top of page

Authority Is Not a Security Control


Audio cover
Authority

I've always had a weird relationship with authority.


Not necessarily a bad one.


Just... peculiar.


And after writing the Flock piece, there's one more part of this I need to get out of my head before I can leave it alone.


It's not really about Flock. It's about authority itself.


More specifically, the weird little trick we all play where we know perfectly well that people abuse power, but the second somebody is officially authorized, we start pretending that somehow answers the trust question.


It doesn't.


Nobody seriously believes every cop is incapable of committing a crime. Nobody believes every government employee is automatically honorable. Nobody thinks every executive, doctor, prosecutor, judge, administrator, contractor, or person with privileged access always behaves exactly as intended.


We know better. We absolutely know better.


We just selectively forget it when the institution feels legitimate enough.


Authorization is permission, not character.


A badge means someone has authority. A clearance means someone has access. An administrator account means somebody has privilege. A title means somebody gets to make certain decisions.


That's it.


None of those things tell you whether the person is honest.


Or competent...Or careful...Or angry...Or desperate...Or vindictive...Or compromised..And there's another part we tend to skip: power itself changes the environment around the person holding it.


People listen differently. People challenge you less. Doors open. Rules start feeling a little more flexible. And it can become surprisingly easy to stop asking "should I do this?" and start saying "I have a reason."


We've been fascinated by this forever. The Stanford Prison Experiment became famous largely because of the idea that ordinary people placed into positions of institutional power could begin behaving very differently. The experiment itself is controversial as hell — serious methodological problems, disputed conclusions, failed replication attempts — so I'm not holding it up as holy scientific proof of anything.


But the reason the story stuck in the culture for fifty years is pretty obvious.


Nobody finds the underlying idea unbelievable.


Give people power and some percentage of them will get weird with it.


Give a ten-year-old a thousand dollars and see what happens.


Actually, don't.


But you get the point.


We grow up. Hopefully we gain judgment, discipline, restraint and experience.


The underlying human machinery doesn't get replaced.


Your office already understands this.


Think about your IT department.


They make you use passwords. Then apparently your password isn't good enough anymore, so now you need MFA. Your computer locks itself. Your account has permissions. Certain things need approval. Admin activity gets logged.


Sometimes entire privileged sessions get recorded.


Why? Because IT hates you? No. Well. Some of you, yes.


Some of you are absolutely loathed by IT, and you know exactly who you are.


But that's not why the controls exist.


They exist because access creates risk.


And generally, the people with the most access get the most controls wrapped around them.


Nobody says "he's the administrator, he's authorized, we don't need to monitor him."


That would be insane.


He's exactly the guy you monitor.


Not because you're accusing him of anything.


Because if he screws up, gets compromised, gets angry, or decides the rules don't quite apply to him today, the blast radius is huge.


That's such a basic concept in IT that nobody even debates it.


Then somehow government gets a hall pass.


Someone gets access to a powerful government system and suddenly: "They're law enforcement."


Okay. And?


That explains why they got access.


It doesn't explain why I should assume they'll never misuse it.


Those are completely different questions.


And somehow saying that out loud gets interpreted as anti-law-enforcement.


It isn't.


If I give somebody enormous authority, I want enormous accountability wrapped around it.


That should be the pro-institution position.


Good institutions shouldn't require us to believe every person inside them will remain awesome forever.


That's not a control.


That's hope.


A badge isn't MFA.


This may be the easiest way to say the whole thing.


An oath isn't encryption.


Training isn't least privilege.


A policy isn't an access control.


A title isn't competence.


And a badge isn't MFA.


Those things establish duty and permission.


They don't magically prevent abuse.


We already understand this everywhere else.


The trusted user is still a threat.


One of the oldest lessons in computing is that the person already inside the system can be more dangerous than the person trying to break in.


The outsider has to get through the wall.


The insider is already standing in the server room.


That doesn't mean every insider is bad.


It means being inside doesn't make someone safe.


So when we build something capable of tracking people, searching movements, accessing sensitive records, or exercising state power, the words "authorized user" shouldn't make us relax.


They should make us ask: who is this person? What exactly can they do? What gets logged? Who reviews it? Can they erase it? Can they share credentials? Can they search without a legitimate case? And what actually happens when they abuse it?


Those aren't radical questions.


They only sound radical because we've gotten strangely comfortable not asking them.


The more power, the more scrutiny.


I think we've got this backward.


The more authority somebody gets, the more deference they tend to receive.


From a security standpoint, it should go in the opposite direction.


The more power somebody has, the more visible the exercise of that power should become.


Financial systems? Logged.


Medical records? Logged.


Root access? Logged.


Government surveillance? You're damn right it should be logged.


Not because we presume guilt.


Because the blast radius matters.


That's the whole idea.


And that's really all I wanted to get out of my head.


This isn't anti-authority.


Civilization needs authority.


It's anti the idea that authority itself proves the person holding it is safe.


It doesn't.


We know it doesn't.


We've always known.


We just get weirdly polite about saying it.


So maybe the rule really is this simple: authority is not a security control.


And the more authority we hand someone, the less we should ever rely on trust alone.


Rich Washburn is a technologist, strategist, and Founder & Chief AI Architect of ARIA AI Labs, working at the intersection of AI, infrastructure, communications, and capital. He also serves as Managing Partner and Chief AI Officer at Eliakim Capital.

Comments


Animated coffee.gif
cup2 trans.fw.png

© 2018 Rich Washburn

bottom of page