21 ms·
Is “acceptably non-dystopian” self-sovereign identity even possible?
- forum_ghost 4y agoHow can identity be self-sovereign? In the end, it boils down to everyone just asking to see the passport or some other government ID, or a proxy for that (credit card, library card, employee card).
- woodruffw 4y agoThe "web of trust" is the canonical example of "self-sovereign" identity: you publish your identity, others verify it, and (in theory) the "web" propagates through degrees of trust in peers. The big problem there is that it doesn't scale beyond a small handful of people who know each other well and trust each other for a specific purpose. Cryptocurrency companies seem to be aware of this (and of the prominent historical record of failure associated with WoT), which might be why they perform remarkable contortions to avoid that phrase (see "web of verifications" in the article.)
- ggm 4y agoPutting crypto currency to one side, you are aware of the pgp 'strong set'? because six degrees of Kevin Bacon says a handful is a serious underestimate of how good transitive trust can be. The strong set is quite large. That word "transitive" is a very important qualifier here: it's weaker than an absolute statement but hierarchical PKI turns out to be weaker than theory, in practice. Crypto coins are trash. Signatures are not trash. Behaviour of people and systems performing signing including HSM operators are mutable and worrisome.
- woodruffw 4y agoI'm aware of the strong set, but I was under the impression that it didn't accomplish much anymore -- GnuPG disabled SKS lookups a while back, in response to the network's inability to handle thousands of clearly malicious key attestations. The last major topological analysis I can find of the strong set was back in 2015, one year before the first series of spam attacks on SKS. (But don't get me wrong: signatures are great! I'm just skeptical of the WoT, from multiple angles.)
- ggm 4y agoAs usual I'm behind the times. It peaked at 60,000 in 2018 and declined and people stopped believing in it around 2020, some people earlier. My point about scale was a footnote to history, not relevant.
- imwillofficial 4y agoDon’t feel bad, so there so much happening in so many spaces these days. What a time to be alive.
- dane-pgp 4y agoI do think there is some potential in the idea of people proving they are at face-to-face events (signing each others' zero-knowledge tokens) and then timing/placing those events such that someone can't be in two places at once. However, doing graph-based Sybil detection is already a hard problem[0], and trying to create an infallible algorithm that also works using homomorphic encryption is maybe pushing beyond the boundaries of known technology, unfortunately. [0] https://dl.acm.org/doi/10.1145/2492517.2492568 https://dl.acm.org/doi/10.1145/2492517.2492568
- justincormack 4y agoIt would still be easy to have more tokens than people in this setup, you could choose which of your tokens to present, or pass some tokens around. So it is hard to guarantee there is a 1:1 correspondance. Which could be a good thing, but also doesn't work for some of the cases that want 1:1, like giving people a universal basic income where you don't want them to create fake people.
- hinkley 4y agoIt also has the Byzantine problem where if you have enough wealth and your web is covetous enough, they can conspire to trick you into giving away financial information. The birth of brand names was all about attaching enough status to a product line that if you ever broke that trust, that you harm yourself more than you did the customers. CAs are built on that idea. But then so is BP, 3M, and DuPont. So was Hooker Chemical Company (Love Canal), and Montrose Chemical Corp (DDT dumping off California). So I don't know what that really buys you. I do think that trust in certificates needs to be incremental, especially when they change. And perhaps you need a way to ask your savvy friend to take a hard look at some and be able to veto them.
- dboreham 4y agoSelf-sovereign identity boils down to : you control a public key (you have the private key). Everything after that is some variant on : someone with another key can sign a message that means they believe something about your key. This turns out to be pretty much the same as X.509 from 30+ years ago, with the names of things changed and modern encoding schemes used for the messages. In this context, much of what we think of as identity on the internet doesn't need a central authority because all most web sites know about you is that you're the same entity that originally created the account (usually implemented via your email address). But email tends to be favored by users because managing your own keys is problematic. Be very skeptical of anyone who claims to have devised a decentralized sybil-resistant identity scheme.
- Grimburger 4y agoCrypto-currency nonsense aside, the article clearly goes into DIDs which is on its way to becoming a standard. https://www.w3.org/TR/did-core/ https://www.w3.org/TR/did-core/ > Decentralized identifiers (DIDs) are a new type of identifier that enables verifiable, decentralized digital identity. A DID refers to any subject (e.g., a person, organization, thing, data model, abstract entity, etc.) as determined by the controller of the DID. In contrast to typical, federated identifiers, DIDs have been designed so that they may be decoupled from centralized registries, identity providers, and certificate authorities. Specifically, while other parties might be used to help enable the discovery of information related to a DID, the design enables the controller of a DID to prove control over it without requiring permission from any other party. DIDs are URIs that associate a DID subject with a DID document allowing trustable interactions associated with that subject.
- hinkley 4y agoNobody gives a shit if your name is Steve Irving. They care if you're wanted in three extradition-treaty countries or on an Interpol list. Federated identities mean you can have five of them and none of them are counterfeit, which is exactly the opposite of what they want to let you into a country, out of a country, to take out a loan, or to be sitting in a jail cell. There was a time that having multiple identities online was a sensible thing to do, and many in the privacy community wanted this, but now that State actors are fucking with elections, that use case is in serious jeopardy.
- 1over137 4y agoState actors have been fucking with elections since elections existed. Do you perhaps have a recent example in mind from somewhere dear to you? How it is different from countless other cases?
- Grimburger 4y agoDid you respond to the wrong comment? I have no idea what you are trying to say here sorry.
- 4y ago
- wyldfire 4y agoI'm woefully underinformed. But SSI seems like some kind of next-gen adtech. Instead of scaring people about privacy we just convince people "it's safe - you are in control." Meanwhile you can now sell your privacy. I hope someone less cynical can convince me it's a good idea.
- epgui 4y agoTo the author: please define acronyms the first time you use them.
- deleted 4y ago[deleted]
- dmitriid 4y agoThey did. Except for DAO and NFT which you're expected to be familiar with since you're reading an article on cryptocurrencies.
- motohagiography 4y agoThis is a thoughtful treatment of some of the issues. I worked on digital identity in govt, and sovereign identity is considered seriously there. The concepts in the article force the question of what things like security, dystopian, and scalable mean, among others. If I were to articulate the gap in perspectives, it would be that it is between the engineering view of solving problems (e.g. Vitalik's "soul bound tokens") and managing them - that is, to extract value from a dynamic, in the case of existing legacy paper/card identity schemes today. Arguably, in a society, all value is created from risk, where someone takes on the risk of an outcome and someone pays them to hold it while reaping the benefits of whatever thing has exposure to the failure. It's imperfect on purpose, as it allows for flexibilty and non-binary failure modes, and it lets people manage (or extract value) from the shifting risk, where the result is an Economy. When you just solve a problem - let's say we had these perfect soul based tokens, where there was no ambiguity or repudiation for anything, you are depriving people of the very thing we have evolved to be good at, which is judge and collaborate to trade in risks. It's not desirable precisely because instinctually people get they don't want to become solved problems and known quantities. Digital identity is a very nuanced power struggle going on in the background within government and industry, as identity is the substrate to a certain type of economy, and who wouldn't want to be the controller of that? The better case is having ephemeral identities and just price in insurance to transactions, much like interest rates on credit, but less centralized, and with more exposure to volatility of real life - just like other crypto solutions. The people writing about this stuff in the crypto community are still sounding out some things for the first time, but just because they are doing so doesn't mean they are the first to consider them. When I worked on an actual govt digital identity and currency product, I pissed off the execs because I said their design didn't pass "the hookers and blow test," which is that if you can't use the payment and identity scheme for grey market transactions, nobody is going to adopt it. Not because they are vice ridden manaics, but because the human animal knows when it is in captivity and it will find ways to resist it. This is the same reason that central bank digital currencies are going to be an economically inferior good, and create dangerous black markets that produce the dystopian corruption that idealists seem to be trying to avoid, as 1/3 of people just aren't going to trust them. Sure, you can impose the schemes, but if you have ever spent time in an authoritarian regime, you know that the culture is completely debased and anything-goes behind closed doors becase the rules themselves are arbitrary and selectively enforced, because the arbitrariness creates a sense of illigitimacy where there is nothing to trust or believe. The stupidity of technocracies is illigitimate, and it breeds contempt and corruption. This may seem meta compared to the implementation details of some nerdy key management protocol, but I'd argue if you haven't thought these other parts through, crypto really is just some naive kids building a bike shed to fill with shaved yaks and thinking they're reinventing democracy and freedom.
- 100xdang 4y ago
- Animats 4y agoMost of those ideas have been around before. See the classic "Why your idea for stopping spam sucks".[1] It's the same problem as email source addresses. [1] https://craphound.com/spamsolutions.txt https://craphound.com/spamsolutions.txt
- jstnwill 4y agoWhy is the techno-libertarian world so overwhelmingly obsessed with extreme individualism? We are social creatures. We sacrifice individual needs because we gain massive security and social value in return. We need a balance of the various ideologies, and not the extremism of any one ideology. Fifty years of narcissistic, anti-social, "Leave me the hell alone" libertarianism is at the heart of the culture-rot collapse we are facing. We need people on hackernews and Ridgewood elsewhere developing civic and social innovations that deepen our connections, not replacing them with with increasingly inauthentic, algorithmic, trustless, artificial substitutes.
- beebmam 4y agoWhat are the proposed alternatives to individualism? Collectivism? No thanks. I've seen what that does to the human spirit. I'd rather take an extremely individualist culture and then fill in the gaps with taxation and some level of wealth redistribution.
- peoplefromibiza 4y agoIndividualism and collectivism are opposites, not simply alternatives. Alternative to individualism is everything that is not based on individualism alone. For example every social democracy out there the majority of which you can find in Europe. We live in countries where we are individuals with rights but also we have to let go some of that individualism because the good of the many overrides the individual rights. It's not very hard actually.
- pas 4y agothat seems like a straw man argument. building systems that give better control to users online is orthogonal to social goals. not too much knobs on Facebook helped elect Trump, quite the opposite
- etherael 4y agoAre you now or have you ever been an adherent of "Leave me the hell alone" libertarianism? I'm sympathetic to it presently and I have been in the past, but I must admit that I struggle mightily to view any segment of the past 40 years in meatspace as anything approaching a shrine to that philosophy. I'd actually find it much easier to say the exact opposite in fact, and I do believe that what's happening in crypto is in large part a backlash to that. The entire point of it being in crypto of course is that the same people and forces that push back so hard against it in meatspace are relatively powerless to do so in the cyptosphere. For better or worse, I can't see that changing any time soon. I was in a meeting at a very large crypto exchange recently and their branded coffee cups all had a very simple message; "freedom is here". That's basically at the core of everything happening in the space, and I don't think arguing against it is going to work in any way shape or form given the polarised attitude toward the philosophy on either side of the cyptosphere border. Like it or not, it's not going away, and it's swinging more towards extreme individualism by the day, not less.
- Laura69 4y ago[dead]
- TheCowboy 4y agoI feel like the "Anonymity [is] central to the crypto world." ship sailed a long time ago. It was one of the original promises of Bitcoin but it is literally a public database. It's also possible that a society with more transparency regarding financial transactions is the better option long-term, but surrendering the dream of anonymity is a tough one for proponents.
- dropnerd 4y agopseudonymity is a reasonable compromise.
- imwillofficial 4y agoAnd equally as untenable in the crypto world.
- dropnerd 4y agohow so? for example, i operate a pseudonym.
- shapefrog 4y agoFacebook also stores all your data with the index key being a 64 character string. A reasonable compromise, protecting people indeed.
- wincy 4y agoCouldn’t I just buy monero off guys on the dark web?
- coderintherye 4y agoThis is a great write-up for introducing some of these concepts. For those who want to go deeper, highly recommend reading up more on DIDs https://w3c.github.io/did-use-cases/ https://w3c.github.io/did-use-cases/ Verifiable Credentials: https://www.w3.org/TR/vc-data-model/ https://www.w3.org/TR/vc-data-model/ Some people working in the space to follow: https://twitter.com/kimdhamilton https://twitter.com/kimdhamilton https://twitter.com/IdentityWoman https://twitter.com/IdentityWoman https://twitter.com/ChristopherA https://twitter.com/ChristopherA Also highly recommend this paper by Fennie Wang and Primavera De Filippi: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3524367 https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3524367 ( Self-Sovereign Identity in a Globalized World: Credentials-Based Identity Systems as a Driver for Economic Inclusion ) Self-sovereign identity has some great use cases, even if it does not solve Sybil attack problems. Further, being able to establish identity at all is still a major problem in many places in the world and a barrier to financial inclusion.
- lottin 4y ago> being able to establish identity at all is still a major problem in many places Are you sure? Where? And why would the tried and tested methods for establishing identity not work in those places?
- rglullis 4y agoThere is a certain company that may or may not be bought by $43 billion, depending on its ability to determine how many of its users are actual humans.
- teh64 4y agoBut they could easily change that by requiring everyone to submit their government ID. Look at Facebook's Real Name Policy [0], which was already not well received. Determining if the users are actual humans is easy, doing it without any loss of privacy is hard, because at in some part of the trust chain, a person has to provide proof to some trusted organization they are human. [0] https://en.wikipedia.org/wiki/Facebook_real-name_policy_controversy https://en.wikipedia.org/wiki/Facebook_real-name_policy_cont...
- bawolff 4y agoI think this article conflates too many different notions of identity together (which tbf, is because the bitcoin people the article is criticizing do the same thing). Identity is one of those concepts that has a lot of parts to it, and you can do the individual parts sanely, but if you try to do everything all at once, its crazy. As a example, my ssh key is an identity system. It works great in some contexts. Would i want my social insurance number attached to it? Obviously not, that is crazy. That doesn't mean ssh keys are bad.
- arbol 4y agoPersonally, I think it's a good summary of the kinds of identity problems being tackled in the Blockchain space. However, the alarmist tone makes the author seem quite dismissive of interesting technological advances that can be used to securely store data publicly. We are obviously going to be sharing more data in the future and these projects are discovering how this can be achieved. Blanketing the entire movement as dystopian is unhelpful.
- gitfan86 4y agoThe "dismissive" tone is not because we believe that technology advancement is impossible. It is because we have been hearing for over a decade about how crypto is going to deliver massive value "in the future". There is only so much time people will be willing to listen to vague promises of future innovation before they take a look at the actual technology of today and realize that most if not all of it is of little value other than gambling. My advice to anyone that actually wants to make real products or advancements in identity would be to avoid crypto. Build the product on top of a generic store layer. It will be obvious to anyone with software expertise that Blockchain could be interested in that storage layer of the product would benefit from it.
- dmitriid 4y agoMolly White consistently writes concise and precise essays about problems in the crypto space that the crypto "community" consistently fail to address or even respond to in as concise and precise a manner. Well, except "it's too early" and "these articles are wrong and a smear campaign".
- disruptalot 4y agoSpeaking personally, they might be concise and precise but the arguments are nothing new and too often have simple counter arguments. That's the reason they're not addressed, there really is no reason to except to directly address the Molly white audience.
- dmitriid 4y ago> too often have simple counter arguments If only there was anyone to provide those. > That's the reason they're not addressed No, it's not the reason. Because you'd think that after a decade there would be blog posts or articles with coherent explanations of how these problems are tackled. Nope. All we hear is "there are arguments but we won't show them to you just join the discords believe in blockchain so many smart people are working on it".
- forum_ghost 4y agoThere are endless blogs and forums with these arguments chewed out, just a google search away. Molly sounds like someone with an agenda of wilful ignorance due to how easily rebuttals of her arguments can be located, and thus it’s a waste of time to even engage.
- davidgerard 4y agosee, this would have been the perfect moment to link your three favourite slam-dunk examples, which I assume from your comment you have right there to hand.
- dmitriid 4y ago
- georgelyon 4y agoThis is an excellent write-up, and I genuinely hope that the brain-cycles the web3 world is spending on this eventually benefit the rest of society. I’ve been musing about a similar but more simple problem: how can we prove we are an individual human in the context of a web service. Think of this like the ultimate CAPTCHA where not only can you prove you are human but every person can do so at most once or, more pragmatically, O(once). The closest thing we have in society today is Sign in with Apple, where you have a delegated identity provided by a company which has effectively put up a large portion of its brand value as collateral that it won’t be shady, for some definition of the term “be shady”. This is suboptimal for a number of reasons, not least of which is that they can be compelled by a government to divulge this data while (mostly) protecting their brand-value-collateral, and they can be selective in what types of services are allowed to use this system. I’m hopeful some of the non-charlatan web3 folks can come up with some sort of scheme where a trusted entity (a government or a civil rights oriented NGO) can participate in a cryptographic handshake with an end user and a service where at the end the service receives a unique identifier for that user which can not be used to associate that user across services, or divulge to the trusted entity which services a particular individual is using. This wouldn’t fully solve the “can I give this person a loan” problem, but would make many things on the web much better (most bots pretending to be human would become cost prohibitive). I also feel like trustworthiness attestation can be incrementally built on such a system (if such a system is possible).
- meheleventyone 4y agoIn Iceland we already have digital identity from a centralised authority. I log into my bank, health service, sign papers (including loans) and so on with a government managed digital ID. So this isn’t even something that needs invention let alone by web3.
- oblio 4y agoThe tech world will start making more sense when you realize that a large chunk of tech is created because of US hyperindividualism and lack of trust in other people so folks keep trying to create tech solutions for social problems they consider intractable (several of which don't even exist in other developed countries). Purely tech solutions for social problems generally don't work and frequently create more social problems.
- rglullis 4y agoFrom a first read, the following problems I see in this critique: - The trilemmas do not need to be solved. They just need to be acknowledged when you are designing your application so that people can understand the types of trade-offs being made. In cases where sybil-resistance is not a requirement, you can build a system that gives you privacy and decentralization. When sybil-resistance is required, you just need to think if you prefer a system that sacrifices privacy or if it sacrifices decentralization. Depending on the use-case, one might be preferred over the other. - "Security practices are hard, no one will do it properly, they will rather have some expert that can do it for them". Well, if you don't want to deal with security hygiene, you delegate. Just like the majority of people will rightfully prefer to have a bank to manage most of their funds, one could still envision a future where service providers will act as a proxy to anything that requires "your" identity(ies). In general, the thing that upsets me with all of anti-crypto/anti-web3 people is that they fall into the same trap as the maxis: they start from this ridiculous notion that "web3" is about creating a Highlander solution (there can be only one!) and that this solution needs to satisfy all constraints, otherwise it rubbish and needs to be discarded. The important thing by having decentralized identities (and decentralized technology in general) is that it gives new options for whole new classes of applications that do not exist. No one is being forced to adopt a system just because it is now possible to do it on a blockchain, and we do not need to destroy the current systems if they work well - or at least if they work better than any alternative. There will be even plenty of cases where the status quo is totally fine.
- nonrandomstring 4y agoEverything you say is very reasonable until: > No one is being forced to adopt a system just because it is now possible to do it on a blockchain, and we do not need to destroy the current systems if they work well - or at least if they work better than any alternative. There will be even plenty of cases where the status quo is totally fine. which is probably true in reality, but still something I'd like to challenge. Every technology that ends up being totalitarian/expansive starts out with "Nobody is being forced to....". I am sure when automobiles first appeared it seemed obvious that "nobody is being forced to drive them", and yet the other day a poster here was absolutely indignant with me for suggesting it might be possible not to have one. I read hundreds if student essays that literally begin with the line: "Today, life without the internet would be impossible." You're right, many (maybe most) technologies do reach a healthy balance with alternatives and legacy systems. But certain "infrastructural" technologies tend to expand aggressively. I think money systems are among them, at least if the number of times I have heard someone say "cashless society seems inevitable" is any guide. (Though often, when one hears these little maxims repeated verbatim, over and over and over, I come to suspect they are not the authentic views of the speakers, but propaganda injected into public discourse.)
- jad___ 4y ago[dead]
- hGkXBvR 4y agoThere are two interesting aspects of self-sovereign identity that are not worth hand-waiving away as dystopian: - it provides identity tools that use standards that span across geographical and platform boundaries. this is a different form of “user account” than say an online Amazon or NYStateGov account. it is good to have an option on the web for auth and identity that is detached from any single corporate entity or jurisdiction. - unlike most of the world’s current identity systems, many of the SSI systems can and are using novel cryptography, which can combine with privacy and encryption techniques such as hashing, private keys and zk-proofs. so instead of sending photos of your passport and drivers license all over the web, SSI allows you to sign a message on a public ledger, or send a zero knowledge proof that the other end can verify. SSI doesn’t need to replace typical identity and web auth but it could be introduced as another option.
- forum_ghost 4y agoWhat SSI systems exist that are widely adopted and have a user base in at least few million MAUs?
- tatertots1234 4y agoYou could consider Ethereum addresses and ENS aliases to be a limited form of SSI. MetaMask alone suggests it has several million MAUs not that this should be a metric in determining whether a tech is dystopian or not. Various web3 platforms already require verifiable attestations through signing messages with private keys such as multi sig wallets, off chain voting, token gated access.
- davidgerard 4y ago> You could (gong show noises)
- lottin 4y agoWhy would anyone sign a message on a public ledger?
- deleted 4y ago[deleted]
- throwaway0x7E6 4y agoI regret having wasted about 5 minutes reading this before scrolling through the rest some surface knowledge, little to no expertise, further watered down by lots of musings nobody except those familiar with the guy who wrote it would really care to read in full
- strogonoff 4y agoThe problem I have with blockchain enthusiasts, after talking with them about their philosophy, is that they seem to consider trust a bug, and believe that ideal world is achievable with straitjackets of technical solutions that eliminate trust. Trust is a feature, not a bug. If trust is violated by rogue agents, it is because they exist[0], not because trust itself is a folly. However, blockchain-adjacent initiatives seem to suggest a future where we implicitly label[1] every human as motivated to hurt another by making all aspects of their activities subject to verification checks. In addition to strong dystopian vibes, won’t this act of labeling everyone as potential threat actually be instrumental in bringing this motivation to everyone, making it a self-fulfilling prophecy? Aren’t we sort of codifying malicious intent, instead of trying to remove it from the equation? Whom would this serve? There is place for verification in the interim, such as maintaining security of your home, but if we are looking ahead (as blockchain enthusiasts do) we should strive for a future where humans are not motivated to hurt other humans. Not treating it as some sort of default is a good start. [0] Their core motivation to benefit at others’ expense is to me indicative of mental health issues, possibly caused by insecurity and upbringing trauma. [1] https://en.m.wikipedia.org/wiki/Labeling_theory https://en.m.wikipedia.org/wiki/Labeling_theory
- vosper 4y agoYou hit the nail on the head with this comment. And not only is trust a feature, it’s a requirement for society. It’s a deep part of human nature to trust, and trust can’t be removed from how people manage to function in groups.
- gitfan86 4y agoThe problem is scale. If society only had 400 people, the 390 people that were not scammers could remove the 10 people who are scammers from their economic system manually. If you create a online store, one million strangers could connect to it. You need a way to understand who is a scammer in that situation.
- headsoup 4y ago
- dalbasal 4y agoI suspect privacy is the most malleable point on the trilema. You can't compromise on security while still being usable. You can compromise on decentralisation, and everything will work. Your gym, bank and employer already have you in a centralised identity system. Compromising on decentralisation fails the other way. There's no way of holding the centralised body to its side of the compromise. If worldcoin controls identity, they'll control downstream of identity too. For actual solutions, I think it's better to think of specifics applications. Once you get specific, there are often more options. Take DAUS governance. Say you want to implement a voting system that requires identity for sybil resistance. Maybe it's ok if voting requires a limited compromise on privacy. You expose just enough information to demonstrate eligibility, then vote. If privacy is more important that voting, you can maintain privacy instead.
- llegard 4y agoThis is not quite true that "considerations of ethics, user safety, privacy, security, how can this be used for evil, and is this even good for society often come as a belated afterthought". Referencing only recent popular articles in mass media does not paint the whole picture. The very concept of SSI was motivated by ethical concerns: https://www.moxytongue.com/2016/02/self-sovereign-identity.html https://www.moxytongue.com/2016/02/self-sovereign-identity.h... There is a field of academic research on ethics of SSI: [1] https://link.springer.com/article/10.1007/s10676-020-09563-x https://link.springer.com/article/10.1007/s10676-020-09563-x [2] https://www.frontiersin.org/articles/10.3389/fbloc.2020.00015/full https://www.frontiersin.org/articles/10.3389/fbloc.2020.0001... And there is a great deal of awareness regarding these issues in industry https://www.coindesk.com/policy/2021/04/26/self-sovereign-identity-5-years-on/ https://www.coindesk.com/policy/2021/04/26/self-sovereign-id... (yes including core Ethereum developers community).
- MadeThisToReply 4y ago> Jack Dorsey just launched “Web5”, a buzzwordy project focused on decentralized identity Woah, hold on, I thought we were still on "Web3"? Actually I'm not convinced that we've even moved past Web 2.0, since Web3 is still mostly just bullshit, scams, vaporware and monkey jpegs. Did "Web4" get swallowed up by the same beast that made us skip IPv5?
- supert56 4y agoI am convinced that crypto/blockchains are slowly and pointlessly re-encountering the same problems that existing centralised systems and agencies were setup to solve. It’s as if we are all disregarding the centuries of evolution that has gone into creating what we already have today. Systems that, whilst sometimes flawed, for the most part enable us to live our daily lives freely and easily. Systems that already have means of verifying people when you need to make an important transaction and that already allow for trust and stability. As the essay mentions making people the agents of their own verification with documents that you’d have to backup forever would be an absolute nightmare. There is a reason we have centralised systems and there is a reason we can’t escape them.
- talkingtab 4y agoDAO is Decentralized Autonomous Organizations - entities with no central leadership, for those of you like me who didn't know. And where, Oh where, are other good original thinkers, please? I don't care about "agree" or "disagree" I just care about the #$?* thinking.
- pqwEfkvjs 4y agoEU has already solved this problem 10+ years ago using electronic ID cards. You can transfer money, sign contracts etc with these. You have your private key on chip + PINs for 2nd factor auth. Why not build a block-chain on that tech?
- Thiez 4y agoWhat use-case do you have in mind? Because your current suggestion sounds like "$existingThing, but with a blockchain!". What would this blockchain do?
- JohnHaugeland 4y agoSelf-sovereign is such a great admiralty flag phrase No, of course cryptocurrency doesn't give you the powers of a nation state
- jollybean 4y ago'Username and Password' is 'most' of 'sovereign identity'. 'Proof of Personhood' is mostly only going to matter in a legal context, in which there will be some kind of state that recognizes that personhood. Even governments kind of screw that up though. For the later we probably just need a slightly more advanced 'Ministry of Information and Identity'. Like the passport office, but digital. And away you go. This whole 'decentralize everything' is a big of a canard. Useful though experiment, but not much more. Also: "Soulbound token" make me cough up my coffee a little bit.
- ouid 4y agoNo. As long as there is a mechanism for adding new identities to the system, (presumably you want this, because people can be born), people can disguise themselves as new people. This is not trivial to accomplish, but there's no law of nature preventing you from growing a remote control infant should the need arise. It's certainly impractical, but new people are legitimately allowed to enter the system, and there's no way to establish that someone does not know something (in this case knowing something would be the RC baby actually being me, I know how to say goo goo ga ga, and you can't prove I know more than that). That's obviously a silly example, but the point is that soulbinding isn't a cryptographic primitive. There's just no such thing. Not only is non-dystopian identity impossible, No amount of dystopia will change this. Even a totally authenticated system is vulnerable to the "Add a new person that I control" attack. It's not current technology, but it's also not science fiction, and in simple fact, a lesser version of this attack happens all the time. People who have more kids get more representation in government. I don't think that we should totally ignore this effect, but it's certainly useful to mostly ignore it. Anyway, there is no way to establish a sophisticated adversary's unique identity and also allow new identities to be created based on phenomena external to the system.
- survirtual 4y agoTo give an absolute “no” here is presumptive. There are many unique indicators for a human. DNA is unique. At most, there is a small statistical chance of one or two other twins with identical DNA. That could be used to have some level of digital identity binding. If the technology existed to take a neural snapshot, that would be completely unique. And I would argue if anything had the ability to operate at the complexity of a brain, then it deserves representation. If you were to automated the entire system top down for identity validation, there are possible avenues to get a high degree of assurance that someone is uniquely human on a system. Just because it hasn’t been done yet does not me it is impossible. But it is a very hard problem.
- nixpulvis 4y agoHi Molly, great article. I was just thinking about the CAP theorem again a few days ago and the trilemma you describe here, interestingly, feels quite related. As for what I personally consider to be the heart of the problem, I believe proof of personship (or whatever a soul is) is an unsolvable problem in the most rigorous sense. This is one reason why we have government. The issue isn't that government exists, it's that we cannot trust them, nor control them effectively. Still, a local government is much better positioned to prove my identity than some nebulous algorithm. Even the crazy Orb people knew this, and took to physically scanning retinas as you mention. We just need to build trust locally again somehow. Of course, people move and trust must be (re)bootstrapped. This is the root of the heart of the problem if you will; and a problem I cannot see concrete solutions to that don't approximate the existing systems. Here in MA, I have to both pay to get an ID, and provide various information to verify my address and initiate background checks, etc. This is all worth something, no? So why not have local governments provide this verification service...? Well, there's another complicating factor. The higher the value of a secret (i.e. identity proof), the less one should use it, or the more careful one should be with it. If I'm asked to give out my SSN to log into some new video game, I might stop and think twice. Whereas, providing my SSN to apply for a loan from a trustworthy financial institution is pretty commonplace. Finnaly, on data stewardship. Why not have companies like Apple and Google selling HomePods which act as local clouds which store, sync, and replicate encrypted data as requested by the user? Give me a static IPv6 and a decent authenticated tunnel into my LAN and I'm good to go! I choose what files go up to iCloud.com, I choose where 3rd party services point to for authentication credentials, and I decide when I want to delete and invalidate things! Anyway, thanks for the thought provocation. </rant>
- titanomachy 4y agoI agree that government proof-of-identity systems are actually pretty decent, and I think they could offer something really useful by making those services available as cryptographic proofs. In America, using a government-issued proof of identity over the internet amounts to sending someone my SSN, or a picture of my passport or drivers license. Obviously this sucks because they can now convincingly impersonate me on the internet. If they also provided some kind of public-key database, any internet service could verify my identity without learning how to impersonate me. If I lose my private key (or it gets leaked), I can go to the DMV or whatever and have them revoke my old one and issue a new one, just like if I lose my physical license today. EDIT: I know, Estonia/Iceland/whoever already do this. Not an original idea.
- kwatsonafter 4y ago(Disclaimer: I wrote this response before I realized this was a link; I thought it one of those, "Ask HN" questions so I replied in turn. Upon reading the article I think comment still has relevancy.) No. Give up illusions like your rights exist in some vacuous transcendental place outside of other people and society. Read, "Leviathan" by Thomas Hobbes or if you really want to get the, "tarian" washed out of your soul dig into Rousseau's, "the Social Contract." I will state this over and over: "The Divine Right of Individuals" is a myth rooted in how the United States' constitution is worded. God isn't real and he can't give you rights and claiming in a court of law (made up of people) where evidence is of the highest concern, "God gave me rights and I'm a sovereign unto myself do to certain unalienable rights which I cannot obviously or readily demonstrate without making an appeal to hundreds of years of political development" doesn't seem a compelling enough reason for society to release a suspected criminal or the like. Meta: The fundamental fallacy with crypto is that it ignores that the vitality of, "currencies" is quite like the vitality of languages vs their counterparts, dialects-- What makes distincts a dialect from a language? Borders and armies. It's a tough pill to swallow that the world is kind of fundamentally based on violence but once you get past what is sometimes referred to as, "Democratic Peace Theory" and have a sense of history (start with Thucydides) it becomes very hard to take the idea of cryptocurrency seriously. Digital payments have practical value. I think that's about the extent of it. Trustlessness is a character defect and a social mallady and it doesn't surprise me nerds see this as forward movement.
- scrollbar 4y agoI think the discourse you started here becomes even more interesting and defensible if your assertion goes from “God isn’t real” to “God is human created.” It makes the idea of rights clearer as some kind of higher order, purer version of law
- flaque 4y agoMuch of the problem with crypto-skepticism is that basically every problem it raises is true. The argument is effectively boiled down to “here are a bunch of people working on very hard problems. Hard problems are hard, and therefore crypto won’t work”. If you were to replace the word crypto with “computers” or “space travel”, most folks here would push back, saying that “yes these are hard problems, but there’s a lot of people working on it, and there’s lots of different solutions in many different directions.” And that would be a perfectly reasonable counter. Most pro-crypto and anti-crypto have attached their identity to liking or dislike crypto. If you disagree, ask yourself if, upon meeting someone who likes crypto, your brain naturally likes or dislikes the person. If you see someone talk about crypto in a positive light on the internet, do you instinctively upvote or downvote them? This identity makes it very hard to make rational predictions about crypto. It’s too easy to weigh the same evidence in favor of crypto if you like crypto, or against crypto if you don’t like crypto. Since most folks on HN dislike crypto, you may want to ask “what evidence would cause me to think crypto would work? What evidence would cause me to think it was good? Say crypto worked in 20 years, what would now like?” If, when you’re attempting to answer those questions, your brain instead starts to answer the opposite questions (ex: “here is why crypto can’t possibly work”), then you know you’ve been trapped by the soldier mindset, and are not thinking rationally. If your mind draws a blank or thinks “there is no evidence that crypto will work”, then either you are living in a bubble, your brain refuses to see information counter to your prior, or you have to figure out what makes you more able to understand the situation.
- titanomachy 4y agoMost of the crypto-enthusiasts I’ve met in the real world seem to be motivated more by narrow-minded self-enrichment rather than a genuine belief that society can be reshaped to serve humanity better. The more ideological ones seem to be driven by an arsonist’s enthusiasm for destroying and subverting existing systems rather than an architect’s enthusiasm for building something better. I can appreciate the potential of the technology, but that doesn’t mean I embrace the community.
- flaque 4y ago> I can appreciate the potential of the technology, but that doesn’t mean I embrace the community. That seems fine, and is basically the opinion I hold. The intellectually challenging thing about crypto is that it is very easy to go from “I don’t like these people” to “these people’s predictions are wrong”. Hacker news seems so caught up in disliking a subset crypto people, that they assume that not only are they “bad people”, but they’re wrong.
- ChainOfFools 4y agoShort answer: No. The desire to be "identified" incorporates the desire to be identified as "Self sovereign," which is an appeal that only other people can fulfill. Your identity is sovereign thus depends on their collaboration in constructing and maintaining a space where such an identity is even possible. You cannot be self sovereign because the mandate to make that identification is not entirely reserved to yourself. Unless of course you impose it on others by force, in which case you're no longer self sovereign but sovereign, period.
- bsedlm 4y agoThis seems to trying to pin down the "problem of identity" (how to ensure people maintain a stable identity over a digital realm) I think it's important to be clear about why this is important, depending on the use case (votes, currency, etc) there may be a different reasons why it's important that one identity follows one person. In the case of currency, the reason behind needing stable identity has to do with double spending. But I have a toy scenario that I like to play around with, consider a cryptocurrency such that anybody can emit tokens (credits) however they deem appropriate, in this case the necessity of a stable identity is clear, the person needs to be able to answer for their emited tokens. If people can just shed the token-emitting-identity, then they cannot be held accountable (forced to answer) for their emitted tokens and the entire construction is useless. However, for the case of votes and other group-concensus schemes, the scenarios are sufficiently different that I'm not sure if it'e even worthwhile to try to come up with ONE answer to the identity "problem"
- theptip 4y agoI find it fascinating to watch as the crypto community gradually recapitulates the evolution of the existing financial regulation/structure. In this case, negative attestations are reimplementing liens / UCC filings (for business loans) and credit reports (for individuals). But without any plausible consumer rights recourse, of course. (Like for example your right to have errors on your credit report fixed.) It will be interesting to see if they can use zk-SNARKs to come up with a scheme that’s substantially better here. Another corollary of this observation is that crypto will recapitulate the evolution of privacy legislation too. As the OP notes these systems are going to struggle to comply with deletion requests under GDPR. And while many would buy the premise that financial regulations are not helpful to the public (I don’t personally buy that), I think privacy legislation is much more popular and clearly a case of hard-won consumer protection.