3 ms·
Hey! Author of the thread here. Thanks for your comments! > This is an extremely solved problem. Not with the properties of Sign-In with Ethereum (SIE), which
by bcmillegan 5y ago
Hey! Author of the thread here. Thanks for your comments!
> This is an extremely solved problem.
Not with the properties of Sign-In with Ethereum (SIE), which is single, user generated authentication credentials, a self-custody portable username in a naming system that isn't reliant on a trusted-third party, and that people are already getting for other reasons (to use Ethereum, so extra incentive to get set up, not just SSO incentive).
> ordinary home users are effectively tethered to their email accounts, because that's how you reset a login
Yep, and I don't expect that to change very much anytime soon, but there is a small but growing community of people tethered to their Ethereum wallets and ENS names and using those instead. Given the advantages and crypto incentives, I expect it to continue to grow. Note also that service can always re
> The actual last thing in the world home users want is an authentication system where credential loss is literally irrevocable.
Doesn't have to be. Depends on how your wallet provider works. There are already some wallet providers with social recovery, etc.
Note two other key things:
1) Crypto incentives (unrelated to sign-in) mean that the private key management industry ("wallet" industry) is already highly incentivized to make it very difficult for people to lose access to their accounts (because then lost money). That's part of my point: private key management has never been good enough for average people, but crypto incentives have spurred on an massive industry to solve this problem. And while it's not solved (still needs improvement), it has improved rapidly in the last five years to be much better than ever before, and I expect it to continue to improve.
2) What I've described is just on the user side. If a web2 service adopted this, they can always do things like require you provide an email address or other information, and they can still have a process for reassigning your account with them to a different Ethereum account.
> The actual last thing in the world corporate users want is an authentication system their IT department doesn't control absolutely.
Again, depends on what you want, you can make it so that a third-party has access to all of your company's employees Ethereum accounts.
> Internet identity evangelists tend to overlook the fact that people have multiple identities on purpose.
Yep. I don't expect this to replace everything else immediately, but I do expect overtime for this to become a ubiquitous option, such that a user could use their one Ethereum account everywhere if they wanted to. Also, re the need for multiple identities: as i point out in the thread, a person can generated as many Ethereum accounts and have as many ENS names as they'd like.