Decentralized identity explained

Sdílet
Vložit
  • čas přidán 13. 08. 2020
  • What is decentralized identity? How does it give you more control over your digital identity and keep your information on the internet safer? This video explains in short what decentralized identity is and how it can replace usernames and passwords to verify you are who you say you are quickly and easily.
    Own your identity: msft.it/6003TUBI7
    ► Subscribe to Microsoft Security on CZcams here: aka.ms/SubscribeMicrosoftSecu...
    ► Follow us on social:
    LinkedIn: / microsoft-security
    Twitter: / msftsecurity
    ► For more about Microsoft Security: msft.it/6002T9HQY
    #DecentralizedIdentity #SelfsovereignIdentity #BlockchainIdentity
  • Věda a technologie

Komentáře • 76

  • @dileebanthilakaraja8702

    Confused.... When I start my Microsoft journey with Centralize solutions , like ADDS Domain, Now why this De- centralize solution?

  • @muthuraj5341
    @muthuraj5341 Před rokem

    Anybody know how to generate a DID for issuer

  • @karlcastor8692
    @karlcastor8692 Před 3 lety +6

    This is the easy part to centralise. What about LUA?
    How do we know that it was Alice how got the ID in the first place?

    • @MasterNeiXD
      @MasterNeiXD Před 2 lety

      Alice controls the private key of the DID that the school signed.

    • @karlcastor8692
      @karlcastor8692 Před 2 lety +3

      @@MasterNeiXD Yes..."Alice" have the key. I meant Levels of assurance (LOA), misspell from my part. How do we know that it was Alice that collected the key. Thats the hard part. Validation of the user collecting the ID in a manner that works for everyone without losing LOA.

    • @ulyssepinon9177
      @ulyssepinon9177 Před rokem

      @@MasterNeiXD same as for the credentials we use today, add biometrics

    • @MasterNeiXD
      @MasterNeiXD Před rokem

      @@karlcastor8692 oh, yeah. We need to trust the "issuers". The signers. If someone you trust, for example a big university, signed a message confirming a public key belongs to Alice, then you know it's true.

  • @RubberTag
    @RubberTag Před 3 lety +16

    Scary!

  • @shelbycobratOG
    @shelbycobratOG Před 27 dny

    Can it really be called "decentralized" if one person controls it?

  • @SSIKorea
    @SSIKorea Před 2 lety +1

    I know MS's identity is based on Bitcoin protocol. This is called ION. Hope to see it their products and sevices soon.

    • @genkiferal7178
      @genkiferal7178 Před 2 lety +1

      you don't like your freedom and privacy? Russian millioniares just had their yachts and townhouses taken from them - even if they were against the Russian invasion. Canadians protesting had their bank accounts frozen. This digital ID will mean the end of freedom.

  • @kamome3813
    @kamome3813 Před rokem +2

    "digital wallet generates a unique identifier"
    That's a hard thing to do with secure anti-counterfeiting.

  • @sprintwithcarlos
    @sprintwithcarlos Před 3 lety +3

    Shouldn't DID be revokable? Immnutability recording on a blockchain goes against that, don't you think?

    • @GabrielRodriguezInjectedFusion
      @GabrielRodriguezInjectedFusion Před 3 lety +4

      The Decentralized Identity Public Key Identifier is recorded for sure, but not necessarily the Identity Attributes. Think of it similar to a torrent file which is the metadata and link to a media file, however, the actual bits are stored and distributed in a decentralized fashion.

    • @sprintwithcarlos
      @sprintwithcarlos Před 3 lety +3

      @@GabrielRodriguezInjectedFusion I'm curious about how Microsoft has dealt with revocation. I've been studying the subject and I haven't found a clear demonstration on this. W3C specs for DIDs are defined very broadly, it's still a work in progress. I think the only way to really achieve revocability is by hosting the DID on users' device. It's the only way to wipe out the DID for sure. Blockchain is unnecessary IMHO and can be perfectly replaced by IPFS or using hypercore protocol (formally dat)

    • @GabrielRodriguezInjectedFusion
      @GabrielRodriguezInjectedFusion Před 3 lety +3

      @@sprintwithcarlos It's important to note the DID address itself is what is committed to a blockchain, not the details of the identity. There really isn't any big deal about a randomized DID address existing on a distributed public ledger. That's just the lookup and points the way to more conventional datastore that actually hosts the identity details and attributes itself. So in terms of revocation, Alice with the private key controls who has access and can grant and revoke access anytime to her identity details & attributes. Lastly, it is possible for Alice to completely block all access to her identity trust stores and her mobile phone and also cloud-storage providers. Then delete her private key. This also known as cryptographic deletion.

    • @johannessedlmeir3045
      @johannessedlmeir3045 Před 3 lety

      Why would you need to store Alice's identifier/public key in a public registry anyway, and who would register it? To verify credentials, publishing the issuer's public signing key should be sufficient.

    • @sprintwithcarlos
      @sprintwithcarlos Před 3 lety +1

      @@johannessedlmeir3045 According to W3C specs, since DID should resolve to a DID document, you need a "verifiable data registry". Beside a blockchain, it could be also a distributed ledger, decentralized file system, distributed database, peer-to-peer network, etc. The identifier does not include the public key, is just an URI that resolves to a DID document. The public key then could be included in that document. At the beginning I also thought that sharing everything with a JWT will suffice but since attributes can change after the issuance developmentdecentralizeddon't require such a huge infrastructure. For a peer DID, no blockchain should be necessary

  • @DocaTafner
    @DocaTafner Před 3 lety +2

    I'm losing momentum. This is a great topic.

  • @CarloReggiani
    @CarloReggiani Před 3 lety +1

    In Italy we have SPID and CIE!

  • @Alfredito999
    @Alfredito999 Před 3 lety +1

    What if fingerprint is replicated

    • @GabrielRodriguezInjectedFusion
      @GabrielRodriguezInjectedFusion Před 3 lety +5

      That's why security systems should still leverage Multi-Factor-Authentication. For Alice to use her private keys within her digital identity wallet should only happen after multiple forms of proof are presented. In the example, something like Alice's fingerprint should be given (something Alice has) AND the pin number (something Alice knows). Additional challenge proofs requirements, e.g., one-time-passwords, hardware security tokens, etc. can be enforced depending on the security level required.

    • @sprintwithcarlos
      @sprintwithcarlos Před 3 lety +2

      Replication is almost impossible because the pseudonym ID is cryptographically generated and secured with a biometric proof or a pin only known by the user. It's how Bitcoin uses and in 10 years nobody has broken the system. The only way a hacker would have to grant access to another account is by obtaining both the private key and the pin. Self sovereign identity users should understand this and act accordingly (handling the storage of credentials in a secure way).

  • @argusfest
    @argusfest Před 2 lety +12

    Life on the blockchain will be increasingly controlled and managed by inhuman technocratic artificial intelligence.

    • @colenewaltersmusicandother9330
      @colenewaltersmusicandother9330 Před 2 lety

      While human intervention is the Block chain.

    • @mvrtgt
      @mvrtgt Před 11 měsíci

      Depends if the blockchain is decentralized than it is okay.

    • @argusfest
      @argusfest Před 11 měsíci +2

      @@mvrtgt The protocol (rules) are centralized. Only the storage and automated operation is decentralized. It doesn't give power to people. Quite the opposite.

    • @aristidequercetti7587
      @aristidequercetti7587 Před 8 měsíci

      ​@@argusfestquindi è una trappola?

  • @nicedaygraphics
    @nicedaygraphics Před 3 lety +15

    Credit cards today are very much traceable indeed. This offers the same. It's even more centralized identity. Don't think Microsoft thought that one through,

    • @nordle4208
      @nordle4208 Před 2 lety

      This isn’t microsoft's idea xD they just jump on the train because this is inevitable…
      Digital id’s are coming only question is will they be decentralized, or are we going the chinese way of dictatorship (centralized)

    • @taryn2736
      @taryn2736 Před 2 lety +3

      A centralized Chinese-style all-encompassing social credit system is the goal. Everything about this was thought through thoroughly.

    • @genkiferal7178
      @genkiferal7178 Před 2 lety +1

      @@taryn2736 exactly. one world government and all of us underlings will be serfs, peons and easily controlled. The US president just signed a bill to give all new cars sold 5 years from now a kill switch. So, if a big protest is coming, your car, your ability to buy gas, or food, or a bus ticket or poster board could easily be stopped. Heck, they could do that for everyone everywhere for a few days until they could figure out where the threat was.
      Covid-19 lockdowns were a small taste of what was to come.

  • @notmebeingme461
    @notmebeingme461 Před 3 lety +6

    I'm still confused about how the problems have been solved. in short, it's the same thing, but in a new format.

    • @aresgood1
      @aresgood1 Před 2 lety +1

      yes. this video is crap. it just claims you can prove to someone you are not a robot if you just show them a bunch of people who agree you are human.
      but how is this system supposed to trust that bunch of people? how does it know they are not all bots? do they also ask them for people who agree they are human? doesn't work, unless you have at some point some authority you can trust that just decides who is a robot and who is human. the bitcoin people have tried this every way imaginable and they can't .

    • @ragnarok7976
      @ragnarok7976 Před 2 lety +6

      @@aresgood1 that's not the problem this is trying to solve.
      Just like with "sign in with google/Facebook etc" You have an identity with that provider. Other companies/or applications can leverage that identity to know who you are with out you having to repeat your information to them. None of that can prove you weren't a bot in the first place. If you do happen to be a human though it can give you more control over where you store your data, who has access, and a single company can't just delete that identity on you.
      The key word is "decentralized".

    • @aresgood1
      @aresgood1 Před 2 lety +1

      @@ragnarok7976 yeah. it claims to be decentralized, and it workd by giving you multiple providers. so it's centralized around them

    • @ragnarok7976
      @ragnarok7976 Před 2 lety +2

      @@aresgood1 Not exactly. MS is providing the initial service but they don't really control much once the ball is rolling. They will post the public key to a block chain but they can't remove it once that is done. They might provide the blockchain service but most of the talk I've seen say MS won't be making their own block chain they will use one that already exists like say bitcoin. Theoretically though this method would work on any block chain.
      That's the decentralization. No one really "owns" a blockchain or can mutate data that has been added to it. Not to say I implicitly trust MS but if the implementation is how they claim it is the science and math behind is sound.

    • @aresgood1
      @aresgood1 Před 2 lety +3

      @@ragnarok7976 i am suck and tired of people claiming something is decentralized just because it's on a block-chain. if the block-chain has to interact with entities outside the blockchain, and these entities are centralized, then so is the system.

  • @skypygmy1369
    @skypygmy1369 Před rokem +15

    Digital identity is the beginning of a prison planet

    • @mvrtgt
      @mvrtgt Před 11 měsíci +2

      Decentralized Identity is the solution.

    • @kobeshaq1320
      @kobeshaq1320 Před 10 měsíci

      arcblock abt@@mvrtgt

    • @aristidequercetti7587
      @aristidequercetti7587 Před 8 měsíci +1

      ​@@mvrtgtchi ti assicura che sia realmente decentralizzato?

  • @Simpaulme
    @Simpaulme Před měsícem

    So, three years later, where is it?

  • @kewlbeone5949
    @kewlbeone5949 Před 2 lety +13

    These people are monsters.

    • @genkiferal7178
      @genkiferal7178 Před 2 lety +1

      they must be stopped before this digital ID takes effect, before it is too late.

  • @Spithreus
    @Spithreus Před 3 lety +5

    Can't wait for this to become standard in usage and development.

    • @padkirsch
      @padkirsch Před 3 lety

      @Rene Elon lol yes right

    • @padkirsch
      @padkirsch Před 3 lety

      @Kenzo Wilder lol yea right

    • @genkiferal7178
      @genkiferal7178 Před 2 lety

      why not just rob a bank if you want to live in a prison. that is what a digital ID will be - a technocracy that will imprison most people.

  • @ytPiglet
    @ytPiglet Před 13 dny

    They glazed over the organization that issues standards-based credentials, which is just another centralized authority.

  • @user-nn9zf5io2h
    @user-nn9zf5io2h Před 3 lety +4

    This not required as this app designed to trace you...

  • @QUANT_PAPA
    @QUANT_PAPA Před rokem

    Quamfy

  • @enjay8950
    @enjay8950 Před 2 lety +8

    yeah no, this is all round a bad direction

  • @luckyguy600
    @luckyguy600 Před 2 měsíci

    Sheeple cards

  • @saimak7079
    @saimak7079 Před 2 lety +3

    No thanks

  • @ETERNAL_MODS
    @ETERNAL_MODS Před 2 lety +2

    LOLLLLLLLLLLLLLLL ITS ALL ABOUT N4Z1 CENTRALISED CONTR0L BE YOUR OWN BANK WITH BTC NOT THIS G0V PL4N

  • @nonyabuiz2023
    @nonyabuiz2023 Před rokem +1

    Nope, it’s enslavement