Live data from Hacker News

Ethereum community has solved a major problem of the Internet: Single Sign-On

twitter.com

41–50 of 97 posts

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#41
post #38

Earlier quoted context omitted.

If the company in your example can be contacted to overturn ownership, essentially degenerating the immutability and irreversibility of the ledger to levels comparable of existing solutions, then what is the actual advantage of this not only inefficient, but inefficient by design method of bookkeeping? I find it hard to reconcile "99.9% of transfers very cheap" with the property that at least proof-of-work and proof-…

> If the company in your example can be contacted to overturn ownership, essentially degenerating the immutability and irreversibility of the ledger to levels comparable of existing solutions, then what is the actual advantage of this not only inefficient, but inefficient by design method of bookkeeping? Currently when you buy a house, you have to go through a decent amount of effort both in time and money to essenti…

These are all plausible arguments for associating real estate ownership with a database. What are the arguments for this database being maintained by a blockchain?

If you do not trust the authorities of the locality, e.g. the courts, to properly assign ownership and, more importantly, to defend your claim of ownership through further legal action, then how do you trust the blockchain implementation with its share of elected people and override mechanisms to do the same?

> Yes, it's not ideal that someone can override the ownership [...] Yes, allowing ownership overriding isn't ideal, but I don't think allowing a group to override ownership in a transparent way completely negates all benefits [...]

The assertion already is that mutability and reversibility are necessary and desired properties under the assumption that mistakes and mis-assessments happen, whether through human error or technological failure. The question is, what benefit does a blockchain bring over a regular database under this requirement?

> Ethereum will be moving to proof of stake in a year or 2 (> $10B are locked up until this occurs, so I am very confident it will happen).

I know proof-of-work down to the very detail, I have not yet looked at proof-of-stake. If proof-of-stake exists, and does not share the same problem of massive inefficiency (directly or indirectly), then I still think that a classical database solves these problems more easily, but I cease to care what solutions stakeholders choose. Proof-of-work, on the other hand, makes me and everyone else an unwilling participant in this scheme through unnecessary, and growing, consumption of energy and resources.

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#43
the continued annoying arrogance of these crypto people, claiming things are just 'web3' all of a sudden because they've built some crazy thing that seems to be outside the mainstream.... but then posting stupid twitter threads (seriously, use a fucking blog post) claiming they've solved identity, while ignoring all the world SSO and SSI people have been doing/real work/tackling issues and dealing with how real world people actually deal with (successfully/not so successfully) with these things and the way users ended up with today password managers/email still the internet's killer app/ID thing.

sigh.

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#44
post #10

This is an extremely solved problem. Unless you have a dramatically interesting solution to the real hard problem, global account recovery , ordinary home users are effectively tethered to their email accounts, because that's how you reset a login. Since you're doing that already, "Sign in with Google" and "Sign in with Apple" are perfectly cromulent solutions and likely to continue dominating. The actual last thing…

Hey! Author of the thread here. Thanks for your comments!

> This is an extremely solved problem.

Not with the properties of Sign-In with Ethereum (SIE), which is single, user generated authentication credentials, a self-custody portable username in a naming system that isn't reliant on a trusted-third party, and that people are already getting for other reasons (to use Ethereum, so extra incentive to get set up, not just SSO incentive).

> ordinary home users are effectively tethered to their email accounts, because that's how you reset a login

Yep, and I don't expect that to change very much anytime soon, but there is a small but growing community of people tethered to their Ethereum wallets and ENS names and using those instead. Given the advantages and crypto incentives, I expect it to continue to grow. Note also that service can always re

> The actual last thing in the world home users want is an authentication system where credential loss is literally irrevocable.

Doesn't have to be. Depends on how your wallet provider works. There are already some wallet providers with social recovery, etc.

Note two other key things:

1) Crypto incentives (unrelated to sign-in) mean that the private key management industry ("wallet" industry) is already highly incentivized to make it very difficult for people to lose access to their accounts (because then lost money). That's part of my point: private key management has never been good enough for average people, but crypto incentives have spurred on an massive industry to solve this problem. And while it's not solved (still needs improvement), it has improved rapidly in the last five years to be much better than ever before, and I expect it to continue to improve.

2) What I've described is just on the user side. If a web2 service adopted this, they can always do things like require you provide an email address or other information, and they can still have a process for reassigning your account with them to a different Ethereum account.

> The actual last thing in the world corporate users want is an authentication system their IT department doesn't control absolutely.

Again, depends on what you want, you can make it so that a third-party has access to all of your company's employees Ethereum accounts.

> Internet identity evangelists tend to overlook the fact that people have multiple identities on purpose.

Yep. I don't expect this to replace everything else immediately, but I do expect overtime for this to become a ubiquitous option, such that a user could use their one Ethereum account everywhere if they wanted to. Also, re the need for multiple identities: as i point out in the thread, a person can generated as many Ethereum accounts and have as many ENS names as they'd like.

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#45
post #10

This is an extremely solved problem. Unless you have a dramatically interesting solution to the real hard problem, global account recovery , ordinary home users are effectively tethered to their email accounts, because that's how you reset a login. Since you're doing that already, "Sign in with Google" and "Sign in with Apple" are perfectly cromulent solutions and likely to continue dominating. The actual last thing…

Hey! Author of the thread here. Thanks for your comments!

> This is an extremely solved problem.

Not with the properties of Sign-In with Ethereum (SIE), which is single, user generated authentication credentials, a self-custody portable username in a naming system that isn't reliant on a trusted-third party, and that people are already getting for other reasons (to use Ethereum, so extra incentive to get set up, not just SSO incentive).

> ordinary home users are effectively tethered to their email accounts, because that's how you reset a login

Yep, and I don't expect that to change very much anytime soon, but there is a small but growing community of people tethered to their Ethereum wallets and ENS names and using those instead. Given the advantages and crypto incentives, I expect it to continue to grow. Note also that service can always require a user to also provide an email address, it just wouldn't be used for authentication.

> The actual last thing in the world home users want is an authentication system where credential loss is literally irrevocable.

Doesn't have to be. Three things on this point:

1) Depends on how your wallet provider works. There are already some wallet providers with social recovery (multisig under the hood), etc.

2) Crypto incentives (unrelated to sign-in) mean that the private key management industry ("wallets") is already highly incentivized to make it very difficult for people to totally lose access to their accounts (because then lost money). That's a key part of my point: private key management has never been good enough for average people, but crypto incentives have spurred on a massive industry to solve this problem. And while it's not totally solved (still needs lots of improvement), it has improved rapidly in the last five years to be much better than ever before, and I expect it to continue to improve.

3) What I've described is just on the user side. If a web2 service adopted this (not aware of any right now, it's pretty much just web3 services that use it), they can always do things like require you provide an email address or other information, and they can still have a process for reassigning your account with them to a different Ethereum account.

> The actual last thing in the world corporate users want is an authentication system their IT department doesn't control absolutely.

Again, depends on what you want, you can make it so that you have access to all of your company's employees Ethereum accounts.

> Internet identity evangelists tend to overlook the fact that people have multiple identities on purpose.

Yep. I don't expect this to replace everything else immediately, but I do expect overtime for this to become a ubiquitous option, such that a user could use their one Ethereum account everywhere if they wanted to.

Also, re the need for multiple identities: as I point out in the thread, a person can generated as many Ethereum accounts and have as many ENS names as they'd like, using their real name or pseudonym, or whatever they'd like.

Anyway, sorry for long comment, thanks for engaging!

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#46
post #38

Earlier quoted context omitted.

> If the company in your example can be contacted to overturn ownership, essentially degenerating the immutability and irreversibility of the ledger to levels comparable of existing solutions, then what is the actual advantage of this not only inefficient, but inefficient by design method of bookkeeping? Currently when you buy a house, you have to go through a decent amount of effort both in time and money to essenti…

These are all plausible arguments for associating real estate ownership with a database. What are the arguments for this database being maintained by a blockchain? If you do not trust the authorities of the locality, e.g. the courts, to properly assign ownership and, more importantly, to defend your claim of ownership through further legal action, then how do you trust the blockchain implementation with its share of…

I think we're both in agreement that a blockchain is just a glorified database. That said, there are advantages to a blockchain over a database:

With a database, you can only do what the county auditor (or equivalent) lets you do / what their ui lets you do. With a blockchain, you can build things on top of it, fractionalized ownership, simple transfers, etc. It's basically a permissionless database that anyone can build on top of vs a database shoved in a closet at the county auditors that you can only use via their api and ui.

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#48
post #37

Earlier quoted context omitted.

> The actual last thing in the world home users want is an authentication system where credential loss is literally irrevocable. This is generally a concern I have about blockchain technology. What if it succeeds in its goal to play a major role in some sector, and something immensely important becomes attached to it. Mistakes happen. Both by humans and by computers. Software having bugs, hardware failing, bits rando…

The main practical example is git. It does have some partial mitigations for fixing its historical record, for example the mailmap file for correcting names and email addresses. And, I suppose in the worst case a project could rebase its entire history to expunge illegal commits. Fortunately there’s little chance of blockchain as in cryptocurrency succeeding outside the scammers and their marks.

git does not have a distributed consensus algorithm, however, and does not rely on proof-of-work/space/stake. Whether a rewrite of history is accepted is up to every consumer of any repository individually.

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#49
post #10

This is an extremely solved problem. Unless you have a dramatically interesting solution to the real hard problem, global account recovery , ordinary home users are effectively tethered to their email accounts, because that's how you reset a login. Since you're doing that already, "Sign in with Google" and "Sign in with Apple" are perfectly cromulent solutions and likely to continue dominating. The actual last thing…

> "Part of what's happening with ideas like this, and the reason Internet identity has been such a tar pit for the last 20 years, is that there isn't one single service model for identity. Internet identity evangelists tend to overlook the fact that people have multiple identities on purpose."

Urbit's approach seems pretty good for this? They use Ethereum to manage ID ownership/transfer, but they generate pseudonymous IDs by default (the user can decide if they want to connect them to their real name). They also have a small, but non-zero cost making them not really economically viable for mass spam - people hold on to them and develop reputation with them. There's a lot to like about that model (I think it solves a lot of these issues while also not having the IDs entirely owned by one company).

Re: Ethereum community has solved a major problem of the Internet: Single Sign-On

#50

So the Director of Operations of ENS Domains says Ethereum has solved an extremely solved problem and one of the cornerstones of that solution is... wait for it... ENS Domains. Gotcha. I also take issue with: >Ethereum is giving average ppl computer generated public/private key pairs... 'Average' people aren't into crypto. And the average computer user doesn't know how to use asymmetric keypairs. Anyone want to try t…

Have you tried using MetaMask or WalletConnect as a sign in tool? It's great. The extension pops up with a message indicating the app is requesting access to account. You click yay or nay. MetaMask already has millions of users and growing rapidly.

Average people didn't know how to use email 30 years ago. Didn't know how to use GPS 20 years ago. Didn't know how to use social media 15 years ago. Didn't know how to hail an Uber 10 years ago (and still thought riding in cars with strangers was dangerous).

I think they can be educated.

Post reply on HN