Live data from Hacker News

Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

lists.w3.org

51–60 of 66 posts

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#51

Better imho to ask: what user problem is DID solving? Because: if it's truly decentralized then there's no need to publish it. But publication is a core aspect of DID. That it must be published is a jedi mind trick that allows in "on a blockchain". Now we see the real problem being solved (not a user problem): need something published on a blockchain.

From https://www.w3.org/TR/did-core/#design-goals Decentralization | Eliminate the requirement for centralized authorities or single point failure in identifier management, including the registration of globally unique identifiers, public verification keys, services, and other information. Control | Give entities, both human and non-human, the power to directly control their digital identifiers without the need to re…

> In short, if the large platforms like Facebook, Google, Apple, Microsoft et al started using DIDs, we could start using logins across platforms instead of creating new accounts for each one.

Not a chance really.

First, DIDs define a method behind resolving data be it use a website, use bitcoin classic, etc. There are over 100 defined, and only "web" and "key" (inlined data in the URI) have achieved interoperability.

Second, if DIDs define authentication then your Apple/Facebook/Google account will require to own the DID so that they can make sure the authentication requirements aren't rewritten to be too weak to qualify.

Third, DIDs used in that way are less privacy preserving than the existing system, since it is now a global identifier shared with everyone.

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#52
post #4

Does anyone have links to the Google and Microsoft reviews mentioned in this email? Browsing the last 6 months of public-new-work archives doesn't seem to yield many other reviews of the DID proposal.

Reviews may be public or private, Google and Microsoft did not make their reviews public.

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#53
post #49

Earlier quoted context omitted.

Google stands to lose a lot if DIDs take off. They'll stop at nothing.

Before the argument against blockchain methods is an argument against centralized methods such as "did:ccp", which seems to be an identity mechanism backed by Baidu accounts: https://w3c.github.io/did-spec-registries/#did-methods If this were a Google conspiracy using Mozilla sock puppets, why would they bring that up as an objection, and ask to move the spec back to the discussion phase explicitly forbidding such me…

mozilla conspiracy:

Mozilla referenced quite openly "Google sez PoW bad", idk if something this open is a conspiracy.

"Proof-of-work methods (e.g. blockchains) are harmful for sustainability (s12y). Also as noted by __Google__, the registry contains methods which rely upon proof-of-work which is wasteful. “Successful” proof-of-work systems ..."

Google simply wants to own the entire identity stack end to end, and they can, because they own Android. Same with Apple. Apple is canvassing various jurisdictions right now with their Digital ID, and demands internal govt discussions use a codename and that nobody mentions Apple by name, and also try to restrict who gets to know, gonna be one anti-open standard if they get their way. Google is likely doing the same, haven't been following this stuff too closely these days, but their ventures arm has made investments all over in identity in the last decade.

centralized objection:

The DID push from Microsoft hinges on their ability to route around the mobile platform control (because they don't have a mobile platform), so that they can even begin to compete with Apple/Google here. I'm sure Apple and Google just love the idea of being cut out and commoditized.

That's all this is about, Microsoft not having a mobile platform. so now MSFT is fighting for an open standard, which is hilarious. They don't care if it's centralized on some identity provider like github or whatever. If you dig deep enough all identity is centralized in the end on the most authoritative source of identity: government. "decentrablazed" is just a window dressing.

I concede that this doesn't explain Mozilla actions very clearly, but they are at this point a mostly irrelevant player in the identity market anyway, nobody except their 3% of marketshare cares what they think. Mozilla just renewed their deal with Google for 400mil, so it could very well be an executive decision that "DID very bad, no matter what", and how their standards architects have to contort themselves into pretzels on mailing lists and invent new catchy acronyms. The mozilla-google contract terms haven't been published even in the roughest approximation, make of that what you will.

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#54

Better imho to ask: what user problem is DID solving? Because: if it's truly decentralized then there's no need to publish it. But publication is a core aspect of DID. That it must be published is a jedi mind trick that allows in "on a blockchain". Now we see the real problem being solved (not a user problem): need something published on a blockchain.

It solves the problem of Microsoft not having a mobile platform in which to lock you in. Unlike their competitors in identity: Apple iOS and Google's Android.

Therefore MSFT now needs an open-ish standard so that it's not dead in the water.

Funny how times have changed.

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#55
post #49

Earlier quoted context omitted.

Before the argument against blockchain methods is an argument against centralized methods such as "did:ccp", which seems to be an identity mechanism backed by Baidu accounts: https://w3c.github.io/did-spec-registries/#did-methods If this were a Google conspiracy using Mozilla sock puppets, why would they bring that up as an objection, and ask to move the spec back to the discussion phase explicitly forbidding such me…

mozilla conspiracy: Mozilla referenced quite openly "Google sez PoW bad", idk if something this open is a conspiracy. "Proof-of-work methods (e.g. blockchains) are harmful for sustainability (s12y). Also as noted by __Google__, the registry contains methods which rely upon proof-of-work which is wasteful. “Successful” proof-of-work systems ..." Google simply wants to own the entire identity stack end to end, and they…

Right, it's not a conspiracy. When there are multiple participants in a forum, and one participant has already raised a point that you agree with, saying "I agree with so-and-so's point about..." is the normal way to do things.

What would be a conspiracy - and a genuine problem - is if Mozilla were repeating Google's line because they were there to advocate for Google's beliefs instead of what they thought was best, i.e,. the group was stacked in Google's favor. But the evidence we have doesn't permit us to conclude that this is happening or even likely.

As a simple example, Mozilla and Google tend to reach the same conclusions about whether a new CA should be trusted or an old CA should be distrusted. But this isn't because one is telling the other what to do; it's because they have similar standards and expectations of CAs.

(It would also be weird, and perhaps a conspiracy and a problem, if Google were not a participant in the W3C and Mozilla felt that its role was to represent Google's thoughts instead of its own. But that's not what's happening here, either.)

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#56
post #35

Earlier quoted context omitted.

The user problem- for those who see it that way- is that right now, digital stuff related to a person, is tied up primarily with the person's email address, or in some cases with the person's phone number. (For the purposes of this discussion, call the email address or phone number an "identifier".) Why is this a problem? Two reasons: 1. People don't "control" those identifiers Many email addresses used in this conte…

Somebody introduces a new technology to address these concerns every couple years and it doesn't go anywhere. These aren't actually problems to a lot of users. That's the real problem that needs to be solved - awareness. And that's a lot harder than taking the identity solutions we came up with in the Identity 2.0 days and adding a blockchain.

> Somebody introduces a new technology to address these concerns every couple years and it doesn't go anywhere. These aren't actually problems to a lot of users.

"Use Cases and Requirements for Decentralized Identifiers" https://www.w3.org/TR/did-use-cases/

> 2. Use Cases: Online shopper, Vehicle assemblies, Confidential Customer Engagement, Accessing Master Data of Entities, Transferable Skills Credentials, Cross-platform User-driven Sharing, Pseudonymous Work, Pseudonymity within a supply chain, Digital Permanent Resident Card, Importing retro toys, Public authority identity credentials (eIDAS), Correlation-controlled Services

And then, IIUC W3C Verifiable Credentials / ld-proofs can be signed with W3C DID keys - that can also be generated or registered centrally, like hosted wallets or custody services. There are many Use Cases for Verifiable Credentials: https://www.w3.org/TR/vc-use-cases/ :

> 3. User Needs: Education, Retail, Finance, Healthcare, Professional Credentials, Legal Identity, Devices

> 4. User Tasks: Issue Claim, Assert Claim, Verify Claim, Store / Move Claim, Retrieve Claim, Revoke Claim

> 5. Focal Use Cases: Citizenship by Parentage, Expert Dive Instructor, International Travel with Minor and Upgrade

> 6. User Sequences: How a Verifiable Credential Might Be Created, How a Verifiable Credential Might Be Used

IIRC DHS funded some of the W3C DID and Verified Credentials specification efforts. See also: https://news.ycombinator.com/item?id=26758099

There's probably already a good way to bridge between sub-SKU GS1 schema.org/identifier on barcodes and QR codes and with DIDs. For GS1, you must register a ~namespace prefix and then you can use the rest of the available address space within the barcode or QR code IIUC.

DIDs can replace ORCIDs - which you can also just generate a new one of - for academics seeking to group their ScholarlyArticles by a better identifier than a transient university email address.

The new UUID formats may or may not be optionally useful in conjunction with W3C DID, VC, and Verifiable News, etc. https://news.ycombinator.com/item?id=28088213

When would a DID be a better choice than a UUID?

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#57

It is much easier to destroy than to create. The attack on DIDs is the same pattern of attack on Extensible Resource Identifiers (XRIs), one of the standardization attempts along the path to DIDs. Politics and soundbytes popular at the time are used to garner a boost in public opinion, or to defeat something that may threaten the status quo, or to just defeat the efforts of someone disliked by a group (some of the sa…

I'm not going to give bigcorps a pass, but the thing with specs is that it is hard to criticize it until the spec is, you know, published in many cases, especially if you aren't in the committee.

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#58

Better imho to ask: what user problem is DID solving? Because: if it's truly decentralized then there's no need to publish it. But publication is a core aspect of DID. That it must be published is a jedi mind trick that allows in "on a blockchain". Now we see the real problem being solved (not a user problem): need something published on a blockchain.

It solves the problem of Microsoft not having a mobile platform in which to lock you in. Unlike their competitors in identity: Apple iOS and Google's Android. Therefore MSFT now needs an open-ish standard so that it's not dead in the water. Funny how times have changed.

Isn't Microsoft also objecting to making this a W3C standard?

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#59
post #35

Earlier quoted context omitted.

Somebody introduces a new technology to address these concerns every couple years and it doesn't go anywhere. These aren't actually problems to a lot of users. That's the real problem that needs to be solved - awareness. And that's a lot harder than taking the identity solutions we came up with in the Identity 2.0 days and adding a blockchain.

> Somebody introduces a new technology to address these concerns every couple years and it doesn't go anywhere. That's the problem, we need protocols and standards, then laws to enforce those, not _technology_. The DID specification is a "old" attempt at this, I remember first coming across DIDs back in 2015-2016 sometime, so DIDs are hardly new. > we came up with in the Identity 2.0 days and adding a blockchain Good…

While of course it is just one of many (alongside e.g. “just use a public key”(or hash of one or something. I don’t know the details), and “just use a github username”, when looking at the example resolver, and trying to read the docs, my impression was that a fair proportion of the examples given were blockchain related?

So, that could be part of the reason for the misconception.

I was first introduced to it by the, bold post on the Protocol Labs (the people behind IPFS) blog, about ION as a particular type of DID (sorry, “type of” is probably not quite the right terminology, but I’m not sure what the preferred terminology is) which appears to use the Bitcoin chain (but in a way that involves only very few transactions and very little on-chain data).

Personally I found the FAQ page for DIDs to be a little,

well, it isn’t particularly focused on assisting the reader in evaluating “should I care about this”?

I guess in some ways it seemed a third of the from being a normal FAQ and being a specification, or, not a specification but a, documentation of policy and plans etc.

Re: Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'

#60
post #58

Earlier quoted context omitted.

It solves the problem of Microsoft not having a mobile platform in which to lock you in. Unlike their competitors in identity: Apple iOS and Google's Android. Therefore MSFT now needs an open-ish standard so that it's not dead in the water. Funny how times have changed.

Isn't Microsoft also objecting to making this a W3C standard?

I'm sure they do object to things from time to time, but my impression from DIF conference calls was that MSFT is the biggest corporate backer.

Google and Apple aren't even members and do not really participate, afaik. https://identity.foundation/

Post reply on HN