Live data from Hacker News

The Asymmetry of Internet Identity

crawshaw.io

1–10 of 40 posts

Re: The Asymmetry of Internet Identity

#3
Layer 5 belongs before Layer 4, its more like a half layer similar to IP vs MAC. OAuth is a way to communicate someones registered personhood securely.

The last layer should be "Persona" and be about how people present their personality and behavior, having potentially multiple identities, characters, depending on the service, context, how much anonymity exists, etc and it would be akin to Layer 7 Applications, running on top of our wetware. Steven Colbert vs Steven T Colbert.

Re: The Asymmetry of Internet Identity

#4
> There is no good way for a person to identify another person without first mutually agreeing on Brand identities.

How is this absence not a good thing? If someone wants to be identified, they have to go through the trouble of creating an identity. In fact, it would be preferable to also not have a permanent or consistent personal identity with respect to brands either.

Re: The Asymmetry of Internet Identity

#6
post #3

Layer 5 belongs before Layer 4, its more like a half layer similar to IP vs MAC. OAuth is a way to communicate someones registered personhood securely. The last layer should be "Persona" and be about how people present their personality and behavior, having potentially multiple identities, characters, depending on the service, context, how much anonymity exists, etc and it would be akin to Layer 7 Applications, runni…

I can be name@mydomain.com without using "Inter-brand Identity protocols," so the layers seem to be in the right order to me.

Re: The Asymmetry of Internet Identity

#7
Really good read. Provides a new abstraction model that we've not seen before. It shows the depth of the problem and why we have never solved it since the days of PGP, 1991. It does not mention the idea of owning your own identity[1], a possible solution. [1] https://wiki.p2pfoundation.net/Self-Sovereign_Identity

Re: The Asymmetry of Internet Identity

#8
I don't necessarily want to rely on brands to use the jargon of the article to facilitate informational exchange.

As a user I certainly am interested to exclude the brand wherever I can, because it is a security flaw and allows for countless attack vectors.

I know about the current ambitions of identity providers and I make use of them because I am lazy too and don't know enough about security to match their services. But it is still a concession.

I think keeping the logistical perspective of key exchange can work for new ideas, while this perspective obfuscates ambitions the brand could want to see realized.

Quote from the link in the text:

> User-centric designs turned centralized identities into interoperable federated identities with centralized control, while also respecting some level of user consent about how to share an identity (and with whom).

... "while also respecting ~some~ level of user consent" is the issue where legislation for informational self determination is needed.

Again, if this problem is transparently presented, I would have less issue with this new perspective.

You can already upload everything to Amazon beanstalk and use Amazon cognito as an identity provider. Hacked together but very usable. I already sold my soul countless times but there is still one problem: Amazon.

Re: The Asymmetry of Internet Identity

#9
post #7

Really good read. Provides a new abstraction model that we've not seen before. It shows the depth of the problem and why we have never solved it since the days of PGP, 1991. It does not mention the idea of owning your own identity[1], a possible solution. [1] https://wiki.p2pfoundation.net/Self-Sovereign_Identity

[deleted]
Post reply on HN