Live data from Hacker News

Is “acceptably non-dystopian” self-sovereign identity even possible?

blog.mollywhite.net

201–210 of 295 posts

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#201

Earlier quoted context omitted.

Absolutely! Dont trust institutions is the message.

I suppose that was an original message for Bitcoin, but the current state with various institutions serving in trust-based roles for so many users, Bitcoin doesn't seem to have met that goal. The users who out of practical concern are considering between trusting Citibank and Bitfinex, will benefit from chosing the one that's regulated.

At this point, I too would not recommend anyone put their life savings into crypto. Especially given the clearly powerful astroturfing campaign against it. But where can you put it? The banks are not trust worthy, they caused the financial crisis. Real estate, I guess. No wait, real estate being corrupt is what got bitcoin started in the first place.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#202

Earlier quoted context omitted.

> Trust is a feature, not a bug Why do people always misunderstand "trustless"? Being ABLE to trust somebody is a good thing. Being REQUIRED to trust somebody is a problem.

That argument is not that clear if you state it in the converse. Being able to operate with nobody trusting you is potentially a problem. Being required to be trusted by at least somebody is arguably a good thing.

> Being required to be trusted by at least somebody

That's in no way related to what I wrote and to the concept of trustless is security.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#203

This is a great write-up for introducing some of these concepts. For those who want to go deeper, highly recommend reading up more on DIDs https://w3c.github.io/did-use-cases/ Verifiable Credentials: https://www.w3.org/TR/vc-data-model/ Some people working in the space to follow: https://twitter.com/kimdhamilton https://twitter.com/IdentityWoman https://twitter.com/ChristopherA Also highly recommend this paper by Fen…

This essay introduces Self-Sovereign Identity very nicely! Even deeper deep dive into this topic : Sybil attacks are not solved with the "Soul" bound reputation approach. This was mathematically proven some years ago by Harvard University phd student Sven[0]. See his impossibility results on "weakly beneficial Sybil attacks" and "single report responsiveness property". The blockchain crowd has not yet discovered this…

In the case of bitcoin, isn't Sybil prevented by requiring a majority hash rate? I think I don't understand what attack you're considering in this context.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#204
No. As long as there is a mechanism for adding new identities to the system, (presumably you want this, because people can be born), people can disguise themselves as new people. This is not trivial to accomplish, but there's no law of nature preventing you from growing a remote control infant should the need arise. It's certainly impractical, but new people are legitimately allowed to enter the system, and there's no way to establish that someone does not know something (in this case knowing something would be the RC baby actually being me, I know how to say goo goo ga ga, and you can't prove I know more than that).

That's obviously a silly example, but the point is that soulbinding isn't a cryptographic primitive. There's just no such thing. Not only is non-dystopian identity impossible, No amount of dystopia will change this. Even a totally authenticated system is vulnerable to the "Add a new person that I control" attack. It's not current technology, but it's also not science fiction, and in simple fact, a lesser version of this attack happens all the time. People who have more kids get more representation in government. I don't think that we should totally ignore this effect, but it's certainly useful to mostly ignore it.

Anyway, there is no way to establish a sophisticated adversary's unique identity and also allow new identities to be created based on phenomena external to the system.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#205

The problem I have with blockchain enthusiasts, after talking with them about their philosophy, is that they seem to consider trust a bug, and believe that ideal world is achievable with straitjackets of technical solutions that eliminate trust. Trust is a feature, not a bug. If trust is violated by rogue agents, it is because they exist[0], not because trust itself is a folly. However, blockchain-adjacent initiative…

The reality is that as you move up the social hierarchy in modern human society, trust tends to vanish and is ultimately viewed as something only a rube would rely on. This is why contract law exists, doesn't it?

For example, in the upper tiers of corporations all employment is on a contract basis. Nobody at these levels trusts they will be treated fairly and given a severance package if they are fired, without an explicit contract stating the terms and conditions of employment. Contracts are renewed or renegotiated every few years, right? In contrast, entry-level employees never get contracts, they can be fired at will with no warning or severance, at least in the United States where union power is very limited, relative to Europe.

Similarly, look at the prevalence of marital contracts that imply a lack of trust among the parties, i.e. the famous pre-nuptial agreement regarding how the net wealth of the couple will be divided up in the event of a divorce. There's a zero-trust situation that's increasingly common.

It's true that a society where nobody trusts anyone else and all are suspicious of each other's motives is not a very healthy society, but isn't this also the assumption of the economic theorists who claim all humans are basically little more than rational autonomous self-improving algorithms, with net assets being the benchmark of success?

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#206
post #86

Earlier quoted context omitted.

But does it allow you to anonymously prove that you are a human? You don't want to go telling random websites who you are. No one says this can't be done. In fact, it's explicitly mentioned in the essay, that the problem this approach has is that it's centralized and you typically can't use it as an anonymous proof of humanity, or disclosing information selectively. So, why is this important? Well, while you can stil…

What sort of digital services are you thinking of?

In a local context, many kinds of "social networks" or spaces to share things with other people from the same area, specially related to art and culture. Also many local associations organizing events could use unique identities to make it easier to make reserves for events with food, races, slots in talks, concerts, etc. Many other kinds of specific applications are also possible. You could even organize games and augmented reality activities much more easily if people didn't have to create accounts for everything, we had an easy way to verify that a human is trying to use the service... and even more if we could verify some info like "this person is from this area" (though there are some workarounds for that). Mostly, use tech to reivindicate public space, which public administrations have a tendency to mismanage as if it was their own private space (lack of vision is typically also an issue). There are many other ways to do similar things, but that's what I had in mind when I talked about democratization.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#207

The problem I have with blockchain enthusiasts, after talking with them about their philosophy, is that they seem to consider trust a bug, and believe that ideal world is achievable with straitjackets of technical solutions that eliminate trust. Trust is a feature, not a bug. If trust is violated by rogue agents, it is because they exist[0], not because trust itself is a folly. However, blockchain-adjacent initiative…

>Aren’t we sort of codifying malicious intent, instead of trying to remove it from the equation? Whom would this serve?

Define malicious intent.

What and whome one person is willing to trust will always be different than another person. This is a hard truth that we will never work around. Culture vs Culture, family vs family, idea vs idea. We can't get rid of conflict or therefore 'malicious intent' and by extension we can't (or shouldn't) bank on trust. I think the better way to deal with our very real human differences is to look past them in the spirit that all of us are creations of a higher power, and thus working together is in everyone's greatest interest.

Money as a medium of exchange is a very powerful concept It holds the idea of an IOU that can transcend our differences in the spirit of building a better world. But in order for that to happen money needs to be fungible, else our differences will enviably tear it apart.

Perhaps when the dollar was backed by gold this concept was more or less true, but central banks undermined that, hense the pull towards extreme decentralization.

>There is place for verification in the interim, such as maintaining security of your home, but if we are looking ahead (as blockchain enthusiasts do) we should strive for a future where humans are not motivated to hurt other humans. NOT TREATING IT AS SOME SORT OF DEFAULT IS A GOOD START.

I must disagree with this concept.

To treat it in a trusted manner is to ignore the fact that we have insurmountable differences and therefore those differences will raise their ugly heads elsewhere and tear our hopes for peace apart.

Rather to start with the presupposition that these differences exist, but that we will create a form that transcends them for the better of all is imo the ideal.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#208

Earlier quoted context omitted.

That mitigates these risks for people who are able to have an in-depth understanding of Bitcoin, which is in itself extremely complex and requires tons of prior knowledge. Everyone else has to trust someone with their crypto needs and is left to be fleeced with no recourse at all. As of now, that merely replaces the group that profits disproportionately with a crypto bros and the like.

Crypto Bros are the vaguely defined boogeyman, scape goat, and hate magnet for a coordinated disinformation campagain against crypto .. Are you sure you want to associate your position with that kinda PR?

Don't try to stand up a strawman. The exchanges are manipulating the value of Bitcoin, which affects those not using exchanges' ability to trade at a 'proper' value.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#209
post #86

Earlier quoted context omitted.

In Iceland we already have digital identity from a centralised authority. I log into my bank, health service, sign papers (including loans) and so on with a government managed digital ID. So this isn’t even something that needs invention let alone by web3.

But does it allow you to anonymously prove that you are a human? You don't want to go telling random websites who you are. No one says this can't be done. In fact, it's explicitly mentioned in the essay, that the problem this approach has is that it's centralized and you typically can't use it as an anonymous proof of humanity, or disclosing information selectively. So, why is this important? Well, while you can stil…

This reply hits the nail on the head, but I’ll just add that this isn’t only a benefit to small scale services. I’ve been at well funded startups and medium sized companies where we spent quite a bit of time and effort dealing with spam and bot activity, to the point of making trade offs in the product to lower the impact of bad actors. Even companies that are more or less successful at this spend a TON of money and engineering resources on this problem, and it still manages to detract from the UX (think Twitter bots). I wouldn’t be surprised if the economic benefit of a technical solution to this problem was on the order of tens of billions of $$.

Re: Is “acceptably non-dystopian” self-sovereign identity even possible?

#210
post #204

No. As long as there is a mechanism for adding new identities to the system, (presumably you want this, because people can be born), people can disguise themselves as new people. This is not trivial to accomplish, but there's no law of nature preventing you from growing a remote control infant should the need arise. It's certainly impractical, but new people are legitimately allowed to enter the system, and there's n…

To give an absolute “no” here is presumptive. There are many unique indicators for a human. DNA is unique. At most, there is a small statistical chance of one or two other twins with identical DNA. That could be used to have some level of digital identity binding.

If the technology existed to take a neural snapshot, that would be completely unique. And I would argue if anything had the ability to operate at the complexity of a brain, then it deserves representation.

If you were to automated the entire system top down for identity validation, there are possible avenues to get a high degree of assurance that someone is uniquely human on a system. Just because it hasn’t been done yet does not me it is impossible.

But it is a very hard problem.

Post reply on HN