Jpeg NFTs are dumb, cos the record is public. But a singular record that can out of band handle authorizations? Neat.
Jpeg NFTs are dumb, cos the record is public. But a singular record that can out of band handle authorizations? Neat.
Firstly, we have that on the web today with OAuth. It is centralised in the hands of a few companies but that's because people trust those companies. There simply is no consumer demand to allow other options but it's easy enough to do.
Secondly, the problem with the NFT approach you described is that it coerces people to use a single wallet for everything. Which goes against the best practice for crypto at the moment which is to have multiple wallets due to the many, many NFT scams that can steal your wallet. So in effect your approach trades off centralisation in one area for another. With the end user not really being in a fundamentally better position.
You trust them. I don't. Now what? Are you saying I'm forced to trust them, because you do?
For every story of crypto projects going awry we can find a story of Google shutting down someone's account without any recourse, Apple abusing their App Store position to ban reasonable content (commentary on sweat shops or even mildly adult content), or Facebook accidentally toppling an entire democracy.
The reality is that these centralized systems aren't some panacea and you are frankly naive to be so happy about using them for the rest of your life.
OpenSea takes the blockchain data, filters it and augments it with their proprietary data. Which means that as a user I may buy an NFT that OpenSea is filtering and which therefore is useless on other sites.
There is nothing inherently special about blockchain that prevents centralisation or allows you to have a trustless ecosystem. At some point I will trust Metamask with my wallet, Binance for my trades etc.
Metamask is the same, if you can't use it you can easily take your coins to another wallet and use them there, you just import your seed phrase.
How is this different from setting up a website and requiring a password to access it?
Rather than maintain and protect a local set of usernames and hashes, you let anyone in who can present signature and address. Then server side you check that address has some NFT. Done. No hashes or usernames or anything.
OAuth or one of many services e.g. Auth0, AWS Cognito, Okta can provide a managed service for you.
This isn't a problem Web3 is uniquely solving.
Ya know, about 14 years ago something happened where we could maintain these eternal data structures with rules around state mutation. Humanity is only learning the power of such structures a decade later. There are very much unique problems being solved here and you are missing the dark forest for the legacy trees.
User installs a browser extension (wallet) that is created by a third party that they have to trust unconditionally?
Is that what the promised land of zero trust is about? Trusting a 3rd party with all your finances?
It's about user empowerment and not letting other entities have any control over any aspect of it.