Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
Forwarded message:
Date: Sun, 18 Jan 1998 12:02:34 -0800 From: Kent Crispin <kent@songbird.com> Subject: Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
There are alternative ways of paying for the service that do not in any way depend on ecash, and after thinking about it a bit, they seem more robust, as well.
The basic idea is as follows: The fundamental eternity service is free to readers, and is financed entirely by writers. The writers supply the disk space, the network bandwidth, and possibly pay for the software to support all this.
It is clear that there are two diametricaly opposed models of payment mechanisms and who those costs should fall on; producers or consumers. I personaly have no faith in systems where the producers bear the burden of the costs since they have no clear mechanism to obtain the funds to finance the enterprise in the first place. Imagine for a moment that a couple of persons come into possession of a set of documents which would cause considerable political embarassment and legal difficulties for a head of the local government. Why should these two individuals pay to have their data dissiminated to anyone who wants it? It certainly isn't going to improve their social, political, or professional standing since the server will anonymize the data. They then have two options, release it themselves and hope for the best (and hence reap the benefit of any economic benefits that might acrue) or do nothing with it. How about information to build man portable atomic bombs? It doesn't make sense to take all those chances and the data haven operators to take the chances when they will get at most the monetary input from a *single* party. It is clear that these resources are clearly inferior to many parties paying to get the data. I guess the question boils down to why the individual operator in running the server in the first place. I assume a priori that the goal of both the submitter and the operator is to make a reliable income from the users of the service since there are clearly many more consumers of information than producers of it. ____________________________________________________________________ | | | The most powerful passion in life is not love or hate, | | but the desire to edit somebody elses words. | | | | Sign in Ed Barsis' office | | | | _____ The Armadillo Group | | ,::////;::-. Austin, Tx. USA | | /:'///// ``::>/|/ http://www.ssz.com/ | | .', |||| `/( e\ | | -====~~mm-'`-```-mm --'- Jim Choate | | ravage@ssz.com | | 512-451-7087 | |____________________________________________________________________|
Jim Choate <ravage@ssz.com> writes:
Kent Crispin <kent@songbird.com> writes:
Subject: Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
There are alternative ways of paying for the service that do not in any way depend on ecash, and after thinking about it a bit, they seem more robust, as well.
The basic idea is as follows: The fundamental eternity service is free to readers, and is financed entirely by writers. The writers supply the disk space, the network bandwidth, and possibly pay for the software to support all this.
It is clear that there are two diametricaly opposed models of payment mechanisms and who those costs should fall on; producers or consumers. I personaly have no faith in systems where the producers bear the burden of the costs since they have no clear mechanism to obtain the funds to finance the enterprise in the first place.
Imagine for a moment that a couple of persons come into possession of a set of documents which would cause considerable political embarassment and legal difficulties for a head of the local government.
Why should these two individuals pay to have their data dissiminated to anyone who wants it? It certainly isn't going to improve their social, political, or professional standing since the server will anonymize the data.
If the would be disseminater was happy to have their name associated with the document, they could put it on their own web page. The problems may be that: - they do not want to suffer the legal and extra-legal reprisals for posting, - they have little faith in the data remaining available for long on their web page, once well resourced determined attackers try to remove it. Eternity helps here in that it obscures the poster's identity, and reduces their exposure in that they personally don't have to send as many messages. Eternity also helps ensure continued availability, at least while somebody is funding that availability.
They then have two options, release it themselves and hope for the best (and hence reap the benefit of any economic benefits that might acrue) or do nothing with it.
Releasing the data themselves is problematic. They may not wish to accept the risk. Eternity provides a way to pay someone else to take the risks in ensuring availability.
How about information to build man portable atomic bombs? It doesn't make sense to take all those chances and the data haven operators to take the chances when they will get at most the monetary input from a *single* party. It is clear that these resources are clearly inferior to many parties paying to get the data.
The users is getting value for money from the eternity servers -- the eternity server is providing the service of risk taking. It is true that someone could pay for accessing the data, and resubmit it to eternity with themselves as the beneficiary. They would likely want to undercut the price charged by the initial poster. This suggests a recursive auction market with prices falling over time. The eternity server operators win in that they are being paid for their services. The original poster possibly doesn't make that much money, but the operator could counter by reducing their prices over time to undercut other copies also. There are other ways where the submitter could get higher prices. He could for example post the data in encrypted form, and send the decryption key to a high reputation third party to verify the authenticity of the data. He could then demand $10,000 for the key. Bids would be placed by users interested in obtaining the data. When the bid price is reached the data is posted. Bids would be held in escrow by the third party. In the event that the requested price is not met the ecash could be returned to the bidders. The market will discover the value of the risk taking services provided by the eternity servers in that if the servers over-charge, users will take their own risks, by starting their own servers. If a given server under-charges, other servers will sub contract to that server. There is a risk here that the NSA may offer eternity services at prices undercutting everyone else. This risk suggests that users would not necessarily select the cheapest services. If this pattern of usage emerges, it also suggests that the NSA would better optimise their efficacy by not offering the cheapest prices. The problem of preventing eternity servers sub-contracting all their work to the cheapest eternity-server (the NSA operated servers) suggests that it may be desirable to design a system so that the poster, or some third party auditing agent is able to verify where data resides. I can not see how this can generally be achieved, because it seems difficult to verify whether a server is sub-contracting or not. So in conclusion the safest strategy seems to be to select random servers regardless of price. This results in a flat demand curve, and no incentive for servers to offer cheap service. The model is more complex that this in that there are different risk documents and this risk would affect the price a submitter is willing to pay. Adam
On Sun, Jan 18, 1998 at 02:53:54PM -0600, Jim Choate wrote:
Forwarded message:
Date: Sun, 18 Jan 1998 12:02:34 -0800 From: Kent Crispin <kent@songbird.com> Subject: Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
There are alternative ways of paying for the service that do not in any way depend on ecash, and after thinking about it a bit, they seem more robust, as well.
The basic idea is as follows: The fundamental eternity service is free to readers, and is financed entirely by writers. The writers supply the disk space, the network bandwidth, and possibly pay for the software to support all this.
It is clear that there are two diametricaly opposed models of payment mechanisms and who those costs should fall on; producers or consumers. I personaly have no faith in systems where the producers bear the burden of the costs since they have no clear mechanism to obtain the funds to finance the enterprise in the first place.
You must find the advertising business completely mystifying, then.
Imagine for a moment that a couple of persons come into possession of a set of documents which would cause considerable political embarassment and legal difficulties for a head of the local government.
Why should these two individuals pay to have their data dissiminated to anyone who wants it? It certainly isn't going to improve their social, political, or professional standing since the server will anonymize the data. They then have two options, release it themselves and hope for the best (and hence reap the benefit of any economic benefits that might acrue) or do nothing with it.
You pay to have your data disseminated in a form that you can be later paid -- for example, leave the juciest part of the data in encrypted form, along with a public key through which payment options can be negotiated. [...]
I guess the question boils down to why the individual operator in running the server in the first place. I assume a priori that the goal of both the submitter and the operator is to make a reliable income from the users of the service since there are clearly many more consumers of information than producers of it.
Why on earth do you try to be an ISP, then? You pay for disk drives for other people to store their data, and make it available to the world. The eternity service is actually very similar. Given a protocol such as I described, you could move to Data Haven Island, and charge up front to supply pornographers with an entrance to the eternity service, while John Young could wallow in righteous ego gratification as he provides space for morally important documents by donating his disk space to eternity. You do it for the money, he does it for the buzz -- there are all kinds of ways to get paid. -- Kent Crispin, PAB Chair "No reason to get excited", kent@songbird.com the thief he kindly spoke... PGP fingerprint: B1 8B 72 ED 55 21 5E 44 61 F4 58 0F 72 10 65 55 http://songbird.com/kent/pgp_key.html
The basic idea is as follows: The fundamental eternity service is free to readers, and is financed entirely by writers. The writers supply the disk space, the network bandwidth, and possibly pay for the software to support all this.
It is clear that there are two diametricaly opposed models of payment mechanisms and who those costs should fall on; producers or consumers. I personaly have no faith in systems where the producers bear the burden of the costs since they have no clear mechanism to obtain the funds to finance the enterprise in the first place.
Assume the existence of a for-profit service provider. The service provider needs to cover the costs of the service, plus enough profit to make the effort interesting. The prices charged need to reflect the costs (or be higher) or the service provider can't make money and goes out of business. So what are the costs, and who can be talked into paying for them? 1) Storage of information - Storage currently costs < $1/MB for raw disk, and getting cheaper by the minute, but sysadmins, lawyers, etc. cost money and they're not getting cheaper as fast. The costs of the equipment for permanent storage are probably about 10-50% more than the costs for storing for 5 years; the costs of administration (assuming inflation is limited to some small number) can be covered by an annuity. Every technology upgrade or two you need to copy the archives to new storage media, and data that doesn't get accessed often may get migrated out to slower or perhaps even offline media; storage contracts need to reflect that retrieving data that hasn't been accessed in a while may involve some delay. 2) Transmission of information - Roughly proportional to MB/time - unlike storage, this one's not predictable, unless the provider and author agree in advance (e.g. N free accesses per year, per password.) So the provider could charge the reader for access, or use advertising banners to fund retrieval costs (if that remains a valid model for financing the web over the next N years, especially if the readers retrieve data through anonymizers.) 3) Legal defense - This one's harder to predict :-) The current US climate is that service providers are relatively immune as long as they cooperate with subpoenas and court orders, discourage copyright violators, and avoid having legal knowledge of the contents of their sites, but that could change.
Why should these two individuals pay to have their data dissiminated to anyone who wants it? It certainly isn't going to improve their social, political, or professional standing since the server will anonymize the
If they want their names known, they can include them in the contents of the data that readers retrieve, independent of what the server does. (Of course, they can forge other peoples' names as well :-) And they can use pseudonyms, with or without digital signatures, and accumulate reputation capital under those nyms. If they want to collect money from the readers, that's independent - they may be able to include advertising, or may sell the decryption keys to the data for digicash or information using some contact mechanism, or they may just be publishing their manifestos for The True Cause. Thanks! Bill Bill Stewart, bill.stewart@pobox.com PGP Fingerprint D454 E202 CBC8 40BF 3C85 B884 0ABE 4639
participants (4)
-
Adam Back
-
Bill Stewart
-
Jim Choate
-
Kent Crispin