{"id":1484,"date":"2007-04-02T16:12:05","date_gmt":"2007-04-02T23:12:05","guid":{"rendered":"http:\/\/redmonk.com\/sogrady\/2007\/04\/02\/history_or_technology\/"},"modified":"2007-04-02T16:12:05","modified_gmt":"2007-04-02T23:12:05","slug":"history_or_technology","status":"publish","type":"post","link":"https:\/\/redmonk.com\/sogrady\/2007\/04\/02\/history_or_technology\/","title":{"rendered":"Best Defense: History or Technology?"},"content":{"rendered":"<p>It&#8217;s not often that I disagree with Jon Udell, but I&#8217;m not sure that I can quite convince myself of his <a href=\"http:\/\/blog.jonudell.net\/2007\/04\/02\/online-accountability-and-the-threat-of-impersonation\/\">latest argument<\/a> that implies dramatic and potentially long term consequences for the compromise of weak authentication common to many blogging systems.<\/p>\n<p>Jon&#8217;s responding to Tim Bray&#8217;s <a href=\"http:\/\/www.tbray.org\/ongoing\/When\/200x\/2007\/04\/01\/You-Are-Your-Website\">post<\/a>, which in turn was a response to <a href=\"http:\/\/radar.oreilly.com\/archives\/2007\/03\/call_for_a_blog_1.html\">Tim O&#8217;Reilly<\/a>&#8216;s post, which in turn was a response to the horrifying Kathy Sierra <a href=\"http:\/\/headrush.typepad.com\/creating_passionate_users\/2007\/03\/as_i_type_this_.html\">situation<\/a>. Still with me?<\/p>\n<p>The gist of Bray&#8217;s argument, and the one that Udell clearly concurs with is that one should be held responsible &#8211; not to mention accountable &#8211; for what appears on your website. I happen to agree with both of them &#8211; with an important exception. <\/p>\n<p>The exception, of course, is the precise scenario that is the implicit topic of Udell: the vulnerability of all of accounts &#8211; blog, del.icio.us, Flickr, whatever &#8211; to hijack. I think you should be held accountable, in other words, to what <i>you<\/i> post or allow to be posted to your website. Due to the weak authentication\/authorization mechanisms typically employed by such systems, as he discusses, &#8220;we are frighteningly vulnerable to impersonators.&#8221; All true. <\/p>\n<p>I could argue the point on a frequency basis &#8211; I can&#8217;t remember the last time anyone I knew personally had an account taken over &#8211; but that it can and does happen is not in dispute. <\/p>\n<p>What I&#8217;m not convinced of, however, is the longer term concern. Specifically, Jon&#8217;s belief is that in such cases, &#8220;impersonators&#8230;could irreparably damage our online reputations.&#8221; Is that really true?   <\/p>\n<p>I don&#8217;t question the short term damage. Nor do I question the possibility of lingering damage. But I&#8217;d like to believe, as I discussed with someone at the IBM conference last week, that if some of the hideously offensive anti-Kathy posts appeared in this space, you&#8217;d all know better than to think they came from me. That you&#8217;d know that something was amiss. Call me naive, but I&#8217;d like to think that my track record here counts for something, and that something completely out of line with that track record would be identified and credited as such. <\/p>\n<p>Not that that helps with the casual browser, of course, who might visit once, read something maliciously posted and firm permanent conclusions as a result. But the regular readers, I&#8217;d hope, would give me the benefit of the doubt. Await an explanation for a clearly anomalous datapoint. <\/p>\n<p>I agree with Jon that there&#8217;s no perfect defense. And I somewhat agree that &#8220;cryptographically strong multi-factor authentication&#8221; login systems would be helpful, although I have yet to see one that would pass the &#8220;average user&#8221; test. I believe, however, that the best defense is actually a strong track record &#8211; a history of behavior against which you can be judged. Just as <a href=\"http:\/\/alexking.org\/blog\">Alex<\/a> would have his body of work take the place of <a href=\"http:\/\/alexking.org\/blog\/2007\/03\/04\/around-the-web\">his resume<\/a>, so too would I have mine be my defense in cases where my ethics or integrity are questioned. But maybe that&#8217;s just me being a Pollyanna.   <\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s not often that I disagree with Jon Udell, but I&#8217;m not sure that I can quite convince myself of his latest argument that implies dramatic and potentially long term consequences for the compromise of weak authentication common to many blogging systems. Jon&#8217;s responding to Tim Bray&#8217;s post, which in turn was a response to<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[70],"tags":[],"class_list":["post-1484","post","type-post","status-publish","format-standard","hentry","category-privacy-security"],"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/posts\/1484","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/comments?post=1484"}],"version-history":[{"count":0,"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/posts\/1484\/revisions"}],"wp:attachment":[{"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/media?parent=1484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/categories?post=1484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/redmonk.com\/sogrady\/wp-json\/wp\/v2\/tags?post=1484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}