So the topic of our panel is Truth, Trust, and Identity in an AI-Powered World. Who do you believe? So maybe we'll just start with a quick round of introduction. Could you please tell us who you are and what's your cloud in this area? Sounds good. Okay. I'm Patrick Parker. I'm the CEO and founder of EmpowerID and work a lot on automation, IGA, and AI security. My name is Rolf Lindemann. I work for Nok Nok, which is one of the founding members of the FIDO Alliance.
We work especially in the authentication space to make authentication more secure and, as I said, so much more secure that it's not practical to detect anymore. Hi. Shigeya Suzuki, Keio University.
Also, I'm a chair of the technical development of originator profile technology, just as I described. Okay, awesome. So every time there is a discussion about trust and truth on the internet, there are always like two pictures on two ends of the spectrum. On the one end, you have the famous meme of, on the internet, nobody knows you're a dog. The complete anonymity, if you will. On the other end, we have this dystopian future with chips implanted into everyone's brains, and you're basically always identified by the big brother. The reality is hopefully somewhere in between, but where exactly?
Like, where are we going to in the next five years, say? What's your opinion on those developments? I'd say it's, I mean, it's going to vary depending upon what you're doing.
If you're, you know, browsing the web, social media, I think it's going to be everybody could be a dog on the other side of it, because most people there are selecting the sources that show them the information they want to see anyway, so they're not really looking for fakes. If the fake confirms their bias, then they're okay with that.
Now, no one wants fakes when you're doing online transactions, when you're doing banking, when you're dealing with your health information. So I think in those cases, we're going to be a lot more toward the big brother, but not in a bad way.
You know, wallets, government standards, proof of identity, that type of thing. Yeah, for me, that's a very interesting question. How do we get there, and what is the balance we are willing to accept as a society? And especially as we heard when browsing the internet, to build your mind, right, to come up with something you think you are relying on information, and that always, if you read anything, it will influence the way you think about things, right? It could influence you in a good way, and it could influence you in a bad way, and it could maliciously try to influence you in a bad way.
Now, this is where accountability is, in my opinion, required even more, and that is where AI really has a bad influence on that. And for me, it helps to have an analogy to the non-digital world, right? So how was the world before we had the internet?
Sure, you would meet people, but over time, you would learn who those people are, right? So, meaning, you as a person, you would know whether this is a new person, and you had no idea what they are, and how you might want to rely on them, or trust them, or really believe what they say, whereas the other ones, where you had to say, okay, now I build a relationship, a trust relationship, for years, and that will not change quickly. And you had media, and way back, all media was government regulated, right? We kind of forget about those, but newspapers, they had some transparency rules, right?
They had to abide to specific rules, broadcasting companies were regulated, there were government companies in early times, right, if you go 60, 70, 80 years back, right? And that also had a bad impact, so now we need to find a new balance, and the new balance is, the internet doesn't forget, right, and it's global. In the past, if something went wrong, horribly wrong, you would move to a different city and could have a fresh start, right? In the internet, you don't have that, right? You can't move to another planet, which has a different internet, right, where you could have a fresh start.
So it's a different environment, and that needs a different responsibility for us to deal with it. Two things came into my mind, and the first thing is that we are, of course, living in a physical world, and still using papers, cards, and such kind of thing. And we now have our own computer, using the internet, and we have a digital world. That is totally different from our physical world. And since the inception of the internet, and also, like, starting the introduction of the browser, we gradually shift what we are in the physical world into the digital world.
So we are kind of expecting that some of the digital world mimics part of the physical world. But when we are discussing lately about how we treat the digital certificate and the physical paper-based certificate, when we are looking at these two, when we are discussing about the digital certificate, we are too much referencing to the actual paper world thing, use cases, or requirements, or such kind of thing. So paper-based certificate can be copyable.
Of course, this data is copyable, but that copy is happening in a very different way. So we need to treat these two very carefully, but we do not know well enough about the digital world yet. So we may need to transform the digital world in a different way to achieve maximum usability and safety in the future. The second thing is that when I was discussing about the digital identity to the public information dissemination, I was thinking that establishing and verifying the digital identity, the first thing, and communicating these two is an essential part of the thing.
But in the last few years, we are seeing that quick, multiple evolution of the AIs. I think that we need to think about, we need to create a digital self and to act as much like an agent. Many people are discussing about that, but we need to seriously think about it. And of course, we need to think about how we are going to implement that in the browser.
But as in our previous discussion, the browser was interesting, but we probably do not want to provide our detailed information to the browser, but actually the person who really needs the information directly, not by depending on the browser security, I think. So that is the thing I thought. Okay. So just earlier, we had a question. So do we maybe need two different internets? One is for the anonymous stuff and the other one for highly regulated and important things. But obviously, this will never work. But is there a way to combine those two?
Maybe like to add a uniform identity layer, like a meta internet with strong identities? Is there any other way to enforce this kind of on the technology level? I think there is one more aspect here. If you think about scalability, scalable business model, what does that mean? It typically means you have fixed cost and you do not have variable cost. A scalable attack is where you have a fixed cost, maybe a million to run a phishing toolkit, but no cost per attack target. So what is the analogy here? If I want to send you a spam letter, that is real cost for me per target.
Just a sheet of paper, the envelope, and I have to spend some money for the post to get it transported to you. If I do that on the internet, it is for free. Someone else is taking the cost. This moves the balance. Now it is very easy to scale a certain type of attack. Spreading misinformation is for free. Before the internet, it was not for free. Sometimes there are alternative measures to just the total control, which sometimes we want to get to. Just by switching it a little bit, make it not zero cost per target. Make it a very small fraction of a penny or a cent cost per target.
I would argue that would change. You would have significantly less spam mails than you get today. Sometimes there are very interesting, surprising solutions, which we could find as well. I don't have the best answer to that, but I think there are good ways. We need to really use our intelligence to find good solutions. They will likely differ on different levels. I don't understand anything political, but I think the best way to stop deepfakes and dissemination of false information is really you have to be able to identify it and flag it.
The points at which you can identify and flag it is where you have enough data for AI to analyze it, and the patterns of how it's being distributed in the sources to detect that it's likely false information, misinformation, etc., which would put the burden or the onus on the social media providers. There was some headway where they were starting to flag information as false. I think that would overall improve the entire system, the accuracy, the truthfulness of the information, but recently that's been rolled back in the name of free speech.
I think we're going backwards on that instead of making forward progress. Which is true. On the other hand, it's sometimes difficult to rate it in a true or false thing. Sometimes information is just new. It's not verified yet. We don't know whether it's true or whether it's false. It's just a bold claim. Maybe research will find over time that this is really true or false. So there is a gray zone in addition to that.
But you'll never have enough data at the endpoints to detect that accurately, only in the source system where you have all of that signal, all of those patterns for the same bit of information. You'll never accurately be able to stop it quickly. It really has to happen there. Now you have to get to all these sources, right? But the Internet makes it difficult because there may be some sources which are regulated, and by that regulation, but there might be sources from other places on the planet, right, which are not regulated yet, different legislation.
And they might still feed into that, which makes it – I'm not saying it's impossible. I'm just saying this is not an easy thing to do because it needs to be a global approach. It cannot be a regional one to really work.
Sure, but most of the traffic goes through a few sources. There is an aggregation point where it goes through X, it goes through Facebook, it goes through Insta.
So, I mean, if you could make a huge 80-20 rule, 80 percent of the progress, if you could stop it at those key points. The question is can you actually delegate this kind of level of trust to a single entity, especially if you know it is an entity owned by or affiliated with a certain political power? Or should it be a community effort, or should it be like an independent, traditionally trusted institution like those Japanese associations of editors? What would work?
So, interesting part of the discussion is that I actually am working on two types of disinformation, misinformation projects, and one of them is an original profile, which is focusing on who is sending this data. And the other one is how we can achieve, decide the correctness of the information provided by a multiple way to analyze the data itself.
So, it has a different approach. And I think it is very challenging to judge just by its information with using some sort of algorithm. Since the truth is different among people, I think. And part of the problem is that how the trust work is very difficult. But we are really relying on the multiple information from multiple sources to decide on whether this thing can be trustable or not.
So, some of them can be provided by the very trustable sources. For example, if you trust the government, the information provided by the government, then it is trustable. But if we meet today, then whether you can judge. What I'm saying is whether it is trustable or not.
Of course, you can judge today, right? So, you need to watch out for me and how I behave, for example. Looking at that kind of information, correcting my information, then we decide whether this information source is trustable or not.
So, it's not simple. So, I think the reason why we are really looking at the originator's information is that that is the kind of information we can make trustable in a deterministic way.
So, of course, that is not the complete answer. But that is one of the ways to at least extend the area of potential trustable information. That is what we are looking at. And maybe one more aspect regarding social media. That's an interesting debate whether they are a news source, which is regulated, or just a transport mechanism, meaning like a telco. They have to be neutral. They have to send everything through, which is kind of an interesting question because now no one is responsible, right? I'm just publishing this on this social media channel.
So, how would I know how many people are reading that? And they are just transporting whatever information to someone else. They cannot be regulated either. But I'm not a company. I'm just an individual sitting somewhere on the planet or, I don't know, in a plane.
As I say, it's difficult to regulate. Sometimes there are formal rules which are in the way, but it's at least different from the non-digital world. And we haven't found new rules to get it under control. The important thing is that when you trust something, usually you trust the behavior of this person, for example. Then the behavior is constrained by regulation, potentially, or the commitment as a journalist, for example.
So, there is a way to adjust the behavior of the entity by some restriction or self-commitment or regulation or whatever. Then, if that kind of information, like a commitment to journalism or regulated by government, this entity can be easily distinguishable from the other party who do not have a commitment or regulation from the third party, for example. Which only leaves us with the challenge, is that flag that I see as a user, is that meaningful to me or do we need mechanisms? Let me distinguish that.
I think the experience we had with the lock, the browser would show for the different certificate types, EV as one and the others, that was not successful. People don't pay attention. They don't understand what they are doing. They don't understand.
So, a trust signal in some way is not very meaningful, especially if attackers could just mimic that. And so, we might need to find other ways for dealing with that. Especially user interface-wise. I think once they're so large, they serve a public service or like a public utility, there has to be a willingness to hold them to some standards, a do-no-harm standard at least. I think so. Even though they're private companies. And maybe they are not just a communication company, right? They are really a news company. I think they have a burden of responsibility because of the power there.
But that's a discussion. It's a political discussion in the end.
So, if the only thing I've learned now is that this traditional way of building a trust profile for every person I meet, it's very difficult. It's very unpredictable. And it doesn't scale very well. I've met a few hundred people just this week here. I already forgot probably half of them, unfortunately. Sorry. Can it be delegated to an AI, though? For example, let's say Siri. Should I trust Patrick Parker?
I think eventually everyone will have an AI personal assistant that will be a lot smarter and have access to more information in a quicker time period to try to help us judge the realness, liveness, humanness of who we're interacting with, for sure. It would be interesting to be the provider of that system. You would get a lot of information. Which opens another interesting question. How much do we want to rely on those public sources? But I would agree those things will happen. It's just that that has another impact.
And to get back to the arms race versus leapfrog, it doesn't get us out of the arms race. It still leaves us here. There might be some tools. And those tools will be misused. And who has control of that? It might skew the answers just a little bit to get us into a different decision or a different route. To get that under control will be a long-time effort. And I think it has just started. So the arms race on AI is on. It's already on. And we will have to live with that. Future conference talks for you. Definitely.
Yeah, AI, as I mentioned, we need to develop some kind of agent. And since AI will be very useful when the agent knows about me as far as possible. But that means that we need to disclose everything to the AI agent. So how to control that privacy of the AI agent in a meaningful way to protect the AI agent, also do not allow the AI agent to leak any information of me, is a really challenging thing. And I'm looking forward to seeing such kind of technology. So I think we have to focus on the things which are easier to decide at this stage.
For me, that's the authentication space. That's the identification space. Maybe who's the originator of information? Maybe that's an easier problem to tackle. And the other generic, do I trust a person or not, might be a thing which is not up for regulation at technology solutions at this stage. We have to focus on the others to make at least the business work in the Internet in a more reliable way and get cybercrime under control a bit more. Definitely.