11 ms·
Ethereum community has solved a major problem of the Internet: Single Sign-On
- bluebirdfirewin 5y agoThat would be a step in the good direction. But the DID should be preferred as it will enable much more features.
- saba2008 5y ago> an average person having one username and password/authentication method that works across all services It's a bug, not a feature. It's people throwing away their privacy for convenience. It's proverbial dancing piggies. Problem with global-scale SSO is not corporations, that control shared identity. It's shared identity itself. Distributed SSO is as good idea, as eco-friendly vegan huffing solvent.
- anyfoo 5y agoYeah, SSO does not seem to be a problem inside e.g. corporations. The SSO solutions I've encountered there work rather well, and nowadays employees authenticate not much more than once or twice a day to get access to everything. SSO outside of such closed realms, i.e. in the open Internet, rather only seems to be a "problem" because people don't want to adopt it. Instead, password managers are the solution that won. The Twitter thread mentions "No sweat: you can have as many Eth accounts as you want w/ different ENS names", but if you end up having one (or more, see throwaway accounts on Hacker News) accounts for each site anyway, why go through the trouble with public/private keys, when the random shared secret in your Password Manager works so well?
- pixel_fcker 5y ago> nowadays employees authenticate not much more than once or twice a day to get access to everything. Unless you have multiple devices, in which case it feels like you’re logging in constantly
- ska 5y agoIt's odd this thread doesn't mention the sovereign self identity (SSI) efforts, DID Auth, etc. Folks who have been working in this area for years at this point and have some traction.
- arcticbull 5y agoThe issue with placing your identity on the blockchain is if someone gets your keys they become you. That's not a useful construct. Not your keys, not your life sounds awful.
- bluebirdfirewin 5y agoToday when someone get a copy of your passport they become you. So I still prefer a private key.
- arcticbull 5y agoThey most certainly do not lol, not without some serious plastic surgery. If they wanted to avoid the plastic surgery route they'd have to update the details by proving them to a central authority who can verify the update.
- deleted 5y ago[deleted]
- ska 5y agoRegardless of the pros and cons of various schemes, it's a strange omission. For what it's worth I think the whole effort is wrong-headed except in some pretty niche areas of credentialing, somewhat for reasons you allude to; but it's weird context to ignore.
- iSnow 5y agoRevocation would still be possible, I guess. At least it should be possible to build a revocation flow on top of blockchain. I am not so sure this kind of authentication will really catch on - the UX of Metamask and other wallets is just atrocious for say my father. BUT I do happen to like to connect to a site just with my ETH wallet, it is much nicer than using username/password or handing over ALL your data to Google for the OAuth convenience. It's a bit sad that the web is no longer a place for people with basic tech literacy, I'd love to use my Ledger Nano everywhere. I also was really fond of Civic for KYC and stuff, but it's gotten awfully silent.
- arcticbull 5y agoIs this really what people want? Seems strange that a single set of keys or a passphrase would grant you access to not only your wallet - all your money - but also all your online services. Am I missing something or is this just a fancy way of having a single password that gets you access to everything, and if compromised would be utterly devastating.
- rektide 5y ago> But wait, what if you don't want a single account for the Internet? You definitely should keep certain activities separate. > No sweat: you can have as many Eth accounts as you want w/ different ENS names https://twitter.com/BrantlyMillegan/status/1402388168041811971 https://twitter.com/BrantlyMillegan/status/14023881680418119...
- anaganisk 5y agoNo way i want my logins to be controlled by the eth gas price mood.
- tptacek 5y agoThis is an extremely solved problem. Unless you have a dramatically interesting solution to the real hard problem, global account recovery, ordinary home users are effectively tethered to their email accounts, because that's how you reset a login. Since you're doing that already, "Sign in with Google" and "Sign in with Apple" are perfectly cromulent solutions and likely to continue dominating. The actual last thing in the world home users want is an authentication system where credential loss is literally irrevocable. Meanwhile, the real market for Internet SSO is at companies, and one of the major reasons companies deploy SSO is to have policy control (particularly: onboard and offboarding) of who has access to what. A globally distributed authentication fabric is actually an anti-feature for those people. The actual last thing in the world corporate users want is an authentication system their IT department doesn't control absolutely. Part of what's happening with ideas like this, and the reason Internet identity has been such a tar pit for the last 20 years, is that there isn't one single service model for identity. Internet identity evangelists tend to overlook the fact that people have multiple identities on purpose.
- jonplackett 5y agoAnyone else wondering what cromulent means: https://www.merriam-webster.com/words-at-play/what-does-cromulent-mean https://www.merriam-webster.com/words-at-play/what-does-crom...
- DarmokJalad1701 5y agoThe word reminds me of scones for some reason ...
- jonplackett 5y agoI wondered if it was a reference to Oliver Cromwell who was known for his utilitarian manner. Scones sounds tastier.
- chrisweekly 5y agoThomas Cromwell is the historical figure "cromulent" triggers for me; the Wolf Hall trilogy is worthwhile historical fiction.
- Imnimo 5y agoThere are a lot of downsides to "Sign in with Google", but I am generally willing to accept them because I think I could recover my account if I lost my password. I'm not certain I could do so, because we've all read plenty of horror stories about Google's customer support. But I don't think I could recover an Ethereum private key. I'm sure there are esoteric ways of doing this. But ultimately what I want is the comfort that if worst comes to worst, there is a human somewhere on the planet who can reset my password for me. They might be hidden in a nigh-impenetrable labyrinth of automated emails, but they exist, and I could get them to help me if I make enough of a fuss on Twitter.
- bcmillegan 5y agoFYI, you can still have that exact kind of service with Ethereum accounts, some wallets offer that. It's improving all the time, but there are already and will continue to be many offerings on how to manage an Ethereum account. But the key thing is that the underlying system is the same.
- Imnimo 5y agoBut ultimately, even if I trust someone else with my private key, if they lose it, it's irrecoverably lost forever. If Google loses my password, they just set me up with a new one, and I'm on my merry way.
- whoknew1122 5y agoSo the Director of Operations of ENS Domains says Ethereum has solved an extremely solved problem and one of the cornerstones of that solution is... wait for it... ENS Domains. Gotcha. I also take issue with: >Ethereum is giving average ppl computer generated public/private key pairs... 'Average' people aren't into crypto. And the average computer user doesn't know how to use asymmetric keypairs. Anyone want to try to explain asymmetric keypairs to mother-in-law who's in her 70s and needs help applying Windows patches? I sure don't. And I spend my days in SAML and OAuth world.
- chrischen 5y agoWhat is this hypothetical “average” person, and if you aren’t one (presumably) then how do you know what they are?
- whoknew1122 5y agoI work in support for AWS's security services, which includes both web auth and encryption services. I deal with plenty of IT professionals every single day that don't have a solid grasp on concepts like "don't attach your private key to a support case". If IT professionals--who are presumably above average in IT knowledge since it's what pays their bills--don't uniformly understand how to handle asymmetric keys, what hope do most non-professionals have? Do I know the exact profile of what the average computer user is? No, but I'd bet a paycheck that it doesn't include using crypto or private/public keys.
- meowkit 5y agoI agree, but this stuff will be abstracted away. Everyone has a smartphone and the “average” user knows next to zero about how the device itself works.
- chrisco255 5y agoHave you tried using MetaMask or WalletConnect as a sign in tool? It's great. The extension pops up with a message indicating the app is requesting access to account. You click yay or nay. MetaMask already has millions of users and growing rapidly. Average people didn't know how to use email 30 years ago. Didn't know how to use GPS 20 years ago. Didn't know how to use social media 15 years ago. Didn't know how to hail an Uber 10 years ago (and still thought riding in cars with strangers was dangerous). I think they can be educated.
- schlotzisk 5y agoThat just sounds like OpenID with extra steps
- ChrisArchitect 5y agoha! good. OpenID yes
- mattbee 5y agoThere were loads of vendor-neutral identity ideas that all fell flat because nobody wants to sign up just for an identity. This one is hilariously complicated; the thread ends with this call to action: Want to get a portable web3 account? Pick an Eth wallet: https://ethereum.org/en/wallets/find-wallet/ https://ethereum.org/en/wallets/find-wallet/ Get ETH (sometimes built into wallet, otherwise use a service like Coinbase) Get an ENS name: http://app.ens.domains http://app.ens.domains * (Choose which is your username by setting reverse record at My Account)* It's that easy! I think the author underestimates how little most people care about their weak passwords, or centralised authentication.
- chrisco255 5y agoYou don't need ETH or an ENS domain to use Ethereum for single sign on. Just need a wallet. The wallet can be totally empty. The ENS domain is simply for human readable account names.
- deft 5y agoNo, the ENS domain is simply an additional layer of rent-seeking. Metamask sign-on is great. ENS is a pointless cash grab.
- chrisco255 5y agoIt's not a cash grab. Its an optional domain registrar. Feel free to start your own smart contract based registrar. Otherwise .eth domains are accepted pretty much everywhere as a substitute for a public key. ETH addresses are 40 digits long. Yes, you can copy/paste. But having yourname.eth is nice for user friendliness. Best part though is, you have a choice. And you can always register a domain much later if you ever feel the need.
- bcmillegan 5y agoYep. Also note that ENS is a generic naming system, not just .eth names. You can also import in DNS names you already use, e.g. I own brantly.xyz on DNS and also imported it into to ENS: https://app.ens.domains/name/brantly.xyz https://app.ens.domains/name/brantly.xyz
- ChrisArchitect 5y agothe continued annoying arrogance of these crypto people, claiming things are just 'web3' all of a sudden because they've built some crazy thing that seems to be outside the mainstream.... but then posting stupid twitter threads (seriously, use a fucking blog post) claiming they've solved identity, while ignoring all the world SSO and SSI people have been doing/real work/tackling issues and dealing with how real world people actually deal with (successfully/not so successfully) with these things and the way users ended up with today password managers/email still the internet's killer app/ID thing. sigh.
- mt_ 5y agoThey need to keep their ponzi relevant
- space_rock 5y agoBut think of how one can pump the price of their worthless token by writing this crap
- deleted 5y ago[deleted]
- deft 5y agoThis has already been solved, its called Public-key cryptography. Ethereum gave everyone a key, but usability issues have stifled making that useful offchain. ENS isn't needed.
- bcmillegan 5y agoYes, public key cryptography is not new. What's new is that crypto incentives has spurred the creation of a highly competitive industry to improve private key management, and incentives people to get and manage one. ENS isn't needed strictly speaking, but highly useful to make everything human-friendly. It's like saying DNS isn't useful because you can just input a website's IP address.
- cors-fls 5y agoThis ENS thing could be interesting. It makes it possible to have a distributed identity. If only if Ethereum was not overinflated. As a result, reserving a name on ENS costs 120$ a year. Few people would be ready to pay that to get a username.
- bcmillegan 5y agoIt does not cost $120/yr. ENS protocol fees are: - unlimited subdomains, free - importing DNS name into ENS, free - for .eth names, based on length: 3 characters, $640/yr; 4 ch, $160/yr; +5 ch, $5/yr For .eth names, you can pay ahead as many years as you want, so you can pay once and forget it about it. The you likely got to $120 is that there is also Ethereum network gas fees to pay to registration a name. That's a one time thing and fluctuates a lot. Since you can register for many years at a time, you can pay the gas fee once and get the name for many years. We're also working on putting parts of ENS on L2s to cut down on gas fees dramatically.
- anaganisk 5y agoRealistically avg joe, would at max pay for 5 years. After that? Gas is just unpredictable, with un-controlled inflation. I just don't want to loose my logins because Elon Musk tweeted some BS
- leppr 5y agoA lot of SSI is about delegating Sybil-resistance. Websites use Google or Facebook sign-on not just because it's more convenient for users, but also because signing up many accounts on these services is a bore, thus managing spam. If the sign-up process was as difficult for the small services as it is with Google or Facebook, users would give up. But users already have Google/FB accounts or know it's worth it to have one, so they don't mind the process for Google/FB. For now, there's no accepted standard identity mechanism attaching to ETH wallets. It's not a trivial problem either. If while reading this you just had some idea how to quickly solve it, chances are someone had it before and it's vulnerable to either centralized control or user abuse. ENS might work at deterring spam but it's way too restrictive for now.
- dang 5y agoRelated thread: “The Ethereum community has accidentally solved a major problem of the Internet - https://news.ycombinator.com/item?id=27473889 https://news.ycombinator.com/item?id=27473889 - June 2021 (14 comments)
- cordite 5y agoHow is this different from signing in with a yubikey that you can never lose?
- anaganisk 5y agoYou would be part of the Ponzi scheme
- browningstreet 5y agoI’ve been trying to follow cryptocurrency conversations online… it’s amazing how much pumping and noise there is in every forum, Twitter thread, etc. Where are the real conversations happening?
- kybernetikos 5y agoI think a big advantage of current SSO systems as opposed to cryptowallet systems is that they usually come with a verified way to contact the user. On the other hand, cryptowallet based sign in systems generally don't give you a verified way to contact the user, but they do allow you to see if the user has put money behind this identity. That could be an interesting way to reduce sybil attacks. Having an email address does not mean much in terms of level of buy in to a particular identity (and that, much more than 'real names' is key for managing behaviour).