5 ms·
> I don't think you necessarily need blockchain. Can't you just prove that you are who you say by signing something and sending it to the service? It's importa
by Sargos 5y ago
> I don't think you necessarily need blockchain. Can't you just prove that you are who you say by signing something and sending it to the service?
It's important to remember that blockchains are just public-key cryptography where you have a private key that can sign things and, importantly, everyone knows everyone else's verified public keys. That's it. It solves the key distribution and verification problem that PGP and TLS etc have and this enables a lot of use cases such as universal private communication channels and authentication.
Signing the message is key for this yes but knowing that a certain key is connected to a specific user and that user having the ability to use it to sign verified messages everyone in the world can trust is the real utility here and what makes this universal SSO system work well.
- readams 5y agoBut it doesn't solve that at all since there's no way to tie something on the block chain to the real world. All the same problems of knowing whether some particular PGP key belongs to the person you want apply the same to a wallet address.
- Sargos 5y agoI probably should have worded it differently to avoid that connotation. There are a lot of identity protocols but that's not what I was focusing on. On HN I am Sargos. You know this because I am replying to you and only I can do that with this account. I can also tell you that I'm @JamesCarnley on Twitter but there's no way for you to verify that. If I were using my public key to log into HN and Twitter you would know those are both my accounts and thus my persona is verified across multiple applications. If I were to link my public key to my government's identity database then you'd also be able to verify I am really James in real life as well.
- readams 5y agoAnd none of that has anything to do with blockchain.
- Sargos 5y agoIt feels like you're trying really hard to not get web3 any credit here. Try making something like this in the traditional web. People have tried and failed. Ethereum provides a robust, secure, and increasingly usable key storage and usage system to everyone which makes "just signing a message" a simple task and not a 10 step process probably involving a CLI. It's worth considering the utility of this and the possibilities everyone having a person public/private key pair allows. My fellow software developers among us likely have their mouths watering at the use cases this unlocks. Here's a pretty good thread about the implications: https://twitter.com/BrantlyMillegan/status/1389270115884097536 https://twitter.com/BrantlyMillegan/status/13892701158840975...
- rank0 5y agoI haven’t heard a convincing argument for why only ethereum can get users to use key pairs. You can improve the UX of key management tools without a global network of redundant computers.
- Sargos 5y ago> I haven’t heard a convincing argument for why only ethereum can get users to use key pairs. I never said this. >You can improve the UX of key management tools without a global network of redundant computers Yet nobody has ever done it until now.
- uncomputation 5y agoI’m not sure what utility signing a message has inherently. You do this already behind the scenes on apps like iMessage or Signal with end to end encryption.[1] Or if you want to do it more directly but without the command line, there is Keybase: https://keybase.io/sign https://keybase.io/sign Unless you were to upload each and every chat to a blockchain - which is prohibitively expensive - I don’t see the killer advantage over the previous alternatives. Also, many people here are also programmers, developers, and - surprise - hackers, so I am sure we would be interested in the mouth-watering use cases you’re thinking of (I looked at the Tweet thread you linked but it was just an explanation of public key cryptography in general.) [^1]: Apple also refused to backdoor a terrorist’s iPhone at the demand of the FBI. OpenSea intervened when someone stole assets from a collector (https://blockzeit.com/opensea-nft-marketplace-stops-hacker-from-selling-stolen-bores-apes-worth-2-2m/ https://blockzeit.com/opensea-nft-marketplace-stops-hacker-f...)
- xigoi 5y agoYou can verify that you're the same person on Twitter by mentioning “I'm @Sergos on HackerNews” in your Twitter.
- accountofme 5y agoHow does everyone know everyone's verified public keys? How are they verified? Who does the verification? How do you trust the verifiers? How do you know that person x in the real world has pubkey x?
- Sargos 5y agoVerified probably isn't the right word here. Authentic would probably work better. I as a person have accounts on lots of apps but no real way to prove I own all of them. When you use a public key as your identifier then everyone can verify that the entity that owns Sargos on HN also owns Blah on Reddit if I want them to. Essentially you can trust that the digital entity you are interacting with is the digital entity you knew and trusted on the rest of the web in the past. If you are using a web3 app and see vitalik.eth then you know for a fact that it's Vitalik Buterin. Unfortunately we only know this for sure because he said that is his address in public but there are many identity protocols trying to solve this problem and if you were to tie your public key to your government's identity database then you would be able to prove real world provenance.
- biztos 5y ago1. They can (theoretically) examine the whole ledger. 2. Your possession of the private key “verifies” your public key, if someone takes it they are now you. 3. Depends on the consensus mechanism but in the best case, “everyone” and in the worst case “coinbase.” 4. You don’t trust them, the system is supposed to be trustworthy with untrustworthy participants, and when that’s not true you will just have to trust the architects of the hard fork. 5. Magical off-chain oracle!
- uncomputation 5y agoThis description fits Keybase equally well, which never really took off into mainstream and then shot itself in the foot by being acquired by Zoom. Also GPG doesn’t have a key distribution problem. You can spin up a keyserver or use a popular existing one.