Live data from Hacker News

The Future of Online Identity Is Decentralized

yarmo.eu

91–100 of 202 posts

Re: The Future of Online Identity Is Decentralized

#91
post #8

If anything, my bet is the future of identity is more centralized. Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in…

Beaker Browser is getting close to solving it.

When you visit a website that works with it, to login, you just grant the webpage access to one of your profiles. (I just use one profile for everything, but you may wish to keep some things separate). Then any activity you do can be associated with that profile. No passwords or keys or even email addresses to remember.

Re: The Future of Online Identity Is Decentralized

#92

Your identity is going to come down knowledge of the private key from some sort of public key system. Why not just standardize that? An excellent example of something perversely non-standardized for identities can be found in messaging. Signal, Matrix, Whatsapp and OMEMO are even supposedly based on the same protocol. In terms of identity they are all complete silos. All the things you establish about an identity on…

What happens when the private key is lost? We can either have certificate authorities issue you a new one, or you would need to approach your peers and have e.g. three of them confirm that you've changed keys.

Then you have lost that particular identity and would have to start over with a new one for that particular aspect of your online life. If you lose it and can get it back somehow then it wasn't really yours in the first place.

You can have as many passphrase protected backups of your identity in as many places as you like so in practice the more likely issue would be where someone else gets access to your private key. So that means some sort of revocation contingency.

Re: The Future of Online Identity Is Decentralized

#94
Agree.It is decentralized. You need to be able to maintain your identity as a currency whereby you get compensated for access to it vs. others who get to monitize your persona. Google, LinkedIn, FB all do this. If you grant specific rights you maintain your identity and get compensated directly for a business to gain access to market, contact, or interact with you.

Re: The Future of Online Identity Is Decentralized

#95

Have worked in the identity space for a long time. Authentication isn't a hard problem, but identity is. It will be decentralized because if it is not fragmented, it is literally just oppression. Trusting authentication is not trusting identity, and the origin of identity is the Ur-problem because it comes down to questions of recourse, collateral, risk, authority, and legitimacy - which are all political economy que…

It will be decentralized because if it is not fragmented, it is literally just oppression.

I've never understood that way of viewing things. For me identity is a right. The government must provide me with the means to prove who I am and my associated data like birth certificates, academic titles, health (vaccination), real estate and indirectly verifying identity for private contracts that use my national id card number.

In an oppressive state identity surely could be oppression, just like everything else, but in a democratic country? Come on. In the USA goverment and even private entities are collecting massive databases of everybody's data. But there's this panic about a centralized service providing identity. It makes no sense.

Re: The Future of Online Identity Is Decentralized

#96

I agree with a lot of this post. A lot of the left-leaning intellectuals that are now criticizing the harder-left stances in academia; people like Brent Weinstine, Jonathan Haidt, Sam Harris, et. al. ... I've heard all of them say they want less anonymity and more accounts tied to real identities. Whenever I hear this I think, "What? No! That's the opposite direction we should be going." Identities that are hard lock…

...left-leaning intellectuals...

Didn't you get the memo? We're supposed to like government surveillance now. After all, now FBI/CIA/NSA are on our side and we can totally trust them forever.

Re: The Future of Online Identity Is Decentralized

#97

Earlier quoted context omitted.

It's more about a fundamental design trade-off rather than removing accidental complexity coming from UX. Currently, most of us delegate the responsibility of identity management (other than memorizing id and password) to one of big-techs, presumably much better at this area than 99% of us. In the fully decentralized world, the burden of proof is now up to users. And they usually don't really care about the best prac…

On the other hand, however, the outcomes of a breach are vastly different. An individual who fails to secure their information is liable for only their information. If a "big-tech" is compromised, they are liable for everyone's information. If users are still unwilling to run their own infra, then that seems like a great opportunity for Identity as a Service. I'd feel much more comfortable handing identity to a firm…

"I'd feel much more comfortable handing identity to a firm whose entire business model revolves around securing my information and protecting my privacy rather than a big-tech." - in order for that company to be rock solid, trusted by most of the world and with a proven track record of top notch security, would mean that the said company is a big-tech.

I would call okta, auth0 and iWelcome big-tech already, even if they're not FAANG-level big tech yet.

Re: The Future of Online Identity Is Decentralized

#98

Have worked in the identity space for a long time. Authentication isn't a hard problem, but identity is. It will be decentralized because if it is not fragmented, it is literally just oppression. Trusting authentication is not trusting identity, and the origin of identity is the Ur-problem because it comes down to questions of recourse, collateral, risk, authority, and legitimacy - which are all political economy que…

Identity federation seemed to promise solutions to some of these problems, but never quite took off. The part I liked most was the ability to verify someone as being over 18 without divulging their age or any other meta data. That was 10 years ago though, and I have no idea what the citizen/consumer identity space looks like now.

Did the industry ever get around the sub-par SAML protocol which had no support for the active requestor profile, and the superior WS-Federation protocol which had to use the technically superior SAML token?

Re: The Future of Online Identity Is Decentralized

#99
post #95

Have worked in the identity space for a long time. Authentication isn't a hard problem, but identity is. It will be decentralized because if it is not fragmented, it is literally just oppression. Trusting authentication is not trusting identity, and the origin of identity is the Ur-problem because it comes down to questions of recourse, collateral, risk, authority, and legitimacy - which are all political economy que…

It will be decentralized because if it is not fragmented, it is literally just oppression. I've never understood that way of viewing things. For me identity is a right. The government must provide me with the means to prove who I am and my associated data like birth certificates, academic titles, health (vaccination), real estate and indirectly verifying identity for private contracts that use my national id card num…

I can reasonably change my hardware, software, and habits to avoid being matched with some corporate aglomerated profile of "me".

However, I cannot change my government provided identity.

Right now I can have multiple identities: one for work, one for my WoW guild, one for security research.

With a single centralized identity provider I couldn't do that. They wouldn't just be able, they would by default associate my personal and professional associations.

I feel that the risk of a single central (and especially government run) identity provider is that it can chill freedom of association by disallowing you to anonymously, or if not anonymously then disconnectedly associate with people or groups.

Re: The Future of Online Identity Is Decentralized

#100
It is tragic that Mozilla killed Persona just when it was starting to take off. Sadly I didn’t save the link to a retrospective written by the project lead, in which it was explained that they gave up because it was taking too long. But internet standards aren’t like a Megabar that you can foist on everyone within 6 months, they take years.
Post reply on HN