Re: [Smart] Epistemology in the Cloud

Henry Story <henry.story@co-operating.systems> Mon, 17 December 2018 18:44 UTC

Return-Path: <henry.story@co-operating.systems>
X-Original-To: smart@ietfa.amsl.com
Delivered-To: smart@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6FE85130F04 for <smart@ietfa.amsl.com>; Mon, 17 Dec 2018 10:44:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0BGhqrnbN4yr for <smart@ietfa.amsl.com>; Mon, 17 Dec 2018 10:44:38 -0800 (PST)
Received: from relay3-d.mail.gandi.net (relay3-d.mail.gandi.net [217.70.183.195]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B9979130F01 for <smart@irtf.org>; Mon, 17 Dec 2018 10:44:37 -0800 (PST)
X-Originating-IP: 80.12.27.211
Received: from [192.168.43.200] (unknown [80.12.27.211]) (Authenticated sender: henry.story@co-operating.systems) by relay3-d.mail.gandi.net (Postfix) with ESMTPSA id 80E3D6000F; Mon, 17 Dec 2018 18:44:34 +0000 (UTC)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 12.2 \(3445.102.3\))
From: Henry Story <henry.story@co-operating.systems>
In-Reply-To: <LO1P123MB08368C330C36927CEE4C7682D7A10@LO1P123MB0836.GBRP123.PROD.OUTLOOK.COM>
Date: Mon, 17 Dec 2018 19:44:32 +0100
Cc: "smart@irtf.org" <smart@irtf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <008AD704-FD01-4AC9-B462-014FEFF0F296@co-operating.systems>
References: <7F20A91C-B493-4955-9547-552BE718A29D@co-operating.systems> <LO1P123MB08368C330C36927CEE4C7682D7A10@LO1P123MB0836.GBRP123.PROD.OUTLOOK.COM>
To: Kirsty P <Kirsty.p@ncsc.gov.uk>
X-Mailer: Apple Mail (2.3445.102.3)
Archived-At: <https://mailarchive.ietf.org/arch/msg/smart/RZxQZlvEoWZngxuamQ1LfYaTBBQ>
Subject: Re: [Smart] Epistemology in the Cloud
X-BeenThere: smart@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Stopping Malware And Researching Threats <smart.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/smart>, <mailto:smart-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smart/>
List-Post: <mailto:smart@irtf.org>
List-Help: <mailto:smart-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/smart>, <mailto:smart-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Dec 2018 18:44:41 -0000

Hi Kirsty, 

> On 17 Dec 2018, at 18:49, Kirsty P <Kirsty.p@ncsc.gov.uk> wrote:
> 
> Hi Henry,
> 
> Thanks for your interest in the group! I can see that you discussed phishing on the SAAG list in July - perhaps an example of many people having the same good idea at the same time! I actually had the idea for SMART a bit earlier, with the ambition that SMART will span more than only phishing - to defend against the breadth of attacks that we see on the Internet today. If you have specific research on phishing that you would like to bring into SMART, we would be very interested to see it, especially as significantly reducing UK-hosted phishing has been one of NCSC's key achievements since we started.

It's great to have company in thinking about these topics. :-)

The blog post that most directly and concretely presents the idea in terms 
of Phishing is 
"Phishing in Context - Epistemology of the Screen"
https://medium.com/cybersoton/phishing-in-context-9c84ca451314

But the idea goes much further. 

I see the web as a socio/technical system [1] and so security thinking needs to 
take technology as well as the humans and social into account. Once one looks at this 
carefully one sees that what is missing is institutional and national 
integration in the security architecture of the web. Not any way to do that
would work of course: one needs to respect the sovereignty of each nation if it is
to work, ie: there can be no centralised system. Luckily a decentralised web
of Nations is technically feasible - the standards are ready - and politically of 
course requires a much longer process of co-operation. But the stakes are worth it.

There is a longer post "From Digital Sovereignty to the Web of Nations"
https://medium.com/cybersoton/from-digital-sovereignty-to-the-web-of-nations-61fbc28d79cd
which looks at the issue of digital sovereignty, by also bringing in the debate
on the issue going on in France.

I hope that helps, and am happy to answer any further questions,

	Henry Story


[1] I am actually part of the Social Machines project https://sociam.org/

> 
> Your linked research looks interesting; however I suggest it might be a better fit for the HRPC RG. 

You mean this one:
https://datatracker.ietf.org/rg/hrpc/about/ 
?

> In fact, I think "Fake News" was brought up in the last IETF as a possible future work topic!

I see that at least a large part of fake news is that people cannot tell where the news
they are reading is coming from. The web does not make it easy to know what type of instution
a web site is tied to.

> 
> Kirsty
> 
> 
> From: Smart <smart-bounces@irtf.org> on behalf of Henry Story <henry.story@co-operating.systems>
> Sent: 14 December 2018 13:33:30
> To: smart@irtf.org
> Subject: [Smart] Epistemology in the Cloud
>  
> Hi folks,
> 
>         this group was started following a thread I started on IETF
> SAAG mailing list this summer. I had to write up my second year PhD 
> report, and move apartments in the mean time, so I have not yet been 
> able to follow the activity here, but will have time now.
> 
> My paper was published at the International Semantic Web conference
> and I put it online here:
> 
>   https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmedium.com%2F%40bblfish%2Fepistemology-in-the-cloud-472fad4c8282&amp;data=02%7C01%7Ckirsty.p%40ncsc.gov.uk%7Cb8f1af6d83a14a59f7ad08d661c8c5aa%7C14aa5744ece1474ea2d734f46dda64a1%7C0%7C0%7C636803912285466919&amp;sdata=iN5BTpiUrD%2FTFyOZShwANcNPH0rEnvLm2H1dlBqWaUc%3D&amp;reserved=0
> 
> with a number of follow up blog posts.
> 
> I would be happy to try to adapt this paper to get it published
> somewhere that could start a discussion with people involved in
> thinking about security issues - I am trying to make semantic web
> and security folks meet, which is about as difficult as getting
> hippies to work with army folks. :-) If you have ideas what would be
> the best place to do that I'd be happy to try. And of course I'd 
> be happy to know that questions this paper raises in this community
> so that I can try to address them.
> 
> 
> Sincerely,
> 
>   Henry Story
>   https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fco-operating.systems%2F&amp;data=02%7C01%7Ckirsty.p%40ncsc.gov.uk%7Cb8f1af6d83a14a59f7ad08d661c8c5aa%7C14aa5744ece1474ea2d734f46dda64a1%7C0%7C0%7C636803912285466919&amp;sdata=2KIcrdke%2BDSigWq%2Fn754ultFa2VXUMpZFBEs1TqWc0A%3D&amp;reserved=0
> 
> -- 
> Smart mailing list
> Smart@irtf.org
> https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.irtf.org%2Fmailman%2Flistinfo%2Fsmart&amp;data=02%7C01%7Ckirsty.p%40ncsc.gov.uk%7Cb8f1af6d83a14a59f7ad08d661c8c5aa%7C14aa5744ece1474ea2d734f46dda64a1%7C0%7C0%7C636803912285466919&amp;sdata=1JyxOFlO47rpe4qWQlkeAsHWagFr899PbbbBs3PKh10%3D&amp;reserved=0
> This information is exempt under the Freedom of Information Act 2000 (FOIA) and may be exempt under other UK information legislation. Refer any FOIA queries to ncscinfoleg@ncsc.gov.uk