4 ms·
Genuine question: what has private key authentication to do with blockchain? I've been using this for my ssh connections for almost 15 years now. And the secon
by leifg 5y ago
Genuine question: what has private key authentication to do with blockchain? I've been using this for my ssh connections for almost 15 years now.
And the second question: what happens if you use your private key? Every website that uses password has a mechanism to reset your password. Take that feature away you'll lock out millions of users.
- shiohime 5y agoYeah PKI has been around of course for a long time and is a core facet to how the web functions today. The private key authentication I'm referring to is because wallet extensions allow for users to connect their wallet to applications, as a method of authentication. You don't even have to have funds in your wallet to perform this authentication, you just need a wallet. If you lose your private key, you're probably out of luck, but there may be some wallets / platforms that have strategies to mitigate risk, but idk to be honest. So yes, for sensitive applications it is a risk vector, however for users that are already familiar with crypto, it's not really a new risk. If you ever lose your private key or it's compromised you can lose whatever money is in that wallet. The thing that I like about the infra personally as a solo dev is that using this for authentication for small scale applications on whatever chain I chose is really easy to set up and is a great user experience, and I'm not worried about this as an app developer as my target audience already should be vaguely familiar with how this works.
- pornel 5y agoA crypto wallet is just a random number. Literally. Everyone using wallets for identity equals everyone just picking a random number to represent themselves (and then classic cryptography allows you to prove to others that you know this number without revealing it). The hard part of this is not cryptography — that is already solved quite well. It's the human side. People forget pass phrases. Or disclose them to whoever calls them and says they're from Microsoft Pass Phrase Verification Authority. People break computers they haven't backed up. People click "Yes" on security prompts, and open random mail attachments. With private keys involved, these situations are irreversibly catastrophic.
- UncleMeat 5y ago> You don't even have to have funds in your wallet to perform this authentication, you just need a wallet. OK. This was literally 100% possible and functioned in 100% the same way a decade ago. A wallet address is just a public key for which you control the private key. Literally nothing about this requires blockchains. When you sign up for a service you say "here is my public key" and then you sign a message providing that you have the private key for that public key to authenticate in the future. Where is the blockchain?
- shiohime 5y agoIt's just really easy to use and easier authentication than any scheme I've worked with before. If you want to try it out yourself, it's easy and only takes a few minutes to try out, I recommend it if you're really curious. Just download metamask and connect your wallet to opensea or some other nft marketplace. Once you connect that's registering for the site and you can play around with the functionality on the site afterwards. The blockchain is involved for you to be able to make transactions and execute smart contracts, which take your wallet public key and signed message as inputs. So yeah you could use a traditional web app and the only thing you are using is this wallet for authentication purposes if you want, but most apps using this approach are going to natively interact with the blockchain, whether it's a financial app, gaming app, whatever. They're going to be inseparably part of the experience.
- UncleMeat 5y ago> It's just really easy to use and easier authentication than any scheme I've worked with before. But this is literally the same as just "connecting my pgp public key" to some authentication service that manages this. This is no more convenient than the stuff that happens the first time I ssh into a service. And surprise, passwords crushed this and virtually nobody uses this for consumer applications. > but most apps using this approach are going to natively interact with the blockchain, whether it's a financial app, gaming app, whatever. Now the story is very different. You led with "a good use of web3 technologies is auth." Now you say "yeah, auth isn't any better but you might as well do it this way given that your web3 service is using ETH for whatever other hypothetical thing."