Re: Single model or framework for reputation/trust

Jeff_Silverman <[email protected]> Mon, 3 May 2004 13:00:52 -0700 (PDT)
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <Pine.LNX.4.44.0405031257310.25002-100000@angel>
On Mon, 3 May 2004, Alan DeKok wrote:

> Ed Gerck <[email protected]> wrote:
> > Reputation is usually understood as something from the past. It's
> > not about promises.
> 
>   Reputation (or past behavior) is a strong indicator of future
> behavior.  It shouldn't be ignored.
> 
>   e.g. See any book on profiling criminals.  The books lay out exactly
> what the criminals are doing wrong, and describe how to use that
> information to catch them.  Yet despite having this information,
> criminals *can't* change their behavior, because of the exact problems
> that make them criminals.
> 
> > In addition, you are, perhaps, familiar with the example given by 
> > Bertrand Russel, where a farmer would go everyday and walk to a 
> > chicken to give food to it. One day, the farmer walked in the same 
> > way to the chicken and killed it. If reputation applies here, the 
> > farmer should have had a good reputation with the chicken. 
> 
>   Very cute, also carefully misleading.  It's trying to pretend that
> reputation is perfect, when it's not.  It's also pretending that
> positive reputation carries more information than negative reputation,
> when it doesn't.
> 
>   e.g. 90% of the population doesn't commit crimes more serious than
> jaywalking... except for the occasional "surprise".  The positive
> reputation they have is useful, and is a good predictor of future
> non-criminality.
> 
>   The other 10% has a negative reputation, and that reputation IS a
> stronger indicator of future behavior than the positive reputation of
> non-criminals.
> 
>   Alan DeKok.
> 
Alan,

     If reputation is a poor indicator in the "real" world, then is it 
possible to use reputation for any useful purpose in the "cyber" world?

	As I write these words, I am seized with a tremendous feeling of 
despair: that our institutions, policies and procedures are utterly 
inadequate for dealing with the cyber world.  Maybe that's uncalled for or 
naive, but that's how I feel.


Jeff