It's crazy that some functionality on e.g. the IRS website requires me to verify my identity using a private company (ID.me).
For all the faults of current Fediverse software implementations, it at least gives more options than nostr. If you don't care about controlling your own identity, you can use someone else's server. Nostr doesn't give you that, it's all or nothing.
Passports have had keys in them for a while now (so-called "e-passports")
but no one understands it, including the people who need to issue new signing keys.
it didn't get anywhere really. it was just a good opportunity for a lot of taxpayer money to... "lose its taxpayer money nature" (actual phrase by an actual politician when cornered by questions).
and now they are "moving on" to an app that must be installed on your phone to access more and more services.
ID2030 is roaring on worldwide... soon mandatory iris scans, vaccine implants, and who knows when they will try to roll out mandatory brain implants against thought crimes.
the more i think about the sign of the beast (as an atheist), the more sense it makes.
All of this is currently pretty messy and there's only limited practical cross-country acceptance of eIDAS signatures, but is supposed to get unified under the banner of EUDI (EU Digital Identity) "wallets".
Many EU countries have existing e-signature rails completely independent from physical ID cards, which only have to conform to ICAO document verification standards (and these are intentionally not usable in an e-signature context).
Private companies are bad enough, but at least they won't declare you an undesirable for your political beliefs or religion or ethnicity or gender identity or sexual preference or whatever and shoot you in the head over it.
Except where governments and private companies collaborate, which of course happens (looking at you literally every American social media platform.)
It would be great if governments provided the option to authenticate with third party PKI. Having a public option would be nice as well. Identity management and verification is a core competency of government, after all.
A wallet is easier to lose than a bank vault, but it also holds less money for the same reason. Crypto keys can be designed the same way, with high importance keys managed by safer means like m of n schemes mixed with traditional "hard" storage in geographically distributed safe deposit boxes or whatever, while less important keys can be treated in a more relaxed fashion.
yes because if you lose your house keys you don't lose your property, precisely because there is an entire legal and governmental apparatus securing it, the exact thing the crypto people first try get rid off and then reinvent (shoddily) when they inevitably discover that nobody wants to live in the jungle
Your local locksmith would beg to differ.
So i think there are viable solutions here. It mostly just means having an app to manage the keys for you.
Nostr's whole shtick is about "users owning their keys". If I can not change the keys used on WhatsApp or Signal, I do not own them. They are not in the same class, so the comparison is moot.
But honestly one of the reasons why these sorts of apps dont take off, is they rigidly adhere to security properties that dont make sense and nobody really cares about, at the expense of making an unusable app.
Matrix clients have e2ee encryption like Signal or WhatsApp.
Every single one of my close contacts that I have on my server have ignored or misunderstood the instructions to download and store the recovery key when they first access the servers.
I have customers on my support channel who keep trying different clients (Element, ElementX, Fractal) and every time they fail to validate their sessions.
Then I have customers who got their phone stolen and then come asking me to either delete the data on their phone.
---
There is no magic about "putting it in a app to manage it". If any "app approach" you come up with creates a sandbox between user and device, then the user can not even see their private keys, then they effectively do not own it.
If you are doing "nostr, but with keys sandboxed on the device", then you are just recreating Signal - which is not decentralized - then what's the point?
The opposite is the case: WhatsApp and Signal manage the keys for them, mostly in the background (unless you actively verify identities).
You can try it yourself: Turn off your phone, ask a friend to send you a message, throw your phone into a volcano, reactivate your account on a new phone without entering any secret keys. You'll still receive the message.
I personally think that most of Signal's and even WhatsApp's tradeoffs are reasonable for a product with an adaption of hundreds of millions, but it's decidedly not cryptographic self-custody.
sneak’s law: “Users can not and will not securely manage key material.”
People also take care of their house keys and their wallets, but If I lose the keys to my house, it isn't automatically taken over by squatters and if I lose my ID card I can issue a new one quickly.
What happens if you lose the cryptographic key to your nostr account? Who do you call for help?
What happens when the key is lost, and the consequences like "lose all your money" or "lose your account access" are non-starters, as someone who owns a hardware key for my email account
Multi-sig wallets are even more complicated and not for normies
It is the same problem.
It's not the same problem