4 ms·
“You can't solve social problems with software.” (Marcus Ranum).
by Create 13y ago
“You can't solve social problems with software.” (Marcus Ranum).
- niels_olson 13y agoRight. You have to go meet people. Invite them over to your house, have dinner, and understand their concerns.
- redblacktree 13y agoThat sounds tedious.
- niels_olson 13y agoTo quote from the HN front page > What is there in this that is unbearable and beyond endurance? http://www.theatlantic.com/entertainment/archive/2013/05/marcus-aureliuss-one-question-to-beat-procrastination-whining-and-struggle/276288/ http://www.theatlantic.com/entertainment/archive/2013/05/mar...
- EthanHeilman 13y agoYes you can, given three assumptions: 1. Social relations depend on communication flows (i.e. Marx was wrong the superstructure is informational). 2. Software allows new communication flows. 3. Communication, like water, finds its own level. Rearrange social relations by altering communications flows. Rearrange communication flows by creating a flow that is easier than the Status Quo. The Babylonians did this with cuneiform, the Romans did this with roads, Radio did this, TV did this, the Internet did this. Software allows you to create new communication flows. The question is what social problems can be solved by reordering social relations and to what extend these particular social relations depend on communication flows.
- stinkytaco 13y agoI would argue that none of these developments solved the social problem we're talking about, however, i.e. keeping conversations private and creating trust. Indeed, these developments made it worse because face to face interaction is no longer necessary, and putting the means of communication out of your control (either by transmitting it over a medium you don't control or simply by making it so complicated you can't possibly control it) increasing the likelihood of the "man in the middle" either intercepting your communications or impersonating them. So I would say that you can reflow communication all you want, but that the underlying problem here is trust and knowledge and those are social problems. People either need to appreciate what these new communication flows mean and/or establish ways to bring their communications under their control (i.e. crypto). That said, I think the idea of establishing trust through key signing parties (and "crypto" parties) is an interesting one. One of the key features of this is learning from someone you likely don't know, just as when you do a key signing party everyone requires some sort of government ID. In the end, you've got to put your trust in someone, right? So, back to the social problem.
- EthanHeilman 13y agoI agree, I was objecting to the general statement that “You can't solve social problems with software.". There are social problems that are solvable with software and social problems that are not. It is an open question which cryptographic problems are of which class. I would argue that provable-identity is probably solvable in software, but that identity and utility are deeply connected notions. For instance Alice wants to talk to Bob to satisfy some want or need. His identity is only important to the extent that it is a necessary part of the utility of the communication. Generally two nodes in a network can prove that they have access to a particular set of keys, but the system tends to fall down on proving that they are useful to each other. A MITM attack is merely one party pretending to be as useful to the communicator as the intended recipient. If you disagree consider that your packets don't go directly to your bank, but are "rebroadcast" by routers and switches along the route.
- stinkytaco 13y agoI'm not following this argument. If someone is able to compromise Bob's key and impersonate them, then the identity system has broken down. The "utility" and "identity" are effectivly the same in your arguement. If I have something I want to communicate to Bob what matters is his identity not really anything else. Thus I either need to trust the party that verifies his identity or I need to verify the identity personally and I need to trust Bob to maintain control of his keys.
- EthanHeilman 13y ago>If I have something I want to communicate to Bob what matters is his identity not really anything else. But how do you know that Bob exists and you want to talk to him? At some point you met someone named Bob and at some point you decided you wanted to communicate with him, but Bob as an identity really only exists in your head. He could be named Jim, he could be someone that is pretending to be Bob, Bob might be one of two twins both named Bob. Maybe Bob is working for your enemies. One way to simplify the thorny issue of identity is to look at what someone wants out of the communication. The part of the identity Bob that matters to a communication is the expected utility of the communication. The identity is merely an end to that utility. For instance when you call tech support, you are trying to solve a problem and it doesn't really matter if the person tells you their name is Jim rather than James. The only hard and fast identity is cryptographic identity, it can be compromised if someone shares their secret key, but at least you know that you are communicating with someone that has access to that secret key. That is, I can send to a message to all parties with access to the secret key, SK0. The next question is how do I know that parties which have access to SK0 will increase my utility via communication. That can only be built from past actions either directly or indirectly performed by that party. Utility of identity depends on reputation of identity. Reputation of identity depends on past actions of identity (think stackoverflow/hackernews/silkroad). All of which can be cryptographically proved if the identity consists merely of access to SK0. Note, this is how identity and trust works outside of computers.