Live data from Hacker News

Web3 Is Bullshit

stephendiehl.com

71–80 of 125 posts

Re: Web3 Is Bullshit

#71
post #65

Earlier quoted context omitted.

Is this what the struggles of the transition from scarcity to post scarcity looks like? Building systems that simulate scarcity to generate the illusion of value and to front run that value?

I don’t understand how a post-scarcity society would even be desirable. For things like art and music, their creators need to be able to command a price on their creations. The digitization of these things removes their scarcity and essentially makes them function as a public good, making it impossible to set a price on them that will support the artist. If there’s no way for digital artists to support themselves, th…

> If there’s no way for digital artists to support themselves, then they’ll cease to exist.

They'll have day jobs and create art on the weekends and evenings. Alternately, they'll be sponsored through some full-time fellowship to create art.

Re: Web3 Is Bullshit

#72

I think many people’s postive Web3 experience has been signing a transaction with Metamask as a proof of identity, at least that’s the most obvious magic I’ve seen, the notion that I can interact with a website without registering an account with email and 2FA etc etc feels futuristic and a good step toward whatever the metaverse is, allowing me to have a consistent identity across platforms. But can’t this be accomp…

You can do passwordless login already with WebAuthn. It's just a matter of sites integrating it. https://webauthn.guide/

WebAuthn isn't cryptographic. The root of your identity isn't a public key.

Re: Web3 Is Bullshit

#73

if Web2 became a dystopic Zuckerbergia and Web3 is a disguised Cryptobrosia is there maybe a chance for a Web 2.5 that doesn't suck? Like something that isn't fake techno-solutionism on steroids? What would be its building blocks? IFPS, Activitypub, XMPP, Matrix? but more importantly what would be the governance and incentives that would prevent it from rapidly degenerating as with all other versions

The alternate path is one the free software community has been pushing towards for decades. The ability to voluntarily associate (and disassociate) from trusted communities, software and communities that works for users and not the other way around, and autonomy coupled with mutual aid/benefit. Compare the focus of the GNU, Mastodon, Matrix, etc. projects to blockchain world and the fundamental difference is they're…

>making us have to pay (spend tokens) for everything.

If you have to pay, or someone else has to pay for something (in FOSS it is just done in a more distributed way), why use a massively corrupt and degenerate currency to do it?

Re: Web3 Is Bullshit

#74

Earlier quoted context omitted.

You can do passwordless login already with WebAuthn. It's just a matter of sites integrating it. https://webauthn.guide/

WebAuthn isn't cryptographic. The root of your identity isn't a public key.

WebAuthn is based on public key cryptography. U2F signs website's challenge ("transaction") with your private key that sits in the key fob ("wallet"). SSH and TLS client certs work the same (I can take your public ssh key, and I'll know when you try to log in to my server, obviously).

You don't need a blockchain for identity. The unique feature that Blockchains provide is protection against double spending (without reliance on a single party), but that isn't a concept relevant to authentication.

Everything else in "crypto" is the old boring cryptography. All the zero-knowledge proofs, secret sharing, anonymity, proofs of identity are just general-purpose tools that blockchain systems happen to use.

"I've used a transaction to log in — we should use wallets for identity" is like "I've used my car radio to listen to music — we should replace ipods with cars!"

Re: Web3 Is Bullshit

#75
post #74

Earlier quoted context omitted.

WebAuthn isn't cryptographic. The root of your identity isn't a public key.

WebAuthn is based on public key cryptography. U2F signs website's challenge ("transaction") with your private key that sits in the key fob ("wallet"). SSH and TLS client certs work the same (I can take your public ssh key, and I'll know when you try to log in to my server, obviously). You don't need a blockchain for identity. The unique feature that Blockchains provide is protection against double spending (without r…

The root of identity is still not a public key. To perform essential actions on such a website doesn't need your public key. You are only proving that you have access the private key correspondent to the public key stored in the database entry, and nothing else. Authz is still database records and not inherently trustless akin to cryptographic authentication.

Imagine I had a entirely PGP-based comment system, where the key used to sign comments serves as the identity rather than a database record. The software remaining the same, not even the owner of the database can change the text of the comment without also changing the key, which would immediately destroy the utility of such an action. Applications utilizing MetaMask are actually able to develop this kind of application where it's trustless end to end. Furthermore, comments could also be embedded as a transaction to a hash of the URL (or something akin to that), where anyone with an access to a ethereum node, public or private can access a global comments system.

>You don't need a blockchain for identity. The unique feature that Blockchains provide is protection against double spending (without reliance on a single party), but that isn't a concept relevant to authentication.

Blockchain doesn't solve the Authn problem, it only solves the Authz problem. I can hypothetically make my own game which has a DRM that can only be unlocked if your private key owns the access NFT. They are complementary.

Re: Web3 Is Bullshit

#76
post #42

Earlier quoted context omitted.

Genuine question: what has private key authentication to do with blockchain? I've been using this for my ssh connections for almost 15 years now. And the second question: what happens if you use your private key? Every website that uses password has a mechanism to reset your password. Take that feature away you'll lock out millions of users.

Yeah PKI has been around of course for a long time and is a core facet to how the web functions today. The private key authentication I'm referring to is because wallet extensions allow for users to connect their wallet to applications, as a method of authentication. You don't even have to have funds in your wallet to perform this authentication, you just need a wallet. If you lose your private key, you're probably o…

A crypto wallet is just a random number. Literally.

Everyone using wallets for identity equals everyone just picking a random number to represent themselves (and then classic cryptography allows you to prove to others that you know this number without revealing it).

The hard part of this is not cryptography — that is already solved quite well. It's the human side. People forget pass phrases. Or disclose them to whoever calls them and says they're from Microsoft Pass Phrase Verification Authority. People break computers they haven't backed up. People click "Yes" on security prompts, and open random mail attachments. With private keys involved, these situations are irreversibly catastrophic.

Re: Web3 Is Bullshit

#77
post #44

Earlier quoted context omitted.

> I just want the common man to see crypto for what it really is with a balanced debate or interview, not just a blog post that only 'nerds' reads as Diehl states. I've been following this space for a while and honestly I don't see how a counterpart would actually look like. We had blockchains/crypto for almost 13 years and the only thing that came out of it is a speculative semi-unregulated asset market. Still Forbe…

Considering BTC's network uptime has been about 99.9% for over a decade, I'd say the "here to stay" articles may have been relatively accurate? (I don't care much for BTC, though I do feel a narrow scope of its usage will probably persist in some fashion for many more years.) > Show me one blockchain application that has nothing to do with virtual assets that not only turns a profit but is provably more efficient tha…

A centralized database can handle the escrow too, and far more efficiently. The only reason decentralized crypto solutions have a head start is that people who work in crypto tend not to care about what is legal.

Re: Web3 Is Bullshit

#78

"The Ethereum virtual machine has the equivalent computational power of an Atari 2600 from the 1970s except it runs on casino chips that cost $500 a pop and every few minutes we have to reload it like a slot machine to buy a few more cycles. That anyone could consider this to be the computational backbone to the new global internet is beyond laughable. We’ve gone from the world of abundance in cloud computing where t…

Is this what the struggles of the transition from scarcity to post scarcity looks like? Building systems that simulate scarcity to generate the illusion of value and to front run that value?

if you are joking, I hope you realize you have stumbled on a real epiphany, and keep pulling the thread.

Re: Web3 Is Bullshit

#79

"The Ethereum virtual machine has the equivalent computational power of an Atari 2600 from the 1970s except it runs on casino chips that cost $500 a pop and every few minutes we have to reload it like a slot machine to buy a few more cycles. That anyone could consider this to be the computational backbone to the new global internet is beyond laughable. We’ve gone from the world of abundance in cloud computing where t…

The author beautifully missed the point of having a EVM in the first place, he missed the "it's trustless" memo. EVM is slow because it runs the same code in millions of computers where no computers are trusted and only the consensus of the computers are trusted. You won't be running Firefox or Linux on EVM. I like how even the most educated and experienced people in the world can't bother to read the bitcoin whitepa…

> I like how even the most educated and experienced people in the world can't bother to read the bitcoin whitepaper with no reservations.

I get your sarcasm, but the bitcoin paper has little to do with the EVM and smart contracts except as a foundational idea.

Either way, I’m inclined to agree with the beautiful sarcasm the OP posted. Trustless doesn’t make it more valuable than the trusted systems that we already have that are cheaper and do a decent job without artificial scarcity

Re: Web3 Is Bullshit

#80

Earlier quoted context omitted.

The author beautifully missed the point of having a EVM in the first place, he missed the "it's trustless" memo. EVM is slow because it runs the same code in millions of computers where no computers are trusted and only the consensus of the computers are trusted. You won't be running Firefox or Linux on EVM. I like how even the most educated and experienced people in the world can't bother to read the bitcoin whitepa…

> I like how even the most educated and experienced people in the world can't bother to read the bitcoin whitepaper with no reservations. I get your sarcasm, but the bitcoin paper has little to do with the EVM and smart contracts except as a foundational idea. Either way, I’m inclined to agree with the beautiful sarcasm the OP posted. Trustless doesn’t make it more valuable than the trusted systems that we already ha…

>but the bitcoin paper has little to do with the EVM and smart contracts except as a foundational idea

I am not claiming the bitcoin whitepaper has anything to do with EVM, but it explains why a trustless, digital currency is needed and how it can be implemented. It predates real cryptocurrencies, so it can read easier without references to cryptocurrencies that exist today. The author has demonstrated incredible ignorance of why things like EVM exist in the first place.

>Trustless doesn’t make it more valuable than the trusted systems

Author doesn't understand why people think it could be/is valuable either.

Post reply on HN