sort\add critique\caution

This commit is contained in:
⧉ infominer 2023-06-29 06:45:12 +05:30
parent d14fdd6cde
commit 6a30f70e6e
6 changed files with 15 additions and 151 deletions

View File

@ -23,6 +23,8 @@ last_modified_at: 2023-06-07
> However, all of this has not proceeded without dissent and challenges. The 2018 Supreme Court verdict limited Aadhaar authentication only to public service delivery and taxation purposes, prohibiting even its voluntary use in the private sector.
* [Video] [India-stack and self-sovereign identity](https://www.youtube.com/watch?v=of-iuDZpWuA) EUBS 2022
> A panel discussion with Akhilesh Srivastava (IT Advisor at Government of Uttarakhand), Mallikarjun Karra (Director of Research And Partnerships at Timechain Labs), Prof. Sandeep Shukla (Computer Science & Engineering at Indian Institute of Technology Kanpur), Swapnil Pawar (Founder of Newrl) and Ishan Roy (Head of Blockchain at Tamil Nadu E-Governance Agency)
* [India Will Once Again Require Biometric Attendance for Government Employees](https://findbiometrics.com/india-will-once-again-require-biometric-attendance-government-employees-110505/) 2021-09-05 Find Biometrics
> Public institutions in India will soon be resuming their use of contact-based biometric sensors. Biometric authentication had been mandatory for all government employees prior to the pandemic, but the Indian central government was [one of several institutions](https://findbiometrics.com/biometrics-news-hyderabad-punjab-join-governments-banning-fingerprint-based-biometrics-amid-fears-covid-19-030602/) that [suspended the practice](https://findbiometrics.com/authorities-in-pakistan-india-suspend-biometric-attendance-systems-over-covid-19-concerns-902281/) due to health concerns following the outbreak of COVID-19.
* [Revisiting the non-personal data governance framework](https://www.orfonline.org/expert-speak/data-development-revisiting-non-personal-data-governance-framework/) 2020-12-30
> In July 2020, an expert committee established by the Ministry of Electronics and Information Technology (MEITY) released a report on the Non-Personal Data (NPD) governance framework for India. The document is well-intentioned in that it recognises the public value of data, and the need to democratise its use.
* [Video] [Self-sovereign identity system: Blockchain-based tech for identity verification](https://www.youtube.com/watch?v=Q7IhaY4eKEc) 2021-12-28 Economic Times

View File

@ -37,6 +37,8 @@ last_modified_at: 2023-06-15
> The EUs Digital Markets Act (DMA) is set to become law; it will require the biggest tech companies in the world (Apple, Google and Facebook, and maybe a few others) to open up their instant messaging services (iMessage, Facebook Messenger, Whatsapp, and maybe a few others) so that smaller messaging services can plug into them. These smaller services might be run by startups, nonprofits, co-ops, or even individual tinkerers.
* [The European Digital Identity Regulation](https://www.european-digital-identity-regulation.com/) 2023-04-08
> The Regulation amends Regulation (EU) 910/2014 on electronic identification and trust services for electronic transactions in the internal market (the eIDAS Regulation). This amendment is required, as digitalisation of all functions of society has increased dramatically. The provision of both public and private services is increasingly becoming digital after the COVID-19 pandemic.
* [The European Declaration on Digital Rights puts people in the firing line of the digital transformation](https://blog.xot.nl/2022/03/06/the-european-declaration-on-digital-rights-puts-people-in-the-firing-line-of-the-digital-transformation/index.html) 2022-03-06 Jaap-Henk Hoepman
> By focusing on the risk to individual citizens, the Declaration complete ignores the systemic risks introduced by the digital transformation (and in general the reliance on so called [programmable infrastructures](https://www.tudelft.nl/tbm/programmable-infrastructures), as expressed by Seda Gürses and Martha Poon among others).
* [Commission puts forward declaration on digital rights and principles for everyone in the EU](https://ec.europa.eu/commission/presscorner/detail/en/ip_22_452) 2022-01-26 EU Commission
> The draft declaration covers key rights and principles for the digital transformation, such as placing people and their rights at its centre, supporting solidarity and inclusion, ensuring the freedom of choice online, fostering participation in the digital public space, increasing safety, security and empowerment of individuals, and promoting the sustainability of the digital future.
>

View File

@ -79,7 +79,10 @@ toc_sticky: true
## Do you need a blockchain?
* [Self Sovereign Identity ≠ Blockchain](https://jolocom.io/blog/dezentrale-identitaten-%e2%89%a0-blockchain-2/) 2021-11-09 Jolocom
* [SSI-on-Blockchain is Objectively a Bad Thing](https://weh.wtf/ssi.html) 2022-07-08 Niko
> “Blockchain” in SSI exists for PR only, not for engineering reasons.\
> Note: I am only going to talk about the “blockchain” part of Self-sovereign Identity. Many things, good and bad, can be said about self-sovereign identity, but in order to keep the scope of this document manageable, Ill leave the broader SSI-discussion to others.
* [Self Sovereign Identity ≠ Blockchain](http://web.archive.org/web/20211205223357/https://jolocom.io/blog/dezentrale-identitaten-%E2%89%A0-blockchain-2/) 2021-11-09 Jolocom
> Due to the ID-Wallet project in Germany, some articles and comments have equated Self Sovereign Identity (SSI) with blockchain technology in the last few weeks. The impression is given that SSI only works in conjunction with a blockchain. Spoiler, thats not the case.
* [Do You Need Blockchain for Enabling SSI?](https://academy.affinidi.com/do-you-need-blockchain-for-enabling-ssi-452d62b34890) 2021-08-13 Affinidi
> We hope this will get you thinking about enabling SSI using an option that best suits your application or business requirement.

View File

@ -12,3 +12,5 @@ Central banks are realising CBDCs will have to be intimately linked to identity
* [New Video: MetaMUI SSID](https://sovereignwallet.medium.com/new-video-metamui-ssid-8bcef6281cf3) Sovereign Wallet
MetaMUI SSID is the worlds first true Self-Sovereign Identity Application that enables running Blockchain-Based E-Government System, and CBDC payments on top of MetaMUI Blockchain.
* [Video] [Dividing the Movement w. Alison McDowell (Separating Signal from Noise)](https://www.youtube.com/watch?v=awCcnstfhLY) 2022-03-08 Doom&GloomHQ
> Something that i found on some of the research that we were doing on the international bank of settlements (BIS). I don't like them, but I like the way that they present information sometimes. But CBDC 2.0 since we're moving toward that direction um they kind of called it a like a money flower. It has like four different sections which is: your accessibility, what kind of money, who issues that money, and then the technology that it

View File

@ -4,29 +4,14 @@ published: false
# Concerning
* [#Identity. Are we (the industry) the problem?](https://www.mydigitalfootprint.com/2021/08/identity-are-we-industry-problem.html) MyDigitalFootprint
It is evident that our ongoing discussions about identity, ethics, bias, privacy and consent revolve around a lot of noise (opinions) but little signal (alignment), but why?  Recognising that in 30 years of digital identity, we still lack coherent and coordinated action to make it work for everyone is a reality.
* [Facebook & Instagram outages expose the pain points of Centralized identity systems](https://blockchainmagazine.net/facebook-instagram-outages-expose-the-pain-points-of-centralized-identity-systems/)
For example, projects such as PhotoChromic are developing a biometrically managed self-sovereign identity on the blockchain utilising the feature sets of NFTs (non fungible tokens). Self-sovereign identity ensures that a user retains complete control over their identity without anyone else having access to it.
> For example, projects such as PhotoChromic are developing a biometrically managed self-sovereign identity on the blockchain utilising the feature sets of NFTs (non fungible tokens). Self-sovereign identity ensures that a user retains complete control over their identity without anyone else having access to it.
* [“The power to surveil, control, and punish”: The dystopian danger of a mandatory biometric database in Mexico](https://restofworld.org/2021/the-dystopian-danger-of-a-mandatory-biometric-database-in-mexico/) RestofWorld.org
there is a push by corporations and international institutions such as the World Bank to create these kinds of databases to identify people and conflate two things: the right of every person to be recognized legally by a government and an identification system that intermediates peoples transactions with public and even private services.
* [India Will Once Again Require Biometric Attendance for Government Employees](https://findbiometrics.com/india-will-once-again-require-biometric-attendance-government-employees-110505/)
Public institutions in India will soon be resuming their use of contact-based biometric sensors. Biometric authentication had been mandatory for all government employees prior to the pandemic, but the Indian central government was [one of several institutions](https://findbiometrics.com/biometrics-news-hyderabad-punjab-join-governments-banning-fingerprint-based-biometrics-amid-fears-covid-19-030602/) that [suspended the practice](https://findbiometrics.com/authorities-in-pakistan-india-suspend-biometric-attendance-systems-over-covid-19-concerns-902281/) due to health concerns following the outbreak of COVID-19.
> there is a push by corporations and international institutions such as the World Bank to create these kinds of databases to identify people and conflate two things: the right of every person to be recognized legally by a government and an identification system that intermediates peoples transactions with public and even private services.
* [Singapores tech-utopia dream is turning into a surveillance state nightmare](https://restofworld.org/2021/singapores-tech-utopia-dream-is-turning-into-a-surveillance-state-nightmare/) RestofWorld
“What [technology] will do for people is make our lives a hell of a lot easier, more convenient, more easily able to plug into the good life,” said Monamie Bhadra Haines, an assistant professor at the Technical University of Denmark, who studies the intersection between technology and society. “But … the surveillance is what is here, now.”
> “What [technology] will do for people is make our lives a hell of a lot easier, more convenient, more easily able to plug into the good life,” said Monamie Bhadra Haines, an assistant professor at the Technical University of Denmark, who studies the intersection between technology and society. “But … the surveillance is what is here, now.”
* [Portpass app may have exposed hundreds of thousands of users' personal data](https://ca.news.yahoo.com/portpass-app-may-exposed-hundreds-172257702.html)
The fderal privacy commissioner also said it has not yet received a report, and said it has contacted Portpass to seek further information in order to determine next steps, and that it is in communication with its provincial counterpart.
> The fderal privacy commissioner also said it has not yet received a report, and said it has contacted Portpass to seek further information in order to determine next steps, and that it is in communication with its provincial counterpart.
## "DIDAlliance"
@ -39,7 +24,7 @@ Here is a link to the [video presentation](https://www.youtube.com/watch?v=Zj44R
* [The business models of identity](https://blog.verim.id/the-business-models-of-identity-bb3336773727)
A post by Verim justifying their pay to play for Identity credentials.  Adding another layer of complication
### Very Worrying Development [Internet Identity: The End of Usernames and Passwords](https://medium.com/dfinity/internet-identity-the-end-of-usernames-and-passwords-ff45e4861bf7) via centralized issuance of a number?
* Very Worrying Development [Internet Identity: The End of Usernames and Passwords](https://medium.com/dfinity/internet-identity-the-end-of-usernames-and-passwords-ff45e4861bf7) via centralized issuance of a number?
## Breaches
U.S. Treasury breached by hackers backed by a foreign government
@ -87,7 +72,3 @@ Today, everyone including powerful actors and decision-makers like the UK
* [Bolt drivers in Nigeria are illicitly selling their accounts, putting passengers at risk](https://restofworld.org/2022/bolt-drivers-in-nigeria-are-illicitly-selling-their-accounts-putting-passengers-at-risk/) RestofWorld
“I asked the driver why the app showed me a different drivers face, and he claimed Bolt blocked his account so he was using his brothers.”
* [Is "acceptably non-dystopian" self-sovereign identity even possible?](https://blog.mollywhite.net/is-acceptably-non-dystopian-self-sovereign-identity-even-possible/) By Molly Wood ([Hacker News](https://news.ycombinator.com/item?id=31701601)
as more and more developers and companies and “blockchain visionaries” seek to eschew centralization and trust in the state and institutions, it seems that their definition of “acceptably” when they describe “acceptably non-dystopian” projects is very different from my own.

View File

@ -1,126 +0,0 @@
---
published: false
---
# Critique
* [SteveWilson](https://twitter.com/Steve_Lockstep/status/1524073204805160960) Considering SSI critics
> I reckon most cases of over-identification stem either from bad habits (e.g. RPs gathering circumstantial AuthN signals) or from Surveillance Capitalism. Either way, better deals for users will come from better design, not by weaponising Digital Identity (SSI, DIDs).
* [Negative press related to DIDs and VCs](https://lists.w3.org/Archives/Public/public-did-wg/2021Jun/0032.html) Manu Sporny (29 June)
Just drawing your attention towards this:
* [https://twitter.com/harryhalpin/status/1409615372538548227](https://twitter.com/harryhalpin/status/1409615372538548227)
![https://www.notion.soimages/image2.png](https://www.notion.soimages/image2.png)
* [https://lists.w3.org/Archives/Public/semantic-web/2021May/0177.html](https://lists.w3.org/Archives/Public/semantic-web/2021May/0177.html)
These are things that I would expect we would normally just ignore, but I've received a number of private emails over the tweet above from various decision making parties inside the EU requesting that we respond publicly to theses sorts of accusations.
The accusations are being taken seriously by some because Harry Halpin is ex-W3C staff. Also note that he his company is developing "competing technology" to DIDs and VCs.
Just raising awareness here as Harry's campaign is having a negative effect on adoption of VCs and DIDs.
Ted Thibodeau Jr Shares
it was not the only nor the first related tweet emanating from Harry --
* [https://twitter.com/search?q=W3C%20(DID%20OR%20%22Verifiable%20Credentials%22%20OR%20VCs)%20(from%3Aharryhalpin)&src=typed_query&f=live](https://twitter.com/search?q=W3C%20(DID%20OR%20%22Verifiable%20Credentials%22%20OR%20VCs)%20(from%3Aharryhalpin)&src=typed_query&f=live)
Nor has he limited his commentary to Twitter --
* [https://www.google.com/search?q=W3C+(DID+OR+%22Verifiable+Credentials%22+OR+VCs)+%22harry+halpin%22](https://www.google.com/search?q=W3C+(DID+OR+%22Verifiable+Credentials%22+OR+VCs)+%22harry+halpin%22)
* [An Examination of the Biases within Commercialized Identity](https://www.pingidentity.com/en/company/blog/posts/2021/biases-commercialized-identity.html) on [Hello User Podcast](https://www.pingidentity.com/en/company/podcast.html)
“There is no discipline for software engineers when it comes to identity and privacy due to the pace at which they are expected to build, but this will likely change because of liabilities and regulation.”
Takeaway #3: A potential side effect of the future of identity management could be a lack of anonymity.
“This exposes that gray area around allowing free speech while maintaining the right to privacy, and who should have access to authentication and verification.”
Takeaway #4: The technology exists to be able to create accountability models as it pertains to identity and to reduce misinformation.
“The challenge is having uncomfortable conversations to address the issues surrounding diversity.”
- [A rant about #trust following the terrific discussions at #IDPolicyForum](https://twitter.com/Steve_Lockstep/status/1357801068898308097) Steve Willson, Lockstep
> 9/9 "Trust over IP" #ToIP is such a misnomer. It just doesnt do what it says on the box. @trustoverip
## Sheldrake Vs SSI
* [dystopia of self-sovereign identity](https://www.philipsheldrake.com/2020/11/the-dystopia-of-self-sovereign-identity-ssi/#more-31058) by Philip Sheldrake
> A community is forming under the banner of generative identity. By generative I mean participating as nature. It denotes a capacity to produce unprompted change, growing not shrinking the possible; a capacity for leverage across a range of tasks, adaptability to a range of different tasks, ease of mastery, and accessibility
* [Self Sovereign Identity Critique, Critique.](https://identitywoman.net/self-sovereigh-identity-critique-critique/) IdentityWoman
> > if ever theres a technological innovation for which move fast and break things is not the best maxim, this is it.
>
> To think that some how this community who has been working very slowly and diligently for 15 years [...] is some how “moving fast” is preposterous.
* [Self-Sovereign Identity Critique, Critique /2](https://identitywoman.net/self-sovereign-identity-critique-critique-2/)
> It might be a surprise to you Philip but we have “an identity layer” that is used on the internet right now. It exists and billions use it every day (with standards we created out of the IIW community, Oauth and OpenIDConnect). The problem with it is [...] companies own the identifiers we anchor our digitial representations of ourselves
* [Self-Sovereign Identity Critique, Critique /3](https://identitywoman.net/self-sovereign-identity-critique-critique-3/)
> > When the SSI community refers to an identity layer, its subject is actually a set of algorithms and services designed to ensure the frictionless transmission of incorruptible messages between multiple parties. This involves some clever mathematics and neat code that will undoubtedly prove of some value in the world with appropriate tight constraints, and it will certainly impact the operation of various conceptualisations of identity, but this is not human identity per se, or the digitalization of human identity. Far from it, as we shall see.
> > THE DYSTOPIA OF SELF-SOVEREIGN IDENTITY (SSI)
>
> So again. When I say you dont understand the technology. I am reading things like this and asking myself what is he referring to?
* [Self-Sovereign Identity Critique, Critique /4](https://identitywoman.net/self-sovereign-identity-critique-critique-4/)
> Philips essay has so many flaws that I have had to continue to pull it a part
* [Self-Sovereign Identity Critique, Critique /5](https://identitywoman.net/self-sovereign-identity-critique-critique-5/)
> before you go pulling out and “waving around” the book Code: And other Laws of Cyberspace and saying “Code is Law” as if his work was a reason to NOT do anything in relationship to digital identity on the internet. He himself proposed an architecture for a certificate based digital identity system for the whole internet.
* [Self-Soverieng Identity Critique, Critique /6](https://identitywoman.net/self-soverieng-identity-critique-critique-6/)
> What is the point of doing this to show you are “smart” you arent the first guy to show up and say stop the presses I have figured out all of identity. “Pay attention to ME”.
* [Self-Sovereign Identity Critique, Critique /7](https://identitywoman.net/self-sovereign-identity-critique-critique-7/)
> We have now gotten to the Buckminster Fuller section of the document.
* [The Generative Self Sovereign Internet](https://www.windley.com/archives/2020/12/the_generative_self-sovereign_internet.shtml) Phil Windley
> Generativity is a function of a technologys capacity for leverage across a range of tasks, adaptability to a range of different tasks, ease of mastery, and accessibility.
* [Generative Identity](https://www.windley.com/archives/2021/01/generative_identity.shtml) - Phil Windley
> The Generative Self-Sovereign Internet explored the generative properties of the self-sovereign internet, a secure overlay network created by DID connections. [...]
>
> In this article, I explore the generativity of self-sovereign identity—specifically the exchange of verifiable credentials. One of the key features of the self-sovereign internet is that it is protocological—the messaging layer supports the implementation of protocol-mediated interchanges on top of it. This extensibility underpins its generativity.
* [Blockchain, Self-Sovereign Identity, and Selling Off Humanity](https://wrenchinthegears.com/2018/07/15/blockchain-self-sovereign-identity-and-selling-off-humanity/) Wrench in the Gears 2018-07-15
I think this piece is full of inaccuracies - it is also put together by someone really trying to understand a whole bunch of different things that some how get merged into being “all that bad blockchain technology that deprives people of dignity and rights” (Kaliya)
Its time activists began to develop a working knowledge of Blockchain and self-sovereign digital identity, because these are the mechanisms that will drive the transition to IoT monitoring for the purposes of Pay for Success deal evaluation
* [The European Declaration on Digital Rights puts people in the firing line of the digital transformation](https://blog.xot.nl/2022/03/06/the-european-declaration-on-digital-rights-puts-people-in-the-firing-line-of-the-digital-transformation/index.html) Jaap-Henk Hoepman 2022-03-06
By focusing on the risk to individual citizens, the Declaration complete ignores the systemic risks introduced by the digital transformation (and in general the reliance on so called [programmable infrastructures](https://www.tudelft.nl/tbm/programmable-infrastructures), as expressed by Seda Gürses and Martha Poon among others).
* [Dividing the Movement w. Alison McDowell (Separating Signal from Noise)](https://www.youtube.com/watch?v=awCcnstfhLY) Doom&GloomHQ
* [SSI-on-Blockchain is Objectively a Bad Thing](https://weh.wtf/ssi.html) Niko
“Blockchain” in SSI exists for PR only, not for engineering reasons.
Note: I am only going to talk about the “blockchain” part of Self-sovereign Identity. Many things, good and bad, can be said about self-sovereign identity, but in order to keep the scope of this document manageable, Ill leave the broader SSI-discussion to others.
* [Identity Cycle](https://iang.org/identity_cycle/) book by Iang
Identity Cycle is a book in four parts exploring the nature of identity and how it might or might not fit in a digital world
Oddly, unlike most other innovations, the efforts to build flexible large scale identity systems into the digital domain have more or less flopped. More, in that they did not seem to protect and serve people, and less in that they have done something, even as their original promises were discarded.
Philip Sheldraks new ANTI- SSI Paper
* [Human identity: the number one challenge in computer science](https://generative-identity.org/human-identity-the-number-one-challenge-in-computer-science/) Sheldrake
I find that many people working on digital identity today understand their undertaking solely in this bureaucratic context, even if they deny it, and they appear to operate therefore under the illusion that this somehow describes and supports our selves, culture, and nature, or at least has the qualities to do so.
## Response to Kailiyas post on AnnonCreds
* [A response to Identity Woman's recent blog post about Anoncreds](https://kyledenhartog.com/response-to-anoncreds-criticism/) Kyle Den Hartog
Its only when I started to take a step back that I realized that the architecture of Indy being a private, permissioned ledger leaves it heading in the same direction as many large corporations now extinct browser and intranet projects for many of the same reasons.
* [Moving Toward Identity Technology Ready for Mass Adoption](https://trinsic.id/moving-toward-identity-technology-ready-for-mass-adoption/)
when we realized our customers were facing critical limitations caused by the underlying tech stack, we began developing an updated version of our platform that would reduce our dependency on these technologies and enable a better platform for our customers.
* [Kai @Kai_dentity Replying to @IdentityWoman](https://twitter.com/Kai_dentity/status/1568559448876060675)
Great overview @IdentityWoman It matches with many conversations we had in the community in recent years, as well as observations we made ourselves at @GETJolocom. I hope it will help to make these issues more widely discussed and hopefully get them addressed.
* [Tim Bouma @trbouma Replying to @IdentityWoman](https://twitter.com/trbouma/status/1568583725092413444)
Excellent post. No matter how great a tech or framework is, I am always on the lookout for its Achilles heel.