Live data from Hacker News

Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

w3.org

41–50 of 199 posts

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#41
post #34

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

I'm gonna bet just from the requirements list quoted in that post that the implementations are supposed to be blockchains.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in.

Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#42

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

(Disclaimer - I work in this space, but these words are my own). My understanding is DIDs are a unique identifier. There's a few methods that can be used regarding the construction of the identifier. It could be a unique key (did:key- https://w3c-ccg.github.io/did-method-key/ ). It could be using web infrastructure (did:web - https://w3c-ccg.github.io/did-method-web/ ). It could be using blockchain infrastructure (di…

On second reading with that background knowledge, the crypto pedigree reveals itself: "decentralized", "distributed", "independently of any centralized registry", "distributed ledger", "non-registry based", etc...

It all makes sense now! It's yet another attempt at making Web 3.0 happen.

Sigh...

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#43
post #22
post #19

I don’t understand the point of having a specification when 2 out of the 3 major browsers have objected. Who will implement it? Why bother with this?

Because expecting standardization of DID methods at this point is unreasonable. A premature attempt to standardize DID methods would be both futile and likely harmful. It's futile because the future universe of DID methods can't be anticipated now, so whatever wrong set of DID methods W3 promulgated would include both poor choices and omit good choices. It's harmful because whatever future methods might emerge will r…

If you have literally no idea what a good or bad answer even looks like, it's not time to standardize it at this sort of formal level yet.

Beyond that, some of this is just odd. " It's harmful because whatever future methods might emerge will relegated to a second class for having failed to 'get in' on the initial standard."

Good. We can deal with that in v2.0.

Trying to design this kind of thing to anticipate every possible future good thing that might come along is a folly. If you can't standardize them yet because you don't even know, then i go back to the first sentence i wrote :)

Beyond that, your optimism in what will happen (shakeout of bad ideas and then harmonious replacement with standards) seems ... mostly misplaced.

Assume it takes off - what will instead happen is that you will be stuck supporting tons of non-standard methods developed between now and when anyone standardizes them forever. It will likely hamstring your future development as well. I cite as evidence - literally the history of everything :)

There was 100% no reason to standardize this now other than wanting to feel good about themselves. It isn't needed to push forward. It should have waited until someone had any idea what good looks like.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#44
Wow, the person who wrote that text has some talent for bureaucratese. It's comparatively rare to see that in English, since the language tends toward clear verbs and the active voice. But here I had to re-read a bunch of sentences to figure out what refers to what, while wondering if I need to take a coffee break. I would say that the author probably moonlights as a writer for NYT or something—if the dryness of the document wasn't quite outstanding, beyond what is still considered fit for consumption.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#45
post #19

I don’t understand the point of having a specification when 2 out of the 3 major browsers have objected. Who will implement it? Why bother with this?

> I don’t understand the point of having a specification when 2 out of the 3 major browsers have objected.

That's how standard bodies are supposed to work: by finding consensus. If there are many objections, the spec should be adjusted until people agree.

However, if you have enough clout, you can try and still ram it through. See hardware APIs. 2 out of 3 major browsers have objected.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#46
post #22

Earlier quoted context omitted.

Because expecting standardization of DID methods at this point is unreasonable. A premature attempt to standardize DID methods would be both futile and likely harmful. It's futile because the future universe of DID methods can't be anticipated now, so whatever wrong set of DID methods W3 promulgated would include both poor choices and omit good choices. It's harmful because whatever future methods might emerge will r…

If you have literally no idea what a good or bad answer even looks like, it's not time to standardize it at this sort of formal level yet. Beyond that, some of this is just odd. " It's harmful because whatever future methods might emerge will relegated to a second class for having failed to 'get in' on the initial standard." Good. We can deal with that in v2.0. Trying to design this kind of thing to anticipate every…

> Trying to design this kind of thing to anticipate every possible future good thing that might come along is a folly. If you can't standardize them yet because you don't even know

Whatever you design for the web stays on the web for decades. So yes, you have to look into the future and anticipate things. It's not "move fast and break things"

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#47
post #34

Earlier quoted context omitted.

I'm gonna bet just from the requirements list quoted in that post that the implementations are supposed to be blockchains.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in. Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

Do they explain anywhere whether the browser is expected to keep a bunch of multi-gigabyte blockchains on my disk?

Or, is it simply that Google, Mozilla and whoever else have to serve verification requests for their users?

Or is the whole joke in that none of this is figured out?

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#48
post #22

Earlier quoted context omitted.

Because expecting standardization of DID methods at this point is unreasonable. A premature attempt to standardize DID methods would be both futile and likely harmful. It's futile because the future universe of DID methods can't be anticipated now, so whatever wrong set of DID methods W3 promulgated would include both poor choices and omit good choices. It's harmful because whatever future methods might emerge will r…

If you have literally no idea what a good or bad answer even looks like, it's not time to standardize it at this sort of formal level yet. Beyond that, some of this is just odd. " It's harmful because whatever future methods might emerge will relegated to a second class for having failed to 'get in' on the initial standard." Good. We can deal with that in v2.0. Trying to design this kind of thing to anticipate every…

> Good. We can deal with that in v2.0.

There are many, many examples of v2.0 standards that, although better in every respect, never actually supplant v1. v1 has immense inertia.

It's not all as willy nilly as it might seem. W3C standardized the parts they could without painting themselves into a corner and wisely factored out the part they couldn't. There is an official W3C hosted registry of methods, each with a specification. They vary hugely in purpose, quality and applicability, all of which will eventually determine their viability. There are at least 3 based on the Bitcoin ('btcr', 'ion' and 'stack') block chain, for example. Which, if any, of these should W3C prefer?

The fact of this Cabirian explosion supports the W3C argument. Not selecting some arbitrary subset of these as SHALLs in the v1 standard affords room to discover the benefits and pitfalls given time and iteration.

I can understand the viewpoint of Mozilla, Google, et al. I'm sure they'd love to throw a room full of coders at a simple specification and knock out a planetary scale identity system, collect a few billion names and sell all that info to the highest bidders before the next quarterly report. It seems that W3C has other ideas about how this should work.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#49

I may be suffering from a deficiency of reading comprehension. Can someone please explain to me in plain terms what a DID is and what it's for? It's a "globally unique persistent identifier that does not require a centralized registration authority"[1] - great, an identifier for what exactly? Is it just supposed to be an identifier for anything at all ? Local and remote resources? People? Pokemon cards? [1] https://w…

It's an attempt to put a "standards-compliant" veneer of legitimacy on "Web 3.0" blockchain nonsense. The list of supported methods at https://www.w3.org/TR/did-spec-registries/#did-methods should make clear who this is really for.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#50

I may be suffering from a deficiency of reading comprehension. Can someone please explain to me in plain terms what a DID is and what it's for? It's a "globally unique persistent identifier that does not require a centralized registration authority"[1] - great, an identifier for what exactly? Is it just supposed to be an identifier for anything at all ? Local and remote resources? People? Pokemon cards? [1] https://w…

It's an attempt to put a "standards-compliant" veneer of legitimacy on "Web 3.0" blockchain nonsense. The list of supported methods at https://www.w3.org/TR/did-spec-registries/#did-methods should make clear who this is really for.

Baidu's did is literally "ccp:" ...
Post reply on HN