Live data from Hacker News

Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

w3.org

51–60 of 199 posts

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#51
The notion of decentralized identity has been an enchanting vision since Christopher Allen first articulated it in 2016. Since then, DID spec has been around for years in draft form, and there are at least a dozen vendors and/or projects producing DID-compatible or DID-relevant technology.

Of course, these different packages are not (yet) compatible, but that's not the problem. The problem is that, after a good 4 or 5 years, it's hard to find a single project that uses DID protocols at scale in a worthwhile and effective manner.

There are tons of pilot projects and PoCs. A few go into production at limited scale, languish for a while, and then do a slow fade.

I agree with other commenters that DID does not seem to address real-world pain points. I also think that the spec appears murky, abstract, overly complex and hard for developers to work with. I have tried to use DID in projects a couple of times, and found myself sidelining or pushing it into a corner of the system, because it did not seem to serve a useful purpose.

There's a recent alternative to DID, which is narrower in scope and more pragmatic. That is "login with Metamask" or "sign-in with Ethereum" (or something similar in the case of other blockchain platforms).

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#52
post #47

Earlier quoted context omitted.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in. Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

Do they explain anywhere whether the browser is expected to keep a bunch of multi-gigabyte blockchains on my disk? Or, is it simply that Google, Mozilla and whoever else have to serve verification requests for their users? Or is the whole joke in that none of this is figured out?

If I had to guess, I'd say it's the third one.

Given that Mozilla and Google have already publicly objected to this proposal, I don't expect them to implement it. The W3C's word is not the law; no one is obligated to implement every specification they put forth.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#53
post #51

The notion of decentralized identity has been an enchanting vision since Christopher Allen first articulated it in 2016. Since then, DID spec has been around for years in draft form, and there are at least a dozen vendors and/or projects producing DID-compatible or DID-relevant technology. Of course, these different packages are not (yet) compatible, but that's not the problem. The problem is that, after a good 4 or…

> Of course, these different packages are not (yet) compatible

You say this is not a problem, and immediately say this:

> it's hard to find a single project that uses DID protocols at scale in a worthwhile and effective manner.

Of course it's hard. For a protocol to operate at scale its implementations have to be compatible

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#55
post #34

Earlier quoted context omitted.

I'm gonna bet just from the requirements list quoted in that post that the implementations are supposed to be blockchains.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in. Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

I think it speaks extreme volumes that the "methods" of "did" and "com" were both proposed by no-name crypto organizations; "cosmos" seems to be proposed by one guy with a template website maybe unrelated to the relatively major Cosmos blockchain (they're fighting amongst themselves lol); "ens" was proposed by some organization with no website; "evan" was picked up by literally some guy named Evan.

Its not just that they're crypto related; its not even the major players in the crypto space. There are physical organizations you can point to in the crypto space, and if they hopped in and said "yeah this is cool" then that's something. 80% of these organizations have nothing to them. They look like they were formed overnight as this proposal was going through its development.

The only seemingly legitimate proposal in that list, not an obvious planting-my-flag-in-the-ground, is: Baidu proposes "ccp". Lol. Looks like Workday is there proposing "work" as well, that's... something.

I need to read up more on the spec, but that list alone is an extreme embarrassment for W3. Google & Mozilla bring up a fantastic point: What are these things actually going to be used for, not hypothetically, in reality, what is the use case? Its very clear that the Web2 players don't have a good answer for that, and even the successful Web3 players don't either. Is the best response W3 has actually a bunch of nobodies who see something that kind of resembles (but not really) a new DNS, and want to plant their flag in case it gets big?

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#56

I may be suffering from a deficiency of reading comprehension. Can someone please explain to me in plain terms what a DID is and what it's for? It's a "globally unique persistent identifier that does not require a centralized registration authority"[1] - great, an identifier for what exactly? Is it just supposed to be an identifier for anything at all ? Local and remote resources? People? Pokemon cards? [1] https://w…

See https://w3c.github.io/did-use-cases/#onlineShopper

It's blockchain bullshit that you can ignore.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#57
post #22

Earlier quoted context omitted.

Because expecting standardization of DID methods at this point is unreasonable. A premature attempt to standardize DID methods would be both futile and likely harmful. It's futile because the future universe of DID methods can't be anticipated now, so whatever wrong set of DID methods W3 promulgated would include both poor choices and omit good choices. It's harmful because whatever future methods might emerge will r…

> It's futile because the future universe of DID methods can't be anticipated now, so whatever wrong set of DID methods W3 promulgated would include both poor choices and omit good choices Or maybe it's just too soon to try to carve a "standard" into the w3c process stone. A half-baked protocol is worse than no protocol at all.

> A half-baked protocol is worse than no protocol at all.

I think the literal opposite is true, no?

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#58

Something that should be a bit of a warning flag is that I have two decades of identity-related experience but I still have no idea what DID even is . For reference, I've worked with three vendors' implementations of LDAP, several versions of SAML, OAuth, JWT, Okta, Azure Active Directory, etc, etc... I've even deployed Smart Card authentication in the field several times. I literally have no idea, not a clue what DI…

[deleted]

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#59
post #55

Earlier quoted context omitted.

Spot on. The list at https://www.w3.org/TR/did-spec-registries/#did-methods tells you everyone who hopes to cash in. Basically it's like a urn, but every sketchy blockchain startup gets their own namespace.

I think it speaks extreme volumes that the "methods" of "did" and "com" were both proposed by no-name crypto organizations; "cosmos" seems to be proposed by one guy with a template website maybe unrelated to the relatively major Cosmos blockchain (they're fighting amongst themselves lol); "ens" was proposed by some organization with no website; "evan" was picked up by literally some guy named Evan. Its not just that…

> plant their flag in case it gets big?

You have just summarised crypto.

Re: Mozilla and Google Objections Overruled on “Decentralized Identifiers” by W3C

#60
post #44

Wow, the person who wrote that text has some talent for bureaucratese. It's comparatively rare to see that in English, since the language tends toward clear verbs and the active voice. But here I had to re-read a bunch of sentences to figure out what refers to what, while wondering if I need to take a coffee break. I would say that the author probably moonlights as a writer for NYT or something—if the dryness of the…

> It is not questioned that any single DID method might fail to achieve one or more of these properties. The consideration here is whether the proposed DID identifier syntax and associated mechanisms has been sufficiently shown to have defined an extensible class of identifiers that has these properties.

This paragraph gave me temporary brain fog. I think it's saying that so long as the proposed syntax is flexible enough that one or more DID methods can satisfy... and then I'm lost again.

Post reply on HN