Discussion about this post

User's avatar
John Wunderlich's avatar

Your comment about more identity <> more security reminded me of something that Bruce Schneier wrote years ago. Paraphrasing, he said that we don't need to know anything ABOUT the person sitting next to us on the plane (i.e. identity attributes). All we need to know is that they are not carrying explosives or weapons.

Expand full comment
James Bonifield's avatar

Totally agreed with those observations. Your point on the “more identity != more security” I think takes on another layer of meaning in a world captivated by LLMs.

With these models being stochastic in nature, I think we are at risk of drifting even further away from a clear, deterministic way of enforcing and managing access/AuthN+AuthZ, and if the solution to this problem relies to heavily on purely AI (at least as we currently understand it) we are at risk of adding an unauditable and unaccountable piece to this quagmire

Expand full comment
5 more comments...

No posts