A Model for When Disclosure Helps Security: What Is Different About Computer and Network Security: Difference between revisions

From Cybersecurity Wiki
Jump to navigation Jump to search
(New page: ==Full Title of Reference== A Model for When Disclosure Helps Security: What is Different About Computer and Network Security? ==Full Citation== Peter P. Swire, ''A Model for When D...)
 
 
(3 intermediate revisions by the same user not shown)
Line 5: Line 5:
==Full Citation==
==Full Citation==


Peter P. Swire, ''A Model for  When Disclosure  Helps Security: What is Different About Computer and Network Security? '' (Journal on Telecommunications and High Technology Law, Vol. 2, Public Law and Legal Theory Working Paper Series No. 17, 2004).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID581001_code69688.pdf?abstractid=531782&mirid=1 ''Web''] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&view=&startkey=Swire:2004&f=wikibiblio.bib ''BibTeX''] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 ''SSRN'']
Peter P. Swire, ''A Model for  When Disclosure  Helps Security: What is Different About Computer and Network Security? '' (Journal on Telecommunications and High Technology Law, Vol. 2, Public Law and Legal Theory Working Paper Series No. 17, 2004).   
 
[http://www.rootsecure.net/content/downloads/pdf/disclosure_helps_security.pdf ''Web'']  
 
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&view=&startkey=Swire:2004&f=wikibiblio.bib ''BibTeX'']
 
[http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 ''SSRN'']


==Categorization==
==Categorization==
Line 12: Line 18:


==Key Words==  
==Key Words==  
 
security, free software, secrecy
''See the article itself for any key words as a starting point''


==Synopsis==
==Synopsis==

Latest revision as of 10:59, 4 June 2010

Full Title of Reference

A Model for When Disclosure Helps Security: What is Different About Computer and Network Security?

Full Citation

Peter P. Swire, A Model for When Disclosure Helps Security: What is Different About Computer and Network Security? (Journal on Telecommunications and High Technology Law, Vol. 2, Public Law and Legal Theory Working Paper Series No. 17, 2004).

Web

BibTeX

SSRN

Categorization

Issues: Information Sharing/Disclosure

Key Words

security, free software, secrecy

Synopsis

This Article asks the question: When does disclosure actually help security? The discussion begins with a paradox. Most experts in computer and network security are familiar with the slogan that there is no security through obscurity. The Open Source and encryption view is that revealing the details of a system will actually tend to improve security, notably due to peer review. In sharp contrast, a famous World War II slogan says loose lips sink ships. Most experts in the military and intelligence areas believe that secrecy is a critical tool for maintaining security. Both cannot be right - disclosure cannot both help and hurt security.

Using a law and economics approach to resolve the paradox, Part I provides a model for deciding when either the Open Source or the military/intelligence viewpoints is likely to be correct. Part II explains why many computer and network security problems appear different from the traditional security problems of the physical world. Part III applies the analytic tools developed earlier in the paper to issues including the following: the enlargement of the public domain in a world of search engines; the relationship between disclosure and deterrence; the importance of not disclosing passwords or the combination to a safe.

Additional Notes and Highlights

* Outline key points of interest