TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ethereum community has solved a major problem of the Internet: Single Sign-On

135 pointsby throwkeepalmost 4 years ago

17 comments

tptacekalmost 4 years ago
This is an extremely solved problem. Unless you have a dramatically interesting solution to the real hard problem, global account <i>recovery</i>, ordinary home users are effectively tethered to their email accounts, because that&#x27;s how you reset a login. Since you&#x27;re doing that already, &quot;Sign in with Google&quot; and &quot;Sign in with Apple&quot; are perfectly cromulent solutions and likely to continue dominating.<p>The actual last thing in the world home users want is an authentication system where credential loss is literally irrevocable.<p>Meanwhile, the real market for Internet SSO is at companies, and one of the major reasons companies deploy SSO is to have policy control (particularly: onboard and offboarding) of who has access to what. A globally distributed authentication fabric is actually an anti-feature for those people.<p>The actual last thing in the world corporate users want is an authentication system their IT department doesn&#x27;t control absolutely.<p>Part of what&#x27;s happening with ideas like this, and the reason Internet identity has been such a tar pit for the last 20 years, is that there isn&#x27;t one single service model for identity. Internet identity evangelists tend to overlook the fact that people have multiple identities on purpose.
评论 #27477821 未加载
评论 #27477660 未加载
评论 #27479483 未加载
评论 #27479770 未加载
评论 #27479771 未加载
评论 #27477730 未加载
评论 #27479202 未加载
评论 #27479172 未加载
评论 #27481145 未加载
whoknew1122almost 4 years ago
So the Director of Operations of ENS Domains says Ethereum has solved an extremely solved problem and one of the cornerstones of that solution is... wait for it... ENS Domains. Gotcha.<p>I also take issue with:<p>&gt;Ethereum is giving average ppl computer generated public&#x2F;private key pairs...<p>&#x27;Average&#x27; people aren&#x27;t into crypto. And the average computer user doesn&#x27;t know how to use asymmetric keypairs.<p>Anyone want to try to explain asymmetric keypairs to mother-in-law who&#x27;s in her 70s and needs help applying Windows patches? I sure don&#x27;t. And I spend my days in SAML and OAuth world.
评论 #27479625 未加载
评论 #27480124 未加载
评论 #27477852 未加载
mattbeealmost 4 years ago
There were loads of vendor-neutral identity ideas that all fell flat because nobody wants to sign up just for an identity.<p>This one is hilariously complicated; the thread ends with this call to action:<p><i>Want to get a portable web3 account?</i><p><i>Pick an Eth wallet: <a href="https:&#x2F;&#x2F;ethereum.org&#x2F;en&#x2F;wallets&#x2F;find-wallet&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ethereum.org&#x2F;en&#x2F;wallets&#x2F;find-wallet&#x2F;</a></i><p><i>Get ETH (sometimes built into wallet, otherwise use a service like Coinbase)</i><p><i>Get an ENS name: <a href="http:&#x2F;&#x2F;app.ens.domains" rel="nofollow">http:&#x2F;&#x2F;app.ens.domains</a></i> * (Choose which is your username by setting reverse record at My Account)*<p>It&#x27;s that easy!<p>I think the author underestimates how little most people care about their weak passwords, or centralised authentication.
评论 #27480144 未加载
评论 #27479643 未加载
ChrisArchitectalmost 4 years ago
the continued annoying arrogance of these crypto people, claiming things are just &#x27;web3&#x27; all of a sudden because they&#x27;ve built some crazy thing that seems to be outside the mainstream.... but then posting stupid twitter threads (seriously, use a fucking blog post) claiming they&#x27;ve solved identity, while ignoring all the world SSO and SSI people have been doing&#x2F;real work&#x2F;tackling issues and dealing with how real world people actually deal with (successfully&#x2F;not so successfully) with these things and the way users ended up with today password managers&#x2F;email still the internet&#x27;s killer app&#x2F;ID thing.<p>sigh.
评论 #27479792 未加载
评论 #27479797 未加载
saba2008almost 4 years ago
&gt; an average person having one username and password&#x2F;authentication method that works across all services<p>It&#x27;s a bug, not a feature. It&#x27;s people throwing away their privacy for convenience. It&#x27;s proverbial dancing piggies.<p>Problem with global-scale SSO is not corporations, that control shared identity. It&#x27;s shared identity itself.<p>Distributed SSO is as good idea, as eco-friendly vegan huffing solvent.
评论 #27477633 未加载
Imnimoalmost 4 years ago
There are a lot of downsides to &quot;Sign in with Google&quot;, but I am generally willing to accept them because I think I could recover my account if I lost my password. I&#x27;m not <i>certain</i> I could do so, because we&#x27;ve all read plenty of horror stories about Google&#x27;s customer support. But I don&#x27;t think I could recover an Ethereum private key. I&#x27;m sure there are esoteric ways of doing this. But ultimately what I want is the comfort that if worst comes to worst, there is a human somewhere on the planet who can reset my password for me. They might be hidden in a nigh-impenetrable labyrinth of automated emails, but they exist, and I could get them to help me if I make enough of a fuss on Twitter.
评论 #27480165 未加载
arcticbullalmost 4 years ago
Is this really what people want? Seems strange that a single set of keys or a passphrase would grant you access to not only your wallet - all your money - but also all your online services.<p>Am I missing something or is this just a fancy way of having a single password that gets you access to everything, and if compromised would be utterly devastating.
评论 #27482693 未加载
评论 #27477635 未加载
cors-flsalmost 4 years ago
This ENS thing could be interesting. It makes it possible to have a distributed identity. If only if Ethereum was not overinflated.<p>As a result, reserving a name on ENS costs 120$ a year. Few people would be ready to pay that to get a username.
评论 #27480179 未加载
skaalmost 4 years ago
It&#x27;s odd this thread doesn&#x27;t mention the sovereign self identity (SSI) efforts, DID Auth, etc. Folks who have been working in this area for years at this point and have some traction.
评论 #27477579 未加载
leppralmost 4 years ago
A lot of SSI is about delegating Sybil-resistance. Websites use Google or Facebook sign-on not just because it&#x27;s more convenient for users, but also because signing up many accounts on these services is a bore, thus managing spam.<p>If the sign-up process was as difficult for the small services as it is with Google or Facebook, users would give up. But users already have Google&#x2F;FB accounts or know it&#x27;s worth it to have one, so they don&#x27;t mind the process for Google&#x2F;FB.<p>For now, there&#x27;s no accepted standard identity mechanism attaching to ETH wallets. It&#x27;s not a trivial problem either. If while reading this you just had some idea how to quickly solve it, chances are someone had it before and it&#x27;s vulnerable to either centralized control or user abuse. ENS might work at deterring spam but it&#x27;s way too restrictive for now.
schlotziskalmost 4 years ago
That just sounds like OpenID with extra steps
评论 #27479012 未加载
kybernetikosalmost 4 years ago
I think a big advantage of current SSO systems as opposed to cryptowallet systems is that they usually come with a verified way to contact the user.<p>On the other hand, cryptowallet based sign in systems generally don&#x27;t give you a verified way to contact the user, but they do allow you to see if the user has put money behind this identity. That could be an interesting way to reduce sybil attacks. Having an email address does not mean much in terms of level of buy in to a particular identity (and that, much more than &#x27;real names&#x27; is key for managing behaviour).
dangalmost 4 years ago
Related thread:<p><i>“The Ethereum community has accidentally solved a major problem of the Internet</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=27473889" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=27473889</a> - June 2021 (14 comments)
deftalmost 4 years ago
This has already been solved, its called Public-key cryptography. Ethereum gave everyone a key, but usability issues have stifled making that useful offchain. ENS isn&#x27;t needed.
评论 #27480197 未加载
bluebirdfirewinalmost 4 years ago
That would be a step in the good direction. But the DID should be preferred as it will enable much more features.
browningstreetalmost 4 years ago
I’ve been trying to follow cryptocurrency conversations online… it’s amazing how much pumping and noise there is in every forum, Twitter thread, etc. Where are the real conversations happening?
corditealmost 4 years ago
How is this different from signing in with a yubikey that you can never lose?
评论 #27482731 未加载