8 ms·
Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'
- junon 5y agoFirst time I've seen "s12y" (sustainability) and while I'm usually averse to new buzzwords I quite like the association with "i18n" (internationalization) and "a11y" (accessibility). Somehow feels like the trinity of responsible software ("responsible" probably isn't the right word here).
- a_imho 5y agoMaybe r9e s6e?
- MauranKilom 5y agoThanks for providing this context. I didn't know s12y stood for sustainability, and I also only now realized that the number in e.g. i18n is the number of letter omitted (and not leet speak or some "sk8er"-like abbreviation).
- SkyMarshal 5y agoA framework of responsible software isn't complete unless it includes security (s6y?), given the rampant breaches, data theft, and cyber war these days.
- junon 5y agoI disagree. Responsible software is something opted into. As engineers, security should be a requirement. It should go without saying. I agree with you, I just don't think your stance is radical enough :D
- pwlb 5y agoSelf-Sovereign Identity and DIDs are a very fast moving train. People argue that in the early internet days there was a similar competition between new protocols(compare with DID methods) before we arrive in our todays HTTP(S)-only world. Similarly DID methods will probably consolidate to a handful within few years and DID Core is only a first step to get a minimal common denominator. Also its questionable if Microsoft&Google and the others are fearing a rapidly evolving ecosystem that they can not jump on as fast and therefore remain sceptic in any case
- zcw100 5y agoThis is probably the last thing that the likes of Microsoft and Google are worrying about right now. I'm sure it is fun imagining being the lone hacker keeping them up at night.
- pwlb 5y agonot yet, but identity giants like okta and ping are already looking at SSI very carefully. digital identity will be key in the next years
- csixty4 5y agoMicrosoft hired Kim Cameron at the tail end of the last decentralized digital identity craze and once built an OS feature (CardSpace) to support it. I really doubt anyone there is afraid of sovereign identity.
- dochtman 5y agoDoes anyone have links to the Google and Microsoft reviews mentioned in this email? Browsing the last 6 months of public-new-work archives doesn't seem to yield many other reviews of the DID proposal.
- dwaite 5y agoReviews may be public or private, Google and Microsoft did not make their reviews public.
- EGreg 5y agoOne of my acquaintainces at Microsoft worked for years to get this through: https://identity.foundation/sidetree/spec/ https://identity.foundation/sidetree/spec/ DIDs built as a Sidetree on top of Bitcoin. At least they don’t require everything being on-chain, but securing with proof-of-work is unfortunate.
- de_keyboard 5y agoPoW is the only proof mechanism that has seen real world use for a significant length of time.
- EGreg 5y agoSure, and in the 50s, vacuum tubes were the only mainstream computing mechanism that had seen real world use for a significant length of time. Same goes for all other outdated technologies. When you have a distributed system, it really isn’t hard to “retain” information in a byzantine fault tolerant way. Proof of Work is mostly used to help with liveness, not persistence.
- geofft 5y agoAll the more reason to incentivize real-world use of other approaches. "This is how we've always done it" is poor reasoning, whether it's about blockchain or lead pipes or asbestos.
- southerntofu 5y agoWhat kind of proof mechanism are you talking about? Do you mean PoW can prevent an attacker spawning many identities? That's certainly not the case, because bad actors have plenty of resources. PGP signatures + Web of Trust have been in use for about two decades now and have proved robust over time (can't say the same of all PGP implementations unfortunately), but at the cost of revealing (parts of) the social graph which is an anti-feature for privacy. I've heard the word Fog of Trust employed by GNU/Net project to refer to research projects on zero-knowledge proofs for a Web of Trust, so you can infer trust relationships without exposing the social graph. But i can't vet for the math behind that. I'd be happy to have more alternative patterns explored, instead of insisting on the aspects that made Bitcoin a failure. Bitcoin was a revolutionary PoC for replacing centralized trust with trust in the majority of global computing resources allocated to the network. But that model has shown its limits and weaknesses (high economic/environmental cost, vulnerability to advanced actors like Bitmain, low transaction throughput) so we can research other approaches. So far, the most advanced/consistent proposal i've read on decentralized identity, which is not based on monetary speculation or proof-of-work, is the GNU Name System [0], which features recursive resolution of zones (retro-compatible with DNS) via a global DHT, crypto-secure zone delegation (retrofittable into existing ICANN infrastructure), hyper-hyper local root (like /etc/hosts but with recursive resolution), query privacy (client requests don't leak), enumeration-proof zones (private zone entries). Alongside the reclaim:ID [1] self-sovereign identity scheme, that looks like the most solid proposal for replacing both insecure DNS infrastructure and cracking the decentralized identity problem. Alongside the Taler [2] privacy-friendly payment platform, that looks like the most solid proposal for enabling fully-decentralized pseudonymous electronic transactions. See also this somewhat recent article on the topic: https://gnunet.org/en/news/2021-05-DISSENS.html https://gnunet.org/en/news/2021-05-DISSENS.html [0] Some video presentations: https://gnunet.org/en/video.html https://gnunet.org/en/video.html [1] https://reclaim.gnunet.org https://reclaim.gnunet.org [2] https://taler.net/en/ https://taler.net/en/
- bmn__ 5y agoCalled it. https://news.ycombinator.com/item?id=27024026 https://news.ycombinator.com/item?id=27024026 Feels good to be validated by someone like Tantek.
- todd8 5y agoFrom the article: > We (W3C) can no longer take a wait-and-see or neutral position on technologies with egregious energy use. We must instead firmly oppose such proof-of-work technologies including to the best of our ability blocking them from being incorporated or enabled (even optionally) by any specifications we develop. If anything we should pursue the opposite: develop specifications that supersede existing specifications, but with much less power consumption. We believe this is consistent with the TAG Ethical Web Sustainability principle
- capableweb 5y agoWhat are these people smoking? DID has nothing to do with PoW, it's merely one of the methods you could use to timestamp when a signature was made. There are plenty of other ways (centralized too, since that's probably what Microsoft and Google care about) to do this, so not sure why sustainability is being brought up as a counter-point to the DID specification.
- detaro 5y agoAs someone who has attempted to follow a few events in this space, there was massive presence of PoW blockchain advocates, underlying assumption that everything is blockchain, ... and it very much felt as if other things were very much an afterthought (EDIT: and sadly such afterthoughts in theory being in the spec but useless/not really wanted is not entirely uncommon in specs). If that was a common impression others got, don't be surprised by the reaction.
- capableweb 5y agoAs another person who've followed DID closely, where is the "underlying assumption that everything is blockchain" part coming from? The specification has one mention of "blockchain" and many parts of the specification leaves the storage part free for implementors to decide freely how it works.
- PretzelPirate 5y agoDaniel from Microsoft’s Identity team has been driving the Microsoft DID effort for years and has been pushing Bitcoin as the storage layer for that entire time. https://mobile.twitter.com/csuwildcat https://mobile.twitter.com/csuwildcat
- chrisco255 5y agoIt's interesting to me the amount of energy people spend on convincing themselves that a technology (POW) that didn't even exist 12 years ago and ran on home PCs up until 7 years ago is somehow responsible for wildfires in California or deforestation in Brazil. DID has little to do with Bitcoin. I don't even know if it's the best option, but clearly the lack of decentralized identity on the web has been significant in propagating corporatist monopoly ownership and influence over the web. Nitting about an integration with one particular blockchain (DID works with multiple) is not productive and it's a distraction from the core point of the proposal. At any rate, I've become fairly convinced at this point that something like ENS (https://ens.domains/ https://ens.domains/) is better suited for a decentralized identity. Optionally registering a simple domain name via a smart contract and signing in to services with a public-private key pair (such as an Ethereum address) is a far superior experience to anything I've seen as far as simplicity goes. I don't need to give up personal contact info. I have ownership of my address. I can create new addresses if I need. I can augment my ENS-linked domain with social media info or website info and that is all stored on-chain. However, one-click sign in doesn't require hitting the chain, just requires signing a message. It's pretty elegant. I just think it needs more standardization.
- geofft 5y ago> It's interesting to me the amount of energy people spend on convincing themselves that a technology (POW) that didn't even exist 12 years ago and ran on home PCs up until 7 years ago is somehow responsible for wildfires in California or deforestation in Brazil. I'm not sure why years of time matters. Rapid growth is extremely common in technology. How much time did you need to spend convincing yourself that a microblogging website that didn't exist 12 years before 2016 and was constantly crashing 7 years before 2016 had become a major influence on world politics, up to the level of the US presidency? Hopefully not more than a few seconds. How much time would it take to convince you that one BTC, which did not exist 12 years ago and was worth $300 7 years ago, hit more than 200 times that amount this year? Does it seem impossible? The ecological argument against Bitcoin-style consensus is short and fairly obvious from Satoshi's paper. The innovation in that paper (compared to existing techniques like Merkle trees) was the ability to stop double-spend attacks by "mining" chains of transactions. This requires making sure that no single participant - not even the financially-meddling central banks that Bitcoin is supposed to provide an alternative too, and the might of their governments - can mine at a rate higher than the network. This immediately produces an incentive for both the network to make use of as much computational capacity as possible to keep itself safe, and for any attacker to amass enough computational capacity to mount an attack. The incentive goes up as the block reward goes up, which it has been doing in terms of real value (e.g., number of Big Macs you can buy with a reward), even though the reward denominated in BTC goes down over time. Therefore, Bitcoin-style consensus, if it works, is necessarily a major consumer of worldwide computational power, and as long as computers require energy, it is a major consumer of worldwide energy, which isn't really a thing we have an excess of. That's the entire argument. It doesn't take you very much time - unless, of course, you're incentivized to keep trying to find counterarguments.
- Communitivity 5y agoIt is much easier to destroy than to create. The attack on DIDs is the same pattern of attack on Extensible Resource Identifiers (XRIs), one of the standardization attempts along the path to DIDs. Politics and soundbytes popular at the time are used to garner a boost in public opinion, or to defeat something that may threaten the status quo, or to just defeat the efforts of someone disliked by a group (some of the same people in DIDs were in the XRI effort). DIDs may not be the best technology to solve decentralized identity, but it is the best technology we have right now. ENS is great, but completely tied into Ethereum. I am horribly disappointed in Mozilla in general, and Tantek in particular. For me this is the last signpost on Mozilla's road from being a bastion for Open Source to being a JACM (Just Another Corporate Monolith). Why the big-name detractors coming out the woodwork now for the review did not take part in the DID standardization effort is unclear to me. They could have influenced its growth and helped it mature into something they could live with - proper pre-natal care for standards and by those involved with Standard Development Orgs. Instead they have sent corporate hatchetmen to abort DIDs stillborn at birth.
- AtlasBarfed 5y agoI'm not going to give bigcorps a pass, but the thing with specs is that it is hard to criticize it until the spec is, you know, published in many cases, especially if you aren't in the committee.
- vmception 5y agoProof of Work (POW) solutions can be equally deployed on other consensus protocols that don't have unbounded energy demands, given the ways the platforms function. Proof of Stake (POS), Delegated Proof of Stake (DPOS), etc. There should be standardized education in this field if standards communities themselves can be so reactionary, equally missing that decentralized identifiers have nothing to do with blockchain, and even if they did that they have nothing to do with POW.
- user-the-name 5y agoAs usual with blockchain promotion, the word "can" is doing a whole lot of heavy lifting in that sentence.
- vmception 5y agoIt is database state consensus acknowledgment, not blockchain promotion. If you deploy a development environment where certain functions can run, it doesn't matter if the underlying hardware is using 1% of global emissions, or a couple households worth. This post is acknowledging that the "nearly none at all solutions exist" and are good enough for some purposes, while also acknowledging that it is weird that a standards committee did not acknowledge them but reacted to the global emissions one.
- zcw100 5y agoSnooze. Yet another half baked idea from the W3C. Remember WebID? Probably not because it went nowhere after repeatedly ignoring major weaknesses. What did they do? Address them with well thought out solutions? No, they did exactly what they always do, ignore it until they can't and then bolt on some actually implemented solution hoping to ride their coat tails. Sort of like what we've got here with JSON-LD. So now we can be lectured to for a decade about how superior their DID solution is if only we would listen.
- fennecfoxen 5y agoThe link goes to a takedown of the idea, agreeing with you it’s pretty half-baked. Lectures on its superiority seem unlikely.
- dboreham 5y agoBetter imho to ask: what user problem is DID solving? Because: if it's truly decentralized then there's no need to publish it. But publication is a core aspect of DID. That it must be published is a jedi mind trick that allows in "on a blockchain". Now we see the real problem being solved (not a user problem): need something published on a blockchain.
- Noujin 5y ago> if it's truly decentralized then there's no need to publish it. How do you come to that conclusion?
- pwlb 5y agoNot necessarily is DID connected to publishing something on a blockchain. First: DID does not make any statements to the underlying infrastructure, this can be a completely decentralized public, permissionless blockchain but also public, permissoned ledger(also decentral but a little less) or the did Methods using a central server as referenced in the w3c mozilla response. DID for example solves/enables some aspects of the 10 principles of SSI, e.g. portability
- capableweb 5y agoFrom https://www.w3.org/TR/did-core/#design-goals https://www.w3.org/TR/did-core/#design-goals Decentralization | Eliminate the requirement for centralized authorities or single point failure in identifier management, including the registration of globally unique identifiers, public verification keys, services, and other information. Control | Give entities, both human and non-human, the power to directly control their digital identifiers without the need to rely on external authorities. Privacy | Enable entities to control the privacy of their information, including minimal, selective, and progressive disclosure of attributes or other data. Security | Enable sufficient security for requesting parties to depend on DID documents for their required level of assurance. Proof-based | Enable DID controllers to provide cryptographic proof when interacting with other entities. Discoverability | Make it possible for entities to discover DIDs for other entities, to learn more about or interact with those entities. Interoperability | Use interoperable standards so DID infrastructure can make use of existing tools and software libraries designed for interoperability. Portability | Be system- and network-independent and enable entities to use their digital identifiers with any system that supports DIDs and DID methods. Simplicity | Favor a reduced set of simple features to make the technology easier to understand, implement, and deploy. Extensibility | Where possible, enable extensibility provided it does not greatly hinder interoperability, portability, or simplicity. In short, if the large platforms like Facebook, Google, Apple, Microsoft et al started using DIDs, we could start using logins across platforms instead of creating new accounts for each one. Basically, the specification is trying to come up with a way of offering federated authentication ala OpenID, but without locking down the storage mechanism of the ID itself.
- motohagiography 5y agoThe energy argument seems like a disingenuous signal to dilute the discourse into a political one instead of examining the architectural merit. If the best argument they have against decentralization is that proof of work uses electricity, it's a red herring holding a dog whistle in front of a motte and baily while it asks whether anyone will think of the children.
- inter_netuser 5y agoGoogle stands to lose a lot if DIDs take off. They'll stop at nothing.
- geofft 5y agoBefore the argument against blockchain methods is an argument against centralized methods such as "did:ccp", which seems to be an identity mechanism backed by Baidu accounts: https://w3c.github.io/did-spec-registries/#did-methods https://w3c.github.io/did-spec-registries/#did-methods If this were a Google conspiracy using Mozilla sock puppets, why would they bring that up as an objection, and ask to move the spec back to the discussion phase explicitly forbidding such mechanisms? It would be extremely straightforward for Çelik's handler at Google to ask him to remove that paragraph before publishing it. (There are more centralized identity mechanisms there, including a proposal to use Microsoft GitHub. That spec doesn't even have the veneer of distributed ledger that Baidu's one does, and it was added by Transmute, one of the authors of the DID spec. How do we know Transmute isn't a Microsoft sock puppet, helping them "embrace, extend, and extinguish" this spec? It seems like Çelik's concerns are all reasonable and it would be entirely possible to make a DID spec that satisfied all of them - is the reason that we ended up with this DID spec that Microsoft and Google are deliberately producing a bad version?)
- inter_netuser 5y agomozilla conspiracy: Mozilla referenced quite openly "Google sez PoW bad", idk if something this open is a conspiracy. "Proof-of-work methods (e.g. blockchains) are harmful for sustainability (s12y). Also as noted by __Google__, the registry contains methods which rely upon proof-of-work which is wasteful. “Successful” proof-of-work systems ..." Google simply wants to own the entire identity stack end to end, and they can, because they own Android. Same with Apple. Apple is canvassing various jurisdictions right now with their Digital ID, and demands internal govt discussions use a codename and that nobody mentions Apple by name, and also try to restrict who gets to know, gonna be one anti-open standard if they get their way. Google is likely doing the same, haven't been following this stuff too closely these days, but their ventures arm has made investments all over in identity in the last decade. centralized objection: The DID push from Microsoft hinges on their ability to route around the mobile platform control (because they don't have a mobile platform), so that they can even begin to compete with Apple/Google here. I'm sure Apple and Google just love the idea of being cut out and commoditized. That's all this is about, Microsoft not having a mobile platform. so now MSFT is fighting for an open standard, which is hilarious. They don't care if it's centralized on some identity provider like github or whatever. If you dig deep enough all identity is centralized in the end on the most authoritative source of identity: government. "decentrablazed" is just a window dressing. I concede that this doesn't explain Mozilla actions very clearly, but they are at this point a mostly irrelevant player in the identity market anyway, nobody except their 3% of marketshare cares what they think. Mozilla just renewed their deal with Google for 400mil, so it could very well be an executive decision that "DID very bad, no matter what", and how their standards architects have to contort themselves into pretzels on mailing lists and invent new catchy acronyms. The mozilla-google contract terms haven't been published even in the roughest approximation, make of that what you will.
- jude- 5y agoThis response is full of mostly terrible, uninformed takes. > No practical interoperability. As Microsoft & Google expressed, the DID “Core” spec has not demonstrated any degree of practical interoperability, instead delegating that to a registry of 50+ “methods”, none of which themselves have interoperable implementations. While there are 50+ DID methods, they're all trivially made accessible via a uniform API [1]. DID method specs and implementations are service-specific drivers, which are meant to plug into a generic resolver and registrar service endpoint which anyone can run. The point of the DID W3C spec is to provide a standard for creating individual DID methods. It is not, and was never about, creating a uniform API for using them. > Encourages divergence rather than convergence. The DID architectural approach appears to encourage divergence rather than convergence & interoperability. Again, the author misses the point. DID methods are service-specific drivers; providing a uniform API is the responsibility of the layer above them. The "divergence rather than convergence" dichotomy here is absurd -- it's like saying that the proliferation of link-layer protocols encourages divergence rather than convergence in networking protocols, while completely ignoring that IP exists and is meant to provide a uniform narrow-waist protocol for using them. Obviously, link-layer protocols don't implement IP, nor are they expected to. Similarly, DID methods are not expected to implement the higher-level universal resolver and registrar protocols. > Centralized methods allowed, in contradiction to WG & spec goals & name. This I think is the only fair point in this email. Why the fuck is did:ccp considered a good-faith DID method?! It's a DID method for Baidu Cloud. > Proof-of-work methods (e.g. blockchains) are harmful for sustainability (s12y). Also as noted by Google, the registry contains methods which rely upon proof-of-work which is wasteful. “Successful” proof-of-work systems waste a staggering amount of electricity world-wide (e.g. Bitcoin consumes more energy than most countries. The amount of electricity PoW blockchains spend is orthogonal to the worthiness of the DID spec. That PoW spends a "staggering amount" of electricity is not a consequence of PoW blockchains' designs; it's a consequence of the governments of the world permitting it to happen. The absolute energy use is not an intrinsic requirement for these systems -- PoW blockchains would work just the same if the world's budget for mining was only 1 KW. I expected better from the W3C. (Disclaimer: I am the author of one of the DID method specs). [1] https://github.com/decentralized-identity/universal-resolver https://github.com/decentralized-identity/universal-resolver
- still_grokking 5y agoIs someone going to reinvent Namecoin¹ and IPFS's IPNS²? At least the abstract of the spec reads like that to me: Abstract Decentralized identifiers (DIDs) are a new type of identifier that enables verifiable, decentralized digital identity. A DID refers to any subject (e.g., a person, organization, thing, data model, abstract entity, etc.) as determined by the controller of the DID. In contrast to typical, federated identifiers, DIDs have been designed so that they may be decoupled from centralized registries, identity providers, and certificate authorities. Specifically, while other parties might be used to help enable the discovery of information related to a DID, the design enables the controller of a DID to prove control over it without requiring permission from any other party. DIDs are URIs that associate a DID subject with a DID document allowing trustable interactions associated with that subject. Each DID document can express cryptographic material, verification methods, or services, which provide a set of mechanisms enabling a DID controller to prove control of the DID. Services enable trusted interactions associated with the DID subject. A DID might provide the means to return the DID subject itself, if the DID subject is an information resource such as a data model. This document specifies the DID syntax, a common data model, core properties, serialized representations, DID operations, and an explanation of the process of resolving DIDs to the resources that they represent. [ Source: https://www.w3.org/TR/did-core/ https://www.w3.org/TR/did-core/ ] ¹ https://www.namecoin.org/ https://www.namecoin.org/ ² https://docs.ipfs.io/concepts/ipns/ https://docs.ipfs.io/concepts/ipns/
- inter_netuser 5y agoYou are exactly correct. In fact quite a few implementations rely on IPFS. The hilarious part is that these supposedly "decentralized" ID systems pull data from the most centralized entity: government's civil register.