Live data from Hacker News

The Future of Online Identity Is Decentralized

yarmo.eu

41–50 of 202 posts

Re: The Future of Online Identity Is Decentralized

#41
post #18

In my ideal world, we have a framework for brick-and-mortar businesses to act as internet notary service providers. If you want a general-purpose open-id style account, you visit a notary, and provide them with a fee and proof of your identity. You tell the notary how much information they can share (in particular, whether they can release your name to the internet, or just the "we verified this account is held by a…

> You could have a notary vouch that you're a licensed driver, or have a college degree, visited a certain country, etc. Humans, generally, are very bad at caching document fraud. It wouldn't be a vouch for a licensed driver but instead it would be a vouch for "a bit of plastic that looked like a driving license to me". There is lots of sophisticated fraud and often automated solutions have a much higher rate of dete…

Certificate authorities with brick and mortar locations would be an improvement over the current USA situation of SSN+DOB as master password to all IRL accounts. Checking a drivers license IRL is better than looking at an uploaded scan or photo. They could use those box scanners casinos use.

The main issue is minimizing cost. Dot com companies and banks don't want to pay for this so they peg online identities and account security to SMS effectively pushing off the problem to cellular companies. Cellular companies lack the competence to handle IAM. Opening a branch in every city is very expensive and companies don't want to even pay ~$10 for an offshore script reader to check a SMS code and verify "public information" off a credit report.

Credit card companies that are already liable for fraud usually settle for SSN+DOB, ID scans and aforementioned Equifax data verification because fraud losses are cheaper than in person due diligence.

Re: The Future of Online Identity Is Decentralized

#43

I agree with a lot of this post. A lot of the left-leaning intellectuals that are now criticizing the harder-left stances in academia; people like Brent Weinstine, Jonathan Haidt, Sam Harris, et. al. ... I've heard all of them say they want less anonymity and more accounts tied to real identities. Whenever I hear this I think, "What? No! That's the opposite direction we should be going." Identities that are hard lock…

how about we have a whole range of options so that we can express our full selves via the various venues made available? sometimes you want (pseudo-)anonymity and sometimes you don't. being able to pick and choose seems to offer the greatest freedom, rather than pigeon-holing everyone into one option.

This! While sometimes I want to use a pseudonym, there are many times I want to say "I am the human who I say I am," and currently, that means hoping a platform will magically verify me (if they even verify anyone) or, I suppose, posting a copy of my ID to the internet, and even that doesn't work so well.

While there are many routes to be semi-anonymous, there are very few to being verified (or maybe I just don't know about them)

Re: The Future of Online Identity Is Decentralized

#44
post #30

Earlier quoted context omitted.

Why would I ever trust a notary? As a person being notarized it sounds like I have to give that business more personal information about myself than I usually have to do to get an online identity, as suggested by your subpoena statement. As a service trying to verify accounts I now have to trust a third party. Maybe the notary has a business that sells fake IDs in the back that are then used in the notarizing process…

You've never provided any business with ID? How do you get into nightclubs? The internet is important. When something is important enough, it is worth the risk. That's why people share secrets with their bank, lawyer, doctor, psychologist, etc. We are squandering most of the potential of social media, because its design limits worthwhile conversation to hypotheticals. Since there's no reason to trust the honesty or m…

> How do you get into nightclubs?

Clubs don't care about identity. In some parts of the world they care about age and outward signs of affluence and/or attractiveness.

Re: The Future of Online Identity Is Decentralized

#45
The future is Decentralized - you have very large actors working to deploy systems based on the Verifiable Credentials (VC) Data Model (W3C Standard) and the Decentralized Identifiers (soon to be W3C Standard) extensive work is being done on how the data is exchanged (Credential Handler API, OpenID Connect Self Issued Identity Provider (OIDC_SOIP) <- so any installed openID can accept VCs and DID Communications (spec under development at the Decentralized Identity Foundation). Actors supporting this work include wester liberal governments, MSFT, IBM and many many others many cool small startups. We gather twice a year at the Internet Identity Workshop. Our archives for the last 10 years are online.

Re: The Future of Online Identity Is Decentralized

#46

In my ideal world, we have a framework for brick-and-mortar businesses to act as internet notary service providers. If you want a general-purpose open-id style account, you visit a notary, and provide them with a fee and proof of your identity. You tell the notary how much information they can share (in particular, whether they can release your name to the internet, or just the "we verified this account is held by a…

CAcert has a system in place that is close to what you described[1]. Basically already verified users check the identity documents of new users and vouch for their authenticity. Their "Assurer Handbook"[2] is an interesting read. When I became an assurer a few years ago the person that trained me also took their task very seriously and I learned a ton about how to check identity documents for forgeries. That alone made it worth it.

Since we have Let's Encrypt I'm not entirely sure what CAcert's place and purpose is, but I think with an existing network of trusted people they are in an ideal position to pivot into a decentralized online identity system.

Mark Shuttleworth's Web of Trust similarly had so called Thawte Notaries but I think it was discontinued a few years ago.

[1] http://wiki.cacert.org/FAQ/AssuringPeople

[2] http://wiki.cacert.org/AssuranceHandbook2

Re: The Future of Online Identity Is Decentralized

#47
post #14
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

Couldn't the UX just be improved and deliver the benefit while hiding the complexity?

It's more about a fundamental design trade-off rather than removing accidental complexity coming from UX. Currently, most of us delegate the responsibility of identity management (other than memorizing id and password) to one of big-techs, presumably much better at this area than 99% of us. In the fully decentralized world, the burden of proof is now up to users. And they usually don't really care about the best practice for security, privacy and reliability. Technology may improve over time so the equation will get better, but I don't expect this dynamic to change that much.

Re: The Future of Online Identity Is Decentralized

#48

In my ideal world, we have a framework for brick-and-mortar businesses to act as internet notary service providers. If you want a general-purpose open-id style account, you visit a notary, and provide them with a fee and proof of your identity. You tell the notary how much information they can share (in particular, whether they can release your name to the internet, or just the "we verified this account is held by a…

Who notarizes the notaries?

Reputation?

Re: The Future of Online Identity Is Decentralized

#49

In my ideal world, we have a framework for brick-and-mortar businesses to act as internet notary service providers. If you want a general-purpose open-id style account, you visit a notary, and provide them with a fee and proof of your identity. You tell the notary how much information they can share (in particular, whether they can release your name to the internet, or just the "we verified this account is held by a…

Who notarizes the notaries?

The people who consume the notarized documents. If too much crap comes through they can reject the issuer. Kind of like how Symantec CA got dropped by browser makers.

Public notaries are licensed by US state governments. There is generally a background check, brief training course, and application fee. In at least some states they have strict liability for theft of their stamp.

Re: The Future of Online Identity Is Decentralized

#50
post #44

Earlier quoted context omitted.

You've never provided any business with ID? How do you get into nightclubs? The internet is important. When something is important enough, it is worth the risk. That's why people share secrets with their bank, lawyer, doctor, psychologist, etc. We are squandering most of the potential of social media, because its design limits worthwhile conversation to hypotheticals. Since there's no reason to trust the honesty or m…

> How do you get into nightclubs? Clubs don't care about identity. In some parts of the world they care about age and outward signs of affluence and/or attractiveness.

I was thinking of North America, where "carding" is still standard practice.
Post reply on HN