Real Problems That Web3 Solves, Part 1
billprin.com
billprin.com
It failed to gain traction, and Mozilla eventually pulled the plug.
Persona had many advantages over the Web3 vision described in this article. It was painless for a new user to create an account, because Mozilla provided a default identity server. It was easy for a website owner to set up, because Mozilla provided a JavaScript shim that worked on any browser. And it didn't rely on a wasteful and slow distributed ledger.
Despite these advantages, Persona failed. I don't see how a blockchain-based approach, with so many disadvantages compared to Persona, could possibly succeed outside of the blockchain enthusiast community. And, on a technical level, a federated approach seems innumerably simpler and less wasteful than a blockchain-based approach.
Seems to be the selling point of most web3 and blockchain solutions once you brush the buzzwords off the copy.
WeWork might not have a a 'tech' company, but it behaved like one after juicing on all that Softbank money. Turns out they had nothing Regus or other 'boring' companies couldn't provide. But they bought a lot prestige properties and advertised constantly, so they became the household name for co-working.
My worry with the blockchain is that now it has VCs that are going to pump so much funds in it to keep it spinning and force everybody to use it because you need that service, and now (in the future) it's only provided through the blockchain (because the alternative off-chain company cannot raise funds so it doesn't exist, it fails, or it's a worse experience).
Looking back, I now see that not volunteering myself for the challenge was one of the biggest mistakes I've made in my career. It was one of those rare opportunities to make a difference.
I also wonder why nobody has tried it since. It's a simple approach, but you'd need a good security team backed by a trusted organization to make an implementation credible.
For what it's worth, the vision does live on and people are working on developing web standards that get us closer towards it. One example is the W3C's "Credential Management Level 1" from 2019, which specifically references[0] Mozilla's work:
"The API defined here does the bare minimum to expose user agent’s credential managers to the web, and allows the web to help those credential managers understand when federated identity providers are in use. The next logical step will be along the lines sketched in documents like [WEB-LOGIN] (and, to some extent, Mozilla’s BrowserID [BROWSERID])."
More recently, in fact, today, I see there is a "Federated Credential Management API" draft published,[1] which has the goal of:
"enabling a website to request a users [sic] federated credentials from a user agent, and to help the user agent store the users [sic] federated credentials for future use."
[0] https://www.w3.org/TR/credential-management-1/#teh-futur
I would never use these services unless it was completely open, free and privacy centric though.
Apple comes a bit of the way but they tend to make stuff work only on their own hardware wish won't work for me. Persona would have been a good option. Especially because it could be self hosted. That would be amazing. It was just a bit too early.
Google / FB login still would have probably won
Sometimes it's all about being in the right place, at the right time, with the right amount of hype. Inferior technologies win out all the time.
That being said, if (major if) auth through web3 did take off, I wouldn't be surprised if over time it slowly creeped back toward a solution that doesn't use blockchain since a non-blockchain solution would probably be simpler, cheaper, and faster.
Even if the technological ideal comes to fruition in a few years (sharded modular proof-of-stake consensus blockchains with zero-knowledge rollups and dedicated data availability layers), it will still eternally remain enmeshed with speculation and scamming. I think there's a narrow time and place for the speculative assets but wouldn't want that interwoven throughout the fabric of everything online.
An idea will come along that enough of us can get behind, that idea will attract money and solve real problems for a while and when they're no longer problematic enough to warrant spending money on the system will collapse back into speculation hell until the next idea-that-we-can-get-behind comes along.
I don't think you necessarily need blockchain. Can't you just prove that you are who you say by signing something and sending it to the service? You can just use the protocol.
Login/verification doesn't require a transaction though, so is relatively quick. Blockchain in this context can be thought of as a collection of (public) keys.
It's important to remember that blockchains are just public-key cryptography where you have a private key that can sign things and, importantly, everyone knows everyone else's verified public keys. That's it. It solves the key distribution and verification problem that PGP and TLS etc have and this enables a lot of use cases such as universal private communication channels and authentication.
Signing the message is key for this yes but knowing that a certain key is connected to a specific user and that user having the ability to use it to sign verified messages everyone in the world can trust is the real utility here and what makes this universal SSO system work well.
On HN I am Sargos. You know this because I am replying to you and only I can do that with this account. I can also tell you that I'm @JamesCarnley on Twitter but there's no way for you to verify that. If I were using my public key to log into HN and Twitter you would know those are both my accounts and thus my persona is verified across multiple applications. If I were to link my public key to my government's identity database then you'd also be able to verify I am really James in real life as well.
Ethereum provides a robust, secure, and increasingly usable key storage and usage system to everyone which makes "just signing a message" a simple task and not a 10 step process probably involving a CLI. It's worth considering the utility of this and the possibilities everyone having a person public/private key pair allows. My fellow software developers among us likely have their mouths watering at the use cases this unlocks. Here's a pretty good thread about the implications: https://twitter.com/BrantlyMillegan/status/13892701158840975...
You can improve the UX of key management tools without a global network of redundant computers.
I never said this.
>You can improve the UX of key management tools without a global network of redundant computers
Yet nobody has ever done it until now.
Unless you were to upload each and every chat to a blockchain - which is prohibitively expensive - I don’t see the killer advantage over the previous alternatives. Also, many people here are also programmers, developers, and - surprise - hackers, so I am sure we would be interested in the mouth-watering use cases you’re thinking of (I looked at the Tweet thread you linked but it was just an explanation of public key cryptography in general.)
[^1]: Apple also refused to backdoor a terrorist’s iPhone at the demand of the FBI. OpenSea intervened when someone stole assets from a collector (https://blockzeit.com/opensea-nft-marketplace-stops-hacker-f...)
Keybase.io is a quite elegant solution and didn't "fail" due to any fault of its own (the team was acquired by Zoom).
I as a person have accounts on lots of apps but no real way to prove I own all of them. When you use a public key as your identifier then everyone can verify that the entity that owns Sargos on HN also owns Blah on Reddit if I want them to. Essentially you can trust that the digital entity you are interacting with is the digital entity you knew and trusted on the rest of the web in the past.
If you are using a web3 app and see vitalik.eth then you know for a fact that it's Vitalik Buterin. Unfortunately we only know this for sure because he said that is his address in public but there are many identity protocols trying to solve this problem and if you were to tie your public key to your government's identity database then you would be able to prove real world provenance.
2. Your possession of the private key “verifies” your public key, if someone takes it they are now you.
3. Depends on the consensus mechanism but in the best case, “everyone” and in the worst case “coinbase.”
4. You don’t trust them, the system is supposed to be trustworthy with untrustworthy participants, and when that’s not true you will just have to trust the architects of the hard fork.
5. Magical off-chain oracle!
Also GPG doesn’t have a key distribution problem. You can spin up a keyserver or use a popular existing one.
What’s in it for the user to sign up for persona? Nothing
What’s in it for the user to get a crypto wallet? Money
There’s your answer.
No idea as to why you didn't get any payments, but I do know that you don't have to click on the ads.
https://support.brave.com/hc/en-us/articles/360026361072-Bra...
"Users are rewarded for viewing ad notifications as they appear in Brave. Users are not rewarded for clicking on ads."
Money will never be a good enough reason to do things. Especially not the infinitesimal fractions of garbage coins that web3 will pay.
Those are two major advantages.
I suspect that this will be a major issue in the long-run. Once these sort of crypto-based logins become synonymous with CP and terrorism, they're going to be shunned by the average person on the street.
Yes yes yes, people use email and whatsapp for the same, but at least there is the option for Google and Facebook to censor or block/ban those users (and it feels like there is increasing legal/legislational tension to try and compel the tech giants to actually do something in this area). You cannot say the same about an indelible blockchain.
Anybody looking to build a tech ecosystem is looking to build vendor lock-in. There is no advantage to planning for decentralization, and no laws to force companies to adopt a decentralized approach.
It's a bit sad because it never started out as something intended for "make money fast" kind of investors. Bitcoin started as a way to free users from the centralised banks and regulation.
And if they cant do what banks already provide, what sort of "freedom" do they offer ? The ability not to have a retail account, the low hanging fruit of banking ?
This BS kneejerk 2008 crisis reaction Satoshi pretend to have had at the time, made him both one of the richest financial force in the world and the biggest financial risk (if he sells for some random reason just one btc from a genesis wallet of 1M BTC, what do you think will happen?). He became Maddoff...
Persona failed because it was fighting against a head-wind of an already established trend of using Google/FB OAuth2, without giving the service provider any new benefits. There was no incentive for a website to actually implement Persona, since it was just another auth provider and users weren't using it. Users didn't use it because no one implemented it. Chicken and egg.
Websites that integrate web3 wallet login do get something new: built-in, straightforward payment rails.
Is this really any better than Apple/Google pay? Those are already set up, trustworthy, I don't need to convert my fiat into a cryptocurrency than can swing in value wildly, and it's super easy to set up with stripe or any of the other platforms that the website is probably already using.
Clicking the "Connect My Wallet" button is kind of fun. But I feel like I've gained nothing over just using my credit card -- in fact my credit card provides me (as the consumer) tons more benefit than using ETH -- and don't get me started on gas fees!
One can imagine a world in which this is completely transparent to the end user.
High ETH gas fees are also being solved by Layer 2 solutions which get fees down to cents by either batching transactions or doing the work off the main chain and posting only the proofs to the main ETH chain. Checkout zero knowledge rollups, aka zk-rollups.
https://www.nytimes.com/2020/12/10/business/visa-mastercard-...
https://edition.cnn.com/2021/08/20/tech/onlyfans-explicit-co...
I'm not convinced it's that a large benefit.
For the foreseeable future, any website that aspires to be anything more than a niche web3 player will need to support web2 auth and web2 payments. So web3 is just adding layers, not removing them. Until web3 becomes powerful enough that you're losing customers because you aren't supporting it, there's no incentive to support it. (Exactly the same predicament Persona was in.)
Additionally, cryptocurrency is not practical as a currency right now because of high transaction fees and slow settlement. This situation won't change until layer 2 networks come of age, which seem to have been "just around the corner" for the past five years.
That's because you're not a merchant that has to deal with the monopoly of Visa/Mastercard which inflict high fees on your business and who at a moments notice can bankrupt your business by blocking all payments.
Companies that are built around "SIN" such as weed and porn have basically been strong-armed by this financial monopoly, to the point that Crypto is a welcome addition and which they offer big discounts to users who pay with it.
Additionally, cryptocurrency is not practical as a currency right now because of high transaction fees and slow settlement. This situation won't change until layer 2 networks come of age
There are plenty of L1 solutions like Solana and Avalanche which offer low txn fees and high TPS. L2 networks such as Polygon have already launched and are being used.
Visa and MasterCard don't have a duopoly on payment. They have a duopoly on “instant credit-card-based payment with charge back”, and Blockchain "tech" isn't competing in any of these features. If you don't need this and don't care about subpar UX, you can use bank transfers and still have a better solution than a blockchain-based one.
> high fees on your business
You think Visa fees are high? Blockchain transaction fees must look giagantic to you then…
Yeah. Crappy ones with high latency and high fees.
With super high fees, transfers that take litteral minutes to complete, no charge back and the ability to lose all the money yoy have if you ever get hacked. How exciting! Even bank transfer as a mean of payment is way better UX.
it has none now ;)
Everyone would be better off with better identity management, but it's not worth anyone's time to be one of the first users of a system with no sites supporting it or one of the first site supporting a system with no users. The web3 version of this will be something where if it takes off the first adopters get super rich at the expense of late adopters, and that makes it take off.
Similarly, conventional profit models incentivize the creators of a technology to make it as centralized and locked in as possible, so that they can profit off it over time. The pyramid scheme business model incentivizes the creators to make a decentralized and open system, so that they don't have to do any work over time once it takes off.
Is this the special kind of stupidity that only really smart people can aspire to, or the special kind of genius that only really stupid people can? Time will tell, I guess.
[1] ok most sites limit it to 2-3 options, but which 2-3 is up in the air.
But I don't use oAuth; while I was writing the code, I understood it, but I don't any more. An auth system needs to be understandable and transparent to a normal user, and oAuth is not such a system. Like, I couldn't explain it to my non-tech relatives, even if I swotted up on it first.
Explaining blockchain-based auth to a non-tech user is a problem of a much greater magnitude.
fwiw I agreee, but first to market is often first to fail.
Do we really need this? Do we really want to permanently tie identity across websites like this? I find this initial "need"/justification/requirement questionable.
I have a login on HN that is totally unique to e.g. Twitter and Instagram and <shudder> LinkedIn. Same with work vs personal. This is deliberate. I do not want to have the same identity here as I do elsewhere. There are many hopefully obvious reasons for this - mostly privacy (both in terms of immediate "in the moment" privacy, but also temporal privacy in the sense that I might not want some potentially ill-advised comments I made on some website 15 years ago to come back and bite me), but also it offers protections against "cancel culture" and general cyber-stalking and doxxing etc as that would become a whole lot easier if you can just run some query on a blockchain and find every single website I've ever used and dredge up my comments/content/etc. Being able to do that sounds very dystopian to me - why don't we just tattoo a barcode on our necks and be done with it?
You don't need to make any transactions or whatever, but you're inheriting all these tools for free.
There's nothing requiring a user to use the same identity across every service they interact with, but the option should be there. I wouldn't want my matrix username(s) and my fediverse account(s) tied to my HN username(s), but I might want a github/gitlab/codeberg account tied to a social/messaging account while having different "personas" for different applications. Overall it's a useful tool to have in your belt, so long as it doesn't limit you in other ways.
The argument seems to be that consistency allows you to prove ownership and re-use all of your content etc across the web by tying everything back to one verified identity. If you are having different identities on different sites then that benefit disappears, and I fail to see how it is then any better than using email addresses? You end up with different wallet IDs each with their own island of content, just like you have with email addresses.
Sure you could chose to "move" content with one of your many identities by just logging in with the ID (presumably losing all of your existing content), but we have copy-paste for that already (and I am only half-joking saying that...)
Either way though, I don't see how an account claiming to be "wan23" would be any more trustworthy to me as created off of the back of an email account or off of a wallet ID - I still have no idea (nor do I care) who you are.
This is also true of a private key, in fact it's literally the same scenario...
So what ? I am still struggling to understand what immediate and painful need users have with trusting Apple, Facebook, Google etc with their identity.
If people had some issue with this then users would simply not use OAuth and default to creating an account for each service they use.
It's not so immediate until you get banned, but they've all been gradually stepping up their politicised banwaves. And there's always the concern about what happens when one of them goes the way of Yahoo.
> If people had some issue with this then users would simply not use OAuth and default to creating an account for each service they use.
Which has huge practical headaches, to the point that OAuth being the least-bad option doesn't say a lot.
Using your Google account to log into everything is great....until your account gets locked.
https://www.pcmag.com/news/not-even-google-employees-can-unl...
Are you actually serious right now?
Do you really believe this? Plenty of people use services they don't particularly like because it's better than the alternative or they have an immediate need. I know lots of people who didn't want to use zoom but needed to, have a Facebook account to keep up with family even though they'd rather not, etc.
Plenty of people would love an option that works as easy as oauth but doesn't lock them to a FAANG provider. Just because they use it when there's not another option doesn't mean they wouldn't use another option if it existed.
And again, with these web3 identities, centralized services would still be providing the authorization even if they did not provide the authentication. I don't see what web3 identities provide.
Mostly what I care about is logins and payments which are addressed by password managers and form filling for credit cards. I just want a friction free experience for setting up an account, logging back into it, and maybe purchasing something.
And ideally I'd like to self-host, maybe with a service that looked like a NAS appliance hanging off a guest network on my router with a forwarded port through the firewall and some method for tracking my IP address (dyndns or similarish).
And ideally payments happen by a handshake between the service I run, the processor and the merchant in a way that my actual credit card details are never used. And for recurring payments I have the ability to just switch them off. Bringing all the control back to me and not leaking out reusable PII everywhere.
Of course corporations would aggressively hate that since it would destroy their business models of recurring payments for services the user is no longer using and the requirement of calling up the business and having to convince some phone operator that you really want to cancel.
Your comment just gave me a thought - just imagine the online advertisers using this for tracking purposes!
At the risk of spreading FUD, it would not surprise me to learn that perhaps this web3 thing is being fuelled/funded by the existing crop of online advertising networks or their close associates? (or at the very least they are watching this situation develop with an incredibly close level of detail)
Who needs cookies if you have a 100% reliable & long-lived (potentially immortal?) ID that the user takes with them everywhere they go online (and is the same on every site they visit) and for every purchase they make (using that wallet) online and offline?
This would be advertising networks' absolute dream situation if it becomes widespread - users voluntarily creating their own unique tracking fingerprint and using it on all the sites they visit, as well as helpfully logging all of their purchases they make with that ID on a public ledger that anyone can mine the data from.
It really does not get much better for the online advertising industry than that.
If you want a cynical take on web3 and are looking for your next billion dollar startup idea, then web3 ad tracking & targeting might be your best bet :)
Hardly FUD, of course these companies are watching. They have more cash than they know what to do with. They will acquire anything that even remotely takes off (even by the low standards of crypto).
Google acquired their way into all of their major businesses. None of the following were built by them:
- Google Ads (DoubleClick, acquired 2005)
- Google Analytics (Urchin, 2004)
- Youtube (acquired 2005)
- Android (also 2005)
The dates are off the top of my head, so I could be off by a year or two.
The author makes a bunch of silly assumptions:
> We need some way of saying “who we are” on the internet in a consistent manner. That way we can communicate with others in a verified way and associate with digital data that we own. We also often need that data to be interoperable between different web properties.
No, this is not true. That's why most people on this site are not logging in through Google. Sites will store their own data, and if you trust them to store that data there’s really no reason to just trust them to store a link to your identity.
The author advocates third parties like Metamask and using a Chrome extension, which is ridiculous. If you're going to trust that, why not trust Microsoft, or Amazon, or Google?
> With social recovery, instead of having to trust Google, you can choose who you trust, and instead trust a given set of friends, family, and services
Yes, because Google is not a service.
Ultimately the author makes up a problem and says blockchain is the solution.
Even if we suppose it's a solution there's no discussion around phishing, stolen identities, or any failure mode really. Of course there isn't though - in general recourse requires an authority. Blockchain has none.
Private keys are portable between wallets.
In fact, if you believe in privacy at all you’d want to reject this idea for that alone.
An antidote to that would be using a different key on each site you authenticate to. You still only need to store a single key, all other keys are derived from that yet cannot be associated with their sibling keys.
> What you’re saying is also trust with web3.
Not quite sure what you mean here, web3 is a pretty overloaded term. If you mean the very concept of web3..that's pretty fundamentally different from trusting a company that can unilaterally ban you, alter your data etc. There is no such parallel in web3. If you mean the JS library, that's also fundamentally different, and it's not the only game in town.
The author advocates using third party services such as meta mask, who would need to be trusted.
How do you implement it without any third party site.
If we are talking about likelihood it’s unlike you’d be banned from Microsoft/Facebook/Google for no reason too.
Furthermore as the administrator how you stop bad actors?
> If we are talking about likelihood it’s unlike you’d be banned from Microsoft/Facebook/Google for no reason too.
I've seen posts on this forum about it. It happens and there's not much you can do if it does.
> you could also create a new Google account per website or simply use an email address.
> Furthermore as the administrator how you stop bad actors?
Apologies if I'm missing something, if it's easy to spin up unique identities on both what's the difference here? It seems like it would be one or the other.
And yes you can create a new Google account per website, but you are still at Google's mercy to authenticate. My 1Password has ~250 logins, I'd be seriously worried about a ban from Google if I made 250 accounts.
Yes except for a centralized entity the admin would have recourse. How does a web server admin deal with it in the case of blockchain?
> I've seen posts on this forum about it. It happens and there's not much you can do if it does.
If we are talking about anecdotes I’ve seen people lose their private keys to phishing and consequently all of their money, so…
> You have to trust MetaMask to some extent, like any software you run locally, but MetaMask never gains control of your keys or identities, it's just a tool for using them (obviously 99.9% of users aren't auditing the code or building from source, but that's a totally different threat model). If MetaMask stops working for you, you can use a different tool with the same keys. If Google stops working for you you cannot transfer your account to Microsoft or Facebook.
This is not true, depending on implementation. Even if we accept what you’re saying as true you can run your own oauth server.
Basically it seems the entirety of your argument rests upon trusting a centralized service. However the scenarios posited by the author are ones where blockchain is used to login to a centralized service to begin with so I don’t understand the criticism. Furthermore, unless one is to accept the infinite possibility and quantity of accounts, inevitably just like most other identity services, blacklists will be created.
If that is not effective then blockchain will simply not be an option for most sites.
Ultimately this convoluted web3 is no better than using an email address forwarder and a regular email and password.
Can you be more specific? How is it easier to sniff out a user using multiple emails vs multiple keys?
> If we are talking about anecdotes I’ve seen people lose their private keys to phishing and consequently all of their money, so…
Losing your keys is a huge problem that needs to be solved. I think social recovery is super promising in that respect but you're right that we aren't there yet. Phishing exists in both worlds, although I'd argue for logins specifically it's less of an issue in the MetaMask world, as you do not need to expose your private keys for that. You need to expose your password to log into Google.
> This is not true, depending on implementation. Even if we accept what you’re saying as true you can run your own oauth server.
Which part isn't true?
There is..some difficulty gap between a browser extension and running your own authentication infra..
If someone made 2109@gmail.com 238@gmail.com 2398@gmail.com you could contact Google, send them the information and potentially block all of them collectively and/or find the person responsible. This would be important if your application has to do with financial activity. How would you do this if someone kept making random private keys?
> I'd argue for logins specifically it's less of an issue in the MetaMask world, as you do not need to expose your private keys for that. You need to expose your password to log into Google.
I'm not understanding you. If you're someone who won't use Google, or a centralized service, then you are capable of hosting your own web server. If you're capable of that an email address + password is superior to blockchain and gives you more control.
If you're not capable of that and are using centralized services for things like email then you lose no more control using their oauth server.
You and author have yet to address failure modes, or the superiority of this compared to email and password.
Citation needed, I very much doubt Google would comply without a search warrant. For financial activity, it depends whether the application requires authentication, or simply funds. For authentication see things like DECO, where you could prove some personal information about yourself without actually revealing that information (SSN for example). Obviously that is piggy backing off of a legacy system; it's up to the application to say what data they need.
> I'm not understanding you. If you're someone who won't use Google, or a centralized service, then you are capable of hosting your own web server. If you're capable of that an email address + password is superior to blockchain and gives you more control.
You are completely wrong that everyone currently using MetaMask is capable of hosting their own web server. Securely hosting a web server is orders of magnitude harder than securely using MetaMask.
I think I did address both failure modes and the benefits. I agree with you that it's not ready to replace email and password, but I don't think the issues are insurmountable either.
There's plenty of evidence out there for this (https://www.jamesmadison.org/the-governments-secret-google-s...). Furthermore Google has a contact to official subpoena them if you want (https://support.google.com/faqs/answer/6151275?hl=en). For mild things you could just report abuse and escalate - https://support.google.com/mail/contact/abuse?hl=en
Again, you're not answering the question. What does the web administrator do if someone is creating fake accounts using a private key? If you're going to use third party systems you don't need blockchain to begin with.
> You are completely wrong that everyone currently using MetaMask is capable of hosting their own web server. Securely hosting a web server is orders of magnitude harder than securely using MetaMask.
You're addressing a claim I didn't make. I'm not sayin everyone using metamask can host their own server, I'm saying someone who isn't using a centralized entity anywhere can do it, by definition. Hosting a web server is trivial in 2022. You can literally setup a server by going to digitalocean.com right now, paying $5, and spinning up a one-click machine. Administrating it at scale is obviously more difficult, but it's trivial to setup a little oAuth server if you want.
You are completely moving the goalposts, I thought we were talking about internet services trying to prevent spam..not government snooping and subpoenas. Are you claiming the government's ability to collect data about you from Google is a good thing? I'm pretty confused.
> Again, you're not answering the question. What does the web administrator do if someone is creating fake accounts using a private key? If you're going to use third party systems you don't need blockchain to begin with.
You are not answering the question either, is this web administrator the government? Are they going to serve Google with a subpoena?
> I'm not sayin everyone using metamask can host their own server, I'm saying someone who isn't using a centralized entity anywhere can do it, by definition.
Ok fair enough, I'm not saying anybody will be using "no centralized entity anywhere", not totally sure what your point is. Using a centralized entity for A is equivalent to using it for A+B?
good luck
I feel like you are intentionally ignoring the dangers of SSO tied to a company that can unilaterally delete your account, and has little incentive to unlock it or even let you plead your case.
Cheers.
I feel like you are intentionally ignoring the dangers of crossing a road where there is a higher probability of dying than a FAANGM deleting your account.
Account deletion is not the only risk, it's also privacy (Google knows what you sign into and when) and a myriad other advantages (native payments being the obvious one).
> I lost access to my Google account because I was away too long, and therefore all the accounts it was tied to.
Wouldn't there be a common, shared list of malicious wallets that can be automatically blocked?
Ublock Origin doesn't update its ad domains list itself, it relies on a number of lists that other people have created. I've never had to lift a finger ever since I installed UBO.
And even if it is a problem you can always reach out to the website and get them involved in moving your account to a different provider.
You're missing the point. Yes, we don't need oAuth to log into HN. But HN is a site that is over 15 years old, and reflects the technology of its time. Instead, look at the companies YC funds and ask yourself how many of them DON'T have oAuth/SSO of some kind. Reddit is roughly HN's age, and you can see that with the introduction of VC money and profit goals, they've shifted towards discouraging anonymous logins. My 10-year old Reddit account doesn't even have an email associated with it; I doubt that's allowed now.
The old web made by hobbyists having fun and not trying to sell anything is long gone. Even sites like HN are disappearing, and everything IS being monetized, whether we like it or not.
It is. You have to hit next when prompted to enter an email address when registering (the input is not required)
Even if HN used oAuth - even if they required oAuth - ultimately oAuth, oAuth as implemented on most sites is just a thin layer over email so you don't have to make another account.
The problem doesn't require blockchain as a solution. What would the website administrator gain from accepting a blockchain login? People would create accounts but you have no way of contacting them since you have no email. Clearly the kinds of sites you're describing wouldn't accept that.
OK so you associate an email with your blockchain login - so now it's the same as the status quo. What's the point?
And what, you think they'll be okay with anonymous users if those users log in with web3?
Reddit wants users to be somewhat identifiable in order to play to advertisers. However if people start buying and selling goods on Reddit itself (e.g. subscriptions to private subreddits), the company wouldn't have to rely as heavily on advertising.
Arguing that "web3" will help because it will improve UX is ludicrous. "web3" provides nothing directly to boost UX. "web3 hype means there's lots of money sloshing around which can be used to improve UX" is an admission of defeat; all the money being sucked into the crypto space could be better deployed to solve these problems directly.
If this is the best shot at "real problems web3 solves", then there really is nothing there :-(.
Also, I find it funny whenever someone says something like "web3 doesn't actually solve anything that hasn't been solved by other technologies like X". Then why isn't anyone using X? Why is nobody using Persona or Webauthn despite being "superior"?
The statement that web3 doesn't solve anything which hasn't already been solved wrt authentication... is about as close to a true statement as one can make.
Sorry, there are plenty of standard ways to make logins seamless without a Blockchain.
Persona failed for various reasons. Big companies didn't want to offer Persona logins because they wanted to control the user relationship, especially the barrier to getting an account, and were unwilling to delegate that to arbitrary third parties. There was also a chicken-and-egg problem: not many sites accepted Persona logins, so not many people bothered to sign up to Persona, so not many sites bothered to accept Persona logins. This latter problem could have perhaps been solved if Mozilla had worked harder to integrate Persona into Firefox, but mistakes were made.
For Webauthn, AFAIK it's mainly an implementation issue on the server side. Maybe not enough people have the required secure tokens, on some platforms.
Obviously, blockchains and smart contracts don't help with any of the above issues.
I find it funny that you do not detect the irony in what you just said.
For every website I can just press TouchID once, it will auto complete my credentials and click the login button for me. I can't see how web3 could possibly be faster.
Plus I can still access that website on any device e.g. public or work computer without needing to worry if I can install a Chrome plugin.
So much of the web3 discourse involves the same two tropes:
1) "If you ignore the hard parts and only focus on the easy parts, then it looks much easier"
2) Ignoring the fact that regular old solutions are actually even more streamlined. It's not like web3 invented the concept of storing credentials and auto-filling forms. These are basic features used by hundreds of millions of end-users on a daily basis. It takes mountains of effort to get web3 just to almost reach UX parity with what we already have.
The only way web3 can feel like a better UX is if you haven't bothered to try any recent UX advancements in regular, non-web3 technologies.
Because the use case itself is flawed and niche? I don't really want my entire digital life and spending history linked and especially not on a public ledger.
The world is still old school.
Grandpa dies and I go find the paper will.
I get an affidavit from a lawyer and a death certificate with a seal from the state.
I go into the bank with a bunch of papers and they figure out what to do.
There isn't a chain of trust that the state uploads a PK signed death certificate to, which in conjunction with a PK signed 'will and trust' then triggers a preexisting blockchain contract to effect the asset transfer.
This is 20 or 30 years off. Maybe 10 or 15 in China.
My hot-take parallel argument is that full self driving is a smart road problem with 'dumber' cars and not a dumb road and smart cars problem. But there's no scope to VC of profit your way into smart road infrastructure so we do it the wrong way round and hope we can throw resources at it till its fixed.
https://docs.digdir.no/idporten_overordnet.html
https://www.altinn.no/hjelp/innlogging/id-portenminidbankid/
Some very few non-digital government services remain, unfortunately, and it seems like the storage of wills is one of them. Asset transfer is still going to remain a manual process though, even when digital wills are here, thankfully.
Not a problem web3 can solve either. Social Security Numbers aren't secure, but we keep using them everywhere because the political will to implement a better solution doesn't exist.
Additional example: I need to pay property taxes on my mother's house in New Jersey. I'm physically on the other side of the planet. While the town has a website, it's pretty much just a phone directory. I have to call them every 3 months, usually when it's 2-3am in my timezone, ask them what the property taxes are assuming I pay them by {$date}, and then mail them checks. I can't even do something as simple as enter the property lot number in a search field on their site, have it look up the outstanding taxes, and then just pay with a VISA card.
The Federal government SHOULD be able to force certain things in the name of "regulating interstate commerce". I would think that data standards and APIs would have efficiencies at scale that would reduce friction in inter-state transactions.
I work for a bank and it has nothing to do with being old school. We use exactly the same technologies as any modern startup would e.g. Serverless, Kubernetes, Cloud etc and deploy into Production with blue/green releases every week.
It's just that the user experience of our entire customer base comes first. And whilst everyone "gets" usernames, passwords, PINs, TouchID, FaceID etc they really don't understand OAuth and other federated identity approaches. Like what Google or Amazon has to do with my finances and why I have to visit their site to reset my password.
People thinking that Web3 is going to solve this problem really don't understand that it isn't a problem that needs solving.
> Problem #1: Owning Your Own Digital Identity & Fixing Authentication
My very technical friends who are security minded are on keybase.io. Multiple usernames and passwords across the internet is solved in various ways without blockchain. There are a lot of good password managers (I use and encrypted text file.) I don't feel Google owns my identity because I use their authentication system, so unless I'm missing something, I don't see a problem.
> enables advanced features like social recovery, which lets you recover your account if you lose your key via a smart contract that takes votes from guardians (friends or paid services).
> The idea here is that you could give keys to your friends and family, or to some sort of business service, then if you lose your key, use your friends to “vouch” for you and move the account to a new key.
This doesn't seem very workable in a practical sense. It seems like this could be spoofed fairly easily or the business service gets hacked
Apple finally implemented a solution in iOS 15 (15.1?). You can designate people you trust to be able to help recover your account. Like your spouse or a sibling. If they don’t have full access, they can just help recover it.
You are 100% right. A single point of failure without any chance of recovery is a complete disaster for normal users.
Facebook already has this functionality and it's an absolutely massive pain if you're somehow not on their happy path. With no real way to figure out what the issue is and get it fixed or on the happy path.
You could give keys to two businesses / people and require them both to agree before they can "unlock" the account. You could also add a timelock, so you have time to respond if they get hacked or collude against you.
These aren't really new ideas and exist in existing, non-crypto social recovery schemes.
Let's say you give a key to a business and that business gets hacked. That's fine because a single key can't steal your wallet and you have 8 keys left. You can even invalidate the keys and generate 9 new ones.
Web 1.0: Great
Web 2.0: Ugh, ok
Web 3.0: You're serious with this?
Do you know what site that was? I don’t. I can’t remember. I think the password may be in my password manager, but I’m not sure. I’d have to go digging.
But I am SURE I’ll remember which of the 1200 common block chains I use for my credentials.
The solution is that there should only be one or two chains that everyone uses. Then there’s only one or two little icons you need.
The people who run the trains could make sure they keep running by having tens of thousands of computers. Of course that cost money. Luckily they get money out of the block chain because they can spend coins.
Of course users don’t really like buying things. Maybe it wouldn’t be too hard to put an ad or two in there to pay for things.
The easiest thing to get users on board is to use brands they trust. No normal person is going to trust everything they have two the Kakarot blockchain with an anime superhero for a logo.
Do you know who people trust? Facebook and Google. If they were to…
Oops. I invented today. Only with much more energy use.
To then attach all kinds of good qualities to it that are not shown, nor proven, and often demonstrable incorrect just finishes it off.
As you say, a lot of the bigger ideas claimed to be part of this "new" web3 thing aren't new, and are interesting ideas that should be further explored, it would be much better without the ponzi sauce.
(Just like IPv5 never got anywhere ??)
We might as well also try the HTML approach, attach some letters (DWeb, XWeb) then once we all regain our sanity continue with web 4.0
.... or it ends up that everyone just logs in using an ethereum wallet and you're back to centralisation.
That "Web 3.0 login" portion of the slide only makes that problem worse. Decentralization and a variety of choices absolutely fall apart when they meet non-tech users who have no idea what icon means what.
I already have this problem with Matrix/Element all the time. Not only do I forget my username and/or password on networks I've been logged into for months, I also forget homeserver addresses and all these other settings I had to set up at some point. Every time I get logged out of something, it takes a day or two to figure out how to get back in.
Web3 is indeed a social solution to this social problem, but the real problem with Web3 is that it's a terrible social solution. Web3 (aka blockchain enthusiasts, aka cryptobros) is a community comprised of on one end by true believers who believe they're smarter than anyone else in the room and that anyone who brings up complaints are only mad because they didn't get in when the cryptocoin was cheap, and on the other end by grifters and scammers who fully acknowledge that they're only in it for a quick buck off the back of unsuspecting rubes.
This is the core problem with most crypto projects. Most blockchain projects have technical problems [0], but even for the few things that blockchain uniquely solves [1] the general scummyness of everyone involved means that anyone advertising they're solving problems with a blockchain is not someone to trust your money with [2].
Of course, the blockchain isn't the only technology to suffer this problem. Blockchain's at the top of the hype cycle right now so of course it's filled with scammers. But even though Pets.com may not have the most competent business, the technology behind ecommerce was generally sound. Blockchain on the other hand has so few useful niches that the only thing left are the hype-men.
[0] Eg you could use NFTs to prove ownership of IRL property, but why? You're just storing a deed in a different place. It used to be in a SQL server somewhere, now it's on a blockchain instead.
[1] That is, decentralized databases where you don't trust all parties not to modify the data. But uh, with whom do you need to share data that you don't trust, and how do you guarantee they're not just feeding false data into it in the first place?
[2] I'm not implying all blockchain enthusiasts are pretentious and/or scammers. Just that there's a much higher proportion of them in the Web3 community than elsewhere.
Technically "independent" SSO providers and similar existed, but non made it mainstream because there was no reason for App's to support them, but there was cost to support them.
There is even less reason IMHO for most App's to support Web3 login (more complexity).
Furthermore even if they do the web3 login would probably still list Google etc. as the web2 login still lists email.
It's questionable that more than one maybe two blockchains will be supported.
It's likely that often only a small number of wallets will be supported, it's also likely that "bigtech" companies like google will provide web3 logins if it becomes successful.
So, it might happen. But I don't see it tbh.
There is just no reason to go the extra length to support web3 login for most Apps/Companies.
EDIT: Also trust of the general public into anything containing the word "crypto" or "blockchain" is constantly undermined by an endless slew of scams, and money grabbing schemes. Which can hurt adoption of web3 login.
You don't really need a blockchain unless you need to keep data on a blockchain. To login and identify a user you can simply sign a message. I consider the address as the user "identity". Any blockchain data related to that address is mean to be public (some people register <some-name>.eth on the ENS for example)
If it’s just cryptographically signing things we’ve had that ability since PGP came out.
The reason is the UX/UI flow, complexity for integrating them and users which already have it.
So if all people have a wallet at some point which they also can use for SSO that might get adoption.
Through for investment into crypto, instead of "daily using it" you probably don't want a hot walled on your phone.
So as long as "daily/frequent/casual crypto usage" doesn't become a supper common thing for large parts of the society (in the "western" world) it's hard for it to gain wide spread adoption I think.
With social Web 2.0 login, I can be fairly sure the person logging in has a valid email address, a name, etc, and it is a single click for the user vs filling in all the info all over again.
With a Web3 login, it is basically the same. Except I'm not really given any personal info like name or email, so I need ask them for that anyway. I guess you can tie that into your wallet somehow?
But I don't see this as a 10x solution. Do people really not trust FB/Google/Twitter that much? Why does currency and money need to get involved?
But in another world, isn't this the problem Keybase was trying to solve? Of course, they got mixed up in their own cryptocurrency as well (XLM) which had so many issues with bots trying to get into the airdrop. So idk.
I know some people (especially us techies) like to control the whole stack but who do you think the majority of normal users would prefer?
Apple has a closed platform mindset, I hope users will see the benefits in a decentralized open protocol.
See I think this here is the biggest issue. I feel like we have 30+ years of proof that normal users LIKE centralization for the convenience and ease it provides.
Email is basically the last man standing when it comes to distributed implementations and 1) it had reached mass adoption early enough to survive and 2) we’ve centralized it to a large degree anyway with Gmail and outlook.com
People in general or HN audience?
> Why does currency and money need to get involved?
It doesn't. You only need a blockchain to keep public data. You can sign a message and login with that, no need to send a transaction, can be done with balance 0
why do you twist "owning your identity" to mean putting everything about you "somewhere public" (like a blockchain)
Correct me if I'm wrong, but the only new idea here is to use a ledger to hold public keys associated with an identity. You could add keys by signing a new key with one of the previously globally accepted ones proving you are that entity and the same would go for removing a lost one, by signing a new message with all the remaining keys.
Having a key copied without your knowledge would be a major disaster, however.
Apart from that, this is not very different from using keys in SSH and providing a challenge/response login form would be very simple.
What everyone seems to be missing is that the web3 apps and UI conventions already have broad adoption among millions of only mildly techy users. They don't know what SSH is but they do know how to sign things with their in-browser wallet app. Of course, they also seem to not always know that giving away your private keys is quite bad...
But any "solution" that requires e.g. using the terminal is not really competing in the same space.
The UI required for that is something that can be done in a couple minutes. The heavy lifting is done by libraries provided with the OS.
Yet, crypto wallets remain the only cryptographic signature UI that normal people interact with.
Ease of use is EVERYTHING.
At no point does anything described about how web3 works or solves problems sound easier to use than the current system. Logging in with email and a password is easy. Using a Google to sign in is even easier. Apple’s sign in system is ridiculously simple and frictionless.
“Start by finding a chain you like and creating a wallet” is not easy. Do you have to buy coins on the chain? I’ve been seeing a lot of these web3 articles and I truly don’t know. Buying coins is another huge hassle.
“Oh but they’ll already have a wallet.” How? At some point they have to create them. Even if it was easier once they’ve created it (which I dispute), how is that supposed to happen?
If you have an iPhone, you have an Apple account, can do sign in with Apple trivially. If you have an android phone, you have a Google account, you can do sign in with Google trivially. Either way you have an email address, that’s quite easy.
How can you EVER make something simpler than those? I think best case scenario you would be able to match them.
But then you’re back to the problem of why I should switch to the new thing when the current thing works just as well.
I just have a very hard time seeing normal users ever buy into any of this.
If a huge number of people were using cryptocurrency to pay for things every day, I would agree with you. But I think a huge number of people just make one purchase and then sit. What percent of them could actually make a purchase without having to go look up how to do it?
Also, the ledger doesn't have to be public.
This is how JWTs and many other protocols ensure message authenticity.
Nobody can claim to have your private key, but they can sure as hell claim to be you.
We won't know who the real numtel ever is without some real-world proof and verification. This is where a lot of this crypto-based stuff starts to crumble: sure the mathematics of the cryptography works well on chain, but there is a very limited set of things that exist 100% purely on the blockchain - as soon as you need to go off of the blockchain for anything (e.g. proving human identity, proving ownership of a physical asset like a house etc) then you're back to the same old problems we've always had of having to prove identity/ownership/whatever, and you cant use a cryptographic hash to prove that I own the apple I am eating right now ... perhaps you can prove that I own an apple, but can you prove I own this apple?
A non public ledger would be something agreed upon by participants only. So you and I and 5 other people for example could run some type of organization using some private way to keep track of state. You choose to trust it, if you don't, then don't use it.
In a private system, you just need consensus among participants, potentially in an adversarial environment, but decidedly not a permissionless environment. As long as state can be kept, depending on the constraints of the system any sort of consensus and canonical state keeping mechanism would work. Could be a blockchain or something resembling one, could just be a document and it's hash kept by all participants and updated when the participants agree to a change. How complex you make consensus in a permissioned system depends on the goals and constraints of the system.
>Every Git clone is a full-fledged repository with complete history and full revision tracking capabilities, not dependent on network access or a central server...
http://web.archive.org/web/20080821113906/http://git-scm.com...
Sure git can be used without the need to have have a central server, but everything became so much simpler with github and other code repositories.
Decentralized systems are hard to navigate and humans will choose the easy thing every time.
me < To Ty's app + whatever they can get away with.
me + apple > To Ty's app.
The only thing blockchain would add is a gas fee whenever I would log in somewhere, and would keep the same UX problems I'd have with login anywhere else.
Keep in mind the most successful project EVER in managing identity was let's encrypt. A centralized non-profit that got the internet to use https everywhere by signing ssl certificates and vouching for everyone's server for free, and as far as I can tell without collecting any personal data about anyone. Web3 is going to solve "this" (whatever this is)... Riiight.
Also article: to use it, you need to trust a centralized entity like Metamask that develops your Chrome extension and some unknown programmers that code some "smart contracts" aka unverifiable code in esoteric programming languages.
Also article: look! a solution! it's better!
Unless, of course, you are a programmer yourself and can implement that "decentralized auth smart contract" from scratch
The quote from Vitalik is great though - the goal of crypto is to let people make all the same mistakes and find out single central authorities actually have been established for a reason.
Coinbase is a nice example; turns out it's quite nice if some sort of company protects your money, makes sure you don't loose access to it, provides you with insurance in case something goes wrong, and lets you easily send, trade, and convert money. Such a revolutionary idea, right?
I believe this guy is being intellectually honest (which is a feeling I don’t get often in this space) but I don’t think he’s capable of asking the right questions.
The question that should be asked is what is a problem we (humans) have that is not only solved by this new tech, but can’t in any way even by bending over backwards be solved with some other technology?
The point about financial incentives aligning more easily in web3 is good, but I understood that even the poster child Metamask is not complete as it's missing good social recovery UX.
Please stop trying to sell snake oil.
This is progress?
It's absurd how HN users in general are so dismissive of anything cryptocurrency
It's absurd how HN users in general are so dismissive of anything cryptocurrency.
It's quite reasonable actually, given the prevalence of not just hype, but frequently delusional / just plain rambling and incoherent hype surrounding it -- not to mention blatant fraud and manipulation aimed specifically at unsophisticated users.
And the skivviness of many people involved in it.
That said, the OP presents one of the more thoughtful proposals I've read recently, and may belong to the 5 percent or so of blockchain applications that just might have a useful application. With emphasis on "just might".
We'll see.
I agree with you on this. For the purpose of login in with a private key, i would prefer some browser extension (or built in the browser) that generates a key from a seed (like a crypto wallet) and only does that. This doesn't exist at this point.
> ... not to mention blatant fraud and manipulation aimed specifically and unsophisticated users
Also agree, but probably for different reasons. Many people on twitter have the tendency to be mean, twitter doesn't make people mean, but it amplifies it. There is so many scams and manipulation because scammers and con artists always existed and people's greed for that 100x token and so does the scamming
The speed of communication that the internet gave us also serves as an amplifier of the ugliness of human nature
What about https://www.yubico.com/products/yubikey-5-overview/ or https://cloud.google.com/titan-security-key/ or https://krypt.co/ (before it was acquired, I still use it though) or any of it's equivalents?
my issue with using a physical device is that it detracts adoption if there is no other alternative. a browser extension or built-in helps adoption and adoption probably increases the number of people using physical devices.
Various authentication schemes have used digital signatures...on the web... for decades at this point.
It shows up as a marketing trick because it obviously means something very specific for that crowd and it is explained somewhere with a fine print.
I will stay with a thought that trust is not something that can be solved by technology :)
>You can also do this to require approval from your friends before a certain amount of money moves out of your account, making theft significantly harder.
Okay, what if your relationship with those people changes? If you've lost your key or its destroyed (maybe as a result of those relationships changing before you've had a chance to do anything), presumably you can't remove the trust relationship with your former friends. You then can't withdraw unless your new enemies say so, and you can't change that trust relationship.
Plus what are the rules around removing the withdrawal limit? If I can just remove it at any time, how's that going to prevent theft, as I can just remove the limit before the theft?
This is now yet another security consideration for regular users. In addition to ensuring your key is backed up, you have to think about contingencies for if/when these trust relationships change.
But flip this feature on its head and give your bank this trust, and at least you have the same resiliency as your current bank account. Ironically, you likely want to trust a large entity with vast resources (presumably too big to fail) instead of friends and family if you're looking to be secure against loss of your private key.
"Some of you might already be familiar with multisig, which is a similar concept... The idea here is that you could give keys to your friends and family, or to some sort of business service, then if you lose your key, use your friends to “vouch” for you and move the account to a new key. ... With social recovery, instead of having to trust Google, you can choose who you trust, and instead trust a given set of friends, family, and services. If you ever lose access to your private key, there is a smart contract encoded on the blockchain that syas that if some number of your guardians all agree (you pick the number) then you can move your account to a new private key."
I didn't see anything about Google being a requirement for multisig, so I'll skip the author's aside and ask, "How are these two things different?" Multisig lets friends "vouch" for us to move our account to a new key and social recovery lets friends "agree" to let us move our account to a new key.
These sound exactly the same to me?
The original writeup says something about "multisig moves the burden down to the user to issue keys" etc., but setting up smart contracts would still require someone to do some kind of setup work. Those contracts aren't just going to magically appear out of nothing; at the very least you'll have to select your friends, get their agreement, and a contract would have to be issued and signed.
I dunno, I still fail to "get it" (this is not an invitation to try and help me "get it", as helping people "get it" is kind of the point of the original blog post)
For better or worse, there are a large (and ever growing) number of Metamask users these days...
The point still is that logging in with public-key cryptography is not exclusively a technology supported by cryptowallets.
I would argue that the biggest successes of crypto are selling GPUs and facilitating malware ransom payments.
GPUs have sold like crazy and you are lucky to get a high end one with the current demand. Everybody and their pets are running mining rigs. Good luck getting a nice GPU for machine learning or graphics rendering.
Previously malware authors had to rely on gift cards or similar means to get paid. Now they have variety of cryptocurrencies to choose from and they can even trade cryptocurrencies to launder the paid ransom funds.
Is it? U2F is actually rolling out to more and more websites but I've never seen any website offer to log in with a dropdown for cryptocurrencies
It’s literally titled “ Real Problems That Web3 Solves, Part 1”
[0] https://en.wikipedia.org/wiki/IndieAuth and https://indieweb.org/IndieAuth
[0] Except for OAuth since OAuth provider could ban you at any time.
[1] Until it's encrypted with your own public key and isn't stored anywhere in plaintext. Which can't be 100% guaranteed with any proprietary 3rd party service.
This definitely has me thinking more about the extent to which the strength of a particular identity representation is determined by our willingness to bind artifacts of value to it.
One of the great things about usernames/passwords is it didn't demand that vulnerability - you could come up with whatever and it was your responsibility to keep up with your shit. Systems that mimic real world systems on average feel less prone to this silliness.
If not, then it seems to be a superior method and experience. You don't have to deal with usernames/email/password, and it offers more functionality with currency.
The only way anyone can gain control of your wallet is if you give them your private key (or the seed to the privk) or if your PC is compromised (but you have bigger issues then)
Technology won't fix greed which drives business.
As in potentially link your income to every site you want access to?
If I wanted to do micro transactions, and let everyone drain my bank account, I'd not have 2fa on, use my real name, address DoB for things.
Can’t wait for my reddit or meta tokens which have a zero value.
In the real world I might have a physical key (or some other interesting object) - there is exactly one of it and it exists in exactly one place (though of course I can create copies - but they are new objects).
In the virtual world this is a bit harder to construct and enforce - information is entirely ephemeral, and has no concrete existence or place. Maybe blockchain can provide that (in the context of the chain only of course).
Better to give one or more nonprofits the job, have them manage identities and do nothing else. No energy-sucking blockchain needed.
The cryptocurrency and decentralization are possible because some people believe and live on those ideas. For those who don't care, bitcoin is $0 or worse: a Ponzi scheme. For those who believe in it, the goal is to own one's id, data and money, and collaborate without a big company or a central government.
Client cert auth has been available for decades. There was never a need for centralized login.
It’s a one-liner in Apache with mod-ssl, and here’s a random google result showing the entire thing in a few lines of standard library python: https://gist.github.com/nebulak/6d865ddd768fb905a562d6026cdd...
Do any mainstream sites let you log in that way? Any plans for Metamask login on HN?
After reading this article it seems that the most useful thing someone has thought to use the blockchain for is [checks notes] a form of social media popularity contest to recover the key to your blockchain wallet.
The article suggests, you should let a network vouch for u instead of a corporation. By doing this you gain “ownership”
You only “own” something when you can create, destroy and erase all signs of its existence at will.
Explain how you do this with Web3.
What gives?
There is a different group here on HM that REALLY hates it all. It was interesting technologically but then it started producing more CO2 and using more energy than reasonably sized countries. It also seems to be the method du jour for scammers to take money from people. It’s almost single handedly enabled the ransomware industry.
And people like to shit on the current hot thing, deservedly or not.
So here we are.
I visit other sites where I can honestly say their users are honestly ignorant, given their lack of technical understanding. But here? This is sad to watch. If crypto/blockchain/web3 continues the current trajectory (or bitcoin goes to 100K), it will be worse, because the proud/bitter HN user will never admit to themselves that others can "get it" even though "I didn't get it".
I think the almost religious zeal makes it much worse. People win the lottery but they don’t claim to be geniuses or representatives of a shining new utopia for it. They just say they won the lottery.
The article doesn’t show any problem solved by web3 tech that existing solutions can address much better.
If my email account is phished or hacked, it's bad, but there's a level between my cash and my email account. If I make a mistake here, potential losses are higher. In which case I'd probably have a 2nd wallet for auth and another I actually use, which then becomes more of a pain. I don't trust my parents or less technical relatives to use this flow safely.
> Many people, including myself, believe that the individual should be able to own their own identity.
Yes, this is nice wishful thinking, but on a global scale it's not really possible or feasible.
> OAuth2 should be used for what it was intended to, which is for a web service to provide another web service with a user’s data given that user’s consent. It should not be used as a global digital identifier because that’s too important to be owned by anyone but the individual themselves.
So, instead of OAuth being in the hands of FAANG[1] it's in the hands of ${blockchain-of-the-year}? How does moving the trust from a centralized company to a centralized blockchain change MY ownership? If I move everything away from FAANG to someone's blockchain, I have no assurance that chain will continue existing. If there's a flaw found in it and everyone moves to another chain, now what? Sure, we can make the same claim about FAANG not continuing to exist, but the point is there's no inherent advantage here, they're equal. FAANG are supported by millions of individuals and companies that are all, together invested in their success. There's no unilateral agreement on blockchains and I doubt there ever will be.
>With social recovery, instead of having to trust Google, you can choose who you trust, and instead trust a given set of friends, family, and services.
Again with the trust this and not that. All of my friends, family and other services need to then agree that they're all going to trust ${chain} instead of FAANG. It doesn't fix the problem. "the blockchain" isn't just one thing. Who's chain do we all shift trust to and from and based on what security? At least with Google I can rely on their security because if they end up with a breach of trust it's going to have a massive, real impact on share prices and consumer trust around the globe. That's incentive enough for me to rely on it day-to-day.
This article has some interesting tidbits but overall seems like just a baseless rally against FAANG by someone who knows very little about complex authentication or trust and security in the real world.
That said, its initial and continued existence is dependent on economics. Who will market a service that they don't stand to profit from? Who will drive large organizations to invest in infrastructure that doesn't improve their profits? Either no one will, or it will be adulterated in the process. Sadly the community spirit that drove a lot of early internet development seems to be lost.
My issue with the article is that it uses a lot of words to try to explain why web3 and blockchain may be the future. But for what point? If an important technology comes around which happens to use web3 or blockchain, i’ll see it’s important from its description and i’ll adopt it. I don’t need to support “web3” as a concept, because web3 basically means nothing. And i don’t think that web3 or blockchain is intrinsically bad, i just haven’t seen anything particularly useful with those technologies yet.