Live data from Hacker News

Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

w3.org

181–190 of 199 posts

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#181

Earlier quoted context omitted.

What is the Web 3.0 garbage? I though DID needed some sort of blockchain like Bitcoin.

The word "blockchain" is mentioned only once in the spec, and only in one of the 12 use cases. The garbage part is that 9 of 10 (give or take) methods registered on https://www.w3.org/TR/did-spec-registries/#did-methods are from crypto-hyper-cosmos-nonsense. The reason is that serious organizations like MasterCard or BankID will only begin considering registering a method once the spec is a W3C Recommendation. At thi…

The only decentralized one is the one that uses Bitcoin. No Bitcoin no real DID.

Decentralization matters.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#182

Earlier quoted context omitted.

That's up to the 'method' part, which is what all the fuss is about.

Ok, so if I show my did to someone's they're going to reach out to the method and ask for verification. How does the method place know that the person using the did is the right person? I assume it's some kind of federation? They send me over to the method place, I authenticate, and get kicked back?

Every method currently has different answers for every single one of those questions, directly leading to Google and Mozilla's complaints here that there's already a "registry" of 50+ methods, no actual standardization among them, and it's all punted to "ask the method".

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#183

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

Some reading: https://w3c-ccg.github.io/did-primer/

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#184

Earlier quoted context omitted.

The word "blockchain" is mentioned only once in the spec, and only in one of the 12 use cases. The garbage part is that 9 of 10 (give or take) methods registered on https://www.w3.org/TR/did-spec-registries/#did-methods are from crypto-hyper-cosmos-nonsense. The reason is that serious organizations like MasterCard or BankID will only begin considering registering a method once the spec is a W3C Recommendation. At thi…

The only decentralized one is the one that uses Bitcoin. No Bitcoin no real DID. Decentralization matters.

Please don’t hijack the term decentralization to solely mean blockchain &co. What you are describing is a single system that uses technical means to decentralize (quite cleverly so).

The classical D. is achieved by not having a single system like Blockchain but instead having as many as you wish - anyone can install nginx on their server. This results in a multitude of systems achieved through policy means. The spec means decentralization in this way - Sweden can rely on some DID methods, UK on other, and you can use Bitcoin :)

You may argue that the latter is flawed but please don’t make it sound like the former is the only way.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#185
post #88
post #73

Earlier quoted context omitted.

> DID in my opinion is unlikely to succeed. Probably a few big tech companies will form a consortium and use their weight for setting a de-facto standard.

Or they won't use it and will be confined to a long tail of use cases? I mean, not all of the Internet is accessed through a browser but if Chrome and Firefox don't support DIDs, even if Safari would, who would use DIDs in a context exposed to browsers?

Apple objected too I think.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#186

Earlier quoted context omitted.

What a brilliant and unambiguous abbreviation!

Because this is my specialty, I long ago learned to specify either authn or authz. The OAuth spec should have been the OAuthz spec.

Agree, or could be OAF just like the way GNAP named itself.

Btw, I'm relatively new to this field. Didn't the terms like authn/authz exist at the time they named OAuth? Or any other reason not to use them?

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#187

Earlier quoted context omitted.

The only decentralized one is the one that uses Bitcoin. No Bitcoin no real DID. Decentralization matters.

Please don’t hijack the term decentralization to solely mean blockchain &co. What you are describing is a single system that uses technical means to decentralize (quite cleverly so). The classical D. is achieved by not having a single system like Blockchain but instead having as many as you wish - anyone can install nginx on their server. This results in a multitude of systems achieved through policy means . The spec…

All methods that don't rely on Bitcoin are not really decentralized.

All other systems can get decisions reversed and rules changed without much trouble. Try doing that in Bitcoin :)

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#188
post #161

Earlier quoted context omitted.

If you have arguments against DIDs, then raise them here for rational discussion from all POVs, which is something HN is great at. '"evan" was picked up by literally some guy named Evan' is not an argument. It's also not factual. The Evan DID method spec [1] was written by Sebastian Wolfram and Philip Kaiser. It is for the Evan Network, which is a blockchain attempting to provide a usable decentralized market infrast…

Ok; that's my mistake on the Evan one. But here's my counter: when it comes to web standards like this, I am fully prepared and willing to delegate my opinion to Mozilla (and a lesser but still positive degree, Google). The W3 (ok you want to be pedantic; W3C; talk about SNR) additionally has a ton of other extremely mature member organizations; Apple, Amazon, Meta, Microsoft, Cloudflare, if even one of these organiz…

Apple, Amazon, Meta, Microsoft, Cloudflare, if even one of these organizations had their name anywhere on this spec I'd give it the time of day. I work at one of them; I've worked for two in the past; I know the people, they're extremely smart and well-intentioned.

Microsoft spent years helping to develop the ION DID method. https://techcommunity.microsoft.com/t5/identity-standards-bl...

Not to mention incorporating DIDs and Verifiable Credentials into Azure AD (which services 95% of the Fortune 1000): https://docs.microsoft.com/en-us/azure/active-directory/veri...

Block/Square? They're getting very deep into crypto right now; also a member org; silent.

This would be the exact opposite of silence: https://twitter.com/csuwildcat/status/1542598105044078595?t=...

Still feels like your intent is to rag on something you've taken little to no time to look into.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#189

Earlier quoted context omitted.

>1. Permissionless, censorship-resistant global money transfer >5. Microtransactions for online games and to replace web advertising how money transfer and microtransactions are different?

They are (at least) two separate use cases, even though they are both examples of sending money. (You could equally say that they are all examples of sending data). 1. Some people want to be able to send large amounts of money internationally to their family in a country which has currency controls and "official" exchange rates. Others want to be able to send funds to organisations that have been banned by traditiona…

1. The problem there is exactly why the space is going to remain a reserve for fundamentally illegal activity. Arguably it shouldn't be. I get that. That still doesn't get me any closer to me suggesting anyone's grandma hop into Web3.

5. So you're still being tracked, because there isn't a company around that isn't monetizing viewership data. Also, if you're fine with fiscal policies, why are you hesitant to wire? Sounds to me like you're dissatisfied with your host country's fiscal controls, or service provider's offerings.

Look, control over financial networks is one of the most powerful soft control mechanisms on the planet. You will not work around that. Government is slow to catch up, but I assure you, these folks aren't stupid anywhere close to 100% of the time. The fact regulation is crystalizing around crypto as fast as it is without taking the multi-century learning experience trad-fi did is evidence enough of that.

If it comes down to "a bunch of nerds created an unregulable financial system" I can pretty much guarantee it'll get gobbled by trad-fi snd re-centralized.

In fact, anyone could roll their own financial networks without using banks/Visa/you name it. No one has because we've made laws that specifically increase the barrier to entry because finance is the spine that provides support for all manner of economic activity, which includes the illegal stuff, and Government is putatively in the business of making sure that the illegal stuff doesn't see the light of day.

I just do not see the compelling argument that'll carry weight to switch someone from "financial system that makes crime hard" to "financial system that makes crime easy" and feel alright about it. You have to already accept that crime is just an endemic human phenomena, and this is just a rebalancing of the spectrum.

Given you've got much more efficient implementations of your other use cases available, this is the sticking point for me. No people I've spoken to and laid out what Web3 really is, even with the most charitable framing gets passed that.

If I can't convince people it's a good idea with full disclosure in effect, I'm not sure it's something worth pushing forward.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#190
post #28

Earlier quoted context omitted.

I found it all pretty simple after looking at it briefly when I first learned about it. A DID URI is a URI with a 'method' and globally unique part: did:method:somegloballyuniqueid. The "did" part is literal; a standardized URI namespace. The method part is some symbol that specifies how the unique id resolves and its representation (JSON, whatever.) The method part is what this story is about; W3C has declined to en…

What advantages does DID have to something like OpenID? Which is actually decentralised without a central registry.

This is OpenID's privacy policy: https://openid.net/foundation/members/privacy_policy

They will turn your information to the authority when requested. How is that decentralised?

Post reply on HN