Meanwhile, when I buy a book from my local bookshop, the shop accepts cash or debit cards. But if I use a card, the bank will take a cut of the transaction (from the shop). So I prefer to pay cash if I can: cash doesn't really cost me any more than card, but I prefer the shop to get all the money.

Some people feel safer just carrying a card, because cash can be lost or stolen. But which is the greater risk - being mugged by a drug addict in the street, or being ripped off by a major corporation? Different people balance those risks differently.

Friday, June 20, 2008

Plausible Denial

In the annual Underhanded C Contest, programmers compete to construct code that looks innocent but does undocumented and devious things. One of the judging criteria is plausible deniability - which in this case means the ability to claim the error as a genuine mistake rather than a cunning trick. (Via Bruce Schneier)

In delegating stuff from an agent to a principal, plausible deniability can operate in either direction. Many well-known examples, both in real-life and in fiction, involve the principal denying knowledge or responsibility of the actions of the agent. For example, governments sometimes keeping the dirty details of espionage at arms length. Or well-known companies sometimes being strategically ignorant of the exploitation of child labour in their suppliers' factories, or turning a blind eye to short-cuts and risks taken by subcontractors.

But the programming example works in the other direction. It involves the agent (in this case a programmer) craftily subverting the intentions of the principal (the user of the program), while remaining "innocent" if the trick is detected. There are many situations in delegation and procurement where a dishonest agent or supplier can abuse trust with impunity. Even if the trick is detected, it can be passed off as human error, and probably forgiven and forgotten after a sufficiently charming apology and repair.

Tuesday, November 27, 2007

Shakespeare on Identity Theft

On the Loss of Two CDs by Her Majesty's Revenue and Customs containing the Records of 25 Million Taxpayers and their Children.

Shall I compare thee to a string of digits?
Thou art more personal and more private.
Rough Humphreys doth quiz the Darling on Today,
And Gordon's lease hath all too short a date.
Sometime too close the eye of Google shines,
And oft is gold from banking accounts skimmed;
And every mother’s maiden name declines,
By chance, or nature's changing course untrimmed.
But thy perfect database shall not leak
Nor lose possession of that CD they sent;
Nor shall the hacker spam and phish and phreak,
When with eternal ID card thou went,
So long as cars have chips and streets have CCTV,
So long lives your identity, and this gives life to thee.


Sources: BBC News, The Register, Robin Wilton, Into the Machine.

Sunday, July 30, 2006

Security Trends

Sean of F-Secure avers "that the lack of large virus outbreaks is evidence that the malware environment could be getting worse, not better". [Exploit Wednesday, via Emergent Chaos]

F-Secure does seem to have some evidence for the growing sophistication of malware attacks, and a plausible explanation for the fact that these attacks are less visible. But explanation is not evidence.

Point One. Even if visible attacks are decreasing, this doesn't provide conclusive evidence that invisible attacks are decreasing.

Point Two. The lack of evidence that invisible attacks are decreasing does not imply any evidence that invisible attacks are increasing.

But that's not quite what F-Secure says. F-Secure avers that the reduction in visible attacks provides evidence that invisible attacks could be increasing.

But this is rubbish. We don't need evidence for the possibility of increased attack; it's not something that requires evidence. What we want to know, which F-Secure avoids telling us, is some measure of what is going on. And F-Secure is not offering us any evidence that is relevant to this question.

This illustrates a general problem with evidence-based policy in risk and security matters. When preventative action is effective, it is often difficult to demonstrate its necessity. So security experts and vendors feel themselves obliged to talk up the (sometimes counterfactual) possibility of attack, without always being able or willing to present concrete evidence of the incidence of attack.

Technorati Tags:

Tuesday, July 11, 2006

Double Bluff 2

Barry Briggs worries that the bad guys might get to scan our data, thanks to Passport RFID.

"Achieving international cooperation for RFID encryption would probably never work anyway, and of course there are those nations that would be fine letting the algorithms/decoding chips into the wrong hands."


Now, which nations would those be? In my post Double Bluff (Oct 2005), I commented on the claim that the British security forces deliberately leaked some technologies to the IRA, playing a devious game they thought they could control. These technologies later led to the death of British soldiers in Iraq.

It seems we can't even trust our own side to look after our own security, or to think through the consequences of their actions.


Updated 4 April 2014

Wednesday, July 5, 2006

Collective Bargaining

Collective bargaining used to refer mainly to wage negotiations in which the workforce negotiated collectively rather than individually - typically delegated to special representatives such as trade union officials.

Collective bargaining has always involved a pattern of collective mutual trust known as solidarity, often enforced by formal discipline or social pressure.

A new form of collective bargaining is emerging in China, known as team buying or tuangou, where gangs of customers arrive at a shop and demand high discounts. [source: Economist via Confused of Calcutta]

I wonder how these gangs enforce solidarity? Suppose the gang leader demands a 20% discount, and the shop offers a 10% discount. What if some of the shoppers are happy to accept this? Is there a collective decision process? If a few shoppers accept the deal that the majority has rejected, would this be regarded as a breach of trust?

Technorati Tags:

Protection and Resistance

Adam Shostack notes that business tactics can sometimes be compared to the mafia.
  • Identity Theft Protection (Eric Rescorla). "That's a great credit rating you've got there ... shame if anything happened to it" (Adam).
And legitimate business services can be used by the mafia.
  • Mexican kidnappers are in league with the insurance companies (Tyler Cowen). Columbian kidnappers pull your credit file from the credit agency to calculate optimum ransom (Alex Tabarrok).
Does this mean that some structural similarity with the mafia should be sufficient to reject some business innovation?
  • Net Neutrality. "FedEx would never suggest intentionally losing your packages. They also would never suggest tearing them open to see if there’s anything good inside. But Verizon and Comcast and a number of other broadband providers are gleefully declaring their intent to drop your traffic, starting with whatever you consider most valuable. This, they call "innovation". (Dan Kaminsky).
Many stakeholders clearly regard arguments against network neutrality, or proposals that undermine network neutrality, as a form of bad faith. For example, telecoms analyst Martin Geddes argues eloquently against network neutrality, tells his readers You Won't Like This, Not One Bit, and is rewarded with the following comment: "There is a special place in jail for people like you".

Of course it's natural to be suspicious of change. Even if the old Internet model was a myth, people may regard any kind of innovation as a breach of trust.

It't not easy to decide which innovations to trust. While superficial similarities to mafia practice make good rhetoric, they may not be the best basis for trust decisions.

Technorati Tags:

Wednesday, June 28, 2006

Naked Feet

Two contrasting stories this week about employees taking stuff away in their shoes.

Chandler makes a useful point about motivation, which probably applies to both examples.
"When assessing security, never assume that people share your priorities or value assessments–if anything, you would probably be better-served to assume they don’t."
And Johannes adds a comment on
"how professionals go about undermining whatever technologies and organizational models we are putting in place".

The security implications of these two cases should not be muddled by value judgements of the two situations. Many people might (exceptionally) approve of stealing from an organization if they disapprove of the organization, or if they think the organization has no ownership rights over the items being taken. But it's still the same physical act.

There is an additional trust issue in the Mitrokhin case. The CIA disbelieved the authenticity and value of the scraps of paper, but MI6 thought it worth protecting him and preserving his material. Why did he steal these documents? Because he had an attitude against his employer? Does this call their accuracy into question?

Meanwhile, the low-denomination coins stolen by Grzeskowiac were of limited value (to him), because they could not be used in such large quantities. Most of the coins were recovered from his mother's garage. Why did he steal them? Because he could.

Technorati Tags:

Monday, June 19, 2006

Cheating 2

[Update] Corrections to this post have been made for legal reasons.

Apparently there are two ways for American students to pay someone else to write their college assignments. The all-American way recommended by an outfit called EssayFraud.org, and the cheap foreign imports allegedly offered by other organizations.

EssayFraud suggests that essay-writers in other countries will not be as knowledgeable or literate as Americans, and may not be as scrupulous in respecting copyright. (Yeah, right.)

Daniel Nexon, on the Duck of Minerva blog, sees this as part of the FightBack Against Outsourcing. Of course, it's still outsourcing if you get a fellow-American to do the essay for you - even your Mom - but the real issue here is apparently off-shore outsourcing ("off-shoring").

Obviously EssayFraud doesn't explicitly encourage students to pass off outsourced essays as their own work. However, it is difficult to see why any students would be willing to pay anyone for "research" unless they were intending to commit some kind of fraud. (Is there a clue in the name of the company?)

And it is perhaps when people are intending to commit untrustworthy acts themselves that they are most vulnerable to being ripped off by others.

[Update] I should have made clear that Essay Fraud is a watchdog organization, which invites membership applications from bona fide American research organizations. Essay Fraud does not itself sell services to American students or have foreign competitors, but it appears to represent the interests of companies that do so. I apologize to Essay Fraud and its members for this misunderstanding, which I hope I have now corrected.

Links: Essay Fraud, Essay Fraud 2.

Thursday, May 25, 2006

Cheating

Alex Halavais has some advice on How to Cheat Good, and there is some further discussion on Bruce Schneier's blog Cheating on Tests.

One of the indicators of poorly executed plagiarism is a discrepancy of style.
  • formatting - for example, text inserted in a different font, size and colour
  • spelling - for example sudden instances of British spelling in an otherwise American text - or vice versa.
  • grammar - correct and complete sentences in an otherwise illiterate text
  • fog - sudden clarity and precision in an otherwise muddy stream of prose
  • logic - contradictory material pasted together with no acknowledgement
In my (thankfully limited) experience of marking student assignments, I have found that the students who commit one type of stylistic error are also prone to the others. And exceptionally weak logic is often enough to generate a very poor mark, even without definite proof of plagiarism.

I did catch two identical submissions last year. Two scripts contained a particularly striking piece of idiocy, which I recognized on reading it for a second time. I had to wade back through the pile of already-marked scripts to find the first one, because they hadn't been quite stupid enough to submit the identical scripts consecutively.

Many of the worst cases of plagiarism are executed so poorly that they reveal the incompetence, ignorance and stupidity of the writer. So perhaps teachers should just fail such students for incompetence and ignorance, instead of trying to convict them of cheating.


Update

At the other extreme, plagiarism can also be detected by an implausible level of sophistication. Andrew Bomford was told about an essay containing a word so erudite that the marker needed to look it up. It turned out that the student didn't know the word either. Fail.

The man who helps students to cheat (BBC Magazine, 12 May 2016)


Updated 13 May 2016

Identity Differentiation

Kim Cameron asks
"if there is some blood alcohol level after which informed consent no longer applies?"
According to an informal view of identity, there is some blood alcohol level at which you are no longer the same person. Can a sober person repudiate the past or future actions of his drunk alterego? Or vice versa?

I thought this would be a good opportunity to republish some of my earlier notes on Security and Identity and Signatures.
It is not unusual for decisions of trust to make a distinction between different identities of the same person. Let's say I have a friend called John. JOHN-SOBER and JOHN-DRUNK are two different identities, with recognizably different patterns of behaviour and risk. I am happy to lend my car keys to JOHN-SOBER, but not to JOHN-DRUNK.

If a person has a gun to his head, or his children are held hostage, his behaviour is likely to be uncharacteristic. ("You are not yourself today.") Signatures and voice patterns change under stressful conditions, including duress and torture. If this uncharacteristic behaviour is detected at a security checkpoint, then it might be appropriate to hinder a person's entry, until the identity difference is resolved.

This is about a difference in identity, not just a difference in behaviour. I am not refusing John my car keys because of his slurred speech; I am refusing them because he is drunk It may be his slurred speech that alerts me to the fact that he is drunk; but if he convinces me that his slurred speech on this occasion is a result of a visit to the dentist, I may let him have the car keys. Conversely, if he learns to speak normally even when drunk, I shall just have to find a different way to determine when he is drunk and when sober.

After his attempt to blow up the Houses of Parliament, Guy Fawkes was taken to the Tower of London and tortured to extract a confession. His signature - an important token of identity - degenerated under torture, and on his confession it is barely legible. There are serious questions about the validity and authenticity of confessions extracted under torture. The Guy Fawkes example indicates that the identity of the person signing the confession may be brutally transformed by torture, or perhaps even destroyed. We also know that identity and character may be tranformed by brainwashing - which we may sometimes regard as just another more subtle form of violence. In other contexts, identity may be altered by advertising or other modes of influence.

And can Hogwarts parents trust Professor Lupin with the care of their children? Not when there's a full moon. Remus Lupin has two identities - man and werwolf. As man, he is an excellent teacher. As werwolf he is a danger to himself and others. However, the werwolf identity manifests itself only at the full moon; at other times Lupin is perfectly safe. [Hogwarts Security]
Can "user-centric" identity deal with these cases? How does "user-centric" identity deal with context-dependent identity?

Thursday, April 13, 2006

Private Morality and Public Morality

Interviewed by Joan Bakewell on BBC Radio Three (April 12, 2006), Dame Mary Warnock conceded that the Committee of Inquiry into embryology, human fertilisation and embryology (which she had chaired) had fudged the issue of posthumous fertilization. She said she had thought it might be arrogant of her to impose her own experience (as a posthumous child) onto the committee, so she had remained silent. Here is Bakewell's response.
[JB] Well no what it is, is of course you're using personal experience

[MW] Yes

[JB] to inform your own moral judgement, which of course is what we want everyone to do.

[MW] Yes

[JB] As long as they are truthful about it.
This is of course the exact opposite of what Warnock has just admitted doing. Bakewell takes the moral high ground here, and proceeds to give Warnock a sharp lesson in practical moral philosophy.

Earlier in the interview, Warnock had appealed to a distinction between private morality and public morality. Bakewell is now attacking (or at least disregarding) this distinction, and Warnock acquiesces.

[Transcript] [Audio]

Technorati Tags:

Tuesday, April 11, 2006

Profiling

Scribe has identified some of The Problems with Profiling. He also contributed a comment to my recent POSIWID post on The True Motive for Identity Cards.

The first problem is that profiling (as currently practised) doesn't work. It produces too many false positives, and too many false negatives.

For example, simple profiling based on a supposed correlation between name and affiliation is going to produce a lot of anomalies.
  • Richard Rees doesn't have an islamic name.
  • Sharif Abdel Gawad (the Greek Armenian Christian recently selected as a BNP candidate) apparently does have an islamic name. [source: Guardian, April 8th, 2006]
And profiling based on a history of contact with known evil-doers doesn't work for new emerging clusters of evil-doers.

But of course, the problem isn't with profiling as such - it is with stupid and unimaginative and counterproductive profiling. Aha, so the solution is to have more extensive and deeper profiling?

But this just produces a deeper problem. For me, the most interesting aspect of Foucault's account of the Panopticon was not the impact on the prisoners, but the impact on the prison warders - and by extension on the society that employs them. And the more so-called intelligence goes into the Machine, the less intelligence is deployed by the real human beings with "intelligence" in their job titles.

Profiling is essentially an anthropological act - and requires all the intellectual caution and self-awareness that Bateson championed - first as an anthropologist, and second as a systems thinker. Steps to an Ecology of Mind should be required reading for policemen and spies. On second thoughts, maybe that's not such a good idea ...

Tuesday, April 4, 2006

Who trusts computers?

When I first heard about the September 11th attacks, I thought someone had managed to hack into the aircraft systems. Turned out I was wrong. Actually, it's a relief to think that the only way to carry out this kind of atrocity is when the attacker is in the plane.

Bruce Schneier has picked up a story about Computer-Controlled Fasteners, which suggests that aircraft can be reconfigured remotely. According to the story, "everything is locked down with codes, and the radio signals are scrambled, so this is fully secured against hackers."

So that's all right then. Assuming we trust the computers. (Remember that attacks may not need real-time connectivity - merely a bit of malware that hides in the system until the opportune moment.)

So the security question is not whether the system is technically secure. There is also a risk that people will panic when a nut with a garage-door opener phones the airline and makes some specific threats. (Frankly, I wouldn't like to have the responsibility of clearing a plane for take off in the face of such threats.) Security experts are always telling us to design security in - but this obviously needs to include social attacks and fear as well as technical threats.

Technorati Tags:

Saturday, March 18, 2006

Network Privacy 2

Following on from my previous post on Network Privacy.

Privacy and data protection are primarily understood in terms of facts about one person. But most of the facts we are really interested in (gossip, political scandal, dastardly deeds and worse) involve more than one person.
This is particularly true if we are rigorous about including provenance. An allegation against person A by person B is a fact about B as well as a fact about A. B's credibility (and any other allegations made by B, as well as links between B and any other people making allegations against A) may be relevant to the veracity of the allegation.

(If someone made an unfounded allegation about me, I should perhaps feel slightly more comfortable if this was stored in some database as an allegation, with a defined provenance, rather than as unvarnished fact or vague probability. And I should want anyone reading the allegation to be automatically presented with my refutation as well. See my post on Google and Spin, which discusses the Prince Charles approach to news management.)

Why are we more interested in facts involving two or more people? One reason is that it is relevant to trust. If a politician has failed to disclose a loan, this may be relevant to his/her public duties. This is where there starts to be a conflict between privacy and public interest.

Where does this leave Prince Charles and his diaries? The relationship between royalty and the newspapers has often been uncomfortable. In 1908, Kaiser Wilhelm II of Germany unwisely gave an interview to the London Daily Telegraph, in which he liberally insulted half the people of Europe. Surely the people (vox populi and all that) have a right to know if the Kaiser is an ass?