Live data from Hacker News

Getting started with decentralized identity

nathangould.com

11–20 of 67 posts

Re: Getting started with decentralized identity

#12
post #8

I like the idea that at least in web5, the term "wallet" might actually make sense, because the credentials or whatever actually "live" on your own device/node. Web3 should really use "signet" rather than "wallet." Web3 is all about signing, attestation, and authentication through digital signatures. That's what signets are for, not wallets. Coinkite recently switched to the term "signing device," but 1) that's lame,…

Bingo! =)

Re: Getting started with decentralized identity

#13
post #2

The digital identity infrastructure space is already crowded, with players like Apple, Google and Microsoft working with governments and institutions, because they own the devices we use, and the entire point is that people will be able to use their phones to identify themselves everywhere. Apple ID is already like 90% there, despite having to trust Apple with your personal data, which nobody has a problem with. The…

In the long term I hope Apple does not win. The idea that we should just submit the world’s private data to Apple for the next century is… terrible.

Zero knowledge proofs are one of the more promising things starting to emerge from crypto and decentralized blockchain space. If desired, you can still trust Apple for the ZK proof generation and verification without having to store any private details on their servers.

Re: Getting started with decentralized identity

#14
post #7

As I said 48 days ago when this last came up on YC, the classic "Why your idea for stopping spam sucks" list applies.[1] Go re-read that and you'll see the same identity problems and proposed solutions. If people can create and abandon identities cheaply. they will use those identities for annoyance or fraud. Hence spam, robocalls, etc. This is also why the "federated" social networks are not too useful. On the other…

> The process of binding a DID to something in the physical world, such as a person or an organization — for example, by using verifiable credentials with the same subject as that DID — is contemplated by this specification and further defined in the Verifiable Credentials Data Model [VC-DATA-MODEL].

https://www.w3.org/TR/did-core/#proving-control-and-binding

Here is the diagram:

https://www.w3.org/TR/vc-data-model/#lifecycle-details

The idea there is that identity providers and other authorities (governments, credit agencies, etc) issue credentials after the person authenticates with them.

This isn't much different than how it works today with, for example, a cookie on the Experian website, but the idea is that I can now take this cookie, show it to a third party and the third party can verify the credential's validity.

Re: Getting started with decentralized identity

#15
post #2

The digital identity infrastructure space is already crowded, with players like Apple, Google and Microsoft working with governments and institutions, because they own the devices we use, and the entire point is that people will be able to use their phones to identify themselves everywhere. Apple ID is already like 90% there, despite having to trust Apple with your personal data, which nobody has a problem with. The…

In the long term I hope Apple does not win. The idea that we should just submit the world’s private data to Apple for the next century is… terrible. Zero knowledge proofs are one of the more promising things starting to emerge from crypto and decentralized blockchain space. If desired, you can still trust Apple for the ZK proof generation and verification without having to store any private details on their servers.

Practical ZK is coming from cryptography, like this decentralized gun registry by the Brown University.

https://eprint.iacr.org/2021/107.pdf

People in the crypto space are coming from a different angle, they are franctically trying to find a legitimate use for cryptocurrencies, so far unsuccessfully, by constantly rebranding blockchain technologies without being able to address the challenges. It's not that we desire to trust Apple, it's that they get things done. They have actual solutions that work, not just empty promises aimed at greater fools. People in the crypto space never deliver.

Re: Getting started with decentralized identity

#16
The article completely misses the mark in creating some weird narrative about 'web3 turning into web5', all seemingly based on a wordplay announcement by Dorsey, thereby giving that project a lot of undue credibility.

In reality, many of the good projects and people referenced at the end of the article have been working for years without any notion that their projects are sprung out of some hyped but underspecified 'web3' technology.

Dorsey's 'web5' clamor is mostly about (barely [1]) implementing some existing technology and then writing a bit of slideware around it [2], which proposes to magically "allow individuals, organizations, and companies to publish credentials anyone can discover and independently verify" while not spending any thought on how such a PKI would be ("independently") governed without centralizing everything back again – an all too common failure mode of 'web3' [3].

Meanwhile, both Dorsey's slideware [4] and the actual specifications referenced [5][6] make bad technological choices with regard to privacy where users have stable identifiers (their public keys) which must be published, allowing them to be easily tracked across transactions.

While this can be used as a building block, no material on the 'web5' website or the TBD54566975 Github repository (I guess it's some other wordplay) indicates that they even recognize this as a problem, let alone that they propose how to solve it.

This is no new problem however: Sovrin – which many people referenced in the OP have worked on or with – has published a commentary on this back in 2018 [7]. There's also a great talk by Christopher Allen if you need to refresh your memory about what you need to consider when designing identity systems [8].

Otherwise the OP can be a great introduction to identity, but please don't feed the magical hypetrain.

[1] https://github.com/TBD54566975/ssi-service#whats-supported

[2] https://developer.tbd.website/docs/Decentralized%20Web%20Pla...

[3] https://moxie.org/2022/01/07/web3-first-impressions.html

[4] See the diagram on page 9 of [2]

[5] https://identity.foundation/decentralized-web-node/spec/

[6] https://identity.foundation/ion/

[7] https://sovrin.org/wp-content/uploads/2018/10/What-Goes-On-T...

[8] https://www.youtube.com/watch?v=JzM_Brpk95E&t=1574s

Re: Getting started with decentralized identity

#17
post #7

As I said 48 days ago when this last came up on YC, the classic "Why your idea for stopping spam sucks" list applies.[1] Go re-read that and you'll see the same identity problems and proposed solutions. If people can create and abandon identities cheaply. they will use those identities for annoyance or fraud. Hence spam, robocalls, etc. This is also why the "federated" social networks are not too useful. On the other…

> The process of binding a DID to something in the physical world, such as a person or an organization — for example, by using verifiable credentials with the same subject as that DID — is contemplated by this specification and further defined in the Verifiable Credentials Data Model [VC-DATA-MODEL]. https://www.w3.org/TR/did-core/#proving-control-and-binding Here is the diagram: https://www.w3.org/TR/vc-data-model/#…

Wow now it sounds awful for other reasons.

Still pie-in-the-sky, but I still think we've been low ambition & not had good decentralized-identity-preconditions to begin exploring web-of-trust models. Past behavior is a huge indicator, one we can judge, & which many others will have judged. Trying to filter those other judges, decide what trust anchors we have & what biases to give, is a place where humanity would have a lot of freedom to tweak & explore, if we had these modest adequate technical underpinnings to begin to explore from.

But we just lost a decade to blockchain mania & consensus computing, rather than exploring anything actually genuinely distributed & decentralized & non-consensus. Also worth admitting AI just got good enough to convincingly fake being an online person fairly well, which can potentially massively outperform any attempt at moderation & seeking truth/genuineness that humans might ever make; said explicitly, bad/business-motivated actor's ability to fuck up anything but an ultra-conservative/paranoid web-of-trust has gone up orders of magnitudes in the past couple years.

Re: Getting started with decentralized identity

#18
Are blockchain people physically incapable of speaking plainly?

Its hard to cut theough the buzzword bullshit, but this sounds like they reinvented PKI and added 10 billion layers of indirection.

Is there more to it than that? Or is this really just taking the latest technogies of the 1990s, and explaining it badly so people think they have invented something new?

Re: Getting started with decentralized identity

#19
post #7

As I said 48 days ago when this last came up on YC, the classic "Why your idea for stopping spam sucks" list applies.[1] Go re-read that and you'll see the same identity problems and proposed solutions. If people can create and abandon identities cheaply. they will use those identities for annoyance or fraud. Hence spam, robocalls, etc. This is also why the "federated" social networks are not too useful. On the other…

> The process of binding a DID to something in the physical world, such as a person or an organization — for example, by using verifiable credentials with the same subject as that DID — is contemplated by this specification and further defined in the Verifiable Credentials Data Model [VC-DATA-MODEL]. https://www.w3.org/TR/did-core/#proving-control-and-binding Here is the diagram: https://www.w3.org/TR/vc-data-model/#…

> but the idea is that I can now take this cookie, show it to a third party and the third party can verify the credential's validity.

Or you know, like oauth.

Or if you want to really play up the credential angle, how tls client certificates work, if anyone would ever use them.

Re: Getting started with decentralized identity

#20
post #5
post #4

Earlier quoted context omitted.

Sheesh, "web5"? I guess we blew right past web4. Normally i try to avoid low quality complaint comments like the one i am making, but blockchain naming is frustrating.

It's a little bit tongue and cheek. (Read the post.)

Maybe, but honestly in the article it seems less tounge in cheek, and more "its just a joke bro" to deflect criticism.
Post reply on HN