4 ms·
Hey! Author of the thread here. Thanks for your comments! > This is an extremely solved problem. Not with the properties of Sign-In with Ethereum (SIE), which
by bcmillegan 5y ago
Hey! Author of the thread here. Thanks for your comments!
> This is an extremely solved problem.
Not with the properties of Sign-In with Ethereum (SIE), which is single, user generated authentication credentials, a self-custody portable username in a naming system that isn't reliant on a trusted-third party, and that people are already getting for other reasons (to use Ethereum, so extra incentive to get set up, not just SSO incentive).
> ordinary home users are effectively tethered to their email accounts, because that's how you reset a login
Yep, and I don't expect that to change very much anytime soon, but there is a small but growing community of people tethered to their Ethereum wallets and ENS names and using those instead. Given the advantages and crypto incentives, I expect it to continue to grow. Note also that service can always require a user to also provide an email address, it just wouldn't be used for authentication.
> The actual last thing in the world home users want is an authentication system where credential loss is literally irrevocable.
Doesn't have to be. Three things on this point:
1) Depends on how your wallet provider works. There are already some wallet providers with social recovery (multisig under the hood), etc.
2) Crypto incentives (unrelated to sign-in) mean that the private key management industry ("wallets") is already highly incentivized to make it very difficult for people to totally lose access to their accounts (because then lost money). That's a key part of my point: private key management has never been good enough for average people, but crypto incentives have spurred on a massive industry to solve this problem. And while it's not totally solved (still needs lots of improvement), it has improved rapidly in the last five years to be much better than ever before, and I expect it to continue to improve.
3) What I've described is just on the user side. If a web2 service adopted this (not aware of any right now, it's pretty much just web3 services that use it), they can always do things like require you provide an email address or other information, and they can still have a process for reassigning your account with them to a different Ethereum account.
> The actual last thing in the world corporate users want is an authentication system their IT department doesn't control absolutely.
Again, depends on what you want, you can make it so that you have access to all of your company's employees Ethereum accounts.
> Internet identity evangelists tend to overlook the fact that people have multiple identities on purpose.
Yep. I don't expect this to replace everything else immediately, but I do expect overtime for this to become a ubiquitous option, such that a user could use their one Ethereum account everywhere if they wanted to.
Also, re the need for multiple identities: as I point out in the thread, a person can generated as many Ethereum accounts and have as many ENS names as they'd like, using their real name or pseudonym, or whatever they'd like.
Anyway, sorry for long comment, thanks for engaging!
- tptacek 5y agoIt's interesting how much the problems with blockchain SSO mirror those of blockchain currency. In both cases, the goal is to liberate people from centralized authorities. And in both cases, the advocates seem both to radically miscalculate how much the benefit of that shift accrues to ordinary people versus abusers, and almost completely miss the benefits of central authorities, who have at least some incentive to make recoverability and reversibility accessible to consumers. I don't doubt that there are things you do to facilitate account recovery on immutable distributed ledgers, but it just seems pretty clear to me that you're working against the design of a blockchain when you do that; the blockchain isn't doing much that centralized systems aren't already doing, and they're doing a lot that gets in the way. Certainly, I wouldn't want to be the person whose job it was to explain to a SOC2 auditor how my company's Ethereum SSO system works. I wouldn't stake real money on the value of ETH or BTC; the market can stay irrational longer than I can stay solvent &c &c. But I'd probably make a real bet on blockchain-mediated single signon never achieving significant adoption, for some reasonable definition of "significant".
- deleted 5y ago[deleted]
- NicoJuicy 5y agoThis 100%. Additionally, they want decentralized logins. People use logins of work and their phone all the time. No work environment is going to give control out to help their employees for example. No SAAS wants to be unable to help their users. They mention that DNS isn't meant to be about auth and then they talk about signing your identity with your wallet private keys. I want that to be totally seperated! And blockchain isn't meant for sso either. So many people just won't understand any if this, this is just a dead born baby from the start. The statement "many people use this" is probably insignificant in relative terms. I'd be surprised if there are 50 on Belgium in a population of 10 million.