<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>Advogato blog for fen</title>
    <link>http://www.advogato.org/person/fen/</link>
    <description>Advogato blog for fen</description>
    <language>en-us</language>
    <generator>mod_virgule</generator>
    <pubDate>Sat, 25 May 2013 16:57:20 GMT</pubDate>
    <item>
      <pubDate>Wed, 11 Apr 2001 07:57:40 GMT</pubDate>
      <title>11 Apr 2001</title>
      <link>http://www.advogato.org/person/fen/diary.html?start=5</link>
      <guid>http://www.advogato.org/person/fen/diary.html?start=5</guid>
      <description>The RSA Conference is huge this year - they say 10,000
people, and I believe it.  Quite a change from the 60-odd
attendees in 1991 (though most of us are still pretty odd!).
&lt;p&gt;
I'm a bit disappointed that nothing has really caught my
attention and excited me. 
It's nice to hear Adi Shamir likes the Rijndael algorithm
used by the new NIST Advanced Encryption Standard (AES)
which will be the replacement for the ancient (and broken)
DES.  But he did comment that the 10-14 rounds (depending
upon key size) proposed, while sufficient to stay any known
attacks, were
probably insufficient to provide a solution that could last
twenty years...
&lt;p&gt;
Overall, though, my cynical "executive" summary of the
conference (and the field) is that
while encryption techniques are getting better and stronger,
attack methods and general user and developer/implementation
errors seem to be increasing at a greater rate.</description>
    </item>
    <item>
      <pubDate>Mon, 2 Apr 2001 19:35:12 GMT</pubDate>
      <title>2 Apr 2001</title>
      <link>http://www.advogato.org/person/fen/diary.html?start=4</link>
      <guid>http://www.advogato.org/person/fen/diary.html?start=4</guid>
      <description>Still pre-publication, I invite comments and feedback on &lt;a
href="http://www.openprivacy.org/papers/200104-repcap.html"&gt;
&lt;i&gt;Reputation Capital and Exchange Mechanisms&lt;/i&gt;&lt;/a&gt;,
particularly wrt the zero-knowledge proof requirements.
&lt;p&gt;
OpenPrivacy is an Open Source initiative.  We're building a
framework to allow secure reputation trade for pseudonymous
entities.  (See the &lt;a
href="http://www.openprivacy.org/"&gt;home page&lt;/a&gt; for more.)
&lt;blockquote&gt;
&lt;i&gt;...wonder what it takes to get upgraded from Observer...&lt;/i&gt;
&lt;/blockquote&gt;
</description>
    </item>
    <item>
      <pubDate>Sun, 1 Apr 2001 07:01:16 GMT</pubDate>
      <title>1 Apr 2001</title>
      <link>http://www.advogato.org/person/fen/diary.html?start=3</link>
      <guid>http://www.advogato.org/person/fen/diary.html?start=3</guid>
      <description>Here's a snippet from a paper I'm writing on
&lt;i&gt;Reputation Capital and Exchange Mechanisms&lt;/i&gt;. 
&lt;blockquote&gt;
 A reputation exchange is similar to a currency exchange,
but trades in reputation capital instead of money. No one
can force you to start using a new currency but if all your
friends - and you - move to France, you'll want to start
using francs. The Reputation Management Framework provides a
plug-in architecture for Reputation Calculation Engines that
make this sort of "reputation-exchange" feasible. The rules
governing the "exchange rate" are set by the administrators
of the respective systems - poor exchange rates will
discourage newcomers while inflated exchange rates will
disgruntle the existing community. A particularly compelling
feature is that reputation exchanges - unlike their
currency-backed counterparts - are not zero-sum, in that the
process of converting a reputation does not destroy the old
one - it merely enables some reputation carry-though systems.
&lt;/blockquote&gt;
</description>
    </item>
    <item>
      <pubDate>Thu, 29 Mar 2001 02:52:31 GMT</pubDate>
      <title>29 Mar 2001</title>
      <link>http://www.advogato.org/person/fen/diary.html?start=2</link>
      <guid>http://www.advogato.org/person/fen/diary.html?start=2</guid>
      <description>Pymmetry and Bram's "trust" code have gotten me (finally) to
spending a little time with Python.  It's fun and easy
though I still have some of the steep part of the learning
curve to go up.  Emacs integration seems good, but I can't
seem to find the key-binding to evaluate e.g. a test def in
the file I'm working on.  I'm sure there's a way...

&lt;p&gt; &lt;p&gt;

&lt;p&gt; Working with existing trust frameworks has got me thinking
about how cool the &lt;a
href="http://www.openprivacy.org/"&gt;OpenPrivacy&lt;/a&gt;
reputation management framework is.  It's designed so that
trust metrics - such as Pymmetry or Slashdot's moderation -
can be plugged in and evaluated *themselves* on their
reputation.  So a community that uses e.g. Pymmetry today
can easily switch, if and when a better trust metric (or a
newer version of Pymmetry ;-) comes along.  All pre-existing
identities, certification, and reputations would remain
intact, perhaps translated (at owner discretion) to the new
system.

&lt;p&gt; &lt;p&gt;

&lt;p&gt; Think of it like a currency exchange, but with reputations.
 No one can force you to start using a new currency but if
all your friends move to France, you'll want to start using
francs.  The Reputation Management Framework provides a
plug-in architecture for Reputation Calculation Engines that
make this sort of "reputation-exchange" feasible.  And since
reputation-exchanges are not zero-sum, you actually get to
keep your old reputation, too!

&lt;p&gt; &lt;p&gt;

&lt;p&gt; We're putting the finishing touches on the documentation,
but the code
is available now.  We're also working on a example system
called &lt;a
href="http://www.openprivacy.org/projects/reptile.shtml"&gt;Reptile&lt;/a&gt;
(Reputation-enhanced portal using Mozilla technology) -
check it out!
</description>
    </item>
    <item>
      <pubDate>Mon, 26 Mar 2001 06:09:34 GMT</pubDate>
      <title>26 Mar 2001</title>
      <link>http://www.advogato.org/person/fen/diary.html?start=1</link>
      <guid>http://www.advogato.org/person/fen/diary.html?start=1</guid>
      <description>Fought with Debian today.  I had moved up to "unstable" on
my personal machine to get access to some new stuff.  Guess
I've been lucky - and source control is getting better - as
I've had no problems.  But I want to get it back to
"testing" level, which is anything but straightforward.
</description>
    </item>
    <item>
      <pubDate>Sun, 25 Mar 2001 05:23:54 GMT</pubDate>
      <title>25 Mar 2001</title>
      <link>http://www.advogato.org/person/fen/diary.html?start=0</link>
      <guid>http://www.advogato.org/person/fen/diary.html?start=0</guid>
      <description>I've been thinking a lot about 'trust' and 'reputation'
recently. (I
presented a paper at the Boston &lt;a
href="http://www.cfp2001.org/"&gt;
Computers, Freedom and Privacy&lt;/a&gt; conference earlier this month
entitled &lt;a
href="http://www.openprivacy.org/papers/200103-white.html"&gt;
&lt;i&gt;OpenPrivacy - Enhancing the Internet with
Reputations&lt;/i&gt;&lt;/a&gt;.)

&lt;p&gt; &lt;p&gt;

&lt;p&gt; Trust is key to any anonymous network, indeed to any society.
Pseudonyms that over time prove to be trustworthy develop
reputations
that smooth the process of finding the people/entities that
are most
worth dealing with - within any given domain.

&lt;p&gt; &lt;p&gt;

&lt;p&gt; Trust is &lt;i&gt;not&lt;/i&gt; generally transitive, as I may trust an auto
mechanic with my car but perhaps not to invest my money. 
Ultimately,
we find that trust develops through prior experience and
knowledge, is
spread by &lt;i&gt;word-of-mouth&lt;/i&gt;, is dynamic, and non-monotonic.

&lt;p&gt; &lt;p&gt;

&lt;p&gt; There's precious little useful research in the computer science
literature on trust and reputations, perhaps because there's
a need to
understand some background in the social sciences as to what
it is and
how it works.  But I'm excited that more effort is going in this
direction.  Here's a short &lt;a
href="http://www.openprivacy.org/bibliography.shtml#trust"&gt;
Bibliography&lt;/a&gt; that I have compiled.  Suggestions are welcome!

</description>
    </item>
  </channel>
</rss>
