Live data from Hacker News

The Asymmetry of Internet Identity

crawshaw.io

31–40 of 40 posts

Re: The Asymmetry of Internet Identity

#31
post #29

Earlier quoted context omitted.

Not sure. Take the two e-mail addresses I still use; one is on GMail, the other under my domain. There are two "brands" (GMail and my domain), but one communication channel (e-mail). (From my point of view, there are perhaps three "brands" - I own the domain, but the address under my domain is handled by Fastmail.) Let me turn the question around: what about the author's use of the word "brand" seems to conflict with…

> Take the two e-mail addresses I still use; one is on GMail, the other under my domain. There are two "brands" Hmm, I don't see email as an example of a "branded" communications at all. If we're exchanging emails, it doesn't matter to either of us who our email provider is. The identity is our email address, which is not necessarily linked to what email provider we're using. > what about the author's use of the word…

The author means brand to mean authoritative identity holder. It means an institution that 1) doesnt allow two people to use the same name and 2) at a very basic level will reactivity correct fraud

It is being used similar to the way we think of banks, as a provider of trust, and a custodian. Now that I think about it, custodian is a much better word than institution or brand.

Re: The Asymmetry of Internet Identity

#32
post #10

DNSSEC. It's the solution to walled garden brands. The problem is that it needs the support of the big brands to be successful, and the big brands don't want competition.

The solution to walled garden brands is to have registrars and world governments take over identity? If DNSSEC had been widely deployed a few years ago, Muammar Gaddafi would have owned BIT.LY's CA. If a CA misbehaves, Google and Mozilla can nuke them from orbit --- as they just did with several of the industry's largest CAs. If .COM misbehaves --- a thing that has happened repeatedly in the last 10 years, because the DoJ owns it --- Google does, what? Move to .IO? Oh, wait, that's a Five Eyes TLD as well!

You've got one thing right, though: virtually no major Internet tech companies, save Cloud Flare (which sells DNSSEC services) and Paypal (but not their subsidiaries like Braintree or Venmo) use DNSSEC. Not Microsoft, Google, or Apple; not Mozilla, Stripe, or Square; not Facebook, not Cisco, not Oracle; not Salesforce, not Twitter; not Netflix. If there's a conspiracy against DNSSEC, it is deep.

Firefox, Chromium, and Apple piloted DNSSEC years ago, and then withdrew support. It's been 25 years with DNSSEC. He's dead, Jim. Let him go.

Re: The Asymmetry of Internet Identity

#33
This is lovely. I've always considered myself an internet person, I own a few domain names, I have a few servers, actual, physical pieces of hardware, connected to the Internet through my private internet connection. Sure, it took a bit of effort to get it up the first time, to figure out how to configure routers, to configured postfix and setup mail accounts, figuring out how to do DKIM in and DNS, but, now the bar for entry is extremely low..

If I write a PHP adventure in an hour, it won't take more than 5 minutes to put it online for the world to see, and those who know me, know my domain/brand, and I can easily link it to them.

If alice wants to talk to bob, she can just send those IP packets to his computer! If alice and bob are good friends, they probably exchanged certificates at some point.

In retrospect, I used to be rather arrogant about this, not proud, just annoyed why everyone didn't just do that. But I've realized that I probably didn't find any of it easy, I just happened to find it fun and interesting. It'd have been torture if it was not fun for me to do.

So yeah, we should maybe think hard about how to get to that point, where everyone who are online can have that amount of freedom, without having to rely on third parties, and without dedicating days to learning _that_much_ technical stuff. We don't need a new service trying to do this for us on the old Internet, we need some fundamental change, maybe it is not even to the network itself, maybe it is to the way we use or think about it.. Maybe it is just concepts we are missing? Maybe it is tools. Maybe it is really a fundamental change to the network itself. All must be free and equal on the capital I-Internet.

Re: The Asymmetry of Internet Identity

#34
post #14

This article seems to present the state of the Internet as a kind of feudalism, where one must swear fealty to an established "brand", and carving out a life as a freeman is practically unattainable. I'd say the reality is that it's easy to join the Internet land-owning class (buy a domain; get a cert; run services), yet most people prefer to rent because they are not so inclined. Email is widely used, HTTPS is widel…

> Email is widely used Setting up your own email server is notoriously difficult, and requires coordination with major brands. Importantly, people who use brands like GMail can't choose to whitelist you. There's no setting in GMail saying, "I trust everything coming from Bob's domain, don't bounce them." Emails get rejected on the protocol level. Effectively, if your friend is using Gmail, then they're using a brand,…

I wasn't suggesting that you need to run your own email or web servers. It's easy (albeit costly) to pay a service to host your email (e.g. Protonmail; Rackspace; many domain registrars), and there are countless web hosting providers. However, this isn't identity (the identity is still yourdomain.net), and you don't need the hosting provider to be well-known. As I understand it, acceptance by the likes of Gmail is a case of jumping through technical compliance hoops, rather than brand stature.

I wouldn't consider DNS names as brands. Brands are names which become identifying through familiarity, whereas DNS names become identifying simply by purchase; they're more similar to land registration: you are identifiable by a street address because you own / rent / lease it, not because it is widely known.

My point is that I can buy a domain, buy some email and web hosting, then masquerade as i@myself.me, put up whatever files on my website. Nothing about this requires me to build a brand, any more than buying a house to which I can invite people requires a brand. We visit websites we have never heard of all the time.

Re: The Asymmetry of Internet Identity

#35
post #30

Earlier quoted context omitted.

> Email is widely used Setting up your own email server is notoriously difficult, and requires coordination with major brands. Importantly, people who use brands like GMail can't choose to whitelist you. There's no setting in GMail saying, "I trust everything coming from Bob's domain, don't bounce them." Emails get rejected on the protocol level. Effectively, if your friend is using Gmail, then they're using a brand,…

It really sounds like you're using the word "brand" to mean "service" here.

They are, because the article in the topic (re)defines it that way.

Re: The Asymmetry of Internet Identity

#36

There's a book, "Mystery of Capital", wherein the author points out is that in order for identity and contracts to work there has to be "something to lose" for the parties involved. E.g. the power company can't supply power to slums not because of technical limits, but rather economic limits: because the residents don't have titles or leases or bank accounts there's no way to shut off the power to a household for non…

desoto

Re: The Asymmetry of Internet Identity

#37

There's a book, "Mystery of Capital", wherein the author points out is that in order for identity and contracts to work there has to be "something to lose" for the parties involved. E.g. the power company can't supply power to slums not because of technical limits, but rather economic limits: because the residents don't have titles or leases or bank accounts there's no way to shut off the power to a household for non…

This has interesting ramifications in areas which do have the ability to support power supply, but haven't implemented our style of loans tied to collateral (Edit: Or rather haven't implemented automated billing, pre or post paid, tied to an identity.).

I saw this in play in Mozambique. Few people had bank accounts, even fewer had mailing addresses, but many still had power.

Once a month or so you went down to the market and bought a little scratch off ticket worth X amount of power, I assume with the same one time use keys used on gift cards. When a house wanted hooked up to the grid they'd be supplied with a power meter which had a keypad. Type the numbers from your scratch off into the box, and it'd update it's counter with how much electric you had left.

A lot of things worked on this scratch off system, and it's one of the things I really liked. It enabled the power company to trust in their hardware instead of having to place trust in an individual. So the individual didn't have to provide any collateral. There was no credit check to get a new phone plan, because you either bought a scratch off that month or you didn't. No one came around to check your power meter unless there was something wrong with it, and they company didn't much care what it was supplying power to. I watched my neighbor build a new house and transfer his live box (quite dangerously) from his old to the new. The power company trusted the hardware, not a person or house it was tied to, so it didn't matter and there was never any record of what he was powering with it in the first place.

Re: The Asymmetry of Internet Identity

#38

There's a book, "Mystery of Capital", wherein the author points out is that in order for identity and contracts to work there has to be "something to lose" for the parties involved. E.g. the power company can't supply power to slums not because of technical limits, but rather economic limits: because the residents don't have titles or leases or bank accounts there's no way to shut off the power to a household for non…

Hernando de Soto, The Mystery of Capital:

https://www.worldcat.org/title/mystery-of-capital-why-capita...

Re: The Asymmetry of Internet Identity

#39
post #32
post #10

DNSSEC. It's the solution to walled garden brands. The problem is that it needs the support of the big brands to be successful, and the big brands don't want competition.

The solution to walled garden brands is to have registrars and world governments take over identity? If DNSSEC had been widely deployed a few years ago, Muammar Gaddafi would have owned BIT.LY's CA. If a CA misbehaves, Google and Mozilla can nuke them from orbit --- as they just did with several of the industry's largest CAs. If .COM misbehaves --- a thing that has happened repeatedly in the last 10 years, because th…

No conspiracy theories please. DNSSEC is operated by a non-profit called ICANN which manages its key-signing-keys in publicly recorded ceremonies comprised of community representatives from each continent. If you believe Google and Mozilla have legitimacy to govern cryptography affairs in the third-world, then by all means continue supporting the status quo. Also anyone registering novelty names should be aware of the risks.

Re: The Asymmetry of Internet Identity

#40
post #39
post #32

Earlier quoted context omitted.

The solution to walled garden brands is to have registrars and world governments take over identity? If DNSSEC had been widely deployed a few years ago, Muammar Gaddafi would have owned BIT.LY's CA. If a CA misbehaves, Google and Mozilla can nuke them from orbit --- as they just did with several of the industry's largest CAs. If .COM misbehaves --- a thing that has happened repeatedly in the last 10 years, because th…

No conspiracy theories please. DNSSEC is operated by a non-profit called ICANN which manages its key-signing-keys in publicly recorded ceremonies comprised of community representatives from each continent. If you believe Google and Mozilla have legitimacy to govern cryptography affairs in the third-world, then by all means continue supporting the status quo. Also anyone registering novelty names should be aware of th…

I don't know what DNSSEC you could possibly be referring to, because it's not the one that exists in reality. The reality-based DNSSEC does in fact have a silly security-theater ritual managed by ICANN to set the keys for the root, but --- and, this gets a little arcane and involves knowing some intricate details of DNS --- hanging off the root are the TLDs, like "com" and "uk", and there is no publicly recorded key signing ceremony for the TLDs. Nor could there be, because the owners of the most popular TLDs publicly assert their right to control the contents of those zones for public policy; see, for instance, every DOJ domain takedown ever.

I do however enjoy pointing out that, all this aside, you could post the root keys, the product of these elaborate key signing rituals, on Pastebin tomorrow and no real-world security engineers would have to come in on the weekend; they could pick the Jira ticket up to "figure out whether we care that all security in DNSSEC has been revoked" sometime during the next work week and be perfectly OK. Because, of course, nothing in the reality-based reality actually depends on DNSSEC.

Post reply on HN