4 ms·
What should be a good online identity? It's an open problem nobody has yet solved.
by btw0 18y ago
What should be a good online identity? It's an open problem nobody has yet solved.
- aneesh 18y agoFacebook is trying to solve it. It's easy to create a new email account. It's much harder (though not impossibly so) to create a fake identity with 150 friends.
- Devilboy 18y agoThat's true, although I kinda like being pseudo-anonymous on most public forums. Also meet my friend: http://www.facebook.com/profile.php?id=622877592 http://www.facebook.com/profile.php?id=622877592
- Shamiq 18y agoEveryone needs his own key. And needs to sign her own documents.
- potatolicious 18y agoThe better question is what you need from the user's identity. If an identity is simply a means to authenticate the user on your service only then an email is more than good enough. If you don't need anything else that is associated with the person's identity (e.g. his social network, real-life address, etc etc) then I don't see a problem with using email.
- olefoo 18y agoIt's becoming enough of a problem that it is being suggested that the government support some form of credential that could be used online. see: http://www.nytimes.com/2008/12/09/technology/09security.html http://www.nytimes.com/2008/12/09/technology/09security.html And yeah; I'd rather the government than facebook, thank you very much.
- mnemonik 18y agoI wouldn't. I would much rather a private company with experience in determining online identity provide a service like this. A. It would be an optional service, so you would only use it if you wanted to. (Unless gov't got involved somehow, but my whole point is that they shouldn't be involved.) If it were a gov't run operation it would probably be impossible to opt out of. A recent example is the Australian filter. That's not working out very well, neither would this. B. A private company has more to lose if it were to screw up implementation and design than the gov't would. I would trust my privacy to a company before the gov't because I could weigh customer reviews and go to a competitor's service if it was better. C. A gov't can say screw you guys, work with my standards for verification. A private company would be forced to work with others or fail.
- olefoo 18y agoThe way I see it, identity verification is one of those dull, expensive, necessary things that will have to be done for the network economy to function. A private player will always have incentives to screw with it Imagine getting a message like "You must be logged in to facebook if you want to buy groceries. Do you want to let the dietsnoop application see your purchases (Y/N/there is no cancel)?" When you swipe your card at the grocery store? And to go through your objections one by one. a. Any identity validation system has to be a universally accepted standard with strong penalties for misbehaviour on the part of validators, relying parties, and authenticating individuals. If it's less than universal, it doesn't work nearly as well, a bunch of people can opt out, and the effectiveness drops drastically; and we're back where we are now with a bunch of different standards and competing providers each with their own agenda. b. Microsoft Hailstorm? Yahoo IDs? Facebook's multiple data wankeries over the years? All the times that people have horked 100s of thousands out of other people's bank accounts by having the bank email a password reset to an email account? If past is prologue, the cost to businesses of screwing up their identity verification is relatively low. Which is fine if all they control is some crap email and a few digital photos, but rapidly becomes unfine if it's your bank account, or your deed to your vehicle, or your house or your ticket to New Zealand; or (going 15 minutes into the future) your house keys, your medical records, your ownership of businesses, etc. c. But as mentioned in my response to a. a body that can set standards and enforce them with real teeth is exactly what is needed. The other side of that is that any private party that had the wherewithal to pull off the introduction of a new economic system (weak identity authentication is the foundation that credit cards are built upon) is going to be or be rapidly on the way to being a heavily regulated entity. I'm not saying I'm necessarily enthusiastic about the prospect of the government holding the root signing keys to everything; I just think it's inevitable. And the thing is we need to be talking about it now, so that over the next 6 months to two years as the economic crisis plays out and the necessity of doing something is brought to the fore; we can push the discussion towards sane alternatives. We have a window to affect the policy discussion, but that window is closing rapidly, and there are lots of people who would like to close off certain avenues of discussion. You want peer to peer disconnected transactions? You have to convince people that those matter more than law enforcement, garnishments and debt collection. Anonymous transactions are going to be a tough sell; so are pseudonymous transactions. Hell, we're probably going to have to fight to keep J. Random Moral Prude from putting a kill switch in everybody's wallet that will limit purchases to socially acceptable ones (more of a worry in the UK and commonwealth nations).