6 ms·
Show HN: Hellō, a cooperative approach for online identity
We are looking for feedback on a novel way to build and run a service for you to manage and share your identity.
Demo: https://greenfielddemo.com https://greenfielddemo.com
- dickhardt 4y agoHi HN! I’m Dick Hardt[1]. Over the last twenty years, I’ve led the design of identity standards (OAuth 2.0, JWT) and systems that you and billions of others use every day.[2] You know that these systems don’t always work in your favor. Each is bespoke and most, if not all, of your identity is locked up in these silos. I called this out in my Identity 2.0 OSCON talk in 2005 where I popularized a user-centric identity vision.[3] Unfortunately, we have failed to realize the vision of user-centric identity: of giving you control of your identity. We have far too many passwords. Identity theft is rampant. Online interactions are either tedious or risky. In short, internet identity is a disaster today. Most proposals today to give you control of your identity require you, your applications, and the issuers of claims about you (such as your bank or government), to adopt a new technology - a three-sided cold start problem. I founded Hellō to take a different approach -- an abstraction layer that lets you use the technology and identity you already have -- that’s operated by a not-for-profit co-operative. The Hellō journey did not start with building a product -- it started with exploring how to resolve the risks of a central service, and finding organizations aligned on the vision. Once three industry-leading organizations joined as founding corporate members of the co-operative, we built and tested our PoC, our MVP, and then our developer console. Hellō is available for you to use today. We have a demo at https://greenfielddemo.com https://greenfielddemo.com. Several apps use Hellō today, and many are exploring adoption. If you are building a new app, you can tick off most of your identity tasks in a few hours if you use Hellō. Details at https://hello.dev https://hello.dev We’d love feedback on your experience. In contrast to other identity service offerings, Hellō does not help the developer manage and store user data -- Hellō helps the user manage their data and share it with the developer. The Hellō business model is to charge (in the future) an interchange fee of a few pennies for each new verified claim the user releases to the application. There is no MAU fee. No fee for authentication. No fee for users. No fee for issuers. We expect you have more questions. https://www.hello.coop/pages/approach.html https://www.hello.coop/pages/approach.html describes: - Our approach - How the cooperative works - How we’ll fund Hellō with smart contracts - Our guiding tenets - How we protect people’s privacy - Our architecture Thanks for reading and trying! Please share your questions, impressions, criticisms, and requests! Want a more personal interaction? I am hosting an AMA on Twitter Space later today (Wed Oct 12) from 4-5PM PT. https://twitter.com/i/spaces/1LyxBqvnmAyJN https://twitter.com/i/spaces/1LyxBqvnmAyJN You can also email me dick.hardt@hello.coop [1] https://www.linkedin.com/in/dickhardt/ https://www.linkedin.com/in/dickhardt/ https://en.wikipedia.org/wiki/Dick_Hardt https://en.wikipedia.org/wiki/Dick_Hardt https://twitter.com/DickHardt https://twitter.com/DickHardt [2] https://datatracker.ietf.org/doc/html/rfc6749 https://datatracker.ietf.org/doc/html/rfc6749, https://datatracker.ietf.org/doc/html/rfc6750 https://datatracker.ietf.org/doc/html/rfc6750, https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/ https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/ [3] https://www.youtube.com/watch?v=RrpajcAgR1E https://www.youtube.com/watch?v=RrpajcAgR1E
- e-clinton 4y agoCongrats on the name, I mean, the launch! :)
- dickhardt 4y agoMy name? It is special. =)
- ascorbic 4y agoCan you support GitHub as aprovider? It seems to be the de-facto standard for dev tool services, and is the only one I regularly use.
- dickhardt 4y agoYes. GitHub, GitLab, and Discord are on our roadmap. Twitter is also -- but more as a way to claim a Twitter handle. We did not do GitHub and Discord at first as they are OAuth only -- no OpenID Connect support. Thanks for letting us know what you would like!
- trog 4y ago> - How we’ll fund Hellō with smart contracts extremely hard for me to get excited about something that has blockchain in it these days
- dickhardt 4y agoThe blockchain aspect is not supposed to get you excited. :) As a co-operative we don't have equity to sell for financing. Tokens enable us to separate ROI from governance, and many investors are willing to invest in tokens. As a developer or user, the blockchain aspect is hopefully irrelevant.
- dane-pgp 4y ago> Hellō provides a fully-featured OpenID Connect interface Why not just use self-issued OpenID identities then? Well, I guess the reason is that the standard[0] hasn't even been finalised yet, and there are no implementations (as far as I know), but it seems like some combination of that plus Verifiable Claims is the correct way to provide decentralised identities. [0] https://openid.net/specs/openid-connect-self-issued-v2-1_0.html https://openid.net/specs/openid-connect-self-issued-v2-1_0.h...
- dickhardt 4y agoSIOP has been around for a long time without any adoption. A critical technical challenge is getting the operating systems to support managing the app that responds to the 'openid:' scheme. On iOS, the last app installed gets the call, which is not what you want for your identity wallet. I gave a talk on the need to be pragmatic to get adoption: https://www.kuppingercole.com/watch/eic2021-hardt-dogmatism-pragmatism https://www.kuppingercole.com/watch/eic2021-hardt-dogmatism-...
- dane-pgp 4y agoThanks for the reply. I hadn't realised that SIOP has been around for a long time, but I'm pleased that Microsoft and others still seem to be working on it (the most recent draft was published last month). That's an interesting point about the 'openid:' scheme. Are you worried about someone having a use case where they want two separate wallet apps installed at the same time on their phone (rather than one app that can support multiple identities)? Or is the concern more that someone might install a (seemingly unrelated) second app which surreptitiously hijacks the scheme and spoofs the interface of the existing app, to trick people into... revealing which sites they have accounts on? (The second app wouldn't be able to steal the keys from the first one, right?) Anyway, it's good that multiple approaches are being attempted to solve the vital problem of decentralised identity, and I look forward to seeing how much adoption Hellō gets.
- dickhardt 4y agoThe second point is more concerning. A related point is that it only works if the user already has a wallet installed that is listening on "openid:". "mailto:" and "tel:" work on a phone since there is an email and phone app on all phones by default. This is a classic chicken and egg problem. Why would a developer use "openid:" if there are few, if any users, and why would a user install a wallet for "openid:" if there are no apps. Thanks for your encouragement! ... would love any other feedback you have. We believe Hellō is SSI (Self Sovereign Identity) -- decentralized approaches are one way to approach -- a distributed centralized approach like Hellō is another way that is more pragmatic.
- derekzhouzhen 4y agoThis looks like a wrapper around several popular social login. While it is convenient, I fail to see how it is decentralized. If anything, it just add another single point of failure, so it is more centralized? As a SaaS vendor, I likely already support several social logins and email verification. Why should I switch? If I have not implemented the social logins, I can see the convenient factor. However, social login is not that hard to implement, and if you did for one vendor, it is just mechanic to do the same to other vendors. Users are your most valuable asset so I consider it time well spent.
- dickhardt 4y agoThanks for the questions! Hellō is not decentralized -- apologies for any confusion -- did I mistakenly write that somewhere? The governance is decentralized. Yes, it is another point of failure, as is any other service you build your app on. I have extensive experience with tier zero services such as AWS IAM and have applied those learnings to the Hellō deployment if that is any consolation. The value proposition of Hellō is not as great for you as you have already made a substantial investment in your identity implementation. In the future when Hellō has a larger claims selection than verified email, phone and ethereum address -- you may find it valuable to use Hellō to request claims from your users. Additionally, depending on your application, you may want to make claims about your users that they can share with other sites. Empowering users to control their identity and share it is our mission. Claims can range from VIP cards to memberships to reputation scores. Fully agree that social login is not hard to implement. (I'll take that as a compliment as one of the designers!) As you add additional providers so that you provider more choice to your users, the risk of a user fragmenting their identity by choosing a different provider when they return increases. Dealing with fragmented identities in your app is hard. Additionally, registering and configuring your app at Apple / Facebook / Google etc. is non-trivial. I know what I am doing in theory, and I have already invested a week of time in configuration and approvals and updates.
- danpalmer 4y ago> Additionally, registering and configuring your app at Apple / Facebook / Google etc. is non-trivial. I know what I am doing in theory, and I have already invested a week of time in configuration and approvals and updates. I don't feel like it's worth giving up control over your user's authentication to an intermediary in return for saving a week of work. Maybe the case could be made for day-1 of a startup, but certainly not year-1, it's just too critical a component. I'd also challenge this taking a week. Apple/FB/Google sign-on is pretty straightforward, and I've found the cost is mostly in setting up an open-source auth library in my webapps rather than enabling a given service provider.
- motohagiography 4y agoWhat I'm interpreting the value of this to me would be is that I can bootstrap user enrollment by getting them to login to my application with a social identity they assert via hello.coop, and then I can add layers of additional identity assurance on top of that login if my application requires it. As a developer/architect, I would have a user enrollment waiting room role in my application/service where certain features would be available to hello.coop asserted identities, and then more features would become available as I got the necessary identity assurance/KYC from them. It removes the need for me to do password management and account recovery, because that's on the user to manage via their social identities. As a user, I presume if I want access to a service, I just pick the IDP of my choice to use for a given service. (imo, protonmail needs to provide an oauth2 identity service as well) The resilliance of this could be provided by linking social identities on a blockchain, so if any one or two IDPs decide they're going to cut hello.coop off, the users can still use their hello.coop identity that was linked to their other social logins, and just not the IDP who defected. Is this an accurate interpretation?
- dickhardt 4y agoThanks for the comments and describing your interpretation -- which is correct -- clarifications follow: We not only support social login, but also crypto wallets that support browser extensions or Wallet Connect. The user can also just use email or phone. We will be adding support for Passkey once the implementations have sorted out some details. Yes, you can bootstrap enrollment with Hellō and then prompt the user for additional profile / identity assurance. We are working on supporting KYC claims as well so that you could request them and then Hellō would interact with the user on how best to gather those from the user if we don't already have them. IE we would be an abstraction layer for KYC similar to being an abstraction for login and profile registration. As a user, you pick your "IdP" for your Hellō wallet, and use that IdP for all apps that support Hellō until you want to change your preferred provider. In the future, the user does KYC once with us and then has a reusable identity. wrt. resilience -- we encourage users to setup two or more backup providers so they can recover their Hellō Wallet if they lose access to their preferred provider. Recovery requires logging in with two backup providers, and then they can change their preferred provider.
- nathias 4y agoI like this direction, I think for web3 to really become a thing the user should never see any cryto stuff, and advanced use and control can come as an enchancement of the basic case.
- dickhardt 4y agoThanks & I agree!
- rideontime 4y agoI created my account with Google. But then Google shut my account down for posting too much pirated music to Youtube. How do I get back into my Greenfield Fitness account?
- zakgreant 4y agoHellō has you set up multiple recovery providers and methods, making it unlikely that you'll lose access to your Hellō account. Visit https://wallet.hello.coop https://wallet.hello.coop after you go through https://www.greenfielddemo.com/ https://www.greenfielddemo.com/ and you'll see the workflow.
- dickhardt 4y agoGiving you control of your identity is our mission. You online presence should not be held hostage by any of the social providers, which is why we encourage you to add backup providers so you can recover your Hellō Wallet if you lose access to your preferred provider. Losing access to your users is also a risk as a developer as the provider can take away your app access to their service. Our goal is to be neutral and not be able to take away either the user's account, or the developer's access.
- agentdrtran 4y agoThis looks great, good luck.
- dickhardt 4y agoThanks! Any other feedback?
- Ennea 4y agoI just have one question: with a name like Hello, how do you ever expect anybody to find your service on the Internet?
- dickhardt 4y agoYou are correct -- a generic word like 'hello' is challenging. Today people find https://hello.coop https://hello.coop through Google currently by searching for "hello coop" or "hello identity"
- halostatue 4y agoI don't really see what this gives over Auth0, Orly or various other identity providers which have social login plugins available…and none of those seem to be involved with anything related to smart contracts, which makes them infinitely preferable in my opinion.
- zakgreant 4y agoYou don't need to register with the various providers or set up any plugins. You set things up once and then you're done. See Dick's comment about the reg bit at https://news.ycombinator.com/item?id=33180661 https://news.ycombinator.com/item?id=33180661 Also, jrockway shared relevant Auth0 comments in this discussion at https://news.ycombinator.com/item?id=33180939 https://news.ycombinator.com/item?id=33180939. Is your reluctance around smart contracts influenced at all by https://www.hello.coop/pages/financing.html https://www.hello.coop/pages/financing.html?
- halostatue 4y agoNot at all. I do not believe that smart contracts are a feature. With smart contracts, there's a shift to mostly untested buggy contracts written on buggy and wasteful execution systems (e.g., Ethereum or some other crypto-chain). It's also completely unclear whether "smart" contracts would be considered enforceable in many or most jurisdictions. There's well-documented failures of so-called "smart" contracts, and IMO building something like this on top of one is a recipe for disaster, just like the rest of the crypto-blockchain ecosystem.
- dickhardt 4y agoAgree that there have been many failures in the smart contract market. In contrast to many crypto projects, we are only using smart contracts for financing Hellō so that we can separate the return on investment from the cooperative governance. This removes one of the common failure modes of governance gone awry. There is significant innovation in the crypto ecosystem and while there are failures (as there will be with any novel technology) there are also successes. As we don’t need to issue any smart contracts in the immediate future, we will be able to build upon the successes.
- schroeding 4y agoLooks nice and convenient! One question, though: How do you say Hellō? [həˈləʊ] or [həˈlø] or [həˈlɔː]? :-)
- dickhardt 4y agoThanks! [həˈləʊ] just like "hello" =)
- entwife 4y agoReminds me of Estonia digital identity. https://www.politico.eu/article/estonia-digital-id-scheme-europe/ https://www.politico.eu/article/estonia-digital-id-scheme-eu...
- entwife 4y agoAlso Spain digital certificate. (in translation) https://www.exteriores.gob.es/Consulados/toronto/en/ServiciosConsulares/Paginas/Consular/digital-certificate.aspx https://www.exteriores.gob.es/Consulados/toronto/en/Servicio...
- jezclaremurugan 4y agoJust chiming to say that we used Hellō for one of our products ( bestozy.com ) and the whole experience was a breeze. Dick Hardt was very accessible - but tbh we didn't need much help at all as the integration was straightforward and the documentation comprehensive.
- dickhardt 4y agoThanks for the kind words!
- tamasnet 4y agoWhat is the role/responsibility/benefit of corporate members? It's not clear from the available descriptions why a company would want to become one. Perhaps simply to support the initiative?
- dickhardt 4y agoSupporting the initiative is one reason to join. Influencing the direction of the co-operative is another. Our current corporate members want Hellō to succeed as it will help their business succeed. A rising tide raises all boats. The only responsibility of a corporate member is to abide by the bylaws, and vote for the corporate board members. We have been having regular corporate member meetings to review progress and discuss identity trends. I think the current members learn something from the other members at each meeting.
- zakgreant 4y agoCorporate members can also can elect board members – as can the other classes of coop member. See https://www.hello.coop/pages/cooperative.html https://www.hello.coop/pages/cooperative.html
- mpeg 4y agoI can see this being very useful for web3 projects once you add support for the discord scope. A lot of the time you just want a way of logging in with a wallet and link to discord in a secure way. I've implemented this for a bunch of clients lately and would probably have used something like this if it was available and mature.
- dickhardt 4y agoThanks for sharing! I’ve moved discord up in our priorities. Feel free to reach out directly.
- lucasmo5075 4y ago