@windley 's last book landed on "identity is about relationships, not identifiers." The new one is the sequel to that idea: once you know the relationship, what does it actually let you do?
Authorization in Action, out from Manning.
To rent a car, you proved you have a license.
The system kept six high-res scans of it β front, back, infrared, ultraviolet, each timestamped.
153M of those allegedly ended up in a dark web catalog last week.
Verification should be an event, not a permanent file.
https://t.co/Qw1TogGa7B by @briankrebs
π¨We DID IT!π¨
"The British people were clear that they do not want mandatory ID. The government backing down shows what campaigns like Big Brother Watch's can achieve"
"But the dangers of a 'papers please' society have not gone away. Big Brother Watch is concerned that the government's approach to social media restrictions will lead to a de facto mandatory ID regime for the internet"
"If this is a signal, it is a positive one, but we must all keep a wary eye on Tony Blair's former ID card minister" - Jack Coulson, Head of Advocacy at Big Brother Watch (@JCoulson1013)
// F-Droid, the open-source Android app store, calls Google's developer verification an "existential threat" to alternative app distribution. The EFF warns it creates a pathway to censorship. https://t.co/mxxPuXAusz #KeepAndroidOpen
this is really fuck up :P
The takeover needed two things: Meta holding your account, and Meta's own centralized AI acting on it β a provider-controlled agent you can't sandbox.
Self-sovereign identity + local agents close each gap. Both, as @VitalikButerin says.
meta gave their AI support agent the ability to modify your instagram account. no identity verification. people figured this out and accounts are being taken over right now
@VitalikButerin Two failures stacked: Meta custodies your account (so a master key exists), and Meta runs the agent β centralized, over-permissioned, not yours to sandbox.
Self-sovereign identity kills the first; CROPS-style local agents kill the second. You need both.
One OpenAC spec, many credentials: @PrivacyEthereum on the national citizen cert, us across passport / SD-JWT / mDoc.
All proven client-side on iOS via mopro. This is what privacy-preserving identity over deployed PKI actually looks like.
Let's converge.
Great to see OpenAC proving the Taiwan Citizen Digital Certificate in production.
We've been implementing the same OpenAC design in Noir β but credential-agnostic: ePassport (RSA DSCβSOD), SD-JWT, mDoc and X.509, all with prepare/show-link.
Code -> https://t.co/pTOQYODllX
We built a real-world OpenAC implementation for privacy-preserving proof of personhood.
It uses an existing government-issued credential, proves eligibility in zero knowledge, supports revocation checks, and runs the proof flow on mobile devices.
Check threads for links and summary π
@PrivacyEthereum Builders here π we've been implementing OpenAC in Noir across multiple credentials β ePassport (RSA DSCβSOD), SD-JWT, mDoc, X.509 β all prepare/show-link, proving on-device via mopro (iOS).
Would love to compare notes on the spec with @PrivacyEthereum
https://t.co/pTOQYODllX
Your phone probably has 2,000 contacts in it. How many of those people have you actually met?
Solid(ar)ity keeps track of the ones you have. When you meet someone, the handshake gets cryptographically signed, so what ends up in there is a real record, not a name you typed in once and forgot about.
LinkedIn shows who people claim to be. This is more about who you've actually crossed paths with.
It isn't really another identity wallet; that wasn't the point. It's just a way of holding onto the people you meet. Tap phones, leave a short note, and the moment stays.
A single envelope in a world of postcards is suspicious, but a world of envelopes is just mail.
We keep stressing privacy precisely because we're all living in a world that doesn't take it seriously. it's sad, but that's the reality right now. We've been thinking about and exploring use cases where privacy is the default, and where everyday users don't need to know about it.
Proof of personhood doesn't need a $1,000 orb scanning your eyeball. Your passport chip is already signed by a government. Yes @worldnetwork , we're talking about youπ
@Independent : 32% of kids aged 9β16 have bypassed age verification. 46% say it's easy. 26% of parents allow it. 17% actively help them do it.
You can't enforce your way out of this. It's a design problem.
Solidarity does it differently: scan your passport's NFC chip, generate a ZK proof on your phone, prove you're 18+ to any site. Your name, birthday, document number never leave the device.
https://t.co/LQJkmgaxgJ
good to see more passport ZK out there. we took a different angle: proof runs fully on-device, no server in the path. credential isn't the endgame for us. every IRL meeting is an edge in your own graph.
Traditional ID upload verifications are a broken system: now users can spin up hyperrealistic images of false IDs with just a few prompts.
Self solves this without sacrificing user privacy by reading the NFC chip rather than the image.
Just shipped Solidarity 1.3.0
almost a year since launch and this is the first build that actually feels like a product instead of a hackathon repo lol
finally got a designer in (not AI !!) β cream + pink palette, animal avatars, sakura petals, the whole thing
@p2p_solidarity
Introducing Solid(ar)ity 1.3.0
A local-first, peer-to-peer identity wallet. Your identity credentials never leave your device. Identity is verified by zero-knowledge proofs β no central server, no oversharing.
This is our biggest update yet, and the first time we're properly introducing @p2p_solidarity to the world.
What's new in 1.3
Β· Brand-new light theme
Β· Chunked QR codes for richer credentials
Β· Reply inside the proximity radar
Β· Manual contact entry
Β· Steadier iCloud backup and restore
Β· Redesigned Settings
All offline-capable. All peer-to-peer. All on your device.
Privacy isn't a setting. It's an architecture.
Solid(ar)ity 1.3 is live on the App Store.
1/ π± The zkID team published OpenAC: Open Design for Transparent and Lightweight Anonymous Credentials earlier this week with a show proof time of 0.129 seconds.
It describes a zero-knowledge identity construction designed to work with existing identity stacks and was purposely constructed to be compatible with the European Digital Identity Architecture and Reference Framework (EUDI ARF).
https://t.co/1T8QxFxuJT