Live data from Hacker News

Using blockchain for identity management is mostly ridiculous

blog.xot.nl

21–30 of 49 posts

Re: Using blockchain for identity management is mostly ridiculous

#21
The architect of the Blockcerts system replies to this article here:

http://community.blockcerts.org/t/response-to-blockchain-blo...

“It’s interesting that he focuses on blockchain for identity management, which Blockcerts doesn’t even do.

However, DIDs, which can improve the ability of individuals to own/control their identity, will feature blockchain-based method specs.”

Re: Using blockchain for identity management is mostly ridiculous

#22
post #18

Im a "blockchain-for-x" skeptic, but I disagree with this article. A timestamped, immutable blockchain would be useful for reviewing credentials from 3rd world countries where qualifications/experience/government certification are all able to be bought. It wouldn't solve fraud, but it would make it a lot harder to suddenly decide to fake a whole lot of credentials, and would make it more obvious that a particular org…

> scan a fingerprint (to establish identity)

> annually update information about themselves onto the blockchain (how?)

What could possibly go wrong? Fingerprints alone should not be used as a key.

Re: Using blockchain for identity management is mostly ridiculous

#24
post #18

Im a "blockchain-for-x" skeptic, but I disagree with this article. A timestamped, immutable blockchain would be useful for reviewing credentials from 3rd world countries where qualifications/experience/government certification are all able to be bought. It wouldn't solve fraud, but it would make it a lot harder to suddenly decide to fake a whole lot of credentials, and would make it more obvious that a particular org…

You're basically specifiying PKI, not anything to do with Blockchain.

If you truly want the timestamps to "lock in" the time of a transaction without trusting either party, a hash-commitment could be used, akin to https://opentimestamps.org/.

Re: Using blockchain for identity management is mostly ridiculous

#25
post #18

Im a "blockchain-for-x" skeptic, but I disagree with this article. A timestamped, immutable blockchain would be useful for reviewing credentials from 3rd world countries where qualifications/experience/government certification are all able to be bought. It wouldn't solve fraud, but it would make it a lot harder to suddenly decide to fake a whole lot of credentials, and would make it more obvious that a particular org…

You're basically specifiying PKI, not anything to do with Blockchain. If you truly want the timestamps to "lock in" the time of a transaction without trusting either party, a hash-commitment could be used, akin to https://opentimestamps.org/ .

A blockchain seems like a very reasonable way to provide a distributed immutable log of actions that take place within a PKI infrastructure. It even adds the ability for 3rd party auditors to participate in the system in a real-time manner.

You might even extend it, so that instead of it being PKI with a blockchain transport, to something more akin to Kerberos with a blockchain transport -- every attempt, successful or not, to access a resource could be immutably logged, and access could be granted by the targeted resource only once the authorization message has been committed to the blockchain (and therefore approved by auditors)

Re: Using blockchain for identity management is mostly ridiculous

#26
post #18

Im a "blockchain-for-x" skeptic, but I disagree with this article. A timestamped, immutable blockchain would be useful for reviewing credentials from 3rd world countries where qualifications/experience/government certification are all able to be bought. It wouldn't solve fraud, but it would make it a lot harder to suddenly decide to fake a whole lot of credentials, and would make it more obvious that a particular org…

You're basically specifiying PKI, not anything to do with Blockchain. If you truly want the timestamps to "lock in" the time of a transaction without trusting either party, a hash-commitment could be used, akin to https://opentimestamps.org/ .

A blockchain adds trustless governance rules and a verifiable audit trail to using just PKI alone. These are hugely valuable features of an identity management systems.

Re: Using blockchain for identity management is mostly ridiculous

#28
post #22
post #18

Im a "blockchain-for-x" skeptic, but I disagree with this article. A timestamped, immutable blockchain would be useful for reviewing credentials from 3rd world countries where qualifications/experience/government certification are all able to be bought. It wouldn't solve fraud, but it would make it a lot harder to suddenly decide to fake a whole lot of credentials, and would make it more obvious that a particular org…

> scan a fingerprint (to establish identity) > annually update information about themselves onto the blockchain (how?) What could possibly go wrong? Fingerprints alone should not be used as a key.

I don't mean using the fingerprint as a key.

I mean that if you can produce a fingerprint image corresponding to a blockchain hash and it matches your fingerprint 20 years later, and this is linked to 20 years worth of blockchain recorded credential information, I would find that very compelling evidence that you are who you say you are.

Re: Using blockchain for identity management is mostly ridiculous

#29
post #14

Earlier quoted context omitted.

As with any transaction on a proof of work chain, the more work there is layered on top of the item in question, the more confidence you can have. Even if you don't know that someone's presenting you with a truncated chain, you can still see that their credential is at the end of it, and know that they could have cheaply faked it. Proof of stake would require more human consensus but proof of work is measurably expen…

> As with any transaction on a proof of work chain, Only active proof of work chains. Discontinued chains have no active, competitive consensus and may be arbitrarily rewritten by attackers since there is no competition at any historical point in the chain for a quick mining operation and there is no consensus about the head of the chain. If there are additional credentials and signatures embedded in the chain (there…

You can still measure the total amount of hashpower applied. Someone could add arbitrarily many blocks but you can calculate how much it cost for them to do it.

Re: Using blockchain for identity management is mostly ridiculous

#30
post #18

Im a "blockchain-for-x" skeptic, but I disagree with this article. A timestamped, immutable blockchain would be useful for reviewing credentials from 3rd world countries where qualifications/experience/government certification are all able to be bought. It wouldn't solve fraud, but it would make it a lot harder to suddenly decide to fake a whole lot of credentials, and would make it more obvious that a particular org…

Is there a preference for the term ‘third-world’ to ‘developing nation’
Post reply on HN