Re: im2000 protocol base
"clemens fischer" <[email protected]>
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Rickard Armiento <[email protected]>: > Rickard: >>> You still have the problem that you trust a new identity more than >>> a rejected one. This creates an incentive for hostile nodes to >>> re-appear under a new identity. > > clemens: >> this is one of the reasons i want authentication be part of im2000. >> keys used for this would have to be back tracable to a natural >> person. if this goal can be reached, im2000 users could verify >> messages to a practically useful degree. it is not some anonymous >> node suddenly starting spamming, there's always somebody real >> behind it, and it seems easy to check certificate chains. > > Okay... If you do plan to base your trust model upon a fully > traceable "one identity" => "one physical person" model, then you > have opened a whole septic tank of worms :-). Until you are able to > describe how to build the infrastructure to handle this, other > technical details of such an approach are less relevant. there's another mailinglist at cacert.org, which is a non-profit organization facing the same problem. they offer free X509 certificates, and just now start planning a PKI to allow other people than the cacert admin(s) to manage the policy. they operate internationally, and discussions lately reveiled that not even in english-speaking countries the same words mean the same thing. for example cacert needs a paper signed by a trusted authority that "proves" your identity. the concept seems intuitively simple an clear: get a paper with seals and stamps on it and send it over. but we exchanged a dozen emails until it became (un)clear that notary publics don't exist everywhere in the same form, that police won't do the same things in every country etc. but you're right. the trust model must provide levels and appeals. i first thought that simply trusting every new service (with users beeing services themselves) and exchanging signatures and revokations, the system could adapt to real world needs. you argued that this imposes a problem: what hinders an abuser to change identity and start anew? i tried to fix this, and it's also my belief, with making authenticated identity always be traceable to a real person. then you say: > To be specific, these are the most basic questions: > > * How does an international social/society infrastructure handing > out im2k identities work? How should it be constructed? > Who should pay for it? > > * If someone hacks my computer and turns it into a hostile node; can > I ever be forgiven by the system? Since I cannot reappear under a > new identity, do I risk being negatively "marked" forever? well, i never thought im2000 should imply "one identity == one physical person", and this is not what my proposal boils down to. im2000 services themselves need to have multiple identities. as the identity in a computer system is never the same as a physical person, this abtraction leaves natural dimensions. my "solution"(?) to the second point is this: if your computer is hacked, your computer-identity is compromised, but not you yourself. thus you just go create another key and will have to rebuild trust in it by getting it signed. i want others to be able to use your new computer identity (signed key), but be able to ultimately find out what your real name is. so there's an intermediate level. this is where appeals might help in case (i) you get successfully attacked many times or (ii) you _claim_ to have been successfully attacked many times. this is not perfect, of course, it makes the entire machinery more and more complicated, but i think it goes with the territory. if you want to be an agile networked user, you face security problems you will have to deal with, and no system can protect you from it. X509 didn't manage to resist theft of identity, PGP seems complicated to use for beginners. > Rickard: >>> When you say "draw business", what kind of business do you mean? >>> Few external services would serve users for free, only for the >>> sake of the trust of serving yet more users. If that is the idea, >>> you would probably quickly end up with a system with ISP:s >>> providing a set of services only to its own paying customers >>> (quite similar to how most services are handled today). > > clemens: >> and what is wrong about that? > > Then there is very little need for a generic node-network. If there > is only a handfull "external" services available it would be very > easy for every user to keep track of these and, using your own > words, "analyze all the available options in a given infrastructure > and within a given budget". ok, but look at what current ISPs offer: you get incomplete service for free, and pay-services is hogged with all sorts of needless stuff they try to make you buy as well. the problem may well be the granularity and cost-structure of the offerings. don't you think if the costs of service can be efficiently negotiated on a per message and per service level, market forces may be able to bid/compete for that fraction of a cent you want to spend? i'd like im2000 to enable both large ISPs and single individuals to stay in business, and i know there are creative marketers out there, but i don't know any of those few. although i have the feeling their numbers rise. i'm not sure if this feeling is the result of alien manipulation though (i did have a cup of coffee today :). > clemens: >> fact is that we can't have both a system capable of negotiating >> contracts _and_ allow anonymity [...] > > Perhaps the capability of negotiating binding contracts without any > prior key-exchange has to be left out. This does not remove the > possibility of using im2k to charge for services: for example, the > mobile phone SMS service are used today to charge for small business > services, despite there not being a traceable "one identity" => "one > physical person" relationship. oh, no, this is a complete misunderstanding. i can't imagine any binding contract between anonymous individuals on "items" other than ethics and moral and mutual respect and tolerance "et cetera". the SMS initiated and controlled contracts are a good example, though. they are implemented in germany as well, only they've failed to deliver profit yet. the reason for this was that too few customers registered and used it. people could order taxi transport, tickets for cinemas etc. here the information transferred in the messages is actually small, most of it is "contextual". clemens btw, rickard, i appreciate the discussion.