16 ms·
Dangers of “decentralized” ID systems
- wmf 2y agoSummary: Relying on government ID isn't decentralized. I'm having a hard time thinking of one such system though.
- deleted 2y ago[deleted]
- jandrewrogers 2y agoThe US is an odd case where there is no central government ID or identification base layer. There are many independent authorities that can issue an ID, none of which are universally provisioned or recognized by governments within the country. This creates enough edge cases that it is essentially required to be possible to bootstrap an identity from negligible formal documentation, which is also a rather large loophole.
- jiveturkey 2y agowhy doesn’t a passport count? or do you mean, no central ID that is the only acceptable ID for various services
- jasode 2y ago>why doesn’t a passport count? In the USA, non-citizens (legal permanent residents aka "green card" holders) can't get passports. They can get state-level drivers licenses but only citizens can get passports from the centralized-level Federal government.
- photonbucket 2y agoGreencards have a MRZ just like passports though. Green cards are effectively entry-only passports (from the perspective of the US). You can enter the country by land with just the GC with no passport. Additionally, if you arrive by air and you have global entry they don't look at your passport at all, just the GC.
- techsupporter 2y ago> In the USA, non-citizens (legal permanent residents aka "green card" holders) can't get passports. Is there a reason they can't get a passport from their country of citizenship? Plus, passports are fully standardized, at least the biometric ones are. It's possible to read and verify the data on a biometric passport entirely offline using open source applications that implement the documented processes.
- arlort 2y agoPresumably they can but it won't prove their legal status in the US, assuming the local government even recognises it as a legal form if ID
- wdb 2y agoHow did the green card holder enter the USA without a valid ID / passport?
- dragonwriter 2y agoWell, they probably didn’t do so with a valid US ID, and certainly not with a valid US passport.
- pvg 2y agoYes but they definitely have centralized id - the 'Alien Registration Card' itself. Technically, lawful permanent residents are supposed to carry it at all times.
- dragonwriter 2y ago> In the USA, non-citizens (legal permanent residents aka “green card” holders) can’t get passports. Yes, but legal permanent residents (and some other legally resident aliens) also have federally-issued ID, and its not optional the way passports are for citizens. (For LPRs, the Permanent Resident Card, for others the Employment Authorization Document or Immigrant Visa.)
- michaelt 2y agoForgive my ignorance, but isn't the green card already a federally issued, nationally recognised photo ID?
- dylan604 2y agoI think you greatly underestimate the number of people that do not have a passport.
- jiveturkey 2y agoI recognize that percentage-wise, dissapointingly few US citizens have passports. I suppose it's more linked to economic status than anything else. But I was merely rebutting the parent's statement that there is no centrally issued ID in the USA, in the context of ironic use for a base layer for "decentralized" identity. It's too bad the article focused on that nonsense instead of, what good is a decentralized identity -- if it can't assert your actual physical identity.
- jandrewrogers 2y agoA passport is an ID. However, it is not mandatory and some State governments do not recognize it as a valid ID for legal purposes. In the US, the power to issue authoritative IDs resides with the individual States, not the Federal government, which creates many interesting edge cases.
- pvg 2y agosome State governments do not recognize it as a valid ID for legal purposes. Do you know which state governments?
- tptacek 2y agoI don't believe this is true, and the reason I don't is that this question nerdsniped me and I looked up every state and found that they all, every one of them, including the ones that made me click into PDFs to verify the fact, accept passports as identification in order to obtain Real ID drivers licenses. (Also I have writers block).
- pvg 2y agoHah, thanks, I sort of suspected as much, weird as US id stuff is. Like if you'd told me 20+ years ago that the federal government can't get states to standardize their ids even in full anti-terrorism super saiyan mode, I'd have thought that was bullshit too.
- deleted 2y ago[deleted]
- jiggawatts 2y agoAustralia is the same. Even accessing federal systems involves a baroque system of multi-credential attestation where you nominally have a single “GovId” but in practice you have to jump through a bunch of hoops on a per-agency basis. The GovId itself is a weird amalgam of “n-of-m” identity papers. This all happened because back in the early 2000s there was an attempt at a single “Australia ID” but geriatrics had their brains pickled in decades of anti-communist propaganda and voted against it. The logic is: “Only communist governments know who their citizens are.” Democracies apparently have to be ignorant and easily exploited by criminals falsely claiming pensions and other benefits using easily forged identity papers.
- acdha 2y ago> This all happened because back in the early 2000s there was an attempt at a single “Australia ID” but geriatrics had their brains pickled in decades of anti-communist propaganda and voted against it. This is similar to how the U.S. has a certain amount of opposition from Christian sects who believe any sort of national ID number would be the biblical mark of the beast. There’s a certain dark humor in the way privacy is used to complain about identification cards but that only leads to the semi-regulated private data brokers being used by everyone, including the government, with purchased access to far more data.
- spacebanana7 2y ago> geriatrics had their brains pickled in decades of anti-communist propaganda and voted against it. Isn’t the CCP’s behaviour still one of the best arguments against universal government ID?
- jiggawatts 2y agoI cannot fathom the error in logic that yields the conclusion that elected governments having a SQL table with a primary key constraint is somehow "the same thing" as the authoritarian abuses of power by a single-party communist dictatorship. A number on a piece of paper is not the root cause of secret police brutally cracking down on dissidents!
- techsupporter 2y ago> The US is an odd case where there is no central government ID or identification base layer. As others have mentioned, the US Federal government issues passports and passport cards, yet it's entirely up to the agency that wants ID what IDs they will accept. I've been turned down for using a passport card for some Washington State government activities ("the card doesn't have a signature"), using a passport to buy an age-restricted item from a store ("we can't scan it"), and a passport card with the state's largest credit union ("too much fraud with passport cards"). Yet none of these are documented anywhere. Everyone just assumes you'll have a state-issued driver license and if you don't, well, you're obviously up to something nefarious. (Before anyone asks, I do have a state-issued enhanced identification card. It looks identical to a driver license, except it says "identification" on it. I've still been told "that's not a driver's license, I can't take that.")
- jandrewrogers 2y agoI use a Federal ID when dealing with legal purviews of the Federal government, and a State ID when dealing with the legal purviews of State governments (which is most things). This is the only reliable scheme I've found. As a matter of Constitutionality, the States are largely required to recognize State IDs, but no one is required to recognize Federal IDs because there is no authority and as a practical matter many governments don't. It doesn't help that some clerks are confused by the zoo of government issued IDs that exist in the US. IDs in the US are a mess, the legal barriers to making it possible to have an organized identity system are very high, and both the Democrats and Republicans are resistant to removing those legal barriers, so this situation is unlikely to change.
- maxerickson 2y agoReal ID has more or less happened. States still issue IDs that don't meet those requirements, but at some point it's likely enough to actually become a requirement for using the ID to fly (instead of being delayed again).
- jandrewrogers 2y ago
- briffle 2y agoAnd even then, most of us can do a ton of damage just knowing the last 4 of someones social security number, and their bithday.
- cloudhead 2y agoLow quality post that doesn’t understand how DIDs work.
- justinko 2y agoThat's because it was clearly very heavily assisted by AI.
- jiggawatts 2y agoThis article avoids the elephant in the room: nobody except cryptocurrency nuts asked for this. The “Decentralised” part of DID should give a hint that this is yet another attempt to make crypto relevant to the real world outside of bypassing sanctions, paying for drugs, or extorting hacking victims. Web 3.0 failed because cryptocurrencies can’t support the high bandwidth and low latency required. So the same people came up with DID, which can tolerate multi-hour transaction delays and storage capacities measured in single-digit kilobytes. Most of the criticisms against Web 3.0 still apply to DID. It can be impossible to revoke, as the article stated. Which means if grandma’s wallet is hacked, she can be impersonated forever by the hacker, and not even the government can help her with this. “Yay, censorship resistant!” many will proclaim. (Loudly) Okay, name me one instance (1) where a citizen of a western country had their identity censored in any sense by their government.
- bawolff 2y ago> Okay, name me one instance (1) where a citizen of a western country had their identity censored in any sense by their government. I don't think this is the problem DID is trying to solve, but the article mentions illegal immigrants and stateless people.
- hughesjj 2y agoAlso, the entire witness protection program, whistleblower protection, certain government 'contractors' Agreed this isn't the problem DID is trying to solve from what I can tell though. As an aside, it's hard for me to read DID as anything other than disassociative identity disorder https://en.m.wikipedia.org/wiki/Dissociative_identity_disorder https://en.m.wikipedia.org/wiki/Dissociative_identity_disord...
- _akhe 2y agoThe crypto phase ended up accidentally showing us why centralized authority is important. It sounds great on paper: If we can simply enforce a protocol, then we don't need authority, right? But we still have to trust who enforces the protocol. If we rely on trusts and exchanges to any degree, for example, to enable faster, more convenient transactions, or for user experience, then those trusts (banks) cannot be running off with the customer deposits like BitConnect and FTX did. The trust should be insured and should have to follow normal bank and currency exchange regulations. When you add in all the banking infrastructure that would be needed to bring cryptocurrencies up to speed we'd end up with a clunkier version of what we have (we already have fast digital banking, and cash is already anonymous and instant). Regarding crypto for content chains: Basically the same ideas, if certain peers are trusted to host, serve, and/or broker content in some way, how do you trust those parties, or if there are content "vaults" off-chain to enable faster access to data, how do we know it wasn't tampered with off-chain? Can't store it on chain feasibly either, especially if the content is say full-length films. I think blockchain for both cryptocurrencies and content chains is better suited for smaller peer networks where you know you can trust the node hosts and the cryptography is used more for keeping nodes in sync, and for lower-level security, not as a replacement for trust. Or if you don't trust the node hosts, then the trusted party is whoever maintains the "peer list" - but that's just a road toward what our Federal Reserve, or our Wikipedia, can already do much better with consumer banking and open-source contributions (respectively).
- cmdli 2y agoOne thing that is worth mentioning is the idea of a “private life” really hasn’t ever existed. Even before the internet and computers, banks still held records of customer identity, merchants would still track their customers and what they bought, and the government could still take those records with a warrant. Even before then in pre industrial or rural areas, people would generally know who the people around them were and would regularly discuss what others were doing. The idea of a completely anonymous citizen that can bank, buy, and talk with others with full control of what other people know about them is pretty much a modern invention and is slowly disappearing again and society adapts to a technological world.
- mjevans 2y agoThe problem is; it used to take lots of real effort and therefore expense to investigate those facts. The results are now worth far more, and the cost is now far less. That is a change in the structure, the unwritten expectations of society, that I agree we should resist that change. The previously unwritten expectations should be codified into rules that should be followed.
- andy99 2y agoThese "gaslighters" seem to show up to many discussion to say "what's the big deal, it's always been that way" when it obviously hasn't. I guess it's people who want the change and are trying to justify it? Anyway, a good analogy is photo radar. Speed limits are set knowing everybody speeds. We could now easily enforce them everywhere. But if we do, we need to raise them to an appropriate level, not the "we know you're breaking them" level. Same with what you're saying about privacy, as the cost of invading it goes down, we need different controls, we can't just be cool with it because it was always hypothetically possible to hire a private investigator to stalk someone.
- vladms 2y ago> We need to raise them to an appropriate level I do not know what most people would find an appropriate level (I for one would prefer the current level, you would prefer a raised level). Somehow I feel the same about all the privacy discussions. Are people really understanding and would be impacted in the same why by privacy issues or is this just a fight between various interests with no connection with the actual people? To give an (extreme) example: without social networks elections will be influenced by newspapers and television. Would "the actual person" be much better of because he is influenced "by different people"? Sometimes I wonder how it would be if some things would be less private. (for example if wealth information would be less private, would it be harder for some people to do "dubious stuff", from straight illegal, to huge bonuses, etc.). I mean look at open source - is open source a result of "let's keep everything private and separate" idea or exactly the opposite... ?
- deathanatos 2y agoI feel like I'm missing some background. Yes, there's been much clamor for forcing use of government IDs recently, but I would hardly call any such system "decentralized", given its reliance on government ID — that seems like an inherently centralized system. Is someone calling these "decentralized"? To me, decentralized ID is OIDC, which is "being developed" it's mostly not catching on at all, in favor of sadly centralized system like "login with [Google|Facebook]". Is there some weird crypto-blockchain-something-something that I'm not aware of?
- bawolff 2y agoI think OIDC is more "federated" than "decentralized" I have no idea what the bitcoin people mean by decentralized. It sounds like PKI with extra steps. shrug
- mdavidn 2y agoOIDC has very much “caught on” in business contexts. Large organizations end up with hundreds or thousands of independent internal tools, many hosted externally. OIDC and SAML are common protocols for centralizing employee authentication and governance.
- fiddlerwoaroof 2y agoIt’s not really “OIDC”, though, because there’s so many options possible that the standard itself is basically useless: you have to implement Google, Microsoft, Okta, etc. separately anyways
- jebby 2y agoOIDC has for sure caught on. I've worked in multiple roles where very smart identity-centric people consider it the best option.
- bdd8f1df777b 2y agoIn my working context, a "decentralized" government issued (digital) ID refers to an identity whose verification does not require a connection to the government server (e.g. verification is done by public key cryptography). So the government always has to participate in the issuance of that digital ID, but it doesn't know when and where you have used your identity. ISO/IEC 18013-5 is an example of this type. By contrast, a "centralized" digital ID phones home every time it presents and verifies. I don't know any standards, but most digital identities in China are of this form.
- bawolff 2y agoKey management & binding keys to identities is one of the hard problems in cryptography. Cryptocurrency and friends really have no bearing on the problem. The known solutions are the same as they always were - web of trust, pki, tofu, pre-shared keys, or just give up and ignore the outside world. All have tradeoffs and are very far from satisfactory. If you take a subpar solution and wrap it in 10 layers of cryptocurrency and magical thinking, you are just left with a complex version of the same subpar solution.
- aaomidi 2y agoYep. There is no silverbullet. All these systems are doing are just increasing areas where a vulnerability in logic can happen.
- ugjka 2y agoIt must be tied to person's biological features, i don't see any other way. Some kind of crypto-bio hash
- hughesjj 2y agoYou can't revoke biological credentials though, at least not if you want the holder if those credentials to participate in your system
- bawolff 2y agoEven then you still have problems with revocation. If someone steals my passport, i tell the gov and they cancel the old one. If someone steals your fingerprint, you are just screwed. There are some systems that verify things like bloodflow to ensure that the finger belongs to a live person instead of a cut-off hand. However then you end up having the problem of needing to trust hardware, which is fine for an iphone unlock feature but not so fine for this magical decentralized web3 stuff.
- ugjka 2y agoAgreed, i need look more into this
- mattdesl 2y agohaving a cryptographic government-backed digital ID could really be a great and privacy-preserving feature of modern society. for example: ZK proofs are now practical, and could improve upon the status quo of sending a digital JPG of a scan of your passport to a third party for some arbitrary verification. The post reads a little bit overblown.
- anonym29 2y agoI will never upload photographs of my government-issued photo ID for any reason. I will never utilize any gov-backed digital ID. I will go down screaming, fighting, kicking, biting, and faxing my tax returns to the IRS, really doing everything lawful in my power to drag the whole system to a halt if digital ID gets forced on me. I don't care if I have to write a script that's going to trade bitcoin 800 times a second on 12 different exchanges, I don't care if I have to make my tax return 200,000 pages long and deliberately reorder the stack so that every single sheet is out of order, and it's all in a font that was deliberately chosen to be incompatible with OCR systems. If the US government will let me submit my tax returns in Farsi, Urdu, or Esperanto, or some other obscure language that the IRS would need to hire someone to translate, I will, just to add all of the absolute maximum pain, inefficiency, and suffering into this process. Keep pushing this shit on people who don't want it. Malicious compliance is like reflected DDoS attacks with huge asymmetric I/O sizes: I alone can easily force the government to waste 10,000+ hours of effort for each hour I put in, and what's more, I can and will write tutorials, open source all of this, and advertise it everywhere if digital ID does get forced on society. Problem with this? Stop pushing digital ID or start pushing to let me renounce my American citizenship without posessing another citizenship.
- mattdesl 2y agoDigital ID that I’m describing would be a way to avoid the current awful status quo of uploading your passport online (which, in the UK, has become common for things like banking, immigration, and other services). I’m not sure what your issue is.
- 2y ago
- megadal 2y agoThis entire article is just wrongly conflating Verifiable Credentials (VCs) with DIDs and then citing those false conflations as weaknesses of DID. > If decentralized ID is just an extension of the existing government ID system, it provides neither privacy nor financial inclusion. VC is a spec built on top of DID, in no way shape or form is VC required for DID. This statement alone shows the author doesn't understand (or is intentionally misrepresenting) the relationship between DID and VC (which is kind of crucial to write an entire blog post on either topic)
- megadal 2y agoAlso, the other points made aren't the reason VC was conceived. > And just like the existing system, it continues to exclude millions of people who can’t get government ID VC is a technology for convenience, not solving social problems. It's basically just to enable technologies like Tap to Pay but for your Gov IDs. E.g. rather than having to carry your drivers license you just carry your phone. It's almost as if the article misses the entire purpose for which VC is designed (but then again, what can one expect when they're criticizing DIDs yet -actually- talking about VC throughout the entire post)
- krunck 2y agoI reject any system that will require me to carry a phone. Phones are expensive, brittle, and annoying. Biometric is far better.
- adastra22 2y agoYou can't change your biometric password.
- megadal 2y agoI would much rather buy a new phone than stand in the DMV if I lost my driver's license. I thought I lost mine days ago and was ready to hop on TaskRabbit to employ a line stander. Also, biometrics to verify ID? Hard pass. Would rather not have to be fingerprinted or swabbed at the gas station for cancer sticks.
- filleokus 2y agoI'm reading the article as essentially saying "decentralised ID's dosen't solve anything". If you have them "backed" with governmentally issued ID's, they allow the government ID monopoly to continue (with all its claimed faults). If they are instead completely separate they will not be considered "valid" in most situations where ID's are required. Then the author warn against the whole idea of having one, single, strong identifier connected to your person at all, and urges for the option of creating multiple identities. In almost all circumstances where identification is required, the whole point of requiring ID falls apart of you can create a new one whenever you want. We can of course argue that the whole surveillance society is wrong. KYC requirements, no fly lists, credit scores etc, but any proposed system need to have these in consideration or forever only be applicable in niche environments. Feels like DID is just keybase.com (pre coin-spam and zoom acquisition) or pgp.mit.edu wrapped in a pyramid scheme.
- kiitos 2y agoIdentity (in any meaningful sense) must always delegate trust to some kind of issuing authority. If for no other reason than because any humane system must always accommodate users who forget their passwords, lose their private keys, etc. Key-pairs are ephemeral device tokens, they are not sources of identity. KYC is in no way any kind of problem that needs to be fixed, it's a necessary and Actually Good feature of any sufficiently broad financial system. Avoiding KYC-type stuff may make sense in the small, but is actively harmful in the large.
- crooked-v 2y agoMore important, I think, is that the issuing authority is also legally obliged to actually give a shit, or else you just get a repeat of the current state of affairs where, for example, forced 2FA and no customer support means homeless people get locked out of all their accounts every time a device fails or is stolen.
- vintermann 2y agoYes, and if there's any easy way to recover from that, then implicitly the identity system can't be used to prevent Sybil attacks/spam, since it would be easy to make a new account when you didn't lose your keys too. But the article suggests that relying on government issued IDs as a base lets government track all that we do. That's not the case, and is the point with all these systems. It should be possible for instance, using cryptography, to make a distributed chat room service where it's public who has signed up for a chat room, but not who of the posters in it are who. To be able to selectively prove your identity, including connection to the government-accountable you, without directly involving the government or even anything licensed by the government, would make us more free online, not less.
- brabel 2y agoThat's one of the big reasons why the EU is avoiding using DID. The author seems unaware that DIDs are now removed from the latest specs from the OIDC Working Group and EU's eIDAS.
- 2y ago
- Joker_vD 2y ago> But why do you need to verify a name? Why not take someone at their word, and allow them to choose what name they want to use? Why do all actions need to be linked to a single persistent physical identity? Why indeed. There is an adventure novel "The Count of Monte Cristo" in which, as a small subplot, two ex-convicts are made to pose as Italian nobility in the Parisian upper society. Of course, nobody would believe such claims just on their own word for obvious reasons, which is why an "introduction to the society" was a custom. It still could be faked, of course, which is exactly what happened. Also, why link it all to a single persistent physical identity? Because, no matter how many digital identities you use, you are still a single physical person, and it's actually noticeable.
- ggm 2y agoThe count gives both of them a significant line of credit: money overcomes much suspicion of this pair. Their assumed identities are a weapon, and I do not think the scam they are parties to helps your case.
- Joker_vD 2y agoWell, "their assumed identities are a weapon" is precisely my case, and I don't even argue that G.I. identification is actually that great of a solution. The con tricks are as old as humanity, even if they take different forms in different eras, but the ground problem is the same: if someone approcaches you and claims to be e.g. an important noble named such and such from the overseas, they could very well be telling truth—or they could be lying, and there is almost no way to tell for certain, even though there are some good heuristics (their wealth is one, as you allude to).
- ggm 2y agoPeople believe in them because the count backs them. It's totally facilitated by the count. He's like a corrupt CA signing the diginotar certificate
- 2y ago
- caporaltito 2y agoI think "The state won’t give up its monopoly on identity" is the most violently american sentence I read in the whole year.
- bhawks 2y agoI am who they say I am. Who gets to choose the they?
- soco 2y agoIf you choose to request and receive "their" services then "they" get a say. Thus, if you use stuff like roads, schools, ambulances, airports, insurances, or the police, then you are part of the society. Of course you can retreat in a forest and use none of those, then you have a valid point in rejecting central authorities, but only then.
- bhawks 2y agoNow I need to have an ID to bike down a road, ride a bus, report a crime? Do they also have a right to build a database of every time I utilize my ID? What's stopping them? I think there is already a large group of people who would prefer to live in a society without ceding that much power to a centralized authority.
- RandomLensman 2y agoAny ID system that isn't just totally run be each individual themselves is ceding power to someone. Whether you need an ID to do certain things or are tracked doing certain things is also a very separate issue. What is stopping "them" is that "them" in liberal democracies (as a technical term) isn't free to do whatever they please nor beyond control/recall/etc. If you want to live in a society, there will be rules, implicit or explicit, on how people interact, delegate, etc.
- raverbashing 2y agotogether with "I'm only traveling" and appearing on some YT video on roadstops with predictable but hilarious consequences
- BlueTemplar 2y ago> Unfortunately, it is unlikely that the state, who forces government ID regulations onto businesses, employers, landlords and healthcare providers, will accept web-of-trust vouches or biometrics as “proof of identity”. Having looked into it a little bit, web of trust (in the word of mouth / paper form) is already a legal proof of identity. It was legalized again after WW2, and government ID made optional again rather than mandatory, because the people that forced mandatory IDs on everyone were literally the Nazis. (Related previous history : factory owners and workers.) So looks like it's a matter of preservation of fundamental rights to insist on using web of trust rather than ID... and most specifically a question of everyday(ish) practice, so the question is how to best push back against the normalization of mandatory IDs ? (In which countries can you sue an administration / a business for refusing to work with you because you refused to provide them an ID ? Does it need to be escalated to civil disobedience and laws changed ? Other options ?) Of note : this is perhaps only a step in the "Police State-ification" of our societies. At some point, you didn't have a fixed first name / surname / address. But then (for instance) Hausmann demolished your neighborhood, made one more legible to the state instead, and next time the (Paris Commune) riots happened, they failed. It also made you easier to tax, but also brought better sanitation and "foreign" firefighters and ambulance drivers could actually quickly find you. The question is : how much (by definition, unnatural) state legibility is too much, how little is too little, and how to maintain homeostasis in the right range ?
- alfiedotwtf 2y agoCan’t we just go back to drawing a squiggle on a piece of paper where the verifying party kind of just eyeballs it and if it’s good enough (if they even looked at it in the first place), then it’s authenticated.
- vinay_ys 2y ago> With a web-of-trust, friends or family could vouch for your name, age or location; landlords could vouch for your address; employers could vouch for your skills; customers could vouch for businesses; and so on. As it doesn’t rely on government databases, but rather the people you know, it is truly decentralized and accessible. This is literally how it works in majority of the real world; except for things where government has a role to play; most common case is taxes. If you are a landlord and collect rent from tenant and if either of you want to make tax related claims to the government, then you will have to provide/quote each other's government recognized identity in your tax returns. For large parts of the population in the lower socio-economic strata, even this won't be relevant. And that reliance on that web-of-trust is the problem for them due to class discrimination etc. Hence, having a government issued identity (as a universal right) which acts as an anchor to which trusted attestations can be attached to is critical to make a difference in the life of the last person in that socio-economic line. This is in essence the basis for India's identity system Aadhaar[1] – which is super minimal identity system – just biometrics (fingerprint, iris scan, head/shoulder photo, gender) – mapped to a a 12 digit number (basically a unique key in its database); plus 3 additional demographic fields – name, age (date of birth), address – which require external anchor proofs (which are very weak proofs). Here's the full list of accepted proofs - https://uidai.gov.in/images/commdoc/valid_documents_list.pdf https://uidai.gov.in/images/commdoc/valid_documents_list.pdf 1. https://uidai.gov.in https://uidai.gov.in
- jgeada 2y agoWhy do people keep (deliberately?) confusing identity with authentication (and authorization)? 1) Identity is not supposed to be a secret, it is merely who you claim to be. It is no more secret than someone's name. Somewhat similar to the public key in a public key cryptosystem. 2) Authentication is the proving that who you claim to be is actually who you are. Many systems fail or don't even perform this step. Failure to do this causes wrong attribution of problems, it is why identity theft is not a failure of the victim but of the provider: a bank just took identity as if it was authentication and gave an unauthenticated user invalid access 3) Authorization: does the person who we've authenticated to be the person they claim to be actually have permissions to do what they're attempting to do. Not everyone with legitimate access to a system has the authorization to do everything. For example, maybe you can read a file, but not modify it.
- from-nibly 2y agoI dont want my identity to be public. Its not like a public key at all. My weight, height, eye color should only be as public as i make it. Thats all part of my identity.
- ShariSalinas77 2y ago[dead]
- kkfx 2y agoEhm... Actually "problem 2" is not a problem but a feature, at social level, and unfortunately some states start to think allowing private companies to give identities (for driving license or ID cards or "just" digital identities) to citizens-users. A democratic State is owned by their Citizens, formally at least, so only Citizens can identify other Citizens. Not really a monopoly but a safeguard not to be bannable by Google ID because some "terms violation" with no appeal. For really decentralized systems the classic chain-of-trust model is more than enough IF people really invest in it.
- letsSpy 2y ago[dead]
- zubairq 2y agoGood article. I predict that in the future government ID shops (like mobile phone shops today) will be everywhere as people will constantly be losing their ID and keys and will keep needing to reverify their identity
- amaliamaka381 2y ago[dead]
- PamelaKIngram 2y ago[flagged]
- debrahofstader 2y ago[dead]
- praestrudtulle 2y ago[dead]
- GustavaDell 2y ago[dead]