4 ms·
Maybe I misspoke, the identity is as secure as a password in a password keeper or authentication key. I think it's analogous to a decentralized SSO (e.g. Googl
by huntertwo 5y ago
Maybe I misspoke, the identity is as secure as a password in a password keeper or authentication key.
I think it's analogous to a decentralized SSO (e.g. Google login, Apple ID login, etc.) that can be used as a source of identity without the service provider/smart contract writer needing to implement it themselves.
With Ethereum-style blockchains, this auth is built into the programming language itself. The msg.sender field is guaranteed to be consistent with the actual sender of a transaction. If it isn't, the computation that is ran will not be published to the blockchain.
This sort of auth infrastructure is not trivial to implement and you get it for free by deploying your service on blockchain. In addition, you get persistent storage for free. On top of that, smart contracts have common published interfaces. My IERC721 implementation will respond to the same calls as your IERC721 implementation. Standardized APIs is not really a thing on the normal Internet, but it's commonplace in web3.
EDIT: by "for free" I mean in terms of implementation and infrastructure work. The gas fees definitely are not free.
- themacguffinman 5y ago> the identity is as secure as a password in a password keeper or authentication key So, not very secure. Passwords aren't very secure on its own and practically always supplemented by human support systems and alternative factors of authentication. In really critical systems like government, these supplements extend all the way to a physical meeting with a bureaucrat. What's my recourse if I lose my blockchain secret? All of that is the main cost of a serious user authentication system. Who cares if the msg.sender field is guaranteed to be consistent with the sender of a transaction if no one knows who the sender actually is.
- littlestymaar 5y ago> All of that is the main cost of a serious user authentication system. So much this. If you don't care about credential theft or recovery, authentication is a straightforward problem. With a blockchain what changes is that you just can't care about this problem, and when it happens, your user is f*cked.