TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Getting started with decentralized identity

80 点作者 ngould将近 3 年前

11 条评论

Animats将近 3 年前
As I said 48 days ago when this last came up on YC, the classic &quot;Why your idea for stopping spam sucks&quot; list applies.[1] Go re-read that and you&#x27;ll see the same identity problems and proposed solutions.<p>If people can create and abandon identities cheaply. they will use those identities for annoyance or fraud. Hence spam, robocalls, etc. This is also why the &quot;federated&quot; social networks are not too useful.<p>On the other hand, publicly visible identities that are very strongly tied to a person or physical place lead to strong tracking and the abuses associated with that.<p>So, explain how &quot;Web5&quot; avoids those problems.<p>[1] <a href="https:&#x2F;&#x2F;craphound.com&#x2F;spamsolutions.txt" rel="nofollow">https:&#x2F;&#x2F;craphound.com&#x2F;spamsolutions.txt</a>
评论 #32284143 未加载
评论 #32283223 未加载
评论 #32283068 未加载
评论 #32284240 未加载
Comevius将近 3 年前
The digital identity infrastructure space is already crowded, with players like Apple, Google and Microsoft working with governments and institutions, because they own the devices we use, and the entire point is that people will be able to use their phones to identify themselves everywhere. Apple ID is already like 90% there, despite having to trust Apple with your personal data, which nobody has a problem with. The Web3 approach of having to trust nobody is not really practical to begin with. Blockchains are slow and expensive. Worst yet it&#x27;s still up to you to verify the client and whether it&#x27;s connected to the authoritative version of the blockchain, since blockchains can be replaced by a fork. At that point you might as well trust Apple.
评论 #32283208 未加载
评论 #32282973 未加载
评论 #32282674 未加载
评论 #32284537 未加载
jeroenhd将近 3 年前
Blockchain. It&#x27;s always blockchain. Can we just not?<p>How about we go back to web 1.0. TLS mutual cert auth with an ID card as a smart card, either from the government or from your favourite third party.<p>Or maybe we go back to web 2.0 with OpenID. Users pick their own identity providers and websites can pick which ones to trust and which ones not to trust. Actually, we already have that, and it&#x27;s &quot;sign in with Google&#x2F;Facebook&#x2F;Apple&quot;.<p>If you&#x27;re a fan of stuffing Javascript everywhere you can, just use FIDO2&#x2F;WebAuthn before or after validating the user through OAuth.<p>Solutions exist. Nobody wants to implement them, it seems. Inventing new ways to do what has been done before doesn&#x27;t solve the problem, it just creates more dead protocols.
评论 #32286845 未加载
评论 #32287204 未加载
评论 #32287565 未加载
bawolff将近 3 年前
Are blockchain people physically incapable of speaking plainly?<p>Its hard to cut theough the buzzword bullshit, but this sounds like they reinvented PKI and added 10 billion layers of indirection.<p>Is there more to it than that? Or is this really just taking the latest technogies of the 1990s, and explaining it badly so people think they have invented something new?
评论 #32284386 未加载
smeej将近 3 年前
I like the idea that at least in web5, the term &quot;wallet&quot; might actually make sense, because the credentials or whatever actually &quot;live&quot; on your own device&#x2F;node.<p>Web3 should really use &quot;signet&quot; rather than &quot;wallet.&quot; Web3 is all about signing, attestation, and authentication through digital signatures. That&#x27;s what signets are for, not wallets.<p>Coinkite recently switched to the term &quot;signing device,&quot; but 1) that&#x27;s lame, and 2) &quot;signet&quot; already exists and means the same thing.<p>At least with web5, the wallet analogy works.
评论 #32283194 未加载
geonnave将近 3 年前
For the &quot;Learning resources&quot; section, I would also recommend checking ION¹. I have tested a few DID Methods including Sovrin, Veres One, and ION, and the latter is the most spec-adherent and well-implemented, apart from receiving funding from companies like Microsoft and TBD (which is proposing web5 in the first place). And yes, it is the only DID Method to receive support from big tech (was incubated within Microsoft, then donated to the Decentralized Identity Foundation), and it also happens to be a technically better solution.<p>Why I think it is better: (1) don&#x27;t need a new blockchain (re-uses Bitcoin&#x27;s); and (2) implements DIDs &#x2F; DID Documents with all needed features (e.g. last time I tried, Sovrin&#x27;s implementation did not support serviceEndpoints!)<p>¹ <a href="https:&#x2F;&#x2F;identity.foundation&#x2F;ion&#x2F;" rel="nofollow">https:&#x2F;&#x2F;identity.foundation&#x2F;ion&#x2F;</a><p>² <a href="https:&#x2F;&#x2F;www.coindesk.com&#x2F;markets&#x2F;2021&#x2F;03&#x2F;25&#x2F;microsofts-ion-digital-id-network-is-live-on-bitcoin&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.coindesk.com&#x2F;markets&#x2F;2021&#x2F;03&#x2F;25&#x2F;microsofts-ion-d...</a>
评论 #32287482 未加载
pabe将近 3 年前
DIDs recently became a web2 standard [1] that&#x27;s also embraced in web3 e.g. by Cardano &#x2F; Atala Prism [2].<p>[1] <a href="https:&#x2F;&#x2F;www.w3.org&#x2F;TR&#x2F;did-core&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.w3.org&#x2F;TR&#x2F;did-core&#x2F;</a><p>[2] <a href="https:&#x2F;&#x2F;atalaprism.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;atalaprism.io&#x2F;</a>
smoyer将近 3 年前
Two weeks ago I was part of a small group that met at IPFS Thing in Iceland. One very promising specification missing from this article is UCAN (from Fission) which provides a set of custom claims that can be added to a JWT to allow delegation of privileges in a decentralized environment. Definitely worth a look!
otikik将近 3 年前
Thanks, I hate it.<p>Web2 is not perfect but all the complexity brought by web&gt;2 is just not worth the bits it’s written in.<p>Make something simple and easy to use and understand, dammit. I don’t want my mum to call me because her identity provider for Instagram is down.
skeyo将近 3 年前
What happened to web4
评论 #32284385 未加载
评论 #32284147 未加载
评论 #32286600 未加载
Confiks将近 3 年前
The article completely misses the mark in creating some weird narrative about &#x27;web3 turning into web5&#x27;, all seemingly based on a wordplay announcement by Dorsey, thereby giving that project a lot of undue credibility.<p>In reality, many of the good projects and people referenced at the end of the article have been working for years without any notion that their projects are sprung out of some hyped but underspecified &#x27;web3&#x27; technology.<p>Dorsey&#x27;s &#x27;web5&#x27; clamor is mostly about (barely [1]) implementing some existing technology and then writing a bit of slideware around it [2], which proposes to magically &quot;allow individuals, organizations, and companies to publish credentials anyone can discover and independently verify&quot; while not spending any thought on how such a PKI would be (&quot;independently&quot;) governed without centralizing everything back again – an all too common failure mode of &#x27;web3&#x27; [3].<p>Meanwhile, both Dorsey&#x27;s slideware [4] and the actual specifications referenced [5][6] make bad technological choices with regard to privacy where users have stable identifiers (their public keys) which must be published, allowing them to be easily tracked across transactions.<p>While this can be used as a building block, no material on the &#x27;web5&#x27; website or the TBD54566975 Github repository (I guess it&#x27;s some other wordplay) indicates that they even recognize this as a problem, let alone that they propose how to solve it.<p>This is no new problem however: Sovrin – which many people referenced in the OP have worked on or with – has published a commentary on this back in 2018 [7]. There&#x27;s also a great talk by Christopher Allen if you need to refresh your memory about what you need to consider when designing identity systems [8].<p>Otherwise the OP can be a great introduction to identity, but please don&#x27;t feed the magical hypetrain.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;TBD54566975&#x2F;ssi-service#whats-supported" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;TBD54566975&#x2F;ssi-service#whats-supported</a><p>[2] <a href="https:&#x2F;&#x2F;developer.tbd.website&#x2F;docs&#x2F;Decentralized%20Web%20Platform%20-%20Public.pdf" rel="nofollow">https:&#x2F;&#x2F;developer.tbd.website&#x2F;docs&#x2F;Decentralized%20Web%20Pla...</a><p>[3] <a href="https:&#x2F;&#x2F;moxie.org&#x2F;2022&#x2F;01&#x2F;07&#x2F;web3-first-impressions.html" rel="nofollow">https:&#x2F;&#x2F;moxie.org&#x2F;2022&#x2F;01&#x2F;07&#x2F;web3-first-impressions.html</a><p>[4] See the diagram on page 9 of [2]<p>[5] <a href="https:&#x2F;&#x2F;identity.foundation&#x2F;decentralized-web-node&#x2F;spec&#x2F;" rel="nofollow">https:&#x2F;&#x2F;identity.foundation&#x2F;decentralized-web-node&#x2F;spec&#x2F;</a><p>[6] <a href="https:&#x2F;&#x2F;identity.foundation&#x2F;ion&#x2F;" rel="nofollow">https:&#x2F;&#x2F;identity.foundation&#x2F;ion&#x2F;</a><p>[7] <a href="https:&#x2F;&#x2F;sovrin.org&#x2F;wp-content&#x2F;uploads&#x2F;2018&#x2F;10&#x2F;What-Goes-On-The-Ledger.pdf" rel="nofollow">https:&#x2F;&#x2F;sovrin.org&#x2F;wp-content&#x2F;uploads&#x2F;2018&#x2F;10&#x2F;What-Goes-On-T...</a><p>[8] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=JzM_Brpk95E&amp;t=1574s" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=JzM_Brpk95E&amp;t=1574s</a>
评论 #32284242 未加载