Re: Single model or framework for reputation/trust
Ed Gerck <[email protected]> Mon, 03 May 2004 17:37:54 -0700
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
Jeff Silverman wrote: > > Ed Gerck wrote: > > >In the cyber-world things get more complicated. There are no > >assets to seize, no liability to measure. Reputation alone will > >not correspond to the models we use in the real-world and will > >not have the recourse mechanisms we need. Think of that farmer and > >chicken example by the noted logician Russel: the reputation > >model fails for the chicken. The trust model would give the > >chicken the right information, though: you can't trust the farmer. > > > >Cheers, > >Ed Gerck > > > Ed, > > How can the chicken know, a priori, that the farmer is not > trustworthy? > > I'm sorry that the question sounds ludicrous. Not at all. The "chicken" represents the average user, who thinks that what he sees today is what he will see tomorrow. If (instead of reputation) the chicken would use the model of trust that I explained before in order to decide what to do, what would have happened? The chicken would have determined that the farmer cannot be trusted. Why not? The chicken would know that the farmer could not be trusted because self-affirmations, even repeated many times, cannot induce trust. All that the chicken could see were the self-affirmations of the farmer. Hence, stay away from the farmer until the farmer leaves. In other words, it doesn't matter how many times Jon tells you "trust me". It still is a self-affirmation and you should not trust Jon just because Jon asks for it many, many times. Jon may even have a good reputation but Jon cannot be trusted. > But please assume for > sake of discussion that the chicken is arbitrarily intelligent, and > presumably is in communication with other chickens, but can only know > what it has observed and the reports of its fellow chickens. How can it > know that the farmer has arrived with evil intent? The first determination by the chicken is that the farmer cannot be trusted (see above). The second determination, as you ask, is whether the farmer is distrusted (i.e., whether there is trust that the farmer has evil intent). This determination could be done by the chicken observing what happens to other chickens (are chickens ever killed by the farmer?) and/or by communication from other chickens (did you ever see chickens killed by the farmer?). The second determination depends on reputation reported by others (i.e., backward-looking chains of trust), but the chicken would still have to verify the degree of independence of those reports, to its own satisfaction. For example, if all reports came from younger chickens, the chicken might need to verify with older chickens. BTW, in the reference paper cited here before, I discuss a similar example using a lamb and a lion. The lion represents an all-powerful adm (with root access, for example). The lamb represents a user with no power at all. How can the user survive? By using the rules of trust. > To make the question > even more tantalizing, how can the chicken know that the farmer has > arrived today with evil intent, whereas yesterday, he brought food? If > the chicken flees every time the farmer is seen, then the chicken will > starve - all of the other chickens will get the food first. Depends on the determination of trust (see above). If the farmer cannot be trusted, the chicken can let other chickens test the farmer's intent first, before approaching. If the farmer is untrustworthy, the chicken should stay away while the farmer is near. If the chicken flees every time the farmer is seen, the farmer will choose another chicken to kill, allowing the chicken to approach with less risk. Of course, these are contrived and a bit silly examples. However, they could equally well have been writen with different user roles in an IT system. Again, he "chicken" represents the average user, who thinks that what he sees today is what he will see tomorrow. Cheers, Ed Gerck