Hide the detail, keep a way to check¶
Cross-Domain EchoesShared pattern · Information Hiding
A newsroom can check a confidential source without publishing the person’s identity. The public receives a supported claim through a deliberately limited disclosure, while verification occurs behind that boundary. A formal software model can also hide an internal representation and expose only permitted observations. Its claims about behavior are checked through those observations rather than by demanding that the hidden representations be identical. In both settings, concealment needs an account of what remains observable and checkable. The purposes differ: journalism protects a vulnerable person and future reporting channels; the software model defines a precise way to reason about hidden state. Neither kind of checking substitutes for the other.
Choose a role to see its counterpart in both examples. The diagrams show relationships, not measured quantities.
Journalism
A protected reporting source
Read Source ProtectionDomain-specific abstraction
Identity stays protected while the newsroom verifies the contribution and decides what can be published.
In this example: The receiver can know and check facts that an outside audience must not receive. Protection is not a guarantee that a claim is true.
Formal software models
A state observed through operations
Read Hidden algebraDomain-specific abstraction
Hidden internal states are studied through declared visible observations and behavioral equivalence.
In this example: All-admissible-observation agreement is a formal criterion. A newsroom’s evidential judgment is not that kind of proof.
The boundary needs permitted channels. Newsroom verification and formal observations are different forms of accountability, not interchangeable tests.
Written comparison
What stays behind the boundary
Journalism
Source identity
Formal software models
Internal representation
Both distinguish information kept inside from a usable visible surface. The reason for concealment differs.
A controlled way across
Journalism
Verified, selected disclosure
Formal software models
Declared observation operations
The boundary needs permitted channels. Newsroom verification and formal observations are different forms of accountability, not interchangeable tests.
What outsiders can use
Journalism
A supported published claim
Formal software models
Observable behavior
The visible result supports limited reliance without exposing every underlying detail. It does not license arbitrary conclusions about the concealed part.
What carries across
When details must stay hidden, ask what can still be observed and how claims about the hidden side are checked.
Where the comparison stops
Protecting an identity is an ethical and adversarial task; hiding a representation is a formal modeling choice. The resemblance is controlled exposure, not a shared proof of trustworthiness.
- Behavioral equivalence in hidden algebra is defined over all admissible observations; journalistic confidence is evidential and fallible.
- Source protection also preserves future willingness to report. The software diagram makes no equivalent claim about vulnerable people or trust.
- The public surface does not mean everyone has the same access: the newsroom can internally corroborate information it cannot safely publish.
Conditions for this comparison
- A newsroom actually verifies contributions while restricting identity disclosure.
- The software model declares hidden sorts, visible observations and its behavioral comparison criterion.
Source entries
Shared pattern
Information Hiding
Prime
Core Idea
Information hiding is the structural pattern of *deliberately concealing some internal facts about a system behind a stable public surface, so that consumers of the system interact only with the surface and remain unable — and unconcerned — about what lies behind*.
Journalism
Source Protection
Domain-specific abstraction
Core Idea
A structural tension runs through every instance: the stronger the protection, the less the news organisation can publicly corroborate the source's claims to external audiences, imposing a credibility cost on the published story. Receivers compensate by building internal verification disciplines — document authentication, cross-referencing with independent lines of reporting, editorial oversight of the source's access claims — that maintain internal confidence without externalising the source's identity.
What It Is Not
- Not generic confidentiality. Confidentiality withholds any information from disclosure; source protection has a specific object — the channel's *upstream provider* — shielded in order to preserve the channel's *future* operation. The defining feature is not that something is kept secret but that a vulnerable source is shielded against a party who would harm them on identification. - Not concealment from the receiver, and not "unverifiable." Anonymity *to the adversary* and accountability *to the receiver* are compatible: a source can remain unknown outside the dyad while still answering for fabrication inside it. "Protected" therefore does not mean the claim cannot be checked — the newsroom builds internal verification (document authentication, independent cross-reporting) precisely so shielding does not cost confidence. - Not concern for the present source alone. The load-bearing function is the *future channel*: protection demonstrates to not-yet-contacted sources that coming forward is survivable. This is why a single breach is catastrophic out of proportion to the one identity exposed — it collapses the protection promise's credibility across every potential source, not just the one. - Not obstruction or stonewalling. Refusing a subpoena reads from outside as concealment, but the construct reframes it as protecting the conditions under which the next whistleblower will come forward — the chilling-effect logic at the heart of shield-law jurisprudence. The stake is the channel, not evasion of scrutiny. - Not a single safeguard or an after-the-fact fix. Protection is *layered* — identity, channel, legal, physical stacked in parallel and scaled to adversary reach — and the architecture must be designed *before* the source makes contact, because the disclosure event itself creates the adversarial attention. A single mechanism, or one added after contact, is already compromised against a capable adversary. - Not a substrate-free mechanism wearing a journalism name. Whistleblower statutes, IRB pseudonymization, legal privilege, intelligence asset-handling, and witness relocation are genuine *co-instances* of the same channel-preservation parent, but each field re-codifies it in its own terms. What is specific to source protection is the shield-law and SecureDrop/newsroom apparatus; the cross-field mechanism is the composition of confidentiality, access control, trust, and traceability-interruption, not "source protection" as named.
Formal software models
Hidden algebra
Domain-specific abstraction
Core Idea
Hidden algebra models objects as elements of hidden sorts, operations as methods or transitions, and observations as visible results, with behavioral equivalence replacing equality of inaccessible internal representations. Contexts built from observations test hidden states; equations are interpreted behaviorally, and coinductive proof establishes that states agree under all admissible observable experiments.
What It Is Not
- It is not the neighboring catalog concept Abstract data type. An ADT hides representation behind operations broadly; hidden algebra supplies a specific many-sorted algebraic and behavioral-equivalence semantics suited to evolving or concurrent objects.