Trust, but Verify

Trust, but Verify

Update: 2021-10-01
Share

Description

In this episode of Beneficial Intelligence, I discuss trusting your vendors. You trust them to make their best effort at producing bug-free code. You probably trust that their software will perform at least 50% of what they promise. You might trust them to eventually build at least some of the features on their roadmap. But can you trust them to not build secret backdoors into the software they give you?

Snowdon showed we cannot trust any large American tech company because they send our data straight into the databases of the National Security Agency. Apparently, you cannot trust Chinese smartphone vendor Xiaomi. The Lithuanian National Cyber Security Centre just published the results of their investigation, and they recommend that people with such phones replace them with non-Xiaomi phones "as fast as reasonably possible."  

It turns out these phones send some kind of encrypted data to a server in Singapore, and that it has censorship built in. Phrases such as "Free Tibet" simply cannot be rendered by the browser or any other app. Right now, that feature is not active in Europe, but it might be enabled at any time.  

During the nuclear disarmament discussions between the United States and the Soviet Union in the 1980s, Ronald Reagan was fond of quoting a Russian proverb: Doveryay, no proveryay - Trust, but verify. The ability for both parties to verify what the other was doing became a defining feature of the eventual agreement. 

In software, we can verify Open Source. If you cannot find open source software that does what you need, many enterprise software vendors will make their source code available to you under reasonable non-disclosure provisions. 

In your organization, there should be both trust and verification. Don't simply trust your software vendors. Trust, but verify. 

 

Beneficial Intelligence is a bi-weekly podcast with stories and pragmatic advice for CIOs, CTOs, and other IT leaders. To get in touch, please contact me at sten@vesterli.com

 

Comments 
In Channel
People Shortage

People Shortage

2021-11-2605:43

Data Hoarding

Data Hoarding

2021-10-2907:29

Monoculture

Monoculture

2021-10-1509:04

Trust, but Verify

Trust, but Verify

2021-10-0109:34

Time to Recover

Time to Recover

2021-09-1708:28

Goal Fixation

Goal Fixation

2021-09-0309:10

Narrow Focus

Narrow Focus

2021-08-2008:28

Back to the Office

Back to the Office

2021-08-0608:38

Humans and Computers

Humans and Computers

2021-07-2306:42

Competition

Competition

2021-07-0910:18

Pseudo-Security

Pseudo-Security

2021-06-2507:53

Good Enough

Good Enough

2021-06-1807:55

Unnecessary Roadblocks

Unnecessary Roadblocks

2021-06-0409:08

Expectation Management

Expectation Management

2021-05-2807:50

Gaming the Metrics

Gaming the Metrics

2021-05-0710:31

Accidental Publication

Accidental Publication

2021-04-3007:55

Irrational Optimism

Irrational Optimism

2021-04-2308:05

Risk Aversion

Risk Aversion

2021-04-1605:23

Biased Data

Biased Data

2021-04-0907:29

loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Trust, but Verify

Trust, but Verify

Sten Vesterli