Managing trust in our digital world

In this month's piece, John Arnold, chief security architect at Capgemini UK, discusses the Jericho Forum's concepts of online trust and collaboration-oriented architecture. The Forum is an organization dedicated to encouraging innovations in e-commerce security.

Would you trust someone you've never met?

Lack of trust is the most serious problem with the Internet today. Lack of trust encourages phishing and spam, and limits the Internet to low-value transactions. Trust cannot be developed using technical security concepts alone; it must come from examining how humans create trust. The Jericho Forum's collaboration-oriented architecture addresses what we see as serious shortcomings in traditional approaches to online trust. Let's take a closer look:

We'll start by establishing a common understanding of key terminology, derived from the non-electronic world:
* Trust is a precondition for choosing to rely upon a collaboration with another party.
* Collaboration is an interaction between parties for some mutual purpose. A collaboration is governed by a contract between the parties involved.
* A contract is a mutually understood set of obligations between parties backed up by an accountability mechanism to handle non-performance. A contract is a legal entity but it does not have to involve lawyers – there are unwritten and implied contracts, for example.
* Reputation is an opinion that one party has of another that a collaboration between them is likely to succeed. If I have a high reputation with you, it is because, based on my previous history, you believe some combination of the following:

* That I am well disposed towards you.
* That I have an incentive to collaborate with you properly and not to misbehave.
* That I have the resources and skills to perform my part of the collaboration.

Reputation, contract and collaboration are related: If I have a high reputation then I will find it easier to contract with people. If I collaborate as expected by the contract, then my reputation will rise; and so on.

We all know that reputation is hard-earned, but easily lost. Just one failure to honor a deal can set you back almost to square one. Even a suspicion (not proven) of dishonorable dealing can ruin a reputation – as credit rating errors have amply demonstrated many times. The saying "Would you buy a used car from this man?" has entered our language as a good measure for deciding trust. Indeed, reputation is something that business traders truly value higher than all else.


Recent News:
· McColo takedown: Vigilantism or Neighborhood Watch?
· Spam drop could boost Trojan attacks
· Hosting firm shutdown forces botnets to relocate
· ISP cut off from Internet after security concerns
· Spam plummets after hosting service shuttered