Web of trust has of course been tried but it never got out of the it's a geeky things for tin foil hat wearing geeks kind of corner. It may be time to give that another try.
Web of trust has of course been tried but it never got out of the it's a geeky things for tin foil hat wearing geeks kind of corner. It may be time to give that another try.
This does nothing to guarantee that the content was written or edited by a human. Because of the risk of key theft, it doesn't even guarantee that it was published by the human who signed it.
It is physically, philosophically, and technically impossible to verify the authenticity of digital content. At the boundary between the analog world and the digital world, you can always defraud it.
This is the same reason that no one ever successfully used blockchains for supply-chain authentication. Yes, you can verify that item #523 has a valid hash associated with it, but you can't prove that the hash was applied to item #523 instead of something fraudulent.
Though there are many brands built on trust, whose domain name is very difficult to spoof, that are an exception to this.
Hate on nytimes.com, but you have reasonable confidence the content on that site is written, fact-checked and edited by staff at the New York Times Company.
Like Sports Illustrated? Oh, wait...
They will probably still have human review and higher publishing standards than generic blog spam. But in just a few months or sooner you can no longer safely assume a NYT article was not written by AI.
I tear off the Scooby-Doo mask, and the person is now exposed as being a different person.
You hunt me down (somehow? magically? nothing in PK infrastructure allows this, but let's say you do it) and I say "yes, that's my PK, and yes, I signed that" but how can you then verify I didn't take it from chatGPT and sign it?
That's the entire point of cryptocurrencies. They do that as well as is possible right now in a distributed network, conceding the point about key theft.
I would argue it's not all-or-nothing. Signing would verify the the majority of content from creators that have not had their keys stolen. Adding currency/value to this equation boosts the quality further and discourages spamming "content based marketing" garbage. The obstacles are usability and behavior changes, and also that any given user can now copy/paste LLM prompt responses, of course.
Blockchain may be largely over-hyped, but from this bubble I think important research in zero-knowledge proofs and trust-less systems will one day lead to a solution to this that is private and decentralized, rather than fully trackable and run by mega-corps.
Once you have that, unsigned content or content signed by AIs is easy to spot. Because it would either have no reputation at all, or a poor one.
Signatures are impossible to forge (or sufficiently hard that we can assume so), and easy to verify. Reputations are a bit more work but we could provide some tools for that or search engines and other content aggregators could check things for us. But it all starts with a simple signature. Once you have lots of people signing their work, checking their reputation becomes easy. And the nice thing with a reputation is that people care about guarding it is as well. Reputation is hard to fake; you build it throughout your life. And you stake it with everything you publish.
There's no need for blockchains or any fancy nonsense like that. It might help but it's a bit of a barrier to taking this into use.
This is the real play IMO. With the push for identity systems that support attestation [1], it doesn't matter if AI is successful at producing high quality results or if it only ever produces massive amounts of pure garbage.
In the latter case, it's a huge win for platform owners like Apple, Google, or Microsoft (via TPM) because they're the ones that can attest to you being "not a bot". I wouldn't be surprised if 5 years from now you need a relationship with one of those 3 companies to participate online in any meaningful way.
So, even if AI "fails", they'll keep pushing it because it's going to allow them to shift a large portion of internet users to a subscription model for identity and attestation. If you don't pay, your content won't ever get surfaced because the default will be to assume it's generated trash.
On the business side we could see schemes that make old-school SSL and code signing systems look like charities. Imagine something like BIMI [2], but for all content you publish, with a pay-per-something scheme. There could even be price discrimination in those systems (similar to OV, EV SSL) where the more you pay the more "trustworthy" you are.
My fear is that eventually you'll start seeing government services where identity and auth are handed off to private companies like Google and Apple. Imagine having your real identity tied to an attestation by one of those companies.
1. https://www.w3.org/TR/webauthn/#sctn-defined-attestation-for...
My country (the UK) is one of the worst right now, with the current government on a crusade to make the internet 'safer' by adding checkpoints[1] at various stage to tie your internet usage to your real-world identity. Unlike some other technically advanced countries, though, the UK doesn't have the constitutional robustness to ensure civil liberties under such a regime, nor does the population have what I like to think of as the 'continental temperament' to complain about it.
I'd like to make a shout-out to a project in which I participate: the Verifiable Credentials Working Group[2] at the World Wide Web Consortium is the steward of a standard for 'Self-Sovereign Identity' (SSI). This won't be able to fix all the issues with authenticity online, but it will at least provide a way of vouching for others without disclosing personal information. It's a bit like the GPG/PGP 'Web of Trust' idea, but with more sophisticated cryptography such as Zero-Knowledge Proofs.
[1]: https://www.eff.org/deeplinks/2023/09/uk-online-safety-bill-...
One enticing alternative (for the government!) is to require you to upload your actual documents and use some government sanctioned attestation service.
In theory. in practice there are 3 competing online ID systems within the Spanish government, which is pretty typical beaurocratic bullshit
a general taste for dysfunctional public-private partnerships and the fact that auth is a seriously hard problem at scale, make this scenario a few percentage points more likely than anyone should feel comfortable with.
They do.
So…the current system?
My impression of Flat Earthers, is that a lot of them are indeed authentic.
Funny.
Has it ever been anything else?
Don't feel sorry for people that has no ability to be authentic. They try to hard.
Don't try.
We have found a way to mathematically determine the veracity of Internet information and have developed a fundamentally new algorithm that does not require the use of cryptographic certificates of states and corporations, voting tokens that can bribe any user, or artificial intelligence algorithms that are not able to understand the exact meaning of what a person said. The algorithm does not require external administration, review by experts or special content curators. We have neither semantics nor linguistics — all these approaches have not justified themselves. We have found a unique and very unusual combination of mathematics, psychology and game theory and have developed a purely mathematical international multilingual correlation algorithm that uses graph theory and allows us to get a deeper scientometric assessment of the accuracy and reliability of information sources compared to the PageRank algorithm or the Hirsch index. The algorithm allows betting on different versions of events with automatic determination of the winner and allows to create a holistic structural and motivational frame in which users and news agencies can earn money by publishing reliable information, and a high reputation rating becomes a fundamentally new social elevator.
CyberPravda mathematically evaluates the balance of arguments used by different authors to confirm or refute various contradictory facts to assess their credibility, in terms of consensus in large international and socially diverse groups. From these facts, the authors construct their personal descriptions of the picture of events, for the veracity of which they are held responsible by their personal reputations. An unbiased and objective purely mathematical correlation algorithm based on graph theory checks these narratives for mutual correspondence and coherence according to the principle of "all with all" and finds the most reliable sequences of facts that describe different versions of events. Different versions compete with each other in terms of the value of the flow of meaning, and the most reliable versions become arguments in the chain of events for facts of higher or lower level, which loops the chain of mutual interaction of arguments and counterarguments and creates a global hypergraph of knowledge, in which the greatest flow of meaning flows through stable chains of consistent scientific knowledge that best meet the principle of falsifiability and Popper's criterion. A critical path in the sequence of the most credible facts forms an automatically generated multi-lingual article for each of the existing versions of events, which is dynamically rearranged according to new incoming evidences and the desired credibility levels set by readers in their personal settings ranging from zero to 100%. As a result, users have access to multiple Wikipedia-like articles describing competing versions of events, ranked by objectivity according to their desired level of credibility.