5 ms·
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority.
by FatActor 4y ago
Thank you for the link.
> It's also been built by people who are respected in the security industry.
This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
- beckingz 4y agoMost people don't read open source and instead trust that the experts will catch any issues....
- FatActor 4y agoIt's turtles all the way down. Would you rather NOT have the option for other experts to see the code?
- danShumway 4y agoOf course not, I'd rather the code be Open and audited. Being Open Source is in some ways a multiplier on security because it allows more expert review. But the expert review is the important part; if security-critical code is Open Source but hasn't been looked at by anyone other than the main developers, the Open Source part is a multiplier on zero. It's a little bit more complicated than that, and there are a lot other factors at play as well even outside of security. We're not really getting into stuff like future-proofing and what happens if 1Password gets a lot worse in the future. It's complicated. But the gist is that while it would be a lot better if 1Password was Open Source, it's still in its current state probably got more eyes on it than some Open Source security projects do.
- JamesBarney 4y agoWhen the tool is opened sourced honest and rogue security experts are going to go through it. Now how much value is the first adding versus the second removing is the case. And based on incentives for each, an honest security research maybe getting a small bug bounty, and a rogue one potentially gaining access to 10's of thousands of accounts I think it might be a net negative overall.
- function_seven 4y agoEven so, the number of experts looking at the code will increase if it's open, right? I know the concept of "many eyes makes all bugs shallow" isn't the panacea we once thought it was; that still there can be bugs lurking in widely-read sources. But it must be smaller than the number of bugs that exist in code read by a smaller group.
- Espressosaurus 4y agoAn appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain.
- fatbird 4y agoI wish more people would remember this.
- butthisiswrong 4y agoBut its incorrect, its literally the logical fallacy, argument from authority, if the person us not an authority then it cannot by definition be argument by authority. Experts must prove their views with evidence and not rely upon their reputation, that is the meaning of the fallacy. No wonder so many people cant reason well.
- fatbird 4y agoAn argument from authority is not a fallacy in and of itself. An appeal to false authority is always a fallacy, such as considering an authority's opinion on a topic on which they're not authoritative. If the participants in a debate agree that an authority is legitimate, then an unchallenged appeal to their authority is not fallacious. If an authority's opinion is contradicted by undisputed evidence, then an appeal to their authority is fallacious. The whole point of the distinction is to admit authority as a valid source of information, in the absence of direct evidence, because we can't possibly reason from direct evidence in every single case.
- ValentineC 4y ago> if the person in question is actually an authority in the domain I haven't seen a name mentioned in much of the discussion here. Who are we talking about from this list, and what else have they done? https://1password.com/company/ https://1password.com/company/
- thefaux 4y agoThe truth of a statement is what matters, not who uttered it.
- burkaman 4y agoAppeal to authority is not a fallacy, it's basically a necessity to function in the world.
- FatActor 4y agohttps://www.grammarly.com/blog/appeal-to-authority-fallacy/ https://www.grammarly.com/blog/appeal-to-authority-fallacy/
- inthepipe 4y ago> When you need to support a claim, it can be tempting to support it with a statement from an authority figure. But if done improperly, this could be a logical fallacy—the appeal to authority fallacy. The key words are: “if done improperly, this could be…” The article goes on the give non-fallacious examples of an appeal to authority. The quality of an implantation will be correlated to experience, so this is an example of a non-fallacious appeal to authority.
- burkaman 4y ago> if done improperly, this could be a logical fallacy Maybe I'm wrong but doesn't this put it in a totally different category than other fallacies? Circular arguments, for example. All circular arguments are wrong. If you identify a circular argument you don't even have to fully understand what is being said, you can immediately conclude "this is a bad argument". But appeal to authority isn't like that. "I'm not going to drive through the mountains today because the roads are iced over, and I know that because the highway department said so." That's an appeal to authority, and it isn't proof, but it's a good argument and there's no need to drive out yourself and confirm that the roads are dangerous. Identifying an appeal to authority is not enough to discard an argument, you need to evaluate the authority. When you see a circular argument you don't have to measure the diameter of the circle or something. So I don't think appealing the Grammarly was a fallacy, but in this case I think they're wrong.
- FatActor 4y agoThat's a good clarification. Thanks for the example. Hmm... perhaps my concern is that expert opinions matter way more than non-experts, but we still can't blindly trust them. ...and I'm sure you're not saying to take everything they say as word of truth. I withdraw my argument on the grounds it is poorly constructed.
- inthepipe 4y agoJust curious: Imagine two people took the 1Password white paper and created two separate implementations. The only information you have on the two implementations is the background of the people who implemented them. One is a first year CS student; the other is a seasoned security researcher with multiple published vulnerability discoveries. Which would you choose and why?