→ Notes
Community · · 10 min read

Security by obscurity vs Security by Design

Personal background

(Feel free to skip to the next section without losing any content.)

Late in the 1990s, I turned to Bhakti yoga and Karma yoga. My family and friends thought, and worried, that I would become a sanyasi. Later, in the 2000s, I turned into a software professional. To my family and friends, it looked like a stark contrast, a shift they were really happy with; it gave them peace of mind that I was getting grounded in the “normal” world.

But to me, personally, it didn’t feel like a difference or a directional change in my life. I was always able to see the connecting thread between Bhakti yoga and Karma yoga and the open source software world that I engaged with over the last two decades. Sure enough, my venture into the open source software world was an “accident” (I didn’t plan it) but as Master Oogway says, “There are no accidents.” I learned and saw in action a lot of “spiritual” lessons from the open source community (the way people interact with each other) and from the open source design mindset (how systems are designed and developed). I would like to share one such value and practice from the open source community that we need in our own community: transparency.

Transparency

A few months ago, our previous BCC members wrote to the community saying that they declined to provide “data about the current budgets and personal Maintenance disbursements with names”:

We were not comfortable providing such data to a body whose right to request it was not established, and whose intentions were not disclosed.

Before I go further, let me pause to clarify: this is not about the individual members of the previous BCC. I do not know most of them personally, and what follows is not about them individually. On top of that, I’m simply picking this up as a recent incident from my memory that is convenient for illustrating and relating to a larger culture, not trying to nitpick this specific incident alone. So read everything below as text that illustrates a larger problem through a specific incident, rather than sticking to the incident itself. It must also be noted that the previous BCC was the first to come up with a public dashboard of income and expense stats: a great first step towards transparency. So let’s proceed with this mindset.

The BCC Mandate 2018 starts with three guiding principles. The third one reads:

c) Ensure transparency, accountability and proper utilisation of the City Services budget.

As transparency is one of the three guiding principles, someone, or some group, who drafted the mandate placed a high level of importance on this value. Thanks to this anonymous X.

Now, going back to the previous BCC statement about declining to provide data, let’s ask what was asked, and what reason was provided to refuse the request.

What was asked

data about the current budgets and personal Maintenance disbursements with names

It means:

  • The data about how much each of the 100+ services in Auroville that are supported by BCC got as their current budget to run their service.
  • The data about who the working people in these 100+ services are who get maintenance from BCC, and how much they get, whether full maintenance or half-maintenance, etc.

What was the reason to refuse?

Three reasons were cited to refuse the data, and to me they reveal a larger problem than this specific incident. Do we, as a community, have a shared understanding of what we mean by transparency when we put “transparency” as one of the three guiding principles of the BCC Mandate?

“Not comfortable.” I do not see anything uncomfortable with the request per se, but, still honouring the judgement of the team, I would like to say that being transparent means we share data that is both “comfortable” and NOT comfortable to share. That’s the basic tenet of transparency. That’s why being transparent is very difficult. Otherwise, the world would be transparent with no effort of our human will.

“Whose right to request it was not established.” Who is asking for the data? It’s the FAMC. Who are these members of the FAMC? These are Aurovilians living here like everyone else, paying a monthly contribution to the city both as individuals and as the businesses they manage (where applicable). Are we saying that a resident who pays contributions, both as an individual and as the business they manage, has no right to know how their money is utilised? In the first place, why not make it available to every Aurovilian, so it’s not a matter of “can I share with this group or not?” It’s available to all.

“Whose intentions were not disclosed.” Here again we break the basic tenet of transparency. A system that is transparent should not depend on inspecting the intentions of the requesting party for its security. We should depend on the values we hold and the honesty in our system as our security, and not depend on selective sharing as a means to security.

Security by obscurity vs Security by design

In the open source world, these two ideologies are clearly named “Security by Obscurity” and “Security by Design / Open Security”. The world is already moving towards Security by Design rather than Security by Obscurity. There are enough incidents to prove that Security by Obscurity only gives a false sense of safety. Let’s imagine the following scenarios to understand these two models better.

Scenario 1: Some good X requests the XYZ committee for some information. The XYZ committee reviews the intentions of X, doubts the integrity of X, and fears that if the requested data is shared, X would cause harm. However, the real intention of X is collaboration. He wanted to see the “problems”, if any, and solve them. Because the presence of the problem was never allowed to be scrutinised, the problem continues to exist.

Scenario 2: Some evil Y requests the XYZ committee for some information. XYZ reviews the intentions of Y, but Y is very clever (as he is evil) and succeeds in masquerading his real intentions. The XYZ team feels satisfied with the false reasons cited by Y and shares the information. After receiving the data, Y finds out all the “problems”, things that can be used to point out the mistakes of individuals, units, or any group in Auroville, and uses it to cause harm. Something that X could have helped solve in the first place.

Scenario 3: Some unknown Z requests the XYZ committee for some information. The XYZ committee has always kept this data transparently available to anyone. So it has nothing to do with Z’s request, as the data is in the public domain and Z takes the data from it. Because the data had been sitting in the public domain for long, most of the issues present in it had been addressed as and when they were identified.

XYZ has nothing to worry about regarding Z’s intention, be it bad or good. If Z uses the data to do good, XYZ thanks him for doing that. If Z uses the data to point out mistakes, XYZ again thanks him, citing that it’s the culture of XYZ to take inputs from everyone to fix the issues in the system. Z has nothing to defame.

Having said this, how is XYZ responsible in Scenario 2? It should be obvious by now, but let me restate the obvious:

  • Due to the bad judgement of XYZ, they denied X, who could have helped fix the problem in the first place.
  • Due to the bad judgement of XYZ, they shared information with Y that was used to cause harm.

To be light on XYZ, we should consider that XYZ is composed only of humans, and not lie-detecting machines. So it’s obvious that XYZ can only do a best-guess job, and not an accurate assessment.

Scenarios 1 and 2 belong to the category of “Security by Obscurity”, and Scenario 3 belongs to the category of “Security by Design / Open Security”.

What is secrecy good for?

Finally, even if, for argument’s sake, we think security by obscurity (or selective sharing) is a good thing, let’s examine what it is good at securing.

In the corporate world, an individual doesn’t know the salary of their peers or their managers. Salary information is considered secret because, if it’s made transparent, the management fears it would lead to:

  • Jealousy: e.g., how is this other person getting more than I could?
  • Greed: e.g., now, knowing how much others get, I don’t feel content with what I got anymore; I need more.
  • Hatred: e.g., this other guy not only makes me work more, he gets more money than I do.
  • Fear: e.g., now others might isolate me or plot to take me out because I get more money than them.
  • Injustice: e.g., the other guy is a favourite of the manager, and he gets more money and less work.

The above are just some examples, but you get the point. Keeping salary information opaque makes life easier for the management, so they don’t have to justify why someone gets more and someone less, and it avoids all the lower emotions and feelings in their workforce.

But remember, by keeping the information secret, the problem was never solved; it was only avoided. There is no transformation of the employees by keeping the information secret. There is peace in secrecy, but is that real peace? No, it’s a “mutual fear brings peace”, as William Blake aptly puts it in his collection of poems “Songs of Innocence and of Experience”.

The benefits of this secrecy hold no good for what Auroville aspires to:

A place where the needs of the spirit and the concern for progress would take precedence over the satisfaction of desires and passions, the search for pleasure and material enjoyment.

In short, it would be a place where human relationships, which are normally based almost exclusively on competition and strife, would be replaced by relationships of emulation in doing well, of collaboration and real brotherhood.

How are we going to transform if we are still fearing the darkness and hiding it with secrecy? Sure enough, the moment we open up the gates and truly share information in a transparent manner, it’s going to open up a can of worms. But it’s something we need to deal with head on if we are to transform our lower nature.

The open source community, spread over multiple cultures and nationalities, is already breaking barriers and setting a new culture of transparency, both in knowledge sharing and in financial management. The knowledge (IP) behind Babel (a critical software tool for modern software development), the budget of the organisation, and even what an individual developer was paid for a specific month, are all openly available for anyone to look up.

At Auroville, aiming for something beyond all this as a society, can we take some inspiration from them?

Finally, I would like to end my long note with Linus’s Law, which gives a sense of hope that being transparent will make things easier:

Given enough eyeballs, all bugs are shallow.

Linus’s Law

There is a sequel to this post: The environment a community needs for transparency.