Re: Single model or framework for reputation/trust
Einar Stefferud <[email protected]> Tue, 4 May 2004 15:00:48 -0700
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <p06100502bcbd8a8170a4@[192.168.1.100]> |
Hello All -- Cutting to the chase scene, I see that you "Alan DeKok" actually agree with many of us that reputation is ONLY ONE possibly useful factor in assessing the validity of trust in specific cases, and that, thus, one source is generally not enough by itself to establish trustability in anything. And, it seems you agree that Trust information is not always nicely aggregated into YES/NO answers for all given situations. Thus Trust cannot be equal to Reputation. Trust is thus a bigger issue and a bigger problem than reputation. And, reputation was not a simple thing in the first place, having arisen from many observed events, seen by many different observers. The obvious result of this increasingly vitriolic exchange is that one requires more than one channel (or source) of reliable information in order to trust any assessment of trust reliance. Reputation is sometimes useful, but I would not bet my life on it unless nothing else is available. This realization is the basic first thing we must understand about trust. Single sources of information do not enable trustful reliance! This is intuitively obvious in certain situations. For example: Why does everyone intuitively laugh when the Used Car Salesman says "Trust Me!"? It is probably because intuitive trust is conveyed in the human genome (and so in the gene pool of all people) to not accept self assertions as trust from used car salesmen, and even from well meaning friendly chicken farmers. An Aside: There is even an old (perhaps undocumented) Yiddish saying that "TRUST ME" means "F... Y..!" Dogs and cats inherently Do Not Trust each other, but we have evidence that they can learn from life experience to trust each other and even to become life long friends, if not buddies! So, our innate genetic trust mechanisms are only the beginning of understanding trust, and its being genetically based only gives us an initial foundation at birth, which given the great array of channels provided by living, then builds sophisticated TRUST behavior from life-long learning from experience. There is recent research that notes that young children tend to suddenly stop eating everything that is put in their mouths, right around the time they gain mobility and start to walk and run, and gain access to lots of (bad) stuff that is not selected by their mothers to put in their mouths. It seems that being able to walk and run triggers a genetic reaction. Now, back to the chicken farmer;-)... We humans do not just trust the chicken farmer with our lives. We also look for other trust information about the butchered chicken in the meat department. We look for signs of tampering with medications on the drug store shelf, etc, et al. So, lets stop this contentious thread and go on to what it means to use more than one channel to enable trustful interactions via Internets. Trust in the Internet, in any way you wish to look at it, is going to be different from prior situations that require trust, because so many of the face to face, or voice quality, or document access encounters are now virtual, and are provided through untrustworthy channels. Also, we need to consider how to define what we mean by a "channel of communication" in the Internet, and how to enable multiple channels where we have previously seen only one. Some people have scoffed at Ed Gerck's claim to be able to put more than one channel in a 7 character token that looks and behaves and functions very much like a password or User-Name. They dismiss out of hand the very idea of such a small ASCII token being able to carry three independent channels of information. Well, my response is "What Do You Think a Channel must look like? And in general, these people just repeat the fact of their disbelief. Which is to say that they do not seem to have a clue as to what a channel is or what trustful information looks like in transit in any channel. Now, lets go back to our discussions of organizing Reputation Information into a single channel to be used for generating trusting behavior by the recipients of this single public value of reputation to be made available by some official behavior observing agency via the untrustworthy net. For example, it seems to me that the discussions of reputation information being consolidated for use in trust determination are engaged in reduction of the number of channels to be used, rather than increasing the number of channels to be used. So, by its definition, it violates one of the primary requirements of trust development and induction. Beyond this point of observation we find ourselves in new conceptual territory so we need to accept that the Internet is a different situation, where old notions of what generates trust perhaps do not fit the new network environment. The existence of NETWORKS and Inter-NETWORKS have injected new paradigms into our world and we need to translate our knowledge of TRUST (unconscious though it be) into conscious logical technical forms for use in the new paradigmatic statements of fact that can be applied to induce Internet Trust via new technologies that use more (rather than fewer) communication channels. After all, what the Internet does best is provide channels! What is the point of avoiding their use? Cheers...\Stef ++++++++++++++ Old Stuff Below This Point. (I did not delete anything;-)... >Ed Gerck <[email protected]> wrote: >> > I'm sorry to disagree with you and Bertrand Russell, but the story >> > is based on misconceptions, as I pointed out previously. Was the >> > chicken wrong for 6 months, when it predicted that "today, the farmer >> > will feed me?" No. >> >> The story illustrates the leap of faith that occurs when reputation >> is used to predict behavior. It's simply not warranted. > > Cut the crap, Ed. You *deleted* my qualification that, in this >case, reputation was correct 99.5% of the time. You then talk about a >"leap of faith", as though it was relevant to the discussion. > > To repeat my point again, which you seem to have misunderstood: > > Reputation is a strong indicator of future behavior. > > It's not a PERFECT indication of future behavior. To claim so would >be idiotic. I'm NOT claiming it's perfect, so a leap of faith isn't >required. So top talking about leaps of faith, it's annoying. > >> The chicken should never have predicted anything based on reputation >> alone. > > And again, you're talking as if I'm trying to use reputation >"alone". I'm not. I never have, and I never will. > > This is a problem I've seen with many discussions. There's talk >back and forth, but little communication. e.g. > > Party One: Tool X is useful for solving problem Y. > > Party Two: You're forbidding anyone from using anything OTHER > than tool X to solve problem Y! > You're claiming that tool X is perfect! > You're claiming tool X is the best way to solve problem > Y! > > Party One: WTF? > >> You can't rely on reputation to predict behavior, as Russel's chicken >> story exemplifies. To do so would be a leap of faith. > > Only if you're an idiot, and think that reputation is perfect. > > But 99.5% correct? That's useful. > > And wasn't Betrand Russsel the guy who wrote a ~400 page document >trying to prove "1+1=2"? My recollection is that he failed, so I >can only conclude that he believes it as a "leap of faith". So a >"leap of faith" isn't a very good argument against anything. > >> To rely on means to trust. To be able to trust future beahvior, we >> need more than just past behavior. We need more than reputation. > > Did I ever claim otherwise? > > Reputation is a tool which can be used by an email recipient to >determine how to deal with a message. It would be stupid to think >reputation is perfect, and it would be stupid to rely on reputation >alone, to the exclusion of everything else. > > Now that that's clear (I hope), can we agree that reputation MAY BE >used as ONE PART of the information available, for input to a >recipients decision-making process? > > And given that (potential) agreement about reputation, I believe >it's useful to have on-line reputation systems. > > Alan DeKok.