4 ms·
I think Blockchain removes the cost of user authentication (you are your address) which is non-negligible. Everybody has an identity that only they can use. On
by huntertwo 5y ago
I think Blockchain removes the cost of user authentication (you are your address) which is non-negligible. Everybody has an identity that only they can use.
On top of this, smart contracts take the code that would usually run these centrally administrated APIs and makes it public. I think this is the more powerful idea.
It's not just a decentralized ledger anymore, but a decentralized and public execution environment. And it's not crazy to believe that we've barely scratched the surface of what this type of execution environment can enable in user/provider interactions and user/user interactions.
- edent 5y agoHow do you validate that an identity can be used by one - and only one - person? If my spouse borrows my authentication device (with or without my permission) - then that ID is being used by multiple people.
- huntertwo 5y agoMaybe I misspoke, the identity is as secure as a password in a password keeper or authentication key. I think it's analogous to a decentralized SSO (e.g. Google login, Apple ID login, etc.) that can be used as a source of identity without the service provider/smart contract writer needing to implement it themselves. With Ethereum-style blockchains, this auth is built into the programming language itself. The msg.sender field is guaranteed to be consistent with the actual sender of a transaction. If it isn't, the computation that is ran will not be published to the blockchain. This sort of auth infrastructure is not trivial to implement and you get it for free by deploying your service on blockchain. In addition, you get persistent storage for free. On top of that, smart contracts have common published interfaces. My IERC721 implementation will respond to the same calls as your IERC721 implementation. Standardized APIs is not really a thing on the normal Internet, but it's commonplace in web3. EDIT: by "for free" I mean in terms of implementation and infrastructure work. The gas fees definitely are not free.
- themacguffinman 5y ago> the identity is as secure as a password in a password keeper or authentication key So, not very secure. Passwords aren't very secure on its own and practically always supplemented by human support systems and alternative factors of authentication. In really critical systems like government, these supplements extend all the way to a physical meeting with a bureaucrat. What's my recourse if I lose my blockchain secret? All of that is the main cost of a serious user authentication system. Who cares if the msg.sender field is guaranteed to be consistent with the sender of a transaction if no one knows who the sender actually is.
- littlestymaar 5y ago> All of that is the main cost of a serious user authentication system. So much this. If you don't care about credential theft or recovery, authentication is a straightforward problem. With a blockchain what changes is that you just can't care about this problem, and when it happens, your user is f*cked.
- littlestymaar 5y ago> I think Blockchain removes the cost of user authentication (you are your address) which is non-negligible. Everybody has an identity that only they can use. Like a login/password… With a specific difference, that if you lose your private key or if it's stolen, you're doomed and you cannot recover. The user authentication story is actually the weakest point of blockchains/cryptocurrencies, and that's exactly why 99% of their user actually uses a third-party wallet. Also, smart contract sound like some magic sauce, but in fact aren't anything magical, they are short programs that can be executed on public data in the ledger, that's it. And the execution environment isn't distributed either (at least in the meaning of distributed computing, every node have to process the entire contract).
- huntertwo 5y ago> smart contract sound like some magic sauce, but in fact aren't anything magical, they are short programs that can be executed on public data in the ledger, that's it. The only ways they can modify this ledger is publically and immutably defined at the creation of the smart contract. Sure they're not magic, but at any given time, you can query events published by that contract and query that contract's state. That's at least different than the traditional internet. It may feel like I'm moving the goal posts but I'm just trying to highlight the differences between the stuff that happens on the traditional internet vs web3.
- littlestymaar 5y agoI'm not trying to say smart contract are useless, just that they are only useful in the context of the ledger they are built-on. I was specifically responding to this sentence: > It's not just a decentralized ledger anymore, but a decentralized and public execution environment. “decentralized and public execution environment” really sounds like you could execute arbitrary programs in a distributed fashion (which would be really cool), which is absolutely not what smart contracts are.