<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>delirandom</title>
	<atom:link href="http://www.delirandom.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.delirandom.net</link>
	<description>on the doubt: encrypt it!</description>
	<lastBuildDate>Tue, 11 Oct 2011 23:28:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>feedbacks and pertinence value in whistleblowing environment</title>
		<link>http://www.delirandom.net/20111012/feedbacks-and-pertinence-value-in-whistleblowing-environment/</link>
		<comments>http://www.delirandom.net/20111012/feedbacks-and-pertinence-value-in-whistleblowing-environment/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 23:22:55 +0000</pubDate>
		<dc:creator>vecna</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[globaleaks]]></category>
		<category><![CDATA[anonymity]]></category>

		<guid isPermaLink="false">http://www.delirandom.net/?p=348</guid>
		<description><![CDATA[In the last week I&#8217;ve worked on a pretty relevant feature in GlobaLeaks. I believe that dedicating a blog post to explain this feature could be useful. The problem faced was one of the most relevant in any whistleblowing platform: &#8230; <a href="http://www.delirandom.net/20111012/feedbacks-and-pertinence-value-in-whistleblowing-environment/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In the last week I&#8217;ve worked on a pretty relevant feature in GlobaLeaks. I believe that dedicating a blog post to explain this feature could be useful.</p>
<p>The problem faced was one of the most relevant in any whistleblowing platform: &#8220;<em>how much a data receiver could trust the anonymously received data?</em>&#8221;</p>
<p>We know that if an anonymous source send a block of data, it can either be:</p>
<ul>
<li>a person trying to hide his identity for security and privacy reasons.</li>
<li>a person who is pretending to be someone else.</li>
</ul>
<p><strong>This is an issue that we can&#8217;t allow to damage the reliability of a service like Globaleaks</strong>, which is supposed to protect the identity of the submitter (and so keeping track of anonymous submissions has to be considered a feature and NOT a problem).</p>
<p>In fact, no technological solution exists: the only way to approve anonymous material is to check the effective correlation of the data. We need to verify if the anonymous data matches with the open source intelligence available, or matches with the previously collected information, in order to insert the new data into a larger picture. If the new data fit, it could be trusted. If not, it could be dangerous. This analysis could require a lot of time by the receiver, and time is a resource not always available: a technological solution can&#8217;t solve this problem, but some technical features could be helpful in speeding up the human process.</p>
<p>Let&#8217;s make some brainstorming. Having a notice dependent from a single source document could be a dangerous exposition for the journalist or for anyone that accept to believe an anonymous source &#8220;leaked&#8221; files. [<span style="text-decoration: underline;">note</span>: <em>leaked</em> is intended for <em>stolen or loss</em>, <em>submitted data</em> mean <em>normally handled by the whistleblower</em>].</p>
<p>What can be the solution ? In the globaleaks point of view, that&#8217;s <a href="https://secure.wikimedia.org/wikipedia/en/wiki/Collaborative_filtering">collaborative filtering</a>.</p>
<p>Additionally, the amount of spam, invalid data, fake data, unbelievable data, incomplete data, could be high in an context [1] where whistleblowing could be in the hands of everyone.</p>
<p>How this collaborative filtering has been implemented ? Every receiver can express a single vote about the &#8220;pertinence&#8221; of a submitted data.</p>
<p>Globaleaks wants to be usable in every context: from &#8220;internal audit&#8221; of a corporation, to websites that complain about environmental abuse, to corrupted behavior in public agencies. The usage contexts are so different that maybe some features can be useful only in a specific implementation. Anyway, the collaborative filtering is something that we thought could be helpful in almost every usage. follow those example with us:</p>
<p><strong>Corporate internal audit</strong>: the amount of notifications can be proportionally high based on how many employees works in the company, may increase if anonymous submission are available, may increase if no strong integrity check is performed in the submitted data. The result could bring the internal audit to be overwhelmed by not so useful submissions. How those features could be helpful ?</p>
<p>The feature of the feedbacks become helpful to give an answer at the whistleblower, explain if the case could be followed, in which time and steps. The (many ?) times the whistleblowing platform role has been misunderstood, the feature could be used to give a standard polite answer.</p>
<p>The collaborative filter could be useful to implement the escalation of the submission. Maybe the internal audit manager need to be updated only when a serious event is reported, and in the GlobaLeaks software is now possible to configure that a receiver will be notified only when a Tulip has reached a certain amount of positive votes from the first line reviewers.</p>
<p><strong>Media relationship</strong>: in this context, verifying the source, collect all the possible proof before declaring a breaking news, and the possibility of exchanging information with the whistleblower are all extremely evaluable. the feedbacks mechanism, extremely similar to an anonymous comments interface, will permit to deeply explore the submitted material in order to finalize the truth.</p>
<p>In our opinion (but this is just an idea about journalism ethics with anonymous sources), the default point of view needs to be: &#8220;<strong>trust no one</strong>&#8220;.<br />
Every submitted source could be an invalid, misleading and deceptive document forged by someone that wants to abuse your media power.  A journalist that aim to guarantee a precise and correct information service can use a &#8220;leaked&#8221; information only when that could fit in the previously collected and trusted intelligence, only when different sources can approve that document and by cross checking it expose the data consistency. A collaborative interface, where the reviewer and the whistleblower could (optionally) cooperate, remaining anonymous and gradually reach the truth, is an extremely important achievement.</p>
<p>From the globaleaks point of view, we aim to provide a software inclusive of all imaginable security, privacy and collaboration features. This software has to cover every usage in the whistleblowing context, and therefore your doubts, ideas and analysis are welcome! join<br />
<a href="http://box549.bluehost.com/mailman/listinfo/people_globaleaks.org">people@globaleaks.org</a> mailing list to discuss (or cooperate, if you&#8217;re interested).</p>
<p>These features have been added in the last github commits. In these days, <a href="https://github.com/globaleaks/GlobaLeaks/commits/master">a lots of new code will be submitted</a>, stay connected! ;)</p>
<p>[1] for who have no idea of what <a title="GlobaLeaks" href="http://www.globaleaks.org">GlobaLeaks</a> aim to be: a free software able to provide a multi purpose whistleblowing platform.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.delirandom.net/20111012/feedbacks-and-pertinence-value-in-whistleblowing-environment/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

