Skip to content

Questions about Economics of security

Short answers, pulled from the story.

Who is credited with founding the field of economics of security?

Ross Anderson is widely credited with founding the field through his 2000 paper Why Information Security is Hard, which argued that security technology fails without incentives aligned to the people who adopt it. That same year, Camp and Wolfram at Harvard published a related argument that security is not a public good.

What is the Gordon-Loeb model in economics of security?

The Gordon-Loeb model, introduced by Lawrence A. Gordon and Martin P. Loeb in a paper called Economics of Information Security Investment, is considered the first economic model built to calculate the optimal amount an organization should spend protecting a given set of information. It weighs the information's vulnerability to breach against the potential loss from a breach.

Why does economics of security treat computer security vulnerabilities as tradable goods?

Camp and Wolfram argued in 2000 that each vulnerability carries its own negative externality value and can be treated as a tradable good rather than a shared public risk. Six years later, iDEFENSE, ZDI, and Mozilla were running actual markets for buying and selling vulnerabilities.

What does Hal Varian's wall metaphor show in economics of security?

Hal Varian modeled security using the height of a wall around a town to show it can behave as a normal good, a public good, or a good with externalities. In every version of his model, free riding was the eventual result.

Why can't proof of work stop spam on its own, according to economics of security?

An early paper in the field found that proof of work cannot function as a spam deterrent by itself. A later paper, titled Proof of Work can Work, showed it only succeeds once combined with price discrimination.

What does economics of security say is the true opposite of privacy?

Andrew Odlyzko argued in his paper Privacy and price discrimination that the true economic opposite of privacy is not anonymity but price discrimination. He wrote that what looks like a company mishandling customer data is often just rational behavior aimed at sorting customers by what they will pay.