Live data from Hacker News

Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

w3.org

61–70 of 199 posts

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#61
post #4

Earlier quoted context omitted.

For those of us who aren't webdevs, what was the final fate of OAuth 2.0?

You may have heard the aphorism, "All problems in computer science can be solved by another level of indirection." This, or some variation of it, is known as the fundamental theorem of software engineering, variously attributed to Andrew Koenig, Butler Lampson, and David J. Wheeler. With oauth2, literally any sort of authorization (or, in theory, authentication) is possible, but first you have to ask some endpoint fo…

> despite the name, oauth2 is not about authentication, it's only about authorization

OAuth is short for Authorization in the first place.

https://datatracker.ietf.org/doc/html/rfc6749

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#62
post #28

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

I found it all pretty simple after looking at it briefly when I first learned about it. A DID URI is a URI with a 'method' and globally unique part: did:method:somegloballyuniqueid. The "did" part is literal; a standardized URI namespace. The method part is some symbol that specifies how the unique id resolves and its representation (JSON, whatever.) The method part is what this story is about; W3C has declined to en…

And so it is as clear as is the Summer's sun.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#63
My TLDR. DID is already a registered URI scheme [1]. The method on a DID [2] is more or less a URI sub-scheme / protocol. Its for the blockchain / web3 crowd for something like the definition of a NFT. Most of their startups will shut down in a year or two anyways. Won't really matter. No one is going to manually type these in, or understand them by reading them. I'd agree that there really isn't a point of declaring it a standard as the DID scheme is already registered.

[1] https://www.iana.org/assignments/uri-schemes/prov/did

[2] https://www.w3.org/TR/did-core/#methods

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#64

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

The New Zealand government used DID for their vaccine passport. (Scan to be allowed to enter a building)

They removed the core part of the DID standard where they made it expire after 6months.

I was told they requested the DID standard as it was needed for future projects.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#65
post #15

A standard flexible enough where you can do literally anything is usually a bad standard. The point of standards is to write up some small-ish base that everyone can agree on so that people can talk to each other. A standard containing everything where each implementation implements a different incompatible subset, is a failure.

Also, too much flexibility ends up being a security nightmare. This building so much flexibility into protocols seems like a 90s holdover. We are realizing that the more moving parts you have, the more edge cases you have, and the more attack surface area.

I guess we'll find out if they have learned anything since the XML Signature specification. That was an adventure, trying to find a subset that actually did what it said it did.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#66

Earlier quoted context omitted.

(Disclaimer - I work in this space, but these words are my own). My understanding is DIDs are a unique identifier. There's a few methods that can be used regarding the construction of the identifier. It could be a unique key (did:key- https://w3c-ccg.github.io/did-method-key/ ). It could be using web infrastructure (did:web - https://w3c-ccg.github.io/did-method-web/ ). It could be using blockchain infrastructure (di…

On second reading with that background knowledge, the crypto pedigree reveals itself: "decentralized", "distributed", "independently of any centralized registry", "distributed ledger", "non-registry based", etc... It all makes sense now! It's yet another attempt at making Web 3.0 happen. Sigh...

I'd argue that of those, "distributed ledger" is the only real red-flaggy one -- and even then, only because of its association with blockchain. I think when engineering web technologies, we should hope to find a lot of talk about decentralized, distributed stuff independent of central registries.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#67

Earlier quoted context omitted.

(Disclaimer - I work in this space, but these words are my own). My understanding is DIDs are a unique identifier. There's a few methods that can be used regarding the construction of the identifier. It could be a unique key (did:key- https://w3c-ccg.github.io/did-method-key/ ). It could be using web infrastructure (did:web - https://w3c-ccg.github.io/did-method-web/ ). It could be using blockchain infrastructure (di…

On second reading with that background knowledge, the crypto pedigree reveals itself: "decentralized", "distributed", "independently of any centralized registry", "distributed ledger", "non-registry based", etc... It all makes sense now! It's yet another attempt at making Web 3.0 happen. Sigh...

Why sigh?

Why are Bitcoin maxis and HN Web 2.0 people so intent on keeping everyone from advancing to the next phases of the Web?

Do you like centralized VC-funded “cloud”-hosted startups incubated in Silicon Valley that get gobbled up by big tech or dumped on the public? You like the extreme power inequality between those who run these systems and the public? You think the best our systems can do is extract rents at the behest of Wall Street? People who bought the shares at $100 dont want them to drop to $50 so Uber will take 50% of all drivers’ paychecks, while a decentralized autonomous network wouldn’t. Selling tokens is a one-time deal that makes the founders rich and then the network belongs to the participants.

What happened to the open source, hacker ethos? You know, counterculture, hacking on something, or at the very least not buying into the corporate morass? What happened to cypherpunks and people who wrote M$ and worked on Free Software alternatives to Big Tech?

Once upon a time America Online, Compuserve and Prodigy were today’s Google, Facebook etc. People left for the open, decentralized protocols like HTTP, as soon as good enough clients (browsers) appeared. Web 2.0 companies like FB or Google could have never even gotten started if they needed permission of AOL or MSN … the permissionless nature Web 1.0 made it possible.

Once upon a time, long distance calls cost $3 a minute. Then the decentralized file sharing network Kazaa guys made Skype, and it became so widespread that VOIP dropped the cost to zero. We can all videoconference now and the telcos are reduced to providing dumb pipes.

So why if Web 1.0 broke barriers and allowed anyone to write some HTML and serve via HTTP a website to the whole world … why is it sooooo terrible that in Web 3.0 people can write a smart contract and deploy it on some EVM compatible blockchain making the rules or payments instantly accessible to people around the world who control their own keys? Do you really think this won’t have any real applications?

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#68
post #55

Earlier quoted context omitted.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in. Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

I think it speaks extreme volumes that the "methods" of "did" and "com" were both proposed by no-name crypto organizations; "cosmos" seems to be proposed by one guy with a template website maybe unrelated to the relatively major Cosmos blockchain (they're fighting amongst themselves lol); "ens" was proposed by some organization with no website; "evan" was picked up by literally some guy named Evan. Its not just that…

Don't forget the Korean Ministry of the Interior, who are apparently using a two-line Markdown file as their website and a random Gmail address as their only method of contact.

For an identity verification standard, you'd think they'd demand the authors have more verifiable identities.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#69
post #55

Earlier quoted context omitted.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in. Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

I think it speaks extreme volumes that the "methods" of "did" and "com" were both proposed by no-name crypto organizations; "cosmos" seems to be proposed by one guy with a template website maybe unrelated to the relatively major Cosmos blockchain (they're fighting amongst themselves lol); "ens" was proposed by some organization with no website; "evan" was picked up by literally some guy named Evan. Its not just that…

> evan" was picked up by literally some guy named Evan.

Easy to check and that appears to not be true at all. Authors : Sebastian Wolfram, Philip Kaiser

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#70
post #15

A standard flexible enough where you can do literally anything is usually a bad standard. The point of standards is to write up some small-ish base that everyone can agree on so that people can talk to each other. A standard containing everything where each implementation implements a different incompatible subset, is a failure.

Sounds like you're describing ActivityPub
Post reply on HN