22 ms·
Real Problems That Web3 Solves, Part 1
- thesuperbigfrog 5y agoWhy can't this be done with existing public key cryptography?
- meheleventyone 5y agoThere’s even a standard for doing this with WebAuthn.
- iskander 5y ago...which has effectively neither adoption not momentum to achieve adoption: https://sec.okta.com/articles/2020/04/webauthn-great-and-it-sucks https://sec.okta.com/articles/2020/04/webauthn-great-and-it-... For better or worse, there are a large (and ever growing) number of Metamask users these days...
- meheleventyone 5y agoAbsolutely, but let’s not pretend this is some magic technology that only cryptocurrency can solve. Nor is it clear cut that we’ll see adoption of wallet logins outside of crypto circles.
- codehalo 5y agoThe web3 solution is significantly easier than webauthn, if what I read in the above article is to be believed.
- meheleventyone 5y agoThere’s a trade off there though. There are also other standards. People should probably want their cryptowallets to be better secured than they are. But crypto is facing the same UX challenge which leads to a worse model with the same attendant risks as phishing passwords. The point still is that logging in with public-key cryptography is not exclusively a technology supported by cryptowallets.
- ziml77 5y agoWebAuthn is exactly what I thought of too... and hardly anyone is supporting it. In fact the only place I've seen it was Best Buy's website, oddly enough! Having yet another way to do this sort of authentication isn't going to magically make people start using it.
- cle 5y agoThe author discusses this explicitly in the article.
- dylkil 5y agoIt can. The biggest success of crypto has been putting public/private key pairs in the hands of 10s of millions of people.
- thesuperbigfrog 5y ago>> The biggest success of crypto has been putting public/private key pairs in the hands of 10s of millions of people. I would argue that the biggest successes of crypto are selling GPUs and facilitating malware ransom payments. GPUs have sold like crazy and you are lucky to get a high end one with the current demand. Everybody and their pets are running mining rigs. Good luck getting a nice GPU for machine learning or graphics rendering. Previously malware authors had to rely on gift cards or similar means to get paid. Now they have variety of cryptocurrencies to choose from and they can even trade cryptocurrencies to launder the paid ransom funds.
- Sargos 5y agoHere is a good thread with more information on why giving everyone a public private key pair is a big deal and the kinds of use cases it unlocks: https://twitter.com/BrantlyMillegan/status/1389270115884097536 https://twitter.com/BrantlyMillegan/status/13892701158840975...
- spinny 5y agoIt can. It just happens that the easiest way to achieve this is using web3, even if there is no blockchains involved. The article is about login methods, not cryptos or web3
- jeroenhd 5y ago> It just happens that the easiest way to achieve this is using web3 Is it? U2F is actually rolling out to more and more websites but I've never seen any website offer to log in with a dropdown for cryptocurrencies
- spinny 5y agowebsites that are related to cryptos do it, others generally don't. try dappradar.com/ for example
- alisonkisk 5y ago
- MBCook 5y ago> The article is about login methods, not […] web3 It’s literally titled “ Real Problems That Web3 Solves, Part 1”
- ozim 5y agoI like how "trustless" falls through the cracks at each and any of the Web3 posts I read. It shows up as a marketing trick because it obviously means something very specific for that crowd and it is explained somewhere with a fine print. I will stay with a thought that trust is not something that can be solved by technology :)
- justinsaccount 5y ago
- deleted 5y ago[deleted]
- nateburke 5y agoGreat post! This definitely has me thinking more about the extent to which the strength of a particular identity representation is determined by our willingness to bind artifacts of value to it.
- evrydayhustling 5y agoI like the starting focus on identity. Imagine if emails to you were authenticated by a token that you authorized by logging in, and could revoke at any time. In a Web2 world, features like this get created by Google, Apple or whomever inventing a permissions system that works on their platform -- and serves their product goals. In a Web3 world where you issue identity tokens, you can revoke them arbitrarily, so if your identity is shared you can trace and revoke at the root. Services move from worrying about how to game Apple's privacy model to how to avoid a ban that remains strictly in your control.
- KarlKemp 5y ago...and in a Web 1 beta II world this was already done by PGP in 1991. Granted, it never achieved mainstream adoption because it's somewhat cumbersome and solves a problem people do not actually experience. Sort-of like everything blockchain, one might say.
- thesandlord 5y agoMy big question with using a Web3 login is what advantages it gives the website owner. With social Web 2.0 login, I can be fairly sure the person logging in has a valid email address, a name, etc, and it is a single click for the user vs filling in all the info all over again. With a Web3 login, it is basically the same. Except I'm not really given any personal info like name or email, so I need ask them for that anyway. I guess you can tie that into your wallet somehow? But I don't see this as a 10x solution. Do people really not trust FB/Google/Twitter that much? Why does currency and money need to get involved? But in another world, isn't this the problem Keybase was trying to solve? Of course, they got mixed up in their own cryptocurrency as well (XLM) which had so many issues with bots trying to get into the airdrop. So idk.
- rafale 5y agoWeb3 emphasizes privacy be default. Emails are no longer needed for password management so if u need them for something else users should opt-in.
- MBCook 5y agoApple already provides something like that that’s WAY more popular and doesn’t require the waste of resources a public blockchain would. I know some people (especially us techies) like to control the whole stack but who do you think the majority of normal users would prefer?
- rafale 5y agoBitcoin doesn't support web3. Ethereum is moving to proof-of-stake, so the resources issue is gonna become a thing of the past. Also using web3 for authentication doesn't broadcast any transaction. So zero resources are used at that point. Apple has a closed platform mindset, I hope users will see the benefits in a decentralized open protocol.
- MBCook 5y ago> I hope users will see the benefits in a decentralized open protocol. See I think this here is the biggest issue. I feel like we have 30+ years of proof that normal users LIKE centralization for the convenience and ease it provides. Email is basically the last man standing when it comes to distributed implementations and 1) it had reached mass adoption early enough to survive and 2) we’ve centralized it to a large degree anyway with Gmail and outlook.com
- somewhereoutth 5y agoI suppose blockchain can be a mechanism for the reification of pure information. So turning something that only has a value, into something that has a unique identity that can be 'pointed to'. In the real world I might have a physical key (or some other interesting object) - there is exactly one of it and it exists in exactly one place (though of course I can create copies - but they are new objects). In the virtual world this is a bit harder to construct and enforce - information is entirely ephemeral, and has no concrete existence or place. Maybe blockchain can provide that (in the context of the chain only of course).
- dathinab 5y agoMost web2 apps supports a smaller number of SSO providers. Technically "independent" SSO providers and similar existed, but non made it mainstream because there was no reason for App's to support them, but there was cost to support them. There is even less reason IMHO for most App's to support Web3 login (more complexity). Furthermore even if they do the web3 login would probably still list Google etc. as the web2 login still lists email. It's questionable that more than one maybe two blockchains will be supported. It's likely that often only a small number of wallets will be supported, it's also likely that "bigtech" companies like google will provide web3 logins if it becomes successful. So, it might happen. But I don't see it tbh. There is just no reason to go the extra length to support web3 login for most Apps/Companies. EDIT: Also trust of the general public into anything containing the word "crypto" or "blockchain" is constantly undermined by an endless slew of scams, and money grabbing schemes. Which can hurt adoption of web3 login.
- spinny 5y ago> It's questionable that more than one maybe two blockchains will be supported You don't really need a blockchain unless you need to keep data on a blockchain. To login and identify a user you can simply sign a message. I consider the address as the user "identity". Any blockchain data related to that address is mean to be public (some people register <some-name>.eth on the ENS for example)
- MBCook 5y agoIf you don’t need a blockchain what makes this web3? I thought that was supposed to be the defining feature. If it’s just cryptographically signing things we’ve had that ability since PGP came out.
- dathinab 5y agoAnd we had "independent" SSO schemes based on it, non of which gained widespread adoption (in the "independent" form). The reason is the UX/UI flow, complexity for integrating them and users which already have it. So if all people have a wallet at some point which they also can use for SSO that might get adoption. Through for investment into crypto, instead of "daily using it" you probably don't want a hot walled on your phone. So as long as "daily/frequent/casual crypto usage" doesn't become a supper common thing for large parts of the society (in the "western" world) it's hard for it to gain wide spread adoption I think.
- jdlshore 5y agoSeveral years ago, Mozilla/Firefox created "Persona," which was an open-source federated identity system that provided all the benefits described here. The idea was that it would eventually be built into browsers. I used it on a commercial site myself for many years. It failed to gain traction, and Mozilla eventually pulled the plug. Persona had many advantages over the Web3 vision described in this article. It was painless for a new user to create an account, because Mozilla provided a default identity server. It was easy for a website owner to set up, because Mozilla provided a JavaScript shim that worked on any browser. And it didn't rely on a wasteful and slow distributed ledger. Despite these advantages, Persona failed. I don't see how a blockchain-based approach, with so many disadvantages compared to Persona, could possibly succeed outside of the blockchain enthusiast community. And, on a technical level, a federated approach seems innumerably simpler and less wasteful than a blockchain-based approach.
- cranberryturkey 5y agoI don't know about that. I feel like oAuth and other forms of authentication are overly complex to implement. If they build a super simple implementation API then I could see it taking off.
- denton-scratch 5y agoI had a go at writing oAuth from scratch, to understand it. I made a working solution. But I don't use oAuth; while I was writing the code, I understood it, but I don't any more. An auth system needs to be understandable and transparent to a normal user, and oAuth is not such a system. Like, I couldn't explain it to my non-tech relatives, even if I swotted up on it first. Explaining blockchain-based auth to a non-tech user is a problem of a much greater magnitude.
- w-j-w 5y ago
- itsdrewmiller 5y agoOne possible advantage web3 has over Persona is that it is not under the control of Mozilla or whatever foundation Mozilla set up to address those very predictable concerns. Being distributed might help it gain early adopter mindshare which could lead to future UX improvements. (Not saying I believe this will definitely happen, just that Persona failing isn't a guarantee of failure here.)
- choward 5y agoI was expecting a blank page.
- armchairhacker 5y agotldr; this article describes one problem that a blockchain solves better than existing non-blockchain solutions (identity). My issue with the article is that it uses a lot of words to try to explain why web3 and blockchain may be the future. But for what point? If an important technology comes around which happens to use web3 or blockchain, i’ll see it’s important from its description and i’ll adopt it. I don’t need to support “web3” as a concept, because web3 basically means nothing. And i don’t think that web3 or blockchain is intrinsically bad, i just haven’t seen anything particularly useful with those technologies yet.
- hdjjhhvvhga 5y agoI'm not sure about the present tense here; a conditional would fit better.
- herlitzj 5y agoI honestly thought this was going to be a joke post because that top image is ridiculous. Maybe I'm just old, but it reads to me as Web 1.0: Great Web 2.0: Ugh, ok Web 3.0: You're serious with this?
- scotu 5y agoI had the same thought. Imagine listing all blockchains in tiny icons you scroll sideways. I suppose that can be done a lot better, but still, who decides which blockchains are included and which are not?
- herlitzj 5y agoPrecisely. Or what if you're some random grandma that has a wallet (since we're living in a make believe world where this is easy to create). Imagine you've forgotten which blockchain your wallet is on. Will there be a search box to find my wallet in this mess of combinatorics that is a login page?
- MBCook 5y agoI mined a teeny tiny bit of Dogecoin years ago. One of the times it spiked in price, I decided to convert my teeny tiny bit into Etherium. So I used a wallet on a cryptocurrency trading site. Do you know what site that was? I don’t. I can’t remember. I think the password may be in my password manager, but I’m not sure. I’d have to go digging. But I am SURE I’ll remember which of the 1200 common block chains I use for my credentials.
- MBCook 5y agoBecause that’s insane. Normal users couldn’t deal with that. Highly technical users can’t deal with that. It’s too much of a pain in the ass. The solution is that there should only be one or two chains that everyone uses. Then there’s only one or two little icons you need. The people who run the trains could make sure they keep running by having tens of thousands of computers. Of course that cost money. Luckily they get money out of the block chain because they can spend coins. Of course users don’t really like buying things. Maybe it wouldn’t be too hard to put an ad or two in there to pay for things. The easiest thing to get users on board is to use brands they trust. No normal person is going to trust everything they have two the Kakarot blockchain with an anime superhero for a logo. Do you know who people trust? Facebook and Google. If they were to… Oops. I invented today. Only with much more energy use.
- kradeelav 5y ago... why would I want to share my wallet to something I trust less than a strange dog? Or part of my identity? No thanks. One of the great things about usernames/passwords is it didn't demand that vulnerability - you could come up with whatever and it was your responsibility to keep up with your shit. Systems that mimic real world systems on average feel less prone to this silliness.
- pxue 5y agoemail/password is terrible UX for vast majority of user. it's forgettable, it's not secure, and it exists only because it have existed since dawn of computers.
- endisneigh 5y agoI disagree. Email and password is terrible compared to what?
- enos_feedler 5y agoThe real issue for me is that I would rather have Apple sitting between me and To Ty's app than a public blockchain with no owners. There are just too many edge cases and circumstances where I would rather have a trillion dollar company defending me, a paying customer, against To Ty if the app turns on me or doesn't meet my expectations. me < To Ty's app + whatever they can get away with. me + apple > To Ty's app.
- lern_too_spel 5y agoMy question with any blockchain application is always what does it solve that a centralized trusted database doesn't solve faster and with less waste? You can implement social recovery in a centralized database with less waste.
- dylkil 5y agotrustless, immutable, censorship resistant, permissionless.
- lern_too_spel 5y agoHow is any of that useful for a particular application? For every single application blockchain has been applied to, these are downsides.
- linseed_213 5y agoAre there security/UX risks with users getting used to using their wallet for auth ? It's difficult to know a safe vs. potentially unsafe site when it comes to crypto. Reading the docs, it appears to be relatively limited permissions, but either by giving more permissions than desired or phishing? Or can they combine the authentication with additional information to become a more effective spearphishing target? If my email account is phished or hacked, it's bad, but there's a level between my cash and my email account. If I make a mistake here, potential losses are higher. In which case I'd probably have a 2nd wallet for auth and another I actually use, which then becomes more of a pain. I don't trust my parents or less technical relatives to use this flow safely.
- steelstraw 5y agoAre there any security risks with signing onto a site with Metamask? Is there any way for them to drain your wallet without prompting you? If not, then it seems to be a superior method and experience. You don't have to deal with usernames/email/password, and it offers more functionality with currency.
- TylerE 5y agoThere have already been many many scams perpetrated by things CLAIMING to be MM/OpenSea
- dylkil 5y agoWhen you sign in with web3 you are signing a message with your private key, and the website is verifying the it was in fact you that signed the message by checking the messages signature with your public key. The only way anyone can gain control of your wallet is if you give them your private key (or the seed to the privk) or if your PC is compromised (but you have bigger issues then)
- larsrc 5y agoI like the "social wallet" idea, though no blockchain is needed for that. But there's a real danger that if enough of your friends get compromised, you can get compromised as well, and that can snowball. And most people would not be secure enough. So you'd want to have someone more secure as part of your "social set" - a large organization that actually does serious security. But then you're again depending on some large organization. You could require at least one of several large organizations, but that in turn reduces security.
- vanusa 5y agoGreat - now I'm forced to be on some blockchain somewhere to get anything done. This is progress?
- spinny 5y agoYou are missing the point. The article is about login methods. Username/password vs message signed with a private key. The blockchain part is there because is the only ready-to-use way to do it in an browser. It's absurd how HN users in general are so dismissive of anything cryptocurrency
- vanusa 5y agoMy point was usability. And being (effectively) forced to join / legitimize their hive to get anything done. It's absurd how HN users in general are so dismissive of anything cryptocurrency. It's quite reasonable actually, given the prevalence of not just hype, but frequently delusional / just plain rambling and incoherent hype surrounding it -- not to mention blatant fraud and manipulation aimed specifically at unsophisticated users. And the skivviness of many people involved in it. That said, the OP presents one of the more thoughtful proposals I've read recently, and may belong to the 5 percent or so of blockchain applications that just might have a useful application. With emphasis on "just might". We'll see.
- spinny 5y ago> My point was usability. And being (effectively) forced to join / legitimize their hive to get anything done I agree with you on this. For the purpose of login in with a private key, i would prefer some browser extension (or built in the browser) that generates a key from a seed (like a crypto wallet) and only does that. This doesn't exist at this point. > ... not to mention blatant fraud and manipulation aimed specifically and unsophisticated users Also agree, but probably for different reasons. Many people on twitter have the tendency to be mean, twitter doesn't make people mean, but it amplifies it. There is so many scams and manipulation because scammers and con artists always existed and people's greed for that 100x token and so does the scamming The speed of communication that the internet gave us also serves as an amplifier of the ugliness of human nature
- kiernanmcgowan 5y agoAll of these decentralization arguments make me think of early git: >Every Git clone is a full-fledged repository with complete history and full revision tracking capabilities, not dependent on network access or a central server... http://web.archive.org/web/20080821113906/http://git-scm.com/ http://web.archive.org/web/20080821113906/http://git-scm.com... Sure git can be used without the need to have have a central server, but everything became so much simpler with github and other code repositories. Decentralized systems are hard to navigate and humans will choose the easy thing every time.
- evv555 5y agoIs that a bad thing? Web3 is ultimately about building hierarchies(DAO). I would like to see a diversity of new digital hierarchies, new federated systems with unique properties. Not just a purely decentralized system. Decentralized vs. Centralized is a false dichotomy IMO.
- danielmarkbruce 5y agonot just Git. Email. Money (used to be issued by individual banks). Internet infrastructure. The web. Everything goes centralized.... because... it's easier. And humans seem to show over and over again, easier wins.
- IiydAbITMvJkqKf 5y agoThis problem is currently being solved by WebAuthn. For social recovery, if desired, the private key can be split up using Shamir's secret sharing.
- grey-area 5y agoYes webauthn is a much better solution to this.
- ranger207 5y agoAs other comments have pointed out, there are other technical solutions to decentralized identity. The blockchain doesn't solve this problem any better than private keys or Persona or whatever. The article acknowledges this. The problem with existing solutions is not the technical problem, it's the social problem: making the new solution easy to use, fixing bugs and covering edge cases, and getting it deployed widely. The author claims that the social problem is what Web3 solves; that Web3 is the social solution counterpart to the blockchain technical solution. Web3 is indeed a social solution to this social problem, but the real problem with Web3 is that it's a terrible social solution. Web3 (aka blockchain enthusiasts, aka cryptobros) is a community comprised of on one end by true believers who believe they're smarter than anyone else in the room and that anyone who brings up complaints are only mad because they didn't get in when the cryptocoin was cheap, and on the other end by grifters and scammers who fully acknowledge that they're only in it for a quick buck off the back of unsuspecting rubes. This is the core problem with most crypto projects. Most blockchain projects have technical problems [0], but even for the few things that blockchain uniquely solves [1] the general scummyness of everyone involved means that anyone advertising they're solving problems with a blockchain is not someone to trust your money with [2]. Of course, the blockchain isn't the only technology to suffer this problem. Blockchain's at the top of the hype cycle right now so of course it's filled with scammers. But even though Pets.com may not have the most competent business, the technology behind ecommerce was generally sound. Blockchain on the other hand has so few useful niches that the only thing left are the hype-men. [0] Eg you could use NFTs to prove ownership of IRL property, but why? You're just storing a deed in a different place. It used to be in a SQL server somewhere, now it's on a blockchain instead. [1] That is, decentralized databases where you don't trust all parties not to modify the data. But uh, with whom do you need to share data that you don't trust, and how do you guarantee they're not just feeding false data into it in the first place? [2] I'm not implying all blockchain enthusiasts are pretentious and/or scammers. Just that there's a much higher proportion of them in the Web3 community than elsewhere.
- epolanski 5y agoOwnership IRL is proved by notarial deeds, what do you want to prove with a blockchain and how?
- rbanffy 5y agoI was fully expecting to see an empty HTML page. Correct me if I'm wrong, but the only new idea here is to use a ledger to hold public keys associated with an identity. You could add keys by signing a new key with one of the previously globally accepted ones proving you are that entity and the same would go for removing a lost one, by signing a new message with all the remaining keys. Having a key copied without your knowledge would be a major disaster, however. Apart from that, this is not very different from using keys in SSH and providing a challenge/response login form would be very simple.
- iskander 5y agoA lot of these "this is not very different from X, you could do Y" replies remind me of the original Dropbox news.yc thread. What everyone seems to be missing is that the web3 apps and UI conventions already have broad adoption among millions of only mildly techy users. They don't know what SSH is but they do know how to sign things with their in-browser wallet app. Of course, they also seem to not always know that giving away your private keys is quite bad... But any "solution" that requires e.g. using the terminal is not really competing in the same space.
- rbanffy 5y ago> But any "solution" that requires e.g. using the terminal is not really competing in the same space. The UI required for that is something that can be done in a couple minutes. The heavy lifting is done by libraries provided with the OS.
- iskander 5y agoAnd Dropbox was trivially just rsync... Yet, crypto wallets remain the only cryptographic signature UI that normal people interact with.
- MBCook 5y agoDropbox was “just rsync“ but WAY easier to use for normal people. The iPod was JUST a normal MP3 player with a very easy interface everyone could understand. Ease of use is EVERYTHING. At no point does anything described about how web3 works or solves problems sound easier to use than the current system. Logging in with email and a password is easy. Using a Google to sign in is even easier. Apple’s sign in system is ridiculously simple and frictionless. “Start by finding a chain you like and creating a wallet” is not easy. Do you have to buy coins on the chain? I’ve been seeing a lot of these web3 articles and I truly don’t know. Buying coins is another huge hassle. “Oh but they’ll already have a wallet.” How? At some point they have to create them. Even if it was easier once they’ve created it (which I dispute), how is that supposed to happen? If you have an iPhone, you have an Apple account, can do sign in with Apple trivially. If you have an android phone, you have a Google account, you can do sign in with Google trivially. Either way you have an email address, that’s quite easy. How can you EVER make something simpler than those? I think best case scenario you would be able to match them. But then you’re back to the problem of why I should switch to the new thing when the current thing works just as well. I just have a very hard time seeing normal users ever buy into any of this.
- riddleronroof 5y agoNot to be that HN poster, But wouldn’t pgp key browser plug-in do just as well?
- codehalo 5y agoWhat recourse would you have if you lose your private key? The author mentions a solution to that problem.
- riddleronroof 5y agoSame as Argent. Elect 4 trusted people, if they all ok it’s really you, the custodian (a company that stores your private keys, like LastPass), releases it to you.
- erosenbe0 5y agoHe isn't describing the true state of the world. Banks, brokerages, mortgage providers, and medical entities mostly don't use oauth2 and won't use this stuff either. The world is still old school. Grandpa dies and I go find the paper will. I get an affidavit from a lawyer and a death certificate with a seal from the state. I go into the bank with a bunch of papers and they figure out what to do. There isn't a chain of trust that the state uploads a PK signed death certificate to, which in conjunction with a PK signed 'will and trust' then triggers a preexisting blockchain contract to effect the asset transfer. This is 20 or 30 years off. Maybe 10 or 15 in China.
- candiddevmike 5y agoWhoever has the ability to generate that PK is the real centralized authority.
- weego 5y agoIt's forever off because it's the wrong solution to a problem that no one is invested in even fully identifying let alone working at. My hot-take parallel argument is that full self driving is a smart road problem with 'dumber' cars and not a dumb road and smart cars problem. But there's no scope to VC of profit your way into smart road infrastructure so we do it the wrong way round and hope we can throw resources at it till its fixed.
- erosenbe0 5y agoYou are correct. I would be plenty happy with 80% self-driving and lots of safety features, but the VCs want the robot trucks and taxis for their trillion dollar win. No way full self-driving can do the last mile or work in all conditions. For example, human eyes have pretty decent dynamic range in dark, snowy conditions. We basically make intuitive decisions about which patch of white stuff in the dark of night is the best one to smash through to get our driveways, and I don't think the computer vision is yet discerning enough to facilitate that.
- kristofferR 5y agoThis is kind of funny to read, since in Norway basically every interaction with the government (paying taxes, filing for divorce, accessing our health records etc.) is done through an oauth2 system, the same one we use to log in to our bank accounts/get loans through. Most people haven't interacted with the government via paper in years. https://docs.digdir.no/idporten_overordnet.html https://docs.digdir.no/idporten_overordnet.html https://www.altinn.no/hjelp/innlogging/id-portenminidbankid/ https://www.altinn.no/hjelp/innlogging/id-portenminidbankid/ Some very few non-digital government services remain, unfortunately, and it seems like the storage of wills is one of them. Asset transfer is still going to remain a manual process though, even when digital wills are here, thankfully.
- JesseObrien 5y agoThis article doesn't add up the points to anything that solves for the given problem. Owning identity isn't solved by saying "don't trust ${third party}! Come trust ${my preferred third party}, it's better!" Any blockchain is still a third party that all parties involved with need to place trust in. It isn't somehow more or less trustworthy just because it exists. > Many people, including myself, believe that the individual should be able to own their own identity. Yes, this is nice wishful thinking, but on a global scale it's not really possible or feasible. > OAuth2 should be used for what it was intended to, which is for a web service to provide another web service with a user’s data given that user’s consent. It should not be used as a global digital identifier because that’s too important to be owned by anyone but the individual themselves. So, instead of OAuth being in the hands of FAANG[1] it's in the hands of ${blockchain-of-the-year}? How does moving the trust from a centralized company to a centralized blockchain change MY ownership? If I move everything away from FAANG to someone's blockchain, I have no assurance that chain will continue existing. If there's a flaw found in it and everyone moves to another chain, now what? Sure, we can make the same claim about FAANG not continuing to exist, but the point is there's no inherent advantage here, they're equal. FAANG are supported by millions of individuals and companies that are all, together invested in their success. There's no unilateral agreement on blockchains and I doubt there ever will be. >With social recovery, instead of having to trust Google, you can choose who you trust, and instead trust a given set of friends, family, and services. Again with the trust this and not that. All of my friends, family and other services need to then agree that they're all going to trust ${chain} instead of FAANG. It doesn't fix the problem. "the blockchain" isn't just one thing. Who's chain do we all shift trust to and from and based on what security? At least with Google I can rely on their security because if they end up with a breach of trust it's going to have a massive, real impact on share prices and consumer trust around the globe. That's incentive enough for me to rely on it day-to-day. This article has some interesting tidbits but overall seems like just a baseless rally against FAANG by someone who knows very little about complex authentication or trust and security in the real world. [1]https://www.investopedia.com/terms/f/faang-stocks.asp https://www.investopedia.com/terms/f/faang-stocks.asp
- svachalek 5y agoA properly decentralized blockchain isn't a third party in the traditional sense, a human or organization that is bound to follow its agreements until it doesn't feel like it anymore. It's an algorithm incarnated. That said, its initial and continued existence is dependent on economics. Who will market a service that they don't stand to profit from? Who will drive large organizations to invest in infrastructure that doesn't improve their profits? Either no one will, or it will be adulterated in the process. Sadly the community spirit that drove a lot of early internet development seems to be lost.
- ryan93 5y agoWhat’s the recourse if you lose your private key?
- mwattsun 5y agoI'm reading this with an open mind, but I have questions: > Problem #1: Owning Your Own Digital Identity & Fixing Authentication My very technical friends who are security minded are on keybase.io. Multiple usernames and passwords across the internet is solved in various ways without blockchain. There are a lot of good password managers (I use and encrypted text file.) I don't feel Google owns my identity because I use their authentication system, so unless I'm missing something, I don't see a problem. > enables advanced features like social recovery, which lets you recover your account if you lose your key via a smart contract that takes votes from guardians (friends or paid services). > The idea here is that you could give keys to your friends and family, or to some sort of business service, then if you lose your key, use your friends to “vouch” for you and move the account to a new key. This doesn't seem very workable in a practical sense. It seems like this could be spoofed fairly easily or the business service gets hacked
- YXNjaGVyZWdlbgo 5y agoAlone the audacity to think a single point of failure without any chance of recovery is a good idea for persona management in the real world is insane.
- MBCook 5y agoThis is one of those things that has been an absolutely terrible thing for Apple over the years. People would forget their passwords on their phones or their iCloud account and lose access to everything. And there was nothing Apple could do to help them. So the poor people at the Apple Store just had to tell someone that the last pictures of their dead mom are gone forever. Apple finally implemented a solution in iOS 15 (15.1?). You can designate people you trust to be able to help recover your account. Like your spouse or a sibling. If they don’t have full access, they can just help recover it. You are 100% right. A single point of failure without any chance of recovery is a complete disaster for normal users.
- llbeansandrice 5y ago> The idea here is that you could give keys to your friends and family, or to some sort of business service, then if you lose your key, use your friends to “vouch” for you and move the account to a new key. Facebook already has this functionality and it's an absolutely massive pain if you're somehow not on their happy path. With no real way to figure out what the issue is and get it fixed or on the happy path.
- yob89 5y ago
- mattlondon 5y ago> We need some way of saying “who we are” on the internet in a consistent manner. That way we can communicate with others in a verified way and associate with digital data that we own. We also often need that data to be interoperable between different web properties. Do we really need this? Do we really want to permanently tie identity across websites like this? I find this initial "need"/justification/requirement questionable. I have a login on HN that is totally unique to e.g. Twitter and Instagram and <shudder> LinkedIn. Same with work vs personal. This is deliberate. I do not want to have the same identity here as I do elsewhere. There are many hopefully obvious reasons for this - mostly privacy (both in terms of immediate "in the moment" privacy, but also temporal privacy in the sense that I might not want some potentially ill-advised comments I made on some website 15 years ago to come back and bite me), but also it offers protections against "cancel culture" and general cyber-stalking and doxxing etc as that would become a whole lot easier if you can just run some query on a blockchain and find every single website I've ever used and dredge up my comments/content/etc. Being able to do that sounds very dystopian to me - why don't we just tattoo a barcode on our necks and be done with it?
- pkulak 5y agoPrivate keys are cheap to make. There's no reason you couldn't have a different one for every site. Of course, then it's on you to keep track of them, but it's already on you to keep track of the credentials you're using now. At least this way, the default of "use the same creds everywhere" is secure, if not more private.
- thebean11 5y agoThis is already solved by existing crypto wallet tooling too, you can create an infinite number of keys all derived from a single root key (usually a 12-20 word phrase in modern wallets). A service with access to a single child public or even private key can't tie them to the sibling keys.
- DeepYogurt 5y agoI agree that we don't need unique identities across everything, but even if that is a real problem it is also solved by public key cryptography without a requirement of a blockchain.
- endisneigh 5y agoSo what happens when you get phished with Web3? If the value of all crypto goes down 10% YoY why would you use it? The author makes a bunch of silly assumptions: > We need some way of saying “who we are” on the internet in a consistent manner. That way we can communicate with others in a verified way and associate with digital data that we own. We also often need that data to be interoperable between different web properties. No, this is not true. That's why most people on this site are not logging in through Google. Sites will store their own data, and if you trust them to store that data there’s really no reason to just trust them to store a link to your identity. The author advocates third parties like Metamask and using a Chrome extension, which is ridiculous. If you're going to trust that, why not trust Microsoft, or Amazon, or Google? > With social recovery, instead of having to trust Google, you can choose who you trust, and instead trust a given set of friends, family, and services Yes, because Google is not a service. Ultimately the author makes up a problem and says blockchain is the solution. Even if we suppose it's a solution there's no discussion around phishing, stolen identities, or any failure mode really. Of course there isn't though - in general recourse requires an authority. Blockchain has none.
- thebean11 5y agoIdentities on Microsoft, Amazon, and Google are not portable. They can permanently ban you and you lose access to every single service you used them to authenticate to. Private keys are portable between wallets.
- endisneigh 5y agoWhat you’re saying is also true with web3. A bad actor’s key could be banned and a list of bad actors could be shared among sites resulting in the same thing. In fact, if you believe in privacy at all you’d want to reject this idea for that alone.
- thebean11 5y agoSure, multiple independent sites could individually ban you. That's a fundamentally different problem, and much much less likely. An antidote to that would be using a different key on each site you authenticate to. You still only need to store a single key, all other keys are derived from that yet cannot be associated with their sibling keys. > What you’re saying is also trust with web3. Not quite sure what you mean here, web3 is a pretty overloaded term. If you mean the very concept of web3..that's pretty fundamentally different from trusting a company that can unilaterally ban you, alter your data etc. There is no such parallel in web3. If you mean the JS library, that's also fundamentally different, and it's not the only game in town.
- mexicanandre 5y agoAll these “web 2” companies are going to create their own “web 3” services that will only work on their own product, and we have overly complicated solutions to an issue which didn’t really need solving. Can’t wait for my reddit or meta tokens which have a zero value.
- dmitriid 5y agoArticle: web3 solves decentralized auth, and you are now in control! Also article: to use it, you need to trust a centralized entity like Metamask that develops your Chrome extension and some unknown programmers that code some "smart contracts" aka unverifiable code in esoteric programming languages. Also article: look! a solution! it's better!
- codehalo 5y agoYou don't need to specifically use Metamask to use a blockchain, just like you don't need to use a specific browser to view this site.
- dmitriid 5y agoIt doesn't matter. You end up trusting a centralized entity with your auth. Unless, of course, you are a programmer yourself and can implement that "decentralized auth smart contract" from scratch
- avereveard 5y agoSo, web3 regularly gets updated into the front page, only to be utterly trashed in the comments session. What gives?
- MBCook 5y agoThere is a group of users here on HN that REALLY like cryptocurrency‘s and blockchains and such. Web3 seems to be the latest on that hype-train. There is a different group here on HM that REALLY hates it all. It was interesting technologically but then it started producing more CO2 and using more energy than reasonably sized countries. It also seems to be the method du jour for scammers to take money from people. It’s almost single handedly enabled the ransomware industry. And people like to shit on the current hot thing, deservedly or not. So here we are.
- codehalo 5y agoA lot of HN users were aware of bitcoin when it was worth pennies. Seeing it sitting at 50,000 dollars after trashing it created bitterness and cognitive dissonance. I visit other sites where I can honestly say their users are honestly ignorant, given their lack of technical understanding. But here? This is sad to watch. If crypto/blockchain/web3 continues the current trajectory (or bitcoin goes to 100K), it will be worse, because the proud/bitter HN user will never admit to themselves that others can "get it" even though "I didn't get it".
- api 5y agoThat’s not totally wrong but I’d put it differently. This site is home to a lot of people who work hard to try to do something useful. It inspires resentment to see people get rich by just holding a token. Makes you feel like a fool for trying to do useful work. I think the almost religious zeal makes it much worse. People win the lottery but they don’t claim to be geniuses or representatives of a shining new utopia for it. They just say they won the lottery.
- codehalo 5y agoI understand, but people get rich all the time holding stock like AAPL or TSLA. HN doesn't seem to have a problem with that. Some people see the future, do the research and risk it all on a stock or a cryptocurrency, some people take their last ten dollars blindly gamble on a lotto ticket or a cryptocurrency. How they earned the money they risk should be of no concern.
- nanofortnight 5y agoFederated/Decentralised identity/authentication is a solved problem. For example, this is essentially OpenID. Unfortunately this entire concept failed to gain traction.
- sazz 5y agoThe major issue with the article is that the source of the described problems are due to business agenda and not technology. Everybody can run an OAuth2 authority but of course of only tech giants have the marketing to lure everybody into their nest. Technology won't fix greed which drives business.
- StrLght 5y agoWhat’s even the difference between «owning your digital identity» with email/password vs any other authentication method? Why does it even matter [0]? You don’t own any data connected to that digital identity [1]. I might be a bit on a radical side here, but to me it’s either you own everything or you own nothing. There’s no in-between. [0] Except for OAuth since OAuth provider could ban you at any time. [1] Until it's encrypted with your own public key and isn't stored anywhere in plaintext. Which can't be 100% guaranteed with any proprietary 3rd party service.
- astoor 5y agoIndieAuth[0] is an open standard decentralised authentication protocol which doesn't need blockchain or cryptocurrency. [0] https://en.wikipedia.org/wiki/IndieAuth https://en.wikipedia.org/wiki/IndieAuth and https://indieweb.org/IndieAuth https://indieweb.org/IndieAuth
- roca 5y agoI'm open to the idea that there are real problems that are best solved by PoW/PoS blockchains and smart contracts, so I was hoping this article would reveal one. It doesn't. As mentioned elsewhere, Persona was already a perfectly good technical solution to this, years ago. It failed for various reasons, none of which would be addressed by blockchains/smart contracts. Likewise, the problem of "conveniently and securely log in everywhere" is well solved by Webauthn. Arguing that "web3" will help because it will improve UX is ludicrous. "web3" provides nothing directly to boost UX. "web3 hype means there's lots of money sloshing around which can be used to improve UX" is an admission of defeat; all the money being sucked into the crypto space could be better deployed to solve these problems directly. If this is the best shot at "real problems web3 solves", then there really is nothing there :-(.
- serverholic 5y agoHave you actually used a web3 website? Once you have your wallet setup it's the most seamless login experience I've ever had. Also, I find it funny whenever someone says something like "web3 doesn't actually solve anything that hasn't been solved by other technologies like X". Then why isn't anyone using X? Why is nobody using Persona or Webauthn despite being "superior"?
- cycrutchfield 5y ago> Also, I find it funny whenever someone says something like "web3 doesn't actually solve anything that hasn't been solved by other technologies like X". Then why isn't anyone using X? Why is nobody using Persona or Webauthn despite being "superior"? I find it funny that you do not detect the irony in what you just said.
- danielmarkbruce 5y agoLots of people use and used X, for various X. Various auth only companies exist, like Okta. They don't care for your "data", they are just trying to log you in. Same for Ping, Oracle Identity (or whatever they are called these days), Amazon etc. Then there are services where you use a physical card for auth (many federal government jobs require people to auth using a card which basically just holds keys). There are many auth services with waaaaay more users than any web3 wallet. The statement that web3 doesn't solve anything which hasn't already been solved wrt authentication... is about as close to a true statement as one can make.
- gdsdfe 5y agounless you're running your own servers, you don't own nothing ... you still going to be tied to a 3rd party that does that for you. This is what the web3 crowd don't want to understand, they will keep telling you : big tech ruined the internet bla bla bla switch to us because we are decentralized and you own your own data, ok ... but if anyone wants to use it or access it they need to go through us
- Traster 5y agoI'm glad someone took the time to write this. I think it's quite interesting that the prime example picked here is UI issue. The author freely admits that the "web3" solution is basically just private keys with better UI. I'm not all that up to date on web3 stuff, but... it's not UI. The quote from Vitalik is great though - the goal of crypto is to let people make all the same mistakes and find out single central authorities actually have been established for a reason.
- codeptualize 5y agoI do think a lot of these things go round the circle then end up on the same solutions we had before. Coinbase is a nice example; turns out it's quite nice if some sort of company protects your money, makes sure you don't loose access to it, provides you with insurance in case something goes wrong, and lets you easily send, trade, and convert money. Such a revolutionary idea, right?
- AlexandrB 5y agoThis is probably the first blockchain use case that I've found compelling, outside of using its obvious use as a speculative asset of course. I hope the author elaborates more on this in the next part because there are still lingering questions - like how much would CRUD operations on your digital identity cost? After all, most blockchain technologies have associated "gas" or other transaction fees.
- KaiserPro 5y agoSo the main selling point to "rational" people is that you can connect your wallet to websites? As in potentially link your income to every site you want access to? If I wanted to do micro transactions, and let everyone drain my bank account, I'd not have 2fa on, use my real name, address DoB for things.
- mdoms 5y agoSo now I have to manage not only my own key, but they keys of any of my friends who want me to vouch for them every time they lose their phone? No thank you.
- codehalo 5y agoThe contract would likely be constructed to use any address (public key) you prefer, so it could be the public address your favorite private key. Or not. The choice is yours.
- timeon 5y agoFinally straight to the point: Web3 log in with your wallet.
- vsareto 5y ago>The idea here is that you could give keys to your friends and family, or to some sort of business service, then if you lose your key, use your friends to “vouch” for you and move the account to a new key. >You can also do this to require approval from your friends before a certain amount of money moves out of your account, making theft significantly harder. Okay, what if your relationship with those people changes? If you've lost your key or its destroyed (maybe as a result of those relationships changing before you've had a chance to do anything), presumably you can't remove the trust relationship with your former friends. You then can't withdraw unless your new enemies say so, and you can't change that trust relationship. Plus what are the rules around removing the withdrawal limit? If I can just remove it at any time, how's that going to prevent theft, as I can just remove the limit before the theft? This is now yet another security consideration for regular users. In addition to ensuring your key is backed up, you have to think about contingencies for if/when these trust relationships change. But flip this feature on its head and give your bank this trust, and at least you have the same resiliency as your current bank account. Ironically, you likely want to trust a large entity with vast resources (presumably too big to fail) instead of friends and family if you're looking to be secure against loss of your private key.
- alisonkisk 5y ago
- alkonaut 5y agoOk that’s one try. And there were… literally zero reasons in the article for actually using blockchains or cryptocurrency. I believe this guy is being intellectually honest (which is a feeling I don’t get often in this space) but I don’t think he’s capable of asking the right questions. The question that should be asked is what is a problem we (humans) have that is not only solved by this new tech, but can’t in any way even by bending over backwards be solved with some other technology?
- joshuamorton 5y agoA question that isn't really delved into here, given a social recovery scheme, this iiuc must run on chain, so there are gas fees associated with account recovery. What's the cost to recover an account if I lose it today? Is there any way to reduce that cost, or will there always be some (potentially hundreds-of-dollars) fee associated with account recovery?
- ChristopherDrum 5y agoI sincerely don't follow the logic on how Web3 "solves" the problem posited in the "But what if someone loses their private key?" section: "Some of you might already be familiar with multisig, which is a similar concept... The idea here is that you could give keys to your friends and family, or to some sort of business service, then if you lose your key, use your friends to “vouch” for you and move the account to a new key. ... With social recovery, instead of having to trust Google, you can choose who you trust, and instead trust a given set of friends, family, and services. If you ever lose access to your private key, there is a smart contract encoded on the blockchain that syas that if some number of your guardians all agree (you pick the number) then you can move your account to a new private key." I didn't see anything about Google being a requirement for multisig, so I'll skip the author's aside and ask, "How are these two things different?" Multisig lets friends "vouch" for us to move our account to a new key and social recovery lets friends "agree" to let us move our account to a new key. These sound exactly the same to me? The original writeup says something about "multisig moves the burden down to the user to issue keys" etc., but setting up smart contracts would still require someone to do some kind of setup work. Those contracts aren't just going to magically appear out of nothing; at the very least you'll have to select your friends, get their agreement, and a contract would have to be issued and signed. I dunno, I still fail to "get it" (this is not an invitation to try and help me "get it", as helping people "get it" is kind of the point of the original blog post)
- not2b 5y agoI don't see any advantage in the proposed system over oauth-based solutions. Currently, you trust one of some set of big companies to verify your identity, but these big companies might misbehave. The web3 solutions mean that you trust that some blockchain-based approach will be programmed correctly and not have bugs that render it useless; requiring N different people to recover an account will impose unacceptable delays in emergencies. Better to give one or more nonprofits the job, have them manage identities and do nothing else. No energy-sucking blockchain needed.
- polio 5y agoDigital signatures have already solved the identity problem for anybody too paranoid to trust Google and OAuth. It doesn't require a blockchain either.
- epolanski 5y agoSo the author made up a problem and said blockchian was a solution.
- BoppreH 5y agoThe proposal is strictly inferior to SQRL[1] plus emailing your friends shares of your secret[2]. You get private keys, no third parties at all, social recovery, but with no Blockchain costs. Bonus point: you automatically get a pseudonym for each app. The point about financial incentives aligning more easily in web3 is good, but I understood that even the poster child Metamask is not complete as it's missing good social recovery UX. Please stop trying to sell snake oil. [1]: https://www.grc.com/sqrl/sqrl.htm https://www.grc.com/sqrl/sqrl.htm [2]: https://en.m.wikipedia.org/wiki/Secret_sharing https://en.m.wikipedia.org/wiki/Secret_sharing
- laserbeam 5y agoNothing in this article requires or benefits from a blockchain. Social recovery of your account is a feature on Facebook and has been for years... There's nothing novel or particularly interesting here. The only thing blockchain would add is a gas fee whenever I would log in somewhere, and would keep the same UX problems I'd have with login anywhere else. Keep in mind the most successful project EVER in managing identity was let's encrypt. A centralized non-profit that got the internet to use https everywhere by signing ssl certificates and vouching for everyone's server for free, and as far as I can tell without collecting any personal data about anyone. Web3 is going to solve "this" (whatever this is)... Riiight.
- jl2718 5y agoWeb3 did not invent cryptographic login! Client cert auth has been available for decades. There was never a need for centralized login. It’s a one-liner in Apache with mod-ssl, and here’s a random google result showing the entire thing in a few lines of standard library python: https://gist.github.com/nebulak/6d865ddd768fb905a562d6026cdd508a https://gist.github.com/nebulak/6d865ddd768fb905a562d6026cdd...
- arvindrajnaidu 5y agoIdentity is a system of vouching so as to gain access to protected resources. The article suggests, you should let a network vouch for u instead of a corporation. By doing this you gain “ownership” You only “own” something when you can create, destroy and erase all signs of its existence at will. Explain how you do this with Web3.
- hamilyon2 5y agoMajor browsers support client certificate authentication. rfc5246, is this it? And where is web 3.0 part?
- morelandjs 5y agoI’m open to web3 being a new and exciting phase of the Internet. I’m just wondering when it will come to me. You’d think if it were such a huge revolution it would start appearing organically in my every day web experience, but I don’t own any crypto, and to the best of my knowledge I have not yet organically stumbled into a new experience built on web3 innovations.
- ladyattis 5y agoI still don't see how this is solving any problems. What if I just want to consume the content on the open web as is without logging in? It's one of the reasons why I have to use archiving sites to read the news because half the time NYT or WaPo whine about me not being logged in (as if being able to spam me with ads wasn't enough). I think all the noise about fixing identity and the like is just another way to force end users to give up privacy so content creators can just data mine more and sell it all off to ad companies. Like even to pay for something via crypto currency doesn't need much of a fixed identity other than an wallet address to send/receive coins from/to. Outside of that, why do they need to know I am X person rather than just X wallet/address?
- tim333 5y agoI'm curious. The main thing he's pitching seems to be logging in with Metamask or similar with I guess the 'username' equivalent being a public key and you verify it with a private key. This tech has been around a while, since 2017 at least. I still have Metamask and keys in my browser from speculating on tokens back in the day. Do any mainstream sites let you log in that way? Any plans for Metamask login on HN?
- yingliu4203 5y agoI believe the key issue of debate is that people ignored the context: "Many people, including myself, believe that the individual should be able to own their own identity." The cryptocurrency and decentralization are possible because some people believe and live on those ideas. For those who don't care, bitcoin is $0 or worse: a Ponzi scheme. For those who believe in it, the goal is to own one's id, data and money, and collaborate without a big company or a central government.
- louwrentius 5y agoThe only tangible authentication solution is MetaMask, a crypto wallet. This is just typical Web3 dishonesty. The article doesn’t show any problem solved by web3 tech that existing solutions can address much better.
- davecheney 5y ago> One common refrain is that “blockchain is a solution in search of a problem.” After reading this article it seems that the most useful thing someone has thought to use the blockchain for is [checks notes] a form of social media popularity contest to recover the key to your blockchain wallet.
- PostThisTooFast 5y ago