4 ms·
> Doesn't this just shift the problem? No. Perhaps counter-intuitively the "problem" isn't trust here. What I'm raising above is not the necessity to trust bu
by nonrandomstring 2y ago
> Doesn't this just shift the problem?
No. Perhaps counter-intuitively the "problem" isn't trust here.
What I'm raising above is not the necessity to trust but the extent to
which verification is possible or frustrated. For example, with open
versus proprietary code you may or may not have the capacity to audit
it, but you always have the possibility.
> I would rather trust a company with x persons
Trustworthiness does not scale in this way. Though the "many eyes"
theory has some weight, we also say "two people can keep a secret if
one of them is dead." Assigning more cooks to the broth yields rapidly
diminishing returns for reasons Fred Brooks explains [0].
But that is not my strongest objection. A more serious reason not to
trust a BigTech company with your security is the "principal agent
problem" [1]. As Ross Anderson puts it; "If Alice guards a system and
Bob pays the cost of failure, you can expect trouble!" [2]. Microsoft
does not "pay the price".
Worse, Google (and Meta, Linked-In etc) base their business model on
your insecurity - they are primarily in the business of acquiring data
about you to use in selling your person to advertisers. They are
therefore motivated, however weakly, against your actual security.
It's a scandal that such companies also act as data processors and
suppliers of services like online storage.
So while you can outsource trust, you cannot unload responsibility to
verify. A solution is education based on a credo of "principles not
products" [4].
[0] https://en.wikipedia.org/wiki/The_Mythical_Man-Month https://en.wikipedia.org/wiki/The_Mythical_Man-Month
[1] https://en.wikipedia.org/wiki/Principal-agent_problem https://en.wikipedia.org/wiki/Principal-agent_problem
[2] https://www.csail.mit.edu/news/dertouzos-distinguished-lecture-prof-ross-anderson https://www.csail.mit.edu/news/dertouzos-distinguished-lectu...
[3] https://techrights.org/n/2024/09/25/Technology_rights_or_responsibilities.shtml https://techrights.org/n/2024/09/25/Technology_rights_or_res...
[4] https://cybershow.uk/blog/posts/principles https://cybershow.uk/blog/posts/principles