Sunday, 19 July 2026

In security

Every lock, by definition, must have a key, which allows its rightful owners access to the thing locked.  But after locking, there is always the danger that the key could be lost, rendering the lock worse than useless.  Worse, because the lock would not just be inoperative, failing to keep out the world as it should, it would now be turned against its very owners, refusing to acknowledge them, refusing to open.  This is the Paradox of the Lock: that by using it you may one day have it used against you.
 
The obvious remedy is to keep a spare key, separate from the first. But where? If it is kept too conveniently near to the lock, it can be found by others who will use it to open the lock.  If it is too hard to find, or too difficult of access, the lock whose main key has been lost remains effectively closed to its rightful owners.  A compromise avoiding these two pitfalls seems hard to find.

Nor is this problem one that is likely to disappear, germane only to an older society where locks played important practical and symbolic roles.  As our cities become ever more threatening, and the countryside more touched by the city, more and more people will turn to locks - several of them - and will be faced with the Paradox of the Lock several times over. 

We might look to technology to resolve this dilemma, replacing the crude mechanism of turning wards with silent, incorruptible silicon in the form of computer-controlled doors with secret passwords.  But there a different conundrum awaits us - what might be called the Pitfall of the Password.

A password is a word or phrase or collection of letters and numbers known only to you.  It is used to activate certain processes within a computer that has been set up earlier to recognise you through precisely this password.  The temptation is to choose a password that is easy to remember - your name, for example.  Except that anyone trying to gain unauthorised admittance to your computer could easily guess this.  So you may try something more obscure, something that no one else could guess.

But by definition 'obscure' in this context means not obviously connected with you.  Which means that the link between you and the word is necessarily tenuous - and hence eminently forgettable.  Just as before, the key can always be lost - but now mentally.

Once again, the solution is to keep a separate record of the password.  But as with the second key, this cannot be too near to the machine - because it will be found - nor too distant, otherwise it is effectively useless.  This is the Pitfall of the Password.

Perhaps, some might argue, there is hope beyond the physical key or the abstract password.  Perhaps a computer could be trained to recognise you just as your friends or your family do - from your face or your voice.  Although this technology will soon be with us, it does have one serious flaw.  Choosing these manifest characteristics is like brandishing a key in public, or giving the world hints about your password; it makes forgery much easier.  Ironically, the homely key, for all its problems and paradoxes, probably offers more security.  Hang on to it.

(27.12.91)

No comments:

Post a Comment

Note: only a member of this blog may post a comment.

Introduction

I published Glanglish , a collection of essays, back in 1990.  And I mean published in the traditional sense: it was a physical book – secon...