In today’s increasingly interconnected digital society, one of the princi ples of Software Security, no system can ever be fully secure, underscores the inherent vulnerability and risks present in the complex digital systems we rely on daily. High-profile breaches like the Facebook-Cambridge Analytica scandal often spotlight the critical role of trust in such systems. These incidents illustrate the fragility of trust and the devastating consequences of misplaced trust. This work investigates how the concept of trust manifests in Web technologies, specifically in the domain of digital Security and Privacy. We explore the intricate relationship between trust and the technologies in place designed to protect Security and Privacy in the digital space. We reveal fundamental contradictions stemming from reliance on single entities, trust chains obscured by a system’s complexity, or simply an insufficient mental model. Our results emphasise the need for comprehensive, integrated approaches for the distribution and maintenance of trust. Furthermore, we advocate rethinking the suitability of traditional methods for trust maintenance in today’s digital society.
Alexandra Dirksen (2026) studied this question.