Re: Defining Trust and Reputation

Ed Gerck <[email protected]> Mon, 29 Mar 2004 16:42:07 -0800
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
Yakov Shafranovich wrote:
> 
> Ed Gerck wrote:
> > To begin:
> >
> > Define all the input information streams in the proposed
> > protocol/method. Identify what allows the *recipient* to
> > rely on each one -- these are the trusted introducers.
> > Cross-reference the list of trust introducers and inputs.
> > Present for discussion.
> >...
> 
> Sorry for taking so long. Do you Ed want to volunteer some time to work
> on this stuff? 

Yes. This effort is within the scope of my main interest, which I 
loosely describe as the design and development of large-scale, secure 
and reliable infrastructure services where users are not trusted 
ab initio to any extent. In other words, to introduce trust as an 
explicit part of the Internet design, with least changes as possible, 
which trust was implicit when the Internet was based on an honor system. 

In particular, trusting user intervention is increasingly recognized 
as a very weak assumption. Thus, I am especially interested in solutions
that can solve current security and network problems without trusting 
user intervention. The solution being discussed by this group would/should 
fall in this category, I believe.

Cheers,
Ed Gerck