4 ms·
There are a ton of individuals and big companies in tech working through standardization bodies to create an identity layer for the internet, that no single org
by infominer 7y ago
There are a ton of individuals and big companies in tech working through standardization bodies to create an identity layer for the internet, that no single organization is in control over. Google is not among them.
A link to the ISO Standard Google is waiting for approval on:
https://www.iso.org/standard/69084.html https://www.iso.org/standard/69084.html
Examples of organizations working to solve identity problems, rather than compound them:
https://www.weboftrust.info/ https://www.weboftrust.info/
https://identity.foundation/ https://identity.foundation/
- Avamander 7y agoThere's no way to do one-to-one identity verification and authentication without centralized coordination and control. Just as an example, even if we really wanted to there'd be now way to let only one CA issue a certificate for a domain if any of the CAs is rogue.
- marcosdumay 7y agoThere is no easy way. What is an important distinction, since there exist situations when even hard to follow procedures are better than a centralized option. Those are just not your daily "how do I know if I can show you my credit card" situations.
- Avamander 7y agoThere's no cryptographically secure way as far as I'm aware.
- marcosdumay 7y agoYou do get in front of the other person and exchange public keys. Or you ask for help from a set of trusted middle-man. Those are perfectly fine ways to run a PKI, they are just not fit for the "entire web" PKI.
- Avamander 7y agoThose methods really don't scale by the fact that we haven't had a single system like that catch any popularity. It's usually just too cumbersome and not more trustworthy.
- glennpratt 7y ago> even hard to follow procedures are better than a centralized option Sorry, I don't have nearly enough information to accept that.