In fact, if you believe in privacy at all you’d want to reject this idea for that alone.
In fact, if you believe in privacy at all you’d want to reject this idea for that alone.
An antidote to that would be using a different key on each site you authenticate to. You still only need to store a single key, all other keys are derived from that yet cannot be associated with their sibling keys.
> What you’re saying is also trust with web3.
Not quite sure what you mean here, web3 is a pretty overloaded term. If you mean the very concept of web3..that's pretty fundamentally different from trusting a company that can unilaterally ban you, alter your data etc. There is no such parallel in web3. If you mean the JS library, that's also fundamentally different, and it's not the only game in town.
The author advocates using third party services such as meta mask, who would need to be trusted.
How do you implement it without any third party site.
If we are talking about likelihood it’s unlike you’d be banned from Microsoft/Facebook/Google for no reason too.
Furthermore as the administrator how you stop bad actors?
> If we are talking about likelihood it’s unlike you’d be banned from Microsoft/Facebook/Google for no reason too.
I've seen posts on this forum about it. It happens and there's not much you can do if it does.
> you could also create a new Google account per website or simply use an email address.
> Furthermore as the administrator how you stop bad actors?
Apologies if I'm missing something, if it's easy to spin up unique identities on both what's the difference here? It seems like it would be one or the other.
And yes you can create a new Google account per website, but you are still at Google's mercy to authenticate. My 1Password has ~250 logins, I'd be seriously worried about a ban from Google if I made 250 accounts.
Yes except for a centralized entity the admin would have recourse. How does a web server admin deal with it in the case of blockchain?
> I've seen posts on this forum about it. It happens and there's not much you can do if it does.
If we are talking about anecdotes I’ve seen people lose their private keys to phishing and consequently all of their money, so…
> You have to trust MetaMask to some extent, like any software you run locally, but MetaMask never gains control of your keys or identities, it's just a tool for using them (obviously 99.9% of users aren't auditing the code or building from source, but that's a totally different threat model). If MetaMask stops working for you, you can use a different tool with the same keys. If Google stops working for you you cannot transfer your account to Microsoft or Facebook.
This is not true, depending on implementation. Even if we accept what you’re saying as true you can run your own oauth server.
Basically it seems the entirety of your argument rests upon trusting a centralized service. However the scenarios posited by the author are ones where blockchain is used to login to a centralized service to begin with so I don’t understand the criticism. Furthermore, unless one is to accept the infinite possibility and quantity of accounts, inevitably just like most other identity services, blacklists will be created.
If that is not effective then blockchain will simply not be an option for most sites.
Ultimately this convoluted web3 is no better than using an email address forwarder and a regular email and password.
Can you be more specific? How is it easier to sniff out a user using multiple emails vs multiple keys?
> If we are talking about anecdotes I’ve seen people lose their private keys to phishing and consequently all of their money, so…
Losing your keys is a huge problem that needs to be solved. I think social recovery is super promising in that respect but you're right that we aren't there yet. Phishing exists in both worlds, although I'd argue for logins specifically it's less of an issue in the MetaMask world, as you do not need to expose your private keys for that. You need to expose your password to log into Google.
> This is not true, depending on implementation. Even if we accept what you’re saying as true you can run your own oauth server.
Which part isn't true?
There is..some difficulty gap between a browser extension and running your own authentication infra..
If someone made 2109@gmail.com 238@gmail.com 2398@gmail.com you could contact Google, send them the information and potentially block all of them collectively and/or find the person responsible. This would be important if your application has to do with financial activity. How would you do this if someone kept making random private keys?
> I'd argue for logins specifically it's less of an issue in the MetaMask world, as you do not need to expose your private keys for that. You need to expose your password to log into Google.
I'm not understanding you. If you're someone who won't use Google, or a centralized service, then you are capable of hosting your own web server. If you're capable of that an email address + password is superior to blockchain and gives you more control.
If you're not capable of that and are using centralized services for things like email then you lose no more control using their oauth server.
You and author have yet to address failure modes, or the superiority of this compared to email and password.
Citation needed, I very much doubt Google would comply without a search warrant. For financial activity, it depends whether the application requires authentication, or simply funds. For authentication see things like DECO, where you could prove some personal information about yourself without actually revealing that information (SSN for example). Obviously that is piggy backing off of a legacy system; it's up to the application to say what data they need.
> I'm not understanding you. If you're someone who won't use Google, or a centralized service, then you are capable of hosting your own web server. If you're capable of that an email address + password is superior to blockchain and gives you more control.
You are completely wrong that everyone currently using MetaMask is capable of hosting their own web server. Securely hosting a web server is orders of magnitude harder than securely using MetaMask.
I think I did address both failure modes and the benefits. I agree with you that it's not ready to replace email and password, but I don't think the issues are insurmountable either.
There's plenty of evidence out there for this (https://www.jamesmadison.org/the-governments-secret-google-s...). Furthermore Google has a contact to official subpoena them if you want (https://support.google.com/faqs/answer/6151275?hl=en). For mild things you could just report abuse and escalate - https://support.google.com/mail/contact/abuse?hl=en
Again, you're not answering the question. What does the web administrator do if someone is creating fake accounts using a private key? If you're going to use third party systems you don't need blockchain to begin with.
> You are completely wrong that everyone currently using MetaMask is capable of hosting their own web server. Securely hosting a web server is orders of magnitude harder than securely using MetaMask.
You're addressing a claim I didn't make. I'm not sayin everyone using metamask can host their own server, I'm saying someone who isn't using a centralized entity anywhere can do it, by definition. Hosting a web server is trivial in 2022. You can literally setup a server by going to digitalocean.com right now, paying $5, and spinning up a one-click machine. Administrating it at scale is obviously more difficult, but it's trivial to setup a little oAuth server if you want.
You are completely moving the goalposts, I thought we were talking about internet services trying to prevent spam..not government snooping and subpoenas. Are you claiming the government's ability to collect data about you from Google is a good thing? I'm pretty confused.
> Again, you're not answering the question. What does the web administrator do if someone is creating fake accounts using a private key? If you're going to use third party systems you don't need blockchain to begin with.
You are not answering the question either, is this web administrator the government? Are they going to serve Google with a subpoena?
> I'm not sayin everyone using metamask can host their own server, I'm saying someone who isn't using a centralized entity anywhere can do it, by definition.
Ok fair enough, I'm not saying anybody will be using "no centralized entity anywhere", not totally sure what your point is. Using a centralized entity for A is equivalent to using it for A+B?
good luck
I feel like you are intentionally ignoring the dangers of SSO tied to a company that can unilaterally delete your account, and has little incentive to unlock it or even let you plead your case.
Cheers.
I feel like you are intentionally ignoring the dangers of crossing a road where there is a higher probability of dying than a FAANGM deleting your account.
Account deletion is not the only risk, it's also privacy (Google knows what you sign into and when) and a myriad other advantages (native payments being the obvious one).
> I lost access to my Google account because I was away too long, and therefore all the accounts it was tied to.
Wouldn't there be a common, shared list of malicious wallets that can be automatically blocked?
Ublock Origin doesn't update its ad domains list itself, it relies on a number of lists that other people have created. I've never had to lift a finger ever since I installed UBO.