5 ms·
How can identity be self-sovereign? In the end, it boils down to everyone just asking to see the passport or some other government ID, or a proxy for that (cre
by forum_ghost 4y ago
How can identity be self-sovereign?
In the end, it boils down to everyone just asking to see the passport or some other government ID, or a proxy for that (credit card, library card, employee card).
- woodruffw 4y agoThe "web of trust" is the canonical example of "self-sovereign" identity: you publish your identity, others verify it, and (in theory) the "web" propagates through degrees of trust in peers. The big problem there is that it doesn't scale beyond a small handful of people who know each other well and trust each other for a specific purpose. Cryptocurrency companies seem to be aware of this (and of the prominent historical record of failure associated with WoT), which might be why they perform remarkable contortions to avoid that phrase (see "web of verifications" in the article.)
- ggm 4y agoPutting crypto currency to one side, you are aware of the pgp 'strong set'? because six degrees of Kevin Bacon says a handful is a serious underestimate of how good transitive trust can be. The strong set is quite large. That word "transitive" is a very important qualifier here: it's weaker than an absolute statement but hierarchical PKI turns out to be weaker than theory, in practice. Crypto coins are trash. Signatures are not trash. Behaviour of people and systems performing signing including HSM operators are mutable and worrisome.
- woodruffw 4y agoI'm aware of the strong set, but I was under the impression that it didn't accomplish much anymore -- GnuPG disabled SKS lookups a while back, in response to the network's inability to handle thousands of clearly malicious key attestations. The last major topological analysis I can find of the strong set was back in 2015, one year before the first series of spam attacks on SKS. (But don't get me wrong: signatures are great! I'm just skeptical of the WoT, from multiple angles.)
- ggm 4y agoAs usual I'm behind the times. It peaked at 60,000 in 2018 and declined and people stopped believing in it around 2020, some people earlier. My point about scale was a footnote to history, not relevant.
- imwillofficial 4y agoDon’t feel bad, so there so much happening in so many spaces these days. What a time to be alive.
- dane-pgp 4y agoI do think there is some potential in the idea of people proving they are at face-to-face events (signing each others' zero-knowledge tokens) and then timing/placing those events such that someone can't be in two places at once. However, doing graph-based Sybil detection is already a hard problem[0], and trying to create an infallible algorithm that also works using homomorphic encryption is maybe pushing beyond the boundaries of known technology, unfortunately. [0] https://dl.acm.org/doi/10.1145/2492517.2492568 https://dl.acm.org/doi/10.1145/2492517.2492568
- justincormack 4y agoIt would still be easy to have more tokens than people in this setup, you could choose which of your tokens to present, or pass some tokens around. So it is hard to guarantee there is a 1:1 correspondance. Which could be a good thing, but also doesn't work for some of the cases that want 1:1, like giving people a universal basic income where you don't want them to create fake people.
- hinkley 4y agoIt also has the Byzantine problem where if you have enough wealth and your web is covetous enough, they can conspire to trick you into giving away financial information. The birth of brand names was all about attaching enough status to a product line that if you ever broke that trust, that you harm yourself more than you did the customers. CAs are built on that idea. But then so is BP, 3M, and DuPont. So was Hooker Chemical Company (Love Canal), and Montrose Chemical Corp (DDT dumping off California). So I don't know what that really buys you. I do think that trust in certificates needs to be incremental, especially when they change. And perhaps you need a way to ask your savvy friend to take a hard look at some and be able to veto them.
- dboreham 4y agoSelf-sovereign identity boils down to : you control a public key (you have the private key). Everything after that is some variant on : someone with another key can sign a message that means they believe something about your key. This turns out to be pretty much the same as X.509 from 30+ years ago, with the names of things changed and modern encoding schemes used for the messages. In this context, much of what we think of as identity on the internet doesn't need a central authority because all most web sites know about you is that you're the same entity that originally created the account (usually implemented via your email address). But email tends to be favored by users because managing your own keys is problematic. Be very skeptical of anyone who claims to have devised a decentralized sybil-resistant identity scheme.
- Grimburger 4y agoCrypto-currency nonsense aside, the article clearly goes into DIDs which is on its way to becoming a standard. https://www.w3.org/TR/did-core/ https://www.w3.org/TR/did-core/ > Decentralized identifiers (DIDs) are a new type of identifier that enables verifiable, decentralized digital identity. A DID refers to any subject (e.g., a person, organization, thing, data model, abstract entity, etc.) as determined by the controller of the DID. In contrast to typical, federated identifiers, DIDs have been designed so that they may be decoupled from centralized registries, identity providers, and certificate authorities. Specifically, while other parties might be used to help enable the discovery of information related to a DID, the design enables the controller of a DID to prove control over it without requiring permission from any other party. DIDs are URIs that associate a DID subject with a DID document allowing trustable interactions associated with that subject.
- hinkley 4y agoNobody gives a shit if your name is Steve Irving. They care if you're wanted in three extradition-treaty countries or on an Interpol list. Federated identities mean you can have five of them and none of them are counterfeit, which is exactly the opposite of what they want to let you into a country, out of a country, to take out a loan, or to be sitting in a jail cell. There was a time that having multiple identities online was a sensible thing to do, and many in the privacy community wanted this, but now that State actors are fucking with elections, that use case is in serious jeopardy.
- 1over137 4y agoState actors have been fucking with elections since elections existed. Do you perhaps have a recent example in mind from somewhere dear to you? How it is different from countless other cases?
- Grimburger 4y agoDid you respond to the wrong comment? I have no idea what you are trying to say here sorry.
- 4y ago
- wyldfire 4y agoI'm woefully underinformed. But SSI seems like some kind of next-gen adtech. Instead of scaring people about privacy we just convince people "it's safe - you are in control." Meanwhile you can now sell your privacy. I hope someone less cynical can convince me it's a good idea.