Live data from Hacker News

The Future of Online Identity Is Decentralized

yarmo.eu

61–70 of 202 posts

Re: The Future of Online Identity Is Decentralized

#61

Your identity is going to come down knowledge of the private key from some sort of public key system. Why not just standardize that? An excellent example of something perversely non-standardized for identities can be found in messaging. Signal, Matrix, Whatsapp and OMEMO are even supposedly based on the same protocol. In terms of identity they are all complete silos. All the things you establish about an identity on…

What happens when the private key is lost? We can either have certificate authorities issue you a new one, or you would need to approach your peers and have e.g. three of them confirm that you've changed keys.

Re: The Future of Online Identity Is Decentralized

#62
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

In the US, everyone uses credit cards (centralized identity) to pay for stuff. In Mexico, credit cards are stolen and reamed for all they're worth by criminals. As a result, everyone uses cash (decentralized, anonymous, difficult to use). Everyone could move to decentralized in the face of significant pressure, even if centralized identity is more convenient.

All central authorities are built on trust, fear, or complacency. Americans are complacent with the credit card system and trust it for the most part. The Experian breach has shown that breaches of trust are easily overlooked in favor of complacency, at least to a point.

Considering how Americans view other Americans (I hear "stupid" thrown around a lot), I strongly doubt that a decentralized authority would ever gain enough trust in the US to take hold today without a strong historical precedent.

For what it's worth, cash is still centralized. It's made "legitimate" by the power of the central government, and is managed & controlled by that authority. Given, it is somewhat "decentralized" because the value of fiat money comes from the people's agreement that the currency has value. On the other hand, the US dollar's global hegemony exists in large part because of global US Military presence, which is absolutely a "central authority".

Re: The Future of Online Identity Is Decentralized

#63

Your identity is going to come down knowledge of the private key from some sort of public key system. Why not just standardize that? An excellent example of something perversely non-standardized for identities can be found in messaging. Signal, Matrix, Whatsapp and OMEMO are even supposedly based on the same protocol. In terms of identity they are all complete silos. All the things you establish about an identity on…

Keybase kludge's it together, and yet still, no one seems to care or use it.

Re: The Future of Online Identity Is Decentralized

#64
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

In the US, everyone uses credit cards (centralized identity) to pay for stuff. In Mexico, credit cards are stolen and reamed for all they're worth by criminals. As a result, everyone uses cash (decentralized, anonymous, difficult to use). Everyone could move to decentralized in the face of significant pressure, even if centralized identity is more convenient.

Bad example. In Australia, everyone was using credit cards.. but they have PIN code + chip.

If a centralized system is not inept, it can do all the same things decentralized things do and better.

Re: The Future of Online Identity Is Decentralized

#65
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

In the US, everyone uses credit cards (centralized identity) to pay for stuff. In Mexico, credit cards are stolen and reamed for all they're worth by criminals. As a result, everyone uses cash (decentralized, anonymous, difficult to use). Everyone could move to decentralized in the face of significant pressure, even if centralized identity is more convenient.

Yes, I suppose if we moved to becoming a lawless society fuelled by drug lords....then yes, I can see how the hoops could be worth it.

Re: The Future of Online Identity Is Decentralized

#67
post #19

In my ideal world, we have a framework for brick-and-mortar businesses to act as internet notary service providers. If you want a general-purpose open-id style account, you visit a notary, and provide them with a fee and proof of your identity. You tell the notary how much information they can share (in particular, whether they can release your name to the internet, or just the "we verified this account is held by a…

It would create a small financial (and convenience) pressure to use one identity. Careful design would be needed to ensure that multiple identities are encouraged and accepted.

There is enormous pressure to converge on one identity. IAM has huge network effects. On-boarding customers is an expense so businesses and governments rely heavily on existing rails like email, SSN+DOB, Facebook, SMS, etc. If you don't want to surrender SSN or your whole Facebook profile your only option is to reject the service entirely.

Re: The Future of Online Identity Is Decentralized

#68
post #62

Earlier quoted context omitted.

In the US, everyone uses credit cards (centralized identity) to pay for stuff. In Mexico, credit cards are stolen and reamed for all they're worth by criminals. As a result, everyone uses cash (decentralized, anonymous, difficult to use). Everyone could move to decentralized in the face of significant pressure, even if centralized identity is more convenient.

All central authorities are built on trust, fear, or complacency. Americans are complacent with the credit card system and trust it for the most part. The Experian breach has shown that breaches of trust are easily overlooked in favor of complacency, at least to a point. Considering how Americans view other Americans (I hear "stupid" thrown around a lot), I strongly doubt that a decentralized authority would ever gai…

It's unfair to say we still use credit because we are complacent. If you stop caring about building a credit score, you will end up paying more money in things like mortgages or car loans. There is a financial incentive to use credit cards (if you don't miss payments) despite the breach of trust.

Re: The Future of Online Identity Is Decentralized

#69
post #52

Earlier quoted context omitted.

So since you have one identifier, companies can track you across all domains. They can find out if you are a user of sex.com or dangerouspoliticalopinions.com They can do this by trying to register an account with your email address, and being told it was already registered. Here is a tool that allows anyone to do it: https://www.quora.com/Is-there-a-way-to-know-which-all-sites... https://brandyourself.com/blog/priva…

Everyone? Unless the sites publish a list of logins for everyone to read the only one with that knowledge would be the identity provider.

Not at all. See above.

Re: The Future of Online Identity Is Decentralized

#70

Earlier quoted context omitted.

Who notarizes the notaries?

The people who consume the notarized documents. If too much crap comes through they can reject the issuer. Kind of like how Symantec CA got dropped by browser makers. Public notaries are licensed by US state governments. There is generally a background check, brief training course, and application fee. In at least some states they have strict liability for theft of their stamp.

What does it mean to reject the issuer when there are around 4.4 million notaries in the US? What systems are in place now or would need to be created in order to aggregate trust and what are the pros and cons associated with those systems?
Post reply on HN