Live data from Hacker News

Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

w3.org

121–130 of 199 posts

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#121
post #28

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

I found it all pretty simple after looking at it briefly when I first learned about it. A DID URI is a URI with a 'method' and globally unique part: did:method:somegloballyuniqueid. The "did" part is literal; a standardized URI namespace. The method part is some symbol that specifies how the unique id resolves and its representation (JSON, whatever.) The method part is what this story is about; W3C has declined to en…

What advantages does DID have to something like OpenID? Which is actually decentralised without a central registry.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#122

Earlier quoted context omitted.

(Disclaimer - I work in this space, but these words are my own). My understanding is DIDs are a unique identifier. There's a few methods that can be used regarding the construction of the identifier. It could be a unique key (did:key- https://w3c-ccg.github.io/did-method-key/ ). It could be using web infrastructure (did:web - https://w3c-ccg.github.io/did-method-web/ ). It could be using blockchain infrastructure (di…

On second reading with that background knowledge, the crypto pedigree reveals itself: "decentralized", "distributed", "independently of any centralized registry", "distributed ledger", "non-registry based", etc... It all makes sense now! It's yet another attempt at making Web 3.0 happen. Sigh...

It's common courtesy not to interject in a technical discussion with identity politics.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#123

As a user, I am very happy that W3C has overruled the objections. As a developer, it may a bit of a PITA, albeit a necessary one. For Google, it makes sense for them to request at least some "standard" methods. If the number of DID methods is sufficiently large, Google won't be able to use their network effect to dominate any of them. Surprise, that's the aim of the spec. For Mozilla, it makes sense to support a smal…

> "As a user, I am very happy that W3C has overruled the objections. As a developer, it may a bit of a PITA, albeit a necessary one."

It's not immediately clear what DIDs are, what problems they're solving (and what value they're providing to the ecosystem), why they're better than other options in the same space, and how they'll function and scale years into the future. That's a legitimate cause for skepticism.

That the objections brought on by the two largest browser vendors are dismissed entirely, without further addressing the concerns stated, is unsettling.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#124
post #47

Earlier quoted context omitted.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in. Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

Do they explain anywhere whether the browser is expected to keep a bunch of multi-gigabyte blockchains on my disk? Or, is it simply that Google, Mozilla and whoever else have to serve verification requests for their users? Or is the whole joke in that none of this is figured out?

It's simply a URI standard for crypto signatures. It provides no function except an address to something else. That's why Google is asking for a few "working" integrations to prove the theory.

Because someone goes to implement it and figures out the standard is missing something they need critically, they can modify the standard before it becomes a 1.0 standard.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#125

As a user, I am very happy that W3C has overruled the objections. As a developer, it may a bit of a PITA, albeit a necessary one. For Google, it makes sense for them to request at least some "standard" methods. If the number of DID methods is sufficiently large, Google won't be able to use their network effect to dominate any of them. Surprise, that's the aim of the spec. For Mozilla, it makes sense to support a smal…

I can't find BankID in the list of methods, I suppose you are saying that it could be?

Some other interesting entries in this same vein, that are already in the DID registry, are Mastercard (https://idservice.com) and SecureKey (https://securekey.com).

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#126

As a user, I am very happy that W3C has overruled the objections. As a developer, it may a bit of a PITA, albeit a necessary one. For Google, it makes sense for them to request at least some "standard" methods. If the number of DID methods is sufficiently large, Google won't be able to use their network effect to dominate any of them. Surprise, that's the aim of the spec. For Mozilla, it makes sense to support a smal…

Isn't BankID only used in Sweden? At least I have not heard that it is used in Norway, Finland or Denmark.

BankID is definitely a thing in Norway. Besides being used by banks here, I can use it to submit my taxes, view my prescriptions and lots of other things.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#127
My take is that the Director of the DID working group is tired and wants this to be over. They want to enjoy a few months break and some future Working Group can deal with the problems.

We've all been there. Coding is complete, but QA comes back with some fundamental issue that might require us to redo the design of the program. We'd rather not.

Winners ship.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#128

As a user, I am very happy that W3C has overruled the objections. As a developer, it may a bit of a PITA, albeit a necessary one. For Google, it makes sense for them to request at least some "standard" methods. If the number of DID methods is sufficiently large, Google won't be able to use their network effect to dominate any of them. Surprise, that's the aim of the spec. For Mozilla, it makes sense to support a smal…

Isn't BankID only used in Sweden? At least I have not heard that it is used in Norway, Finland or Denmark.

Sweden and Norway both use BankID and I believe they are compatible. Finland and Denmark have very similar systems.

Edit: Norway and Sweden both use a system called "BankID" that does the same thing in a compatible way, but they seem to be developed and managed by two separate companies.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#129

As a user, I am very happy that W3C has overruled the objections. As a developer, it may a bit of a PITA, albeit a necessary one. For Google, it makes sense for them to request at least some "standard" methods. If the number of DID methods is sufficiently large, Google won't be able to use their network effect to dominate any of them. Surprise, that's the aim of the spec. For Mozilla, it makes sense to support a smal…

What is the Web 3.0 garbage? I though DID needed some sort of blockchain like Bitcoin.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#130
post #67

Earlier quoted context omitted.

Why sigh? Why are Bitcoin maxis and HN Web 2.0 people so intent on keeping everyone from advancing to the next phases of the Web? Do you like centralized VC-funded “cloud”-hosted startups incubated in Silicon Valley that get gobbled up by big tech or dumped on the public? You like the extreme power inequality between those who run these systems and the public? You think the best our systems can do is extract rents at…

Because if you actually look at what cryptocurrency is being used for, it’s overwhelmingly: - Scams - Risky financial structures that we regulated out of existence because they were risky and unregulated - Money laundering If there are real applications of the technology, they would’ve popped up by now. Just look at the whole space of cryptocurrency lending. Regulations exist for good reason, we have stress tests htt…

Love how you think your money is safe.

You are losing 10-15% a year from inflation. Nobody has to literally steal it when they can dilute it

Post reply on HN