Privatizing our digital identities
notes.volution.ro
notes.volution.ro
We desperately need to break the assumption that email is your identity. It’s like saying your postal address is your identity and if it changes everything gets messy. It doesn't work: it’s not universal and some people don’t even have addresses.
The problem is not that email is privatized (though I agree I’d love to see ssn@id.gov as a usable recovery address), it’s that we’re tied to it as the only way to identify people online. Hopefully webauthn will change this and as long as services accept any signature, we aren't tied to blessed identity providers. So in my book, legislation and political effort need to focus around the “right to self-sign”.
Less abstractly, we cannot allow Google, Apple, and Facebook to become the de-facto blessed ID providers. It’s silly and there’s no meatspace equivalent because it would be absurd like the article points out. We need to require that services accept any email (side rant and any oauth provider url so you can run self-hosted oauth) and, as webauthn proliferates, any signature.
Finally, we need a political solution here because this is not behavior that has or will come naturally. Platforms want to own identity for profit and lock in. Other companies using identity want to only trust certain platforms/oauth providers/vendors for “security” and product simplicity. Nobody is thinking about protecting users’ rights so we must take that upon ourselves.
I along with IBM Research folks wrote a paper on even more interesting ways of exchanging identity information between two entities called Private Certifier Intersection [4].
[1] https://www.w3.org/TR/did-core/
[2] https://www.w3.org/TR/vc-data-model/
[3] https://identity.foundation/
[4] https://www.ndss-symposium.org/ndss-paper/private-certifier-...
Or we legislate and make companies provide a minimum amount of service. You can't offload your operating expenses to the government.
However, if you are fraudster and get to the point where Apple and Facebook and Google all cancel their accounts with you for non-payment or use of stolen credit cards of whatever other reason that a company would decline to do business with an individual...
Well, now you don't exist since the big IDPs won't auth you.
Or, are we suggesting that we legislate so that companies are required to do business with individuals who are making fraudulent use of their services?
The only reasonable organization to do this is the one that has an inherent obligation to do it and for better or worse, that's the government.
No, the Government has a long track record of successfully ignoring people who have hard to solve problems.[1]
> ...we legislate so that companies are required to do business with individuals who are making fraudulent use of their services
I suppose instead of just canceling your account and you losing your email, you could get arrested and charged. Or more likely end up having to use facial recognition[2] administered by a third party which is incapable of verifying people. If you think going to the Social Security Administration to have a paper card printed for you is bad, wait until you have to go to have your password reset...
Or we can legislate Google, Apple and co that if someone holds an account with them and is banned they are entitled to a human led review process, possibly by a third party or other group. We can legislate that if you're a customer in good standing, they have to have human support available. Does this mean they might be more stingy with "free" services? Probably - that isn't a bad thing. Most people take offense to Walmart moving in to areas, taking a loss for a year or two to steal customers and close local stores and then jacking up prices. I don't understand why we're ok with big tech getting a pass to do the same thing digitally.
[1]: https://www.grandforksherald.com/newsmd/va-audit-finds-thous...
[2]: https://www.foxbusiness.com/economy/irs-facial-recognition-s...
Start using that identity mechanism for everything and that vulnerability spreads to everything. Someone compromises your ID and then starts trying it against every service on the internet. They get your bank and retirement savings and drain your accounts, ransomware all your files and your employer's files, read through your messages on every platform to find something to blackmail you with so you don't go to the police, sign into your router and use your IP address for criminal activity etc.
I'd much rather be told to go fuck myself by one service than have my life wrecked because a low level bureaucrat issued someone else a universal ID in my name.
How do you get back a compromised Google or Facebook or Twitter account?
If your former spouse changes your password on google and is able to answer every security question you've set up just as well as you can... what can you do about it?
On the other hand, when the change of address form at the post office goes in you can walk into the post office and say "this is my government issued ID and I still live at this location. Change my address back to my proper residence and put a hold on future address changes for that address without verification."
If you had 16 followers, create a new one. If you had 16M, you get on the front page of HN etc. and they fix it.
> If your former spouse changes your password on google and is able to answer every security question you've set up just as well as you can... what can you do about it?
Have them prosecuted for fraud so they have to change it back. You don't need centralized identity for that.
> On the other hand, when the change of address form at the post office goes in you can walk into the post office and say "this is my government issued ID and I still live at this location. Change my address back to my proper residence and put a hold on future address changes for that address without verification."
So instead your ex files the ID renewal form with an "updated" picture of their friend instead of you, has the new ID sent to your old address (i.e. their address), and then prevents you from filing a change of address form or getting a new ID.
We really don't.
The most important thing about authentication over the internet is that it enable people to create multiple separate accounts that aren't tied to each other in any way. You can get more than one email address or even phone number. You only get one social security number. If you're required to use that on the internet, it becomes a universal tracking ID. That must never be allowed to happen.
Meanwhile the US government lacks the competence to do this. All of their existing identification methods are either fully insecure (e.g. social security cards) or no better than anything corporations use (e.g. ID cards that can be lost or stolen or hacked). They don't have some special magic that allows you to prove who you are in a unique way. And trying to centralize everything into a single ID only makes it that much worse if you lose access to it or someone else gains access to it.
The actual solution to identification is redundancy and decentralization. You have e.g. a password, an app and an email for any given service. If you lose one you sign in with another and update the one you lost. If all of that fails, you lose access only to the service where it failed, instead of losing your whole life at once.
Never centralize identity.
I empathize with these concerns but think they're outdated by a decade or two. We already have universal tracking IDs, we just don't see them because they're opaque and proprietary. We already use government identification online, we just do it in the dumbest way possible: "please upload a photo of your driver's license." We've got the worst parts of centralized identity and none of the benefits.
> They don't have some special magic that allows you to prove who you are in a unique way.
Yes they do, the magic is called "losing money." FaceGoogAzonRosoft have done everything related to auth that's profitable, but the one thing they will never do is build an office in your hometown and staff it with a person who can do deal with you as an individual and physically hold your two recent utility bills when corner cases or fraud or whatever require it. The government has already built that office and hired that person, and you've already paid for it, so you might as well get some value out of it.
This is simply not true. I can go to a public library, sign up for a free email account, sign up for Google or Twitter without it being tied to my name or face or work email etc.
If signing up for any of that required giving them something tied to your social security number, that wouldn't be possible, and that must not happen.
> We already use government identification online, we just do it in the dumbest way possible: "please upload a photo of your driver's license."
The vast majority of websites don't require this, specifically because it's a pain in the butt. It needs to continue to be a pain in the butt so they continue to not require it. Ideally we should create new ways to make it even more difficult.
> FaceGoogAzonRosoft have done everything related to auth that's profitable, but the one thing they will never do is build an office in your hometown and staff it with a person who can do deal with you as an individual and physically hold your two recent utility bills when corner cases or fraud or whatever require it.
That has just no security value whatsoever. A utility bill is a piece of paper. Anybody with a printer can forge one in five minutes.
On top of that, who still gets a utility bill in the mail?
Second, your position rests on the assumption that this hypothetical federal ID will be mandatory. How will it be "required"? By whom? If the government makes a federal oauth, and it works well, sure, some webapps might require it, but they can also just require your identity today. I think you haven't wrapped your mind around the idea that any big tech company that doesn't already have your identity doesn't want it. Google doesn't care about your SSN, they care about your browsing and shopping history, but the day they decide they want it, they'll demand it, and you'll comply or go without Google services (and they'll probably get it from data sharing partner anyway). None of that would change due to what I'm proposing.
A separate device is <$50. Local VMs are ~free. VPNs hide "geographical location" and anyway they were never unambiguous because there can be arbitrarily many people in the same place.
> Second, your position rests on the assumption that this hypothetical federal ID will be mandatory. How will it be "required"?
If you make it easy to use and use of it allows you to be tracked more effectively then websites that want to track you more effectively will require its use.
> but they can also just require your identity today.
That is more difficult to do now and so they do it less. Making it easier would allow them to do it more, which is bad.
I mean there are two options. One is nobody would use it, and then it shouldn't exist. The other is that people would use it, which is bad, and so it shouldn't exist.
You need a decentralized philosophical and technical concept of identity. Nobody owns who you are except you. Self-sovereign ra ra yay.
But we also need to be able to integrate this self-sovereign identity with organized systems of shared sovereignty (gov’t). It’s silly that in 2023 I can’t oauth against id.gov using webauthn and obtain a signed assertion containing my SSN, or that I don't get a digital certificate alongside my physical drivers license, for instance.
What you're saying boils down to: we cannot allow service providers to enforce any quotas, limits, or payment requirements, on the services they provide.
"Self-sovereign" means each individual is their own identity provider.
"Identities" must be uniquely identifiable, otherwise... they're not identities, they're just bits of data.
Practically, that means there must be a centrally-managed namespace of identities that is tightly regulated, ACID-compliant, etc. Federation is practical here, but it will all tie back to the central entity (e.g. government).
(In my interpretation 'uniquely identifiable' should be satisfied by your unique ability to sign data -- actions, statements, etc. associated with that key. there's a problem of making the identity itself human readable, which essentially needs a name system on top)
That said, I think the government de facto already has many useful functions around identity verification, I think making it more accessible, modern and useful is a good idea. Also with good design practices of digital systems, we can also make things more transparent, auditable, etc.. The downside I would say is the possibility of some kind of catastrophic breach or denial of service event having a large impact (any of our usual web services are subject to that though), and having a fallback offline infrastructure should be worthwhile.
When I go get a drivers license, I'm issued a physical "certificate" by my local government that says I qualify to drive a motor vehicle. It has some useful properties like being hard to counterfeit. A drivers license is not my identity. It's a document that asserts claims about my identity like "I passed a test", "I showed up in person", "I have a utility bill for this address", etc. Meatspace identity is self-sovereign but also sometimes assertions about an identity are made are verified.
All of this is possible with a self-sovereign digital identity system. It's how the CA system works. I make an identity, I get it certified for a short period of time. The CA issues me a digital certificate with useful properties like being hard to counterfeit. It's a document that asserts claims e.g. "I manage this domain". CA system is self-sovereign and also sometimes you verify the authenticity of my certificate.
But the signature on my certificate is not a stable identifier. That's my public key. The pubkey is the identity. The certificate authority just issues and signs a document vouching for it.
So the appropriate digital analog to the present day identity system is one where we create keypairs and then sign assertions about their owners. The thing you're looking for is a modern social security office that looks at your birth certificate, requires you to digitally sign your name, and then issues an assertion along the lines of "a human in possession of this birth certificate showed up before me, a truthful government agent, an signed their name like so". And thus, you have bound some human assertion to a pubkey. (And if your use case cares about a country-unique birth-certificate verified human, then you require the pubkey owner present you the certificate and you verify it.)
Or maybe you're looking for a novel digital email verification service that verifies a given pubkey controls a specific inbox. The email verification service periodically sends you a secret via email, you sign the secret and reply, and in response the service issues you a certificate stating that your pubkey is associated with and in control of the email address it just verified. You re-verify every 3 months. In fact, your email client automatically does it for you as you login via webauthn every so often.
Just like I can wear a mask, have a twin, have my license stolen, copy the data on my license, or use someone else's drivers license in places that don't care about the picture or credit cards in places that don't check the signature, the same can happen with a private key. Identity is not as sophisticated as you are making it out to be.
There is meatspace equivalent that is landline phone numbers and telecommunications companies
Attempts at creating digital identity will invariably be gored by one of the two horns of the bull: either it is recoverable like a password-protected account and therefore anyone who can pass the recovery check can steal that identity, or it is non-recoverable like a crypto wallet address and therefore it can be lost due to carelessness.
Our philosophical concept of an identity is not stealable (you cannot actually become someone else, you can only pretend to be them in some way, and they don’t stop being themselves when you do) nor is it losable (you can’t stop being yourself).
Note that “recoverable” and “non-recoverable” are mutually exhaustive. There really is no third way here.
You might think you can asymptotically approximate a digital identity by making it exponentially hard for anyone except you to pass the recovery check; if you do, you’re also making it harder for you to pass the recovery check - you’re just offloading into the “non-recoverable” failure state (loss).
Likewise, you might think you can asymptotically approximate a digital identity by making it extremely easy to keep the access code so it won’t get lost; if you do, you’re also making it easier for anyone else else to steal the access code - you’re just off-loading into the “recoverable” failure state (theft).
It fundamentally cannot be done. Instead, everything must be built to work without a Single Source of Identity Truth.
That is equally true for physical identity documents like passports and various id cards, and yet it isn't nullifying completely the utility of such documents.
> yet it isn't nullifying completely the utility of such documents.
I don't think that anyone is claiming the absolute uselessness of any means of identifying anyone for any purpose, so "complete nullification" shouldn't be the standard. The standard should at least be "more benefit than cost."
Consider for example the Australian system for proving one’s identity: https://www.afp.gov.au/sites/default/files/PDF/NPC-100PointC...
To “log in” to a government service in person (i.e. for the person at the desk to accept that you are you for the duration of your appointment), you have to present at least 100 “points” worth of documents attesting to your identity. A passport is 70 points, a driver’s license is 40 points, and various other documents are 25 or 20 points. In practice the most common way by far is showing your passport and drivers license*.
Both your passport (federally issued) and your drivers license (state issued) have an individual biometric authentication process required for them to be valid: they have a photo on them, and the official checks to see that the photo matches your physical appearance.
So an equivalent digital version of this whole process might be: present a Yubikey (federal) security key (passport) with a successful thumbscan (picture matches), and then present another non-Yubikey (state) security key (drivers license) also with a successful thumbscan (picture matches as well). This logs you in for a single session that expires when you leave the page (valid for just the duration of appointment).
By digital standards this is an onerous authentication process, and it only gets you a short-lived session token at a single service/vendor. Clearly, physical identity documents are grappling with this exact same dilemma.
*: Second most common is showing your drivers license, Medicare card, credit card, and a recent utility bill/bank statement - four pieces of attestation!
Digital IDs offer the ability to go 'off-grid' and hide in humility and also to be tracked and seen everywhere you go, without public awareness of it. It has the strongest cultural implications in the US, without a clear advantage to foreigners.
An e-commerce license or a software engineer's certificate based on a paper test that you must upkeep every 5 years or so, would be a largely unpopular, but basically effective way of getting just enough identity out of the people who are paying for stuff and making money on the internet to ID them, when required. You would have to show it makes the user more employable and grant them better access to domestic internet services, as part of the benefits of becoming 'vaguely certified'.
Do we really need more online identity though. The five eyes see it all. Personally, I don't want to hide and I don't want to see what everyone's doing. Let's just get on with trading code and making this whole internet work better.
Meanwhile, even if you somehow had secure, irrevocable ownership of some kind of identifying name or number, websites could still cancel your account with them for any reason and keep you from logging in with that ID. They can use the ID to more easily share reputation information, similar to credit scores. Your ID could be put on a list, similar to what happens with ad blockers and lists of spammers.
By itself, ownership of a name or number doesn’t get you much. If you use Google to log in to a website, what it’s really providing is a minimal kind of reputation, sort of like how a captcha vouches that you’re probably not a bot. For an ID to be useful, there needs to be reputation attached, and that isn’t something you can do yourself; other people or entities need to vouch for you. It’s also not permanent. Good reputations can go bad if people decide they don’t like you anymore.
Instead of centralizing using a single ID, there’s a lot to be said for having having multiple identities (alts) for when you don’t need reputation and you don’t want what you’re doing to affect unrelated activities.
This. While I avoid creating accounts as much as I can, when I do, I do not use the same "identity" for each of them. The ability to have multiple independent identities is, in my opinion, essential.
What I don't want about any kind of identity system is that I can only have one.
The globalist types[0] are looking to implement such a system. From what I have gathered, they want a social credit score. Unvaccinated? Good luck getting a loan. Posted something 'wrong' on an online message-board? You can't travel. And the list goes on...
I think at the core digital id is just having a form of asking your government "Can you verify this is me to someone else?" (which is already something you do with id photos, passports, etc.). I wouldn't want to use it everywhere.
I think consumer protection laws that restrict denying digital service to a customer (without something like a criminal or legal basis) or indiscriminately requiring digital ids could be useful in reaping the benefits without the downsides.
Maybe that changes in the near future but the internet is only as real as you make it.
Seems pretty real to me.
The new paradigm is that everything has shifted online. The Internet is the proverbial town square. If you don't participate, that's on you, but all manner of discourse happens online now, and most importantly; that discourse shapes public opinion, and can have real lasting change in the world.
I've long supported the "right to be forgotten".
But, until this essay, I had never considered the corollary "right to be remembered".
This real world concern is timely, relevant.
Nicely done.
I want to be able to configure my Discord or Slack "profile" to have all my messages automatically deleted after say 2 months. But at the same time I also want my email address to be permanently available (even after I die) because it's registered in so many places, tied to so many important things, so that if Google decides to erase me I'll be in a lot of pain...
And although I do use a *payed* GMail account, I do it mainly because I trust them more from a security point of view than I trust myself. However I don't trust them not even 1% not to screw me over if the accountants say it's more profitable to drop GMail...
At the same time I don't trust the government not even 1% not to screw the security of such a system, or not try to misuse it for political gains. But, I also don't see any way out of this situation with the technology, society, economy, and judicial system we have right now...
Europe seems to be working hard on establishing an identity for every citizen: https://commission.europa.eu/strategy-and-policy/priorities-... (most countries already have that, but this is about unifying the various countries' ID systems).
> We need to support the case when a person wakes but-naked in a corn field, suffering from complete amnesia, and remembering nothing about himself. Today, such a person has a chance of getting his identity back, but in a pure technological world, "the computor just says no!"
----
Regarding the various European ID initiatives: they might seem a good idea, but they don't actually work in practice: for better or worse, our internet solutions seem to have settled on email as the de-facto identification system. Are any of these EU ID initiatives completely interoperable with the email system? If not, they are useful only for purely official interactions with the government, and solve nothing outside of that realm.
Also, because most such ID initiatives are actually X.509 tokens that work solely on Windows, with Adobe products, they are beyond useless...
(Let alone that one costs ~50 EUR per year in my country, Romania...)
> We need to support the case when a person wakes but-naked in a corn field
DIDs can have a controller, and the controller can be your "real-world" identity... If that is government-issued, you can recover it the same way you recover your identity today in case you lose all your documents. After that, you regain control of all your other DIDs (which you keep to ensure anonimity, e.g. you can have a different DID for each service you sign up with).
> Are any of these EU ID initiatives completely interoperable with the email system? If not, they are useful only for purely official interactions with the government, and solve nothing outside of that realm.
That's plain wrong. It's already possible to use DIDs to sign up with any business you want, though admidetly as the specs are still in flow, there's no much out there other than lots of PoCs - but those already show it's absolutely possible and desirable to use DIDs instead of email addresses... private accounts are an actual liability for most businesses (except those selling your data for marketing purposes, of course).
> Also, because most such ID initiatives are actually X.509 tokens
Where did you get that impression?? There are several DID methods and the most popular so far have nothing to do with X.509 certificates (I think that's what you meant by "token"?). Many are using JWKs (JSON Web Keys) as most alternative solutions do. Check the current registry of DIDs here: https://www.w3.org/TR/did-spec-registries/#did-methods
The EU seem to be using both Web DIDs (no blockchain) and [EBSI](https://ec.europa.eu/digital-building-blocks/wikis/display/E...) (EU blockchain initiative).
(Over simplifying: just like properly salted and hashed password files. Lose the password and you cannot retrieve the encrypted data.)
Using your essay as a starting point, I'll start pondering what a future "right to be remembered" system might look like. Both technically and legally.
Now you have problems.
Is it impossible to do in the US? Why? Zero trust in government (at all levels)?
The problem is that there needs to be laws preventing private companies from requiring this identity, otherwise it would devolve into yet another unique identifier for the surveillance industry to abuse. And in the US context, we don't even have basic privacy laws. So until the abuse of basic identifiers like social security and driver's license numbers gets reigned in, having the government create digital structure just feeds into the surveillance industry.
"This post is authentically produced by Ged Sparrowhawk, born in Gont, living at Roke Island, a student" or
"This post is authentically produced by a student" or
"This post is authentically produced by someone living in Gont" or
"This post is authentically produced by someone born in Roke" or
"This post is authentically produced by Ged Sparrowhawk"
Giving the user the ability to have an authenticating government stamp their items with whatever level of identifiers they want seems like a far preferrable solution to me than creating a strong identity system. Users can pick whatever fits their desire: residing on the planet Earthsea, the island Roke, the town Thwil, or the place the School of Wizards, or the room whatever there-at. Nation/state/county/town/area/street/address, whatever. Government can let us say what we want about ourselves. This is a far more interesting & flexible proposition to me than creating an identity system.
Imagine you got that address assigned, 42@id.tld. Now, every private company you want to do business with wants you to register using that ID. Now, when you get banned, they can share that ban throughout their network. Because every company requires you to register using your national email address for password recovery, you've created a system that radically expands the power of the private sector to profile you and control your reputation, if not your identity.
Maybe very careful regulation could prohibit companies from asking you for your government email address, but I recall the (apocryphal?) quote by LBJ, "You do not examine legislation in the light of the benefits it will convey if properly administered, but in the light of the wrongs it would do and the harms it would cause if improperly administered."
I prefer your proposed solution of some regulation that treats email like phone or utilities so there are a few protections before services are terminated.
They come in two forms: SPID (which is just username and password + TOTP, issued by private companies on behalf of the State, but allowing you to change your provider without becoming "a completely different person" [1]), and CIE (which is the new national ID card, and can be used as an electronic ID using any NFC reader). Additionally, some services allow to log in using equivalent eIDs from other EU countries [2].
Edit: It does not completely ignore this option but frames it a bit restrictively. I set mine for auto renewal and use my domain at an email provider. It is not necessary to run your own SMTP.
What if you[1] fail to renew your driver's license, passport, professional certification, homeowner's/renter's insurance and/or refilling your prescription for a life-saving drug? If so, you screwed up. Not paying your bills or maintaining your person-hood and infrastructure is your fault.
Unless (in the US at least) you are a member of a "protected group/class"[0], no one is required to do business with you. And even if you are a member of such a group, good luck proving that you're being discriminated against because of your membership in such a group/class even if that is the case. And even then, there is more than one registrar on the planet.
If my "hosting facility" catches fire, I have much bigger problems (i.e., finding a new place to live and replacing all my belongings) than not getting email. And since there is more than one "hosting facility" (including your own premise), just move to another one.
It's not clear to me what, exactly, you're railing against. Each and every potential issue you mention has a "meat space" parallel that, I imagine (please do correct me if I'm wrong) you are a responsible human who makes sure to do what's necessary to maintain your life/person-hood/place in society.
If those digital things you mention are so unimportant to you that you don't/won't take responsibility to manage them, that's on you, not the rest of the world.
[0] https://en.wikipedia.org/wiki/Protected_group
[1] That's a general "you" rather than DeathArrow specifically. But it applies just as much to DeathArrow as it does everyone else. Including me.
Edit: Removed text artifact.
You just renew them late. There's a risk that you'll need them right then, sure, but generally those mistakes don't lock you out of fixing them for the future. However, a domain is easily irrecoverable.
It does mention it along with the associated costs.
> What can you do? Register your own domain and run your own SMTP server? Better make sure you renew your domain each year, else... --- You are no more. Don't have $5 per month to lease a VPS and run your SMTP server? --- You are no more. Has your domain gotten on some mail blacklists? --- You are not more.
In the name of efficiency, it won't be the state doing it until someone, or groups of someone, get sufficiently pissed.
EDIT: passwords & other secrets must be shared with someone of trust.
We use Coze to sign messages that authorize user actions, such as uploading images, logging in, and leaving comments.
Government and its ids, licenses, laws and monopoly on force, is not there to help. And yet, despite all the examples of how government is by far and away the cause of most problems we experience, on hn you will find endless discussion on how to best assist it. Eg here - 'what type of id is best?'. It's amazing.
Programmers, technologists, etc seem to be hardwired to develop the enslavement structure of everyone, including themselves, for the sake of some perceived comforts, such as a nice holiday, better car. Its literally turkeys voting for Christmas, as we plan and develop the hardcore enslavement of the future.
Just think - do woodland creatures need id? Does any individual need an id? No. It is only useful if you want to control access to this or that for others. Ie you want to force your control on others who are doing you no wrong.
I've been working on this exact problem for years, and have solved it differently. If anyone is interested, here's the draft whitepaper on my solution: https://www.stampchat.io/whitepaper.pdf
It doesn't really solve any of the traditional usability problems of maintaining a private key, which is why so many users end up just signing up for a website that will handle it for them.
Specifically the issues that come to mind are key recovery and rotation.
I.e MyAwesomeBlockchain can be totally awesome but since no one uses kt it is useless.
This will be the fate of well over 90% of the block chains that exist today I think. In fact I guess more than 90% of them.
Is there a way to guarantee that a user maintains "full control" over their identity as opposed to having it be stored on a 3rd party site?
What would a 3rd party site that is operating less than trustworthy (a not uncommon situation in the web3 world) way be able to do with an identity that they hold in trust for someone who doesn't possess the consistent access to the previously mentioned hardware resources?
If your only computing device is your phone and someone steals it, do you lose your identity?
In the event that your house burnt down and all of your computing resources have been destroyed, is there a way to attest to be able to recover your identity?
In the event that your evil twin decides to burn down your house, what mechanisms exist to prevent them from claiming your identity?
https://twitter.com/DefiIgnas/status/1633626349226319872
> 5/ Account abstraction is a huge breakthrough for crypto self-custody.
> It enables:
> • Create & restore a wallet with an email or a phone number
> • 1-Click transactions
> • App pre-approvals & limits
> • 2FA protection
> and much more.
Do you use Bitcoin and tomorrow Venezuela buys up 51% of global hashing power? Your identity is now managed by Venezuela, have fun
Self-signed identity means you own a private key. Being a human means you own a body. You can call yourself whatever you want in meatspace. People deal with it. You can sign whatever statements you want in cyberspace. If you need to verify that someone has passed a driving test, then yes you need an authority to issue a certificate (or whatever better tech you choose) saying this private key met these requirements.
There's no inherent problem with the identity being self-signed if you just need a user-id.
On the other hand, a real ID check makes sure with a high degree of certainty that the person is actually the same one who performed other actions (was born, purchased a home, has money, etc.)
So yes, you can have self-signed identity. And you can use it 99% of the time. If you need government-level identity verification, you can build that, do the hard check, and link to a self-signed identity by issuing a certificate for a reasonable amount of time until a re-check is desired. Your drivers license is exactly that in physical form. I'm not saying we shouldn't have a digital DMV that issues digital drivers licenses. I'm saying you don't need that as the foundation of your identity system. Identity is self-sovereign by nature. Don't fight it.
Read up on account abstraction: https://blog.jarrodwatts.com/what-is-account-abstraction-and...
https://twitter.com/DefiIgnas/status/1633626349226319872
> 5/ Account abstraction is a huge breakthrough for crypto self-custody.
> It enables:
> • Create & restore a wallet with an email or a phone number
> • 1-Click transactions
> • App pre-approvals & limits
> • 2FA protection
> and much more.