Re: Defining Trust and Reputation

Yakov Shafranovich <[email protected]> Sun, 28 Mar 2004 00:02:11 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
Ed Gerck wrote:

> 
> Yakov Shafranovich wrote:
> 
>>Ed Gerck wrote:
>>
>>>We can start with a simplied model -- trust no one. And refine as
>>>we go -- for example: yes, we can trust the information if a number
>>>X of MTAs in different networks (defining 'different' is a challenge
>>>by itself) agrees with a margin of Y.
>>>
>>>...
>>>Having incompatible trust models would be... incompatible. Your suggestion
>>>can work well though, and I go back to my example above, if we parametrize
>>>the trust model and let different users pick their own parameters
>>>(for example, X, Y and 'different' above). The model is the same, the
>>>instantiation is different.
>>>
>>
>>So practically speaking - how would we proceed with this?
> 
> 
> To begin:
> 
> Define all the input information streams in the proposed
> protocol/method. Identify what allows the *recipient* to 
> rely on each one -- these are the trusted introducers. 
> Cross-reference the list of trust introducers and inputs. 
> Present for discussion.
> 
> Then, we need to work on things such as the list of trusted 
> witnesses, the parametrized trust model starting from "trust
> no one" and the parametrized risk model. We need to choose 
> a risk model too. 
> 

Sorry for taking so long. Do you Ed want to volunteer some time to work 
on this stuff? Does anyone else in the subgroup want to work on this as 
well?

Yakov