Live data from Hacker News

Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

w3.org

81–90 of 108 posts

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#82
post #11

I was initially pretty hyped when I read the abstract for DIDs, bookmarked the spec and read it later. The "spec" is a bunch of buzzwords and vague generic "concepts". The DIDs themselves mean basically nothing, it's the "methods" that actually must have their own specification and actually "do something". Another feeling you can quickly get from DIDs is that they're blockchain centric. The entire concept is "jack of…

Here is a spec for the `did:key` method: https://w3c-ccg.github.io/did-method-key/

Thank you. Skimming this was much more informative.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#83

Earlier quoted context omitted.

> Only positive thing is to see Google loosing once in a standards fight It is far from the first time. For instance, Google was involved in the WHATWG, which developed the HTML standard while the W3C pushed XHTML. The standards war, itself, is only lost when nearly nobody uses the standard, which is what happened to XHTML, which lost to WHATWG’s HTML when browsers simply didn’t use XHTML. It sounds like a lot of cry…

> browsers simply didn’t use XHTML Do you mean "developers didn't use XHTML"? All browsers implement XHTML. It's referred to as "the second concrete syntax for HTML" in the WHATWG spec.[1] Indeed many websites do use XHTML, the HTML application of XML. However, since proper documents render identically, you won't be aware that you're visiting an XHTML site - that is, unless you check the source. Fun history side note…

In context, the xml serialization of html5 is not what is being referred to.

Although you are right that the issue was more user acceptability and not implementor willingness.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#84
post #49
post #43

Earlier quoted context omitted.

The standard has grown out of the blockchain space, because they finally offered a way to do decentralized PKI. Most methods are based on blockchain networks. But there are some that work without blockchains. Like IOTA, IPFS, p2p, web, etc.

IPFS still looking for something useful it can do.

Location independent stable identifiers for immutable docker images that allow you to cache them wherever you want (including in airgapped envs) and still don't require users to patch your image names with kustomize/helm/whatever

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#85
post #41
post #8

Earlier quoted context omitted.

Google and Mozilla objected: https://www.w3.org/2022/06/DIDRecommendationDecision.html

Google is not very surprising, because they're probably the largest issuer of centralized identities. DIDs eat their core business.

well google did not outright reject, they said, it's not complete and the final should wait until the methods are implemented and used in practice (like most stuff is done nowadays)

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#86

Earlier quoted context omitted.

> Only positive thing is to see Google loosing once in a standards fight It is far from the first time. For instance, Google was involved in the WHATWG, which developed the HTML standard while the W3C pushed XHTML. The standards war, itself, is only lost when nearly nobody uses the standard, which is what happened to XHTML, which lost to WHATWG’s HTML when browsers simply didn’t use XHTML. It sounds like a lot of cry…

> browsers simply didn’t use XHTML Do you mean "developers didn't use XHTML"? All browsers implement XHTML. It's referred to as "the second concrete syntax for HTML" in the WHATWG spec.[1] Indeed many websites do use XHTML, the HTML application of XML. However, since proper documents render identically, you won't be aware that you're visiting an XHTML site - that is, unless you check the source. Fun history side note…

> All browsers implement XHTML.

Internet Explorer did not. It completely refused to render XHTML pages served with an XML MIME type (application/xhtml+xml). It would only display pages if they were served with the text/html MIME type, which meant that none of XML’s vaunted features (such as strict parsing) came into play, and such pages were effectively treated as “HTML with syntax errors.”

A big part of why WHATWG was able to dethrone W3C was W3C’s insistence on dropping HTML in favor of XHTML when the overwhelmingly dominant browser of the time had zero support for it.

> They came up with XML, the clean subset, and XHTML, the DTD. … Basically, XHTML was the first actual standardization of HTML.

No, the first formal HTML standard was 2.0 (RFC 1866), which was released in November 1995 and had a DTD that among other things disallowed overlapping hierarchies. XML’s first draft was released a full year later (November 1996), and the first W3C spec was XML 1.0 in 1998. Later that year came the initial drafts for XHTML 1.0, which was a straightforward translation of HTML 4.0 to XML.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#87
post #27

So I've just scanned over this stuff, maybe someone can fill in some gaps for me. There's a list of DID methods "in development" [1]. Is this the list of methods, or is there a centralized registry, or are these just "known" methods? If there's a centralized registry -- then this isn't really "decentralized" is it? On top of that there's a land-grab that's already begun for the method names, and isn't that going to k…

It's such a bad spec it'll never be implemented by anyone

In a round about way W3C successfully did the opposite of what they claimed they where trying to do, killing the entire concept and ensuring it won't ever actually happen

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#88

Earlier quoted context omitted.

This reminds me of web service/UDDI registries, that were supposed to come, and all the WS buzz in early 2000s. Some of them came indeed only to be shut down in a few years.

That's exactly the same comparison I've been making regards the W3C VC and DID specifications - we're basically repeating the bad parts of the WS specifications.

Somebody up above mentioned the land grab smell of the DID spec.

So what's different this time? gRPC, protobuf and GraphQL are out there vs. SOAP or CORBA? Some new thing about to rev up? Just plain old loss aversion?

Lambda? We need a FrontPage or Macromedia ColdFusion for that...

I guess that's it, somebody else from the Roblox generation can pick that up.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#89

So, I take it that the "decentralized" aspect of all this stuff really comes into play when all of the server hardware is surgically implanted into our limbs!

No, the cloud systems still need to be there (to track when you are trying to use your identity), but they will rely on private keys that you can surgically implant in your limbs.

In fact a more realistic (but symbolically equivalent) scenario is that you'll be expected to carry around a device with you at all times that is biometrically linked to your limbs, and auto-updates its code (and the EULA that you agreed to in perpetuity).

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#90
post #21
post #18

Earlier quoted context omitted.

> lined up the tech in their products Link? Or an explanation as to what this means? > before it becomes available in a shop nearby Meaning what exactly? If you're saying Microsoft will implement DIDs, my question is, "Which of the 50+ methods?"

Here's the link: https://www.microsoft.com/en-us/security/business/solutions/... I haven't used their implementation yet but Microsoft initiated the did:ion method. I guess they'll support it :-D In general, the idea with DID methods is that you can support many methods without too much effort - for example the Universal Resolver implements already a good bunch: https://dev.uniresolver.io/ However, pointing in the di…

DID resolution is a security operation and has to be done by a trusted component. The document you get back does not have any additional integrity protection on it, so a resolver that lies will basically let the malicious party impersonate anyone.

The resolution process for DID methods also vary in their processing and storage requirements. Some method implementations may result in gigabytes of local data.

For these and other reasons, I don't believe real-world deployments will resolve more methods than they deem necessary. Of course, that would mean that between implementer networks you have far less portability and interoperability for DIDs.

Post reply on HN