9 ms·
I've wanted to have domains as identity for years, so I'm thrilled to see someone actually doing it. I want to use a domain validated identity for everything;
by ryan29 4y ago
I've wanted to have domains as identity for years, so I'm thrilled to see someone actually doing it. I want to use a domain validated identity for everything; social networks, package repositories, code signing, etc..
I hope this idea catches on. I think a more decentralized approach to identity combined with 3rd party attestations or filters could change the way the internet works.
Imagine what could be built if everyone used domains as handles / identities. Social networks could go hands off for moderation and allow plugable moderation engines that rely on domains for identity, trust, reputation, etc..
I'm convinced that domain validated identities and attestation could usher in a revolution for reputation and trust. Are there any more projects doing similar things?
- 2h 4y ago> Social networks could go hands off for moderation and allow plugable moderation engines that rely on domains for identity, trust, reputation Every time this has been tried, it's failed miserably, as it should. People need to be able to post anonymously. Otherwise it's too easy to target the messenger, rather than the message. Think journalists, hackers, abuse victims, political dissidents, whistleblowers. Yes, this makes moderation harder. Sorry but that's life.
- ryan29 4y agoIf the social networks don't moderate, or let you opt out of their moderation, and you can opt in to whatever moderation system you want, how would that be any worse than trusting big tech to moderate fairly?
- 2h 4y agoI don't even understand what you're asking here, but it sounds like you're arguing against yourself, so please continue.
- nbrempel 4y agoDomain handles are a feature but not a requirement.
- charcircuit 4y ago>Think journalists, hackers, abuse victims, political dissidents, whistleblowers. The vast vast majority of people are not those things. Even if you wanted to be anonymous to other people you could still prove your identity to a service and the service could keep that identity hidden.
- _heimdall 4y agoFor anyone that's serious about wanting or needing to anonymously post a public message, I would strongly recommend against this advice. Part of the strength of your anonymity is based on the cost for anyone trying to figure you out. Centralizing your trust in a service that promises to keep your identity hidden is begging for trouble. The service doesn't have to be malicious and can genuinely make every effort to keep your identity hidden. Trusting services like that creates choke points where it may not have been viable to attack the service for one identity but for hundreds its worth it. Theres no such thing as flawless anonymity and you can't escape having some number of trusted parties, but you want to keep that list as low as possible.
- markdown 4y ago> Social networks could go hands off for moderation and allow plugable moderation engines Just imagine the bubbles. Bubbles everywhere.
- ithkuil 4y ago> I've wanted to have domains as identity for years, so I'm thrilled to see someone actually doing it. on a tangentially related note: Go "package management" is based on domain identity (although most people just use github.com), yet for some reason people seem to prefer to defer to a centralized registry and praise "good package managers" like cargo.
- ryan29 4y agoYeah. I've used that enough to learn how it works. I think the biggest issue is that it's not the default and most people take the easiest path which is using GitHub, etc.. There's a neat project that can help generate some of the web resources needed to use vanity imports: https://github.com/leighmcculloch/vangen https://github.com/leighmcculloch/vangen
- TeMPOraL 4y agoThe pattern repeats fractally in everything. Since you mention Github - it happens to be by far the widely-used, centralized repository hosting, and promoter of pull-request based workflows - for a version control system whose whole entire point is for you to not do that. I mean, the "D" in "DVCS" doesn't stand for "has no manual file-level locking".
- nixpulvis 4y agoI agree, I'm just worried if it truly catches on, domain prices will become a strange new hot button issue.
- wmf 4y agoIt's not strange IMO. Domains need to be cheaper. Even "non-profit" .org includes a mandatory donation and a bunch of other fat.
- IncRnd 4y agoCurrently, a domain can only be a brand and cannot be a true identity. There are methods to get free domain names [1], domain names without identity validation [2], etc. So, a domain is nothing but a method of verifying internet presence. [1] https://www.hostinger.com/free-domain https://www.hostinger.com/free-domain one example [2] Any regular domain purchased from a registrar. You simply pay and get the domain with no further identity validation required.
- ryan29 4y agoThe reason I say I think domains make a great identity is that I don't think it's important for identities to be verified. I even think there's room for 100% anonymous blockchain domains. The value is in the way the domain owner participates online and what kind of reputation they build. There are many old-school communities where I recognize the handles of extremely knowledgeable, friendly, helpful people and I have no idea what their real names are. Imagine if the well earned reputations of high quality participants were transferable across online communities by using a domain as global handle.
- IncRnd 4y agoA domain can expire and be used by a different party. A different person can maintain a website. There are many ways a domain's admin can change. Domains are not guaranteed to be unique even if they are in some cases considered anonymous.
- mox1 4y ago1. Domains are guaranteed to be unique. We have global registrars and global DNS, its not possible to have duplicate domains.. 2. Don't utilize a domain that is shared by lots of people. There is also lots of DNS tricks (TXT records) to "pin" a user to a domain or whatever. If the domain is shared (for example a company website), you just add a TXT record denoting what private key is allowed to do things. Heck you could setup fine grained permissions per key via txt records. 2. Yes they can expire and that situation is detectable. How is this any different than twitter or another service allowing re-use of a deleted username?
- abtinf 4y agoThis was essentially the intent behind the .tel tld—using dns as an identity metadata database. Circa 2008, they did a bunch of podcasts and interviews about uses for the domains, like encryptions schemes for secure messages using keys posted to an individual’s .tel.
- vidarh 4y agoI interviewed with .tel around then, and declined an offer after it was clear their plans were wildly unrealistic. The "identity metadata" bit had already been pushed by multiple registrars for years at that point, as it doesn't require the cooperation of a registry to allow it, and largely gotten abandoned because of lack of user interest.
- hem777 4y agoI personally don’t want to use a domain name for everything. I want all my identities to be unique, I want an infinite number of them, that I can change between multiple ones per service and that they’re not connected to each other unless I specifically say so, and they should be fully free and permission less for me to create. Public/private keys have or enable all those properties. While there a many problems with how domains work today as a public goods system, domain names as identities is infinitely better than what we have now, but I think we can have it much better and domain names are one step in that self-sovereign ownership.
- georgyo 4y agoI think you missed the part when the original username was a subdomain of bluesky. There will be a great many anonymous registration services I'm sure. And things like afraid.org make that number of possible domains you can use anonymously a truly massive number. The problem with pub/priv keys as user identities is discoverability and validation. How do I find your key? How do I prove this key is actually yours? Sure they are anonymous, but that isn't a desirable property if you are an established public figure.
- hem777 4y agoMost of us are not established public figures and many of us, I’m sure, want to keep it that way. With keys, validation can happen in several ways: attestation by reputable orgs, reputation systems, off-band, 2FA, “Hi, I’m John”, etc etc. Discovery is also highly context dependent in that it can and should happen “in the app/system” (=whatever the context of the use case is, eg. you know me by pubkey 123, the tax office knows me by pubkey xyz). “anonymous registration services” from the perspective of self-sovereign identity is by definition not anonymous :)
- georgyo 4y agoTo be clear, I understand the desire for truly anonymous services. But after two decades of experimenting and thinking of this problem. I don't think it is possible for an truly anonymous solution that is also ergonomic to use. Things like briar exist, and for you use cases, existing tools might be enough. Briar is fantastic for communicating with people you know and willing to jump through some hoops be part of a community that is anonymous, secure, and provides lots of ways of making introductions and posts. But there are reasons why Meta, Twitter, Linkedin and the like are well above any anonymous solution in terms of users. - Identity (including pseudo identity of anonymous users) is established. - Spam. There is ungodly amount of spammers out there, as email has shown. If you have played with nostr or scuttlebutt you would also see just how horrible the spam is. - Account recovery, people are bad with passwords and storing secrets. Very bad. And even the most secure people can get exploited. - Hosting your data is problematic. Who hosts data which may be illegal? When illegal data is flagged, how does it get purged? Merely being the transit for data is protected in the US, but physically hosting that data is not. - The vast majority of people are unable to run a persistent service for their identity and content. Even if they are willing, they lack the means. You end up targeting a very small subset of people who are willing, able, and capable of running a service. And that service requires care and feeding. You might end up with millions of vulnerable instances. - Scalability. No one has come remotely close to solving how one of these solutions would scale to billions of users. Or even tens of millions. DHTs become painfully slow and bloated. Even if a solution did start catching on, it would quickly then fail because the user experience would crater as it gains popularity. I have become convinced that making an ergonomic briar is impossible without making some concessions. Complaining that a new and unproven tool's chosen concessions are bad inhibits experimentation.
- swyx 4y agopeople lose domains by forgetting to renew all the time. major corporations do it. do you want people to be compromised/have their identity stolen because they forgot to pay 7.99 to ICANN?
- echelon 4y agoThat's not a problem. I don't mean that in the sense that it doesn't happen. Rather that the market succeeds despite it. People forget to pay fines, mortgages, taxes -- the system has rails to put most back on the correct path. And the failure isn't permadeath. Your domain expires and life goes on. There are also protective mechanisms to prevent your domain from expiring. You can pay a balance in advance. Pay for "renewal insurance", etc. As more people use the system, it will grow even more safety rails.
- nkozyra 4y agoBut the stakes are much higher here. You can fix those things if you forget. You're in trouble if you forget to renew your domain. And you're in much bigger trouble if your identity is tied to ownership of that domain.
- namaria 4y ago>Your domain expires and life goes on. Replace 'domain' with 'identity' and you have a very scary proposition. This is just another form of 'code is law' and doomed for all the same reasons. Bugs and exploits become severe threats to your wealth and well being. As much as we hate to depend on institutions and 'other people', depending on computers program is inherently worse.
- echelon 4y agoIf you use your domain for email, you already have this problem. This problem isn't new at all. Would you rather have a situation of ownership with responsibility or no ownership at all? The "free" alternative is a crypto like identity, and there's zero restitution if you lose your key. People will struggle even more with this. At least with domains there is a legal framework if you're paid up.
- luvItorLvit 4y ago[dead]
- weird-eye-issue 4y agoThousands if not tens of thousands of domains expire every hour How many Gmail accounts expire and then get held hostage with higher renewal fees before going to auction? Oh yeah, zero
- Taganov 4y agoGmail accounts with phone numbers attached get regularly locked permanently with no recourse.
- weird-eye-issue 4y agoWe are talking orders of magnitude difference. Plus this is a much more solvable problem than what I mentioned: domains getting held hostage and then going to auction.
- stevekemp 4y agoFor a while we had a similar thing, via OpenID. OpenID was wonderfully portable, you could host it yourself, or you could defer to gmail, etc. However after a period of being used and growing it suddenly disappeared from most of the places I used to see it.
- vidarh 4y agoThis was a big fad from around, and then rapidly died, as most users simply didn't care. Instead we got attempts at e.g. OpenID and similar, which rapidly converged on a handful of large identity providers who ended up dominating. A large problem to encourage and retain a truly decentralised nature is usability. It must be as simple as allowing a site to authenticate you with Google or Facebook, as most users don't care enough to be willing to do more than that, including finding somewhere they trust to register something new.
- mro_name 4y agonothing will be as simple to onboard as a billion-dollar monopoly solution. agency requires a least bit of activity.
- vidarh 4y agoTo late to edit now, but should have read "from around 2000".
- ryan29 4y agoI always liked the idea of OpenID, but you're right, it was far too complex for the average person. I was enthusiastic about it, but never got around to using it because it wasn't simple enough. I think the kind of approach used here is a bit better than OpenID in terms of separating authentication and identity. You have a permanent account on the service for authentication and the identity (your domain) is more of a pointer / shortcut. That strikes a good balance in terms of letting the service provider dictate authentication policies without usurping your identity people recognize. Unfortunately I don't think any of the big tech companies would get onboard with an idea like this. They're all racing / competing to control identity right now. Although I've always thought the idea would fit well with Twitter.
- DeathArrow 4y ago>Imagine what could be built if everyone used domains as handles / identities. Social networks could go hands off for moderation and allow plugable moderation engines that rely on domains for identity, trust, reputation, etc.. Imagine we let people build communities that self moderate instead of imposing a way to moderate and censor.
- deleted 4y ago[deleted]
- AndyMcConachie 4y agoYou should check out the Kurer project from GMU researcher Eric Osterweil and his researchers. https://kurer.daneportal.net/ https://kurer.daneportal.net/ https://cs.gmu.edu/~eoster/talks/2022-04-27%20Obj%20Sec%20Comp%20Cyber%20light.pdf https://cs.gmu.edu/~eoster/talks/2022-04-27%20Obj%20Sec%20Co... You probably also want to read up on anything DANE and DNSSEC related if you want to have reliable information storage in the DNS.
- kimburgess 4y agoIf you're willing to consider PGP, there's also https://wiki.gnupg.org/WKD https://wiki.gnupg.org/WKD which provides a much neater mechanism for domain owners to publish pub keys that can be used for identity verification too. Also somewhat intersecting with that space is https://keyoxide.org/ https://keyoxide.org/ which can provide proofs of that identity across different services.
- jamietanna 4y agoWe've been using domain names for identity in the IndieWeb (https://indieweb.org/why https://indieweb.org/why) particularly for the IndieAuth extension to OAuth2 (https://indieauth.spec.indieweb.org https://indieauth.spec.indieweb.org) and it's worked pretty well
- itslennysfault 4y agoNostr has beein doing this with Nip05 for a little over a year now. They just use a json file in the .well-known directory of the domain that contains your public key. https://github.com/nostr-protocol/nips/blob/master/05.md https://github.com/nostr-protocol/nips/blob/master/05.md
- rchaud 4y ago> Imagine what could be built if everyone used domains as handles / identities. I imagine Namecheap and GoDaddy getting involved before long. > Social networks could go hands off for moderation and allow plugable moderation engines that rely on domains for identity, trust, reputation, etc.. How is this materially different from Facebook handing off moderation tasks to Accenture?
- raffy 4y ago> I hope this idea catches on This already exists with Ethereum Name Service (ENS) https://ens.domains https://ens.domains and Sign-in With Ethereum.
- ryan29 4y agoI have one of those. When everyone was changing their Twitter (display) names to *.eth I thought there might be a chance Twitter would use ENS for domain validated identities, so I grabbed one that matches a good .com I own. The ENS stuff is cool, but I hope it doesn’t catch on unless they come up with a way to coexist with ICANN. I think multiple DNS roots would be a net negative no matter what.
- raffy 4y agoENS has DNS import via TXT Record verification proof, so the entire DNS tree can coexist in ENS trustlessly as long as future ENS-only TLDs are chosen wisely (seems simple: just use 0x80+ Unicode.) For example, try resolving my domain, "raffy.antistupid.com" in ENS. I believe, the ENS registry only contains "eth" as an rogue node (also "[0-9a-f]{40}.addr.reverse" is used for wallet names). Recently, ".art" started offering tokenized names, where you get both DNS and ENS.