Live data from Hacker News

Can I Be Trusted?

schneier.com

11–20 of 62 posts

Re: Can I Be Trusted?

#11
post #7
post #6

Earlier quoted context omitted.

Yes, he just have disclosed the reason not to be trusted. He conflates absence of evidence with evidence of absence.

No, he is suggesting "innocent until proven guilty", you are suggesting the opposite. This is a "have you stopped beating your wife" question, what could any person say except "there is no evidence that I am untrustworthy". How do you mathematically verify a person?

In computer security, guilty until proven innocent tends to be best practice.

Re: Can I Be Trusted?

#13
post #6
post #5

So far, I haven't seen the good reasons why I might be untrustworthy. I'd help, but that seems unfair. The better question to ask would be "Why might I be trustworthy" which he could then try to answer. Not that I don't think Schneier is untrustworthy..

Yes, he just have disclosed the reason not to be trusted. He conflates absence of evidence with evidence of absence.

I took it as a joke, not a statement of evidence.

Re: Can I Be Trusted?

#15
post #8

I think a fair bit of his non-cryptography security advice of the past 10+ years has been...different than a lot of people I know better and have direct evidence of their competence would give. Increasingly so recently (the past year or two). As a cryptographer, particularly on the symmetric side, he does a good job (at least, the other people who I know who are good at that also think he does a good job; I understan…

[deleted]

Re: Can I Be Trusted?

#16
After the wall came down, the stasi shredded a lot of their files. But they were reassembled a few years ago and they revealed that some of the dissidents at the time were snitching on their fellows in return for less harsh treatment.[1]

I don't think Schneier is similarly compromised - to give out misleading interpretations of the NSA leaks - but we can't know that with 100% certainty as long as the documents he's commenting on are not public.

[1] http://articles.latimes.com/2009/nov/01/world/fg-germany-sta...

Re: Can I Be Trusted?

#17
post #8

I think a fair bit of his non-cryptography security advice of the past 10+ years has been...different than a lot of people I know better and have direct evidence of their competence would give. Increasingly so recently (the past year or two). As a cryptographer, particularly on the symmetric side, he does a good job (at least, the other people who I know who are good at that also think he does a good job; I understan…

[deleted]

Re: Can I Be Trusted?

#18
post #13
post #6

Earlier quoted context omitted.

Yes, he just have disclosed the reason not to be trusted. He conflates absence of evidence with evidence of absence.

I took it as a joke, not a statement of evidence.

I agree, it was a joke.

Furthermore, I took it as him saying that he could provide a list of reasons that people should not trust him but he won't because it would be the security pundit version of cock-blocking himself.

Re: Can I Be Trusted?

#20
You'd have to define trust to understand and then answer the question.

Trust is the inverse of what most people think it is.

Trust isn't about what someone will do, it's about what they won't do.

You might trust a guy with your life by asking him to hold a ladder whilst you climb up it, but you probably wouldn't trust the same guy with your medical history and insights into your state of mind and personal relationships.

Yet you would trust a doctor with your medical history, and you would trust a psychiatrist with your mental wellbeing.

The basis of trust is a belief that the person/entity you are trusting won't do something. In the case of that ladder, that the guy won't let go. In the case of the physician and psychiatrist that they won't share information about you.

The NSA stuff can be seen in that light, there is a betrayal of trust as the basis for trust in a government spy agency was that they wouldn't do a certain thing... spy on their own people. The rest is all forgiveable (you pretty much should expect them to spy on everyone else whether you agree with it or not, that's their purpose).

When it comes to Bruce Schneier the question is "Do you trust Bruce Schneier?", but this seems to just beg the next question, "To not do what?".

I trust Bruce Schneier to not sacrifice his own principles and belief system in backdooring some code or otherwise compromising his work.

But I don't necessarily trust Bruce Schneier to hold a ladder that I'm standing on (he may well have a sense of humour that reflects silent cinema, and being up a ladder was never a good thing when a Loki character was holding it).

Post reply on HN