<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: The Advogato trust metric is not attack-resistant</title>
	<atom:link href="http://www.squarefree.com/2005/05/26/advogato/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/2005/05/26/advogato/</link>
	<description>Jesse Ruderman on Firefox, security, and more</description>
	<pubDate>Thu, 20 Nov 2008 08:48:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: paolo</title>
		<link>http://www.squarefree.com/2005/05/26/advogato/#comment-1365</link>
		<dc:creator>paolo</dc:creator>
		<pubDate>Thu, 02 Jun 2005 11:23:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=263#comment-1365</guid>
		<description>Google (stanford) and yahoo! (one of the author of the paper is from Yahoo!) are going for trustRank http://moloko.itc.it/paoloblog/archives/2005/04/26/from_pagerank_to_trustrank.html

However this is still a Global trust metri while I'm trying to push "local trust metrics"
see http://moloko.itc.it/trustmetricswiki/moin.cgi/LocalTrustMetric and http://moloko.itc.it/paoloblog/archives/2005/04/30/paper_accepted_at_aaai05_controversial_users_demand_local_trust_metrics_an_experimental_study_on_epinionscom_community.html</description>
		<content:encoded><![CDATA[<p>Google (stanford) and yahoo! (one of the author of the paper is from Yahoo!) are going for trustRank <a href="http://moloko.itc.it/paoloblog/archives/2005/04/26/from_pagerank_to_trustrank.html" rel="nofollow">http://moloko.itc.it/paoloblog/archives/2005/04/26/from_pagerank_to_trustrank.html</a></p>
<p>However this is still a Global trust metri while I&#8217;m trying to push &#8220;local trust metrics&#8221;<br />
see <a href="http://moloko.itc.it/trustmetricswiki/moin.cgi/LocalTrustMetric" rel="nofollow">http://moloko.itc.it/trustmetricswiki/moin.cgi/LocalTrustMetric</a> and <a href="http://moloko.itc.it/paoloblog/archives/2005/04/30/paper_accepted_at_aaai05_controversial_users_demand_local_trust_metrics_an_experimental_study_on_epinionscom_community.html" rel="nofollow">http://moloko.itc.it/paoloblog/archives/2005/04/30/paper_accepted_at_aaai05_controversial_users_demand_local_trust_metrics_an_experimental_study_on_epinionscom_community.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Brubeck</title>
		<link>http://www.squarefree.com/2005/05/26/advogato/#comment-1330</link>
		<dc:creator>Matt Brubeck</dc:creator>
		<pubDate>Fri, 27 May 2005 18:15:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=263#comment-1330</guid>
		<description>Ah, that's right.  Nice work!</description>
		<content:encoded><![CDATA[<p>Ah, that&#8217;s right.  Nice work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesse Ruderman</title>
		<link>http://www.squarefree.com/2005/05/26/advogato/#comment-1329</link>
		<dc:creator>Jesse Ruderman</dc:creator>
		<pubDate>Fri, 27 May 2005 17:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=263#comment-1329</guid>
		<description>Matt, I think my attack still works even if the confused nodes can only be made to trust bad nodes (rather than any nodes the attacker chooses).  Instead of making the expensive confused node trust the cheap confused nodes directly, the attacker would make the expensive confused node trust one of his nodes, which would in turn trust each of the cheap confused nodes.  This makes the attack more expensive, but not more than 4 times as expensive.</description>
		<content:encoded><![CDATA[<p>Matt, I think my attack still works even if the confused nodes can only be made to trust bad nodes (rather than any nodes the attacker chooses).  Instead of making the expensive confused node trust the cheap confused nodes directly, the attacker would make the expensive confused node trust one of his nodes, which would in turn trust each of the cheap confused nodes.  This makes the attack more expensive, but not more than 4 times as expensive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Brubeck</title>
		<link>http://www.squarefree.com/2005/05/26/advogato/#comment-1328</link>
		<dc:creator>Matt Brubeck</dc:creator>
		<pubDate>Fri, 27 May 2005 14:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=263#comment-1328</guid>
		<description>Your counterproof depends on a particular interpretation of the attack model.

It's not explicitly stated in Levien's proof exactly how much control the attacker has over "confused" nodes.  If the attacker can only convince confused nodes to trust "bad" nodes, then Levien's proof holds.  If, however, the attacker can convince confused nodes to trust arbitrary other nodes, then your proof holds.  The former assumption might be reasonable because the attacker controls the "bad" nodes, and can use their behavior to influence other users' perceptions of them; the attacker does not have the same control over perception of non-bad nodes.

Levien's proof isn't very explicit about the attacker's influence over confused nodes.  His definition of a confused node states only: &lt;i&gt;"The confused nodes themselves represent valid accounts, but may contain certificates to the bad nodes."&lt;/i&gt;  This could reasonably mean that the confused nodes are assumed to be valid in every way except for their certification of bad nodes.</description>
		<content:encoded><![CDATA[<p>Your counterproof depends on a particular interpretation of the attack model.</p>
<p>It&#8217;s not explicitly stated in Levien&#8217;s proof exactly how much control the attacker has over &#8220;confused&#8221; nodes.  If the attacker can only convince confused nodes to trust &#8220;bad&#8221; nodes, then Levien&#8217;s proof holds.  If, however, the attacker can convince confused nodes to trust arbitrary other nodes, then your proof holds.  The former assumption might be reasonable because the attacker controls the &#8220;bad&#8221; nodes, and can use their behavior to influence other users&#8217; perceptions of them; the attacker does not have the same control over perception of non-bad nodes.</p>
<p>Levien&#8217;s proof isn&#8217;t very explicit about the attacker&#8217;s influence over confused nodes.  His definition of a confused node states only: <i>&#8220;The confused nodes themselves represent valid accounts, but may contain certificates to the bad nodes.&#8221;</i>  This could reasonably mean that the confused nodes are assumed to be valid in every way except for their certification of bad nodes.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
