Rohingya turn to blockchain to solve identity crisis
theguardian.com
theguardian.com
The article states: "Noor’s goal is to give Rohingya the power to reclaim their identities with a resilient system that their host countries will recognise, allowing them access to social programmes, legal rights, education and healthcare." But that's begging the question. The problem is that the state won't recognize them. Why would a blockchain based solution change that?
An illustration: you do not trust Amazon because of a TLS certificate. That certificate means that you trust the entity on the other end is Amazon. But it doesn't make you trust them. You trust Amazon because of a bunch of soft reasons: you have ordered through them before, and it worked; they appear in the media a lot as a place people go to buy stuff online; a lot of your friends and colleagues buy things through them and are satisfied. All of these factors go into your soft judgement of why you're willing to give Amazon money.
(If you don't trust Amazon, substitute them for some online entity that you do trust. If there are none, please accept that some people do trust online entities enough to give them money and expect to receive goods or services in return.)
This is what I mean by technology does not solve civil problems: in this case, a specific technology solves the specific problem of establishing an online entity is who they say they are. But now you're back to the same problem that exists with any human interaction: do you actually trust the other side?
Back to the database: if we're going to trust some individual or institution to be the arbiter of accuracy, we're better off just using a normal database with whatever encryption we want. Because once your system has that basic level of trust, you don't need blockchain.
And back to my original point: this set of information (in whatever form) makes no difference if the people in power don't care. This information will not make the people in power care. The problem with any oppressed people is caused by those in power abusing that power. Those in power have power because they have might and the belief of the people that they will use that might to enforce their power. Blockchain doesn't change that.
If you have a trusted oracle for people's identities, you might just be able to trust that oracle's assertions (maybe that's what you're referring to as "cross signing") without also recording them in a blockchain, unless you're concerned that the oracle will tell the truth initially and then lie later on.
If you have a web of signatures, similar to PGP, Keybase and a few other systems, you can't do that.
The same goes for a blockchain.
What you put in there is susceptible to the oracle problem, but that is another level. Both these things need attention.
That's true, and that's an important issue. But I might still ask, for each application, is there someone who's trusted to introduce records into the system but not to update them later?
(We can definitely envision applications where the answer might be "yes" -- often related to concerns about censorship -- but it doesn't seem like this is the case for every application.)
The last thing you want to do to an oppressed minority in an autocratic state is compile a public membership list. This article is someone tagging their pet fad to a humanitarian crisis.
How does the printing press making books cheaper not help end widespread illiteracy? Why does better engineering allowing construction of sewers not drastically improve civil life?
Heck something as simple as street lights must have done a lot to make people feel safer going out of their homes at night.
With a blockchain approach, rather than separate entities clamoring to be the source of truth in lieue of an ineffective state everyone can instead look to the blockchain. (Which theoretically has no agenda, distributed control, etc...)
Let's assume this blockchain-based identity exists. What problem is now solved? What does it matter if people can now point to the blockchain to say "Yup that's me"? The state has a monopoly on force - that's rather what makes them "the state." Why would people look to the blockchain rather than the entity with a police force and military?
Rohingya refugee: "But isn't a blockchain supposed to be trustless. Aren't we just trusting you to verify me?"
Blockchain person: "Yeah whatever, do you want to be on my blockchain or not? I got a lot of funding for this"
Rohingya refugee: "Sure okay"
Rohingya refugee Myanmar government: "Hey I'm a real person. I'm on this fella's blockchain. That proves it."
Myanmar govenrment: "We don't care."
Allowing mutability to any of those things doesn’t work well with preventing hostile forces with far more resources from corrupting your records — even a bug free implementation should, on topics like this, presume the hostile attackers can mount a 51% attack.
(I’d go further and assume hostile actors could mount a 99.99% attack when it’s homeless stateless refugees fleeing hundreds of thousands of armed malitia).
The whole system appears to rely on a trusted group certifying the [probable] authenticity of an individual's records and Rohingya refugee status, in which case you might as well let them host it on a well-backed up regular database...
A regular database has no way to make it infeasible to insert fake old records. Sure, you can publish checkpoints. But that doesn't work so well when you're up against a government that wants to erase your entire ethnicity.
(In practice, I think the Myanmar government's strategy would simply be to disregard the database rather than to attack it anyway, on the basis the local prejudice against the Rohingya isn't based around their numbers or individual identities but the claim that they are actually Bangladeshi illegal immigrants lying about Myanmar ancestry and land)
And yeah, a government would certainly try to ignore facts it didn't like.
Git is a distributed database only if every copy eventually syncs to tip, and only if everyone can agree what "tip" is. Each of those conditions is hard to meet if the problem statement assumes that malicious actors have write access to the repo and can arbitrarily assert which fork is master.
If your solution is "proof of work", then you have the additional problem that there is a large group of people with significant computational power who can take over your new blockchain for the appropriate fee.
Blockchain as implemented in Bitcoin takes a thorny sociopolitical problem (how to store monetary value) and turns it into an economic problem (how to calculate SHA-256 moving the smallest number of electrons).
As applied to the Rohingya situation, it switches out the political power of whoever is currently dominant and replaces it with monetary power (proof of work). It commoditizes political power. I don't know about you, but I'd take an economic problem of being the group with the most money (== computing power) over an intricate, shifting political problem any day of the week.
My assertion is that using a blockchain, as opposed to existing proven technologies, adds nothing of value.
You keep restating the opposite claim, but you have yet to explain how a blockchain adds any value over not using one.
If existing proven technologies have a way of making rewrites hard (not reputationally hard but economically hard), then I'd appreciate the education. I'm not aware of such a power.
That's not exclusive to blockchains. Blockchains impose a cost to rewriting history because peers follow a set of rules that make it so. You can impose a similar set of rules in any alternative solution, blockchain or not. Simply do not accept non-fast-forward branch updates. Validate all proposed updates against your standard rules, and if validated, use your custom merge driver to implement any required merging rules.
I have yet to see an description of a threat model here which explains how such a blockchain's decentralized consensus system solves this particular real world problem.
Either you're agreeing that you could stick proof of work into a more conventional database (not sure if that's what you mean by "You can impose a similar set of rules in any alternative solution, blockchain or not"), or you don't think the self-validating nature of a proof-of-work blockchain is interesting.
The alternative solution you describe in your first paragraph still has the flaw that a nation-state could delete all known copies of the real national database, publish a new one, and say "Here's the national git log. Oceania has always been at war with Eastasia." Someone finds a backup copy of the original and publishes it. Now, determining which one is right is basically a question of whoever shouts louder. There's nothing inherently better or worse about the fake log compared to the real one, since both follow the rules; it's a question of who you believe.
In a blockchain solution, on the other hand, the nation-state would have to say "here's the real blockchain," but either the amount of work required to produce the fake one was more than the work required to produce the real one (in which case congratulations, they win), or else it's self-disproving. Nobody has to argue whether the real one's real, because the real one by definition has the most work put into it. Unless I'm misunderstanding you, your example alternative solution doesn't have that important feature.
Myanmar obliterated all traces of the Rohingya, razing their villages, rebuilding entirely different structures on those locations, and then claiming that the Rohingya burned down their own homes and voluntarily left the country (listen to https://www.nytimes.com/2018/08/14/podcasts/the-daily/myanma... for more). It's completely within the threat model of this situation that a nation-state might want to rewrite its identity database and deny that it ever happened.
Sorry if I'm still somehow talking past you.
This was a solved problem before Bitcoin: https://en.wikipedia.org/wiki/Trusted_timestamping
Now that Bitcoin exists, you don't need to trust a third party for trusted timestamping any more; you can insert hashes into an existing (stronger) blockchain instead.
I accept this is technically "blockchain" in that case, but I wouldn't really call it "blockchain technology" or "turning to blockchain" and there's no need to reinvent a new blockchain with all the risks that entail.
Take my git repository and add a rule that to be considered valid by a client an authority must have inserted the commit hash (or a child commit hash) into the Bitcoin blockchain. If an alternate branch appears, the earliest appearance wins. You get the property you're looking for, but you don't need to invent a whole new system to do it. Bitcoin (or any blockchain) isn't required; any trusted timestamp service will do instead. If you don't want to use a third party, then sure, use Bitcoin, but no need to invent anything new.
I argue that this is far better than "turning to blockchain". All the components are well understood. There is no risk in this model.
I'm sure that people who are starving to death are grateful to know that a bunch of rich techbros are dumping money into an exercise in patting themselves on the back rather than spending it on anything actually useful.
Your last paragraph is just hilariously naive.
In this case it seemed to be based on regions or zones in rural territories. Anybody in those towns or villages, was in the wrong place at the wrong time, and no amount information was going to make a difference.
I don’t think they were going around, checking names and marking clipboards. By all accounts, there was nothing orderly about this one. Little more than a perimeter walked down to a kill zone. The people that got away had to move fast, and of the ones that made it out of the round up, it seemed to be children and people who played dead.
So, add computerized record keeping to the mix. Will it be used to hunt people down? It’s probably a concern worth considering, but really the modus operandi seems to be search and destroy eviction from a territory, to clear out an area, not understanding and targeting network nodes in a constellation of peers.
crickets chirping
"Solve it with block-chains!"
"You've not heard my problem yet."
"Doesn't matter!"
Blockchain-overuse snark is not the solution to every blockchain proposal.... especially if you haven't heard the proposal yet.
A decentralized solution removes the question who maintains a centralized database. That's important because, as you say, the answer to that question has always been the state. Which means it's never really been a question.
If you're cool with the government owning your identity -- and truly having the power to erase your entire existence, so they're not denying you any rights because there is no "you" -- then it doesn't matter. But for some people, it might matter to be able to point to something other than the mirror and say "I exist, and not just because I say I do. This matters because [this entity] is taking actions that are inconsistent with my existence and implied rights."
It's a small step, but it's one that opens up options that don't exist today.
It doesn't matter because the provider of identity is the same entity that needs to accept the identity: the Myanmar government and they don't want to accept them. This "solution" is ridiculous.
So-called "recognized states" make monumental efforts at disallowing creation of new states and at making citizenship scarce, to help keep their monopoly. This doesn't seem to be in the benefit of Earth's people, and also amount of "unrecognized states" grows year by year. Previously, this backlog could only processed by holding a World War.
It's an elephant in a room and I'm quite surprised I've never seen this idea discussed seriously anywhere.
The real issue is that cultural identity is a very fluid concept, and states can try to steer their citizenry to express a very broad, inclusive notion of cultural attachment (as France and Germany did in the late 19th century) or a very narrow and exclusive sentiment (as the Ottoman Empire did).
What's with the Ottoman Empire in the late 19th century? You seem to refer of it as of something well-know and yet I have no idea.
Oh, there's still ethnic violence on a large scale in South Sudan. It's between different groups inside the new country.
> Since the outbreak of conflict, armed groups have targeted civilians along ethnic lines, committed rape and sexual violence, destroyed property and looted villages, and recruited children into their ranks.
https://www.cfr.org/interactives/global-conflict-tracker#!/c...