Live data from Hacker News

Getting started with decentralized identity

nathangould.com

61–67 of 67 posts

Re: Getting started with decentralized identity

#61

Earlier quoted context omitted.

Blockchain has value here, essentially acting as a distributed collection of digital signatures. If I need to prove my date of birth, why not present a credential, signed by the vital records agency of where I was born to prove it without any data broker in the middle?

Signatures exist outside of the blockchain. You can just send your signed data point, that's the point. The only thing the blockchain protects against in these circumstances would be that the government is denying ever signing your date of birth and you losing your signed token. I don't think that's a problem in practice in most countries where an alternative trust system would even work.

Sure; vaccination credentials took this approach by establishing a registry of known signers.

That approach doesn’t scale.

It’s easy to shit on blockchain, but this particular area is one worth understanding.

Re: Getting started with decentralized identity

#62

Earlier quoted context omitted.

Signatures exist outside of the blockchain. You can just send your signed data point, that's the point. The only thing the blockchain protects against in these circumstances would be that the government is denying ever signing your date of birth and you losing your signed token. I don't think that's a problem in practice in most countries where an alternative trust system would even work.

Sure; vaccination credentials took this approach by establishing a registry of known signers. That approach doesn’t scale. It’s easy to shit on blockchain, but this particular area is one worth understanding.

I don't understand it though. What trust can you derive from the blockchain? If a user visits my site and says "I'm jeroenhd, Spooky23 verified it" then that means absolutely nothing to me. The blockchain may be unalterable (without hard forks, at least) but there's no reason why I'd trust the blockchain more than a piece of paper that says "I'm 18 you can sell me booze".

Re: Getting started with decentralized identity

#63
post #49

Blockchain. It's always blockchain. Can we just not? How about we go back to web 1.0. TLS mutual cert auth with an ID card as a smart card, either from the government or from your favourite third party. Or maybe we go back to web 2.0 with OpenID. Users pick their own identity providers and websites can pick which ones to trust and which ones not to trust. Actually, we already have that, and it's "sign in with Google/…

Well, one of the few plausibly-valuable additions to the world offered by blockchains are globally-distributed databases not owned/controlled/bound to any single organization. Why not make use of them for something other than scams, pump & dumps, etc.?

Because the times where a globally distributed non-controllable database is actually useful to solve problems is fairly limited.

Blockchain people are the epitome of the "when all you have is a hammer everything looks like a nail" proverb.

Re: Getting started with decentralized identity

#64

Earlier quoted context omitted.

Signatures exist outside of the blockchain. You can just send your signed data point, that's the point. The only thing the blockchain protects against in these circumstances would be that the government is denying ever signing your date of birth and you losing your signed token. I don't think that's a problem in practice in most countries where an alternative trust system would even work.

Sure; vaccination credentials took this approach by establishing a registry of known signers. That approach doesn’t scale. It’s easy to shit on blockchain, but this particular area is one worth understanding.

> That approach doesn’t scale.

Why not? Traditional PKI has generally met the scalability test, so this is a pretty bold claim.

> It’s easy to shit on blockchain, but this particular area is one worth understanding.

Sometimes i wonder if blockchain is really an edgy teenager in trenchcoat. Criticism is always met with "~ThEY jUSt donT UnderStAnD Meeee!!!~~~"

Re: Getting started with decentralized identity

#65
post #29
post #17

Earlier quoted context omitted.

Wow now it sounds awful for other reasons. Still pie-in-the-sky, but I still think we've been low ambition & not had good decentralized-identity-preconditions to begin exploring web-of-trust models. Past behavior is a huge indicator, one we can judge, & which many others will have judged. Trying to filter those other judges, decide what trust anchors we have & what biases to give, is a place where humanity would have…

> web-of-trust models Been there, done that, seen it abused for SEO.

Hi John. Where has it been done distributedly ever and at any decent size of adoption?

To me, the premise that we start with some self soverign moderation opens to the door to endless creatives refinements & betterments we can collaboratively explore? Afaik Earth has never had that privilege, has never really tried this at any degree. We've had some keysigning parties but actual reputation & moderation... no.

Im not sure what evidence we have to stick a fork in this one & call it done. Doesnt feel to me like we hardly ever began.

Re: Getting started with decentralized identity

#66
post #65
post #29

Earlier quoted context omitted.

> web-of-trust models Been there, done that, seen it abused for SEO.

Hi John. Where has it been done distributedly ever and at any decent size of adoption? To me, the premise that we start with some self soverign moderation opens to the door to endless creatives refinements & betterments we can collaboratively explore? Afaik Earth has never had that privilege, has never really tried this at any degree. We've had some keysigning parties but actual reputation & moderation... no. Im not…

Google's original backlink-based rating system was a web of trust model. A whole industry developed around gaming it.

Re: Getting started with decentralized identity

#67
post #39
post #37

Earlier quoted context omitted.

> then you can pretty much get rid of them storing anything at all about you. But why would they want to? If i understand, the premise of this idea is basically that we don't trust service providers with our data/to have our best interests at heart. So we make a complex system where service providers (for the sake of argument, i dont know if i buy this) must respect our wishes. Which raises the question, why would th…

>> then you can pretty much get rid of them storing anything at all about you. > But why would they want to Well the overall premise is that if they don't need to, it will become harder to justify to your users. The second premise is that legislation can be put in place to forbid the ad hoc storage of PIIs. Europe already has in place legislation to allow users to have read and removal access to their PIIs stored by…

> Well the overall premise is that if they don't need to, it will become harder to justify to your users. The second premise is that legislation can be put in place to forbid the ad hoc storage of PIIs.

If your system requires a government enforced monopoly, or some sort of class uprising, to succeed, its probably a bad system.

Literally any system, regardless of how good an idea it is, would succeed under those conditions.

Post reply on HN