9 ms·
Getting started with decentralized identity
- otikik 4y agoThanks, I hate it. Web2 is not perfect but all the complexity brought by web>2 is just not worth the bits it’s written in. Make something simple and easy to use and understand, dammit. I don’t want my mum to call me because her identity provider for Instagram is down.
- Comevius 4y agoThe digital identity infrastructure space is already crowded, with players like Apple, Google and Microsoft working with governments and institutions, because they own the devices we use, and the entire point is that people will be able to use their phones to identify themselves everywhere. Apple ID is already like 90% there, despite having to trust Apple with your personal data, which nobody has a problem with. The Web3 approach of having to trust nobody is not really practical to begin with. Blockchains are slow and expensive. Worst yet it's still up to you to verify the client and whether it's connected to the authoritative version of the blockchain, since blockchains can be replaced by a fork. At that point you might as well trust Apple.
- ngould 4y agoDefinitely possible that Apple will win the identity wars. That said, I don't agree with the characterization of web3/web5 as "having to trust nobody". If anything, all the efforts around identity are meant to allow for bringing IRL notions of trust onto the internet. In other words, the whole pseudonymity thing is not a result of using blockchain, but just the fact that nobody's bothered to add identity verification to a lot of stuff happening in web3. That's changing though.
- bawolff 4y agoSheesh, "web5"? I guess we blew right past web4. Normally i try to avoid low quality complaint comments like the one i am making, but blockchain naming is frustrating.
- rektide 4y ago> The Web3 approach of having to trust nobody is not really practical to begin with. Blockchains are slow and expensive. I generally agree, for almost all uses blockchains are pretty bad. But it has, so far, been an eventually consistent global write-only data store where reads have 100% uptime. I don't want a service layer on blockchain, don't want to be using the blockchain to transact, but if there's some small modicum of write-once globally-read-many datum (such as oh say, a cryptographic token I can use to sign things to prove my identity) where blockchain actually seems like a good match. The slow and expensive isn't a problem, if all I'm doing is proving an identity I made a long time ago. I'm not super worried about people verifying me using a bad blockchain. These systems should be self-verifying & diverging for too long should trip systems.
- whatisweb3 4y agoIn the long term I hope Apple does not win. The idea that we should just submit the world’s private data to Apple for the next century is… terrible. Zero knowledge proofs are one of the more promising things starting to emerge from crypto and decentralized blockchain space. If desired, you can still trust Apple for the ZK proof generation and verification without having to store any private details on their servers.
- Comevius 4y agoPractical ZK is coming from cryptography, like this decentralized gun registry by the Brown University. https://eprint.iacr.org/2021/107.pdf https://eprint.iacr.org/2021/107.pdf People in the crypto space are coming from a different angle, they are franctically trying to find a legitimate use for cryptocurrencies, so far unsuccessfully, by constantly rebranding blockchain technologies without being able to address the challenges. It's not that we desire to trust Apple, it's that they get things done. They have actual solutions that work, not just empty promises aimed at greater fools. People in the crypto space never deliver.
- whatisweb3 4y agoI don’t see any reference to zero knowledge proof in there. Look into modern research around succinct and generalized ZK proofs. SNARKs, STARKs, PLONK, zkVMs, MPC and secure setup ceremonies. All of this is coming from blockchain and crypto space and will transform some ways we manage privacy in the future. It does not need to be used with a blockchain but pairs well as the choices of arithmetic are often optimized to EVM. “Apple is faster at delivering than a decentralized group of developers and researchers creating novel cryptographic protocols and open source software” - well, no shit.
- baxtr 4y ago> Blockchains are slow and expensive. Yeah. In every other situation, people try to improve the speed and efficiency of software. In this case, it’s like people prefer to do bubble sort even if there is quick sort available. And then sell it as the best thing ever invented.
- Animats 4y agoAs I said 48 days ago when this last came up on YC, the classic "Why your idea for stopping spam sucks" list applies.[1] Go re-read that and you'll see the same identity problems and proposed solutions. If people can create and abandon identities cheaply. they will use those identities for annoyance or fraud. Hence spam, robocalls, etc. This is also why the "federated" social networks are not too useful. On the other hand, publicly visible identities that are very strongly tied to a person or physical place lead to strong tracking and the abuses associated with that. So, explain how "Web5" avoids those problems. [1] https://craphound.com/spamsolutions.txt https://craphound.com/spamsolutions.txt
- ThalesX 4y agoWould having all data produced by a DID being verifiable mean that I could stop any nugget of information coming out of that producer from reaching me just by a simple computation?
- conradev 4y ago> The process of binding a DID to something in the physical world, such as a person or an organization — for example, by using verifiable credentials with the same subject as that DID — is contemplated by this specification and further defined in the Verifiable Credentials Data Model [VC-DATA-MODEL]. https://www.w3.org/TR/did-core/#proving-control-and-binding https://www.w3.org/TR/did-core/#proving-control-and-binding Here is the diagram: https://www.w3.org/TR/vc-data-model/#lifecycle-details https://www.w3.org/TR/vc-data-model/#lifecycle-details The idea there is that identity providers and other authorities (governments, credit agencies, etc) issue credentials after the person authenticates with them. This isn't much different than how it works today with, for example, a cookie on the Experian website, but the idea is that I can now take this cookie, show it to a third party and the third party can verify the credential's validity.
- rektide 4y agoWow now it sounds awful for other reasons. Still pie-in-the-sky, but I still think we've been low ambition & not had good decentralized-identity-preconditions to begin exploring web-of-trust models. Past behavior is a huge indicator, one we can judge, & which many others will have judged. Trying to filter those other judges, decide what trust anchors we have & what biases to give, is a place where humanity would have a lot of freedom to tweak & explore, if we had these modest adequate technical underpinnings to begin to explore from. But we just lost a decade to blockchain mania & consensus computing, rather than exploring anything actually genuinely distributed & decentralized & non-consensus. Also worth admitting AI just got good enough to convincingly fake being an online person fairly well, which can potentially massively outperform any attempt at moderation & seeking truth/genuineness that humans might ever make; said explicitly, bad/business-motivated actor's ability to fuck up anything but an ultra-conservative/paranoid web-of-trust has gone up orders of magnitudes in the past couple years.
- smeej 4y agoI like the idea that at least in web5, the term "wallet" might actually make sense, because the credentials or whatever actually "live" on your own device/node. Web3 should really use "signet" rather than "wallet." Web3 is all about signing, attestation, and authentication through digital signatures. That's what signets are for, not wallets. Coinkite recently switched to the term "signing device," but 1) that's lame, and 2) "signet" already exists and means the same thing. At least with web5, the wallet analogy works.
- ngould 4y agoBingo! =)
- smoyer 4y agoTwo weeks ago I was part of a small group that met at IPFS Thing in Iceland. One very promising specification missing from this article is UCAN (from Fission) which provides a set of custom claims that can be added to a JWT to allow delegation of privileges in a decentralized environment. Definitely worth a look!
- skeyo 4y agoWhat happened to web4
- pizzathyme 4y agoObvious gap in the market for a promising startup to own
- 3np 4y agoI hear it's part of Winamp 4 for Windows 9.
- stavros 4y agoFollows the Winamp naming of web2 + web3 = web5.
- Confiks 4y agoThe article completely misses the mark in creating some weird narrative about 'web3 turning into web5', all seemingly based on a wordplay announcement by Dorsey, thereby giving that project a lot of undue credibility. In reality, many of the good projects and people referenced at the end of the article have been working for years without any notion that their projects are sprung out of some hyped but underspecified 'web3' technology. Dorsey's 'web5' clamor is mostly about (barely [1]) implementing some existing technology and then writing a bit of slideware around it [2], which proposes to magically "allow individuals, organizations, and companies to publish credentials anyone can discover and independently verify" while not spending any thought on how such a PKI would be ("independently") governed without centralizing everything back again – an all too common failure mode of 'web3' [3]. Meanwhile, both Dorsey's slideware [4] and the actual specifications referenced [5][6] make bad technological choices with regard to privacy where users have stable identifiers (their public keys) which must be published, allowing them to be easily tracked across transactions. While this can be used as a building block, no material on the 'web5' website or the TBD54566975 Github repository (I guess it's some other wordplay) indicates that they even recognize this as a problem, let alone that they propose how to solve it. This is no new problem however: Sovrin – which many people referenced in the OP have worked on or with – has published a commentary on this back in 2018 [7]. There's also a great talk by Christopher Allen if you need to refresh your memory about what you need to consider when designing identity systems [8]. Otherwise the OP can be a great introduction to identity, but please don't feed the magical hypetrain. [1] https://github.com/TBD54566975/ssi-service#whats-supported https://github.com/TBD54566975/ssi-service#whats-supported [2] https://developer.tbd.website/docs/Decentralized%20Web%20Platform%20-%20Public.pdf https://developer.tbd.website/docs/Decentralized%20Web%20Pla... [3] https://moxie.org/2022/01/07/web3-first-impressions.html https://moxie.org/2022/01/07/web3-first-impressions.html [4] See the diagram on page 9 of [2] [5] https://identity.foundation/decentralized-web-node/spec/ https://identity.foundation/decentralized-web-node/spec/ [6] https://identity.foundation/ion/ https://identity.foundation/ion/ [7] https://sovrin.org/wp-content/uploads/2018/10/What-Goes-On-The-Ledger.pdf https://sovrin.org/wp-content/uploads/2018/10/What-Goes-On-T... [8] https://www.youtube.com/watch?v=JzM_Brpk95E&t=1574s https://www.youtube.com/watch?v=JzM_Brpk95E&t=1574s
- ngould 4y ago
- bawolff 4y agoAre blockchain people physically incapable of speaking plainly? Its hard to cut theough the buzzword bullshit, but this sounds like they reinvented PKI and added 10 billion layers of indirection. Is there more to it than that? Or is this really just taking the latest technogies of the 1990s, and explaining it badly so people think they have invented something new?
- Galanwe 4y ago> Are blockchain people physically incapable of speaking plainly? While I agree that blockchain technologies can quickly fall in bullshit buzzwords, there is still food for thoughts here, but you have to be somewhat familiar with the subject to understand it. Let me try to explain it from software engineer to software engineer. The core of web 5 is "self sovereign identity" . That means you (the user) gets to be in control of authentication, identification, and user data access and lifecycle. Take a typical web 2.0 worflow: - You sign up on a website / app by providing mail, password, and some other user data like address, phone, etc. - The website / app stores your information + their own metadata (admin flag, purchase history, whatever) in their database somehow. - When you log in, you are given a JWT which basically is just a subset of the data you provided + the website metadata, along with a signature to ensure you're not forging all that. - The website / app have you perform API calls providing the JWT. The whole idea of self sovereign identity is that you don't need the website / app to own any of your data and metadata in the first place. If your data is stored in a place _you_ control, and where _you_ can delegate read access to them, as well as the capability for them to enhance it with their metadata that they can sign, then you can pretty much get rid of them storing anything at all about you. This place where you store your data is a blockchain dedicated for that purpose. You can have all your information stored there, encrypted, and just encrypt for their public key what you are willing to share with them. If you don't want them to know you anymore, just remove the version of your data encrypted for them. If they need to store additional metadata on you (say an "is_admin" flag), have them store it in your wallet and sign it. You can pretty much see it as a blockchain of persistent JWT claims that you control. These claims would be accessed through a browser plug-in a-la-metamask. The overall idea is that by switching to this model, websites / apps will become 99% front-end only, APIs will switch to smart contracts, and you will have total control of your data. Hope that clarifies a bit the jargon of the article.
- pabe 4y agoDIDs recently became a web2 standard [1] that's also embraced in web3 e.g. by Cardano / Atala Prism [2]. [1] https://www.w3.org/TR/did-core/ https://www.w3.org/TR/did-core/ [2] https://atalaprism.io/ https://atalaprism.io/
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- geonnave 4y agoFor the "Learning resources" section, I would also recommend checking ION¹. I have tested a few DID Methods including Sovrin, Veres One, and ION, and the latter is the most spec-adherent and well-implemented, apart from receiving funding from companies like Microsoft and TBD (which is proposing web5 in the first place). And yes, it is the only DID Method to receive support from big tech (was incubated within Microsoft, then donated to the Decentralized Identity Foundation), and it also happens to be a technically better solution. Why I think it is better: (1) don't need a new blockchain (re-uses Bitcoin's); and (2) implements DIDs / DID Documents with all needed features (e.g. last time I tried, Sovrin's implementation did not support serviceEndpoints!) ¹ https://identity.foundation/ion/ https://identity.foundation/ion/ ² https://www.coindesk.com/markets/2021/03/25/microsofts-ion-digital-id-network-is-live-on-bitcoin/ https://www.coindesk.com/markets/2021/03/25/microsofts-ion-d...
- Confiks 4y agoION makes bad choices that are disastrous for user privacy. They don't even acknowledge these problems, let alone propose a solution for them. See: https://news.ycombinator.com/item?id=32283529 https://news.ycombinator.com/item?id=32283529
- jeroenhd 4y agoBlockchain. It's always blockchain. Can we just not? How about we go back to web 1.0. TLS mutual cert auth with an ID card as a smart card, either from the government or from your favourite third party. Or maybe we go back to web 2.0 with OpenID. Users pick their own identity providers and websites can pick which ones to trust and which ones not to trust. Actually, we already have that, and it's "sign in with Google/Facebook/Apple". If you're a fan of stuffing Javascript everywhere you can, just use FIDO2/WebAuthn before or after validating the user through OAuth. Solutions exist. Nobody wants to implement them, it seems. Inventing new ways to do what has been done before doesn't solve the problem, it just creates more dead protocols.
- ahelwer 4y agoWell, one of the few plausibly-valuable additions to the world offered by blockchains are globally-distributed databases not owned/controlled/bound to any single organization. Why not make use of them for something other than scams, pump & dumps, etc.?
- jeroenhd 4y agoBlockchains are expensive in terms of money and energy consumption. I'm not paying $10-$30 to store data on the ethereum blockchain every time I need to add some kind of datum (assuming the ethereum blockchain). That price will only go up once such a system actually becomes used by many parties, making the system even more expensive. I'm already overpaying for getting the government to do stuff for me. I don't want to overpay some random servers all over the world instead of my government, that's just moving (and duplicating) the problem.
- bawolff 4y agoBecause the times where a globally distributed non-controllable database is actually useful to solve problems is fairly limited. Blockchain people are the epitome of the "when all you have is a hammer everything looks like a nail" proverb.
- Spooky23 4y agoBlockchain has value here, essentially acting as a distributed collection of digital signatures. If I need to prove my date of birth, why not present a credential, signed by the vital records agency of where I was born to prove it without any data broker in the middle?