Showing posts with label asymmetry. Show all posts
Showing posts with label asymmetry. Show all posts

Tuesday, September 13, 2005

Wash Out 2

The Biblical symbolism of the New Orleans flood is becoming unmissable.
From a security thinking perspective, Hurricane Katrina apparently provides an excellent proof of Intelligent Design. Surely only the most wise and angry God could find a way to destroy such well-engineered flood protection.

The Intelligent Design model assumes that we can build effective security by a top-down process. But the actual state of hurricane-readiness in New Orleans was not determined by a simple top-down process, but by a complex emergent process including large quantities of development in the surrounding area.

Security thinking also assumes symmetry between threat and defence. But Acts of God are often asymmetric. As Security Nerd indicates, there is no competition between an imperfect city and a perfect storm.


Previous post: Wash Out

Technorati Tags:

Friday, April 29, 2005

Dividing Risk

Responsibility for security of credit card transactions is divided between credit card companies and merchants. The credit card companies don't entirely trust the merchants, and want to ensure they take every possible precaution against fraud.

Credit card companies are larger and fewer, so they call the shots. Some elements of risk are unilaterally exported onto the merchant. In case of doubt, the merchant bears the financial burden. This is surely an example of asymmetric trust.

So who is responsible for specifying the security requirements, and designing the security mechanisms? Steven Hofmeyr argues that the credit card companies should leave this as a problem for the merchants to solve. "My suggestion to the credit card companies would be to impose heavy penalties on merchants that get compromised, but not to specify what exactly those merchants should do to make themselves secure." He favours incentives for companies to secure their systems, "without restricting or constraining the way in which they should do so, leaving companies to choose the most effective way", on the grounds that this will encourage innovation in defence, and notes how legislation or regulation often generates such incentives. Hofmeyr's suggestion is endorsed by Adam Shostack.

Given the asymmetry of power, any requirements imposed on merchants by credit card companies are effectively equivalent to regulations. Leaving merchants free to interpret these regulations (and suffer the consequences if their interpretations aren't good enough) may affect the security of the whole ecosystem in some interesting ways.

Firstly, each merchant is faced with fear, uncertainty and doubt. The big companies probably know much more about the possible security mechanisms, and their advantages and disadvantages, but the small companies have to decide for themselves - and woe betide them if they get it wrong. This anxiety effect tends to erode confidence and trust in the network, thus reducing economic efficiency and ethical balance.

Secondly, we may expect considerable diversity of security mechanisms. This diversity may be one of the factors leading to the innovation argued by Hofmeyr. But at the same time, diversity may impede the communication and adoption of innovation, so the effective innovation benefits are not clearcut. Very occasionally, a centrally coordinated development effort may be both more cost-effective and more innovative than a large number of independent parallel developments. So it remains an open question whether the credit card companies should provide more specific guidance, whether they should "own" the security requirements.

Thirdly, the greater the diversity of security mechanism, the smaller the proportion of merchants likely to be affected by any given attack. This appears to be beneficial for the population of merchants as a whole, since it reduces the risk for any individual merchant, and makes some form of mutual insurance viable. Above all, it is beneficial to the credit card companies, whose business would only be seriously threatened by the loss of a significant number of merchants in one incident. However, given the incessant search for new modes of attack, this benefit depends on the collective ability to develop new forms of defence.

In a complex collaboration, a careful division of risk requires detailed analysis, robust negotiation, and attentive governance. Redistribution of risk-responsibility can have a huge effect on the total shared risk within the system, generating both economic and ethical benefits.

Technorati Tags:

Thursday, September 09, 2004

Asymmetric Trust

Our experience of trust starts at the human level: between parent and child, or between neighbour and neighbour. This can be symmetrical, because both sides are people.

As soon as we treat corporations as if they were people, we start to get into difficulties. I may have warm feelings about some of the companies in my neighbourhood, especially those that have been around for a long time; but any trusting relationship between myself and a company is essentially asymmetric, because a company is not a person (legal fiction notwithstanding). I may trust the shop where I buy my groceries, and I may have little choice but to trust my bank, but these are not symmetric relationships.

Similar difficulties arise in relationships between companies and trade unions, and between nations and other organizations. Aidan writes of negotiations between terrorists and the USA government. But such negotiations (if they take place at all) are inescapably asymmetrical, because the two sides are of different types. Terrorist leaders typically have the power to inspire violence; but when they instruct their followers to lay down their arms, the most likely outcome is that a proportion of them will switch allegiance to other leaders (previously unknown) who want to carry on the fight.

If we pretend that AlQaeda is like a conventional army, or a conventional nation state, we are likely to get into worse trouble. We cannot create symmetrical trust by pretending that different entities are of the same type. (Aidan talks about "the amount of skin in the game", as if it was simply a game of cards with high stakes and we can find a system frame in which these stakes are equal in some sense. But it's not GWB or OBL whose skin is at risk, and the balance of power is an illusion.)

We can only create symmetrical trust by forging genuine relationships between entities of the same type – people to people, community to community.


Previous Posts on Asymmetric Trust: Fearful Asymmetry, Identity Cards, State of Trust 2, Who Needs Symmetry?

More on Asymmetry.

Monday, August 09, 2004

State of Trust 2

In his last post, John describes some geopolitical and constitutional aspects of trust.

John is scornful of the entities in which we are supposed to invest our trust, and questions the legitimacy of these entities. But the problem goes deeper. These entities are symbolic or imaginary entities – they simply don't reflect political reality.

The British constitution is a symbolic façade, which has very little to do with the true distribution of power and influence. Similarly, the African political map is a series of imaginary lines, historically imposed by colonial powers, which do not adequately reflect the identities and affiliations of the people who live there.

Nation-state dealing with nation-state is an example of the assumption of symmetry.

Symmetric trust assumes that trust can be managed through symmetric relationships between entities of the same kind (albeit different quantities of power).

Military strategists now increasingly recognize that the assumption of symmetry doesn't work for warfare, in which the primary threat doesn't come from nation states but from sources of a different kind – hence the interest in asymmetric warfare. The assumption of symmetry doesn’t work for demand either – hence the interest in asymmetric demand.

And it certainly doesn't work for trust. Hence Asymmetric Trust.

Friday, July 16, 2004

Trusting Words

John’s recent posts refer to the relationship between trust and language.

People often use words in a deceptive way, to conceal truth or intention. When people choose their words carefully, this may be because of a strong desire for accuracy and clarity, or it may be quite the opposite. Obviously this is (among other things) a trust issue.

But words can also be misused or misleading without any conscious intent to deceive. To the disappointed, it may make little first-order difference whether I'm disappointed by accident or design. But it makes a big second-order difference. (And in any case, the POSIWID principle suggests that Nothing Happens By Accident.)

People talk nostalgically about handshake-based trust or eyeball-based trust. But these trust mechanisms assume a shared and unambiguous language and culture, and may not work in a heterogeneous (asymmetric) world.

Thursday, November 27, 2003

Metacommunication

The speech act "Trust Me" often conveys the exact opposite of its literal meaning. This is an example of metacommunication, as analysed by Gregory Bateson and his associates.

When an agency (whether the Home Office or Police, Inland Revenue or Customs and Excise) behaves mistrustingly towards the population, the rational and symmetrical response may be to regard the agency with equal mistrust. However, the actual response is often an asymmetrical one -- to regard the agency with elevated trust.

And when a technology puts forward a claim that it can perfectly detect fraud or impersonation, the rational and symmetric response may be to regard the technology as the fraudulent one. However, the preferred response is sometimes to wrap the technology in a sociopolitical casing, so that it becomes impervious to purely technical criticism. Notions of fraud, fallibility and repression are no longer amenable to technical judgement, but are under political control. This politically encapsulated technology is what is sometimes called a black box. We trust these black boxes because we have no choice.

Building Dynamic Coalitions (Jane Angelis)

Sunday, November 23, 2003

Identity Cards

The identity card is seen both as a mechanism for Government agencies to provide citizens with some set of services (in a reliable and secure manner), and as a mechanism for Government agencies to perform some set of mandated controls over the citizenry. These objectives naturally conflict, and this is part of the reason for the distrust mentioned by Aidan.

Furthermore, there is a common pattern of service providers distrusting their users/customers. Banks assume all their customers are engaged in money laundering or some other fiddle, while Insurance companies assume all their customers are in a perpetual state of moral hazard, and that all claims are potentially fraudulent.

And yet service providers expect their customers to trust them absolutely - trust them and their staff and their overseas contractors and their extremely complex computer systems. Government agencies are no different in this respect from any other service provider.

This is an example of Asymmetric Trust. See also Finance Industry View of Security.