Live data from Hacker News

The Future of Online Identity Is Decentralized

yarmo.eu

51–60 of 202 posts

Re: The Future of Online Identity Is Decentralized

#51
post #44

Earlier quoted context omitted.

You've never provided any business with ID? How do you get into nightclubs? The internet is important. When something is important enough, it is worth the risk. That's why people share secrets with their bank, lawyer, doctor, psychologist, etc. We are squandering most of the potential of social media, because its design limits worthwhile conversation to hypotheticals. Since there's no reason to trust the honesty or m…

> How do you get into nightclubs? Clubs don't care about identity. In some parts of the world they care about age and outward signs of affluence and/or attractiveness.

>Age

Re: The Future of Online Identity Is Decentralized

#52
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

So since you have one identifier, companies can track you across all domains.

They can find out if you are a user of sex.com or dangerouspoliticalopinions.com

They can do this by trying to register an account with your email address, and being told it was already registered.

Here is a tool that allows anyone to do it:

https://www.quora.com/Is-there-a-way-to-know-which-all-sites...

https://brandyourself.com/blog/privacy/find-all-accounts-lin...

Re: The Future of Online Identity Is Decentralized

#54
post #22
post #14

Earlier quoted context omitted.

Couldn't the UX just be improved and deliver the benefit while hiding the complexity?

Yes, but that requires an economic model. UX is often well over 90% of the work for a product and usually includes a ton of work that is not much fun and people have to be paid to do. Centralized has subscriptions, advertising, and "surveillance capitalism." Decentralized has nothing. I had some hope that cryptocurrency would provide some kind of mechanism, but cryptocurrency was taken over and destroyed by scammers…

The lack of an economic model is IMHO why decentralized solutions have not succeeded, not technical challenges.

You’re right. This lack needs to be addressed for us to progress.

How about this model? Would like feedback: https://qbix.com/token

Re: The Future of Online Identity Is Decentralized

#55
post #14

Earlier quoted context omitted.

Couldn't the UX just be improved and deliver the benefit while hiding the complexity?

It's more about a fundamental design trade-off rather than removing accidental complexity coming from UX. Currently, most of us delegate the responsibility of identity management (other than memorizing id and password) to one of big-techs, presumably much better at this area than 99% of us. In the fully decentralized world, the burden of proof is now up to users. And they usually don't really care about the best prac…

On the other hand, however, the outcomes of a breach are vastly different. An individual who fails to secure their information is liable for only their information. If a "big-tech" is compromised, they are liable for everyone's information.

If users are still unwilling to run their own infra, then that seems like a great opportunity for Identity as a Service. I'd feel much more comfortable handing identity to a firm whose entire business model revolves around securing my information and protecting my privacy rather than a big-tech.

Re: The Future of Online Identity Is Decentralized

#56
post #14

Earlier quoted context omitted.

Couldn't the UX just be improved and deliver the benefit while hiding the complexity?

It's more about a fundamental design trade-off rather than removing accidental complexity coming from UX. Currently, most of us delegate the responsibility of identity management (other than memorizing id and password) to one of big-techs, presumably much better at this area than 99% of us. In the fully decentralized world, the burden of proof is now up to users. And they usually don't really care about the best prac…

This is a great point that I hadn't thought of. Well said.

I'd rather, as a company, risk managing all of my users' identities (vulnerability to a data breach, mitigated by a well-trained security team) than trust my users to manage their own security well and inevitably deal with a mass amount of compromised accounts.

As a user, especially if I'm not technical, I'd have a strong bias towards handing my identity to a team that's spent years studying computer security. Managing my own identity would involve learning a lot about computer security. That would take a lot of time and I'd really have to care about it to do it "right". Regardless, I'd likely get a lot of things wrong, leading to my identity being more insecure than if I had just stored it with someone like Apple.

Re: The Future of Online Identity Is Decentralized

#57
post #52
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

So since you have one identifier, companies can track you across all domains. They can find out if you are a user of sex.com or dangerouspoliticalopinions.com They can do this by trying to register an account with your email address, and being told it was already registered. Here is a tool that allows anyone to do it: https://www.quora.com/Is-there-a-way-to-know-which-all-sites... https://brandyourself.com/blog/priva…

Everyone? Unless the sites publish a list of logins for everyone to read the only one with that knowledge would be the identity provider.

Re: The Future of Online Identity Is Decentralized

#58
Your identity is going to come down knowledge of the private key from some sort of public key system. Why not just standardize that?

An excellent example of something perversely non-standardized for identities can be found in messaging. Signal, Matrix, Whatsapp and OMEMO are even supposedly based on the same protocol. In terms of identity they are all complete silos. All the things you establish about an identity on one system is completely unusable on another.

Creating systems to kludge this mess together seems to be a way of avoiding the root problem here...

Re: The Future of Online Identity Is Decentralized

#59
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

In the US, everyone uses credit cards (centralized identity) to pay for stuff.

In Mexico, credit cards are stolen and reamed for all they're worth by criminals. As a result, everyone uses cash (decentralized, anonymous, difficult to use). Everyone could move to decentralized in the face of significant pressure, even if centralized identity is more convenient.

Post reply on HN