Live data from Hacker News

Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

w3.org

161–170 of 199 posts

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#161
post #55

Earlier quoted context omitted.

I think it speaks extreme volumes that the "methods" of "did" and "com" were both proposed by no-name crypto organizations; "cosmos" seems to be proposed by one guy with a template website maybe unrelated to the relatively major Cosmos blockchain (they're fighting amongst themselves lol); "ens" was proposed by some organization with no website; "evan" was picked up by literally some guy named Evan. Its not just that…

If you have arguments against DIDs, then raise them here for rational discussion from all POVs, which is something HN is great at. '"evan" was picked up by literally some guy named Evan' is not an argument. It's also not factual. The Evan DID method spec [1] was written by Sebastian Wolfram and Philip Kaiser. It is for the Evan Network, which is a blockchain attempting to provide a usable decentralized market infrast…

Ok; that's my mistake on the Evan one.

But here's my counter: when it comes to web standards like this, I am fully prepared and willing to delegate my opinion to Mozilla (and a lesser but still positive degree, Google). The W3 (ok you want to be pedantic; W3C; talk about SNR) additionally has a ton of other extremely mature member organizations; Apple, Amazon, Meta, Microsoft, Cloudflare, if even one of these organizations had their name anywhere on this spec I'd give it the time of day. I work at one of them; I've worked for two in the past; I know the people, they're extremely smart and well-intentioned.

I don't agree with your statement that its worth discounting the professionalism and expertise of some member organizations just because you had one third-hand experience in an entirely unrelated organization of some no-name member roadblocking a proposal because of... market interests. Market interests?! Of course that would be a concern! Proposals need to serve the members of the org. The members of the org are, mostly, for-profit organizations! I'm blown away at the dissonance it takes to complain about non-professional SNR, then immediately follow-up with hearsay and supposition.

But, ok, maybe not Web2 Big Tech. Maybe Web3 big tech? Where's the Ethereum Foundation? They're a W3C member org! Block/Square? They're getting very deep into crypto right now; also a member org; silent. Coinbase? Just an exchange, but a member. I mean, the list keeps going on.

I've read the spec. I would not claim to fully understand it, but like Mozilla, it feels abstract and very short on even high-level use-cases. I also think TBL's response signals that's by-design; and I think that's a weak response because ultimately if the organizations who do develop tangible use-cases fly-in-the-night four years from now, the spec will become an unnecessary vestige of the web, like so many before it, while the organizations who actually put in the work and deliver value to Real Humans ignore it (or worse, are forced to keep the dying-but-not-dead vestige on life support) (its not the W3C/TBL who pays the six figure engineer salaries that maintain this shit, its their member orgs, and not even the ones who proposed and approved this).

I also feel, weakly but still prescient, that while the W3C is relatively egalitarian, we can't ignore the politics. This was GOOGLE and MOZILLA who raised concerns (not to mention one anonymous org). TBL can object, and W3C can set the spec, but at the end of the day it will become a vestige even if the people involved with this spec do their best to make it happen, if Big Tech isn't on-board. I'm not, then, asserting that fighting big tech is never worthwhile; I'm just asserting that the W3C probably isn't the best abstraction layer to fight the fight.

So yes: I will criticize. And I'll hyperbolize: the fact that the W3C has hundreds of member organizations, from implementors to thinkers to for-profits and non-profits, and they're willing to overrule real concerns from multiple established and respected members in-favor-of a grocery list of flag-planters, half of which DON'T EVEN HAVE LEGITIMATE WEBSITES, is an embarrassment.

But, fortunately, probably, one that everyone will soon forget about.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#162
post #72

Earlier quoted context omitted.

It might have something to do with all the cryptobro’s pushing get-rich-quick-schemes. Crypto-enthusiasts ignore how regulations existed for good reasons before regulatory capture made a mess of things. Not everyone likes the idea of an anarchocapitalist future. And I’m not even talking about the outright scamming and the fact that most crypto’s primary use case is criminal. Or the environmental issues of spending en…

>Crypto-enthusiasts ignore how regulations existed for good reasons before regulatory capture made a mess of things. What way do you propose out of regulatory capture?

Transparency laws, stricter regulation on moving between regulatory agencies and regulated industries, in general, better democratic accountability. All of these are imperfect, but it's also the case that cryptocurrency doesn't make any of it better.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#163
post #55

Earlier quoted context omitted.

I think it speaks extreme volumes that the "methods" of "did" and "com" were both proposed by no-name crypto organizations; "cosmos" seems to be proposed by one guy with a template website maybe unrelated to the relatively major Cosmos blockchain (they're fighting amongst themselves lol); "ens" was proposed by some organization with no website; "evan" was picked up by literally some guy named Evan. Its not just that…

> evan" was picked up by literally some guy named Evan. Easy to check and that appears to not be true at all. Authors : Sebastian Wolfram, Philip Kaiser

Fair; I just scanned the list and saw it was associated with a company named Evan GmbH; I didn't, and still don't, feel it was worthwhile to investigate further; but fine, they're a no-name crypto org with a template website promising to provide the technical and legal framework for the future of the decentralized market economy based on blockchain technology. I'm really excited about their promise that "Digital Identities turn goods into active and autonomous participants in business relationships." And Gartner named them a "Cool Business" in 2020, watch out for these guys I'm sure they'll still be around in four years.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#164

Earlier quoted context omitted.

I think reflexco meant this as a joke….

No, this is what identity politics is, reducing technical matters to which camp you're in ("your post gives me crypto vibes, scam!!"). Correct me if I'm wrong but I believe this doesn't belong on HN.

Honestly pretty funny that you are so critical of identity politics yet so uninformed about what that term actually means

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#165

An "Explain Like I'm Five" of what DID is (for those who don't know, like me): "Decentralized identifiers (DIDs) are a new type of identifier that enables verifiable, decentralized digital identity. A DID refers to any subject (e.g., a person, organization, thing, data model, abstract entity, etc.) as determined by the controller of the DID. In contrast to typical, federated identifiers, DIDs have been designed so th…

How does one prove they own the DID?

That's up to the 'method' part, which is what all the fuss is about.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#166
post #28

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

I found it all pretty simple after looking at it briefly when I first learned about it. A DID URI is a URI with a 'method' and globally unique part: did:method:somegloballyuniqueid. The "did" part is literal; a standardized URI namespace. The method part is some symbol that specifies how the unique id resolves and its representation (JSON, whatever.) The method part is what this story is about; W3C has declined to en…

What problem does adding a common “did:” prefix to these identifiers solve over plain old URIs?

Or perhaps my question is more general. What problem does this particular common standard address that individually standardised uri-schemes would not?

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#167

Earlier quoted context omitted.

How does one prove they own the DID?

That's up to the 'method' part, which is what all the fuss is about.

Ok, so if I show my did to someone's they're going to reach out to the method and ask for verification. How does the method place know that the person using the did is the right person? I assume it's some kind of federation? They send me over to the method place, I authenticate, and get kicked back?

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#168

Earlier quoted context omitted.

Love how you think your money is safe. You are losing 10-15% a year from inflation. Nobody has to literally steal it when they can dilute it

Straight to criticizing something else. lol

Because you live in a privileged bubble.

You have no idea how serious the problems Bitcoin is trying to solve are.

One day you will be forced to understand it though. Hopefully it doesn't result in you losing all your savings, like it has happened to billions of people through history....

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#169

I may be suffering from a deficiency of reading comprehension. Can someone please explain to me in plain terms what a DID is and what it's for? It's a "globally unique persistent identifier that does not require a centralized registration authority"[1] - great, an identifier for what exactly? Is it just supposed to be an identifier for anything at all ? Local and remote resources? People? Pokemon cards? [1] https://w…

It's an attempt to put a "standards-compliant" veneer of legitimacy on "Web 3.0" blockchain nonsense. The list of supported methods at https://www.w3.org/TR/did-spec-registries/#did-methods should make clear who this is really for.

I think this is an unfair generalization. The core of the DID spec was developed by the folks at the Internet Identity Workshop, who have been discussing identity far longer than blockchain even existed.

Some of their members (e.g. Sovrin, Evernym) only very reluctantly included blockchain as a piece of the solution, and only then when they saw how certain aspects of blockchain were desirable for credentials and revocations without a central, controlling cabal.

Using Sovrin as an example, they did not create a token sale, NFT, or defi anything, which I think speaks volumes about their motives. Instead, they created a non-profit that was funded through traditional means.

IMO some of these founding members are legitimately trying to solve the very difficult problem of digital identity (including privacy, decentralization, and compatibility).

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#170

I may be suffering from a deficiency of reading comprehension. Can someone please explain to me in plain terms what a DID is and what it's for? It's a "globally unique persistent identifier that does not require a centralized registration authority"[1] - great, an identifier for what exactly? Is it just supposed to be an identifier for anything at all ? Local and remote resources? People? Pokemon cards? [1] https://w…

It's an attempt to put a "standards-compliant" veneer of legitimacy on "Web 3.0" blockchain nonsense. The list of supported methods at https://www.w3.org/TR/did-spec-registries/#did-methods should make clear who this is really for.

Here's a real world example of an identifier for a meme I just made using one of the linked sites in that table: https://didme.me/did:meme:1zgs0ue8me4gt3ls5uvq87n7v7ykhrvr50...

On the one hand, it seems like this is going to be (and/or is currently being) used by NFT peddlers, but on the other hand it's not like we'll be seeing less NFTs and cryptocurrency garbage if this spec dies.

However, I also can't think of any interesting use-cases for this that don't involve cryptocurrency/NFT garbage. Some of the example use-cases seem range from being consumer rights and privacy nightmares, to being just uninteresting ideas that can be implemented without DID.

The Transferable Skills Credentials[1] case for example seems to be trying to make a case for adding an NFT/minting schemes as a middle-man for certification programs. What value could that possibly add? Certification programs are centralized by design, so the only "gain" would be that the certification authority doesn't need to maintain a database of the certifications it gives out...or something like that?

Also the "Cross-platform User-driven Sharing"[2] one reads like some sovereign citizen wet dream (in semi-broken English). Franklyn is a military war veteran with two young daughters and he is very concerned about protecting their privacy online, so he writes HIS OWN terms of service that companies need to agree with if they want to do business with him. After a long probationary period, he decides to share more information with services (like a shopping list!), but he keeps his finger on the trigger at all times (the delete my DID button) in case the company gets any ideas.

I didn't realize the W3C had become such a clown show.

1: https://w3c.github.io/did-use-cases/#vcEcosystem

2: https://w3c.github.io/did-use-cases/#crossPlatform

Post reply on HN