Something that really surprised me was the signing/metamask integration(a kind of webauthn). I would definitely use that to login into various websites instead of the invasive facebook/google login plugins we see all over the web. There is even something akin to oauth2 but without the requirement to have "developer keys".
Recently I've been working at converting an existing web business to web3 (at least my interpretation of web3), with the goal of making it all decentralized. My impression at this point is that it's mostly possible but not all that practical.
It might make more sense if I reimagine what the business is, which is part of my exploration here.
I'd much rather have the convenience of "Sign-In with X" but backed by something I have control over.
The reason is: With private key auth alone, you don’t have identity, just a non-human readable public key, and no universally known exclusive association with a particular username. With OpenID or WebAuthn or any of that, you would still need a company or org to keep a centralized database of everyone’s credentials and user info. With Blockchain you don’t: As long as the Ethereum blockchain keeps going, your info (username: “johndoe.eth” public_key: “420abc” avatar: “some HTTP or IPFS url”) will stay stored. This is the exact precise thing blockchains are unusually good at doing, and given how much people these days are hating on big tech companies managing their identities and harvesting data in the process, “SSO with no company attached” seems like a thing people actually want.
I’m still highly skeptical of art NFTs and crypto as currency and lots of other blockchain stuff, but in this one case they’ve won me over. This seems legit.
Someone else posts into the blockchain that jondoe.eth public_key "420abc..." is {this real data about the person}.
And now that identity and every login it is associated with has been doxed in a permeant, public, and unalterable way.
If someone doxes my gmail account, I can go through the process of dissociating myself with that identity and hopefully the provider were that doxing is stored could be persuaded to delete that content (yes, the internet has a long memory).
This would seem to be much harder if not impossible with an identity stored on a public blockchain (that also allows for other data to be stored).
Also it’s up to you how you use the system. You could have a number of online persona’s each with it’s own login.
This is about having a public, centralized source of identities that cannot be erased.
Yes, you can have multiple identities on it - but if an identity on that chain is doxed, it is forever doxed.
If you are maintaining one identity per application... then what is the advantage of having the identity in a place where it can be accessed by multiple applications?
I have difficulty seeing the advantage of a public, append only, identity provider compared to say... setting up your own auth server on AWS and managing your identities out of there.
OpenID gives a few organizations like Google, Okta, and Microsoft "root on the entire world." It terrifies me.
How does "wallet as resume" solve the implied competency better than a GitHub repo with signed commits?
How does the wallet-as-resume solve the "I copied a project" or "I followed the tutorial line for line?" One can create a NFT or whatever equivalent for code you wrote just as easily as code you copied (be it with cp or typing it all in yourself). Can only one person would be verify a particular implementation of FizzBuzz? If the code is copied, can the original author usurp the "I wrote this" from a pretender?
Does anyone reading resumes actually think that this is a problem that needs solving?
For example, once a reasonable digital ID system exists, we can start to build trust systems, such that your good reputation among one community can be used to bootstrap your reputation in a new community. Again, zero-knowledge proofs should be a viable mechanism for conveying trust relationships without having to reveal your social graph.
Some of this data would have to be stored off-chain, or only in encrypted form on-chain, but I don't think there are any practical limits of blockchain technology which prevent this.
https://openid.stackexchange.com/
HN could be a provider! You could be news.ycombinator.com/api, which admittedly would be a very confusing name to the casual observer.
The reason it all ended up being centralised is that almost nobody really valued it being decentralised.
If you're signing in via some other 3rd party, you can change your password.
I'm just trying to think of how "Sign in with Ethereum" would work if you're trying to get your technophobic grandma that clicks on phishing links and responds to the County Password Inspectors [0] when they call to use it.
For example, you can generate 7 tokens and only need 5 to reset your wallet keys. You can give 3 to your relatives, 1 in a safe-deposit box, etc.
Grandma’s kids can help her set it up.
Edit: Or, for people who really prefer centralization, you can give all 7 tokens to Bank of America. The point is you have a choice and can design the security system you want.
2. SIWE lets the user share a cryptographically verified shared state of the user. For example, digital asset collections, reputation in a group etc.
2. Once smart contract wallets properly gain adoption, you'll be able to do recovery (see: https://vitalik.ca/general/2021/01/11/recovery.html )
3. Lots of built-in anti-sybil techniques (eg. verifying that the address has nonzero balance is a pretty simple and effective one)
Why does ethereum need to come into the picture?
Agreed (and I agree that ENS and the SSO stuff looks interesting). The problem here is that the crypto community are the ones setting the high expectations.