Federated Reputation

Although I find the “trusted forums” approach interesting and useful, I also see a potential security issue, where attackers would target less policed “trusted forums” to gain access to their actual target – where they could not gain access directly. So if we are to implement such a transitive trust mechanism, it should not be easily traversable and should come with a strong retaliation mechanism that would suspend an aggressor across instances: I see this as a hard constraint that would add a fair amount of complexity, and would better be left for a second phase of development.

OTOH it would (seem to) be easier to maintain a private list of trusted forums where the remote reputation of a member on each of these forums would reinforce its status locally. Maybe the concept of trust levels could be extended to instances as well as users? If an instance, say Meta, has a TL3, then people coming from there could have TL2 initially, with a decay factor if the user does not participate ; this adds another layer of complexity, but I am thinking aloud and wanted to sketch some alternative possibilities to trusting whole instances.

I agree on the discretion regarding who is using which instances. It should be taken into account, although publishing to public instances may be equivalent to publishing the fact you’re using them anyway ; this may apply to private boards though.

2 Likes