5 ms·
"Sign-In with Ethereum" will be huge. I purposefully avoid "Sign-in with Google" because putting too much power in a centralized authority terrifies me. I'd mu
by serverholic 5y ago
"Sign-In with Ethereum" will be huge. I purposefully avoid "Sign-in with Google" because putting too much power in a centralized authority terrifies me.
I'd much rather have the convenience of "Sign-In with X" but backed by something I have control over.
- yepthatsreality 5y agoLike OpenID?
- deleted 5y ago[deleted]
- theplumber 5y agoOpenID is a closed system both to the end-user and the website owner based on secrets(`state` `code`, developer keys) from identity providers(google/facebook) not cryptography.
- Uehreka 5y agoI’m a long time blockchain skeptic (check my comment history) but I recently came around on the SSO stuff and can vouch for it enough to say the magic words: it is in fact a novel thing that cannot be done without blockchain using pre-existing crypto or auth tech. The reason is: With private key auth alone, you don’t have identity, just a non-human readable public key, and no universally known exclusive association with a particular username. With OpenID or WebAuthn or any of that, you would still need a company or org to keep a centralized database of everyone’s credentials and user info. With Blockchain you don’t: As long as the Ethereum blockchain keeps going, your info (username: “johndoe.eth” public_key: “420abc” avatar: “some HTTP or IPFS url”) will stay stored. This is the exact precise thing blockchains are unusually good at doing, and given how much people these days are hating on big tech companies managing their identities and harvesting data in the process, “SSO with no company attached” seems like a thing people actually want. I’m still highly skeptical of art NFTs and crypto as currency and lots of other blockchain stuff, but in this one case they’ve won me over. This seems legit.
- UncleMeat 5y agoI don't see how this is beneficial compared to signature-based auth. Didn't people all recoil in horror at the real-names policy that Google performed ages ago? Making it fundamentally difficult to separate my identity on various platforms is bad. And further, I really don't see the benefit of having my username stored on a blockchain rather than in an application database. Is the goal to prevent other people from making an account using the same username that I use on other platforms?
- serverholic 5y agoWho said you need to use your real name?
- UncleMeat 5y agoThe overlap here is the centralization of identity, not the actual real name part. Is it desirable to have my hn handle also match my wow character name?
- Uehreka 5y agoWho said you need to only have one ENS name either? You could have one that you use for personal tech-related stuff, one that you use for work stuff, one that you use for gaming-related stuff, etc. (although for that kind of usage to really take off, Gas fees will need to come down).
- UncleMeat 5y agoThen why aren't you just using old school signature based auth? What does having your public key stored on the ethereum blockchain accomplish?
- Sargos 5y agoYour public key is available to everyone on the internet so anyone can verify your signed message. You can't do that without a blockchain unless a trusted third party is used.
- api 5y agoIMHO this could be the "killer app" and is something I might actually use if it got sufficient traction and support. OpenID gives a few organizations like Google, Okta, and Microsoft "root on the entire world." It terrifies me.
- knownjorbist 5y agoA key "ah-ha" moment for me was realizing that your wallet is your login on every dApp that's ever existed or ever will exist. It's pseudonymous and developers sort of get various things for free out of it as a result(payments, authorization, authentication)
- TigeriusKirk 5y agoThere's also the potentially interesting idea of wallet-as-resume. IE allowing different types of access depending on what sorts of things you've done with your wallet in the past. Certainly not for all applications, but a certain level of implied competency might be appropriate in some cases.
- shagie 5y agoI've heard that one before... I've yet to hear a "how is it better" set down in a way that describes the architecture in a way that can be explored with more than handwavium. How does "wallet as resume" solve the implied competency better than a GitHub repo with signed commits? How does the wallet-as-resume solve the "I copied a project" or "I followed the tutorial line for line?" One can create a NFT or whatever equivalent for code you wrote just as easily as code you copied (be it with cp or typing it all in yourself). Can only one person would be verify a particular implementation of FizzBuzz? If the code is copied, can the original author usurp the "I wrote this" from a pretender? Does anyone reading resumes actually think that this is a problem that needs solving?
- UncleMeat 5y ago"Service X preemptively bans me because I signed up for service Y with my wallet" sounds like the opposite of censorship resistance and decentralization.
- aditya 5y agothis already exists, just not widely deployed on web2. 'Connect Wallet'.
- serverholic 5y agoFyi “Sign-In with Ethereum” is just standardizing the “Connect Wallet” button.
- Sohcahtoa82 5y agoWhat's the recovery if your private Ethereum key gets deleted, or worse, stolen? If you're signing in via some other 3rd party, you can change your password. I'm just trying to think of how "Sign in with Ethereum" would work if you're trying to get your technophobic grandma that clicks on phishing links and responds to the County Password Inspectors [0] when they call to use it. [0] https://www.smbc-comics.com/comic/2012-02-20 https://www.smbc-comics.com/comic/2012-02-20
- knownjorbist 5y agoSocial Recovery is one of a couple methods people have proposed: https://vitalik.ca/general/2021/01/11/recovery.html https://vitalik.ca/general/2021/01/11/recovery.html
- serverholic 5y agoI think smart wallets will help with that. You’ll be able to create a set of recovery tokens such that you only need a subset of the tokens to recover your wallet. For example, you can generate 7 tokens and only need 5 to reset your wallet keys. You can give 3 to your relatives, 1 in a safe-deposit box, etc. Grandma’s kids can help her set it up. Edit: Or, for people who really prefer centralization, you can give all 7 tokens to Bank of America. The point is you have a choice and can design the security system you want.
- xur17 5y agoAnd I imagine the "recovery tokens" part being abstracted away. There will be a bunch of apps that work this, and there's no reason it couldn't be as simple as checking a few boxes to select the people you want to be able to help you with recovery, with some default rules that you can change.
- mNovak 5y agoSurprised actually this doesn't exist in a more general sense -- just X of N decryption of arbitrary files. Could be your private key recovery, or just mundane corporate documents with provable "two man rule"
- 5y ago
- UncleMeat 5y agoWhat is the difference between "Sign-in with Ethereum" and the signature-based auth that has been available for decades without blockchains?
- deltaeerie 5y agoPeople are actually using it.
- maccolgan 5y agoYou can't assign value or tokens to public keys without a blockchain, we've come full circle.
- somebodythere 5y ago1. A lot more people are using Sign In With Ethereum than other kinds of signature-based auth to log into websites. The UX, while not perfect, is a lot more figured out. 2. SIWE lets the user share a cryptographically verified shared state of the user. For example, digital asset collections, reputation in a group etc.
- vbuterin 5y ago1. Has an actual path to adoption (because people have keys and have a motivation to try hard to retain their keys because they have crypto assets) 2. Once smart contract wallets properly gain adoption, you'll be able to do recovery (see: https://vitalik.ca/general/2021/01/11/recovery.html https://vitalik.ca/general/2021/01/11/recovery.html ) 3. Lots of built-in anti-sybil techniques (eg. verifying that the address has nonzero balance is a pretty simple and effective one)
- captn3m0 5y agoIsn’t sign in with U2F exactly the same guarantees and issues? (Cryptographically proven pseudonymous identities, but no recourse if you lose your keys) Why does ethereum need to come into the picture?