Live data from Hacker News

Is “acceptably non-dystopian” self-sovereign identity even possible?

blog.mollywhite.net

91–100 of 295 posts

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#91

From a first read, the following problems I see in this critique: - The trilemmas do not need to be solved . They just need to be acknowledged when you are designing your application so that people can understand the types of trade-offs being made. In cases where sybil-resistance is not a requirement, you can build a system that gives you privacy and decentralization. When sybil-resistance is required, you just need…

> they start from this ridiculous notion that "web3" is about creating a Highlander solution (there can be only one!) and that this solution needs to satisfy all constraints, otherwise it rubbish and needs to be discarded.

I dub this the Highlander bias.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#92

The problem I have with blockchain enthusiasts, after talking with them about their philosophy, is that they seem to consider trust a bug, and believe that ideal world is achievable with straitjackets of technical solutions that eliminate trust. Trust is a feature, not a bug. If trust is violated by rogue agents, it is because they exist[0], not because trust itself is a folly. However, blockchain-adjacent initiative…

You hit the nail on the head with this comment. And not only is trust a feature, it’s a requirement for society. It’s a deep part of human nature to trust, and trust can’t be removed from how people manage to function in groups.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#93
post #89

The problem I have with blockchain enthusiasts, after talking with them about their philosophy, is that they seem to consider trust a bug, and believe that ideal world is achievable with straitjackets of technical solutions that eliminate trust. Trust is a feature, not a bug. If trust is violated by rogue agents, it is because they exist[0], not because trust itself is a folly. However, blockchain-adjacent initiative…

Everyone is a potential threat, that's the whole point of trust in the first place. If that wasn't the case, trust (in terms of safety) wouldnt even be a thing.

Not if you reframe it as the absence of mistrust, trusting being the natural state.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#94

The problem I have with blockchain enthusiasts, after talking with them about their philosophy, is that they seem to consider trust a bug, and believe that ideal world is achievable with straitjackets of technical solutions that eliminate trust. Trust is a feature, not a bug. If trust is violated by rogue agents, it is because they exist[0], not because trust itself is a folly. However, blockchain-adjacent initiative…

I disagree - trust is a bug in technical systems. Maintaining trust has a really high cost and is an obvious and common single point of failure.

Take TLS - wouldn't it be nice if we could have the same system without certificate authorities?

The thing is - like everything else, trust is a tradeoff. Bitcoin folks will discard it at any cost. Sometimes discarding it is not worth the cost. That doesn't mean adding trusted third parties is a good thing, just that it is often the lesser evil.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#95
I suspect privacy is the most malleable point on the trilema.

You can't compromise on security while still being usable.

You can compromise on decentralisation, and everything will work. Your gym, bank and employer already have you in a centralised identity system. Compromising on decentralisation fails the other way. There's no way of holding the centralised body to its side of the compromise. If worldcoin controls identity, they'll control downstream of identity too.

For actual solutions, I think it's better to think of specifics applications. Once you get specific, there are often more options.

Take DAUS governance. Say you want to implement a voting system that requires identity for sybil resistance. Maybe it's ok if voting requires a limited compromise on privacy. You expose just enough information to demonstrate eligibility, then vote. If privacy is more important that voting, you can maintain privacy instead.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#96
post #93
post #89

Earlier quoted context omitted.

Everyone is a potential threat, that's the whole point of trust in the first place. If that wasn't the case, trust (in terms of safety) wouldnt even be a thing.

Not if you reframe it as the absence of mistrust, trusting being the natural state.

Trusting blindly is not a natural state. We evolved in the ecosystem you see around you. In freak cases, eg. the dodo bird, you can see what happens when blind trust meets competition.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#97

This is an excellent write-up, and I genuinely hope that the brain-cycles the web3 world is spending on this eventually benefit the rest of society. I’ve been musing about a similar but more simple problem: how can we prove we are an individual human in the context of a web service. Think of this like the ultimate CAPTCHA where not only can you prove you are human but every person can do so at most once or, more prag…

In Iceland we already have digital identity from a centralised authority. I log into my bank, health service, sign papers (including loans) and so on with a government managed digital ID. So this isn’t even something that needs invention let alone by web3.

I mean, client side TLS certificate support goes back to the netscape days. Not like its a new idea on the web.

Having to identify yourself to every website ever does sound dystopian (albeit there are cryptography (the old fashioned type not botcoin) solutions like blacklistable anonoymous credentials.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#98

This is an excellent write-up, and I genuinely hope that the brain-cycles the web3 world is spending on this eventually benefit the rest of society. I’ve been musing about a similar but more simple problem: how can we prove we are an individual human in the context of a web service. Think of this like the ultimate CAPTCHA where not only can you prove you are human but every person can do so at most once or, more prag…

I would say https://privacypass.github.io/ is a lot closer than "sign in with apple"

See also crypto papers on blacklistable credentials, e.g. https://www.cypherpunks.ca/~iang/pubs/blacronym-wpes.pdf

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#99

Earlier quoted context omitted.

Some good points. I think a major problem is with the word "identity", is that there are always (at least two) meanings that may or may not intersect. We have self-regarding identities and other-regarding identities. The set of things we define about ourselves that includes beliefs, intentions, secrets and so on may be (for secrets must be) disjoint from the set of things others attribute to us, reputation, observed…

> right to be forgotten 1984 had a pretty good argument why it’s dystopian to tell people they are not allowed to remember or continue believing something.

People can remember all they want… It’s the permanent digital record indexed by search engines, available at the tip of your fingers anywhere anytime - that is the problem.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#100
post #94

The problem I have with blockchain enthusiasts, after talking with them about their philosophy, is that they seem to consider trust a bug, and believe that ideal world is achievable with straitjackets of technical solutions that eliminate trust. Trust is a feature, not a bug. If trust is violated by rogue agents, it is because they exist[0], not because trust itself is a folly. However, blockchain-adjacent initiative…

I disagree - trust is a bug in technical systems. Maintaining trust has a really high cost and is an obvious and common single point of failure. Take TLS - wouldn't it be nice if we could have the same system without certificate authorities? The thing is - like everything else, trust is a tradeoff. Bitcoin folks will discard it at any cost. Sometimes discarding it is not worth the cost. That doesn't mean adding trust…

The thing is, it is not always a bug and it does not always help to give the decision out of your own hands.

E.g. I would really trust myself to decide which products should stay in my Online Shop and which I want out. I don't need (or even want) a public append-only structure that is out of my control. For me the blockchain is good for all usecases where I would in real life use a notary. And that is not many use cases.

Post reply on HN