Live data from Hacker News

The Future of Online Identity Is Decentralized

yarmo.eu

71–80 of 202 posts

Re: The Future of Online Identity Is Decentralized

#71
post #62

Earlier quoted context omitted.

All central authorities are built on trust, fear, or complacency. Americans are complacent with the credit card system and trust it for the most part. The Experian breach has shown that breaches of trust are easily overlooked in favor of complacency, at least to a point. Considering how Americans view other Americans (I hear "stupid" thrown around a lot), I strongly doubt that a decentralized authority would ever gai…

It's unfair to say we still use credit because we are complacent. If you stop caring about building a credit score, you will end up paying more money in things like mortgages or car loans. There is a financial incentive to use credit cards (if you don't miss payments) despite the breach of trust.

I didn't say it's just complacency that keeps the credit system going. Low friction purchasing (complacency) absolutely plays a strong role. Trust is important, too (but is less strong than complacency) because the system wouldn't be used at all without it, and, to your point, fear absolutely plays a role as well.

Re: The Future of Online Identity Is Decentralized

#72
I’m happy to support IndieAuth (a decentralized identity protocol built on top of OAuth 2.0) on my site and give people the option to use their personal site, if they have one, as a way of identifying themselves and performing authentication.

I described the motivation in more detail at https://github.com/shurcooL/home/issues/34.

Re: The Future of Online Identity Is Decentralized

#73

Earlier quoted context omitted.

The people who consume the notarized documents. If too much crap comes through they can reject the issuer. Kind of like how Symantec CA got dropped by browser makers. Public notaries are licensed by US state governments. There is generally a background check, brief training course, and application fee. In at least some states they have strict liability for theft of their stamp.

What does it mean to reject the issuer when there are around 4.4 million notaries in the US? What systems are in place now or would need to be created in order to aggregate trust and what are the pros and cons associated with those systems?

For individual notaries file a complaint about incompetence or report them for fraud. Signatures, seals, and watermarks aren't as good as public crypto but that's okay because phone calls, clearinghouses, and the legal system backstops them (especially for reversible transactions).

Rejecting issuers would be more applicable to repeated transactions from a corporate certificate authority.

Re: The Future of Online Identity Is Decentralized

#74
post #21

The future of online identity is indeed decentralized and not distributed, meaning that users will always have some super nodes to handle their identity on behalf of them. In my opinion Facebook/Twitter/etc are not identity providers, they are silos. Sure they are very successful ones and can even used as identity providers at some places, but as long as they don't open up they can easily die anytime. The author sugg…

They did offer @facebook enails once, and it would integrate with your messages app. It didn’t really take off though, and I guess was quietly withdrawn. https://techcrunch.com/2010/11/15/facebook-messaging/

yeah I remember that but it was never really pushed forward properly

Re: The Future of Online Identity Is Decentralized

#75

Your identity is going to come down knowledge of the private key from some sort of public key system. Why not just standardize that? An excellent example of something perversely non-standardized for identities can be found in messaging. Signal, Matrix, Whatsapp and OMEMO are even supposedly based on the same protocol. In terms of identity they are all complete silos. All the things you establish about an identity on…

What happens when the private key is lost? We can either have certificate authorities issue you a new one, or you would need to approach your peers and have e.g. three of them confirm that you've changed keys.

One could also use Shamir's Secret Sharing algorithm to have a number of your peers hold your secret key without them being able to access it. When you've lost the key, you have a subset of the peers reproduce it for you, by sharing their portion of the secret. Cryptography is pretty great.

Re: The Future of Online Identity Is Decentralized

#76
"Built for individuals, I recently launched Keyoxide which uses cryptographic keypairs to accomplish decentralized identity verification."

So this is about the introduction of a new identity service. From what I get looking into Keyoxide it basically strives to be what Keybase originally intended to be.

From their Keybase migration guide [1]:

"Keyoxide as a partial replacement for Keybase

It's important to moderate expectations and state that Keyoxide only replaces the subset of Keybase features that are considered the "core" features: message encryption, signature verification and identity proofs.

Message decryption and signing are not supported features: they would require you to upload your secret key to a website which is a big no-no.

Encrypted chat and cloud storage are not supported features: there are plenty of dedicated alternative services.

If you need any of these Keybase-specific supports, Keyoxide may not be a full Keybase replacement for you but you could still generate a profile and take advantage of distributed identity proofs."

[1] https://keyoxide.org/guides/migrating-from-keybase

Re: The Future of Online Identity Is Decentralized

#77

"Built for individuals, I recently launched Keyoxide which uses cryptographic keypairs to accomplish decentralized identity verification." So this is about the introduction of a new identity service. From what I get looking into Keyoxide it basically strives to be what Keybase originally intended to be. From their Keybase migration guide [1]: "Keyoxide as a partial replacement for Keybase It's important to moderate e…

The key difference is that instead of the Keybase server storing verifications, it looks like they tell you to add the link to the proof directly to your key as a notation.

This means the proof isn't dependent on a central server, which seems like a significant improvement.

Re: The Future of Online Identity Is Decentralized

#78
Correctly identified problem.

Far too technical and obscure a solution for 99% of the world.

I think Apple, while not a complete solution, shows a path forward with Sign In with Apple allowing you to generate a relay email.

As always, whoever nails the user experience will win.

Re: The Future of Online Identity Is Decentralized

#79
post #62

Earlier quoted context omitted.

In the US, everyone uses credit cards (centralized identity) to pay for stuff. In Mexico, credit cards are stolen and reamed for all they're worth by criminals. As a result, everyone uses cash (decentralized, anonymous, difficult to use). Everyone could move to decentralized in the face of significant pressure, even if centralized identity is more convenient.

All central authorities are built on trust, fear, or complacency. Americans are complacent with the credit card system and trust it for the most part. The Experian breach has shown that breaches of trust are easily overlooked in favor of complacency, at least to a point. Considering how Americans view other Americans (I hear "stupid" thrown around a lot), I strongly doubt that a decentralized authority would ever gai…

> The Experian breach has shown that breaches of trust are easily overlooked in favor of complacency, at least to a point.

I disagree that it matters for trust in CC's. It may have damaged experians reputation, but people still trust amex/MasterCard/visa and their banks, despite Experian being useless. The fact that Experian is required to access those systems is unfortunate, but most people don't deal with Experian directly.

I think people's day-to-day trust in banks is well placed, for what it's worth. I banked with a large bank that fell in 2008, and had less than 10,000 in my bank. My money wasn't affected, I just had to find a new provider.

I've had multiple incidents of fraudulent transactions on debit and credit cards over the last 15 years, and in _every_ instancr, my card provider has sided with me and refunded me the money immediately (even in the one case I was actually wrong and it was a billing mistake). Those amounts we're almost always in the few hundreds.

Re: The Future of Online Identity Is Decentralized

#80
Have worked in the identity space for a long time. Authentication isn't a hard problem, but identity is. It will be decentralized because if it is not fragmented, it is literally just oppression. Trusting authentication is not trusting identity, and the origin of identity is the Ur-problem because it comes down to questions of recourse, collateral, risk, authority, and legitimacy - which are all political economy questions and not technical ones.

The technology can change the economics of identity, but identity itself reduces to how you organize to provide recourse to people within your scope. Sure, we can use escrow systems and smart contracts, but these still require a means to organize and provide adjudication.

All the use cases for digital identity are about enforcement and liability, and there are almost none that anyone would volunteer for. In this sense, identity is necessarily imposed, so all products in the space are necessarily aimed at a customer who is imposing identity on a group. It's why I tell identity companies who ask to find some other problem to solve because holding out for some government to adopt your product as their source of sovereignty is a waste of time. There is one other use case for identity, and yes, it is decentralized and bottom-up, because it is about dividing into secure, self-sovereign affinity groups, and the reasons for doing that are on a very short list of uses. Super fun, but basically a weapon.

Post reply on HN