Live data from Hacker News

Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

w3.org

61–70 of 108 posts

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#61
post #52

Earlier quoted context omitted.

That's the list of methods; and yes, there is very much a land grab going on right now. No, there's nothing stopping you making your own methods. But will anyone actually use it?

So if I’m building a service that lets somebody login with a DID, and I’m using a DID library to verify your authN then that library needs a different code block for every one of those methods?? LOL. What could possibly go wrong? Or less sarcastically, how could this possibly be expected to work?

Yeah DID is a dumpster fire. It's a consulting company's dream spec. Anything is possible but almost nothing is required. It smells a bit like SAML all over again, wherein they try to satisfy every stakeholder and end up satisfying none.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#62
I wonder if this drives a schism in Google's Chrome implementation of W3C recommendations, given Google's objections to the spec. I feel like they already have shown a willingness to diverge from the specs and do what they feel is best, with a large number of experimental chrome features not included in w3c.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#63
post #40
post #24

Why not simply a uri with an uuid in it?

More flexibility. The did:peer: method, for example, encodes the did document directly in its URI.

Like `data:text/plain;base64,SGVsbG8sIFdvcmxkIQ==`?

I must be too old, I do not understand the interest of this stuff compared to controlling a domain.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#64
The idea behind DIDs and VCs (verifiable credentials, that go along with did's to prove claims about an entity) is fantastic.

Decentralize and normalize global IDs! Have ways to express data about them that contains the proof of ownership of the ID embedded.

The issues are with the execution in my opinion: the spec is too complex, the did methods are not nearly mature enough / constrained enough (some don't even use PKI...), and verifiable credentials / presentations are hard to get going.

For this to take off, they need to overcome a 3 sided market cold start (issuers, holders, controllers), with no clear monetization behind it.

I hope it works but I'm guessing we're not quite there.

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#65
There's still a lot to figure out in the space, and the blockchain adjacency always makes things feel like a land grab or first-mover obsessive. I don't think that much matters though. The majority of us will still keep our identity in centralized providers, but the real win is on the overhead of developers and the overall security model of identity on the web as the methods and registries get fleshed out.

Something important to track is the OIDC-SIOP v2 spec [1]. As this gets adopted by libraries and services that people are already using to handle their auth, it becomes effectively easier to "turn on" self-custody of identities for your users. I imagine there will be a lot of different options in terms of methods and registries to choose to accept, and the centralized providers of today will probably have a large say in what methods and registries get accepted.

Ultimately there are a lot of use cases enabled by deferring to the user for their identity and potentially other verifiable claims about themselves. The most obvious use case is phones using their secure elements to actually provide a password-less UX on the web while also allowing developers to skip dealing with user authentication. Less obvious (to most people) are things like verifying you own some NFT, or verifying that you have Bitcoin in some escrow so you're likely not a bot willing to get blacklisted on some platform.

This is the step that's required to create the real land grab over semantic User space - where "JoeSchmoe" really is the one and only.

[1] https://openid.net/specs/openid-connect-self-issued-v2-1_0.h...

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#66
post #5

This relies on public-key cryptography? If that is the case, then who is responsible for maintaining the private key? If that responsibility is with the user, then what happens if the user loses the private key? Does the user loses the identity as well? Is there a way to recover that?

We're already in use of dIDs on the chia blockchain, and it can be used to verify who issued an NFT to prevent fraud. People have already built games on this and used it to save character profiles (dIDs). Custody solutions are what save you, you can see Bram Cohen talk about it here https://odysee.com/@Chia:d/off-the-chain-Bram-Cohen-2022:5

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#67
post #43
post #11

I was initially pretty hyped when I read the abstract for DIDs, bookmarked the spec and read it later. The "spec" is a bunch of buzzwords and vague generic "concepts". The DIDs themselves mean basically nothing, it's the "methods" that actually must have their own specification and actually "do something". Another feeling you can quickly get from DIDs is that they're blockchain centric. The entire concept is "jack of…

The standard has grown out of the blockchain space, because they finally offered a way to do decentralized PKI. Most methods are based on blockchain networks. But there are some that work without blockchains. Like IOTA, IPFS, p2p, web, etc.

I mean, let's be real here. IOTA is a blockchain in all but name, IPFS is substantially blockchain-adjacent, "p2p" is vague to the point of meaninglessness (and isn't actually a registered method), and "web" is silly (a web site is already identified perfectly well by its URL).

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#68
post #41
post #8

Earlier quoted context omitted.

Google and Mozilla objected: https://www.w3.org/2022/06/DIDRecommendationDecision.html

Google is not very surprising, because they're probably the largest issuer of centralized identities. DIDs eat their core business.

[deleted]

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#69
post #57

Earlier quoted context omitted.

Funny to see Google and Mozilla siding on ethical issues. It really seems like the W3C has finally lost its compass and now wants to venture into the blockchain. Only positive thing is to see Google loosing once in a standards fight, however, I think it might just have been the wrong anarchist endeavour inside the W3C. In the end we will get more centralisation because looks like nobody except the big ones can push s…

> Funny to see Google and Mozilla siding on ethical issues It's not the first time Google and Mozilla sided together against the W3C on web standards, and the last notable time resulted, over time, in the W3C ultimately being displaced from any role in the HTML and DOM standards. The standards group that implementers listen to (which, for some reason, seems to be the one that listens to implementers, when there are c…

> It's not the first time Google and Mozilla sided together against the W3C on web standards, and the last notable time resulted, over time, in the W3C ultimately being displaced from any role in the HTML and DOM standards.

By who?

Re: Decentralized Identifiers (DIDs) v1.0 Becomes a W3C Recommendation

#70

Earlier quoted context omitted.

> Funny to see Google and Mozilla siding on ethical issues It's not the first time Google and Mozilla sided together against the W3C on web standards, and the last notable time resulted, over time, in the W3C ultimately being displaced from any role in the HTML and DOM standards. The standards group that implementers listen to (which, for some reason, seems to be the one that listens to implementers, when there are c…

> It's not the first time Google and Mozilla sided together against the W3C on web standards, and the last notable time resulted, over time, in the W3C ultimately being displaced from any role in the HTML and DOM standards. By who?

WHATWG

https://whatwg.org/

Post reply on HN