15 ms·
Online Identity
- mooreds 4y agoThis was a weird post. Kinda a grab bag of random thoughts around identity: * we have fractured identity online * FB/Google might be going away * Web3 may protect against that * Large Language Models might cause the death of the internet. I'm not really sure what to take away from the post. I found it confusing.
- chayesfss 4y agoAgreed, simple things like 'there identity' also make it hard for me to focus too much on it as well. Everyone has a lot of different personas online, it's free to do and there's zero downside.
- PaulHoule 4y agoThe conclusion I got from it is that he wants to get 1000 followers on TikTok so he's got to do something to inflame people and get attention.
- ja3k 4y agoThe first idea I had with this post was definitely: it would be funny to make an over the top long identity archipelago with unrelated identities. So I guess you're sort of right.
- ja3k 4y agoYou're right. It is four only vaguely related topics that don't come together into a real thesis besides 'online identity feels a little noisy and precarious'. The fact that I couldn't come up with a better title than 'Online Identity' maybe should have been a clue that what I was writing was a little unfocused. Thanks for reading though!
- vorpalhex 4y agoThose three points are related. Facebook/Twitter/Et al wanted to play gatekeeper and now are becomining festering corpses, which has made the disparate online identity problem worse. Because these platforms are gamified, they are worth gaming and gave rise to lots of fake automated content. Go search "best tablet" or "best lawnmower" for several hundreds of thousands of examples. Or look at Twitter. Instead of any of these achieving a plaza of conversations, people are farther apart than they were to begin with.
- Jaruzel 4y agoThe thing about a single online Identity is that there should be no way for it to be revoked against the will of the person it identifies. In real life I am who I am, and unless I choose to change that, no-one can legally take my identity from me. There's been too many horror stories of people being locked out of their Google or Facebook accounts by Google and Facebook, even for the most minor of infractions, and that person immediately also losing access to to all the other services they used 'Sign in with...' Until this problem is solved, I will never switch to a single online Identity for access, and I certainly will never use my Google or Facebook account to register with third party services.
- causi 4y agoYes. It would be nice to have a government-issued e-mail address that couldn't be taken away from me by anything short of a court order.
- harlanji 4y agoWhat about starting with a public library? 120 year email + static hosting tied to library card. Start with one branch or small system, scale from there. Could reasonably be managed per branch with central support orgs. I guess most of them have a server room or colo or similar with a couple U free.
- toomuchtodo 4y ago[US centric] It feels like we're almost there between usps.gov and login.gov, someone at USDS just needs to make the equity and digital access case to get the funding to build out the app. The current administration has already expressed its position on federal service delivery improvements [1], and frankly, USDS/18F has a track record of crushing it. This would go hand in hand with the USPS slowly making its way to being a meatspace trust anchor/identity proofing|credentialing provider [2]; problem with your email account? Get help in person at your local USPS. [1] https://www.whitehouse.gov/briefing-room/presidential-actions/2021/12/13/executive-order-on-transforming-federal-customer-experience-and-service-delivery-to-rebuild-trust-in-government/ https://www.whitehouse.gov/briefing-room/presidential-action... [2] https://www.cfr.org/report/solving-identity-protection-post-office https://www.cfr.org/report/solving-identity-protection-post-...
- Macha 4y ago> The problem it hopes to solve is we don't trust Google or Facebook. I have this problem as well. I trust them not to fuck me. Mostly because I trust them not to notice me at all. But I don't trust them to live forever. I'm some bacteria in the gut of a whale. What will I do when the plankton stop flowing? My fear is actually the opposite here. I don't think Google will cease to exist overnight, or something without a ton of warning signs that others using them will have to adapt to. But being squashed like a fly because of some malfunctioning ML algorithm with no recourse? That makes it to HN a few times a month, so I have to assume happens more frequently once you count people without the following to independently draw attention to it.
- rhacker 4y agoWe should just advertise our own website. not all of these other companies.
- ja3k 4y agoYeah, I guess it is sort of a personal ad to put all those account links in the middle of my post. I meant it as an illustration of how fractured our online identities are. Also as a joke about how noisy the internet is: Almost every website has 2-6 such icons, usually twitter, github, rss and email. I don't know how most people use the internet but my eyes just glaze over them (Which is sort of sad actually, when I read a blog I like I really should subscribe to the author directly somehow). I think expanding it out to more than 20 is funny, but I may have an idiosyncratic sense of humor here.
- rhacker 4y agoI see trucks on the freeway where I can't really tell what company it is driving for except sometimes there's a large panel sticker that says LIKE US ON FACEBOOK and as far as I can tell it's a Facebook truck. I think some people are losing the concept that everyone's advertising for Facebook instead of themselves.
- robmccoll 4y agoI just want a real federated identity protocol with public key distribution and access delegation through signed certificates. Do discoverability through DNS. Tie identities to providers via their hostnames (user@provider seems to work fine for email).
- disadvantage 4y ago> I'm not really anonymous anywhere because I'm lazy and milquetoast Worth having a few anon accounts so you can experiment with different concepts without having your real identity cancelled. I'm not talking about malicious hate speech or harassment, just toying with a new online avatar and toying with new concepts. I've tried tweeting under my real identity, and usually end up regretting the post a week later. With an anon account you can leave the tweet up because no-one knows it's you.
- pphysch 4y agoOnline "privacy" is a bad meme. Our digital society would be 100x healthier if you could trust that the persona on the other side is real and can be held accountable for bad behavior. Advertisers and crooks already have under-the-counter access to our private data (via Equifax, etc.), but we don't get to benefit from it. Let's get over our misguided ideological fetishization of "privacy" that we adopted when we read a fantasy book by George Orwell in middle school and implement a proper identity scheme for the 21st century.
- vorpalhex 4y agoFacebook's real name policy, Youtube's real name policy, Twitter's blue checks.. This hasn't worked. Not once. Full stop. IRC continues to be the best place to have real conversations. Discord is pretty great too and even has built in alt support.
- pphysch 4y ago> Facebook's real name policy, Youtube's real name policy, Twitter's blue checks.. These are all opt-in verification mechanisms, likely with the main purpose of protecting the rights of influencers and other content creators so that the platforms keep making money off them. I'm talking about a single federal government-run identity provider that obsoletes all the above schemes. That's what we need and where we are headed, whether we like it or not. It is absurd that we still rely on SSNs and home address verification in 2022.
- vorpalhex 4y agoYou mean like the IRS hiring a private shady biometric company to try and match you to a grainy drivers license photo before they canceled the whole thing due to the bureacratic nightmare hellscape it spawned?
- pphysch 4y agoThat sounds awful. No, it would need to be an in-house thing, a proper government agency, complete with their own datacenters and software teams across the US. Probably impossible with the current "print $$$ and outsource" culture in Washington.
- uneventual 4y agoThis is a solved problem, but nobody realizes it yet. We already have a decentralized system of unique identities, and we have since the '80s. It's called the domain name system. They're human-readable, they have strong guarantees about being able to own and control them (so long as you pay a nominal fee), and they have a rock-solid infrastructure behind them that backs everything from Google to the US government to your friend's blog. We even have a (somewhat less convincing) way of verifying that the server you're talking to really is the one that your DNS record points to. What still needs work is getting from an identity system, which tells you which server to look at for a given name, to a system of authentication for specific tasks. Given that someone controls a given domain name, how can they use that to log in to a service or post messages that are verifiably theirs? If you're willing to run a server for it, OpenID works. If you only want to send email, DKIM has you covered. The w3c's decentralized identity specs are really cool, and I think did:web [1] has the potential to bring us to a world where you can buy a domain, cname it to some host, and upload your public keys there so that you can sign anything and login anywhere. Making this easy for non-technical users will be important, but I think it can be done. The fact that ICANN policy requires companies to allow you to migrate your domain guarantees that you can sign up with some fancy startup that will manage everything for you and keep your identity if you want to move somewhere else. [1] https://w3c-ccg.github.io/did-method-web/ https://w3c-ccg.github.io/did-method-web/
- Zamicol 4y agoDNS is centralized.
- uneventual 4y agoIt's a mixed picture, but to me the fact that irangov.ir still resolves in spite of an all-out siege by OFAC tells me that it's decentralized enough for almost anyone.
- mxuribe 4y agoSopme of what you've mentioned actually is trying to be solved by groups like IndieWeb...For example: * For identity by way of DNS, such as via domain name, see: https://indieweb.org/personal-domain https://indieweb.org/personal-domain * For logging into systems by authentication based on controlled domain name, see: https://indieweb.org/Web_Authentication https://indieweb.org/Web_Authentication There are many other related topics on indieweb.org and other related websites. What we need more of includes systems that make implementing such methods and protocols super easy.
- teucris 4y agoA proper identity solution is impossible. I see three requirements: 1. Uniqueness: Exactly one ID assigned to each human 2. Irrevocability: nobody may invalidate the ID except it’s owner in the case of replacement 3. Anonymity: The owner of the ID can use it to prove their singular humanity without revealing anything else about themselves. #3 is relatively easy to achieve provided #1 is solved. But #1 requires an Oracle [0] and cannot be decentralized to ensure #2 is upheld. The only practical solution we’ve found is identity assignment by nation states, eg. social security numbers. 0: https://encyclopedia.pub/entry/2959 https://encyclopedia.pub/entry/2959
- olah_1 4y agoThe blockchain is the oracle. (Note that a DHT can be the oracle too) Can you explain what the problem is exactly? The infinitely small possibility that the same ID is generated for two different people?
- teucris 4y agoThe Oracle problem is defined as the inability for blockchain solutions to validate their data with the real world. In this case it’s that any specific ID is actually a singular human, and not a bot, sock puppet, etc. Note this means any one person cannot get two or more IDs. How would you implement a system that issued such IDs?
- dane-pgp 4y agoIt might be possible to have a multi-layer identity system, where at the top level we have face matching and social vouching to implement uniqueness, and then we add a layer of zero knowledge proofs to allow people to mint new identities for themselves which can share reputation or attestations.