Live data from Hacker News

The Future of Online Identity Is Decentralized

yarmo.eu

1–10 of 202 posts

Re: The Future of Online Identity Is Decentralized

#2
I have always felt identity, including online such as domain names, should be decentralized — it’s too much power for a central authority to dictate who gets (and doesn’t get) a name. Further, it’s too easy for people to impersonate others online. It even happened at reddit where the CEO masqueraded as users by modifying their comments [1].

Handshake [2] is a great project that helps decentralize online identity. Not only is naming distribution in the hands of the people with Handshake which ends the deplatforming/censorship debacle the world has been facing recently, but also, anything a name does can be verified with signatures verifiable against the blockchain.

[1] https://www.theverge.com/2016/11/23/13739026/reddit-ceo-stev...

[2] https://handshake.org

Re: The Future of Online Identity Is Decentralized

#5
There's the "European" ID4Me project (https://id4me.org/), which tries to add federation on top of OpenID Connect / OAuth2. The idea is to give users globally valid IDs that contain a domain name. Using a TXT record on that domain you then specify which OpenID auth provider a service should use to authenticate the user. If you have your own domain this enables you to switch ID providers without having to update your accounts.

In general I like the idea but since it's a EU-style project I don't expect it to go anywhere to be honest. And personally I don't think the benefit over e-mail based authentication is marginal. That said there are some extensions in OpenID Connect that can achieve something similar, and that (IMHO) are more likely to actually get widely adopted.

Re: The Future of Online Identity Is Decentralized

#6
Feels like you'd have to lean significantly away from anonymisation to want to leave public proofs of cross account identities lying around. Maybe that's a more common use case for businesses and high profile people though than wanting to link, say, a pseudo-anonymous forum account with a payment account.

Re: The Future of Online Identity Is Decentralized

#7
I think one of the great parts of the internet is that it promotes this identity decentralisation (or, as i have always thought about it, identity fragmentation). You are allowed to isolate online identity from the rest of your life, or from separate online accounts/personae.

Which is why I am confused as to why the author spent so much time worrying about verifying identity. To me, that feels like it's completely missing the point of fragmenting your online experience. Is the author simply concerned with the amount of power associated with their google login?

Re: The Future of Online Identity Is Decentralized

#8
If anything, my bet is the future of identity is more centralized.

Decentralized solutions, as I've read about them in their current form, require a significant amount of technical knowledge to understand. That is, to understand both what they are and, more importantly, their benefits ("why does this specific solution matter to me?"). Past that, the user experience is extremely poor in comparison to clicking "log in with Google", and I'm not convinced it can ever fully get there.

It is for those reasons that I think centralized identity is here to stay long term. Most people aren't going to spend the time to learn about this because they just want the easiest solution and don't care about their data being sold. I know several people in tech that fully understand the extent of how their data is used by internet corps, and don't mind it because they prefer convenience for free. And I think that's OK--it's their informed choice.

Personally, I try to login with email most of the time, and that's the limit of my drive to care about the security of my personal data. But my email is gmail, so I doubt it really makes a difference from login with Google.

Re: The Future of Online Identity Is Decentralized

#9
The future of online identity is indeed decentralized and not distributed, meaning that users will always have some super nodes to handle their identity on behalf of them. In my opinion Facebook/Twitter/etc are not identity providers, they are silos. Sure they are very successful ones and can even used as identity providers at some places, but as long as they don't open up they can easily die anytime.

The author suggests that services built on top of these Silos that provide proofs of connection between all the identities. I welcome such initiatives and but I doubt they will lead anywhere, cause they are built on top of silos. And a silo, as soon as it figures out it loses money, it will cut down that connection.

What won't die is decentralized published standards and protocols that handle the Identity management through the internet. Starting from plain DNS, we can get AoR for SMTP, SIP, XMPP and on top of that we have frameworks that facilitate the identity management like Oauth2, OpenID etc. All open and standardized. We are getting there, we just need some more time I guess.

That's why I always thought that, Google, who owns emails has much more value than Facebook, that asks for your email. If facebook dies, you lose one aspect of your digital social part. If you lose your email though, you almost lose your online identity. I really can't get how Zuckerberg has missed that.

Re: The Future of Online Identity Is Decentralized

#10

in before everyone shills their unnecessarily tokenized identity cryptocurrency that nobody ever used and never ever will

I 100% agree with you, but generally I find "in before..." comments to be unhelpful at best and harmful to the discussion at worst. In the latter case, it's typically because it's not only attacking on a straw man, it's actually announcing, "Hey, I'm creating a straw man!" at the beginning of the comment.

If you do want to head off the crypto founders before they show up, perhaps you could write a comment along the lines of, "In case anyone is wondering, here are the reasons cryptocurrency/identity makes no sense when solving this problem..."

Post reply on HN