Information Security 101 - the Rules of Thumb

James Davis james.davis at ja.net
Wed Jun 24 09:50:29 BST 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Peter Fairbrother wrote:

> "The chance of a secret being revealed is proportional to the square of
> the number of people who can access it; this is because the more
> possible suspects there are, the less each of them thinks they are
> likely to think they will be caught."

I don't see that this follows from your explanation. Isn't it true if,
and only if, your perception of the likelihood  of being caught varies
linearly with size of the group? I'm not sure that's always true. If
you're going to be this specific, there ought to be a rigorous explanation.

(I'm also confident that it's possible to design a scheme for the
sharing of secrets in which it's possible to tell who disclosed the
secret. If the group knows this ...)

James

- --
James Davis	+44 1235 822 229    	   PGP: 0x890F159E
JANET CSIRT	0870 850 2340	        (+44 1235 822 340)
Lumen House, Library Avenue, Didcot, Oxfordshire, OX11 0SG
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQCVAwUBSkHo1La926eJDxWeAQJuHAQAtrfi2nAqD25tqjfjyw7Lh0H69J3WhZta
R9Wwxh5J7FTZ2o1DruEKyPCQUxyix/8KIr4eDnqkHXbJUbgCWWuge/7ehax1sEog
rE/HTUJWdKL9NHnLP8RIHuKKd9z+vhC/MoKZUU0zBwe9vIaN8vwNpyTIfUjQBw5z
RSnPNgDiiAs=
=vrfs
-----END PGP SIGNATURE-----

JANET(UK) is a trading name of The JNT Association, a company limited
by guarantee which is registered in England under No. 2881024 
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Science and Innovation Campus, Didcot, Oxfordshire. OX11 0SG




More information about the ukcrypto mailing list